0.4.0 Beta 18 - Playback settlement, Mac redesign, Android Usenet, and account sync
Install this over any earlier build. Beta 18 brings together the reviewed changes since Beta 17 for Apple TV, iPhone, iPad, Apple Silicon Mac, Android phones and Android TV. It retains the preceding playback, binge-watching, automatic-skip and subtitle repairs. Apple build 254, Android version code 239. Package versions, signing, checksums and Latest promotion are separate checks before publication.
What's new
A native Mac sidebar and in-window Settings. Home, Discover, Live, Library, Search, Add-ons and Settings now have persistent sidebar destinations. Settings opens inside the app with categorized navigation rather than an oversized floating phone-style sheet. Search remains available in the shell; Command-F and the Go menu route to it. Keyboard shortcuts select destinations, Escape returns focus to the shell when appropriate without stealing a child screen's Back action, and transitions respect Reduce Motion. This is an implemented native shell, not a claim that every Mac screen has received its final visual redesign.
Direct NZB indexers on Android. Save and manage Newznab-compatible HTTPS indexers, including NZBGeek, and search them from normal movie and selected-episode source lists. Credentials are encrypted and scoped to the account and profile. Editing, disabling, removing or switching configuration invalidates old requests; a finished search cannot publish stale results into source selection or next-episode preparation. Configuration survives a new session for the same account/profile instead of being keyed to a temporary generation.
Multiple Android Usenet servers with priority and fallback. Save, edit, disable, remove and prioritize NNTP servers on phone and TV. Existing single-server settings migrate. Configured routes use the shared resolver rather than an unconnected settings screen. The local provider loop tries the configured alternatives and retains the existing cloud path when separately configured. TorBox cloud preparation still requires its API key and may prepare an uncached job; this is not a guarantee of immediate playback from every article or provider.
Trakt Continue Watching on Android. An optional, read-only Home rail loads Trakt's movie and episode playback queues, resolves artwork, and carries the exact series, season and episode into detail navigation. It is Off by default and does not turn imported Trakt progress into synthetic native watched history. Both playback lists must succeed before a new complete cache is published. A same-owner fetch failure can retain the last successful rail.
Manual Trakt check-in from Android detail pages. The optional action follows the primary movie or selected episode on phone and TV. It requires the owner profile and manual-check-in opt-in. Duplicate taps are blocked; authentication, profile, title and episode changes reject old results. A conflicting active check-in is not silently replaced: the app offers an explicit “Check in here” action. Manual check-in does not mark the title watched. Apple's check-in chip also re-evaluates the stored session at the authentication boundary while retaining its episode and opt-in requirements.
Phone Library segments and TV add-on reordering. Android phone and TV share All, Movies, Shows and Anime segments and their applicable smart filters. Native sorting is retained; the app does not invent genre metadata to populate those filters. Android TV add-on ordering has remote-friendly move controls, and configured Usenet/indexer routes are reachable through TV Settings with normal Back behavior.
What's fixed
AVPlayer recovery settles against the current item and the viewer's transport choice. Recovery seeks have an explicit owner, accepted landing and bounded repair result. A newer seek, source change or player replacement retires the older recovery. An accepted small forward remux landing is normalized to its actual local origin, avoiding a repeated remount loop. A false seek completion or deadline consumes a concrete repair target instead of leaving a ticket silently unresolved. If a ready callback synchronously replaces the item, the retired callback cannot apply tracks, Play/Pause or startup state to the replacement. A paused recovery remains paused until the viewer resumes it.
VortX Player cache maintenance no longer drops playback before its seek runs. A complete overnight TV diagnostic showed repeated cache trims followed by a false end-of-file, a failed high-position resume and a restart around nine seconds. The queued buffer-drop and seek were not an atomic transport operation in the shipped player. Maintenance now requests the low-level seek without first resetting the decoder, keeps its temporary cache option until an owned seek receipt settles, and requires an increased low-level-seek counter plus a compatible landing before reporting success. One bounded reissue handles the demux thread's option-adoption race; a timeout is a failure, not a completed trim. Memory-pressure and background cache limits remain in force.
Paused replacement playback keeps its target and the viewer's choice. A repair's temporary engine pause is no longer mistaken for the viewer pressing Pause. A paused reopen waits for the exact replacement file and its duration before deciding whether to seek or clear a target, and retains the seek obligation if command admission fails. An early zero-position tick cannot settle a high-position restoration. Stale callbacks carry their original maintenance attempt rather than adopting a later operation.
Late subtitle discovery cannot resurrect an old selection. External-subtitle selection settles independently against its owned item and inventory. Explicit choices and Off supersede pending restoration; outgoing and late callbacks cannot restore an older track. Native subtitle single-renderer and background-style handling from earlier betas remain. Authored bitmap styling and system accessibility overrides are still separate limits, not evidence of duplicate-renderer closure on every file.
The iPhone episode Watch action sits at the hero seam. Portrait phones retain the large cinematic hero, place the real selected-episode Watch action across its bottom edge and wrap long action text without the narrow vertical-letter collapse. Manual quality, language and player controls remain below it, and source rows preserve add-on-authored formatting. The phone-only overlap is limited to finite portrait phone widths; iPad and Mac retain their source-list Play action rather than losing it through a shared layout change.
Android Usenet admission uses decoded article evidence. Whole-file sizing and multipart coverage come from validated yEnc headers, not a sum of estimated article sizes. Invalid, overlapping or incomplete ranges cannot be admitted as complete cached media. Loopback binding happens inside the provider attempt: a bind failure cleans up the session and advances fallback. Cancellation and a configuration/account change after readiness dispose the producer and loopback registration instead of leaving a stale playable URL behind. Credential and provider-document locking use one consistent order.
Trakt episode intent survives metadata and owner reloads. Android routes the typed episode hint rather than parsing a display caption. A valid manual selection takes precedence, then the matching Trakt target, then the existing native primary-episode policy. If an interim owner has no matching episode, the original intent remains available when returning to the previous owner. In-player intent changes only after an episode switch is accepted.
Android filmography opens the latest title selected. A second tap during a slow title lookup now cancels and supersedes the first instead of being ignored. Back and screen disposal invalidate pending navigation immediately on both phone and TV; an old completion cannot open a title after leaving the page.
Old Trakt responses cannot repopulate a new account's Home rail. Requests carry the exact Trakt session epoch, toggle revision and cache generation. Network and artwork work run outside the cache lock. Clear invalidates immediately, including while a fetch is pending. Home clears visible personalized rows before awaiting provider cleanup and checks the receipt again immediately before assignment. Turning the feature off and on cannot admit an old request just because the account name is unchanged.
Home rail order travels through account sync and backup. Ordered rail IDs use the same ordered array shape across Apple and Android. Hidden rails remain a string set and layout remains a string. Android converts its local JSON string representation at the account/backup boundary, retains unknown rail IDs in order, reads legacy Android backups and skips malformed values without wiping a valid local arrangement. Local dirty settings are protected from an older pull. Per-profile catalog order stays profile-scoped rather than being flattened into one global arrangement.
Account add-on changes respect both native ownership and the VortX session. A delayed install, removal or reorder cannot run under a replacement account merely because the native Stremio UID happens to be the same. Accepted account descriptors enter the actual native gateway, and routine reads cannot acknowledge or replace a newer local order edit. The earlier no-shrink roster, removal/reinstall, local-only mirroring and source-group ordering protections are retained.
An asynchronous remove/re-add keeps its history ownership. Android waits for the exact native result of the original account-owned operation instead of assuming its immediate disk read already includes the change. A later re-add, including an authenticated metadata-only account update, continues that captured transition. Failed proof storage cannot be reported as successful publication.
Android owner-library events have a real native read and restore path. Account sync now distinguishes library membership from genuine history. Exact title type, current video, position, duration, event timestamp, nullable viewing timestamp, watched bitfield, per-video watched state, count and movie-only whole-title state travel through a receipt-checked batch. Genuinely newer events can update an already-present identity; a metadata-only read cannot overwrite peer progress. Zero progress is valid and is not replaced with a fabricated current viewing time. Partial series progress is not promoted to a fictional whole-series watched flag. Manual movie unwatch retains explicit evidence even when the movie has no viewing timestamp.
Failed history restoration cannot advance the account's accepted version. Native and account admission are checked again at dispatch, including a fresh native LWW read. Null, wrong-owner, duplicate, incomplete or mismatched receipts are rejected. Opaque peer fields are preserved rather than “repaired” from an unclocked local snapshot. Real local progress, playback completion and watched/library actions arm the durable debounced account push instead of depending on an app restart.
Manual watched actions and genuine playback history have separate cross-client carriers. Apple and Android use the same owner-profile history array for real viewing events, including unsaved titles, without turning Continue Watching into Saved library membership. Watched/unwatched intent remains separately clocked. Sparse Apple events inherit optional fields only from proven same-owner state; malformed, unsupported and oversized peer sections are preserved rather than flattened. Secondary profiles with their own accounts cannot export their history into the main owner's carrier.
Adding a title cannot erase another device's resume position. The native library constructor stamps a newly saved title with the current time even before viewing it. That metadata-only clock is no longer treated as a newer viewing event on either side of reconciliation. Genuine zero rewinds and completed playback remain valid, and unknown peer fields survive a metadata refresh.
A later library edit cannot block a newer real resume. Android and its native bridge now distinguish an owned playback event from the row's later membership/persistence timestamp. A conditional restore requires the complete, freshly matching account-owned state and a genuinely newer viewing event. It retains the real viewing time and the existing membership time separately; it does not manufacture a later event to satisfy the engine. Changed, unknown or foreign rows keep the stricter original admission rule. The same rule covers a proven pristine newly saved title whose constructor timestamp is not viewing evidence.
A library removal belongs to the account that made it. Removal/reinstall stamps use account-specific durable stores and captured revisions. Switching A to B and back invalidates the old A handle while restoring A's own saved stamps. Unassigned legacy data is not adopted by whichever account signs in next. Queued typed library actions capture the account, native owner and removal capability before their first dispatcher suspension; an A action cannot begin its queued body as B. The final upload filter removes only recognized removed identities and retains unknown objects, arrays, scalars and nulls from peer documents.
Retained from Beta 17
The configurable automatic intro/credits skip countdown with Off and Cancel, source-owned watch suggestions, real first-frame admission at 0:00, failed-resume retirement across replacement chains, player/source/prewarm lifecycle ownership, independent audio/subtitle restoration, file-matched add-on subtitle requests, Trakt and Top Shelf artwork, bounded batch metadata recovery, recoverable opt-in watched-download cleanup, web source paging/skip parsing and artifact-bound Android update metadata remain. See the Beta 17 notes and their retained Beta 16 list for the preceding repairs.
Android
This candidate includes source for both signed distribution variants. Both contain the phone and Android TV interfaces and the three shipped ABIs: arm64-v8a, armeabi-v7a and x86_64.
VortX-0.4.0-full-mpv-universal.apk: the sideloaded VortX/MPV build with Media3 fallback.VortX-0.4.0-play-media3-universal.apk: the GPL-native-free Media3 build.VortX-0.4.0-play-media3.aab: the matching Play distribution bundle, not an installable APK.
The direct NZB/Usenet, Library, Trakt and remote-ordering work closes concrete feature gaps. It does not establish 100% visual or functional parity with Apple, physical Shield/Fire TV compatibility, or a complete redesign of every Android page. Broader detail/hero composition and live remote journeys remain separate verification work.
Verification and remaining limits
The source batch has independent review receipts, passing Apple playback/layout/source contracts and real tvOS/iOS/Apple Silicon macOS debug builds. The integrated Android suites passed 1,492 Full tests and 1,419 Play tests, with no failures, errors or skipped tests. The native history/storage suite passed 21 tests against the pinned upstream dependency without a local source override. Apple and both Android build lanes use one immutable, reviewed wrapper revision retaining the shipping add-on lifecycle changes.
Android artifact gates verify callable JNI definitions, not just matching symbol names. They check both engines in both APKs and the Play AAB across all three ABIs, including ELF class, architecture, little-endian shared-object type and visible defined function exports. Package signing, exact tagged-source provenance, packaged versions, checksums and feed publication remain separate fail-closed release gates.
This is a beta with repaired failure paths, not a promise that every playback failure is gone. Sustained DV/NNTP throughput, hardware HDR/audio output, frame pacing, physical pause/seek/source switching and Android process-death/remote behavior require fresh device receipts. The Mac shell and iPhone detail improvements do not finish every screen's visual work.
Account publication now requires exact persisted-row ownership, captured account/native admissions and separate authorized outbound history. Sharing a native UID or signed-out bucket is not sufficient evidence. The typed account-library path currently covers movie/series tt… and tmdb:… identities, not every custom anime provider ID.
Android upgrade boundary: older unsynced add-on order/removal/addition records without an exact-owner marker remain quarantined rather than being assigned to whichever account signs in. They are retained on disk, not deleted; cloud sync can restore changes that reached the account, but cannot reconstruct an edit that was never uploaded. Reapply any such pending edits in this version. This is not a transparent migration of ambiguous legacy records.
The website's latest deployment passed its tests/build and live page readback. Its add-on heading no longer implies every account-saved item is already installed on every device, and QR approval no longer claims that the device has finished sign-in. Those checks do not establish a full live cross-device account journey or provider availability.
Please test
- Resume from Continue Watching, pause and resume, seek backward, switch source/player and confirm the current episode and pause choice survive.
- Start a new episode at 0:00, try automatic next episode and manual Next/Previous, and compare any source that previously remained blank or reconnecting.
- Choose a subtitle, then Off, during recovery; confirm a late inventory cannot restore the prior choice.
- On Mac, try all sidebar destinations, categorized Settings, Command-F, keyboard route shortcuts and Back/Escape inside a child screen.
- On iPhone, test episode Watch, long labels and manually formatted source rows; on iPad confirm the source-list Play action remains.
- On Android, test NZB indexers, ordered NNTP alternatives, disable/remove during a search, and a stale warm-result cancellation. Live provider throughput is not established by protocol fixtures.
- Enable Android Trakt Continue Watching, open a queued episode, switch accounts or toggle during refresh, and test optional manual check-in and its explicit conflict action.
- Reorder Home rails, export/import a backup and sync to another current client; test explicit library watch/unwatch and account switching without importing the previous account's history.
- If a failure remains, export diagnostics promptly with the title, add-on/provider and preceding action so the initiating event is retained.
Install
Apple TV. Use VortX-tvOS-v0.4.0-beta.18-ci.ipa for Full or VortX-tvOS-lite-v0.4.0-beta.18-ci.ipa for Lite through your usual signing service.
iPhone and iPad. Use VortX-iOS-v0.4.0-beta.18-ci.ipa. Distribution IPAs require re-signing through your usual installer. Apple installation guide.
Mac. Use VortX-macOS-v0.4.0-beta.18-ci.dmg. This is the Apple Silicon, ad-hoc-signed package rather than a notarized release. Mac installation guide.
Android. Choose the signed APK appropriate to your preferred engine/distribution. Android checksums and signer evidence are in SHA256SUMS-android.txt and SIGNING_PROVENANCE.txt; Apple checksums are in SHA256SUMS-ci.txt.
This beta uses the Latest beta channel. Package integrity, Latest promotion and the live install/update feeds are verified separately; the GitHub label alone is not an update-feed receipt.