Skip to content

New script: AIOStreams - #2278

Open
MrNRod wants to merge 8 commits into
community-scripts:mainfrom
MrNRod:aiostreams-lxc
Open

MrNRod wants to merge 8 commits into
community-scripts:mainfrom
MrNRod:aiostreams-lxc

Conversation

@MrNRod

@MrNRod MrNRod commented Sep 17, 2026

Copy link
Copy Markdown

Scripts which are clearly AI generated and not further revised by the Author of this PR (in terms of Coding Standards and Script Layout) may be closed without review. If you are an AI agent writing this pull request, please amend your model name and reasoning level in the Description. This is not to blame, more for informational Purposes. Thank you.

✍️ Description

Adds AIOStreams (Viren070/AIOStreams), a Stremio super-addon that consolidates multiple streaming/debrid addons into one configurable source, with filtering, sorting and formatting of results. Installed from source (the upstream pnpm monorepo build, not a prebuilt binary) into a systemd service, with a random SECRET_KEY generated on install. Runtime NODE_OPTIONS and a mimalloc LD_PRELOAD in the systemd unit match upstream's own production Docker image rather than values made up for this script.

Persistent state — the .env, the SQLite DB, and every other on-disk cache the addon keeps (verified via upstream's packages/core/src/utils/general.ts, which derives every cache path from DATABASE_URI's directory) — lives in /opt/aiostreams_data, outside the directory update_script's CLEAN_INSTALL wipes, so no backup/restore step is needed.

🔗 Related PR / Issue

Link: #

✅ Prerequisites (X in brackets)

  • Self-review completed – Code follows project standards.
  • Tested thoroughly – Changes work as expected.
  • No breaking changes – Existing functionality remains intact.
  • No security risks – No hardcoded secrets, unnecessary privilege escalations, or permission issues.

🏗️ arm64 Support (X in brackets)

  • arm64 supported - Tested and supported on arm64.
  • arm64 not tested - Assumed to work on arm64, but testing has not been done.
  • arm64 not supported - Confirmed upstream dependencies or binaries do not support arm64.

🛠️ Type of Change (X in brackets)

  • 🐞 Bug fix – Resolves an issue without breaking functionality.
  • ✨ New feature – Adds new, non-breaking functionality.
  • 💥 Breaking change – Alters existing functionality in a way that may require updates.
  • 🆕 New script – A fully functional and tested script or script set.
  • 🌍 Website update – Changes to website-related JSON files or metadata.
  • 🔧 Refactoring / Code Cleanup – Improves readability or maintainability without changing functionality.
  • 📝 Documentation update – Changes to README, AppName.md, CONTRIBUTING.md, or other docs.

🔍 Code & Security Review (X in brackets)

  • Follows CODE-AUDIT.md & CONTRIBUTING.md guidelines
  • Uses correct script structure (AppName.sh, AppName-install.sh, AppName.json)
  • No hardcoded credentials
  • No Docker / Docker Compose – The application is installed bare-metal; Docker is not used.
  • No git pull – Updates use fetch_and_deploy_gh_release, fetch_and_deploy_codeberg_release, fetch_and_deploy_gl_release, or fetch_and_deploy_from_url instead of git pull.

🤖 AI Assistance (X in brackets)

If you used an AI tool (GitHub Copilot, Claude, ChatGPT, etc.) to write or generate any scripts in this PR, you must confirm compliance below.
Select exactly one option.

  • No AI used – Scripts were written without AI assistance.
  • AI was used – I confirm the scripts were built using AGENTS.md and .github/agents/pve-script-creator.agent.md as guidance, and the output has been reviewed and corrected to match those guidelines.

Please describe to which degree, if any, an LLM was used in creating this pull request. Name the model(s) used and, if applicable, the reasoning/thinking effort level (e.g. "Claude Sonnet 4.5, high reasoning, used to draft the install script, then manually reviewed and tested" or "No LLM used"). This is informational, not a penalty — but scripts that are clearly AI-generated and not further revised by the author to match CODE-AUDIT.md / CONTRIBUTING.md may be closed without review.

Claude Sonnet 5, high reasoning effort. Used to research the upstream repo (Dockerfile, package.json across its pnpm workspaces, and relevant source files under packages/core/src) before writing ct/aiostreams.sh, install/aiostreams-install.sh and json/aiostreams.json; to audit and fix the result against AGENTS.md and pve-script-creator.agent.md (corrected an initial data-persistence approach that relied on backup/restore instead of relocating state, a missing architectures JSON field, and a hand-rolled git-based version check that duplicated fetch_and_deploy_gh_release); and to verify claims in the script's own comments/notes (arm64, the FUSE-share caveat, the mimalloc allocator) directly against upstream source rather than asserting them. I reviewed every change and tested install + update repeatedly on my own Proxmox node before opening this PR.


