2.0.02026-09-26#
New · Changes · Fixes · +1
Dedicated to Benjamin Weber (ITSWEBER), whose external audit brings most of what changes in this version. Items that come from the report are marked «(audit)»; the others do not come from it.
New
- First setup: creating the first administrator asks for the one-time code shown on the NAS screen (or with
sudo lgm alta). (audit) - Package Center: each app's page says which catalogue it comes from, who maintains it and where to get help; the catalogue licences are under Catalogue sources. (audit)
- The website: third-party licences page and legal notice. (audit)
- The website: What's new opens with credits for those who have helped improve LGM-OS, each with their own page.
- LGM Connect: folders from this computer on the NAS. Share a PC folder and the NAS reads it (to back it up, or for Plex) while the app is open, at home or away. Read-only.
- LGM Connect: “Connection” screen. Tests each route to the NAS and says where it fails and what to do, with the app log live and a report for getting help, without any passwords.
- LGM Connect: the side menu hides and comes back with one click.
- Package Center: n8n, Uptime Kuma, Home Assistant, Gitea, Nextcloud and others warn before installing that whoever opens them first creates the administrator account; Nginx Proxy Manager states its factory login. (audit)
Changes
- Terminal and consoles: opening the terminal, the root session or a container console asks you to confirm your password and second factor. If you had a tab open, reload it; in LGM Connect, update the app. (audit)
- Updates: the source repository can no longer be changed from the panel: do it over SSH with
sudo git -C /opt/nas/src remote set-url origin <address>. (audit) - Updates: a version older than the installed one is not installed; to go back, use «Go back to the previous version».
- Updates: each release carries only what the NAS uses and is half the size. (audit)
- Privacy: the machine's technical details are no longer sent to lgm-os.com by default; switch them on in Control Panel → Licence if you want to share them with support. (audit)
- Licence: the periodic report to lgm-os.com no longer carries your licence key, only a fingerprint that cannot be used as a licence. (audit)
- Licence: the licensing check becomes daily, and the public IP is only looked up with dynamic DNS, the VPN or something published. (audit)
- Installation: the boot menu and the language screen are in Spanish, English and German, with proper umlauts, and the time zone follows the chosen language. (audit)
- Installation: the progress bar moves while the system packages install. (audit)
- Machine console: speaks the language chosen at install time from the first boot. (audit)
- Server screen: the browser starts without Google services and in the NAS language. (audit)
- New installs: the web server and the media server no longer start by default; they start when WebDAV, external access or Media is turned on. (audit)
- Accounts: «Close all sessions», pressed by an administrator, also closes every other account's sessions. (audit)
- Certificate: the prompt to install the NAS authority explains what trusting it implies. (audit)
- The website: says where the apps come from (31 of ours and more than 3,000 from the community) and who builds LGM-OS. (audit)
- The website: the privacy policy details everything the NAS sends, to whom and when, now also in German. (audit)
- Virtual machines: the screen toolbar no longer hides by itself: it folds and unfolds with one click on its handle, and stays the way you leave it.
- Firewall: it now filters the applications' ports too: new ones open only to the home network, and in Security → Firewall you close them or open them to any source. The ones you already had stay open as they were. (audit)
- Updates: the interface no longer declares its own version, different from the system's. (audit)
- Unused services: on update, Apache and the media server are switched off if nothing uses them; a site or folders set up by hand keep them running. (audit)
- Printer: on new installations CUPS no longer starts by default; it starts when you share the printer. (audit)
- Server screen: with no monitor connected, the full-screen panel does not start or use memory; it starts when one is plugged in. (audit)
- Your first volume: the assistant names the volume and the first folder in the panel's language; existing volumes keep their names. (audit)
- First setup and User and group: they say which account opens a folder from another computer and warn when an administrator lacks «Shared folders». (audit)
- Package Center: an app's page warns when the firewall has its port closed and it will not open from other devices. (audit)
Fixes
- Storage: replacing a failed disk in a Btrfs volume now works; before, it did nothing and gave no warning. (audit)
- Storage: a failed disk replacement now sends a notification with the reason and is recorded in the Log Center. (audit)
- Storage: a missing disk in a volume shows as "missing" instead of "ONLINE". (audit)
- Storage: a disk that is plugged back in is recognised as the missing one, and the notification says what to do. (audit)
- Storage: creating and deleting a volume replies fully in the panel's language. (audit)
- Notifications: disk connected, disconnected and missing-from-volume alerts come out fully in the panel's language. (audit)
- Your first volume: empty but small disks say why they don't qualify instead of showing as in use. (audit)
- Your first volume: with three or more disks it suggests parity when ZFS is loaded. (audit)
- Cameras: since 1.92 recording did not start when the recordings folder was shared; it repairs itself on update. (audit)
- Cameras: a camera that is not recording stops showing «Recording» after two minutes and gives the reason. (audit)
- Shared folders: creating a folder with SMB or NFS opens its port in the firewall. (audit)
- Package Center: Community Applications apps with old-style templates (Emby, Plex, GitLab…) install with their ports, folders and variables. (audit)
- Package Center: PUID, PGID and the time zone use this NAS's values. (audit)
- Package Center: Big Bear recipes no longer show part of a hash as their version. (audit)
- Snapshots: restored files no longer come back with the execute permission. (audit)
- Configuration backups: restoring no longer turns off the two-step verification accounts have on this NAS; whoever must turn it on again is told.
- Licence: the "Share technical details" text says what is always sent and what only goes with it on. (audit)
- The website: no longer claims the code isn't public: the code of everything that runs on the NAS ships with every release. (audit)
- The website: the offline licence is explained as it is: the trial and the activation need a connection once. (audit)
- The website: What's New and the documentation announced one version more than the published one.
- Clouds: those already mounted are brought up to date with each update; until now they kept the settings they were mounted with.
- LGM Connect: with the NAS down, a folder connected from outside home no longer freezes Explorer for minutes.
- LGM Connect: folders connected from outside home no longer freeze after a while, and one that disconnects by itself no longer shows as connected.
- LGM Connect: closing the app releases folders connected from outside home instead of leaving them hanging.
- External access: the DuckDNS certificate is now issued; the system rejected the command that requests it.
- Firewall: the screen no longer says SMB, NFS and WebDAV stay blocked: whatever you switch on from the panel opens its own port. (audit)
- Country blocking: a country without an IPv6 list no longer stops the whole firewall from loading.
- Files: opening a folder on a cloud, another computer or a disk that is slow to answer no longer leaves the whole panel unresponsive.
- Clouds: a MEGA cloud now opens as a folder; it connected but never got mounted.
- Package Center: in Catalogue sources, a source that brings applications no longer shows in red because of repeated or unsupported ones.
- LGM Connect: errors from the NAS and from sharing a folder from this computer show in the app's language.
- The website: the download and installation guide, now also in German, describes the current installer.
- Installation: with several disks the Debian partitioning menu no longer appears: the wizard asks which disk the system goes on and, if it holds data, says what is on it before erasing it. (audit)
- Installation: the boot loader goes on the system disk, not on the first disk of the machine.
- Installation: the first boot no longer says LGM-OS could not be prepared when the installation went fine.
- LGM Connect: «Alerts on this device» now shows the NAS alerts; until now none arrived.
- Firewall: the rules the NAS opens by itself are shown in the panel's language.
- Package Center: a community application's folders are labelled in the panel's language.
- Desktop: the «Updates» widget no longer says «No source repository» on a NAS installed from the ISO.
- System check: the warning about a DNS server that does not answer now also appears in English and German.
- NFS: with the firewall on, NFSv3 mounts and
showmountwork again: its helper services use fixed ports, open to the home network only. (audit) - ZFS: the warning that a new kernel has been left without ZFS works again; it used to always report the machine as fine.
- Package Center: the in-house apps (Vaultwarden, Nextcloud, Jellyfin…) no longer appear in Spanish with the panel in English or German, neither their description nor the install fields. (audit)
- Package Center: updating also brings the in-house recipes (Vaultwarden, Gitea…) up to date on NAS already installed; any you changed by hand stay as they are. (audit)
- Package Center: the catalogue a new NAS ships with has ports, author and support link; Emby opens on port 8096. (audit)
- Package Center: NAS units already installed rebuild the catalogue when updating instead of waiting for the weekly sync. (audit)
- Package Center: Community Applications apps no longer land almost all in «Other»: each one appears in its own category. (audit)
- Package Center: CasaOS and Big Bear apps ask for their settings at install (user, password, addresses) and the NAS generates any password you leave empty.
- Package Center: an app published under the same name by several authors appears once, with the most complete template.
- Package Center: Community Applications descriptions no longer show markup such as «[br]» or «[b]».
- Storage: a mirror of three or more disks shows the space that actually fits, the same figure the assistant gives, not two thirds of it. (audit)
- Storage: after restarting with a failed mirror disk, «Replace» no longer refuses: it mounts the volume with the remaining disks and replaces the missing one. (audit)
- Storage: a new disk larger than the one it replaces is used in full. (audit)
- Storage: whatever was written while the mirror was missing a disk is stored twice again once the replacement finishes. (audit)
- Notifications: when a volume is not mounted because a disk is missing, the alert no longer says it «keeps working»: it says its folders are unavailable until the disk is replaced.
- Shared folders: the administrator created in first setup now opens them from other computers with their NAS username and password. On a NAS already set up, tick «Shared folders» for them in User and group. (audit)
- VPN: the client configuration file and the address warnings come out entirely in the panel's language. (audit)
- Updates: each version's package carries the same number it is published under. (audit)
- The website: storage is described as it is: Btrfs by default, ZFS as an option, and parity (RAID 5/6) only with ZFS. (audit)
- The website: the feature list no longer says the NAS updates from a git repository: it uses signed packages. (audit)
- The website: the installation guide warns that the first boot, the long part, can take an hour or more. (audit)
- The website: the «What it can do» table is translated on the German site and no longer shows an empty card on the English one.
- The website and Package Center: they speak of around 3,000 community apps, not 2,000.
- The website: in the demo, window and tab titles follow the page language.
Security
- Updates: each version's signature is also checked by the part of the system that installs it. (audit)
- Updates: hardened updating from a git repository. (audit)
- Updates: building the interface no longer runs its dependencies' install scripts. (audit)
- First setup: the console account password is no longer stored in a file readable by the whole system. (audit)
- System helper: hardened argument validation for several internal commands, the shared-folder configuration filter and writes in data folders. (audit)
- Files: each folder's recycle bin can only be seen, emptied and restored by those with permission on it. (audit)
- Files: search only returns files from the searcher's own folders. (audit)
- Files: restoring previous versions requires write permission. (audit)
- Documents: hardened saving from the editor. (audit)
- SFTP: jailed accounts can no longer create links. (audit)
- Accounts: regenerating second-factor backup codes has the same attempt limit as signing in. (audit)
- Accounts: «Close all sessions» also renews the session key. (audit)
- Permissions: stricter administrator check. (audit)
- Invitations: an invitation link used twice at once sets only one password. (audit)
- Panel: live connections are only allowed to the NAS itself. (audit)
- Licence: a portal reply can no longer swap your licence for a worse one or expire the trial early. (audit)
- Package Center: recipes' example passwords are replaced at install with unique ones, shown on the app's page. (audit)
- Vaultwarden: installs with its own admin token and warns that sign-ups stay open until you close them. (audit)
- Whoever took over the panel can no longer take over the machine through a remote folder, a cloud or a disk mount.
- Remote folders: those added with older versions are now mounted without allowing setuid programs.
- LGM Connect: "Sign out" removes from the computer the password used to connect folders; the next time you connect one, it will ask for it.
- LGM Connect: removing a NAS from the app removes everything it kept: password, folders at startup and syncs.
- LGM Connect: an account name with commas or other signs can no longer slip options in when connecting a folder.
- LGM Connect: the window's internal key no longer travels to the NAS with every request.
- Application firewall: country blocking and «Deny» rules apply to their ports too, and closing an application also cuts connections already open. (audit)
- Firewall: a «Deny» rule for a device or network blocks even when a broader rule opens that port.
- Firewall: «Home network» counts only private home networks and the VPN, also with the NAS plugged straight into the fibre or modem. (audit)
- Log: firewall changes record the IP of whoever makes them.
- Machine console: the
lgmaccount password is hidden on the NAS screen; press C on that screen to see it for a minute. (audit) - Shared folders: whoever stops administering the NAS immediately loses network access to the administrators' folders.
- Shared folders: what the system creates, writes or deletes in them can no longer end up in someone else's folder by swapping a folder for a link mid-operation. (audit)
- Package Center: the page of an installed app warns if it still uses its recipe's example password, the same on every machine, and says what to do. (audit)
- Package Center: store recipes are written by the panel's user, not root, and links inside their folder are not followed.
