github bluenviron/mediamtx v1.21.2

5 hours ago

Fixes and improvements

General

  • fix dropping UDP packets during connection close (#6278) UDP packets were dropped in case of errors regardless of their size. Now they are dropped only if they are empty and there's an error.
  • docs: fix youtube rtmps URL (#6286) The rtmps URL for Youtube was wrong. The fingerprint is not required anymore.
  • prevent free access to playback server in case of legacy credentials (#6311) When legacy credentials are in use (readUser, readPass, publishUser, publishPass), access to the playback server is granted to anyone. Prevent this by granting access only to users using readUser, readPass.
  • auth: skip JWKS fetch when no JWT is provided (#6274) authenticateJWT fetched the JWKS before checking whether the request carried a token at all. Every anonymous request, such as the first unauthenticatedRTSP DESCRIBE or HLS request that precedes a 401, caused an outbound request to the JWKS server while holding the manager's write lock. An unauthenticated client could therefore make the server contact the identity provider at will and, while that endpoint was slow or unreachable, stall JWT authentication for everybody. Return "JWT not provided" before touching the JWKS. Also check the JWKS response status code. A non-2xx reply was fed straight to the JSON decoder, so an error page surfaced as a confusing parse error,and an error reply that happened to hold valid JSON was cached as the key set for an hour. Reject it with the status code, as authenticateHTTP already does. Behavior for requests that carry a token against a healthy JWKS server is unchanged.
  • rewindablereader: fix possible OOM (bluenviron/mediacommon#383) empty datagram packets might cause the allocation of unnecessary entries. Fix that.
  • h264: revert bluenviron/mediacommon#142 (bluenviron/mediacommon#384) supporting standalone SEI units should not be necessary anymore since these are filtered out at the root (bluenviron/gortsplib#1184). In case of any issue that should arise after this change, open a bug report and we'll adjust things accordingly.
  • h264: support SEI recovery point in DTS extractor (bluenviron/mediacommon#341) Treat a SEI recovery point message (payload type 6) as a random access point, similarly to a CRA in H265, so the DTS extractor can (re)initialize its state from the first coded frame that follows the recovery point.

API

  • fix race condition when kicking RTSP sessions (#6260) (#6275)
  • do not change passwords when their value is "" (#6141) (#6287) (#6292) some users call /config/global/get and passits content to /config/global/patch. Since the former now redacts passwords and replaces their value with "", this string is used as an effective password, breaking authentication. Now password values equal to "" are ignored by /config/global/patch, and the original password value is kept unchanged.
  • fix deadlock when reloading the API (#6280) (#6279) (#6310) When the API is closing, a /config endpoint might be waiting on the server to reply, but the server is busy waiting on all API endpoints to return, causing a deadlock. Fix this by canceling requests from API endpoints to the server when the API is closing.

Media-Over-QUIC

  • use "catalog" as catalog track name (#6268) Previously, the catalog track name was ".catalog" which is non-standard.

RTSP

  • stop forwarding in case of read errors (#6266)
  • apply path-level rtspUDPReadBufferSize to the first connection (#6291) The RTSP static source built its client before reading the path-level rtspUDPReadBufferSize, so the value only reached the client after a reconnection. Compute it before creating the client, as the MPEG-TS and RTP sources do and as this source did before #5488.
  • server: change error return code of some methods (bluenviron/gortsplib#1091) (bluenviron/gortsplib#1174)
  • drop standalone H264/H265 trailing SEIs (bluenviron/gortsplib#1184) #3614 bluenviron/mediacommon#142 #6257 bluenviron/mediacommon#382 H264/H265 access units containing a single SEI only, trailing other units, generated by someTP-Link/Tapo cameras, are non-standard and cause several issues in downstream components, including the DTS extractor and the recorder. Previously, the H265 DTS extractor was adjusted to support such units (bluenviron/gortsplib#142) but the problem represented itself with H265. Filter these units out at the root.
  • make all decoders return at least 1 byte (bluenviron/gortsplib#1185)
  • complete RTP/JPEG implementation (bluenviron/gortsplib#1187) add support for restart headers, limit support to JPEG types 0 and 1.

RTMP

  • detect read errors even when the server is writing (#6267) Until now we relied exclusively on write errors to detect broken RTMP connections. Now read errors are checked too.
  • make rawmessage.Write thread-safe (bluenviron/gortmplib#136)
  • writer: drain inbound messages (#5776) (bluenviron/gortmplib#132) Some servers periodically send messages even when we're publishing. If they are not read, they fill an internal connectionbuffer and cause periodic disconnections. Now the Writer also drains inbound messages.
  • reader: support FLV video command frames and skip empty audio messages (bluenviron/gortmplib#128) Someservers (e.g. Wowza Streaming Engine) send a video info/command frame before the first frame: a 2-byte message with frame type 5 and a single command byte (start of seek / end of seek). Video.unmarshal rejected it on length, aborting the whole connection. Add Video.FrameType (key frame, inter frame, command) and Video.Command, deprecate Video.IsKeyFrame in favour of FrameType, and skip command frames in Reader since they carry no data. Some servers (e.g. Wowza Streaming Engine) send an audio message with an empty bodybefore the first frame. allocateMessage rejected it with "not enough bytes", aborting the whole connection. Parse an empty body into an Audio with Codec = 0 and no other field, marshal it back to an empty body, and skip such messages in Reader since they carry no data, like FFmpeg does.
  • rename message.Video.Type into message.Video.PacketType (bluenviron/gortmplib#138) This is to avoid confusion with the new message.Video.FrameType field.

HLS

  • muxer: keep EXT-X-MAP in delta updates (bluenviron/gohlslib#397) Delta updates were generated without EXT-X-MAP, although all tags that are not skipped must remain in them. Apple clients stop playback (MoofManifold -16046) at the first delta update that skips a segment after delta updates without skipped segments.

WebRTC

  • fix panic with specially-crafted WHEP requests (#6301) (#6309) this happened in case of WHEP requests with no media descriptions in the SDP.

Dependencies

  • Go updated from 1.26 to 1.27
  • code.cloudfoundry.org/bytefmt updated from v0.90.0 to v0.92.0
  • github.com/bluenviron/gohlslib/v2 updated from v2.4.5 to v2.4.6
  • github.com/bluenviron/gortmplib updated from v1.0.3 to v1.0.4
  • github.com/bluenviron/gortsplib/v5 updated from v5.6.6 to v5.6.7
  • github.com/bluenviron/mediacommon/v2 updated from v2.9.5 to v2.9.6
  • github.com/datarhei/gosrt updated from v0.11.1-0.20260812091715-a77b40bb4b76 to v0.12.0
  • github.com/gin-contrib/pprof updated from v1.5.5 to v1.5.6
  • github.com/go-git/go-billy/v5 updated from v5.9.1 to v5.9.2
  • github.com/go-git/go-git/v5 updated from v5.19.2 to v5.19.3
  • github.com/pion/ice/v4 updated from v4.4.2 to v4.4.5
  • github.com/pion/interceptor updated from v0.1.48 to v0.1.49
  • github.com/pion/rtcp updated from v1.2.17 to v1.2.19
  • github.com/pion/transport/v4 removed
  • github.com/pion/webrtc/v4 updated from v4.2.20 to v4.2.22
  • github.com/quic-go/quic-go updated from v0.62.0 to v0.63.0
  • github.com/pion/datachannel updated from v1.6.2 to v1.6.3
  • github.com/pion/dtls/v3 updated from v3.1.8 to v3.1.9
  • github.com/pion/mdns/v2 updated from v2.2.0 to v2.2.2
  • github.com/pion/sctp updated from v1.11.1 to v1.11.3
  • github.com/pion/srtp/v3 updated from v3.0.15 to v3.1.3
  • github.com/pion/stun/v4 updated from v4.0.0 to v4.0.1
  • github.com/pion/turn/v5 updated from v5.1.0 to v5.1.2
  • github.com/pjbgf/sha1cd updated from v0.6.0 to v0.7.0
  • github.com/pion/transport/v5 v5.1.1 added

Security

Binaries are compiled from source code by the Release workflow, which is a fully-visible process that prevents any change or external interference in produced artifacts.

Checksums of binaries are also published in a public blockchain by using GitHub Attestations, and they can be verified by running:

ls mediamtx_* | xargs -L1 gh attestation verify --repo bluenviron/mediamtx

You can verify checksums of binaries by downloading checksums.sha256 and running:

cat checksums.sha256 | grep "$(ls mediamtx_*)" | sha256sum --check

Don't miss a new mediamtx release

NewReleases is sending notifications on new releases.