/
/
1"""Constants for the AirPlay provider."""
2
3from __future__ import annotations
4
5from dataclasses import replace
6from enum import IntEnum, StrEnum
7from typing import Final
8
9from music_assistant_models.enums import ContentType, PlayerFeature
10from music_assistant_models.media_items import AudioFormat
11
12from music_assistant.constants import CONF_ENTRY_SYNC_ADJUST
13from music_assistant.controllers.streams.constants import SEEK_WAIT_THRESHOLD
14
15DOMAIN = "airplay"
16
17
18class StreamingProtocol(IntEnum):
19 """AirPlay streaming protocol versions."""
20
21 RAOP = 1 # AirPlay 1 (RAOP)
22 AIRPLAY2 = 2 # AirPlay 2
23
24
25class AirPlayRemoteCommand(StrEnum):
26 """Transport commands received from an AirPlay receiver."""
27
28 PLAY = "play"
29 PAUSE = "pause"
30 PLAY_PAUSE = "play_pause"
31 NEXT = "next"
32 PREVIOUS = "previous"
33
34
35class ClockReadiness(StrEnum):
36 """
37 How a receiver's clock readiness resolved for an anchor decision.
38
39 Only PROJECTED carries an instant; the rest all mean "anchor on the lead
40 alone", but for very different reasons - one is a device that will not play
41 at all, and treating them alike hides it.
42 """
43
44 # The binary projected when the receiver's clock becomes usable.
45 PROJECTED = "projected"
46 # NTP timing: there is no receiver clock to wait for.
47 NOT_APPLICABLE = "not_applicable"
48 # The receiver never answered our PTP clock and will render silence.
49 STALLED = "stalled"
50 # Nothing arrived within the wait: a slow device (retryable) or a receiver
51 # whose readiness went unreported.
52 UNREPORTED = "unreported"
53
54
55CONF_PASSWORD: Final[str] = "password"
56# Storage-only marker (no config entry) set when the device rejected the stored
57# password, so the player keeps asking for setup across restarts until a working
58# password is entered.
59CONF_PASSWORD_INVALID: Final[str] = "password_invalid"
60# Provider marker that the stored password verdicts were reviewed once. Releases
61# that could not tell a password challenge apart from a flat refusal wrote the
62# key above for both, so what they left behind is no evidence about a password
63# and is dropped a single time; a device that really challenges marks itself
64# again on its next connect.
65CONF_PASSWORD_MARKERS_REVIEWED: Final[str] = "password_markers_reviewed"
66CONF_IGNORE_VOLUME: Final[str] = "ignore_volume"
67CONF_ENCRYPTION: Final[str] = "encryption"
68# Advanced per-device streaming mode: pins the protocol/timing lane for
69# receivers whose automatic route misbehaves. Options are offered per device
70# capability; Automatic is the default and the setting is only ever written by
71# the user â a failing automatic route is reported, never switched away from.
72CONF_STREAMING_MODE: Final[str] = "streaming_mode"
73# Per-device 24-bit toggle, only offered for devices that advertise 24-bit
74# support. Defaults per device family (see default_hires_enabled).
75CONF_ENABLE_HIRES: Final[str] = "enable_hires"
76# Provider marker that the compatibility-mode pins were reset once. Earlier
77# releases switched a player here themselves when its native control channel
78# failed (usually a network dropout), pinning it to a lane many devices reject
79# outright, so those machine-written values are returned to Automatic a single
80# time; a deliberate choice can simply be made again.
81CONF_COMPAT_PINS_REVIEWED: Final[str] = "compat_pins_reviewed"
82STREAMING_MODE_AUTO: Final[str] = "auto"
83STREAMING_MODE_AP2_PTP: Final[str] = "ap2_ptp"
84STREAMING_MODE_AP2_NTP: Final[str] = "ap2_ntp"
85STREAMING_MODE_AP2_COMPAT: Final[str] = "ap2_compat"
86STREAMING_MODE_RAOP: Final[str] = "raop"
87CONF_STORED_VOLUME: Final[str] = "stored_volume"
88CONF_COMPANION_CREDENTIALS: Final[str] = "companion_credentials"
89CONF_MRP_CREDENTIALS: Final[str] = "mrp_credentials"
90CONF_NATIVE_MRP_CREDENTIALS: Final[str] = "native_mrp_credentials"
91
92# Bundle id of the Music Assistant tvOS dashboard app, launched over Companion on
93# eligible Apple TVs (see tvos/docs/launch-contract.md).
94TVOS_APP_BUNDLE_ID: Final[str] = "io.music-assistant.tvos"
95
96AIRPLAY_DISCOVERY_TYPE: Final[str] = "_airplay._tcp.local."
97COMPANION_DISCOVERY_TYPE: Final[str] = "_companion-link._tcp.local."
98MRP_DISCOVERY_TYPE: Final[str] = "_mediaremotetv._tcp.local."
99RAOP_DISCOVERY_TYPE: Final[str] = "_raop._tcp.local."
100DACP_DISCOVERY_TYPE: Final[str] = "_dacp._tcp.local."
101
102# Floor for a late joiner's anchor, and the one it rests on whenever the binary
103# reports no readiness projection ([STATUS] clock_ready). A joiner cannot
104# honour an instant in the past, and that second case has no device evidence at
105# all, so this carries it the whole way: the command's trip to the binary, the
106# binary's own 250 ms floor, and the receiver seating the anchor. The value is
107# field-proven, not derived from those.
108# It is NOT headroom for the binary's post-commit clock verification, which
109# arms only when the receiver has still not probed by the time it reads the
110# START, and only for an anchor that clears the receiver queue depth plus
111# 500 ms - past ~2 s of effective depth, an anchor this close leaves no room.
112AIRPLAY_LATE_JOIN_MIN_HEADROOM_MS: Final[int] = 2500
113# How long a group start, a join or the Sendspin bridge waits for the binary's
114# first receiver-clock projection ([STATUS] clock_ready with state=probing|
115# ready). The binary emits its first line right after [STATUS] connected and
116# refreshes it about every 250 ms, and the projection exists from the receiver's
117# first probe (~1078 ms after connect on a cold device), so this only has to
118# cover a slower device before giving up and anchoring on the lead alone.
119# Independent of the binary's own stall report (state=stalled), which is a
120# slower, higher-confidence diagnosis of a receiver that never answers at all: a
121# wait that times out here has simply run out of planning time and falls back,
122# while a stall says the speaker will not play. Keep them apart - tightening the
123# stall report to meet this deadline would trade the margin that keeps it free
124# of false alarms.
125AIRPLAY_CLOCK_READY_TIMEOUT_MS: Final[int] = 2500
126# Lead added on top of a reported readiness instant, wherever one is waited for.
127# The binary refuses to place an anchor inside its own 250 ms floor, measured
128# from when IT reads the START command rather than when the server sends it (the
129# same trap as AIRPLAY_START_LEAD_MS), so the lead carries that floor plus 250 ms
130# for the command reaching the binary and for the convergence error of a
131# projection made from the receiver's very first probe.
132AIRPLAY_CLOCK_READY_LEAD_MS: Final[int] = 500
133# Default receiver buffer depth per device family: (manufacturer wildcard,
134# model wildcard, firmware wildcard) -> depth in ms, matched case-insensitively
135# in order, first match wins; unmatched devices stay on Automatic (the binary's
136# stock depth). The table is EMPTY since the buffered (type 103) stream became
137# the auto-route for the receivers that used to need a deepened queue: the
138# LinkPlay pipelines that starved on the realtime stream (WiiM at 1750 ms,
139# Edifier MS50A silent below 2500 ms) manage their own buffer on the buffered
140# stream and play fine on Automatic. The per-player depth setting remains as
141# an advanced override; extend the table only for devices that starve on the
142# route they actually take.
143AIRPLAY_BUFFER_DEPTH_DEFAULTS: Final[tuple[tuple[str, str, str, int], ...]] = ()
144# Per-player override of the splice receiver-queue depth in ms (0 = automatic).
145CONF_BUFFER_DEPTH: Final[str] = "buffer_depth"
146# How long a plain (non-join) START waits for the binary's [STATUS] started ack.
147# A strict buffered receiver can reject its anchor until its clock is seated;
148# cliairplay then makes up to 12 attempts, 500 ms apart. Cover that 5.5-second
149# retry span plus control-response and status-delivery margin.
150AIRPLAY_START_ACK_TIMEOUT_MS: Final[int] = 7000
151# A join can additionally withhold its ack while receiver-clock verification
152# settles. Keep its independently named bound aligned with the buffered retry
153# span too; command failures still answer either wait immediately.
154AIRPLAY_JOIN_START_ACK_TIMEOUT_MS: Final[int] = 7000
155# How far the content a corrected anchor actually cut may fall short of the cut
156# it asked for before the reported media position is re-based and the shortfall
157# reported. The binary derives the cut it took from the bytes it discarded, so a
158# few ms of byte quantization is expected and correcting for it would only
159# jitter the base; anything larger means the cut really did end early (the input
160# ran out inside it, or a teardown settled it) and the position is over-advanced
161# by that much for the rest of the anchor.
162AIRPLAY_CONTENT_CUT_TOLERANCE_MS: Final[int] = 20
163# Anchor leads for a readiness-confirmed START (cold and warm alike), solo and
164# group: the session only anchors after the binary confirmed the connection
165# ([STATUS] connected) and the new audio flowing ([STATUS] audio), so a lead no
166# longer guesses at setup or transcoder spin-up time. Both cover the receiver
167# re-anchor (accepted down to ~150 ms in the flush-ladder measurements) plus
168# the command's trip down the pipe; the group one also covers fanning the
169# shared instant out to every member. The pipe margin is what keeps them
170# workable: the binary rejects any instant inside its own 250 ms floor,
171# measured from when IT reads the command, and corrects a miss to that floor
172# plus another full lead â so a lead sitting exactly on the floor misses by the
173# delivery time every time and turns a start into a group-wide re-anchor ladder.
174AIRPLAY_START_LEAD_MS: Final[int] = 400
175AIRPLAY_GROUP_START_LEAD_MS: Final[int] = 500
176# Cold GROUP starts anchor further out: a receiver on a brand-new session
177# still acquires its PTP slave lock (~1.7-2.3 s measured on Sonos) and cannot
178# render at an anchor inside that window - it starts late and the group opens
179# audibly out of sync. Warm re-anchors reuse a locked clock and keep the
180# short leads above; solo cold starts have no sync partner to miss.
181AIRPLAY_COLD_GROUP_START_LEAD_MS: Final[int] = 2500
182
183# How long a start waits for the source to hand over its first audio before it
184# judges the members on what they never received. A seek may land up to
185# SEEK_WAIT_THRESHOLD seconds ahead of what the source has produced, and the
186# wait has to outlast the producer covering that; the margin covers its own
187# spin-up. It is a backstop rather than a budget: this runs under the player
188# lock, so a producer that neither delivers nor gives up would otherwise hold
189# every command for the player behind it.
190AIRPLAY_FEED_START_TIMEOUT: Final[float] = SEEK_WAIT_THRESHOLD + 5
191# Margin added on top of a member's reported warm lead (the splice-timeline
192# queue depth; that timeline is the default for every native AirPlay 2 session)
193# when anchoring a warm re-start: covers the command round-trips between the
194# flush acks and the shared START so every member's skip target lands beyond
195# its queued audio.
196AIRPLAY_SPLICE_LEAD_MARGIN_MS: Final[int] = 150
197
198# Floor for the late-join PCM ring, which has to hold every sample between the
199# audible position and the write head: a joiner's anchor maps onto content the
200# group was already fed but has not played yet. That distance - the write-head
201# lead - is the sum of every buffer between the session's byte counter and the
202# speaker, and it is far larger than the binary's own ring alone:
203# ~5.7 s the per-member ffmpeg and the pipes around it (measured 5.2 s
204# steady / 5.7 s peak at 44.1 kHz/16-bit, which is the worst case in
205# SECONDS - the same buffers hold ~4.3 s at the 32-bit hi-res carrier
206# rate, and low-delay ffmpeg flags do not shrink them)
207# ~4.0 s the cliairplay ring: the binary's own lead (2000 ms default,
208# clamped to the device-reported window) plus its 2 s of slack
209# ~2.0 s the receiver's own buffer
210# ~11.7 s in total, against 8.9-11.0 s measured across native AirPlay 2
211# sessions (Apple TV and Sonos, joining in both directions). This floor is that
212# sum rounded up, and it is only a floor: the lead is measured per session and
213# the ring grows to match, because a receiver that reports a wider lead window
214# or buffers more deeply moves the sum with nothing to announce it.
215AIRPLAY_LATE_JOIN_RING_MIN_SECONDS: Final[float] = 12.0
216# Grown on top of the largest lead a session has actually shown, so a lead that
217# drifts up between two joins cannot clip the oldest sample a joiner needs.
218AIRPLAY_LATE_JOIN_RING_MARGIN_SECONDS: Final[float] = 2.0
219# Hard bound on the ring, which is per session (one ring feeds every member) and
220# costs byte_rate x seconds. Bounded in BYTES rather than seconds on purpose:
221# the seconds the ring must hold are largest at the LOWEST byte rate (see the
222# measurements above), so a single byte bound buys ~35 s at 44.1 kHz/16-bit -
223# three times the measured lead, where the seconds are actually needed - and
224# still ~16 s at the 32-bit hi-res carrier, where the pipeline holds fewer
225# seconds anyway. 6 MiB per playing group is a few percent of the server's idle
226# footprint.
227AIRPLAY_LATE_JOIN_RING_MAX_BYTES: Final[int] = 6 * 1024 * 1024
228
229# Delays (seconds) between automatic re-join attempts for a group member whose
230# cliairplay process died unexpectedly mid-session (e.g. the device rode out a
231# network blackout longer than the binary's own keepalive tolerance). A device
232# recovering from a network dropout typically needs tens of seconds to come
233# back, so the ladder stretches to a few minutes; every attempt re-validates
234# that the group still plays and the player was not repurposed meanwhile, and
235# the whole schedule is abandoned as soon as either no longer holds.
236AIRPLAY_REJOIN_ATTEMPT_DELAYS: Final[tuple[int, ...]] = (5, 15, 30, 60, 120)
237
238# Shared audible instant for a native announcement over a live stream: now +
239# the largest member span + this margin. A member can only mix the clip into
240# audio it has not delivered yet, and its span (warm_lead_ms on the splice
241# timeline, the reported lead_ms otherwise) is how far its delivery head runs
242# ahead of the audible position - so the earliest instant EVERY member can
243# honor lies one max-span out. The margin covers fanning the command out over
244# the pipes and the per-member arm processing, so one shared instant stays
245# feasible for all members.
246AIRPLAY_ANNOUNCE_AT_MARGIN_MS: Final[int] = 300
247# Span assumed for a member whose binary reported neither a warm lead nor a
248# device lead (both read 0 = unreported): the binary's own default playback
249# lead, which bounds how far its delivery head can run ahead.
250AIRPLAY_ANNOUNCE_FALLBACK_SPAN_MS: Final[int] = 2000
251# Music gain (dB) under the clip while it plays; the binary ramps the duck in
252# and out itself. <= -60 mutes the music entirely. -18 dB puts the music
253# clearly in the background under speech (-12 was field-judged too shallow).
254AIRPLAY_ANNOUNCE_DUCK_DB: Final[int] = -18
255# Silence prepended to every announcement clip. The binary holds the music duck
256# for the whole clip file, so this is a window in which the music is already
257# ducked and the announcement has not started yet: the announcement volume is
258# raised inside it, where it cannot be heard as the music getting louder. It
259# has to cover the duck's ramp plus the round trip of the volume command.
260AIRPLAY_ANNOUNCE_DUCK_LEAD_S: Final[float] = 0.5
261# Silence appended to every announcement clip, so the volume restore has a
262# cushion to land in. The binary holds the duck for the whole clip, so the
263# restore lands while the music is still ducked instead of racing the duck's
264# 200 ms tail ramp (a restore that lands after the ramp plays a moment of
265# full-level music at the still-bumped device volume).
266AIRPLAY_ANNOUNCE_DUCK_TAIL_S: Final[float] = 1.0
267# On top of the lead to the commanded instant: how long to wait for a member's
268# announce_started before treating that member as not announcing. An outdated
269# binary silently ignores the unknown command, so this bounded wait is also what
270# detects that, and the announcement then fails instead of playing nowhere.
271AIRPLAY_ANNOUNCE_STARTED_TIMEOUT_MS: Final[int] = 3000
272# On top of the clip's audible end: how long to wait for announce_done. The
273# wait stays bounded because a queue that ends mid-clip emits its eof, which
274# ends the status stream while the clip still plays out over the drain.
275AIRPLAY_ANNOUNCE_DONE_TIMEOUT_MS: Final[int] = 5000
276# Pad after the clip's audible end before the pre-announcement volume is
277# restored: covers the jitter between the acked instant and true audibility.
278AIRPLAY_ANNOUNCE_VOLUME_RESTORE_PAD_MS: Final[int] = 500
279# Where inside the ducked lead-in the announcement volume is raised: past the
280# duck's own ramp, with the rest of the lead left for the command to reach the
281# receiver before the announcement itself becomes audible.
282AIRPLAY_ANNOUNCE_VOLUME_BUMP_DELAY_MS: Final[int] = 200
283# The AirPlay volume parameter is linear dB: 0..100 maps onto -30..0 dB on
284# every flow (libraop raopcl_float_volume, reused verbatim by the native AP2
285# SET_PARAMETER path), so one volume point is exactly 0.3 dB of output. This
286# makes the announcement volume bump's effect on the music bed computable, and
287# the duck is deepened by the same amount to keep the music's perceived level
288# at the configured duck depth.
289AIRPLAY_VOLUME_DB_PER_POINT: Final[float] = 0.3
290
291# Cover art is rendered to a local JPEG for the binary to embed (the binary
292# does not fetch URLs). 512px keeps the SET_PARAMETER payload small while still
293# looking sharp on speaker apps and the Apple TV now-playing screen.
294AIRPLAY_ARTWORK_SIZE: Final[int] = 512
295# How long a track-change metadata push waits for that render, so the artwork
296# can ride the SENDMETA bundle and the receiver rewrites its now-playing state
297# once instead of twice (bare replace, then artwork). A render that misses the
298# budget is not abandoned: it keeps running and is delivered with the
299# stand-alone ARTWORK command once it completes.
300AIRPLAY_ARTWORK_RENDER_TIMEOUT: Final[float] = 1.5
301EXTERNAL_ARTWORK_PATH_PREFIX: Final[str] = "external_artwork"
302
303# Per-protocol credential storage keys
304CONF_RAOP_CREDENTIALS: Final[str] = "raop_credentials"
305CONF_AIRPLAY_CREDENTIALS: Final[str] = "airplay_credentials"
306
307# AirPlay serves the shared sync-adjust control as a non-advanced (always visible)
308# setting: the binary handles the playback lead automatically and does not apply
309# device-reported render latency, so sync_adjust is the primary way to compensate
310# a device wired to a TV / AV receiver / amplifier that adds its own audio delay.
311# The AirPlay-scoped strings spell out the sign; the shared entry stays advanced
312# for other providers.
313CONF_ENTRY_SYNC_ADJUST_AIRPLAY = replace(CONF_ENTRY_SYNC_ADJUST, advanced=False)
314
315# Interactive setup-flow input keys (transient PIN/password form fields and the
316# optional "set up now?" choice for the control pairing steps).
