Combined severity totals — deduplicated across both reviews (204 raw findings → 153 distinct issues), harmonized per §5
The two reviews agree on every mutually-inspected high-risk area and disagree on almost nothing factually — where they overlap, file/line references match within a few lines. The prior review's dynamic tooling (Staticcheck, race, shuffle, live Chromium, coverage) and the glm-5.3 audit's broader static depth are complementary: Review B caught 9 issues glm-5.3 missed (notably a privilege-escalation path and a config-tree divergence), while Review A caught ~104 issues Review B missed (notably the updater's exec-before-hash ordering, crash-consistency defects, and large TUI/frontend correctness surfaces).
| Check | Result | Source |
|---|---|---|
go vet ./... | Pass | B; re-run this session (A) |
go test ./... | Pass, all packages | A (this session) + B |
go test -race -count=1 ./... | Pass | B |
go test -shuffle=on -count=3 ./... | Pass | B |
| gofmt / tidy -diff / mod verify / git diff --check | Pass | B |
govulncheck@v1.7.0 (Go 1.27) | 0 vulnerabilities | B |
Staticcheck 0.8.1 (SA*) | 13 diagnostics; 4 production correctness findings | B |
npm test (157 assertions, shuffled too) | Pass | B |
npm audit --audit-level=moderate | 0 vulnerabilities | B |
| Alpine/htmx vendor freshness | Pass, byte-for-byte | B |
| Six release cross-builds | Pass | B |
| Local Web route/API/auth smoke test | Pass (cookie auth, hostile Host/Origin, graceful shutdown) | B |
| Live Chromium jobs-modal focus reproduction | Reproduced | B |
| Coverage (one repo-wide run) | 43.7% overall; installer 84.1%, platform 92.3%, version 72.9%, config 70.3%, web 28.5%, TUI 26.0%, cmd 11.9% | B |
| Source re-verification of all 9 Review-B-unique claims | All confirmed | This session |
Highest-confidence findings of the audit. Severity harmonized (§5).
| # | Finding | A (glm-5.3) | B (prior) | Verification |
|---|---|---|---|---|
| 1 | CRITICALRelaunched self-updated TUI renders into helper.log while consuming terminal input; health acknowledged before any real initialization, so the broken relaunch can be committed as "healthy" | C-1 + H-3 | H-15 | Source-verified by both; B notes ack placement in main.go |
| 2 | HIGHWindows uninstall recursively deletes the install directory with no ownership proof; per-entry errors are warnings; success returned regardless | H-6 | H-02 | A lead verified windows.go:103-157 |
| 3 | HIGHTUI update/uninstall drops AppID/InstallPath; operations run against the global installer destination — selecting install B can update/delete install A | H-14 | H-03 | Both traced models_types.go / models_update.go |
| 4 | HIGHJob cancellation archives/removes the job before the worker stops; a conflicting destructive job is accepted while side effects continue | H-11 | H-05 | Both traced jobs.go:482-543 |
| 5 | HIGHJob conflict detection protects method IDs, not shared resources; different methods (or direct config APIs) can concurrently mutate the same config/UI tree | I-M5 (Med→High) | H-06 | Both traced jobs.go:256-279 |
| 6 | HIGHPhysical success reported when authoritative persistence fails (untracked installs, tracked uninstalls, stale adoption/UI metadata) | T-M2 (Med→High) | H-07 | Both traced install/adopt workers |
| 7 | HIGHConfig setters mutate in-memory state and return errors without rollback; failed mutations later persisted by unrelated successful saves | P-M2 (Med→High) | H-08 | Both enumerated setter families |
| 8 | HIGHConfig restore renames the live file aside before validating/staging the replacement; no rollback; date-only backup names collide same-day | H-20 | H-10 | Both traced installer.go / common.go |
| 9 | HIGHPackage-version "10 s timeout" ineffective: unlabeled break exits only the select; unkillable probes; run at startup and under the cache write lock | H-10 | H-11 | A lead verified line 313; Staticcheck SA4011 flags the same line (B) |
| 10 | HIGHIINA install discards hdiutil attach output, assumes /Volumes/IINA; volume collision copies an unverified bundle; detaches the wrong path | H-9 | H-12 | Both traced macos.go |
| 11 | HIGHUnauthenticated upstream "latest" artifacts hashed and signed into MPV.Rocks trust (no upstream signature/allowlist check) | U-M12 (Med→High) | H-14 | Both traced generate-info |
| 12 | HIGHFFmpeg replacement: deferred deletion of ffmpeg.old runs even when the rollback rename failed — destroys the only known-good binary | H-7 | H-16 | Both traced installer.go:525-614 |
| 13 | HIGHTUI language apply renames the entire mpv.conf away for a single-field write; editor writes fresh defaults (all user settings vanish); failed rename ignored | H-16 | H-17 | Both traced language_preferences.go / editor.go |
| # | Finding | A | B |
|---|---|---|---|
| 14 | uOSC/ZIP extraction runs external Expand-Archive -Force/unzip -o directly over live config; rollback allowlist covers only known UI paths | I-M6 | M-01 |
| 15 | Crash before the first updater journal write permanently blocks future updates (orphan dir; recovery stops at first bad dir) | U-M2 | M-03 |
| 16 | Windows discovery executes every discovered mpv.exe --version from user-writable/PATH/registry locations before adoption, unbounded | I-M1 | M-04 |
| 17 | Multi-field config/language API writes validated together, persisted field-by-field; partial apply on mid-failure (batch writer exists, unused) | W-M5 | M-05 |
| 18 | Job-history serialization per-Store instance; TUI creates fresh stores; fixed .tmp name; cross-process record loss | P-M7/S-M8/T-M10 | M-06 |
| 19 | Persistent SSE handlers defeat graceful shutdown: 2 s timeout → fatal → exit 1 with a connected browser | S-M1 | M-07 |
| 20 | SSE terminal-event delivery/reconnect gaps: narrow concurrent-sender drop window; reconnect snapshots only active jobs; client never reconciles | F-M2 + Low | M-08 |
| 21 | TUI Ctrl+C quits without cancelling/joining backend work (context.Background workers; children outlive the TUI) | H-18 | M-09 |
| 22 | UI migration resolution spans two stores with check-then-act, no CAS; file changed while resolution says Keep | L-2 (Low→Med) | M-10 |
| 23 | Jobs modal opens focus controller while still hidden; initial focus lands on inert body | F-M6 | M-11 (reproduced in live Chromium) |
| 24 | Windows resources: only amd64 .syso, hardcoded 1.0.0.0/Win7; generator failures suppressed; arm64 has none | B-M2 + Low | M-12 |
| 25 | Manager-data reset ignores backup failure, overwrites a fixed .backup, logs success; TUI claims "backup saved" | T-M13 | M-13 |
| 26 | Backup validation misses intermediate symlinks; restore/delete can escape the backup dir | W-M2/P-M1 | M-14 |
| 27 | File/config locks process-local while Web/TUI/CLI share the same files (snapshot Write parses before locking) | S-M6/S-M7 | M-15 |
| 28 | Privileged release jobs run mutable container tags (alpine:latest, release-cli:latest) | B-M6 | M-16 |
| 29 | TUI PATH add/remove: non-idempotent aliases, failures reset to nil, removal never removes aliases, Windows broken | T-M9 | M-18 |
| 30 | Release-generator artifact downloads unbounded in time and size | U-M9/B-M4 | M-19 |
| 31 | Signed manager manifest computed from re-downloaded registry bytes, not the pipeline's build artifacts | H-21 (High; B Med) | M-20 |
| 32 | BLAKE3SUMS.txt emits blake3: prefix — incompatible with documented b3sum -c; never exercised by CI | U-M11/B-M8 | M-21 |
| 33 | Stored-password Web installs dispatch the privileged request twice (ensurePassword invokes callback and returns true) | F-M1 | M-22 |
| 34 | Config Apply baseline rebuilt from current controls, not the submitted payload; concurrent edits silently marked saved | F-M3 | M-23 |
| 35 | UI-option saves and regional-language requests allow stale responses to overwrite newer intent | F-M4 + F-M5 | M-24 |
| 36 | CLI --path ignored by ModernZ/uOSC/FFmpeg dispatch but recorded as InstalledApp.InstallPath | S-M9 | M-25 |
| # | Finding | A | B |
|---|---|---|---|
| 37 | No CSP on the privileged loopback UI | Frontend Low | L-02 |
| 38 | Public parsed script-options Write can overwrite fresher edits (no revision check) | Support Low | L-05 |
| 39 | Reset text claims language preferences cleared; they live in mpv.conf | T-M13 (partial) | L-06 |
| 40 | Staticcheck-exposed TUI defects (SA4005 value receiver, SA4014 duplicate branches, SA9003 empty branches) | TUI Lows | L-07 |
| 41 | Docs claim macOS universal output that CI contradicts; release metadata/native gates unenforced | B-Low + U-Low + H-23 context | L-08 + coverage gaps |
mpv-unregister.bat is copied from the (possibly adopted, user-writable) MPV tree and executed via Start-Process -Verb RunAs with no digest/ownership/ACL check before UAC. An unprivileged process can replace the .bat and wait for the user to approve the expected prompt → admin code execution.
This session: confirmed — copy from install tree, fallback to the original path, elevated Start-Process, zero verification.
portable_config treesInstaller writes <custom>\portable_config, but config/hotkeys/ModernZ/uOSC/migration/backup resolvers use %APPDATA%\mpv or legacy home; the common resolver never consults the configured custom path (and caches with sync.Once). UI reports success against a tree MPV never reads.
This session: confirmed — getWindowsMPVBaseDir checks only APPDATA/home existence via windowsPathOnce.
Permission errors, transient I/O failures, and unavailable mounts all fall through to default configuration and are saved over the existing file. The parse-error log prints the shadowed outer err (always <nil>).
This session: confirmed — any ReadFile error reaches "Start fresh defaults" + saveLocked(); inner err shadows the read error used in the log.
