* fix(stalker): keep live search within the selected category
* test(stalker): assert retained video ownership without source timing
* test(stalker): distinguish paged All Items from the initial cache grid
* fix(stalker): reveal remote selections in uncached search results
* test(stalker): wait for category rows and retain settled playback
* fix(migration): recover legacy desktop sources without replacing current data
* test(migration): cover legacy recovery IPC contracts
* test(migration): use static legacy Electron bootstrap
* fix(playback): apply themes to player and EPG panels
* test(playback): verify active recording icon theme
* fix(epg): keep loading shimmer visible in both themes
* fix(playback): close legacy picture-in-picture on video replacement
* test(playback): wait for the selected video before PiP setup
* test(playback): await changed settings before PiP navigation
* fix(playback): release legacy WebKit picture-in-picture
`epgTimestampMs` in the dashboard live-EPG helpers returned
`EpgProgram.startTimestamp`/`stopTimestamp` as-is, but those fields are
unix SECONDS everywhere else (`getProgramTimeMs` in `@iptvnator/ui/epg`
multiplies by 1000). The bug was latent: the backend
`GET_CURRENT_PROGRAMS_BATCH` rows never set the fields, so the ISO
fallback always ran.
Scale a positive finite timestamp by 1000 and treat zero/non-finite
values as absent, mirroring `getProgramTimeMs`. Add a dedicated spec
that feeds seconds-based timestamps and asserts the formatted range and
progress, and fix the rails component spec fixture, which stored
millisecond values in the seconds fields and so encoded the old bug.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Adds a global EPG display-time offset (Settings → EPG, whole minutes, ±720) for guides whose provider labels programme times with the wrong timezone. Display-only: parsed XMLTV values, SQLite rows, catch-up URLs and recording snapshots keep the provider's own times, so changing it needs no guide refresh. Closes the global part of #50.
The contract lives in `libs/shared/interfaces/src/lib/epg-display-offset.util.ts` with two equivalent forms: `epgDisplayTimeMs` shifts a programme for display, `epgProviderClockMs` shifts "now" into the provider's clock for every "currently airing" decision — the batched `GET_CURRENT_PROGRAMS_BATCH` lookup takes an explicit `nowMs`, and the channel lists, the Xtream/Stalker previews, the M3U player's current-programme mirror, the unified collection resolver, the dashboard live cards and the recording overlap all pick the same programme the guide renders as "now". Portal short-EPG windows start at the provider's own "now", so under a non-zero offset the Xtream preview surfaces cut their window from the full guide at the provider clock, Stalker short-EPG requests are widened for negative offsets, and every per-stream memory of the previous offset is retired together when the setting changes.
Co-authored-by: Mark Jardine <markjardine27@gmail.com>
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
* fix(playback): seek Embedded MPV steps relative to mpv's own position
Arrow keys and the ±10 s buttons in the Embedded MPV player advanced only
about a second per press when pressed repeatedly or held. The shortcuts
already asked for 5 s steps, but `EmbeddedMpvCommandRunner.seekBy` turned
each step into an absolute `seek` computed from `session.positionSeconds`,
which is floored to whole seconds, polled every 500 ms (helper snapshots at
most every 250 ms) and not refreshed by the seek reply. Every press inside
that window therefore landed on the same target.
Steps now go through a new `EMBEDDED_MPV_SEEK_BY` IPC / `seekEmbeddedMpvBy`
bridge method that every backend forwards as mpv `seek <delta>
relative+exact`: `seekBy` exports in the macOS addon and the Windows/Linux
`wid` addon (Linux over its JSON IPC socket), and a `seek-by` stdin command
in the frame-copy helper. mpv resolves the delta against its own position
and merges queued relative seeks, so presses accumulate as in mpv itself.
The absolute form survives only as a fallback for a preload without the
method or an addon binary without `seekBy`; the timeline scrub still
commits an absolute target.
Validated with a real mpv 0.39 IPC probe: three relative seeks in a burst
advance +15 s, three absolute seeks from one stale base advance +5 s.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(playback): drop speculative position update from relative Embedded MPV seeks
Review follow-up for the relative seek path.
The macOS and Windows/Linux `seekBy` exports advanced `snapshot.positionSeconds`
by the delta after dispatching the mpv command. That is not idempotent the way
the absolute seek's optimistic write is: the observer (mpv event thread, or
the Linux IPC poll) can already have stored the post-seek `time-pos` under the
same mutex, so adding the delta on top counted the step twice, and while paused
nothing corrected it. On Linux it also advertised a position that a failed
socket delivery never reached. Relative steps now leave the snapshot alone;
only the observed `time-pos` updates the position.
