Compare commits

..

13 Commits

Author SHA1 Message Date
MickLesk 34a9032152 romm: add missing /decode and /cache Angie locations for multi-file downloads 2026-08-18 11:17:25 +02:00
community-scripts-pr-app[bot] f0b236ec77 Update CHANGELOG.md (#16579)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 09:27:52 +00:00
CanbiZ (MickLesk) e683dd92e7 patchmon: fetch only SCAP datastream XMLs (#16565)
* patchmon: fetch only SCAP datastream XMLs, not the full 2.1GB content archive

* Increase default disk size from 4GB to 8GB
2026-08-17 11:27:25 +02:00
community-scripts-pr-app[bot] 8490cd606d Update CHANGELOG.md (#16578)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 09:27:02 +00:00
community-scripts-pr-app[bot] 9e6d1c1c71 Update CHANGELOG.md (#16577)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 09:26:38 +00:00
CanbiZ (MickLesk) ee06ad86f1 teslamate: use precompiled Elixir (#16561) 2026-08-17 11:26:34 +02:00
CanbiZ (MickLesk) 7d7db6dd33 keycloak: remove invalid ExecStop, kc.sh has no stop subcommand (#16563) 2026-08-17 11:26:13 +02:00
community-scripts-pr-app[bot] b3531bb0a8 Update CHANGELOG.md (#16576)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 09:23:46 +00:00
community-scripts-pr-app[bot] bdbe5d4043 Update CHANGELOG.md (#16575)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 09:23:21 +00:00
CanbiZ (MickLesk) b559bcef39 Pin ownfoil release to version 2.3.0 (#16574) 2026-08-17 11:23:12 +02:00
CanbiZ (MickLesk) 4ec4bb26ed kometa: add git, needed by requirements.txt's git dependency (#16562) 2026-08-17 11:22:53 +02:00
community-scripts-pr-app[bot] bb7721b199 Update CHANGELOG.md (#16573)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-17 07:23:58 +00:00
Tim Moore 22e2a6d73e fix romm: deploy EmulatorJS and Ruffle after the frontend build (#16571) 2026-08-17 09:23:31 +02:00
13 changed files with 221 additions and 17 deletions
+16
View File
@@ -524,6 +524,22 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-08-17
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- keycloak: remove invalid ExecStop, kc.sh has no stop subcommand [@MickLesk](https://github.com/MickLesk) ([#16563](https://github.com/community-scripts/ProxmoxVE/pull/16563))
- Pin ownfoil release to version 2.3.0 [@MickLesk](https://github.com/MickLesk) ([#16574](https://github.com/community-scripts/ProxmoxVE/pull/16574))
- kometa: add git, needed by requirements.txt's git dependency [@MickLesk](https://github.com/MickLesk) ([#16562](https://github.com/community-scripts/ProxmoxVE/pull/16562))
- fix romm: deploy EmulatorJS and Ruffle after the frontend build [@angusmaul](https://github.com/angusmaul) ([#16571](https://github.com/community-scripts/ProxmoxVE/pull/16571))
- #### 🔧 Refactor
- patchmon: fetch only SCAP datastream XMLs [@MickLesk](https://github.com/MickLesk) ([#16565](https://github.com/community-scripts/ProxmoxVE/pull/16565))
- teslamate: use precompiled Elixir [@MickLesk](https://github.com/MickLesk) ([#16561](https://github.com/community-scripts/ProxmoxVE/pull/16561))
## 2026-08-16
### 🚀 Updated Scripts
+8
View File
@@ -28,6 +28,14 @@ function update_script() {
msg_error "No ${APP} Installation Found!"
exit
fi
if grep -q '^ExecStop=/opt/keycloak/bin/kc.sh stop$' /etc/systemd/system/keycloak.service 2>/dev/null; then
msg_info "Correcting Service"
sed -i '/^ExecStop=\/opt\/keycloak\/bin\/kc.sh stop$/d' /etc/systemd/system/keycloak.service
systemctl daemon-reload
msg_ok "Corrected Service"
fi
if check_for_gh_release "keycloak_app" "keycloak/keycloak"; then
msg_info "Stopping Service"
systemctl stop keycloak
+1
View File
@@ -39,6 +39,7 @@ function update_script() {
cp /opt/kometa/config/config.yml /opt
msg_ok "Backup completed"
ensure_dependencies git
PYTHON_VERSION="3.13" setup_uv
fetch_and_deploy_gh_release "kometa" "Kometa-Team/Kometa" "tarball"
+3 -3
View File
@@ -29,15 +29,15 @@ function update_script() {
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "ownfoil" "a1ex4/ownfoil"; then
RELEASE="2.3.0"
if check_for_gh_release "ownfoil" "a1ex4/ownfoil" "${RELEASE}" "pinned until 2.4.0 (coming soon) is tested, possible Breaking Changes."; then
msg_info "Stopping Service"
systemctl stop ownfoil
msg_ok "Stopped Service"
create_backup /opt/ownfoil/app/config
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "ownfoil" "a1ex4/ownfoil" "tarball"
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "ownfoil" "a1ex4/ownfoil" "tarball" "${RELEASE}"
restore_backup
+9 -1
View File
@@ -76,7 +76,15 @@ EOF
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "PatchMon" "PatchMon/PatchMon" "singlefile" "latest" "/opt/patchmon" "patchmon-server-linux-$(arch_resolve)"
mv /opt/patchmon/PatchMon /opt/patchmon/patchmon-server
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "ssg-content" "ComplianceAsCode/content" "prebuild" "latest" "/opt/patchmon/ssg-content" "scap-security-guide-*.tar.gz"
msg_info "Updating SCAP Content"
RELEASE=$(get_latest_github_release "ComplianceAsCode/content")
curl_with_retry "https://github.com/ComplianceAsCode/content/releases/download/v${RELEASE}/scap-security-guide-${RELEASE}.tar.gz" "/tmp/ssg.tar.gz"
mkdir -p /opt/patchmon/ssg-content
find /opt/patchmon/ssg-content -mindepth 1 -delete
tar -xzf /tmp/ssg.tar.gz -C /opt/patchmon/ssg-content --strip-components=1 --wildcards '*/ssg-*-ds.xml'
rm -f /tmp/ssg.tar.gz
msg_ok "Updated SCAP Content"
restore_backup
+107 -1
View File
@@ -81,7 +81,113 @@ function update_script() {
ln -sfn "$ROMM_BASE"/resources /opt/romm/frontend/dist/assets/romm/resources
ln -sfn "$ROMM_BASE"/assets /opt/romm/frontend/dist/assets/romm/assets
if [[ -f /etc/angie/http.d/romm.conf ]]; then
sed -i "s|alias .*/library/;|alias ${ROMM_BASE}/library/;|" /etc/angie/http.d/romm.conf
if ! grep -q "js_content decode.decodeBase64" /etc/angie/http.d/romm.conf; then
msg_info "Adding missing /decode and /cache locations to Angie config"
dpkg -l angie-module-njs &>/dev/null || $STD apt-get install -y angie-module-njs
grep -q "ngx_http_js_module.so" /etc/angie/angie.conf || sed -i '1i load_module modules/ngx_http_js_module.so;' /etc/angie/angie.conf
mkdir -p /etc/angie/js "${ROMM_BASE}/cache"
cat <<'JSEOF' >/etc/angie/js/decode.js
// Decode a Base64 encoded string received as a query parameter named 'value',
// and return the decoded value in the response body.
function decodeBase64(r) {
var encodedValue = r.args.value;
if (!encodedValue) {
r.return(400, "Missing 'value' query parameter");
return;
}
try {
// Use Buffer to return raw bytes — atob() returns a JS string which r.return()
// would re-encode as UTF-8, corrupting any non-ASCII bytes (e.g. in filenames
// like "Pokémon") and causing CRC mismatches in the mod_zip manifest.
r.return(200, Buffer.from(encodedValue, 'base64'));
} catch (e) {
r.return(400, "Invalid Base64 encoding");
}
}
export default { decodeBase64 };
JSEOF
cat <<EOF >/etc/angie/http.d/romm.conf
js_import /etc/angie/js/decode.js;
upstream romm_backend {
server 127.0.0.1:5000;
}
map \$http_upgrade \$connection_upgrade {
default upgrade;
'' close;
}
server {
listen 80;
server_name _;
root /opt/romm/frontend/dist;
client_max_body_size 0;
location / {
try_files \$uri \$uri/ /index.html;
}
location /assets {
alias /opt/romm/frontend/dist/assets;
try_files \$uri \$uri/ =404;
expires 1y;
add_header Cache-Control "public, immutable";
}
location ~ ^/rom/.*/ejs\$ {
add_header Cross-Origin-Embedder-Policy "require-corp";
add_header Cross-Origin-Opener-Policy "same-origin";
