Files
silo-server/internal/playback/capabilities_v3.go
T
854d07cf8f feat(playback): add protocol v3 planning and recovery (#398)
* docs(playback): plan protocol v3 server implementation

* docs(playback): incorporate protocol v3 review

* feat(playback): implement protocol v3 server

* fix(playback): persist empty route diagnostics

* feat(playback): harden protocol v3 HDR routing

* feat(playback): complete protocol v3 client contract

* fix(playback): harden protocol v3 recovery

* fix(playback): restore dovi_rpu strip filter for DV remuxes

The v3 work renamed the Dolby Vision strip recipe to a dovi_split=mode=bl
bitstream filter that does not exist in stock FFmpeg or jellyfin-ffmpeg;
the probe failed closed on every deployment, disabling the new validated
DV7-to-HDR10 route and regressing the previously working dovi_rpu=strip=1
remux path from main. Restore dovi_rpu across the probe, remux and HLS
copy arguments, and the recipe-card constant.

Also from review: validate the remux DV mode for every profile (garbage
modes on non-P7 sources silently no-opped), reject preserve mode for P7
outright (a base-layer-only remux cannot preserve dual-layer DV), tag
dvhe sample entries only for the explicit v3 preserve recipe so legacy
web/jellycompat remuxes keep their pre-v3 hev1 labeling, and honor the
token-frozen DV mode in the proxy remux path instead of legacy-auto.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(playback): correct v3 planner policy and contract validation

Review fixes to the v3 planner and wire contracts:

- Bar Profile 7 sources from the non-strip progressive remux route: a
  base-layer-only remux can never deliver native dual-layer DV, so the
  planner no longer emits plans claiming validated Dolby Vision while
  the executed remux drops the enhancement layer.
- Accept the device-quirks feature flag from either capability location,
  matching every other dual-location feature check.
- Treat legacy hdr_unknown rows as HDR10 for HDR10-capable clients with
  a degradation warning instead of leaving them unplayable under v3.
- Honor bandwidth_cap_kbps as a hard ceiling in every quality mode and
  wire the previously dead Metered signal into conservative auto rungs.
- Degrade to the validated source-quality route instead of a terminal
  when only an implicit quality reduction demanded an unsupported
  transcode; explicit user-selected rungs keep terminal behavior.
- Bound inner capability lists and strings; compare attempt keys exactly
  instead of case-folded; make ParseTrackIDV3 strict about canonical
  numerics; accept dvdsub/pgssub/dvbsub aliases and stop promising
  burn-in for unknown subtitle codecs; probe every h264 encoder rather
  than requiring libx264; normalize the file-level bitrate fallback.
- Evaluate subtitle renderability against the engine each candidate
  route executes on, not always media3_direct.
- Pin the with-quirks attempt-key preimage arity in the cross-language
  fixture so the Kotlin client stays in lockstep.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(playback): harden v3 control-plane reliability

Review fixes to the v3 session, store, and handler layer:

- Bound concurrent replans with a slot semaphore: each replan pins a
  pooled connection for its advisory lock while issuing further store
  queries from the same pool, so an unbounded recovery storm could turn
  every connection into a lock holder and deadlock the server.
- Make CompleteReplan a real compare-and-swap (base-revision predicate,
  ErrReplanSupersededV3) and map BeginReplan insert races to a replay
  instead of a raw unique violation.
- Fingerprint start requests (request_digest column): an attempt ID
  reused with different input is now a 409-style conflict rather than a
  silent replay, and both replay paths check session liveness so dead
  sessions surface as retryable terminals.
- Pre-delete expired attempt rows on SaveAttempt so a retry during the
  cleanup window cannot wedge on an unreachable conflict.
- Align the in-memory store's semantics with Postgres and add DB-backed
  planstore tests (SILO_TEST_DATABASE_URL), including a regression test
  inserting every route-event name against the real CHECK constraint.
- Session manager: v3 route-set updates own RemuxDVMode outright so a
  replan onto an SDR source clears a stale strip mode; replacement
  reservations survive unrelated legacy stream updates; replacement
  admission excludes the replaced session explicitly instead of
  decrementing totals it may no longer be part of; the admission CAS
  loop is bounded and decider errors are logged.
- Map transient store failures to 500s instead of terminal 404/403s;
  authorize route events via identity-only projections after the rate
  limiter; keep sanitized diagnostics deterministic.
- Merge the server-computed durable plan key into replan exclusions so
  unreproducible client history cannot re-select the failed route.
- Remap tracks only when the effective edition changes (a same-file
  replan no longer switches audio to a lookalike track) and remap
  ID-only subtitle selections on edition fallback.
- Cache the v3/shadow feature flags for five seconds instead of one
  settings SELECT per playback request; stop remote transports
  best-effort when the start call times out; carry dvm/tid claims and
  the transport-scoped job identity through the legacy audio-change
  re-mint; index playback_route_events(received_at) for the retention
  delete; run store maintenance for DB-less deployments too.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(transcode): reap idle node jobs and gate WebVTT conversion