The packaged Linux frame-copy smoke now drives `seekEmbeddedMpvBy` through the
built app: a burst of three +2 s steps issued without waiting for snapshots has
to land on 6 s, and a -60 s step has to clamp at 0. The generated Y4M fixture
grows from 2 s to 12 s (about 415 KB) so the burst and the playing section that
follows stay inside the clip. Replayed against a local mpv 0.39 with the same
fixture and media server: burst -> 6.0, -60 -> 0.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* docs(agents): mirror the Embedded MPV relative-seek contract into AGENTS.md
Review follow-up: the Shared Player Controls section documents the frame-copy
commands and shortcuts, so the relative seekEmbeddedMpvBy invariant lives
there too, next to the CLAUDE.md note.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
* fix(playback): reject a Linux relative seek the mpv IPC socket did not accept
Review follow-up: the Linux branch of SeekBy discarded the socket transaction
result and returned normally, so a step that never reached mpv looked like a
seek still awaiting observation. It now throws like a failed mpv_command_async
on the in-process engines; the renderer swallows the rejection and resyncs
from the next snapshot, and the main process logs it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Follow-up to #1516 for the vendor-chrome path (shared controls opted out). With
Video.js's own controls, Chromium leaves a clicked control-bar button focused,
and a focused Video.js component captures the keyboard entirely, so after
clicking fullscreen Space left fullscreen instead of pausing and the seek,
volume and mute keys did nothing until the user clicked the video. ArtPlayer
and the native HTML5 controls were verified unaffected.
The legacy Video.js chrome now releases the focus a pointer interaction leaves
on a control (vjs-pointer-focus-release.ts). The release is scoped to the
.vjs-control-bar and pointer-attributed, and runs on both focusin (focus
landing on a control, e.g. a menu handing focus to its button) and click (a
control clicked while already focused, which fires no focusin); keyboard Tab
focus and modal-dialog focus traps are preserved. The eligibility helper is
shared with ControlsSurface via pointer-focus-release.ts.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
🤖 Generated with [Claude Code](https://claude.com/claude-code)
Extra libmpv options (Settings > Playback) reach every embedded engine off the command line (createSession array on Windows/macOS, a 0600 --include file on Linux native-view, a stdin preamble for the frame-copy helper); the keys the embed depends on are refused, and keys libmpv rejects are reported once per session. Dropped streams reload automatically (error, or ended on live) with 2 s -> 30 s backoff, six attempts per outage and a 30 s stability reset, only for a load that already played; engine failures stay terminal, a running recording is filed as interrupted and restarted after the reload, and an external subtitle file is re-added. Settings.embeddedMpvAutoReconnect (default on) opts out; the player shows 'Reconnecting... attempt N of M'.
Started by Bpl5966 in #1515 and finished by the maintainers in the same PR.
Co-authored-by: Bpl5966 <amine.b1959@gmail.com>
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Publish "How to Connect a Stalker or Ministra Portal to IPTVnator": the
portal URL shapes discovery accepts, MAC normalization, the optional
serial/device-ID/signature fields and the pinning rules behind the
"generate device IDs" toggle, what endpoint discovery does on Add, the
sections a portal source gets, Account info, and a troubleshooting list
built from the app's own refusal messages, plus a seven-question FAQ.
The guide is cross-linked from the download pages and llms.txt.
Guide screenshots come from the capture script. Shots that walk into a
Stalker portal start the stalker-mock-server and seed its marketing-demo
portal for that run only, so release shots never gain a third source
card. The frame guard allowlists exactly that scenario's MAC and keeps
rejecting every other MAC-shaped string.
To keep the live-TV frame free of third-party images, the fictional live
channel list and the channel-logo SVG renderer move into
@iptvnator/shared/marketing-fixtures; both mocks now serve
/assets/marketing/logo/<slug>.svg, the Stalker marketing-demo scenario
builds its ITV categories, channels and schedule from those fixtures
instead of faker names with picsum logos, and the mock resolves asset
URLs on get_all_channels too, which is the response the app renders
the channel list from.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Switching the Live TV or radio category in the shell context panel tore
down the Stalker player: `onStalkerCategoryClicked` cleared the selected
item for every section, and the live layout gates its player on
`selectedItem`. Xtream live (#936) and M3U groups already keep the channel
playing across a category/group switch.
- Context panel: return before `clearSelectedItem()` for `itv`/`radio`;
VOD/series clicks still drop the open detail before navigating.
- Live layout: the category-change reset effect no longer wipes the
playing channel's short-EPG fallback or cancels a fallback load in
flight; only a section change (itv <-> radio) does that now.
- Regression coverage in the context panel spec, the live layout spec and
a new web E2E scenario; docs and a `.changes/` note added.
Co-authored-by: Claude Fable 5.1 <noreply@anthropic.com>
Chromium focuses a clicked <button>, and a focused control captures the
keyboard: Space and Enter activate it again, and ControlsShortcuts yields
to any interactive element in the key's path. After a click on the
fullscreen button, Space left fullscreen instead of pausing and the seek,
volume and mute keys did nothing until a click on the video took focus
away. Follow-up to #1512, which stopped that focus from pinning the bar
but left it on the button.
A completed pointer click now releases the focus it left on the control
(onBarClick -> ControlsSurface.releasePointerFocus). The click is
attributed by its pointerType (empty for Enter/Space activation and
element.click()), with the legacy MouseEvent fallback answered once per
recorded press, so keyboard activation keeps focus where Tab put it.
Only buttons and range sliders are released. Chromium keeps its
sequential-focus starting point at the blurred control, so a later Tab
continues from it. The release dispatches a focusout while the pointer
still rests on the control, so the volume anchor ignores it instead of
closing the popover under the hovering mouse.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Settings > General gains "Window on startup" (normal / maximized /
fullscreen), Electron only, mirrored into the main-process config by
SETTINGS_UPDATE and applied at the next window creation. `--fullscreen`
forces one fullscreen launch (consumed by the first window). F11 toggles
OS-level fullscreen through WINDOW:TOGGLE_FULLSCREEN — the exit path on
Windows/Linux where the title bar is hidden — and is skipped while the
player owns document.fullscreenElement.
attachWindowStateEvents tracks native and HTML fullscreen as two flags,
since Electron leaves only the HTML state when the window was already
natively fullscreen. macOS ignores the constructor `fullscreen` option on a
hidden window, so ready-to-show repeats the request after show(). Toggles
are decided by an observe-only, event-fed tracker
(native-fullscreen-transitions.ts), never against isFullScreen().
Closes#1455
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Chromium focuses a clicked <button>, so the shared controls bar treated every
mouse click on a control (fullscreen, mute, ...) as keyboard navigation and
pinned itself open until a click on the viewport took focus away — a click
that also paused playback. Most visible on Embedded MPV frame-copy after
entering fullscreen; reproduces on HTML5, Video.js and ArtPlayer too.
Only keyboard-originated focus pins the bar now: pointer-attributed focus
reveals without a pin, the press record is discarded on the first bar focus
event or any keydown, a pointerdown inside the bar releases a keyboard pin,
and a keydown bubbling out of a bar control re-pins it.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
The HTML5 player chose its engine by exclusion: anything that was not
mpd/ts/mp4 went to hls.js, so .mkv (the default Xtream series/VOD
container), .webm, .avi, .mov and .m4v were fed to hls.js as manifests.
hls.js raised a manifest error and the player showed the network/provider
diagnostic over media Chromium plays natively.
Add resolvePlaybackUrlSourceKind() to @iptvnator/playback/util as the one
URL-to-engine rule (mpd -> dash, m3u8/m3u -> hls, ts/m2ts/extension-less
-> mpegts, everything else -> native) and read it from both the HTML5
player and ArtPlayer's getArtPlayerVideoType(), so the two engines agree.
ArtPlayer serves every native container through a single
ART_PLAYER_NATIVE_SOURCE_TYPE custom type, keeping the source session the
owner of teardown and controls binding. The HTML5 native <source> carries
the video/mp4 hint only for MP4-family files: a hint the browser's
canPlayType() rejects makes it skip the source, and Chromium demuxes
containers it does not advertise there.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
WebPlayerViewComponent remounts the engine component for every playback
application, and the DOM Fullscreen API exits the moment its element leaves
the document. The fullscreen element was the engine shell, so every next-
episode click, autoplay hand-off, channel zap and alternative-source switch
dropped the viewer back to the page.
app-player-controls gains a `fullscreenTarget` input; HTML5, Video.js,
ArtPlayer and Embedded MPV forward it, and WebPlayerViewComponent passes its
own host element, which spans all applications of one mount. Keeping
fullscreen exposed a latent bug: the Electron header handoff set plain
fields under OnPush hosts and was only rendered thanks to the fullscreen
exit's stage resize; `channel`/`vjsOptions` are signals now.
Covered by unit regressions (fullscreen target, WebPlayerView remount, OnPush
handoff), a web-e2e run through a manual and an automatic episode switch, and
a manual Electron check. Docs and release note updated.
Closes#1498
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
An ancestor re-layout can translate the player host without resizing it
(sidebar content settling, EPG panel loading below the player).
