10044 Commits

Author SHA1 Message Date
James Valleroy
5d099e13cb
Release v25.16~bpo13+1 to trixie-backports v25.16_bpo13+1 2025-11-29 09:15:19 -05:00
James Valleroy
8ae32a9d11 freedombox Debian release 25.16
-----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmklpbwWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICPLqD/4/MOQb5Qv+UWYC6h2tSNUs2BFr
 Fk6RoUJv0nDDrsDRYQvA9eqAWH3uqa53CUlSBP0i4aDyZnGttuZtTcekfp8z6aQP
 oF9npspNgkvmHaD+jF2AJFTg52lJ96vtKAHcWXpI92GzpmOLJVT5EVAMDSSerahO
 9wmuBQEhDFzi0tao2AKk1OBifTYx3lBXtTqzRAJ6CtEF0ekyTE3A2ofWsFbb34QI
 7GYlLYE8PNxz7tfvSN/PRt9jeLrht7OQQtVDH+AAjXt78bd3WQm4NN1RLmz3J6OG
 pHcOb4VTTt7pOabMHMmU8OWTqKm9I/mcd3oRDlTFZV1Rywlu4wy8K6xPAHKXBYfN
 xG284qTInVuS2V9XEPJD0MZpqOfIqNNsZ6BTgyo6g13d3RgD7gHpthhLPR/ywawo
 aEhnyQjpw5jMwiCFviq1R9+cDlbir2atE0sViU/B19LJ0RbXq2smqwWqngpTrG89
 Bd9t7LbWawSKiLhjNhMl0COvrUuGxHKx08yejIlIxbAjL5yL1uD2NDvzw6vqX6pU
 A2hkxQ6/hr6K3uUwxXzSRuJTTW8GFn5ubb1kzria2E5p0ZFAczmLUQDWjf8REliy
 S6o39cLxi2f5OfergGmmd5VRanRskCYeykB9oRtdtzQBs74oqIdYRCpqEeGj0csX
 l0+85hNWEZMkQTAbqw==
 =5eh0
 -----END PGP SIGNATURE-----
gpgsig -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmkq/94WHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICEmuD/9XEEm2J7+lbPzDTgvAjcIqnNW+
 5g6QLJHqY7CMdSgvYr/MWZn76tm8mRllXOI7yvbLBBvg0KtodPaEcaDNaWpw3wON
 +vJBQflPJBYWTdS0Ho+ZlLB0nP+VyQtliZ/bXuT2m6mkqlA9e/VBeZ1wVkUOIWpu
 CD5NQdA/yNJiyS0hh9M4VxyO06GAyOjTdn6+Mem7byW/0GNui9Tx4+Pq6FeLELEO
 qjpBT+JH34n1yaqsiYIryt611x/kpDLubomig/7mrRk6YK8lXEqqG1l7uZz1LaR1
 aS0JSCtDqfiIgDGMB13VZBt6BMwCvXac0MkrNRwzXxYXrx1SumGKhvThi49tzmLr
 kqsmKf3BeqmHkR20YJlcNApBZ1Z/iG4dtSz18dsAexB7lcYec2c5wPldgbTHQlwP
 ZWx+ufX0OfLglRQE5Yy6iwHqRSQK48eIszHwYNXgTpdSb7OUhY5JHBsC9OXFZk4W
 lhDpdtypIQXepaZddlGCa9MhXUKGWCQHgVWSc9hM8sixZSOVcrhUGYzGqEvUxlPq
 jwOQ+gNCip06vUjWL8RwBTWvo/fEXJtBV4PPGuZygtVMux8woijeAsK6efA8yuQI
 B3bXFDedf99ZcRdZeVEDYKojbTdedNusnbuTOfYhEEYT2s04GvJy9qa+vQscFIMn
 rZK7GWHk9YHP4yw0pQ==
 =6qUh
 -----END PGP SIGNATURE-----

Merge tag 'v25.16' into debian/trixie-backports

freedombox Debian release 25.16
2025-11-29 09:14:53 -05:00
James Valleroy
d63324160a
Release v25.16 to unstable v25.16 2025-11-24 20:44:22 -05:00
James Valleroy
d16c18be37
doc: Fetch latest manual 2025-11-24 20:44:09 -05:00
James Valleroy
3fe62bac0b
locale: Update translation strings 2025-11-24 20:22:18 -05:00
Sunil Mohan Adapa
ffecd1411b
jsxc: Update content security policy to prevent style errors
- Without the CSP, during loading there are no errors in the console. However,
during chatting, some styling related error show up.

Tests:

- Ensure that there are no CSP related errors in the browser console.

Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-21 22:31:27 -05:00
Sunil Mohan Adapa
a66c011f0b
jsxc: Fix missing dependencies
Fixes: #2547.

- Earlier, FreedomBox itself depended on Bootstrap 4 as needed by the room we
built for JSXC. Since FreedomBox moved to Bootstrap 5 this library is no longer
available for JSXC. libjs-jsxc itself depends on libjs-bootstrap which is of
version 3.

- Also fix the path for jquery-slimscroll. This is was likely updated for Trixie
cycle.

Tests:

- Connect to JSXC with two different browsers. Add contacts. Initiate chat and
send messages.

- Re-run app setup and it succeeds.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-21 22:31:14 -05:00
Sunil Mohan Adapa
a10ba40001
dynamicdns: Use only IPv4 for GnuDIP protocol
- The following messages was seen on the ddns.freedombox.org server:
"Unserviceable IP address from <ipv6_address>: user <username>.fbx.one - IP:
<ipv6_address>". This is due to code that checks for validity of incoming IP
address and fails. The current configuration only handles IPv4 address. Even if
this restriction is lifted, GnuDIP code does not contain code to add/remove AAAA
records.

- Fix this by forcing GnuDIP HTTP update requests to go on IPv4.

Tests:

- Copy the code for _request_get_ipv4() into a python3 console and run
_request_get_ipv4('https://ddns.freedombox.org/ip'). Do this on a dual stack
machine with both public IPv4 and IPv6 addresses. Only IPv4 address returned.
Changing the AF to AF_INET6 returns only the IPv6 address.

- Take a test DDNS account offline. Configure it in FreedomBox stable VM. The IP
address is properly updated.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-21 22:03:10 -05:00
Roman Akimov
7b93932868
Translated using Weblate (Russian)
Currently translated at 100.0% (1875 of 1875 strings)
2025-11-21 02:51:20 +00:00
Sunil Mohan Adapa
6c3b2e1f82
package: Prevent freedombox's deps from removal during app uninstall
- If an app declares dependency on package that is also a dependency for
freedombox, then during the app's uninstall, the dependency is attempt to be
removed and will fail (because freedombox package will be held state).

- Add freedombox (and thus its dependencies) to the list packages that should be
removed from list of packages to be removed during app uninstall.

- In test case, update list of packages attempted removal as the 'freedombox'
package is installed only in some environments.

Tests:

- Uninstall janus works. Log messages show that libjs-bootstrap5 and
node-popper2 are in the list of packages originally set to removed during app
uninstall but are later filtered out.

- Run pytest with 'freedombox' package installed and ensure all tests pass.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-17 13:03:06 -05:00
Sunil Mohan Adapa
b6bade7d06
janus: Update the video room code from latest upstream
- Bootswatch is a theme library for bootstrap. In Debian, only 3.x version of
the package is available. It is compatible with bootstrap 3.x but not bootstrap
5. Drop the theming altogether and use the basic bootstrap style (which is
already very close to the theme).

- Updated copyright year, mention the video room files in debian/copyright.

- Drop libjs-spin.js which is no longer used by the updated code.

- Change bootstrap version to 5.x from the earlier 4.x. Also add node-popper2
library (needed by bootstrap5 and video room code) as explicit dependency.

- Add missing style for btn-default class dropped in bootstrap 5.

- .simulcast-button CSS style is not longer needed as updated code used flex box
with .d-flex bootstrap class.

Tests:

- Compare the files in janus source code around Mar 2022 with the files in
FreedomBox source code before this patch. Compare latest janus source code with
the files after this patch. Both sets of changes are very similar.

- Connect to video room using two browser windows. Connection is successful and
2 video streams are shown in each of the browser windows.

- Styling looks close to the demo on janus website and is acceptable.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-17 13:03:02 -05:00
Sunil Mohan Adapa
94c344573b
janus: Relax content security policy for the video room
- Needed for the new video room code to run without CSP errors in the browser
console. JS error happens immediately after loading the page before Janus
initialization. Styling related errors happen after joining the room despite
eliminating use of'style=' attributes from JS code.

Tests:

- The video room works for a conference without showing any
Content-Security-Policy header related errors in the Firefox developer console.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-17 13:02:59 -05:00
Sunil Mohan Adapa
32520c7c89
janus: Allow app to be installed from Debian unstable
- Janus is currently not installable in Trixie because Janus was temporarily
removed during the release process of Trixie.

- Installing it from unstable, despite the instability is better than keeping
the app unavailable. Users have reported using the app.

Tests:

- Restarting the service after applying the patch leads to setup for upgrades
app to run. Apt preferences for janus packages are set. App is shown as
available. It can be installed.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-17 13:02:56 -05:00
Sunil Mohan Adapa
2467d6a033
middleware: Implement middleware for common headers such as CSP
- This allows overriding these headers in individual pages easily instead of
relaxing global policy.

- Drop the obsolete CSP directive "block-all-mixed-content" and avoid a console
warning in Firefox.

Tests:

- Load a page and notice in the browser developer tools that the three headers
referrer-policy, content-security-policy, and x-content-type-options are set as
before.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-17 13:02:52 -05:00
James Valleroy
2afb69e619
Release v25.15~bpo13+1 to trixie-backports v25.15_bpo13+1 2025-11-14 17:23:23 -05:00
James Valleroy
ceedfeb39f freedombox Debian release 25.15
-----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmkSpRgWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICEygD/oDYpC84hMyoRXQ5djJU+r24UDo
 CRzPBROHBS8okraYs8Hzg7GeKuxjVIZVUtKsw9qUYOeXxAmhDM54ABy12hMnk89O
 OsvtBaOW5BFC2IJQz1D1/L0bSzYY6oUi0kmzohbIjwiVI4uc/jCzoYQ5pqf2gY0E
 o+iTEetM/PWyZbw73t9GTeVglKTXJsY75rUbj30I4ezatANuV6YYK+mnZX8b3gFZ
 SuP/TWTjMVUPx9BK59kzKhxZDjV5oNXbSUKHIYKBMnVv3CH806ccuW64tcxBdoV6
 K59OtfW7woLjdz9GKW9V7z/jwI9BPqUrTwBCP1QWzRvz/k0Dgek/7jTy55F2nc3A
 0Z42PXH6uLq9ufQzet4wfevkt9i1QWkoZTMTeEJuFJaBgFLPsm3o2hJKhbH+aJf6
 j1FvOmYzNfJ5G784R9Cj7h+STq5cfqoymtKh2GmoC8M3spJ0aNorlo8rYEjBPDEj
 Gg0BdCU7iW9rs1+J28E6CtjT6W8HqgqokQ/knSzlZBg9/yWIy4YG8ydHPWj/t9ka
 rZI8DrJdn3v22Jq6sdP66gLcZ0ufmblENyp7zC2+6vBQY+pONKcyQF4OgYK0dwMS
 /kmYiosEKGNfEdno4XBOJa4aFVbNuqQvZ/+SDMoJPUqw8el22jaETbDbkAdsT1zn
 RVxx/n9nbohFOlssLQ==
 =bTME
 -----END PGP SIGNATURE-----
gpgsig -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmkXq7IWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICOMbD/9SrZldrpfewRHxbDw20n4xsqmr
 OL6aN+1tx58Xw72ZeG1CAMLDnOpofM7pAZ4VtmeqMmjhFTzcrpkDY8auTJXq+LBI
 u1V/EtAEy2zOYjsEvbHgQxri247kpYZK7xMgTIVQAT+4/5obryUtDzk61nAgC/0d
 gQJtGbKYo76TpXjbKwFToKkSqvUVUG9HTROuOL5i/KWmJgKi0BcPk30QBJdc/tW0
 +5RGYC9yPLzqFlpevQ+T3bGnMpcJLIw3z8V3kiDRUgSiivDq5QAhyar3lV5Qricl
 59ZLZbpTV0ONFtDJkXFQ+iYE0hTZKbfB7diiWrlOQYv8SEnZsBDJ8dJTfWNaOt4y
 Dd2Ciz/jhK/szw63XWW0UbVXcyPqEd6uelWbGW4ERQ1WNz43kWUrI/sDGF3VxGAF
 tbDJy8vo8wAnuj4NMYMBUx2RF231Zk/pC9blEqPWmmeBDLs8CLz3LNSOCSEPUXrs
 Lpjz1EKK9jXBpthXRXc3dTYhvHcK699vwpHkpR8kgkU13yuia4lS7enU1kYH5gkM
 0bvb5jst1bWDttATibe/RJRTVaf3F1FFpsTdkumYWY733TWXaonXvFpoI+h2Iyps
 fg4TNWHWPp8WBCjgDxjnMuzQwUoKS2+QKtIRA850BPrARHCO1FP3Q0SX0r2eIRID
 tukhRXcqWHAEaPSxJA==
 =jzgf
 -----END PGP SIGNATURE-----

Merge tag 'v25.15' into debian/trixie-backports

freedombox Debian release 25.15
2025-11-14 17:22:40 -05:00
Dietmar
3eef1d9324
Translated using Weblate (Italian)
Currently translated at 47.5% (891 of 1875 strings)
2025-11-13 13:51:19 +00:00
Dietmar
7d38f49dd8
Translated using Weblate (German)
Currently translated at 98.9% (1856 of 1875 strings)
2025-11-13 13:51:16 +00:00
Besnik Bleta
601de6d0e3
Translated using Weblate (Albanian)
Currently translated at 99.7% (1871 of 1875 strings)
2025-11-12 07:51:36 +00:00
Максим Горпиніч
cdfdacabad
Translated using Weblate (Ukrainian)
Currently translated at 100.0% (1875 of 1875 strings)
2025-11-12 07:51:34 +00:00
Jiří Podhorecký
d4c4900b1d
Translated using Weblate (Czech)
Currently translated at 100.0% (1875 of 1875 strings)
2025-11-12 07:51:22 +00:00
大王叫我来巡山
8f87d658a6
Translated using Weblate (Chinese (Simplified Han script))
Currently translated at 61.5% (1154 of 1875 strings)
2025-11-12 07:51:19 +00:00
Burak Yavuz
117932e66f
Translated using Weblate (Turkish)
Currently translated at 100.0% (1875 of 1875 strings)
2025-11-12 07:51:17 +00:00
James Valleroy
91de3e6e3b
Release v25.15 to unstable v25.15 2025-11-10 20:49:27 -05:00
James Valleroy
b98e156bfe
doc: Fetch latest manual 2025-11-10 20:48:34 -05:00
James Valleroy
d7bdc73fb3
locale: Update translation strings 2025-11-10 20:21:09 -05:00
Dietmar
56762409d2
Translated using Weblate (Italian)
Currently translated at 47.3% (890 of 1879 strings)
2025-11-11 02:13:37 +01:00
Dietmar
9a8ddf326b
Translated using Weblate (German)
Currently translated at 99.0% (1861 of 1879 strings)
2025-11-11 02:13:37 +01:00
Sunil Mohan Adapa
743b7bd163
ttrss: Remove app not available in Trixie
Tests:

- Running 'make build install' remove the module loading include file for ttrss.

- TT-RSS is no longer available in apps page.

- Installing Tor works. Onion header is set correctly. Re-running app setup
works.

- RSS Bridge's description is updated as expected. Links work.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-10 19:20:33 -05:00
Sunil Mohan Adapa
76b360bb68
matrixsynapse: Explicitly set the trusted key server to matrix.org
The following message is shown when Matrix Synapse server is started.

"""
This server is configured to use 'matrix.org' as its trusted key server via the
'trusted_key_servers' config option. 'matrix.org' is a good choice for a key
server since it is long-lived, stable and trusted. However, some admins may
wish to use another server for this purpose.

To suppress this warning and continue using 'matrix.org', admins should set
'suppress_key_server_warning' to 'true' in homeserver.yaml.
"""

Explicitly configure the server to use matrix.org as the trusted key server to
avoid the warning. The value can be set to empty list of servers, however, our
users are served best by this default.

Tests:

- On a testing container, when patch is applied after Matrix app installation,
the configuration file is updated.

- After the configuration is updated the warning is removed during Matrix
Synapse startup.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-10 18:54:46 -05:00
Sunil Mohan Adapa
084c9c5a47
matrixsynapse: Explain federation and link to testing tool
- Create a separate section for federation as it is so important.

Tests:

- Federation description and TLS warning are shown in a separate section on the
app's post-setup page.

- Clicking on the testing tool link takes the user to the testing tool and the
current server's domain is automatically tested.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-10 18:54:41 -05:00
Sunil Mohan Adapa
35cedd7923
matrixsynapse: Clarify how to change domain name in status section
- This has already been update in the pre-setup page.

Tests:

- View the post-setup page and notice that the message was updated.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-11-10 18:54:38 -05:00
Sunil Mohan Adapa
a74028a73f
help: Fix serving images from help pages
Tests:

- Images are shown in the pages /plinth/help/manual/en/bepasty and
/plinth/help/manual/en/. Before the patch, images are not shown and 404 errors
are raised.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: Joseph Nuthalapati <njoseph@riseup.net>
2025-11-06 20:03:04 +05:30
Sunil Mohan Adapa
d5062ef5ea
README: Use the Weblate's language chart widget
- This shows status of each language rather than just a single number for all
the languages. This hopefully highlights languages needing more work.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: Veiko Aasa <veiko17@disroot.org>
2025-11-03 13:58:50 +02:00
Sunil Mohan Adapa
24d2d92ab5
Run service using systemd even for development
- This means that systemd sandbox will be in effect even during development. We
won't miss out on bugs in sandbox configuration.

- We won't have disable systemd sandbox features just because we can test
properly on development setup. Such as JoinsNamespaceOf=.

- This also leads to significant reduction in hacky code for setting up for
development and functional tests.

- One disadvantage is that first setup is run before user gets a chance to
interact with the started container/VM. However, this is okay since first setup
can be re-run easily by removing the /var/lib/plinth/plinth.sqlite3 file and
also the need for doing this is rare.

Tests:

- Start a fresh container and run functional tests with './container run-tests'
on it. The tests run as expected (succeed or fail).

- While first setup is in progress, running the command 'make
wait-while-first-setup' waits while printing dots. After the first setup is
done, it exists.

- Running the command freedombox-logs shows FreedomBox logs for both the web and
privileged services.

- Changing a source code file in the /freedombox directory (or on the host)
leads to a restart of the Plinth web service.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: Veiko Aasa <veiko17@disroot.org>
2025-11-03 13:54:00 +02:00
Sunil Mohan Adapa
e5026282fe
main: Allow setting development mode from environment
- Similar to freedombox-privileged daemon. It makes it easy to turn on
development mode from a systemd service override (without having to override the
entire command line).

Tests:

- With the changes to systemd service file in this patch series, changing source
code file leads to plinth getting restarted.

Reviewed-by: Veiko Aasa <veiko17@disroot.org>
2025-11-03 13:54:00 +02:00
Sunil Mohan Adapa
623604649e
views: Implement an API to retrieve the readiness status in JSON
- This can have may uses such as:

  - Waiting properly on the reboot page until the system has been restarted
  while showing the status.

  - Or, waiting for first setup to complete before running functional tests.

  - Or, monitoring for the health status of FreedomBox in general.

- The page is public as all the information conveyed there is also already
public. Should we introduce any sensitive information there such as
'operations_in_progress', we can provide that information only to
administrators.

Tests:

- Visiting /plinth/status/ shows the status in JSON. Using curl to retrieve the
information is also possible.

