Audit date: 2026-07-18
Ledger item: RB.3 service audit Status: Complete — 17 deployable services and 36 directly adjacent libraries were read sequentially; extraction work remains separate and open.
Decision standard#
This audit separates reusable live-media mechanics from Aphrodite's adult-ring policy and product surfaces before any code moves. A service is not reusable merely because its names are generic. For each deployable app, the audit checks its composition root, routes or UI boundary, state and repository interfaces, cross-package dependencies, tests, and production defaults. Each verdict is one of:
- extract organ — move the reusable behavior behind a tenant-parameterized shared streaming contract, preserving Aphrodite through equivalence tests;
- thin tenant adapter — keep Aphrodite policy/presentation in the app and replace generic mechanics with shared-organ calls;
- retain tenant control plane — the app is not a streaming organ; connect it only through narrow substrate hooks; or
- client of substrate — the surface consumes shared viewer/broadcaster contracts and owns no server-side media organ.
Production-readiness gaps are recorded because extraction must not turn an
in-memory default, simulated transform, or permissive auth boundary into a
shared promise. The target remains one shared stack consumed by Aphrodite,
Veritas, V3 Stage, and the V10 video lane; it does not create a second stack
under apps/v10 or libs/v10.
Deployable inventory#
| # | Service | Audit status | Preliminary class |
|---|---|---|---|
| 1 | admin |
complete | retain tenant control plane |
| 2 | admin-bi-dashboard |
complete | retain tenant control plane |
| 3 | analytics |
complete | extract organ |
| 4 | analytics-dashboard |
complete | retain tenant control plane |
| 5 | auth |
complete | retain tenant control plane |
| 6 | broadcaster |
complete | thin tenant adapter |
| 7 | cdn |
complete | extract organ |
| 8 | chat |
complete | extract organ |
| 9 | devices |
complete | retain tenant control plane |
| 10 | mobile-broadcaster |
complete | client of substrate |
| 11 | mobile-viewer |
complete | client of substrate |
| 12 | notifications |
complete | retain tenant control plane |
| 13 | payment |
complete | retain tenant control plane |
| 14 | realtime-analytics |
complete | extract organ |
| 15 | streaming |
complete | thin tenant adapter |
| 16 | viewer |
complete | thin tenant adapter |
| 17 | vr |
complete | extract organ |
1. apps/aphrodite/admin#
Role and boundary. A deployable Hono admin API on port 3004 exposes public health/selected-settings reads and bearer-protected user, moderation, and settings routes. Its domain types cover account sanctions, content flags and review actions, audit records, platform settings, and operational metrics. The service emits local process events after mutations; it does not ingest, transcode, deliver, or play media.
State and integration reality. The service defines useful repository ports
for users, audit logs, moderation items, and settings, but its composition root
installs in-memory repositories by default. The current auth middleware checks
only for a Bearer prefix and then stamps a fixed mock administrator; its own
comment defers real JWT/JWKS verification. The only service-specific automated
test file covers moderation escalation and terminal-state behavior. These facts
make the current app unsuitable as a shared authorization or durable moderation
authority.
Generic vs tenant-specific. Queue pagination, moderation lifecycle, audit recording, and settings interfaces are broadly useful control-plane concepts. The concrete violation taxonomy, public settings, admin roles, moderation policy, and user-action semantics belong to Aphrodite and its adult-ring governance. None is required in the synchronous media path.
Reuse verdict: retain tenant control plane. Do not move this app into the streaming substrate. Shared live chat and ingest should expose narrow, tenant-parameterized moderation/event hooks that this service can consume. Aphrodite remains responsible for authenticating operators, choosing policy, persisting cases, and applying sanctions. Before it can protect a production tenant, its composition root needs verified operator identity and durable repositories; RB.3 must not disguise those separate gaps as extraction.
2. apps/aphrodite/admin-bi-dashboard#
Role and boundary. A deployable Hono reporting API exposes platform, revenue, user, content, and compliance endpoints plus health and a static API description. It is an operator read surface; it owns no ingest, media delivery, viewer session, or chat lifecycle.