ResizeObserver reports size changes only and no DOM event observes
"position changed", so the native child window silently kept its stale
coordinates and rendered offset from the DOM stage.
The session controller now polls the host bounds every 500 ms while a
session is active, compares them against the last synced bounds with a
half-pixel tolerance, and re-syncs only on drift — idle cost is one
getBoundingClientRect per tick with no IPC. The interval is registered
via NgZone.runOutsideAngular and never re-enters the zone, so zone change
detection does not run every tick for the whole stream. Frame-copy
sessions skip the measurement entirely: the canvas is laid out by the DOM
and moves with the layout, so only the native-view child window can go
stale on a position-only shift.
Fixes#1428
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(search): keep a trailing space when the trimmed q echo lands after the debounce
The #1432 guard only held while a debounce was still pending. Once it
fired, the router echo of our own trimmed q (replaceUrl navigation)
reset the one-way-bound search box to the trimmed term, deleting the
just-typed trailing space — typing "Bein Sports" collapsed into
"BeinSports".
Applied terms are now always trimmed at the apply choke point (URL sync
and portal stores only ever act on the trimmed form anyway), so the
echoed q compares directly, and the echo guard no longer requires a
pending debounce. Back/forward stays authoritative via the untouched
imperative-trigger check.
Residual part of #1338.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(search): make the trimmed-applied-term invariant structural and update the shell contract doc
Review follow-ups on the echo-guard widening:
- setSearchState now trims too, so URL-sourced terms (deep links with
?q=Bein%20, actor/discover prefills passing raw provider titles) cannot
put an untrimmed term into appliedSearchQuery — previously that path
failed the echo guard's equality check, snapped the box, and dispatched
the portal search twice. Regression spec added.
- docs/architecture/workspace-shell.md item 8 updated: the applied-term
echo is now always ignored, not only while input is still debouncing.
- The facade spec's router mock exposes a mutable navigation trigger so
facade-level tests can exercise the popstate branch.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(search): compare the echoed q in trimmed form in the echo guard
Adoption trims, so a same-page imperative navigation still carrying a
not-yet-rewritten untrimmed q adopts to exactly the applied state —
syncing it could only cancel a pending debounce. Comparing the trimmed
form closes that window.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: 4gray <fourgray@proton.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(dashboard): detail-first continue watching cards with quick actions (#1441)
Continue Watching cards now open the detail page on click like movie
cards; resuming the saved episode, marking it watched, and removing the
entry from history move into a per-card ⋮ menu. Series details land on
the earliest season with unwatched episodes (or the latest once all are
watched) instead of always season 1.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(dashboard): address review findings and season auto-select regressions
- A session's own watched toggles no longer re-resolve the selected
season when the positions map first fills — marking season 1 watched
used to jump the view to season 2 (CI regression in the web and
Electron season-watched-toggle E2Es).
- The all-watched season fallback skips loaded-but-empty seasons and
picks the latest season that has episodes (Greptile P1).
- Mark as Watched uses the strict failure-propagating save boundary
(Codex P2), and both card mutations surface persistence failures via
a snackbar with the new WORKSPACE.DASHBOARD.ACTION_FAILED key in all
19 languages (Greptile P2).
- Season E2Es now assert the intended post-reload behavior: the fresh
mount lands on the earliest unwatched season while season 1 keeps its
watched state behind its tab.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: 4gray <fourgray@proton.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
* feat(downloads): track live-TV recordings in the download manager
Embedded MPV recordings were written to disk and forgotten: no list, no
reveal/play, no missing-file handling, and the channel/EPG context was lost
the moment the recording stopped. Recordings now live beside downloads:
- New `recordings` table (no unique index, no playlist FK — recordings
survive source deletion; playlist name stored via playlistDisplayLabel).
- EmbeddedMpvRecordingTracker persists the lifecycle: start/stop hooks plus
a session-snapshot observer for implicit stops (stream-replacement
auto-stop, frame-copy helper crash, session error/close); startup repair
turns rows a hard kill left behind into playable `interrupted` partials.
- Channel/EPG metadata is captured at recording START in all four live
hosts (M3U, Xtream, Stalker ITV, unified live tab); a clean stop triggers
renderer-side enrichment with every program overlapping the recorded
window, keyed by target path — covering recordings that span a program
boundary. Provider EPG never reaches SQLite, so post-hoc lookup is
impossible by design.
- Own RECORDINGS_* IPC surface + RECORDINGS_UPDATE_EVENT ping and a
separate supportsRecordings capability gate (the supportsDownloads
allowlist is all-or-nothing and stays untouched). Reveal/play shell IPCs
are gated on the recordings table, so the renderer-supplied recording
directory stays a write-location preference, not a shell-access grant.