CI builds cmd/generate-info from the tag, injects MANIFEST_SIGNING_KEY, and executes that artifact. A malicious or compromised tagged generator can export the private key and forge future manifests; protected-tag rules do not separate signer trust from the code being authorized.
This session: confirmed — the generator job requires MANIFEST_SIGNING_KEY_ID/MANIFEST_SIGNING_KEY.
| # | Finding | B | This session's verification |
|---|---|---|---|
| B-5 | MEDMulti-target self-update locks only the primary executable; concurrent primary/secondary updates can both mutate the same secondary | M-02 | CONFIRMEDtransaction.go:205-210: single tryAcquireUpdateLock(updateLockPath(primaryPath)) |
| B-6 | MEDReduced-motion preferences don't cover dialog animations (generic/job/password/UI-select modals) | M-17 | CONFIRMEDstyle.css:430-455 covers toast/badge/progress/priority-list only |
| B-7 | LOWManifest-status network exceptions leave install controls enabled (catch only logs) | L-01 | CONFIRMEDmanifest-status.js:34-48: catch does console.error only |
| B-8 | LOWLocal make release can package stale frontend assets (no frontend deps/freshness/tests in the chain) | L-03 | CONFIRMEDMakefile:227 chain; also corroborates A's B-M3 (release-build omits trust check) |
| B-9 | LOWDuplicate hotkey lines only partially edited (first-match Set/Remove) | L-04 | Consistent with the first-match parser traced by A's hotkeys review; not line-by-line re-verified |
Single-sourced but lead-verified during the original audit. Grouped summary (full detail in the glm-5.3 report and .opencode/reviews/):
PrepareSelfUpdateFromCheck DTO (U-M3)--qualifier-driver uncontained destructive mode (U-M10)Start-Process without -Wait (I-M3); detection collapses uncertainty into "not installed" (I-M2); runtime file transactions not crash-durable (I-M7)"updates" menu ID (T-M1); progress bar 0–100 vs 0–1 unit bug (T-M5); quadratic output rendering (T-M7); Unicode backspace byte-slicing (T-M14); terminal control-sequence injection (T-M15); hardcoded version overlay (T-M11); ~33 s non-offline-first startup (T-M12)sudo -S -v without -k (W-M1); locale cache data race (W-M4); ui_type unvalidated (Low); downgrades labeled updates (Low)# parsing in mpv.conf/input.conf/script-opts — three independent implementations (P-M3, P-M8, S-M4); Linux GPU model truncation and hybrid-order dependence (P-M4); macOS AV1 over-reporting incl. M2 (P-M5); arm64 labeled x86-64-v2 (P-M6); locale dataset/selection disagreements (P-M9); BOM/CRLF round-trip corruption (S-M5)formatKeys template.HTML trust boundary (Low)--verbose cli starts Web) (S-M2); --verbose/--debug no-op console logging (S-M3); symlink-replacing atomic writes (S-M6); browser-launch/bind race (S-M10); os.Exit cleanup bypass; zombie browser helpermake lint unpinned; browser E2E absence (B-M5)| Topic | A (glm-5.3) | B (prior) | Resolution |
|---|---|---|---|
| Helper-log relaunch + early health ack | CRITICALC-1 + H-3 | HIGHH-15 | Critical. Both agree on facts. No supported recovery after commit, terminal silently captured, shipped qualification cannot detect it. Not attacker-triggerable RCE, but by impact-and-permanence the single worst defect. |
| Manifest signs re-downloaded registry bytes | HIGHH-21 | MEDM-20 | High. GitLab permits duplicate generic-package files by default; the signature is the root of trust and must bind to pipeline-produced bytes. B's own remediation implies the same. |
| Job conflict detection scope | MEDI-M5 | HIGHH-06 | High. Overlapping config/UI mutations can roll back committed work — authoritative-state failure. |
| Persistence-failure false success | MEDT-M2 | HIGHH-07 | High. Tasks UI as untrustworthy state is a core-flow failure. |
| Config setter rollback | MEDP-M2 | HIGHH-08 | High. Failed mutations later persisted by unrelated saves. |
| UI migration CAS | LOWL-2 | MEDM-10 | Medium. Two-store check-then-act verified this session. |
| TUI Ctrl+C | HIGHH-18 | MEDM-09 | High. Combined with Escape abandonment and shutdown-orphaned jobs, one systemic lifecycle failure (Theme 3). |
.bat (B-1), wrong-target TUI operations, config-tree divergence (B-2), fail-open config reset/restore, FFmpeg backup deletion, language-apply rename, defaults-on-read-failure (B-3), date-colliding backups.--path recording fiction.# without quote tracking..bat (H-01/B-1), app-identity-carrying TUI operations (H-03/H-14), one installed-app-aware config resolver (H-04/B-2).os.IsNotExist (H-09/B-3).ensurePassword single-owner, SSE reconnect reconciliation, latest-intent saves, $nextTick modal focus, reduced-motion dialogs (M-22–M-24, M-11, M-17).b3sum -c-compatible checksums + tests; license notices in archives; Windows resources for both arches; tag grammar before publication; generator download bounds (M-21, M-19, M-12).SA* in CI.os.Root writes.