The documentation described a system that no longer exists, and in two
places described the opposite of what the code now does.
- The layout section documented `<recording-root>/users/<owner-id>/<rel>`
for private recordings and `shared/<rel>` for shared ones. That resolver
was deleted: recordings are stored owner-independently at
`<recording-root>/<rel>`, because one physical file is shared by every
user who asked for it. The organised layouts and the component
sanitisation rules are now documented as they are implemented.
- The config reference claimed persisted queue recovery "is tolerant of
corruption" and "starts with an empty transfer queue instead of aborting
server boot". The queue now fails closed: a damaged database is rebuilt
from the recovery history, and a database ahead of every surviving
history refuses to start. An operator following the old text would have
expected silent recovery from a condition that is deliberately fatal.
- `download.read` / `download.write` were still listed as grantable
permissions after their removal, and `recording.write` after its split.
bin/dvr_doctor.sh looked for `downloads_state.json` and summarised it with
jq. That file never existed under this name, and the queue it stood for is
now a B+Tree, so the section printed "(absent)" and skipped its summary
exactly when an operator needed it. It now reports the repository and its
recovery generations: the CURRENT pointer, the retained generation pair,
journal sizes, the fail-closed case where a database has no history, and a
warning when the recovery directory shares a filesystem with the database
— which survives a corrupt file but not the loss of the volume it exists
to protect against.
CHANGELOG records the three breaking changes: the non-migrating queue, the
permission split, and the moved recording files.
feat: complete DVR and improve streaming, security, configuration, and UI
Complete the Digital Video Recorder subsystem and add a broad set of
reliability, security, streaming, configuration, processing, and Web UI
improvements across Tuliprox.
DVR:
* complete live recording and provider-aware VOD download support
* add recording queue, workers, scheduling, and recurring recording rules
* add conflict detection and capacity-aware scheduling
* add pause, resume, retry, edit, cancel, and delete workflows
* add recording quotas and configurable retention policies
* add crash recovery and startup reconciliation
* add durable lifecycle notifications with per-channel retries
* add DVR health monitoring and diagnostic tooling
* add secure access to recordings, thumbnails, and subtitles
* add WebSocket notifications for recording and rule changes
* add Web UI management for recordings, rules, progress, and task state
* add RBAC, configuration, documentation, and i18n support
Streaming and HLS:
* fix shared-stream idle handling and release dead provider streams correctly
* stop tee streams when both client and cache consumers are gone
* cancel provisioning probes when client streams terminate
* fix transient HLS origin work accounting and intermittent 503 responses
* make stream buffer byte limits configurable
* make shared subscriber idle timeout configurable
* make initial HLS manifest wait timeout configurable
* add configurable TS chunk packet count
* add configurable HLS refresh failure backoff
* centralize redirect limits and retry jitter handling
* improve provider DNS refresh behavior and failover tuning
* preserve UTF-8 characters in catchup templates
* improve stream history validation and persistence error handling
Security:
* use constant-time credential comparisons
* harden library and media path handling against traversal and symlink escapes
* only trust forwarded client IP headers from configured trusted proxies
* redact credentials and sensitive URL data from logs
* reject invalid authentication status-code configuration
* deny users with unresolved plans or invalid content filters
* improve authentication error handling across proxy and HLS endpoints
Configuration and reliability:
* prevent invalid api-proxy.yml reloads from terminating the running server
* fully validate API proxy configuration before persisting changes
* log configuration and EPG cleanup failures instead of silently discarding them
* keep the last valid configuration active after failed hot reloads
* align backend and shared media-server validation
* remove duplicated path and normalization logic
* improve DNS-store recovery and Windows rename fallback handling
* reject invalid duration, timestamp, and numeric conversions safely
* fix playlist bouquet save error handling
* fix provider record update detection
* fix cache boundary handling
* improve startup and persistence failure diagnostics
Filtering, search, sorting, and processing:
* add field-scoped playlist explorer search
* centralize shared stream-history search field definitions
* extend the filter DSL with string, set, and numeric operators
* add EPG ID, channel number, and detected quality as filterable fields
* add filter dry-run preview API with match statistics and samples
* report filter syntax errors with line and column information
* add natural numeric-aware sorting
* add quality-aware channel deduplication
* add accent-independent deduplication
* move natural sorting and quality detection helpers into shared code
* persist explorer search-field selection across reloads
User plans and content access:
* add reusable API user plans for capability tiers
* support inherited cluster and connection limits with per-user overrides
* add plan-level and user-level content filters
* enforce content filters across Xtream, M3U, direct playback, resource access,
stream info, short EPG, categories, and XMLTV
* add trial plans with automatic expiry and Trial status
* add plan selection and content filtering to the user editor
* add full plan management to the API configuration Web UI
* migrate the API user database to schema V7 with plan and filter persistence
Web UI and accessibility:
* add live logging console to the stats page
* improve login error handling and prevent duplicate authentication requests
* add keyboard navigation to tabs, menus, tables, and search
* add ARIA roles, labels, validation state, and live-region feedback
* add confirmation dialogs for destructive actions
* add unsaved-change warnings and Ctrl/Cmd+S shortcuts
* add loading, progress, empty, and in-flight states across views
* improve dropdown and single-selection behavior
* add clipboard and credential-copy helpers
* persist table pagination and explorer search preferences
* improve error recovery when UI context providers are unavailable
* remove multiple panic-prone unwrap and browser API paths
* replace remaining hardcoded UI strings with translation keys
Maintenance:
* resolve backend and frontend compiler and Clippy warnings
* update packages and test fixtures
* consolidate duplicated helpers and validation logic
* improve documentation for configuration, filters, plans, DVR, and REST APIs
* add and update tests for migrations, filters, deduplication, sorting,
configuration, streaming, and accessibility behavior
* **Performance**
* Improved memory usage and persistence speed for large playlists and electronic programme guides.
* Large EPG datasets now process more reliably while preserving channel priorities and cleaning up temporary data.
* Reduced allocation overhead during parsing and playlist processing.
* **Bug Fixes**
* Prevented programme descriptions from being truncated during XMLTV imports.
* Improved handling of empty or single-source EPG data.
* **Network**
* Optimized response compression by avoiding compression for small or already-compressed media files.
Shared HLS cache session feature and aligns the runtime, cache, provisioning, recovery, custom-response, and documentation paths with the new shared-session model.
* Fix HLS session handling and disable retry for adaptive segment requests
* Resolve / probe vod task uses last modified date
* Resolve expiration date in input form
* fixed m3u parsing
* fixed wasm opt for frontend build
* - Refactored Shared-Stream hot path from Arc<Bytes> to Bytes (leveraging internal reference counting).
- Switched Metadata Trigger deduplication from Arc<Mutex<HashSet<_>>> to Arc<DashSet<_>> to reduce lock contention.
- Eliminated expensive key cloning in the InputMetadataUpdatesCompleted handler.
- Changed active_target_inputs to HashSet<Arc<str>> to avoid per-event to_string() allocations.
- Implemented bounded Cleanup-Queue (switched from unbounded to mpsc::channel(4096)) with a dedicated overflow path (try_send + async flush) to prevent uncontrolled memory growth.
- Optimized by_provider storage by switching from Vec<(addr, alloc_id)> to HashSet<(addr, alloc_id)>, reducing removal complexity from $O(n)$ to $O(1)$ average.
- Optimized ActiveConnectionInfo data layout by reordering fields (large fields first) to minimize padding and improve cache efficiency.
* Improve shared-stream reliability and align docs
- make shared connection registration fallible with rollback on failure
- guard shared broadcaster startup behind successful subscription
- optimize shared stream/provider key maps to Arc<str>
- add Tokio macros feature for runtime and dev dependencies
- harden build_resources.sh with fail-fast ffmpeg error handling
- clarify StreamError display messages with variant context
- sync README stream/custom-response sections with current behavior
* low_priority_preempted stream
* Keep custom TS timestamps monotonic across loops
- advance timestamp offset by stream duration on buffer wrap
- avoid resetting PTS/DTS to zero each cycle
- prevents players from treating looped custom streams as ended/corrupt
* low_priority_preemption custom video stream fix
* inc_version uses now main toml file
* Fixed some coderabbit issues
* Optimized build
* timeout secs for custom video response
* init custom video timeout on mode switch
* terminate immediately when custom video buffer is missing
* add provisioning missing-custom timeout regression test
* add missing-custom termination tests for all custom modes
* fix ts continuity handling for discontinuity and adaptation-only packets
* fix ts loop duration estimation to use min/max timestamps
* harden pes timestamp patching and normalize pid cc sequence
* Resource ffmpeg creation without B-Frames and short GOPs
* Discontinuity patch for transport stream buffer
* grace hold stream is now default true
* streaming fixes
- Add Makefile to simplify installing required tools
- Add CONTRIBUTING.md welcome new contributors
- Add fmt, lint, test tasks to makefile and update CONTRIBUTING.md
- Add CI workflow
- Log with local date
Release process now includes validation to confirm that release notes are present before deployment can proceed; if release notes are missing, the release process will terminate with an error message
Release workflow now requires an interactive confirmation step during the release process; explicit user approval is mandatory before any release actions commence
- Added logic to prepare Docker tags for the master and develop branches, allowing for versioned and latest tags on master, and a dev tag on develop.
- Streamlined the image building process by using the prepared tags in the Docker build command.
- Updated caching strategy in the GitHub Actions workflow to include additional paths and keys for cargo tools, dependencies, and frontend resources.
- Modified the build script to check if resources are already built before executing the build process, improving efficiency.
- Implemented cache handling for frontend builds and cross-compilation tools to optimize build times.
- Adjusted Dockerfile to improve layer caching by copying dependency files first and creating dummy source files for pre-building dependencies.
- Introduced a new stage in the Dockerfile to select binaries based on target architecture.
- Updated the build script to copy architecture-specific binaries for multi-platform support.
- Merged master and develop build jobs into a single `docker-build` job.
- Updated steps for installing Rust and caching cargo registry.
- Introduced a new script `build_docker.sh` for building and pushing Docker images.
- Removed obsolete scripts `build_github_docker_aarch64.sh` and `build_github_docker_beta.sh`.