- During the first setup 'is_first_setup_running' is 'true'. After it has
completed, it is 'false'.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: Veiko Aasa <veiko17@disroot.org>
2025-11-03 13:53:59 +02:00
James Valleroy
f94a21e788
Release v25.14~bpo13+1 to trixie-backports v25.14_bpo13+1 2025-10-30 07:24:37 -04:00
James Valleroy
0e29d8a7e8 freedombox Debian release 25.14
-----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmkAJMQWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICKlkD/4zACLOfO2pdZwhIfAenZh2PPue
 kxuaVFLaifx798Pkx5AaaKAY93vLDN/Egjz/y4ome3bmPhCVSSJzLyEaSNZxf8UL
 j8HY7U7WhtSpzLNd4NM/f/xR7DCqgRmRVp2ecr/7Xw81hypf4srcw0jcrzc9LuYx
 S7peuzwjP77Igg6ILYN6jHkO3/sKHn3fvats6hhFcOh6h5gedFG+uyHYNSKlHhGJ
 TeHLkrBViBt1+iAgD56S+FfNM0YxAIHoavx/JqbC+xYFyfng7Fx5nDKRIEChd0oU
 SNcYTtL9CKsH7tKEbiG9/WtUmZQaQMh9YdN75UK568HVfI/p5etlaT1qb5ffrSg3
 3aJfM+Is5CSgjTeia2660EVtCqLy069P+wY2pxYRIpLN7Mw4f7xNKS+93mUe+D7q
 mBRZLm3j9Ly+tj1JuEw4NpgG9siL7n6FZlJmU5xXcQY6AL3PpQkFh/anJh2G+z/X
 GMOkTz8+HV40SFHOAg5CH9+z+Hg6PsZfXf3orCM6Bul+66tEedEGTX1fQ+9HSb9d
 NQBOshMhcRm/oK6oveI4Gmbqb76zzuUrApJdreKKuBzXcxz5hF0SBPQCgRqE2+5I
 UNz3/e0eV8IB3dS8AQJMo3cfcMG7xucFqSOz52p19rShP7Yjg3w3/xEy0t9864Ya
 7IjXizG17ug2dECt3g==
 =YhyP
 -----END PGP SIGNATURE-----
gpgsig -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmkDSmoWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICO+NEACCIiDebqIBjKWlGJ4LwehlSKPZ
 U5piKVqIjEeiLbS+Z8+vA1eCaop/kiOHsmAzasUHGaUNz1zt3KS75ZmHg+3N1/js
 TS/6viX8sVPPDQCUQFvKdH2ZdnwO2A1KLXdVGKD+02I4YE8jZ9mA7MtemNZ9vF9p
 nu7r10VAXOThZUr81bOO8q3+GeuCyLN80BIO62qv/sl/+jRB+Kj2UONRasrzZs06
 OGTAsVLOQQqfGY8sLixHJRUZvHe7zZI6HoTZlLTGeK5DW6Wv8QSoruaCOuOdZ7J0
 pBRpuls8JJ0HcXhTx2XuHDWkiuURfBMSWyAJi++auoX+b8WvQlQzwXUcLHgMxrUA
 G0PcnrY/kdCU9yCZfgBi86EvJxqXlGoE9m5g8WNvh+zE1d7AiTFAk1eEQV+uf9+F
 0IrNzU1iJZrxMP9m4PQx1m23Ut3suKbtBBWfHA/LbPL1nMi2C52qnoIiDV0QYO6h
 0T7eS4SmmEPzVmR5gnNr9iki3txpK8JWFy63tXrZy7TO0E1YqcOeUGTHlPGO0X7r
 L6C2qO50xxlM3vfCqncphhVlPULri9kppvKevIP34lfBYbBpO8+CRHxWuMTNhoa2
 SKZlhtPzPHNWqqbz2yg3dH+DUKxt8WpP6YvUJnRbOBX1AHq3We9XkxCFZ/GHOF3g
 DnzH67EUK34GyYMoUg==
 =H16M
 -----END PGP SIGNATURE-----

Merge tag 'v25.14' into debian/trixie-backports

freedombox Debian release 25.14
2025-10-30 07:22:16 -04:00
Coucouf
8a4f03c58a
Translated using Weblate (French)
Currently translated at 100.0% (1879 of 1879 strings)
2025-10-30 04:24:25 +00:00
James Valleroy
21694c5e99
Release v25.14 to unstable v25.14 2025-10-27 20:23:02 -04:00
James Valleroy
80977c3727
doc: Fetch latest manual 2025-10-27 20:22:32 -04:00
Sunil Mohan Adapa
a4505978ad
Enable private tmp and join namespaces for the two daemons
- Earlier PrivateTmp=no is set freedombox-privileged.service in
4140d3b4444d2fd55ac682d066fd859cb2f034b5 and the fix was not properly tested.
Similar change was needed in plinth.service and it was not done.

- Complete the fix but this time enable private tmp and join namespaces for the
two daemons.

- This will cause issues with file uploading when plinth is run from command
line (for development purposes). This will be addressed separately.

Tests:

- Apply the change and reload systemd and restart service. Don't run plinth on
command line and run it as service.

  - Uploading libraries to kiwix works

  - Uploading backup tarballs works.

  - Uploading TiddlyWiki and Feature Wiki wiki files works.

Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org>
Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
2025-10-27 20:09:46 -04:00
Coucouf
949ab18486
Translated using Weblate (French)
Currently translated at 100.0% (1879 of 1879 strings)
2025-10-27 16:02:43 +00:00
James Valleroy
44005a075b
Release v25.13.1~bpo13+1 to trixie-backports v25.13.1_bpo13+1 2025-10-24 14:37:07 -04:00
James Valleroy
a3dcbf0c17 freedombox Debian release 25.13.1
-----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmj3eLEWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICESEEAC7gaC+dSaRIBbmCAbZrgA7OyLr
 eb7OUKNxbx11UzwkHpHya83IoBJEx3g8MEVZDA2o4ofISNWOZdlhFBDYFqeYFjRh
 Jx3lUljTYYtzyFnkYxW3wZH2E6N0/DOdB4EbG3z99vhJrtZQhYtYzDvBZOZr6vJW
 E/AnHxJvoL0P5GMuLmGvsRPbGMkgocpQyW1XmkI/69gOSGG/igdIcyYYcCcm8qVp
 4Ky41xHZTxKJDFbBiABR2HIrr5Kilv52kktNN84j6LM5u3UaE+T2ToB2Pdopcq3x
 3xe5H0HXCq/Y2bzPTIsvW9Y6mAqbfBGqv5qoNjxdIN/Gi7gk6iow3jq/r5GoQQK8
 xhMmK7k3tOL3WjLjoQpbnQD1LvH6Z5gwv62VAS6kfieGpczobF2C1EkfouxXdrdF
 hq12gqC2KgP89cSb4NIGfDC60h3WPvVpvaHysGt/9EC/x+dnjrJS5TwcVMd7Fe6H
 egqmGUapo0TYBNor635DCx6SCKXuMlwwWiywxaudeqXAP4f+0fMrlIknvDo4qSQk
 1QYSoPU+kBgIV5ND+w2kdVNGUXL5cHj1ta+S1GBJVB62gmHipw+YYS8OvYVe+lHN
 siUZwWckFRbTU5eAk8ikRGTtLE0WXeWuvvPL6AeRiKLTI33ERW/54zIDypYBkkOq
 uI/K7Trews2Yw0MkAw==
 =HsVY
 -----END PGP SIGNATURE-----
gpgsig -----BEGIN PGP SIGNATURE-----
 
 iQJKBAABCgA0FiEEfWrbdQ+RCFWJSEvmd8DHXntlCAgFAmj7xzEWHGp2YWxsZXJv
 eUBtYWlsYm94Lm9yZwAKCRB3wMdee2UICIMXEAC+bCDkQHSUd8QaMm/lqgFG3nFm
 ZZxo8Qwx90DioMCGT5s3BXVk1ewngz13kIINn7o8/omgIxT5cGBPDDvg83i1L4RV
 TQuoHPS4SV+0+FgZZaMBT/u/5IPkI20kAq8I12am+/U/71U9xB/3KPWCaDvnt4E5
 hGERkwrw3NxZlSI+7HGQsSsZMYc65p1VTZtmzkWwm9SybvL4zzp/C/9obLDWsk5J
 Iacv8P5BYtWacF/f3mlFlR7lrp1Uhw5QtXmRbSsjv5jsswOWxJxS4GBigCw5+Tk8
 RJypRJGXE2v0pvl/tosOUBDEQ+HY98AuxsDkQJJC1A5TPn/tuf7BjzM9f/457WrK
 ufe1+5NEno8i7WxxLCzPtx1yLB+gxjz3XJUCi6WtfjHXGSM8QRY1IHBfJ40IrxBY
 zJJ+PY1x5flilEBI8XQUJ0Iv7KeUWVusEjZjK/1MwEknEdDK85hzDrqRZAxFgp0g
 GuIHBTIZSIJwJ0Bd4hr29QNRjG5T+rioR24MkV3Nkr/aKI0/uLWduXjYXNhUYQ89
 r5v8htZ2U05F6zYgrqD4H8PqVvExtruhcFTDmPJdx5VfqgOOhrmO/uuMpDg9WsHR
 GAWs4tRW0TwZOII8vwcHUVS3+j4HrboHeF6aHCCT3bBvpVZAbwe6UHl4Hg8P5b/H
 G+aOPaPeWolUxuxyGg==
 =Oc+1
 -----END PGP SIGNATURE-----

Merge tag 'v25.13.1' into debian/trixie-backports

freedombox Debian release 25.13.1
2025-10-24 14:36:30 -04:00
Jun Nogata
678107959a
Translated using Weblate (Japanese)
Currently translated at 5.4% (103 of 1879 strings)
2025-10-24 18:02:52 +02:00
Coucouf
20dc640b4e
Translated using Weblate (French)
Currently translated at 100.0% (1879 of 1879 strings)
2025-10-23 00:02:41 +02:00
James Valleroy
a410ef2548
Release v25.13.1 to unstable v25.13.1 2025-10-20 20:21:14 -04:00
James Valleroy
38b7a05a61
doc: Fetch latest manual 2025-10-20 20:20:08 -04:00