MPV Manager — Deep Codebase Audit

Reconciliation update (2026-09-05): The August fixes are confirmed present and identical to checkpoint fa0a678. Cross-review reconciliation maps all findings to their origins. R21 is now resolved: the missing historical report pairs were recovered byte-for-byte. The findings below preserve the initial audit record.

Implementation checkpoint (2026-09-05): Commit 346f272 preserves the August remediation, restored evidence, and both September reports. R04 is fixed in 979152e; R01/R02 are fixed in bf43eeb. R21 was resolved by restoring the historical reports. The remaining 18 findings are tracked in Atlas. The recovery changes passed the full Go race suite, lint, and all seven Linux native updater cases; the CI script passed all six targets. Windows/macOS native reruns remain release gates. Legacy unauthenticated update journals require manual recovery; see Troubleshooting.

Initial audit record: reviewed 2026-09-05 before implementation. Findings and counts below describe that baseline; subsequent fixes are listed above.

Atlas audit task: cebaeea6-fed6-4d19-811a-7288b1e9ed69 · Project: mpvrocks-mpv-manager. All R01–R22 belong to this audit task. Suggested work below preserves the original review recommendations; Atlas records subsequent implementation status.

Download Markdown · Validation · Reproduction fixtures

Assessment

The current tree contains substantial security and reliability improvements, but it is not ready to treat the earlier remediation pass as complete. This audit retains 22 findings: 4 High, 12 Medium, and 6 Low. The most consequential are destructive recovery replay (R01), journal-controlled backup execution under a weaker-trust parent directory (R02), Web shutdown abandoning workers (R03), and cross-target CI tools that cannot execute on the build host (R04). Review those four before release work continues.

The existing validation suite is green: normal/race Go tests, vet/Staticcheck, 180 frontend assertions, dependency scans, embedded-asset freshness, and six application cross-builds. Targeted probes still reproduced integration defects. Passing unit suites and compilable target binaries do not establish crash recovery, process ownership, real browser initialization, or complete CI-script correctness.

“AI slop” is assessed here as observable maintenance waste: unreachable paths, unused extension points, mock-only tests, redundant wrappers, and duplicated rules. No conclusion is drawn about who or what originally wrote a file. Existing failure-injection, authentication, archive, transaction, and lifecycle tests are valuable; wholesale test deletion or architectural replacement is not recommended.

SeverityCountInterpretation
High4Material data-loss/security boundary risk or a direct release/lifecycle blocker; R02 has an explicit local attacker-access precondition.
Medium12Incorrect user-visible behavior, persistence/concurrency gaps, or boundedness problems with a concrete live path.
Low6Measured or source-supported cleanup, performance, and developer-experience opportunities.

Reviewed tree and method

Repository: /home/agent/Projects/mpvrocks/mpv-manager. HEAD: bdfb31b95030c2d992e5cfc4cb0ba5bada368d1b on master. The starting working tree had 195 tracked dirty paths and 89 untracked files, including earlier remediation and review artifacts. Findings apply to those actual working files, not to HEAD alone. Existing work was preserved.

A SHA-256 inventory captured 798 tracked/untracked nonignored files before analysis. Aggregate fingerprint of the sorted compact JSON path-to-hash map: 270747fe7c23e6252098960547f1575f948e06c8f9df714c3ae0ff9f1a8b90cf. Appendix C records hashes for the files cited by findings. Line references refer to this reviewed snapshot and may move after later edits.

The audit combined broad source inventory with risk-directed tracing of installer/update transactions, recovery and authentication boundaries, configuration persistence, Web/TUI/CLI lifecycle, package observations, frontend components, build/release scripts, tests, and agent instructions. Production Go and authored JavaScript accounted for approximately 58,000 lines; corresponding Go/JavaScript tests accounted for approximately 37,000 lines. This was a deep path-based review, not a claim that every line or platform behavior was independently proven correct.

Validation ran on Linux amd64 with go1.27.0-X:nodwarf5, Node 26.8.1, and npm 12.0.2. The repository’s CI uses Node 22; the complete CI container workflow was not run. Reproductions used disposable directories, harmless marker files, Go overlay tests, and a headless Chromium fixture. No application source, existing tests, dependency files, CI configuration, or live installation was modified.

Confidence labels distinguish executed behavior from source-confirmed paths and conditional exposure. Synthetic persisted journal states demonstrate replay behavior; they do not replace power-loss testing. Windows/macOS install/uninstall, UAC, signatures, ACLs, quarantine, and native process-tree handling were source-reviewed or cross-compiled, not exercised natively during this audit. No live signing service, protected GitLab settings, publication endpoint, or historical released-client bootstrap was newly qualified.

Findings index

Each item identifies the live code, observed behavior, impact, a proposed direction, and useful validation. R06/R20 cover consolidation at different boundaries; R12/R13/R17 should share one configuration-parser effort. Counts are this audit’s retained items, not additions to the historical 101-entry register.

IDSeverityCategoryFinding
R01HighBugs, SecurityInstaller recovery can delete the only original copy
R02HighSecuritySelf-update recovery executes backups authorized only by a local journal
R03HighBugsWeb shutdown neither cancels nor joins background installation jobs
R04HighBugs, Agent DXCross-platform release jobs run target executables on the Linux build host
R05MediumBugs, PerformanceCommand cancellation leaves descendants running and can keep output draining indefinitely
R06MediumBugs, PerformanceLegacy version probes bypass the newer timeout and locale safeguards
R07MediumBugsInstall jobs disable cancellation before downloading or staging
R08MediumBugsWindows MPC-QT uninstall reports success without waiting for or checking the uninstaller
R09MediumBugsThe Windows ownership safeguard has no migration path for existing installations
R10MediumBugsA UI update overwrites configuration saved while its download is running
R11MediumBugsUI transactions omit version metadata and clean-baseline state
R12MediumBugsThe mpv.conf editor ignores profile scope and effective duplicate settings
R13MediumBugsScalar configuration values containing commas are truncated in the Web editor
R14MediumBugs, PerformanceAlpine components call init twice, duplicating Tasks requests and timers
R15MediumPerformance, BugsInstallation output limits do not bound memory across the complete pipeline
R16MediumBugsChecking updates bypasses the lease used for the same installed-app reconciliation
R17LowPerformanceRendering Config repeatedly reads and parses the same file
R18LowAI slop, Agent DXAt least 24 production functions are unreachable from repository programs and tests
R19LowAI slop, Agent DXUnused interfaces and tests exercise mock bookkeeping instead of shipped behavior
R20LowAI slopShortcut wrappers repeat platform dispatch already represented by the installer interface
R21LowAgent DXThe finalized historical audit depends on four missing evidence reports
R22LowAgent DXRoot agent instructions mix durable rules with extensive history and stale status
HighReproducedBugs, Security

Installer recovery can delete the only original copy

Source: pkg/installer/transaction_journal.go:468; pkg/installer/file_transaction.go:366; pkg/installer/file_transaction.go:461

Observation: rollbackInstallerJournal removes the live target before checking whether the required backup exists. The forward operation durably records intent before moving the original into that backup. Recovery also consumes backups with Rename without a durable per-entry replay state.

Evidence and confidence: A disposable, schema-valid file-swap journal with had_original=true, a live original, and an absent backup caused RecoverInstallerTransactions to delete the original and then report a missing-backup error. This persisted state represents both interruption after intent but before backup creation, and interruption after a previous recovery restored the original but before journal retirement. Both fixtures returned original_deleted=true. These were constructed boundary states, not physical power-loss tests; the complete probe is in Appendix A.

Impact: An interrupted installation, FFmpeg replacement, or overlay can turn a recoverable situation into permanent data loss on the next recovery attempt. Ordinary rollback tests do not cover this replay ordering.

Proposed direction: Record enough durable per-entry state and original evidence to distinguish untouched, backed-up, applied, and restored targets. Validate restoration prerequisites before deleting anything. Make replay safe to repeat at every filesystem/journal boundary, and retain recovery evidence until restored bytes and directory entries are durable.

Validation after approval: Inject termination at every journal write, original rename, replacement, restore, and journal retirement boundary. Restart recovery repeatedly and assert that an original or authenticated replacement always survives, including when the backup is absent.

HighReproduced; exposure conditionalSecurity

Self-update recovery executes backups authorized only by a local journal

Source: pkg/version/transaction.go:921; pkg/version/transaction.go:935; pkg/version/transaction.go:738; pkg/version/transaction.go:1165; pkg/version/version.go:742

Observation: Startup recovery scans adjacent transaction directories and accepts structurally valid JSON as authority. ManifestKeyID need only be nonempty; the recovery loader does not authenticate that field or establish the journal directory and backup as belonging to a trusted transaction. rollbackUpdateTargets invokes the backup for identity checking. Its legacy fallback first captures evidence from the very backup it is about to trust; attacker-supplied evidence in a forged journal is not an independent trust anchor either.

Evidence and confidence: A fabricated applying journal with manifest_key_id=not-a-trusted-key and a dummy expected digest caused a harmless shell backup to create a marker before identity validation rejected it: backup_executed=true, original_preserved=true. The probe used only disposable paths and the current user. No cross-user privilege escalation was attempted. See Appendix A.

Impact: Execution is demonstrated; exploitation requires an attacker able to create appropriately named sibling files/directories beside the portable executable, or to modify trusted transaction state. A shared writable parent can have weaker trust than the executable itself, including a sticky directory where the attacker cannot replace that executable. Under that condition recovery can run attacker code with the manager’s privileges. This is not a demonstrated remote manifest-signature bypass.

Proposed direction: Establish and enforce transaction ownership, parent-directory trust, no-follow path handling, and restrictive permissions before inspecting executable artifacts. Bind recovery to durable evidence in a protected transaction store. Reject or explicitly migrate unauthenticated legacy state without executing it. Keep authenticating downloaded payloads separately.

Validation after approval: Exercise forged, symlinked, foreign-owned, and modified journals and backups under different user identities on native platforms. No backup should execute before independent trust is established; valid interrupted transactions must still recover.

HighReproduced lifecycle gapBugs

Web shutdown neither cancels nor joins background installation jobs

Source: pkg/web/server.go:284; pkg/web/jobs.go:256; pkg/web/api_settings.go:365; cmd/mpv-manager/main.go:442

Observation: Jobs derive their contexts from context.Background. Server.Shutdown closes server/SSE signals and shuts down HTTP, but it has no worker cancellation-and-join phase. Install workers outlive the HTTP requests that created them. runWebMode can return when the server stops accepting requests, without waiting for an independently running shutdown routine to finish.

Evidence and confidence: An overlay probe created an active job and called Server.Shutdown: shutdown_error=<nil>, job_context_cancelled=false, active_jobs=1, with an immediate return. The probe isolates job ownership; source tracing connects that gap to process exit through the Web lifecycle. Go HTTP shutdown drains HTTP connections, not arbitrary background workers. Go Server.Shutdown documentation.

Impact: Closing the manager or triggering its shutdown endpoint can terminate the process during installer/configuration mutation and before a terminal job result is persisted. Subprocesses can continue independently (R05). The replay defect in R01 makes this combination especially concerning.

Proposed direction: Give the server explicit ownership of worker admission, contexts, and completion. Stop new operations, cancel work that can safely stop, let commit/rollback complete, drain output and persist outcomes, then allow main to exit. Make the main goroutine wait for that whole lifecycle.

Validation after approval: Use a controlled slow worker and a commit barrier. Verify shutdown rejects new jobs, cancels pre-commit work, waits for in-flight commit/rollback and output drain, records terminal history, and exits only afterward.

HighReproducedBugs, Agent DX

Cross-platform release jobs run target executables on the Linux build host

Source: .gitlab-ci.yml:225; .gitlab-ci.yml:237; .gitlab-ci.yml:242; .gitlab-ci.yml:313

Observation: The shared build script runs go run ./cmd/verify-manifest and go run go-winres while job-level GOOS and GOARCH describe the target artifact. go run compiles for those values and then attempts to execute the result inside the Linux image.

Evidence and confidence: GOOS=windows GOARCH=amd64 go run ./cmd/verify-manifest -keys-only failed before the program ran: fork/exec .../verify-manifest.exe: exec format error. Windows and Darwin jobs inherit the offending command. Linux arm64 also needs host/tool separation on an amd64 runner without configured emulation. Six direct application cross-builds passed; they do not execute this CI script.

Impact: Non-native tagged release jobs cannot reach artifact production. The go-winres generation and extraction invocations have the same environment problem, so correcting only manifest verification is insufficient.

Proposed direction: Run build-time utilities with explicit host GOOS/GOARCH, or prebuild host tools once. Apply target variables only to compilation of the release artifact. Keep the Windows resource architecture as an explicit tool argument.

Validation after approval: Execute the complete shared script in the pinned Linux CI image for every target, including verification and Windows resource generation/extraction. Assert both tool execution and artifact identity; do not substitute go build-only checks.

MediumReproduced on LinuxBugs, Performance

Command cancellation leaves descendants running and can keep output draining indefinitely

Source: pkg/installer/command_runner.go:71; pkg/installer/command_runner.go:84; pkg/installer/command_runner.go:176

Observation: The command runner uses exec.CommandContext without process-tree ownership or a bounded post-cancellation pipe-drain interval. Killing the immediate shell does not kill its descendants; descendants can retain inherited output descriptors. This matches Go’s documented default cancellation behavior. Go CommandContext documentation.

Evidence and confidence: A shell with a child that slept and wrote a harmless marker was given a 100 ms deadline. RunCommand returned after 602 ms, and the marker existed: child_mutated_after_cancel=true. An indefinitely living child can extend this mechanism indefinitely. See Appendix A.

Impact: Cancellation may appear acknowledged while child installers continue changing files. Inherited pipes can also keep a worker blocked after its direct child has died, preventing a correct shutdown join.

Proposed direction: Own subprocess trees using appropriate Unix process groups and Windows Job Objects or equivalent native handling. Define safe termination behavior for package managers, wait for descendants, and bound pipe draining with WaitDelay or equivalent handling.

Validation after approval: Run descendants that ignore termination, hold pipes, spawn grandchildren, and mutate a temporary marker. Verify no mutation occurs after cancellation completion and that output-drain waits remain bounded on each platform.

MediumSource-confirmedBugs, Performance

Legacy version probes bypass the newer timeout and locale safeguards

Source: pkg/version/updates.go:155; pkg/version/updates.go:288; pkg/version/updates.go:341; pkg/web/server_version_cache.go:203; pkg/web/server_version_cache.go:354; pkg/web/package_version.go:64; pkg/web/api_install.go:552

Observation: CheckForAppUpdates falls back to queryPackageManagerVersion for records with no AppVersion. Its Flatpak, Brew, apt, pacman, and rpm commands use exec.Command and unbounded Output/CombinedOutput without LC_ALL=C. The Web cache calls this shared updater before reaching its newer concurrent bounded probes. The post-install Web GetPackageVersion wrapper also supplies context.Background instead of a job deadline.

Evidence and confidence: The live call chains were traced from synchronous Web cache initialization/refresh and the TUI update check into these helpers. The context-aware Web probe implementation therefore does not bound all version queries. Package and distro detection remain duplicated between pkg/version, pkg/web, pkg/installer, and pkg/platform.

