Commit Graph
6136 Commits
Author SHA1 Message Date
Josh Hawkins 3f86876630 document automatic device access grants 2026-08-29 15:59:23 -05:00
Josh Hawkins 3c9e77ffb5 assert device access grants in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins d5eca09797 grant runtime users access to mapped device nodes at boot 2026-08-29 15:59:23 -05:00
Josh Hawkins 49f520d3e5 install acl for device access grants 2026-08-29 15:59:23 -05:00
Josh Hawkins b9ce2988d8 clean up 2026-08-29 15:59:23 -05:00
Josh Hawkins 39d2883a87 clarify granular root services docs 2026-08-29 15:59:23 -05:00
Josh Hawkins a572936d91 skip missing media paths in the per-boot ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins 208f606d5a clear the cached runtime ids when ownership tests finish 2026-08-29 15:59:23 -05:00
Josh Hawkins 0c366aeace own every directory level created for a recording segment 2026-08-29 15:59:23 -05:00
Josh Hawkins 9b089c4bcb document FRIGATE_ROOT_SERVICES 2026-08-29 15:59:23 -05:00
Josh Hawkins f873933aab assert granular root services in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins 576949f7c3 recommend FRIGATE_ROOT_SERVICES in the bandwidth stats warning 2026-08-29 15:59:23 -05:00
Josh Hawkins a2883a6509 chown the database files after init 2026-08-29 15:59:23 -05:00
Josh Hawkins 2f450ea661 chown recordings, previews, and exports to the runtime user at create 2026-08-29 15:59:23 -05:00
Josh Hawkins e8b2e06323 cache the runtime ids in the ownership helper 2026-08-29 15:59:23 -05:00
Josh Hawkins 903c59ff8c record the root-services mode in the sentinel and sweep small trees each boot 2026-08-29 15:59:23 -05:00
Josh Hawkins 9d3a38d234 let services listed in FRIGATE_ROOT_SERVICES skip the privilege drop 2026-08-29 15:59:23 -05:00
Josh Hawkins 53ffa72e28 validate FRIGATE_ROOT_SERVICES and fail fast on unknown names 2026-08-29 15:59:23 -05:00
Josh Hawkins dda3730a76 add a service-runs-as-root helper for granular root services 2026-08-29 15:59:23 -05:00
Josh Hawkins d2c9f18d49 collapse the duplicated sentinel comment 2026-08-29 15:59:23 -05:00
Josh Hawkins bc62eb4adc harden root writes into unprivileged-owned paths
Restrict the sweep sentinel to a mount at or below /media/frigate so a
parent /media mount cannot bless a later-shadowed volume. Rebuild
/tmp/nginx root-owned each start so root's cp and tempio writes cannot
follow a symlink an unprivileged nginx planted in the previous run.
2026-08-29 15:59:23 -05:00
Josh Hawkins 17b37a08a9 reload nginx by signaling the master instead of parsing its config as root 2026-08-29 15:59:23 -05:00
Josh Hawkins 2cd51a31a8 make bundled models readable by the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 93470c4ea5 hand /tmp/cache to the runtime user before services start 2026-08-29 15:59:23 -05:00
Josh Hawkins 9e356f1d3f skip lost+found during the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins 890cd751ae document network storage ownership and the remaining detector hardware 2026-08-29 15:59:23 -05:00
Josh Hawkins 69e30ac3b6 expand the non-root device access docs with diagnosis steps and udev rules 2026-08-29 15:59:23 -05:00
Josh Hawkins 11db4a2756 document EXTRA_GROUPS as the only device access path for dropped services 2026-08-29 15:59:23 -05:00
Josh Hawkins 7f175e1a17 report progress during the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins f776fffb9e unwrap hard-wrapped prose in the installation docs 2026-08-29 15:59:23 -05:00
Josh Hawkins e8987fc22c discard stdout for the unprivileged smoke nginx -t 2026-08-29 15:59:23 -05:00
Josh Hawkins 04bb2f4ed1 re-own the nginx shm cache on service restart 2026-08-29 15:59:23 -05:00
Josh Hawkins ab393c2cb2 run smoke nginx -t and the write probe as the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 1f68ba0cd4 set HOME to /config for non-root services 2026-08-29 15:59:23 -05:00
Josh Hawkins e7a0743ec0 chown the s6 log pipe so non-root nginx can reopen /dev/stdout 2026-08-29 15:59:23 -05:00
Josh Hawkins 8f5c441239 tolerate homekit config chown failures in the go2rtc run script 2026-08-29 15:59:23 -05:00
Josh Hawkins 8119bea0b3 only write the sweep sentinel when a media volume is mounted 2026-08-29 15:59:23 -05:00
Josh Hawkins b07e36237a Assert non-root services, JWT migration, and escape hatch in CI 2026-08-29 15:59:23 -05:00
Josh Hawkins 55a8672896 Create /media/frigate after the ownership sweep 2026-08-29 15:59:23 -05:00
Josh Hawkins cb5bfe1bd7 Document non-root operation and per-hardware device access 2026-08-29 15:59:23 -05:00
Josh Hawkins 944541f41c Hand TensorRT model cache ownership to the runtime user 2026-08-29 15:59:23 -05:00
Josh Hawkins 5d9f715c35 Disable bandwidth stats gracefully when not running as root 2026-08-29 15:59:23 -05:00
Josh Hawkins b7368197a2 Run nginx as the frigate user with writable state in /tmp/nginx 2026-08-29 15:59:23 -05:00
Josh Hawkins 7530590066 Run go2rtc as its own restricted user 2026-08-29 15:59:23 -05:00
Josh Hawkins 9ce146fd99 Run the frigate service as the frigate user 2026-08-29 15:59:23 -05:00
Josh HawkinsandGitHub a1fd978cab switch nginx-vod-module to the maintained dio-az fork (#24123)
The `v1.x` line is the same muxed fMP4 code as Kaltura's 1.31 with fixes backported, so the mapping JSON, manifest routes, and ffmpeg consumers are unchanged. The `MAX_CLIPS` patch applies as-is and the HEVC workaround is rewritten for the fork's reformatted source.

