Skip to content

Harden stream recovery, catalog loading, and account lifecycle - #34

Merged
capy-ai[bot] merged 1 commit into
mainfrom
capy/harden-stream-recovery-catalog
Sep 12, 2026
Merged

capy-ai[bot] merged 1 commit into
mainfrom
capy/harden-stream-recovery-catalog

Conversation

@zortos293

Copy link
Copy Markdown
Contributor

This overhaul follows parallel audits against OpenNOW and OpenNOW-Mac. The source findings, port requirements, verification methods, and remaining limits are recorded in docs/switch-streaming-audit.md.

Streaming and input

  • Fix partial decoder-allocation cleanup and propagate receive failures into generation-safe recovery without dropping the replacement IDR's dependent frames.
  • Retire GPU mappings, hardware frames, uploads, and command storage using completion fences; preserve the previous image under backpressure and reject incompatible frame layouts.
  • Preserve audio timeline gaps after dropped output packets, short Plus/Minus taps, and neutral input delivery during keyboard, overlay, NTE, and focus capture.
  • Reassemble fragmented WebSocket messages, validate upgrade challenges, bound sender-report history and first-frame startup, and remove raw signaling/SDP credential logging.
  • Replace the non-retransmitting internal SCTP path with the pinned usrsctp implementation, bounded per-peer callback queues, loss/reconnect tests, and exception-safe shared SRTP runtime ownership. Keep the existing reliable input-channel profile.

Catalog, TLS, and application state

  • Replace the 360-game truncation with typed incremental catalog pages and reject malformed or cycling cursors without discarding the prior listing.
  • Move covers off the shared serial worker, cap pending requests, defer live-image admission under saturation, cancel obsolete transfers, and make cache replacement/clearing atomic. A 61-widget regression covers overflow recovery and failure fallbacks.
  • Bundle verified DigiCert Root G3 as supplemental Switch trust, retain certificate/hostname/date verification, and redact request URLs in errors while reporting TLS backend and UTC for certificate failures.
  • Fix startup callback lifetime, canceled cloud-allocation ownership, client-token-only renewal, and background refresh overwriting account selection, logout, or a newer sign-in.
  • Recover settings backups, validate integer conversions and legacy gain migration, preserve unrelated preferences when repairing fields, and guard asynchronous provider, region, proxy, and cache UI work by lifetime/session generation.

Verification and limits

  • bash scripts/test-host.sh: 96 reported checks pass.
  • OPENNOW_SANITIZERS=address,undefined UBSAN_OPTIONS=halt_on_error=1 bash scripts/test-host.sh: the same checks pass, including the pinned SCTP packet tests.
  • Full SwitchNOW.nro build passes in the pinned devkitPro container; the packaged certificate bytes match the verified source PEM.
  • The new host CI workflow passes actionlint validation. Independent Grok 4.6 review has no remaining confirmed high findings after the cover fix.

The screenshot's actual console-side certificate cause remains unconfirmed. Root G3 is older-firmware compatibility, not a proven cure for clock or modern-firmware failures. Native NVST is not implemented; the report explains the distinct negotiation, authenticated-video, and input work required. No hardware gameplay, visual UI, CPU/GPU performance, or live SPS-layout renegotiation result is claimed. Full ThreadSanitizer reports upstream usrsctp lock-order warnings; the race-only run is not represented as a clean full TSan pass.

Open in Capy

@coderabbitai

coderabbitai Bot commented Sep 12, 2026

Copy link
Copy Markdown

Important

Review skipped

Too many files!

This PR contains 112 files, which is 12 over the limit of 100.

To get a review, reduce the PR to 100 files or fewer by splitting it into smaller PRs or changing its base branch.

Upgrade to a paid plan to raise the limit.

This review couldn't start because sufficient usage credits or metered capacity aren't available. Add credits or update usage-based reviews in the billing tab, then retry.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 0e401ff2-7def-4207-9067-5504d52912d1

📥 Commits

Reviewing files that changed from the base of the PR and between 404263a and 7084fc7.

⛔ Files ignored due to path filters (1)
  • resources/certs/DigiCertGlobalRootG3.pem is excluded by !**/*.pem
📒 Files selected for processing (112)
  • .github/workflows/host-tests.yml
  • CMakeLists.txt
  • README.md
  • app/src/StreamView.cpp
  • app/src/StreamView.hpp
  • app/src/WebSocketClient.cpp
  • app/src/WebSocketClient.hpp
  • app/src/app_state.cpp
  • app/src/app_state.hpp
  • app/src/catalog_paging_policy.hpp
  • app/src/catalog_tab.cpp
  • app/src/catalog_tab.hpp
  • app/src/cloud_launch_state.hpp
  • app/src/controller_delivery_policy.hpp
  • app/src/cover_image_cache.cpp
  • app/src/cover_image_cache.hpp
  • app/src/cover_image_worker.hpp
  • app/src/game_card_view.cpp
  • app/src/game_card_view.hpp
  • app/src/game_detail_view.cpp
  • app/src/gfn/authentication.cpp
  • app/src/gfn/catalog.cpp
  • app/src/gfn/persistence.cpp
  • app/src/gfn/persistence_internal.hpp
  • app/src/gfn_client.hpp
  • app/src/http_client.cpp
  • app/src/http_client.hpp
  • app/src/library_tab.cpp
  • app/src/main.cpp
  • app/src/main_activity.cpp
  • app/src/main_tabs_view.cpp
  • app/src/models.hpp
  • app/src/providers_tab.cpp
  • app/src/providers_tab.hpp
  • app/src/qr_login_dialog.cpp
  • app/src/settings_tab.cpp
  • app/src/settings_tab.hpp
  • app/src/settings_tab_account.cpp
  • app/src/settings_tab_actions.cpp
  • app/src/settings_tab_pages.cpp
  • app/src/signaling_client.cpp
  • app/src/startup_callback_policy.hpp
  • app/src/stream/audio/AudioPipeline.cpp
  • app/src/stream/audio/AudioPlaybackTimeline.hpp
  • app/src/stream/deko3d/DKVideoRenderer.cpp
  • app/src/stream/deko3d/DKVideoRenderer.hpp
  • app/src/stream/deko3d/GpuFrameQueue.hpp
  • app/src/stream/ffmpeg/FFmpegVideoDecoder.cpp
  • app/src/stream/ffmpeg/FFmpegVideoDecoder.hpp
  • app/src/stream_settings.cpp
  • app/src/stream_view_controller.cpp
  • app/src/stream_view_input.cpp
  • app/src/stream_view_overlay.cpp
  • app/src/top_bar_frame.cpp
  • app/src/top_bar_frame.hpp
  • app/src/ui_helpers.cpp
  • app/src/webrtc/decode_recovery_state.hpp
  • app/src/webrtc/diagnostics.cpp
  • app/src/webrtc/input.cpp
  • app/src/webrtc/internal.hpp
  • app/src/webrtc/media.cpp
  • app/src/webrtc/negotiation.cpp
  • app/src/webrtc/peer_runtime.hpp
  • app/src/webrtc/sender_report_cache.hpp
  • app/src/webrtc/session.cpp
  • app/src/webrtc/signaling_diagnostics.hpp
  • app/src/webrtc/startup_timeout_policy.hpp
  • app/src/webrtc_session.hpp
  • app/src/websocket_handshake.hpp
  • docs/switch-streaming-audit.md
  • extern/libpeer/src/CMakeLists.txt
  • extern/libpeer/src/peer.c
  • extern/libpeer/src/peer_connection.c
  • extern/libpeer/src/sctp.c
  • extern/libpeer/src/sctp.h
  • resources/certs/README.md
  • scripts/test-host.sh
  • scripts/test-streaming-host.sh
  • tests/app_state_session_generation_test.cpp
  • tests/audio_pipeline_test.cpp
  • tests/audio_playback_timeline_test.cpp
  • tests/auth_client_token_refresh_test.cpp
  • tests/auth_saved_session_refresh_test.cpp
  • tests/cached_image_admission_test.cpp
  • tests/catalog_paging_policy_test.cpp
  • tests/catalog_response_test.cpp
  • tests/cloud_launch_state_test.cpp
  • tests/controller_delivery_policy_test.cpp
  • tests/controller_input_capture_test.cpp
  • tests/cover_cache_stubs/borealis.hpp
  • tests/cover_cache_stubs/borealis/core/cache_helper.hpp
  • tests/cover_image_cache_test.cpp
  • tests/cover_image_worker_test.cpp
  • tests/decode_recovery_state_test.cpp
  • tests/ffmpeg_video_decoder_test.cpp
  • tests/gpu_frame_queue_test.cpp
  • tests/http_client_error_test.cpp
  • tests/http_client_transfer_fixture.py
  • tests/http_client_transfer_integration_test.cpp
  • tests/http_tls_policy_test.cpp
  • tests/http_transfer_test.cpp
  • tests/peer_runtime_test.cpp
  • tests/run_sctp_reliability_test.sh
  • tests/sctp_reliability_test.c
  • tests/sender_report_cache_test.cpp
  • tests/signaling_diagnostics_test.cpp
  • tests/startup_callback_policy_test.cpp
  • tests/startup_timeout_policy_test.cpp
  • tests/stream_settings_persistence_test.cpp
  • tests/stream_stubs/borealis.hpp
  • tests/websocket_client_test.cpp
  • tests/websocket_handshake_test.cpp

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@capy-ai capy-ai Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Capy found no issues.

View 3 other findings in Capy.

Open in Capy

@capy-ai
capy-ai Bot merged commit 159c8f3 into main Sep 12, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant