Audit date: 2026-07-17
Decision: the Rail channel's technical identity is v3.stage, with the
working display name V3 Stage. Existing V3 tenant packages, contracts,
Unreal paths, and database models retain their historical Saraswati names; they
are not renamed in place. The separate @saraswati/* family is an
industrial-technology domain covering EVs, batteries, manufacturing, robotics,
health hardware, IoT, and related infrastructure. It is not a media or
performance dependency.
Calliope Stage is the normative concert-design and performance-programming reference for V3 Stage. V3 does not currently import it at runtime. V3 owns the tenant-specific persona, rights, catalog, recorded-evidence authoring, quality, provenance, and Unreal contract seams. A future cook composition root should combine those V3 release gates with selected Calliope stage outputs, then require a separately rendered and verified playable artifact. Neither system may be treated as a media renderer merely because it produces an asset id, protocol plan, or VOD package description.
Audited source map#
| Concern | Existing source | What is real today | Rail decision |
|---|---|---|---|
| V3 tenant and release ownership | libs/v3/saraswati-stage, especially concert-authoring-pipeline.ts, discography-release-flow.ts, and track-c2pa-manifests.ts |
Persona/catalog/rights state and ten deterministic authoring gates exist. Recorded evidence can drive speech review, rehearsal, choreography, and cadence; a declared drill is explicitly labeled and cannot publish unless a caller opts into a drill-only receipt. | Use V3's recorded-evidence and release decisions as required inputs. Never admit GA inventory or a declared-drill receipt to the playable catalog. |
| V3 export quality | libs/v3/concert-quality |
Scene quality, corpus diversity, provenance/consent, signoff, and the authoring release state compose into a real fail-closed export report. The shared Ed25519 content signer backs track C2PA. | Require a passing export report and verified provenance for every first-party item. A report is evidence about authored content, not proof that video bytes exist. |
| V3 Unreal concert contract | ConcertMaster.v3sequence.json, V3Cinematics, and V3Audio |
The repository carries a JSON concert-master binding contract and thin module registration seams. The .uasset path is JSON text rather than a cooked LevelSequence; there is no checked-in rendered concert or music-video media. |
A cook job may invoke an injected Unreal render/export port, but cannot claim a render from the contract file. Local UE verification must use the checked-in UE5.5 tree when that job lands. |
| Calliope concert specification | libs/calliope/stage, especially types/live-performance.ts and its 30 deterministic services |
Typed, test-covered concept, setlist, stage, lighting, screens, choreography, venue, cameras, VFX, spatial-audio, audience, streaming, and VOD-package designs are substantially complete. Cross-object refinements reject mismatched artist, concept, setlist, venue, camera, and audience identities. | Cite Calliope as the normative stage specification and compose only the needed cook-time outputs. Do not duplicate its setlist/venue/camera/streaming-plan types in the channel. |
| Calliope streaming output | streaming-integration-layer.ts |
It deterministically describes destinations, ingest/output protocols, quality profiles, moderated chat, and four VOD package plans. It does not emit a stream URL, media manifest, object-store artifact, checksum, or playback receipt. | Use its pacing, perspective, and packaging metadata after render. Never convert a planned hls, ll_hls, webrtc, or VOD package label into a playable source. |
| V3 Pixel Streaming | libs/v3/lilith-web-pxstream |
A real browser client can match a worker, connect the Epic UE5.5 frontend, enforce first-frame/input-probe budgets, and reconnect. This is an interactive session path, not a scheduled progressive/VOD catalog. | Phase A stays VOD/progressive as required. Do not create a live concert dependency or use a Pixel Streaming signalling URL as a VOD item. |
| Namespace collision | libs/saraswati/README.md |
@saraswati/* is the advanced-technology intelligence domain: manufacturing, energy, mobility, health hardware, telecom, robotics, and IoT. It shares only the name with the V3 virtual-artist tenant. |
Reserve v3.stage and rail-channel-stage for this Rail channel. Keep @oshun/tenant-saraswati-stage as the legacy V3 implementation package and list any final public brand choice under HG-7. |
Phase A programming path#
The channel adapter consumes a narrow StageRenderedCatalogPort, not the V3 GA
constants or Calliope test fixtures. An eligible item must bind:
- a stable performance/version id and first-party/generated rights status;
- a V3 recorded-evidence authoring receipt and passing concert-export report;
- a real progressive/VOD delivery object plus duration, byte size, media type, SHA-256 digest, and a successful playback-verification observation;
- a separately playable paired audio source for the one-holder lane-coupling path;
- truthful artwork metadata whose referenced asset is also delivery-verified;
- Calliope-derived energy, set section, camera perspective, and pacing metadata when the cook used those plans.
The programming compiler is deterministic. It filters ineligible or unplayable rows, chooses an explicit daypart pacing target, scores energy and cut density distance, penalizes recent repetition, and orders ties by stable item id. It compiles a bounded horizon without shuffle or a seed catalog. Empty input produces no program.
