# MPV Manager codebase audit October 3 2026

This audit reviews bugs, security boundaries, dead and duplicated code, and
performance opportunities in MPV Manager at
`b09e4d8d6d583c6711e92ada119536c5b09e1e6e` on `master` (v1.3.1).
The main concerns are destructive installer recovery that trusts planted journals,
startup shortcut creation that bypasses safe manager replacement, and several
configuration and recovery paths that lose user state or cannot replay safely.

There are **17 findings: two P1, thirteen P2, and two P3**. Sixteen have a
demonstrated defect or a direct production call-path explanation; F15 is a
reproduced but qualified finalization-policy finding. Additional cleanup,
performance and coverage candidates are separated below. **All findings remain
open.** This task changed audit documentation/evidence and Atlas status, without
fixing product code, committing, pushing or publishing.

The normal/race Go suites, lint, 183 frontend unit tests, 21 existing Chromium
integration tests, asset freshness and six application cross-builds passed.
Govulncheck found no advisories for the six target configurations. npm audit
returned one underlying high-severity advisory in the development dependency
chain, represented as four affected dependency nodes. Green existing suites do
not cover the new failures reproduced here.

[Validation and runnable reproductions](qa/2026-10-03/audit/README.md) ·
[Scope and tool versions](qa/2026-10-03/audit/scope.json) ·
[Previous September audit](CODEBASE_AUDIT_2026-09-05.md) ·
[September reconciliation](REVIEW_RECONCILIATION_2026-09-05.md) ·
[September 8 review](CODEBASE_REVIEW_2026-09-08.md) ·
[September 8 remediation](REVIEW_REMEDIATION_2026-09-08.md)

## Scope and evidence

The repository contains 188 production Go files (48,963 lines), 186 Go test files,
and 29 first-party JavaScript/MJS implementation files (9,196 lines), plus Go
templates, embedded assets and build/release configuration. These are inventory
counts, not a claim that every line received equal review depth. Review traced
the supported Web, TUI and CLI entry points through mutation, persistence and
recovery, inspected failure tests and previous remediation, and checked the
following areas.

| Area | Review focus and result |
| --- | --- |
| Installers, archives and discovery | Staging/commit ordering, ownership, recovery journals, temporary paths, Windows/macOS/Linux dispatch, subprocess bounds and package parsers; F01–F04, F12, F17. |
| Updater and release trust | Signature/schema checks, authenticated selections, replay policy, artifact identity, helper handoff, rollback, terminal outcomes and provenance/publisher tooling; F05 and qualified F15. |
| Persistent settings and editors | Manager-config publication, profiles/comments, UI migration recovery, hotkeys, script options, backups and history; F06–F10. |
| Web and frontend | Auth/Host/Origin/CSP, leases/shutdown, jobs/SSE, cancellation, modal state, htmx/Alpine lifecycle and configuration forms; F11, F16 and separate performance candidates. |
| TUI and CLI | Operation ownership, signals/framework exits, terminal output, selected-app state, update cancellation and shared editor use; shared defects above, no new abandonment finding. |
| Platform and supporting packages | CPU/GPU selection/probes, constants/paths, locales, keyring, logging, process/file coordination; F13 and targeted optimization candidates. |
| Tooling and dependencies | Make/CI, generator/checksum/publisher/key tooling, locked npm inputs, embedded inventory, vulnerability and cross-target reachability analysis; F14 and cleanup candidates. |

**Evidence labels:** “Reproduced” means an isolated probe exercised the current
implementation and observed the stated behavior. “Source trace” means the
reachable branch establishes the issue, but the affected native operation was
not executed. JavaScript VM probes use shipped implementation code with DOM and
EventSource adapters; they are explicitly not framework/browser/SSE acceptance
tests. P1 denotes urgent security or unsafe destructive replacement; P2 denotes
material correctness, preservation or validation-gate defects; P3 denotes lower
impact behavior or performance work.

The working tree already contained documentation/QA changes. They were preserved.
Source references below use the reviewed checkout's line numbers. Baseline
commands ran on Linux amd64 with Go `1.27.1-X:nodwarf5`, Node `26.10.0` and npm
`12.2.0`. No new native Windows/macOS destructive QA, actual power-loss test,
second-account attack, signing-service review or production deployment occurred.
The accepted Windows arm64 beta and waived Intel Mac execution coverage remain
coverage gaps; cross-compilation does not convert them into native passes.

## Finding inventory

| ID | Priority | Finding | Evidence |
| --- | --- | --- | --- |
| F01 | P1 | Planted installer journals can delete unrelated sibling paths during recovery. | Public recovery API and real temporary filesystem; cross-user abuse conditional. |
| F02 | P1 | Enabled Web shortcut startup directly overwrites an installed manager. | Linux reproduction; Windows source trace. |
| F03 | P2 | FFmpeg cleanup deletes pre-existing scratch-directory contents. | Real cleanup on controlled download/parser failure. |
| F04 | P2 | Flatpak prerequisite discovery ignores operation cancellation and bounds. | 50 ms deadline blocked by a one-second probe. |
| F05 | P2 | Interrupted updater rollback rejects a successfully restored target on replay. | Authenticated transaction/restore/recovery fixture. |
| F06 | P2 | ModernZ migration recovery erases unrelated later edits. | Real journal and on-disk editor/recovery fixture. |
| F07 | P2 | Editing one hotkey corrupts quoted arguments in untouched bindings. | Public on-disk hotkey edit. |
| F08 | P2 | Restore and hotkey writes widen private config and backup permissions. | Linux 0600→0644 reproductions. |
| F09 | P2 | Unrelated Config saves overwrite custom dropdown values. | Shipped template, Chromium DOM and real HTTP handler. |
| F10 | P2 | Clearing Config text fields reports success while keeping old values. | Real HTTP handler and unchanged file. |
| F11 | P2 | A terminal event during the details GET leaves the job dialog Running. | Shipped JavaScript VM reproduction. |
| F12 | P2 | Standalone Windows arm64 FFmpeg update selects and requires x64. | Asset-selection and PE-validation source trace. |
| F13 | P2 | AVX2 alone selects binaries compiled for the full x86-64-v3 baseline. | CPU feature-mask reproduction and install/update trace. |
| F14 | P2 | Development dependency advisory fails the current npm security gate. | Live npm audit and primary advisory. |
| F15 | P2 qualified | A finalized helper journal can block updates after manual replacement. | Successful helper followed by valid original-manager replacement. |
| F16 | P3 | Slow adoption never refreshes the managed app card on completion. | Shipped JavaScript probe and lease/timer trace. |
| F17 | P3 | Compressed-tar preflight delays cancellation and size rejection. | Canceled 256 MiB fixture and parser/control-flow trace. |

## Security and destructive operation findings

### F01 Installer recovery trusts a journal for an unrelated sibling

Locations: [journal scanning](../pkg/installer/transaction_journal.go#L255),
[journal validation](../pkg/installer/transaction_journal.go#L360),
[startup recovery](../cmd/mpv-manager/main.go#L235).

Recovery reduces its requested destinations to parent directories, then scans
every matching journal in those parents. It checks regular-file type, filename
shape and lexical containment, but does not authenticate the journal, inspect
its owner/permissions, or require `Destination` to be one of the requested
installation identities. A schema-1 `file-swap` journal with `HadOriginal=false`
can direct rollback's `RemoveAll` at any sibling.

The public API probe requested recovery of `configured-install`; a planted
journal instead deleted `unrelated-private-documents/keep.txt`, and recovery
returned nil. This proves unauthorized destination selection and destructive
replay. Cross-user exploitation requires an attacker able to create the journal
and backup directory in a scanned shared parent, while the manager can delete
the victim path. A custom installation directly under a shared/sticky temporary
parent is one example; private default home/config parents ordinarily prevent
planting. A second OS account was not used in the probe. The parent lock does
not authenticate journal content.

Bind replay to inventoried destinations and verify journal/backup ownership and
ancestry. Authenticate destructive intent when shared parents are supported, or
refuse automatic replay there. Keep ambiguous evidence for manual recovery.
Regression tests should reject forged same-target and unrelated-sibling intent
without changing victim bytes, including owner, permission and symlink cases.
Retain the existing legitimate interrupted-transaction tests.

### F02 Web shortcut startup bypasses manager replacement safeguards

Locations: [Web startup](../cmd/mpv-manager/main.go#L399),
[Linux shortcut copy](../pkg/installer/linux.go#L614),
[Windows shortcut copy](../pkg/installer/windows_shortcuts.go#L304).

When `CreateManagerShortcut` is enabled, Web startup calls shortcut creation
synchronously. Linux copies the running executable to the installed manager
when the paths differ; Windows copies when executable bytes differ. Both use
`os.WriteFile` directly on the destination, without version ordering, the updater
lock, staged replacement, journal or rollback. The option defaults disabled,
but enabling it is supported behavior. The Linux probe replaced an installed
sentinel with the running test executable through this exact shortcut function.

