Compare commits

..

14 Commits

Author SHA1 Message Date
Alexandre
8984e64ca0 Add sub_filter for '/auth' in ingress.conf 2026-08-18 09:58:52 +02:00
Alexandre
76770b181c Update ingress.conf 2026-08-18 09:58:10 +02:00
dependabot[bot]
2b6e07040f Bump anthropics/claude-code-action from 1.0.187 to 1.0.193 (#2984)
Bumps [anthropics/claude-code-action](https://github.com/anthropics/claude-code-action) from 1.0.187 to 1.0.193.
- [Release notes](https://github.com/anthropics/claude-code-action/releases)
- [Commits](1623c36729...9d7150bc8a)

---
updated-dependencies:
- dependency-name: anthropics/claude-code-action
  dependency-version: 1.0.193
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 08:43:45 +02:00
dependabot[bot]
680386525f Bump EndBug/add-and-commit from 10 to 11 (#2985)
Bumps [EndBug/add-and-commit](https://github.com/endbug/add-and-commit) from 10 to 11.
- [Release notes](https://github.com/endbug/add-and-commit/releases)
- [Commits](https://github.com/endbug/add-and-commit/compare/v10...v11)

---
updated-dependencies:
- dependency-name: EndBug/add-and-commit
  dependency-version: '11'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-18 08:43:31 +02:00
github-actions
20a2f997c9 GitHub bot: changelog [nobuild] 2026-08-17 16:43:17 +00:00
Alexandre
15de5e3a39 fix(seerr): add trailing slash to ingress root-link rewrites (#2976)
Seerr's Discover link is href="/". nginx rewrote it to the bare ingress
entry, but Home Assistant only routes ingress on
"/api/hassio_ingress/{token}/{path:.*}", so a URL without the trailing
slash matches no route and Home Assistant answers its own plain-text
"404: Not Found" before the request reaches the add-on.

Closes #2975

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 18:35:14 +02:00
Pol Montanera
232e697301 Fix FileBrowser Quantum direct web access (#2979)
* Fix FileBrowser Quantum direct web access

* fix(filebrowser_quantum): make direct ip:port access actually work

ports: {8080/tcp: 8071} alone (as originally proposed) publishes the app's
own port, but FileBrowser Quantum's server.baseURL is set at boot to the
Supervisor ingress-entry path (an opaque, per-install hash), so the app only
serves correctly under that exact path -- a bare port publish gives an
unreachable page, per alexbelgium's own analysis on #2978.

Add a second, dedicated nginx vhost (direct.conf) that proxies a fixed public
path (/filebrowser_quantum/) onto the same ingress-entry baseURL the existing
ingress vhost already targets, instead of changing the app's baseURL itself.
This leaves the ingress vhost, and therefore Ingress access, completely
unchanged -- only the new vhost is new surface area. config.yaml now
publishes the new vhost's internal port (8072) to host 8071, not the app's
own 8080 directly.

Co-authored-by: polmonta <polmonta05@gmail.com>

---------

Co-authored-by: polmonta <polmonta05@gmail.com>
Co-authored-by: alexbelgium <alexandre.pary@gmail.com>
2026-08-17 18:32:48 +02:00
Alexandre
53ad396e5b fix(claude_desktop): sign-in persistence broke again — safeStorage patcher didn't handle bundles without a use-strict directive (#2983)
* fix(claude_desktop): patch safeStorage on bundles without a use-strict directive

The v1.37 safeStorage patcher only knew how to inject its plaintext-encryption
opt-in after a leading "use strict" directive in Claude Desktop's main bundle,
and refused to patch anything else. Confirmed live: Claude Desktop 1.30096.1's
main bundle no longer opens with that directive (bare IIFE instead), so the
patch has been silently refusing to run on every boot and sessions stopped
persisting across restarts again, with the same "Encryption not available"
warning documented in SIGN_IN.md before v1.37.

applyPatch() now falls back to prepending the opt-in as the bundle's first
statement when no directive is found, after skipping any leading BOM,
hashbang, or banner comment so a directive hidden behind a comment is still
protected rather than pushed out of position zero.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* fix(claude_desktop): scan the full directive prologue, not just line 0

Addresses two Codex review findings on PR #2983:

1. skipPrologue()'s //-comment scan only recognized "\n" as a line
   terminator. A comment ending in CR-only or U+2028/U+2029 (all valid
   ECMAScript LineTerminators) made it swallow the rest of the file as
   "still the comment", landing the patch after the bundle's last
   statement instead of before it. Reproduced with
   `// banner\r"use strict";(function(){})();`.

2. applyPatch() only checked whether the very first statement was
   literally "use strict". A directive prologue can hold more than one
   string-literal statement, and "use strict" only has to appear
   somewhere in it, not first; prepending ahead of an earlier directive
   pushed the whole prologue out of first-statement position and
   silently dropped strict mode. Reproduced with
   `"use custom";"use strict";(...)`.

Replaced the single-directive check with scanDirectivePrologue(), which
walks every leading string-literal-only statement and inserts right
after the full prologue (or at the same position when there is none).
skipPrologue/applyPatch split into skipBomAndHashbang +
skipWhitespaceAndComments + scanDirectivePrologue accordingly.

Verified: both findings reproduced against the pre-fix code and no
longer occur; 13-case regression suite covering the original edge cases
plus both findings all pass; re-run against the live production
app.asar still patches successfully and idempotently.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-17 18:31:20 +02:00
Alexandre
bcdd972c2f Revert "docs(filebrowser_quantum): stop advertising direct access on port 807…" (#2982)
This reverts commit 65233d1291.
2026-08-17 07:57:24 +02:00
Alexandre
65233d1291 docs(filebrowser_quantum): stop advertising direct access on port 8071 (#2981)
config.yaml declares ingress_port: 8071 but no ports: key, so nothing is
published to the host network. ingress_port is the internal port the
Supervisor ingress proxy connects to on the add-on's private IP, and Home
Assistant only renders the Network card for add-ons that declare ports:.
Direct access at <your-ip>:8071 has therefore never worked; the README was
carried over from the sibling filebrowser add-on, which does declare
ports: 8080/tcp: 8071.

Correct the three README claims rather than publishing a port, since the
app is configured with server.baseURL set to the ingress entry and would
not serve correctly on a plain published port without further work.

Closes #2978

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-17 07:55:10 +02:00
github-actions
f63b4f3f92 Github bot : image compressed 2026-08-16 23:05:57 +00:00
github-actions[bot]
4b68ce7efd Update stargazer map & cache 2026-08-16 00:22:00 +00:00
Alexandre
9b9eab47bc fix(birdnet-pi): make ALSA_CARD actually select the microphone (#2972)
* fix(birdnet-pi): turn ALSA_CARD into a valid ALSA PCM name for REC_CARD

99-run.sh copied ALSA_CARD verbatim into REC_CARD, but BirdNET-Pi passes
REC_CARD to "arecord -D" (scripts/birdnet_recording.sh) and "ffmpeg -f alsa
-i" (scripts/livestream.sh), which expect an ALSA PCM name. A card index such
as ALSA_CARD=1 therefore produced "Unknown PCM 1" and no recording at all.