- Add an idle reaper to the transcode node: a job untouched by manifest
  or segment requests for ten minutes is closed and unregistered. After
  a v3 replan retires a transport ID, a stale in-flight stream token
  could resurrect the old job via reconstruct and encode to end-of-file
  for nobody; jobs waiting on readiness count registration as access
  and are never reaped mid-wait, and reaping keeps the recipe so a
  still-valid token reconstructs on the next hit.
- Reject bitmap subtitle tracks (PGS) on the .vtt conversion path with
  415 before headers are written instead of spawning an ffmpeg command
  that always fails mid-response, and make the extract-format override
  fall back to source-driven mapping for bitmap codecs.
- Drain error bodies on non-202 node responses so the HTTP transport
  can reuse connections.
- Pin the transcode-dir cleanup separator-boundary semantics with a
  regression test (a session ID sharing another's prefix must not
  retain foreign directories).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(playback): close v3 planner policy gaps from review

- Clamp the final transcode bitrate to bandwidth_cap_kbps: the ladder has
  no rung below 480p/1500kbps, so lower caps were silently exceeded even
  though the cap is documented as a hard delivery ceiling.
- Treat video-only media as audio-compatible instead of forcing an AAC
  conversion (or an audio_conversion_unsupported terminal) onto a file
  with no audio stream. Tracks whose codec failed to probe keep the gate.
- Only promise a bitmap subtitle sidecar for embedded PGS with an engine
  that renders embedded bitmap: external/downloaded bitmap and embedded
  DVD/DVB published artifact URLs that always failed at fetch. They now
  fall through to burn-in or its terminal.
- Accept client_video_transformations_v1 from either client_features or
  the nested context when validating client-executor transformations,
  matching the planner's dual-source reads.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(playback): probe and execute DV remuxes with one ffmpeg binary

The v3 transformation registry probed the configured playback.ffmpeg_path
while progressive remux execution resolved the process-global discovery
path, so a deployment where only one binary carries dovi_rpu could plan a
server_dv7_to_hdr10 route and then fail it at stream time. Resolution now
goes through a shared ResolveFFmpegPath (configured path first, discovery
fallback — the same rule the transcode pipeline already used), the
dovi_rpu probe is cached per binary path, and the stream handler and proxy
worker pass their configured path into ServeRemuxWithDVMode.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(playback): harden v3 replan identity and control-plane limits

- Seed failure-replan track selections from the durable current plan
  before overlaying the request: after an alternate-version fallback the
  normalized request still carries requested-edition track IDs, so a
  replan omitting unchanged tracks was rejected as a track/file mismatch.
- Remap ID-only audio selections across edition changes (parse the ID to
  an index like the subtitle remap already does) instead of leaving a
  stale file-bound ID to fail validation.
- Release the node planner reservation when a prepared remote transport
  rolls back after the node accepted the job; repeated failed starts
  could otherwise pin max-job/bandwidth budgets for the full reservation
  age.
- Size the replan semaphore below the PostgreSQL pool via a store
  capacity advisor: with max_connections at or below the fixed bound,
  advisory-lock holders could starve the inner store queries they need
  to finish.
- Contain shadow-planner panics with a recover boundary; it runs on a
  bare goroutine where an escaped panic kills the process for what is
  telemetry-only work. Document why the memory store's session lock is
  deliberately a no-op.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix(transcode): serialize node job teardown against reconstructs

- Look up and touch manifest/segment sessions in one critical section so
  the idle reaper cannot unregister a job between the lookup and its
  liveness refresh.
- Re-validate each reap candidate under the per-session lifecycle lock
  before closing it: Close removes the output directory, and without the
  lock it could race a token reconstruct and wipe the segments the fresh
  ffmpeg is writing.
- Take the lifecycle lock in handleStop so a stop racing a RequireReady
  start's readiness wait blocks until registration and tears the job
  down, instead of 404ing and orphaning the ffmpeg until the reaper.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
2026-07-14 11:51:27 -04:00

306 lines
10 KiB
Go

package playback
import (
"strconv"
"strings"
"github.com/Silo-Server/silo-server/internal/models"
)
func SourceDescriptorFromFileV3(file *models.MediaFile, audioIndex int) SourceDescriptorV3 {
if file == nil {
return SourceDescriptorV3{DVEnhancementLayer: EnhancementUnknownV3}
}
source := SourceDescriptorV3{
MediaFileID: file.ID,
Container: normalizeCodecV3(file.Container),
VideoCodec: normalizeCodecV3(file.CodecVideo),
AudioCodec: normalizeCodecV3(file.CodecAudio),
AudioChannels: file.AudioChannels,
BitrateKbps: normalizeBitrateKbpsV3(file.Bitrate),
DVEnhancementLayer: EnhancementNoneV3,
}
if len(file.VideoTracks) > 0 {
track := file.VideoTracks[0]
source.VideoCodec = firstNonEmptyV3(normalizeCodecV3(track.Codec), source.VideoCodec)
source.VideoProfile = strings.ToLower(strings.TrimSpace(track.Profile))
source.VideoLevel = track.Level
source.BitDepth = models.NormalizeVideoBitDepth(track.BitDepth, track.PixelFormat, track.Profile)
source.Width = track.Width
source.Height = track.Height
source.FrameRate = parseFrameRateV3(track.FrameRate)
if track.Bitrate > 0 {
source.BitrateKbps = normalizeBitrateKbpsV3(track.Bitrate)
}
source.DynamicRange = normalizeDynamicRangeV3(track)
source.HDR10Plus = track.HDR10Plus || strings.Contains(strings.ToLower(track.VideoRangeType), "hdr10+")
source.DVProfile = track.DVProfile
source.DVBLCompatID = track.DVBLCompatID
switch EnhancementLayerV3(strings.ToLower(track.DVEnhancementLayer)) {
case EnhancementNoneV3, EnhancementMELV3, EnhancementFELV3, EnhancementUnknownV3:
source.DVEnhancementLayer = EnhancementLayerV3(strings.ToLower(track.DVEnhancementLayer))
case "":
// Legacy rows predate the explicit enhancement-layer fields. A
// Profile 7 DOVIWithEL label proves an EL exists but cannot prove
// MEL versus FEL, so keep it unknown rather than misclassifying it
// as a safe single-layer stream.
legacyProfile7EL := track.DVProfile == 7 && strings.Contains(strings.ToLower(track.VideoRangeType), "withel")
if track.DVELPresent || legacyProfile7EL {
source.DVEnhancementLayer = EnhancementUnknownV3
} else {
source.DVEnhancementLayer = EnhancementNoneV3
}
default:
source.DVEnhancementLayer = EnhancementUnknownV3
}
}
if source.Width == 0 || source.Height == 0 {
source.Width, source.Height = dimensionsFromResolutionV3(file.Resolution)
}
if audioIndex >= 0 && audioIndex < len(file.AudioTracks) {
track := file.AudioTracks[audioIndex]
source.AudioCodec = firstNonEmptyV3(normalizeCodecV3(track.Codec), source.AudioCodec)
source.AudioChannels = track.Channels
source.AudioLayout = normalizeLayoutV3(track.Layout)
}
if source.DynamicRange == "" {
if file.HDR {
source.DynamicRange = "hdr_unknown"
} else {
source.DynamicRange = "sdr"
}
}
return source
}
func detailedVideoEligibleV3(source SourceDescriptorV3, request StartRequestV3) bool {
if !HasFeatureV3(request.ClientFeatures, FeatureDetailedDecodeV3) && !HasFeatureV3(request.ClientPlaybackContext.Features, FeatureDetailedDecodeV3) {
return false
}
if !detailedVideoEvidenceCompleteV3(source) {
return false
}
for _, capability := range request.Capabilities.VideoDecode {
if !strings.EqualFold(capability.Codec, source.VideoCodec) || !capability.Hardware {
continue
}
if len(capability.Profiles) > 0 && !containsFoldV3(capability.Profiles, source.VideoProfile) {
continue
}
if len(capability.Levels) > 0 && !containsAtLeastV3(capability.Levels, source.VideoLevel) {
continue
}
if len(capability.BitDepths) > 0 && !containsIntV3(capability.BitDepths, source.BitDepth) {
continue
}
if capability.MaxWidth > 0 && source.Width > capability.MaxWidth || capability.MaxHeight > 0 && source.Height > capability.MaxHeight || capability.MaxFrameRate > 0 && source.FrameRate > capability.MaxFrameRate || capability.MaxBitrateKbps > 0 && source.BitrateKbps > capability.MaxBitrateKbps {
continue
}
return true
}
return false
}
func detailedVideoEvidenceCompleteV3(source SourceDescriptorV3) bool {
return source.VideoCodec != "" &&
source.VideoProfile != "" &&
source.VideoLevel > 0 &&
source.BitDepth > 0 &&
source.Width > 0 &&
source.Height > 0 &&
source.FrameRate > 0 &&
source.BitrateKbps > 0
}
func outputRangeEligibleV3(source SourceDescriptorV3, request StartRequestV3) (bool, VideoClaimsV3) {
hdr := request.ClientPlaybackContext.Output.HDRDetails
if hdr == nil {
hdr = request.Capabilities.HDRDetails
}
claims := VideoClaimsV3{}
switch source.DynamicRange {
case "", "sdr":
return true, claims
case "hdr10":
claims.HDR10 = hdr != nil && hdr.HDR10
return claims.HDR10, claims
case "hdr_unknown":
// Legacy rows only recorded a file-level HDR flag without per-track
// range metadata. HDR10 is by far the most common static-HDR range, so
// an HDR10-capable output treats the source as HDR10 instead of
// refusing playback outright; the planner attaches a degradation
// warning for these assumed-range plans.
claims.HDR10 = hdr != nil && hdr.HDR10
return claims.HDR10, claims
case "hdr10_plus":
claims.HDR10Plus = hdr != nil && hdr.HDR10Plus
return claims.HDR10Plus, claims
case "hlg":
claims.HLG = hdr != nil && hdr.HLG
return claims.HLG, claims
case "dolby_vision":
if source.DVProfile == 7 && source.DVEnhancementLayer == EnhancementUnknownV3 {
claims.DolbyVisionReason = "profile_7_enhancement_layer_unknown"
return false, claims
}
if hdr != nil && containsIntV3(hdr.DolbyVisionProfiles, source.DVProfile) {
claims.DolbyVision = true
claims.DolbyVisionReason = "native_profile_supported"
return true, claims
}
claims.DolbyVisionReason = "native_profile_not_supported"
return false, claims
default:
return false, claims
}
}
func clientSupportsHDR10V3(request StartRequestV3) bool {
hdr := request.ClientPlaybackContext.Output.HDRDetails
if hdr == nil {
hdr = request.Capabilities.HDRDetails
}
return hdr != nil && hdr.HDR10
}
func audioEligibilityV3(source SourceDescriptorV3, request StartRequestV3) (copyOK, passthrough bool, claim AudioClaimsV3) {
claim.Codec = source.AudioCodec
passthroughCaps := request.ClientPlaybackContext.Output.AudioPassthrough
if passthroughCaps == nil {
passthroughCaps = request.Capabilities.AudioPassthrough
}
if passthroughCaps != nil && containsFoldV3(passthroughCaps.PassthroughCodecs, source.AudioCodec) &&
(HasFeatureV3(request.ClientFeatures, FeatureLayoutPassthrough) || HasFeatureV3(request.ClientPlaybackContext.Features, FeatureLayoutPassthrough)) {
