Go: - staticcheck 399 -> 0 with staticcheck.conf (style checks ST1000/1003/ 1005/1016/1020/1021/1022 excluded; error strings are shown in the UI). - io/ioutil and rand.Seed removed; CloseNotifier kept with a lint-ignore until the Phase 2 context rewrite. - Dead code deleted: Auto handler, getStreamByChannelID, updateXEPG, indexOfInt, jsonToMapInt64, removeOldSystemData, randomTime, and the commented-out blocks in struct-buffer.go and internal/authentication. - Duplicates folded: cacheImagesInBackground(), one addErrorToStream(). - Bugs found by SA4006/SA5001: os.Create handle leaked per ffmpeg segment (buffer.go), http.NewRequest error unchecked (buffer.go), xepg.json migration wrote null on read error (migrate.go), WriteUserData errors silently dropped (authentication.go), defer Close before error check (buffer.go, toolchain.go). checkFilePermission results were discarded; an unwritable config or temp dir is now fatal at start-up. - gofmt applied repo-wide; Drone runs gofmt check and staticcheck. Docker: - Entrypoint starts as root, applies PUID/PGID (falls back to XTEVE_UID/ XTEVE_GID, then image defaults), fixes config ownership only when it differs, then drops to xteve via su-exec. --user starts skip all of it. - /xteve removed from LEGACY_CONFIG_DIRS (it is the parent of the default). - mwader/static-ffmpeg pinned to 7.1.1; VOLUME /xteve/config. - Compose files pull registry.coadcorp.com/nathan/xteve:latest, use PUID/PGID/TZ, and explain that SSDP needs host networking. - .dockerignore excludes the npm toolchain (bundle stays in html/js). Docs: README rewritten for the fork (about, registry, compose, env vars, security notes); README-DEV gains a container section.
2.8 KiB
Developer notes
Layout
| Path | What it is |
|---|---|
xteve.go |
main: flags, version, start-up |
src/ |
the application (one Go package src) |
src/internal/ |
authentication, image cache, M3U parser |
html/ |
web interface: HTML pages, CSS, images, the compiled js/app.js, and embed.go which embeds the lot |
ts/ |
TypeScript sources for the web interface |
docker/ |
container entrypoint |
tasks/ |
improvement plan and checklist |
Build the binary
Go 1.27.1 is pinned in go.mod; the go command downloads it automatically.
go build ./...
go vet ./...
go test ./...
The web interface is embedded with go:embed from html/, so a bare clone builds a complete binary.
Web interface
The UI is plain TypeScript compiled as global scripts (no modules yet) into a single bundle, html/js/app.js, which is committed. CI rebuilds it and fails if the committed file is stale.
npm ci # installs the pinned TypeScript compiler
npm run build # ts/*.ts -> html/js/app.js
npm run check # type-check only
File order in the bundle is fixed in ts/tsconfig.json and matches the old per-page script order. All pages load the same bundle.
English strings are inlined in the TypeScript. There is no language layer.
Run from source
go run . -config /path/to/config -port 34400
Add -dev to serve the web interface from the local html/ directory instead of the embedded copy, so CSS and HTML edits show up on reload. JavaScript still needs npm run build.
Versioning and release
The version lives in two places that must agree: var Version in xteve.go and the first #### heading in changelog-beta.md (without the -beta suffix). CI fails on drift.
Drone (.drone.yml) runs vet, tests, the bundle check, hadolint and compose validation on every push. Pushes to master publish registry.coadcorp.com/nathan/xteve:latest and :<sha>; other branches publish :<branch> and :<sha>.
Endpoints useful for operations
GET /healthzreturns{"status":"ok","version":...,"scanInProgress":...}with no authentication. The Docker healthcheck uses it.
Container image
Dockerfile builds the binary in a golang:1.27.1-alpine stage, copies static ffmpeg/ffprobe from a pinned mwader/static-ffmpeg tag (bump the tag in the Dockerfile; there is no other place to change) and runs on alpine. The runtime stage installs su-exec and does not set USER: docker/entrypoint.sh starts as root, applies PUID/PGID to the xteve user by editing /etc/passwd and /etc/group, fixes ownership of the config directory, and execs su-exec xteve:xteve xteve. With --user it skips all of that. ARG XTEVE_UID/XTEVE_GID remain the build-time defaults so Drone's build args still work. Check the script with sh -n and shellcheck -s sh after editing.