Launching an older downloaded copy can therefore replace a newer idle installed
manager. Interruption or a write failure after truncation can damage that copy;
these failure outcomes follow from the write path and were not power-loss tested.
Windows behavior is source-confirmed, not newly run natively. Existing macOS
bundles return early, so this finding does not assert the same macOS overwrite.

Remove implicit replacement during startup, or route an explicitly requested
manager installation through coordinated durable replacement. Test enabled Web
startup preserving an existing newer manager, failed copies retaining old bytes,
and exclusion with a simultaneous updater. September R2-09 removed the TUI
overwrite path; the Web path makes the broader retirement claim incomplete.

### F03 FFmpeg update deletes scratch paths it never owned

Locations: [fixed download path](../pkg/installer/installer.go#L561),
[fixed extraction directory and cleanup](../pkg/installer/installer.go#L577).

Standalone FFmpeg update downloads to `ffmpeg-update.7z` and extracts into
`ffmpeg-temp` inside the installation, then unconditionally removes both. It
does not reserve either name or prove ownership. The probe placed an unrelated
document in the existing extraction directory, supplied hash-matching controlled
bytes that fail 7z parsing, and observed the document deleted despite the update
failing before live replacement. A valid archive reaches the same cleanup.

Use a unique private staging directory and delete only that owned directory.
Keep the existing durable replacement of the live executable. Test both existing
name collisions through success, parse/hash failure and cancellation, plus two
concurrent preparations. The collision requires these particular names; this
is not deletion of every unrelated installation file.

### F04 The live Flatpak prerequisite remains unbounded

Locations: [quiet executor](../pkg/installer/linux.go#L67),
[remote discovery](../pkg/installer/linux.go#L189),
[Flatpak install](../pkg/installer/linux.go#L232).

`InstallFlatpakWithOutput` reaches `CheckFlathubEnabled` after beginning commit.
Its `runQuietOutput` fallback is plain `exec.Command(...).Output()`, independent
of the operation context, with no timeout, output budget or owned process-tree
cleanup. The otherwise bounded shared package-query runner does not cover it.
A harmless `flatpak remote-list` fixture slept one second; a 50 ms operation
deadline was observed only after the entire one-second probe returned. Subsequent
installation was canceled, so the reproduced failure is delayed cancellation.

A genuinely hung probe can indefinitely hold a committed worker/lease and block
shutdown draining; output can also accumulate without a bound. Use the shared
bounded process runner with the caller context and a short prerequisite budget,
and move read-only discovery before commit where possible. Test stalled/noisy
discovery, cancellation and descendants without weakening ownership of committed
mutations. Shortcut icon-cache `runQuiet` is another similar fallback to review.

## Recovery and configuration findings

### F05 Updater rollback consumes its backup before durable replay state

Locations: [missing-backup handling](../pkg/version/transaction.go#L751),
[restore and applied-state update](../pkg/version/transaction.go#L792),
[Unix replacement](../pkg/version/update_replace_unix.go#L38),
[Windows replacement](../pkg/version/update_replace_windows.go#L52).

Both native restore implementations move the backup over the live target.
If execution stops after restoration but before publishing restored state in the
journal, the backup is gone while durable `Applied=true` remains. Next recovery
rejects the missing backup without checking whether the protected live target
already matches its authenticated original evidence.

The Linux fixture applied a normal authenticated update, used the production
restore function, and simulated this interruption. Original live bytes were
correct, but recovery reported `required primary backup unavailable`, retained a
failed journal, and left future preparation blocked. This is a replay defect,
not execution of untrusted backup bytes. Windows has the same move-based source
ordering but still needs native interruption testing.

Retain backup evidence until restoration is durably recorded, or recognize an
already-restored target only after verifying its original authenticated
size/hash/identity and ownership. Test interruption after each restore in one-
and two-target transactions, followed by successful repeated recovery and a new
update. Missing or mismatched original evidence must continue to fail closed.

### F06 ModernZ migration recovery overwrites later user edits

Locations: [whole-file restore](../pkg/uiconfig/migration_transaction.go#L125),
[recovery decision](../pkg/uiconfig/migration_transaction.go#L160).

An uncommitted migration journal retains original file content but no expected
applied revision. Startup recovery replaces the whole file with that snapshot.
The recovery lock serializes its write; it cannot establish that no edits
occurred while the manager was stopped.

The probe captured `vidscale=auto` and `scalewindowed=1.5`, persisted the migration
to `vidscale=no`, then saved a later unrelated `scalewindowed=2.5`. Recovery
returned success and silently restored `1.5`. If the original file was absent,
the corresponding branch removes a later-created file instead. Web, TUI and
startup all reach this shared recovery path.

Record and compare the applied revision before whole-file rollback, or revert
only an owned `vidscale` change while preserving other options. On ambiguous
content, retain the journal and return a conflict. Test interrupted migrations
followed by unrelated edits, edits to the migrated key, later creation/deletion
and repeated recovery.

### F07 An unrelated hotkey edit changes quoted command arguments

Locations: [binding parser](../pkg/hotkeys/inputconf.go#L131),
[whole-file serialization](../pkg/hotkeys/inputconf.go#L185),
[Web edit](../pkg/web/api_hotkeys.go#L229),
[TUI edit](../pkg/tui/hotkey_bindings.go#L100).

`strings.Fields` followed by `strings.Join` normalizes whitespace inside quoted
arguments. Every binding is regenerated even though `RawLine` is retained.
Editing `y` through the public API changed untouched
`x loadfile "/tmp/two  spaces.mkv"` to a different, single-space filename and
returned success. Deleting another binding uses the same serializer. Comments,
line endings and indentation also lose fidelity, but the main defect is changed
command meaning.

Parse only the key separator, keep command text verbatim, and serialize untouched
lines from their original representation. Test unrelated edits/deletes with
quoted whitespace, hashes/escapes, tabs, comments and CRLF, checking untouched
lines byte-for-byte.

### F08 Restore and hotkey writes widen private file permissions

Locations: [backup restore](../pkg/installer/common.go#L196),
[restore rollback](../pkg/installer/common.go#L218),
[recommended config publication](../pkg/installer/installer.go#L1101),
[hotkey writes and backups](../pkg/hotkeys/inputconf.go#L432).

These paths use fixed `0644` permissions instead of preserving existing metadata.
Two independent Linux probes observed an existing `0600` mpv.conf become `0644`
after restore, and an existing `0600` input.conf plus its new backup become `0644`
after a binding edit. The fixed-mode replacements can also change Unix
owner/group; that consequence is source-derived, not cross-owner tested.

Configs and commands may contain private paths or authenticated URLs. Immediate
disclosure depends on ancestor traversal permissions; a `0700` parent reduces
exposure but does not preserve the file's intended permissions. Use existing
`AtomicWritePreserve` for live files, carry original metadata through rollback,
and create backups using inspected source metadata. Define explicit behavior for
missing targets and refuse ambiguous/symlink targets. Cover edit/delete/preset,
restore/reset, failure rollback, modes and native ownership/ACL behavior.

### F09 Config dropdowns silently replace custom settings

Locations: [video output dropdown](../internal/webassets/templates/config.html#L58),
[profile dropdown](../internal/webassets/templates/config.html#L69),
[scale dropdown](../internal/webassets/templates/config.html#L81),
[form collection](../internal/webassets/static/config-page.js#L33),
[apply handler](../pkg/web/api_config.go#L173).

The dropdowns do not represent current values absent from their fixed options.
The browser then chooses the first option, and Apply submits every control.
Changing only Screenshot Directory can change `profile=cinema`,
`scale=ewa_lanczos` and `vo=libmpv` to `high-quality`, `ewa_lanczossharp` and
`gpu-next`. The named profile block remains; its activation is lost.

The actual rendered Go fragment was parsed in a detached Chromium document,
which produced those defaults. The real handler persisted them with HTTP 200.
This combines real template/DOM/handler evidence, but is not a complete browser
form-submission test. It is distinct from the previously repaired profile-aware
mpv.conf parser.

Render an existing custom value as selected and submit only changed fields.
Preserving an unchanged value should not require inventing an allowlisted
replacement. Add a full browser regression that changes one unrelated input
while retaining a custom profile, scale and video output, then reloads the file.

### F10 Clearing text settings reports success without clearing them

Locations: [empty-field omission](../pkg/web/api_config.go#L203),
[saved frontend state](../internal/webassets/static/config-page.js#L94),
[advertised empty directory behavior](../internal/webassets/templates/config.html#L144).

Plain string request fields conflate omitted and explicitly empty values.
`configUpdatesForApply` skips all empty candidates. The probe posted empty
screenshot directory, template and AVIF options over existing nonempty values;
the actual handler returned HTTP 200 success and left all lines unchanged.
The frontend nevertheless records the blank form as saved. The page's advertised
empty-directory default cannot be restored this way.

