feat(offline): play downloaded video, and drain the offline sync queue (0.4.6)
🏗️ Build and Test JellyTau / Run Tests (push) Successful in 20m34s
Publish Documentation / Build & publish docs to gitea-pages (push) Successful in 6m6s
Traceability Validation / Check Requirement Traces (push) Successful in 18s
Build & Release / Run Tests (push) Successful in 20m26s
🏗️ Build and Test JellyTau / Android Compile Check (push) Successful in 10m3s
Build & Release / Build Linux (push) Successful in 37m59s
Build & Release / Build Windows (push) Successful in 23m0s
Build & Release / Build Android (push) Successful in 40m26s
Build & Release / Create Release (push) Successful in 1m20s

Bundles this session's work plus the concurrent search/offline/player changes.
Every gate passes on the combined tree: 885 frontend tests, 610 Rust tests,
clippy clean, boundary clean, trace coverage 86%.

Offline video playback — four separate defects, each of which alone stopped it:

  DR-133  A completed download's file_path is already absolute (the worker
          rewrites it on completion), but the player rooted it a second time and
          handed the webview /data/user/0/app//data/user/0/app/videos/x.mp4.
  DR-134  The asset protocol was never enabled: no protocol-asset feature and no
          assetProtocol config, so convertFileSrc produced URLs nothing answered.
          Also silently defeated the cached-thumbnail path, which fails soft to
          the server copy and hid it whenever the server was reachable.
  DR-137  Tauri's asset protocol answers a range-less request by reading the
          whole file into memory, and only advertises Accept-Ranges from inside
          its range branch, so the first request never learns ranges exist.
          Chromium gave up with PIPELINE_ERROR_READ after ~31s. Local media is
          now served by a loopback HTTP server: bounded 4 MiB chunks streamed
          from the file handle, every response length-delimited, and a range-less
          request answered with one chunk rather than the file. Confined by a
          per-session token and to the app data directory, because loopback is
          shared between apps on Android.
  DR-138  Release builds set usesCleartextTraffic=false, so Android rejected the
          request to that server before any I/O. A network-security-config
          exempts 127.0.0.1 only; a remote server must still be HTTPS.

Downloads:

  DR-135  download_item never records media_type and the reconnect resolver read
          that NULL as 'audio', so a movie queued from a media card had its URL
          resolved by get_audio_stream_url and completed as an audio-only
          transcode. The item's own type now decides.
  DR-136  Rows already downloaded that way are requeued on reconnect, since
          prevention alone leaves them reading "downloaded" and still unplayable.

Known limitation: a download taken at `original` quality is a byte copy of the
source, so it can be any container. One such file is an AVI holding XVID, which
the webview cannot play in any case — the media server serves it correctly and
Chromium refuses it. That needs either a transcoded download preset or the
native ExoPlayer surface work, and is not addressed here.

Also fixes two ID collisions between concurrent work: DR-143 defined twice
(search vs offline gate) and UT-131 defined twice (Episode Focus hero vs channel
cap). The search requirement is now DR-147 and the channel-cap test UT-141, with
their code references and matrix rows updated.
This commit is contained in:
2026-08-09 16:38:07 +02:00
parent 7b531a40be
commit 1b70926c36
58 changed files with 8130 additions and 2347 deletions
+240 -6
View File
@@ -106,6 +106,14 @@ const CATALOG_ITEM_TYPES: &[&str] = &[
"Playlist",
];
/// Jellyfin item types whose download is a *video* stream rather than an audio
/// one. The download queue stores an opaque `media_type` ('audio'/'video'); this
/// is where the taxonomy that produces it lives, so the frontend never has to
/// know which item types are video.
///
/// TRACES: UR-071 | DR-135
const VIDEO_ITEM_TYPES: &[&str] = &["Movie", "Episode", "Video", "MusicVideo"];
#[derive(specta::Type, Debug, Clone, serde::Serialize, serde::Deserialize)]
#[serde(rename_all = "camelCase")]
pub struct CatalogSyncResult {
@@ -463,6 +471,51 @@ pub struct ResumeQueuedResult {
pub failed: usize,
}
/// Requeue video downloads that were fetched as audio.
///
/// Before [`resolve_pending_download_urls`] consulted the item's type, a row
/// with no `media_type` — which is every row queued from a media card, since
/// `download_item` does not record one — resolved against
/// `get_audio_stream_url`. A movie queued that way completed with an audio-only
/// transcode on disk, so playing it offline could only ever fail. Those rows are
/// identifiable after the fact (no `media_type`, but a video item), so reset them
/// to pending with no URL and let the resolver fetch the real video.
///
/// Rows carrying an explicit `media_type` were resolved correctly and are left
/// alone, as are genuine audio downloads.
///
/// Returns the number of rows requeued.
///
/// TRACES: UR-071 | DR-136 | UT-126
pub(crate) async fn requeue_mistyped_video_downloads(
db_service: &Arc<crate::storage::db_service::RusqliteService>,
) -> Result<usize, String> {
let video_types = VIDEO_ITEM_TYPES
.iter()
.map(|t| format!("'{t}'"))
.collect::<Vec<_>>()
.join(", ");
let query = Query::new(&format!(
"UPDATE downloads
SET status = 'pending', stream_url = NULL, progress = 0,
bytes_downloaded = 0, started_at = NULL, completed_at = NULL
WHERE media_type IS NULL
AND status = 'completed'
AND item_id IN (SELECT id FROM items WHERE item_type IN ({video_types}))"
));
let n = db_service.execute(query).await.map_err(|e| e.to_string())? as usize;
if n > 0 {
info!(
"[Catalog] Requeued {} video download(s) that were fetched as audio",
n
);
}
Ok(n)
}
/// Core of [`resume_queued_downloads`], factored out for testing: select every
/// `pending`/`stream_url IS NULL` row, resolve each via `resolve` (returning
/// `None` leaves the row pending), and heal the row so the pump can start it.
@@ -476,11 +529,31 @@ where
F: Fn(String, String, String) -> Fut,
Fut: std::future::Future<Output = Option<String>>,
{
let rows_query = Query::new(
"SELECT id, item_id, COALESCE(media_type, 'audio'), COALESCE(quality_preset, 'original')
FROM downloads
WHERE status = 'pending' AND stream_url IS NULL",
);
// A row's own media_type wins; otherwise the *item's* type decides. Rows
// queued from a media card never carry one (`download_item` does not record
// it), and defaulting that NULL to 'audio' resolved movies against
// `get_audio_stream_url` — the file on disk was an audio-only transcode, so
// offline video could never play. Falling back to 'audio' only when the item
// is unknown keeps the historical behaviour for uncached items.
// TRACES: UR-071, UR-052 | DR-135
let video_types = VIDEO_ITEM_TYPES
.iter()
.map(|t| format!("'{t}'"))
.collect::<Vec<_>>()
.join(", ");
let rows_query = Query::new(&format!(
"SELECT d.id, d.item_id,
COALESCE(
d.media_type,
CASE WHEN i.item_type IN ({video_types}) THEN 'video'
WHEN i.item_type IS NOT NULL THEN 'audio'
END,
'audio'),
COALESCE(d.quality_preset, 'original')
FROM downloads d
LEFT JOIN items i ON i.id = d.item_id
WHERE d.status = 'pending' AND d.stream_url IS NULL"
));
let rows: Vec<(i64, String, String, String)> = db_service
.query_many(rows_query, |row| {
Ok((row.get(0)?, row.get(1)?, row.get(2)?, row.get(3)?))
@@ -590,6 +663,16 @@ pub async fn resume_queued_downloads(
Err(e) => warn!("[Catalog] Failed to reset stale downloads: {}", e),
}
// Repair rows that completed as audio because their media_type was missing;
// they hold an audio-only transcode where a video should be, so requeue them
// for the resolver below. TRACES: UR-071 | DR-136
if let Err(e) = requeue_mistyped_video_downloads(&db_service).await {
warn!(
"[Catalog] Failed to requeue mis-typed video downloads: {}",
e
);
}
// Resolve each row's URL against the (now reachable) repository.
let repo_for_resolve = Arc::clone(&repo);
let outcome = resolve_pending_download_urls(
@@ -699,7 +782,15 @@ mod tests {
stream_url TEXT,
target_dir TEXT,
media_type TEXT,
quality_preset TEXT
quality_preset TEXT,
progress REAL DEFAULT 0,
bytes_downloaded INTEGER DEFAULT 0,
started_at TEXT,
completed_at TEXT
);
CREATE TABLE items (
id TEXT PRIMARY KEY,
item_type TEXT
);
"#,
)
@@ -707,6 +798,18 @@ mod tests {
Arc::new(RusqliteService::new(Arc::new(Mutex::new(conn))))
}
async fn insert_item(db: &Arc<RusqliteService>, item_id: &str, item_type: &str) {
db.execute(Query::with_params(
"INSERT INTO items (id, item_type) VALUES (?, ?)",
vec![
QueryParam::String(item_id.to_string()),
QueryParam::String(item_type.to_string()),
],
))
.await
.unwrap();
}
async fn insert_download(
db: &Arc<RusqliteService>,
item_id: &str,
@@ -799,6 +902,137 @@ mod tests {
assert_eq!(url, None);
}
/// A movie queued from a media card has no `media_type` — `download_item`
/// never records one. Defaulting that NULL to 'audio' resolved the row
/// against `get_audio_stream_url`, so the "downloaded movie" on disk was an
/// audio-only transcode and offline video playback could never work. The
/// item's own type is the authority.
///
/// TRACES: UR-071, UR-052 | DR-135 | UT-125
#[tokio::test]
async fn null_media_type_resolves_from_the_item_type_not_audio() {
let db = test_db();
insert_item(&db, "movie-1", "Movie").await;
insert_item(&db, "ep-1", "Episode").await;
insert_item(&db, "track-1", "Audio").await;
for id in ["movie-1", "ep-1", "track-1"] {
insert_download(&db, id, "pending", None, None).await;
}
let seen = Arc::new(Mutex::new(Vec::new()));
let seen_c = Arc::clone(&seen);
resolve_pending_download_urls(&db, "/data", move |item_id, media_type, _q| {
let seen = Arc::clone(&seen_c);
async move {
seen.lock().unwrap().push((item_id.clone(), media_type));
Some(format!("http://resolved/{item_id}"))
}
})
.await
.unwrap();
let seen = seen.lock().unwrap().clone();
let of = |id: &str| {
seen.iter()
.find(|(i, _)| i == id)
.map(|(_, m)| m.clone())
.unwrap()
};
assert_eq!(of("movie-1"), "video", "a Movie must download as video");
assert_eq!(of("ep-1"), "video", "an Episode must download as video");
assert_eq!(of("track-1"), "audio", "a track is still audio");
}
/// An unknown item (never cached locally) has no type to derive from, so it
/// keeps the historical audio default rather than failing the row.
///
/// TRACES: UR-071 | DR-135 | UT-125
#[tokio::test]
async fn unknown_item_falls_back_to_audio() {
let db = test_db();
insert_download(&db, "ghost", "pending", None, None).await;
let seen = Arc::new(Mutex::new(String::new()));
let seen_c = Arc::clone(&seen);
resolve_pending_download_urls(&db, "/data", move |_id, media_type, _q| {
let seen = Arc::clone(&seen_c);
async move {
*seen.lock().unwrap() = media_type;
Some("http://x".to_string())
}
})
.await
.unwrap();
assert_eq!(*seen.lock().unwrap(), "audio");
}
/// An explicit `media_type` on the row always wins over the item's type.
///
/// TRACES: UR-071 | DR-135 | UT-125
#[tokio::test]
async fn explicit_media_type_beats_the_item_type() {
let db = test_db();
insert_item(&db, "odd", "Audio").await;
insert_download(&db, "odd", "pending", None, Some("video")).await;
let seen = Arc::new(Mutex::new(String::new()));
let seen_c = Arc::clone(&seen);
resolve_pending_download_urls(&db, "/data", move |_id, media_type, _q| {
let seen = Arc::clone(&seen_c);
async move {
*seen.lock().unwrap() = media_type;
Some("http://x".to_string())
}
})
.await
.unwrap();
assert_eq!(*seen.lock().unwrap(), "video");
}
/// Rows already downloaded under the audio default hold an audio-only
/// transcode on disk, so they play as a broken video forever. They are
/// identifiable — no `media_type` but a video item — and are requeued so the
/// resolver fetches the real video. Correctly-typed rows and genuine audio
/// downloads must be left alone.
///
/// TRACES: UR-071 | DR-136 | UT-126
#[tokio::test]
async fn requeues_video_downloaded_under_the_audio_default() {
let db = test_db();
insert_item(&db, "movie-1", "Movie").await;
insert_item(&db, "track-1", "Audio").await;
insert_item(&db, "movie-ok", "Movie").await;
// Mis-downloaded: completed, no media_type, video item.
insert_download(&db, "movie-1", "completed", Some("http://audio/url"), None).await;
// A real audio download: untouched.
insert_download(&db, "track-1", "completed", Some("http://audio/ok"), None).await;
// A correctly-typed video download: untouched.
insert_download(
&db,
"movie-ok",
"completed",
Some("http://video/ok"),
Some("video"),
)
.await;
let requeued = requeue_mistyped_video_downloads(&db).await.unwrap();
assert_eq!(requeued, 1);
let (status, url, _t) = get_row(&db, "movie-1").await;
assert_eq!(status, "pending", "the mis-typed row must download again");
assert_eq!(url, None, "its audio URL must be cleared so it re-resolves");
let (status, url, _t) = get_row(&db, "track-1").await;
assert_eq!(status, "completed", "a real audio download is untouched");
assert_eq!(url.as_deref(), Some("http://audio/ok"));
let (status, _u, _t) = get_row(&db, "movie-ok").await;
assert_eq!(status, "completed", "a correct video download is untouched");
}
#[tokio::test]
async fn video_rows_use_media_type_in_resolver() {
let db = test_db();
+2
View File
@@ -17,6 +17,7 @@ pub mod repository;
pub mod sessions;
pub mod storage;
pub mod sync;
pub mod sync_drain;
pub use auth::*;
pub use catalog::*;
@@ -34,3 +35,4 @@ pub use repository::{RepositoryManager, RepositoryManagerWrapper, *};
pub use sessions::*;
pub use storage::*;
pub use sync::*;
pub use sync_drain::*;
+24
View File
@@ -80,6 +80,30 @@ pub fn storage_init(db: State<DatabaseWrapper>) -> Result<String, String> {
Ok(database.path().to_string_lossy().to_string())
}
/// A playable URL for a downloaded file on disk.
///
/// Local media is served over a loopback HTTP server rather than handed to the
/// webview as a `file://`/asset URL, because the asset protocol cannot stream a
/// large file — it answers a range-less request with the whole thing, which
/// Chromium abandons. See `media_server` for why real HTTP is used.
///
/// The returned URL carries the server's per-session token, so it is only valid
/// for this run of the app and must not be persisted.
///
/// TRACES: UR-071 | DR-137
#[tauri::command]
#[specta::specta]
pub fn media_local_url(
server: State<crate::media_server::MediaServerWrapper>,
path: String,
) -> Result<String, String> {
server
.0
.as_ref()
.map(|s| s.url_for(&path))
.ok_or_else(|| "Local media server is not running".to_string())
}
/// Get storage directory path (parent directory of the database file)
#[tauri::command]
#[specta::specta]
+29 -15
View File
@@ -2,7 +2,9 @@
//!
//! The sync queue stores mutations (favorites, playback progress, etc.)
//! that need to be synced to the Jellyfin server when connectivity is restored.
//! TRACES: UR-002, UR-017, UR-025 | DR-014
//! Draining it lives in `sync_drain` (DR-131); this module is the storage and
//! read side the UI lists from (DR-132).
//! TRACES: UR-002, UR-017, UR-025 | DR-014, DR-131, DR-132
use serde::{Deserialize, Serialize};
use std::sync::Arc;
@@ -24,6 +26,12 @@ pub struct SyncQueueItem {
pub retry_count: i32,
pub created_at: Option<String>,
pub error_message: Option<String>,
/// Cached title of the item the operation is about, when the catalog knows
/// it. Resolved here rather than by a per-row frontend fetch — the queue
/// list is otherwise a wall of opaque ids.
///
/// TRACES: UR-025 | DR-132
pub item_name: Option<String>,
}
/// Queue a mutation for sync to server
@@ -74,20 +82,20 @@ pub async fn sync_get_pending(
Arc::new(database.service())
};
let sql = if let Some(l) = limit {
format!(
"SELECT id, user_id, operation, item_id, payload, status, retry_count, created_at, error_message
FROM sync_queue
WHERE user_id = ? AND status IN ('pending', 'failed')
ORDER BY created_at ASC
LIMIT {}",
l
)
} else {
"SELECT id, user_id, operation, item_id, payload, status, retry_count, created_at, error_message
FROM sync_queue
WHERE user_id = ? AND status IN ('pending', 'failed')
ORDER BY created_at ASC".to_string()
// The `items` join names the queued item where the catalog has it; a row for
// an item that was never cached still lists, with a null name.
// `abandoned` rows (DR-131 gave up on them) are excluded here for the same
// reason they are excluded from the count — they are no longer waiting.
const SELECT: &str = "SELECT q.id, q.user_id, q.operation, q.item_id, q.payload, q.status,
COALESCE(q.retry_count, 0), q.created_at, q.error_message, i.name
FROM sync_queue q
LEFT JOIN items i ON i.id = q.item_id
WHERE q.user_id = ? AND q.status IN ('pending', 'failed')
ORDER BY q.created_at ASC, q.id ASC";
let sql = match limit {
Some(l) => format!("{} LIMIT {}", SELECT, l),
None => SELECT.to_string(),
};
let query = Query::with_params(sql, vec![QueryParam::String(user_id)]);
@@ -104,6 +112,7 @@ pub async fn sync_get_pending(
retry_count: row.get(6)?,
created_at: row.get(7)?,
error_message: row.get(8)?,
item_name: row.get(9)?,
})
})
.await
@@ -256,6 +265,7 @@ mod tests {
retry_count: 0,
created_at: Some("2024-02-14T08:00:00Z".to_string()),
error_message: None,
item_name: None,
};
// Should serialize successfully
@@ -280,6 +290,7 @@ mod tests {
retry_count: 3,
created_at: Some("2024-02-14T07:00:00Z".to_string()),
error_message: Some("Connection timeout".to_string()),
item_name: None,
};
let json = serde_json::to_string(&item).unwrap();
@@ -300,6 +311,7 @@ mod tests {
retry_count: 0,
created_at: None,
error_message: None,
item_name: None,
};
let json = serde_json::to_string(&item).unwrap();
@@ -323,6 +335,7 @@ mod tests {
retry_count: 0,
created_at: None,
error_message: None,
item_name: None,
};
let json = serde_json::to_string(&item).unwrap();
@@ -363,6 +376,7 @@ mod tests {
retry_count: 0,
created_at: None,
error_message: None,
item_name: None,
};
// Simulate retries
+838
View File
@@ -0,0 +1,838 @@
//! Draining the offline mutation queue (`sync_queue`) to the server.
//!
//! `sync_queue` had producers but no consumer: `PlaybackReporter::queue_for_sync`
//! inserts a row whenever a start/stop/mark-played cannot reach the server, and
//! nothing ever pushed one. `sync_mark_processing`/`_completed`/`_failed` were
//! registered commands with no callers, so the queue only grew — the offline
//! banner's "N pending" climbed forever and the watch positions those rows stood
//! for never reached Jellyfin.
//!
//! Same shape as the favourites drain (DR-120), and for the same reason: a drain
//! started by a component dies with it, so it lives in Rust and hangs off the
//! `connectivity:reconnected` transition the `ConnectivityMonitor` already emits.
//!
//! TRACES: UR-025, UR-002 | DR-131 | UT-122
use std::sync::Arc;
use async_trait::async_trait;
use log::{debug, info, warn};
use tauri::{Emitter, Listener, Manager};
use crate::repository::types::RepoError;
use crate::repository::MediaRepository;
use crate::storage::db_service::{DatabaseService, Query, QueryParam, RusqliteService};
/// How many times a row may fail before it stops being retried.
///
/// A row that can never succeed (a deleted item, an operation this build does
/// not know how to push) must eventually leave the queue, or it re-creates the
/// bug this module fixes: a count that only ever goes up.
pub const MAX_SYNC_ATTEMPTS: i32 = 5;
/// Emitted after a drain so open views can re-read the queue instead of waiting
/// for the frontend's 10s poll.
pub const SYNC_QUEUE_CHANGED_EVENT: &str = "sync-queue-changed";
/// A queued mutation, resolved from its stored `operation` + JSON `payload`.
#[derive(Debug, Clone, PartialEq, Eq)]
pub enum QueuedOp {
PlaybackStart {
item_id: String,
position_ticks: i64,
},
/// Also where `update_progress` lands: replaying a mid-playback progress
/// report long after the fact would tell the server we are still playing.
/// What the row actually carries is a resume position, and "stopped at N"
/// is how that reaches Jellyfin's `UserData`.
PlaybackStopped {
item_id: String,
position_ticks: i64,
},
MarkPlayed {
item_id: String,
},
/// Legacy rows only — live favourite toggles drain via `user_data.pending_sync`
/// (DR-120). Supported so a row written by an older build still lands.
Favorite {
item_id: String,
is_favorite: bool,
},
}
/// Turn a stored row into something pushable.
///
/// Payload keys differ by producer: the Rust reporter writes `position_ticks`,
/// while `syncService.queuePlaybackProgress` writes camelCase `positionMs`.
/// Both are accepted rather than normalised at the producer, because rows
/// already in users' databases were written by both.
///
/// TRACES: UR-025 | DR-131 | UT-122
pub fn parse_queued_op(
operation: &str,
item_id: Option<&str>,
payload: Option<&str>,
) -> Result<QueuedOp, String> {
let json: serde_json::Value = match payload {
Some(raw) if !raw.trim().is_empty() => {
serde_json::from_str(raw).map_err(|e| format!("Unreadable payload: {}", e))?
}
_ => serde_json::Value::Null,
};
let item_id = item_id
.filter(|id| !id.is_empty())
.ok_or_else(|| format!("Operation '{}' has no item id", operation))?
.to_string();
let ticks = || -> i64 {
if let Some(t) = json.get("position_ticks").and_then(|v| v.as_i64()) {
return t;
}
if let Some(ms) = json.get("positionMs").and_then(|v| v.as_i64()) {
return ms * 10_000; // ms → Jellyfin ticks (100ns)
}
0
};
match operation {
"report_playback_start" => Ok(QueuedOp::PlaybackStart {
item_id,
position_ticks: ticks(),
}),
"report_playback_stopped" | "update_progress" => Ok(QueuedOp::PlaybackStopped {
item_id,
position_ticks: ticks(),
}),
"mark_played" => Ok(QueuedOp::MarkPlayed { item_id }),
"mark_favorite" => Ok(QueuedOp::Favorite {
item_id,
is_favorite: true,
}),
"unmark_favorite" => Ok(QueuedOp::Favorite {
item_id,
is_favorite: false,
}),
other => Err(format!("Unsupported operation '{}'", other)),
}
}
/// The slice of the repository the drain needs — narrow so it can be doubled in
/// a test without forty `unimplemented!()` methods.
#[async_trait]
pub trait SyncSink: Send + Sync {
async fn push(&self, op: &QueuedOp) -> Result<(), RepoError>;
}
#[async_trait]
impl<T: MediaRepository + ?Sized> SyncSink for T {
async fn push(&self, op: &QueuedOp) -> Result<(), RepoError> {
match op {
QueuedOp::PlaybackStart {
item_id,
position_ticks,
} => self.report_playback_start(item_id, *position_ticks).await,
QueuedOp::PlaybackStopped {
item_id,
position_ticks,
} => self.report_playback_stopped(item_id, *position_ticks).await,
QueuedOp::MarkPlayed { item_id } => self.mark_played(item_id).await,
QueuedOp::Favorite {
item_id,
is_favorite,
} => {
if *is_favorite {
self.mark_favorite(item_id).await
} else {
self.unmark_favorite(item_id).await
}
}
}
}
}
/// What a drain did, for logging and for the frontend's "Sync now" button.
#[derive(
Debug, Clone, Default, PartialEq, Eq, serde::Serialize, serde::Deserialize, specta::Type,
)]
#[serde(rename_all = "camelCase")]
pub struct DrainReport {
/// Rows that reached the server and are now `completed`.
pub pushed: i32,
/// Rows that failed and will be retried on the next reconnect.
pub deferred: i32,
/// Rows that exhausted `MAX_SYNC_ATTEMPTS` and were given up on.
pub abandoned: i32,
/// Rows still waiting afterwards (what the badge counts).
pub remaining: i32,
}
/// Why a push failed, and whether the row should be charged an attempt for it.
struct PushFailure {
reason: String,
/// The server could not be reached at all — retry later, free of charge.
transient: bool,
}
#[derive(Debug, Clone)]
struct QueuedRow {
id: i64,
operation: String,
item_id: Option<String>,
payload: Option<String>,
retry_count: i32,
}
async fn read_queue(db: &Arc<RusqliteService>, user_id: &str) -> Result<Vec<QueuedRow>, String> {
db.query_many(
Query::with_params(
"SELECT id, operation, item_id, payload, COALESCE(retry_count, 0) \
FROM sync_queue \
WHERE user_id = ? AND status IN ('pending', 'failed') \
ORDER BY created_at ASC, id ASC",
vec![QueryParam::String(user_id.to_string())],
),
|row| {
Ok(QueuedRow {
id: row.get(0)?,
operation: row.get(1)?,
item_id: row.get(2)?,
payload: row.get(3)?,
retry_count: row.get(4)?,
})
},
)
.await
}
async fn remaining_count(db: &Arc<RusqliteService>, user_id: &str) -> Result<i32, String> {
db.query_one(
Query::with_params(
"SELECT COUNT(*) FROM sync_queue WHERE user_id = ? AND status IN ('pending', 'failed')",
vec![QueryParam::String(user_id.to_string())],
),
|row| row.get(0),
)
.await
}
/// Push every queued mutation for this user, oldest first.
///
/// Chronological order matters: a stale start replayed after a later stop would
/// otherwise move the server's resume position backwards.
///
/// A row that fails keeps its place and is retried on the next reconnect, until
/// `MAX_SYNC_ATTEMPTS` — after which it is abandoned, because a row nothing can
/// ever push is exactly what turned this queue into a counter that only grew.
///
/// TRACES: UR-025, UR-002 | DR-131 | UT-122
pub async fn drain_sync_queue(
db: &Arc<RusqliteService>,
sink: &dyn SyncSink,
user_id: &str,
) -> Result<DrainReport, String> {
let queued = read_queue(db, user_id).await?;
if queued.is_empty() {
return Ok(DrainReport::default());
}
info!(
"[SyncQueue] Pushing {} operation(s) queued while offline",
queued.len()
);
let mut report = DrainReport::default();
for row in queued {
let outcome = match parse_queued_op(
&row.operation,
row.item_id.as_deref(),
row.payload.as_deref(),
) {
Ok(op) => sink.push(&op).await.map_err(|e| PushFailure {
// An unreachable server is not the row's fault: burning its
// budget would abandon perfectly good rows just because the app
// was opened offline a few times.
transient: matches!(e, RepoError::Offline | RepoError::Network { .. }),
reason: e.to_string(),
}),
// An unreadable or unsupported row can never succeed, so it does
// burn attempts rather than being deleted outright — the panel shows
// the reason until it is abandoned.
Err(reason) => Err(PushFailure {
reason,
transient: false,
}),
};
match outcome {
Ok(()) => {
mark_completed(db, row.id).await?;
report.pushed += 1;
}
Err(failure) if failure.transient => {
mark_deferred(db, row.id, &failure.reason).await?;
debug!(
"[SyncQueue] Server unreachable, {} stays queued: {}",
row.operation, failure.reason
);
report.deferred += 1;
}
Err(failure) => {
let attempts = row.retry_count + 1;
let give_up = attempts >= MAX_SYNC_ATTEMPTS;
mark_failed(db, row.id, attempts, give_up, &failure.reason).await?;
if give_up {
warn!(
"[SyncQueue] Giving up on {} after {} attempts: {}",
row.operation, attempts, failure.reason
);
report.abandoned += 1;
} else {
debug!(
"[SyncQueue] Deferring {} (attempt {}): {}",
row.operation, attempts, failure.reason
);
report.deferred += 1;
}
}
}
}
report.remaining = remaining_count(db, user_id).await?;
info!(
"[SyncQueue] Drain finished: {} pushed, {} deferred, {} abandoned, {} remaining",
report.pushed, report.deferred, report.abandoned, report.remaining
);
Ok(report)
}
async fn mark_completed(db: &Arc<RusqliteService>, id: i64) -> Result<(), String> {
db.execute(Query::with_params(
"UPDATE sync_queue \
SET status = 'completed', processed_at = CURRENT_TIMESTAMP, error_message = NULL \
WHERE id = ?",
vec![QueryParam::Int64(id)],
))
.await?;
Ok(())
}
/// Put a row back in the queue untouched apart from its error note — used when
/// the server was simply unreachable.
async fn mark_deferred(db: &Arc<RusqliteService>, id: i64, reason: &str) -> Result<(), String> {
db.execute(Query::with_params(
"UPDATE sync_queue SET status = 'pending', error_message = ? WHERE id = ?",
vec![
QueryParam::String(reason.to_string()),
QueryParam::Int64(id),
],
))
.await?;
Ok(())
}
async fn mark_failed(
db: &Arc<RusqliteService>,
id: i64,
attempts: i32,
give_up: bool,
reason: &str,
) -> Result<(), String> {
db.execute(Query::with_params(
"UPDATE sync_queue \
SET status = ?, retry_count = ?, error_message = ?, processed_at = CURRENT_TIMESTAMP \
WHERE id = ?",
vec![
QueryParam::String(if give_up { "abandoned" } else { "failed" }.to_string()),
QueryParam::Int(attempts),
QueryParam::String(reason.to_string()),
QueryParam::Int64(id),
],
))
.await?;
Ok(())
}
/// Drain on every offline→online transition.
///
/// TRACES: UR-025 | DR-131
pub fn spawn_sync_queue_drain(app: tauri::AppHandle) {
let handle = app.clone();
app.listen("connectivity:reconnected", move |_event| {
let app = handle.clone();
tauri::async_runtime::spawn(async move {
if let Err(e) = run_drain(&app).await {
warn!("[SyncQueue] Drain skipped: {}", e);
}
});
});
}
/// Resolve app state and drain. Shared by the reconnect hook and the manual
/// "Sync now" command.
pub async fn run_drain(app: &tauri::AppHandle) -> Result<DrainReport, String> {
let db_service: Arc<RusqliteService> = {
let db = app.state::<crate::commands::storage::DatabaseWrapper>();
let database = db.0.lock().map_err(|e| e.to_string())?;
Arc::new(database.service())
};
let (repo, user_id) = {
let manager = app.state::<crate::commands::repository::RepositoryManagerWrapper>();
let handles = manager.0.handles();
let Some(handle) = handles.first() else {
// Not signed in — nothing to push on behalf of.
return Ok(DrainReport::default());
};
let repo = manager.0.get(handle).ok_or("Repository not found")?;
let user_id = repo.user_id().to_string();
(repo, user_id)
};
let report = drain_sync_queue(&db_service, repo.as_ref(), &user_id).await?;
if report.pushed > 0 || report.abandoned > 0 {
if let Err(e) = app.emit(SYNC_QUEUE_CHANGED_EVENT, &report) {
warn!("[SyncQueue] Failed to emit change event: {}", e);
}
}
Ok(report)
}
/// Push the queue now, on the user's say-so, instead of waiting for a reconnect.
///
/// TRACES: UR-025 | DR-132
#[tauri::command]
#[specta::specta]
pub async fn sync_process_pending(app: tauri::AppHandle) -> Result<DrainReport, String> {
run_drain(&app).await
}
#[cfg(test)]
mod tests {
use super::*;
use rusqlite::Connection;
use std::sync::Mutex;
/// Records what the server was asked to do, and can be told to fail.
struct RecordingSink {
calls: Mutex<Vec<QueuedOp>>,
fail_with: Option<RepoError>,
}
impl RecordingSink {
fn new() -> Self {
Self {
calls: Mutex::new(Vec::new()),
fail_with: None,
}
}
/// The server is there and refuses the operation — the row's own fault.
fn always_rejecting() -> Self {
Self {
calls: Mutex::new(Vec::new()),
fail_with: Some(RepoError::Server {
message: "HTTP 400".to_string(),
}),
}
}
/// The server cannot be reached at all — nothing to do with the row.
fn unreachable() -> Self {
Self {
calls: Mutex::new(Vec::new()),
fail_with: Some(RepoError::Offline),
}
}
fn calls(&self) -> Vec<QueuedOp> {
self.calls.lock().unwrap().clone()
}
}
#[async_trait]
impl SyncSink for RecordingSink {
async fn push(&self, op: &QueuedOp) -> Result<(), RepoError> {
if let Some(err) = &self.fail_with {
return Err(err.clone());
}
self.calls.lock().unwrap().push(op.clone());
Ok(())
}
}
fn test_db() -> Arc<RusqliteService> {
let conn = Connection::open_in_memory().unwrap();
conn.execute_batch(
r#"
CREATE TABLE sync_queue (
id INTEGER PRIMARY KEY AUTOINCREMENT,
user_id TEXT NOT NULL,
operation TEXT NOT NULL,
item_id TEXT,
payload TEXT,
status TEXT DEFAULT 'pending',
retry_count INTEGER DEFAULT 0,
created_at TEXT DEFAULT CURRENT_TIMESTAMP,
processed_at TEXT,
error_message TEXT
);
"#,
)
.unwrap();
Arc::new(RusqliteService::new(Arc::new(Mutex::new(conn))))
}
/// (user, operation, item_id, payload, status, retry_count, created_at)
type Seed<'a> = (
&'a str,
&'a str,
&'a str,
Option<&'a str>,
&'a str,
i32,
&'a str,
);
async fn seed(db: &Arc<RusqliteService>, rows: &[Seed<'_>]) {
for (user, op, item, payload, status, retries, created) in rows {
db.execute(Query::with_params(
"INSERT INTO sync_queue (user_id, operation, item_id, payload, status, retry_count, created_at) \
VALUES (?, ?, ?, ?, ?, ?, ?)",
vec![
QueryParam::String(user.to_string()),
QueryParam::String(op.to_string()),
QueryParam::String(item.to_string()),
payload
.map(|p| QueryParam::String(p.to_string()))
.unwrap_or(QueryParam::Null),
QueryParam::String(status.to_string()),
QueryParam::Int(*retries),
QueryParam::String(created.to_string()),
],
))
.await
.unwrap();
}
}
async fn row_state(db: &Arc<RusqliteService>, item_id: &str) -> (String, i32) {
db.query_one(
Query::with_params(
"SELECT status, COALESCE(retry_count, 0) FROM sync_queue WHERE item_id = ?",
vec![QueryParam::String(item_id.to_string())],
),
|row| Ok((row.get::<_, String>(0)?, row.get::<_, i32>(1)?)),
)
.await
.unwrap()
}
/// UT-122 — the bug itself: rows queued while offline reach the server on
/// reconnect and stop counting towards the offline banner's badge.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_drain_pushes_queued_operations_and_clears_the_queue() {
let db = test_db();
seed(
&db,
&[
(
"u1",
"report_playback_start",
"ep1",
Some(r#"{"position_ticks": 100}"#),
"pending",
0,
"2026-08-01T10:00:00Z",
),
(
"u1",
"report_playback_stopped",
"ep2",
Some(r#"{"position_ticks": 5000}"#),
"pending",
0,
"2026-08-01T10:01:00Z",
),
(
"u1",
"mark_played",
"ep3",
None,
"pending",
0,
"2026-08-01T10:02:00Z",
),
],
)
.await;
let sink = RecordingSink::new();
let report = drain_sync_queue(&db, &sink, "u1").await.unwrap();
assert_eq!(
sink.calls(),
vec![
QueuedOp::PlaybackStart {
item_id: "ep1".to_string(),
position_ticks: 100
},
QueuedOp::PlaybackStopped {
item_id: "ep2".to_string(),
position_ticks: 5000
},
QueuedOp::MarkPlayed {
item_id: "ep3".to_string()
},
],
"every queued operation pushes, oldest first"
);
assert_eq!(report.pushed, 3);
assert_eq!(report.remaining, 0, "the badge must reach zero");
assert_eq!(row_state(&db, "ep1").await.0, "completed");
}
/// A push that fails stays queued for the next reconnect rather than being
/// dropped.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_drain_defers_failed_pushes() {
let db = test_db();
seed(
&db,
&[(
"u1",
"report_playback_stopped",
"ep1",
Some(r#"{"position_ticks": 42}"#),
"pending",
0,
"2026-08-01T10:00:00Z",
)],
)
.await;
let report = drain_sync_queue(&db, &RecordingSink::always_rejecting(), "u1")
.await
.unwrap();
assert_eq!(report.deferred, 1);
assert_eq!(report.remaining, 1);
assert_eq!(row_state(&db, "ep1").await, ("failed".to_string(), 1));
}
/// An unreachable server does not charge the row an attempt — otherwise
/// opening the app offline a few times abandons perfectly good rows.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_unreachable_server_does_not_burn_the_retry_budget() {
let db = test_db();
seed(
&db,
&[(
"u1",
"mark_played",
"ep1",
None,
"pending",
MAX_SYNC_ATTEMPTS - 1,
"2026-08-01T10:00:00Z",
)],
)
.await;
let report = drain_sync_queue(&db, &RecordingSink::unreachable(), "u1")
.await
.unwrap();
assert_eq!(report.deferred, 1);
assert_eq!(report.abandoned, 0);
assert_eq!(
row_state(&db, "ep1").await,
("pending".to_string(), MAX_SYNC_ATTEMPTS - 1),
"still queued, with its budget intact"
);
}
/// A row that can never succeed must eventually leave the queue, or the
/// count climbs forever — which is the bug this module exists to fix.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_drain_abandons_a_row_after_max_attempts() {
let db = test_db();
seed(
&db,
&[(
"u1",
"report_playback_stopped",
"doomed",
Some(r#"{"position_ticks": 1}"#),
"failed",
MAX_SYNC_ATTEMPTS - 1,
"2026-08-01T10:00:00Z",
)],
)
.await;
let report = drain_sync_queue(&db, &RecordingSink::always_rejecting(), "u1")
.await
.unwrap();
assert_eq!(report.abandoned, 1);
assert_eq!(report.remaining, 0, "an abandoned row stops being counted");
assert_eq!(row_state(&db, "doomed").await.0, "abandoned");
}
/// An operation this build cannot push does not wedge the queue behind it.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_unsupported_operation_records_a_reason_and_lets_others_through() {
let db = test_db();
seed(
&db,
&[
(
"u1",
"playlist_reorder_item",
"pl1",
None,
"pending",
0,
"2026-08-01T10:00:00Z",
),
(
"u1",
"mark_played",
"ep1",
None,
"pending",
0,
"2026-08-01T10:01:00Z",
),
],
)
.await;
let sink = RecordingSink::new();
let report = drain_sync_queue(&db, &sink, "u1").await.unwrap();
assert_eq!(
sink.calls(),
vec![QueuedOp::MarkPlayed {
item_id: "ep1".to_string()
}],
"the unsupported row must not block the ones behind it"
);
assert_eq!(report.pushed, 1);
assert_eq!(report.deferred, 1);
assert_eq!(row_state(&db, "pl1").await, ("failed".to_string(), 1));
}
/// Another user's queued changes are not pushed with this user's token.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_drain_only_touches_the_given_user() {
let db = test_db();
seed(
&db,
&[
(
"u1",
"mark_played",
"mine",
None,
"pending",
0,
"2026-08-01T10:00:00Z",
),
(
"u2",
"mark_played",
"theirs",
None,
"pending",
0,
"2026-08-01T10:00:00Z",
),
],
)
.await;
let sink = RecordingSink::new();
drain_sync_queue(&db, &sink, "u1").await.unwrap();
assert_eq!(
sink.calls(),
vec![QueuedOp::MarkPlayed {
item_id: "mine".to_string()
}]
);
assert_eq!(row_state(&db, "theirs").await.0, "pending");
}
/// Nothing queued means no server calls at all — a reconnect must not
/// generate traffic just because it happened.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[tokio::test]
async fn test_drain_is_a_noop_when_the_queue_is_empty() {
let db = test_db();
let sink = RecordingSink::new();
let report = drain_sync_queue(&db, &sink, "u1").await.unwrap();
assert_eq!(report, DrainReport::default());
assert!(sink.calls().is_empty());
}
/// Both payload dialects parse: `position_ticks` from the Rust reporter and
/// camelCase `positionMs` from the frontend's queue helper.
///
/// TRACES: UR-025 | DR-131 | UT-122
#[test]
fn test_parse_accepts_both_payload_dialects() {
assert_eq!(
parse_queued_op(
"report_playback_stopped",
Some("ep1"),
Some(r#"{"position_ticks": 1234}"#)
)
.unwrap(),
QueuedOp::PlaybackStopped {
item_id: "ep1".to_string(),
position_ticks: 1234
}
);
assert_eq!(
parse_queued_op("update_progress", Some("ep1"), Some(r#"{"positionMs": 5}"#)).unwrap(),
QueuedOp::PlaybackStopped {
item_id: "ep1".to_string(),
position_ticks: 50_000
},
"milliseconds convert to ticks"
);
assert_eq!(
parse_queued_op("mark_played", Some("ep1"), None).unwrap(),
QueuedOp::MarkPlayed {
item_id: "ep1".to_string()
},
"a payload-less operation is not an error"
);
assert!(parse_queued_op("mark_played", None, None).is_err());
assert!(parse_queued_op("teleport", Some("ep1"), None).is_err());
}
}