The peer top-up loop re-announced to trackers only at the full advertised
interval (~30 min), so a torrent that dropped to a handful of peers would
sit there for up to half an hour with only the 5-minute DHT refresh to
help — looking like the re-announce system was dead.
Now, when fewer than LOW_PEER_THRESHOLD (10) peers are connected, the next
tracker announce is scheduled at the tracker's min_interval floor (never
below 60s) instead of the full interval, so a thin swarm actually tries to
recover. Once peers recover the full interval is used again. Capture the
tracker's min_interval (was being dropped) to stay announce-compliant.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move RSS persistence out of the daemon blob store and into the webui's
own SQLite DB (feeds, rules, indexers tables; articles + affectedFeeds
held as JSON columns). Remove the now-unused daemon blob store
(set/get_webui_blob, blob_lock, data_dir).
With this, all webui-owned state — accounts, taxonomy, RSS — lives in
the webui DB; the daemon only keeps naut's own data (per-torrent labels
still flow through set_labels for Lua).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the category + tag lists out of the daemon (labels.json + the
get/set_label_taxonomy RPCs) and into the webui's own SQLite DB
(categories, tags tables). The daemon no longer persists webui taxonomy;
per-torrent labels still flow through set_labels for Lua.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a real backend behind the RSS and Search tabs:
- nautd gains a generic web-UI blob store (set/get_webui_blob) so the
web layer can persist RSS feeds, auto-download rules and indexer
config under <state_dir>/webui_<key>.json.
- The webui plugin runs a background poller that fetches each feed over
HTTP(S), parses RSS 2.0 / Atom items (title, link, enclosure, size,
pubDate, magnet incl. torrent:magnetURI), dedupes, and stores articles.
- Auto-download rules (substring or POSIX regex, mustContain/
mustNotContain, per-feed scope) fire on newly-seen items and add the
torrent via the daemon — from a magnet, or by fetching a .torrent
enclosure and uploading its bytes — applying category/save path/paused.
- Search queries every enabled Torznab indexer and merges results
(name, size, seeders, leechers, magnet/.torrent), exposed as
searchPlugins in /api/meta.
New endpoints: GET/POST /api/rss(+/delete), /api/rss/rules(+/delete),
/api/indexers(+/delete), GET /api/search?q=.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A paused torrent never ran a worker, so it never verified on-disk data
and showed no progress. Add a one-shot check-only swarm mode (open +
resume scan + report, no peers/engine/download). The reconciler runs it
for a paused torrent flagged needs_check (set on paused-add and recheck);
the worker stays paused afterward. New TORRENT_CHECKING state -> webui
checkingDL/UP. Mark #11 done.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
spawn_torrent parses each torrent's file list (at add and restore) and
refuses an add whose files would write where a registered torrent's data
lives (NAUT_ERR_EXIST). Magnets are checked once metadata is known is
out of scope; restore skips the check. webui surfaces it as HTTP 409.
Mark #10 done.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
report_progress now fills peer_stats via engine_peer_list, so the peer
list (ip, progress, dl rate, state) shows again. Mark #12 done.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Address the review of the webui plugin:
- Live download rates. A background sampler polls the daemon once per
second, derives per-torrent dlspeed from successive byte counts (EWMA
smoothed), and computes a real ETA. dl_info_speed now aggregates the
fleet instead of reporting a hardcoded 0.
- Single shared snapshot. The sampler publishes one cached snapshot that
/api/snapshot, /api/torrents and every SSE stream serve, so N browser
tabs no longer each poll the engine and race the speed table. SSE
waiters block on a condition and wake promptly on shutdown.
- Honest /api/action. The engine has no pause/resume/recheck/queue verbs,
so the endpoint returns 501 with an explanatory message instead of
claiming success.
- Reject oversized uploads with 413 instead of silently truncating a
torrent into garbage.
- Auth hardening: constant-time credential comparison, CSPRNG-only token
generation via getrandom (fail closed, no weak fallback), oldest-session
eviction instead of clobbering slot 0, and a warning when bound to a
non-loopback address.
- Cap concurrent connections (503 beyond the limit) so a client can't
spawn unbounded threads.
- nautd: tear down plugins (joining the webui's threads) before freeing
torrent tasks, closing a shutdown-time use-after-free window where an
in-flight request could touch freed state.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Drop the web UI that was compiled into nautctl and serve the
torrent-ui front end (../torrent-ui/public) from a native plugin
(plugins/webui) loaded via `nautd --plugin`. The plugin talks to the
engine only through the host call_rpc ABI and adapts the daemon's RPC
surface to the qBittorrent-style contract the UI expects (snapshot/SSE,
torrent detail tabs, add/delete, cookie auth).
Also folds in the daemon refactor that owns per-torrent worker threads
and the swarm engine (naut_swarm) used by the plugin's data source.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>