diff --git a/free_games_claimer/CHANGELOG.md b/free_games_claimer/CHANGELOG.md index 8314c6f919..1ea7d83b4a 100644 --- a/free_games_claimer/CHANGELOG.md +++ b/free_games_claimer/CHANGELOG.md @@ -1,3 +1,34 @@ +## 2.2.0 (2026-09-24) + +- Moved the application data out of the add-on's private `/data` volume and + into `/config/data`, so it is visible from Home Assistant as + `/addon_configs/xxx-free_games_claimer/data` instead of needing a + `docker exec`. Everything the application writes now lands there: `fgc.db`, + the `screenshots/` captures, the `browser/` profiles, `TurboVNC.log` and + upstream's debug dumps (#3081). +- An existing `/data` payload is copied over once on the first start of this + version: `fgc.db` with its rollback journal and its pre-migration backup, + `browser/`, `screenshots/`, the `epic-games.json`, `prime-gaming.json` and + `gog.json` claim histories, the legacy `data/` directory and the migration + marker. Logs and last-run debug dumps are not copied, because the application + regenerates them. The copy is staged and renamed into place, so an interrupted + migration is retried rather than leaving a half-copied database or browser + profile. Nothing is deleted from `/data`: the migration needs temporary free + space roughly equal to the existing data, can take a few minutes for a large + browser profile, and leaves the old copy in place so a downgrade still + works. +- **The migrated `browser/` directory holds authenticated store sessions and + `config.env` holds the account credentials. Both are now readable by any + add-on with access to `addon_configs`, such as File Editor or Samba. Treat + that directory as secret and do not share or back it up publicly.** +- Removed the `cp -rnf /fgc/* /data/` line from `20-folders.sh`, which copied + the whole upstream source tree into the persistent volume on every start. + Nothing read those copies. They are left in `/data` and can be deleted by + hand. +- Stopped applying a recursive `chmod 777` to the configuration directory on + every start, which would otherwise have made the migrated browser profile + and credentials world-writable. + ## 2.1.1 (2026-09-12) - Update to latest version from P-Adamiec/Free-Games-Claimer-Remaster (changelog : https://github.com/P-Adamiec/Free-Games-Claimer-Remaster/releases) diff --git a/free_games_claimer/Dockerfile b/free_games_claimer/Dockerfile index f56c24935d..bcfd464924 100644 --- a/free_games_claimer/Dockerfile +++ b/free_games_claimer/Dockerfile @@ -118,7 +118,7 @@ RUN (curl --proto "=https" --tlsv1.2 -fsSL \ && chmod 0755 /usr/local/bin/docker-entrypoint.sh \ && rm -f /tmp/free-games-claimer-remaster.tar.gz \ && rm -rf /fgc/data \ - && ln -s /data /fgc/data + && ln -s /config/data /fgc/data # Add Home Assistant integration files and shared helper modules. COPY rootfs/ / diff --git a/free_games_claimer/README.md b/free_games_claimer/README.md index 0dcb0a2256..ed7911826f 100644 --- a/free_games_claimer/README.md +++ b/free_games_claimer/README.md @@ -67,6 +67,31 @@ the default and preserves the behavior of the former vogler-based add-on. With `RUN_ONCE: false`, the remaster remains running and uses its internal scheduler. Set `SCHEDULER_HOURS` in `config.env` to control the interval. +## Application data + +The add-on stores everything the application writes in `/config/data`, which +Home Assistant exposes as `/addon_configs/xxx-free_games_claimer/data`. It can +be inspected with a file browser add-on without a `docker exec`, and contains: + +| Path | Contents | +|------|----------| +| `fgc.db` | SQLite claim history | +| `screenshots//` | Screenshots taken during a claiming run | +| `browser/` | Chromium profiles, one per store | +| `TurboVNC.log` | Virtual display server log | +| `config.env` | Runtime copy of `CONFIG_LOCATION` | + +**This directory is secret.** `browser/` holds signed-in store sessions and +`config.env` holds the account credentials, so anyone with access to +`addon_configs` — the File Editor and Samba add-ons, for instance — can use +them. Do not share or publish it. + +Versions up to 2.1.1 kept this data in the private `/data` volume. An existing +payload is copied to `/config/data` once, on the first start of version 2.2.0. The copy needs temporary free space roughly equal to the +existing data and can take a few minutes when the browser profile is large. +Nothing is removed from `/data`, so a downgrade keeps working; the old copy can +be deleted by hand once the new location is confirmed to work. + ## Environment configuration The add-on keeps its configuration in `CONFIG_LOCATION`, which defaults to @@ -124,12 +149,13 @@ The add-on performs the following migration automatically on first start: 1. The existing `config.env` remains at the same configured location. 2. Legacy `epic-games.json`, `prime-gaming.json`, and `gog.json` claim history - is imported into the remaster SQLite database at `/data/fgc.db`. + is imported into the remaster SQLite database at `/config/data/fgc.db`. 3. Existing database rows are detected and are not duplicated if migration is retried. 4. A pre-migration database backup is created when an existing `fgc.db` is present. -5. All old files remain under `/data/data` for rollback or manual recovery. +5. All old files remain under `/config/data/data` for rollback or manual + recovery. Browser sessions cannot be converted because the old add-on used a shared Firefox profile while the remaster uses separate Chromium profiles per store. diff --git a/free_games_claimer/config.yaml b/free_games_claimer/config.yaml index bdaf2c7b68..1d7d21322f 100644 --- a/free_games_claimer/config.yaml +++ b/free_games_claimer/config.yaml @@ -96,5 +96,5 @@ schema: slug: free_games_claimer udev: true url: https://github.com/alexbelgium/hassio-addons -version: "2.1.1" +version: "2.2.0" webui: "[PROTO:ssl]://[HOST]:[PORT:6080]" diff --git a/free_games_claimer/rootfs/etc/cont-init.d/20-folders.sh b/free_games_claimer/rootfs/etc/cont-init.d/20-folders.sh index 396a0ebb13..a63ee54126 100755 --- a/free_games_claimer/rootfs/etc/cont-init.d/20-folders.sh +++ b/free_games_claimer/rootfs/etc/cont-init.d/20-folders.sh @@ -2,14 +2,41 @@ # shellcheck shell=bash set -e +# Up to version 2.1.1 the application stored its data in the add-on's private +# /data volume, which is only reachable with "docker exec". It now lives in +# /config/data, which Home Assistant exposes as +# /addon_configs/xxx-free_games_claimer/data. Copy an existing payload over +# once. The copy is staged and renamed into place, so an interrupted migration +# is retried on the next start instead of leaving a half-copied database or +# browser profile behind. Nothing is removed from /data, so downgrading still +# finds its data. +# +# This runs before the CONFIG_LOCATION directory is created below: a +# CONFIG_LOCATION under /config/data would otherwise create the destination +# and make the migration skip itself. +if [ ! -d /config/data ]; then + legacy=() + for entry in fgc.db fgc.db-journal fgc.db.pre-vogler-migration \ + .vogler-remaster-migrated-v1.json browser screenshots data \ + epic-games.json prime-gaming.json gog.json; do + if [ -e "/data/$entry" ]; then + legacy+=("/data/$entry") + fi + done + if [ "${#legacy[@]}" -gt 0 ]; then + echo "Copying the application data to /config/data, this can take a few minutes ..." + rm -rf /config/.data-migration + mkdir -p /config/.data-migration + cp -a "${legacy[@]}" /config/.data-migration/ + mv /config/.data-migration /config/data + fi +fi + +mkdir -p /config/data + # Define home # Creating config location echo "Creating config location ..." HOME="$(bashio::config "CONFIG_LOCATION")" HOME="$(dirname "$HOME")" mkdir -p "$HOME" -chmod -R 777 "$HOME" - -# Copy files to data -echo "Copying files if needed..." -cp -rnf /fgc/* /data/ diff --git a/free_games_claimer/rootfs/etc/cont-init.d/99-run.sh b/free_games_claimer/rootfs/etc/cont-init.d/99-run.sh index 7dac64162d..693909c3ae 100755 --- a/free_games_claimer/rootfs/etc/cont-init.d/99-run.sh +++ b/free_games_claimer/rootfs/etc/cont-init.d/99-run.sh @@ -7,9 +7,9 @@ if bashio::config.has_value 'CONFIG_LOCATION'; then CONFIG_FILE="$(bashio::config 'CONFIG_LOCATION')" fi CONFIG_DIR="$(dirname "${CONFIG_FILE}")" -RUNTIME_CONFIG="/data/config.env" +RUNTIME_CONFIG="/config/data/config.env" -mkdir -p "${CONFIG_DIR}" /data +mkdir -p "${CONFIG_DIR}" /config/data # Recover from an old add-on bug that could create config.env as a directory. if [ -d "${CONFIG_FILE}" ]; then @@ -25,9 +25,13 @@ else bashio::log.info "Using configuration from ${CONFIG_FILE}" fi -# The remaster reads /fgc/data/config.env. /fgc/data is linked to Home -# Assistant's persistent /data volume by the Dockerfile. -install -m 0600 "${CONFIG_FILE}" "${RUNTIME_CONFIG}" +# The remaster reads /fgc/data/config.env. /fgc/data is linked to /config/data +# by the Dockerfile, so the runtime copy is visible under /addon_configs. +# CONFIG_LOCATION may itself be /config/data/config.env, in which case the two +# paths are the same file and install would fail. install applies the mode as it +# creates the file; the chmod is for that same-file case. +[ "${CONFIG_FILE}" -ef "${RUNTIME_CONFIG}" ] || install -m 0600 "${CONFIG_FILE}" "${RUNTIME_CONFIG}" +chmod 0600 "${RUNTIME_CONFIG}" sed -i 's/\r$//' "${RUNTIME_CONFIG}" # Export values needed by the VNC entrypoint as well as by the Python app. diff --git a/free_games_claimer/rootfs/usr/local/bin/migrate_vogler_data.py b/free_games_claimer/rootfs/usr/local/bin/migrate_vogler_data.py index 1c11bf6e3b..0b683b1cc7 100644 --- a/free_games_claimer/rootfs/usr/local/bin/migrate_vogler_data.py +++ b/free_games_claimer/rootfs/usr/local/bin/migrate_vogler_data.py @@ -12,7 +12,7 @@ from datetime import datetime, timezone from pathlib import Path from typing import Any, Iterator -DATA_DIR = Path(os.environ.get("FGC_DATA_DIR", "/data")) +DATA_DIR = Path(os.environ.get("FGC_DATA_DIR", "/config/data")) LEGACY_DIR = DATA_DIR / "data" DATABASE = DATA_DIR / "fgc.db" MARKER = DATA_DIR / ".vogler-remaster-migrated-v1.json" @@ -220,7 +220,7 @@ def migrate() -> int: if legacy_browser.exists(): log( - "Legacy Firefox browser data remains in /data/data/browser. It is " + "Legacy Firefox browser data remains in /config/data/data/browser. It is " "not compatible with Chromium, so use noVNC for a one-time login if needed." )