diff --git a/.gitignore b/.gitignore index 415c2b0..84f3020 100644 --- a/.gitignore +++ b/.gitignore @@ -1,4 +1,5 @@ .DS_Store __pycache__/ *.pyc +.pytest_cache/ .validation-output/ diff --git a/CHANGELOG.md b/CHANGELOG.md index fb2857b..283bc40 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,14 @@ ## Unreleased — targeting v0.1.0 +- Added a `Changes` field to the template so Community Apps shows a changelog + to users who already installed the app. +- Project status now lives in one place, the top of `docs/RELEASE-REVIEW.md`. + Other documents link to it. Removed internal review narrative and stale test + and file counts from the public documentation. +- The publication inventory test now reads Git's file list, so `pytest` caches + and other ignored files no longer fail it. Tests check document structure and + links rather than exact status sentences. - Added a PNG export of the existing community artwork and switched template/profile icon URLs to PNG for Docker Manager compatibility. Original SVG preserved. - Changed the default host WebUI/API port to `6969` for CPU, CUDA 12 and CUDA 13 @@ -38,8 +46,8 @@ - Prepared least-privilege, commit-pinned GitHub Actions CI, Dependabot action updates, contribution/security guidance and a standalone Git publishing checklist. - September 13: published the approved GitHub review draft with a clean signed - history and noreply commit identity. First hosted CI passed all 25 checks; - public links/file hashes and recorded repository security settings verified. + history and noreply commit identity. First hosted CI passed. Public links, + file hashes and recorded repository security settings verified. No public versioned release has been made; the GitHub repository is a review draft. Version numbers describe the Unraid integration, diff --git a/SECURITY.md b/SECURITY.md index 776c165..bb57a9a 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -1,7 +1,7 @@ # Security This integration is beta, with no versioned stable release yet. Once released, -maintenance will focus on the current integration template; it does not provide +maintenance will focus on the current integration template. It does not provide security maintenance for upstream images, dependencies, models or Unraid itself. The application port exposes unauthenticated UI/API management. Keep it on trusted @@ -11,11 +11,8 @@ and GPU access are described in the [README](README.md#security). Do not post credentials, private audio or exploitable vulnerability details in public issues. Use the repository's **Security → Advisories → Report a vulnerability** option for sensitive integration -reports. Private vulnerability reporting was enabled and verified through -GitHub's API on September 13, 2026; the advisories page is live. See the -[publication checklist](docs/PUBLISHING.md). -If it is unavailable, request a private reporting channel in a public issue +reports. If it is unavailable, request a private reporting channel in a public issue without including sensitive details. Follow upstream's own reporting policy for -vulnerabilities in audio.cpp; do not assume this integration can fix them. +vulnerabilities in audio.cpp. Do not assume this integration can fix them. No response-time guarantee or independent security certification is offered. diff --git a/docs/MAINTAINER.md b/docs/MAINTAINER.md index dd53147..fd04399 100644 --- a/docs/MAINTAINER.md +++ b/docs/MAINTAINER.md @@ -7,23 +7,19 @@ status tracker; detailed experiment reports remain in this docs directory. ## Validation and submission context -**Status: beta integration, targeting v0.1.0; full deployment acceptance pending.** -CPU, CUDA 12 and CUDA 13 have passed isolated Pocket TTS testing on one Unraid -host. Native Docker `--user=99:100` resolved the initial model-folder permission -failure. The [September 12 CPU retest](CPU-RETEST-20260912.md) passed short-text, -streaming and restart checks using a fixed official image; the owner also confirmed -playback. Controlled CUDA 13 recreation, image update and rollback passed within -their documented scope. These are not full Community Apps release acceptance. -See the [current release review](RELEASE-REVIEW.md) for completed checks, -remaining gates and the exact proposed repository contents. -The selected repository destination is `lozenge0/audio-cpp-unraid`, with GitHub -Issues as the integration support destination. The owner reports completing the -Community Apps submission and receiving automatic approval. Catalog visibility -and installation through the public listing are not yet verified. Portal approval -does not establish runtime compatibility. See the release review for current status. - -The template requests both **AI** and **Tools** categories. Catalog placement -depends on CA processing the updated template; it has not yet been confirmed live. +The current submission state, completed evidence and remaining gates live in +[the release review](RELEASE-REVIEW.md). Do not repeat that status here. + +CPU, CUDA 12 and CUDA 13 passed isolated Pocket TTS testing on one +Unraid host. Native Docker `--user=99:100` resolved the initial model-folder +permission failure. The [September 12 CPU retest](CPU-RETEST-20260912.md) passed +short-text, streaming and restart checks on a fixed official image. Controlled +CUDA 13 recreation, image update and rollback passed within their documented +scope. These are not full Community Apps release acceptance, and portal approval +does not establish runtime compatibility. + +The repository is `lozenge0/audio-cpp-unraid`, with GitHub Issues for support. +The template requests both **AI** and **Tools** categories. ## Scope and layout @@ -63,17 +59,20 @@ Follow [the release review](RELEASE-REVIEW.md) and The GitHub Actions workflow runs these tests on pushes, pull requests and manual dispatch, with no custom secrets, image builds or server access. Dependabot proposes CI action updates for review, not container updates. -The [first hosted run](https://github.com/lozenge0/audio-cpp-unraid/actions/runs/34725657862) -passed all 25 checks. See [contribution guidance](../CONTRIBUTING.md) and +See [contribution guidance](../CONTRIBUTING.md) and [security reporting](../SECURITY.md). -The public repository and hosted CI are verified, and the owner reports CA -auto-approval. Next verify catalog visibility and the public branch-selection/install -flow, review tested images and complete or explicitly defer outstanding lifecycle +Next verify catalog visibility and the public branch-selection/install flow, +review tested images and complete or explicitly defer outstanding lifecycle checks. Rerun CA Validate/Scan after meaningful XML changes. Follow the [GitHub publishing checklist](PUBLISHING.md). Never publish the surrounding audio.cpp checkout. Portal approval is not full deployment acceptance. +When a template change affects installed users, add a dated entry to the +`Changes` field in `templates/audio-cpp.xml`. Community Apps shows that field +as the app changelog. Docker Manager does not refresh installed templates, so +the entry must say what an existing user needs to change by hand. + ## Primary references - [Upstream Docker guide](https://github.com/0xShug0/audio.cpp/blob/main/docs/docker.md) @@ -93,5 +92,4 @@ and tests, not upstream software, third-party dependencies or model weights. The icon is separately dedicated under CC0 1.0 Universal, to the extent the owner holds applicable rights; see [artwork provenance and terms](../assets/README.md). The owner approved these choices and subsequent GitHub draft publication on -2026-09-12. The owner subsequently completed the CA submission and reported -auto-approval. No versioned integration release has been created. +2026-09-12. diff --git a/docs/PLAN.md b/docs/PLAN.md index 5f6abb5..3c5146c 100644 --- a/docs/PLAN.md +++ b/docs/PLAN.md @@ -18,10 +18,9 @@ ## Current publication status -The standalone GitHub repository and CI are live. The owner reports CA submission -and auto-approval; catalog visibility and public installation remain unverified. -The beta template requests AI and Tools categories. See RELEASE-REVIEW.md for the -current evidence and remaining checks. No production migration has been performed. +See the status section at the top of [the release review](RELEASE-REVIEW.md). +That file is the single source for submission state, evidence and remaining +checks. No production migration took place. ## Runtime progress recorded on 2026-09-12 @@ -76,8 +75,8 @@ passed; actual CA rendering and full deployment acceptance remain pending. ## Stage 4 — Community Apps submission -The owner reports automatic approval. Confirm catalog visibility and review -Validate/Scan results; rerun those checks after meaningful XML changes. Do not +Confirm catalog visibility and review Validate/Scan results. Rerun those checks +after meaningful XML changes. Do not create a duplicate submission because the listing is not yet visible. Preserve tested-combination limits, maintenance/support boundaries and rollback guidance. diff --git a/docs/PUBLISHING.md b/docs/PUBLISHING.md index 0b346f7..360ddf5 100644 --- a/docs/PUBLISHING.md +++ b/docs/PUBLISHING.md @@ -33,10 +33,9 @@ Approved initialization procedure: do not overwrite an existing repository or auto-add competing licence/README files. Verify the remote before pushing `main`. Do not force-push. -The draft was published on September 13 (Europe/London); publication checks are -recorded in RELEASE-REVIEW.md. The owner subsequently reported CA auto-approval. -Keep the beta label and outstanding validation limits visible. No versioned -integration release has been created; catalog visibility still needs confirmation. +The draft was published on September 13 (Europe/London). Publication checks and +the current project status are recorded in [the release review](RELEASE-REVIEW.md). +Keep the beta label and outstanding validation limits visible. ## CI and repository settings diff --git a/docs/RELEASE-REVIEW.md b/docs/RELEASE-REVIEW.md index bbf40fe..80a7d49 100644 --- a/docs/RELEASE-REVIEW.md +++ b/docs/RELEASE-REVIEW.md @@ -1,16 +1,24 @@ -# Release review — beta integration +# Release review + +## Status Updated 2026-09-13 (Europe/London). Target: **audio.cpp for Unraid v0.1.0**. -The public repository is published. The owner reports completing CA submission -and receiving automatic approval; catalog visibility and public installation are -not yet verified. No versioned integration release has been created. This is the -current tracker; dated test reports preserve what was known during each experiment. +This section is the single source for project status. Other documents link +here instead of repeating it. + +- The public repository `lozenge0/audio-cpp-unraid` is live with CI. +- The owner completed the Community Apps submission and reported automatic + approval. Catalog visibility and installation through the public listing are + not yet verified. +- No versioned integration release or tag exists. +- Beta status applies to every variant. Runtime evidence covers one host. + +Dated test reports in this folder preserve what was known during each experiment. ## Proposed repository -- Owner/repository: `lozenge0/audio-cpp-unraid`; default branch: `main`. -- Support: repository GitHub Issues. Repository/Issues/advisories pages returned - HTTP 200; public README/template/profile/icon bytes match the local files. +- Owner/repository: `lozenge0/audio-cpp-unraid`. Default branch: `main`. +- Support: repository GitHub Issues. - Contents: Unraid template/profile, community artwork, documentation and local maintainer tests and CI only. No application code, custom image, runtime wrapper, preset model/configuration, personal voice or image-publishing workflow. @@ -18,49 +26,47 @@ current tracker; dated test reports preserve what was known during each experime digests does not validate every future image published to those tags. - Scope: CPU, CUDA 12 and CUDA 13. Runtime evidence is one Unraid 7.3.2 host, Ryzen 7 3700X / RTX 3060 12 GB, using Pocket TTS GGUF Q8. +- Categories: the template requests `AI` and `Tools:`. Both identifiers are in + the public [CA category list](https://github.com/Squidly271/AppFeed/blob/master/categoryList.json). - Licence: owner approved root MIT for integration files and CC0 1.0 for the icon - on 2026-09-12. The artwork dedication applies only to rights the owner holds; - see [artwork terms](../assets/README.md). Subsequent GitHub draft publication is - approved. The owner subsequently completed CA submission and reported auto-approval. + on 2026-09-12. The artwork dedication applies only to rights the owner holds. + See [artwork terms](../assets/README.md). ## Completed evidence | Area | Supported conclusion | Evidence | | --- | --- | --- | -| Template | Three complete configurations; upstream-only launch and native identity controls | `tests/test_template.py` | +| Template | Three complete configurations. Upstream-only launch and native identity controls | `tests/test_template.py` | | Fresh storage | Native downloads work as 99:100 without ownership-changing helpers | [Identity tests](USER-IDENTITY-TESTS.md) | -| Private CA install | Owner installed pre-expanded CPU/CUDA 12/CUDA 13 entries; not the public selector | [UI evidence](VALIDATION.md) | -| CPU regression | Fixed revision `5bea9c7` passes short/long offline, Studio, streaming and restart tests; owner playback confirmed | [CPU retest](CPU-RETEST-20260912.md) | +| Private CA install | Owner installed pre-expanded CPU/CUDA 12/CUDA 13 entries, not the public selector | [UI evidence](VALIDATION.md) | +| CPU