Files
jellytau/docs/specs/README.md
T
dtourolle 214997144f
🏗️ Build and Test JellyTau / Run Tests (pull_request) Successful in 22m51s
🏗️ Build and Test JellyTau / Supply Chain (pull_request) Failing after 25s
Traceability Validation / Check Requirement Traces (pull_request) Successful in 14s
🏗️ Build and Test JellyTau / Android Compile Check (pull_request) Successful in 4m19s
feat(deps): upgrade Tauri to 2.11.5, and own the Android context it stopped setting
The plugin versions could not be matched upward without this: both
tauri-plugin-log 2.9.0 and tauri-plugin-updater 2.10.1 require tauri
^2.10, and the tree was on 2.9.5. So the framework moves with them --
tauri 2.9.5 -> 2.11.5, tauri-build 2.5.3 -> 2.6.3, wry 0.53.5 -> 0.55.1
-- and every plugin's Rust crate and npm package is now pinned to the
same version on both sides.

That upgrade broke Android outright, and the breakage is the interesting
part.

Seven call sites in this crate reach JNI through
ndk_context::android_context(), which reads a process-global pair of
pointers. Nothing here ever set that global. `tao` did -- the windowing
layer under wry, three levels below anything this project names in
Cargo.toml. tao 0.34.5 called initialize_android_context() while starting
the activity and our code read what it left behind. tao 0.35.3 keeps the
same two pointers in a private struct and no longer publishes them.

The result, on every launch, was:

  PANIC at ndk-context/src/lib.rs:72: android context was not initialized
    8: ndk_context::android_context
    9: jellytau_lib::run::{{closure}}

Not a crash in our code, and not a change to our code: an undocumented
side effect of a transitive dependency disappeared. Relying on someone
else to populate a global is a dependency that does not appear in
Cargo.toml and gives no warning when it goes.

src-tauri/src/android_context.rs now owns that invariant instead of
assuming it. JNI_OnLoad captures the JavaVM as the shared library loads
-- the earliest moment available, and nothing in tao, wry or tauri
defines one to collide with. The Context is resolved lazily via
ActivityThread.currentApplication() and pinned as a global reference for
the process lifetime, since ndk_context stores a bare pointer and does
not own it. It publishes the Application rather than the Activity:
SecureStorage.initialize() immediately reduces its argument to
applicationContext anyway, and an Application cannot outlive itself the
way a retained Activity would.

Restoring the global keeps all seven callers untouched. Threading a VM
and Context handle through five credential call sites would have been a
larger change with more risk, on the credential path.

Failure now degrades instead of aborting: it is logged and credentials
fall back to the encrypted-file path, which the app already supports.

Verified on a device, R8-minified, not merely compiled:

  [INIT] Android JavaVM and Application published to ndk_context
  Android SecureStorage initialized successfully
  Android Keystore available via SecureStorage
  [INIT] Using system keyring for credential storage
  [CodecDetection] Detected 7 video codecs: av1,h263,h264,hevc,...

-- the real keystore path, not the fallback, and the app stays up. None
of this is reachable by CI: nothing there runs the app.

Also fixed here, both found the same way:

  - `tauri android build --apk true` is now `--apk`. The CLI took a value
    until 2.10; from 2.11 the stray `true` is a positional and the build
    fails before starting. Three call sites in build-android.sh and one
    in build-release.yml -- the latter builds the signed APK, by far the
    most-downloaded artifact.

  - scripts/build-android.sh ran `npm install` on its clean-build path in
    a bun project, ignoring bun.lock and re-resolving the tree. That is
    exactly how the plugin crate/package versions drift apart again.
    scripts/check-tooling.sh now fails on any npm/yarn/pnpm invocation or
    foreign lockfile, and runs in CI.

DR-222, DR-223.
2026-08-21 22:30:28 +02:00

5.6 KiB

Specs index

Feature specs for JellyTau. Start a new one from SPEC-TEMPLATE.md and run it past SPEC-REVIEW-CHECKLIST.md before accepting it.

