Releases: snapetech/slskdN
Release list
🔋 slskdN 2026080512-slskdn.303 - The Batteries-Included Fork
slskdN 2026080512-slskdn.303
Released: 2026-08-05
Compare: 2026080501-slskdn.302...2026080512-slskdn.303
Highlights
-
Fixed API-key-only browser sessions showing
Disconnected. SignalR hub query
tokens are now promoted from configured API keys to scoped short-lived JWTs,
matching REST API-key authentication and restoring live application, search,
transfer, and log updates. -
Validated the release against a live kspls0 deployment: all 24 declared UI
routes returned 200, 143 rendered internal links loaded, SignalR negotiation
succeeded, no page errors occurred, and safe visible controls completed
without server 5xx responses. -
Wishlist auto-download now rechecks the persisted enablement and download
budget immediately before enqueueing ranked results, so disabling an item
during ranking cannot start a stale batch. -
The Auto-Replace control now explains that failed-download auto-retry is a
separate setting, so disabling one automation does not leave the other
ambiguous. -
Local-identity checks now exclude only immutable GitHub co-author trailers
while continuing to scan release-facing text and other commit content. -
Updated the NuGet dependency baseline, including AngleSharp, BouncyCastle,
AWS S3, API versioning, and SQLitePCLRaw. -
Stabilized the proof-of-storage allocation budget for shared CI runners while
retaining a bounded 4 KB-per-response regression check. -
Hardened the fragmented SOCKS test server so EOF and teardown close active
clients instead of hanging the backend test host. -
Patched transitive
brace-expansionpackages to 1.1.18 and 5.0.9 to close
the current high-severity resource-exhaustion advisories. -
Raised the frontend build and test Node.js baseline to 22.22.2, required by
the jsdom 30 dependency update. -
Empty
SLSKD_*environment variables are now ignored by the configuration
provider, allowing Docker and Unraid templates to expose blank optional
fields without overriding YAML/default values or causing Boolean binding
failures during startup. -
Audited the Unraid template: stale Pushbullet/proxy variable names were
corrected, and the shares media-attribute environment mapping no longer
duplicates theSLSKD_prefix. -
Unraid now keeps incomplete downloads under the writable
/app/incomplete
directory instead of overriding them to/downloads/incomplete, which may
not exist when only the/downloadshost share is mounted. -
Fixed Chromaprint extraction failing before ffmpeg started because redirected
stderr was accessed too early. Fingerprint processing now starts ffmpeg before
consuming redirected streams, preserves decoder diagnostics in the metadata
activity panel, and correctly reports custom absolute ffmpeg paths. -
Fixed HTTP/HTTPS antiforgery-cookie collisions. HTTPS now issues secure
antiforgery cookies, while the optional HTTP listener does not mint them when
HTTPS is enabled, so Firefox/LibreWolf no longer reject the HTTPS cookie after
visiting HTTP. HTTP-only deployments retain scheme-appropriate cookies. -
Antiforgery-cookie deletion now follows the request scheme, preserving secure
deletion for HTTPS responses without incorrectly adding theSecureflag to
HTTP-only responses. -
Fixed auto-replace requeueing user-cancelled downloads. Auto-replace now
handles only timeout, error, and peer-rejection states, and disabling it
cancels an active replacement cycle. Wishlist auto-download also normalizes
numeric duplicate suffixes and refuses peer directories with more than 50
unique tracks. -
Fixed API-key-only browser sessions showing
Disconnected. SignalR hub query
tokens are now promoted from configured API keys to scoped short-lived JWTs,
matching REST API-key authentication and restoring live application, search,
transfer, and log updates. -
CI now keeps its build version in
BUILD_VERSIONso MSBuild does not import
a release label from the environment as an invalidVersionproperty during
release-gate tests. -
Fixed unintended automatic downloads after cancellation. Auto-replace no
longer treats user-cancelled transfers as stuck, disabling it cancels an
active cycle, alternative searches retain release context and require all
identifying tokens, and Wishlist auto-download rejects peer directories
larger than 50 unique tracks while collapsing numeric duplicate suffixes. -
The vendored runtime patch now records the BouncyCastle 2.7.0 dependency
bump, keeping the dependency update reproducible under the runtime sync gate. -
The active council scanner now excludes dependency manifests and lockfiles,
so dependency-only updates do not perturb the durable security-candidate
counts or fail the remediation gate. -
Frontend unit tests now allow 15 seconds for lazy-loaded routes and large
jsdom trees on shared CI runners while retaining their existing assertions. -
Lazy-loaded search-route assertions now use the same 15-second async wait
budget instead of Testing Library's one-second default.
Source: docs/CHANGELOG.md section for 2026080512-slskdn.303.
🔋 slskdN 2026080501-slskdn.302 - The Batteries-Included Fork
slskdN 2026080501-slskdn.302
Released: 2026-08-05
Compare: 2026080415-slskdn.301...2026080501-slskdn.302
Highlights
- Fixed unintended automatic downloads: completed and user-cancelled transfers
are no longer treated as Auto-Replace candidates, disabling Auto-Replace
cancels its active replacement cycle, and alternative searches retain
release context while requiring every identifying token. - Rechecked persisted Wishlist enablement and download budgets immediately
before enqueueing ranked results, normalized numeric duplicate suffixes such
as(1)and(2), and capped automatic peer-directory downloads at 50
unique tracks. - Added a bounded low-result Soulseek fallback through a registry of known
server-suppressed terms while keeping manual, Auto-Replace, and mesh queries
exact or raw as appropriate. - Clarified in the Transfers UI that Auto-Replace and failed-download
Auto-Retry are separate controls. - Updated frontend dependencies, including TypeScript 7, jsdom 30,
@testing-library/jest-dom7, undici 7.29, PostCSS 8.5.25, and the grouped
npm updates; updated the grouped NuGet baseline as well. - Raised the frontend and release workflow Node.js baseline to 22.22.2 and
kept the CI build label isolated inBUILD_VERSIONso MSBuild cannot read it
as an invalid application version. - Patched all locked
brace-expansionpaths to 1.1.18 or 5.0.9 to address the
current high-severity resource-exhaustion advisories. - Stabilized shared-runner proof-of-storage allocation assertions and
hardened the fragmented SOCKS test server so EOF and teardown close active
clients instead of hanging the backend test host.
Source: docs/CHANGELOG.md section for 2026080501-slskdn.302.
🔋 slskdN 2026080415-slskdn.299 - The Batteries-Included Fork
slskdN 2026080415-slskdn.299
Released: 2026-08-04
Compare: 2026080320-slskdn.298...2026080415-slskdn.299
Highlights
- Wishlist/Lidarr searches now keep the exact Soulseek query first and, only for
low-result Wishlist searches, try up to two sequential leading-artist-term
variants to recover operator-suppressed terms without broadening manual or
auto-replace searches; mesh searches continue to receive the raw query.
Source: docs/CHANGELOG.md section for 2026080415-slskdn.299.
🔋 slskdN 2026080320-slskdn.298 - The Batteries-Included Fork
slskdN 2026080320-slskdn.298
Released: 2026-08-03
Compare: 2026080316-slskdn.297...2026080320-slskdn.298
Highlights
- Wishlist filters now preserve structured multi-format/bitrate alternatives
such asmp3 minbr:320 OR aac minbr:256 OR m4a minbr:256, apply exclusions
globally, reject unknown metadata for strict bitrate branches, and rank
same-branch alternatives by the actual file extension. - Wishlist auto-download now deduplicates track copies, prefers album coverage
within the requested limit, and ranks lossless/lossy formats with codec-aware
quality instead of raw bitrate alone. Mesh bitrate metadata remains nullable,
truthful, and is never fabricated. - Wishlist bulk filter edits now use one atomic backend operation, preserving
all other row fields and rolling back when any selected ID is missing. - Lidarr quality-profile mapping now handles multiple allowed formats, broad
Lossless/Any profiles, and ignores sample-rate/bit-depth numbers as bitrates;
explicitAny/Allprofiles override the configured fallback. Both manual
import panels report candidate counts and explicit disabled/skipped reasons
while retaining clean-candidate safety checks.
Source: docs/CHANGELOG.md section for 2026080320-slskdn.298.
🔋 slskdN 2026080316-slskdn.297 - The Batteries-Included Fork
slskdN 2026080316-slskdn.297
Released: 2026-08-03
Compare: 2026080315-slskdn.296...2026080316-slskdn.297
Highlights
- Mesh search now has explicit regression coverage and documentation ensuring
Soulseek server/operator term suppression and incoming-request filters do not
remove mesh results; mesh merging remains limited to duplicate detection. - Integration YAML saves no longer serialize an empty required MusicBrainz
user-agent, so a fresh or partially populated configuration can be saved. - Auto-retry and auto-replace now retain request-level retry budgets across
restarts, carry stable request identity across alternate sources, and record
no-alternative replacement cycles so old failed rows cannot loop forever.
Source: docs/CHANGELOG.md section for 2026080316-slskdn.297.
🔋 slskdN 2026080315-slskdn.296 - The Batteries-Included Fork
slskdN 2026080315-slskdn.296
Released: 2026-08-03
Compare: 2026080115-slskdn.295...2026080315-slskdn.296
Highlights
- Lidarr Wishlist synchronization now derives per-entry audio filters from
Lidarr quality profiles, so artist-specific format choices such as MP3-only
are respected instead of falling back to one global format. - Partial Lidarr albums now reconcile missing tracks individually, persist
album and track identity across syncs, and bound automatic Wishlist enqueue
work to one file per missing-track target instead of repeating a full-album
search. - Unraid Community Applications metadata now includes the required repository
profile, fork-owned links, safer user-selected share paths, and package
smoke validation for the template and profile.
Source: docs/CHANGELOG.md section for 2026080315-slskdn.296.
🔋 slskdN 2026080115-slskdn.295 - The Batteries-Included Fork
slskdN 2026080115-slskdn.295
Released: 2026-08-01
Compare: 2026080114-slskdn.294...2026080115-slskdn.295
Highlights
- Gold Star Club is now strictly opt-in: reserved-pod creation, DHT
publication, and automatic enrollment requirefeature.Pods: trueplus the
exact daemon environment value
SLSKDN_POD_GOLD_STAR_CLUB_AUTOJOIN=true. Unset, malformed, and non-true
values leave it dormant.
Source: docs/CHANGELOG.md section for 2026080115-slskdn.295.
🔋 slskdN 2026080114-slskdn.294 - The Batteries-Included Fork
slskdN 2026080114-slskdn.294
Released: 2026-08-01
Compare: 2026073117-slskdn.293...2026080114-slskdn.294
Highlights
- Refreshed the release-council source inventory after the documentation update
changed the tracked red-team and public-mutable-surface counts. - Clarified public BitTorrent DHT rendezvous, mesh-DHT metadata, and mesh
overlay transfer boundaries throughout user, architecture, research, and
packaging documentation without changing the enabled-by-default DHT policy. - Networked experimental feature defaults remain enabled, while explicit
disable settings now gate hosted services as well as APIs. Disabled
mesh/DHT/pod/VirtualSoulfind settings no
longer publish descriptors, register mesh RPCs, create or auto-join Gold
Star, start mDNS, or wait for disabled DHT initialization. - The shipped YAML template now preserves intended indentation when operators
remove one comment marker, preventing misleadingexpected <document end>
errors when enabled sections are followed by additional root keys. - PPA workflows now serialize uploads per Ubuntu series and wait for the exact
source, binary build, and published binary records, preventing a later source
upload from superseding a package whose binary is still being processed. - Guided System configuration editors now emit bindable YAML for AcoustID,
MusicBrainz, YouTube, Last.fm, transfer schedules, search retention, and
feature flags instead of failing validation when those settings are saved. - Setup Health now reads the live Soulseek connection, integration, and API-key
state contracts instead of falsely reporting a connected node as offline or
overlooking configured provider and automation credentials. - Less, Vite, System.Reactive, .NET servicing packages, telemetry, SQLite, and
parser dependencies are updated together with aligned test-project references
so clean solution restore remains downgrade-free. TypeScript remains on the
compatible 6.x line because 7.x is not yet supported by the current lint
parser stack. - Configured download destinations now work end to end. The folder marked
defaultgoverns automatic and destination-less downloads, and Search
Results plus Browse provide a persistent Download to selector for normal
and bridged downloads. - The process-lifetime Pods mesh adapter now resolves scoped messaging storage
per operation, so application startup succeeds with dependency scope
validation enabled. - Adversarial security status now resolves the registered anonymity transport
selector, while the disabled Web UI avoids unnecessary Tor and transport
probes that previously produced 404 and 503 browser errors. - Download shutdown now takes exclusive ownership of each cancellation source
before cancelling and disposing it, preventing transfer cleanup from racing
service disposal with anObjectDisposedException. - Chat, Rooms, System Files, adversarial security settings, and VPN gateway
settings now render their persistent tab content instead of showing only the
tab menu. - Search result pages now explain that folder-ignore rules belong to one
wishlist item and show where to apply them. Valid Soulseek usernames
containing adjacent dots no longer trigger path-traversal violations or
auto-ban the Web client. - Transfer database migrations now converge instead of repeatedly recreating
and dropping a superseded index. Expected remote upload disconnects produce
one concise warning and briefly cool down retries from that peer, preventing
repeated failure work and log amplification on small hosts. Expired peer
cooldowns are evicted automatically instead of retaining one-time peers for
the process lifetime. - Forced VirtualSoulfind disaster mode now starts the coordinator in full
fallback instead of exposing the configured override without applying it. - Release gates now fail unconditionally when a command exceeds its timeout,
streaming pipe regressions dispose their leases on every assertion path, and
COPR uploads retry bounded transient API failures using the verified SRPM
artifact path while preferring configured API-token credentials over GSSAPI
fallbacks. - Listener IP and port changes no longer report a reconnect requirement after
Soulseek.NET has already rebound the live listeners and advertised the new
endpoint to the Soulseek server. - Live Soulseek listener changes now apply updated type-1 obfuscation options
before rebinding, keeping the obfuscated socket and advertised metadata on
the configured port instead of the previous one. - Adversarial security settings now resolve from their registered options
wrapper, invalid obfuscation advertisement combinations fail during options
validation, and unexpected fatal Web startup errors exit unsuccessfully. - Watched root options now retain a validated value when a replacement fails
validation or binding, including an invalid first reload, and still notify
subscribers after a later valid replacement. - Fractional download auto-retry tolerance values are validated against their
exact double range; blacklist and search-filter regex compilation consistently
honor the configured case mode across cache entries and reloads. - API YAML validation now applies the documented
transfers.groups
compatibility layout with top-level precedence and full nested validation. - The AngleSharp runtime inherited through dotNetRDF is pinned to patched
version1.5.0instead of the vulnerable transitive1.4.0resolution. - MediaCore workflow index links now retain the active
/system/mediacore
route when jumping to a workflow panel instead of resolving fragment targets
against the document base and leaving the page. - API-key authentication now runs before global rate-limit partitioning, so
authenticated callers bypass anonymous API quotas as intended. Kestrel
request-body limit failures now return redacted 413 Problem Details. - Runtime CORS edits now set application
pendingRestartstate because the
policy is constructed from startup options; strict startup validation still
rejects credentialed wildcard CORS whenweb.enforce_securityis enabled. - Live Web validation now has a repeatable authenticated Chromium audit across
all top-level routes, System tabs, runtime-discovered internal links,
external-link reachability, browser/network errors, visible error states,
screenshots, control names, and active-tab visibility measured against the
actual horizontal scroll viewport. - Search and Lidarr pagination, Lidarr refresh, user browsing, wishlist
pagination and view modes, transfer-column selection, and media-server
provider controls now expose clear accessible names and mouseover help.
Media-server selectors use the adapters' real labels instead of rendering
blank, and direct navigation automatically reveals later System tabs inside
the overflowing tab strip. - Release council backlog validation now regenerates its derived report on
every run and scans only Git-tracked repository roots. Local ignored reports,
dependency trees, build outputs, and optional directories can no longer make
a developer checkout pass counts that fail in the clean tag checkout. - The web footer and README now offer direct PayPal and Ko-fi links for
supporting slskdN development. - Mesh DHT interoperability now uses one frozen 20-byte key/node contract,
performs bounded iterativeFIND_VALUElookups after local misses, and binds
signed STORE requester IDs and admission state to the Ed25519 signing key
without assuming that a Soulseek/overlay username uses the same identity
scheme. Canonical JSON signing and MessagePack shard vectors freeze the
cross-runtime wire shapes. Pod, shadow-index, private-gateway, and
introspection mesh handlers are registered with the live router; shadow-index
publication and reads use the distributed client and preserve bounded full
peer hints while rejecting legacy non-routable hints. - Private-gateway tunnels now connect directly to one of the IP addresses that
passed DNS policy validation instead of resolving the hostname again, compare
normalized connected addresses to the approved set, and use the node's real
profile identity for gateway authorization and forwarding. This closes the
DNS time-of-check/time-of-use gap while retaining bounded policy checks. - Pod message sends now report success after durable persistence even when the
immediate best-effort route fails, preventing callers from duplicating an
already-stored message while later delivery remains available. - UTF-8 Base64 string conversion now writes common inputs into stack storage and
oversized inputs into cleared pooled storage, with decoding performed directly
into the same bounded storage. Across 100,000 calls, encoding allocation falls
from 15,200,040 to 9,600,040 bytes (36.8%) while remaining at 7 ms; decoding
allocation falls from 12,800,608 to 7,200,608 bytes (43.8%) while remaining at
6 ms. Exact framework output, whitespace handling, invalid UTF-8 replacement,
malformed Base64 exceptions, null rejection, empty input, Unicode, malformed
surrogates, and oversized pooled inputs remain unchanged. SecurityUtilssalted hashing now hashes combined stack or cleared pooled
input directly into a caller-provided SHA-256 destination, boolean verification
keeps that digest on the stack, and double SHA-256 keeps its first digest in a
fixed span. Across 100,000 calls, public salted-hash allocation falls from
29,601,072 to 5,600,848 bytes (81.1%) and elapsed time falls from 58 to 30 ms
(48.3%); double-hash allocation falls from 40,800,416 to 5,600,192 bytes
(86.3%) and elapsed time falls from 87 to 60 ms (31.0%). After the public hash
optimization, boolean verification removes its remaining result arrays,
falling from 5,600,632 to 64 byt...
🔋 slskdN 2026073117-slskdn.293 - The Batteries-Included Fork
slskdN 2026073117-slskdn.293
Released: 2026-07-31
Compare: 2026072717-slskdn.292...2026073117-slskdn.293
Highlights
- Added first-class self-hosted relay mode for CGNAT deployments. A bounded
Tailscale or WireGuard VPS companion now provides authenticated public-IP and
port discovery, automatic TCP forwarding and outbound routing, fail-closed
liveness, key rotation, connection and bandwidth caps, and relay diagnostics
while all files, configuration, credentials, and management remain at home.
Tailscale mode uses the existing tailnet directly, pins forwarding to the
exact home node, reports direct or DERP path state, and supports an exit node
scoped to the slskdN Docker namespace. - Added linked operator and tester documentation covering released companion
installation, OCI and home-sidecar setup, kernel-mode Tailscale routing,
private API and firewall boundaries, external ingress checks, fail-closed
validation, and safe diagnostic evidence collection. No second WireGuard
tunnel or remote slskdN instance is required for the Tailscale path. - Repaired and standardized all historical GitHub release notes, and added
local plus hosted fail-closed validation requiring informative exact-version
changelog highlights before future stable releases can be tagged or published.
Source: docs/CHANGELOG.md section for 2026073117-slskdn.293.
🔋 slskdN 2026072717-slskdn.292 - The Batteries-Included Fork
slskdN 2026072717-slskdn.292
Released: 2026-07-27
Compare: 2026072716-slskdn.291...2026072717-slskdn.292
Highlights
- Added opt-in Lidarr rejection cleanup that deletes only exact rejected files,
plus exact Wishlist item/peer/release-directory suppression so rejected
automatic acquisitions are not selected repeatedly. - Added live and bounded recent HashDb, Chromaprint, AcoustID, MusicBrainz, and
auto-tagging processing activity to System Integrations without exposing full
local paths or raw fingerprints.
Source: docs/CHANGELOG.md section for 2026072717-slskdn.292.