Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released!

Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released!

Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released. This synchronized release brings together some notable improvements in the heartbeat protocol. These enhancements allow a Relay operator to push stats and information to Directory servers automatically, keeping information up to date.

Live installations of the Relay and Directory may be found at:

https://directory.argentwolf.org

https://relay.argentwolf.org

On the Relay itself, the policy information will be presented on the default home page:

On the Directory, this information will be reflected as well with time stamps on when it was received and last checked for health by the Directory:

Other relays may be manually added to the Directory by the Directory operator/Admin. I have manually collected a list of Fediverse relays and populated my Directory installation with information about them. These sites are not automatically updated with regard to policy, but are verified as reachable by the Directory server.

Relays that are restricted (Approval Required) or closed to sign ups will appear as such on the Directory. Relays that go offline or are otherwise unreachable will appear in the offline list, eventually moving to the Graveyard after 30 days of offline time. Offline relays can be added the the Directory, but they will not become visible on the index until they pass an online check.

As always, if you want to make your own front facing website, you can disable the built in pages and use your own endpoints!

Comments, feedback, and bug reports are all welcome! Repo links below, available in both .deb and docker images. If you found these useful, please consider a tip to my Ko-fi to support further development! Thank you!

https://github.com/thystra/Activity-Relay

Activity-Relay 3.1.0

  • Added Activity-Relay Directory Protocol v2 profile synchronization and Protocol v3 participating-site telemetry.
  • Added automatic Directory reconciliation on relay startup, including an immediate heartbeat for already-registered relays.
  • Improved manual Directory register, heartbeat, and sync commands so they coordinate cleanly with the background scheduler.
  • Added richer relay profile metadata for registration status, topics, languages, regions, contact details, and related information.
  • Added --test-config validation with safer handling of optional profile errors.
  • Added optional SUPPORT information to the generated relay website, including links and plain-text values such as cryptocurrency addresses.
  • Hardened the outbound Directory client against malformed responses, unsafe redirects, oversized responses, and other hostile input.
  • Improved static-site tooling, operator documentation, and deterministic release packaging.
  • Preserves existing relay identity, Redis state, subscriptions, delivery behavior, and queue compatibility.
  • Published for linux/amd64 and linux/arm64 at ghcr.io/thystra/activity-relay:3.1.0.

https://github.com/thystra/activity-relay-directory

Activity-Relay Directory 1.3.0

  • Added source-aware relay profiles with per-field precedence: override > relay > csv.
  • Added bounded CSV import/export for relay metadata, including profile-change previews before applying updates.
  • Added support for updating metadata on already-known relays even when they are currently unreachable.
  • Added Activity-Relay lifecycle Protocol v2 profile synchronization and Protocol v3 participating-site telemetry while retaining Protocol v1 compatibility.
  • Treats successful authenticated registration as current relay-liveness evidence, improving restart and recovery behavior.
  • Expanded /v2/relays and the public Directory with profile information, site counts, and Open/Restricted/Closed registration status.
  • Preserves the existing four operational tiers: Heartbeat + Online, Online, Offline/Unreachable, and Graveyard.
  • Added configurable Directory title, banner, support information, and improved operator-facing presentation.
  • Keeps descriptive metadata separate from reachability, heartbeat health, moderation, pruning, and tier placement.
  • Upgrades existing databases in place to schema 12 while preserving the frozen /v1/relays compatibility API.
  • Published for linux/amd64 at ghcr.io/thystra/activity-relay-directory:1.3.0.

Activity Relay Directory 1.2.0 Released

Activity-Relay Directory 1.2 expands relay discovery, long-term availability tracking, and the public-facing Directory while preserving the authenticated V1 lifecycle protocol and the frozen /v1/relays compatibility API.

Highlights

  • More resilient relay discovery and bulk imports
  • Retention and automatic retry of unavailable relay candidates
  • ActivityStreams Group relay actor support
  • Four public operational relay tiers
  • 30-day transition to the Graveyard tier
  • Aggregate online, offline, and pending-verification counts on the public-facing Directory page
  • Local tier-scoped exports and public plain-text relay downloads
  • Automatic recovery of previously unavailable relays
  • Debian upgrade handling that reloads systemd definitions without automatically restarting an active Directory

Activity Relay Directory 1.2.0 can be downloaded from here: https://github.com/thystra/activity-relay-directory/releases/tag/v1.2.0

A working example of Activity Relay Directory may be found at https://directory.argentwolf.org

If you find this useful, please consider tipping me at my ko-fi! Thanks!

ARD 1.3 is mapped out and will be paired with a synchronized release of Activity Relay server. The 1.3 edition will allow for additional information, e.g. notes, state, and filtering, to be provided by Relay server operators rather than manually input by the Directory server operator/admin.

Activity Relay 3.0.1 maintenance release

30 Sep 2026

Activity Relay 3.0.1 has been released to fix a couple bugs caused by invalid follower states blocking relay operation.

https://github.com/thystra/Activity-Relay/releases/tag/v3.0.1

Activity-Relay 3.0.1 is a focused reliability release for follower-state handling and relay fan-out.

Fixed

  • Prevent stale mutual-follow responses from recreating incomplete Redis follower records.
  • Validate follower state before persistence.
  • Ignore malformed persisted follower records when loading relay state.
  • Isolate invalid or unplannable delivery targets so one bad receiver cannot abort healthy fan-out.
  • Keep queue reservations and remaining-delivery counts aligned with deliveries actually planned.
  • Harden manual follower acceptance ordering.
  • Update Forgejo container/release CI for Debian Trixie’s split Docker client packages.

No configuration or data migration is required.

The 3.0.1 candidate was production-tested on relay.argentwolf.org, including real WordPress fan-out to healthy Friendica and Mastodon receivers while an independently failing receiver continued through its isolated retry path.

Container: ghcr.io/thystra/activity-relay:3.0.1

See docs/releases/v3.0.1.md and CHANGELOG.md for complete details.

The attached files are the exact canonical artifacts produced and accepted by the Forgejo release workflow.

If you find this useful, please consider leaving a tip on my Ko-Fi – https://ko-fi.com/thewolfandtheraven

Jellyfin Hotcache & Hardened Jellyfin Docker Images

I’m pleased to announce the release of Jellyfin Hotcache. This is a helper for Jellyfin that I built to address a fairly simple problem: my kids love to watch the same media over and over, but I’d rather they not spin up the NAS drives every time they want to watch the same episode again.

Jellyfin Hotcache identifies frequently and recently played media and stages a copy on a specified cache drive—ideally an SSD or NVMe device. It preserves the original media on the slower storage, renames that copy for safekeeping, and replaces Jellyfin’s original media path with a symlink pointing to the cached copy.

This helps reduce unnecessary spin-ups of the media drives and can improve playback startup and access times for frequently watched content.

https://github.com/thystra/hotcache-for-jellyfin

Version 1.0.3 has now been released, including several reporting and operator-visibility improvements:

https://github.com/thystra/hotcache-for-jellyfin/releases/tag/v1.0.3

Hotcache is packaged for Debian/Ubuntu-compatible Linux systems. It supports Jellyfin playback history stored in both SQLite and PostgreSQL, and works with both bare-metal and containerized Jellyfin installations. Container installations require the cache directory to be mounted into Jellyfin at the same absolute path so that Jellyfin can follow the cache symlinks.

Hardened Jellyfin Docker Images

Along with Hotcache, I’ve also put together some updated and hardened Jellyfin 10.11.11 Docker images.

These images address CVE-2026-8461, an FFmpeg MagicYUV decoder vulnerability that can result in an out-of-bounds write and potentially remote code execution when a malicious media file is processed.

https://nvd.nist.gov/vuln/detail/cve-2026-8461

The hardened Jellyfin 10.11.11 images use a custom Jellyfin FFmpeg 7.1.4 build with the affected MagicYUV decoder disabled. This mitigates CVE-2026-8461 while retaining Jellyfin’s expected hardware-acceleration support.

I’ve also repackaged the Jellyfin PostgreSQL images with separate PostgreSQL 17 and PostgreSQL 18 client-tool variants. Jellyfin’s PostgreSQL backup functionality relies on tools such as pg_dump, and pg_dump cannot back up a PostgreSQL server running a newer major version than the client itself. After I upgraded my database server to PostgreSQL 18, the older client tools in the Jellyfin image could no longer perform the backup.

The resulting images provide explicit PG17 and PG18 variants and are available for both amd64 and arm64:

https://github.com/thystra/jellyfin-security-images

Jellyfin 12.0 and later currently use Jellyfin FFmpeg 8.1.2 or newer, which contains the upstream fix for CVE-2026-8461, so these hardened FFmpeg images are primarily intended for users remaining on Jellyfin 10.11.11.

If you find any of this useful, I appreciate any tips at my Ko-fi!!

https://ko-fi.com/thewolfandtheraven

Wacky Wednesday

2 Sep 2026

We tried a little experiment, well two actually. One was cutting back the feed for the chickens, and two was using the Tractor Supply delivery service.

Cutting the feed back wasn’t that great. It caused a slow down in their eggs, and I’m not sure if it is related or not, but seemed to trigger a molt. Egg production pretty much stopped (writing this a couple weeks in the future..) and took a while to recover.

Tractor Supply also took their time delivering, missing the original promise date and stretched out the delivery over a few days. That was a little annoying as well.

Read more