Represent omission separately from clearing and implement the correct
empty/reset semantics atomically. Return effective saved values. Test omitted
versus explicit-empty fields and a real input-clear/apply/reload sequence with
comments and profiles retained.

### F11 Job details can miss the terminal event

Locations: [details GET and modal opening](../internal/webassets/static/jobs.js#L700),
[modal subscription](../internal/webassets/static/jobs-modal.js#L53).

Details fetches a running job before registering modal callbacks. If the terminal
event arrives while that response is in flight, the manager sees completion/error
but the modal misses it. Opening with the delayed running snapshot never
reconciles the newer state, leaving Running/Cancel visible and hiding an error
until the user closes and reopens it.

The shipped JavaScript probe held the response, delivered an error status, then
released the stale response: manager state was `error`, modal state was
`running`, and modal error was empty. DOM/EventSource were adapters, so the
new ordering still needs a real browser regression.

Observe the selected job before requesting details and merge newer events after
the response, with request generations so older details cannot replace a later
selection. Test held details responses around real completion/failure/cancellation
events and two reordered job selections.

## Architecture and dependency findings

### F12 Standalone arm64 FFmpeg update selects x64

Locations: [CPU switch](../pkg/installer/installer.go#L538),
[PE machine validation](../pkg/installer/installer.go#L641),
[live component dispatch](../pkg/installer/common_handler.go#L84).

The standalone route has no `arm64` selection branch and falls back to
`FFmpeg.X8664`. Its validator accepts only `IMAGE_FILE_MACHINE_AMD64`.
Initial Windows MPV staging correctly selects the Aarch64 artifact, so a later
standalone update changes a native component to x64, while a correct ARM64
replacement would be rejected. This is a direct source finding; no new native
ARM execution is claimed. Windows x64 emulation may allow execution but does
not make the native architecture selection correct.

Reuse the architecture selector and validate the selected artifact's expected
PE machine. Cover amd64 baseline/v3 and arm64 assets plus wrong-machine rejection
before replacement. The owner's ARM beta coverage waiver remains separate.

### F13 AVX2 does not establish the full v3 binary baseline

Locations: [full Windows level detection](../pkg/platform/cpu_windows.go#L87),
[v3 predicate](../pkg/platform/cpu.go#L197),
[install selection](../pkg/installer/windows.go#L313),
[update selection](../pkg/installer/windows.go#L403).

Windows detection computes the complete `cpuid.X64Level`, but selection ignores
it and uses `SupportsAVX2` alone. The probe masked FMA from an AVX2-capable feature
snapshot: cpuid reported level 2 while MPV Manager still selected v3. Other v3
features are also required by the pinned cpuid implementation.
The reviewed provenance identifies v3 assets; the
[upstream build configuration](https://raw.githubusercontent.com/zhongfly/mpv-winbuild/main/build.sh)
explicitly selects the `x86-64-v3` compiler baseline, corroborating that this is
not an AVX2-only asset contract.

A VM or restricted feature exposure can therefore receive an incompatible
player build. Selection was reproduced; no illegal-instruction crash or playback
failure was executed. Select from the full verified level, accepting level 3
or 4, and fail conservatively when uncertain. Test AVX2 with each other required
feature masked, valid v3/v4, baseline x64 and ARM. Linux's simplified level
labeling should be checked against the same full baseline before future use for
artifact selection.

### F14 The current npm audit gate fails on a development dependency

Locations: [locked dependency chain](../package-lock.json),
[frontend dependency declarations](../package.json#L20),
[CI security gate](../.gitlab-ci.yml#L216).

`npm audit --package-lock-only --json` returned one underlying `braces` stack
exhaustion advisory through
`@tailwindcss/cli → @parcel/watcher → micromatch → braces`. npm represents it as
four high-severity affected nodes. The
[GitHub reviewed advisory](https://github.com/advisories/GHSA-vfj7-8cjw-p6xm)
was published September 18 and updated October 2, 2026; it covers versions through
3.0.3 and currently lists no patched braces version.

This chain is development/build tooling; no invocation through shipped HTTP
inputs was established. The practical verified consequence is that the
repository's current high/critical npm gate returns failure, so the earlier
zero-advisory record no longer describes current validation. npm's suggested
Tailwind downgrade is an automated resolution proposal, not a verified project
fix.

Choose a compatible dependency path or narrowly reviewed mitigation, regenerate
the lockfile with controlled inputs, and rerun frontend/browser/CSS/vendor and
security gates. Do not apply a forced dependency rewrite based only on npm's
suggestion. Preserve the [complete audit response](qa/2026-10-03/audit/npm-audit.txt)
when assessing the actual development-tool exposure.

