## Done ### Round 47 (2026-09-06) — LinTunes writes the device's library (v0.17.0) The first half of andTunes, a music player for the Rabbit R1 that never scans anything. Auxio re-reads Android's MediaStore on every launch, which is what leaves the Rabbit sitting on "your songs will show up here" — so the answer isn't a faster scanner, it's not scanning: LinTunes already knows the artist, album and year of every file it just copied, so it writes them down and the app reads one JSON file. This round builds the desktop side; the app itself is rounds 48–50 (`andtunes/TASKS.md`). - [x] **A de-duplicated tree instead of a folder per playlist.** `lintunes/andtunes/layout.py` lays out `Music/andTunes/` — `Media/ //04 Song.mp3` (the iTunes shape `filename_tags` already reads back, with a `2-04` prefix once a release has more than one disc), `Art/.jpg`, `Playlists/.m3u`, `library.json`. A song in three playlists is stored once, which the Artists/Albums/Songs screens need anyway and which saves the space three copies cost. - [x] **`library.json`, the reason the app opens fast.** `andtunes/manifest.py` is pure — no Qt, no device, no I/O. Rows are sparse the way `Track.to_dict` is sparse, because that file is what the R1 parses before it can draw anything. Artists and albums are *not* shipped: grouping a flat list on device beats parsing three redundant ones. A playlist's ids are filtered to tracks that actually landed, so the app never resolves a dangling reference. - [x] **One cover per album, not per song.** `andtunes/art.py` reads the embedded artwork with mutagen, scales to 480 px (the panel's width) and re-encodes as JPEG through `QImage`/`QBuffer` — no new dependency, and QImage is safe off the GUI thread. Keyed on album artist + album, so a twelve-track record costs one mutagen open and one file. Cached under `$XDG_CACHE_HOME/lintunes/andtunes-art`, invalidated by the audio file being newer — which is exactly right, since embedding new art rewrites the file and moves its mtime. - [x] **A sibling worker, not a flag on the old one.** `andtunes/sync.py` follows the `plan_export`/`ExportWorker` shape exactly: pure planner, then a daemon thread emitting KiB progress, with the same MTP caveats (no copystat, diff by name+size). It is separate because it nests directories, has an album-art pass, and writes several trailing files instead of one m3u. Planning deliberately does *not* render art — that's a mutagen open per album and planning runs on the GUI thread. - [x] **The index is written last, and always describes what's really there.** Cancel mid-sync and the manifest and m3us are rewritten listing only tracks whose files landed, so andTunes opens a smaller working library rather than a broken one. Re-syncing completes it. - [x] **A containment guard, because this is the first code that deletes a directory on the Rabbit.** Every delete goes through `layout.assert_inside`, which refuses anything that isn't strictly inside the andTunes root — so the old `Music//` folders are structurally unreachable, not merely un-referenced. `Buttons/` (the user's own menu artwork) and `plays/` (written by the app) are skipped by the scan entirely: sync reads those, it doesn't own them. Emptied folders are pruned bottom-up, asking the filesystem rather than `os.walk`'s stale listing. - [x] **Unticking a playlist is how it comes off the device.** New `Connections → Sync to Rabbit` (everything ticked, no longer caring which view is open) and `Rabbit Sync Settings…` (`gui/device_sync_dialog.py` — a checkbox list with a filter box, because 487 playlists is a normal library here). The selection lives in `preferences.json` under `device_sync`, so it rides the Syncthing share and both machines agree on what the Rabbit is carrying; keeping it off the `Playlist` keeps it out of the conflict-merge machinery. - [x] **The old per-playlist sync stays, renamed "(Auxio)".** Removing it in the same round that adds the new tree would leave the device full of files and nothing able to open them until round 49. It goes when andTunes can actually play a song. Not done, deliberately: the Android app (rounds 48–50), shipping default button images, the format gate for files Android can't decode, and reading play counts back off the device. Verified against the real 21,531-track library into a scratch device root — a re-sync copies nothing, and unticking a playlist removes its media, its m3u, its now-unused cover and every emptied folder. ### Round 46 (2026-09-02) — The file already told you (v0.16.0) Round 45 shipped and trav broke it in two places within the hour, both real. "B. Clem - Zuuso [1025657891]" fingerprinted fine and matched **nothing**, and "Snowfall (Live At The Alhambra_1961)" matched but proposed a 2002 reissue year and ranked a compilation above the album its own filename named. - [x] **The limit is the database, not the fingerprint.** Verified before building anything: that Zuuso fingerprint returns zero AcoustID results, a MusicBrainz text search for "Zuuso" returns zero, and iTunes returns zero (and irrelevant fuzz for "B. Clem"). The track exists in no metadata service on earth. So no smarter lookup — LLM or otherwise — could have answered it, because there was nothing to answer with. - [x] **But the filename knew.** New `lintunes/filename_tags.py` reads tags out of the name yt-dlp gave the file. "B. Clem - Zuuso [1025657891]" → artist "B. Clem", name "Zuuso", which is exactly what trav said it was. Checked against all 474 files in the untagged folder, not against invented examples. - [x] **Careful about what it strips.** An 11-character trailing token is only a YouTube id if it carries a digit, an underscore, or case that flips repeatedly — otherwise "Cold Draft-Underground" loses a word. A hyphen only splits artist from title when it has spaces around it, so "Jay-Z" and "350-440-DialTone" survive. A 4-digit year is never a numeric id. - [x] **A guess is labelled a guess.** `IdentifyCandidate.source` is "acoustid" or "filename"; the dialog quotes a match confidence only for the former and says "No database knows this — read from the file's name" for the latter, rather than inventing a percentage. - [x] **The file now ranks the results too.** `hint_for(track)` feeds tag + filename tokens into `parse_lookup`: overlap scoring (words count double, bare numbers single — "alhambra" identifies a release, "1961" appears in every compilation spanning it), a coarse duration bucket against the recording lengths AcoustID returns, and a filename year that predates what the database knows. Alhambra now ranks the right album first with year 1961 instead of a compilation with 2002. - [x] **Live is no longer a demerit.** It was lumped in with Compilation, which buried a live album for a file whose name said "Live At The Alhambra". Only compilations, remixes, interviews and the like are demoted now. - [x] **Why the year needed the filename at all:** MusicBrainz's own `first-release-date` for "Ahmad Jamal's Alhambra" is *2002* — its three original 1961 pressings are in the database undated. A second MusicBrainz call, the obvious fix, returns the same wrong answer. 1961 exists only in trav's filename. - [x] Not done, deliberately: trav rejected "never propose a shorter title" — truncating is *wanted*, because the garbage in a title is usually the part being dropped. ### Round 45 (2026-09-02) — Ask the song what it is (v0.15.0) Some files arrive with the title right and everything else missing or wrong, and there was no way to fix that except typing. Now the audio itself is the question: right-click → **Identify Track…** fingerprints the file and asks AcoustID who it is. - [x] **Fingerprint, not filename guessing.** New `lintunes/fingerprint.py`: `fpcalc -json` (Chromaprint's CLI, detected with `shutil.which` like `ffmpeg_available()` — a runtime tool, not a pip dependency) produces a duration + fingerprint, which `lookup_fingerprint` POSTs to the AcoustID web API with `meta=recordings releasegroups releases tracks compress`. `requests` was already a dep, so the round adds none. - [x] **The year is the song's, not the pressing's.** trav's actual complaint: "I don't care when the CD of something from the 60s came out." So `parse_lookup` proposes the *original* release year — the earliest date across every release group the recording appears on — and every candidate carries it, including the one proposing a 1998 greatest-hits as the album. Years sort by when the song came out. `_releasegroup_sort_key` separately ranks a plain studio Album above EP/Single above anything wearing a Compilation/Live secondary type, so the *default* proposal is the real album too. - [x] **Nothing is written until you say so.** `gui/identify_dialog.py` is passive the way `AlbumArtDialog` is — candidates arrive pre-parsed, and the caller applies the result afterwards. Each row shows the current value beside an editable proposed one, with a checkbox that starts checked only where the proposal actually differs from what the file already has (a row the lookup knows nothing about is disabled, so it can't quietly blank a tag). A dropdown switches between alternate releases. - [x] **Applied through the one funnel.** `LibraryManager.edit_track_fields` does it, so tag writes, the abort-if-the-write-fails rule, artist/album file relocation and a single undo step all come free rather than being re-implemented. - [x] **A selection is a queue, one dialog at a time.** Each track is reviewed on its own; "Stop Identifying (N left)" abandons the rest, and a failure (unfingerprintable file, network error, no match) is a status-bar message that moves on to the next rather than ending the batch. - [x] **The key is trav's, and stays out of git.** `preferences.acoustid` + a Preferences row linking acoustid.org/new-application, following the Last.fm precedent — preferences.json rides the Syncthing share, so pasting it once covers both machines. - [x] Fixed an unrelated pre-existing test failure: round 40's `test_the_pre_010_music_root_key_counts_as_an_override` used the real tummult mount point as its stand-in for an unreachable path, so it failed whenever that drive was actually plugged in. It now builds the path under `tmp_path` and never creates it. ### Round 44 (2026-08-27) — A removal you make sticks (v0.14.0) Round 43 made the merge report honest, which made its one real limitation impossible to miss: every merge was a union, so a song removed from a playlist on one machine was handed straight back by the other on the next sync, and a track deleted from the library came back with it. A deletion you cannot make stick is not a deletion. - [x] **Removals are recorded, not inferred.** The union was there for a real reason — two copies and no common ancestor cannot tell "A added this" from "B removed it" — so the missing evidence is now written down. New `lintunes/tombstones.py`: `Playlist.track_events` holds `{track id: [when, "add"|"remove"]}` and `Library.deleted_tracks` holds `{track id: when}` in `library_metadata.json`. A merge takes the newest event per track across both copies and applies it. A removal beats a copy that merely still had the song; a deliberate re-add afterwards beats the removal; a track nobody touched still merges as a union, which is the safe old behavior for everything that has no evidence either way. - [x] **Not "the newer copy wins wholesale".** That was the tempting one-line version and it silently drops a song the other machine added while you were removing one. `test_an_unrelated_addition_is_not_lost` pins it. - [x] **Recorded in the existing funnels.** `_set_track_ids` diffs before/after (so a reorder records nothing), `_remove_tracks` stamps `deleted_tracks`, and `_restore_tracks` clears it, so Ctrl+Z on a delete takes the tombstone back with it. - [x] **Track ids are never reused.** The sharpest edge in the whole design: the next id came from `max(library.tracks)`, so deleting the highest-numbered track freed its id for the next import — and that new track would be dropped on sight by the dead id's own tombstone, on every machine. `_highest_track_id` counts the deletions too. - [x] **`library_metadata.json` merges before `library.json`.** It carries the record the library merge filters against, and `rglob` order is not a plan. `_merge_metadata` unions the two copies' `deleted_tracks` regardless of which whole copy the mtime pick kept. - [x] **A merge applying a deletion never touches a music file.** It drops the library entry only — the file was already trashed on the machine where the delete happened, and the music folder is its own Syncthing share. `test_a_merge_never_touches_a_music_file` fails the run if `send_to_trash` is so much as called. - [x] **Reported as a warning, with the song named.** An applied removal grades WARNING so it opens the merge window, names each track, and says Ctrl+Z does not reach a merge. `_Labeler.remember` keeps the name of a track library.json is about to lose, so the playlist merge can still say which song it dropped rather than "track 4". - [x] **Events expire after 30 days** (`RETENTION_DAYS`), pruned at the save boundary like the derived-membership gate. The trade is stated in the module docstring: a machine offline longer than that can resurrect a song it never learned was deleted. ### Round 43 (2026-08-27) — The merge report says who, what, and where (v0.13.0) The merge window kept saying `Order kept from this machine (most recently edited)` for playlists trav had edited on the *other* machine, and offered a backup folder holding two directories with one hex-named JSON each. Confirmed against the real snapshots in `.resolved/`: in the 9:34 PM `* a fresh master` merge, the copy labelled "the other machine" was this machine's own 3:15 PM merge output (2472 tracks, `date_modified 19:15:26` — the previous merge's own stamp), so the label was exactly backwards. - [x] **Stop guessing which machine wrote which copy.** "this machine" was inferred from which copy held the plain filename, and that is Syncthing's call, not a statement about authorship — it sets the local copy aside as readily as a remote one. The report now names the two copies for what they factually are ("the copy that was already here" / "the copy Syncthing set aside") and attributes the set-aside one from the 7-char device ID in the conflict filename, which `CONFLICT_PATTERN` used to match with a bare `\w+` and delete along with the file. New `lintunes/sync_identity.py` maps that token to a device name out of Syncthing's `config.xml` and works out which one is us by deriving our own device ID from `cert.pem` (base32 of the SHA-256 of the DER cert, the way Syncthing does). Stdlib only, best-effort: no Syncthing, no config or an unreadable cert all mean the report simply names nobody. - [x] **`date_modified` is consulted when only one copy has one.