change: drop the per-provider custom scripts feature (#82) #198

Merged
mysticalsoap merged 1 commit from remove-custom-scripts into trunk 2026-08-28 18:34:51 -04:00
Owner

Problem

The per-provider custom-scripts feature is arbitrary root command execution configured from the GUI: script strings live in config.json and run inside the root service's tunnel threads (#82). Research posted on the issue: upstream added it undocumented and unrequested in 2018, it shipped broken for six weeks before the author noticed himself, and no user ever filed a bug against it — no known users, wide quiet root-exec channel. The hooks also fire per tunnel process while being keyed per provider, which is how #81 (pre/down running for hop connects via the h != 1 string/int comparison) exists.

Closes #82, closes #81 (the buggy guards existed only to gate this feature and are removed with it).

Fix

  • Removes exe_custom_scripts and all six call sites in tunnel.py plus the one in aqomui_service.py, including the #81 guards.
  • Removes the Scripts section of the provider tab: widgets, signal wiring, retranslations, save_scripts/clear_scripts/update_scripts_enabled.
  • Scrubs {provider}_scripts keys in load_config: configs written before the removal carry them, and settings are re-persisted wholesale on the next save, so they'd otherwise linger forever.
  • Drops the now-unused shlex/run imports and scripts-only test stubs.

If demand ever appears, the re-add shape is the inverse (hooks in the GUI process as the user, driven by the state signals it already receives — the Viscosity model); see the issue.

Verification

  • Full suite passes (490 tests) including a new regression test that load_config scrubs legacy *_scripts keys; scripts-enablement tests removed with the feature.
  • ruff check --select E9,F63,F7,F82 . and python -W error::SyntaxWarning -m compileall clean.
  • Not yet eyeballed: the provider tab layout without the scripts section needs a quick visual check in a running GUI before merging.

🤖 Generated with Claude Code

## Problem The per-provider custom-scripts feature is arbitrary root command execution configured from the GUI: script strings live in config.json and run inside the root service's tunnel threads (#82). Research posted on the issue: upstream added it undocumented and unrequested in 2018, it shipped broken for six weeks before the author noticed himself, and no user ever filed a bug against it — no known users, wide quiet root-exec channel. The hooks also fire per tunnel process while being keyed per provider, which is how #81 (pre/down running for hop connects via the `h != 1` string/int comparison) exists. Closes #82, closes #81 (the buggy guards existed only to gate this feature and are removed with it). ## Fix - Removes `exe_custom_scripts` and all six call sites in tunnel.py plus the one in aqomui_service.py, including the #81 guards. - Removes the Scripts section of the provider tab: widgets, signal wiring, retranslations, `save_scripts`/`clear_scripts`/`update_scripts_enabled`. - Scrubs `{provider}_scripts` keys in `load_config`: configs written before the removal carry them, and settings are re-persisted wholesale on the next save, so they'd otherwise linger forever. - Drops the now-unused `shlex`/`run` imports and scripts-only test stubs. If demand ever appears, the re-add shape is the inverse (hooks in the GUI process as the user, driven by the state signals it already receives — the Viscosity model); see the issue. ## Verification - Full suite passes (490 tests) including a new regression test that `load_config` scrubs legacy `*_scripts` keys; scripts-enablement tests removed with the feature. - `ruff check --select E9,F63,F7,F82 .` and `python -W error::SyntaxWarning -m compileall` clean. - Not yet eyeballed: the provider tab layout without the scripts section needs a quick visual check in a running GUI before merging. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
change: drop the per-provider custom scripts feature (#82)
All checks were successful
ci / test (pull_request) Successful in 24s
ci / test (push) Successful in 26s
7a93583e24
Arbitrary root command execution configured from the GUI: script strings
lived in config.json and ran inside the root service's tunnel threads.
polkit gates the writer, but that is a wide, quiet root-exec channel
kept for a feature with no known users -- upstream added it undocumented
and unrequested in 2018, shipped it broken for six weeks before its own
author noticed, and no user ever filed a bug against it. Same reasoning
that dropped the self-updater (#19).

The hooks also received no context (no device, no role, no env), and
were keyed per provider but fired per tunnel process: the h != 1
string/int comparison meant pre/down also ran for hop connects (#81).
Those guards existed only to gate this feature and go with it.

Configs written before the removal still carry {provider}_scripts keys,
and anything left in settings is re-persisted wholesale on the next
save, so load_config scrubs them.

If demand ever shows up, the re-add is the inverse shape: hooks run in
the gui process as the user, driven by the state signals the gui
already receives -- no root involvement.

Closes #82
Closes #81

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
mysticalsoap deleted branch remove-custom-scripts 2026-08-28 18:34:51 -04:00
Sign in to join this conversation.
No description provided.