State and integration reality. The app has logger/cache injection seams, but
its default cache is process-local and the server never composes the listed
analytics, database, prediction, or Redis dependencies into route data. Instead,
the route modules derive purported users, streams, revenue, bitrate, moderation,
age-verification, 2257, and GDPR results from hard-coded category tables and
per-request deterministic hash functions; export records are likewise generated
in the response path. No authentication or permission middleware populates the
declared adminId/permissions context. Production CORS narrows origins, but
the factory default is wildcard while credentials are enabled. The Nx test
target explicitly permits zero tests, and the app contains no test files.
Generic vs tenant-specific. Period parsing, pagination schemas, cache interfaces, and report response shapes could inform a generic operations API. The named categories, adult compliance reports, revenue assumptions, synthetic thresholds, and presentation taxonomy are Aphrodite policy. More importantly, none of the returned values is an authoritative measurement today.
Reuse verdict: retain tenant control plane. Do not extract its generated reports or call them substrate telemetry. Shared streaming organs should emit a small, versioned tenant-tagged operational event/metric vocabulary and expose real read-model ports. Aphrodite may keep this API as its dashboard composition surface after replacing formulas with authenticated queries. Until then, it is neither an equivalence oracle nor a production source for viewer, quality, revenue, or compliance claims.
3. apps/aphrodite/analytics#
Role and boundary. This Hono application accepts single and batch analytics
events, queries the event ledger, returns stream/creator/viewer metrics, and
computes creator-dashboard rollups. Its pipeline normalizes and validates
events, performs process-local ID deduplication and buffering, and writes
through an IAnalyticsClient. The production factory defaults to the real
Postgres-backed SqlAnalyticsClient from @aphrodite/analytics-warehouse;
tests inject the supplied in-memory implementation.
State and integration reality. The SQL client persists and aggregates the
analytics_events table, while the dashboard derives several finer measures
from paged raw events. Eleven focused tests exercise configured-store ingest and
dashboard calculations. However, the app has no authentication or authorization
middleware: public callers can ingest arbitrary identity-bearing events, query
viewer and creator history, read earnings, or invoke the nominal admin flush.
Neither the event contract nor the SQL table access includes a tenant key, so
IDs are globally trusted and isolation cannot be enforced. The package's start
script executes dist/index.js, but source index.ts only exports the factory
and contains no Node listener, signal handling, or initialization call. The
deduplication cleanup interval is not retained or cleared on shutdown, and some
SQL rollups deliberately return zero for unimplemented fields such as unique
viewers, durations, and engagement. These are extraction blockers, not
properties to preserve as shared production behavior.
Generic vs tenant-specific. Buffered ingestion, batch failure reporting, an append-only event-store port, bounded metric queries, and operational stream measurements are reusable mechanics. The concrete taxonomy combines generic stream/viewer events with Aphrodite monetization, private-show, device, social, and VR product events; the creator earnings and audience dashboard is likewise an Aphrodite read model. User, creator, and stream IDs without a tenant context are not a safe cross-product contract.
Reuse verdict: extract organ. Define a small versioned, tenant-required live-media telemetry envelope and durable sink/read ports in the shared substrate. Extract the validated batching/lifecycle mechanics only after adding bounded buffering, managed timers, authenticated producer/reader context, and cross-tenant denial tests. Keep the adult monetization/social taxonomy and creator-dashboard projections behind a thin Aphrodite adapter that maps to its own warehouse. The existing app and schema remain migration inputs and equivalence fixtures; they are not the final multi-tenant telemetry service.
4. apps/aphrodite/analytics-dashboard#
Role and boundary. This is a server-side Hono reporting and prediction API,
not a browser dashboard. It serves revenue, viewer, engagement, trend,
creator/viewer/admin/realtime dashboard, alert, segment, funnel, export, and
prediction routes, and attaches a WebSocket server on port 3400. Its principal
read path pages @aphrodite/analytics-warehouse events and calculates bounded
rollups; Sophia models consume those real histories for selected prediction
routes.
State and integration reality. The default analytics dependency is the real SQL client, with an injectable client for tests. Quick exports and the primary HTTP reports now derive values from actual events or return explicit 501 errors when a source/model is absent. The 112 route/model tests are meaningful evidence against the earlier hash-derived HTTP reports. That does not make the entire surface authoritative: alert configurations, segments, and funnels include hard-coded lists and create/update/delete handlers that only echo a response; several acknowledgement/detail paths synthesize records. Layout, export-job, and scheduled-report persistence is absent. Every WebSocket channel is generated from deterministic hash formulas rather than the warehouse, despite being advertised as real-time analytics. The default cache is process-local, and the global SQL client is neither closed nor reset during context shutdown.