- Manager UI: `recording` filter chip, "Recording now" queue section (REC
pulse, elapsed, live file size — no percentage, the length is unknown),
16:9 channel-logo Recordings library, Needs attention with Remove only,
focused detail at /workspace/downloads/recording/:recordingId.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): close the stop-enrichment race and repair player stubs
Greptile spotted a real ordering bug: the stop IPC returns as soon as mpv
acknowledges, while the recording row's terminal-state update is still queued
in the tracker. The renderer answers that snapshot with stop enrichment, whose
handler only accepts a terminal row — so the covered-program metadata could be
silently dropped with "Recording not found".
- EmbeddedMpvRecordingTracker.whenSettled() exposes the serialized write
chain; RECORDINGS_UPDATE_PROGRAMS awaits it before the terminal-row lookup.
Regression covered from both sides: the handler must not touch the database
until the barrier resolves, and the barrier must imply a committed row.
CI also caught spec stubs that had not learned the new player inputs (my local
run-many had been an Nx cache hit, so the failures only surfaced in CI):
- Teach the `app-web-player-view` and `app-embedded-mpv-player` stubs the
`recordingMetadata` input and `recordingStopped` output across the m3u,
Xtream, Stalker, unified-live-tab and web-player-view specs.
- The races spec now asserts the metadata argument explicitly instead of
matching a two-argument call.
- Extract the Stalker and unified-live-tab spec stubs into sibling
`*.spec-stubs.ts` files (the pattern ui/playback already uses) so both specs
stay under the 1200-line test limit without shaving assertions.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* test(downloads): make the recordings events spec a module
The spec deliberately has no static imports — every dependency is swapped
through jest.doMock before the harness's dynamic import — which also made it a
TS script rather than a module, so its top-level `registeredHandlers` landed in
the global scope and collided with the same-named const in stream-probe.spec.ts
(TS2451). Local per-project runs compile the specs separately and stayed green;
only the Tier A coverage suite builds them into one program, so CI caught it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): address Codex review on recording lifecycle
Four findings from the Codex review, all real:
- P1: `addon.stopRecording()` only dispatches — native-view uses
`mpv_set_property_async`, frame-copy writes a helper command — so
finalizing inside the stop hook could stat a file mpv had not flushed and
even unlink bytes still being written. The tracker now treats the hook as a
request and finalizes on the acknowledged inactive snapshot, with a 10 s
bound so a lost acknowledgement cannot strand the row. Only a recording
that never went active has its empty reservation removed. Stop enrichment
follows through `whenFinalized(targetPath)` (bounded) instead of merely
draining the write queue.
- Live file size: `file_size_bytes` is written at finalization only, so the
manager's 15 s refresh reported nothing while recording. Active rows are
now decorated with a current `fs.stat` size.
- Manager-initiated Stop bypassed both player stop paths, so recordings
spanning program boundaries kept only the start-time program.
`EmbeddedMpvPlayerComponent` now owns the active→inactive edge and emits
`recordingStopped` for every trigger; the adapter and legacy toggle no
longer emit it themselves.
- Startup recovery could terminate a row another live instance was still
writing under IPTVNATOR_ALLOW_MULTIPLE_INSTANCES. Rows carry `owner_pid`
and recovery skips those whose owner process is alive.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): derive the enrichment wait from the stop fallback
Greptile caught the seam my previous fix left: the enrichment barrier waited
5 s while the tracker's acknowledgement fallback only finalizes at 10 s, so a
stop mpv never confirms let the terminal-row lookup expire early and drop the
covered programs with no retry — precisely the case the fallback exists for.
The wait is now derived from the acknowledgement bound (fallback + 1 s), with
a regression test that fails if the two ever drift apart again.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): address the second Codex pass on recordings
Four more findings, all real:
- P1 (macOS native-view): `StopRecording` clears `recordingActive` *before*
dispatching the async property set and restores it if the request is
rejected, so the first inactive snapshot is optimistic, not an
acknowledgement — the tracker could finalize (and stat) a file mpv was
still writing, and a rejected stop would leave the row `completed` while
recording continued. An inactive snapshot now has to survive a 1.5 s settle
window (three poll cycles); a revived recording cancels the pending
finalization.
- Removing a failed row unlinked its path unconditionally, which takes the
file of a newer recording that reused the freed name within the same
timestamp second. The cleanup now runs only while no other row claims it.
- The All chip and the header's active badge ignored recordings, so a manager
holding only recordings read "All 0" and an active recording never showed
up in the badge.
- Switching channels auto-stops the recording, but by the time the host
handled the stop its `activeChannel`/EPG already described the NEW channel,
so the old recording was enriched with the wrong schedule (and an unrelated
program could be promoted to its title). The stop event now carries the EPG
key captured while the recording was active and every host compares it
before enriching.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): close the persistence race and two recording UX gaps
- Greptile P1: the enrichment deadline (fallback + 1 s) still raced the
terminal write — if the tracker queue or the UPDATE took longer than the
remaining margin, `whenFinalized` returned while the row was still
`recording` and the one-shot enrichment was dropped. The deadline now
bounds only the wait for mpv; `finalize()` removes the entry synchronously,
so once it has started the wait follows the write itself.
- Codex: `RECORDINGS_STOP` ignored `owner_pid`. Session ids restart per
process, so under IPTVNATOR_ALLOW_MULTIPLE_INSTANCES stopping another
instance's row could stop an unrelated local recording. Foreign rows are
now refused.
- Codex: the In progress chip counted active recordings while its filter
deliberately hid them, so clicking it showed "no matches". Active
recordings now belong to that filter — a chip whose count disagrees with
its page is a lie.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* refactor(downloads): drop the enrichment barrier instead of tuning it
Three review rounds circled the same class: synchronizing mpv's asynchronous
stop acknowledgement with a one-shot program enrichment. Each fix moved the
deadline (5 s → fallback+1 s → wait-on-the-write) without removing the reason
a deadline existed at all — the handler insisted on a *terminal* row.
It never needed one. `openSync('wx')` makes the reserved path exclusive while
a recording owns it, so the newest row for that path IS the recording that was
stopped, and `finalize()` writes only status/end time/size and never
`programs_json`. Enrichment and finalization are therefore order-independent:
- `RECORDINGS_UPDATE_PROGRAMS` matches the newest row for the path in any
status and awaits only the tracker's write queue, which exists solely to
guarantee the INSERT committed (a recording stopped milliseconds after it
started).
- `whenFinalized`, its deadline constant, and the per-entry finalized promise
are gone; the tracker keeps only the settle window and fallback that make
*finalization* itself correct.
No behavior is lost and the whole timing class disappears with the code.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): bind recording finalization to its entry and shield live rows from startup repair
Two races from the Codex review:
- Tracker timers finalized by reusable session id, so a stop followed by an
immediate restart on the same session let the old settle timer finalize
the NEW row (marked completed while mpv kept writing) and strand the old
row in 'recording'. Finalization is now bound to the exact open entry,
and replacing a session's entry arms the old entry's settle timer so an
unobserved stop still finalizes it.
- reconcileStaleRecordings() runs after the renderer is interactive; a
recording started during bootstrap has ownerPid === process.pid and was
repaired to interrupted/failed mid-write. Recovery now skips rows the
tracker reports as actively tracked (activeRowIds()).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): harden recording startup repair against recycled pids and stale renderer lists
Second Codex pass on the recovery path:
- A live ownerPid alone no longer shields a row: after a crash the OS can
recycle the pid for an unrelated process, which would park the row in
'recording' with no instance able to finalize it. Recovery now also
checks (best-effort, ps/tasklist) that the process looks like an
IPTVnator/Electron instance; an unreadable name stays conservative and
keeps the skip.
- The renderer loads before the repair pass runs and may already hold the
pre-repair list with a stale Stop affordance; recovery now broadcasts
one RECORDINGS_UPDATE_EVENT after changing any rows.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): defer teardown finalization behind the flush window and bound the live-size stat
Third Codex pass:
- A synthetic error/closed snapshot from disposeSession() arrives while
the frame-copy helper may still be flushing (0.5 s quit grace + 2 s
SIGTERM grace before SIGKILL). Finalizing there statted a file mid-write
— short captures became terminal 'failed', longer rows persisted a
truncated size, and startup recovery could repair neither. The tracker
now defers that finalization behind a 2.5 s flush window; the row stays
'recording' (repairable) meanwhile, and an already-acknowledged stop's
settle timer keeps its 'completed' verdict instead of being relabelled
'interrupted'.
- The active row's live file size used a bare await stat(): one stat
hanging on a dead network filesystem wedged every RECORDINGS_GET_LIST.
The probe now mirrors the availability probe's contract — in-flight
coalescing plus a 1 s deadline degrading to no size.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): unmask recycled recording owners, guard the PWA recording route, and unblock file probes
Fourth Codex pass:
- Recycled-pid discrimination no longer stops at the process-name family
check (any Electron app could shield the row): a live holder must also
not provably have started after the recording did (ps -o etime= /
PowerShell StartTime). A pid frees only when its previous owner dies, so
a recycled pid's holder is always younger than the recording; unreadable
evidence stays conservative.
- /workspace/downloads/recording/:recordingId gets a supportsRecordings
capability guard redirecting the PWA to the manager — RecordingsService
never becomes authoritative there, so the detail rendered a permanently
blank workspace.
- Finalization and startup repair stat through a bounded async probe (3 s
deadline, ENOENT/ENOTDIR as the only proof of absence) instead of
main-thread statSync: a dead network mount no longer freezes the main
thread or the tracker queue, repair leaves unjudgeable rows recoverable,
and finalization keeps the requested status with an unknown size rather
than branding a likely-good file failed. The 0-byte reservation unlink
is fire-and-forget for the same reason.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): keep inconclusive recording probes out of Needs attention and bound repair batches
Fifth Codex pass:
- Recording list decoration now uses the bounded availability variant that
preserves 'unknown': a timed-out or permission-errored probe is not
proof of absence, so a good recording on a slow mount no longer lands in
Needs attention with its Play/Reveal hidden.
ElectronRecordingItem.fileAvailability widens accordingly; consumers
already gate on === 'missing'.
- Startup repair probes its whole batch concurrently, so main.ts awaits
roughly one 3 s deadline instead of one per stale row.
Cross-process ping propagation under IPTVNATOR_ALLOW_MULTIPLE_INSTANCES
stays out of scope (debug-only flag, same single-window design as
DOWNLOADS_UPDATE_EVENT) — rationale left on the review thread.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): fix duration rounding at hour boundaries and bound owner-process probes
Sixth Codex pass:
- The recording duration formatter rounded minutes after flooring hours,
so 59:45 read '60 min' and 1:59:45 read '1 h 60 min'. One shared
recordingDurationLabel() now rounds the total minutes before splitting
(both the detail page and the library card used a duplicated copy).
- Startup repair's synchronous ps/tasklist/PowerShell ownership probes get
a 2 s spawn timeout and are memoized per unique pid, so a batch of rows
from one crashed instance costs at most one name query and one
start-time query, and a hung process query degrades to the conservative
fallback instead of blocking the main thread.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): return to the manager through history from the recording detail
Seventh Codex pass (single finding): with a validated returnUrl the manager
is already the previous history entry, so Back now uses Location.back()
instead of pushing a third entry that made the browser Back button reopen
the detail; router navigation remains the fallback for direct links —
matching the offline-detail navigation.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): bound removal cleanup and shell gates, date interrupted rows by file mtime
Eighth Codex pass:
- RECORDINGS_REMOVE no longer awaits an unbounded unlink of a failed
row's leftover reservation: cleanup is raced against the 1 s deadline,
so a hung network unlink cannot keep the Remove action busy — the row
deletion is what matters.
- Reveal/Play swap the synchronous lstat gate for the bounded async
availability probe: a dead mount no longer blocks the main process, and
only PROVEN absence refuses the action — an inconclusive probe lets the
shell try and answer honestly.
- Startup repair dates an interrupted row's endedAt from the captured
file's mtime (mpv's last write) instead of the repair time, so an
overnight shutdown no longer inflates a five-minute capture into an
hours-long recording; the repair-time fallback remains when mtime is
unreadable.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): keep recording-start program metadata fresh across EPG boundaries
Ninth Codex pass (single finding): the unified live tab's
recordingMetadata computed cached its Date.now() verdict — starting a
recording after an EPG boundary snapshotted the previous show. It now
tracks the existing 30 s progress tick. The Stalker live layout's
currentProgram had the same memoization (feeding recording metadata, the
EPG panel summary, and external-player metadata); it gains a 30 s clock
tick with interval cleanup in ngOnDestroy.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): re-select the Xtream current program against the 30 s tick at recording start
Tenth Codex pass (single finding): the Xtream live layout's recording
snapshot read withEpg().currentEpgItem, a computed whose Date.now()
verdict stays cached until epgItems changes — a recording started after
an EPG boundary snapshotted the previous show. The selection logic is
extracted as the pure findCurrentEpgItem(items, nowMs), the store
computed delegates to it unchanged, and recordingMetadata re-selects
with the layout's existing 30 s currentTimeMs tick.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): scope stop enrichment to the exact recorded list item
Eleventh Codex pass (single finding): the stop-enrichment guard compared
only the EPG key, which is not unique for M3U items — two list entries
sharing a tvgId (or the display-name fallback) could hand the first
item's recording the second item's schedule after a switch-triggered
auto-stop. RecordingStartMetadata/RecordingStoppedEvent gain an opaque
sourceItemKey (unified tab: item.uid; M3U player: channel.id), captured
while the recording is active exactly like the EPG key, carried through
the player's stop edge, and compared by the hosts before enriching.
