Commit Graph
34 Commits
Author SHA1 Message Date
Divarion_D 3b163e3d47 fix(install): add libogg0 to debian13/ubuntu20/ubuntu24 package lists
The bundled ffmpeg/ffprobe 8.0 has a hard NEEDED dependency on
libogg.so.0. The debian13, ubuntu20 and ubuntu24 package lists (in
both the MAIN installer and the LB install flow) omitted libogg0,
so ffmpeg would fail to start with "error while loading shared
libraries: libogg.so.0" on those distributions.

Add libogg0 next to libnuma1 in all three lists, in both
install (PACKAGES) and LbInstallFlow::getPackages(), keeping MAIN
and LB in sync. redhat already ships the equivalent libogg RPM.

Refs: #152
2026-08-15 17:31:05 +03:00
Divarion-D 9857ba99e1 feat(proxy): fetch proxy.tar.gz at panel install (installer hook, mirrors GeoLite)
Add a `cron:proxy --force` step to the installer right after `cron:maxmind --force`
(same "no longer bundled — fetch on install" pattern), run as xc_vm and non-fatal,
so a fresh panel downloads proxy.tar.gz and writes proxy_version.json at install time.
Drop the StartupCommand background prefetch — redundant now that install + the daily
cron:proxy + the ServerInstallCommand self-heal cover every path, matching how
cron:maxmind is wired.
2026-07-08 19:49:10 +03:00
Divarion-D 223aa6830c fix(deploy): keep startup/status as root, fix cache ownership at the source
'console.php status' and 'cron:maxmind' refuse to run as non-root, so the
previous sudo -u xc_vm invocations in the installer and service broke the
post-install steps ('Please run as root'). Revert them: startup/status are
root by design (root crontab, system limits, DB migrations) and startup
already delegates 'cron:cache' to xc_vm.

Fix the actual root-owned-cache leak instead:
- StartupCommand::generateCacheIfNeeded() spawned cron:cache_engine as the
  current user (root at boot/install) — drop to xc_vm via sudo -u.
- FileCache::set() now chowns the written file to xc_vm when running as
  root (same pattern as Logger), covering the remaining root-context
  writers such as 'console.php status'.
2026-07-04 19:04:19 +03:00
Divarion-D 29a2c61de9 fix(deploy): run startup/status console.php as xc_vm, not root
A root-run 'console.php startup' (service boot) and 'status 1'/'startup'/
'cron:maxmind' (installer) created root-owned cache files in tmp/cache that
xc_vm daemons could not overwrite until the next boot chown, producing
'Permission denied' warnings and silently stale caches. Run them all via
sudo -u xc_vm. The CacheCronJob wipe branch loses its sudo accordingly —
xc_vm has no sudoers entry and the tmp tree is xc_vm-owned at that point.
2026-07-04 18:11:57 +03:00
Divarion-D 674e630e05 feat(installer): framed package/user output and single credentials file
- Install apt packages one at a time, each under a printc frame naming the
  package with the raw apt log shown below it (_apt_install_framed); MariaDB
  packages likewise.
- Frame the xc_vm user creation and capture adduser/useradd output so its raw
  "info:" lines don't leak past the frame.
- Write credentials to a single /root/credentials.txt (now incl. Admin Access
  Code); drop the duplicate /opt/xcvm-install copy and the duplicate path print.
2026-07-02 21:28:52 +03:00
Divarion-D ac3d388fab feat(geoip): replace maxminddb PHP extension with pure-PHP Composer package
Switch GeoIP/ISP lookups from the native maxminddb C extension to the
pure-PHP maxmind-db/reader, pulled in via geoip2/geoip2. This removes a
compiled-extension runtime dependency — the panel now works on any stock
PHP 8.1+ without building or installing maxminddb.so.

Dependencies:
- Add geoip2/geoip2 ~3.0 (brings maxmind-db/reader, maxmind/web-service-common)
- Rebuild committed vendor/ with `composer install --no-dev` (production-only)

Code fixes:
- Resolve MaxMind\Db\Reader against the global namespace (leading backslash)
  in namespaced classes — `new MaxMind\Db\Reader(...)` previously resolved to
  a non-existent XcVm\...\MaxMind\Db\Reader and would fatal once the extension
  was gone. Fixed in GeoIPService, ResellerApiDispatcher, admin/api.php view.
- Update GeoIP util docblock to reflect the Composer-based source.

