fix(player): mpv draws all Linux video, and no longer runs text from a URL

Security (DR-298, DR-299):
- The pinned libmpv crate's Mpv::command joins its arguments and calls
  mpv_command_string, which parses `;` as a command separator. Stream
  URLs carry server-controlled ids and TranscodingUrl, and a download's
  file:// path carries its track title, so a crafted title could run any
  mpv command, `run` included. Every call now goes through
  mpv_command::command, an argv built for mpv_command. The same parse
  broke loadfile for every downloaded title containing a space.
- mpv's tls-verify defaults to no, and its URLs carry the ApiKey. Every
  handle is now hardened with tls-verify=yes and ytdl=no before its
  first loadfile, and fails construction if it cannot be.

Linux video (DR-235 phase 1):
- native_video::enabled() is unconditional on Linux; the
  JELLYTAU_NATIVE_VIDEO opt-in is retired. No platform reports a
  webview video fallback, so the Settings switch no longer appears.
  Windows keeps the webview element until mpv reaches it (DR-237).
- The Linux device profile is unchanged (still h264, DR-234), so this
  ships the configuration that was tested under the env var.
This commit is contained in:
2026-09-24 20:38:32 -04:00
parent fd1277746d
commit 9d9d81bef3
13 changed files with 298 additions and 161 deletions
+10 -1
View File
@@ -1,6 +1,15 @@
# Spec: Desktop native video — mpv renders the picture, everywhere
**Status:** Proposed
**Status:** Partially implemented — phase 1 routing shipped: mpv is the only
Linux video renderer (`native_video::enabled()` is unconditional on Linux, no
webview fallback is offered). **Left:** Linux's device profile still claims only
`h264` (DR-234), so video still arrives as a server transcode — mpv plays it, but
the direct-play gain is not yet taken; `hwdec` is unset, so mpv decodes in
software (DR-236); a failed surface attach only logs, it does not surface an
error; the phase 1 soak and X11/Wayland criteria are unrecorded; phases 2 and 3.
Phase 3 also deletes the now-inert frontend switch (`experimentalNativeVideo`,
`nativeVideoWanted`, the Settings toggle and the adapter's suppressor flag),
which no platform reaches since `webview_video_fallback` became false everywhere.
**Requirements:** UR-080 (new) → DR-231 … DR-237 (new); IR-033 (new)
**UX spec:** n/a — nothing about the player's appearance changes. What changes is
what is behind the controls.