Implemented 2026-07-17: libs/v10/rail-channel-stage now owns this strict
catalog projection and compiler. It caps catalog reads, rejects duplicate ids,
requires current exact-size/SHA-256 video, audio, and artwork observations, and
keeps follows/favorites exclusive to the player-face score. Stable program ids
derive from the selected versioned rows and schedule rather than randomness.
The cook job is a composition root: read a release candidate, require recorded V3 evidence and export gates, select the cited Calliope specification outputs, invoke an injected render/export port, store immutable media, and verify the stored bytes before publishing the catalog row. A renderer that is not configured fails closed. Licensed third-party catalog expansion remains HG-2; first-party/generated artifacts are the agent-actionable Phase A path.
Implemented 2026-07-17: StageRenderedMediaCookJob supplies this
composition root through injected source, V3 release-gate, render,
immutable-store, delivery-verifier, and catalog-writer ports. It hashes the
renderer-returned bytes itself, rejects changed store or delivery receipts, and
publishes no catalog row on any missing or blocked boundary. The repository
still contains no production renderer binding or rendered Stage catalog row, so
the job does not create fictitious availability.
Playback and premiere truth#
Phase A items are VOD/progressive. The video-lane source may offer its paired
audio through one coupled-holder operation; the channel must never acquire the
audio lane independently and create two effective holders. Concert slots are
premieres of scheduled VOD items. They may request a scheduled Rail live
moment with preannouncement, but their copy and payload must say premiere, not
live. A genuine live class is deferred until RB.4 supplies a verified live
delivery path.
Implemented 2026-07-17: the shared contract now distinguishes
first-party-vod from first-party-live. CoupledMediaLaneArbiter accepts one
digest-derived media identity through an offer/withdraw-only channel port, rolls
back partial offers, preflights both lanes, and commits or releases video and
audio at one validated Rail instant. publishStagePlayback reads and compiles
the verified catalog, then offers the exact progressive video/audio URIs without
selecting them. stagePremiereElevationRequest produces a preannounced
scheduled moment whose customer title, glance copy, and event payload all say V3
Stage premiere. No Stage path declares the unavailable live class.
Presence faces and native playback#
createStageManifest registers the calm v3.stage spectator and player faces.
StageTileRenderer accepts only an injected, strict StageProgram: positions
and timestamps must be contiguous, the requested instant must resolve to one
item, and spectator items cannot carry player preference signals. It emits the
current verified artwork/title/artist, the next scheduled item, a state-derived
text-only summary, and a contextual V3 Stage deep link. The spectator compiler
ignores follows and favorites; the player compiler may use them to shape the
program and labels that signal without leaking it to the public face.
The shared V10 PresenceTile renders one restrained artwork plane with an
explicit now-playing/up-next hierarchy and no media or autoplay motion. The web
video panel mounts a selected first-party-vod progressive URI in a native
<video> element, muted and paused. Only the user Play button invokes
HTMLMediaElement.play(); pause and mute remain explicit 44-pixel controls.
Unsupported non-progressive VOD fails visibly instead of entering a provider or
live fallback.
Vitest covers the strict Stage boundary and native user-action invariant. Playwright runs the real renderer projection for both faces and text-only mode, plus actual encoded test-only WebM bytes, in desktop and mobile Chromium. The encoded browser fixture proves native playback behavior only; it is not a V3 catalog row or production render artifact.
Shared live-media production authority#
Implemented 2026-07-21: libs/v10/rail-channel-stage/src/production.ts now
supplies the V3 Stage tenant-#3 product composition over the canonical shared
media substrate. Pipeline jobs, publisher grants and resource mapping, leased
viewer sessions, signed playback grants, and protected playback all fix tenant
v3-stage after injected options. Product-owned principals,
v3.stage:<stream UUID> external identities, v3-stage.player-client.v1,
v3-stage.immersive.v1, and the bounded identity denial are not caller
replaceable.
Contract tests exercise the wrappers against the real shared controls with the same stream, job, publication, viewer-session, and entitlement identities used by a sibling Veritas tenant. Scopes, resource mappings, principals, adapter selection, and results remain tenant-isolated. This composes production authority without claiming that a Stage renderer, content catalog, scheduler, publisher host, or player host has been deployed.
Immutable rendered delivery#
Implemented 2026-07-21: V3StageImmutableDeliveryAdapter binds the existing
cook to the canonical @oshun/live-media create-only object-store contract.
Every object key is tenant-fixed below
live-media.v1/v3-stage/catalog/v1/<item>/versions/<version>, and only the
closed Stage progressive video, paired-audio, and artwork MIME matrix is
accepted. Exact pre-existing bytes replay idempotently; changed bytes at the
same immutable key, role/MIME substitution, oversized objects, credentialed or
non-HTTPS origins, redirects, and object-path escape all fail closed.
Verification is delivery evidence rather than a storage assertion. The adapter
rechecks the stored object, retrieves the exact public HTTPS URI without
credentials or redirects, requires HTTP 200 plus matching content type, length,
and SHA-256, and passes the bounded returned bytes to
FfprobeStageStoredMediaProbe. That probe uses a private transient file and
requires a decodable video/audio stream with positive duration or artwork with
positive dimensions before the cook may publish. The Streaming release-gate test
generates real MP4, M4A, and PNG bytes with FFmpeg and carries all three through
the create-only store, public-delivery boundary, real ffprobe, and full Stage
cook into an in-memory catalog writer. These generated gate bytes are test
evidence, not V3 content inventory.
Recorded V3 release authority#
Implemented 2026-07-21: the dedicated
@oshun/v10-rail-channel-stage/release entry point exposes
V3StageRecordedReleaseGateAdapter without pulling V3 authoring/export
dependencies through the browser-facing channel root. It binds the cook's
release port to the authoritative @oshun/tenant-saraswati-stage recorded
authoring state and @oshun/v3-concert-quality export-readiness contract. It
requires exact item, version, and concert identity; every recorded authoring
gate; the published Sequencer receipt; full provenance attachment; GA cadence;
and a fresh v3_concert_export report whose non-human results each retain their
exact-subject canonical proof and proof verdict. Duplicate, expired,
wrong-subject, wrong-type, or detached proofs cannot be projected as ready.
When the export suite declares a human-signoff gate, readiness additionally
requires its exact fresh promotion record and canonical human_approval proof,
bound to the same artifact, content hash, signer, decision, and evidence. A
declared-drill authoring result always projects as blocked even if its planning
fixture passed. This closes the release-evidence adapter only: it does not
invent a durable candidate repository, Calliope selection, rendered bytes, or a
catalog row.
Durable V3/Calliope candidate source#
Implemented 2026-07-21: the server-only release entry now also exposes
SqlV3StageCookCandidateRepository. Migration
20260721190000_v10_stage_cook_candidates adds immutable, versioned candidate
projection rows to the canonical OSHUN PostgreSQL schema. A partial unique index
admits only one ready revision for a candidate; exact retries are idempotent,
newer versions transactionally supersede the current row, and withdrawal is
terminal for that version. Bounded cook reads recompute the projection SHA-256
and rebind every indexed identity before returning a candidate.
The projection embeds values validated by the owning V3 persona, concert, setlist, and track schemas and by Calliope's setlist, virtual-camera, and streaming-layer schemas. It additionally requires one recording-authorized V3 concert, exact V3 track coverage and duration, a bijective Calliope-slot/V3-track join with matching titles, and exact Calliope artist, concept, setlist, camera, and venue identities. A selected programming anchor must exist in the setlist, camera coverage, and VOD package plans. Energy, section, and perspective derive from those selected plans; numeric cut density remains a separately cited editorial measurement because Calliope carries only a prose cadence rule. Neither the migration nor its real-PostgreSQL restart test seeds a production candidate or treats a VOD package as playable media.
Durable rendered catalog#
Implemented 2026-07-21: the server-only release entry exposes
SqlV3StageRenderedCatalogRepository as both the cook's catalog writer and the
programming reader. Migration 20260721230000_v10_stage_rendered_catalog adds
immutable, versioned catalog items to canonical OSHUN PostgreSQL with a
canonical item SHA-256, indexed artist/concert identity, explicit lifecycle
evidence, an identity/JSON update fence, and a partial unique index admitting
only one active revision per item.
Publication is transactional and requires increasing versions and publication times. Exact active retries are idempotent, a newer version supersedes the former active row, and explicit withdrawal is terminal for that version. Bounded reads select only due active rows, rebind every indexed identity, recompute the complete item hash, and reject conflicting active ids. Unit and schema coverage plus a disposable full-migration PostgreSQL gate prove restart, direct tamper rejection, concurrent exact retry, supersession, withdrawal, and resurrection denial. No migration or test seeds a production catalog row.
Explicit gaps#
- No playable rendered Stage performance or music-video artifact was found in the repository.
- No V3 or Calliope output currently includes a verified progressive/HLS/DASH delivery URI for a concert VOD.
- No production composition-root binding currently supplies the implemented cook with an Unreal renderer and real candidate/catalog inventory. The durable candidate/Calliope source, recorded-release, immutable-store, exact public-delivery verifier, and durable catalog writer/reader now exist, but no production candidate or catalog row has been authored.
- No deployed long-running V3 Stage scheduler, publisher host, or playback-route host binds the new tenant-fixed shared-media controls.
- The Calliope fixture builders and V3 GA inventories are test/design inputs, not catalog content.
- Licensed third-party music-video rights are a human/business gate (HG-2).
The cook, catalog contract, deterministic compiler, coupled lane adapter,
presence faces, and native progressive renderer now exist, but these
production-content gaps still prevent v3.stage from claiming an available
program. They do not justify a sample playlist, invented media URL, or a
fake-live concert.