Build "plughw:CARD=<value>,DEV=0" from a card index or card id, and pass
through a value that already is a PCM name. Also use sed --follow-symlinks so
the rewrite no longer replaces the ~/BirdNET-Pi/birdnet.conf symlink with a
detached copy of /config/birdnet.conf.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: address CodeRabbit review

* fix(birdnet-pi): bump version so the ALSA_CARD fix actually ships

The PR changed 99-run.sh and added a CHANGELOG entry but left config.yaml
untouched, so `version` still read 2026.08.02. Supervisor only offers a rebuild
when `version` changes: without this the fix would have merged, the add-on would
have kept running the old image, and the issue would have looked closed while
ALSA_CARD stayed broken.

2026.08.15 matches the CHANGELOG heading this PR already adds, which is this
add-on's convention — every past version lines up with a dated heading
(2026.08.02, 2026.07.22, ...). Not a `.N` counter bump: birdnet-pi's `version`
has drifted from updater.json's `upstream_version` (0.11), so the counter rule
does not apply and the add-on's own date scheme governs.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(birdnet-pi-zach): turn ALSA_CARD into a valid ALSA PCM name for REC_CARD

birdnet-pi-zach/rootfs/etc/cont-init.d/99-run.sh carried a byte-identical
copy of the same bug fixed in birdnet-pi by this PR: REC_CARD was copied
verbatim from ALSA_CARD, but BirdNET-Pi passes REC_CARD to "arecord -D"
and "ffmpeg -f alsa -i", which expect an ALSA PCM name, not a card index.
sed -i also replaced the $HOME/BirdNET-Pi/birdnet.conf symlink with a
detached copy on first use.

Apply the same fix: build "plughw:CARD=<value>,DEV=0" from a card index
or card id, pass through a value that already is a PCM name, and use
sed --follow-symlinks against /config/birdnet.conf only. Documented in
README_standalone.md, same as birdnet-pi.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix: resolve ALSA_CARD against real PCM names, not a fixed allowlist

CodeRabbit and Codex both flagged that the passthrough check only recognized
default/null/pulse/pipewire: any other colon-free ALSA PCM name (sysdefault,
front, surround51, a custom .asoundrc alias, ...) was still misread as a card
index/id and rewritten as plughw:CARD=<name>,DEV=0, which then fails to open.

alsa-utils is already installed in both images, so check the value against
"arecord -L" (an exact, whole-line match against its unindented PCM-name
lines) instead of hardcoding the set of names ALSA ships with. Anything that
isn't a real PCM name still falls through to the plughw:CARD= build, so a
numeric index or a card id is handled exactly as before.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: claude[bot] <41898282+claude[bot]@users.noreply.github.com>
Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 19:22:18 +02:00
Alexandre
948a2722f3 fix(ai): let the fix step own config.yaml, and require the patch-counter bump (#2973)
* fix(ai): let the fix step own config.yaml, and require the patch-counter bump

The premise that the fix step cannot touch config.yaml turned out to be wrong,
and the real problem was the opposite of what it looked like.

config.yaml was already in scope — issue-fix.md lists it among the files the
sweep reads and owns, and all three merged ai-fix PRs edited it. What they
edited, though, was the one thing hard limit 2 forbade outright:

  PR #2970  qbittorrent  version: "5.2.3.2" -> "5.2.3.3"
  PR #2912  bazarr       version: "1.6.0.1" -> "1.6.0.2"

Both bumped only the LOCAL PATCH COUNTER, leaving the upstream X.Y.Z alone —
i.e. exactly the right thing, in direct violation of the written rule. Nothing
enforces that rule (ai_guard_paths.sh only covers .github/ and .templates/), so
it has been quietly contradicted by practice, and it also contradicts CLAUDE.md's
own PR requirement to bump version.

It matters because Supervisor will not offer a rebuild without the bump: a fix
merged without one ships inert while the issue looks closed. That is the worst
outcome available — worse than not fixing it.

So the carve-out is narrowed to what addons_updater actually owns (the
`upstream` field and the upstream X.Y.Z), and bumping the trailing .N is now
required rather than forbidden, with the dot-not-hyphen trap called out
(X.Y.Z-N reads as a semver pre-release and Supervisor treats it as older).
Exotic version shapes — LSIO tags, dates, nightlies — are explicitly left alone
rather than guessed at.

Applied to all four places the rule is stated so they cannot drift:
issue-fix.md, issue-execute-plan.md, CLAUDE.md, and pr-coderabbit.md — the last
keeps the restriction, since it amends a PR whose single bump already covers it,
but now says why instead of reading as a contradiction.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

* fix(ai): derive the patch counter from updater.json, not from version's shape

Six review findings, all reproduced against the repo before accepting.

Codex (P1) — the rule "increment the trailing .N" is wrong for most of this
repo, because you cannot tell a local counter from an upstream component by
looking at `version`. Checked all 134 add-ons:

  version == upstream_version (no counter, must APPEND .1):  82
  version == upstream_version + .N (counter, INCREMENT):      8
  version drifted from upstream (LEAVE ALONE):               36
  no usable updater.json (LEAVE ALONE):                       8

So the previous wording would have mutated updater-owned data on 82 add-ons:
sonarr's 4.0.19.3001 IS the upstream version, and incrementing it to
4.0.19.3002 burns the identifier of a future real release; linkwarden's 2.16.0
would have become 2.16.1, indistinguishable from an upstream minor bump.

updater.json's upstream_version is now the authority: append .1 when version
equals it, increment only the digits that follow it, otherwise leave version
alone. Validated by running the rule as written over every add-on — 0
violations of the invariant that a bumped version must still start with
upstream_version.

Copilot — there is no `upstream:` key in any config.yaml (0 of 134); upstream
tracking lives in updater.json as upstream_repo / upstream_version. That was
inherited text naming a field that does not exist, in all four places. Replaced
with the real constraint: never edit updater.json.

Copilot — the "a workflow step enforces them" headers over-claimed. Only limit
1 is machine-enforced (ai_guard_paths.sh); the rest ship silently if broken,
which is worth saying plainly given limit 2 has been quietly contradicted by
practice for months.

