Security (DR-298, DR-299):
- The pinned libmpv crate's Mpv::command joins its arguments and calls
mpv_command_string, which parses `;` as a command separator. Stream
URLs carry server-controlled ids and TranscodingUrl, and a download's
file:// path carries its track title, so a crafted title could run any
mpv command, `run` included. Every call now goes through
mpv_command::command, an argv built for mpv_command. The same parse
broke loadfile for every downloaded title containing a space.
- mpv's tls-verify defaults to no, and its URLs carry the ApiKey. Every
handle is now hardened with tls-verify=yes and ytdl=no before its
first loadfile, and fails construction if it cannot be.
Linux video (DR-235 phase 1):
- native_video::enabled() is unconditional on Linux; the
JELLYTAU_NATIVE_VIDEO opt-in is retired. No platform reports a
webview video fallback, so the Settings switch no longer appears.
Windows keeps the webview element until mpv reaches it (DR-237).
- The Linux device profile is unchanged (still h264, DR-234), so this
ships the configuration that was tested under the env var.