fix(player): mpv draws all Linux video, and no longer runs text from a URL
Security (DR-298, DR-299): - The pinned libmpv crate's Mpv::command joins its arguments and calls mpv_command_string, which parses `;` as a command separator. Stream URLs carry server-controlled ids and TranscodingUrl, and a download's file:// path carries its track title, so a crafted title could run any mpv command, `run` included. Every call now goes through mpv_command::command, an argv built for mpv_command. The same parse broke loadfile for every downloaded title containing a space. - mpv's tls-verify defaults to no, and its URLs carry the ApiKey. Every handle is now hardened with tls-verify=yes and ytdl=no before its first loadfile, and fails construction if it cannot be. Linux video (DR-235 phase 1): - native_video::enabled() is unconditional on Linux; the JELLYTAU_NATIVE_VIDEO opt-in is retired. No platform reports a webview video fallback, so the Settings switch no longer appears. Windows keeps the webview element until mpv reaches it (DR-237). - The Linux device profile is unchanged (still h264, DR-234), so this ships the configuration that was tested under the env var.
This commit is contained in:
@@ -85,6 +85,8 @@ impl MpvPlayer {
|
||||
let mpv = Mpv::new().map_err(|e| PlayerError {
|
||||
message: format!("mpv_create failed: {e:?}"),
|
||||
})?;
|
||||
// TRACES: UR-012 | DR-299
|
||||
super::mpv_command::harden(&mpv).map_err(|message| PlayerError { message })?;
|
||||
|
||||
let set = |k: &str, v: &str| {
|
||||
if let Err(e) = mpv.set_property(k, v) {
|
||||
@@ -229,10 +231,10 @@ impl MediaPlayer for MpvPlayer {
|
||||
})?;
|
||||
|
||||
info!("[MpvPlayer] open {} at {:?}", req.selection.url, req.start);
|
||||
self.mpv
|
||||
.command("loadfile", &[&req.selection.url, "replace"])
|
||||
// TRACES: UR-003, UR-004 | DR-298
|
||||
super::mpv_command::command(&self.mpv, &["loadfile", &req.selection.url, "replace"])
|
||||
.map_err(|e| PlayerError {
|
||||
message: format!("loadfile failed: {e:?}"),
|
||||
message: format!("loadfile failed: {e}"),
|
||||
})?;
|
||||
Ok(())
|
||||
}
|
||||
@@ -275,8 +277,8 @@ impl MediaPlayer for MpvPlayer {
|
||||
}
|
||||
// Idempotent: stopping an already-stopped mpv is not an error worth
|
||||
// propagating, and callers legitimately close twice on teardown.
|
||||
if let Err(e) = self.mpv.command("stop", &[]) {
|
||||
debug!("[MpvPlayer] stop on an idle player: {e:?}");
|
||||
if let Err(e) = super::mpv_command::command(&self.mpv, &["stop"]) {
|
||||
debug!("[MpvPlayer] stop on an idle player: {e}");
|
||||
}
|
||||
Ok(())
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user