317CONF_PAIRING_PIN: Final[str] = "pairing_pin"
318# every AirPlay pairing PIN (streaming, Companion, MRP) is 4 digits
319PAIRING_PIN_FORMAT: Final[str] = "####"
320CONF_PAIRING_PASSWORD: Final[str] = "pairing_password"
321CONF_COMPANION_PAIRING_PIN: Final[str] = "companion_pairing_pin"
322CONF_MRP_PAIRING_PIN: Final[str] = "mrp_pairing_pin"
323CONF_PAIR_NOW: Final[str] = "pair_now"
324
325FALLBACK_VOLUME: Final[int] = 20
326AIRPLAY_VOLUME_MUTE: Final[float] = -144.0
327# How long a volume we sent ourselves keeps the device's own volume reports from
328# being acted on. A receiver echoes every level it is given back over DACP, and
329# an echo that arrives after the next level was already sent would otherwise be
330# read as the user turning the knob and written straight back to the device.
331AIRPLAY_VOLUME_ECHO_GRACE_S: Final[float] = 2.0
332
333AIRPLAY_PCM_FORMAT = AudioFormat(
334 content_type=ContentType.from_bit_depth(16), sample_rate=44100, bit_depth=16
335)
336# Sample rates advertised for a receiver that supports 24-bit (AirPlay 2 flow
337# only). At 24-bit the cliairplay binary expects raw s32le on stdin and truncates
338# to 24-bit ALAC internally.
339AIRPLAY_HIRES_SAMPLE_RATES: Final[list[tuple[int, int]]] = [(44100, 24), (48000, 24)]
340
341# Bits in the audioFormat bit space (shared with the receiver's /info format
342# tables) that mark 24-bit ALAC: 44.1 kHz and 48 kHz respectively. Receivers
343# understate these - the Apple TV lists them for its buffered stream only, yet
344# renders them fine on the realtime stream - so a device advertising either bit
345# on either stream is treated as 24-bit capable.
346AIRPLAY_HIRES_AUDIO_FORMATS: Final[int] = (1 << 19) | (1 << 21)
347
348BASE_PLAYER_FEATURES: Final[set[PlayerFeature]] = {
349 PlayerFeature.PLAY_MEDIA,
350 PlayerFeature.PLAY_ANNOUNCEMENT,
351 PlayerFeature.SET_MEMBERS,
352 PlayerFeature.MULTI_DEVICE_DSP,
353 PlayerFeature.VOLUME_SET,
354 PlayerFeature.VOLUME_MUTE,
355}
356
357
358PIN_REQUIRED = 0x8
359PASSWORD_BIT = 0x80
360LEGACY_PAIRING_BIT = 0x200
361
362# Provider setting: opt-in for the shared PTP daemon's per-packet timing trace
363# (Announce/Sync/Follow_Up) when verbose logging is active. Off by default â
364# the trace floods the log and only matters for clock-sync debugging.
365CONF_VERBOSE_PTP_LOGGING: Final[str] = "verbose_ptp_logging"
366
367# The cliairplay binary tags no log levels on its output, so a genuine problem is
368# recognised by keyword and promoted to a warning that stays visible at normal levels.
369CLI_PROBLEM_MARKERS: Final[tuple[str, ...]] = ("error", "cannot", "failed", "unable")
370# Bound on how many of those promoted lines the shared PTP daemon may produce per
371# window before the rest are counted instead of logged. The markers above are
372# deliberately broad, and "error" is ordinary vocabulary in clock telemetry
373# (offset error, path delay error), so with the daemon's per-packet trace running
374# at ~10 lines/s a single matching line would otherwise fill the log at WARNING.
375# A burst still gets through, which is what a real one-shot daemon failure is.
376PTP_DAEMON_WARN_BURST: Final[int] = 5
377PTP_DAEMON_WARN_WINDOW: Final[float] = 60.0
378