Phase 2a: buffer state under one lock, atomic tuner limit, context-driven external buffer
continuous-integration/drone/push Build encountered an error

- src/buffer_state.go replaces the two sync.Maps plus a global RWMutex with
  one bufferMu guarding a map of *Playlist. Each stream has one shared
  bufferStream (URL, folder, status, client count, error, cancel hook);
  downloaders keep a private ThisStream and publish through helpers.
  Playlist.Clients / ThisClient / ClientConnection are gone: there was one
  client counter per stream in two places that could disagree.
- bufferAcquireStream does the tuner check and the registration under the
  same lock, so two clients tuning at once cannot both pass the limit.
  bufferReleaseClient removes the stream when the last client leaves,
  cancels its process and deletes its segment folder.
- bufferingStream rewritten: waits on r.Context() instead of the deprecated
  CloseNotifier, sets Content-Type before WriteHeader (the old code set
  headers after and one was literally named "Content-Length:"), flushes
  each segment to the client, no defer inside the segment loop.
- connectToStreamingServer: shared streamHTTPClient with dial, TLS and
  response-header timeouts (no overall timeout, bodies are endless); the
  deferred Body/segment closes inside the redirect and read loops are now
  explicit closes, so a multi-hour stream no longer accumulates them.
- thirdPartyBuffer rewritten around exec.CommandContext: the process is
  killed when the last client leaves or when no usable data arrives within
  20 s (time.AfterFunc watchdog, no leaked goroutine); cmd.Start error is
  checked; no panic; one file handle per segment. ffmpeg and VLC command
  lines come from buildFFmpegArgs / buildVLCArgs, which are unit tested.
- Data.Cache.StreamingURLS is guarded by streamingURLsMu and persisted
  from a snapshot.
- Tests (src/buffer_test.go, run with -race): restream shares one provider
  connection, six concurrent tunes against a tuner limit of two, 50-way
  acquire/release contention, cleanup and cancel on last release.
This commit is contained in:
2026-09-26 13:14:48 +10:00
parent 36303fecea
commit 320eaa1b28
10 changed files with 954 additions and 800 deletions
+7 -7
View File
@@ -29,17 +29,17 @@ Status: Phase 0 committed on branch `improvements` 2026-09-26.
- [x] Decide default for web auth on fresh installs (keep off; LAN only, decided 2026-09-25)
## Phase 2: Streaming stability
- [ ] Race tests: two concurrent tuners against a fake TS server, run with `-race`
- [ ] `*Playlist` with own mutex; remove stale store-backs
- [ ] Atomic tuner reservation; clean `BufferClients` on force kill
- [ ] RWMutex around `StreamingURLS`
- [ ] Remove `defer` inside read loops (buffer, compression, imgcache)
- [ ] Single external-process buffer (`exec.CommandContext` + request context) with ffmpeg and VLC argument builders; drop `CloseNotifier`
- [x] Race tests in `src/buffer_test.go`: restream shares one provider connection, tuner limit atomic under 6 concurrent tunes, acquire/release contention, cleanup on last client; run with `-race`
- [x] New `src/buffer_state.go`: one `bufferMu`, playlists by pointer, one `bufferStream` per stream (status, client count, error, cancel hook); downloaders keep a private working copy and publish through helpers. `BufferInformation`/`BufferClients`/`Lock` removed
- [x] Tuner check and registration under one lock (`bufferAcquireStream`); last client out removes the stream, cancels its process and deletes its folder
- [x] `streamingURLsMu` around `Data.Cache.StreamingURLS`; persisted from a snapshot
- [x] No more `defer` inside the buffer read/redirect loops (compression done in Phase 1; imgcache in 2b)
- [x] `thirdPartyBuffer` rewritten: `exec.CommandContext` cancelled when the last client leaves or the 20 s startup watchdog fires; `buildFFmpegArgs`/`buildVLCArgs` tested; no panic, `cmd.Start` checked, one file handle per segment. Client loop uses `r.Context()` instead of `CloseNotifier`
- [ ] Real mutex for screen log
- [ ] `http.Server` with timeouts; timeouts on all outbound clients
- [ ] imgcache: download outside the lock
- [ ] Atomic write helper (temp + fsync + rename)
- [ ] Fix listed concrete bugs (xepg append, range mutation, log overflow, headers after WriteHeader, random notification eviction, unchecked assertions, API double write, WS struct reuse)
- [x] Buffer: headers set before `WriteHeader`, bogus `Content-Length:` header gone, segments flushed to the client as they arrive. Others in 2b
- [ ] Error hygiene: no-op closures, `os.Exit`/`panic` outside main, ignored results
## Phase 3: Build, embed, CI, Docker