Copilot — Outcome B produces a plan and no PR, so "say so in the pull request
body" had no place to land. Now covers both.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 5 <noreply@anthropic.com>
2026-08-15 19:14:29 +02:00
174 changed files with 368 additions and 61 deletions

View File

@@ -11,10 +11,21 @@ Read:
diff, verification, risk). This is your spec.
- `/tmp/ai-exec/issue.json` — the issue it fixes (for `Closes #<n>` and context).
## Hard limits (identical to the fix sweep — a workflow step enforces them)
## Hard limits (identical to the fix sweep; only limit 1 is machine-enforced)
1. **Never modify `.github/` or `.templates/`.** Repo-wide infrastructure.
2. **Never touch the `version` or `upstream` fields in `config.yaml`.**
2. **`config.yaml` is yours to edit, except the upstream part of `version`;
never edit `updater.json`** — `addons_updater` owns both. (There is no
`upstream:` key in `config.yaml`.) You must still
bump the local patch counter, or Supervisor never offers the rebuild and the
fix ships inert. Read `updater.json` to find the boundary — you cannot tell
it from `version` alone, since upstream versions here run to four or five
components. With `U` = `upstream_version`: if `version` equals `U`, **append**
`.1` (sonarr `4.0.19.3001` -> `4.0.19.3001.1`); if it is `U` + `.` + digits,
**increment** those digits (radarr `6.3.0.10514.1` -> `6.3.0.10514.2`);
anything else — no `updater.json`, drifted version, LSIO tag, date, nightly —
leave `version` alone and say so in the pull request body. A dot, never a
hyphen.
3. **One add-on, one branch:** `ai-fix/<addon>-<issue-number>`.
4. **Never merge, never close the issue, never enable auto-merge.** Open the
pull request **ready for review** — CI (`onpr_check-pr.yaml`) validates it,

View File

@@ -13,14 +13,52 @@ about confidence matters more than the number of pull requests you open.
## Hard limits
These are not guidelines. A workflow step enforces them after you finish, and
anything that violates them gets blocked and flagged.
These are not guidelines. Limit 1 is machine-enforced — a workflow step checks
every pull request you open and blocks and flags anything that violates it. The
rest are on you: nothing checks them, so breaking one ships silently.
1. **Never modify `.github/` or `.templates/`.** Those are inherited by every
add-on in the repo. A change there is a 100-add-on incident, not a fix.
2. **Never touch the `version` or `upstream` fields in `config.yaml`.** The
`addons_updater` job owns those. Editing them causes merge conflicts you
will not be around to resolve.
2. **`config.yaml` is yours to edit, with one carve-out.** Never change the
*upstream part* of `version` — the portion that tracks the upstream release
— and never edit `updater.json` at all. The `addons_updater` job owns both,
and editing them causes merge conflicts you will not be around to resolve.
(There is no `upstream:` key in `config.yaml`; upstream tracking lives in
`updater.json` as `upstream_repo` / `upstream_version`.)
The **local patch counter** is a different thing and you must bump it. When
you change any file in an add-on, `version` must change too — otherwise
Supervisor never offers the rebuild, the add-on keeps running the old image,
and your fix ships inert: merged, doing nothing, with the issue looking
closed. That is worse than not fixing it at all.
**You cannot tell the counter from `version` alone — read `updater.json`.**
Upstream versions in this repo have anywhere from one to five components, so
a trailing `.1234` is just as likely to belong to upstream as to be a local
counter. `updater.json`'s `upstream_version` is the authority. Let `U` be
that value, and compare:
| `version` vs `U` | what to do | example |
|---|---|---|
| identical | **append** `.1` | sonarr `4.0.19.3001` -> `4.0.19.3001.1` |
| `U` + `.` + digits | **increment** those digits | radarr `6.3.0.10514.1` -> `6.3.0.10514.2` |
| anything else | **leave it alone** | plex, readarr, joal |
Getting this backwards corrupts data you do not own: sonarr's `4.0.19.3001`
*is* the upstream version, so "increment the last component" would produce
`4.0.19.3002` and burn the identifier of a future real release. 82 of the
add-ons in this repo are in that first row — appending is the common case,
incrementing the rare one.
Use a dot, never a hyphen: `X.Y.Z-N` parses as a semver pre-release, which
Supervisor treats as *older* than `X.Y.Z` and will not offer.
The third row is not a failure — it is the safe answer whenever the add-on
has no `updater.json`, its `version` has drifted from `upstream_version`, or
the format is exotic (LSIO tag `1.43.1.10611-1e34174b1-ls301`, a date, a
nightly). Do not guess a counter onto those. Leave `version` untouched and
say so — in the pull request body, or in the plan if this issue is going out
as Outcome B — so a human can decide.
3. **One add-on per branch, one branch per pull request.** Branch name
`ai-fix/<addon>-<issue-number>`.
4. **Never merge, never close an issue, never enable auto-merge.** Opening a

View File

@@ -23,7 +23,10 @@ Consider only comments authored by `coderabbitai[bot]`. Ignore its collapsed
## Hard limits (a workflow step enforces the first)
1. **Never modify `.github/` or `.templates/`.** Repo-wide infrastructure.
2. **Never touch the `version` or `upstream` fields in `config.yaml`.**
2. **Leave `version` in `config.yaml` alone, and never edit `updater.json`.** The rest of
`config.yaml` is fair game. Unlike the fix sweep, you are amending a pull
request that has *already* bumped the local patch counter — one bump covers
the whole PR, so incrementing it again here would just churn the diff.
3. **Stay within this PR's scope and branch.** Do not open a new PR, do not
touch other add-ons, do not merge, do not mark ready/draft.