try_files \$uri /index.html;
}
location /api {
proxy_pass http://romm_backend;
proxy_buffering off;
proxy_request_buffering off;
proxy_set_header Host \$host;
proxy_set_header X-Real-IP \$remote_addr;
proxy_set_header X-Forwarded-For \$proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Proto \$scheme;
}
location ~ ^/(ws|netplay) {
proxy_pass http://romm_backend;
proxy_http_version 1.1;
proxy_set_header Upgrade \$http_upgrade;
proxy_set_header Connection \$connection_upgrade;
proxy_set_header Host \$host;
proxy_read_timeout 86400;
}
location = /openapi.json {
proxy_pass http://romm_backend;
}
location /library/ {
internal;
alias ${ROMM_BASE}/library/;
}
location /cache/ {
internal;
alias ${ROMM_BASE}/cache/;
}
location /decode {
internal;
js_content decode.decodeBase64;
}
}
EOF
msg_ok "Added /decode and /cache locations"
else
sed -i -e "s|alias .*/library/;|alias ${ROMM_BASE}/library/;|" \
-e "s|alias .*/cache/;|alias ${ROMM_BASE}/cache/;|" /etc/angie/http.d/romm.conf
fi
systemctl reload angie
elif [[ -f /etc/nginx/sites-available/romm ]]; then
sed -i "s|alias .*/library/;|alias ${ROMM_BASE}/library/;|" /etc/nginx/sites-available/romm
+10
View File
@@ -35,6 +35,16 @@ function update_script() {
systemctl stop teslamate
msg_ok "Stopped Service"
if [[ ! -d /opt/elixir ]]; then
msg_info "Migrating to newer Elixir (required by TeslaMate)"
$STD apt remove -y elixir
fetch_and_deploy_gh_release "elixir" "elixir-lang/elixir" "prebuild" "latest" "/opt/elixir" "elixir-otp-27.zip"
for bin in elixir elixirc iex mix; do
ln -sf "/opt/elixir/bin/$bin" "/usr/local/bin/$bin"
done
msg_ok "Migrated to newer Elixir"
fi
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "teslamate" "teslamate-org/teslamate" "tarball"
msg_info "Building TeslaMate (Patience)"
-1
View File
@@ -39,7 +39,6 @@ Type=idle
User=root
WorkingDirectory=/opt/keycloak
ExecStart=/opt/keycloak/bin/kc.sh start
ExecStop=/opt/keycloak/bin/kc.sh stop
Restart=always
RestartSec=3
Environment="JAVA_HOME=/usr/lib/jvm/temurin-21-jdk-$(arch_resolve)"
+4
View File
@@ -13,6 +13,10 @@ setting_up_container
network_check
update_os
msg_info "Installing Dependencies"
$STD apt install -y git
msg_ok "Installed Dependencies"
PYTHON_VERSION="3.13" setup_uv
fetch_and_deploy_gh_release "kometa" "Kometa-Team/Kometa" "tarball"
+1 -1
View File
@@ -18,7 +18,7 @@ $STD apt install -y git
msg_ok "Installed Dependencies"
setup_uv
fetch_and_deploy_gh_release "ownfoil" "a1ex4/ownfoil" "tarball"
fetch_and_deploy_gh_release "ownfoil" "a1ex4/ownfoil" "tarball" "2.3.0"
msg_info "Setting up Ownfoil"
cd /opt/ownfoil
+7 -1
View File
@@ -86,7 +86,13 @@ for arch in "${AGENT_NAME[@]}"; do
done
msg_ok "Fetched PatchMon agent binaries"
fetch_and_deploy_gh_release "ssg-content" "ComplianceAsCode/content" "prebuild" "latest" "/opt/patchmon/ssg-content" "scap-security-guide-*.tar.gz"
msg_info "Fetching SCAP Content"
RELEASE=$(get_latest_github_release "ComplianceAsCode/content")
curl_with_retry "https://github.com/ComplianceAsCode/content/releases/download/v${RELEASE}/scap-security-guide-${RELEASE}.tar.gz" "/tmp/ssg.tar.gz"
mkdir -p /opt/patchmon/ssg-content
tar -xzf /tmp/ssg.tar.gz -C /opt/patchmon/ssg-content --strip-components=1 --wildcards '*/ssg-*-ds.xml'
rm -f /tmp/ssg.tar.gz
msg_ok "Fetched SCAP Content"
msg_info "Creating service"
cat <<EOF >/etc/systemd/system/patchmon-server.service
+50 -8
View File
@@ -42,16 +42,40 @@ $STD apt install -y \
tzdata
msg_ok "Installed Dependencies"
msg_info "Installing Angie with mod_zip module"
msg_info "Installing Angie with mod_zip and njs modules"
setup_deb822_repo \
"angie" \
"https://angie.software/keys/angie-signing.gpg" \
"https://download.angie.software/angie/debian/$(get_os_info version_id)" \
"$(get_os_info codename)" \
"main"
$STD apt-get install -y angie angie-module-zip
sed -i '1i load_module modules/ngx_http_zip_module.so;' /etc/angie/angie.conf
msg_ok "Installed Angie with mod_zip module"
$STD apt-get install -y angie angie-module-zip angie-module-njs
sed -i '1i load_module modules/ngx_http_zip_module.so;\nload_module modules/ngx_http_js_module.so;' /etc/angie/angie.conf
mkdir -p /etc/angie/js
cat <<'EOF' >/etc/angie/js/decode.js
// Decode a Base64 encoded string received as a query parameter named 'value',
// and return the decoded value in the response body.
function decodeBase64(r) {
var encodedValue = r.args.value;
if (!encodedValue) {
r.return(400, "Missing 'value' query parameter");
return;
}
try {
// Use Buffer to return raw bytes — atob() returns a JS string which r.return()
// would re-encode as UTF-8, corrupting any non-ASCII bytes (e.g. in filenames
// like "Pokémon") and causing CRC mismatches in the mod_zip manifest.
r.return(200, Buffer.from(encodedValue, 'base64'));
} catch (e) {
r.return(400, "Invalid Base64 encoding");
}
}
export default { decodeBase64 };
EOF
msg_ok "Installed Angie with mod_zip and njs modules"
PYTHON_VERSION="3.13" setup_uv
NODE_VERSION="24" setup_nodejs
setup_mariadb
@@ -63,7 +87,8 @@ mkdir -p /opt/romm \
/var/lib/romm/resources \
/var/lib/romm/assets/{saves,states,screenshots} \
/var/lib/romm/library/roms \
/var/lib/romm/library/bios
/var/lib/romm/library/bios \
/var/lib/romm/cache
msg_ok "Created directories"
msg_info "Creating configuration file"
@@ -136,8 +161,6 @@ else
fi
fetch_and_deploy_gh_release "romm" "rommapp/romm" "tarball"
fetch_and_deploy_gh_release "ruffle" "ruffle-rs/ruffle" "prebuild" "latest" "/opt/romm/frontend/dist/assets/ruffle" "ruffle-*-web-selfhosted.zip"
fetch_and_deploy_gh_release "EmulatorJS" "EmulatorJS/EmulatorJS" "prebuild" "v4.2.3" "/opt/romm/frontend/dist/assets/emulatorjs" "4.2.3.7z"
msg_info "Creating environment file"
sed -i 's/^supervised no/supervised systemd/' /etc/redis/redis.conf
@@ -214,8 +237,13 @@ ln -sfn "$ROMM_BASE"/resources /opt/romm/frontend/dist/assets/romm/resources
ln -sfn "$ROMM_BASE"/assets /opt/romm/frontend/dist/assets/romm/assets
msg_ok "Set up RomM Frontend"
fetch_and_deploy_gh_release "ruffle" "ruffle-rs/ruffle" "prebuild" "latest" "/opt/romm/frontend/dist/assets/ruffle" "ruffle-*-web-selfhosted.zip"
fetch_and_deploy_gh_release "EmulatorJS" "EmulatorJS/EmulatorJS" "prebuild" "v4.2.3" "/opt/romm/frontend/dist/assets/emulatorjs" "4.2.3.7z"
msg_info "Configuring Angie"
cat <<'EOF' >/etc/angie/http.d/romm.conf
js_import /etc/angie/js/decode.js;
upstream romm_backend {
server 127.0.0.1:5000;
}
@@ -282,10 +310,24 @@ server {
internal;
alias /var/lib/romm/library/;
}
# Internally redirect cached zip file requests (Range-resumable downloads)
location /cache/ {
internal;
alias /var/lib/romm/cache/;
}
# Internal decoding endpoint, used by mod_zip to decode base64-encoded
# multi-file manifest entries (e.g. the generated .m3u for multi-disc games)
location /decode {
internal;
js_content decode.decodeBase64;
}
}
EOF
sed -i "s|alias /var/lib/romm/library/;|alias ${ROMM_BASE}/library/;|" /etc/angie/http.d/romm.conf
sed -i -e "s|alias /var/lib/romm/library/;|alias ${ROMM_BASE}/library/;|" \
-e "s|alias /var/lib/romm/cache/;|alias ${ROMM_BASE}/cache/;|" /etc/angie/http.d/romm.conf
rm -f /etc/angie/http.d/default.conf
systemctl restart angie
systemctl enable -q --now angie
+5 -1
View File
@@ -19,7 +19,6 @@ $STD apt install -y \
erlang \
erlang-dev \
erlang-syntax-tools \
elixir \
mosquitto \
locales
sed -i 's/^# *\(en_US.UTF-8\)/\1/' /etc/locale.gen
@@ -27,6 +26,11 @@ $STD locale-gen
systemctl enable -q --now mosquitto
msg_ok "Installed Dependencies"
fetch_and_deploy_gh_release "elixir" "elixir-lang/elixir" "prebuild" "latest" "/opt/elixir" "elixir-otp-27.zip"
for bin in elixir elixirc iex mix; do
ln -sf "/opt/elixir/bin/$bin" "/usr/local/bin/$bin"
done
PG_VERSION="17" setup_postgresql
PG_DB_NAME="teslamate" PG_DB_USER="teslamate" PG_DB_GRANT_SUPERUSER="true" setup_postgresql_db
NODE_VERSION="22" setup_nodejs