diff --git a/.env.example b/.env.example deleted file mode 100644 index 4091938..0000000 --- a/.env.example +++ /dev/null @@ -1,16 +0,0 @@ -# Copy this file to .env and fill in your values. -# Then run: docker compose up -d - -# Your TorrentClaw API key (required). -# Get it at: https://torrentclaw.com/settings/api-keys -UNARR_API_KEY=tc_your_key_here - -# Absolute path to your media / downloads folder. -# This is where finished movies and shows will be saved. -DOWNLOAD_DIR=/home/youruser/Media - -# (Optional) Config directory — defaults to ./config next to this file. -# CONFIG_DIR=/home/youruser/.config/unarr - -# (Optional) Timezone for logs. -# TZ=Europe/Madrid diff --git a/.forgejo/workflows/docker-rebuild.yml b/.forgejo/workflows/docker-rebuild.yml deleted file mode 100644 index 34cc3d6..0000000 --- a/.forgejo/workflows/docker-rebuild.yml +++ /dev/null @@ -1,61 +0,0 @@ -# Rebuilds and re-pushes the `latest` image without a version bump so newly -# *fixed* Alpine / ffmpeg / Go patches land between tagged releases. Versioned -# tags are immutable and never touched here. Runs weekly and on demand. -name: Docker rebuild - -on: - schedule: - # Mondays 04:17 UTC (off the hour to avoid the scheduler rush) - - cron: "17 4 * * 1" - workflow_dispatch: - -jobs: - rebuild: - runs-on: docker - container: - image: docker.io/library/docker:27-cli - steps: - - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Install build deps - run: apk add --no-cache curl git bash - - - name: Install buildx - run: | - mkdir -p ~/.docker/cli-plugins - curl -sSL https://github.com/docker/buildx/releases/latest/download/buildx-linux-amd64 \ - -o ~/.docker/cli-plugins/docker-buildx - chmod +x ~/.docker/cli-plugins/docker-buildx - - - name: Set up qemu - run: docker run --rm --privileged tonistiigi/binfmt --install all - - # Stamp the binary with the most recent release tag (not "dev"). - - name: Resolve version - id: ver - run: | - v=$(git describe --tags --abbrev=0 2>/dev/null || echo dev) - echo "version=$v" >> "$GITHUB_OUTPUT" - - - name: Login to Docker Hub - env: - DH_USER: ${{ secrets.DOCKERHUB_USERNAME }} - DH_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} - run: echo "$DH_TOKEN" | docker login -u "$DH_USER" --password-stdin - - - name: Build + push (refresh latest) - env: - VERSION: ${{ steps.ver.outputs.version }} - run: | - docker buildx create --name builder --use --driver docker-container - # Refresh the floating tag only — never overwrite a versioned release. - # Force a fresh base pull so apk upgrade picks up new patches. - docker buildx build \ - --platform linux/amd64,linux/arm64 \ - --build-arg "VERSION=$VERSION" \ - --tag "torrentclaw/unarr:latest" \ - --no-cache \ - --push \ - . diff --git a/.forgejo/workflows/release.yml b/.forgejo/workflows/release.yml deleted file mode 100644 index d757612..0000000 --- a/.forgejo/workflows/release.yml +++ /dev/null @@ -1,118 +0,0 @@ -name: Release - -on: - push: - tags: - - "v*" - workflow_dispatch: - -permissions: - contents: write - -jobs: - release: - runs-on: docker - container: - image: docker.io/library/golang:1.25 - steps: - - uses: actions/checkout@v4 - with: - fetch-depth: 0 - - - name: Install build deps (bash, curl, jq, ffmpeg fetch deps) - run: | - apt-get update - apt-get install -y --no-install-recommends bash curl ca-certificates jq xz-utils unzip - - - name: Install goreleaser - run: | - curl -sSfL https://github.com/goreleaser/goreleaser/releases/latest/download/goreleaser_Linux_x86_64.tar.gz \ - | tar -xz -C /usr/local/bin goreleaser - - - name: Run goreleaser - env: - # Forgejo runner auto-injects GITHUB_TOKEN (a per-job, instance-scoped - # token usable against the Forgejo REST API). goreleaser only accepts - # one token; with both GITHUB_TOKEN + GITEA_TOKEN set it errors out - # ("multiple tokens"). Unset GITHUB_TOKEN before invoking goreleaser so - # it picks the Gitea code path + the gitea_urls block in .goreleaser.yml. - GITEA_TOKEN: ${{ secrets.GITHUB_TOKEN }} - SENTRY_DSN: ${{ secrets.SENTRY_DSN }} - # Empty when RELEASE_SIGNING_PUBKEY variable is unset — goreleaser - # accepts it and the resulting binary disables signature checks - # (back-compat: pre-signing releases continue to update). Set - # RELEASE_SIGNING_PUBKEY (variable) + RELEASE_SIGNING_KEY (secret) - # to turn verification on. - RELEASE_SIGNING_PUBKEY: ${{ vars.RELEASE_SIGNING_PUBKEY }} - run: | - unset GITHUB_TOKEN - goreleaser release --clean - - - name: Sign checksums.txt with ed25519 - if: ${{ vars.RELEASE_SIGNING_PUBKEY != '' && secrets.RELEASE_SIGNING_KEY != '' }} - env: - RELEASE_SIGNING_KEY: ${{ secrets.RELEASE_SIGNING_KEY }} - RELEASE_TAG: ${{ github.ref_name }} - FORGEJO_TOKEN: ${{ secrets.GITHUB_TOKEN }} - # Tailscale IP — domain-agnostic; the runner shares the dokploy-network with - # forgejo (hostname `forgejo`), so the in-cluster hostname is fastest, but the - # Tailscale IP is the documented fallback. - FORGEJO_API: http://forgejo:3000/api/v1 - REPO: torrentclaw/unarr - run: | - set -euo pipefail - go run ./scripts/sign-checksums \ - -key "$RELEASE_SIGNING_KEY" \ - -in dist/checksums.txt \ - -out dist/checksums.txt.sig - - # Find the release ID for this tag, then upload the sig as an asset. - rel_id=$(curl -sSf "$FORGEJO_API/repos/$REPO/releases/tags/$RELEASE_TAG" \ - -H "Authorization: token $FORGEJO_TOKEN" | jq -r '.id') - curl -sSf -X POST \ - "$FORGEJO_API/repos/$REPO/releases/$rel_id/assets?name=checksums.txt.sig" \ - -H "Authorization: token $FORGEJO_TOKEN" \ - -F "attachment=@dist/checksums.txt.sig" - - docker: - needs: release - runs-on: docker - container: - # Docker-in-Docker capable image — buildx + qemu pre-installed. - image: docker.io/library/docker:27-cli - steps: - - uses: actions/checkout@v4 - - - name: Install buildx - run: | - apk add --no-cache curl - mkdir -p ~/.docker/cli-plugins - curl -sSL https://github.com/docker/buildx/releases/latest/download/buildx-linux-amd64 \ - -o ~/.docker/cli-plugins/docker-buildx - chmod +x ~/.docker/cli-plugins/docker-buildx - - - name: Login to Docker Hub - env: - DH_USER: ${{ secrets.DOCKERHUB_USERNAME }} - DH_TOKEN: ${{ secrets.DOCKERHUB_TOKEN }} - run: echo "$DH_TOKEN" | docker login -u "$DH_USER" --password-stdin - - - name: Set up qemu - run: docker run --rm --privileged tonistiigi/binfmt --install all - - - name: Build + push multi-arch image - env: - VERSION: ${{ github.ref_name }} - run: | - set -euo pipefail - VERSION_SEMVER="${VERSION#v}" - MAJOR_MINOR="${VERSION_SEMVER%.*}" - docker buildx create --name builder --use --driver docker-container - docker buildx build \ - --platform linux/amd64,linux/arm64 \ - --build-arg "VERSION=$VERSION" \ - --tag "torrentclaw/unarr:$VERSION_SEMVER" \ - --tag "torrentclaw/unarr:$MAJOR_MINOR" \ - --tag "torrentclaw/unarr:latest" \ - --push \ - . diff --git a/.forgejo/workflows/ci.yml b/.github/workflows/ci.yml similarity index 61% rename from .forgejo/workflows/ci.yml rename to .github/workflows/ci.yml index 82ee799..7dabcc4 100644 --- a/.forgejo/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -12,26 +12,35 @@ permissions: jobs: test: name: Test - runs-on: docker - container: - image: docker.io/library/golang:1.25 + runs-on: ubuntu-latest + strategy: + matrix: + go-version: ["1.25"] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: ${{ matrix.go-version }} - name: Run tests run: go test -v -race -count=1 ./... build: name: Build - runs-on: docker - container: - image: docker.io/library/golang:1.25 + runs-on: ubuntu-latest strategy: matrix: goos: [linux, darwin, windows] goarch: [amd64, arm64] steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.25" - name: Build env: @@ -41,30 +50,30 @@ jobs: lint: name: Lint - runs-on: docker - container: - image: docker.io/library/golang:1.25 + runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - - name: Install golangci-lint - run: | - curl -sSfL