regression | Fixed revision `5bea9c7` passes short/long offline, Studio, streaming and restart tests. Owner playback confirmed | [CPU retest](CPU-RETEST-20260912.md) | | CUDA inference | Both variants initialized/computed with CUDA and passed API/Studio tests | [Validation](VALIDATION.md) | -| Restart/model reuse | Files persist; clients explicitly re-register models when required | [Identity tests](USER-IDENTITY-TESTS.md) | +| Restart/model reuse | Files persist. Some clients must re-register models after a restart | [Identity tests](USER-IDENTITY-TESTS.md) | | Same-image recreation | Controlled CUDA 13 recreation preserves settings and model data | [Recreation](RECREATION-TEST.md) | -| Update/rollback | Controlled CUDA 13 upgrade and restoration of retained old container passed; not the full DockerMan/scheduler path | [Update/rollback](UPDATE-ROLLBACK-TEST.md) | +| Update/rollback | Controlled CUDA 13 upgrade and restoration of retained old container passed. Not the full DockerMan/scheduler path | [Update/rollback](UPDATE-ROLLBACK-TEST.md) | The old CPU image's `hello` crash remains a historical failure. The owner confirmed -the fixed test was "working well" after automated checks; this is listening +the fixed test was "working well" after automated checks. This is listening confirmation for their sample, not every saved WAV. ## Remaining gates and decisions -Before publishing any repository contents: - -- [x] Owner approves the root integration licence (MIT, 2026-09-12). -- [x] Owner approves icon reuse terms (CC0 1.0, 2026-09-12). -- [x] Owner chooses to review the draft on GitHub before beta approval; final beta - file approval happens after that review. -- [x] Review preserved artwork metadata and render locally at 32/48/180 px on - white/dark backgrounds. Metadata remains intact; authenticity is not certified. -- [x] Complete independent template, publication-safety and GitHub/CI design - reviews on September 12. These supersede the earlier usage-limited attempt. - Findings and follow-up verification are recorded below. -- [x] Owner explicitly approves clean standalone initialization and public - repository creation/push on September 12. No surrounding checkout/history. -- [x] Verify the initial public push, hosted CI and repository security settings - listed in the publication record below. - -Post-submission verification and remaining deployment gates: - -- [x] Owner reviewed the GitHub files, completed submission and reported auto-approval. +Completed before publication: + +- [x] Owner approved the root integration licence (MIT, 2026-09-12). +- [x] Owner approved icon reuse terms (CC0 1.0, 2026-09-12). +- [x] Owner reviewed the draft on GitHub before beta approval. +- [x] Artwork metadata preserved. Icon rendered locally at 32/48/180 px on + white and dark backgrounds. Authenticity is not certified. +- [x] Template, publication-safety and CI reviews completed on September 12. +- [x] Clean standalone repository created and pushed on September 12 with no + surrounding checkout or history. +- [x] Initial public push, hosted CI and repository security settings verified. +- [x] Owner completed the CA submission and reported automatic approval. +- [x] GitHub Issues and README/template/raw icon links verified after publication. + +Still open: + - [ ] Independently verify catalog visibility and the accepted template contents. - [ ] Validate documented optional JSON under UID 99:100, stable model IDs across restart and CLI precedence, or clearly defer that recipe. @@ -68,31 +74,31 @@ Post-submission verification and remaining deployment gates: instructions. Controlled Engine recreation/rollback is narrower evidence. - [ ] Review scheduled updates safely or explicitly leave unattended updates unvalidated. Never invoke a host-wide updater to test one container. -- [x] Verify GitHub Issues and README/template/raw icon links after approved publication. - [ ] Validate public CA branch selection and installation fields using a supported - preview/feed workflow; private pre-expanded entries cannot prove this. + preview/feed workflow. Private pre-expanded entries cannot prove this. - [ ] Review portal Validate/Scan results and rerun after meaningful XML changes. Owner-reported auto-approval does not prove every runtime acceptance check passed. -- [ ] Recheck moving tags before release; update the tested-image record or disclose +- [ ] Recheck moving tags before release. Update the tested-image record or disclose newer untested images. Do not label a moving