Added
- Production-Grade In-App Self-Update Engine:
- Implemented modular self-update architecture (
src/updater/withcheck.rs,artifact.rs,download.rs,verify.rs,extract.rs, andapply.rs). - Added streaming SHA-256 integrity verification validating exact hash matching against release
SHA256SUMS. - Added hardened archive extraction for
.tar.gzand.zipwith strict path traversal protection against..components and absolute root paths. - Added multi-platform installation strategies: atomic binary replacement with
.oldbackup and automatic rollback on Unix/Linux/macOS/Termux, detached helper process on Windows, and Homebrew prefix detection guiding users tobrew upgrade moviebox-tui. - Added active work protection deferring self-update when active video playback or background downloads are running.
- Connected
[u]shortcut and[u] Update Nowbutton in the existing Update Available modal, preserving visual styling, animations, and dismissal model. - Added safe terminal state restoration (
disable_raw_mode,LeaveAlternateScreen,DisableMouseCapture,ShowCursor) before process exec/restart.
- Implemented modular self-update architecture (
- Update System Concurrency & Platform Compatibility Architecture:
- Added single-flight guard (
is_checking_updates) ensuring manual (/update) and automatic startup checks never spawn duplicate concurrent network requests. - Added shared geometry calculation (
UpdateModalLayout,update_modal_layout) guaranteeing 1:1 synchronization between popup rendering and mouse hit testing. - Added release asset data modeling (
Release,ReleaseAsset,TargetPlatform) with deterministic platform compatibility detection across macOS Universal, Linux x64/arm64, Windows x64/arm64, and Android Termux ARM64. - Added dedicated integration test suite
tests/update_lifecycle.rstesting update single-flighting, error recovery, mouse hit testing, and asset filtering.
- Added single-flight guard (
- Comprehensive QA & Regression Test Architecture:
- Introduced a 132-test automated suite covering critical algorithmic boundaries, end-to-end user journeys, watch history reconciliation & precision progress tracking, cross-mode history audit, in-app self-update lifecycle, real-world release artifact downloads, live SHA-256 verification, genuine version upgrade execution, content & metadata loading pipelines, stale request isolation, active player session lifecycle & duplicate launch protection, dynamic slash command autocomplete (
/download-dir reset), search/command draft cancellation viaEsc, error handling, addon manifest validation, mouse interactions, modal dismissals, TUI rendering across terminal size matrices, state reconciliation, crypto HMAC signing, download chunk arithmetic, and URL/stem security. - Added structured integration tests in
tests/(content_pipeline.rs,error_handling.rs,tui_acceptance.rs,history_reconciliation.rs,history_audit.rs,update_lifecycle.rs,real_acceptance.rs,version_upgrade_e2e.rs,cache_lifecycle.rs,player_integration.rs,m3u_integration.rs,addons_manifest.rs,download_integration.rs,url_security.rs) and test fixtures (tests/fixtures/). - Added
docs/testing.mddetailing test architecture, command references, and manual QA procedures.
- Introduced a 132-test automated suite covering critical algorithmic boundaries, end-to-end user journeys, watch history reconciliation & precision progress tracking, cross-mode history audit, in-app self-update lifecycle, real-world release artifact downloads, live SHA-256 verification, genuine version upgrade execution, content & metadata loading pipelines, stale request isolation, active player session lifecycle & duplicate launch protection, dynamic slash command autocomplete (
- Playback Tracking & Watch History Progress:
- Added real-time playback position tracking for
mpvwith injected tracker script (moviebox_tracker.lua) and 5-second periodic state auto-save to disk. - Added automatic startup state reconciliation (
reconcile_pending_playback_states) ensuring watched progress is preserved even when closing the terminal or killing tmux mid-playback. - Added two-tone smooth scrub line progress bars (
━─────── 1% (2h 18m left) • Watched 11h ago) and completion status badges ([✓ Completed],[✓ Watched]) in/historyand Details screens. - Added cross-provider title-based history deduplication and auto-resume from the last watched position.
- Added real-time playback position tracking for
- Addon Mode Watch History Parity:
- Added full watch history support (
/history) in Addon Mode matching Streaming Mode, enabling seamless watch progress tracking, scrub bars, and completion badges for community HTTP addon content.
- Added full watch history support (
- Pluggable Provider Trait & Capability Architecture:
- Formalized the public
ProviderandReleaseProvidertraits across all built-in scrapers (MovieBox,4KHDHub,CircleFTP,DhakaFlix, andAddons). - Added
ProviderCapabilities(supports_search,supports_pagination,supports_series,supports_subtitles,supports_homepage) andMovieBoxService::capabilities()for dynamic capability reporting. - Added structured
ProviderErrorboundaries (Network,RateLimited,NotFound,Parsing,Unavailable) with.user_message()for consistent error notifications.
- Formalized the public
- Theme System Expansion & Official Color Calibration:
- Added official Dracula, Gruvbox, and Rosé Pine themes to the
/themepicker alongside Catppuccin and Nord. - Added alias parsing support for
"dracula","gruvbox","rose-pine", and"catppuccin". - Guaranteed 100% transparent terminal compatibility across all themes with zero background opacity overrides.
- Fixed modal backdrop rendering by removing fullscreen screen clearing when opening
/theme. - Optimized live preview navigation to eliminate unnecessary disk I/O on arrow key navigation.
- Added official Dracula, Gruvbox, and Rosé Pine themes to the
- Universal Multi-OS Player Detection & Flathub/Snap Compatibility:
- Added sub-millisecond, filesystem-backed player probing across Linux (Flathub, Flatpak exports, Snap, and Native), macOS (Homebrew, MacPorts, App Bundles), Windows (Program Files, WinApps, Scoop, Chocolatey, WinGet), and Android (Termux).
- Fixed Flathub/Flatpak VLC detection failure by adding direct probes for
~/.local/share/flatpak/exports/bin/org.videolan.VLCand/var/lib/flatpak/exports/bin/org.videolan.VLC. - Added full Flathub/Flatpak and Snap compatibility for MPV (
io.mpv.Mpv,/snap/bin/mpv). - Centralized player process construction (
build_player_process_command) and standardized subtitle flag arguments (--sub-file=<path>) across all platforms.
- Codebase Optimization & Comprehensive Caching Architecture:
- Centralized application paths (
config_dir,data_dir,cache_dir,logs_dir,scripts_dir,playback_state_dir) insrc/config.rs. - Added dedicated disk caching for Addon Mode stream aggregation (
2hTTL), catalog/browsepresets (1hTTL), and verified manifests (24hTTL). - Added search pagination caching (
search_{hash}_{page}.json) preventing redundant API calls when navigating multi-page search results. - Eliminated redundant
reqwest::Clientallocations in background poster pipelines in favor of the sharedservice.http_client(). - Streamlined
MovieBoxServiceusage across background tasks and removed redundantaddon_clientfield fromAppState. - Centralized formatting utilities (
format_file_size,format_duration) insrc/tui/text.rs. - Modernized
Configloading and persistence with safe, standard Serde derives.
- Centralized application paths (
- Addon Mode (Community HTTP Addons):
- Added full support for community HTTP addon manifests (
/manifest.json,/catalog,/meta,/stream) with dedicatedCtrl+Amode switching. - Pre-installed and locked Cinemeta out-of-the-box as the default core metadata provider with zero API keys required.
- Added interactive Addon Manager dialog (
/addons,Ctrl+Pin Addon Mode) with one-click enabling, removal, and manifest URL adding. - Added concurrent multi-addon stream resolution aggregating playable releases from all enabled stream addons.
- Added a smart runtime torrent detector that automatically detects if an addon's streams are 100% blocked raw torrents (e.g., Torrentio without Debrid) and flashes a UI warning toast that only HTTP streams are supported.
- Added full support for community HTTP addon manifests (
- Addon Mode
/browse& Curated Catalog Exploration:- Added
/browsesupport in Addon Mode with a minimal, organized 4-preset catalog picker (Top Movies,Top Series,Top Rated Movies,Top Rated Series). - Added direct catalog fetching (
/catalog/{type}/{id}.json) with poster hydration, details navigation, stream resolution, and/reloadsupport.
- Added
- Strict Slash Command Guarding & Guidance:
- Intercepted all
/slash commands to guarantee zero remote catalog network requests. - Added warning toast notifications for unrecognized slash commands (
"Command '/xyz' is not recognized. Type '/' to view available commands."). - Added platform-aware mode-guidance toasts (
^T/^S/^Aon macOS,Ctrl+T/Ctrl+S/Ctrl+Aon Linux/Windows) for mode-restricted commands.
- Intercepted all
- Active Mode & Provider State Persistence:
- Added
active_modeconfiguration field inconfig.jsonautomatically persisting and restoring the last active mode (streaming,tv,addon) and active provider across app restarts.
- Added
- Configurable Mode Navigation:
- Added
/enable-streaming,/disable-streaming,/enable-tv, and/disable-tvslash commands alongside/enable-addonsand/disable-addons. - Enforced safety validation ensuring at least one mode remains active and gracefully migrating focus when disabling the current mode.
- Added
- Dynamic Multi-Source Host & Resolver Resolution:
- Added 100% dynamic domain-based host extractor (
extract_domain_label) and stream tag parser (detect_stream_host) identifying and formatting direct hosts (Pixeldrain, Hubcloud, Fast Download, Google Drive, Mega, etc.) and debrid resolvers without hardcoded tables.
- Added 100% dynamic domain-based host extractor (
- Full Emoji & Symbol Sanitization:
- Added
strip_emojisandclean_stream_textsanitizing all raw stream titles, release names, source labels, and languages from community addons for clean terminal alignment without broken characters. - Standardized checkbox representations to clean ASCII
[x] / [ ].
- Added
- Complete Mouse Navigation:
- Added dynamic footer hitboxes for
[Ctrl+S] Streaming,[Ctrl+T] TV,[Ctrl+A] Addons,[Ctrl+P] {Provider},[?] Help,[q] Quit. - Added complete mouse click support for Addon Manager modal and browse popups.
- Added dynamic footer hitboxes for
Fixed
- Windows MSVC Static CRT Linking (
+crt-static):- Configured
target-feature=+crt-staticin.cargo/config.tomlforx86_64-pc-windows-msvcandaarch64-pc-windows-msvc, statically embedding the C runtime to eliminate externalVCRUNTIME140.dlldependency and resolve0xC0000135(STATUS_DLL_NOT_FOUND) on clean Windows installations.
- Configured
- Cross-Platform Installer Polish & Windows In-Memory Execution:
- Replaced file-based execution commands in Windows documentation with the in-memory stream pipeline (
irm ... | iex) to eliminatePSSecurityExceptionexecution policy blocks. - Added immediate active process
$env:PATHupdate ininstall.ps1so the command is recognized in the current shell session without terminal restart. - Replaced rigid fixed-width boxed summary tables with responsive, borderless hero layouts across both
install.ps1andinstall.sh, preventing broken box-drawing characters and layout overflow on narrow screens.
- Replaced file-based execution commands in Windows documentation with the in-memory stream pipeline (
- Pending History Reconciliation Order:
- Sorted pending Lua tracker state files chronologically during startup reconciliation to guarantee correct playback state replay order.
- MovieBox Title Sanitization (DEF-02):
- Fixed destructive title truncation where leading bracket tags (
[Dub],[1080p],[RAW]) and titles starting with parentheses (e.g.(500) Days of Summer) were stripped down to empty strings. - Preserved release years in parentheses (
Inception (2010)) and added a fallback safeguard returning the trimmed original title if sanitization ever results in an empty string.
- Fixed destructive title truncation where leading bracket tags (
- Watch History Identity & Deduplication Collisions (DEF-03):
- Enforced
stypeseparation inHistoryManager::is_same_showso Movies and TV Series sharing identical titles (e.g.Home) never overwrite one another. - Enforced strict canonical identity (
provider + subject_id), preventing cross-provider conflicts and ensuring remakes with differing release years remain distinct entries.
- Enforced
- Background Episode Playback State Reconciliation (MISS-01):
- Fixed a state loss bug in
reconcile_pending_playback_stateswhere a completed episode's watched status was discarded if the user had already advanced to a subsequent episode before the state file was processed.
- Fixed a state loss bug in
- Windows MPV Script Options Path Escaping (DEF-04):
- Fixed path corruption in MPV's
--script-optson Windows by normalizing backslashes (\) to forward slashes (/), preventing MPV escape sequence parsing from corruptingstate_filepaths inmoviebox_tracker.lua.
- Fixed path corruption in MPV's
- M3U Single-Quoted Attribute Support (DEF-07):
- Extended
M3UParserattribute extraction to support both single-quoted (tvg-id='...') and double-quoted attributes, preserving channel IDs, logos, and groups across varied IPTV playlists.
- Extended
- Continuous OS-Level SIGINT Handling (DEF-05):
- Wrapped
tokio::signal::ctrl_c()in a continuous background loop to ensure repeated non-interactive OS signals are reliably handled.
- Wrapped
- Subtitle Prefetch Fallback (DEF-08):
- Reduced subtitle download timeout from 30s to 8s to prevent unnecessary startup delays when launching external players if a subtitle mirror hangs.
- Addon Stream Sorting & Rendering:
- Fixed addon streams randomly scrambling on UI hover when sizes are tied by adding a secondary stable sort based on the mirror label.
- Fixed misleading
0MBstream sizes for community addons that omit video sizes by cleanly rendering--instead.
- Terminal Race Condition & Blank Screen on
/clear-cache:- Replaced physical terminal clear with a soft image refresh when executing
/clear-cache, resolving a race condition with terminal emulators that swallowed the full Home screen render and caused the screen to go completely blank after a few seconds. - Added comprehensive state isolation preventing search queries, results, and details states from lingering after cache clears.
- Sanitized slash command input handling to prevent visual query glitches.
- Replaced standard status messages with elevated toast notifications for cache actions.
- Replaced physical terminal clear with a soft image refresh when executing
- Atomic Mode Highlight & Single Active Selection:
- Added canonical
AppModeenum (Streaming,Tv,Addon) and atomic state transitions guaranteeing that only one active mode is highlighted in the bottom dock at any time. - Hardened state isolation with automatic cleanup across mode switches.
- Added canonical
- Notification Readability & Word-Boundary Wrapping:
- Replaced horizontal middle-truncation with unicode display-width aware word wrapping (
wrap_text). - Added adaptive width (up to 72 chars) and dynamic height scaling with guaranteed unbroken rounded borders.
- Replaced horizontal middle-truncation with unicode display-width aware word wrapping (
- Resilient Addon Metadata & Fallbacks:
- Added flexible visitors and serde aliases for
genres,cast,director,imdbRating,releaseInfo, andruntimepreventing deserialization failures across varied community addon JSON schemas. - Added multi-tier fallback resolution in the Details screen to guarantee titles, release years, synopsis, and posters are always preserved from search results and previews.
- Added flexible visitors and serde aliases for
- Android / Termux TLS Certificate Compatibility:
- Switched
reqwestto use pure-Rust embeddedwebpki-rootscertificate verification, resolvingrustls-platform-verifiercrashes and panics in non-JVM Android CLI environments like Termux.
- Switched
- Transparent Stream & Search Diagnostics:
- Replaced misleading generic
"No matches"and"Rate Limit"errors with truthful, contextual diagnostics:"No stream sources available on {provider}","Network connection failed to {provider}","Rate limited by {provider}", and"Episode S{season}E{episode} is not listed on {provider}". - Added helpful actionable hints (
Press Ctrl+P to try another provider, or r to refresh).
- Replaced misleading generic
- Rate-Limiting & Concurrency Hardening:
- Added HTTP 429
Retry-Afterheader parsing with bounded exponential backoff inMovieBoxClient. - Added semaphore concurrency limiting (
Semaphore::new(2)) during parallel episode page resolution to prevent burst requests from tripping provider rate limiters.
- Added HTTP 429
- Addon Mode Series Hierarchy & Episode Stream Isolation:
- Fixed series misclassification as movies in Addon Mode when metadata omitted the
videosarray by ensuring canonical season structures and series-first metadata endpoint prioritization. - Added regex and token-based episode stream isolation (
parse_season_episode) instream_item_to_release, preventing cross-episode stream pollution (e.g. S01E06 streams appearing when viewing S01E08). - Added preservation of
episodeNumbersarrays from addon metadata in the season list state.
- Fixed series misclassification as movies in Addon Mode when metadata omitted the
- Direct Addon & BDIX Playback & Download Dispatch:
- Fixed Addon and BDIX playback and download routing in
handle_playbackandhandle_downloadto dispatch directly to external media players and the chunk downloader, preserving custom HTTP headers (behaviorHints.headers) and source labels without unnecessary Moviebox API subtitle timeouts.
- Fixed Addon and BDIX playback and download routing in
- Selector Tab Preservation in Standard Displays:
- Maintained visibility of Audio Languages, Seasons, and Episodes selector tabs side-by-side in standard ~80-column terminals when focusing Streams, preventing tabs from disappearing when 0 streams are available.
Changed
- Modular TV Provider Architecture:
- Reorganized Live TV / IPTV provider into a dedicated module directory (
src/providers/tv/) with separatedmodels.rsandparser.rs.
- Reorganized Live TV / IPTV provider into a dedicated module directory (
- Core Infrastructure Consolidation:
- Centralized atomic file operations (
atomic_write_file,atomic_write_file_async), MD5 digest formatting (md5_hex), and text extraction helpers incache.rsandservice.rs. - Centralized application paths, border type resolution, and mode status announcements across TUI modules.
- Centralized atomic file operations (
- Addon Manager UI Optimization:
- Implemented full cursor navigation (
Left/Rightkeys) and inline editing (Backspace/Delete) for the Addon Manager input field. - Implemented a scrolling viewport renderer for the Addon Manager input, allowing editing of very long manifest URLs without wrapping or truncation.
- Compacted the Addon Manager dialog with an aligned two-tier layout placing
[ Add Manifest URL ]and[ Done ]action buttons side-by-side.
- Implemented full cursor navigation (
- Multi-System Core Module Decoupling:
- Promoted
player.rs(process management & detection),config.rs(shared configuration), andupdater.rs(release checks) to core modules insrc/, preparing the architecture for upcoming CLI and GUI frontends with full backward compatibility.
- Promoted
Documentation
- Streamlined README & Controls Guide:
- Transformed
README.mdinto a focused landing page with measured~5 MB RAMbenchmark data, defensible value propositions, and direct links to deep guides indocs/. - Created standalone
docs/controls.mdcovering all keyboard shortcuts, mouse controls, and slash commands. - Added a 3-phase project roadmap: Terminal UI (TUI) -> Command-Line Interface (CLI) -> Desktop GUI Client.
- Added a community-first feedback and support section with optional crypto donation options.
- Transformed