Canonical remediation register · 2026-08-31

MPV.Rocks Installer
Finalized Combined Review

One normalized, evidence-backed register derived from both deep reviews and both peer reconciliations, with every retained finding assigned to Atlas.

41Corroborated clusters
10Prior-review only
50GLM-only after dedupe
2Claims not upheld
8Severity changes resolved

Final severity totals — 101 actionable entries under one severity model

0Critical
25High
56Medium
20Low / hardening
101Total actionable

MPV.Rocks Installer — Finalized Combined Codebase Review

Finalized: 2026-08-31
Reviewed baseline: bdfb31b95030c2d992e5cfc4cb0ba5bada368d1b (master)
Canonical status: approved remediation register
Atlas umbrella task: c42ba4a7 — finalize the review, map findings, and begin remediation
HTML companion: CODEBASE_REVIEW_FINALIZED_2026-08-31.html

Inputs and finalization rule

This report is the canonical reconciliation of:

The GLM reconciliation is intentionally broad and adversarial; the GPT reconciliation is intentionally deduplicated and conservative. This final report preserves GLM's useful confidence-tier perspective while applying one reproducible severity definition and counting remediation units rather than raw reviewer observations.

The rules are:

  1. Repeated descriptions of one root cause count once.
  2. Closely coupled observations count as one cluster only when they require the same implementation boundary.
  3. A release blocker can be remediation priority P0 without being severity Critical.
  4. External GitLab settings, roles, native signing state, and publication controls are conditional unless observable in the repository.
  5. Historical immutable-client behavior is documented separately from current-code defects.
  6. Every retained finding must map to an Atlas task.

Final outcome

Cross-review overview

Category Count Meaning
Corroborated clusters 41 Independently identified in both source reviews
Unique to the prior review 10 Retained after source re-verification
Unique to GLM-5.3 50 Retained after deduplication and source tracing
Claims not upheld 2 Behavior exists, but the claimed vulnerability does not follow
Severity changes resolved 8 Normalized under the definitions below

The first three categories partition the 101 actionable entries/clusters. They are not derived by adding or subtracting the source reports' raw totals; GLM's 154 labels include repeated cross-area observations.

Final severity totals

Severity Count Definition
Critical 0 Directly exploitable or unrecoverably destructive without an additional intended trust/privilege decision
High 25 Plausible privilege, supply-chain, destructive-data, wrong-target, indefinite-availability, or authoritative-state failure
Medium 56 Material correctness, recovery, concurrency, portability, accessibility, or defense-in-depth defect
Low / hardening 20 Limited-impact correctness, UX, documentation, test, or maintainability cluster
Total actionable 101 Deduplicated remediation entries/clusters

Final severity and claim decisions

Topic Final decision Rationale
TUI relaunch inherits helper.log and acknowledges health early High; P0 remediation It can commit a broken relaunch and capture the terminal, but it is not independently a privilege compromise or irreversible destruction. GLM's Critical label is not retained.
Signed manager manifest hashes registry re-downloads Medium, conditional Provenance is weaker than signing pipeline-local bytes, but the signature still authenticates the bytes fetched. High impact depends on external registry overwrite roles/settings.
Job conflict scope, false persistence success, config mutation rollback High These make destructive core-flow state non-authoritative and can overlap or later persist rejected mutations.
TUI Escape/Ctrl+C worker abandonment High Both inputs share one systemic cancellation/ownership failure affecting active destructive work.
Hotkey quoted-comment/duplicate handling Medium Valid bindings can be corrupted or remain unexpectedly active; this is more than cosmetic cleanup.
Qualifier driver containment Low It is development-only and requires explicit hidden qualification flags.
v1.1/v1.2 unauthenticated bootstrap Historical limitation Immutable old clients cannot gain current signature verification; the supported boundary is documented one-time manual replacement.
Unknown JSON fields are outside the signature Not upheld Unknown fields are ignored and cannot alter behavior; every field consumed by the current schema is canonicalized and signed. Strict decoding is optional hardening.
HTTPS redirects bypass integrity Not upheld as a vulnerability Redirect policy may be tightened, but signed manifests and authenticated size/hash verification still protect trusted behavior.

High findings and Atlas ownership

ID Final finding Primary evidence Atlas task
CH-01 Windows elevates a mutable install-tree batch file. pkg/installer/windows.go:160-212 e8edb50e
CH-02 Windows uninstall recursively removes unrelated contents from a user-selectable directory. pkg/installer/windows.go:103-157 e8edb50e
CH-03 TUI update/uninstall loses selected app identity and can target another installation. pkg/tui/models_types.go:141-148; models_update.go:438-446 e8edb50e
CH-04 Windows custom installs and settings APIs resolve different portable_config trees. pkg/constants/paths.go:47-79,306-319 e8edb50e
CH-05 Web cancellation archives a terminal result before the worker reaches or rejects commit. pkg/web/jobs.go:482-543 a7cae2ff
CH-06 Job exclusion is method-based instead of resource-based. pkg/web/jobs.go:256-279 a7cae2ff
CH-07 Operations report success when authoritative tracking persistence fails. Web install/adopt workers; TUI completion paths a7cae2ff
CH-08 Failed manager-config writes leak rejected mutations into live state. pkg/config/config.go setter families e63624dc
CH-09 Manager-config read errors are treated as absence and can be replaced with defaults. pkg/config/config.go:85-149 e63624dc
CH-10 mpv.conf restore is non-transactional and can leave the active file absent. pkg/installer/installer.go:1165-1195 e63624dc
CH-11 The package-version timeout cannot terminate blocked probes. pkg/web/server_version_cache.go:249-326 33b25a4a
CH-12 IINA validates one DMG but copies from a global hard-coded mount path. pkg/installer/macos.go:422-475 527118d9
CH-13 Tagged application code receives the long-lived release signing key. .gitlab-ci.yml:284-317,477-506 75ddd84a
CH-14 Unauthenticated upstream “latest” bytes are promoted into first-party signed trust. cmd/generate-info/main.go:358-448,948-977 75ddd84a
CH-15 Relaunched TUI inherits helper-log output and acknowledges health before readiness. pkg/version/transaction.go:349-358,466-488; cmd/mpv-manager/main.go:154-184 6bfdc713
CH-16 FFmpeg replacement failure can delete the only known-good backup. pkg/installer/installer.go:525-614 527118d9
CH-17 TUI language apply can replace the full live mpv.conf with defaults. pkg/tui/language_preferences.go:823-859 e63624dc
CH-18 Updater executes staged/replaced code before its helper-side digest recheck. pkg/version/transaction.go:512-519 6bfdc713
CH-19 Apply and rollback create kill windows with no executable at the primary pathname. pkg/version/transaction.go:521-526,575-597 6bfdc713
CH-20 A missing backup for an applied target is treated as successful rollback. pkg/version/transaction.go:575-597 6bfdc713
CH-21 TUI Escape/Ctrl+C abandon active work instead of cancelling and joining it. pkg/tui/models_update.go; models_messages.go 57a2c7cf
CH-22 TUI multi-channel streaming can lose completion or trailing output. pkg/tui/models_messages.go:324-375 57a2c7cf
CH-23 “Change MPV UI” performs a full install against the first MPV record. pkg/tui/models_update.go:1148-1170,1724-1740 57a2c7cf
CH-24 Enter used to accept a list filter can also activate the selected action. pkg/tui/models_update.go list dispatch 57a2c7cf
CH-25 Recommended-config install/reset proceeds after preservation/backup failure. pkg/installer/installer.go:1060-1107 e63624dc

Medium and Low remediation map

The detailed evidence and per-item remediation for CM-01–CM-56 and CL-01–CL-20 remain in the normalized combined review. This table is the authoritative Atlas ownership map.