Impact: A hung package tool can delay startup or leave update/install completion waiting indefinitely. Localized output can be misparsed, while divergent detection code makes fixes easy to apply to only one caller.

Proposed direction: Use one shared package observation service with caller context, an enforced probe timeout, bounded output, locale-stable commands, and distinct absent/unknown/error results. Reuse canonical distro classification and pass the job/server context through every entry point.

Validation after approval: Use a fake PATH with hanging, noisy, localized, and unavailable package tools. Cover missing-version records, startup, TUI refresh, Web refresh, and post-install version discovery; each must complete within its budget and preserve uncertain installed state.

MediumSource-confirmedBugs

Install jobs disable cancellation before downloading or staging

Source: pkg/web/api_install.go:463; pkg/web/api_adopt.go:195; pkg/web/jobs.go:703; pkg/web/jobs.go:722

Observation: runInstallationJob calls BeginCommit at the start of execution, before constructing and running the installer. That installer still needs to download, authenticate, and stage artifacts. UI-change jobs similarly enter commit before the remote work. CancelJob refuses cancellation once commitStarted is set.

Evidence and confidence: The call order places almost the entire operation inside the non-cancellable phase. The UI continues to offer cancellation for running jobs, while the job model does not expose a useful per-phase cancellation capability.

Impact: Users cannot cancel a slow download or staging operation after the initial scheduling gap. This defeats a central background-job feature and can leave long-running operations needlessly holding resource leases.

Proposed direction: Move the commit boundary next to the first live mutation that must finish or roll back. Keep download, verification, and staging cancellable. Expose cancellation capability and the current phase to Web/TUI components.

Validation after approval: Pause a download and a staging step with barriers and verify cancellation works without changing live files. Pause inside commit and verify cancellation is explicitly deferred/rejected while commit or rollback reaches a truthful terminal outcome.

MediumSource-confirmed; native validation pendingBugs

Windows MPC-QT uninstall reports success without waiting for or checking the uninstaller

Source: pkg/installer/windows.go:509; pkg/web/api_install.go:402

Observation: UninstallMPCQTWithOutput starts PowerShell Start-Process with -Verb RunAs but without -Wait or propagated child exit status. A failure to start PowerShell returns nil. A cmd.Wait error only prints a warning and also returns nil. Uninstaller lookup checks two hard-coded Program Files locations.

Evidence and confidence: The success/error branches are explicit in the Windows source. Web job completion removes the installed-app record after a nil uninstall error. Unlike the recently hardened installation path, this uninstall path does not wait for the actual elevated child or verify its result. It was not executed on Windows during this audit.

Impact: A cancelled UAC prompt, failed uninstaller, or still-running uninstall can be recorded as success and remove tracking for an application that remains installed. Custom locations are not reliably resolved.

Proposed direction: Resolve the selected installation’s uninstaller, wait for the actual elevated process, propagate its exit status, and verify the installation outcome before removing tracking. Report failure or a manual-action outcome truthfully.

Validation after approval: Native Windows cases should include UAC rejection, child nonzero exit, delayed completion, missing/custom uninstaller locations, and successful removal. Failed or uncertain outcomes must retain the selected app record.

MediumPolicy rejection reproducedBugs

The Windows ownership safeguard has no migration path for existing installations

Source: pkg/installer/windows_ownership.go:33; pkg/installer/windows_ownership.go:103; pkg/web/api_adopt.go:407

Observation: A populated install directory without .mpv-manager-owned.json is rejected before update; uninstall also requires ownership evidence. The new installer creates that manifest for new payloads, but historical installations and the adoption flow do not establish an equivalent reviewed inventory.

Evidence and confidence: The platform-neutral validator rejected a temporary directory containing an existing mpv.exe with: refusing to modify populated directory without .mpv-manager-owned.json ownership proof. Source tracing shows adoption updates tracking/configuration without creating this ownership proof. Native upgrade from an archived release was not performed.

Impact: Previously installed or adopted MPV copies can appear managed while routine update/uninstall is refused. The refusal protects unrelated files, but the compatibility workflow is incomplete.

Proposed direction: Retain the safety check. Add an explicit ownership migration that proves a narrowly scoped file inventory, or present a supported manual migration/reinstall workflow before treating the install as fully managed. Never infer ownership of an entire populated directory.

Validation after approval: Use fixtures from historical manager releases and external portable MPV installs, including unrelated user files. Verify migration establishes only proven ownership and enables the advertised operations without deleting unrelated content.

MediumReproducedBugs

A UI update overwrites configuration saved while its download is running

Source: pkg/installer/ui_config_update.go:144; pkg/installer/ui_config_update.go:164; pkg/installer/ui_config_update.go:175; internal/scriptopts/scriptopts.go:1

Observation: updateUIWithPreservedConfig reads the live config before invoking the staging/download callback. It later writes that old snapshot into staging and copies it over the live file. The installation transaction lock is acquired afterward, and the update does not revalidate the config revision or share the editor’s per-file update boundary.

Evidence and confidence: An overlay probe began with old-user-setting, saved saved-while-download-runs to the live config inside the staging callback, and completed successfully. The final file was old-user-setting: concurrent_edit_lost=true. The durable pre-update backup also comes from the early snapshot. See Appendix A.

Impact: A successful save from another process or editor can silently disappear during a ModernZ/uOSC update. Same-instance Web leases reduce one entry point, but do not protect other processes or external editors.

Proposed direction: Re-read and compare the live revision immediately before commit under the same coordination used by editors. Preserve the latest accepted bytes, or stop with a conflict instead of overwriting them. Ensure the backup represents the revision actually replaced.

Validation after approval: Coordinate two writers with deterministic barriers during download and just before commit. Assert the newer user edit survives or produces an explicit conflict, including cross-process use and edits through both UI-specific editors.

MediumSource-confirmedBugs

UI transactions omit version metadata and clean-baseline state

Source: pkg/installer/ui_config_update.go:160; pkg/installer/ui_config_update.go:106; pkg/installer/common.go:541; pkg/installer/installer.go:794; pkg/installer/installer.go:940

Observation: The staging install writes the global ModernZ/uOSC version before staged bytes are committed to the live installation. Ordinary error paths attempt to restore that version, but the durable UI journal does not contain it. stagedUIPaths also copies .mpv-manager/ui-baselines although that path is absent from managedUIPaths, the UI rollback snapshot, and the commit sync set. Baseline/version persistence errors are reduced to warnings followed by nil.

Evidence and confidence: Comparing the staging callbacks, the commit path list, and the journal snapshot list exposes the mismatch. A process interruption after staging can leave the version advanced while the live UI is old; a rollback after baseline copy can leave new baseline metadata paired with restored scripts. These interruption cases were source-reviewed, not killed in a native harness.

Impact: Update detection and configuration migration/audit decisions can use metadata that does not describe the installed scripts. A successful-looking operation can also lack the baseline needed for later preservation and migration.

Proposed direction: Have staging return immutable artifact/version/baseline data without changing global state. Include authoritative metadata and baseline updates in the same durable transaction, with recovery compensation where stores differ. Surface persistence failures as failed or partial outcomes.

Validation after approval: Inject errors and restart at stage completion, baseline copy, version persistence, live commit, and rollback. Verify scripts, user config, clean baseline, and reported version always describe one committed generation.

MediumEmitted-file defect reproducedBugs

The mpv.conf editor ignores profile scope and effective duplicate settings

Source: pkg/config/editor.go:29; pkg/config/editor.go:185

Observation: GetConfigValue and applyConfigValue scan for the first key= prefix without tracking profile headers. Missing keys are appended at EOF, which may still be inside a named profile. Spaced assignments are missed, and changing the first duplicate leaves later assignments in place.