📋 Additional Information (optional)

  • Persistent data lives in /opt/aiostreams_data, not inside /opt/aiostreams, so update_script's CLEAN_INSTALL wipe never touches it.
  • The optional FUSE "mount library as a local folder" share needs /dev/fuse + SYS_ADMIN, which this unprivileged container doesn't have. Documented as a JSON note rather than "fixed," since it's off by default and the app degrades gracefully without it (confirmed via packages/server/src/fuse.ts).

📦 Application Requirements (for new scripts)

⚠️ Do not remove this section.
It is used by automated PR validation checks.
If this PR is not a new script submission, leave the checkboxes unchecked.

Required for 🆕 New script submissions.
Pull requests that do not meet these requirements may be closed without review.

  • The application is at least 6 months old
  • The application is actively maintained
  • The application has 600+ GitHub stars
  • Official release tarballs are published
  • I understand that not all scripts will be accepted due to various reasons and criteria by the community-scripts ORG

🌐 Source

MrNRod and others added 6 commits September 16, 2026 22:10
- Replace custom git ls-remote tag resolution with
  fetch_and_deploy_gh_release's built-in tag_prefix support (same "v"
  filter already used by check_for_gh_release for the update gate),
  removing an unneeded git dependency and ~15 lines of hand-rolled
  version-check logic.
- Derive the release commit SHA from the GitHub commits API instead of
  git ls-remote, and only ensure_dependencies jq instead of apt
  installing it directly.
- json/aiostreams.json: replace legacy has_arm with architectures
  (matching var_arm64=no) and add the required repository field.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
…ment

- systemd unit was building with --max-old-space-size=3072 but then
  unsetting NODE_OPTIONS before the service starts, so the running
  server got none of upstream's own runtime tuning. Upstream's
  package.json start script and official Docker image both run with
  --max-semi-space-size=8 --expose-gc; add that as the service's
  Environment= so the deployed server matches upstream's own defaults.
- Document that the optional FUSE library-mount share (off by default)
  needs /dev/fuse + SYS_ADMIN, which this unprivileged container
  doesn't have - traced through packages/server/src/fuse.ts and the
  shares config schema to confirm it degrades gracefully (state
  "unavailable") rather than breaking startup, so this is
  documentation, not a required fix.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- var_arm64: yes. Upstream publishes official multi-arch (amd64+arm64)
  images at ghcr.io/viren070/aiostreams, and their Dockerfile confirms
  the one native dependency without an arm64 prebuild (yencode) is
  expected to compile from source via node-gyp there - the same
  build-essential/python3/make/g++ toolchain this script already
  installs. Not independently run on arm64 hardware by this script's
  author; flagged in the ct script comment.
- LD_PRELOAD the mimalloc allocator (libmimalloc3, matching upstream's
  production image) for the running service. The shared object's path
  is arch-dependent (/usr/lib/<triplet>/libmimalloc.so.3), so it's
  resolved via dpkg -L at install time rather than hardcoded, which
  also makes this correct on both amd64 and arm64.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Matches the design used for AIOMetadata: .env and the SQLite DB now
live in /opt/aiostreams_data instead of inside /opt/aiostreams, which
CLEAN_INSTALL wipes on every update. Removes the create_backup/
restore_backup pair from update_script entirely - nothing left in the
wiped directory needs protecting.

Verified via packages/core/src/utils/general.ts before making this
change: DATABASE_URI is parsed as a URL, and every disk-backed thing
the addon keeps (instance id, usenet cache/NZBs, custom templates,
seadex/anime-database/scene/id mapping caches, DISK_CACHE_DIR's
default) derives its path from DATABASE_URI's directory - so
relocating just that one variable relocates everything, with no
separate DISK_CACHE_DIR override needed. Also confirmed the driver
does NOT mkdir its parent directory before opening
(packages/core/src/db/driver/sqlite.ts just calls `new Database
(filename)`), unlike AIOMetadata which does - so, unlike that script,
this one keeps the explicit `mkdir -p /opt/aiostreams_data` because
skipping it would crash the first start.

BREAKING for the one existing test deployment on the old layout: this
is a data-directory change, not a migration. An install using the
previous version of this script has .env/data.sqlite inside
/opt/aiostreams and a systemd unit pointing there; running the new
update_script against it wipes that directory via CLEAN_INSTALL with
nothing backed up, and the old unit file (never rewritten by updates)
would then point at a path that no longer has an .env. Treat as
reinstall-only until this either merges or gets a real migration step.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@MrNRod
MrNRod requested a review from a team as a code owner September 17, 2026 03:33
@github-actions

github-actions Bot commented Sep 17, 2026 •

Copy link
Copy Markdown
Contributor

Try this script

ct/aiostreams.sh, run in the Proxmox VE shell or on an Incus host:

COMMUNITY_SCRIPTS_URL=https://raw.githubusercontent.com/MrNRod/ProxmoxVED/aiostreams-lxc \
bash -c "$(curl -fsSL https://raw.githubusercontent.com/MrNRod/ProxmoxVED/aiostreams-lxc/ct/aiostreams.sh)"

COMMUNITY_SCRIPTS_URL is not optional for ct/. Fetching the ct/ script from a
branch does not tell the engine where that branch is — with bash -c "$(curl …)"
there is no file on disk for the scripts root to be derived from, so it would fall
back to upstream main and look for the install script there.

