Compare commits

...

17 Commits

Author SHA1 Message Date
MickLesk 3865f855f0 qf 2026-08-05 17:35:32 +02:00
MickLesk 94da6eeb83 qf 2026-08-05 15:00:34 +02:00
MickLesk 078a76f263 Extract reclaim_tty into reusable function
Move the inline TTY reclamation logic from build.func into a standalone reclaim_tty() function in core.func. This improves code reusability, as the function now needs to be called before each interactive prompt (not just after install) since pct exec/pull/enter can take the terminal away again. The function also includes better error handling with checks for perl availability and /dev/tty existence, and explicitly sets SIGTTOU to IGNORE in perl.
2026-08-05 14:57:15 +02:00
community-scripts-pr-app[bot] 58d819b2f4 Update CHANGELOG.md (#16290)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-05 12:04:43 +00:00
CanbiZ (MickLesk) 1c03d0506c NextcloudPI: Bump to Debian Trixie & Tweak broken SSH (#15957)
* Pin NextCloudPi installer to last known-good stable release

The floating "master" branch of nextcloud/nextcloudpi's install.sh
started rejecting our default Debian 12 base with "distro not
supported" (#15944) after a regression landed upstream; the script
is third-party code we don't audit or control. Pin to v1.57.1, the
latest stable (non-prerelease) release, which explicitly targets
Debian bookworm and predates the regression.

* Actually pin the branch nextcloudpi's install.sh clones internally

install.sh is only a thin bootstrapper: it clones BRANCH (default
"master") of the nextcloudpi repo itself and runs the real installer
from that fresh checkout, including the distro-support check. Fetching
install.sh from a pinned tag alone left BRANCH defaulting to "master",
so the internally-cloned code was unaffected and still failed with
"distro not supported" - confirmed by testing the previous fix. Pass
BRANCH explicitly so the internal clone also targets the pinned tag.

* Bump NextCloudPi to Debian 13, matching upstream's trixie move

Upstream's master ncp.cfg now targets release "trixie" (Debian 13);
bookworm (Debian 12) is no longer in the supported check_distro list
at all. Move our own default to Debian 13 and pin the installer ref
to v1.58.0-rc1, the only tagged ref with release=trixie so far (no
stable trixie release exists yet upstream).

* Revert installer pin, track master again

master now targets trixie itself (matches the Debian 13 bump), and
the only tagged trixie ref was an RC explicitly marked "expect bugs".
Tracking master gets upstream trixie fixes as they land instead of
being stuck on a stale test release.

* Work around nextcloudpi's broken ssh.socket restart on Debian 13

Debian 13's openssh-server ships socket-activated by default. NCP's
own bin/ncp/NETWORKING/SSH.sh detects that (systemctl is-active
ssh.socket) but then runs "systemctl restart ssh" in that branch
instead of reloading, which collides with the port ssh.socket already
holds and fails with "Job for ssh.service failed" (#15944). Switch the
container to classic ssh.service before handing off to their
installer so it takes the safe "systemctl reload ssh" branch instead.
2026-08-05 22:04:16 +10:00
community-scripts-pr-app[bot] 27f66a8016 Update CHANGELOG.md (#16285)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 22:27:13 +00:00
CanbiZ (MickLesk) e3e29667c6 Actual Budget: allow native module install scripts under npm 11 (Node 24) (#16277) 2026-08-05 00:26:46 +02:00
community-scripts-pr-app[bot] 3921f03b73 Update CHANGELOG.md (#16284)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 22:26:30 +00:00
CanbiZ (MickLesk) 1336b44a26 Heimdall-Dashboard: run full composer install on update, force production env (#16278) 2026-08-05 00:26:12 +02:00
community-scripts-pr-app[bot] 419f9e397e Update CHANGELOG.md (#16283)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 22:25:59 +00:00
CanbiZ (MickLesk) fcbaedf7d8 xyOps: rebuild xySat satellite during update (#16279) 2026-08-05 00:25:29 +02:00
community-scripts-pr-app[bot] 4eb022fceb Update CHANGELOG.md (#16282)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 22:25:24 +00:00
CanbiZ (MickLesk) 6f4d3b4841 HAOS: remove non-ASCII dash from CPU model dialog text (#16276) 2026-08-05 00:24:56 +02:00
community-scripts-pr-app[bot] a4f893eb7c Update CHANGELOG.md (#16281)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 22:01:31 +00:00
Luke Gustafson 44589819d1 fix: back up Termix db/data so the update stops destroying encryption keys (#16275) 2026-08-05 00:01:02 +02:00
community-scripts-pr-app[bot] 33bfae30e0 Update CHANGELOG.md (#16274)
Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
2026-08-04 21:03:00 +00:00
push-app-to-main[bot] 3fa516f94b Hister (#16259)
* Add hister (ct)

* Update source command in hister.sh

Replace local source with direct curl command for build.func.

* Update ct/hister.sh

* Update install/hister-install.sh

---------

Co-authored-by: push-app-to-main[bot] <203845782+push-app-to-main[bot]@users.noreply.github.com>
Co-authored-by: CanbiZ (MickLesk) <47820557+MickLesk@users.noreply.github.com>
Co-authored-by: Sam Heinz <sam@samheinz.com>
2026-08-04 23:02:28 +02:00
17 changed files with 233 additions and 24 deletions
+12
View File
@@ -518,16 +518,28 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
</details>
## 2026-08-05
### 🚀 Updated Scripts
- NextcloudPI: Bump to Debian Trixie & Tweak broken SSH [@MickLesk](https://github.com/MickLesk) ([#15957](https://github.com/community-scripts/ProxmoxVE/pull/15957))
## 2026-08-04
### 🆕 New Scripts
- Hister ([#16259](https://github.com/community-scripts/ProxmoxVE/pull/16259))
- Obsidian-LiveSync ([#16233](https://github.com/community-scripts/ProxmoxVE/pull/16233))
### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- Actual Budget: allow native module install scripts under npm 11 (Node24) [@MickLesk](https://github.com/MickLesk) ([#16277](https://github.com/community-scripts/ProxmoxVE/pull/16277))
- Heimdall-Dashboard: run full composer install on update, force production env [@MickLesk](https://github.com/MickLesk) ([#16278](https://github.com/community-scripts/ProxmoxVE/pull/16278))
- xyOps: rebuild xySat satellite during update [@MickLesk](https://github.com/MickLesk) ([#16279](https://github.com/community-scripts/ProxmoxVE/pull/16279))
- HAOS: remove non-ASCII dash from CPU model dialog text [@MickLesk](https://github.com/MickLesk) ([#16276](https://github.com/community-scripts/ProxmoxVE/pull/16276))
- fix: back up Termix db/data so the update stops destroying encryption keys [@LukeGus](https://github.com/LukeGus) ([#16275](https://github.com/community-scripts/ProxmoxVE/pull/16275))
- passwordpusher: dynamically read Ruby version from .ruby-version file [@Copilot](https://github.com/Copilot) ([#16242](https://github.com/community-scripts/ProxmoxVE/pull/16242))
- fix(salt): write version cache to ~/.salt, not /~.salt [@TowyTowy](https://github.com/TowyTowy) ([#16265](https://github.com/community-scripts/ProxmoxVE/pull/16265))
- AFFiNE: fix version and build type reported by the app itself [@MickLesk](https://github.com/MickLesk) ([#16251](https://github.com/community-scripts/ProxmoxVE/pull/16251))
+2
View File
@@ -39,7 +39,9 @@ function update_script() {
msg_ok "Stopped Service"
msg_info "Updating Actual Budget to ${RELEASE}"
$STD npm config set allow-scripts=bcrypt,better-sqlite3,argon2 --location=global
$STD npm update -g @actual-app/sync-server
$STD npm rebuild -g
echo "${RELEASE}" >~/.actualbudget
msg_ok "Updated Actual Budget to ${RELEASE}"
+6
View File
@@ -0,0 +1,6 @@
__ ___ __
/ / / (_)____/ /____ _____
/ /_/ / / ___/ __/ _ \/ ___/
/ __ / (__ ) /_/ __/ /
/_/ /_/_/____/\__/\___/_/
+4 -1
View File
@@ -46,8 +46,11 @@ function update_script() {
msg_info "Updating Heimdall-Dashboard"
cd /opt/Heimdall
sed -i 's/^APP_ENV=.*/APP_ENV=production/' .env
rm -f bootstrap/cache/*.php
export COMPOSER_ALLOW_SUPERUSER=1
$STD composer dump-autoload
$STD composer install --no-dev --no-interaction --prefer-dist --optimize-autoloader
$STD php artisan optimize:clear
msg_ok "Updated Heimdall-Dashboard"
msg_info "Restoring Data"
+55
View File
@@ -0,0 +1,55 @@
#!/usr/bin/env bash
source <(curl -fsSL https://raw.githubusercontent.com/community-scripts/ProxmoxVE/main/misc/build.func)
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/asciimoo/hister
APP="Hister"
var_tags="${var_tags:-search;browser-history;personal}"
var_cpu="${var_cpu:-1}"
var_ram="${var_ram:-1024}"
var_disk="${var_disk:-20}"
var_os="${var_os:-debian}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
header_info "$APP"
variables
color
catch_errors
function update_script() {
header_info
check_container_storage
check_container_resources
if [[ ! -f /usr/local/bin/hister ]]; then
msg_error "No ${APP} Installation Found!"
exit
fi
if check_for_gh_release "hister" "asciimoo/hister"; then
msg_info "Stopping Service"
systemctl stop hister
msg_ok "Stopped Service"
fetch_and_deploy_gh_release "hister" "asciimoo/hister" "singlefile" "latest" "/usr/local/bin" "hister_*_linux_$(arch_resolve)"
msg_info "Starting Service"
systemctl start hister
msg_ok "Started Service"
msg_ok "Updated successfully!"
fi
exit
}
start
build_container
description
msg_ok "Completed Successfully!\n"
echo -e "${CREATING}${GN}${APP} setup has been successfully initialized!${CL}"
echo -e "${INFO}${YW}Access it using the following URL:${CL}"
echo -e "${GATEWAY}${BGN}http://${IP}:4433${CL}"
+1 -1
View File
@@ -11,7 +11,7 @@ var_cpu="${var_cpu:-2}"
var_ram="${var_ram:-2048}"
var_disk="${var_disk:-8}"
var_os="${var_os:-debian}"
var_version="${var_version:-12}"
var_version="${var_version:-13}"
var_arm64="${var_arm64:-yes}"
var_unprivileged="${var_unprivileged:-1}"
+37 -9
View File
@@ -112,14 +112,33 @@ EOF
msg_ok "Stopped Termix"
msg_info "Migrating Configuration"
if [[ ! -f /opt/termix/.env ]]; then
mkdir -p /opt/termix/db/data
if [[ -f /opt/termix/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/db.sqlite.encrypted ]]; then
cp -a /opt/termix/data/db.sqlite.encrypted /opt/termix/db/data/db.sqlite.encrypted
[[ -f /opt/termix/data/db.sqlite.encrypted.meta ]] &&
cp -a /opt/termix/data/db.sqlite.encrypted.meta /opt/termix/db/data/db.sqlite.encrypted.meta
[[ -f /opt/termix/data/db.sqlite ]] &&
cp -a /opt/termix/data/db.sqlite /opt/termix/db/data/db.sqlite
fi
if [[ -f /opt/termix/data/.env && ! -f /opt/termix/db/data/.env ]]; then
cp -a /opt/termix/data/.env /opt/termix/db/data/.env
fi
for sub in ssl session_logs session_recordings acme-webroot certbot uploads; do
if [[ -d /opt/termix/data/$sub && ! -d /opt/termix/db/data/$sub ]]; then
cp -a "/opt/termix/data/$sub" "/opt/termix/db/data/$sub"
fi
done
cat <<EOF >/opt/termix/.env
NODE_ENV=production
DATA_DIR=/opt/termix/data
DATA_DIR=/opt/termix/db/data
GUACD_HOST=127.0.0.1
GUACD_PORT=4822
EOF
fi
if ! grep -q "EnvironmentFile" /etc/systemd/system/termix.service 2>/dev/null; then
cat <<EOF >/etc/systemd/system/termix.service
[Unit]
@@ -143,7 +162,11 @@ EOF
fi
msg_ok "Migrated Configuration"
create_backup /opt/termix/data /opt/termix/uploads /opt/termix/.env
create_backup \
/opt/termix/db/data \
/opt/termix/data \
/opt/termix/uploads \
/opt/termix/.env
CLEAN_INSTALL=1 fetch_and_deploy_gh_release "termix" "Termix-SSH/Termix" "tarball"
@@ -158,10 +181,10 @@ EOF
/opt/termix/db/data
msg_ok "Recreated Directories"
if [[ -f /opt/termix/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/db.sqlite.encrypted ]]; then
msg_info "Migrating Database to new layout"
cp -a /opt/termix/data/db.sqlite.encrypted /opt/termix/db/data/db.sqlite.encrypted
msg_ok "Migrated Database to new layout"
if [[ -f /opt/termix/db/data/db.sqlite.encrypted && ! -f /opt/termix/db/data/.env ]]; then
msg_error "Encrypted database restored without its keys (/opt/termix/db/data/.env is missing)"
msg_custom "🛟" "Restore the container from a backup and report this at https://github.com/community-scripts/ProxmoxVE/issues"
exit 1
fi
msg_info "Building Frontend"
@@ -237,7 +260,12 @@ EOF
fi
msg_info "Starting Termix"
systemctl start termix
systemctl daemon-reload
if ! systemctl start termix; then
msg_error "Termix failed to start"
journalctl -u termix -n 30 --no-pager || true
