updates.py 18 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552
  1. """Update checking and management routes."""
  2. import asyncio
  3. import logging
  4. import os
  5. import re
  6. import shutil
  7. import sys
  8. import httpx
  9. from fastapi import APIRouter, BackgroundTasks, Depends
  10. from sqlalchemy import select
  11. from sqlalchemy.ext.asyncio import AsyncSession
  12. from backend.app.core.auth import RequirePermissionIfAuthEnabled
  13. from backend.app.core.config import APP_VERSION, GITHUB_REPO, settings
  14. from backend.app.core.database import get_db
  15. from backend.app.core.permissions import Permission
  16. from backend.app.models.settings import Settings
  17. from backend.app.models.user import User
  18. logger = logging.getLogger(__name__)
  19. router = APIRouter(prefix="/updates", tags=["updates"])
  20. # Global state for update progress
  21. _update_status = {
  22. "status": "idle", # idle, checking, downloading, installing, complete, error
  23. "progress": 0,
  24. "message": "",
  25. "error": None,
  26. }
  27. def _is_docker_environment() -> bool:
  28. """Detect if running inside a Docker container."""
  29. if os.path.exists("/.dockerenv"):
  30. return True
  31. try:
  32. with open("/proc/1/cgroup") as f:
  33. if "docker" in f.read():
  34. return True
  35. except (FileNotFoundError, PermissionError):
  36. pass # cgroup file unavailable; continue with other detection methods
  37. # Check container runtime hint (systemd sets this for Docker/podman,
  38. # but NOT for LXC/LXD — avoids false positives on Proxmox containers)
  39. try:
  40. with open("/run/systemd/container") as f:
  41. runtime = f.read().strip()
  42. if runtime in ("docker", "podman", "oci"):
  43. return True
  44. except (FileNotFoundError, PermissionError):
  45. pass
  46. return False
  47. def _find_executable(name: str) -> str | None:
  48. """Find an executable in PATH or common locations."""
  49. # Try standard PATH first
  50. path = shutil.which(name)
  51. if path:
  52. return path
  53. # Common locations for executables (useful when running as systemd service)
  54. common_paths = [
  55. f"/usr/bin/{name}",
  56. f"/usr/local/bin/{name}",
  57. f"/opt/homebrew/bin/{name}",
  58. f"/home/linuxbrew/.linuxbrew/bin/{name}",
  59. f"{os.path.expanduser('~')}/.nvm/current/bin/{name}",
  60. f"{os.path.expanduser('~')}/.local/bin/{name}",
  61. ]
  62. for p in common_paths:
  63. if os.path.isfile(p) and os.access(p, os.X_OK):
  64. return p
  65. return None
  66. def parse_version(version: str) -> tuple:
  67. """Parse version string into tuple for comparison.
  68. Returns (major, minor, patch, micro, is_prerelease, prerelease_num)
  69. where is_prerelease is 0 for release, 1 for prerelease.
  70. This ensures releases sort higher than prereleases of same version.
  71. Examples:
  72. "0.1.5" -> (0, 1, 5, 0, 0, 0) # release
  73. "0.1.5b7" -> (0, 1, 5, 0, 1, 7) # beta 7
  74. "0.1.5b10" -> (0, 1, 5, 0, 1, 10) # beta 10
  75. "0.1.8.1" -> (0, 1, 8, 1, 0, 0) # patch release
  76. """
  77. # Remove 'v' prefix if present
  78. version = version.lstrip("v")
  79. # Strip daily build suffix (e.g., "0.2.2b4-daily.20260313" -> "0.2.2b4")
  80. version = re.sub(r"-daily\.\d+$", "", version)
  81. # Match version pattern: major.minor.patch[.micro][b|beta|alpha|rc]N
  82. match = re.match(r"(\d+)\.(\d+)\.(\d+)(?:\.(\d+))?(?:b|beta|alpha|rc)?(\d+)?", version)
  83. if match:
  84. major = int(match.group(1))
  85. minor = int(match.group(2))
  86. patch = int(match.group(3))
  87. micro = int(match.group(4)) if match.group(4) else 0
  88. prerelease_num = int(match.group(5)) if match.group(5) else 0
  89. # Check if this is a prerelease (has b/beta/alpha/rc/daily suffix anywhere)
  90. is_prerelease = 1 if re.search(r"[a-zA-Z]", version) else 0
  91. return (major, minor, patch, micro, is_prerelease, prerelease_num)
  92. # Fallback: try simple split
  93. parts = []
  94. for part in version.split("."):
  95. try:
  96. parts.append(int(part))
  97. except ValueError:
  98. num = "".join(c for c in part if c.isdigit())
  99. parts.append(int(num) if num else 0)
  100. return tuple(parts) + (0, 0, 0)
  101. def is_newer_version(latest: str, current: str) -> bool:
  102. """Check if latest version is newer than current.