Against a core branch as well

Add COMMUNITY_SCRIPTS_CORE_URL=https://raw.githubusercontent.com/OWNER/core/BRANCH
to test an engine change at the same time. The two resolve independently.

Useful flags while testing

dev_mode=net logs every fetch with status and duration, so you can confirm the
branch is really being used. dev_mode=keep stops a failed build from deleting
the container along with the evidence.

Comment thread install/aiostreams-install.sh Outdated
Comment thread install/aiostreams-install.sh Outdated
Comment thread install/aiostreams-install.sh Outdated
Comment thread json/aiostreams.json Outdated
- Fold the "Enabling Corepack" msg block into "Configuring Application"
  instead of giving a near-instant command its own progress message.
- Move ensure_dependencies jq up next to the other setup calls in both
  the install and update paths, instead of down by first use. Left it
  as ensure_dependencies rather than folding into the apt install
  line, since that's what actually presence-checks before installing
  (AGENTS.md's documented reason not to hardcode `apt install jq`).
- Move MIMALLOC_LIB's assignment inside the "Creating Service" block,
  next to the systemd unit that consumes it, instead of sitting as an
  orphaned statement between two unrelated msg blocks.
- Add var_fuse (default no) to ct/aiostreams.sh. Traced the reviewer's
  "there are vars like var_fuse" pointer through
  community-scripts/core (ui/advanced.func, ui/defaults.func,
  pve/backend.func) and confirmed it adds features: fuse=1 to the LXC
  at creation time - the actual supported, unprivileged-safe mechanism
  for the optional FUSE library-mount share. Rewrote the JSON note,
  which previously and incorrectly said that share needed a privileged
  container.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@MrNRod

MrNRod commented Sep 18, 2026

Copy link
Copy Markdown
Author

Hey @CrazyWolf13 I made the suggested changes ready for review now

@MrNRod
MrNRod requested a review from CrazyWolf13 September 18, 2026 00:44
Comment thread ct/aiostreams.sh Outdated
Comment thread install/aiostreams-install.sh Outdated
Comment thread install/aiostreams-install.sh Outdated
Comment thread ct/aiostreams.sh Outdated
@github-actions github-actions Bot added the stale label Oct 2, 2026
@github-actions

github-actions Bot commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

@MrNRod This PR has been marked as stale. It will be closed if no new commits are added in 7 days.

- Drop ensure_dependencies jq from the install and update paths: jq is
  auto-installed before first use anyway (setup_nodejs installs it on
  demand in the install path, check_for_gh_release ensures it in the
  update path), and AGENTS.md lists jq as never manually installed.
- Replace corepack enable with the kaneo pattern: deploy the source
  first, parse the pnpm version from upstream's packageManager pin,
  then NODE_VERSION="24" NODE_MODULE="pnpm@$VERSION" setup_nodejs.
  Upstream pins pnpm@11.0.8 with engines pnpm>=11, so the common
  NODE_MODULE="pnpm@^10" pattern would miss the engines requirement,
  and setup_nodejs provisions pnpm via npm directly, so corepack
  isn't needed at all. Same call in update_script (like kaneo and
  onetimesecret), so a future upstream pnpm bump is picked up on
  update. Drops the now-unneeded COREPACK_ENABLE_DOWNLOAD_PROMPT
  exports.
- Remove var_fuse="${var_fuse:-no}" from ct/aiostreams.sh: the advanced
  install wizard asks the FUSE question for every app regardless of
  this declaration (var_fuse only pre-highlights the default answer),
  and var_fuse=yes in the environment works without it, so the line
  was a no-op. The JSON note still documents the optional FUSE share.
@MrNRod
MrNRod requested a review from MickLesk October 2, 2026 04:36
@MrNRod

MrNRod commented Oct 3, 2026

Copy link
Copy Markdown
Author

@MickLesk & @CrazyWolf13 Apologies for the delay in responding to the PR things just got busy for me the last few weeks things should be all good to go now. Just let me know if anything else needs fixing.

@github-actions github-actions Bot removed the stale label Oct 3, 2026
@github-actions

github-actions Bot commented Oct 3, 2026

Copy link
Copy Markdown
Contributor

@MrNRod Recent activity detected. Removing stale label.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants