api_add now forwards the chosen category to the daemon (and fixes a
use-after-free reading it from the freed request). Mark issues #3, #8, #9
done in ISSUES.md.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The daemon segfaulted the moment any torrent existed: map_torrent built
its JSON with one 30-key json_pack whose format string had drifted out of
sync with the argument list, so json_pack misread an int as a char* and
crashed in the next snapshot build (an empty fleet hid it). Rebuild the
object field-by-field with json_object_set_new so it can't drift again.
Add a web-layer category/tag store (in memory, like qBittorrent's own Web
API) so the UI can actually create categories and tags and assign them:
- /api/categories[/delete] and /api/tags[/delete] persist and return them
- /api/meta returns the stored categories/tags
- /api/action handles setCategory/addTags/removeTags (still 501 for
engine-level verbs the daemon can't do)
- map_torrent fills each torrent's category/tags from the store
Uploaded torrents kept their temp upload path as the display name; keep
the name the UI sends at add time and prefer it in the grid.
Fix a use-after-free in api_action that read the action string after
freeing the request, which corrupted the error body into a 500.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Address the review of the webui plugin:
- Live download rates. A background sampler polls the daemon once per
second, derives per-torrent dlspeed from successive byte counts (EWMA
smoothed), and computes a real ETA. dl_info_speed now aggregates the
fleet instead of reporting a hardcoded 0.
- Single shared snapshot. The sampler publishes one cached snapshot that
/api/snapshot, /api/torrents and every SSE stream serve, so N browser
tabs no longer each poll the engine and race the speed table. SSE
waiters block on a condition and wake promptly on shutdown.
- Honest /api/action. The engine has no pause/resume/recheck/queue verbs,
so the endpoint returns 501 with an explanatory message instead of
claiming success.
- Reject oversized uploads with 413 instead of silently truncating a
torrent into garbage.
- Auth hardening: constant-time credential comparison, CSPRNG-only token
generation via getrandom (fail closed, no weak fallback), oldest-session
eviction instead of clobbering slot 0, and a warning when bound to a
non-loopback address.
- Cap concurrent connections (503 beyond the limit) so a client can't
spawn unbounded threads.
- nautd: tear down plugins (joining the webui's threads) before freeing
torrent tasks, closing a shutdown-time use-after-free window where an
in-flight request could touch freed state.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Drop the web UI that was compiled into nautctl and serve the
torrent-ui front end (../torrent-ui/public) from a native plugin
(plugins/webui) loaded via `nautd --plugin`. The plugin talks to the
engine only through the host call_rpc ABI and adapts the daemon's RPC
surface to the qBittorrent-style contract the UI expects (snapshot/SSE,
torrent detail tabs, add/delete, cookie auth).
Also folds in the daemon refactor that owns per-torrent worker threads
and the swarm engine (naut_swarm) used by the plugin's data source.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a worked nautd scripting example that files each anime episode into a
media-server-friendly library the moment its file finishes verifying:
<SORTED_ROOT>/<Title>/Season NN/<Title> - SNNENN.<ext>
- examples/anitomy.lua: a compact, dependency-free reimplementation of Anitomy
(title/season/episode/release-group/resolution/year) in pure Lua — no
require/io/os, so it embeds in the sandbox.
- examples/anime_sort.lua: on_file_complete hook that parses the filename and
calls naut.move_file(); the embedded parser is a verbatim copy of anitomy.lua.
- examples/test_anitomy.lua, test_anime_sort.lua: parser battery + end-to-end
path-building test with an embedded-vs-module drift guard. Wired into ctest as
example_anitomy / example_anime_sort when a lua interpreter is present.
- docs: examples/README.md plus pointers from README and docs/scripting.md.
Verified end to end against a live nautd: file_complete -> move_file -> on-disk
relocate into the sorted tree.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>