/
/
/
1"""Constants for the AirPlay provider."""
2
3from __future__ import annotations
4
5from dataclasses import replace
6from enum import IntEnum, StrEnum
7from typing import Final
8
9from music_assistant_models.enums import ContentType, PlayerFeature
10from music_assistant_models.media_items import AudioFormat
11
12from music_assistant.constants import CONF_ENTRY_SYNC_ADJUST
13from music_assistant.controllers.streams.constants import SEEK_WAIT_THRESHOLD
14
15DOMAIN = "airplay"
16
17
18class StreamingProtocol(IntEnum):
19 """AirPlay streaming protocol versions."""
20
21 RAOP = 1 # AirPlay 1 (RAOP)
22 AIRPLAY2 = 2 # AirPlay 2
23
24
25class AirPlayRemoteCommand(StrEnum):
26 """Transport commands received from an AirPlay receiver."""
27
28 PLAY = "play"
29 PAUSE = "pause"
30 PLAY_PAUSE = "play_pause"
31 NEXT = "next"
32 PREVIOUS = "previous"
33
34
35class ClockReadiness(StrEnum):
36 """
37 How a receiver's clock readiness resolved for an anchor decision.
38
39 Only PROJECTED carries an instant; the rest all mean "anchor on the lead
40 alone", but for very different reasons - one is a device that will not play
41 at all, and treating them alike hides it.
42 """
43
44 # The binary projected when the receiver's clock becomes usable.
45 PROJECTED = "projected"
46 # NTP timing: there is no receiver clock to wait for.
47 NOT_APPLICABLE = "not_applicable"
48 # The receiver never answered our PTP clock and will render silence.
49 STALLED = "stalled"
50 # Nothing arrived within the wait: a slow device (retryable) or a receiver
51 # whose readiness went unreported.
52 UNREPORTED = "unreported"
53
54
55CONF_PASSWORD: Final[str] = "password"
56# Storage-only marker (no config entry) set when the device rejected the stored
57# password, so the player keeps asking for setup across restarts until a working
58# password is entered.
59CONF_PASSWORD_INVALID: Final[str] = "password_invalid"
60# Provider marker that the stored password verdicts were reviewed once. Releases
61# that could not tell a password challenge apart from a flat refusal wrote the
62# key above for both, so what they left behind is no evidence about a password
63# and is dropped a single time; a device that really challenges marks itself
64# again on its next connect.
65CONF_PASSWORD_MARKERS_REVIEWED: Final[str] = "password_markers_reviewed"
66CONF_IGNORE_VOLUME: Final[str] = "ignore_volume"
67CONF_ENCRYPTION: Final[str] = "encryption"
68# Advanced per-device streaming mode: pins the protocol/timing lane for
69# receivers whose automatic route misbehaves. Options are offered per device
70# capability; Automatic is the default and the setting is only ever written by
71# the user â a failing automatic route is reported, never switched away from.
72CONF_STREAMING_MODE: Final[str] = "streaming_mode"
73# Per-device 24-bit toggle, only offered for devices that advertise 24-bit
74# support. Defaults per device family (see default_hires_enabled).
75CONF_ENABLE_HIRES: Final[str] = "enable_hires"
76# Provider marker that the compatibility-mode pins were reset once. Earlier
77# releases switched a player here themselves when its native control channel
78# failed (usually a network dropout), pinning it to a lane many devices reject
79# outright, so those machine-written values are returned to Automatic a single
80# time; a deliberate choice can simply be made again.
81CONF_COMPAT_PINS_REVIEWED: Final[str] = "compat_pins_reviewed"
82STREAMING_MODE_AUTO: Final[str] = "auto"
83STREAMING_MODE_AP2_PTP: Final[str] = "ap2_ptp"
84STREAMING_MODE_AP2_NTP: Final[str] = "ap2_ntp"
85STREAMING_MODE_AP2_COMPAT: Final[str] = "ap2_compat"
86STREAMING_MODE_RAOP: Final[str] = "raop"
87CONF_STORED_VOLUME: Final[str] = "stored_volume"
88CONF_COMPANION_CREDENTIALS: Final[str] = "companion_credentials"
89CONF_MRP_CREDENTIALS: Final[str] = "mrp_credentials"
90CONF_NATIVE_MRP_CREDENTIALS: Final[str] = "native_mrp_credentials"
91
92# Bundle id of the Music Assistant tvOS dashboard app, launched over Companion on
93# eligible Apple TVs (see tvos/docs/launch-contract.md).