Evidence and confidence: Setting hwdec on a file containing [special] and scale=bilinear appended hwdec=nvdec inside that profile. Changing hwdec in hwdec=no followed by hwdec=auto produced hwdec=nvdec followed by hwdec=auto. Both calls returned nil. The mpv manual confirms that settings remain in a named profile until another header or [default]. mpv configuration profiles. Player-level behavior was not exercised with a native mpv process here.

Impact: A successful settings save may affect only an inactive profile, alter an unintended profile, or leave a later effective assignment unchanged. The UI can display a value different from the setting mpv actually uses.

Proposed direction: Use a shared lossless parser that understands profile boundaries, whitespace, comments, quoting, and repeated assignments. Define the editor’s scope explicitly, update the effective assignment in that scope, and insert global settings into a valid default section.

Validation after approval: Round-trip global/default/named profiles, spaced keys, duplicate definitions, inline comments, and quoted values. Where practical, compare resulting effective options with a real mpv process rather than only checking generated text.

MediumRead truncation reproducedBugs

Scalar configuration values containing commas are truncated in the Web editor

Source: pkg/config/editor.go:73; pkg/web/api_config.go:182; pkg/web/server.go:431; internal/webassets/static/config-page.js:1

Observation: GetConfigValue splits every setting except hwdec into comma-separated items. getMPVConfigValue returns only the first item, including for scalar values such as screenshot-avif-opts. The settings form uses that shortened value and submits its settings on Apply.

Evidence and confidence: Reading screenshot-avif-opts=crf=20,speed=6 returned ["crf=20", "speed=6"]. The Web scalar helper selects "crf=20". The read behavior was reproduced; the subsequent form rendering/submission path was source-traced.

Impact: Opening settings and applying a change can silently remove AVIF encoder options after the first comma. Other scalar path/template values with commas share the parsing problem.

Proposed direction: Separate scalar and list accessors using an explicit option schema. Preserve scalar text intact, and split only options whose data type is actually a list. Share the representation across Web and TUI.

Validation after approval: Round-trip AVIF suboptions and comma-bearing scalar values through GET, rendered form, and POST without edits, then with an unrelated field changed. Preserve all original scalar content.

MediumReproduced in ChromiumBugs, Performance

Alpine components call init twice, duplicating Tasks requests and timers

Source: internal/webassets/templates/tasks.html:20; internal/webassets/templates/hotkeys.html:65; internal/webassets/templates/base.html:35; internal/webassets/static/tasks-page.js:17

Observation: Tasks, Hotkeys, and the jobs modal combine x-data components that expose init() with x-init="init()". Alpine automatically invokes an init method on a component before evaluating x-init. Alpine initialization documentation.

Evidence and confidence: A headless Chromium fixture loaded the repository’s vendored Alpine and actual Tasks component while counting calls: {"fetches":2,"intervals":2}. This uses the real framework lifecycle, which direct factory unit tests do not exercise. Hotkeys also installs media listeners in init; the jobs-modal initialization is likewise entered twice, although its downstream dialog effects were not separately counted.

Impact: Tasks performs duplicate initial requests and maintains two polling timers per mounted component. Other components repeat initialization side effects; missing lifecycle cleanup can compound leaks during remounts.

Proposed direction: Use Alpine’s automatic init convention consistently and remove redundant explicit invocation. Store and clean up timers/listeners in destroy where components can be removed. Make framework-mounted behavior part of focused frontend validation.

Validation after approval: Mount each affected component with the pinned Alpine runtime and assert one initialization, one fetch/polling loop, and complete timer/listener cleanup after removal and remount.

MediumBackend retention reproduced; frontend source-confirmedPerformance, Bugs

Installation output limits do not bound memory across the complete pipeline

Source: pkg/installer/command_runner.go:131; internal/webassets/static/jobs.js:269; internal/webassets/static/jobs-modal.js:177; pkg/web/jobs.go:1

Observation: outputCapture accumulates pending text until a newline with repeated string concatenation and no byte cap. Carriage-return-only progress and a long unterminated line can grow indefinitely. The browser appends live output to job.output and the modal’s output array without retaining only the server’s bounded tail; per-line rendering/scroll updates add work.

Evidence and confidence: A probe fed 64 chunks of 64 KiB without a newline: pending retained 4,194,304 bytes. Repeated concatenation copies the accumulated prefix. Source tracing shows unconditional array pushes in both browser consumers, so server line-count limits do not bound an open client.

Impact: Verbose or malformed tool output can consume growing memory and increasing CPU, and a long-lived output modal can accumulate an expensive DOM. This is a local tool-output resilience issue, not a demonstrated unauthenticated network attack.

Proposed direction: Apply explicit byte and line budgets at capture, retained job history, SSE payload, and browser layers. Handle carriage-return progress, bound partial lines, use bounded buffers, and batch rendering/scrolling. Make truncation visible to the user.

Validation after approval: Stream very long single lines, CR-only progress, and many short lines through the full pipeline. Measure bounded retained bytes/nodes and responsiveness, including when the output modal stays open for the entire job.

MediumSource-confirmed concurrency gapBugs

Checking updates bypasses the lease used for the same installed-app reconciliation

Source: pkg/web/server.go:183; pkg/web/api.go:91; pkg/web/server_version_cache.go:338; pkg/web/server_version_cache.go:379

Observation: /api/apps/refresh-installed acquires resourceManagerConfig, but /api/apps/check-updates does not. Both handlers call refreshVersionCache, which runs DetectAndSyncApps and removes stale app records. The latter is therefore a mutating reconciliation operation despite its update-check label.

Evidence and confidence: The route registrations and shared call chain expose the missing lease. Cache publication has a mutex, but that protects the cache assignment, not filesystem observation and config reconciliation against concurrent install/uninstall. The secondary stale-removal path also removes by method rather than the observed app identity.

Impact: An update check can observe a temporary installation state and alter tracking while a job owns the same resource. A stale observation can remove or recreate records and interfere with final job persistence. The exact timing-dependent end-user failure was not reproduced in this audit.

Proposed direction: Route every mutating reconciliation through the same operation coordinator, or make update checks read-only and move reconciliation behind a separately leased operation. Revalidate snapshot/identity before applying removals; preserve unknown observations.

Validation after approval: Hold an install/uninstall lease and call each refresh route with barrier-controlled detection. Verify that reconciliation is blocked or safely deferred, and that stale observations cannot remove a changed app record.

LowSource-confirmed optimizationPerformance

Rendering Config repeatedly reads and parses the same file

Source: pkg/web/server.go:389; pkg/config/editor.go:29; pkg/web/api_config.go:182

Observation: getConfigSettings performs 22 GetConfigValue/getMPVConfigValue field reads. Each resolves the path, reads the entire mpv.conf, converts it to a string, and splits its lines. API/settings consumers repeat the pattern.

Evidence and confidence: The 22 call sites were counted in getConfigSettings and traced to os.ReadFile in GetConfigValue. No end-user latency improvement is claimed without a benchmark.

Impact: A small settings request does repeated I/O and allocations, and fields can come from different revisions if another writer saves between reads. Larger hand-maintained configs make the cost more noticeable.

Proposed direction: Parse once into an immutable request snapshot with typed scalar/list accessors, sharing the corrected semantics from R12/R13. Prefer request-scoped reuse before introducing a global invalidation cache.

Validation after approval: Benchmark representative small and large configs and count reads per request. Verify all fields are derived from one revision and that a subsequent request observes a newly saved file.

LowMulti-platform reachability analysisAI slop, Agent DX

At least 24 production functions are unreachable from repository programs and tests

Source: pkg/web/package_detection.go:1 (removed by R18; baseline 346f272); pkg/web/locale_utils.go:34; pkg/config/config.go:625; pkg/version/version.go:449; pkg/web/server.go:919

Observation: The intersection of deadcode -test results for Linux amd64, Windows amd64, and Darwin arm64 contains 25 functions: 24 in production files and one unused test helper. The entire pkg/web/package_detection.go helper family is included, along with locale adapters, old config setters, a self-update wrapper, and SetPendingNotice.

Evidence and confidence: Analysis used golang.org/x/tools/cmd/deadcode@v0.45.0. The complete intersection is in Appendix B. Platform-specific results outside the intersection were deliberately excluded. Exported symbols may have external consumers, and custom build tags were not exhaustively analyzed; this is in-repository reachability, not proof that every public API can be deleted. Go deadcode analysis and limitations.

Impact: Unused alternate APIs and wrappers increase the search surface and invite agents to fix or reuse paths that the application never calls. Correctness-only Staticcheck does not establish that this exported surface is live.

Proposed direction: Confirm external API commitments, remove unneeded internal/public helpers, and explicitly retain any supported compatibility APIs. Add a reproducible platform-aware deadcode inventory or allowlist instead of claiming that the repository is clean from a single analyzer run.

Validation after approval: Re-run reachability with supported production roots/platforms and relevant build tags; then run normal tests and cross-builds after approved removals. Do not remove a platform-specific helper merely because Linux cannot reach it.

LowSource-confirmedAI slop, Agent DX

Unused interfaces and tests exercise mock bookkeeping instead of shipped behavior

Source: pkg/installer/interfaces.go:50; pkg/installer/mocks.go:437; pkg/installer/interfaces_test.go:451; pkg/installer/interfaces_test.go:558

Observation: ArchiveExtractor and OutputWriter have no production consumers or real implementations. Their mock implementations are used by tests that check whether the mocks recorded strings, retained a format list, reset slices, or called a configured callback. TestInterfaceCompliance wraps compile-time assignments in a runtime test.

Evidence and confidence: Repository reference searches found these two interfaces only in their declarations, mock implementations, and mock-specific assertions. Six tests beginning at TestMockOutputWriter_RecordsOutput cover this unused scaffolding, not installation or extraction behavior. Other injected downloader/filesystem/command tests do exercise real behavior and should be retained.

Impact: The scaffolding inflates the apparent test surface and creates extension points that are not actually part of the running design. It adds maintenance cost without protecting the failures demonstrated in this audit.

Proposed direction: Remove unused seams and their mock-only tests after confirming intended consumers. Keep necessary compile-time assertions at package scope. Invest focused integration coverage in durable replay, subprocess ownership, framework initialization, and real orchestration boundaries.

Validation after approval: For every retained test, identify the production invariant it can fail. Verify removal of this scaffolding leaves production behavior tests intact; avoid replacing it with tests that simply restate a new implementation.

LowSource-confirmed cleanupAI slop

Shortcut wrappers repeat platform dispatch already represented by the installer interface

Source: pkg/installer/common_handler.go:280; pkg/installer/common_handler.go:304

Observation: CreateInstallerShortcutWithOutput and CreateWebUIShortcutWithOutput repeat Windows/Darwin/Linux branches that perform the same nil check and call the same PlatformInstaller method. The interface implementation already chooses platform behavior. Some comments still describe these multi-platform wrappers as Windows-only.

Evidence and confidence: The three CreateWebUIShortcutWithOutput branches differ only in error wording; CreateInstallerShortcutWithOutput repeats the same shape. This is a concrete redundant wrapper pattern, not a recommendation to remove all delegation methods or rewrite the architecture.

Impact: Small policy changes require repeated edits, and comments make the supported behavior harder to infer. Similar low-value branching adds noise to an already large installer surface.

Proposed direction: Validate the platform installer/capability once and delegate once where behavior is truly identical. Keep explicit platform policy where it actually differs, such as Windows file associations. Correct stale comments during the approved cleanup.

Validation after approval: Use existing shortcut and platform tests plus cross-builds. A new test that only checks which identical branch called the same method is unnecessary.

LowMissing references verifiedAgent DX

The finalized historical audit depends on four missing evidence reports

Source: docs/CODEBASE_REVIEW_FINALIZED_2026-08-31.md:10; docs/CODEBASE_REVIEW_FINALIZED_2026-08-31.md:99

Observation: The finalized August review links four source/reconciliation reports that do not exist in this working tree. Its Medium/Low section explicitly delegates detailed evidence and remediation to one of those missing files.

Evidence and confidence: Missing: CODEBASE_REVIEW_2026-08-31.md; CODEBASE_REVIEW_2026-08-31_glm-5.3.md; CODEBASE_REVIEW_COMBINED_2026-08-31-gpt-5.6-sol.md; CODEBASE_REVIEW_COMBINED_2026-08-31-glm-5.3.md. The current frontend/documentation contract tests still pass.

Impact: A new reviewer or agent cannot follow the advertised evidence for the earlier completion claims. The commit named in that report also does not describe the many uncommitted remediation files by itself.

Proposed direction: Restore the intended historical artifacts or make the canonical review self-contained with stable evidence and explicit supersession links. Associate remediation evidence with the actual reviewed tree/commit. Validate real local documentation links rather than only selected source strings.

Validation after approval: Check local Markdown/HTML references from maintained reports, verify every retained finding has resolvable evidence, and distinguish historical counts from the current findings. Preserve Atlas as the status authority.

LowSource-confirmed documentation driftAgent DX

Root agent instructions mix durable rules with extensive history and stale status

Source: AGENTS.md:9; AGENTS.md:222; AGENTS.md:423; AGENTS.md:479

Observation: AGENTS.md is 499 lines, with a long session chronology, duplicated documentation indexes, old validation counts/tool versions in historical sections, and a current supported-platform list that omits the Windows arm64 artifact present in CI. Its frontend example pattern points to components affected by R14.

Evidence and confidence: The root document combines mandatory working conventions, current claims, historical narrative, and generated Atlas guidance. Reading it does not cleanly identify which claims are current or which test commands are sufficient for a particular subsystem.

Impact: Agents spend context on repeated history and can copy stale implementation patterns or mistake an old successful validation run for evidence about their current change. This is a navigation/maintenance problem, not an assertion that chronology is inherently useless.

Proposed direction: Keep root instructions focused on current invariants, Atlas workflow, repository entry points, and concise validation commands. Move history into maintained change/review documents and use narrowly scoped instructions for frontend, release, and installer work where needed. Link one canonical platform/build matrix and avoid duplicating mutable status.

Validation after approval: Walk through onboarding from atlas brief and the root instructions with a fresh checkout. Each rule, platform claim, and command should resolve to current code or authoritative documentation without relying on session history.

Validation results

CheckCommand / methodObserved result
Go behaviorgo test -count=1 ./...Passed: 28 packages with tests; two additional packages report no test files.
Go concurrencygo test -race -count=1 ./...Passed for the same package set on Linux amd64.
Go static analysismake lintPassed: go vet and Staticcheck 0.8.1 SA* correctness analyzers.
Go dependency scango run golang.org/x/vuln/cmd/govulncheck@v1.7.0 ./...No vulnerabilities found by this scan.
Module consistencygo mod tidy -diff; go mod verifyNo tidy diff; all modules verified.
Frontend behaviornpm testPassed: 21 files, 180 tests under Vitest 4.1.11.
npm dependency scannpm audit --package-lock-only --jsonZero reported vulnerabilities in the lockfile scan.
Embedded vendor freshnessnpm run vendor:frontend:checkPassed for the committed htmx and Alpine distributions.
Tailwind freshnessRebuild Tailwind to a temporary file and byte-comparePassed; committed CSS was not rewritten.
Target compilationCGO_ENABLED=0 go build ./cmd/mpv-manager for six target pairsPassed: Linux, Windows, Darwin × amd64/arm64. amd64 used GOAMD64=v2. Outputs were temporary.
Release script probeGOOS=windows GOARCH=amd64 go run ./cmd/verify-manifest -keys-onlyFailed as expected for R04: exec format error. This is a defect reproduction, not a passing release qualification.
Reachabilitydeadcode@v0.45.0 -test ./... on three target pairs25 common unreachable symbols; see R18 and Appendix B.
Targeted defect probesTemporary Go programs, Go -overlay tests, Chromium fixtureReproduced R01/R02/R03/R05/R09/R10/R12/R13/R14 and backend retention in R15.
Patch hygienegit diff --check; compare baseline SHA-256 inventoryNo whitespace errors; pre-existing source, tests, dependencies, CI, and documentation inputs stayed unchanged. Atlas regenerated TRACKING.md.

The targeted Go overlay tests intentionally assert the defective behavior to document the finding; they are temporary audit probes, not proposed regression tests. A regression test added during remediation should assert the desired corrected invariant instead. Final baseline comparison found only Atlas-generated TRACKING.md changed among pre-existing files. Application source, existing tests, dependency files, CI, and pre-existing documentation stayed byte-for-byte unchanged. TRACKING.md was not hand-edited.

Controls and prior remediation that should be preserved

Relationship to the August review and external gates

The existing finalized August report retains a historical 101-entry baseline and says 98 are repository-remediated. This audit does not rewrite that register or automatically reopen every earlier item. R01 revisits the crash-durable installer boundary previously mapped to CM-01/CM-29. R02 revisits recovery trust and pre-execution authentication. R03/R05/R07 revisit worker lifetime and cancellation. R06 shows that fixing bounded Web probes did not cover all shared update callers. R11/R16 show incomplete integration of metadata transactions and resource coordination. R18 qualifies the earlier “dead-code clean” claim. Review and map these residual findings before updating earlier completion status.

Atlas still tracks isolated signing/provenance provisioning (75ddd84a), release controls/native gates (22a13f11), and final release validation. Their current live external state was not independently rechecked. Keep them separate from this audit’s new source findings. A passed cross-build is not native installation evidence; synthetic unsigned audit fixtures are not release-signing qualification.

Recommended order after owner review

PhaseFindingsReason / exit evidence
1 — Recovery and lifecycleR01–R05Protect original bytes and executable trust; establish worker/process ownership; make the actual release script executable for all targets. Require repeated-recovery and native boundary evidence.
2 — Correct user operationsR06–R13, R16Restore bounded/cancellable work, truthful uninstall and ownership migration, coherent metadata, concurrent config preservation, and correct mpv.conf semantics.
3 — Frontend and performanceR14–R15, R17Remove duplicate initialization; bound output end-to-end; use one coherent settings snapshot. Measure requests, retained memory, and render work.
4 — Focused cleanup and agent workflowR18–R22Prune verified unreachable/scaffold code, simplify genuinely identical wrappers, restore review evidence, and make agent guidance concise and current.

Approval can be scoped by finding or phase. The next step is owner review of these reports; no fixes, dependency upgrades, refactors, native uninstall operations, publication, or implementation task execution were performed.

Appendix A — Reproduction fixtures

The following fixtures preserve the strongest evidence inside the reports so it does not depend on the lifetime of temporary files. Run standalone Go fixtures from the repository root with go run /path/to/fixture.go. They create and remove their own disposable data; Linux shell probes require /bin/sh. They intentionally demonstrate current defects. Ignore exact random temporary path names and microsecond timing differences.

R01: persisted recovery boundaries
package main

import (
	"encoding/json"
	"fmt"
	"gitgud.io/mike/mpv-manager/pkg/installer"
	"os"
	"path/filepath"
)

func main() {
	for _, phase := range []string{"intent-before-backup", "recovery-after-backup-consumed"} {
		root, e := os.MkdirTemp("", "mpv-audit-recovery-")
		if e != nil {
			panic(e)
		}
		defer os.RemoveAll(root)
		target := filepath.Join(root, "player")
		backup := filepath.Join(root, ".mpv-manager-file-backup-review")
		os.Mkdir(backup, 0700)
		os.WriteFile(target, []byte("ONLY ORIGINAL COPY"), 0600)
		journal := map[string]any{"schema": 1, "kind": "file-swap", "state": "applying", "destination": target, "backup_root": backup, "changes": []any{map[string]any{"target": target, "backup": filepath.Join(backup, "player"), "had_original": true}}}
		b, _ := json.Marshal(journal)
		os.WriteFile(backup+".journal.json", b, 0600)
		err := installer.RecoverInstallerTransactions(target)
		_, stat := os.Stat(target)
		fmt.Printf("%s: recovery_error=%v original_deleted=%v\n", phase, err, os.IsNotExist(stat))
	}
}
R02: journal-controlled backup execution
package main

import (
	"encoding/json"
	"fmt"
	"gitgud.io/mike/mpv-manager/pkg/version"
	"os"
	"path/filepath"
	"runtime"
	"strings"
)

func main() {
	root, e := os.MkdirTemp("", "mpv-audit-update-")
	if e != nil {
		panic(e)
	}
	defer os.RemoveAll(root)
	os.Setenv("XDG_CONFIG_HOME", filepath.Join(root, "config"))
	target := filepath.Join(root, "mpv-manager")
	os.WriteFile(target, []byte("ORIGINAL"), 0755)
	id := "01950000-0000-7000-8000-000000000001"
	dir := filepath.Join(root, ".mpv-manager-update-"+id)
	os.Mkdir(dir, 0700)
	marker := filepath.Join(root, "unexpected-execution")
	backup := filepath.Join(root, ".mpv-manager.update-"+id+".backup")
	script := "#!/bin/sh\n: > '" + marker + "'\necho '{\"product\":\"not-a-manager\"}'\n"
	os.WriteFile(backup, []byte(script), 0755)
	journal := map[string]any{"schema_version": 1, "id": id, "state": "applying", "lock_path": target + ".update.lock", "helper_path": filepath.Join(dir, "mpv-manager-update-helper"), "health_path": filepath.Join(dir, "health.json"), "payload_path": filepath.Join(dir, "manager-payload"), "manifest_key_id": "not-a-trusted-key", "expected_size": 1, "expected_blake3": "blake3:" + strings.Repeat("0", 64), "expected_identity": map[string]any{"product": version.ProductID, "component": version.ComponentID, "version": "1.3.0", "goos": runtime.GOOS, "goarch": runtime.GOARCH}, "targets": []any{map[string]any{"role": "primary", "path": target, "staged_path": filepath.Join(root, ".mpv-manager.update-"+id+".new"), "backup_path": backup, "applied": true}}}
	b, _ := json.Marshal(journal)
	os.WriteFile(filepath.Join(dir, "transaction.json"), b, 0600)
	version.RecoverSelfUpdateTransactions(target)
	_, stat := os.Stat(marker)
	original, _ := os.ReadFile(target)
	fmt.Printf("forged unsigned recovery journal: backup_executed=%v original_preserved=%v\n", stat == nil, string(original) == "ORIGINAL")
}
R05: descendant mutation after cancellation
package main

import (
	"context"
	"fmt"
	"gitgud.io/mike/mpv-manager/pkg/installer"
	"os"
	"path/filepath"
	"time"
)

func main() {
	root, _ := os.MkdirTemp("", "mpv-audit-cancel-")
	defer os.RemoveAll(root)
	marker := filepath.Join(root, "child-write")
	ctx, cancel := context.WithTimeout(context.Background(), 100*time.Millisecond)
	defer cancel()
	cr := installer.NewCommandRunnerWithContext(ctx, make(chan string, 50), make(chan error, 10))
	start := time.Now()
	err := cr.RunCommand("/bin/sh", "-c", "(sleep 0.6; echo survived > '"+marker+"') & wait")
	_, stat := os.Stat(marker)
	fmt.Printf("deadline=100ms elapsed=%s error=%v child_mutated_after_cancel=%v\n", time.Since(start).Round(time.Millisecond), err, stat == nil)
}
R12/R13: settings round-trip
package main