View File

@@ -442,6 +442,7 @@ Lolekpolek,,2026-08-10
LonelySoul7X,,2026-08-10
Lorsel,Italy,
Luca2165801154,,2026-08-10
Lucius-Waverly,,2026-08-16
LuciusEternal,,2026-08-10
LuckyTriple7,Germany,
Luckyfuzz,,2026-08-10
@@ -539,6 +540,7 @@ NoFace3D,,2026-08-10
Noa3129,,2026-08-10
Noob25930,,2026-08-10
NuclearTruck,,2026-08-10
OXERY,,2026-08-16
Oberknecht,Germany,
OdorDecoder,,2026-08-10
Omega7572,,
@@ -1083,6 +1085,7 @@ cecet23,Italy,
cecilchurms,,2026-08-10
celynw,United Kingdom,
ch4d1,Germany,
chapliak,Canada,2026-08-16
charithmadhuranga,Sri Lanka,
charl3y15,United States,
charlestephen,United States,
@@ -1112,6 +1115,7 @@ cicishahita,,2026-08-10
cipector,,2026-08-10
circasurvivor55,,2026-08-10
cirf,,2026-08-10
citizenserious,,2026-08-16
cityeyes,,2026-08-10
classhu,,2026-08-10
clementleroy,France,
@@ -1744,6 +1748,7 @@ lakshanthad,Canada,
lallinger-tech,Germany,
laoto1234,,2026-08-10
larry3,,2026-08-10
lassepi,,2026-08-16
laughedelic,Norway,
lazymule,Türkiye,2026-08-10
lazytarget,Sweden,
@@ -1760,6 +1765,7 @@ letrouf,,2026-08-10
levvvy,,2026-08-10
lexluthors,,2026-08-10
lguerard,,2026-08-10
lheinke,,2026-08-16
lhimo,,2026-08-10
liangshao200,,2026-08-10
lichenophile,,2026-08-10
@@ -1842,6 +1848,7 @@ mareklab,,2026-08-10
marevers,Germany,
marian-paun,Romania,
mariusvslprts,Germany,
mark-219,United States,2026-08-16
markcshaz,,2026-08-10
markist,,2026-08-10
marlonqpa,,2026-08-10
@@ -1885,6 +1892,7 @@ mediaexplorer74,Russian Federation,2026-08-10
mefisto22,,2026-08-10
megavolts,United States,
megawubs,Netherlands,
meremortals70,,2026-08-16
meska,,2026-08-10
methbkts,France,
mevlutdemirbas,,2026-08-10
@@ -1940,6 +1948,7 @@ mmstano,,2026-08-10
mmz06,,2026-08-10
mnex9191,,2026-08-10
mnpeart,United States,
mocodev-io,,2026-08-16
moein805,"Iran, Islamic Republic of",
mohammedmulazada,Netherlands,
mohammednafeel,,2026-08-10
@@ -1979,6 +1988,7 @@ natbrood,,2026-08-10
nate-marshall,,2026-08-10
nduest,Germany,
ne7runner,,2026-08-10
nean,,2026-08-16
nedsined,,2026-08-10
neildotwilliams,,2026-08-10
neilpercy,,2026-08-10
@@ -2167,6 +2177,7 @@ qdominik,,2026-08-10
qezzo,,2026-08-10
qianc123,,2026-08-10
qimingzihaofan233,,2026-08-10
qtoosha,,2026-08-16
quank1968,,2026-08-10
quartzbear,,2026-08-10
quirbiefe,,2026-08-10
@@ -2369,6 +2380,7 @@ stDragon,,2026-08-10
stagietek,Australia,
stanisboiko,Ukraine,
starbuck93,United States,
statuscue,Germany,2026-08-16
steef84,,2026-08-10
stef-th,,2026-08-10
stefangries,,2026-08-10
@@ -2455,6 +2467,7 @@ threnard,,2026-08-10
tianmaozuo,,2026-08-10
tibonou,,2026-08-10
tigroff,,2026-08-10
tijmenvanstraten,,2026-08-16
tillmannschatz,Germany,
tim-frensch,,2026-08-10
timTam97,Australia,
1 username country last_checked
442 LonelySoul7X 2026-08-10
443 Lorsel Italy
444 Luca2165801154 2026-08-10
445 Lucius-Waverly 2026-08-16
446 LuciusEternal 2026-08-10
447 LuckyTriple7 Germany
448 Luckyfuzz 2026-08-10
540 Noa3129 2026-08-10
541 Noob25930 2026-08-10
542 NuclearTruck 2026-08-10
543 OXERY 2026-08-16
544 Oberknecht Germany
545 OdorDecoder 2026-08-10
546 Omega7572
1085 cecilchurms 2026-08-10
1086 celynw United Kingdom
1087 ch4d1 Germany
1088 chapliak Canada 2026-08-16
1089 charithmadhuranga Sri Lanka
1090 charl3y15 United States
1091 charlestephen United States
1115 cipector 2026-08-10
1116 circasurvivor55 2026-08-10
1117 cirf 2026-08-10
1118 citizenserious 2026-08-16
1119 cityeyes 2026-08-10
1120 classhu 2026-08-10
1121 clementleroy France
1748 lallinger-tech Germany
1749 laoto1234 2026-08-10
1750 larry3 2026-08-10
1751 lassepi 2026-08-16
1752 laughedelic Norway
1753 lazymule Türkiye 2026-08-10
1754 lazytarget Sweden
1765 levvvy 2026-08-10
1766 lexluthors 2026-08-10
1767 lguerard 2026-08-10
1768 lheinke 2026-08-16
1769 lhimo 2026-08-10
1770 liangshao200 2026-08-10
1771 lichenophile 2026-08-10
1848 marevers Germany
1849 marian-paun Romania
1850 mariusvslprts Germany
1851 mark-219 United States 2026-08-16
1852 markcshaz 2026-08-10
1853 markist 2026-08-10
1854 marlonqpa 2026-08-10
1892 mefisto22 2026-08-10
1893 megavolts United States
1894 megawubs Netherlands
1895 meremortals70 2026-08-16
1896 meska 2026-08-10
1897 methbkts France
1898 mevlutdemirbas 2026-08-10
1948 mmz06 2026-08-10
1949 mnex9191 2026-08-10
1950 mnpeart United States
1951 mocodev-io 2026-08-16
1952 moein805 Iran, Islamic Republic of
1953 mohammedmulazada Netherlands
1954 mohammednafeel 2026-08-10
1988 nate-marshall 2026-08-10
1989 nduest Germany
1990 ne7runner 2026-08-10
1991 nean 2026-08-16
1992 nedsined 2026-08-10
1993 neildotwilliams 2026-08-10
1994 neilpercy 2026-08-10
2177 qezzo 2026-08-10
2178 qianc123 2026-08-10
2179 qimingzihaofan233 2026-08-10
2180 qtoosha 2026-08-16
2181 quank1968 2026-08-10
2182 quartzbear 2026-08-10
2183 quirbiefe 2026-08-10
2380 stagietek Australia
2381 stanisboiko Ukraine
2382 starbuck93 United States
2383 statuscue Germany 2026-08-16
2384 steef84 2026-08-10
2385 stef-th 2026-08-10
2386 stefangries 2026-08-10
2467 tianmaozuo 2026-08-10
2468 tibonou 2026-08-10
2469 tigroff 2026-08-10
2470 tijmenvanstraten 2026-08-16
2471 tillmannschatz Germany
2472 tim-frensch 2026-08-10
2473 timTam97 Australia

Binary file not shown.

Before

Width:  |  Height:  |  Size: 404 KiB

After

Width:  |  Height:  |  Size: 68 KiB

BIN
.github/stats.png vendored

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.0 KiB

After

Width:  |  Height:  |  Size: 1.9 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 9.6 KiB

After

Width:  |  Height:  |  Size: 4.1 KiB

View File

@@ -228,7 +228,7 @@ jobs:
echo "... done"
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "GitHub bot : README updated"
default_author: github_actions

View File

@@ -125,7 +125,7 @@ jobs:
- name: Analyse and fix
if: steps.batch.outputs.count != '0'
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange. The scheduled path

View File

@@ -237,7 +237,7 @@ jobs:
# Get stars evolution
wget -S -O .github/starsevol.svg "https://api.star-history.com/svg?repos=alexbelgium/hassio-addons&type=Date" || true
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "GitHub bot : graphs updated"
default_author: github_actions

View File

@@ -64,7 +64,7 @@ jobs:
fetch-depth: 1
- name: Run Claude Code
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# AI_PR_TOKEN, not GITHUB_TOKEN, so a PR Claude opens triggers CI.

