Documentation
Everlock 0.9.2
The 0.9.2 release restores the embedded model's text recognition and
non-English answers, serves IPv4 and IPv6 side by side on every frontend,
and repairs writer grants on photo instances. Binaries are on the
download page; the container image is published as
cr.everlock.sh/everlock:0.9.
Highlights
-
Photos are read and described correctly again. The embedded model ships at a higher precision (Q6_K rather than Q4_K_M), which restores three things that had degraded together. Text recognition works: asked to transcribe a page, the model reads it instead of describing it. Non-English descriptions and tags come back in the language asked for, rather than in English or with characters from another script appearing mid-word. And the
/aishell picks the right tool and arguments markedly more often. All three share a cause — the lower precision collapsed rare tokens onto unrelated ones, and text recognition and non-English writing both depend on exactly those tokens. -
Every frontend serves IPv4 and IPv6 together. A listen setting now takes a comma-separated list of addresses, so one frontend binds both families — and specific addresses of each rather than every address on the host:
--frontend-http-listen-http '198.51.100.7:80,[2001:db8::1]:80'. Each address binds independently: one that fails is logged and the rest still serve, so a host without IPv6 loses nothing. Under systemd, aFileDescriptorName=now covers as many sockets as the unit files point at it. The new IPv4 and IPv6 page covers both modes, including what containers change. -
The
/aishell works with better information. Every admin tool the assistant can call now carries a JSON Schema for its arguments — names, types, which are required, and the permitted values where a setting has a fixed set — where it previously inferred argument shapes from a prose sentence. Its context window also grows from 9216 to 16384 tokens, so long exchanges stop shedding their oldest turns.
Behavior changes
-
A listen address without a port now binds that address. A bare IP literal such as
--frontend-http-listen-http 198.51.100.7previously fell back to the IPv4 wildcard and bound every address on the host; it now binds the address named, with the frontend's default port. A bare hostname still falls back to the wildcard, since a name selects no single address. Settings that already carry a port are unaffected. -
The download grows by about 70 MB. The higher-precision model is the entire difference.
-
Update checks identify themselves. The daily check against
everlock.shnow sendseverlock/<version>as itsUser-Agent, so a release host can see which versions are still polling and a proxy in front of one has something to match on.
Fixes
-
A
writergrant on a photo instance can see the photos. Write implies read, but the image backend derived the photo role from delete permission alone, so only anownerreached the library: awritergot a login that worked and a timeline that rendered empty, and could upload photos without being able to see them.writerandownernow both reach the whole library, andreaderis an album-scoped guest. Changing a grant now also updates the role recorded inside the photo instance, so a grant change takes effect on the next login. -
Socket activation no longer strands sockets systemd passes it. Everlock keyed inherited descriptors by name alone, so when a name carried more than one socket — two
ListenStream=lines, or an IPv4 and an IPv6 unit — only the last was adopted. The others stayed bound by systemd with nothing accepting on them: clients completed the TCP handshake and hung forever rather than being refused. Every socket under a name is now served, unrecognised socket names are reported at startup, and a bare IPv6 address in a listen setting is understood rather than mistaken for ahost:portpair.
Upgrading
Self-updating servers pick 0.9.2 up on their daily check. For a manual upgrade, download the new binary (or pull the new image tag) and restart — stores, mail, and all versioned content carry over untouched. The full list of changes is in the changelog.