Update server changelog
Jump to a version or snapshot
History of the unversioned update-server application, comparing the older modules/update_server.py copy with the active root update_server.py. Only those two source states are available; the large interval between them cannot be split into individual releases.
How to read this history
- Approximate dates: source-file modification timestamps in UTC, not confirmed release dates. A timestamp may reflect a later save, backup, or copy.
- Evidence: surviving source snapshots and direct comparisons; no usable Git history is available. A baseline lists capabilities already present, not their original introduction dates.
- Scope: source-based reconstruction; historical code was not imported or executed.
Compatibility changes to notice
- Upload paths now reject invalid Base64 and invalid Python before replacing a module.
- Manifest/signature and documentation endpoints exist in the current snapshot but not in the older copy.
Releases and snapshots
Current unversioned snapshot
Approximate date: 2026-09-28 (snapshot timestamp, UTC).
- Added
/update/versionsand/update/manifest, including SHA-256 module digests and optional Ed25519 signatures from the configured signing key. Signed metadata binds module name, version, and content digest. - Changed module uploads to validate Base64 and compile Python source before replacement. Added temporary-file writes, flush/fsync, preservation of existing permissions, and atomic
os.replacefor publishing file contents. - Normalized version extraction by stripping surrounding whitespace and quotes, and adjusted backup filenames. These changes explain older backups containing quotes/newlines; they do not retroactively fix those names.
- Added the ZIP/county CSV resource route, HTML documentation serving, an automatically populated
/docsindex,.htmland index redirects, and rejection of hidden/path-shaped document names. - Added configurable public-site URLs, an XML sitemap with document timestamps, and
robots.txtadvertising the sitemap. - Removed the direct
pmblue_updateimport and addedaiohttp_ws.toggle_badstatusline()before startup. All changes above are observed across the 2024-to-2026 snapshot interval, not proven to have shipped on this single date.
Evidence: Active root server update_server.py; compared with older server copy modules/update_server.py.
Earlier unversioned baseline
Approximate date: 2024-07-27 (snapshot timestamp, UTC).
- Already creates an
aiohttp_ws.Server, loads registered modules frommodules.json, extracts their versions, and serves module versions and module source. - Already provides authenticated module replacement/addition, backs up outgoing module code, persists the registry, and serves JavaScript resources.
- Already rewrites
primary_mod=Truetoprimary_mod=Falsein distributed module bytes. This is a baseline observation rather than a dated introduction.
Evidence: Older server copy modules/update_server.py.
Source inventory and reconstruction limits
Neither server copy declares a version, and no versioned server backups exist. The root file’s filesystem birth timestamp is 2024-05-28 at 23:26 UTC, suggesting the file existed by then, but no source state from that date survives; it is not listed as a release. The snapshots establish source states at approximate modification dates only.