Atlas task Priority Finding IDs Implementation boundary
7b114046 P1 CM-01, CM-29 Archive staging and crash-durable installer transactions — complete
b0ce0058 P1 CM-02, CM-03, CM-30–CM-33, CM-54, CM-55 Updater locking, journaling, durability, identity, outcome, and trust lifecycle — complete
7ae284c4 P1 CM-05, CM-06, CM-09, CM-12–CM-14 Cross-process config/history, backups, and migration coordination — complete
b5874805 P1 CM-07, CM-08, CM-10, CM-21–CM-23, CM-25, CM-26 Web SSE, modal, password, config, language, and locale concurrency — complete
b2b8ccff P1 CM-04, CM-27, CM-28, CM-42–CM-46 Platform install detection, MPC-QT, CPU/GPU detection, and locale integrity — complete
9e257733 P1 CM-34–CM-40, CM-56 TUI progress, output, bookkeeping, offline startup, Unicode, and terminal safety — complete
22a13f11 P1 CM-11, CM-15, CM-18–CM-20, CM-50–CM-53 Release checksums, artifacts, resources, tags, native gates, and trusted builds — repository controls complete; external gate open
96f6eca6 P1 CM-17, CM-24, CM-41, CM-47–CM-49 CLI paths/parsing, script-option round trips, and bind/browser lifecycle — complete
78a290dc P2 CM-16, CL-01–CL-20 Accessibility, frontend hardening, documentation, tooling, and remaining Low clusters — complete

Cross-cutting conclusions

  1. Ownership must be explicit. Paths, install records, privileged helpers, config trees, worker lifetimes, and terminal results currently rely too often on global or inferred ownership.
  2. A transaction ends only when durable state and user-visible state agree. Logging a persistence or backup failure and returning success is not a valid terminal outcome.
  3. Recovery must survive the process that performs the mutation. In-memory rollback and startup recovery cannot protect a primary pathname that temporarily does not exist.
  4. Signing is necessary but not sufficient provenance. The bytes accepted by the signer should be the reviewed pipeline-local bytes, sourced from pinned/verified upstream inputs.
  5. High-risk seams are under-tested. Native crash points, cancellation at commit, browser reconnect/focus, terminal descriptor ownership, parser round trips, and cross-process contention account for a disproportionate share of the findings.

Remediation order

Gate 1 — destructive ownership and launchability

Atlas tasks e8edb50e, e63624dc, 527118d9, and 6bfdc713 are complete. Retain native Windows/macOS validation and expanded power-loss fault injection as release gates.

Gate 2 — worker lifecycle and authoritative results

CH-11 task 33b25a4a, CH-05–CH-07 task a7cae2ff, and CH-21–CH-24 task 57a2c7cf are complete. Ordered-stream, exact-selected-app, terminal-ownership, and filter-routing regressions now protect this gate.

Gate 3 — supply-chain provenance

The repository-side portion of 75ddd84a and release task 22a13f11 is implemented: tag-bound reviewed upstream locks, pipeline-local manager hashes, registry byte comparison, OIDC submission to a signer outside tagged application trust, digest-pinned CI images, protected canonical-SemVer rules, serialized duplicate-refusing publication, and a protected approval that binds exact native evidence to the Windows/macOS artifact digests. Keep both tasks open until the isolated service, a real approved tag lock, protected environment/tag policy, registry immutability, and native-evidence workflow are provisioned and exercised.

Gate 4 — reliability and platform correctness

Updater task b0ce0058 is complete: one user-wide lock covers every executable target; intent is journaled before staging; safe pre-journal orphans no longer block later recovery; committed targets are revalidated before rollback evidence is deleted; current secondary identity and child termination are proven; detached outcomes replace truthful handed_off task records; update selections carry opaque verified-manifest proof; and stable metadata has persistent anti-replay/rollback/equivocation state plus build floors, key epochs, and revocation.

Installer transaction task 7b114046 is complete: ZIP, tar, gzip, xz, and 7z extraction uses native bounded parsing into private sibling staging; ZIP/tar/7z inventories reject traversal, non-portable names, links/special files, case collisions, file-as-parent layouts, entry-count overflow, and expanded-size overflow before output. uOSC has a reviewed-path allowlist. Overlay, whole-path, regular-file, and managed-UI replacements persist exact intent under a cross-process parent lock, sync before commit, and are rolled back at startup after validated journal recovery.

Configuration coordination task 7ae284c4 is complete: manager configuration and job history serialize complete read/modify/write cycles across processes and publish unique durable replacements; manager mutations rebase on the latest disk snapshot, while malformed history is retained under a unique quarantine name. Config and language APIs validate complete requests and commit one mpv.conf snapshot. Backup restore/delete is flat-file-only and descriptor-relative beneath a validated real conf_backups directory. ModernZ migration apply uses a strict intent journal, cross-resource serialization, compare-and-set resolution, synchronous rollback, and startup recovery.

CLI/parser/startup task 96f6eca6 is complete: mode conflicts, stray positionals, and incompatible flags fail explicitly; custom destinations are accepted only by Windows portable MPV methods that actually consume them; verbose/debug logging reaches stderr from startup. Unix and Windows PATH registration is idempotent and rollback-capable across files, shell/registry state, and manager metadata. MPV, hotkey, and script-option parsing shares a quote-aware comment lexer; script-option writes preserve BOM, newline, permission, and ownership metadata while refusing symlinks. Web startup binds synchronously and publishes exactly one listener before browser/banner activity.

Web concurrency task b5874805 is complete: shutdown closes the SSE broadcaster/root signal before bounded HTTP drain; every connection receives an authoritative active-plus-recent snapshot; bounded client queues prioritize terminal/status state. Stored-password flows dispatch once, Config Apply retains edits made while saving, modal focus waits for Alpine visibility, sudo validation invalidates cached credentials, and locale cache publication is immutable. UI-setting mutations serialize per key, while regional-language requests use monotonic request ownership so stale completions cannot overwrite newer intent.

Platform detection task b2b8ccff is complete: Windows discovery never executes candidate binaries; package probes are locale-stable, time/output bounded, and produce explicit uncertainty; synchronization preserves multiple method/path identities and removes only a proven exact absence. MPC-QT waits, propagates the native child result, and verifies the installed executable. Linux GPU discovery aggregates GLX, Vulkan, and PCI adapters without truncating trademarked model names, resolves sysfs PCI IDs, and combines hybrid capabilities. Hotkey duplicate edits are complete and # cannot serialize as a key; every common locale code resolves through a canonical 2-/3-letter code and the audited regional data is integrity-tested.

TUI task 9e257733 is complete: every detached operation uses a panic-to-result lifecycle and disables interactive sudo while Bubble Tea owns raw terminal mode. Output is terminal-sanitized before display and shared-history persistence, retained in a bounded amortized buffer, refresh-coalesced, keyboard/mouse scrollable, and reflowed with every list at safe dimensions. One post-first-frame manifest refresh supplies both installer and manager-update state with explicit offline behavior. Stable selected IDs persist update versions, including MPC-QT; progress and Unicode deletion use the correct fractional/rune semantics.

Low/hardening task 78a290dc is complete at the repository boundary. The loopback UI now emits a restrictive CSP, forbids inline scripts/native event attributes, disables htmx script-tag execution, and externalizes page behavior; Alpine/htmx expression evaluation and existing dynamic styles retain narrowly documented unsafe-eval/unsafe-inline exceptions. Local release packaging runs locked frontend install, vendor/CSS freshness, and tests. Script-option snapshots use revision/CAS writes, SSE clients and writes are bounded, Web routes and asynchronous state ownership are validated, and installer/updater/shortcut/lifecycle edge cases are hardened. Staticcheck SA and dead-code checks are clean, the tool version is pinned in Make and CI, aggregate coverage is parsed correctly, documentation contracts are tested, public catalogs return copies, parent-directory durability/metadata retention are enforced, and the qualifier requires a controller capability inside an owned disposable root. Alpine was refreshed from 3.16.3 to the current exact 3.17.1 pin with the embedded artifact regenerated.

Validation baseline

The source reviews collectively reported clean normal/race/shuffle Go suites, vet, formatting/tidy/module verification, govulncheck, 157 frontend assertions, npm audit, vendor freshness, six cross-builds, and local Web auth/route smoke checks. During the GPT reconciliation, the full Go suite, focused race suite, vet, and all 157 frontend tests were rerun successfully.

Those green results establish a regression baseline, not absence of defects. Most retained findings require failure injection, inter-process contention, native platform behavior, real browser timing, PTY behavior, or kill-point testing that the existing suite does not cover.

The initial remediation batch was validated again on its resulting working tree:

The first race run exposed a test-hook cleanup race in the new blocked-probe regression. Probe functions are now snapshotted before workers launch; the focused race suite passed after that correction.

The CH-01–CH-04 remediation was then validated on the same working tree:

The CH-08–CH-10, CH-17, and CH-25 remediation was validated with the full normal and race Go suites, go vet ./..., Windows amd64 cross-compilation for the affected packages, and focused fault-injection regressions. Manager-config candidates are published only after persistence; non-absence read errors retain and freeze the last known-good state; config reset, recommended-config installation, restore, and language changes require unique durable recovery copies and atomic replacement. The same work also closes CM-12's ignored manager-reset backup failure.

The CH-12 and CH-16 remediation passed focused normal/race tests, go vet, and Darwin arm64/amd64 plus Windows amd64 test-binary cross-compilation. IINA now mounts read-only under an owned root, parses and validates the exact returned device/mount pair, checks bundle ID, Developer ID signature presence, and architecture, and detaches that device. FFmpeg now uses a destination-adjacent fsynced and byte-verified stage, validates AMD64 PE structure, and retains the old executable until post-swap validation and durable version persistence both succeed; injected restore failure retains and reports the recovery backup.

The CH-05–CH-07 remediation passed the full normal, race, and shuffled Go suites, go vet ./..., all 167 frontend assertions, frontend-vendor freshness, JavaScript syntax checks, and Windows amd64 plus Darwin arm64/amd64 test-binary cross-compilation for affected packages. Cancellation is now a nonterminal request until the worker acknowledges a safe stop, is rejected after an explicit commit boundary, and retains resource leases throughout. Background jobs and synchronous mutations share atomic resource leases across installer, manager config, MPV config, install target, package manager, and keyring state. Physical success followed by tracking-persistence failure is exposed and persisted as an explicit partial reconciliation outcome in both Web and TUI flows.

The CH-21–CH-24 remediation passed the full normal, race, and shuffled Go suites, go vet ./..., git diff --check, all 167 frontend assertions, frontend-vendor freshness, and Windows amd64 plus Darwin arm64/amd64 cross-compilation for the affected TUI/version packages. Escape and Ctrl+C now cancel and join the owned worker before navigation or exit; terminal results cannot overtake trailing output. “Change MPV UI” requires an exact stable app selection and performs only the UI/config transaction, and list filter Enter/Escape is consumed before application action dispatch.

The CH-15 and CH-18–CH-20 remediation passed the full normal, race, and shuffled Go suites, go vet ./..., git diff --check, all 167 frontend assertions, frontend-vendor freshness, the Linux native-PTY terminal relaunch regression, the expanded seven-case native updater qualifier, and Windows amd64/arm64 plus Darwin arm64/amd64 cross-compilation. Helper and relaunched TUI processes retain the initiating terminal, and health is acknowledged only after Bubble Tea's first rendered frame. Candidate size/digest is checked immediately before every identity execution; apply/restore use never-absent platform replacement; original target evidence is journaled; and missing, corrupted, or unverifiable backups produce rollback failure rather than a false success.

The repository-side CH-13/CH-14 and CM-19 work passed the full normal Go suite, go vet ./..., git diff --check, focused race tests, and a CGO-free generator build. pkg/releaseprovenance strictly decodes a tag/version-bound review lock; unattended generation cannot use upstream “latest,” rejects missing/extra/mismatched pins, and hashes manager entries from build-job artifacts. CI byte-compares registry uploads, generates an unsigned candidate, rejects legacy raw signing-key variables, and submits candidate plus lock under a short-lived GitLab OIDC assertion. Completion remains externally gated on deploying and validating the isolated signer and release policies described in docs/RELEASE_SIGNING_SERVICE.md.

The CM-02/CM-03/CM-30–CM-33/CM-54/CM-55 updater pass passed the full normal, race, and shuffled Go suites; go vet, gofmt, tidy/module verification, and git diff --check; all 167 frontend assertions, npm audit, and vendor freshness; Windows amd64/arm64 and Darwin amd64/arm64 application plus affected-package cross-builds; the build-tagged qualifier tests; and all seven Linux native updater cases. Regressions cover authenticated hash and length rejection before mutation, intent-before-download journaling, safe orphan cleanup that continues to later transactions, committed-target revalidation/rollback, opaque selection mutation rejection, stable-manifest replay/rollback/equivocation, build floors/key epochs/revocation, durable helper outcome read/clear, origin-task binding, and handed-off history replacement.

The CM-01/CM-29 archive and installer-transaction pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, and git diff --check; all 167 frontend assertions, npm audit, and vendor freshness; Windows amd64/arm64 and Darwin amd64/arm64 installer test-binary cross-compilation; and Windows amd64 plus Darwin arm64 application builds. Regressions cover native ZIP/tar/gzip/xz/7z extraction, traversal/link/special-file/case-collision/file-parent/size refusal, uOSC inventory containment, unrelated-file preservation, partial overlay rollback, interrupted existing/new target recovery, interrupted UI recovery, committed-journal cleanup, and tampered out-of-scope journal rejection.

The CM-05/CM-06/CM-09/CM-12–CM-14 configuration/history pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, git diff --check, and current-Go govulncheck; all 167 frontend assertions, npm audit, and vendor freshness; and Windows amd64/arm64 plus Darwin amd64/arm64 affected-package and application cross-builds. Regressions cover helper-process lock contention, independent-store lost-update prevention, corrupt-history retention, latest-snapshot rebasing, all-fields-before-write API validation, flat backup/symlink refusal, manager-reset backup failure, synchronous migration rollback, and both startup recovery outcomes.

The CM-17/CM-24/CM-41/CM-47–CM-49 CLI/parser/startup pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, git diff --check, and current-Go govulncheck; all 167 frontend assertions, npm audit, and vendor freshness; and Windows amd64/arm64 plus Darwin amd64/arm64 application and affected-package cross-builds. Regressions cover incompatible custom destinations, CLI mode/positional contracts, startup verbose output, quoted hashes across all three config grammars, script-option BOM/CRLF/mode preservation and symlink refusal, repeated Unix PATH install/removal with rollback, ready-before-browser listener binding, occupied-port non-publication, and concurrent-start single ownership. Native Windows registry PATH mutation remains a release smoke gate.

The CM-07/CM-08/CM-10/CM-21–CM-23/CM-25/CM-26 Web concurrency pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, git diff --check, and current-Go govulncheck; all 172 frontend assertions, npm audit, vendor freshness, and Windows amd64/arm64 plus Darwin amd64/arm64 affected-package/application cross-builds. Regressions cover persistent-stream shutdown, closed/late clients, terminal queue priority, reconnect snapshots, missed-terminal browser reconciliation, modal focus, single password dispatch, in-flight Config edits, sudo cache invalidation, immutable locale copies, per-key setting order, and stale regional-controller ownership.

The CM-04/CM-27/CM-28/CM-42–CM-46 platform pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, git diff --check, and a Go-1.27-built copy of the pinned govulncheck (zero findings); all 172 frontend assertions, npm audit, and vendor freshness; Windows amd64/arm64 installer test-binary and application builds; and Darwin amd64/arm64 application builds. Regressions cover non-executing Windows scans, C-locale/time/output-bounded package probes, found/not-found/unknown reconciliation, multiple same-method paths, exact-identity removal, elevated MPC-QT wait/exit and post-install discovery, aggregated hybrid GPU enumeration and codec unions, PCI resolution, duplicate hotkey mutation, reserved #, canonical common-language resolution, unique locale IDs, and corrected Punjabi/Filipino/Telugu/Latin-America metadata. Native Windows MPC-QT execution remains a release smoke gate.

The CM-34–CM-40/CM-56 TUI pass passed the full normal, race, and shuffled Go suites; go vet ./..., gofmt, tidy/module verification, git diff --check, and a Go-1.27-built copy of the pinned govulncheck (zero findings); all 172 frontend assertions, npm audit, and vendor freshness; Windows amd64/arm64 TUI/installer test-binary and application builds; and Darwin amd64/arm64 TUI test-binary and application builds. Regressions cover worker panic conversion, noninteractive TUI sudo policy, fractional progress, bounded/coalesced output, keyboard auto-follow control, all-list resize reflow, stable-ID MPC-QT version persistence, post-first-frame single-manifest refresh and offline state, Unicode deletion, and CSI/OSC/C0/C1 removal before display and shared-history persistence.

The CM-11/CM-15/CM-18–CM-20/CM-50–CM-53 release pass added fail-closed, versioned Windows resources for amd64 and arm64 with post-link PE inspection; immutable CI image digests; total, size, idle, low-speed, cleanup, and environment-proxy download controls; canonical protected-tag rules; serialized duplicate-path preflight; exact native-evidence approval; mandatory embedded release trust; notice-bearing archives; and an executed b3sum -c check. Focused Go tests and vet passed, the CI YAML parses under the repository's YAML parser, both Windows targets cross-built as Windows-10 PE files with exact 1.2.0 file/product metadata, empty release trust was rejected, and all six archives were built in the pinned Alpine image and confirmed to contain LICENSE plus THIRD_PARTY_NOTICES.md. Live GitLab policy, isolated signing, and native evidence remain external release gates.

The final CM-16/CL-01–CL-20 pass was validated on the completed working tree with go test -count=1 ./..., the full race and shuffled suites, go vet ./..., pinned Staticcheck SA* and repository-wide U1000, gofmt/tidy/module verification, git diff --check, and current govulncheck with no findings. All 180 frontend assertions, npm audit, exact embedded-vendor comparison, and regenerated Tailwind freshness pass. Aggregate statement coverage is 55.2%. All six Linux/Windows/macOS application cross-builds pass; --version --json and --help are side-effect free in an isolated home; and the seven-case Linux native qualifier passes hash rejection, length rejection, commit, rollback, lock refusal, healthy relaunch, and relaunch-health rollback. A race-only browser-helper test timeout found during this final run was replaced with explicit process-completion synchronization before the suite was rerun successfully.

Strengths retained

Limitations

Remediation status

Repository-side remediation now corrects the root defect for 98 findings and partially advances the remaining three supply-chain entries (CH-13, CH-14, and CM-19). Finding counts above remain the baseline audit result rather than shrinking when an item is fixed. External release-service and project-policy gates are deliberately not presented as complete merely because their repository controls exist.

Status Finding IDs Result
Implemented; Atlas task complete CH-01–CH-04 Windows payload ownership is now explicit and fail-closed; mutable install-tree association scripts are never elevated; TUI update/uninstall operations retain the exact app ID and destination; all config consumers share the selected portable tree.
Implemented; Atlas task complete CH-08–CH-10, CH-17, CH-25 Manager state uses candidate-before-publish persistence and preserves last-good state on read errors; MPV config install/reset/restore and TUI language edits use unique durable backups and staged atomic replacement.
Implemented; Atlas task complete CH-11 Package probes now receive one bounded context, the deadline returns immediately, workers snapshot their inputs, and cache replacement is built off-lock.
Implemented; Atlas task complete CH-12, CH-16 IINA install is bound to the verified DMG's returned mount/device and validates identity/signature/architecture; FFmpeg replacement stages and validates before a binary-plus-metadata transaction with recoverable rollback.
Implemented; Atlas task complete CH-05–CH-07 Cancellation remains nonterminal until worker acknowledgement and is rejected after commit begins; background jobs and synchronous mutations coordinate on explicit resources; Web and TUI expose physical-success/tracking-failure outcomes as durable partial results requiring reconciliation.
Implemented; Atlas task complete CH-21–CH-24 TUI cancellation owns and joins workers, ordered streams drain before terminal completion, UI changes target one exact installed app without reinstalling, and filter keys cannot also dispatch actions.
Implemented; Atlas task complete CH-15, CH-18–CH-20 TUI relaunch preserves terminal ownership and acknowledges after first render; updater integrity precedes execution; apply/restore never expose an absent target; and rollback requires verified recovery evidence.
Implemented; Atlas task complete CM-02, CM-03, CM-30–CM-33, CM-54, CM-55 Self-update is serialized across its complete target set, journals intent before fallible work, survives pre-journal orphans, durably revalidates commit state, proves secondary identity and child exit, reports detached outcomes through shared task history, requires opaque authenticated selections, and enforces stable-manifest replay/key lifecycle policy.
Implemented; Atlas task complete CM-01, CM-29 Every supported archive format extracts through bounded native parsing and private staging; uOSC is inventory-allowlisted. Installer overlays, path/file swaps, and managed-UI replacement persist exact rollback intent, hold a cross-process parent lock, sync before commit, and recover validated interrupted journals at startup.
Implemented; Atlas task complete CM-05, CM-06, CM-09, CM-12–CM-14 Manager config and job history use cross-process read/modify/write serialization and durable unique publication; multi-field Config/language requests commit one validated snapshot; backup operations reject intermediate symlink redirection; reset requires its backup; and ModernZ migration is journaled, compare-and-set, rollback-capable, and startup-recoverable.
Implemented; Atlas task complete CM-17, CM-24, CM-41, CM-47–CM-49 PATH registration is idempotent, native, and rollback-capable; unsupported CLI destinations and conflicting arguments fail explicitly; verbose/debug logs are visible from startup; shared parsing retains quoted hashes and script file metadata; and browser/banner launch follows synchronized listener readiness.
Implemented; Atlas task complete CM-07, CM-08, CM-10, CM-21–CM-23, CM-25, CM-26 Persistent SSE handlers drain on shutdown; reconnect snapshots and terminal-priority queues reconcile jobs; modal/password/Config flows retain single ownership; setting/language requests reject stale completions; sudo validation bypasses cached timestamps; and locale data is immutably published.
Implemented; Atlas task complete CM-04, CM-27, CM-28, CM-42–CM-46 Windows scans are non-executing; bounded probes preserve uncertainty and exact install identities; MPC-QT completion requires child success and executable discovery; CPU/GPU detection is architecture-correct, aggregate, PCI-aware, and fail-closed on macOS AV1; duplicate/reserved hotkeys are safe; and common/regional locale data is canonical and integrity-tested.
Implemented; Atlas task complete CM-34–CM-40, CM-56 TUI workers convert panics to joined terminal results and never share raw terminal input with sudo; progress, Unicode editing, stable update identity, asynchronous one-manifest startup, bounded/coalesced scrolling output, complete resize reflow, and terminal-safe display/history persistence are regression-tested.
Repository controls implemented; external gate open CH-13, CH-14, CM-19 Tag CI no longer receives the private key or trusts upstream “latest”; it consumes reviewed pins and pipeline-local manager bytes. The isolated signer, real approved lock, protected policy, and registry immutability must be provisioned before this Atlas task can close.
Implemented; external release exercise open CM-11, CM-15, CM-18, CM-50–CM-53 Both Windows resource architectures are generated and inspected; all CI images are digest-pinned; generator downloads are comprehensively bounded; release tags, publication, native evidence, and trust fail closed; and every archive carries its license/notices. Live protected-policy and native-evidence execution remain release gates.
Implemented; Atlas task complete CM-16, CL-01–CL-20 Reduced motion, CSP and externalized behavior, release frontend gating, script-option CAS, Web/SSE/installer/updater/TUI/core/frontend/file/lifecycle hardening, pinned Staticcheck SA/U1000 cleanup, documentation contracts, dependency freshness, and qualifier containment are implemented and regression-tested. Live orchestration browser E2E remains separately tracked rather than being misreported as part of this repository-only closure.

Atlas now records 15 completed, 2 in-progress, and 0 queued grouped remediation tasks. The finalization umbrella task c42ba4a7 is complete. The isolated-signing P0 task and final release-evidence P1 task remain open because they require live external service, policy, native evidence, and publication work; native Windows install/update/uninstall, Windows registry PATH mutation, and macOS IINA execution remain release gates.