https://raw.githubusercontent.com/golangci/golangci-lint/v2.11.4/install.sh \ - | sh -s -- -b /usr/local/bin v2.11.4 + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.25" - name: Run golangci-lint - run: golangci-lint run ./... + uses: golangci/golangci-lint-action@v9 + with: + version: v2.11.4 coverage: name: Coverage - runs-on: docker - container: - image: docker.io/library/golang:1.25 + runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 - - name: Install python3 - run: apt-get update && apt-get install -y --no-install-recommends python3 + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.25" - name: Run tests with coverage (all packages) run: | @@ -93,13 +102,24 @@ jobs: print('OK: Coverage meets minimum threshold') " + - name: Upload coverage to Codecov + uses: codecov/codecov-action@v6 + with: + files: ./coverage.out + fail_ci_if_error: false + env: + CODECOV_TOKEN: ${{ secrets.CODECOV_TOKEN }} + vet: name: Vet - runs-on: docker - container: - image: docker.io/library/golang:1.25 + runs-on: ubuntu-latest steps: - - uses: actions/checkout@v4 + - uses: actions/checkout@v6 + + - name: Set up Go + uses: actions/setup-go@v6 + with: + go-version: "1.25" - name: Run go vet run: go vet ./... diff --git a/.github/workflows/docker-rebuild.yml b/.github/workflows/docker-rebuild.yml new file mode 100644 index 0000000..c1634f1 --- /dev/null +++ b/.github/workflows/docker-rebuild.yml @@ -0,0 +1,52 @@ +# Rebuilds and re-pushes the `latest` image without a version bump so newly +# *fixed* Alpine / ffmpeg / Go patches land between tagged releases. Versioned +# tags are immutable and never touched here. Runs weekly and on demand. +name: Docker rebuild + +on: + schedule: + # Mondays 04:17 UTC (off the hour to avoid the scheduler rush) + - cron: "17 4 * * 1" + workflow_dispatch: + +jobs: + rebuild: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + with: + fetch-depth: 0 + + # Stamp the binary with the most recent release tag (not "dev"). + - name: Resolve version + id: ver + run: echo "version=$(git describe --tags --abbrev=0 2>/dev/null || echo dev)" >> "$GITHUB_OUTPUT" + + - uses: docker/setup-qemu-action@v4 + - uses: docker/setup-buildx-action@v4 + + - uses: docker/login-action@v4 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - uses: docker/build-push-action@v7 + with: + context: . + push: true + platforms: linux/amd64,linux/arm64 + # Refresh the floating tag only — never overwrite a versioned release. + tags: torrentclaw/unarr:latest + build-args: | + VERSION=${{ steps.ver.outputs.version }} + # Force a fresh base pull so apk upgrade picks up new patches. + no-cache: true + + - name: Scan image for fixable CVEs (gate) + uses: docker/scout-action@v1 + with: + command: cves + image: torrentclaw/unarr:latest + only-severities: critical,high + only-fixed: true + exit-code: true diff --git a/.github/workflows/pages.yml b/.github/workflows/pages.yml new file mode 100644 index 0000000..d0c683d --- /dev/null +++ b/.github/workflows/pages.yml @@ -0,0 +1,52 @@ +name: Deploy install scripts to Pages + +on: + push: + branches: [main] + paths: + - install.sh + - install.ps1 + - CNAME + - .nojekyll + - .github/workflows/pages.yml + workflow_dispatch: + +permissions: + contents: read + pages: write + id-token: write + +concurrency: + group: pages + cancel-in-progress: false + +jobs: + deploy: + runs-on: ubuntu-latest + environment: + name: github-pages + url: ${{ steps.deployment.outputs.page_url }} + steps: + - uses: actions/checkout@v4 + - uses: actions/configure-pages@v5 + - name: Stage install scripts + run: | + mkdir -p _site + cp install.sh install.ps1 _site/ + [ -f CNAME ] && cp CNAME _site/ + touch _site/.nojekyll + # Also index page (humans landing) + cat > _site/index.html <<'HTML' + + unarr installer +

unarr CLI installer

+
Linux/macOS:  curl -fsSL https://unarr.torrentclaw.com/install.sh | sh
+          Windows:      irm https://unarr.torrentclaw.com/install.ps1 | iex
+

Source: github.com/torrentclaw/unarr

+ + HTML + - uses: actions/upload-pages-artifact@v3 + with: + path: _site + - id: deployment + uses: actions/deploy-pages@v4 diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml new file mode 100644 index 0000000..dcb49ce --- /dev/null +++ b/.github/workflows/release.yml @@ -0,0 +1,210 @@ +name: Release + +on: + push: + tags: + - "v*" + +permissions: + contents: write + +jobs: + release: + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + with: + fetch-depth: 0 + + - uses: actions/setup-go@v6 + with: + go-version-file: go.mod + + - uses: goreleaser/goreleaser-action@v6 + with: + version: "~> v2" + args: release --clean + env: + GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} + SENTRY_DSN: ${{ secrets.SENTRY_DSN }} + # Empty when RELEASE_SIGNING_PUBKEY variable is unset — goreleaser + # accepts it and the resulting binary disables signature checks + # (back-compat: pre-signing releases continue to update). Set + # RELEASE_SIGNING_PUBKEY (variable) + RELEASE_SIGNING_KEY (secret) + # to turn verification on. + RELEASE_SIGNING_PUBKEY: ${{ vars.RELEASE_SIGNING_PUBKEY }} + + - name: Sign checksums.txt with ed25519 + # Reference secrets.X directly — step-level env defined in this same + # step is unreliable to read from this step's own if: expression. + if: ${{ vars.RELEASE_SIGNING_PUBKEY != '' && secrets.RELEASE_SIGNING_KEY != '' }} + env: + RELEASE_SIGNING_KEY: ${{ secrets.RELEASE_SIGNING_KEY }} + RELEASE_TAG: ${{ github.ref_name }} + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + set -euo pipefail + go run ./scripts/sign-checksums \ + -key "$RELEASE_SIGNING_KEY" \ + -in dist/checksums.txt \ + -out dist/checksums.txt.sig + gh release upload "$RELEASE_TAG" dist/checksums.txt.sig --clobber + + docker: + needs: release + runs-on: ubuntu-latest + steps: + - uses: actions/checkout@v6 + + - name: Docker meta + id: meta + uses: docker/metadata-action@v6 + with: + images: torrentclaw/unarr + tags: | + type=semver,pattern={{version}} + type=semver,pattern={{major}}.{{minor}} + type=raw,value=latest + + - uses: docker/setup-qemu-action@v4 + - uses: docker/setup-buildx-action@v4 + + - uses: docker/login-action@v4 + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + + - uses: docker/build-push-action@v7 + with: + context: . + push: true + platforms: linux/amd64,linux/arm64 + tags: ${{ steps.meta.outputs.tags }} + labels: ${{ steps.meta.outputs.labels }} + build-args: | + VERSION=${{ github.ref_name }} + + # CVE gate. Fails the release on FIXABLE critical/high only — unfixed + # upstream ffmpeg codec CVEs are accepted (see SECURITY.md), so the + # codec noise does not block. Runs post-push (image already published); + # a failure here flags that a fixable CVE slipped through. + - name: Scan image for fixable CVEs (gate) + uses: docker/scout-action@v1 + with: + command: cves + image: torrentclaw/unarr:latest + only-severities: critical,high + only-fixed: true + exit-code: true + + # Sync the Docker Hub repo description from DOCKERHUB.md. Non-fatal: a + # description-API auth hiccup must not undo a successful image push. + - name: Update Docker Hub description + uses: peter-evans/dockerhub-description@v4 + continue-on-error: true + with: + username: ${{ secrets.DOCKERHUB_USERNAME }} + password: ${{ secrets.DOCKERHUB_TOKEN }} + repository: torrentclaw/unarr + readme-filepath: ./DOCKERHUB.md + short-description: "unarr — the single binary that replaces your *arr stack" + + + virustotal: + needs: release + runs-on: ubuntu-latest + if: vars.VT_ENABLED == 'true' + steps: + - name: Get release tag + id: tag + run: echo "tag=${GITHUB_REF#refs/tags/}" >> "$GITHUB_OUTPUT" + + - name: Download release assets + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + mkdir -p assets + gh release download "${{ steps.tag.outputs.tag }}" \ + --repo "${{ github.repository }}" \ + --dir assets \ + --pattern '*.tar.gz' \ + --pattern '*.zip' \ + --pattern 'checksums.txt' + + - name: Scan