Files
Bose-SoundTouch/scripts/on-device-install
Tobias GesellchenandClaude Sonnet 5 ec340847f2 fix(install): preflight disk-space check before replacing the live binary
The gzip fix in the previous commit only helps once a backup is being
made; it doesn't address the actual moment that broke on real hardware:
the cross-device mv/copy of the new binary into place ran out of space
mid-write, leaving a truncated, non-executable binary as the live one.
UBIFS is a log-structured flash filesystem, so space "freed" by
overwriting the old binary isn't guaranteed reusable in time for the new
one to land -- this happened on a device with 15.7MB available against
a ~14.8MB binary.

Add a preflight check before downloading anything: fetch the new
binary's real size via a HEAD request (adapts automatically as binaries
grow, instead of a threshold that goes stale every release) and compare
against available space plus a flat 5MB safety margin.

- Comfortably enough room for old + new + a compressed backup: proceed
  exactly as before, silently.
- Enough for old + new but not enough extra for a backup: warn
  interactively and require explicit confirmation before proceeding
  without one. Reads from /dev/tty since the script is normally piped
  via `curl | sh` (stdin is consumed by the script itself). Defaults to
  the safe choice (abort) on empty input, matching the [y/N] prompt.
  AFTERTOUCH_FORCE_NO_BACKUP=yes overrides for non-interactive/scripted
  use.
- Not enough room even for the replace itself: abort before starting
  the download, rather than attempting a doomed download/replace that
  could leave a truncated live binary.
- No TTY available and the operator didn't set the override: abort
  rather than silently guessing.
- HEAD request fails for any reason: skip the check with a warning
  rather than blocking the install on it.

Verified: all five decision branches (plenty of room, warn+decline,
warn+confirm, warn+forced-override, hard abort) produce the correct
result under both dash and a real BusyBox v1.38.0 container, including
the gzip/gunzip streaming backup and glob-based pruning from the
previous commit. The HEAD-request size lookup was separately verified
against a live GitHub release URL with real curl -- catching and fixing
a bug where naively taking the first "content-length:" header grabbed
the 302 redirect's (0), not the actual asset's, size. Not yet re-tested
end-to-end on real hardware.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-08-23 20:50:27 +02:00
..

On-Device Installer

Allows to run AfterTouch on SoundTouch devices directly, eliminating the need to run and maintain a separate server on the local network.

For a complete step-by-step walkthrough — from first SSH connection through verified radio preset playback — see docs/guides/ON-DEVICE-INSTALL-WALKTHROUGH.md.

Disclaimer

Invasiveness

AfterTouch usually normally migrates the SoundTouch devices very noninvasive, by changing the configuration of the device. Running AfterTouch on the device itself is slightly more invasive, because it needs to create a script that starts AfterTouch on boot.

AfterTouch Availability

Some devices will expose the AfterTouch port, some won't. We currently (May 2026) suspect that the newer generation devices (those with Bluetooth) will expose the port, while the older ones won't. We're still investigating how to expose AfterTouch on all devices.

If your device doesn't expose the port, you can still use the on-device installer, but you'll need to run AfterTouch on each one of your speakers individually and may only access AfterTouch via ssh port forwarding. This will also make OAuth authentication a little more tricky, but should also work via SSH port forwarding.

Space Limitation

The storage space on the SoundTouch devices is very limited — stock rootfs typically has only a few MB free (e.g. ~4 MB on the ST20, see issue #268), well below the AfterTouch binary's ~12 MB. To work around this, the installer puts everything on /mnt/nv/aftertouch by default (the persistent partition, typically ~30 MB free) and points /opt/aftertouch at it via a symlink so the init script and runtime paths stay unchanged. Override the install target with INSTALL_DIR=/some/path if you've got room elsewhere.

The space limitation also means we are currently unsure on how to update the system, because two binaries are already too large. We are currently working on this - both by checking how we can make the binaries smaller, but also on how we can extend the storage space (e.g. by running AfterTouch from a USB drive).

Logs

The daemon writes to BusyBox syslog (tagged aftertouch) rather than to a file. Disk usage stays bounded — the syslog ring buffer is in memory — and the same logread recipe used elsewhere in this project works:

logread        | grep aftertouch | tail -20   # recent entries
logread -f     | grep aftertouch              # live tail

If the install command reports "running but :8000 not responding" or aftertouch status reports the listener is down, the syslog tail is the first place to look.

Installation

Enable SSH on your SoundTouch device using the usual "Stick with remote_services" method. Connect with the following command.

ssh -oHostKeyAlgorithms=+ssh-rsa root@<IP_ADDRESS_OF_SPEAKER>

Then, run the following command to install AfterTouch on the device.

rw && curl -sSL https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/install.sh | sh

This installs the latest release by default (the script resolves it from GitHub's releases/latest redirect). To pin a specific version, see Updating AfterTouch below.

After the installation check if you can access AfterTouch from your local device by navigating to http://<IP_ADDRESS_OF_SPEAKER>:8000. If you can access the AfterTouch UI, you're good to go!

If http://<IP_ADDRESS_OF_SPEAKER>:8000 fails: SSH port forwarding

On some device models AfterTouch's port is reachable from other machines on your LAN out of the box. On others (see issue #196) it isn't, and (unlike the phrasing this README used to have) that's not AfterTouch or its firewall configuration choosing to bind loopback-only. AfterTouch itself binds 0.0.0.0 (all interfaces) correctly, confirmed by inspecting the running device directly, and there's no firewall rule (iptables, nftables, or otherwise) blocking it either.

Current knowledge (2026-08-16), confirmed on real hardware via a decrypted firmware backup plus simultaneous packet captures on both the speaker and a client machine: some SoundTouch models built around a "combo" WiFi/Bluetooth co-processor (used for AirPlay) route LAN traffic through that co-processor before it reaches the main application processor where AfterTouch actually runs. That co-processor only relays a fixed set of the device's own original service ports (the same ones the stock SoundTouch app and companion services always used), a list that, as far as we can tell, is compiled into the co-processor's own firmware. AfterTouch's ports were never part of that original design, so they never got included. This isn't a bug in AfterTouch, a router/firewall setting, or WiFi client isolation; all three were separately ruled out.

The installer works around this automatically. On an affected speaker it redirects one of the ports the co-processor does relay to AfterTouch, so the UI is reachable from the LAN without any tunnel:

http://<IP_ADDRESS_OF_SPEAKER>:17008

Port 17008 is Bose's software-update listener; that cloud service no longer exists, so taking over its inbound traffic costs nothing. Only traffic from other machines is affected; anything running on the speaker still reaches AfterTouch on :8000 as before. Change or disable this with AFTERTOUCH_LAN_PORT (auto / none / a port number) in /opt/aftertouch/aftertouch.conf, or pass it at install time:

rw && curl -sSL https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/install.sh | AFTERTOUCH_LAN_PORT=none sh

aftertouch.conf isn't limited to AFTERTOUCH_LAN_PORT. The init script exports every assignment in this file into the daemon's own environment, so any env var soundtouch-service reads (see the configuration table) can be set the same way — for example, to change the admin credentials:

MGMT_USERNAME=admin
MGMT_PASSWORD=change-me

Edit /opt/aftertouch/aftertouch.conf over SSH, then /etc/init.d/aftertouch restart to apply. DEPLOYMENT_MODE=on-device is already set by the init script itself — it never needs to be added here. The auto-export behavior described here needs a build including the fix for issue #546; older installs (before aftertouch.conf even existed, or between then and that fix) need to reinstall/update first.

