Compare commits

..

7 Commits

Author SHA1 Message Date
github-actions[bot]
d463ee4275 Update CHANGELOG.md 2026-10-10 05:22:28 +00:00
Austin
c5c107c374 paperclip: honor custom PAPERCLIP_HOME on update (#17825)
The update path chowned a hardcoded /opt/paperclip-data and always moved
root-run services to a dedicated user. Installs that keep their data
elsewhere (for example an NFS bind mount reachable only by root) failed
with "chown: cannot access '/opt/paperclip-data'" after the rebuild, and a
non-root user could not have reached that data anyway.

Read PAPERCLIP_HOME from the install's .env. Keep the service as root when
it points somewhere other than /opt/paperclip-data, and only chown
/opt/paperclip-data when it is the configured data dir and exists.

Co-authored-by: root <root@paperclip.pilz.dev>
Co-authored-by: Claude <noreply@anthropic.com>
2026-10-10 07:22:13 +02:00
community-scripts-pr-app[bot]
8e11d877b9 Update CHANGELOG.md (#17818)
Some checks failed
Create Changelog Pull Request / update-changelog-pull-request (push) Has been cancelled
Set state to is_deleted in pocketbase / delete-pocketbase-entry (push) Has been cancelled
Sync ct/install to Incus / dispatch (push) Has been cancelled
Update script timestamp on .sh changes / update-script-timestamp (push) Has been cancelled
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:27:09 +00:00
community-scripts-pr-app[bot]
623a7a1cf2 Update CHANGELOG.md (#17817)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 19:24:33 +00:00
CanbiZ (MickLesk)
969cc5e9b8 FileBrowser Quantum: migrate the config and database to v2 (#17815)
v2.0.0 reads the config strictly and stops at the v1 keys the addon
wrote (server.port, conditionals, indexingIntervalMinutes). It also only
imports the old BoltDB when server.database.migrateFrom names it and no
database.db is left in the working directory. The update now rewrites
the config, renames the database and points migrateFrom at it, keeping
a copy of the v1 config. New installs write the v2 layout.
2026-10-09 21:24:00 +02:00
community-scripts-pr-app[bot]
14cd4cb667 Update CHANGELOG.md (#17814)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-10-09 18:44:20 +00:00
Sim Kai Long
63cf41174f OpenCloud: allow OpenCloud to embed Collabora on 26.04.4 (#17810)
Collabora 26.04.4 ignores frame-ancestors set in content_security_policy,
so the editor iframe is blocked. Use net.frame_ancestors (as
opencloud-compose does) on install, and add it on update when missing.
2026-10-09 20:43:49 +02:00
7 changed files with 86 additions and 62 deletions

View File

@@ -559,6 +559,14 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-10-10
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- paperclip: keep root and skip /opt/paperclip-data chown when PAPERCLIP_HOME is custom [@austinpilz](https://github.com/austinpilz) ([#17825](https://github.com/community-scripts/ProxmoxVE/pull/17825))
## 2026-10-09
### 🆕 New Scripts
@@ -569,10 +577,24 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08
### 🆕 New Scripts

View File

@@ -31,6 +31,15 @@ function update_script() {
exit
fi
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"

View File

@@ -63,7 +63,13 @@ function update_script() {
# Claude Code refuses --dangerously-skip-permissions as root; migrate existing installs to a dedicated user
PAPERCLIP_USER=$(sed -n 's/^User=//p' /etc/systemd/system/paperclip.service)
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_HOME=$(sed -n 's/^PAPERCLIP_HOME=//p' /opt/paperclip-ai/.env)
PAPERCLIP_HOME="${PAPERCLIP_HOME:-/opt/paperclip-data}"
if [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]] && [[ "$PAPERCLIP_HOME" != "/opt/paperclip-data" ]]; then
# A custom data dir (e.g. an NFS bind mount) may only be reachable by root; don't move the service off root
msg_warn "PAPERCLIP_HOME is ${PAPERCLIP_HOME}; keeping the service user as root"
PAPERCLIP_USER=root
elif [[ -z "$PAPERCLIP_USER" || "$PAPERCLIP_USER" == "root" ]]; then
PAPERCLIP_USER="${var_paperclip_user:-paperclip}"
if [[ "$PAPERCLIP_USER" == "root" || ! "$PAPERCLIP_USER" =~ ^[a-z_][a-z0-9_-]{0,31}$ ]]; then
msg_error "Invalid var_paperclip_user '${PAPERCLIP_USER}' (must be a non-root lowercase Linux username)"
@@ -85,7 +91,10 @@ function update_script() {
fi
PAPERCLIP_USER_HOME=$(getent passwd "$PAPERCLIP_USER" | cut -d: -f6)
chmod 600 /opt/paperclip-ai/.env
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai /opt/paperclip-data "$PAPERCLIP_USER_HOME"
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-ai "$PAPERCLIP_USER_HOME"
if [[ "$PAPERCLIP_HOME" == "/opt/paperclip-data" && -d /opt/paperclip-data ]]; then
chown -R "${PAPERCLIP_USER}:${PAPERCLIP_USER}" /opt/paperclip-data
fi
msg_info "Running Database Migrations"
set -a && source /opt/paperclip-ai/.env && set +a

View File

@@ -157,6 +157,8 @@ function update_script() {
sed -i '$a\PAPERLESS_ARCHIVE_FILE_GENERATION=never' "$PAPERLESS_CONF"
fi
fi
[[ -n "$(sed -n '/^PAPERLESS_CONSUMER_IGNORE_PATTERNS=/p' "$PAPERLESS_CONF")" ]] &&
msg_warn "PAPERLESS_CONSUMER_IGNORE_PATTERNS now uses regex patterns; please verify custom values."
[[ -n "$(sed -n '/^PAPERLESS_PRE_CONSUME_SCRIPT=/p;/^PAPERLESS_POST_CONSUME_SCRIPT=/p' "$PAPERLESS_CONF")" ]] &&
msg_warn "Pre/post consume scripts no longer receive positional arguments in v3; please verify custom scripts."
msg_ok "Migrated Paperless-ngx configuration"
@@ -170,9 +172,7 @@ function update_script() {
fi
for svc in consumer scheduler task-queue webserver; do
unit="/etc/systemd/system/paperless-${svc}.service"
[[ -f "$unit" ]] || continue
sed -i 's|uv run -- |uv run --no-sync -- |g' "$unit"
grep -q '^Restart=' "$unit" || sed -i '/^\[Service\]/a Restart=on-failure\nRestartSec=5' "$unit"
[[ -f "$unit" ]] && sed -i 's|uv run -- |uv run --no-sync -- |g' "$unit"
done
$STD systemctl daemon-reload
cd /opt/paperless
@@ -181,34 +181,6 @@ function update_script() {
$STD uv run -- python manage.py migrate
msg_ok "Updated Paperless-ngx"
if ((BRIDGE_UPDATE == 0)); then
IGNORE_FIXED="$(
/opt/paperless/.venv/bin/python - /opt/paperless/paperless.conf <<'EOF'
import json, re, sys
key = "PAPERLESS_CONSUMER_IGNORE_PATTERNS="
lines = open(sys.argv[1]).read().splitlines(True)
def is_glob(p):
if p.startswith("^") or p.endswith("$"):
return False
try:
return bool(re.search(p, "scan.pdf"))
except re.error:
return True
for i, line in enumerate(lines):
if line.startswith(key):
patterns = json.loads(line[len(key):].strip().strip("'"))
fixed = ["^" + re.escape(p).replace(r"\*", ".*").replace(r"\?", ".") + "$" if is_glob(p) else p for p in patterns]
if fixed != patterns:
lines[i] = key + json.dumps(fixed) + "\n"
print(json.dumps(fixed))
open(sys.argv[1], "w").writelines(lines)
EOF
)" || IGNORE_FIXED=""
[[ -n "$IGNORE_FIXED" ]] && msg_warn "Converted glob PAPERLESS_CONSUMER_IGNORE_PATTERNS to regex (required since v3): ${IGNORE_FIXED}"
fi
if ((BRIDGE_UPDATE == 0)) && [[ "$PAPERLESS_INSTALLED_VERSION" == "2.20.15" ]]; then
$STD apt -y purge libzbar0t64 libzbar0 2>/dev/null || true
$STD apt -y autoremove 2>/dev/null || true

View File

@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true
sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}"
useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no

View File

@@ -109,8 +109,6 @@ Requires=redis.service
[Service]
WorkingDirectory=/opt/paperless/src
ExecStart=uv run --no-sync -- celery --app paperless beat --loglevel INFO
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
@@ -125,8 +123,6 @@ After=postgresql.service
[Service]
WorkingDirectory=/opt/paperless/src
ExecStart=uv run --no-sync -- celery --app paperless worker --loglevel INFO
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
@@ -141,8 +137,6 @@ Requires=redis.service
WorkingDirectory=/opt/paperless/src
ExecStartPre=/bin/sleep 2
ExecStart=uv run --no-sync -- python manage.py document_consumer
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
@@ -159,8 +153,6 @@ Requires=redis.service
WorkingDirectory=/opt/paperless/src
#ExecStartPre=uv run --no-sync -- python manage.py document_index reindex --if-needed --no-progress-bar
ExecStart=uv run --no-sync -- granian --interface asginl --ws --loop uvloop "paperless.asgi:application"
Restart=on-failure
RestartSec=5
Environment=GRANIAN_HOST=::
Environment=GRANIAN_PORT=8000
Environment=GRANIAN_WORKERS=1

View File

@@ -96,6 +96,27 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
fi
fi
# v2 rejects v1 config keys and imports the BoltDB on its first start
migrate_v1_config() {
local dir="/usr/local/community-scripts" db=0
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
((db)) && mv "$dir/database.db" "$dir/database.db.old"
awk -v db="$db" '
{ match($0, /^ */); ind = RLENGTH }
/^[^ #]/ { top = $1 }
cond && ind > ci { print substr($0, 3); next }
{ cond = 0 }
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
/^[[:space:]]*indexingIntervalMinutes:/ { next }
top == "server:" && /^ port:/ { port = $2; next }
{ print }
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
END { if (port != "") { print "http:"; print " port: " port } }
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
}
# Existing installation
if [[ -f "$INSTALL_PATH" ]]; then
msg_warn "${APP} is already installed."
@@ -126,6 +147,7 @@ if [[ -f "$INSTALL_PATH" ]]; then
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
if [[ -f "$CONFIG_PATH" ]]; then
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
migrate_v1_config
fi
if [[ "$OS" == "Debian" ]]; then
systemctl restart filebrowser.service
@@ -173,22 +195,21 @@ read -r noauth_prompt
# === YAML CONFIG GENERATION ===
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
methods:
noauth: true
@@ -196,22 +217,21 @@ EOF
msg_ok "Configured with no authentication"
else
cat <<EOF >"$CONFIG_PATH"
server:
http:
port: $PORT
server:
sources:
- path: "$SRC_DIR"
name: "RootFS"
config:
denyByDefault: false
indexingIntervalMinutes: 240
conditionals:
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
rules:
- neverWatchPath: "/proc"
- neverWatchPath: "/sys"
- neverWatchPath: "/dev"
- neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth:
adminUsername: admin
adminPassword: community-scripts.org