dtourolle 65d3d912f7 fix(player): declare and enforce a lock hierarchy for PlayerController
The controller carries seventeen mutexes, reached from the MPV event loop,
JNI callbacks, sleep and autoplay timers, the session poller and every IPC
command. Nothing prevented two threads taking the same pair in opposite
orders, which deadlocks playback outright — and this subsystem has already
produced one deadlock.

No inversion exists today: the acquisitions really are scoped, and
`previous()` explicitly drops the backend guard before touching the queue.
That is the point. It holds by convention, convention is not checked, and
the failure it guards against is a frozen app with no error anywhere.

`LOCK_ORDER` writes the convention down, following the nesting the code
already relies on — `backend` before `queue` ("what is playing" before
"what is next"), `event_emitter` last because notifying the frontend must
never reach back for player state.

The tripwire only reports acquisitions that actually *overlap*, since two
locks taken one after another, each released before the next, cannot
deadlock. Verified by injecting a real inversion into `seek()`, which the
test located by line and rank.
2026-09-07 22:24:45 +02:00
2026-08-27 17:58:06 +02:00
2026-01-26 22:21:54 +01:00
2026-08-27 17:58:06 +02:00
2026-08-27 17:58:06 +02:00
2026-01-26 22:21:54 +01:00
2026-01-26 22:21:54 +01:00

JellyTau logo
JellyTau

A cross-platform Jellyfin client built with Tauri, SvelteKit, and TypeScript.

Business logic lives in a Rust backend; a UI-rich Svelte frontend handles presentation and talks to it over Tauri's IPC. Targets Linux (libmpv) and Android (ExoPlayer).

Getting Started

This project uses bun as its package manager.

# Activate the Rust environment (fish shell)
source "$HOME/.cargo/env.fish"

# Install dependencies
bun install

# Run in development
bun run tauri dev

# Type-check the frontend
bun run check

# Build for Linux
bun run tauri build

# Build for Android
bun run tauri android build

For the full set of build, test, and Android helper scripts, see scripts/README.md.

Documentation

Topic Location
Architecture overview & subsystem docs docs/architecture/
Requirements, traceability & technical debt docs/requirements.md
Build & release process docs/build/build-release.md
Docker builds docs/build/docker.md
Traceability tooling & CI docs/traceability.md, docs/traceability-ci.md
Release checklist docs/release-checklist.md
UX flows docs/ux-flows.md
CI operations (builder image, secrets, runner) docs/build/ci-operations.md

Contributing

CONTRIBUTING.md covers the setup, the gates a change has to pass, and the two rules that catch people out (bug fixes start with a failing test; Jellyfin's taxonomy stays in Rust). Please also read the Code of Conduct.

Found a security problem? Do not open an issue — see SECURITY.md.

Verifying a download

Every release publishes SHA256SUMS covering all of its artifacts, plus an SBOM of what went into the build:

sha256sum -c SHA256SUMS

Desktop builds update themselves from Settings → Updates, verifying each payload against JellyTau's signing key before installing. Android installs are handled by the system installer, so the app links to the releases page instead.

VS Code + Svelte + Tauri + rust-analyzer.

License

MIT

S
Description
A jellyfin client with Tauri
Readme MIT
198 MiB
2026-09-07 20:30:29 +00:00
Languages
Rust 51.4%
TypeScript 25.4%
Svelte 16.2%
Kotlin 4.7%
Shell 1.7%
Other 0.5%