Xtream/Stalker keys are already playlist+id-scoped and need no extra key.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): derive the M3U start-snapshot program from the active channel's schedule
Twelfth Codex pass (single finding): the M3U recording snapshot read the
NgRx currentEpgProgram, which retains its last value across a channel
switch and through EPG gaps (the mirror effect only dispatches when a
program exists) — a recording started on a channel with no airing
program could persist the previous channel's title, which stop
enrichment deliberately never overwrites. The snapshot now derives the
program from the active channel's own schedule against the existing 30 s
clock, and an EPG gap snapshots no program.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): keep finalizing rows in the recovery ledger and guard the repair update
Thirteenth Codex pass (single finding): finalize() removes an entry from
the open map before its queued terminal update commits, so
activeRowIds() briefly omitted a row still persisted as 'recording' —
startup recovery overlapping a clean stop could relabel it interrupted,
after which the tracker's status-guarded update could not restore
'completed'. Finalizing entries now stay in a dedicated ledger until the
update settles, and the repair UPDATE itself is guarded on
status='recording' as a second belt against a finalization that commits
between recovery's SELECT and its write.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(downloads): register update listeners before the initial list load
Fourteenth Codex pass (single finding): RecordingsService awaited its
initial RECORDINGS_GET_LIST before subscribing to the update ping — a
recording transition during that request pinged into the void while the
response still reflected the pre-transition state, and recording pings
are rare enough that nothing self-healed until the 15 s poll (armed only
once an active row is visible). The listener now registers first so the
load-state coalescing queues the trailing refresh. DownloadsService had
the same latent window and gets the same reorder.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: 4gray <fourgray@proton.me>
* feat(playback): add quality selection to shared player controls
Adds a per-session video quality menu (Auto + "1080p"-style levels) to the
shared player-controls layer, mirroring the audio-track pattern:
- Contract: qualityLevels capability, qualityLevels/qualityAutoEnabled state,
setQualityLevel command with AUTO_QUALITY_LEVEL_ID (-1) restoring ABR.
- hls.js (HTML5/ArtPlayer via the neutral source bridge): levels with
list-index ids, smooth switching through nextLevel, selection read from
manualLevel; refresh events extended with MANIFEST_PARSED, LEVELS_UPDATED,
LEVEL_SWITCHED.
- Shaka (DASH): variant tracks filtered to the active audio language, ABR
disabled before selectVariantTrack; manual state keyed to the exact player
instance so a session restart never shows a stale selection.
- Video.js: new VjsQualityLevels over videojs-contrib-quality-levels (manual =
exactly one enabled level, auto = all enabled, derived statelessly).
- Embedded MPV and external players report the capability false.
The capability derives from the manifest (advertised only for >1 video
rendition), nothing persists to Settings, and the menu rides the default-off
webPlayerSharedControls rollout gate. Labels come from one shared helper so
all engines render the same vocabulary. QUALITY/QUALITY_AUTO keys added to
all 19 i18n files.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(playback): pin DASH quality candidates to the active audio stream
Review findings on #1470:
- Shaka quality candidates now match the active variant's exact audioId
(language fallback only when Shaka reports none), so a DASH manifest with
same-language audio tracks (main vs. commentary, stereo vs. 5.1) can no
longer switch the audio track or show duplicate levels when a quality is
picked. Regression test added.
- Mirror the quality-selection contract into AGENTS.md's Shared Player
Controls section, which must stay in sync with CLAUDE.md.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(playback): track Video.js manual quality intent explicitly
Codex re-review finding on #1470: VHS flips a rendition's `enabled` flag off
itself when it temporarily excludes failing renditions, so inferring the
manual/auto mode from the enabled count could report a manual selection the
user never made once exclusions leave a single survivor.
VjsQualityLevels now records the picked level object as explicit manual
intent: error exclusions read as auto, a picked level that leaves the list
reverts to auto, and the bridge resets the intent on every new source.
Regression tests added.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
* fix(playback): re-enable surviving renditions when the picked level is removed
Codex follow-up on #1470: dropping manual intent when the picked
QualityLevel leaves the list reverted the UI to auto but left the surviving
renditions disabled by the earlier manual pick, pinning VHS with no
selectable rendition. Reverting to auto now re-enables every remaining
level, both on the removal event and lazily from the state read.
Regression tests added.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
---------
Co-authored-by: 4gray <fourgray@proton.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Coordinated replacement for the Dependabot branch: the bot updated only the
root package.json, leaving the ^21 specifier in libs/shared/interfaces, which
failed the @nx/dependency-checks lint rule.
Co-authored-by: 4gray <fourgray@proton.me>
Co-authored-by: Claude Fable 5 <noreply@anthropic.com>