4gray
faad8fd8fd
docs(agents): compact root guidance and preserve task-specific knowledge ( #1645 )
...
* docs(agents): compact root guidance and preserve task-specific knowledge
* fix(agents): parse guidance navigation with Markdown tokens
* fix(agents): validate generic literal repository paths
* fix(agents): distinguish code symbols and shortcut images
* fix(agents): recognize SCSS filename literals
* fix(agents): handle fenced imports and encoded paths
* fix(agents): parse prose and rendered HTML anchors
* fix(agents): validate rendered HTML navigation
* fix(agents): use GitHub-compatible heading slugs
* fix(agents): require standalone top-level Claude import
* fix(agents): exclude HTML-contained guidance imports
* fix(agents): handle image fragments and quoted imports
* fix(agents): validate visible HTML and image source sets
* fix(agents): recognize package scopes and route source work
* fix(agents): parse JSONC and constrain package exemptions
* fix(agents): decode link entities and allow package subpaths
* fix(agents): route source work and check extensionless files
* fix(agents): support package versions and source fragments
* fix(agents): accept qualified package prose
* fix(agents): retain rendered context for Markdown references
* fix(agents): validate visible headings and spaced paths
* fix(agents): validate media and hyphenated literal paths
* fix(agents): decode full HTML entities and media assets
* fix(agents): recognize possessive package mentions
* fix(agents): validate extensionless imports and version comparators
* fix(agents): retain visible backticks and explicit path punctuation
* fix(agents): validate image-map navigation targets
* fix(agents): count all Markdown line endings in budgets
* fix(agents): delimit package prose at Unicode punctuation
* fix(agents): normalize punctuation for extensionless imports
* fix(agents): preserve filenames across prose punctuation
* fix(agents): validate iframe document references
* fix(agents): inspect document suffix before URL fragments
* fix(agents): unify Markdown suffix and encoded import guards
* fix(agents): handle wildcard versions and alternate documents
* fix(agents): validate document formats and trim HTML URLs
* fix(agents): cover document families and guidance basenames
* fix(agents): require files for media references
* fix(agents): preserve block boundaries and validate embeds
* fix(agents): normalize internal HTML URL whitespace
* fix(agents): reject empty media and ignore URL at-signs
* fix(agents): validate srcdoc references and empty srcset
* fix(agents): honor HTML bases and preserve adjacent imports
* fix(agents): convert base file URLs to native paths
* fix(agents): preserve imports after bare URL punctuation
* fix(agents): exclude opaque URI prose from import scans
* fix(agents): keep import tokens outside URI scheme matches
* fix(agents): restrict opaque URI exemptions to parsed links
* fix(agents): handle opening prose delimiters
* fix(agents): scan nested imports and share document suffixes
* fix(agents): reject pathless media and direct file URLs
* fix(agents): reject file bases and preserve quoted URL boundaries
* fix(agents): distinguish URL quotes and cover guidance variants
* fix(agents): validate SVG images and conventional guides
* fix(agents): handle declared package names handles and SVG use
* fix(agents): normalize closing punctuation on federated handles
* fix(agents): normalize Unicode punctuation on handles
* fix(agents): normalize possessive federated handles
* fix(agents): separate parenthetical prose from handles
* fix(agents): exclude www autolinks from import scanning
* ci: allow manual CodeQL validation of PR branches
* fix(agents): reject nonportable Windows drive links
2026-09-21 18:07:14 +02:00
4gray and Claude Fable 5
46c58f4f57
fix(stalker): keep session headers on same-host redirects ( #1322 )
...
* fix(stalker): keep session headers on same-host redirects
Since 0.22 requestWithValidatedRedirects stripped Cookie/Authorization
whenever a redirect changed the *origin*, so a portal answering with an
http->https upgrade or a port move lost the MAC cookie and Bearer token
mid-session. Real Stalker/Ministra servers then reply with a plain-text
"Authorization failed." body: categories fail to load, create_link never
resolves, and no player receives a stream URL (#1158 regression window).
Scope credential stripping to the host instead: same-host scheme/port
redirects keep headers, basic auth, params, and request bodies; a
redirect to a different host still drops all of them, preserving the
original hardening intent (no credential leaks to third-party hosts).
Also adds the Stalker API compatibility roadmap produced by the
2026-08-01 protocol audit (.plans/, force-added like earlier plans).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
* fix(electron): strip credentials on same-host https-to-http downgrades
Review follow-up (Greptile P1 + Codex on #1322 ): the host-only check
kept Authorization/Cookie/basic auth/params/body when an https request
was redirected to http on the same host, replaying a TLS-obtained
session in cleartext. Treat that downgrade like a host change: strip
credentials and refuse to replay request bodies. Scheme upgrades and
port moves on the same host keep headers — the actual #1158 scenarios.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com >
---------
Co-authored-by: Claude Fable 5 <noreply@anthropic.com >
2026-08-01 17:36:44 +02:00
4gray
8fdac824fd
feat(packaging): ship Linux embedded MPV frame-copy runtime ( #1200 )
...
* docs: design Linux frame-copy packaging
* docs: plan Linux frame-copy packaging
* feat(packaging): define Linux frame-copy profiles
* fix(packaging): reject inherited profile names
* feat(embedded-mpv): validate staged Linux runtime
* fix(embedded-mpv): require Linux source packages
* fix(embedded-mpv): harden Linux runtime staging
* feat(embedded-mpv): build LGPL Linux runtime
* fix(embedded-mpv): pin Linux runtime inputs
* feat(embedded-mpv): build relocatable Linux helper
* fix(embedded-mpv): require bundled Linux runtime
* fix(embedded-mpv): make Linux runtime portable
* feat(packaging): ship Linux frame-copy artifacts
* fix(embedded-mpv): verify Linux helper linkage
* fix(packaging): enforce Linux frame-copy isolation
* fix(embedded-mpv): pin Linux display data
* docs(embedded-mpv): document Linux frame-copy packaging
* feat(embedded-mpv): probe Linux frame-copy runtime
* test(embedded-mpv): smoke packaged Linux frame-copy
* docs(embedded-mpv): clarify Linux system runtime baseline
* fix(embedded-mpv): harden Linux runtime capability gate
* ci: verify Linux frame-copy packages
* test(embedded-mpv): harden packaged Linux smoke
* test(embedded-mpv): preserve packaged GL mode
* test(packaging): harden Linux package probes
* fix(embedded-mpv): enable private Snap shared memory
* fix(embedded-mpv): sanitize Linux helper environment
* fix(packaging): enforce private Snap memory semantics
* fix(packaging): reject ambiguous Snap memory metadata
* fix(embedded-mpv): prioritize trusted Snap GL
* fix(packaging): reject advanced Snap YAML semantics
* fix(packaging): reject arbitrary Snap YAML aliases
* feat(packaging): ship Linux runtime license notices
* docs(embedded-mpv): document Linux runtime distribution
* fix(packaging): parse Snap trailing comments safely
* fix(release): gate Snap publish on public source release
* fix(packaging): strip VCS metadata from source bundle
* docs(packaging): clarify Linux source release gate
* test(embedded-mpv): smoke missing bundled libmpv
* style(embedded-mpv): format final validation inputs
* fix(e2e): satisfy fixture index signature typing
* fix(ci): declare fontconfig gperf generator
* fix(embedded-mpv): hash runtime cache identities
* fix(packaging): harden Linux frame-copy delivery
* fix(packaging): tighten runtime delivery gates
* fix(ci): decouple Linux runtime matrix
* fix(packaging): harden Linux frame-copy delivery
* fix(packaging): validate Linux frame-copy runtimes
* fix(packaging): scope Snap Electron library checks
* feat(packaging): ship Linux frame-copy runtimes
* fix(packaging): improve Linux runtime smoke diagnostics
* fix(packaging): expose bounded helper probe details
* test(packaging): trace Snap EGL probe failures
* fix(packaging): prefer core22 ABI in Snap helper
* fix(packaging): bound helper probe capture
* fix(packaging): harden Linux frame-copy releases
* fix(packaging): canonicalize libplacebo submodule identity
* fix(packaging): make source archive inspection portable
* fix(packaging): harden Snap release verification
2026-07-18 17:28:22 +02:00
4gray
06700b318a
feat(electron): add embedded mpv support for windows and linux ( #1031 )
...
Adds experimental embedded MPV support for Windows and Linux, expands packaging/runtime validation, and updates CI coverage for the cross-platform native addon.
2026-06-09 08:58:38 +02:00
4gray
ec2f6a702a
chore: resolve master conflicts for embedded mpv branch
...
Entire-Checkpoint: 5b514fe72836
2026-05-02 02:19:54 +02:00
4gray
c14b5d5aff
fix(xtream): search all vod and series items
...
Entire-Checkpoint: 3f453cc0085a
2026-05-02 00:35:37 +02:00
4gray
31258624b5
feat: unify live epg toolbar
...
Entire-Checkpoint: 978eaff2e478
2026-04-29 00:20:34 +02:00
4gray
51347fc226
feat: add collapsible live epg panel
...
Entire-Checkpoint: 0518c49b948d
2026-04-28 19:56:41 +02:00