import (
	"fmt"
	"gitgud.io/mike/mpv-manager/pkg/config"
	"os"
	"path/filepath"
)

func main() {
	root, _ := os.MkdirTemp("", "mpv-audit-config-")
	defer os.RemoveAll(root)
	os.Setenv("XDG_CONFIG_HOME", root)
	dir := filepath.Join(root, "mpv")
	os.MkdirAll(dir, 0700)
	file := filepath.Join(dir, "mpv.conf")
	config.Load()
	for _, body := range []string{"screenshot-avif-opts=crf=20,speed=6\n", "[special]\nscale=bilinear\n", "hwdec=no\nhwdec=auto\n"} {
		os.WriteFile(file, []byte(body), 0600)
		if body[0] == 's' {
			fmt.Printf("scalar_read=%q\n", config.GetConfigValue("screenshot-avif-opts"))
		} else {
			err := config.SetConfigValue("hwdec", []string{"nvdec"}, true)
			after, _ := os.ReadFile(file)
			fmt.Printf("set_error=%v config_after=%q\n", err, after)
		}
	}
}
R03: background job survives shutdown

Package web probe. Save this outside the repository, then use a Go overlay mapping an otherwise absent pkg/web/audit_review_test.go to that absolute file path. Run go test -overlay=/absolute/overlay.json ./pkg/web -run TestAudit -v. The overlay JSON has the shape {"Replace":{"/absolute/repo/pkg/web/audit_review_test.go":"/absolute/probe_test.go"}}. No checked-in test file is required.

package web

import (
	"testing"
	"time"
)

func TestAuditShutdownLeavesJobAlive(t *testing.T) {
	jm := NewJobManager()
	job := jm.CreateJob("install", "mpv-binary", "MPV")
	server := &Server{jobManager: jm, shutdownCh: make(chan struct{})}
	start := time.Now()
	err := server.Shutdown()
	t.Logf("shutdown_error=%v elapsed=%s job_context_cancelled=%v active_jobs=%d", err, time.Since(start), job.Context().Err() != nil, len(jm.GetActiveJobs()))
	if err != nil || job.Context().Err() != nil || len(jm.GetActiveJobs()) != 1 {
		t.Fatal("reproduction changed")
	}
	job.Cancel()
}
R09/R10/R15: ownership, concurrent UI edit, and output retention

Package installer probe. Save this outside the repository, then use a Go overlay mapping an otherwise absent pkg/installer/audit_review_test.go to that absolute file path. Run go test -overlay=/absolute/overlay.json ./pkg/installer -run TestAudit -v. The overlay JSON has the shape {"Replace":{"/absolute/repo/pkg/installer/audit_review_test.go":"/absolute/probe_test.go"}}. No checked-in test file is required.

package installer

import (
	"bytes"
	"gitgud.io/mike/mpv-manager/pkg/config"
	"os"
	"path/filepath"
	"testing"
)

func TestAuditLegacyOwnershipRefusal(t *testing.T) {
	dir := t.TempDir()
	os.WriteFile(filepath.Join(dir, "mpv.exe"), []byte("existing player"), 0600)
	err := validateWindowsInstallOwnership(dir)
	t.Logf("existing_install_without_new_manifest: %v", err)
	if err == nil {
		t.Fatal("reproduction changed")
	}
}
func TestAuditUnboundedOutputLine(t *testing.T) {
	capture := &outputCapture{}
	chunk := bytes.Repeat([]byte("x"), 64*1024)
	for range 64 {
		capture.Write(chunk)
	}
	t.Logf("single_unterminated_line_retained_bytes=%d", len(capture.pending))
	if len(capture.pending) != 4*1024*1024 {
		t.Fatal("reproduction changed")
	}
}

func TestAuditUIUpdateLosesConcurrentEdit(t *testing.T) {
	root := t.TempDir()
	t.Setenv("XDG_CONFIG_HOME", filepath.Join(root, "state"))
	live := filepath.Join(root, "mpv")
	opts := filepath.Join(live, "script-opts")
	os.MkdirAll(opts, 0700)
	path := filepath.Join(opts, "modernz.conf")
	os.WriteFile(path, []byte("old-user-setting"), 0600)
	inst := NewInstaller(ReleaseInfo{}, live)
	cr := NewCommandRunner(make(chan string, 100), make(chan error, 10))
	config.Load()
	err := inst.updateUIWithPreservedConfig(cr, live, "modernz", func(stage string) error {
		os.MkdirAll(filepath.Join(stage, "script-opts"), 0700)
		os.WriteFile(filepath.Join(stage, "script-opts", "modernz.conf"), []byte("upstream-default"), 0600)
		return os.WriteFile(path, []byte("saved-while-download-runs"), 0600)
	})
	after, _ := os.ReadFile(path)
	t.Logf("update_error=%v final_config=%q concurrent_edit_lost=%v", err, after, string(after) == "old-user-setting")
	if err != nil || string(after) != "old-user-setting" {
		t.Fatal("reproduction changed")
	}
}
R14: real Alpine initialization fixture

Save this HTML at the repository root in a disposable copy, or adapt the two script paths to absolute file URLs. Open with Chromium using file access enabled. The rendered counter is {"fetches":2,"intervals":2} in the reviewed tree. The audit’s fixture loaded the exact authored Tasks script and committed Alpine bytes.

<!doctype html><html><body><pre id="result">pending</pre><div x-data="tasksPage()" x-init="init()"></div><script>
window.counts={fetches:0,intervals:0};window.MPVUtils={apiFetch:async()=>{counts.fetches++;return {ok:true,data:{active:[],recent:[]}}}};const nativeInterval=window.setInterval;window.setInterval=(...args)=>{counts.intervals++;return nativeInterval(...args)};
window.addEventListener('load',()=>setTimeout(()=>document.getElementById('result').textContent=JSON.stringify(counts),10));
</script><script src="./internal/webassets/static/tasks-page.js"></script><script defer src="./internal/webassets/static/js/alpine.min.js"></script></body></html>

Observed key outputs:

R01: original_deleted=true (both constructed boundary states)
R02: backup_executed=true original_preserved=true
R03: shutdown_error=<nil> job_context_cancelled=false active_jobs=1
R04: fork/exec .../verify-manifest.exe: exec format error
R05: deadline=100ms elapsed=602ms child_mutated_after_cancel=true
R09: refusing to modify populated directory without .mpv-manager-owned.json ownership proof
R10: update_error=<nil> final_config="old-user-setting" concurrent_edit_lost=true
R12: config_after="[special]\nscale=bilinear\n\nhwdec=nvdec"
R13: scalar_read=["crf=20" "speed=6"]
R14: {"fetches":2,"intervals":2}
R15: single_unterminated_line_retained_bytes=4194304

Appendix B — Common unreachable symbols

Reproduce with go run golang.org/x/tools/cmd/deadcode@v0.45.0 -test ./... on Linux. For other targets, build the analyzer for the host first, then run that host executable with GOOS=windows GOARCH=amd64 and GOOS=darwin GOARCH=arm64. This deliberately avoids the build-tool error described in R04. Compare the intersection, not the union.

internal/assets/mpv.go:108:6: unreachable func: ExtractPNGIcon
pkg/config/config.go:1185:6: unreachable func: UpdateInstalledAppUIType
pkg/config/config.go:1243:6: unreachable func: UpdateInstalledAppManaged
pkg/config/config.go:625:6: unreachable func: SetCurrentUIType
pkg/config/config.go:632:6: unreachable func: GetCurrentUIType
pkg/constants/paths.go:336:6: unreachable func: GetMPVConfigBackupDirWithHome
pkg/constants/paths.go:84:6: unreachable func: GetWindowsPathPreference
pkg/hotkeys/hotkeys.go:206:6: unreachable func: SearchHotkeys
pkg/hotkeys/hotkeys.go:233:6: unreachable func: matchAliases
pkg/hotkeys/inputconf.go:170:6: unreachable func: WriteInputConf
pkg/installer/common_test.go:714:31: unreachable func: TestCommandRunner.GetOutputMessages
pkg/version/version.go:449:6: unreachable func: UpdateSelfFromCheckWithProgress
pkg/web/locale.go:273:6: unreachable func: GetCommonLanguages
pkg/web/locale.go:302:6: unreachable func: GetAllLanguages
pkg/web/locale_utils.go:110:6: unreachable func: extractFlagEmoji
pkg/web/locale_utils.go:34:6: unreachable func: ConvertToWebOption
pkg/web/locale_utils.go:50:6: unreachable func: ConvertToWebOptionSlice
pkg/web/models.go:255:6: unreachable func: LanguageName
pkg/web/package_detection.go:15:6: unreachable func: IsFlatpakAvailable
pkg/web/package_detection.go:27:6: unreachable func: IsBrewAvailable
pkg/web/package_detection.go:38:6: unreachable func: IsPackageManagerAvailable
pkg/web/package_detection.go:51:6: unreachable func: GetPackageManagerCommand
pkg/web/package_detection.go:9:6: unreachable func: IsCommandAvailable
pkg/web/package_version.go:85:6: unreachable func: GetAvailableVersion
pkg/web/server.go:919:18: unreachable func: Server.SetPendingNotice

Appendix C — Cited-file fingerprints

SHA-256 values below identify the pre-existing files cited by findings. Report files themselves are intentionally excluded. The full 798-file starting inventory and raw validation logs remain locally in /tmp/mpv-manager-audit-20260905; the findings and reproduction code above are self-contained.

Reviewed pathSHA-256
.gitlab-ci.ymlbf01232d64d38b152bebd5fe0f812013731d31241e0e0d80c0c50aef69e163f7
AGENTS.md4277872c6b747cc4119bbc0dedc38ae5240ce76b239cb5c4ab9fe7caffd028a1
cmd/mpv-manager/main.goe7d0d4ad39c1e704c3cbb9d518da7d1cf0a661398789cd3c00e0d4e0bd10e572
docs/CODEBASE_REVIEW_FINALIZED_2026-08-31.mde2b42110a6aea353f2b74bb761794d68166309cb77d7ded4dba47b9d2b594350
internal/scriptopts/scriptopts.goffd35159c548e184c80bb573cc150bd9405bf61e2864a710e0228c83f73a284e
internal/webassets/static/config-page.jsc010de32497c8ce5e7bbfcd884c3e6240f0672b0b2770c9f0eae8cec1917fe0a
internal/webassets/static/jobs-modal.js17594478ba963997602bd48808273795426b16fa7ac0a1c19725b913d10bc5f4
internal/webassets/static/jobs.jscfe949b02726941ea0bf110edee0e635f57a3ae0152218b4fa20c1f425f67a0e
internal/webassets/static/tasks-page.jscc0bdd179531c99ee1e468779770b998ea1524aa7cd888d4e6d5f68b01d53fbc
internal/webassets/templates/base.htmlbee3487151662babfa1b5f4d2fd41c88fa25bcb6927c1090cf7e9613e1aeb89e
internal/webassets/templates/hotkeys.htmlb264b8f4cecb6871482a174cbc76256ee131136f1136ef7822d398e39411ff4c
internal/webassets/templates/tasks.htmlbf69b6a41c77872bf22dfbfbf2750e302282bd63742f0dffd9365bdb418cdbdf
pkg/config/config.goeedf3c98669d13390d08b65e428da2712fa88a31c299fbdaf98209fa4f815dcf
pkg/config/editor.go7aecf60285fc829c7b579284691326312fdb431703f1ba467385fd04e2cd5eb6
pkg/installer/command_runner.goed2cb603201c5b01e2b89a55de364404ea7f965691796a51173d13731ffb10a5
pkg/installer/common.go0cdb09fefd7313b255ad3adf620686aa06f1ad3167ff87ba73f58d28602cdeae
pkg/installer/common_handler.go53397858db4419ac5ab7a4fc5d58751704012449e03887544778ea053bb9290c
pkg/installer/file_transaction.go73dc5c00a8d6a9b0cc62feaaf5b560fb751cf0fa3f82a8f031a00fff9fa5cb63
pkg/installer/installer.go6a6b7b9a3e5849ea7d74532729245d28e1588e10114527b679f2df10c2b2b251
pkg/installer/interfaces.gob698399eeee476b553adef3427a8e060475c7339a433b141623d53db25b12b27
pkg/installer/interfaces_test.go6d60bafaf4254f888da541bedbd58a49ac01f9eccd78e7120022deced5b13ff3
pkg/installer/mocks.go985645ceb27ba218c4393649db0bfeba25cb3379e6b8fb209130e299ceb7535d
pkg/installer/transaction_journal.go47249c003f2ad2523c731c8b07489bb95a64783f17930fe25c7de62fed19a4c6
pkg/installer/ui_config_update.go641dde6cdbdcf7e7ebe4a4be9d9a92e9f0b543223dccb1dcd42052c3ae769571
pkg/installer/windows.goe065fb452e468c175cd84388565ef76c05b0ca77da58958b39ea7c2a27ff7b75
pkg/installer/windows_ownership.go373bde6e8bd6d42e828cf70774ce6cbe02629bac74e44370e90ae16d4f569f02
pkg/version/transaction.god9dbb2305b82c4eb2f49d5fda5fc636fc0e1c3124938d604de1cdb083b745249
pkg/version/updates.go213af237c92c6ffd9a0caa73106fc9783feb3bf46af9e06b0f3bc9c689256b72
pkg/version/version.go0c11427d52d0d79101f97238515a13c4e8a8b4b4861c9ec215ebe05fadbeac29
pkg/web/api.gobf306a6ee4f42a30f6090c06d6568344c4862a6496d407586be3937486cfe0a0
pkg/web/api_adopt.go11388bece87d9310c7a6fcc9c5104d5d36405fc979fbae599ebb124182eba0bb
pkg/web/api_config.go7c1745a679ce08db742bf1a5bc7b1d3cba13a0e90d0ccafc82b82e2504eda85a
pkg/web/api_install.go60ce5be29e7272c181fe110d699f7135491b1a2af3064a8b0bf7947fffad0399
pkg/web/api_settings.go1d921c558361dae915fa22cc58c703ab1431db5a7a48b7595aa64a646a839a0d
pkg/web/jobs.go376bc28a74753c6edd7751b6d2b2fc450a2326a9adf166fa96a07c2f739dde8d
pkg/web/locale_utils.go901f80a0045ea58ef488cacaab629d390f61790e3f673f3dcde20e95961de374
pkg/web/package_detection.go (removed by R18; baseline 346f272)af0de100221614c7120e42a8b0e8c1bf0036e802b730af556aaedf5ecb00847e
pkg/web/package_version.go1192dba7111b2f8bf6ac7cd2c9ccf1154c387289216bed35403e3e028c44ea5c
pkg/web/server.go7a7a0628977a7cddd514407752158f354041fdcced4fd789e97830195d54762b
pkg/web/server_version_cache.go4bbd46480581fe074595a53a7daa7cfb7564ab4e98758adc83bb3636170d6a65