media: publish to our own origin instead of mirroring a file host
All checks were successful
Deploy / build-deploy (push) Successful in 7m34s

A 167 MB screen recording uploaded to catbox.moe hit fetch-media.sh's 64 MB
MAX_BYTES, so curl refused it, the entry kept its third-party URL, and e2e
failed "/posts media origin" on a file we had on disk the whole time. Raising
the cap would have papered over it: the mirror step still depends on someone
else's server being up, fast, and still holding the file.

Invert it. tools/publish-media.sh uploads a recording to the media mount under
its content hash BEFORE the post exists and prints the URL to post, and
fetch-media.sh adopts an own-origin URL by rewriting it to /media/<hash> with no
request at all — no size cap, no third party in the build.

Also here, because publishing exposed them:

  * Rotation. Phones record 1920x1080 and attach a display matrix rather than
    rotating pixels, so an untouched file reports landscape while playing
    portrait and width/height reserve exactly the wrong box. publish-media.sh
    bakes rotation into the frames; fetch-media.sh swaps the dimensions on a
    quarter-turn matrix for anything mirrored straight from a phone.
  * Posters. pict-rs will not thumbnail AV1, so a self-hosted video usually
    arrives with no poster. publish-media.sh uploads <hash>.poster.webp beside
    the video and fetch-media.sh falls back to it — a real thumbnail still wins.
  * The workflow comment claiming a file on the mount is never downloaded again
    was wrong: the name is the hash of the bytes, so third-party media is
    re-fetched every build and only the write is skipped.

Transcoding to AV1 is what makes self-hosting cheap: that clip was 78 s of a
dark room at 17 Mbps, and denoise + AV1 gives the same picture in 15 MB. Note
<video> carries a single src with no fallback, so AV1 excludes Safari < 17;
--raw skips the transcode when that matters.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
Jorijn van der Graaf 2026-08-08 01:16:17 +02:00
commit c1b0c29af6
4 changed files with 351 additions and 66 deletions

View file

@ -97,10 +97,16 @@ jobs:
# loads is third-party — which is what keeps the privacy notice's
# "everything comes from catcrafts.net" true.
#
# Content-addressed and incremental: a file already on the media mount is
# never downloaded again. Writes straight into the mount so the copies
# persist across deploys — they are NOT always reproducible, because a
# source instance deleting a file leaves ours as the only one.
# Content-addressed: the name is the hash of the bytes. Note what that
# does NOT mean — a third-party file is re-fetched on every build, because
# the name cannot be known until the bytes are in hand; only the write is
# skipped when the hash is already on the mount. Media we host ourselves
# (tools/publish-media.sh) is the exception that is genuinely incremental:
# fetch-media.sh adopts an own-origin URL without any request at all.
#
# Writes straight into the mount so the copies persist across deploys —
# they are NOT always reproducible, because a source instance deleting a
# file leaves ours as the only one.
run: |
set -eu
if [ -d /deploy-app ]; then