Skip to content

xlight 3.9.5 - #6

Merged
N6REJ merged 3 commits into
mainfrom
3.9.5
Aug 10, 2026
Merged

N6REJ merged 3 commits into
mainfrom
3.9.5

Conversation

@jwaisner

Copy link
Copy Markdown
Contributor

No description provided.

@jwaisner
jwaisner requested a review from N6REJ as a code owner August 10, 2026 04:03
@jwaisner jwaisner added enhancement ✨ Improve program Security 🔐 Security issue labels Aug 10, 2026
@qodo-code-review

Copy link
Copy Markdown

PR Summary by Qodo

Add xlight 3.9.5 module bundle and release metadata

✨ Enhancement ⚙️ Configuration changes 🕐 10-20 Minutes

Grey Divider

AI Description

• Add a new versioned xlight 3.9.5 module directory with default FTP server configs.
• Introduce downloadable “extras” URLs (help/remote admin/language) for the 3.9.5 bundle.
• Publish new release coordinates by updating build and releases property mappings.
Diagram

graph TD
  A[Bearsampp Core] --> B["releases.properties"] --> C{{"GitHub Release (7z)"}} --> D["bin/xlight3.9.5"] --> E["bearsampp.conf"] --> F["xlight.exe"]
  D --> G["ftpd.* configs"] --> F
Loading
High-Level Assessment

The following are alternative approaches to this PR:

1. Template + generate per-version configs
  • ➕ Reduces duplication across versioned module directories
  • ➕ Makes future version bumps mostly data-driven (version/URLs only)
  • ➖ Requires adding/maintaining a generation step in the build/release process
  • ➖ Harder to manually tweak a single version’s config without updating templates
2. Shared baseline config with per-version overrides
  • ➕ Keeps a single canonical set of ftpd defaults while allowing version-specific deltas
  • ➕ Smaller archives when most files are identical
  • ➖ Adds runtime/config resolution complexity
  • ➖ May be awkward on Windows packaging if symlinks or include semantics aren’t supported

Recommendation: Current approach (fully versioned, self-contained config directory + explicit release mapping) is appropriate for predictable packaging and rollback. Consider templating only if maintaining many near-identical xlight versions becomes a frequent workflow pain.

Files changed (10) +32 / -1 · 1 not counted

Other (10) +32 / -1
.gitignoreIgnore generated Xlight log output for the 3.9.5 module not counted

Ignore generated Xlight log output for the 3.9.5 module

• Adds a .gitignore under the versioned Logs directory to prevent committing runtime log artifacts.

bin/xlight3.9.5/Logs/.gitignore

bearsampp.confAdd xlight 3.9.5 module runtime settings +4/-0

Add xlight 3.9.5 module runtime settings

• Introduces module settings for the xlight version, executable name, and default FTP/FTPS ports (21/990).

bin/xlight3.9.5/bearsampp.conf

extras.propertiesDefine downloadable extras for xlight 3.9.5 +3/-0

Define downloadable extras for xlight 3.9.5

• Adds URLs for optional help, remote admin, and language packs hosted in modules-untouched releases.

bin/xlight3.9.5/extras.properties

ftpd.hostsAdd default virtual server host definition +5/-0

Add default virtual server host definition

• Creates a localhost virtual server on 127.0.0.1:21 with UTF-8 enabled and a server note.

bin/xlight3.9.5/ftpd.hosts

ftpd.optionAdd default daemon options (icon, logging, backups) +4/-0

Add default daemon options (icon, logging, backups)

• Enables service icon display, command logging, and auto config backups; sets remote admin bind to 0.0.0.0:0.

bin/xlight3.9.5/ftpd.option

ftpd.passwordAdd anonymous password entry for localhost virtual server +4/-0

Add anonymous password entry for localhost virtual server

• Defines an anonymous account password hash entry within the 127.0.0.1:21 virtual server scope.

bin/xlight3.9.5/ftpd.password

ftpd.rulesAdd placeholder rules file for 3.9.5 +1/-0

Add placeholder rules file for 3.9.5

• Introduces an (currently empty) rules file to support future access/control rules configuration.

bin/xlight3.9.5/ftpd.rules

ftpd.usersAdd default anonymous user mapping and virtual path +9/-0

Add default anonymous user mapping and virtual path

• Creates an anonymous user entry allowing no password and maps a virtual path to a local sandbox www directory.

bin/xlight3.9.5/ftpd.users

build.propertiesBump bundle release stamp to 2025.8.9 +1/-1

Bump bundle release stamp to 2025.8.9

• Updates the bundle.release value to reflect the new build/release date for packaging.

build.properties

releases.propertiesRegister xlight 3.9.5 download URL +1/-0

Register xlight 3.9.5 download URL

• Adds a new releases.properties entry mapping version 3.9.5 to its GitHub release artifact URL.

releases.properties

@qodo-code-review

qodo-code-review Bot commented Aug 10, 2026 •

Copy link
Copy Markdown

Code Review by Qodo

🐞 Bugs (1) 📘 Rule violations (0) 📎 Requirement gaps (0) 🎨 UX issues (0) 🔗 Cross-repo conflicts (0) 📜 Skill insights (0)

Grey Divider


Action required

1. Mismatched release identifiers ✓ Resolved 🐞 Bug ≡ Correctness
Description
The new 3.9.5 entry mixes a download tag/date (2026.8.9) with an archive name derived from
bundle.release (2025.8.9), creating inconsistent release metadata that can cause
consumers/automation to look under the wrong GitHub release tag for the expected artifact name.
Code

releases.properties[1]

+3.9.5 = https://github.com/Bearsampp/module-xlight/releases/download/2026.8.9/bearsampp-xlight-3.9.5-2025.8.9.7z
Evidence
The repo’s build logic derives output paths and archive filenames from bundle.release, but the
newly added 3.9.5 download URL uses a different release tag segment, and the extras dependencies
also use that different tag—showing an internal mismatch introduced by this PR.

releases.properties[1-1]
build.properties[1-4]
bin/xlight3.9.5/extras.properties[1-3]
build.gradle[20-28]
build.gradle[36-40]
build.gradle[56-57]
build.gradle[839-842]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
`releases.properties` introduces a 3.9.5 URL whose GitHub release tag segment (`.../download/2026.8.9/...`) does not match the module’s build release identifier (`bundle.release=2025.8.9`) that is used to construct output directories and archive filenames. This makes the release metadata internally inconsistent and can break tooling that expects these to match.

### Issue Context
- `bundle.release` is used to name archives and output folders during `gradle release`.
- The PR’s `releases.properties` and `extras.properties` use a different date/tag (`2026.8.9`) than `build.properties` (`2025.8.9`).

### Fix Focus Areas
- build.properties[1-4]
- releases.properties[1-1]
- bin/xlight3.9.5/extras.properties[1-3]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools



Remediation recommended

2. Nonportable anonymous FTP config 🐞 Bug ⛨ Security
Description
The shipped 3.9.5 FTP configuration enables an anonymous/no-password user and sets its VirtualPath
to an absolute developer machine path (e:\Bearsampp-development\...), which will typically not
exist on user machines and can result in a broken FTP root (security risk increases if the server
bind address is later widened beyond localhost).
Code

bin/xlight3.9.5/ftpd.users[R4-5]

+AllowNoPassword:yes
+VirtualPath: "/|e:\Bearsampp-development\sandbox\www\|R--L---S"
Evidence
The PR adds a 3.9.5 ftpd.users with no-password anonymous access and an absolute,
environment-specific path; the packaged build copies these config files directly into the release,
and the host binding shows it’s localhost by default (mitigating remote exposure unless changed).

bin/xlight3.9.5/ftpd.users[1-8]
bin/xlight3.9.5/ftpd.password[1-3]
bin/xlight3.9.5/ftpd.hosts[1-4]
build.gradle[744-749]

Agent prompt
The issue below was found during a code review. Follow the provided context and guidance below and implement a solution

### Issue description
The new `bin/xlight3.9.5` configuration ships an anonymous account with `AllowNoPassword:yes` and a hardcoded absolute VirtualPath pointing to a developer-local directory. This is non-portable and can lead to incorrect runtime behavior.

### Issue Context
The Gradle release build copies `bin/<version>/` config files into the packaged output as-is (no templating/substitution visible in this repo), so these defaults are what users receive.

### Fix Focus Areas
- bin/xlight3.9.5/ftpd.users[3-6]
- bin/xlight3.9.5/ftpd.password[1-3]
- bin/xlight3.9.5/ftpd.hosts[1-4]
- build.gradle[744-749]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools


Grey Divider

Tip of the day
💡 Did you know, you can reply 'qodo' on any finding to push back, ask questions, or dig deeper

More tips ↗ | Customize Qodo ↗ | Qodo docs ↗

Grey Divider

Qodo Logo

Comment thread releases.properties Outdated
Comment on lines +4 to +5
AllowNoPassword:yes
VirtualPath: "/|e:\Bearsampp-development\sandbox\www\|R--L---S"

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remediation recommended

2. Nonportable anonymous ftp config 🐞 Bug ⛨ Security

The shipped 3.9.5 FTP configuration enables an anonymous/no-password user and sets its VirtualPath
to an absolute developer machine path (e:\Bearsampp-development\...), which will typically not
exist on user machines and can result in a broken FTP root (security risk increases if the server
bind address is later widened beyond localhost).
Agent Prompt
### Issue description
The new `bin/xlight3.9.5` configuration ships an anonymous account with `AllowNoPassword:yes` and a hardcoded absolute VirtualPath pointing to a developer-local directory. This is non-portable and can lead to incorrect runtime behavior.

### Issue Context
The Gradle release build copies `bin/<version>/` config files into the packaged output as-is (no templating/substitution visible in this repo), so these defaults are what users receive.

### Fix Focus Areas
- bin/xlight3.9.5/ftpd.users[3-6]
- bin/xlight3.9.5/ftpd.password[1-3]
- bin/xlight3.9.5/ftpd.hosts[1-4]
- build.gradle[744-749]

ⓘ Copy this prompt and use it to remediate the issue with your preferred AI generation tools

@N6REJ
N6REJ merged commit fdf65eb into main Aug 10, 2026
2 checks passed
@N6REJ
N6REJ deleted the 3.9.5 branch August 10, 2026 22:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement ✨ Improve program Security 🔐 Security issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants