I’ve been trying to upgrade from 10.10 to 10.11 for a while now, as the Android TV app keeps nagging me, and every attempt ended with impossibly long library scan times.

After some thorough investigation, it appeared that a Home Videos type collection causes unending scan (yet to be solved), but also that Jellyfin does a lot of writes to the config directory (either database or metadata or both). Mine’s on spinning media part of a ZFS pool. I tried a few performance tuning options, such as testing the config dir with recordsize (similar to block size) of 4K, 8K, 64K, 128K and library scans fell from 30-40 minutes down to 8-13min with 4K-64K. The ZFS tuning wiki suggest 64K recordsize with LZ4 compression for SQLite workloads such as Jellyfin. That seems to work as well as 4K and 8K but likely is faster when reading thumbnails and such.

Note that upgrading to 12-rc3, which is supposed to speed up library scans did not improve scan times for me. Optimizing config/database write speed did. I cross-checked the culprit by experimenting with moving the config dir to NVMe and RAM. Both of those got the scan times down to 8-9 minutes compared to the optimized spinning media’s 12-13.

So if you had upgraded (or about to) to 10.11 your library scans are (about to get) dog slow and your Jellyfin’s config dir resides on spinning media, optimize its write performance for SQLite.

    • Blue_Morpho@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      arrow-down
      3
      ·
      edit-2
      2 days ago

      Which Plex does by default. He doesn’t understand that running Plex at home opens itself up to the Internet. I specifically referenced a CVE that let hackers into your home if you ran Plex.

      His claim that securing Jellyfin with an encrypted tunnel does nothing is false.

      • GoatSynagogue@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        1
        ·
        2 days ago

        He never claimed that in the comment you replied to.

        Plex doesn’t open a port to the internet at large, unsecured no less, like jellyfin does.

          • GoatSynagogue@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            ·
            2 days ago

            OK so you don’t understand networking, don’t understand how Plex works, don’t understand how that CVE does nothing of the sort, and have poor reading comprehension skills.

            I’d hate to be your poor server.

            • Blue_Morpho@lemmy.world
              link
              fedilink
              English
              arrow-up
              2
              ·
              1 day ago

              I quoted Plex documentation where it explains in detail that you need port 32400 OPEN for remote access. https://support.plex.tv/articles/200289506-remote-access/

              I linked the CVE but here is the plain language version because you didn’t read what I linked:

              https://www.howtogeek.com/over-300k-plex-servers-are-still-vulnerable-to-attackers-despite-emails/

              "The flaw has been assigned a CVSS score of 10.0, the highest possible level of severity. This score indicates that the vulnerability can be exploited remotely over the internet, is easy to execute, and requires no authentication or interaction from the server’s owner. A successful attack could result in a total loss of confidentiality, integrity, and availability. An attacker could access, modify, or delete a user’s private media files, or even disable the entire Plex server. "

              What the fuck is wrong with you?

              • GoatSynagogue@lemmy.world
                link
                fedilink
                English
                arrow-up
                1
                arrow-down
                2
                ·
                1 day ago

                You clearly don’t understand how Plex and port forwarding work if you think that is in any way the same as opening a port to the Internet for everyone to hit jellyfin with zero security on it.

                The CVE has been exploited zero times that we know of, and at worst they can delete your media files and Plex server. It’s never been reported of happening, and we have no idea how difficult it is to do - but because it hasn’t happened, it’s probably extremely hard and requires a chain of very unlikely things to have happened first.

      • Blue_Morpho@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        arrow-down
        3
        ·
        2 days ago

        He said an encrypted tunnel does nothing. I don’t even run Jellyfin but that statement is false.

        • MaggiWuerze@feddit.org
          link
          fedilink
          English
          arrow-up
          3
          arrow-down
          1
          ·
          edit-2
          2 days ago

          An encrypted tunnel and a reverse proxy are two very different things. He (I) never talked about a tunnel and neither did the comment I (he) responded to

          • Blue_Morpho@lemmy.world
            link
            fedilink
            English
            arrow-up
            1
            arrow-down
            2
            ·
            2 days ago

            The reason to run the reverse proxy with Jellyfin is for the encryption. It’s written in the documentation that way. It’s why I still run Plex. I never finished getting through their steps to get the reverse proxy setup for the encryption.

            It’s like I said you use a car to go to work and you reply AKSUALLY a car runs on TIRES. The OP didn’t say CAR.

            • MaggiWuerze@feddit.org
              link
              fedilink
              English
              arrow-up
              1
              arrow-down
              1
              ·
              1 day ago

              Having an https connection doesn’t do shit if the Backend is insecure. The issue with exposing Jellyfin are not man in the middle attacks, but badly managed access controls and unsecured endpoints.

              Thede issues and the unwillingness of the devs to fix them because they are hellbent on keeping a maximum of client compatibility is what makes it hard to trust the overall security of the project.

              That’s why basically everyone, including the devs, says to not do that and instead rely on a vpn to mitigate security risks.