tag permanently verified. +- [ ] Tag `v0.1.0` once the app is visible in the public catalog. Failure/retry recovery, optional residency/resource controls, other models, GPUs -and Unraid versions are not covered exhaustively. Test or narrow relevant claims; -do not mark the entire acceptance protocol complete from one model installation. +and Unraid versions are not covered exhaustively. Test or narrow relevant claims. +Do not mark the entire acceptance protocol complete from one model installation. -Vulkan is a future scope decision, not an upstream-image availability blocker: -the [reviewed upstream workflow](https://github.com/0xShug0/audio.cpp/blob/5bea9c726881f6a7ce3e9adf18c060b5a6a8eb8e/.github/workflows/docker.yml) +Vulkan is a future scope decision, not an upstream-image availability blocker. +The [reviewed upstream workflow](https://github.com/0xShug0/audio.cpp/blob/5bea9c726881f6a7ce3e9adf18c060b5a6a8eb8e/.github/workflows/docker.yml) includes it. No Vulkan branch, AMD/Intel compatibility claim or new deployment is authorized here. CPU/CUDA can remain the first release scope. The sequence follows [CA submission guidance](https://ca.unraid.net/submit/help): public active repository, OSI-approved root licence, profile/template metadata, -then Validate/Scan. Local preparation does not authorize these external steps. +then Validate/Scan. ## Exact proposed file list -Only these relative paths belong in the future repository after approval. -Local publication tests enforce this list, excluding ignored Python caches. +Only these relative paths belong in the repository. The publication tests +enforce this list from Git's file inventory, so ignored caches do not count. ```text .github/dependabot.yml @@ -129,87 +135,37 @@ tests/test_template.py Never include the parent checkout/history, `speak.sh`, `.devops/unraid`, SSH/API credentials, test harnesses, raw Docker inspections, WAVs/screenshots, downloaded models, personal configuration or original icon pack. Reports here contain selected -technical evidence; raw artifacts stay outside this folder. +technical evidence. Raw artifacts stay outside this folder. ## Local review procedure -Run `python3 -m unittest discover -s tests -v` from this directory. Checks cover -structure, explicit file inventory, relative documentation links and selected -accidental-data patterns. They are not a complete secret scanner, legal clearance, -CA validation or proof of current upstream compatibility. The same tests are -used by read-only GitHub Actions CI; the first hosted run passed all 25 tests. -No image build, custom CI credentials or server access is required. - -The September 12 licence update passed the then-current 21 checks. The subsequent -three independent reviews found no template launch or publication-safety blocker -for a clearly labelled GitHub draft. Corrections remove a host-specific GPU ID -prefix from a negative test fixture, label optional JSON guidance unvalidated, -distinguish the CPU image/config ID from pullable digests, and separate GitHub -review publication from CA release. The inventory guard now checks symlinks before -exclusions and permits only root Git metadata and recognized test bytecode caches. - -Preparation adds read-only, commit-pinned CI, Dependabot action updates and -contribution/security/publishing guidance. The initial publication inventory contained 26 files; -the suite includes 16 template, five publication and four CI policy checks. -These CI checks inspect policy text, not the complete GitHub workflow schema. -Final local verification: all **25 tests passed**, both YAML files parsed locally, -and all three reviewers rechecked the final changes with no blocking findings -for GitHub draft publication. Each independently reran the 25-test suite. -Actual CA rendering remains unverified; hosted CI and repository verification -are recorded below. -See [publishing steps](PUBLISHING.md) for author-email privacy, clean Git history, -repository settings and first hosted-CI verification. The standard root MIT text -and original SVG remain unchanged. The prepublication review involved no Git -initialization, commits, server operations, GitHub writes or CA submissions. -The owner subsequently approved the separate GitHub publication step above. - -## GitHub publication record — September 13 (Europe/London) +Run `python3 -m unittest discover -s tests -v` from the repository root. The +checks cover template structure, the file inventory, relative documentation +links, CI policy text and selected