Skip to content

feat(synology): add native DSM 7.3 and SRM 1.3 packages - #433

Open
floppy69 wants to merge 17 commits into
sirrobot01:betafrom
ESI69190:synology-upstream-beta
Open

floppy69 wants to merge 17 commits into
sirrobot01:betafrom
ESI69190:synology-upstream-beta

Conversation

@floppy69

Copy link
Copy Markdown

📌 Description

Add native Synology DSM 7.3 and SRM 1.3 packages using a pinned SynoCommunity spksrc overlay.

The Synology compatibility changes are intentionally isolated to the SPK build. Normal Linux/Docker/macOS/Windows builds keep the upstream dependency set and behavior unchanged.


Target Branch Check (IMPORTANT)

  • I confirm this PR is targeting the correct branch

Expected target:

  • beta (for features)

Changes Made

  • Add native DSM 7.3 / SRM 1.3 SPK builds and a GitHub Actions architecture matrix.
  • Package Decypharr, rclone, FUSE 2 and FUSE 3 with an unprivileged Synology service account.
  • Add an explicit post-install decypharr-fuse-fix helper for the setuid FUSE helpers required by DSM.
  • Keep the DSM compatibility profile local to the SPK source copy:
    • pin github.com/hanwen/go-fuse/v2 to v2.5.1 only while building the SPK;
    • use conservative FUSE values validated on an older Synology Linux 3.10 kernel;
    • remove the newer MountOptions.PanicHandler only from that packaging copy because v2.5.1 predates the field.
  • Add 32-bit compatibility shims:
    • stdlib JSON fallback instead of Sonic on 32-bit targets;
    • cross-built ARM32 rapidyenc using the exact upstream rapidyenc submodule SHA referenced by the current mnightingale/rapidyenc dependency.
  • Attach architecture-specific SPKs and SHA256SUMS to tagged GitHub releases.
  • Document DSM FUSE helper and shared-folder ACL requirements.

Testing

  • Tested on real Synology hardware

Validated on a DS1817+ / Avoton running DSM 7.3.1:

  1. Package installs and runs as the dedicated sc-decypharr account.
  2. decypharr-fuse-fix validates /dev/fuse, package-local fuse.conf, and FUSE helper permissions.
  3. fuse.decypharr remains mounted and connected.
  4. The mount exposes max_read=131072.
  5. Sonarr and Radarr can browse and read the mounted filesystem after DSM ACL traversal permissions are applied.
  6. The original failure mode, Transport endpoint is not connected, no longer occurs with the Synology compatibility profile.

The validated fork implementation also completed the full DSM 7.3 / SRM 1.3 package matrix successfully.

A clean CI run rebased on the current upstream beta branch is running on this PR branch.


Risks / Notes

  • The go-fuse downgrade is not applied to upstream's normal dependency graph. It is performed only inside the temporary SPK build source tree.
  • DSM does not allow this third-party package to declare broad root execution privileges. The main service remains unprivileged; an administrator explicitly runs decypharr-fuse-fix after install/upgrade to enable only fusermount and fusermount3.
  • Shared-folder ACL paths are installation-specific and therefore documented rather than hard-coded.
  • The spksrc revision is pinned for reproducible builds.

Screenshots (if applicable)

N/A


Checklist

  • Code builds successfully on the current beta branch
  • No runtime FUSE errors on the validated DSM system
  • Reviewed my own code
  • Target branch is correct

@floppy69
floppy69 marked this pull request as ready for review September 26, 2026 16:01

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant