Skip to content

Tags: navidrome/navidrome

Tags

v0.64.2

Toggle v0.64.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
test(plugins): stub DNS in the host SSRF guard tests (#6208)

The dial-time SSRF guard runs on the resolved IP, so the tests that prove a
symbolic hostname cannot reach loopback used "localhost." — a trailing dot never
matches /etc/hosts, so Go queries real DNS. Machines whose resolver does not
answer "localhost." (a VPN DNS, for example) got "no such host" before the dial
guard ever ran, failing three specs.

Add tests.StubResolver, a net.Resolver backed by an in-memory DNS responder over
net.Pipe, and let the plugin dialers take a resolver so tests can inject it.
Name resolution in those specs no longer depends on the machine's DNS.

v0.64.1

Toggle v0.64.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(lastfm): report a failure when the artist page has no image (#6198)

GetArtistImages scrapes the og:image tag off the Last.fm artist page, because
the API only ever returns the placeholder image. Last.fm now answers non-browser
clients with a Fastly bot challenge, served as a 200 with valid HTML, so the
query found no og:image and the agent returned an empty list with no error. The
artwork worker read that as a definitive "this artist has no image" and settled
the state as absent, silently and with nothing in the log.

A real artist page always carries an og:image, so its absence now returns an
error instead. The worker keeps the previous state, other agents still get their
turn, and its per-agent circuit breaker bounds the retries. The error is
deliberately not a RetryLaterError: that would park the whole Last.fm agent,
including the API-backed biography, similar-artists and top-songs calls, which
the page block does not affect.

The new fixture is the real 3038-byte challenge page.

Fixes #6192

v0.64.0

Toggle v0.64.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(plugins): document requiredHosts rules and deprecate pdk.NewHTT…

…PRequest (#6129)

* fix(plugins): align the Python HTTP example with the repo's host-call pattern

Bind http_send with raw memory offsets like nowplaying-py does, drop
guards for fields the host always sends, and document how plugins
without a PDK call host services and which built-in HTTP APIs are
disabled.

* docs(plugins): document the private-address rules for HTTP requiredHosts

Explain in the README and manifest schema that named hosts can't reach
private addresses while IP/CIDR entries and a bare "*" can.

* docs(plugins): document the private-address rules for requiredHosts

Explain in the README and manifest schema that named hosts can't reach
private addresses while IP/CIDR entries and a bare "*" can, for both
HTTP and WebSocket. Inline the single-use HTTP isHostAllowed wrapper.

* feat(plugins): derive Default for Rust host service structs

The ndpgen client.rs template now adds Default to the derive list of host
service structs, as the capability and shared types templates already do.
Plugin authors can now set only the fields they need, for example
HTTPRequest { method, url, ..Default::default() }. The webhook-rs and
discord-rich-presence-rs examples use this form now. The golden files and
the generated nd-pdk-host crate are updated to match.

* feat(plugins): deprecate pdk.NewHTTPRequest in the Go PDK

Navidrome no longer enables extism's http_request host function, so a
request built with pdk.NewHTTPRequest always fails. ndpgen now reads a small
deprecation table and writes a Deprecated: paragraph for the listed extism
functions, in both the WASM wrapper and the native stub. Linters and IDEs
now point plugin authors to host.HTTPSend. The PDK example tests used to
teach NewHTTPRequest. They now use host.HTTPSend and host.HTTPMock.

* docs(plugins): correct requiredHosts rules for websocket and private addresses

Two statements in the plugin docs did not match the code.

The WebSocket section claimed requiredHosts behaves like HTTP. It does not:
host_httpclient.go only consults the allowlist when the list is non-empty and
otherwise falls back to allowing public addresses, while host_websocket.go
always calls isHostInAllowlist, so an absent list blocks every connection.

The HTTP section claimed a named host can never reach a private address.
checkPrivateDial scans the whole requiredHosts list, so a named host does
reach a private address when the same list also holds a covering IP or CIDR.

Reworded both, plus the matching requiredHosts descriptions in
manifest-schema.json, and regenerated manifest_gen.go.

v0.63.2

Toggle v0.63.2's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
ci: don't skip release jobs after the DB migration check on tag pushes (

#5760)

* ci: don't skip release jobs after the DB migration check on tag pushes

The validate-migrations job added in #5750 was gated at job level with
if: github.event_name == 'pull_request', so it concluded "skipped" on tag
pushes. GitHub Actions propagates a skipped job transitively through the
needs chain (actions/runner#491): even though Build overrode its own gate
with !cancelled() && !failure() and ran successfully, every job downstream
of Build (msi, release, push-manifest-*, PKG uploads) still failed the
implicit success() check and was skipped, which broke the v0.63.2 release.

Move the pull_request gate from the job to its steps. On non-PR events all
steps are skipped and the job concludes "success", so downstream jobs run
normally. This also restores the default success() gate on Build, keeping
the fail-fast behavior on PRs with a bad migration.

* ci: trim workflow comment

Condense the explanation of the step-level pull_request gate on the
validate-migrations job to the essential rationale.

v0.63.1

Toggle v0.63.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(build): prevent 32-bit startup crash (segfault/SIGILL) in downloa…

…ds binaries (#5739)

* fix(build): force nodynamic webp tag on 32-bit standalone binaries

gen2brain/webp's native libwebp backend links ebitengine/purego, whose
reverse callbacks are unsupported on 32-bit ARM and x86. purego registers
its callback in package init(), so the binary crashes at startup (SIGSEGV
or SIGILL) before any Navidrome code runs.

The nodynamic build tag from #5606 forces the safe WASM path, but it was
only applied to the Docker-image build stage. The standalone build stage,
which produces the downloads-page tarballs and the deb/rpm packages, still
linked purego, so the armv7/v6/v5 and 386 downloads crashed on launch
(#5738, #5735).

Move the tag decision into release/build-tags.sh, shared by both build
stages so they can no longer drift, and add release/verify-binary.sh as a
build-time guard that fails if a 32-bit binary links purego.

* fix(build): harden webp build-tag scripts per review

- verify-binary.sh: fail loudly when the target binary is missing (e.g. an
  unmatched glob) instead of letting `go version -m` fail inside a pipeline
  and silently pass, which would bypass the guard.
- build-tags.sh / verify-binary.sh: fall back to `go env GOARCH` when xx-info
  is unavailable, so the scripts stay correct outside the xx build image.
  (Not `uname -m`, which reports the build host, not the cross target.)
- Dockerfile: use `set -e` in the standalone build block and drop the
  redundant `|| exit 1` suffixes; keep the debug GOENV dump non-fatal.

* chore(build): quote -tags argument in both build stages

Defensive quoting per review; the value comes from release/build-tags.sh and
contains no whitespace today, but quoting prevents word-splitting if it ever does.

* fix(build): link 32-bit arm binaries with LLD to fix startup crash

The standalone armv7/v6/v5 binaries of 0.63.0 crash before main() with
SIGSEGV/SIGILL (issues #5738, #5735). Root cause, established from a core
dump of the crashing binary under qemu: GNU ld emits corrupt
R_ARM_IRELATIVE addends for libatomic's ifunc resolvers (wrong address and
missing Thumb bit) once .text outgrows the 16MB Thumb branch range. glibc's
static-init ifunc resolution then does `blx` into ARM-mode garbage and the
process dies before any log output. v0.62.0 was unaffected only because its
.text was still under 16MB (15.1MB); v0.63.0 crossed the line (17.5MB), so
every 0.63.0 32-bit arm build crashes regardless of Go or dependency
versions.

Link 32-bit arm with LLD (already installed in the build stage), which
emits correct IRELATIVE addends. Verified under qemu: the armv7 artifact
built by the unchanged pipeline now boots to "Navidrome server is ready"
with SQLite migrations working, where the previous binary segfaulted at
startup.

Also add a CI smoke test that runs each cross-compiled linux binary under
binfmt/qemu right after building it, so any future
crashes-at-startup-on-some-arch regression fails the pipeline instead of
shipping in a release.

v0.63.0

Toggle v0.63.0's commit message
chore(deps): update Go dependencies to latest versions

Signed-off-by: Deluan <deluan@navidrome.org>

v0.62.0

Toggle v0.62.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(ui): update Indonesian translations from POEditor (#5575)

Co-authored-by: navidrome-bot <navidrome-bot@navidrome.org>

v0.61.2

Toggle v0.61.2's commit message
fix(ui): add albumGain and trackGain translations in Brazilian Portug…

…uese

Signed-off-by: Deluan <deluan@navidrome.org>

v0.61.1

Toggle v0.61.1's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
fix(ui): update Esperanto, Dutch translations from POEditor (#5301)

Co-authored-by: navidrome-bot <navidrome-bot@navidrome.org>

v0.61.0

Toggle v0.61.0's commit message

Verified

This commit was created on GitHub.com and signed with GitHub’s verified signature.
chore(deps): bump golang.org/x/image from 0.37.0 to 0.38.0 (#5268)

Bumps [golang.org/x/image](https://github.com/golang/image) from 0.37.0 to 0.38.0.
- [Commits](golang/image@v0.37.0...v0.38.0)

---
updated-dependencies:
- dependency-name: golang.org/x/image
  dependency-version: 0.38.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>