Installer / runtime cleanup:
- bin/php/lib/php.ini: comment out `extension=maxminddb.so`
- install (main installer) and LbInstallFlow: drop libmaxminddb0/-dev,
  libmaxminddb/-devel and the now-unused mmdb-bin from all distro package
  lists (Debian/Ubuntu/RHEL)

Behavior, the raw `->get()` array format and the on-disk GeoIP file cache
are unchanged; legacy libGeoIP packages are left untouched.
2026-06-28 15:12:22 +03:00
Divarion-D a084d69075 fix(install): retry binary download and fail hard when it cannot be installed
The distribution-specific binaries (PHP, nginx, ffmpeg, ...) are mandatory — the
panel will not start without them. Previously install_distribution_binaries()
downloaded them with a single urlretrieve() and no retry, and the caller treated
a failure as a non-fatal warning and continued. A transient DNS/network blip
(e.g. systemd-resolved not ready yet -> "[Errno -5] No address associated with
hostname") therefore left a "successful" install with no binaries.

- Retry the download up to 4 times with a 5s delay on any network/DNS error.
- On supported distros (ubuntu 20/22/24, debian 11/12/13, rhel/rocky/alma 8/9)
  a binary install failure is now FATAL (sys.exit 1) with a clear message,
  instead of a warning + continue.
2026-06-26 18:12:11 +03:00
Divarion-D 8f107c30c9 feat(install): generate a unique self-signed TLS cert per install
The archive ships a placeholder bin/nginx/conf/server.{crt,key}; without this
every installation would run nginx with the SAME private key until certbot issues
a real one. The installer now overwrites the placeholder with a freshly generated
unique RSA-2048 self-signed pair (CN = hostname, 10y) right after extraction and
before nginx is first started, so each server has its own key. CertbotCronJob
still replaces it with a real Let's Encrypt certificate afterwards.

generate_self_signed_cert(): openssl req -x509 -newkey rsa:2048 -nodes; the key is
chowned xc_vm:xc_vm and chmod 640, the cert 644; a generation failure aborts the
install (nginx could not start without a cert anyway).

Follow-ups (out of scope here): rotate the still-shared key on existing installs
via update, and generate on the LoadBalancer install flow.
2026-06-25 21:21:43 +03:00
Divarion-D 16c7053a47 feat(geoip): fetch GeoLite2 (City/Country/ASN) on install and update
GeoLite2-City/Country are no longer bundled in the repo/release archive,
so fetch them (plus ASN) from the XC_VM_Update release:
- getGeolite(): include GeoLite2-ASN.mmdb
- install: run cron:maxmind --force after setup
- UpdateCommand post-update: background GeoLite refresh on MAIN
Reuses the existing MaxMindCronJob mechanism; version.json is updated by it.
2026-06-22 10:35:14 +03:00
Divarion-D 72add936f2 fix(service): improve stop and restart logic for XC_VM processes 2026-06-19 21:58:38 +03:00
Divarion-D 23daad0c50 fix(LbInstallFlow.php): update curl package to libcurl4-gnutls-dev for better compatibility 2026-06-12 15:32:22 +03:00
Divarion-D 1679f16cc2 feat(binaries): implement binary version tracking and update mechanism 2026-05-14 22:05:10 +03:00
Divarion-D 235547168a feat: enhance installation process with dynamic port configuration and database updates 2026-04-21 21:48:10 +03:00
Divarion-D 6dbffd30d9 Refactor configuration and improve error handling
- Updated `install` script to use dynamic thread pool max threads configuration.
- Simplified the check for MariaDB version in `secure_mariadb_installation`.
- Enhanced `generate_mysql_config` function to adjust max connections based on total RAM.
- Improved error handling in `BalancerCommand` for SFTP transfers.
- Refactored `CacheEngineCronJob` to ensure proper handling of cache validity checks.
- Updated `StreamsCronJob` to utilize Redis manager more effectively.
- Enhanced `UsersCronJob` to handle Redis connections safely.
- Refactored `portal.php` to improve handling of series and favorite channels.
- Updated `PortalHandler` to streamline category ID checks.
- Improved `EpgApiController` and `PlaylistApiController` to handle legacy actions more robustly.
- Refactored `StreamRedirector` to enhance server handling logic.
2026-04-21 20:48:05 +03:00
Divarion-D 48039eee67 fix(install): add missing libsodium dep and improve robustness
Root cause of 502: PHP compiled with sodium but libsodium.so.23 not installed.