`vod_hls_version 6` is now explicit because the fork replaced Kaltura's automatic version calculation with a directive that defaults to 4 and only warns when fmp4 needs 6, so playlists were being stamped `EXT-X-VERSION:4` while carrying `EXT-X-MAP`. The `error_page 502 =404` hack is gone: https://github.com/kaltura/nginx-vod-module/issues/468 is a `vod_mode remote` bug and we're `mapped`, so those 502s were really `_vod_response` returning 404 upstream. The fork maps that through now, and the hack was also turning real 5xx into "no recordings".
2026-08-28 12:48:52 -06:00
Josh HawkinsandGitHub 5de5cee3c6 Fix LPR vehicle message for multiple models (#24119)
* use the camera's model for the lpr vehicle check

`FrigateConfig.model` became `models[]` in the detector refactor, so this didn't compile on 0.19. Each camera has its own detector/model pair now, so the check resolves the camera's scene with `getModelForCamera` instead of looking at every model.

* use camera config model

* fix export test
2026-08-28 12:26:05 -05:00
Josh Hawkins e99eb77ca1 Add Apple compatibility switch to the camera wizard (#24115)
* add apple compatibility switch to the camera wizard

* don't require every record stream to be h265
2026-08-27 20:30:36 -05:00
Josh Hawkins bb1e556ba9 Add onboarding wizard for new installations (#24102)
* add onboarding wizard for new users

* resolve hwaccel per camera and clarify recording retention

The hwaccel step listed every preset Frigate ships, so an Intel box was offered Raspberry Pi and Rockchip decoding, and the codec specific presets (`preset-intel-qsv-h264` vs `-h265`) were offered as global values that break as soon as two cameras use different codecs. `/hardware/hwaccel` now returns the decoding families the probed hardware can actually use, each carrying a preset per codec, and the wizard resolves the family against the detect stream codec the camera wizard already probed: one global `ffmpeg.hwaccel_args` when every camera agrees, per-camera `cameras.<name>.ffmpeg.hwaccel_args` when they don't. The global stays on `auto` in that case so cameras added later still resolve at startup. A gen13+ Intel machine keeps its QuickSync recommendation with mixed h264 and h265 cameras instead of dropping to vaapi.

The recording step's "Days to retain recordings" only wrote alert and detection retention, and the storage estimate under it assumed continuous recording. It now asks what to record in plain language, writes `record.continuous.days` to match, shows the estimate only for continuous, and drops the spinner arrows on the number input.

* clean up

* add light/dark mode icon switcher

* use yml as default config file extension when not found

* i18n tweaks

* gate the setup wizard on cameras instead of a config key

* render setup wizard steps by key

* share the setup wizard e2e helpers and mock users

* add an account step to the setup wizard

* add setup wizard account step e2e coverage

* cover the account step's restart behavior

* button consistency

* fix test

* docs

* fixes
2026-08-27 20:30:36 -05:00
Josh Hawkins 4f0c1b8ee7 Fix 500 when an event thumbnail file is empty (#24110)
* fix 500 when an event thumbnail file is empty

* fix test
2026-08-27 20:30:36 -05:00