exit 1
fi
msg_ok "Started Termix"
msg_ok "Updated successfully!"
fi
+7
View File
@@ -48,6 +48,13 @@ function update_script() {
chmod 644 /opt/xyops/node_modules/useragent-ng/lib/regexps.js
msg_ok "Rebuilt Application"
fetch_and_deploy_gh_release "xysat" "pixlcore/xysat" "tarball" "latest" "/opt/xyops/satellite"
msg_info "Building xySat Satellite"
cd /opt/xyops/satellite
$STD npm install
msg_ok "Built xySat Satellite"
msg_info "Starting Service"
systemctl start xyops
msg_ok "Started Service"
+1
View File
@@ -51,6 +51,7 @@ cat <<EOF >/opt/actualbudget-data/config.json
EOF
mkdir -p /opt/actualbudget
cd /opt/actualbudget
$STD npm config set allow-scripts=bcrypt,better-sqlite3,argon2 --location=global
$STD npm install --location=global @actual-app/sync-server
echo "${RELEASE}" >~/.actualbudget
msg_ok "Installed Actual Budget"
+1
View File
@@ -24,6 +24,7 @@ fetch_and_deploy_gh_release "Heimdall" "linuxserver/Heimdall" "tarball"
msg_info "Setting up Heimdall-Dashboard"
cd /opt/Heimdall
cp .env.example .env
sed -i 's/^APP_ENV=.*/APP_ENV=production/' .env
$STD php artisan key:generate
msg_ok "Setup Heimdall-Dashboard"
+51
View File
@@ -0,0 +1,51 @@
#!/usr/bin/env bash
# Copyright (c) 2021-2026 community-scripts ORG
# Author: MickLesk (CanbiZ)
# License: MIT | https://github.com/community-scripts/ProxmoxVE/raw/main/LICENSE
# Source: https://github.com/asciimoo/hister
source /dev/stdin <<<"$FUNCTIONS_FILE_PATH"
color
verb_ip6
catch_errors
setting_up_container
network_check
update_os
fetch_and_deploy_gh_release "hister" "asciimoo/hister" "singlefile" "latest" "/usr/local/bin" "hister_*_linux_$(arch_resolve)"
msg_info "Configuring Hister"
mkdir -p /opt/hister/data /etc/hister
LOCAL_IP=$(hostname -I | awk '{print $1}')
cat <<EOF >/etc/hister/config.yaml
app:
directory: '/opt/hister/data'
server:
address: '0.0.0.0:4433'
base_url: 'http://${LOCAL_IP}:4433'
EOF
msg_ok "Configured Hister"
msg_info "Creating Service"
cat <<EOF >/etc/systemd/system/hister.service
[Unit]
Description=Hister Search Engine
After=network.target
[Service]
Type=simple
User=root
ExecStart=/usr/local/bin/hister listen --config /etc/hister/config.yaml
Restart=on-failure
RestartSec=5
[Install]
WantedBy=multi-user.target
EOF
systemctl enable -q --now hister
msg_ok "Created Service"
motd_ssh
customize
cleanup_lxc
+10
View File
@@ -24,6 +24,16 @@ if [[ ! "$CONFIRM" =~ ^([yY][eE][sS]|[yY])$ ]]; then
exit 10
fi
msg_info "Making ssh.service reloads behave like restarts"
mkdir -p /etc/systemd/system/ssh.service.d
cat <<'EOF' >/etc/systemd/system/ssh.service.d/reload-as-restart.conf
[Service]
ExecReload=
ExecReload=/usr/bin/systemd-run --no-block --quiet /bin/systemctl restart ssh.service
EOF
systemctl daemon-reload
msg_ok "Made ssh.service reloads behave like restarts"
msg_info "Installing NextCloudPi (Patience)"
$STD bash <(curl -fsSL https://raw.githubusercontent.com/nextcloud/nextcloudpi/master/install.sh)
msg_ok "Installed NextCloudPi"
+1 -1
View File
@@ -125,7 +125,7 @@ EOF
cat <<EOF >/opt/termix/.env
NODE_ENV=production
DATA_DIR=/opt/termix/data
DATA_DIR=/opt/termix/db/data
GUACD_HOST=127.0.0.1
GUACD_PORT=4822
EOF
+8 -9
View File
@@ -5200,15 +5200,11 @@ EOF
# TSTP = Ctrl+Z, TTIN = bg read from tty, TTOU = bg write to tty (tostop)
trap '' TSTP TTIN TTOU
# lxc-attach takes the controlling terminal while the install runs and does
# not hand it back, leaving us in a background process group. Reading from
# the terminal then returns EIO instead of blocking, because SIGTTIN is
# ignored above - so every recovery prompt fails before the user can answer.
# Redirecting to /dev/tty does not help: the rule applies to the terminal,
# not the file descriptor. Claim the foreground group back; SIGTTOU is
# ignored too, so tcsetpgrp() succeeds instead of stopping us. No-op when we
# already are in the foreground. perl is a hard dependency of Proxmox VE.
perl -e 'use POSIX; open(my $t, "+<", "/dev/tty") or exit 1; POSIX::tcsetpgrp(fileno($t), getpgrp()) or exit 1;' 2>/dev/null || true