## Qualified recovery and lower priority findings

### F15 Finalized updater journals retain obsolete rollback authority

Locations: [successful helper cleanup](../pkg/version/transaction.go#L672),
[committed recovery](../pkg/version/transaction.go#L1236).

After a successful helper, backups/payload are removed but a committed journal
remains for later startup cleanup. The probe then manually restored a valid
original manager at the same path before that startup. Recovery compared it to
the completed update's expected bytes, attempted rollback using deliberately
deleted backups, changed the journal to failed and blocked later updates.

The behavior is reproduced. Treating legitimate manual portable replacement as
supported is the policy qualification; rejecting genuinely corrupted or
unfinished transactions remains appropriate. This is not an authentication
bypass. The existing committed-target test retains a backup and exercises a
different lifecycle state.

Define finalization separately from executable commit: durably preserve the
terminal outcome, retire obsolete rollback authority, and defer only necessary
helper-file cleanup. Outcome-write failure must retain adequate durable
evidence. Test manual valid replacement after successful finalization, genuinely
incomplete/corrupted transactions, outcome failure and Windows helper cleanup.

### F16 Slow adoption misses the terminal card refresh

Locations: [one-shot adoption timer](../internal/webassets/static/ui-select.js#L457),
[terminal refresh whitelist](../internal/webassets/static/jobs.js#L462),
[adoption job type](../pkg/web/api_adopt.go#L337).

Adoption attempts a refresh after 1.5 seconds. A still-running adoption owns the
manager-config lease, so that refresh conflicts. The terminal refresh whitelist
omits `adopt`; successful slow adoption then leaves a Detected card until manual
refresh/navigation. A shipped-code probe produced zero refresh calls for adopt
completion and one for the install control; the lease and timer trace supplies
the slow-operation condition. No native adoption was executed.

Refresh from actual adoption completion and retry transient lease conflicts.
Add a browser test holding adoption beyond the timer, then verifying the card
becomes Managed without navigation.

### F17 Tar preflight performs decompression before cancellation and limits

Locations: [private-stage preflight](../pkg/installer/installer_archive.go#L233),
[tar inventory collection](../pkg/installer/installer_archive.go#L326),
[late inventory validation](../pkg/installer/installer_archive.go#L345).

Tar preflight has no context and validates aggregate limits after scanning all
headers. `tar.Next` skips unread entry bodies, decompressing them on the way.
An oversized header therefore does not stop body traversal immediately, and
actual extraction decompresses the stream again. A canceled 256 MiB zero-filled
gzip fixture finished preflight before observing cancellation, roughly 28 ms on
this host; a canceled malformed gzip returned a parser error first. This proves
ordering, not a measured large-archive outage. Normal remote payloads are
hash-verified first, limiting an unauthenticated attacker scenario.

Check cancellation before opening parsers, carry it through readers, and enforce
entry/aggregate budgets immediately after header inspection. Test canceled work
and a large declared size without decompressing its body. Benchmark real
gzip/xz archives before considering one-pass private staging; retain full
inventory/containment validation. Artifact hashing also lacks cancellation and
is a related optimization candidate.

## Dead code and duplicated implementations

Pinned `deadcode@v0.46.0` found 99 Linux, 97 Windows and 101 macOS functions
unreachable from the application root, with **71 common functions across six
targets**. Staticcheck U1000 was clean. These results answer different questions:
exported APIs and test seams can be production-unreachable without being
deletable. `ParsePrivateKey`, for example, appears in the application-root
inventory but is reachable from generator tooling. The separate all-command
Linux analysis catches that distinction. The
[common inventory](qa/2026-10-03/audit/deadcode-common.json) is a review aid,
not a deletion list.