94TVOS_APP_BUNDLE_ID: Final[str] = "io.music-assistant.tvos"
95
96AIRPLAY_DISCOVERY_TYPE: Final[str] = "_airplay._tcp.local."
97COMPANION_DISCOVERY_TYPE: Final[str] = "_companion-link._tcp.local."
98MRP_DISCOVERY_TYPE: Final[str] = "_mediaremotetv._tcp.local."
99RAOP_DISCOVERY_TYPE: Final[str] = "_raop._tcp.local."
100DACP_DISCOVERY_TYPE: Final[str] = "_dacp._tcp.local."
101
102# Floor for a late joiner's anchor, and the one it rests on whenever the binary
103# reports no readiness projection ([STATUS] clock_ready). A joiner cannot
104# honour an instant in the past, and that second case has no device evidence at
105# all, so this carries it the whole way: the command's trip to the binary, the
106# binary's own 250 ms floor, and the receiver seating the anchor. The value is
107# field-proven, not derived from those.
108# It is NOT headroom for the binary's post-commit clock verification, which
109# arms only when the receiver has still not probed by the time it reads the
110# START, and only for an anchor that clears the receiver queue depth plus
111# 500 ms - past ~2 s of effective depth, an anchor this close leaves no room.
112AIRPLAY_LATE_JOIN_MIN_HEADROOM_MS: Final[int] = 2500
113# How long a group start, a join or the Sendspin bridge waits for the binary's
114# first receiver-clock projection ([STATUS] clock_ready with state=probing|
115# ready). The binary emits its first line right after [STATUS] connected and
116# refreshes it about every 250 ms, and the projection exists from the receiver's
117# first probe (~1078 ms after connect on a cold device), so this only has to
118# cover a slower device before giving up and anchoring on the lead alone.
119# Independent of the binary's own stall report (state=stalled), which is a
120# slower, higher-confidence diagnosis of a receiver that never answers at all: a
121# wait that times out here has simply run out of planning time and falls back,
122# while a stall says the speaker will not play. Keep them apart - tightening the
123# stall report to meet this deadline would trade the margin that keeps it free
124# of false alarms.
125AIRPLAY_CLOCK_READY_TIMEOUT_MS: Final[int] = 2500
126# Lead added on top of a reported readiness instant, wherever one is waited for.
127# The binary refuses to place an anchor inside its own 250 ms floor, measured
128# from when IT reads the START command rather than when the server sends it (the
129# same trap as AIRPLAY_START_LEAD_MS), so the lead carries that floor plus 250 ms
130# for the command reaching the binary and for the convergence error of a
131# projection made from the receiver's very first probe.
132AIRPLAY_CLOCK_READY_LEAD_MS: Final[int] = 500
133# Default receiver buffer depth per device family: (manufacturer wildcard,
134# model wildcard, firmware wildcard) -> depth in ms, matched case-insensitively
135# in order, first match wins; unmatched devices stay on Automatic (the binary's
136# stock depth). The table is EMPTY since the buffered (type 103) stream became
137# the auto-route for the receivers that used to need a deepened queue: the
138# LinkPlay pipelines that starved on the realtime stream (WiiM at 1750 ms,
139# Edifier MS50A silent below 2500 ms) manage their own buffer on the buffered
140# stream and play fine on Automatic. The per-player depth setting remains as
141# an advanced override; extend the table only for devices that starve on the
142# route they actually take.
143AIRPLAY_BUFFER_DEPTH_DEFAULTS: Final[tuple[tuple[str, str, str, int], ...]] = ()
144# Per-player override of the splice receiver-queue depth in ms (0 = automatic).
145CONF_BUFFER_DEPTH: Final[str] = "buffer_depth"
146# How long a plain (non-join) START waits for the binary's [STATUS] started ack.
147# A strict buffered receiver can reject its anchor until its clock is seated;
148# cliairplay then makes up to 12 attempts, 500 ms apart. Cover that 5.5-second
149# retry span plus control-response and status-delivery margin.
150AIRPLAY_START_ACK_TIMEOUT_MS: Final[int] = 7000
151# A join can additionally withhold its ack while receiver-clock verification
152# settles. Keep its independently named bound aligned with the buffered retry
153# span too; command failures still answer either wait immediately.
154AIRPLAY_JOIN_START_ACK_TIMEOUT_MS: Final[int] = 7000
155# How far the content a corrected anchor actually cut may fall short of the cut
156# it asked for before the reported media position is re-based and the shortfall
157# reported. The binary derives the cut it took from the bytes it discarded, so a
158# few ms of byte quantization is expected and correcting for it would only
159# jitter the base; anything larger means the cut really did end early (the input
160# ran out inside it, or a teardown settled it) and the position is over-advanced
161# by that much for the rest of the anchor.
162AIRPLAY_CONTENT_CUT_TOLERANCE_MS: Final[int] = 20
163# Anchor leads for a readiness-confirmed START (cold and warm alike), solo and
164# group: the session only anchors after the binary confirmed the connection
165# ([STATUS] connected) and the new audio flowing ([STATUS] audio), so a lead no
166# longer guesses at setup or transcoder spin-up time. Both cover the receiver
167# re-anchor (accepted down to ~150 ms in the flush-ladder measurements) plus
168# the command's trip down the pipe; the group one also covers fanning the
169# shared instant out to every member. The pipe margin is what keeps them
170# workable: the binary rejects any instant inside its own 250 ms floor,
171# measured from when IT reads the command, and corrects a miss to that floor
172# plus another full lead â so a lead sitting exactly on the floor misses by the
173# delivery time every time and turns a start into a group-wide re-anchor ladder.
174AIRPLAY_START_LEAD_MS: Final[int] = 400
175AIRPLAY_GROUP_START_LEAD_MS: Final[int] = 500
176# Cold GROUP starts anchor further out: a receiver on a brand-new session
177# still acquires its PTP slave lock (~1.7-2.3 s measured on Sonos) and cannot
178# render at an anchor inside that window - it starts late and the group opens
179# audibly out of sync. Warm re-anchors reuse a locked clock and keep the
180# short leads above; solo cold starts have no sync partner to miss.
181AIRPLAY_COLD_GROUP_START_LEAD_MS: Final[int] = 2500
182
183# How long a start waits for the source to hand over its first audio before it
184# judges the members on what they never received. A seek may land up to
185# SEEK_WAIT_THRESHOLD seconds ahead of what the source has produced, and the
186# wait has to outlast the producer covering that; the margin covers its own
187# spin-up. It is a backstop rather than a budget: this runs under the player
188# lock, so a producer that neither delivers nor gives up would otherwise hold
189# every command for the player behind it.
190AIRPLAY_FEED_START_TIMEOUT: Final[float] = SEEK_WAIT_THRESHOLD + 5
191# Hard cap on how long the stdin EOF withheld for a predicted replacement stream
192# is held. What normally releases that wait is the queue itself: it clears the
193# transition on any failure between rotating its stream session and the
194# play_media that carries the replacement (an item that fails to load, a
195# provider error), and that is the signal no replacement is coming. This only
196# covers a transition that neither completes nor clears. It sits past the load
197# that carries a replacement - the queue's buffer prepare (BUFFER_READY_TIMEOUT,
198# 15s) plus the provider source slot its producer may wait out first - so a slow
199# but real seek is never cut short into a cold restart.
200AIRPLAY_REPLACEMENT_EOF_TIMEOUT: Final[float] = 35.0
201# How often the queue is asked whether it is still loading that replacement.
202# It only bounds how quickly a cleared transition is noticed, so it trades no
203# accuracy for a poll this cheap (one dict lookup).
204AIRPLAY_REPLACEMENT_POLL_INTERVAL: Final[float] = 1.0
205# Margin added on top of a member's reported warm lead (the splice-timeline
206# queue depth; that timeline is the default for every native AirPlay 2 session)
207# when anchoring a warm re-start: covers the command round-trips between the
208# flush acks and the shared START so every member's skip target lands beyond
209# its queued audio.
210AIRPLAY_SPLICE_LEAD_MARGIN_MS: Final[int] = 150
211
212# Floor for the late-join PCM ring, which has to hold every sample between the
213# audible position and the write head: a joiner's anchor maps onto content the
214# group was already fed but has not played yet. That distance - the write-head
215# lead - is the sum of every buffer between the session's byte counter and the
216# speaker, and it is far larger than the binary's own ring alone:
217# ~5.7 s the per-member ffmpeg and the pipes around it (measured 5.2 s
218# steady / 5.7 s peak at 44.1 kHz/16-bit, which is the worst case in
219# SECONDS - the same buffers hold ~4.3 s at the 32-bit hi-res carrier
220# rate, and low-delay ffmpeg flags do not shrink them)
221# ~4.0 s the cliairplay ring: the binary's own lead (2000 ms default,
222# clamped to the device-reported window) plus its 2 s of slack
223# ~2.0 s the receiver's own buffer
224# ~11.7 s in total, against 8.9-11.0 s measured across native AirPlay 2
225# sessions (Apple TV and Sonos, joining in both directions). This floor is that
226# sum rounded up, and it is only a floor: the lead is measured per session and
227# the ring grows to match, because a receiver that reports a wider lead window
228# or buffers more deeply moves the sum with nothing to announce it.
229AIRPLAY_LATE_JOIN_RING_MIN_SECONDS: Final[float] = 12.0
230# Grown on top of the largest lead a session has actually shown, so a lead that
231# drifts up between two joins cannot clip the oldest sample a joiner needs.
232AIRPLAY_LATE_JOIN_RING_MARGIN_SECONDS: Final[float] = 2.0
233# Hard bound on the ring, which is per session (one ring feeds every member) and
234# costs byte_rate x seconds. Bounded in BYTES rather than seconds on purpose:
235# the seconds the ring must hold are largest at the LOWEST byte rate (see the
236# measurements above), so a single byte bound buys ~35 s at 44.1 kHz/16-bit -
237# three times the measured lead, where the seconds are actually needed - and
238# still ~16 s at the 32-bit hi-res carrier, where the pipeline holds fewer
239# seconds anyway. 6 MiB per playing group is a few percent of the server's idle
240# footprint.
241AIRPLAY_LATE_JOIN_RING_MAX_BYTES: Final[int] = 6 * 1024 * 1024
242
243# Delays (seconds) between automatic re-join attempts for a group member whose
244# cliairplay process died unexpectedly mid-session (e.g. the device rode out a
245# network blackout longer than the binary's own keepalive tolerance). A device
246# recovering from a network dropout typically needs tens of seconds to come
247# back, so the ladder stretches to a few minutes; every attempt re-validates
248# that the group still plays and the player was not repurposed meanwhile, and
249# the whole schedule is abandoned as soon as either no longer holds.
250AIRPLAY_REJOIN_ATTEMPT_DELAYS: Final[tuple[int, ...]] = (5, 15, 30, 60, 120)
251
252# Shared audible instant for a native announcement over a live stream: now +
253# the largest member span + this margin. A member can only mix the clip into
254# audio it has not delivered yet, and its span (warm_lead_ms on the splice
255# timeline, the reported lead_ms otherwise) is how far its delivery head runs
256# ahead of the audible position - so the earliest instant EVERY member can
257# honor lies one max-span out. The margin covers fanning the command out over
258# the pipes and the per-member arm processing, so one shared instant stays
259# feasible for all members.
260AIRPLAY_ANNOUNCE_AT_MARGIN_MS: Final[int] = 300
261# Span assumed for a member whose binary reported neither a warm lead nor a
262# device lead (both read 0 = unreported): the binary's own default playback
263# lead, which bounds how far its delivery head can run ahead.
264AIRPLAY_ANNOUNCE_FALLBACK_SPAN_MS: Final[int] = 2000
265# Music gain (dB) under the clip while it plays; the binary ramps the duck in
266# and out itself. <= -60 mutes the music entirely. -18 dB puts the music
267# clearly in the background under speech (-12 was field-judged too shallow).
