v0.152.0 + felhom-samba 1.1.0 — mDNS for macOS, and the card stops offering a dead form

Capture on the box disproved the first theory: macOS DOES send a correct NBNS
query for <NAME><20> and nmbd DOES answer it correctly in 140us (flags 0x8580,
RCODE=0, right address) - macOS just never acts on it. NetBIOS there feeds
legacy browsing, not smb:// URL resolution, so the bare name can never work on
a Mac and nmbd was never the broken part.

felhom-samba 1.1.0 adds avahi + dbus, with avahi-daemon.conf and the _smb._tcp
service file templated from FELHOM_SERVER_NAME so a rename re-advertises. Both
daemons are non-fatal on failure - a discovery gap must not become an outage.

v0.151.0's card offered smb://<NAME> for Mac, which is exactly the dead form;
now smb://<NAME>.local. Windows keeps the flat \\<NAME>, which nmbd serves
correctly. Red-proofed both directions.

NOT claimed: Finder-sidebar discovery - published and answering on the wire,
but not observed working on the test Mac. Recorded OPEN.

TestRenderSambaCompose pinned the literal 1.0.0 tag, so an image bump read as a
renderer regression; now derives from SambaImage and asserts non-:latest.
This commit is contained in:
2026-07-20 13:38:07 +02:00
parent 5c105fb49b
commit 37e12c82a7
8 changed files with 184 additions and 17 deletions
+18 -3
View File
@@ -9,13 +9,28 @@
# in Explorer but the double-click fails 0x80070035 (no flat-name resolution);
# nmbd is what makes \\<NAME> resolve + mount (S4b, proven live).
# - wsdd : WS-Discovery, so the box appears in Windows Explorer's Network view.
# - avahi : mDNS/Bonjour (v1.1.0) — THE macOS path. Windows and macOS do not share a
# discovery mechanism, and nmbd does not cover the Mac: captured live on
# 2026-07-20, macOS broadcasts a correct NBNS query for FELHOM<20>, the box
# answers correctly in 140us (flags 0x8580, RCODE=0, the right address), and
# macOS REFUSES TO ACT ON IT — no TCP follows. NetBIOS feeds legacy browsing
# there, not smb:// URL resolution. With mDNS, `smb://<NAME>.local` connects
# immediately — PROVEN live from a Mac on 2026-07-20.
# NOT proven: automatic appearance in the Finder sidebar. The _smb._tcp record
# is published and answers browse queries on the wire, but the test Mac's
# sidebar stayed empty (it had no Network/Bonjour section shown at all, which
# is a Finder Settings -> Sidebar toggle). Treat sidebar discovery as an OPEN
# question, not a shipped feature.
# Evidence: felhom.eu/documentation/audits/DIAG-sharing-2026-07-20.md.
FROM alpine:3.21@sha256:48b0309ca019d89d40f670aa1bc06e426dc0931948452e8491e3d65087abc07d
# samba = smbd + nmbd + smbpasswd/testparm (meta-package proven installable in the spike);
# wsdd = WS-Discovery daemon; tini = a proper PID1 to reap nmbd/wsdd and forward signals.
RUN apk add --no-cache samba wsdd tini \
# wsdd = WS-Discovery daemon; tini = a proper PID1 to reap nmbd/wsdd/avahi and forward signals;
# avahi + dbus = mDNS/Bonjour (avahi-daemon talks to the system bus, so dbus is not optional).
RUN apk add --no-cache samba wsdd tini avahi dbus \
&& rm -rf /var/cache/apk/* \
&& rm -f /etc/samba/smb.conf
&& rm -f /etc/samba/smb.conf \
&& rm -f /etc/avahi/services/*.service
# passdb on a named volume → the household SMB password survives container recreation
# (share add/remove re-renders + `compose up -d`, which recreates the container).
+52 -2
View File
@@ -23,11 +23,61 @@ fi
mkdir -p /var/lib/samba/private /run/samba
echo "[felhom-samba] launching nmbd + wsdd + smbd (server=${SERVER_NAME} iface=${IFACE} uid=${FELHOM_UID})"
# --- mDNS / Bonjour (v1.1.0) -------------------------------------------------------------
# THE macOS path. Templated from SERVER_NAME rather than baked, so renaming the server in the
# UI re-advertises under the new name on the next container recreate — a baked name would
# leave the box answering to something the customer no longer sees anywhere.
#
# A STATIC service file, deliberately, rather than smbd's own `multicast dns register`: it
# needs no line in smb.conf (which is bind-mounted READ-ONLY and owned by the controller's
# renderer) and it lets us publish _device-info._tcp so the Finder shows a sensible icon
# instead of a generic globe.
mkdir -p /etc/avahi/services /run/dbus
cat > /etc/avahi/avahi-daemon.conf <<CONF
[server]
host-name=${SERVER_NAME}
use-ipv4=yes
use-ipv6=no
allow-interfaces=${IFACE}
ratelimit-interval-usec=1000000
ratelimit-burst=1000
# nmbd: NetBIOS flat-name resolution so \\<NAME> resolves and mounts (the S4b fix).
[wide-area]
enable-wide-area=no
[publish]
publish-addresses=yes
publish-hinfo=no
publish-workstation=no
CONF
cat > /etc/avahi/services/smb.service <<CONF
<?xml version="1.0" standalone='no'?><!DOCTYPE service-group SYSTEM "avahi-service.dtd">
<service-group>
<name replace-wildcards="yes">%h</name>
<service>
<type>_smb._tcp</type>
<port>445</port>
</service>
<service>
<type>_device-info._tcp</type>
<port>0</port>
<txt-record>model=RackMac</txt-record>
</service>
</service-group>
CONF
echo "[felhom-samba] launching nmbd + wsdd + avahi + smbd (server=${SERVER_NAME} iface=${IFACE} uid=${FELHOM_UID})"
# nmbd: NetBIOS flat-name resolution so \\<NAME> resolves and mounts on WINDOWS (the S4b fix).
# It does NOT serve macOS — see the Dockerfile header for the captured proof.
nmbd --daemon --no-process-group
# wsdd: WS-Discovery so the box appears in Windows Explorer's Network view.
wsdd -i "$IFACE" -4 -H 4 -s -n "$SERVER_NAME" -w WORKGROUP &
# dbus + avahi: mDNS, so `smb://<NAME>.local` resolves and the box appears in the Finder sidebar.
# Non-fatal on failure: sharing over an address still works, and refusing to start smbd because
# a discovery daemon did not come up would turn a convenience gap into an outage.
dbus-daemon --system --fork 2>/dev/null || echo "[felhom-samba] WARN: dbus failed to start — mDNS disabled"
avahi-daemon --daemonize --no-drop-root 2>/dev/null || echo "[felhom-samba] WARN: avahi failed to start — mDNS disabled"
# smbd in the foreground = the container's main process.
exec smbd --foreground --no-process-group