What lives here

Only work that has not shipped. Once a spec is fully implemented its design is folded into the architecture docs — which are the maintained description of the build — and the spec file is deleted. Git history keeps the original, including its rejected alternatives and acceptance criteria; the architecture docs keep the reasoning that a future change still needs.

So: a file in this directory is a promise, not a description. If you want to know how something works, read docs/architecture/. If you want to know what is planned, read here.

Status vocabulary

Status Meaning
Proposed Written, not accepted. Nothing built.
Accepted Agreed as the design; implementation not started or not finished.
Partially implemented Some parts shipped; the spec names what is left.
Design authority No code of its own — it records a decision later specs act on.

Next free requirement ids (always re-check requirements.md before allocating): UR-079, IR-033, DR-224. Three specs below suggested ids that have since been taken by other work; each carries a ⚠️ note at the top.

Partially implemented

Spec What landed What is left
frontend-domain-model.md Catalog surface: MediaKind, from_jellyfin isolated, ticks → ms primaryImageTagimageId (~30 sites); player/session/reporting tick math; stream.type
libmpv2-migration.md LICENSE The libmpvlibmpv2 crate swap
read-through-media-cache.md DR-126…128, DR-133…138 — cache entries are download rows; local playback of downloads DR-121/122/124/125 — the player quality selector and the read-through capture
scoped-search-boundary-implementation.md Stage 1: SearchScope owned by Rust (DR-063…067) Stage 2: result-side grouping (GROUP_ITEM_TYPES still in searchScope.ts)

Not started

Spec Blocked on / note
backend-owned-stream-selection.md Rust owns direct-play-vs-transcode, transport and quality; players consume one StreamSelection. Phase 1 (delete the .m3u8 sniff) stands alone. Unblocks Linux native video.
build-provenance.md build.rs is still bare. ⚠️ suggested id DR-093 is taken.
player-facade-enforcement.md ~60 commands.player* sites still outside the facade; no lint rule. ⚠️ suggested id DR-095 is taken.
windows-native-audio-backend.md Blocked on the libmpv2 swap. ⚠️ suggested id IR-030 is taken.
linux-native-video-spike.md Spike run 2026-08-21: compositing works on Linux, X11 and Wayland. G1-G6 green bar the Tauri default_vbox() half of G1. Needs an implementation spec that answers adaptive bitrate.

Design authority

Spec Role
playback-backend-unification.md Why video cannot unify onto one native engine and audio can. The audio half has since shipped on Android; Windows has not.
scoped-search-boundary.md The boundary design the check:boundary rule came from. Stage 1 built.
scoped-search.md Superseded in part — its "frontend only, no Rust changes" decision is the leak the boundary spec reversed. UX still current.

Where the shipped specs went

Sixteen specs were folded into the architecture docs and deleted (2026-08-21). Where to look for each:

Shipped work Now documented in
Account menu & global chrome 02-svelte-frontend.md — App Shell and Chrome
Library mosaic 02-svelte-frontend.md — Library Mosaic
Series current-episode navigation 02-svelte-frontend.md — Series and Episode Navigation
Downloads as an offline library 02-svelte-frontend.md — Downloaded Browse
Favourites browsing 01-rust-backend.md — Favorites System
Streaming bitrate cap 01-rust-backend.md — Streaming quality ladder
Locally-indexed search 03-data-flow.md — Search Flow; 01-rust-backend.md — Background workers
Offline downloaded-only filter 06-downloads-and-offline.md — Offline Catalog Visibility
Audio equalizer · Android audio settings parity 05-platform-backends.md — Audio settings on ExoPlayer
Android native video spike 05-platform-backends.md — Native Video Compositing
Video background audio 05-platform-backends.md — Background Audio Handoff
Traceability gate repair traceability-ci.md
Boundary tripwire hardening scripts/check-frontend-boundary.sh (its header is the spec)
Playback docs corrections · req-coverage script removal Nothing to document — both were corrections that have been applied