-
Notifications
You must be signed in to change notification settings - Fork 33
feat: add OpenWrt ipk packaging support for x86_64 and aarch64 #288
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
1df480a
4f1cac4
901f5cc
a350de3
102c7e2
a30da83
0a1a99d
6981045
4cb4395
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,57 @@ | ||
| include $(TOPDIR)/rules.mk | ||
|
|
||
| PKG_NAME:=rustdesk-console | ||
| PKG_VERSION:=1.8.0 | ||
| PKG_RELEASE:=1 | ||
|
|
||
| ifeq ($(ARCH),x86_64) | ||
| SEA_ARCH:=x64 | ||
| else ifeq ($(ARCH),aarch64) | ||
| SEA_ARCH:=arm64 | ||
| else | ||
| SEA_ARCH:=unsupported | ||
| endif | ||
|
|
||
| PKG_SOURCE:=$(PKG_NAME)-$(PKG_VERSION)-linux-$(SEA_ARCH)-musl.tar.gz | ||
| PKG_SOURCE_URL:=https://github.com/databk/rustdesk-console/releases/download/$(PKG_VERSION) | ||
| PKG_HASH:= | ||
| PKG_MIRROR_HASH:= | ||
|
Comment on lines
+17
to
+18
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win Set the release archive's SHA-256 hash. With both hashes empty, OpenWrt leaves the download hash at its default 🤖 Prompt for AI Agents |
||
| PKG_BUILD_DIR:=$(BUILD_DIR)/$(PKG_NAME)-$(PKG_VERSION) | ||
|
|
||
| include $(INCLUDE_DIR)/package.mk | ||
|
|
||
| define Package/rustdesk-console | ||
| SECTION:=net | ||
| CATEGORY:=Network | ||
| SUBMENU:=RustDesk | ||
| TITLE:=RustDesk Console management platform | ||
| DEPENDS:=+libc +libstdcpp6 +libgcc1 | ||
| MAINTAINER:=databk | ||
| endef | ||
|
|
||
| define Package/rustdesk-console/description | ||
| Enterprise-grade management platform for the RustDesk ecosystem. | ||
| Self-hosted console as an alternative to RustDesk Server Pro. | ||
| This package ships prebuilt musl binaries (Node.js SEA + sqlite3 + sharp) | ||
| for x86_64 and aarch64 only. Running on other architectures will fail. | ||
| endef | ||
|
|
||
| Build/Configure:= | ||
| Build/Compile:= | ||
|
|
||
| define Package/rustdesk-console/install | ||
| $(INSTALL_DIR) $(1)/usr/lib/rustdesk-console | ||
| $(INSTALL_DIR) $(1)/usr/bin | ||
| $(INSTALL_DIR) $(1)/etc/init.d | ||
| $(INSTALL_DIR) $(1)/etc/rustdesk-console | ||
| $(TAR) -C $(PKG_BUILD_DIR) -xzf $(DL_DIR)/$(PKG_SOURCE) | ||
| $(INSTALL_BIN) $(PKG_BUILD_DIR)/rustdesk-console $(1)/usr/lib/rustdesk-console/rustdesk-console | ||
| $(CP) $(PKG_BUILD_DIR)/templates $(1)/usr/lib/rustdesk-console/templates | ||
| $(CP) $(PKG_BUILD_DIR)/node_modules $(1)/usr/lib/rustdesk-console/node_modules | ||
| $(INSTALL_BIN) ./files/rustdesk-console.init $(1)/etc/init.d/rustdesk-console | ||
| $(INSTALL_DATA) ./files/rustdesk-console.env $(1)/etc/rustdesk-console/rustdesk-console.env | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟠 Major | ⚡ Quick win Sensitive Data Exposure Reachability: External Install the JWT configuration with restricted permissions.
🤖 Prompt for AI Agents🗄️ Data Integrity & Integration | 🟠 Major | ⚡ Quick win Declare the environment file as a package conffile. This file contains operator settings, including 🤖 Prompt for AI Agents |
||
| printf '#!/bin/sh\nexec /usr/lib/rustdesk-console/rustdesk-console "$$@"\n' > $(1)/usr/bin/rustdesk-console | ||
| chmod 0755 $(1)/usr/bin/rustdesk-console | ||
| endef | ||
|
|
||
| $(eval $(call BuildPackage,rustdesk-console)) | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,121 @@ | ||
| # RustDesk Console — OpenWrt Package | ||
|
|
||
| This directory contains the OpenWrt/ImmortalWrt package definition for RustDesk | ||
| Console. It ships **prebuilt musl binaries** (Node.js SEA single executable + | ||
| `sqlite3` + `sharp` native modules) and wraps them in `.ipk` and `.apk` | ||
| packages managed by `procd`. | ||
|
|
||
| ## Supported targets | ||
|
|
||
| | Architecture | OpenWrt ARCH | SEA tarball | | ||
| |--------------|--------------|-------------| | ||
| | x86_64 (soft router) | `x86_64` | `rustdesk-console-<ver>-linux-x64-musl.tar.gz` | | ||
| | aarch64 (ARMv8) | `aarch64` | `rustdesk-console-<ver>-linux-arm64-musl.tar.gz` | | ||
|
|
||
| Only **musl** libc builds of OpenWrt/ImmortalWrt are supported (the default). | ||
| glibc-based OpenWrt builds are not supported. | ||
|
|
||
| ## Install a prebuilt package | ||
|
|
||
| Download the package for your architecture from the | ||
| [GitHub Releases](https://github.com/databk/rustdesk-console/releases) page. | ||
|
|
||
| ### OpenWrt < 24.10 (opkg / `.ipk`) | ||
|
|
||
| ```sh | ||
| opkg install rustdesk-console_<version>_x86_64.ipk | ||
| ``` | ||
|
|
||
| ### OpenWrt >= 24.10 (apk / `.apk`) | ||
|
|
||
| ```sh | ||
| apk add --allow-untrusted rustdesk-console_<version>_x86_64.apk | ||
| ``` | ||
|
|
||
| > The `--allow-untrusted` flag is needed because the `.apk` is not signed with | ||
| > a build key. For production feeds, sign the package with your own key and | ||
| > configure `apk` trust accordingly. | ||
|
|
||
| > **Note:** The `.apk` uses `arch: noarch` so it installs on any OpenWrt apk | ||
| > target (e.g. `aarch64_generic`, `aarch64_cortex-a72`, `x86_64`). Make sure | ||
| > to download the file matching your CPU architecture (`x86_64` or `aarch64`) | ||
| > — the package itself does not enforce the CPU architecture. | ||
|
|
||
| Then enable and start the service: | ||
|
|
||
| ```sh | ||
| /etc/init.d/rustdesk-console enable | ||
| /etc/init.d/rustdesk-console start | ||
| ``` | ||
|
|
||
| The backend API is now available at `http://<router-ip>:3000/api`. | ||
|
|
||
| ## Configuration | ||
|
|
||
| Edit `/etc/rustdesk-console/rustdesk-console.env` (a conffile, preserved across | ||
| upgrades) and restart the service. Key variables: | ||
|
|
||
| | Variable | Default | Description | | ||
| |----------|---------|-------------| | ||
| | `PORT` | `3000` | HTTP listen port | | ||
| | `JWT_SECRET` | must be changed | JWT signing secret | | ||
| | `DATA_DIR` | `/var/lib/rustdesk-console` | SQLite DB, avatars, nexus builds | | ||
|
|
||
| ## Build the package from the OpenWrt feed | ||
|
|
||
| This `Makefile` is a **binary package**: it downloads a prebuilt musl SEA | ||
| tarball from GitHub Releases and packages it — it does **not** compile Node.js | ||
| inside the OpenWrt buildroot. | ||
|
|
||
| 1. Add this directory to your OpenWrt feed (e.g. `feeds.conf`): | ||
| ``` | ||
| src-link rustdesk_console /path/to/this/openwrt | ||
| ``` | ||
|
Comment on lines
+70
to
+73
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🎯 Functional Correctness | 🟠 Major | ⚡ Quick win Point the feed at a directory containing a package subdirectory. The documented 🧰 Tools🪛 markdownlint-cli2 (0.23.2)[warning] 71-71: Fenced code blocks should have a language specified (MD040, fenced-code-language) 🤖 Prompt for AI Agents |
||
| 2. Update and install the feed: | ||
| ```sh | ||
| ./scripts/feeds update rustdesk_console | ||
| ./scripts/feeds install rustdesk-console | ||
| ``` | ||
| 3. Select your target (`x86_64` or `aarch64`, musl) in `make menuconfig`, then | ||
| enable `Network -> RustDesk -> rustdesk-console`. | ||
| 4. Update `PKG_HASH` in `Makefile` to the sha256 of the downloaded tarball | ||
| (required by recent buildroot versions): | ||
| ```sh | ||
