MPV Manager — audit remediation and native QA

Recorded 2026-09-05. All 22 September findings are addressed in repository code/docs, building on the preserved August remediation. Vitest is pinned to 5.0.0. Native Windows and macOS checks have been performed. v1.3.0 is not release-ready: signing, protected release policy, exact published-artifact qualification and publication remain open.

HTML report · September audit · August/September reconciliation · August finalized baseline · Machine-readable QA evidence

Provenance and local commits

At review start, master still pointed to bdfb31b. The pre-existing August working tree matched T3 checkpoint fa0a678 across 797 existing files; TRACKING.md was the only differing existing file. The August fixes were preserved in 346f272 before new repairs. They were generally sound foundations, with residual integration defects documented in the reconciliation. No pushes, release tags or publication were performed.

CommitChange
346f272Preserve August remediation and restore eight historical Markdown/HTML evidence files.
979152eRun cross-build utilities with the host toolchain; shared CI script validated on six targets.
bf43eebPreserve replay evidence and authenticate updater journals with a private per-user key.
ac52448Record reconciliation and the first implementation checkpoint.
492f968Upgrade Vitest to exact 5.0.0 and document its supported Node engine floor.
ef85630Own worker/process lifetimes; stage before commit; share bounded probes; preserve config and transactional metadata.
81b60f1Complete Windows migration/uninstall, output/lifecycle fixes, cleanup, real browser QA, and Windows journal-sharing repair.
ef97800Isolate native test state, key the Windows path cache by its environment, and resolve actual platform config paths; full native TUI suites pass.

September finding disposition

FindingImplemented resultEvidence
R01Recovery preflights every required backup before removing live paths; replay copies and retains evidence until durable retirement. Streaming copy avoids file-sized buffers.Installer replay tests on Linux, Windows and macOS; missing evidence preserves live targets.
R02Schema-v2 journals are HMAC-authenticated with a private per-user key outside transaction folders; ownership/DACL checks fail closed. Legacy journals and missing original evidence require manual recovery.Native authentication/tampering/missing-key/legacy checks on all three OSes; Windows DACL and Unix permission checks.
R03Shutdown closes admission, cancels staging jobs and joins all workers and leased mutations before returning. Committed jobs drain to a terminal result.Real listener/worker barriers, race suite, browser jobs, native exit-0 checks.
R04Resource generation and manifest utilities build for GOHOSTOS/GOHOSTARCH independently of the release target.Actual shared CI build script on all six target pairs, plus final six application cross-builds.
R05Owned Unix process groups and Windows Job Objects terminate descendants and drain output with bounds. Web/TUI never inherit interactive sudo prompting.Native process-tree cancellation/retained-pipe/output-limit tests on Linux, Windows and macOS.
R06Installer, Web and shared update checks use one packagequery implementation with a bounded context, LC_ALL=C, explicit method mapping and separate capped stdout/stderr.Native locale, stderr absence, timeout and overflow fixtures on Windows/macOS; parser and race tests.
R07Portable downloads and UI preparation precede the commit guard; cancellation and commit arbitrate once. TUI retains navigation intent until committed work finishes.Staging cancellation and committed-worker tests; native TUI lifecycle tests.
R08MPC-QT uninstall waits for elevated completion, returns child errors, verifies the selected executable is gone and refuses ambiguous legacy locations.Real Windows elevated disposable uninstaller: wait, success and exit 7; failure/still-present/selection tests.
R09Tracked legacy installs or explicit adoption claim only validated MPV launchers. Verified updates commit an ownership manifest and retain unclaimed collision originals in preserved folders.Native Windows migration/update/uninstall preservation and injected rollback failure; untracked populated roots remain refused.
R10UI preparation takes no live config snapshot. Commit re-reads current user files under shared editor locks after staging.Concurrent-edit-during-staging test and complete-config preservation on Windows/macOS.
R11UI journal includes baseline paths and before/after version metadata; rollback and recovery restore both without overwriting newer unrelated metadata.Native crash replay and forced commit failure restore UI versions and baselines.
R12Shared mpv.conf document model respects named profiles, [default], effective duplicates, flags, quotes, comments, BOM and CRLF.Parser/editor fixtures, config tests and Web round trips.
R13Only alang/slang are list-valued; scalar commas survive reads, API submissions and writes.Screenshot path/template comma round trip with profile content retained.
R14Remove duplicate x-init calls; destroy clears timers/listeners and aborts requests. Modal cleanup uses its DOM root as the stable Alpine owner identity.Real Alpine mount/removal/remount on Linux, Windows and macOS.
R15Bound partial lines, job retained bytes/lines and browser tails; batch modal rendering. Handoff output uses the same cap.Large unterminated output tests; 5,000-line real-browser job; retained DOM and tail limits on all native browser runs.
R16All reconciliation routes share the manager-config lease; bounded collectors join probes; removals compare the exact observed app record before mutation.HTTP lease conflict, cancellation/join and changed-record preservation tests.
R17Config rendering/API read one parsed snapshot for all settings.Shared parser and settings API tests; reduced repeated reads by construction.
R18Remove the 24 production symbols and one test helper identified across all three reachability analyses, including the legacy probe wrapper removed during consolidation.Pinned deadcode@v0.45.0 final intersection is empty; target-specific unreachable symbols are retained where another OS uses them.
R19Remove unused ArchiveExtractor/OutputWriter seams, their mock implementations and six mock-bookkeeping tests. Keep meaningful DI tests and package-scope interface assertions.Full Go/race/lint checks; production behavior coverage retained.
R20Shortcut delegation now checks the selected platform implementation once and delegates once; Windows-only policy remains explicit.Existing shortcut/platform tests and six cross-builds.
R21Restore the four maintained historical report pairs byte-for-byte from the August checkpoint.Restored files committed with the baseline; reconciliation links resolve.
R22Replace extensive root agent history with durable commands, code boundaries, mutation rules, native gates and documentation links; retain the Atlas-generated block.Documentation contracts and link checks; task state remains in Atlas.