| Candidate | Evidence and focused direction |
| --- | --- |
| Old frontend job seeding | `jobs.js:73` defines `seedActiveJobs` with no repository caller; SSE snapshot reconciliation now owns seeding. Remove after checking embedding compatibility. |
| Whole-file config export | `config/editor.go:155` exposes `WriteConfig`, used only by tests in this repository; unordered map serialization discards profiles/comments. Review deprecation/removal rather than allowing new callers to bypass the active document editor. |
| Convenience and compatibility exports | Config getters/setters, keyring context-free wrappers, job status helpers and platform elevation helpers appear in the common inventory. Keep intentionally supported APIs or meaningful fault-injection seams; retire only exports whose compatibility obligation is resolved. |
| Runtime test assets | `internal/webassets/assets.go:8` embeds the complete static tree, including 22 frontend test files totaling 101,187 source bytes. Move them outside the runtime inventory. This is bundle hygiene, not a demonstrated security leak. |
| Parallel download implementations | Installer progress/channel downloads and `HTTPDownloader` repeat transfer/limit/cleanup policy; updater progress/no-progress branches repeat completion handling. Share the low-level behavior inside existing boundaries while keeping real production failure tests. |
| Package discovery/parser duplication | `installer/detection.go` and `internal/packagequery` repeat APT/DNF/Pacman/RPM/Flatpak parsing; Pacman epoch handling already differs. Reuse shared parsers while preserving Found/Unknown/NotFound and exact installation identity. |
| Legacy package operations | Non-streaming `linux_package.go:19`–`:204` duplicates the WithOutput routes and retains different Celluloid PPA policy. Review live dispatch/API obligations before removing or consolidating. |
| Backup policies | Hotkeys and script-options duplicate pruning, while their permission/symlink behavior diverges. Consolidation should first enforce the preservation policy in F08. |
| UI capability tables | Web adoption, TUI selection/HWA and frontend selection maintain overlapping method-ID lists. Put shared capability policy in the existing constants/installer boundary; avoid new forwarding-only abstractions. |
| Generator atomic writes | `cmd/generate-info/main.go:165` implements a separate fixed-name temporary write despite existing `internal/fileops`. Align temporary-name, concurrent-writer and durability behavior if this tool is consolidated. No concurrent publication failure was reproduced here. |

## Performance opportunities

These are source-supported opportunities unless a measurement is stated. They
are not promises of a particular speedup, and should follow the preservation and
security fixes.

| Opportunity | Current cost and useful validation |
| --- | --- |
| Avoid redundant Settings requests | `settings.js:17` launches three loaders, each fetching `/api/settings`. Populate all fields from one coherent response; verify one request and unchanged failure/cancellation behavior. |
| Use job summaries for list/SSE metadata | Job-list snapshots copy output slice headers even though list JSON omits output. Ten recent jobs retaining about 1,999 lines can allocate roughly 320 KB of string headers per snapshot on a 64-bit system, plus active jobs; string contents are shared, not copied. Benchmark summary snapshots against full details. |
| Skip unused backup enumeration | Web version-cache refresh calls `CheckForAppUpdatesContext`, which scans config backups, then consumes only `AppsToUpdate`. Let callers request relevant sections; retain TUI's useful backup list. Test large directories and compare filesystem calls. |
| Reuse CPU detection for FFmpeg | Package-level `GetCPULevel` runs a fresh full `Detect`, including GPU subprocess probes, despite startup already obtaining a Platform. Use the operation's validated CPU snapshot or a CPU-only cache, alongside F12/F13. Measure first component update with stalled probes. |
| Avoid repeat macOS GPU discovery | Pure-Go codec detection calls `detectGPUDarwin` after `detectGPU` already gathered the same model. Pass that model into codec inference and keep conservative fallback; measure actual `system_profiler` invocation count. |
| Bound log storage during long sessions | The 10 MiB log rotation check runs only at initialization; the active writer keeps appending. Web/TUI display tails are bounded, but disk growth is not capped during one process lifetime. Rotate in the writer with bounded retained files and verify flush/clear/download semantics. |
| Reduce archive preparation work safely | F17 identifies repeated decompression and delayed limit/cancellation checks. Benchmark real upstream archive formats after repairing those checks; do not remove inventory validation for speed. |

## Additional follow up and coverage candidates

- **Interrupted IINA mount cleanup:** `macos.go:579`–`:601` registers detach only
  after a successful attach result. A device attached before cancellation or
  nonzero exit can escape that cleanup branch. Register cleanup for the owned
  mount root before attach and use an independent bounded cleanup context. Native
  interruption after actual mount creation is needed; no stranded mount was
  reproduced in this audit.
- **Idle Tasks page:** `tasks-page.js:25` polls only while its current active list
  is nonempty and does not subscribe to job lifecycle events. A job started in
  another tab after the page goes idle can update the sidebar without populating
  Tasks. Verify in a two-tab browser regression before prioritizing.
- **Proof-construction API:** `version.go:243` can turn an exported caller-supplied
  release object into an authenticated update-selection capability without
  verifying it at that boundary. A bogus-signature fixture passed the internal
  selection check. Shipped callers currently fetch authenticated releases first;
  no remote signature bypass was established. Require a verified type/token or
  verify the public boundary before adding new callers.
- **Frontend teardown:** `languages-priority.js:95` adds instances to a Set and
  installs an anonymous window listener without destroy. Ordinary navigation
  replaces the document, so an accumulating production navigation leak was not
  established. Add explicit cleanup before in-place component reuse.
- **TUI observation/display coverage:** background update observation commands
  are bounded but context-free; preset mutation is outside installer operation
  ownership; some user-supplied binding comments reach raw model views. Add
  focused cancellation and display-sanitization coverage. Current Bubble Tea
  parsing ignores arbitrary OSC52 in that view path, so the pre-render probe is
  not a clipboard-execution or RCE finding.
- **Existing external tasks:** Windows/Apple native signing, future desktop/htmx
  work and initial protected mirror-publication ordering remain separate Atlas
  work. This source audit did not inspect live signer policy or close those gates.

## Previous remediation checked against current behavior

The September reports were used as evidence and rechecked, rather than copied as
current open findings. Installer recovery now prevalidates required backups and
retains repeatable copies; app-bundle recovery supports validated internal links.
Selected Windows updates carry the app's UI identity, independent UI downloads
precede live commit, and setup failures produce explicit partial outcomes.

Web shutdown excludes admission and drains owned jobs/leased mutations. TUI
signal/framework exits drain owned operations. Bounded output, escaped log/text
rendering, profile-aware mpv.conf edits, atomic manager-config publication,
shared process-tree execution and bounded package queries remain useful fixes.
The audited Web paths retain loopback Host checking, same-origin Origin policy,
per-start HttpOnly/SameSite cookie authentication, method/body limits and keyring
rate limiting. No new reachable remote auth, CSRF, DOM-XSS or signed-manifest
bypass was demonstrated.

F02 is a residual of R2-09 in a different startup mode. F04 is a caller omitted
from the otherwise improved subprocess boundary. F06/F09/F10 are preservation
gaps outside the repaired profile parser and queued migration UI. F01 concerns
installer-journal authorization, distinct from both the repaired replay ordering
and authenticated manager updater journals. Historical reports remain unchanged;
this document records new findings, not completed remediation.

## Validation results and remaining gates

| Check | Result and limit |
| --- | --- |
| `go test ./...` | Passed; all repository packages compiled and applicable host tests ran. |
| `go test -race ./...` | Passed; does not exercise the newly reproduced ordering gaps automatically. |
| `make lint` and separate U1000 | Passed; pinned correctness analyzers, vet and unused check. |
| Module tidy/verify and gofmt | Clean; source files unchanged. |
| `npm ci` and `npm test` | Passed; 22 files, 183 assertions. |
| `npm run test:browser` | Passed; 21 existing real Chromium tests against embedded assets/handlers. |
| Vendor and rebuilt Tailwind comparison | Passed; runtime vendor bytes and committed CSS match locked build inputs. |
| `make build` | Passed with a distinct audit output name, preserving the ordinary dist executable. |
| Six direct application builds | Linux, Windows and macOS × amd64/arm64 passed; amd64 used v2 baseline. No native execution or release acceptance implied. |
| Govulncheck 1.7.0 | No advisories for all six GOOS/GOARCH source configurations, using a host scanner executable. |
| npm audit | Failed; F14 records the underlying development dependency advisory and exposure limits. |
| Focused defect probes | Six installer, four updater/migration package probes, two Web probes, and hotkeys/CPU/JS programs reproduce current behavior. Success here asserts defects, not fixes. |
| Coverage snapshot | Installer 80.4%, updater 72.9%, Web 59.8%, TUI 37.8%, main command 18.1% on this host. Package figures include host-compiling platform paths and are not a cross-OS acceptance score. |

Focused complete-app T3 preview navigation could not reach the fixture's loopback
listener from its browser host. Detached Chromium DOM inspection was available;
the existing full browser suite ran successfully through its repository harness.
New UI ordering scenarios still need dedicated real-browser regressions. Native
Windows/macOS filesystem, permissions, UAC, mount interruption, architecture and
GPU checks must use disposable installations and keep accepted waivers explicit.

Recommended order: first repair F01/F02 and the deletion/bounded-worker paths
F03/F04; then updater replay and editor preservation F05–F10; then job ordering,
architecture selection and the dependency gate. Decide F15's finalization/manual
replacement policy explicitly. Keep cleanup work focused and run relevant failure
regressions before repeating the full gates. No release-readiness claim follows
from this audit.