** It used to need *both* stamps (`if ours and theirs`) and otherwise fell back to file mtime — and a playlist imported from iTunes and never reordered on this machine has no stamp at all, so the honest comparison was skipped exactly when one machine had edited and the other hadn't. A stamp only exists once LinTunes recorded an edit, so stamped-vs-unstamped is evidence: the stamped copy wins. mtime is the fallback only when neither side has ever been edited, and the report says so when it happens. - [x] **No more mtime ratchet.** `_merge_playlist` rewrote the file it kept on every merge, whether or not anything changed, while Syncthing preserves the origin's mtime on the conflict file — so each merge made the copy in place harder to beat on the next one. A no-op merge now writes nothing. A merge that produces a true union stamps `date_modified`, because content neither copy had is genuinely newer than both; that is what stops two machines trading the same 19 tracks back and forth (three times in one evening, in the snapshots). - [x] **The report names the songs.** `merge_track_order` knew every re-inserted track's position and threw it away. Each re-inserted track is now listed as `Artist — Title → position 24, after "…"`, six in the window and all of them in the backup. Titles come from a lazy read of `library.json` (the 15 MB file, so only when a playlist merge actually needs a name). - [x] **Tracks the other copy didn't have are reported, not resurrected in silence.** The union policy is unchanged — nothing is ever removed — but a track only this copy has is now named, with both readings offered ("if you added it here, that's all this is; if you deleted it on the other machine, delete it here too"), since two lists give no way to tell which it was. - [x] **`what-changed.txt` in the backup folder.** The same merge in words, uncapped, beside `original/` and `incoming/` — including the real Syncthing conflict filename and its device, which the merge otherwise destroys. The dialog button is now "Open merge report". - [x] **A rename or folder move made elsewhere survives a merge.** Only `track_ids` and `settings` were ever taken from the winning copy, so a playlist renamed on the other machine was renamed back by every merge. `name` and `parent_persistent_id` come from the winner now, and `_apply_rename`/`_apply_reparent` stamp `date_modified` so a rename is comparable across machines at all. - [x] **The same revert, on the sync path with no conflict file.** `_reconcile_playlist` asserted in its docstring that the local edit was the more recent one and never checked — so a reorder synced in from the other machine was undone and then flushed straight back to disk. It reads the stamps now, and adopts `name`/`parent`/`settings` when the disk copy wins. The branch that reaches it is also gated properly: `_dirty_playlists` is set by a column drag or a sort click too, so a sync landing in the 3 s after a cosmetic click routed through the keep-local path. New `_dirty_playlist_content` marks only real content edits — the Round 42 rule ("cosmetic table settings must not look like edits") one level up. - [x] **The music folder no longer rides a coin flip.** `_merge_metadata` inferred which copy had lost from whichever one `_keep_newer`'s mtime pick had kept; when both files land in the same instant that pick is arbitrary, which is why `test_but_adopting_a_music_folder_is_a_change` passed about half the time. It decides from the two inputs' `music_folder_set_at` directly, and grades CHANGE when the folder actually differs from the one we started with. ### Round 42 (2026-08-22) — A web mix stops shipping an .m3u (v0.11.1) - [x] **No `.m3u` beside `index.html`.** It shipped on the theory that it cost nothing and let the folder double as a plain music folder, but a web mix is a folder you upload — a stray playlist file next to the page is one more thing to explain to whoever receives it. `plan.m3u_name` is now `""` for `WEB` so the plan says so rather than naming a file it won't write, and `index.html` is simply the last thing written, which is what the manifest-last invariant always meant for that branch. Folder exports are untouched. ### Round 41 (2026-08-22) — Web mixes pick their own color (v0.11.0) Every exported mix came out in the same 2010 gold-and-brown skin: a `#c7b563` player bar, `#ccc` progress fill, and a hard-coded `#8c764a` behind every hover. Now the hover backgrounds and the progress fill are one color the user picks in the export dialog, and the rest of the bar is deliberately colorless so that choice is the only color in it. - [x] **One accent, chosen per export.** A swatch button in `WebMixDialog` opening `QColorDialog`, plus Reset. Deliberately *not* persisted — it opens on `exporter.DEFAULT_ACCENT` (`#8c764a`) every time, so an export nobody touches still looks exactly like the mixes already online. `exporter.normalize_accent` is the injection gate, not a nicety: the value is substituted raw into the page's `