Which models need this, and how to report one that isn't listed yet, is tracked in MODEL-SUPPORT-MATRIX.md. The SSH tunnel below still works, and remains the better route for linking music-service accounts: Spotify only accepts https:// or loopback OAuth redirect URIs, so http://localhost:8000 through a tunnel succeeds where a plain LAN address is rejected.

Open a fresh terminal on your own machine (Linux/macOS/Windows — NOT another shell inside the speaker's SSH session — see issue #250 for the trap that catches everyone here) and run:

ssh -oHostKeyAlgorithms=+ssh-rsa -L 8000:localhost:8000 root@<IP_ADDRESS_OF_SPEAKER>

The -oHostKeyAlgorithms=+ssh-rsa flag is required: SoundTouch speakers offer only legacy SSH host-key algorithms (ssh-rsa, ssh-dss) that modern OpenSSH clients refuse by default. Without it you'll see Unable to negotiate with <ip> port 22: no matching host key type found.

Leave that terminal open while you use AfterTouch. With the tunnel up, navigate to http://localhost:8000 in your browser (localhost, not the speaker's IP).

If the tunnel is open but http://localhost:8000 still fails

You should see ERR_CONNECTION_RESET in the browser and channel N: open failed: connect failed: Connection refused in the SSH terminal — that means the tunnel itself works, but the AfterTouch daemon isn't listening on the speaker. Inside the SSH session, check:

netstat -tlnp 2>/dev/null | grep 8000     # is anything listening?
ps | grep -i aftertouch                   # is the daemon running at all?
logread | grep aftertouch | tail -20      # recent daemon output (panics, errors)

If the daemon isn't running, restart it:

/etc/init.d/aftertouch start
/etc/init.d/aftertouch status

The init script's status now distinguishes "running with listener up" from "PID alive but listener silently died" — if you get the latter, the syslog tail above will tell you why.

Updating AfterTouch

Run the installer again with the version you want to install. The script backs up the currently-running binary (named after its version), installs the new one, and prunes older leftover artefacts to keep /mnt/nv free.

Install (or upgrade to) a specific version — three equivalent ways:

# 1. Environment variable — goes on `sh`, not `curl`: in a pipe, each
#    command is a separate process, so `VERSION=X curl ... | sh` silently
#    does NOT set it for `sh` (the one that actually reads $VERSION).
rw && curl -sSL https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/install.sh | VERSION=0.123.0 sh

# 2. Command-line flag (pass args after `sh -s --`)
rw && curl -sSL https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/install.sh | sh -s -- --version 0.123.0

# 3. Download first, then run with a flag
curl -sSLo install.sh https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/install.sh
sh install.sh --version 0.123.0

Running without a version override installs the latest release: the script follows GitHub's https://github.com/gesellix/Bose-SoundTouch/releases/latest redirect to discover the newest tag. If that lookup fails (offline, or a curl build without -w support), it falls back to a pinned version baked into the script.

Tip — rollback: if the new binary misbehaves, the installer left a backup file alongside it, gzip-compressed as .backup.gz (plain .backup, uncompressed, if gzip wasn't available on your device):

ls /mnt/nv/aftertouch/aftertouch-service*.backup*
# .backup.gz (compressed):
gunzip -c /mnt/nv/aftertouch/aftertouch-service.<old-version>.backup.gz \
   > /mnt/nv/aftertouch/aftertouch-service
chmod +x /mnt/nv/aftertouch/aftertouch-service
# or, for an uncompressed .backup:
cp /mnt/nv/aftertouch/aftertouch-service.<old-version>.backup \
   /mnt/nv/aftertouch/aftertouch-service
/etc/init.d/aftertouch restart

Uninstallation

Before uninstall, you might want to revert the migration, especially the changes to the server URLs (even though having configured an unresponsive local server probably is about as bad as having configured unresponsive Bose servers). To uninstall AfterTouch, run the following command on the speaker.

curl -sSL https://raw.githubusercontent.com/gesellix/Bose-SoundTouch/main/scripts/on-device-install/uninstall.sh | sh