View File

@@ -135,7 +135,7 @@ jobs:
- name: Execute the plan
if: steps.bundle.outputs.has_plan == 'true'
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange, which 401s whenever

View File

@@ -59,7 +59,7 @@ jobs:
# Remove issues list
rm issueslist
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "Github bot : issues linked to readme"
default_author: github_actions

View File

@@ -166,7 +166,7 @@ jobs:
id: classify
if: github.event_name != 'issue_comment' || steps.claim.outputs.go == 'true'
continue-on-error: true
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Without this the action falls back to the OIDC -> Claude App token

View File

@@ -79,7 +79,7 @@ jobs:
- name: Address CodeRabbit comments
if: steps.claim.outputs.go == 'true'
uses: anthropics/claude-code-action@1623c36729ac1cd5895198cded705a287de7db79 # v1
uses: anthropics/claude-code-action@9d7150bc8a3dae8149739a88019d192b579ad90c # v1
with:
claude_code_oauth_token: ${{ secrets.CLAUDE_CODE_OAUTH_TOKEN }}
# Skip the OIDC -> Claude App token exchange, which 401s whenever

View File

@@ -95,7 +95,7 @@ jobs:
- name: Commit sanitize changes
id: sanitize_commit
if: ${{ github.event_name == 'push' && github.ref == 'refs/heads/master' }}
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
commit: -u
message: "GitHub bot: sanitize (spaces + LF endings) & chmod [nobuild]"
@@ -410,7 +410,7 @@ jobs:
done
- name: Commit changelog changes
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
commit: -u
message: "GitHub bot: changelog [nobuild]"

View File

@@ -18,7 +18,7 @@ jobs:
uses: erclu/check-crlf@v1
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "Github bot : CRLF corrected"
default_author: github_actions
@@ -50,7 +50,7 @@ jobs:
dos2unix -k "$f"
done
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "Github bot : CRLF corrected"
default_author: github_actions

View File

@@ -31,7 +31,7 @@ jobs:
- name: Commit if needed
if: steps.calibre.outputs.markdown != ''
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
message: "Github bot : image compressed"
default_author: github_actions

View File

@@ -109,7 +109,7 @@ jobs:
#TOTAL3="$(awk '{SUM+=$2}END{print SUM}' Stats)"
- name: Commit if needed
uses: EndBug/add-and-commit@v10
uses: EndBug/add-and-commit@v11
with:
default_author: github_actions
message : "Github bot : stats updated"

View File

@@ -161,7 +161,17 @@ the sweep), `ai:plan-pending` (plan posted, awaiting `ai:approved`), `ai:fixed`,
out of the automated tiers but not the manual ones. **Kill switch:** set the
repo variable `AI_DISABLED=true` to pause every AI workflow with no file edits.
AI fixes must never touch `.github/` or `.templates/` (enforced by
`ai_guard_paths.sh`) or the `version`/`upstream` fields in `config.yaml`.
`ai_guard_paths.sh`). They may edit `config.yaml` freely except the upstream
part of `version`, and must never edit `updater.json``addons_updater` owns
both. (There is no `upstream:` key in `config.yaml`; upstream tracking lives in
`updater.json`.) They must still bump the local patch counter so Supervisor
offers the rebuild —
without it the fix ships inert. The counter boundary comes from
`updater.json`'s `upstream_version`, never from the shape of `version`: append
`.1` when the two are equal (the common case — upstream versions here run to
four or five components), increment the trailing digits only when `version` is
`upstream_version` + `.N`, and otherwise leave `version` alone. This rule is
prompt-only, not machine-enforced.
## Linting Rules

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.7 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.0 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

View File

@@ -49,6 +49,7 @@ server {
sub_filter `/asset `%%ingress_entry%%/asset;
sub_filter "'/asset" "'%%ingress_entry%%/asset";
sub_filter \"/asset \"%%ingress_entry%%/asset;
sub_filter \"/auth \"%%ingress_entry%%/auth;
sub_filter window.location.origin} window.location.origin}%%ingress_entry%%;
}
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.2 KiB

After

Width:  |  Height:  |  Size: 1.1 KiB

View File

@@ -49,6 +49,7 @@ server {
sub_filter `/asset `%%ingress_entry%%/asset;
sub_filter "'/asset" "'%%ingress_entry%%/asset";
sub_filter \"/asset \"%%ingress_entry%%/asset;
sub_filter \"/auth \"%%ingress_entry%%/auth;
sub_filter window.location.origin} window.location.origin}%%ingress_entry%%;
}
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

View File

@@ -1,7 +1,7 @@
## 2026.08.15 (15-08-2026)
- Fix: `ALSA_CARD` now really selects the microphone. Its value was copied as-is into `REC_CARD`, but BirdNET-Pi hands `REC_CARD` to `arecord -D` / `ffmpeg -f alsa -i`, which expect an ALSA PCM name: a card index such as `1` gave `Unknown PCM 1` and no recording at all. It is now converted to `plughw:CARD=<value>,DEV=0`, while a value that already is a PCM name (`dsnoop:CARD=Audio,DEV=0`, `default`, `null`, `pulse`, `pipewire`, ...) is used as provided
- Fix: writing `REC_CARD` no longer detaches `birdnet.conf` from `/config`. `sed -i` replaced the `$HOME/BirdNET-Pi/birdnet.conf` symlink with a regular file, so later edits from the WebUI went to a different file than the one the add-on had written; it now edits `/config/birdnet.conf` with `--follow-symlinks`
- Fix: setting `ALSA_CARD` no longer replaces the `~/BirdNET-Pi/birdnet.conf` symlink with a detached copy of `/config/birdnet.conf` (now only `/config/birdnet.conf`, which the symlink points to, is updated)
## 2026.07.10-2 (10-07-2026)
- Minor bugs fixed

View File

@@ -101,6 +101,17 @@ Ensure you have the following installed on your system:
If rtsp feed doesn't work, perhaps you need to add "-rtsp-transport tcp" to your ffmpeg instruction, or allow udp on your network
### Selecting the microphone
By default the container records through PulseAudio (`REC_CARD=default` in `birdnet.conf`). To record directly from a USB microphone instead, find it on the host with `arecord -l`, then pass its card number (or its card id) as `ALSA_CARD`:
```yaml
environment:
- ALSA_CARD=1 # "card 1: Audio [KT USB Audio]" in the output of "arecord -l"
```
At startup this writes `REC_CARD=plughw:CARD=1,DEV=0` into your `birdnet.conf`. A value that already is a full ALSA PCM name, as listed by `arecord -L`, is used as provided - for example `ALSA_CARD=dsnoop:CARD=Audio,DEV=0`, which allows the recording and the livestream services to read the same microphone at the same time.
## Updating to the Latest Version
To check for new versions of the container and update:

View File

@@ -70,8 +70,9 @@ if [ -n "${ALSA_CARD:-}" ]; then
# "ffmpeg -f alsa -i" (scripts/livestream.sh), so it must be an ALSA PCM name.
# ALSA_CARD holds a card index (1) or a card id (Audio), which are not PCM names:
# writing them as-is gives "Unknown PCM 1" and no recording at all. Build a PCM
# name from them, and pass through a value that already is one (plughw:...).
if [[ "$ALSA_CARD" == *:* ]] || [[ "$ALSA_CARD" =~ ^(default|null|pulse|pipewire)$ ]]; then
# name from them, unless the value already is one of ALSA's own PCM names
# (checked against "arecord -L", e.g. default, null, pulse, sysdefault, front...).
if [[ "$ALSA_CARD" == *:* ]] || arecord -L 2> /dev/null | grep -qx "$ALSA_CARD"; then
REC_CARD="$ALSA_CARD"
else
REC_CARD="plughw:CARD=${ALSA_CARD},DEV=0"

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.4 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

