Commit Graph
2 Commits
Author SHA1 Message Date
Codex (via nyra-lab) 3378ab4663 Fix silent callbacks and shell injection in export/transcribe scripts
mp.command_native second argument is a default return value, not a
completion callback: the callback was discarded, so exports never
reported success or failure and the synchronous subprocess blocked mpv.
Use mp.command_native_async at the four sites that pass a callback.

transcribe-subtitles built a bash -c string with the media path
interpolated, so a filename containing $(...) executed on trigger.
Pass argv directly, carry LD_LIBRARY_PATH via env, and replace the
trailing shell & with detach = true.

Verified on mpv 0.41.0: callback fires, hostile filename inert.
2026-09-27 07:44:22 +00:00
harley 7a6a5fc1f2 Initial import: mpv config + scripts
- mpv.conf: screenshot dir, loop-file
- input.conf: zoom/pan/export/screenshot bindings
- export-loop.lua (e): A-B loop to MP4 with zoom/pan/brightness bake
- export-loop-webp.lua (W): A-B loop to animated WebP + GIF
- screenshot-duo.lua (S): raw+on-screen dual screenshots
- webp-anim-bridge.lua: animated WebP playback via ImageMagick
- transcribe-subtitles.lua (T): faster-whisper SRT export
2026-07-07 23:53:06 -04:00