Files
iptvnator/.plans/2026-07-18-linux-embedded-mpv-frame-copy-packaging.md
4gray 8fdac824fd feat(packaging): ship Linux embedded MPV frame-copy runtime (#1200)
* docs: design Linux frame-copy packaging

* docs: plan Linux frame-copy packaging

* feat(packaging): define Linux frame-copy profiles

* fix(packaging): reject inherited profile names

* feat(embedded-mpv): validate staged Linux runtime

* fix(embedded-mpv): require Linux source packages

* fix(embedded-mpv): harden Linux runtime staging

* feat(embedded-mpv): build LGPL Linux runtime

* fix(embedded-mpv): pin Linux runtime inputs

* feat(embedded-mpv): build relocatable Linux helper

* fix(embedded-mpv): require bundled Linux runtime

* fix(embedded-mpv): make Linux runtime portable

* feat(packaging): ship Linux frame-copy artifacts

* fix(embedded-mpv): verify Linux helper linkage

* fix(packaging): enforce Linux frame-copy isolation

* fix(embedded-mpv): pin Linux display data

* docs(embedded-mpv): document Linux frame-copy packaging

* feat(embedded-mpv): probe Linux frame-copy runtime

* test(embedded-mpv): smoke packaged Linux frame-copy

* docs(embedded-mpv): clarify Linux system runtime baseline

* fix(embedded-mpv): harden Linux runtime capability gate

* ci: verify Linux frame-copy packages

* test(embedded-mpv): harden packaged Linux smoke

* test(embedded-mpv): preserve packaged GL mode

* test(packaging): harden Linux package probes

* fix(embedded-mpv): enable private Snap shared memory

* fix(embedded-mpv): sanitize Linux helper environment

* fix(packaging): enforce private Snap memory semantics

* fix(packaging): reject ambiguous Snap memory metadata

* fix(embedded-mpv): prioritize trusted Snap GL

* fix(packaging): reject advanced Snap YAML semantics

* fix(packaging): reject arbitrary Snap YAML aliases

* feat(packaging): ship Linux runtime license notices

* docs(embedded-mpv): document Linux runtime distribution

* fix(packaging): parse Snap trailing comments safely

* fix(release): gate Snap publish on public source release

* fix(packaging): strip VCS metadata from source bundle

* docs(packaging): clarify Linux source release gate

* test(embedded-mpv): smoke missing bundled libmpv

* style(embedded-mpv): format final validation inputs

* fix(e2e): satisfy fixture index signature typing

* fix(ci): declare fontconfig gperf generator

* fix(embedded-mpv): hash runtime cache identities

* fix(packaging): harden Linux frame-copy delivery

* fix(packaging): tighten runtime delivery gates

* fix(ci): decouple Linux runtime matrix

* fix(packaging): harden Linux frame-copy delivery

* fix(packaging): validate Linux frame-copy runtimes

* fix(packaging): scope Snap Electron library checks

* feat(packaging): ship Linux frame-copy runtimes

* fix(packaging): improve Linux runtime smoke diagnostics

* fix(packaging): expose bounded helper probe details

* test(packaging): trace Snap EGL probe failures

* fix(packaging): prefer core22 ABI in Snap helper

* fix(packaging): bound helper probe capture

* fix(packaging): harden Linux frame-copy releases

* fix(packaging): canonicalize libplacebo submodule identity

* fix(packaging): make source archive inspection portable

* fix(packaging): harden Snap release verification
2026-07-18 17:28:22 +02:00

4.5 KiB

Linux Embedded MPV Frame-Copy Packaging Plan

Audited baseline

  • Linux frame-copy already has an isolated iptvnator_mpv_helper, a frame reader addon, shared controls, native-view fallback, and runtime capability probes.
  • Existing packaged Linux builds intentionally remove the helper/runtime and retain only system mpv --wid native-view.
  • Electron, Electron libraries, embedded_mpv.node, and embedded_mpv_frame_reader.node must never load or link libmpv. Only the helper may link it.
  • Electron Builder produces AppImage, DEB, RPM, Pacman, Snap, and Flatpak Linux targets. The available reproducible native/runtime toolchain is x64.

Decisions

  1. Support official frame-copy artifacts on Linux x64 only. Keep every non-x64 artifact marker-only and fail closed to native-view; never accept an architecture override that injects x64 native files.
  2. Use three isolated packaging profiles:
    • system: DEB/RPM/Pacman use declared distribution libmpv/GL dependencies and contain no private native/lib.
    • portable: AppImage/Snap contain a pinned LGPL-compatible shared-library closure with $ORIGIN-relative helper loading.
    • flatpak: Flatpak contains the same pinned closure, validated in the exact /app runtime context.
  3. Treat the package manifest as necessary but insufficient. Frame-copy is available only after exact manifest/schema/profile checks, executable-mode checks, artifact hashes, dependency-closure/process-isolation checks, and a bounded helper runtime probe. No environment flag bypasses this gate.
  4. Publish exact source archives, recursive source identities, build flags, licenses, notices, patches/tooling, and pinned display data for bundled runtimes. Bind every bundled x64 package manifest to the final compliance archive bytes and released repository revision.
  5. Keep Snap Store credentials isolated from release-tag code on a fresh runner. Store publication is edge-only; candidate/stable promotion remains manual after installed-package smoke.

TDD implementation phases

  1. Add failing tests for target/profile partitioning, x64 and marker-only layouts, exact dependency declarations, RPATH/SONAME rules, executable modes, and Electron/libmpv isolation.
  2. Implement profile-aware build and packaging hooks that stage the helper, frame reader, runtime manifest, private closure where applicable, and legal payload without weakening native-view.
  3. Add failing runtime-policy tests for missing/tampered files, wrong architecture/profile, malformed manifests, loader failures, hostile environments, probe timeout/output bounds, and stable fallback reasons.
  4. Implement one sanitized helper environment shared by probe and playback, including Snap graphics-provider handling and Flatpak runtime paths.
  5. Add failing compliance/release tests for exact recursive submodule records, VCS-free source inventory, archive member/type layout, source checksums, license/notices completeness, package-to-source byte binding, sealed asset receipts, and credential boundaries.
  6. Implement deterministic source generation, package bindings, static Snap inspection, fresh-runner artifact transfer, and minimal direct Store upload.
  7. Add packaged x64 smoke for actual frame-copy playback plus missing-runtime native-view fallback. Run fixture-contract tests before the smoke and allow CI llvmpipe through Chromium's GPU blocklist without bypassing the runtime gate.
  8. Update canonical architecture/maintenance documentation and mirrored AGENTS.md/CLAUDE.md contracts.

Acceptance and verification matrix

  • Local/macOS:
    • Nx discovery
    • packaging and Electron backend unit/integration tests
    • packaged-smoke fixture tests
    • affected lint targets
    • production backend build
    • formatting, syntax, and git diff --check
  • Linux x64 CI:
    • build the pinned runtime/helper/frame reader
    • verify helper links/resolves libmpv and Electron/addons do not
    • extract and statically validate all six package families
    • run system, portable, Snap-installed, and Flatpak application probes
    • run packaged frame-copy playback and missing-runtime native-view fallback
    • regenerate and bind the exact compliance source archive
  • Non-x64 CI:
    • build selected ARM package targets independently
    • require marker-only layout and absence of every x64 native/runtime artifact
  • Merge gate:
    • exact-head CI green
    • no unresolved review findings
    • fresh code review clean
    • no automatic Snap promotion beyond edge