- Add libsodium23 to all debian/ubuntu package lists
- Add libsodium to redhat package list
- Fix libpng16-dev → libpng-dev for Ubuntu 24.04
- Split apt install into system + MariaDB phases with fallback
- Verify MariaDB installed after package step
- Improve SSH2 library search (t64 suffix on 24.04+)
- Remove unsafe chars from generated root passwords
2026-04-14 18:14:02 +03:00
Divarion-D 52024641fb feat: MD5 hash verification for downloads
- install: compute_md5()+download_release_hash() for XC_VM.zip
- BalancerCommand: MD5 verification for LB binary downloads via SSH
2026-04-13 21:52:20 +03:00
Divarion-D 042706e905 installer: use static redis.conf instead of inline template 2026-04-10 20:22:18 +03:00
Divarion-D a64d59b15c fix(docs): update console paths in documentation and scripts 2026-04-07 20:49:44 +03:00
Divarion-D 07789f7a33 Rename test_installer to install 2026-04-07 19:55:28 +03:00
Divarion-D f0ae4645ac refactor: installer overhaul — remove php-ssh2, GitHub binary downloads, security hardening 2026-04-07 19:48:49 +03:00
Divarion-D a3a86951f0 fix(redis): optimize config, timeouts, reconnect and remove ExecRestart 2026-04-05 22:09:22 +03:00
Divarion-D a113fb3ec9 refactor: remove legacy proxy files, migrate all callers to console.php
- Delete src/status, src/tools, src/crons/epg.php (logic already in CLI commands)
- Update BalancerCommand: fix remote file_exists to SSH test -f, fix stripos check
- Update StartupCommand, UpdateCommand: use PHP_BIN + console.php
- Update dashboard.php: replace hardcoded sudo php with PHP_BIN
- Update install/test_installer: sentinel console.php, exec paths
- Update Makefile: remove status/tools from LB_ROOT_FILES and set_permissions
- Update docs: migration_guide, update-system (EN/RU)
- Update test-install: README.md, auto_install.sh
2026-03-18 20:32:51 +03:00
Divarion-D 038a7de356 feat: Migrate legacy CLI scripts to console.php and extract streaming middleware
CLI consolidation:
- Delete 13 legacy CLI scripts from includes/cli/ (ondemand, proxy, queue, record, scanner, signals, startup, thumbnail, tools, update, watchdog, plex_item, watch_item)
- Convert status and tools entry points to thin proxies that delegate to console.php
- Update all shell_exec() calls across admin controllers, views, and API layer to use console.php command syntax instead of direct CLI file paths
- Update src/service to launch daemons via console.php (signals, watchdog, queue, cache_handler, startup)
- Update Python src/update script to call console.php update instead of includes/cli/update.php
- Update test_installer to use console.php startup

Streaming deduplication:
- Extract StreamAuthMiddleware — common response headers and token decryption shared by live/vod/timeshift
- Extract ShutdownHandler — unified shutdown logic replacing 3 duplicate function shutdown() blocks
- Refactor live.php, vod.php, timeshift.php to use new middleware classes
- Add streaming micro-router to www/stream/index.php as fallback entry point

Routing fixes:
- Fix admin index.php redirect to use relative path (supports access code prefixes)
- Add access code root redirect in public/index.php to prevent broken CSS/JS asset resolution
- Fix init.php for CLI compatibility: guard $_SERVER access, define PHP_ERRORS safely

Migrations:
- 001_update_crontab_filenames.sql — strip .php suffix from crontab filenames
- Fix cache.php view query to match new filename format (cache_engine instead of cache_engine.php)
2026-03-14 23:57:33 +03:00
Eoghan CunninghamandGitHub 747fbb3b1f Modify Redis configuration in install script fix 500 error with v1.2.16
Updated Redis configuration in install script.
2026-02-22 09:44:11 +00:00
Divarion-D 080b5c0496 Added libnuma1 to installer 2026-01-03 19:54:18 +03:00
Divarion-D 7af876a7ce Added automatic memory calculation for mariadb and replaced mysql with mariadb 2025-12-14 22:24:09 +03:00
Divarion-D fafe237dff Update mariadb to 11.4 2025-12-04 22:24:27 +03:00
Divarion-D bcdd9f0c5f Updated documentation and installed support for Ubuntu 20.x. libssl3 is installed for compatibility with PHP. The service startup timeout has been changed. 2025-11-30 20:42:55 +03:00
Divarion-D e5fbe79dca Libraries added to the MAIN and LB installer 2025-10-12 13:05:11 +03:00
Divarion-D 0c4cecde21 Added support for Ubuntu 24 2025-10-08 21:05:10 +03:00
Divarion-D 8b6e13deda Added a change to the panel port during installation. Moved the creation of credentials.txt to the top of the script. 2025-10-03 19:49:43 +03:00
Divarion-D 7dc027e6bd Fixes #15 2025-09-30 18:36:34 +03:00
Divarion-D 21867f2f26 Added missing libraries for ffmpeg and removed obsolete mariadb configurations. 2025-09-14 20:24:55 +03:00
Divarion-D 938e8b0868 init 2025-07-10 20:01:56 +03:00