# lxc-attach left us in a background process group - claim the terminal back
# before we print anything. Note this does NOT hold: the log collection
# below uses pct pull/exec, which take it away again, so every interactive
# prompt has to reclaim it again right before its read.
reclaim_tty
msg_error "Installation failed in container ${CTID} (exit code: ${install_exit_code})"
@@ -5338,6 +5334,7 @@ EOF
pct enter "$CTID"
echo ""
echo -en "${YW}Container ${CTID} still running. Remove now? (y/N): ${CL}"
reclaim_tty
if read -r response </dev/tty && [[ "$response" =~ ^[Yy]$ ]]; then
pct stop "$CTID" &>/dev/null || true
pct destroy "$CTID" &>/dev/null || true
@@ -5497,6 +5494,7 @@ EOF
local response=""
local read_rc
reclaim_tty
read -t 60 -r response </dev/tty
read_rc=$?
if [[ $read_rc -eq 0 ]]; then
@@ -5761,6 +5759,7 @@ destroy_lxc() {
trap 'echo; msg_error "Aborted by user (SIGINT/SIGQUIT)"; return 130' INT QUIT
local prompt
reclaim_tty
if ! read -rp "Remove this Container? <y/N> " prompt </dev/tty; then
# read returns non-zero on Ctrl-D/ESC
msg_error "Aborted input (Ctrl-D/ESC)"
+33
View File
@@ -1042,6 +1042,39 @@ ensure_tput() {
fi
}
# ------------------------------------------------------------------------------
# reclaim_tty()
#
# - Reclaims the controlling terminal's foreground process group
# - lxc-attach takes the terminal and does not hand it back, leaving us in a
# background process group. Reading from the terminal then returns EIO
# instead of blocking, because SIGTTIN is ignored during recovery - so the
# prompt fails before the user can answer and their keystroke leaks into the
# parent shell. Redirecting to /dev/tty does not help: the rule applies to
# the terminal, not to the file descriptor.
# - pct exec/pull/enter use lxc-attach internally, so the terminal can be taken
# away again at any point. Call this immediately before each interactive
# read, not once after the install.
# - SIGTTOU is ignored inside perl so tcsetpgrp() succeeds instead of stopping
# us. No-op when we already are in the foreground or there is no terminal.
# perl is a hard dependency of Proxmox VE.
# ------------------------------------------------------------------------------
reclaim_tty() {
command -v perl >/dev/null 2>&1 || return 0
[[ -e /dev/tty ]] || return 0
local pgid
pgid=$(ps -o pgid= -p $$ 2>/dev/null | tr -d ' ') || true
perl -e '
use POSIX;
$SIG{TTOU} = "IGNORE";
my $pgid = $ARGV[0] || POSIX::getpgrp();
open(my $t, "+<", "/dev/tty") or exit 1;
POSIX::tcsetpgrp(fileno($t), $pgid) or exit 1;
' "${pgid:-0}" 2>/dev/null || true
}
# ------------------------------------------------------------------------------
# is_alpine()
#
+1
View File
@@ -499,6 +499,7 @@ error_handler() {
local response=""
local read_rc
declare -f reclaim_tty >/dev/null 2>&1 && reclaim_tty
read -t 60 -r response </dev/tty
read_rc=$?
if [[ $read_rc -eq 0 ]]; then
+1 -1
View File
@@ -402,7 +402,7 @@ function advanced_settings() {
fi
if CPU_TYPE1=$(whiptail --backtitle "Proxmox VE Helper Scripts" --title "CPU MODEL" --radiolist "Choose CPU Model" --cancel-button Exit-Script 10 58 2 \
"KVM64" "Default safe for migration/compatibility" ON \
"KVM64" "Default - safe for migration/compatibility" ON \
"Host" "Use host CPU features (faster, no migration)" OFF \
3>&1 1>&2 2>&3); then
case "$CPU_TYPE1" in