| sha256sum dl/rustdesk-console-<ver>-linux-<arch>-musl.tar.gz | ||
| ``` | ||
| 5. Build: | ||
| ```sh | ||
| make package/rustdesk-console/compile V=s | ||
| ``` | ||
| The `.ipk` appears in `bin/packages/<arch>/rustdesk_console/`. | ||
|
|
||
| ## Frontend | ||
|
|
||
| This package only installs the **backend API**. Deploy the | ||
| [frontend](https://github.com/databk/rustdesk-console-web) separately and point | ||
| it at `http://<router-ip>:3000`, e.g. with an external nginx reverse proxy. | ||
|
|
||
| ## How the prebuilt tarballs are produced | ||
|
|
||
| The musl SEA tarballs, `.ipk` and `.apk` files are built in CI (see | ||
| `.github/workflows/release.yml` and `nightly.yml`): | ||
|
|
||
| 1. `node:24-alpine` container runs `npm ci && npm run build:sea` → musl SEA | ||
| binary + musl native modules (`sqlite3`, `sharp` use their `linuxmusl` | ||
| prebuilds). | ||
| 2. `scripts/build-openwrt-ipk.sh` assembles the `.ipk` (data + control archive) | ||
| with the procd init script and default config. | ||
| 3. `scripts/build-openwrt-apk.sh` assembles the `.apk` using `apk mkpkg` | ||
| (apk-tools 3.x ADB format) for OpenWrt 24.10+ snapshots and newer. | ||
|
|
||
| ## File layout (installed) | ||
|
|
||
| ``` | ||
| /usr/lib/rustdesk-console/rustdesk-console # SEA executable (musl) | ||
| /usr/lib/rustdesk-console/templates/{email,oidc} # email/OIDC templates | ||
| /usr/lib/rustdesk-console/node_modules/{sqlite3,sharp} | ||
| /usr/bin/rustdesk-console # wrapper -> SEA executable | ||
| /etc/init.d/rustdesk-console # procd init script | ||
| /etc/rustdesk-console/rustdesk-console.env # config (conffile) | ||
| /var/lib/rustdesk-console/ # data dir (created on install) | ||
| ``` | ||
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,11 @@ | ||
| # RustDesk Console configuration | ||
| # After editing, restart the service: /etc/init.d/rustdesk-console restart | ||
|
|
||
| # HTTP listen port | ||
| PORT=3000 | ||
|
|
||
| # JWT secret (CHANGE THIS to a strong random value before production use) | ||
| JWT_SECRET=please-change-this-to-a-strong-secret | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🛡️ Detected with Advanced Tier | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- changed file ---'
cat -n openwrt/files/rustdesk-console.env
printf '%s\n' '--- OpenWrt references ---'
rg -n -C 3 'rustdesk-console\.env|JWT_SECRET|rustdesk-console' openwrt src/modules/auth src/main.ts
printf '%s\n' '--- JWT strategy ---'
cat -n src/modules/auth/strategies/jwt.strategy.ts
printf '%s\n' '--- PR diff for the relevant file ---'
git diff --no-ext-diff --unified=20 5476354e7bcbe137a6562255e41f877585b94e5e 4cb43959547ff7c634d4ed8afa021186c1d67f8b -- openwrt/files/rustdesk-console.envRepository: databk/rustdesk-console Length of output: 15598 🏁 Script executed: #!/bin/bash
set -eu
printf '%s\n' '--- service init ---'
cat -n openwrt/files/rustdesk-console.init
printf '%s\n' '--- validateToken definitions and callers ---'
rg -n -C 12 'validateToken\s*\(' src/modules
printf '%s\n' '--- token issuance and persistence ---'
rg -n -C 8 'sign\(|access_token|jti|token' src/modules/auth/services src/modules/auth -g '*.ts' | head -n 260Repository: databk/rustdesk-console Length of output: 24533 Authorization Bypass Reachability: External Replace the shared JWT secret before starting the service. If an installation retains this value, an attacker can forge JWT claims with the publicly known signing key. The token check only confirms that the 🤖 Prompt for AI Agents |
||
|
|
||
| # Data directory for the SQLite database, avatars and nexus build artifacts | ||
| DATA_DIR=/var/lib/rustdesk-console | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🔴 Critical | 🏗️ Heavy lift Move persistent application data out of On a standard OpenWrt image, 🤖 Prompt for AI Agents |
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟠 Major | ⚡ Quick win
Use OpenWrt 25.12 as the
apkcutoff. OpenWrt 24.10 and older useopkg; the current instructions direct 24.10 users to the wrong package manager. (openwrt.org)README.md#L149-L152: change theapkheading to 25.12 and newer; include 24.10 in theopkgrange.openwrt/README.md#L29-L32: make the same cutoff change, and correct the repeated cutoff at Lines 108-109.📍 Affects 2 files
README.md#L149-L152(this comment)openwrt/README.md#L29-L32🤖 Prompt for AI Agents