accidental-data patterns. They are not a +complete secret scanner, legal clearance, CA validation or proof of current +upstream compatibility. GitHub Actions runs the same tests on every push and +pull request. No image build, custom CI credentials or server access is required. + +## GitHub publication record + +Published September 13 (Europe/London). - Public repository: [lozenge0/audio-cpp-unraid](https://github.com/lozenge0/audio-cpp-unraid), - default branch `main`, Issues enabled. No release/tag or CA submission created. -- Fresh signed root commit: `d40ecdfe65dc24509d144264c289ac51e06223c2`, containing - exactly the 26 reviewed files, no parent history. Author and committer use the - owner's approved GitHub noreply identity; GitHub reports the signature verified. + default branch `main`, Issues enabled. +- Fresh signed root commit `d40ecdfe65dc24509d144264c289ac51e06223c2` with no + parent history. Author and committer use the owner's GitHub noreply identity. + GitHub reports the signature verified. - [First hosted validation](https://github.com/lozenge0/audio-cpp-unraid/actions/runs/34725657862) - passed all 25 tests. The first Dependabot Actions update check also completed - successfully. No custom CI secrets, image builds or server access were added. -- Workflow token default is read-only; Actions cannot approve PRs. Fork workflows + passed. The first Dependabot Actions update check also completed. No custom CI + secrets, image builds or server access were added. +- Workflow token default is read-only. Actions cannot approve PRs. Fork workflows require approval for all external contributors. Private vulnerability reporting, - secret scanning and secret push protection are enabled; auto-merge is disabled. + secret scanning and secret push protection are enabled. Auto-merge is disabled. + `main` is protected by the "Template and publication checks" status. - Public repository, Issues and advisories links returned HTTP 200. Downloaded - README/template/profile/icon hashes match local files; the original icon is - unchanged. This does not validate the CA UI or public branch picker. -- The extra publication-settings subagent hit a usage limit; the earlier three - independent file/CI reviews remain valid. Remaining settings were verified - directly against GitHub documentation and API responses, not claimed as a new - successful independent review. + README/template/profile/icon hashes matched local files. This does not validate + the CA UI or public branch picker. The first commit and CI timestamps are September 12 in UTC (after midnight September 13 locally). Dated runtime evidence has not been rerun for publication. No Unraid operations were performed. - -## Category and submission status update - -After publication, the owner reported completing CA submission with automatic -approval, but could not yet find the app in the catalog. The template now requests -`AI Tools:`; both category identifiers are present in the public -[CA category list](https://github.com/Squidly271/AppFeed/blob/master/categoryList.json). -The base and both CUDA branches inherit these categories and retain `Beta=true`. -Removed obsolete pre-submission wording without marking public installation, -DockerMan lifecycle tests or other pending runtime checks complete. No container -image, arguments, mounts, ports, user identity or GPU options were changed. - -The original 25 checks remain, with one additional category/beta regression check. -Catalog processing time and the reason for delayed visibility have not been -established. No duplicate submission or Unraid changes were made for this update. - -## First-time user documentation - -The README now leads with what the app does, hardware choice, installation, a -first Pocket TTS example and ways to connect applications. Broad model capabilities -are attributed to upstream; the tested Unraid scope remains clearly limited. -Detailed notes were moved, not discarded: [configuration](CONFIGURATION.md) holds -image/permission/tuning/update guidance, and [maintainer notes](MAINTAINER.md) hold -project scope, validation context, CI, release process and source references. -The current publication inventory contains 28 files. No template runtime values -or container settings changed in this documentation reorganization. diff --git a/docs/VALIDATION.md b/docs/VALIDATION.md index 12a08fa..2b6703b 100644 --- a/docs/VALIDATION.md +++ b/docs/VALIDATION.md @@ -171,8 +171,8 @@ the protocol below is not a claim that every clause has been completed. - All 16 maintainer structural tests passed, including regression checks for missing/changed identity and unsupported `PUID`/`PGID` variables across every resolved variant. Setup descriptions explicitly identify the effective user. -- Independent subagent review found no blocking issues and independently passed - all 16 tests. It checked fresh versus existing storage, update/rollback identity +- A separate review found no blocking issues and passed the structural tests. + It checked fresh versus existing storage, update/rollback identity preservation and limits of the recorded one-host runtime evidence. Its wording suggestion was applied to distinguish pending CA installation acceptance from the isolated download/inference tests already completed. @@ -185,7 +185,7 @@ the protocol below is not a claim that every clause has been completed. - 12 maintainer structural tests passed, including three resolved variants and negative checks for partial branch fields, custom runtime wrappers and personal tuning. This models reviewed branch semantics; it does not execute CA itself. -- Independent subagent review found no XML/profile defects. Documentation was +- A separate review found no XML/profile defects. Documentation was corrected to separate HTTP health from Docker healthcheck status and to require a unique test name, port and storage directory. - Supplied SVG artwork and metadata are preserved (a final newline was added). diff --git a/templates/audio-cpp.xml b/templates/audio-cpp.xml index 5bfcbbe..80e27f8 100644 --- a/templates/audio-cpp.xml +++ b/templates/audio-cpp.xml @@ -14,6 +14,12 @@ https://github.com/lozenge0/audio-cpp-unraid/issues https://raw.githubusercontent.com/lozenge0/audio-cpp-unraid/main/templates/audio-cpp.xml https://raw.githubusercontent.com/lozenge0/audio-cpp-unraid/main/README.md + +### 2026-09-13 +- Use a PNG icon so the Unraid Docker page shows the app icon. +- New installations default to host port 6969. Existing installations keep their configured port. +- First beta listing with CPU, NVIDIA CUDA 12 and NVIDIA CUDA 13 variants. + audio.cpp for Unraid: community-maintained installation templates using unmodified upstream Docker images and the native WebUI/audio API. Choose CPU, NVIDIA CUDA 12, or NVIDIA CUDA 13 when installing. No models or personal configuration are bundled. Images follow upstream rolling Docker builds, not exclusively numbered releases. BETA: isolated runtime and private installation tests passed on one host; public branch selection and full deployment acceptance remain pending. See the README for tested images and limitations. Trusted-network access only: this setup provides no authentication. Runs as UID 99/GID 100 using Docker --user; model storage must be writable by this identity. Model downloads require network access and adequate storage. CPU variant: no GPU runtime required. Review the README before installation. CPU — no GPU required; upstream rolling image diff --git a/tests/test_publication.py b/tests/test_publication.py index 3a9812b..bcde500 100644 --- a/tests/test_publication.py +++ b/tests/test_publication.py @@ -1,9 +1,22 @@ """Local publication guardrails, not a secret scanner or publishing tool.""" from pathlib import Path import re +import subprocess import unittest ROOT = Path(__file__).resolve().parents[1] + + +def candidate_files(): + """Tracked files plus untracked files Git would not ignore. + + Ignored caches such as __pycache__ and .pytest_cache never appear, while a + stray untracked file still fails the inventory before it is committed. + """ + output = subprocess.run( + ['git', 'ls-files', '--cached', '--others', '--exclude-standard', '-z'], + cwd=ROOT, check=True, capture_output=True, text=True).stdout + return {name for name in output.split('\0') if name} EXPECTED = { '.github/dependabot.yml', '.github/workflows/validate.yml', '.gitignore', 'CHANGELOG.md', 'LICENSE', 'README.md', @@ -28,7 +41,7 @@ def test_first_time_guide_keeps_safety_and_routes_advanced_notes(self): '## Make your first speech sample', '## Security'): self.assertIn(heading, readme) self.assertIn('no login or API authentication', readme) - self.assertIn('public-listing installation checks are still in progress', readme) + self.assertIn('(docs/RELEASE-REVIEW.md)', readme) self.assertIn('(docs/CONFIGURATION.md)', readme) self.assertIn('(docs/MAINTAINER.md)', readme) self.assertNotIn('--max-loaded-models', readme) @@ -47,22 +60,11 @@ def test_approved_licence_scopes(self): self.assertIn('The icon is separately dedicated under CC0', readme) def