Additional native QA findings

QA-01: Windows helper polling intermittently blocked journal replacement with Access denied. Journal reads now permit delete sharing, and native write-through replacement retries only sharing/lock/access conflicts for at most one second while retaining both paths. A held-reader test exercises the real filesystem behavior. Three consecutive Windows qualifier runs passed all seven cases after the fix. Windows sharing semantics.

QA-02: Existing TUI fixtures assumed Linux config paths and isolated HOME/XDG without isolating Windows APPDATA/USERPROFILE. Native runs exposed false failures and state leaking between tests. Fixtures now reload isolated native state and use the production config resolver. The Windows directory cache is keyed by APPDATA/home rather than remaining bound to the first environment for the entire process; its preference stays stable while that environment is unchanged. The tests remain behavior assertions; expected results were not relaxed to match leaked data.

Native tests also corrected two fixture assumptions: macOS /var aliases must be canonicalized when calling an internal recovery function whose production caller already canonicalizes; file-mode preservation compares native modes rather than assuming Windows implements Unix 0600 bits. Windows now exercises the symlink-based UI commit-failure fixture when symlink creation is available.

Validation matrix

CheckResult and scope
Go backend/TUIFull go test -race ./... passes; make lint passes (vet + pinned Staticcheck 0.8.1 SA*). Module tidy diff, integrity verification and gofmt are clean.
FrontendClean npm ci; Vitest 5: 22 files / 182 assertions; vendor bytes and Tailwind freshness; npm audit: zero vulnerabilities. Playwright 1.63.0 is a development-only exact dependency.
Go security scangovulncheck@v1.7.0 built with the repository Go 1.27 toolchain: no vulnerabilities found. An older globally installed scanner was incompatible and is not counted as validation.
Browser integrationThree Playwright scenarios pass on Linux, Windows 11 amd64 and macOS 26.6.2 Apple Silicon: Alpine lifecycle; real workers/SSE/cancel/failure/reconnect/history/output; 11 routes at 390 and 1280 pixels.
Application binariesNative Linux amd64, Windows amd64 and macOS arm64: version/help, real platform detection, 22 route/viewport checks, unauthenticated API 401, authenticated shutdown 200, process exit 0, no page script errors.
Updater qualifierAll seven synthetic 1.3.0→1.3.1 cases pass on Linux amd64, Windows 11 amd64 and macOS arm64: hash rejection, length rejection, two-target commit, forced rollback, lock refusal, healthy relaunch, relaunch-health rollback. Windows passed three consecutive final trials.
Native recovery/installFocused installer replay, UI preservation/version/baseline rollback and ownership tests pass on Windows/macOS. Windows elevated MPC-QT fixtures pass without touching real applications.
Native TUIFull pkg/tui native test binaries pass on Windows amd64 and macOS arm64 in disposable configs, including hotkeys, UI editors/migrations, job history, cancellation and selected-app identity.
Cross-buildsFinal application builds pass for Linux, Windows and Darwin × amd64/arm64; SHA-256 fingerprints are in results.json. These are local QA builds, not signed release artifacts.
CI configurationYAML parses and the frontend job receives a test-only Go fixture artifact from test:linux, then runs Chromium integration. Live GitLab execution remains unperformed because no changes were pushed.

Release gates that remain open

The repository fixes and native QA above do not close the original August external signing/provenance gates. A read-only GitLab recheck on 2026-09-05 found no protected tags, no project CI variables and one project runner. The protected-environments endpoint returned HTTP 404; it does not demonstrate an available protected native-evidence approval gate.

Atlas completion is limited to verified repository work: all September remediation groups, Vitest 5, browser E2E, the Windows journal fix and the native config/TUI isolation fix. The three external release tasks remain open. v1.4 Wails/htmx work and unrelated future feature requests remain outside v1.3 remediation.

Reproduction and evidence

Use Testing, Windows ownership guidance, and CI. Browser source is in tests/browser; synthetic updater qualification is cmd/qualify-selfupdate behind selfupdate_qualification. Tests use disposable home/config/install trees. The evidence JSON records artifact hashes, native test names, qualifier case results, application/platform output and local log hashes.

QA artifacts have git_commit=working-tree-qa and are not a protected tag-bound evidence record. They validate this implementation but must be regenerated and bound to the selected release commit/artifacts by the external release gate.