Dockerfile: add postgresql-client and bake db-customization/ SQL scripts
into the image at /vnc/db-customization/.
config/migrate.sh: detection + migration script with two modes:
- pre-upgrade: runs idempotent prosody-13-new-deployment.sql on 13.0.x
databases; skips 0.11.6 (unsafe pre-upgrade) and new deployments.
- post-upgrade: waits for Prosody table, then runs the appropriate
scripts — full 0.11.6->13.0.6 migration (rules-triggers + migration-once
+ new-deployment) or idempotent drift correction for 13.0.x.
Helm chart: two Job templates (db-migration-pre-upgrade.yaml,
db-migration-post-upgrade.yaml) gated by dbMigration.enabled (default
true). Both reuse the Prosody image and DB credentials from existing
values. backoffLimit: 0, hook-delete-policy: hook-succeeded.
Also tracks the db-customization SQL files (previously untracked, now
referenced by the Dockerfile ADD).
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
Set PROSODY_DEBUG=true to switch the prosody.log level from info to
debug. This makes stanza-too-large rejections and XML parse errors
visible — both are logged at debug level and otherwise invisible.
Usage in k8s:
env:
- name: PROSODY_DEBUG
value: "true"
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
Add c2s_stanza_size_limit and s2s_stanza_size_limit to the config
template, backed by C2S_STANZA_SIZE_LIMIT and S2S_STANZA_SIZE_LIMIT
env vars. Both default to 5242880 (5MB) when unset, set in startup.sh.
The compose harness sets them explicitly.
Prosody 13.0.6 defaults are 256KB (c2s) and 512KB (s2s), which are too
small for large file-transfer invitations and Jitsi meet sessions.
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
Bump Dockerfile to prosody-13.0.6; all 8 patches re-ported against 13.0.6.
Re-ported patches (3 changed, 5 applied with offset):
- hidden.lib.patch: 13.0 uses module:may() instead of um_is_admin; changed
to 'if restrict_public then' (same intent: hide option for everyone)
- mod_muc.patch: 13.0 added restrict_pm between register and
presence_broadcast; updated hunk 1 context
- mod_muc_unique.patch: 13.0 uses 'require "prosody.util.stanza"'
(namespaced); updated context
- muc.lib, mod_carbons, mod_mam, mod_muc_mam, register.lib: applied
with line offsets, no re-port needed
Config changes:
- Remove mod_posix from modules_enabled (13.0 absorbed signal handling,
pidfile, and run_as_root check into core util/startup.lua)
- Move pubsub from modules_enabled to Component (13.0 requires pubsub
to be loaded as a component, not a module)
Test fix:
- test_muc_fcm_push_to_offline_member: wait for count=2 captures instead
of 1 — mod_vnc_muc_fcm pushes to ALL affiliated members (including
sender, because it can't see main-host sessions from the MUC
component); the test was racing on which push arrived first
Verified: prosodyctl check config passes; compose-harness testsuite
green (80 passed, 6 skipped, 0 failed).
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
Three changes to complete the repo-level work for Milestone 1 (0.11.6 →
0.12.6) plus a howto for the remaining manual/external tasks:
1. config/prosody.cfg.lua.template: re-add run_as_root = true. Production
and the compose harness run as root (startup.sh writes into root-owned
/etc/prosody/). Without it, mod_posix calls prosody.shutdown() during
startup, which deactivates c2s (port 5222) before the shutdown itself
errors out (prosody.main_thread is nil during module init), leaving
Prosody running without c2s.
2. tests/test_08_image_patches.py: replace 3 stale patch-marker entries
that checked for patches M1 intentionally dropped (moduleapi,
mod_admin_telnet, muc.lib dumpTable) with markers that verify their
config-based replacements (console_interfaces, http_interfaces) and
the storagemanager.open() rewrite in mod_vnc_muc_fcm.lua.
3. upgrade-plan.md: update M1 status to reflect the post-M1 fixes
(run_as_root, default_storage, stale tests), mark manual steps (DB
migration, telnet console regression, external testsuite) with
cross-references to m1-manual-tasks.md, and correct 0.12.5 → 0.12.6
throughout.
4. m1-manual-tasks.md: new file documenting the three manual tasks that
require external infrastructure — DB schema migration (one-way, with
rehearse-on-copy procedure), telnet console regression test (0.12
reimplemented the console on mod_admin_shell), and external testsuite
run against a dev deployment.
Verified: compose-harness testsuite — 80 passed, 5 skipped, 1 pre-existing
failure (test_vcard_fallback: mod_vnc_vcard_fallback not enabled in config,
unrelated to M1).
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
The M1 upgrade (0ea4d0a) removed default_storage = "sql" as seemingly
redundant with storage = "sql". However, the MUC component sets
storage = { muc_log = "sql" } (a table), and storagemanager.get_driver
falls back to default_storage (or "internal") for stores not listed in
the table. Without default_storage = "sql", the kick store on the MUC
component falls back to internal storage, whose archive driver requires
stanza objects — mod_vnc_track_kicks passes a plain string, causing
"unsupported-datatype" errors and kick data not being persisted.
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>
Re-port all source patches onto 0.12.6; three are gone entirely:
moduleapi (the two vnc_muc_fcm modules call core.storagemanager
directly now), mod_admin_telnet and portmanager (replaced by
console_interfaces/http_interfaces config). The muc.lib fork keeps its
four functional changes including the externally consumed
muc-config-sub-mitted event; the operator-precedence hunk was fixed
upstream. mod_muc_mam shrinks to keep-archive-on-room-destroy since
muc_log_expires_after="never" disables cleanup upstream in 0.12.
Delete the bundled mod_smacks fork and the no-op mod_smacks_offline;
core 0.12 smacks supersedes them (options audited, dead smacks_max_old
corrected to smacks_max_old_sessions).
Config/startup: drop legacyauth, run_as_root, daemonize; bosh_ports ->
http_ports; cross_domain_* -> http_cors_override; randomize
component_secret at startup (env-overridable); export
log_slow_events_threshold fallback (latent render bug).
Found while smoke-testing: pin --idn-library=idn (0.12's ICU default
segfaults without ICU data in the image); http became a private
service in 0.12 so 5280 needs http_interfaces to stay public; the
telnet console now depends on mod_admin_socket, whose socket moves to
/var/log/prosody.
Verified: prosodyctl check config clean; boots against Postgres with
empty error log and same port bindings as 0.11; healthcheck green;
telnet console and SQL storage round-trip; 0.11->0.12 schema upgrade
rehearsed on a 0.11-created database with data intact.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Part-of: <http://gitlab.vnc.biz/uxf/vnctalk-prosody/-/merge_requests/3>