assets with VirusTotal + env: + VT_API_KEY: ${{ secrets.VT_API_KEY }} + run: | + mkdir -p results + for file in assets/*; do + filename=$(basename "$file") + echo "Uploading $filename to VirusTotal..." + + response=$(curl -s --request POST \ + --url https://www.virustotal.com/api/v3/files \ + --header "x-apikey: $VT_API_KEY" \ + --form "file=@$file") + + analysis_id=$(echo "$response" | jq -r '.data.id // empty') + if [ -z "$analysis_id" ]; then + echo "::warning::Failed to upload $filename: $response" + continue + fi + + echo "$filename=$analysis_id" >> results/scans.txt + echo " Analysis ID: $analysis_id" + + # Rate limit: VT free tier allows 4 req/min + sleep 16 + done + + - name: Wait for analysis completion + env: + VT_API_KEY: ${{ secrets.VT_API_KEY }} + run: | + echo "Waiting 60s for VirusTotal analysis to complete..." + sleep 60 + + vt_report="## 🛡️ VirusTotal Scan Results\n\n" + vt_report+="| File | Result | Link |\n" + vt_report+="|------|--------|------|\n" + + while IFS='=' read -r filename analysis_id; do + result=$(curl -s --request GET \ + --url "https://www.virustotal.com/api/v3/analyses/$analysis_id" \ + --header "x-apikey: $VT_API_KEY") + + malicious=$(echo "$result" | jq -r '.data.attributes.stats.malicious // 0') + undetected=$(echo "$result" | jq -r '.data.attributes.stats.undetected // 0') + sha256=$(echo "$result" | jq -r '.meta.file_info.sha256 // empty') + + if [ "$malicious" = "0" ]; then + status="✅ Clean ($undetected engines)" + else + status="⚠️ $malicious detections" + fi + + link="https://www.virustotal.com/gui/file/$sha256" + vt_report+="| \`$filename\` | $status | [View]($link) |\n" + + sleep 16 + done < results/scans.txt + + echo -e "$vt_report" > results/report.md + cat results/report.md + + - name: Append scan results to release notes + env: + GH_TOKEN: ${{ secrets.GITHUB_TOKEN }} + run: | + current_body=$(gh release view "${{ steps.tag.outputs.tag }}" \ + --repo "${{ github.repository }}" \ + --json body --jq '.body') + + new_body="${current_body} + + $(cat results/report.md)" + + gh release edit "${{ steps.tag.outputs.tag }}" \ + --repo "${{ github.repository }}" \ + --notes "$new_body" diff --git a/.gitignore b/.gitignore index 8015bab..7b50c64 100644 --- a/.gitignore +++ b/.gitignore @@ -43,5 +43,18 @@ tmp/ config/ dist-ffbinaries/ -# Claude Code: keep entirely local, do not track -.claude/ \ No newline at end of file +# Claude Code: global ~/.gitignore excludes .claude/ by default, which hides +# project-shared agents/commands/hooks. Override here to commit the shared +# pieces (agents, commands, hooks, settings.json). Keep per-user state local. +!.claude/ +!.claude/agents/ +!.claude/agents/** +!.claude/commands/ +!.claude/commands/** +!.claude/hooks/ +!.claude/hooks/** +!.claude/settings.json +.claude/settings.local.json +.claude/projects/ +.claude/scheduled_tasks.lock +.claude/skills/ \ No newline at end of file diff --git a/.goreleaser.yml b/.goreleaser.yml index 6bc4a51..26ce802 100644 --- a/.goreleaser.yml +++ b/.goreleaser.yml @@ -59,22 +59,6 @@ changelog: - "^test:" - "^chore:" -# Self-hosted Forgejo at git.torrentclaw.com. goreleaser detects GITEA_TOKEN + -# these URLs and publishes the release there instead of GitHub. Reachable via -# `forgejo` hostname inside the dokploy-network (the runner shares it); for -# local goreleaser runs outside the network, override via env GITEA_API_URL. -# -# In goreleaser v2 `gitea_urls` is a top-level key (was nested under `release` -# in v1). -gitea_urls: - api: http://forgejo:3000/api/v1 - download: https://git.torrentclaw.com - skip_tls_verify: false - -release: - draft: false - prerelease: auto - # Homebrew tap — requires PAT with repo scope (not GITHUB_TOKEN) # Enable when torrentclaw/homebrew-tap PAT is configured as HOMEBREW_TAP_TOKEN # brews: diff --git a/CHANGELOG.md b/CHANGELOG.md index fa0d872..c8681bf 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,94 +5,37 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.1.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). -## [0.9.19] - 2026-05-30 - - -### Fixed - -- **docker**: three streaming/reliability bugs found in live docker test -## [0.9.18] - 2026-05-29 - - -### Fixed - -- **stream**: make completed torrent files readable (mmap creates 0000) - -### Other - -- **release**: 0.9.18 -## [0.9.17] - 2026-05-27 - - -### Added - -- **scripts**: prune Forgejo releases >90 days in ship.sh - -### Fixed - -- **hls**: drop nvenc -tune ll — kills hls segmentation, bump 0.9.17 - -### Other - -- **release**: 0.9.17 -## [0.9.15] - 2026-05-27 - - -### Added - -- **sentry**: enhance error handling by skipping user input errors in CaptureError - -### Changed - -- **ci**: point Forgejo URLs at torrentclaw org (post-transfer) -- **sentry**: decouple agent import via string-match, rename predicate - -### Documentation - -- **positioning**: reframe unarr around download/stream/transcode, drop misleading search-first wording - -### Fixed - -- **ci**: unset GITHUB_TOKEN so goreleaser uses GITEA_TOKEN -- **sentry**: skip "daemon not running" stop/reload errors - -### Other - -- **release**: 0.9.15 -- **scripts**: harden release.sh against double-release and inline version bumps -- untrack .claude/ (private local config) -## [0.9.14] - 2026-05-27 - - -### Added - -- **vaapi**: hybrid CPU-scale + hwupload encode path (QW2, 0.9.14) - -### CI/CD - -- port workflows from .github/ to .forgejo/ (Forgejo Actions) - -### Fixed - -- **daemon**: defensive IsClosed check in watchSessionReady poll loop -- **daemon**: use parent ctx for MarkSessionReady so cancel propagates -- **release**: move gitea_urls to top-level (goreleaser v2 schema) ## [0.9.13] - 2026-05-27 +### Added + +- **Session-ready webhook** (`/api/internal/agent/session-ready`). Daemon + watches every new HLSSession's segment counter and, the moment seg-0 + + init.mp4 land on disk, POSTs the sessionId to the server. The web side + flips `streaming_session.ready_at = NOW()`, which its new SSE endpoint + pushes to subscribed players so the "Preparando…" UI flips to + "Stream listo" without waiting for the player's HEAD-probe retry loop + to discover it. Cache-HIT sessions fire the webhook immediately on + StartHLSSession return. +- `engine.HLSSession.ReadyCount()` + `FromCache()` accessors so the + ready-watcher goroutine doesn't reach into private state. + +## [0.9.12] - 2026-05-27 ### Added -- **agent**: session-ready webhook for SSE-driven player handshake (0.9.13) -- **agent**: send full transcoder diagnostic in register payload (0.9.12) +- **transcoder diagnostic in register payload**: daemon now sends the full + HWAccel diagnostic (ffmpeg version, resolved binary path, list of HW + encoders compiled in, list of device files / drivers present) up to the + server on register. The web "Diagnose transcoder" modal surfaces these + so a user stuck on software libx264 can see *why* (e.g. ffmpeg shipped + without `--enable-nvenc`, or `/dev/nvidia0` missing inside a container) + without SSHing into their machine + running `unarr probe-hwaccel`. +- **`[transcode]` startup log line**: daemon prints a single one-line + summary of the picked backend + version + binary path + devices at + start. Same data the web shows; convenient for `journalctl --user -u + unarr | grep transcode`. -### Fixed - -- **daemon**: defer probeCancel so a panic mid-diagnostic still releases ctx - -### Other - -- **release**: add ship.sh end-to-end pipeline as GH Actions backup -- **skills**: add /publish slash command + allow .claude/ in git ## [0.9.11] - 2026-05-27 @@ -110,10 +53,6 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 - **cors**: allow play from .to / staging / onion mirrors - **library**: classify resolution by width + height, not height alone - **transcode**: make preset libx264-only + restore quality opt-in - -### Other - -- **release**: 0.9.11 ## [0.9.8] - 2026-05-27 @@ -576,12 +515,9 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ### Build - add -s -w -trimpath to Makefile, add build-small target with UPX -[0.9.19]: https://github.com/torrentclaw/unarr/compare/v0.9.18...v0.9.19 -[0.9.18]: https://github.com/torrentclaw/unarr/compare/v0.9.17...v0.9.18 -[0.9.17]: https://github.com/torrentclaw/unarr/compare/v0.9.15...v0.9.17 -[0.9.15]: https://github.com/torrentclaw/unarr/compare/v0.9.14...v0.9.15 -[0.9.14]: https://github.com/torrentclaw/unarr/compare/v0.9.13...v0.9.14 -[0.9.13]: https://github.com/torrentclaw/unarr/compare/v0.9.11...v0.9.13 +[0.9.11]: https://github.com/torrentclaw/unarr/compare/v0.9.8...v0.9.11 +[0.9.8]: https://github.com/torrentclaw/unarr/compare/v0.9.7...v0.9.8 +[0.9.12]: https://github.com/torrentclaw/unarr/compare/v0.9.11...v0.9.12 [0.9.11]: https://github.com/torrentclaw/unarr/compare/v0.9.8...v0.9.11 [0.9.8]: https://github.com/torrentclaw/unarr/compare/v0.9.7...v0.9.8 [0.9.7]: https://github.com/torrentclaw/unarr/compare/v0.9.6...v0.9.7 diff --git a/DOCKERHUB.md b/DOCKERHUB.md index 3df5b70..7a9bc0e 100644 --- a/DOCKERHUB.md +++ b/DOCKERHUB.md @@ -1,9 +1,8 @@ # unarr -**The single binary that replaces your whole *arr stack.