View File

@@ -1,3 +1,7 @@
## 2026.08.15 (15-08-2026)
- Fix: `ALSA_CARD` now really selects the microphone. Its value was copied as-is into `REC_CARD`, but BirdNET-Pi hands `REC_CARD` to `arecord -D` / `ffmpeg -f alsa -i`, which expect an ALSA PCM name: a card index such as `1` gave `Unknown PCM 1` and no recording at all. It is now converted to `plughw:CARD=<value>,DEV=0`, while a value that already is a PCM name (`dsnoop:CARD=Audio,DEV=0`, `default`, `null`, `pulse`, `pipewire`, ...) is used as provided
- Fix: setting `ALSA_CARD` no longer replaces the `~/BirdNET-Pi/birdnet.conf` symlink with a detached copy of `/config/birdnet.conf` (now only `/config/birdnet.conf`, which the symlink points to, is updated)
## 2026.08.02 (02-08-2026)
- Fix: ingress returned "502 Bad Gateway" because Caddy never listened on :8082. `91-nginx_ingress.sh` hooked the ingress site into `update_caddyfile.sh` with a sed anchored on `sudo caddy fmt --overwrite`, but 2026.07.10-1 strips `sudo` from every BirdNET-Pi script at build time, so the anchor stopped matching. `update_caddyfile.sh` then rewrote the Caddyfile from scratch just before Caddy started, dropping the ingress site
- Fix: `caddy_ingress.sh` no longer appends a second `:8082` block when it runs twice (a duplicate site address makes Caddy refuse to start)

View File

@@ -101,6 +101,17 @@ Ensure you have the following installed on your system:
If rtsp feed doesn't work, perhaps you need to add "-rtsp-transport tcp" to your ffmpeg instruction, or allow udp on your network
### Selecting the microphone
By default the container records through PulseAudio (`REC_CARD=default` in `birdnet.conf`). To record directly from a USB microphone instead, find it on the host with `arecord -l`, then pass its card number (or its card id) as `ALSA_CARD`:
```yaml
environment:
- ALSA_CARD=1 # "card 1: Audio [KT USB Audio]" in the output of "arecord -l"
```
At startup this writes `REC_CARD=plughw:CARD=1,DEV=0` into your `birdnet.conf`. A value that already is a full ALSA PCM name, as listed by `arecord -L`, is used as provided - for example `ALSA_CARD=dsnoop:CARD=Audio,DEV=0`, which allows the recording and the livestream services to read the same microphone at the same time.
## Updating to the Latest Version
To check for new versions of the container and update:

View File

@@ -116,5 +116,5 @@ tmpfs: true
udev: true
url: https://github.com/alexbelgium/hassio-addons/tree/master/birdnet-pi
usb: true
version: 2026.08.02
version: 2026.08.15
video: true

View File

@@ -66,12 +66,26 @@ fi || true
# Use ALSA CARD defined in add-on options if available
if [ -n "${ALSA_CARD:-}" ]; then
bashio::log.warning "ALSA_CARD is defined, the birdnet.conf is adapt to use device $ALSA_CARD"
for file in "$HOME"/BirdNET-Pi/birdnet.conf /config/birdnet.conf; do
if [ -f "$file" ]; then
sed -i "/^REC_CARD/c\REC_CARD=$ALSA_CARD" "$file"
fi
done
# REC_CARD is passed as-is to "arecord -D" (scripts/birdnet_recording.sh) and to
# "ffmpeg -f alsa -i" (scripts/livestream.sh), so it must be an ALSA PCM name.
# ALSA_CARD holds a card index (1) or a card id (Audio), which are not PCM names:
# writing them as-is gives "Unknown PCM 1" and no recording at all. Build a PCM
# name from them, unless the value already is one of ALSA's own PCM names
# (checked against "arecord -L", e.g. default, null, pulse, sysdefault, front...).
if [[ "$ALSA_CARD" == *:* ]] || arecord -L 2> /dev/null | grep -qx "$ALSA_CARD"; then
REC_CARD="$ALSA_CARD"
else
REC_CARD="plughw:CARD=${ALSA_CARD},DEV=0"
fi
bashio::log.warning "ALSA_CARD is defined, the birdnet.conf is adapted to use device $REC_CARD"
# --follow-symlinks : $HOME/BirdNET-Pi/birdnet.conf is a symlink to /config/birdnet.conf
# (01-structure.sh), and sed -i would replace it with a regular file, detaching it from
# the file the WebUI writes to. Only /config/birdnet.conf is updated directly, since the
# home-path symlink is writable by the pi/caddy user and could be repointed before this
# root-run script gets to it.
if [ -f /config/birdnet.conf ]; then
sed -i --follow-symlinks "/^REC_CARD/c\REC_CARD=$REC_CARD" /config/birdnet.conf
fi
fi
# Define permissions for audio

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.2 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.6 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

View File

@@ -1,4 +1,25 @@
## 07308545.1 (17-08-2026)
- Minor bugs fixed
## 07308543.1 (17-08-2026)
- Fix the "For your security, sign in again" prompt recurring on every restart again. The v1.37
`safeStorage` patch (`86-claude_safestorage.sh` / `claude-safestorage-patch.js`) only knew how
to inject its opt-in after a leading `"use strict"` directive in the app's main bundle, and
refused to patch anything else. Confirmed live on the running add-on (Claude Desktop
1.30096.1): the shipped main bundle (`.vite/build/index.pre.js`) no longer opens with a
`"use strict"` directive at all — it now opens directly with a bare IIFE — so the patcher has
been silently refusing to patch on every boot, `safeStorage.isEncryptionAvailable()` stayed
`false`, and the app's own log kept showing `Encryption not available, returning empty env
vars` exactly as before v1.37. `applyPatch()` now falls back to inserting the opt-in as the
bundle's first real statement when no directive is present, skipping past any leading BOM,
hashbang, or banner comment first so a directive hidden behind a comment is still found and
protected rather than pushed out of position zero. Verified by copying the live production
`app.asar` and running the patcher against it directly: the previously-refused bundle now
patches successfully, the marker lands correctly, a second run reports "Already patched", and
targeted unit tests cover the bare-IIFE, comment-hidden-directive, hashbang, and
unterminated-comment cases.
- One-time step after upgrading, same as v1.37: the previously-stored session is already stale,
so complete one sign-in from a computer; it then persists across restarts.
## 07308545 (2026-08-15)
- Update to latest version from aaddrick/claude-desktop-debian (changelog : https://github.com/aaddrick/claude-desktop-debian/releases)
- Upstream tag : v3.2.2+claude1.30096.1

View File

@@ -13,8 +13,10 @@ streamed desktop.
offline until a fresh sign-in was done from a computer). v1.35 switched to
`--password-store=basic` plus a cont-init script that re-syncs the persistent openbox
`autostart` from the image on every boot — **but that flag alone does nothing**, and the bug
survived it untouched. Actually fixed in v1.37, which adds the application-side opt-in the
`basic` backend requires; see "Why v1.35 did not work" below.
survived it untouched. v1.37 added the application-side opt-in the `basic` backend requires;
see "Why v1.35 did not work" below. That patcher then regressed silently when upstream's
bundle output changed shape — fixed again in 07308543.1; see "Why v1.37 stopped working"
below.
- **Planned only:** Problem A (in-desktop browser for OAuth) is intentionally not implemented.
The image ships no browser; complete the login with the user-side workaround below.
@@ -170,10 +172,40 @@ The third row is the one that matters: it is the restart survival this add-on ne
reaches upgrades, not just fresh installs.
4. `gnome-keyring` stays out of the Dockerfile.
### Why v1.37 stopped working
`claude-safestorage-patch.js` only knew how to inject its opt-in *after* a leading
`"use strict"` directive in the app's main bundle, and refused to patch (leaving the app
unpatched and the session un-persisted) if that directive wasn't there. Confirmed live on the
running add-on: Claude Desktop 1.30096.1's main bundle (`.vite/build/index.pre.js`) no longer
opens with a `"use strict"` directive — it now opens directly with a bare IIFE
(`(function(){try{var e=typeof window...`). Upstream's build output changed shape at some point
after v1.37 shipped, the patcher's one injection point stopped existing, and it had been
silently refusing to patch on every boot since — the app's `main.log` kept showing exactly the
same `Encryption not available, returning empty env vars` warning documented above, and the
session went back to not surviving restarts.
`applyPatch()` now falls back to inserting the opt-in as the bundle's first real statement when
no `"use strict"` directive is found, rather than refusing outright. It skips past any leading
BOM, hashbang, or banner comment first (`skipPrologue()`), so a directive hidden behind a
comment is still found and protected instead of being pushed out of the first-statement
position by a naive prepend — Vite/esbuild banners commonly put a license comment ahead of the
directive. A bundle with no directive at all has nothing to protect, so prepending the opt-in
there is unconditionally safe: the injected code is a complete `try{}catch(e){}` statement, and
a statement can never merge with what follows it via ASI the way a bare expression could.
Verified by copying the live production `app.asar` and running the patcher against it directly
(outside the container's boot sequence): the previously-refused bundle now patches
successfully, the marker lands at the front of the main entry, a second run correctly reports
"Already patched" (idempotent), and unit tests cover the bare-IIFE, comment-hidden-directive,
hashbang, and unterminated-comment cases.
### One-time step after upgrading
The previously-stored session is already stale. Complete **one** sign-in from a computer
(mobile still can't finish the OAuth flow itself, per Problem A) — the session then persists
normally and dispatch stays online regardless of which device connects first afterward.
normally and dispatch stays online regardless of which device connects first afterward. This
applies again after the 07308543.1 fix above, since the affected sessions were never persisted
in the first place.
---
@@ -185,7 +217,10 @@ normally and dispatch stays online regardless of which device connects first aft
- `claude_desktop/rootfs/etc/cont-init.d/86-claude_safestorage.sh` and
`claude_desktop/rootfs/usr/local/bin/claude-safestorage-patch.js` — new in v1.37; the
app-side `safeStorage` opt-in that makes `--password-store=basic` actually take effect.
`claude-safestorage-patch.js` updated again in 07308543.1 to also patch bundles with no
leading `"use strict"` directive, and to look past leading comments/hashbang when deciding
whether one is present.
- `claude_desktop/Dockerfile` — corrected stale comment (gnome-keyring is not installed).
- `claude_desktop/CHANGELOG.md` / `config.yaml` — v1.35, then v1.37.
- `claude_desktop/CHANGELOG.md` / `config.yaml` — v1.35, then v1.37, then 07308543.1.
Problem A (in-desktop browser for OAuth) remains planned-only; not touched by this change.

View File

@@ -136,5 +136,5 @@ schema:
slug: claude_desktop
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "07308545"
version: "07308545.1"
video: true

View File

@@ -128,24 +128,98 @@ function integrityOf(buf, blockSize) {
return { algorithm: 'SHA256', hash: sha256(buf), blockSize, blocks };
}
/* Insert the opt-in after the bundle's leading "use strict" directive. It must go *after* it: a
* directive prologue only takes effect as the very first statement, so prepending would silently
* drop the whole main process out of strict mode.
// Any of the four ECMAScript LineTerminator code points — not just "\n". A //-comment or an ASI
// boundary ends at the first of these, and using a bare "\n" search for that would let a CR- or
// U+2028/U+2029-terminated line swallow real code as "still the comment/still on this line" and
// misplace the insertion point deep inside the bundle instead of before it.
const LINE_TERMINATOR = /[\n\r\u2028\u2029]/;
/* Skip a leading BOM and hashbang line. Only meaningful at byte 0 — called once, before any
* directive scanning. */
function skipBomAndHashbang(source) {
let i = source.charCodeAt(0) === 0xfeff ? 1 : 0; // BOM
if (source.startsWith('#!', i)) {
const m = LINE_TERMINATOR.exec(source.slice(i));
i += m ? m.index + 1 : source.length - i;
}
return i;
}
/* Skip whitespace and comments starting at i. Returns the next index, or -1 for an unterminated
* block comment (caller refuses rather than guesses). */
function skipWhitespaceAndComments(source, i) {
for (;;) {
const rest = source.slice(i);
const ws = /^\s+/.exec(rest);
if (ws) {
i += ws[0].length;
continue;
}
if (rest.startsWith('//')) {
const m = LINE_TERMINATOR.exec(rest);
i += m ? m.index + 1 : rest.length;
continue;
}
if (rest.startsWith('/*')) {
const end = rest.indexOf('*/');
if (end === -1) return -1;
i += end + 2;
continue;
}
return i;
}
}
// A single-line string literal: no raw line terminator in its content (a real one would need an
// escaped line continuation, which this deliberately doesn't special-case — failing to match
// just means the prologue scan below stops there, which is always safe, see applyPatch).
const STRING_LITERAL = /^(['"])(?:\\.|(?!\1)[^\\\n\r\u2028\u2029])*\1/;
/* Scan the bundle's full leading directive prologue: every consecutive ExpressionStatement made
* of nothing but a string literal, per how ECMAScript directives actually work. A directive
* prologue can hold more than one entry, and "use strict" only has to appear *somewhere* in it,
* not first — so this treats every leading directive as needing protection, not just one
* specifically named "use strict". Returns the index right after the full prologue (which is
* also correct as "no prologue, insert here" when there wasn't one), or -1 when a leading string
* literal isn't cleanly terminated as its own statement — ambiguous whether it's a directive at
* all, refused rather than guessed at. */
function scanDirectivePrologue(source, start) {
let i = start;
for (;;) {
const next = skipWhitespaceAndComments(source, i);
if (next === -1) return -1;
const rest = source.slice(next);
const m = STRING_LITERAL.exec(rest);
if (!m) return next; // not a directive; prologue (possibly empty) ends here
const after = rest.slice(m[0].length);
if (after[0] === ';') {
i = next + m[0].length + 1;
} else if (after === '' || LINE_TERMINATOR.test(after[0])) {
i = next + m[0].length;
} else {
return -1; // "use strict" + x and friends: not unambiguously a directive
}
}
}
/* Insert the opt-in right after the bundle's full leading directive prologue (BOM/hashbang, then
* any run of string-literal-only statements — "use strict" among them if present). It must go
* *after* the whole prologue, not just after the first entry: a directive prologue only takes
* effect when its members are the very first statements, so inserting between two of them, or
* ahead of all of them, would silently drop the file out of strict mode just as surely as
* inserting ahead of a lone "use strict" would.
*
* Returns null — meaning "refuse to patch" — for anything that is not unambiguously a directive.
* `"use strict" + x` is an expression, not a directive, and injecting into it would produce a
* syntax error, so the directive is only accepted when it is terminated by its own semicolon, a
* line break, or end of input. */
* When there is no prologue at all (observed from Claude Desktop 1.30096.1 onward, whose main
* entry opens with a bare IIFE instead), there is nothing to preserve: PATCH lands at the same
* position anyway, as the file's first real statement. A `try{}catch(e){}` statement can never
* merge with whatever follows via ASI — unlike a bare expression, a statement is not a valid
* left-hand side for anything a following token could continue — so this is unconditionally
* safe once placed after any banner comment / hashbang / directive prologue. */
function applyPatch(source) {
const m = /^\s*(['"])use strict\1(;?)/.exec(source);
if (!m) return null;
const rest = source.slice(m[0].length);
const terminated = m[2] === ';' || rest === '' || /^[\r\n]/.test(rest);
if (!terminated) return null;
// Supply the terminator when the directive relied on ASI; without it the injected code would
// continue the string-literal expression instead of following it.
const sep = m[2] === ';' ? '' : ';';
return source.slice(0, m[0].length) + sep + PATCH + rest;
const start = skipBomAndHashbang(source);
const end = scanDirectivePrologue(source, start);
if (end === -1) return null;
return source.slice(0, end) + PATCH + source.slice(end);
}
function writeAll(fd, buf) {
@@ -203,7 +277,7 @@ function main() {
const patchedSource = applyPatch(original);
if (patchedSource === null) {
fail(`${mainRel} does not begin with a recognized "use strict" directive; refusing to patch`);
fail(`${mainRel} opens with an ambiguous "use strict"-like string literal; refusing to patch`);
}
const patched = Buffer.from(patchedSource, 'utf8');

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.7 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.7 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.6 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

View File

@@ -1,4 +1,10 @@
## 1.5.1.1 (2026-08-16)
- Expose the web UI on host port 8071, reachable at `<your-ip>:8071`
(redirects to `/filebrowser_quantum/`). Direct access is served by a new,
separate nginx vhost that proxies to the same backend Ingress already uses;
Ingress itself, and the app's own base URL, are unchanged.
## 1.5.1 (2026-08-08)
- Update to latest version from gtsteffaniak/filebrowser (changelog : https://github.com/gtsteffaniak/filebrowser/releases)

View File

@@ -42,11 +42,11 @@ comparison to installing any other Home Assistant add-on.
1. Click the `Save` button to store your configuration.
1. Start the add-on.
1. Check the logs of the add-on to see if everything went well.
1. Access the web UI through the sidebar or at `<your-ip>:8071`.
1. Access the web UI through the sidebar or at `<your-ip>:8071/filebrowser_quantum/`.
## Configuration
The web UI can be found at `<your-ip>:8071` or through the Home Assistant sidebar when using Ingress.
The web UI can be found at `<your-ip>:8071` (redirects to `/filebrowser_quantum/`) or through the Home Assistant sidebar when using Ingress.
**Default credentials:**
- Username: `admin`

View File

@@ -97,6 +97,10 @@ options:
default_user_scope: "/"
panel_admin: false
panel_icon: mdi:file-search
ports:
8072/tcp: 8071
ports_description:
8072/tcp: Web UI port
privileged:
- SYS_ADMIN
- DAC_READ_SEARCH
@@ -114,4 +118,4 @@ schema:
slug: filebrowser_quantum
udev: true
url: https://github.com/alexbelgium/hassio-addons
version: "1.5.1"
version: "1.5.1.1"

View File

@@ -43,6 +43,13 @@ declare ingress_interface
declare ingress_port
#declare keyfile
# The app's own baseURL is always the Supervisor ingress-entry path — this is
# unchanged from before. FileBrowser Quantum has no known "ignore baseURL for
# routing" leniency the way classic filebrowser's app does, so ingress access
# is left completely untouched here. Direct ip:port access is handled below by
# a second, separate nginx vhost (direct.conf) that rewrites a fixed public
# path onto this same ingress-entry baseURL, instead of changing the baseURL
# itself.
FB_BASEURL=$(bashio::addon.ingress_entry)
export FB_BASEURL
@@ -59,6 +66,15 @@ sed -i "s|%%protocol%%|${ADDON_PROTOCOL}|g" /etc/nginx/servers/ingress.conf
sed -i "s|%%port%%|${ingress_port}|g" /etc/nginx/servers/ingress.conf
sed -i "s|%%interface%%|${ingress_interface}|g" /etc/nginx/servers/ingress.conf
sed -i "s|%%subpath%%|${FB_BASEURL}/|g" /etc/nginx/servers/ingress.conf
# --- Direct ip:port access (separate from ingress, see comment above) ---
# Publishes a second nginx vhost on a fixed internal port (published to the
# host as 8071 via config.yaml's `ports:`), at a fixed public path
# (/filebrowser_quantum/), that proxies to the same backend the ingress vhost
# uses. This keeps the app's own baseURL, and therefore ingress, unchanged.
sed -i "s|%%protocol%%|${ADDON_PROTOCOL}|g" /etc/nginx/servers/direct.conf
sed -i "s|%%subpath%%|${FB_BASEURL}/|g" /etc/nginx/servers/direct.conf
mkdir -p /var/log/nginx && touch /var/log/nginx/error.log
############################

View File

@@ -0,0 +1,24 @@
server {
listen 0.0.0.0:8072 default_server;
include /etc/nginx/includes/server_params.conf;
include /etc/nginx/includes/proxy_params.conf;
client_max_body_size 0;
location = / {
return 302 /filebrowser_quantum/;
}
location = /filebrowser_quantum {
return 301 /filebrowser_quantum/;
}
location /filebrowser_quantum/ {
add_header Access-Control-Allow-Origin *;
proxy_connect_timeout 30m;
proxy_send_timeout 30m;
proxy_read_timeout 30m;
proxy_pass %%protocol%%://backend%%subpath%%;
}
}

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.7 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 4.1 KiB

After

Width:  |  Height:  |  Size: 1.8 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.2 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.6 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.0 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.9 KiB

After

Width:  |  Height:  |  Size: 1.4 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.4 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.8 KiB

After

Width:  |  Height:  |  Size: 1.3 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.5 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.1 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 7.9 KiB

After

Width:  |  Height:  |  Size: 2.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 43 KiB

After

Width:  |  Height:  |  Size: 8.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.6 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 3.3 KiB

After

Width:  |  Height:  |  Size: 1.5 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 2.5 KiB

After

Width:  |  Height:  |  Size: 1.2 KiB

Some files were not shown because too many files have changed in this diff Show More