Surface area, not the machinery, was the problem: 16 flags crowded the
bare --help. Re-tag so basic shows only the 10 outcome-changing flags;
every other flag still works behind --help=<group>.
- cut --bt-metadata-timeout, an invented flag with no real counterpart. Keep
its 60s magnet-metadata stall as a fixed internal default (bt.go), not a
user knob.
- fix the parallelism footgun: a bare `got URL` used min(split,x)=1
connection. When -x is unset, let --split drive per-host connections
(capped at 16), so `got URL` gets 5 and `-s16` gets 16. An explicit -x
is honored verbatim, including -x1. Locked by TestHTTPConnDefault.
- -s is the per-download speed dial now, so it moves to basic; -x (a
per-server cap) moves to the http group. -j help says "files at once,
not connections within one file".
Two Pike cleanups.
--auto-split was a third connection-count policy (beside -x and -s) that added
an extra knob rather than keeping the model minimal. Removing it also retires the
now-dead autoConns/maxAutoConns and the per-host transport cap that existed only
to scale for it; min(split, M*-x) is the sole policy again.
main's exit-code mapping fell back to substring-matching third-party error text
(strings.Contains "connection refused"/"timeout"/...), which rots when a
dependency rewords a message. The typed checks (errors.Is on the syscall errno,
*net.DNSError, net.Error.Timeout, context.DeadlineExceeded) already cover the
real stdlib errors -- verified end to end: refused -> 6, bad host -> 19. The two
cases that genuinely needed the text match are our own errors, now typed
sentinels: httpdl.ErrTimeout (idle timeout) and the bt metadata timeout wrapping
context.DeadlineExceeded.
Findings from a Rob-Pike-lens review (bugs/races/network), each verified
against the code before fixing:
- httpdl: name/out are now atomic.Pointer[string] -- the engine publishes a
download to the reporter before Run resolves the name, so Stat raced the
write (bt already did this)
- httpdl: a malformed --proxy fails loudly instead of silently bypassing it
- httpdl: a 206 must carry a matching Content-Range; a 200 in segmented mode is
fatal so it fails over instead of burning the retry budget
- httpdl: single-stream mirror failover validates the range before appending;
ErrTooSlow only when the error is a real ctx cancellation
- httpdl: idle guard tracks progress by timestamp (no Reset/Stop race, no
sticky fired flag)
- httpdl/control: reject a resume file whose segments don't tile [0,total)
- bt: clamp the listen-port range; verify on-disk data before choosing pieces
under --check-integrity
- cli: reject size overflow; show --seed-time=MIN; clamp --select-file range
- progress/engine/main: clamp ETA against int64 overflow; show queued
downloads as waiting; join the reporter on exit instead of a 20ms sleep
webseed/peer/tracker warnings (the 403/429 chatter) go through slog, the
rest through the legacy analog logger; both default to Warning, which
interleaves with and corrupts the live progress block. Filter both to
Error and above so only genuine errors reach stderr. quietSlogger is a
small testable helper; anacrolix/log becomes a direct dependency.