test_exact_candidate_inventory(self): - actual = set() - for path in ROOT.rglob('*'): - rel = path.relative_to(ROOT) - self.assertFalse(path.is_symlink(), f'Unexpected symlink: {rel}') - if rel.parts[0] == '.git': - continue # Only the standalone repository's root Git metadata. - if rel.as_posix() == 'tests/__pycache__' and path.is_dir(): - continue - if len(rel.parts) == 3 and rel.parts[:2] == ('tests', '__pycache__'): - cache = re.fullmatch(r'(test_\w+)\.cpython-\d+\.pyc', rel.name) - self.assertTrue(path.is_file() and cache, - f'Unexpected cache content: {rel}') - self.assertIn(f'tests/{cache.group(1)}.py', EXPECTED) - continue - if path.is_file(): - actual.add(rel.as_posix()) + actual = candidate_files() + for name in sorted(actual): + path = ROOT / name + self.assertFalse(path.is_symlink(), f'Unexpected symlink: {name}') + self.assertTrue(path.is_file(), f'Tracked file missing: {name}') self.assertEqual(actual, EXPECTED, 'Review unexpected files before expanding the publication list') diff --git a/tests/test_template.py b/tests/test_template.py index 3e069c4..442110c 100644 --- a/tests/test_template.py +++ b/tests/test_template.py @@ -5,7 +5,9 @@ """ from copy import deepcopy +from datetime import date from pathlib import Path +import re import shlex import unittest import xml.etree.ElementTree as ET @@ -105,8 +107,8 @@ def test_host_port_default_and_container_port_are_distinct(self): self.assertEqual(root.findtext("WebUI"), "http://[IP]:[PORT:8080]/") args = shlex.split(root.findtext("PostArgs")) self.assertEqual(args[args.index("--port") + 1], "8080") - self.assertIn("Keep host port `6969`", (ROOT / "README.md").read_text()) - self.assertIn("Suggested port: `6969`", (ROOT / "docs/CONFIGURATION.md").read_text()) + for name in ("README.md", "docs/CONFIGURATION.md"): + self.assertIn("`6969`", (ROOT / name).read_text(), name) def test_branch_labels_and_shared_fields(self): shared = [ET.tostring(field) for field in self.root.findall("Config")] @@ -166,30 +168,36 @@ def test_icon_is_self_contained_svg(self): if key.split("}")[-1] == "href": self.assertTrue(value.startswith("#"), "External asset reference") - def test_only_repository_assets_not_runtime_payload(self): - allowed = {".gitignore", ".github", "README.md", "LICENSE", "CHANGELOG.md", - "CONTRIBUTING.md", "SECURITY.md", - "ca_profile.xml", "assets", "templates", "docs", "tests", ".git"} - self.assertTrue({item.name for item in ROOT.iterdir()} <= allowed) - self.assertEqual([p.name for p in (ROOT / "templates").iterdir()], ["audio-cpp.xml"]) + def test_changes_field_has_dated_markdown_entries(self): + """CA shows this field as the app changelog; it is the only channel to + installed users, because Docker Manager never refreshes templates.""" + changes = self.root.findtext("Changes", "") + lines = [line.strip() for line in changes.strip().splitlines()] + self.assertTrue(lines and lines[0].startswith("### "), "Start with a ### date heading") + headings = [line[4:] for line in lines if line.startswith("### ")] + for heading in headings: + date.fromisoformat(heading) + self.assertEqual(headings, sorted(headings, reverse=True), "Newest entry first") + for line in lines: + self.assertTrue(re.fullmatch(r"### \S+|- .+", line), f"Unexpected line: {line!r}") + for tag, resolved in variants(self.root): + with self.subTest(variant=tag): + self.assertEqual(resolved.findtext("Changes"), changes) def test_documented_release_gate(self): readme = (ROOT / "README.md").read_text() self.assertIn("lozenge0/audio-cpp-unraid", readme) self.assertIn("Beta integration", readme) - self.assertIn("public-listing installation checks are still in progress", readme) + self.assertIn("docs/RELEASE-REVIEW.md", readme) self.assertTrue((ROOT / "docs/PLAN.md").is_file()) self.assertTrue((ROOT / "docs/VALIDATION.md").is_file()) self.assertIn("MIT License", (ROOT / "LICENSE").read_text()) - def test_ai_category_and_honest_beta_status(self): + def test_ai_category_and_beta_flag(self): for tag, resolved in variants(self.root): with self.subTest(variant=tag): self.assertEqual(resolved.findtext("Category").split(), ["AI", "Tools:"]) self.assertEqual(resolved.findtext("Beta"), "true") - self.assertIn("full deployment acceptance remain pending", resolved.findtext("Overview")) - self.assertNotIn("Not ready for public submission", resolved.findtext("Overview")) - self.assertNotIn("not yet submitted", (ROOT / "ca_profile.xml").read_text()) def test_selected_publication_destinations(self): base = "https://github.com/lozenge0/audio-cpp-unraid"