for _, entry := range passthroughCaps.Entries {
if !strings.EqualFold(entry.Codec, source.AudioCodec) || len(entry.ChannelCounts) == 0 || len(entry.Layouts) == 0 ||
!containsIntV3(entry.ChannelCounts, source.AudioChannels) || !containsFoldV3(entry.Layouts, source.AudioLayout) {
continue
}
claim.Passthrough = true
claim.AtmosPreserved = strings.Contains(strings.ToLower(source.AudioLayout), "joc") || strings.Contains(strings.ToLower(source.AudioLayout), "atmos")
claim.Reason = "sink_passthrough_validated"
return true, true, claim
}
}
if containsFoldV3(request.Capabilities.CodecsAudio, source.AudioCodec) {
claim.Reason = "client_decode_supported"
return true, false, claim
}
if passthroughCaps != nil && containsFoldV3(passthroughCaps.PassthroughCodecs, source.AudioCodec) {
claim.Reason = "passthrough_layout_unsupported"
} else {
claim.Reason = "audio_codec_unsupported"
}
return false, false, claim
}
func normalizeDynamicRangeV3(track models.VideoTrack) string {
if track.DVProfile > 0 || strings.Contains(strings.ToLower(track.VideoRangeType), "dovi") || strings.Contains(strings.ToLower(track.DolbyVision), "dolby") {
return "dolby_vision"
}
if track.HDR10Plus || strings.Contains(strings.ToLower(track.VideoRangeType), "hdr10+") {
return "hdr10_plus"
}
joined := strings.ToLower(strings.Join([]string{track.VideoRange, track.VideoRangeType, track.ColorTransfer}, " "))
if strings.Contains(joined, "hlg") || strings.Contains(joined, "arib-std-b67") {
return "hlg"
}
if strings.Contains(joined, "hdr") || strings.Contains(joined, "smpte2084") || strings.Contains(joined, "pq") {
return "hdr10"
}
if joined == " " || strings.TrimSpace(joined) == "" {
return ""
}
return "sdr"
}
func parseFrameRateV3(value string) float64 {
value = strings.TrimSpace(value)
if value == "" {
return 0
}
if parts := strings.Split(value, "/"); len(parts) == 2 {
n, nErr := strconv.ParseFloat(parts[0], 64)
d, dErr := strconv.ParseFloat(parts[1], 64)
if nErr == nil && dErr == nil && d != 0 {
return n / d
}
}
v, _ := strconv.ParseFloat(value, 64)
return v
}
func normalizeBitrateKbpsV3(value int) int {
if value > 10_000_000 {
return value / 1000
}
return value
}
func dimensionsFromResolutionV3(value string) (int, int) {
switch strings.ToLower(strings.TrimSpace(value)) {
case "4320p", "8k":
return 7680, 4320
case "2160p", "4k", "uhd":
return 3840, 2160
case "1080p", "fhd":
return 1920, 1080
case "720p", "hd":
return 1280, 720
case "480p", "sd":
return 854, 480
default:
return 0, 0
}
}
func normalizeCodecV3(value string) string {
v := strings.ToLower(strings.TrimSpace(value))
switch v {
case "h265", "h.265", "x265":
return "hevc"
case "h264", "h.264", "avc", "x264":
return "h264"
case "eac3", "e-ac-3", "ec-3":
return "eac3"
case "truehd", "mlp fba":
return "truehd"
default:
return v
}
}
func normalizeLayoutV3(value string) string { return strings.ToLower(strings.TrimSpace(value)) }
func firstNonEmptyV3(values ...string) string {
for _, v := range values {
if v != "" {
return v
}
}
return ""
}
func containsFoldV3(values []string, wanted string) bool {
for _, v := range values {
if strings.EqualFold(strings.TrimSpace(v), strings.TrimSpace(wanted)) {
return true
}
}
return false
}
func containsIntV3(values []int, wanted int) bool {
for _, v := range values {
if v == wanted {
return true
}
}
return false
}
func containsAtLeastV3(values []int, wanted int) bool {
for _, v := range values {
if v >= wanted {
return true
}
}
return false
}