  103. Properly handles prerelease versions:
  104. - 0.1.5 > 0.1.5b7 (release is newer than any beta)
  105. - 0.1.5b8 > 0.1.5b7 (later beta is newer)
  106. - 0.1.6b1 > 0.1.5 (next version beta is newer than current release)
  107. """
  108. try:
  109. latest_parsed = parse_version(latest)
  110. current_parsed = parse_version(current)
  111. # Compare (major, minor, patch, micro) first
  112. latest_base = latest_parsed[:4]
  113. current_base = current_parsed[:4]
  114. if latest_base > current_base:
  115. return True
  116. elif latest_base < current_base:
  117. return False
  118. # Same base version - compare prerelease status
  119. # is_prerelease: 0 = release, 1 = prerelease
  120. # Release (0) should be "greater" than prerelease (1)
  121. latest_is_prerelease = latest_parsed[4] if len(latest_parsed) > 4 else 0
  122. current_is_prerelease = current_parsed[4] if len(current_parsed) > 4 else 0
  123. if latest_is_prerelease < current_is_prerelease:
  124. # latest is release, current is prerelease -> latest is newer
  125. return True
  126. elif latest_is_prerelease > current_is_prerelease:
  127. # latest is prerelease, current is release -> latest is NOT newer
  128. return False
  129. # Both are same type (both release or both prerelease)
  130. # Compare prerelease numbers
  131. latest_prerelease_num = latest_parsed[5] if len(latest_parsed) > 5 else 0
  132. current_prerelease_num = current_parsed[5] if len(current_parsed) > 5 else 0
  133. return latest_prerelease_num > current_prerelease_num
  134. except Exception:
  135. return False
  136. @router.get("/version")
  137. async def get_version():
  138. """Get current application version.
  139. Note: Unauthenticated - needed to display version in UI without login.
  140. """
  141. return {
  142. "version": APP_VERSION,
  143. "repo": GITHUB_REPO,
  144. }
  145. @router.get("/check")
  146. async def check_for_updates(
  147. db: AsyncSession = Depends(get_db),
  148. _: User | None = RequirePermissionIfAuthEnabled(Permission.SYSTEM_READ),
  149. ):
  150. """Check GitHub for available updates."""
  151. global _update_status
  152. # Respect the check_updates setting
  153. result = await db.execute(select(Settings).where(Settings.key == "check_updates"))
  154. setting = result.scalar_one_or_none()
  155. if setting and setting.value.lower() == "false":
  156. return {
  157. "update_available": False,
  158. "current_version": APP_VERSION,
  159. "latest_version": None,
  160. "message": "Update checks are disabled",
  161. }
  162. # Check if beta updates should be included
  163. result = await db.execute(select(Settings).where(Settings.key == "include_beta_updates"))
  164. beta_setting = result.scalar_one_or_none()
  165. include_beta = beta_setting and beta_setting.value.lower() == "true"
  166. _update_status = {
  167. "status": "checking",
  168. "progress": 0,
  169. "message": "Checking for updates...",
  170. "error": None,
  171. }
  172. try:
  173. async with httpx.AsyncClient() as client:
  174. response = await client.get(
  175. f"https://api.github.com/repos/{GITHUB_REPO}/releases?per_page=20",
  176. headers={"Accept": "application/vnd.github.v3+json"},
  177. timeout=10.0,
  178. )
  179. if response.status_code == 404:
  180. # No releases yet
  181. _update_status = {
  182. "status": "idle",
  183. "progress": 100,
  184. "message": "No releases found",
  185. "error": None,
  186. }
  187. return {
  188. "update_available": False,
  189. "current_version": APP_VERSION,
  190. "latest_version": None,
  191. "message": "No releases found",
  192. }
  193. response.raise_for_status()
  194. releases = response.json()
  195. # Find the appropriate release based on beta setting
  196. release_data = None
  197. for release in releases:
  198. tag = release.get("tag_name", "")
  199. if include_beta:
  200. # Accept any release (first = newest)
  201. release_data = release
  202. break
  203. else:
  204. # Skip prereleases (based on version parsing, not GitHub flag)
  205. parsed = parse_version(tag)
  206. if parsed[4] == 0: # is_prerelease == 0
  207. release_data = release
  208. break
  209. if not release_data:
  210. _update_status = {
  211. "status": "idle",
  212. "progress": 100,
  213. "message": "No releases found",
  214. "error": None,
  215. }
  216. return {
  217. "update_available": False,
  218. "current_version": APP_VERSION,
  219. "latest_version": None,
  220. "message": "No releases found",
  221. }
  222. latest_version = release_data.get("tag_name", "").lstrip("v")
  223. release_name = release_data.get("name", latest_version)
  224. release_notes = release_data.get("body", "")
  225. release_url = release_data.get("html_url", "")
  226. published_at = release_data.get("published_at", "")
  227. update_available = is_newer_version(latest_version, APP_VERSION)
  228. _update_status = {
  229. "status": "idle",
  230. "progress": 100,
  231. "message": "Update available" if update_available else "Up to date",
  232. "error": None,
  233. }
  234. is_docker = _is_docker_environment()
  235. return {
  236. "update_available": update_available,
  237. "current_version": APP_VERSION,
  238. "latest_version": latest_version,
  239. "release_name": release_name,
  240. "release_notes": release_notes,
  241. "release_url": release_url,
  242. "published_at": published_at,
  243. "is_docker": is_docker,
  244. "update_method": "docker" if is_docker else "git",
  245. }
  246. except httpx.HTTPError as e:
  247. logger.error("Failed to check for updates: %s", e)
  248. _update_status = {
  249. "status": "error",
  250. "progress": 0,
  251. "message": "Failed to check for updates",
  252. "error": "Failed to check for updates",
  253. }
  254. return {
  255. "update_available": False,
  256. "current_version": APP_VERSION,
  257. "latest_version": None,
  258. "error": "Failed to check for updates",
  259. }
  260. async def _perform_update():
  261. """Perform the actual update using git fetch and reset."""
  262. global _update_status
  263. try:
  264. base_dir = settings.base_dir
  265. # Find git executable (may not be in PATH when running as systemd service)
  266. git_path = _find_executable("git")
  267. if not git_path:
  268. _update_status = {
  269. "status": "error",
  270. "progress": 0,
  271. "message": "Git not found",
  272. "error": "Could not find git executable. Please ensure git is installed.",
  273. }
  274. return
  275. logger.info("Using git at: %s", git_path)
  276. # Git config to avoid safe.directory issues
  277. git_config = ["-c", f"safe.directory={base_dir}"]
  278. _update_status = {
  279. "status": "downloading",
  280. "progress": 10,
  281. "message": "Configuring git...",
  282. "error": None,
  283. }
  284. # Ensure remote uses HTTPS (SSH may not be available)
  285. https_url = f"https://github.com/{GITHUB_REPO}.git"
  286. process = await asyncio.create_subprocess_exec(
  287. git_path,
  288. *git_config,
  289. "remote",
  290. "set-url",
  291. "origin",
  292. https_url,
  293. cwd=str(base_dir),
  294. stdout=asyncio.subprocess.PIPE,
  295. stderr=asyncio.subprocess.PIPE,
  296. )
  297. await process.communicate()
  298. _update_status = {
  299. "status": "downloading",
  300. "progress": 20,
  301. "message": "Fetching latest changes...",
  302. "error": None,
  303. }
  304. # Fetch from origin
  305. process = await asyncio.create_subprocess_exec(
  306. git_path,
  307. *git_config,
  308. "fetch",
  309. "origin",
  310. "main",
  311. cwd=str(base_dir),
  312. stdout=asyncio.subprocess.PIPE,
  313. stderr=asyncio.subprocess.PIPE,
  314. )
  315. stdout, stderr = await process.communicate()
  316. if process.returncode != 0:
  317. error_msg = stderr.decode() if stderr else "Git fetch failed"
  318. logger.error("Git fetch failed: %s", error_msg)
  319. _update_status = {
  320. "status": "error",
  321. "progress": 0,
  322. "message": "Failed to fetch updates",
  323. "error": error_msg,
  324. }
  325. return
  326. _update_status = {
  327. "status": "downloading",
  328. "progress": 40,
  329. "message": "Applying updates...",
  330. "error": None,
  331. }
  332. # Hard reset to origin/main (clean update, no merge conflicts)
  333. process = await asyncio.create_subprocess_exec(
  334. git_path,
  335. *git_config,
  336. "reset",
  337. "--hard",
  338. "origin/main",