** Built-in torrent, -debrid, and usenet engines. Stream, transcode, and organize your library from -one terminal — or run it as a headless daemon with a web dashboard, WireGuard -split-tunnel, and Cloudflare Funnel remote access. +**The single binary that replaces your whole *arr stack.** Search 30+ torrent +sources, inspect real quality before you download, grab subtitles, and manage +your media library — all from one terminal tool or a headless daemon. **[Website & docs](https://torrentclaw.com/unarr)** · **[Install guide](https://torrentclaw.com/cli)** · **[Get an API key](https://torrentclaw.com)** diff --git a/README.md b/README.md index 75c9c62..8a5d26d 100644 --- a/README.md +++ b/README.md @@ -11,9 +11,9 @@ [![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg)](LICENSE) [![Go Version](https://img.shields.io/github/go-mod/go-version/torrentclaw/unarr)](go.mod) -The single-binary terminal client for torrent, debrid, and usenet downloads. **Free and open source.** +Powerful terminal tool for torrent search and management. **Free and open source.** -Built-in torrent engine, debrid (Real-Debrid / AllDebrid), and NZB support. Stream to mpv/vlc, transcode on the fly with hardware acceleration, and manage your library — one binary or a headless daemon with WireGuard split-tunnel and Cloudflare Funnel remote access. +Search 30+ torrent sources, inspect torrent quality, discover popular content, find streaming providers, and manage your media collection — all from your terminal. diff --git a/docker-compose.yml b/docker-compose.yml index 8e0b32e..5f49fcf 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,65 +1,48 @@ -# unarr — TorrentClaw agent -# -# Quick start: -# 1. Copy this file to any directory. -# 2. Set UNARR_API_KEY to your key (Settings → API Keys on torrentclaw.com). -# 3. Set DOWNLOAD_DIR to your media folder (absolute path). -# 4. Run: docker compose up -d -# -# Get your API key: https://torrentclaw.com/settings/api-keys -# Full docs: https://torrentclaw.com/unarr - services: unarr: + build: + context: .. + dockerfile: unarr/Dockerfile image: torrentclaw/unarr:latest - pull_policy: always # always pull on `up` so you stay on the latest release container_name: unarr restart: unless-stopped + user: "1000:1000" - # host network is required for: - # - streaming to reach your TV / mobile / other LAN devices (port 11818) - # - HLS transcode server (port 11819) - # - Tailscale connectivity (if you use it) - # On macOS / Windows Docker Desktop, replace with `ports` mapping (see below). - network_mode: host - - environment: - # --- Required --- - - UNARR_API_KEY=${UNARR_API_KEY:?Set UNARR_API_KEY in .env or export it} - - # --- Optional --- - # Server URL — change only if you run a self-hosted TorrentClaw instance - - UNARR_API_URL=${UNARR_API_URL:-https://torrentclaw.com} - - TZ=${TZ:-UTC} + # Read-only root filesystem — only volumes are writable + read_only: true + tmpfs: + - /tmp:size=64m,mode=1777 volumes: - # Config: config.toml is auto-created here on first run. - # After first start, edit this file to set organize paths, quality, etc. - - ${CONFIG_DIR:-./config}:/config - - # Downloads: where finished media is saved. - # Set DOWNLOAD_DIR in .env or export it before running. - - ${DOWNLOAD_DIR:?Set DOWNLOAD_DIR to your media folder}:/downloads - - # Data: piece-completion DB, HLS cache, DHT nodes. - # Named volume keeps this off your media drive (avoids NFS locking issues). + # Config: your config.toml lives here + - ./config:/config + # Downloads: finished media goes here + - ~/Media:/downloads + # Data: torrent metadata, piece DB, cache - unarr-data:/data - # Optional: limit CPU/RAM for transcoding on shared hosts - # deploy: - # resources: - # limits: - # memory: 2G - # cpus: "4.0" + environment: + - TZ=${TZ:-UTC} + # Optional overrides (uncomment to use): + # - UNARR_API_KEY=tc_your_key_here + # - UNARR_API_URL=https://torrentclaw.com - # --- macOS / Windows alternative (replace network_mode: host above) --- - # network_mode: bridge + # Resource limits — adjust to your needs + deploy: + resources: + limits: + memory: 512M + cpus: "2.0" + + # Torrent P2P needs host network or explicit port range + # Option A: host network (simplest, full P2P performance) + network_mode: host + + # Option B: bridge network with port mapping (more isolated) + # Uncomment below and comment out network_mode above: # ports: - # - "11818:11818" # direct stream (VLC, download) - # - "11819:11819" # HLS transcode (web player) - # - "42069:42069" # BitTorrent incoming peers - # Note: streaming will only reach devices on the same machine. - # For LAN / Tailscale playback use a Linux host with network_mode: host. + # - "6881-6889:6881-6889/tcp" + # - "6881-6889:6881-6889/udp" volumes: unarr-data: diff --git a/internal/agent/state.go b/internal/agent/state.go index cc08ae5..1f00033 100644 --- a/internal/agent/state.go +++ b/internal/agent/state.go @@ -2,8 +2,6 @@ package agent import ( "encoding/json" - "errors" - "fmt" "os" "path/filepath" "time" @@ -11,13 +9,6 @@ import ( "github.com/torrentclaw/unarr/internal/config" ) -// ErrDaemonNotRunning is returned when no daemon state file exists on disk. -// Callers may wrap it with %w; downstream code uses errors.Is to detect it. -// NOTE: the message text is matched by the sentry package (string-match, to -// avoid an import cycle). Keep the prefix "daemon does not appear to be -// running" stable, or update sentry.daemonNotRunningMarker accordingly. -var ErrDaemonNotRunning = errors.New("daemon does not appear to be running (state file not found)") - // DaemonState is written to disk every heartbeat for external tools to read. type DaemonState struct { AgentID string `json:"agentId"` @@ -78,31 +69,17 @@ func WriteState(state *DaemonState) { os.Rename(tmp, path) } -// ReadState reads the daemon state from disk. Returns nil if not found or -// unreadable. Use LoadState when callers need to distinguish "not running" -// from "state file corrupted". +// ReadState reads the daemon state from disk. Returns nil if not found. func ReadState() *DaemonState { - state, _ := LoadState() - return state -} - -// LoadState reads the daemon state and returns explicit errors: -// - ErrDaemonNotRunning when the state file does not exist -// - a wrapped json error when the file exists but cannot be decoded -// (a real bug worth reporting to Sentry) -func LoadState() (*DaemonState, error) { data, err := os.ReadFile(StateFilePath()) if err != nil { - if errors.Is(err, os.ErrNotExist) { - return nil, ErrDaemonNotRunning - } - return nil, err + return nil } var state DaemonState - if err := json.Unmarshal(data, &state); err != nil { - return nil, fmt.Errorf("decode daemon state %s: %w", StateFilePath(), err) + if json.Unmarshal(data, &state) != nil { + return nil } - return &state, nil + return &state } // RemoveState deletes the state file (called on clean shutdown). diff --git a/internal/agent/state_test.go b/internal/agent/state_test.go index 7e275be..6c9abdd 100644 --- a/internal/agent/state_test.go +++ b/internal/agent/state_test.go @@ -1,7 +1,6 @@ package agent import ( - "errors" "os" "path/filepath" "testing" @@ -105,39 +104,3 @@ func TestReadStateCorruptedJSON(t *testing.T) { t.Errorf("ReadState() should return nil for corrupted JSON, got %+v", state) } } - -func TestLoadStateNotFound(t *testing.T) { - tmpDir := t.TempDir() - origFn := stateFilePathFn - stateFilePathFn = func() string { return filepath.Join(tmpDir, "nonexistent.json") } - defer func() { stateFilePathFn = origFn }() - - state, err := LoadState() - if state != nil { - t.Errorf("LoadState() state = %+v, want nil", state) - } - if !errors.Is(err, ErrDaemonNotRunning) { - t.Errorf("LoadState() err = %v, want ErrDaemonNotRunning", err) - } -} - -func TestLoadStateCorruptedJSON(t *testing.T) { - tmpDir := t.TempDir() - origFn := stateFilePathFn - path := filepath.Join(tmpDir, "daemon.state.json") - stateFilePathFn = func() string { return path } - defer func() { stateFilePathFn = origFn }() - - os.WriteFile(path, []byte("not valid json{{{"), 0o644) - - state, err := LoadState() - if state != nil { - t.Errorf("LoadState() state = %+v, want nil", state) - } - if err == nil { - t.Fatal("LoadState() err = nil, want decode error") - } - if errors.Is(err, ErrDaemonNotRunning) { - t.Error("corrupt state must not be reported as ErrDaemonNotRunning — it would be filtered from Sentry") - } -} diff --git a/internal/cmd/daemon.go b/internal/cmd/daemon.go index 425cee0..be66858 100644 --- a/internal/cmd/daemon.go +++ b/internal/cmd/daemon.go @@ -265,16 +265,15 @@ func runDaemonStart() error { // Create torrent downloader torrentDl, err := engine.NewTorrentDownloader(engine.TorrentConfig{ - DataDir: cfg.Download.Dir, - PieceCompletionDir: config.DataDir(), // keep piece-completion DB off NFS/SMB mounts - MetadataTimeout: metaTimeout, - StallTimeout: stallTimeout, - MaxTimeout: 0, - MaxDownloadRate: maxDl, - MaxUploadRate: maxUl, - ListenPort: cfg.Download.ListenPort, - SeedEnabled: false, - VPNTunnel: vpnTunnel, + DataDir: cfg.Download.Dir, + MetadataTimeout: metaTimeout, + StallTimeout: stallTimeout, + MaxTimeout: 0, + MaxDownloadRate: maxDl, + MaxUploadRate: maxUl, + ListenPort: cfg.Download.ListenPort, + SeedEnabled: false, + VPNTunnel: vpnTunnel, }) if err != nil { return fmt.Errorf("create torrent downloader: %w", err) @@ -961,19 +960,9 @@ func watchSessionReady(ctx context.Context, client *agent.Client, hsess *engine. ticker := time.NewTicker(200 * time.Millisecond) defer ticker.Stop() for { - // Session torn down through a path that didn't cancel ctx (registry - // replace, idle sweep, internal kill). Bail before polling further — - // without this check the watcher could keep alive for up to 60 s on - // a dead HLSSession that's never going to become ready. - if hsess.IsClosed() { - return - } // Cache HIT or seg-0 ready → notify + done. if hsess.FromCache() || hsess.ReadyCount() >= 1 { - // Parent ctx so a session cancel mid-POST (user closed tab, - // daemon shutdown) tears down the in-flight webhook instead of - // blocking the goroutine for up to 10 s on a now-orphan call. - rctx, cancel := context.WithTimeout(ctx, 10*time.Second) + rctx, cancel := context.WithTimeout(context.Background(), 10*time.Second) if err := client.MarkSessionReady(rctx, sessionID); err != nil { log.Printf("[hls %s] mark-ready failed: %v", agent.ShortID(sessionID), err) } diff --git a/internal/cmd/daemon_control.go b/internal/cmd/daemon_control.go index 4ac4d10..558fb26 100644 --- a/internal/cmd/daemon_control.go +++ b/internal/cmd/daemon_control.go @@ -1,7 +1,6 @@ package cmd import ( - "errors" "fmt" "os" "os/exec" @@ -263,12 +262,9 @@ func runDaemonReload() error { // stopDaemonByPID reads the state file and sends a graceful stop to the daemon PID. // Used as fallback on platforms without a service manager (and as Windows implementation). func stopDaemonByPID() error { - state, err := agent.LoadState() - if err != nil { - if errors.Is(err, agent.ErrDaemonNotRunning) { - return err - } - return fmt.Errorf("read daemon state: %w", err) + state := agent.ReadState() + if state == nil { + return fmt.Errorf("daemon does not appear to be running (state file not found)") } return killPID(state.PID) } diff --git a/internal/cmd/download.go b/internal/cmd/download.go index 5bf31a5..bd5ceab 100644 --- a/internal/cmd/download.go +++ b/internal/cmd/download.go @@ -119,10 +119,11 @@ func runDownloadWithDeps(input, method string, deps downloadDeps) error { return fmt.Errorf("create downloader: %w", err) } - // Local-only reporter: one-shot downloads have no server-side task, so a nil - // client keeps terminal progress working without spamming the status API - // (which 400s the synthetic "oneshot-" id). - reporter := engine.NewProgressReporter(nil, 5*time.Second) + // Create a dummy reporter (no API reporting for one-shot) + reporter := engine.NewProgressReporter( + deps.newAgentClient(cfg.Auth.APIURL, cfg.Auth.APIKey, "unarr/"+Version), + 5*time.Second, + ) debridDl := deps.newDebridDl() diff --git a/internal/cmd/reload_unix.go b/internal/cmd/reload_unix.go index 34d8e4d..056112f 100644 --- a/internal/cmd/reload_unix.go +++ b/internal/cmd/reload_unix.go @@ -3,7 +3,6 @@ package cmd import ( - "errors" "fmt" "log" "os" @@ -44,12 +43,9 @@ func startReloadWatcher(rc *ReloadableConfig) { // sendReloadSignal sends SIGUSR1 to the running daemon process. func sendReloadSignal() error { - state, err := agent.LoadState() - if err != nil { - if errors.Is(err, agent.ErrDaemonNotRunning) { - return err - } - return fmt.Errorf("read daemon state: %w", err) + state := agent.ReadState() + if state == nil { + return fmt.Errorf("daemon does not appear to be running (state file not found)") } p, err := os.FindProcess(state.PID) if err != nil { diff --git a/internal/cmd/root.go b/internal/cmd/root.go index 375d8e9..b28ec92 100644 --- a/internal/cmd/root.go +++ b/internal/cmd/root.go @@ -25,20 +25,16 @@ var ( func init() { rootCmd = &cobra.Command{ - Use: "unarr", - Version: Version, - Short: "Terminal torrent + debrid + usenet client — download, stream, transcode", - Long: `unarr is a terminal-native client that downloads torrents, debrid links, -and usenet (NZB) — all from the same binary. It streams content straight -to mpv/vlc with sequential piece prioritization, transcodes on the fly via -ffmpeg with hardware acceleration (NVENC, QSV, VA-API, VideoToolbox), and -organizes your library into Movies/TV folders. Run it one-shot or as a -long-running daemon with a built-in WireGuard split-tunnel and remote -playback over Cloudflare Funnel. + Use: "unarr", + Short: "unarr — torrent search and management", + Long: `unarr is a powerful terminal tool for torrent search and management. + +Search 30+ torrent sources, inspect torrent quality, discover popular content, +find streaming providers, and manage your media collection — all from your terminal. Get started: unarr init First-time configuration wizard - unarr download Grab a torrent one-shot + unarr search "breaking bad" Search for content unarr start Start the download daemon Documentation: https://torrentclaw.com/cli @@ -59,7 +55,7 @@ Source: https://github.com/torrentclaw/unarr`, // Command groups for organized help output rootCmd.AddGroup( &cobra.Group{ID: "start", Title: "Getting Started:"}, - &cobra.Group{ID: "search", Title: "Catalog & Discovery:"}, + &cobra.Group{ID: "search", Title: "Search & Discovery:"}, &cobra.Group{ID: "download", Title: "Downloads & Streaming:"}, &cobra.Group{ID: "daemon", Title: "Daemon Management:"}, &cobra.Group{ID: "system", Title: "System & Diagnostics:"}, diff --git a/internal/cmd/version.go b/internal/cmd/version.go index 8551bb1..efb6b30 100644 --- a/internal/cmd/version.go +++ b/internal/cmd/version.go @@ -1,4 +1,4 @@ package cmd // Version is the CLI version. Overridden by goreleaser ldflags at release time. -var Version = "0.9.19" +var Version = "0.9.13" diff --git a/internal/engine/hls.go b/internal/engine/hls.go index 8e0868a..4938c11 100644 --- a/internal/engine/hls.go +++ b/internal/engine/hls.go @@ -534,13 +534,6 @@ func (s *HLSSession) ReadyCount() int { // circuit polling — a cache HIT is ready the moment we return. func (s *HLSSession) FromCache() bool { return s.fromCache } -// IsClosed reports whether Close() has been invoked. Exposed (vs the -// internal isClosed) so external watchers — the ready-webhook -// goroutine in cmd/daemon.go — can short-circuit polling on a session -// that was torn down through a different code path (registry replace, -// idle sweep) without racing on the unexported helper. -func (s *HLSSession) IsClosed() bool { return s.isClosed() } - // MasterPlaylist returns the rendered master.m3u8 contents. func (s *HLSSession) MasterPlaylist() string { return s.manifestRoot } @@ -1150,14 +1143,10 @@ func buildHLSFFmpegArgsAt(cfg HLSSessionConfig, probe *StreamProbe, tmpDir strin // helps when the user has set GOMAXPROCS. args = append(args, "-preset", profile.Preset, "-threads", "0") case "h264_nvenc": - // p3 + vbr keeps NVENC fast (~1.5 s seg-0) without the segmentation - // breakage `-tune ll` introduced in 0.9.9: with -tune=ll the NVENC - // rate control emits long IDR-less GOPs that ignore -force_key_frames, - // so ffmpeg's HLS muxer never closes seg-0 and the player stalls at - // "preparando sesión" until the 60 s mark-ready timeout. Verified on - // ffmpeg 6.1.1 + driver 580 / RTX-class GPUs: dropping -tune ll - // restores per-segment cuts at 27x real-time vs 28x with -tune ll. - args = append(args, "-preset", profile.Preset, "-rc", "vbr") + // p3 + tune=ll trades ~0.3 dB PSNR for 1.5-2× faster encode vs the + // previous p4 + tune=hq pair — first-segment encode drops from + // ~1.5 s to ~0.8 s on RTX-class hardware. + args = append(args, "-preset", profile.Preset, "-rc", "vbr", "-tune", "ll") case "h264_qsv": // veryfast is the fastest realistic QSV preset; medium was too // conservative for first-start. look_ahead=0 keeps the encoder @@ -1172,17 +1161,6 @@ func buildHLSFFmpegArgsAt(cfg HLSSessionConfig, probe *StreamProbe, tmpDir strin // silently ignores `-q:v`, so the constant-quality knob never // took effect anyway. args = append(args, "-realtime", "1") - case "h264_vaapi": - // h264_vaapi has no preset knob. Bitrate args (set later) drive - // rate control. Add `-vaapi_device /dev/dri/renderD128` so the - // encoder doesn't fall back to a NULL device on multi-GPU hosts - // where the default render node is a non-VAAPI GPU (an Nvidia - // dGPU's render node, etc.). The filter chain below switches to - // `format=nv12,hwupload` so frames land on the right VAAPI - // surface before the encoder; we intentionally avoid scale_vaapi - // because mesa 25 + Raphael iGPU emits "Cannot allocate memory" - // per session start, polluting logs even though encode succeeds. - args = append(args, "-vaapi_device", "/dev/dri/renderD128") } // Derive H.264 level from the actual output height. A fixed "4.0" caps the // encoder at 1080p — anything taller (1440p, 4K source on quality=original) @@ -1233,32 +1211,14 @@ func buildHLSFFmpegArgsAt(cfg HLSSessionConfig, probe *StreamProbe, tmpDir strin if maxH == 0 { maxH = cfg.Transcode.MaxHeight } - // VAAPI needs frames as nv12 VAAPI surfaces before the encoder. We do - // scale + format conversion on CPU then `hwupload` once at the end — - // skips the mesa 25 + Raphael iGPU "Cannot allocate memory" log spam - // that scale_vaapi triggers per-session-start while still delivering - // the encoder a GPU surface. setparams is dropped because VAAPI - // surfaces don't expose VUI fields the way libx264 does; the encoder - // records its own color metadata via the source PTS chain. - pixFormat := "yuv420p" - hwUploadTail := "" - colorTail := ",setparams=colorspace=bt709:color_trc=bt709:color_primaries=bt709:range=tv" - if codec == "h264_vaapi" { - pixFormat = "nv12" - hwUploadTail = ",hwupload" - colorTail = "" - } var filterChain string if maxH > 0 && probe.Height > maxH { filterChain = fmt.Sprintf( - "scale=-2:%d:force_original_aspect_ratio=decrease,scale=trunc(iw/2)*2:trunc(ih/2)*2,format=%s%s%s", - maxH, pixFormat, colorTail, hwUploadTail, + "scale=-2:%d:force_original_aspect_ratio=decrease,scale=trunc(iw/2)*2:trunc(ih/2)*2,format=yuv420p,setparams=colorspace=bt709:color_trc=bt709:color_primaries=bt709:range=tv", + maxH, ) } else { - filterChain = fmt.Sprintf( - "scale=trunc(iw/2)*2:trunc(ih/2)*2,format=%s%s%s", - pixFormat, colorTail, hwUploadTail, - ) + filterChain = "scale=trunc(iw/2)*2:trunc(ih/2)*2,format=yuv420p,setparams=colorspace=bt709:color_trc=bt709:color_primaries=bt709:range=tv" } args = append(args, "-vf", filterChain) diff --git a/internal/engine/progress.go b/internal/engine/progress.go index e5eefe0..eba8814 100644 --- a/internal/engine/progress.go +++ b/internal/engine/progress.go @@ -45,19 +45,10 @@ type ProgressReporter struct { lastCheckAt time.Time // last time we reported for control-signal polling } -// NewProgressReporter creates a reporter that flushes every interval. A nil -// client yields a local-only reporter that tracks progress for terminal output -// but never calls the API — used by one-shot `unarr download`, which has no -// server-side task to report against (its synthetic "oneshot-" id is not a UUID -// and the /api/internal/agent/status endpoint 400s it). Passing the typed nil -// straight into the interface field would make it non-nil, so guard explicitly. +// NewProgressReporter creates a reporter that flushes every interval. func NewProgressReporter(ac *agent.Client, interval time.Duration) *ProgressReporter { - var rep StatusReporter - if ac != nil { - rep = ac - } return &ProgressReporter{ - reporter: rep, + reporter: ac, interval: interval, latest: make(map[string]*Task), lastReported: make(map[string]TaskStatus), @@ -117,9 +108,6 @@ func (r *ProgressReporter) Run(ctx context.Context) error { } func (r *ProgressReporter) flush(ctx context.Context) { - if r.reporter == nil { - return // local-only reporter (one-shot): nothing to send - } r.mu.Lock() tasks := make([]*Task, 0, len(r.latest)) for _, t := range r.latest { @@ -251,10 +239,6 @@ func (r *ProgressReporter) handleResponse(task *Task, resp *agent.StatusResponse // ReportFinal sends a final status update for a completed/failed task. func (r *ProgressReporter) ReportFinal(ctx context.Context, task *Task) { - if r.reporter == nil { - r.Untrack(task.ID) - return // local-only reporter (one-shot) - } update := task.ToStatusUpdate() if _, err := r.reporter.ReportStatus(ctx, update); err != nil { log.Printf("[%s] final report failed: %v", task.ID[:8], err) diff --git a/internal/engine/torrent.go b/internal/engine/torrent.go index efcddbe..f4b1b6d 100644 --- a/internal/engine/torrent.go +++ b/internal/engine/torrent.go @@ -61,12 +61,7 @@ var defaultTrackers = []string{ // TorrentConfig holds settings for the BitTorrent downloader. type TorrentConfig struct { - DataDir string - // PieceCompletionDir, when non-empty, stores the piece-completion SQLite DB - // in this directory instead of DataDir. Use the agent's local state dir - // (not the download dir) so the DB never lands on NFS/SMB volumes where - // SQLite locking times out. - PieceCompletionDir string + DataDir string MetadataTimeout time.Duration // how long to wait for torrent metadata (default 15m, 0 = unlimited) StallTimeout time.Duration // no progress during download for this long = stall (default 10m) MaxTimeout time.Duration // absolute maximum per torrent (default 0 = unlimited) @@ -118,23 +113,7 @@ func NewTorrentDownloader(cfg TorrentConfig) (*TorrentDownloader, error) { // Storage: mmap instead of default file backend. // The library author notes file storage has "very high system overhead". // mmap improves I/O throughput and piece verification speed significantly. - // - // When PieceCompletionDir is set (daemon always passes the agent state dir), - // keep the piece-completion SQLite DB off the download dir so it never lands - // on NFS/SMB where SQLite's file locking times out and emits a warning. - if cfg.PieceCompletionDir != "" { - if mkErr := os.MkdirAll(cfg.PieceCompletionDir, 0o755); mkErr != nil { - log.Printf("[torrent] piece-completion dir create failed (%v), DB stays in download dir", mkErr) - tcfg.DefaultStorage = storage.NewMMap(cfg.DataDir) - } else if pc, pcErr := storage.NewDefaultPieceCompletionForDir(cfg.PieceCompletionDir); pcErr != nil { - log.Printf("[torrent] piece-completion db in %q failed (%v), falling back to download dir", cfg.PieceCompletionDir, pcErr) - tcfg.DefaultStorage = storage.NewMMap(cfg.DataDir) - } else { - tcfg.DefaultStorage = storage.NewMMapWithCompletion(cfg.DataDir, pc) - } - } else { - tcfg.DefaultStorage = storage.NewMMap(cfg.DataDir) - } + tcfg.DefaultStorage = storage.NewMMap(cfg.DataDir) // Fixed port for incoming peer connections (enables UPnP port mapping). // With ListenPort=0, only ~30% of peers can connect to us. @@ -373,13 +352,6 @@ func (d *TorrentDownloader) Download(ctx context.Context, task *Task, outputDir result.Method = MethodTorrent result.Size = totalBytes - // anacrolix mmap storage (storage.NewMMap) creates completed files with mode - // 0000 — the running process keeps its own mmap handle so the download works, - // but any fresh open (streaming, ffprobe/HLS, organize-then-reopen) hits - // "permission denied". Relax perms now, before organize moves the file, so the - // readable mode is preserved through the rename. - makeReadable(filePath) - // If seeding enabled, keep alive (don't cleanup). // The manager handles seeding lifecycle. if !d.cfg.SeedEnabled { @@ -487,41 +459,6 @@ func (d *TorrentDownloader) pollDownload(ctx context.Context, t *torrent.Torrent } } -// makeReadable relaxes permissions on a completed download so it can be -// re-opened by streaming/ffprobe/organize. anacrolix mmap storage creates -// files with mode 0000; we set files to 0644 and directories to 0755. Errors -// are logged but non-fatal (e.g. NFS root_squash) — the file may still be -// readable depending on the export. -func makeReadable(path string) { - info, err := os.Stat(path) - if err != nil { - log.Printf("[organize] makeReadable stat %q: %v", path, err) - return - } - if !info.IsDir() { - if err := os.Chmod(path, 0o644); err != nil { - log.Printf("[organize] makeReadable chmod %q: %v", path, err) - } - return - } - err = filepath.WalkDir(path, func(p string, d os.DirEntry, walkErr error) error { - if walkErr != nil { - return nil // skip unreadable entries, keep going - } - mode := os.FileMode(0o644) - if d.IsDir() { - mode = 0o755 - } - if err := os.Chmod(p, mode); err != nil { - log.Printf("[organize] makeReadable chmod %q: %v", p, err) - } - return nil - }) - if err != nil { - log.Printf("[organize] makeReadable walk %q: %v", path, err) - } -} - // Pause drops the torrent handle but keeps partial files on disk for resume. func (d *TorrentDownloader) Pause(taskID string) error { d.activeMu.Lock() diff --git a/internal/engine/vaapi_args_test.go b/internal/engine/vaapi_args_test.go deleted file mode 100644 index 33d0786..0000000 --- a/internal/engine/vaapi_args_test.go +++ /dev/null @@ -1,97 +0,0 @@ -package engine - -import ( - "strings" - "testing" -) - -func TestBuildHLSFFmpegArgsVAAPI(t *testing.T) { - cfg := HLSSessionConfig{ - SessionID: "test", - SourcePath: "/tmp/test.mkv", - Quality: "720p", - AudioIndex: 0, - Transcode: TranscodeRuntime{ - FFmpegPath: "/usr/bin/ffmpeg", - FFprobePath: "/usr/bin/ffprobe", - HWAccel: HWAccelVAAPI, - }, - } - probe := &StreamProbe{Width: 1920, Height: 1080, DurationSec: 100} - args := buildHLSFFmpegArgsAt(cfg, probe, "/tmp/tmpdir", 0, 0) - got := strings.Join(args, " ") - - wants := []string{ - "-hwaccel vaapi", - "-vaapi_device /dev/dri/renderD128", - "-c:v h264_vaapi", - "format=nv12", - "hwupload", - } - for _, want := range wants { - if !strings.Contains(got, want) { - t.Errorf("argv missing %q\n%s", want, got) - } - } - if strings.Contains(got, "scale_vaapi") { - t.Errorf("argv unexpectedly contains scale_vaapi (mesa bug): %s", got) - } - if strings.Contains(got, "format=yuv420p") { - t.Errorf("argv contains format=yuv420p (libx264 path) for VAAPI codec: %s", got) - } -} - -func TestBuildHLSFFmpegArgsLibx264NoRegression(t *testing.T) { - cfg := HLSSessionConfig{ - SessionID: "test", - SourcePath: "/tmp/test.mkv", - Quality: "720p", - AudioIndex: 0, - Transcode: TranscodeRuntime{ - FFmpegPath: "/usr/bin/ffmpeg", - FFprobePath: "/usr/bin/ffprobe", - HWAccel: HWAccelNone, - }, - } - probe := &StreamProbe{Width: 1920, Height: 1080, DurationSec: 100} - args := buildHLSFFmpegArgsAt(cfg, probe, "/tmp/tmpdir", 0, 0) - got := strings.Join(args, " ") - for _, want := range []string{"-c:v libx264", "format=yuv420p", "setparams=colorspace=bt709"} { - if !strings.Contains(got, want) { - t.Errorf("libx264 argv missing %q: %s", want, got) - } - } - for _, bad := range []string{"-vaapi_device", "format=nv12", "hwupload"} { - if strings.Contains(got, bad) { - t.Errorf("libx264 argv unexpectedly contains %q: %s", bad, got) - } - } -} - -// TestBuildHLSFFmpegArgsVAAPIDump prints the full argv buildHLSFFmpegArgsAt -// emits for a typical VAAPI session. Mimics the daemon spawn step so the -// operator can verify the ffmpeg command-line shape without booting the -// stack — equivalent to `journalctl --user -u unarr-dev | grep ffmpeg` -// but without waiting for a real player session. -func TestBuildHLSFFmpegArgsVAAPIDump(t *testing.T) { - cfg := HLSSessionConfig{ - SessionID: "vaapi-smoke", - SourcePath: "/mnt/nas/peliculas/sample.mkv", - Quality: "720p", - AudioIndex: -1, - Transcode: TranscodeRuntime{ - FFmpegPath: "/usr/bin/ffmpeg", - FFprobePath: "/usr/bin/ffprobe", - HWAccel: HWAccelVAAPI, - }, - } - probe := &StreamProbe{ - VideoCodec: "hevc", - Width: 3840, - Height: 2160, - DurationSec: 5400, - AudioTracks: []ProbeAudioTrack{{Index: 0, Lang: "en", Codec: "ac3"}}, - } - args := buildHLSFFmpegArgsAt(cfg, probe, "/tmp/smoke-tmpdir", 0, 0) - t.Logf("ffmpeg %s", strings.Join(args, " ")) -} diff --git a/internal/funnel/funnel.go b/internal/funnel/funnel.go index 7f1b76a..6a8640a 100644 --- a/internal/funnel/funnel.go +++ b/internal/funnel/funnel.go @@ -32,13 +32,9 @@ import ( ) // urlPattern matches the `https://.trycloudflare.com` URL cloudflared -// prints when a Quick Tunnel is registered. Quick Tunnel hostnames are always -// several hyphen-joined dictionary words (e.g. -// `make-appointments-negotiation-blacks`), so we require at least one hyphen. -// This deliberately excludes cloudflared's control-plane endpoint -// `https://api.trycloudflare.com`, which appears earlier in the log stream — a -// permissive `[a-z0-9-]+` matched `api` first and we advertised a dead URL. -var urlPattern = regexp.MustCompile(`https://[a-z0-9]+(?:-[a-z0-9]+)+\.trycloudflare\.com`) +// prints when a Quick Tunnel is registered. The hostname has a random +// hyphen-separated label followed by .trycloudflare.com. +var urlPattern = regexp.MustCompile(`https://[a-z0-9-]+\.trycloudflare\.com`) // Config controls how the tunnel is launched. type Config struct { diff --git a/internal/funnel/funnel_test.go b/internal/funnel/funnel_test.go deleted file mode 100644 index fa9280d..0000000 --- a/internal/funnel/funnel_test.go +++ /dev/null @@ -1,40 +0,0 @@ -package funnel - -import "testing" - -func TestURLPattern(t *testing.T) { - cases := []struct { - name string - line string - want string - }{ - { - name: "real quick tunnel banner", - line: "2026-05-29T22:18:33Z INF | https://make-appointments-negotiation-blacks.trycloudflare.com |", - want: "https://make-appointments-negotiation-blacks.trycloudflare.com", - }, - { - name: "two-word hostname", - line: "https://blue-river.trycloudflare.com is ready", - want: "https://blue-river.trycloudflare.com", - }, - { - name: "control-plane api endpoint is ignored", - line: `2026-05-29T22:17:59Z DBG POST https://api.trycloudflare.com/tunnel`, - want: "", - }, - { - name: "no trycloudflare url", - line: "2026-05-29T22:17:44Z INF Requesting new quick Tunnel on trycloudflare.com...", - want: "", - }, - } - - for _, tc := range cases { - t.Run(tc.name, func(t *testing.T) { - if got := urlPattern.FindString(tc.line); got != tc.want { - t.Fatalf("FindString(%q) = %q, want %q", tc.line, got, tc.want) - } - }) - } -} diff --git a/internal/sentry/sentry.go b/internal/sentry/sentry.go index 3f16c08..633fc0d 100644 --- a/internal/sentry/sentry.go +++ b/internal/sentry/sentry.go @@ -1,14 +1,12 @@ package sentry import ( - "errors" "os" "runtime" "strings" "time" gosentry "github.com/getsentry/sentry-go" - "github.com/spf13/pflag" ) // dsn is injected at build time via ldflags. If empty, Sentry is disabled. @@ -46,16 +44,9 @@ func Close() { gosentry.Flush(flushTimeout) } -// daemonNotRunningMarker matches the message of agent.ErrDaemonNotRunning -// without importing the agent package — avoids a sentry → agent dependency -// that would risk a cycle if agent ever needed to report errors itself. -const daemonNotRunningMarker = "daemon does not appear to be running" - // CaptureError sends a non-fatal error to Sentry with optional command context. -// Expected non-bug errors (bad CLI input, daemon not running) are skipped to -// keep the issue feed signal-heavy. func CaptureError(err error, command string) { - if err == nil || shouldSkipSentry(err) { + if err == nil { return } @@ -67,21 +58,6 @@ func CaptureError(err error, command string) { }) } -func shouldSkipSentry(err error) bool { - var notExist *pflag.NotExistError - var valueReq *pflag.ValueRequiredError - var invalidVal *pflag.InvalidValueError - var invalidSyn *pflag.InvalidSyntaxError - if errors.As(err, ¬Exist) || errors.As(err, &valueReq) || - errors.As(err, &invalidVal) || errors.As(err, &invalidSyn) { - return true - } - msg := err.Error() - return strings.HasPrefix(msg, "unknown command ") || - strings.HasPrefix(msg, "required flag(s)") || - strings.Contains(msg, daemonNotRunningMarker) -} - // RecoverPanic captures a panic and re-panics after reporting. // Usage: defer sentry.RecoverPanic() func RecoverPanic() { diff --git a/internal/sentry/sentry_test.go b/internal/sentry/sentry_test.go index 4005d14..671e641 100644 --- a/internal/sentry/sentry_test.go +++ b/internal/sentry/sentry_test.go @@ -1,10 +1,6 @@ package sentry -import ( - "errors" - "fmt" - "testing" -) +import "testing" func TestEnvironment(t *testing.T) { tests := []struct { @@ -49,16 +45,3 @@ func TestSetUser(t *testing.T) { // Should not panic without initialization SetUser("agent-123") } - -func TestShouldSkipSentryDaemonNotRunning(t *testing.T) { - // String must stay in sync with agent.ErrDaemonNotRunning. If that sentinel - // is reworded, this test fails loudly so the marker can be updated. - err := errors.New("daemon does not appear to be running (state file not found)") - if !shouldSkipSentry(err) { - t.Error("ErrDaemonNotRunning message should be skipped") - } - wrapped := fmt.Errorf("read daemon state: %w", err) - if !shouldSkipSentry(wrapped) { - t.Error("wrapped ErrDaemonNotRunning message should be skipped") - } -} diff --git a/scripts/release.sh b/scripts/release.sh index 46862be..da9b911 100755 --- a/scripts/release.sh +++ b/scripts/release.sh @@ -55,17 +55,6 @@ fi CURRENT_BRANCH=$(git branch --show-current) [ "$CURRENT_BRANCH" = "main" ] || warn "Not on main branch (current: $CURRENT_BRANCH)" -HEAD_SUBJECT=$(git log -1 --pretty=%s) -if [[ "$HEAD_SUBJECT" =~ \(([0-9]+\.[0-9]+\.[0-9]+)\) ]]; then - die "HEAD commit subject contains inline version bump: \"$HEAD_SUBJECT\" -Release contract: version bumps MUST live in a dedicated 'chore(release): X.Y.Z' commit. -Revert the inline bump and re-run this script — it will create the proper commit." -fi -if [[ "$HEAD_SUBJECT" =~ ^chore\(release\): ]]; then - die "HEAD is already a chore(release) commit: \"$HEAD_SUBJECT\" -Nothing new to release. Add commits since the last release or amend intentionally outside this script." -fi - # ── Resolve version ──────────────────────────────────────────────── LATEST_TAG=$(git describe --tags --abbrev=0 2>/dev/null || echo "v0.0.0") LATEST_VERSION="${LATEST_TAG#v}" diff --git a/scripts/ship.sh b/scripts/ship.sh index d81fd6f..e45eab2 100755 --- a/scripts/ship.sh +++ b/scripts/ship.sh @@ -17,8 +17,7 @@ # 3. Rsync to Hetzner via web/scripts/publish-cli-release.sh # 4. Multi-arch Docker build + push (amd64 + arm64) to Docker Hub # 5. Smoke checks (torrentclaw.com/version + docker run image version) -# 6. Prune Forgejo releases older than FORGEJO_PRUNE_DAYS (default 90) -# 7. Optional `git push --follow-tags` +# 6. Optional `git push --follow-tags` # # Usage: # scripts/ship.sh Detect version from internal/cmd/version.go @@ -34,10 +33,6 @@ # SKIP_DOCKER=1 skip Docker build/push # SKIP_HETZNER=1 skip Hetzner publish # SKIP_SMOKE=1 skip smoke checks -# SKIP_FORGEJO_PRUNE=1 skip Forgejo retention prune -# FORGEJO_TOKEN PAT with write:repository for prune (no token = skip + warn) -# FORGEJO_PRUNE_DAYS retention window, default 90 days -# FORGEJO_REPO default torrentclaw/unarr # set -euo pipefail @@ -49,10 +44,6 @@ PUBLISH_SCRIPT="${PUBLISH_SCRIPT:-$REPO_DIR/../torrentclaw-web/scripts/publish-c SKIP_DOCKER="${SKIP_DOCKER:-0}" SKIP_HETZNER="${SKIP_HETZNER:-0}" SKIP_SMOKE="${SKIP_SMOKE:-0}" -SKIP_FORGEJO_PRUNE="${SKIP_FORGEJO_PRUNE:-0}" -FORGEJO_PRUNE_DAYS="${FORGEJO_PRUNE_DAYS:-90}" -FORGEJO_REPO="${FORGEJO_REPO:-torrentclaw/unarr}" -FORGEJO_BASE="${FORGEJO_BASE:-https://git.torrentclaw.com}" DRY_RUN=false PUSH_TAG=false @@ -170,48 +161,7 @@ if [ "$SKIP_SMOKE" != "1" ]; then fi fi -# 6. Forgejo retention prune -if [ "$SKIP_FORGEJO_PRUNE" != "1" ]; then - if [ -z "${FORGEJO_TOKEN:-}" ]; then - warn "FORGEJO_TOKEN not set — skipping Forgejo prune (set it to enable >${FORGEJO_PRUNE_DAYS}-day cleanup)" - else - info "pruning Forgejo releases older than $FORGEJO_PRUNE_DAYS days" - FORGEJO_API="$FORGEJO_BASE/api/v1/repos/$FORGEJO_REPO/releases" - RELEASES_JSON="$(curl -fsSL -H "Authorization: token $FORGEJO_TOKEN" "$FORGEJO_API?limit=50" || echo '[]')" - PRUNE_IDS="$(echo "$RELEASES_JSON" | python3 -c " -import json, sys -from datetime import datetime, timedelta, timezone -days = int('${FORGEJO_PRUNE_DAYS}') -cutoff = datetime.now(timezone.utc) - timedelta(days=days) -for r in json.load(sys.stdin): - created = datetime.fromisoformat(r['created_at'].replace('Z', '+00:00')) - if created < cutoff: - print(f\"{r['id']}\t{r['tag_name']}\t{r['created_at']}\") -" 2>/dev/null || true)" - DELETED=0 - FAILED=0 - if [ -n "$PRUNE_IDS" ]; then - while IFS=$'\t' read -r REL_ID REL_TAG REL_CREATED; do - [ -z "$REL_ID" ] && continue - CODE="$(curl -s -o /dev/null -w '%{http_code}' -X DELETE -H "Authorization: token $FORGEJO_TOKEN" "$FORGEJO_API/$REL_ID")" - if [ "$CODE" = "204" ]; then - echo " deleted $REL_TAG (created $REL_CREATED)" - DELETED=$((DELETED + 1)) - else - warn " failed to delete $REL_TAG (id=$REL_ID, http=$CODE)" - FAILED=$((FAILED + 1)) - fi - done <<< "$PRUNE_IDS" - fi - if [ "$FAILED" -gt 0 ]; then - warn "Forgejo prune: $DELETED removed, $FAILED failed" - else - ok "Forgejo prune: $DELETED release(s) removed (>${FORGEJO_PRUNE_DAYS} days old)" - fi - fi -fi - -# 7. Optional push +# 5. Optional push if [ "$PUSH_TAG" = true ]; then info "git push origin main --follow-tags" git push origin main --follow-tags