From 959a86983c502ef841b9f8735704b0902a555e43 Mon Sep 17 00:00:00 2001 From: MickLesk <47820557+MickLesk@users.noreply.github.com> Date: Fri, 25 Sep 2026 14:30:30 +0200 Subject: [PATCH] Build the venv on the distro python and drop the obsolete extractors A uv-managed interpreter lives where the service user cannot execute it, so every archivebox call as that user died with 'Permission denied' while 0.9 drops privileges on import; Debian 13 ships python3.13 in apt, so the venv now points at /usr/bin. 0.9 also provisions single-file and readability itself through abx-dl - the two npm modules no longer exist - and it needs BASE_URL pinned plus tesseract, imagemagick, ffmpeg, unzip and wget present, or archivebox install reaches for apt as a user that has no root. --- ct/archivebox.sh | 28 ++++++++++++++++++---------- install/archivebox-install.sh | 31 +++++++++++++++++++++---------- 2 files changed, 39 insertions(+), 20 deletions(-) diff --git a/ct/archivebox.sh b/ct/archivebox.sh index 969094411..20bc8894c 100644 --- a/ct/archivebox.sh +++ b/ct/archivebox.sh @@ -13,7 +13,7 @@ var_cpu="${var_cpu:-2}" var_ram="${var_ram:-1024}" var_disk="${var_disk:-8}" var_os="${var_os:-debian}" -var_version="${var_version:-12}" +var_version="${var_version:-13}" var_arm64="${var_arm64:-yes}" var_unprivileged="${var_unprivileged:-1}" @@ -31,20 +31,28 @@ function update_script() { exit fi - NODE_VERSION="22" NODE_MODULE="@postlight/parser@latest,single-file-cli@latest" setup_nodejs - export UV_PYTHON_INSTALL_DIR="/opt/archivebox/python" - PYTHON_VERSION="3.13" setup_uv + NODE_VERSION="22" setup_nodejs + setup_uv - ensure_dependencies chromium + ensure_dependencies chromium ripgrep tesseract-ocr tesseract-ocr-eng imagemagick ffmpeg unzip wget msg_info "Stopping Service" systemctl stop archivebox msg_ok "Stopped Service" - # Earlier installs used the system interpreter, which caps ArchiveBox at 0.7.4. + # Earlier installs used python3.11, which caps ArchiveBox at 0.7.4. if [[ ! -x /opt/archivebox/venv/bin/archivebox ]]; then msg_info "Moving ArchiveBox to its own Python 3.13 environment" - $STD uv venv --python 3.13 /opt/archivebox/venv + # The distro interpreter first: a uv-managed one lands where the service user cannot exec it. + local py="/usr/bin/python3.13" + if [[ ! -x "$py" ]]; then + ensure_dependencies python3.13 || true + fi + if [[ ! -x "$py" ]]; then + $STD uv python install --install-dir /opt/archivebox/python 3.13 + py="$(UV_PYTHON_INSTALL_DIR=/opt/archivebox/python uv python find 3.13)" + fi + $STD uv venv --python "$py" /opt/archivebox/venv # Keep whatever port this container already answers on, or a reverse proxy in front # of it would silently stop resolving. local port @@ -69,13 +77,13 @@ EOF fi msg_info "Updating ArchiveBox" - $STD uv pip install --python /opt/archivebox/venv/bin/python --upgrade archivebox playwright - $STD /opt/archivebox/venv/bin/playwright install-deps chromium - chown -R archivebox:archivebox /opt/archivebox/python /opt/archivebox/venv + $STD uv pip install --python /opt/archivebox/venv/bin/python --upgrade archivebox + chown -R archivebox:archivebox /opt/archivebox # Without this a shell still reaches the old 0.7.4 entry point against a 0.9 collection. ln -sf /opt/archivebox/venv/bin/archivebox /usr/local/bin/archivebox cd /opt/archivebox/data $STD sudo -u archivebox /opt/archivebox/venv/bin/archivebox init + $STD sudo -u archivebox /opt/archivebox/venv/bin/archivebox install msg_ok "Updated ArchiveBox" msg_info "Starting Service" diff --git a/install/archivebox-install.sh b/install/archivebox-install.sh index 0be91c585..3a7ccb54d 100644 --- a/install/archivebox-install.sh +++ b/install/archivebox-install.sh @@ -14,29 +14,34 @@ network_check update_os msg_info "Installing Dependencies" +# ArchiveBox resolves these through its env provider, so it never has to reach for apt itself. $STD apt-get install -y \ git \ - libssl-dev \ - libldap2-dev \ - libsasl2-dev \ procps \ dnsutils \ + chromium \ ripgrep \ - chromium + tesseract-ocr \ + tesseract-ocr-eng \ + imagemagick \ + ffmpeg \ + unzip \ + wget \ + python3.13 msg_ok "Installed Dependencies" +# No NODE_MODULE: 0.9 pulls single-file and readability itself, and postlight-parser is gone. NODE_VERSION="22" setup_nodejs -UV_PYTHON_INSTALL_DIR="/opt/archivebox/python" PYTHON_VERSION="3.13" setup_uv +setup_uv msg_info "Installing ArchiveBox" -mkdir -p /opt/archivebox/{data,.npm,.cache,.local} +mkdir -p /opt/archivebox/data $STD adduser --system --shell /bin/bash --gecos 'Archive Box User' --group --disabled-password --home /home/archivebox archivebox -$STD uv venv --python 3.13 /opt/archivebox/venv -$STD uv pip install --python /opt/archivebox/venv/bin/python archivebox playwright -$STD /opt/archivebox/venv/bin/playwright install-deps chromium +# The distro interpreter: a uv-managed one lands where the service user cannot execute it. +$STD uv venv --python /usr/bin/python3.13 /opt/archivebox/venv +$STD uv pip install --python /opt/archivebox/venv/bin/python archivebox ln -sf /opt/archivebox/venv/bin/archivebox /usr/local/bin/archivebox chown -R archivebox:archivebox /opt/archivebox -chmod -R 755 /opt/archivebox/data msg_ok "Installed ArchiveBox" msg_info "Initializing ArchiveBox" @@ -47,8 +52,14 @@ $STD sudo -u archivebox env \ DJANGO_SUPERUSER_EMAIL=admin@archivebox.local \ DJANGO_SUPERUSER_PASSWORD=community-scripts.org \ /opt/archivebox/venv/bin/archivebox manage createsuperuser --noinput +# Without a pinned canonical URL the admin greets every visitor with a red banner. +$STD sudo -u archivebox /opt/archivebox/venv/bin/archivebox config --set "BASE_URL=http://$(get_ip):5797" msg_ok "Initialized ArchiveBox" +msg_info "Installing Extractors" +$STD sudo -u archivebox /opt/archivebox/venv/bin/archivebox install +msg_ok "Installed Extractors" + msg_info "Creating Service" cat </etc/systemd/system/archivebox.service [Unit]