268AIRPLAY_ANNOUNCE_DUCK_DB: Final[int] = -18
269# Silence prepended to every announcement clip. The binary holds the music duck
270# for the whole clip file, so this is a window in which the music is already
271# ducked and the announcement has not started yet: the announcement volume is
272# raised inside it, where it cannot be heard as the music getting louder. It
273# has to cover the duck's ramp plus the round trip of the volume command.
274AIRPLAY_ANNOUNCE_DUCK_LEAD_S: Final[float] = 0.5
275# Silence appended to every announcement clip, so the volume restore has a
276# cushion to land in. The binary holds the duck for the whole clip, so the
277# restore lands while the music is still ducked instead of racing the duck's
278# 200 ms tail ramp (a restore that lands after the ramp plays a moment of
279# full-level music at the still-bumped device volume).
280AIRPLAY_ANNOUNCE_DUCK_TAIL_S: Final[float] = 1.0
281# On top of the lead to the commanded instant: how long to wait for a member's
282# announce_started before treating that member as not announcing. An outdated
283# binary silently ignores the unknown command, so this bounded wait is also what
284# detects that, and the announcement then fails instead of playing nowhere.
285AIRPLAY_ANNOUNCE_STARTED_TIMEOUT_MS: Final[int] = 3000
286# On top of the clip's audible end: how long to wait for announce_done. The
287# wait stays bounded because a queue that ends mid-clip emits its eof, which
288# ends the status stream while the clip still plays out over the drain.
289AIRPLAY_ANNOUNCE_DONE_TIMEOUT_MS: Final[int] = 5000
290# Pad after the clip's audible end before the pre-announcement volume is
291# restored: covers the jitter between the acked instant and true audibility.
292AIRPLAY_ANNOUNCE_VOLUME_RESTORE_PAD_MS: Final[int] = 500
293# Where inside the ducked lead-in the announcement volume is raised: past the
294# duck's own ramp, with the rest of the lead left for the command to reach the
295# receiver before the announcement itself becomes audible.
296AIRPLAY_ANNOUNCE_VOLUME_BUMP_DELAY_MS: Final[int] = 200
297# The AirPlay volume parameter is linear dB: 0..100 maps onto -30..0 dB on
298# every flow (libraop raopcl_float_volume, reused verbatim by the native AP2
299# SET_PARAMETER path), so one volume point is exactly 0.3 dB of output. This
300# makes the announcement volume bump's effect on the music bed computable, and
301# the duck is deepened by the same amount to keep the music's perceived level
302# at the configured duck depth.
303AIRPLAY_VOLUME_DB_PER_POINT: Final[float] = 0.3
304
305# Cover art is rendered to a local JPEG for the binary to embed (the binary
306# does not fetch URLs). 512px keeps the SET_PARAMETER payload small while still
307# looking sharp on speaker apps and the Apple TV now-playing screen.
308AIRPLAY_ARTWORK_SIZE: Final[int] = 512
309# How long a track-change metadata push waits for that render, so the artwork
310# can ride the SENDMETA bundle and the receiver rewrites its now-playing state
311# once instead of twice (bare replace, then artwork). A render that misses the
312# budget is not abandoned: it keeps running and is delivered with the
313# stand-alone ARTWORK command once it completes.
314AIRPLAY_ARTWORK_RENDER_TIMEOUT: Final[float] = 1.5
315EXTERNAL_ARTWORK_PATH_PREFIX: Final[str] = "external_artwork"
316
317# Per-protocol credential storage keys
318CONF_RAOP_CREDENTIALS: Final[str] = "raop_credentials"
319CONF_AIRPLAY_CREDENTIALS: Final[str] = "airplay_credentials"
320
321# AirPlay serves the shared sync-adjust control as a non-advanced (always visible)
322# setting: the binary handles the playback lead automatically and does not apply
323# device-reported render latency, so sync_adjust is the primary way to compensate
324# a device wired to a TV / AV receiver / amplifier that adds its own audio delay.
325# The AirPlay-scoped strings spell out the sign; the shared entry stays advanced
326# for other providers.
327CONF_ENTRY_SYNC_ADJUST_AIRPLAY = replace(CONF_ENTRY_SYNC_ADJUST, advanced=False)
328
329# Interactive setup-flow input keys (transient PIN/password form fields and the
330# optional "set up now?" choice for the control pairing steps).
331CONF_PAIRING_PIN: Final[str] = "pairing_pin"
332# every AirPlay pairing PIN (streaming, Companion, MRP) is 4 digits
333PAIRING_PIN_FORMAT: Final[str] = "####"
334CONF_PAIRING_PASSWORD: Final[str] = "pairing_password"
335CONF_COMPANION_PAIRING_PIN: Final[str] = "companion_pairing_pin"
336CONF_MRP_PAIRING_PIN: Final[str] = "mrp_pairing_pin"
337CONF_PAIR_NOW: Final[str] = "pair_now"
338
339FALLBACK_VOLUME: Final[int] = 20
340AIRPLAY_VOLUME_MUTE: Final[float] = -144.0
341# How long a volume we sent ourselves keeps the device's own volume reports from
342# being acted on. A receiver echoes every level it is given back over DACP, and
343# an echo that arrives after the next level was already sent would otherwise be
344# read as the user turning the knob and written straight back to the device.
345AIRPLAY_VOLUME_ECHO_GRACE_S: Final[float] = 2.0
346
347AIRPLAY_PCM_FORMAT = AudioFormat(
348 content_type=ContentType.from_bit_depth(16), sample_rate=44100, bit_depth=16
349)
350# Sample rates advertised for a receiver that supports 24-bit (AirPlay 2 flow
351# only). At 24-bit the cliairplay binary expects raw s32le on stdin and truncates
352# to 24-bit ALAC internally.
353AIRPLAY_HIRES_SAMPLE_RATES: Final[list[tuple[int, int]]] = [(44100, 24), (48000, 24)]
354
355# Bits in the audioFormat bit space (shared with the receiver's /info format
356# tables) that mark 24-bit ALAC: 44.1 kHz and 48 kHz respectively. Receivers
357# understate these - the Apple TV lists them for its buffered stream only, yet
358# renders them fine on the realtime stream - so a device advertising either bit
359# on either stream is treated as 24-bit capable.
360AIRPLAY_HIRES_AUDIO_FORMATS: Final[int] = (1 << 19) | (1 << 21)
361
362BASE_PLAYER_FEATURES: Final[set[PlayerFeature]] = {
363 PlayerFeature.PLAY_MEDIA,
364 PlayerFeature.PLAY_ANNOUNCEMENT,
365 PlayerFeature.SET_MEMBERS,
366 PlayerFeature.MULTI_DEVICE_DSP,
367 PlayerFeature.VOLUME_SET,
368 PlayerFeature.VOLUME_MUTE,
369}
370
371
372PIN_REQUIRED = 0x8
373PASSWORD_BIT = 0x80
374LEGACY_PAIRING_BIT = 0x200
375
376# Provider setting: opt-in for the shared PTP daemon's per-packet timing trace
377# (Announce/Sync/Follow_Up) when verbose logging is active. Off by default â
378# the trace floods the log and only matters for clock-sync debugging.
379CONF_VERBOSE_PTP_LOGGING: Final[str] = "verbose_ptp_logging"
380
381# The cliairplay binary tags no log levels on its output, so a genuine problem is
382# recognised by keyword and promoted to a warning that stays visible at normal levels.
383CLI_PROBLEM_MARKERS: Final[tuple[str, ...]] = ("error", "cannot", "failed", "unable")
384# Bound on how many of those promoted lines the shared PTP daemon may produce per
385# window before the rest are counted instead of logged. The markers above are
386# deliberately broad, and "error" is ordinary vocabulary in clock telemetry
387# (offset error, path delay error), so with the daemon's per-packet trace running
388# at ~10 lines/s a single matching line would otherwise fill the log at WARNING.
389# A burst still gets through, which is what a real one-shot daemon failure is.
390PTP_DAEMON_WARN_BURST: Final[int] = 5
391PTP_DAEMON_WARN_WINDOW: Final[float] = 60.0
392