  339. cwd=str(base_dir),
  340. stdout=asyncio.subprocess.PIPE,
  341. stderr=asyncio.subprocess.PIPE,
  342. )
  343. stdout, stderr = await process.communicate()
  344. if process.returncode != 0:
  345. error_msg = stderr.decode() if stderr else "Git reset failed"
  346. logger.error("Git reset failed: %s", error_msg)
  347. _update_status = {
  348. "status": "error",
  349. "progress": 0,
  350. "message": "Failed to apply updates",
  351. "error": error_msg,
  352. }
  353. return
  354. _update_status = {
  355. "status": "installing",
  356. "progress": 50,
  357. "message": "Installing dependencies...",
  358. "error": None,
  359. }
  360. # Install Python dependencies
  361. process = await asyncio.create_subprocess_exec(
  362. sys.executable,
  363. "-m",
  364. "pip",
  365. "install",
  366. "-r",
  367. "requirements.txt",
  368. "-q",
  369. cwd=str(base_dir),
  370. stdout=asyncio.subprocess.PIPE,
  371. stderr=asyncio.subprocess.PIPE,
  372. )
  373. stdout, stderr = await process.communicate()
  374. if process.returncode != 0:
  375. logger.warning("pip install warning: %s", stderr.decode() if stderr else "unknown")
  376. # Try to build frontend if npm is available (optional - static files are pre-built)
  377. npm_path = _find_executable("npm")
  378. frontend_dir = base_dir / "frontend"
  379. if npm_path and frontend_dir.exists():
  380. _update_status = {
  381. "status": "installing",
  382. "progress": 70,
  383. "message": "Building frontend...",
  384. "error": None,
  385. }
  386. # npm install
  387. process = await asyncio.create_subprocess_exec(
  388. npm_path,
  389. "install",
  390. cwd=str(frontend_dir),
  391. stdout=asyncio.subprocess.PIPE,
  392. stderr=asyncio.subprocess.PIPE,
  393. )
  394. await process.communicate()
  395. # npm run build
  396. process = await asyncio.create_subprocess_exec(
  397. npm_path,
  398. "run",
  399. "build",
  400. cwd=str(frontend_dir),
  401. stdout=asyncio.subprocess.PIPE,
  402. stderr=asyncio.subprocess.PIPE,
  403. )
  404. stdout, stderr = await process.communicate()
  405. if process.returncode != 0:
  406. logger.warning("Frontend build warning: %s", stderr.decode() if stderr else "unknown")
  407. else:
  408. logger.info("npm not found or frontend dir missing - using pre-built static files")
  409. _update_status = {
  410. "status": "complete",
  411. "progress": 100,
  412. "message": "Update complete! Please restart the application.",
  413. "error": None,
  414. }
  415. logger.info("Update completed successfully")
  416. except Exception as e:
  417. logger.error("Update failed: %s", e)
  418. _update_status = {
  419. "status": "error",
  420. "progress": 0,
  421. "message": "Update failed",
  422. "error": "Update failed unexpectedly",
  423. }
  424. @router.post("/apply")
  425. async def apply_update(
  426. background_tasks: BackgroundTasks,
  427. _: User | None = RequirePermissionIfAuthEnabled(Permission.SETTINGS_UPDATE),
  428. ):
  429. """Apply available update (git pull + rebuild)."""
  430. global _update_status
  431. if _update_status["status"] in ["downloading", "installing"]:
  432. return {
  433. "success": False,
  434. "message": "Update already in progress",
  435. "status": _update_status,
  436. }
  437. # Check if running in Docker
  438. if _is_docker_environment():
  439. return {
  440. "success": False,
  441. "is_docker": True,
  442. "message": (
  443. "Docker installations cannot be updated in-app. "
  444. "Please update via Docker Compose: "
  445. "git pull && docker compose build --pull && docker compose up -d"
  446. ),
  447. }
  448. # Start update in background
  449. background_tasks.add_task(_perform_update)
  450. _update_status = {
  451. "status": "downloading",
  452. "progress": 10,
  453. "message": "Starting update...",
  454. "error": None,
  455. }
  456. return {
  457. "success": True,
  458. "message": "Update started",
  459. "status": _update_status,
  460. }
  461. @router.get("/status")
  462. async def get_update_status(
  463. _: User | None = RequirePermissionIfAuthEnabled(Permission.SYSTEM_READ),
  464. ):
  465. """Get current update status."""
  466. return _update_status