/
/
1"""Constants for the AirPlay provider."""
2
3from __future__ import annotations
4
5from dataclasses import replace
6from enum import IntEnum, StrEnum
7from typing import Final
8
9from music_assistant_models.enums import ContentType, PlayerFeature
10from music_assistant_models.media_items import AudioFormat
11
12from music_assistant.constants import CONF_ENTRY_SYNC_ADJUST
13from music_assistant.controllers.streams.constants import SEEK_WAIT_THRESHOLD
14
15DOMAIN = "airplay"
16
17
18class StreamingProtocol(IntEnum):
19 """AirPlay streaming protocol versions."""
20
21 RAOP = 1 # AirPlay 1 (RAOP)
22 AIRPLAY2 = 2 # AirPlay 2
23
24
25class AirPlayRemoteCommand(StrEnum):
26 """Transport commands received from an AirPlay receiver."""
27
28 PLAY = "play"
29 PAUSE = "pause"
30 PLAY_PAUSE = "play_pause"
31 NEXT = "next"
32 PREVIOUS = "previous"
33
34
35class ClockReadiness(StrEnum):
36 """
37 How a receiver's clock readiness resolved for an anchor decision.
38
39 Only PROJECTED carries an instant; the rest all mean "anchor on the lead
40 alone", but for very different reasons - one is a device that will not play
41 at all, and treating them alike hides it.
42 """
43
44 # The binary projected when the receiver's clock becomes usable.
45 PROJECTED = "projected"
46 # NTP timing: there is no receiver clock to wait for.
47 NOT_APPLICABLE = "not_applicable"
48 # The receiver never answered our PTP clock and will render silence.
49 STALLED = "stalled"
50 # Nothing arrived within the wait: a slow device (retryable) or a receiver
51 # whose readiness went unreported.
52 UNREPORTED = "unreported"
53
54
55CONF_PASSWORD: Final[str] = "password"
56# Storage-only marker (no config entry) set when the device rejected the stored
57# password, so the player keeps asking for setup across restarts until a working
58# password is entered.
59CONF_PASSWORD_INVALID: Final[str] = "password_invalid"
60# Provider marker that the stored password verdicts were reviewed once. Releases
61# that could not tell a password challenge apart from a flat refusal wrote the
62# key above for both, so what they left behind is no evidence about a password
63# and is dropped a single time; a device that really challenges marks itself
64# again on its next connect.
65CONF_PASSWORD_MARKERS_REVIEWED: Final[str] = "password_markers_reviewed"
66CONF_IGNORE_VOLUME: Final[str] = "ignore_volume"
67CONF_ENCRYPTION: Final[str] = "encryption"
68# Advanced per-device streaming mode: pins the protocol/timing lane for
69# receivers whose automatic route misbehaves. Options are offered per device
70# capability; Automatic is the default and the setting is only ever written by
71# the user â a failing automatic route is reported, never switched away from.
72CONF_STREAMING_MODE: Final[str] = "streaming_mode"
73# Provider marker that the compatibility-mode pins were reset once. Earlier
74# releases switched a player here themselves when its native control channel
75# failed (usually a network dropout), pinning it to a lane many devices reject
76# outright, so those machine-written values are returned to Automatic a single
77# time; a deliberate choice can simply be made again.
78CONF_COMPAT_PINS_REVIEWED: Final[str] = "compat_pins_reviewed"
79STREAMING_MODE_AUTO: Final[str] = "auto"
80STREAMING_MODE_AP2_PTP: Final[str] = "ap2_ptp"
81STREAMING_MODE_AP2_NTP: Final[str] = "ap2_ntp"
82STREAMING_MODE_AP2_COMPAT: Final[str] = "ap2_compat"
83STREAMING_MODE_RAOP: Final[str] = "raop"
84CONF_STORED_VOLUME: Final[str] = "stored_volume"
85CONF_COMPANION_CREDENTIALS: Final[str] = "companion_credentials"
86CONF_MRP_CREDENTIALS: Final[str] = "mrp_credentials"
87CONF_NATIVE_MRP_CREDENTIALS: Final[str] = "native_mrp_credentials"
88
89# Bundle id of the Music Assistant tvOS dashboard app, launched over Companion on
90# eligible Apple TVs (see tvos/docs/launch-contract.md).
91TVOS_APP_BUNDLE_ID: Final[str] = "io.music-assistant.tvos"
92
93AIRPLAY_DISCOVERY_TYPE: Final[str] = "_airplay._tcp.local."
94COMPANION_DISCOVERY_TYPE: Final[str] = "_companion-link._tcp.local."
95MRP_DISCOVERY_TYPE: Final[str] = "_mediaremotetv._tcp.local."
96RAOP_DISCOVERY_TYPE: Final[str] = "_raop._tcp.local."
97DACP_DISCOVERY_TYPE: Final[str] = "_dacp._tcp.local."
98
99# Floor for a late joiner's anchor, and the one it rests on whenever the binary
100# reports no readiness projection ([STATUS] clock_ready). A joiner cannot
101# honour an instant in the past, and that second case has no device evidence at
102# all, so this carries it the whole way: the command's trip to the binary, the
103# binary's own 250 ms floor, and the receiver seating the anchor. The value is
104# field-proven, not derived from those.
105# It is NOT headroom for the binary's post-commit clock verification, which
106# arms only when the receiver has still not probed by the time it reads the
107# START, and only for an anchor that clears the receiver queue depth plus
108# 500 ms - past ~2 s of effective depth, an anchor this close leaves no room.
109AIRPLAY_LATE_JOIN_MIN_HEADROOM_MS: Final[int] = 2500
110# How long a group start, a join or the Sendspin bridge waits for the binary's
111# first receiver-clock projection ([STATUS] clock_ready with state=probing|
112# ready). The binary emits its first line right after [STATUS] connected and
113# refreshes it about every 250 ms, and the projection exists from the receiver's
114# first probe (~1078 ms after connect on a cold device), so this only has to
115# cover a slower device before giving up and anchoring on the lead alone.
116# Independent of the binary's own stall report (state=stalled), which is a
117# slower, higher-confidence diagnosis of a receiver that never answers at all: a
118# wait that times out here has simply run out of planning time and falls back,
119# while a stall says the speaker will not play. Keep them apart - tightening the
120# stall report to meet this deadline would trade the margin that keeps it free
121# of false alarms.
122AIRPLAY_CLOCK_READY_TIMEOUT_MS: Final[int] = 2500
123# Lead added on top of a reported readiness instant, wherever one is waited for.
124# The binary refuses to place an anchor inside its own 250 ms floor, measured
125# from when IT reads the START command rather than when the server sends it (the
126# same trap as AIRPLAY_START_LEAD_MS), so the lead carries that floor plus 250 ms
127# for the command reaching the binary and for the convergence error of a
128# projection made from the receiver's very first probe.
129AIRPLAY_CLOCK_READY_LEAD_MS: Final[int] = 500
130# Default receiver buffer depth per device family: (manufacturer wildcard,
131# model wildcard, firmware wildcard) -> depth in ms, matched case-insensitively
132# in order, first match wins; unmatched devices stay on Automatic (the binary's
133# stock depth). The table is EMPTY since the buffered (type 103) stream became
134# the auto-route for the receivers that used to need a deepened queue: the
135# LinkPlay pipelines that starved on the realtime stream (WiiM at 1750 ms,
136# Edifier MS50A silent below 2500 ms) manage their own buffer on the buffered
137# stream and play fine on Automatic. The per-player depth setting remains as
138# an advanced override; extend the table only for devices that starve on the
139# route they actually take.
140AIRPLAY_BUFFER_DEPTH_DEFAULTS: Final[tuple[tuple[str, str, str, int], ...]] = ()
141# Per-player override of the splice receiver-queue depth in ms (0 = automatic).
142CONF_BUFFER_DEPTH: Final[str] = "buffer_depth"
143# How long a plain (non-join) START waits for the binary's [STATUS] started ack.
144# A strict buffered receiver can reject its anchor until its clock is seated;
145# cliairplay then makes up to 12 attempts, 500 ms apart. Cover that 5.5-second
146# retry span plus control-response and status-delivery margin.
147AIRPLAY_START_ACK_TIMEOUT_MS: Final[int] = 7000
148# A join can additionally withhold its ack while receiver-clock verification
149# settles. Keep its independently named bound aligned with the buffered retry
150# span too; command failures still answer either wait immediately.
151AIRPLAY_JOIN_START_ACK_TIMEOUT_MS: Final[int] = 7000
152# How far the content a corrected anchor actually cut may fall short of the cut
153# it asked for before the reported media position is re-based and the shortfall
154# reported. The binary derives the cut it took from the bytes it discarded, so a
155# few ms of byte quantization is expected and correcting for it would only
156# jitter the base; anything larger means the cut really did end early (the input
157# ran out inside it, or a teardown settled it) and the position is over-advanced
158# by that much for the rest of the anchor.
159AIRPLAY_CONTENT_CUT_TOLERANCE_MS: Final[int] = 20
160# Anchor leads for a readiness-confirmed START (cold and warm alike), solo and
161# group: the session only anchors after the binary confirmed the connection
162# ([STATUS] connected) and the new audio flowing ([STATUS] audio), so a lead no
163# longer guesses at setup or transcoder spin-up time. Both cover the receiver
164# re-anchor (accepted down to ~150 ms in the flush-ladder measurements) plus
165# the command's trip down the pipe; the group one also covers fanning the
166# shared instant out to every member. The pipe margin is what keeps them
167# workable: the binary rejects any instant inside its own 250 ms floor,
168# measured from when IT reads the command, and corrects a miss to that floor
169# plus another full lead â so a lead sitting exactly on the floor misses by the
170# delivery time every time and turns a start into a group-wide re-anchor ladder.
171AIRPLAY_START_LEAD_MS: Final[int] = 400
172AIRPLAY_GROUP_START_LEAD_MS: Final[int] = 500
173# Cold GROUP starts anchor further out: a receiver on a brand-new session
174# still acquires its PTP slave lock (~1.7-2.3 s measured on Sonos) and cannot
175# render at an anchor inside that window - it starts late and the group opens
176# audibly out of sync. Warm re-anchors reuse a locked clock and keep the
177# short leads above; solo cold starts have no sync partner to miss.
178AIRPLAY_COLD_GROUP_START_LEAD_MS: Final[int] = 2500
179
180# How long a start waits for the source to hand over its first audio before it
181# judges the members on what they never received. A seek may land up to
182# SEEK_WAIT_THRESHOLD seconds ahead of what the source has produced, and the
183# wait has to outlast the producer covering that; the margin covers its own
184# spin-up. It is a backstop rather than a budget: this runs under the player
185# lock, so a producer that neither delivers nor gives up would otherwise hold
186# every command for the player behind it.
187AIRPLAY_FEED_START_TIMEOUT: Final[float] = SEEK_WAIT_THRESHOLD + 5
188# Margin added on top of a member's reported warm lead (the splice-timeline
189# queue depth; that timeline is the default for every native AirPlay 2 session)
190# when anchoring a warm re-start: covers the command round-trips between the
191# flush acks and the shared START so every member's skip target lands beyond
192# its queued audio.
193AIRPLAY_SPLICE_LEAD_MARGIN_MS: Final[int] = 150
194
195# Floor for the late-join PCM ring, which has to hold every sample between the
196# audible position and the write head: a joiner's anchor maps onto content the
197# group was already fed but has not played yet. That distance - the write-head
198# lead - is the sum of every buffer between the session's byte counter and the
199# speaker, and it is far larger than the binary's own ring alone:
200# ~5.7 s the per-member ffmpeg and the pipes around it (measured 5.2 s
201# steady / 5.7 s peak at 44.1 kHz/16-bit, which is the worst case in
202# SECONDS - the same buffers hold ~4.3 s at the 32-bit hi-res carrier
203# rate, and low-delay ffmpeg flags do not shrink them)
204# ~4.0 s the cliairplay ring: the binary's own lead (2000 ms default,
205# clamped to the device-reported window) plus its 2 s of slack
206# ~2.0 s the receiver's own buffer
207# ~11.7 s in total, against 8.9-11.0 s measured across native AirPlay 2
208# sessions (Apple TV and Sonos, joining in both directions). This floor is that
209# sum rounded up, and it is only a floor: the lead is measured per session and
210# the ring grows to match, because a receiver that reports a wider lead window
211# or buffers more deeply moves the sum with nothing to announce it.
212AIRPLAY_LATE_JOIN_RING_MIN_SECONDS: Final[float] = 12.0
213# Grown on top of the largest lead a session has actually shown, so a lead that
214# drifts up between two joins cannot clip the oldest sample a joiner needs.
215AIRPLAY_LATE_JOIN_RING_MARGIN_SECONDS: Final[float] = 2.0
216# Hard bound on the ring, which is per session (one ring feeds every member) and
217# costs byte_rate x seconds. Bounded in BYTES rather than seconds on purpose:
218# the seconds the ring must hold are largest at the LOWEST byte rate (see the
219# measurements above), so a single byte bound buys ~35 s at 44.1 kHz/16-bit -
220# three times the measured lead, where the seconds are actually needed - and
221# still ~16 s at the 32-bit hi-res carrier, where the pipeline holds fewer
222# seconds anyway. 6 MiB per playing group is a few percent of the server's idle
223# footprint.
224AIRPLAY_LATE_JOIN_RING_MAX_BYTES: Final[int] = 6 * 1024 * 1024
225
226# Delay (seconds) before automatically re-joining a group member whose
227# cliairplay process died unexpectedly mid-session (e.g. the device rode out a
228# network blackout longer than the binary's own keepalive tolerance). A single
229# attempt keeps the behaviour predictable: it waits long enough for a short
230# blackout to clear, and if the device is still gone the player is left idle.
231# Staged retries can be reintroduced by adding entries to the tuple.
232AIRPLAY_REJOIN_ATTEMPT_DELAYS: Final[tuple[int, ...]] = (5,)
233
234# Shared audible instant for a native announcement over a live stream: now +
235# the largest member span + this margin. A member can only mix the clip into
236# audio it has not delivered yet, and its span (warm_lead_ms on the splice
237# timeline, the reported lead_ms otherwise) is how far its delivery head runs
238# ahead of the audible position - so the earliest instant EVERY member can
239# honor lies one max-span out. The margin covers fanning the command out over
240# the pipes and the per-member arm processing, so one shared instant stays
241# feasible for all members.
242AIRPLAY_ANNOUNCE_AT_MARGIN_MS: Final[int] = 300
243# Span assumed for a member whose binary reported neither a warm lead nor a
244# device lead (both read 0 = unreported): the binary's own default playback
245# lead, which bounds how far its delivery head can run ahead.
246AIRPLAY_ANNOUNCE_FALLBACK_SPAN_MS: Final[int] = 2000
247# Music gain (dB) under the clip while it plays; the binary ramps the duck in
248# and out itself. <= -60 mutes the music entirely. -18 dB puts the music
249# clearly in the background under speech (-12 was field-judged too shallow).
250AIRPLAY_ANNOUNCE_DUCK_DB: Final[int] = -18
251# Silence prepended to every announcement clip. The binary holds the music duck
252# for the whole clip file, so this is a window in which the music is already
253# ducked and the announcement has not started yet: the announcement volume is
254# raised inside it, where it cannot be heard as the music getting louder. It
255# has to cover the duck's ramp plus the round trip of the volume command.
256AIRPLAY_ANNOUNCE_DUCK_LEAD_S: Final[float] = 0.5
257# Silence appended to every announcement clip, so the volume restore has a
258# cushion to land in. The binary holds the duck for the whole clip, so the
259# restore lands while the music is still ducked instead of racing the duck's
260# 200 ms tail ramp (a restore that lands after the ramp plays a moment of
261# full-level music at the still-bumped device volume).
262AIRPLAY_ANNOUNCE_DUCK_TAIL_S: Final[float] = 1.0
263# On top of the lead to the commanded instant: how long to wait for a member's
264# announce_started before treating that member as not announcing. An outdated
265# binary silently ignores the unknown command, so this bounded wait is also what
266# detects that, and the announcement then fails instead of playing nowhere.
267AIRPLAY_ANNOUNCE_STARTED_TIMEOUT_MS: Final[int] = 3000
268# On top of the clip's audible end: how long to wait for announce_done. The
269# wait stays bounded because a queue that ends mid-clip emits its eof, which
270# ends the status stream while the clip still plays out over the drain.
271AIRPLAY_ANNOUNCE_DONE_TIMEOUT_MS: Final[int] = 5000
272# Pad after the clip's audible end before the pre-announcement volume is
273# restored: covers the jitter between the acked instant and true audibility.
274AIRPLAY_ANNOUNCE_VOLUME_RESTORE_PAD_MS: Final[int] = 500
275# Where inside the ducked lead-in the announcement volume is raised: past the
276# duck's own ramp, with the rest of the lead left for the command to reach the
277# receiver before the announcement itself becomes audible.
278AIRPLAY_ANNOUNCE_VOLUME_BUMP_DELAY_MS: Final[int] = 200
279# The AirPlay volume parameter is linear dB: 0..100 maps onto -30..0 dB on
280# every flow (libraop raopcl_float_volume, reused verbatim by the native AP2
281# SET_PARAMETER path), so one volume point is exactly 0.3 dB of output. This
282# makes the announcement volume bump's effect on the music bed computable, and
283# the duck is deepened by the same amount to keep the music's perceived level
284# at the configured duck depth.
285AIRPLAY_VOLUME_DB_PER_POINT: Final[float] = 0.3
286
287# Cover art is rendered to a local JPEG for the binary to embed (the binary
288# does not fetch URLs). 512px keeps the SET_PARAMETER payload small while still
289# looking sharp on speaker apps and the Apple TV now-playing screen.
290AIRPLAY_ARTWORK_SIZE: Final[int] = 512
291# How long a track-change metadata push waits for that render, so the artwork
292# can ride the SENDMETA bundle and the receiver rewrites its now-playing state
293# once instead of twice (bare replace, then artwork). A render that misses the
294# budget is not abandoned: it keeps running and is delivered with the
295# stand-alone ARTWORK command once it completes.
296AIRPLAY_ARTWORK_RENDER_TIMEOUT: Final[float] = 1.5
297EXTERNAL_ARTWORK_PATH_PREFIX: Final[str] = "external_artwork"
298
299# Per-protocol credential storage keys
300CONF_RAOP_CREDENTIALS: Final[str] = "raop_credentials"
301CONF_AIRPLAY_CREDENTIALS: Final[str] = "airplay_credentials"
302
303# AirPlay serves the shared sync-adjust control as a non-advanced (always visible)
304# setting: the binary handles the playback lead automatically and does not apply
305# device-reported render latency, so sync_adjust is the primary way to compensate
306# a device wired to a TV / AV receiver / amplifier that adds its own audio delay.
307# The AirPlay-scoped strings spell out the sign; the shared entry stays advanced
308# for other providers.
309CONF_ENTRY_SYNC_ADJUST_AIRPLAY = replace(CONF_ENTRY_SYNC_ADJUST, advanced=False)
310
311# Interactive setup-flow input keys (transient PIN/password form fields and the
312# optional "set up now?" choice for the control pairing steps).
313CONF_PAIRING_PIN: Final[str] = "pairing_pin"
314# every AirPlay pairing PIN (streaming, Companion, MRP) is 4 digits
315PAIRING_PIN_FORMAT: Final[str] = "####"
316CONF_PAIRING_PASSWORD: Final[str] = "pairing_password"
317CONF_COMPANION_PAIRING_PIN: Final[str] = "companion_pairing_pin"
318CONF_MRP_PAIRING_PIN: Final[str] = "mrp_pairing_pin"
319CONF_PAIR_NOW: Final[str] = "pair_now"
320
321FALLBACK_VOLUME: Final[int] = 20
322AIRPLAY_VOLUME_MUTE: Final[float] = -144.0
323# How long a volume we sent ourselves keeps the device's own volume reports from
324# being acted on. A receiver echoes every level it is given back over DACP, and
325# an echo that arrives after the next level was already sent would otherwise be
326# read as the user turning the knob and written straight back to the device.
327AIRPLAY_VOLUME_ECHO_GRACE_S: Final[float] = 2.0
328
329AIRPLAY_PCM_FORMAT = AudioFormat(
330 content_type=ContentType.from_bit_depth(16), sample_rate=44100, bit_depth=16
331)
332# Sample rates advertised for a receiver that supports 24-bit (AirPlay 2 flow
333# only). At 24-bit the cliairplay binary expects raw s32le on stdin and truncates
334# to 24-bit ALAC internally.
335AIRPLAY_HIRES_SAMPLE_RATES: Final[list[tuple[int, int]]] = [(44100, 24), (48000, 24)]
336
337# Bits in the audioFormat bit space (shared with the receiver's /info format
338# tables) that mark 24-bit ALAC: 44.1 kHz and 48 kHz respectively. Receivers
339# understate these - the Apple TV lists them for its buffered stream only, yet
340# renders them fine on the realtime stream - so a device advertising either bit
341# on either stream is treated as 24-bit capable.
342AIRPLAY_HIRES_AUDIO_FORMATS: Final[int] = (1 << 19) | (1 << 21)
343
344BASE_PLAYER_FEATURES: Final[set[PlayerFeature]] = {
345 PlayerFeature.PLAY_MEDIA,
346 PlayerFeature.PLAY_ANNOUNCEMENT,
347 PlayerFeature.SET_MEMBERS,
348 PlayerFeature.MULTI_DEVICE_DSP,
349 PlayerFeature.VOLUME_SET,
350 PlayerFeature.VOLUME_MUTE,
351}
352
353
354PIN_REQUIRED = 0x8
355PASSWORD_BIT = 0x80
356LEGACY_PAIRING_BIT = 0x200
357
358# Provider setting: opt-in for the shared PTP daemon's per-packet timing trace
359# (Announce/Sync/Follow_Up) when verbose logging is active. Off by default â
360# the trace floods the log and only matters for clock-sync debugging.
361CONF_VERBOSE_PTP_LOGGING: Final[str] = "verbose_ptp_logging"
362
363# The cliairplay binary tags no log levels on its output, so a genuine problem is
364# recognised by keyword and promoted to a warning that stays visible at normal levels.
365CLI_PROBLEM_MARKERS: Final[tuple[str, ...]] = ("error", "cannot", "failed", "unable")
366# Bound on how many of those promoted lines the shared PTP daemon may produce per
367# window before the rest are counted instead of logged. The markers above are
368# deliberately broad, and "error" is ordinary vocabulary in clock telemetry
369# (offset error, path delay error), so with the daemon's per-packet trace running
370# at ~10 lines/s a single matching line would otherwise fill the log at WARNING.
371# A burst still gets through, which is what a real one-shot daemon failure is.
372PTP_DAEMON_WARN_BURST: Final[int] = 5
373PTP_DAEMON_WARN_WINDOW: Final[float] = 60.0
374