Security and tenancy. No HTTP middleware authenticates a viewer, creator, or
administrator or binds request-scope IDs. All reporting, mutation, prediction,
WebSocket stats, and WebSocket subscription paths are public. A caller-selected
clientId identifies a socket but proves no identity, and channel filters do
not enforce tenancy. Like the underlying warehouse contract, all queries lack a
tenant dimension. The production CORS fallback can resolve to * with
credentials when CORS_ORIGINS is unset; CORS would not substitute for access
control in any case.
Generic vs tenant-specific. Bounded event pagination and some stream-quality rollups demonstrate consumers of the reusable telemetry port. Creator earnings, private-show/content-sale analytics, supporter segmentation, dashboard layouts, alerts, and presentation schemas are tenant product/control-plane concerns. Prediction models are already separate packages and do not justify making this API part of the synchronous media substrate.
Reuse verdict: retain tenant control plane. Keep this deployable as an Aphrodite reporting composition surface. Point it at the extracted tenant-safe telemetry read port, then add authenticated roles, durable configuration stores, and real WebSocket sources. Do not extract its route graph, global context, synthetic socket feed, or Aphrodite dashboard schemas. Other tenants can build their own reporting projections over the same shared operational events without inheriting adult monetization policy or a second analytics service.
5. apps/aphrodite/auth#
Role and boundary. This Hono identity API implements registration/login, HS256 access tokens, opaque refresh tokens, password changes/resets, OAuth callbacks, TOTP/backup-code management, authorization middleware, and an uncomposed session service. The server listens on port 3003. Roles and permissions encode Aphrodite user, creator, moderator, administrator, content, stream, and payment policy; no media bytes or session signaling pass through it.
State and integration reality. Repository/store interfaces exist for users, refresh tokens, reset requests, OAuth links, TOTP data, and sessions, but the app and production entry point always install in-memory implementations. The listed database dependency is unused. Process-local maps also hold lockouts, rate limits, revoked access-token IDs, used backup codes, and OAuth state. Some cryptographic primitives are sound in isolation (PBKDF2, HMAC verification, CSPRNG token material, TOTP), but their composed flows are not viable:
- refresh tokens are opaque random hex, yet refresh first calls the JWT decoder, so every issued refresh token is rejected;
- reset tokens are stored with a freshly salted password hash and looked up by a second freshly salted hash, which cannot match;
- the email-verification route accepts any nonempty token and marks an arbitrary supplied user ID verified;
- enabling TOTP updates only the separate 2FA repository, never the auth user's
twoFactorEnabledflag; login does not call the TOTP service and merely emits the supplied code in an event when the flag is set; and - configured JWT issuer and audience are neither placed in nor checked on the token, production secrets fall back to checked-in placeholder strings, and revocation is process-local.
OAuth state is process-local and based on Math.random; callback tokens can be
placed in a caller-provided return URL query. The direct server bootstrap also
reintroduces wildcard credentialed CORS when no environment origin is set,
overriding the factory's default-deny intent. No automated tests exist for any
of these security-critical paths.
Generic vs tenant-specific. Authenticated principal/tenant claims and capability checks are mandatory substrate inputs. The identity provider, credential recovery, OAuth account linking, creator/moderator role hierarchy, and payment/content permissions are tenant control-plane policy. Reusing this custom token implementation would couple every product to Aphrodite claims and inherit broken security flows.
Reuse verdict: retain tenant control plane. The substrate should accept a small verified principal contract from a configured identity adapter and enforce tenant/resource authorization at its own boundary; it should not issue end-user credentials. Keep or replace this app within Aphrodite, but do not extract its JWT, repository, OAuth, 2FA, session, or rate-limit implementation. Aphrodite must first add durable stores, secret fail-fast, issuer/audience/tenant claims, end-to-end negative security tests, and corrected refresh/reset/verification/2FA flows before its tokens can authorize shared media operations.
6. apps/aphrodite/broadcaster#
Role and boundary. This port-3100 Hono API is Aphrodite's broadcaster control surface. It manages stream records/keys/settings/lifecycle, broadcaster profiles and schedules, private/group shows and goals, interactive-device registrations, monetization settings, and broadcaster analytics. It is a server application despite the name; it does not capture a camera or encode media.
State and integration reality. The production route seams lazily compose SQL
stores over @aphrodite/database, with memory stores used as boundary test
doubles. Queries consistently resolve the authenticated user to an owned
broadcaster row. Sixty-four focused route/integration tests cover ownership and
state behavior, and unmodeled features generally return explicit 501 responses
instead of invented success. The media boundary is nevertheless absent. The
declared @aphrodite/streaming-core dependency is never imported. Creating a
stream generates and stores a key locally; start/stop only update the
streams status/timestamps; key rotation only updates the database; playback
URLs are nullable values assumed to have been provisioned elsewhere. No call
provisions ingest, validates that an encoder connected, starts a pipeline,
receives authoritative media lifecycle events, or revokes a key at the ingest
edge. The thumbnail capture and physical-device bridge correctly report gaps.
Security and tenancy. The app verifies an HS256 bearer token through an
environment secret or injectable verifier and fails closed when a presented
token cannot be checked. It extracts only sub; it does not validate or carry a
tenant, issuer, audience, broadcaster capability, or token-to-resource tenant
binding. The SQL schema is Aphrodite-global and ownership is user-based. Thus
the existing boundary is useful Aphrodite authorization evidence but not the
multi-tenant substrate contract.
Generic vs tenant-specific. Create/provision, rotate/revoke ingest credentials, start/stop reconciliation, playback endpoint discovery, media health, and lifecycle events are reusable streaming control-plane mechanics. Sensual/explicit flags, token earnings, private/group shows, tip goals, broadcaster KYC/profile policy, blocked users, and interactive adult-device settings are Aphrodite product behavior. The current analytics are product read models over Aphrodite tables, explicitly not wire telemetry.
Reuse verdict: thin tenant adapter. Keep this app and its adult-ring product APIs in Aphrodite, but replace direct stream/key/status mutations with calls to the shared tenant-parameterized stream-control organ. Persist the returned substrate resource ID and project authoritative lifecycle events back into the Aphrodite schema. Extraction must make ingest-key revocation effective at the edge, make start/stop reflect actual pipeline state, and add equivalence tests through this existing route/store boundary. Do not move shows, devices, profiles, earnings, or their database schema into the substrate.
7. apps/aphrodite/cdn#
Role and boundary. This port-3005 Hono API groups reusable object-upload, delivery signing, cache-control, cache invalidation/warming, and CDN metric operations. It provides S3-compatible single/multipart upload flows, CloudFront-style signed URLs/cookies, a lightweight resource token, CloudFront invalidation and CloudWatch metric adapters, plus cache-header middleware. It does not itself serve an HLS/DASH origin, select renditions, or proxy media segments.
State and integration reality. The CloudFront provider and multipart S3
paths call real AWS SDK surfaces through injectable ports. Twenty-eight tests
cover CloudFront command/error/metric behavior, multipart create/part/complete/
abort behavior, and honest health responses. Production composition does not use
that capability: createApp defaults to MockCDNProvider, and the server entry
never supplies a CloudFront provider, so invalidation/warming reports success
without touching a CDN and stats remain zero. Upload records, invalidation
records, pending batches, and multipart session IDs all default to process-local
memory and disappear on restart. Shutdown does not stop cache batching or close
provider clients.
The direct single-object presigner is a hand-written approximation rather than
the AWS presigner used for multipart parts; its canonical-request digest calls
HMAC-SHA256 with an empty key instead of SHA-256, so it is not valid SigV4
proof. The lightweight token similarly hashes payload + secret rather than
using HMAC and compares strings non-constantly. Neither direct presigning nor
either signing service has automated coverage. publicUrl is constructed from
the S3 endpoint even when the bucket is private, and a client can mark a direct
upload complete without a storage HEAD/checksum confirmation.
Security and tenancy. Any header beginning with Bearer is accepted and
mapped to the same fixed mock user. All protected users can request signatures,
purges, and uploads as that identity; only full invalidation checks a role,
which the mock never grants. Status, completion, failure, abort, progress, and
delete routes accept an arbitrary upload ID without verifying its owner. Object
keys contain a user ID but no tenant ID, resource policy, or media
classification. The direct server also overrides default-deny CORS with wildcard
credentialed CORS and defaults to well-known MinIO credentials.
Generic vs tenant-specific. Provider-neutral object keys, durable upload lifecycle, official presigning, signed playback grants, cache profiles, purge batches, and CDN health/metrics are reusable delivery mechanics. Aphrodite's content categories, user identity, authorization rules, retention/moderation decisions, and public/private entitlement policy must enter through tenant adapters. The current upload API is broader than the streaming core and should not imply that it already delivers adaptive live video.
Reuse verdict: extract organ. Extract provider ports and the verified S3/ CloudFront mechanics into a tenant-required storage/delivery organ. Replace the custom signatures with official/verifiable primitives, bind every object and operation to tenant plus resource ownership, persist resumable state, verify object completion, and make provider readiness fail closed. The shared stream pipeline can then ask this organ for origin/object locations and scoped playback grants. Keep Aphrodite routing/category/policy in a thin adapter, and retain provider integration tests as equivalence evidence; the current mock-composed app is not production delivery evidence.
8. apps/aphrodite/chat#
Role and boundary. This port-5000 Hono plus Socket.IO service provides
stream-room chat, presence/typing, message history/search/deletion, live and
durable moderation surfaces, and one-to-one direct messages. A chat room is
defined as an Aphrodite streams row. Socket messages and DMs write through the
same SQL store ports used by REST; memory implementations serve as boundary
doubles.
State and integration reality. Production messages, room views, direct messages, blocks, and selected moderation history use real Aphrodite tables. Socket handshakes fail closed and derive identity/roles from a verified shared HMAC envelope rather than client-authored claims. Seventy-one tests cover REST behavior, socket auth tampering/expiry, DM persistence/authorization, moderation authorization/clearing, and content-filter edge cases. The realtime plane is single-node: connected users, rooms, broadcasts, typing, filters, duplicate/ slow-mode state, and socket mutes/timeouts live in process memory, with no Socket.IO cluster adapter or distributed presence/rate-limit store.
Moderation has two inconsistent authorities. REST bans persist to
viewer_blocks but none of the socket join/send checks query that store; socket
bans/mutes use a separate memory map and are not persisted. Filter configuration
is public, mutable, and memory-only. Room join accepts any supplied ID without
checking that the stream exists or that the principal is entitled, although the
later message insert can fail for a missing stream. The content filter is called
without userId, disabling its per-user duplicate-message check. A client may
also label any socket message as a tip and supply any amount, which is persisted
as a TIP chat row without payment evidence.
Security and tenancy. WebSocket authentication is the strongest boundary in
this app, but its token contract has no tenant claim and trusts embedded global/
room role strings. The entire REST API has no authentication middleware: DMs and
deletion trust a caller-controlled x-user-id, and ban/filter mutations have no
identity or role check at all. SQL rows are keyed by globally assumed
stream/user IDs, not tenant plus resource. Multi-node delivery, membership, and
moderation therefore cannot currently preserve isolation or consistent policy.
Generic vs tenant-specific. Authenticated room membership, ordered durable messages, bounded history, presence, fan-out, rate limiting, deletion events, and moderation hook ports are reusable live-session mechanics. Direct messages, client presentation events, tip highlights, filtered-word policy, subscriber/ follower access, moderator assignment, and sanctions are tenant product policy. The substrate must never infer a payment from a chat payload.
Reuse verdict: extract organ. Extract stream-room chat behind tenant-required principal, session, membership, persistence, fan-out, and policy-provider ports. Unify REST/socket authorization and the moderation source, require a real stream session before joining, add distributed adapter/state support, and accept tip or system messages only as authenticated server events. Keep Aphrodite DMs, adult-ring filters/sanctions, and user-facing schemas in a thin adapter. Run the existing store/socket tests against both the adapter and shared organ, adding cross-tenant, reconnect/order, multi-node, and policy-denial equivalence cases.
9. apps/aphrodite/devices#
Role and boundary. This port-4003 Hono plus Socket.IO application is an intimate-device gateway. It exposes pairing metadata, device status, custom and built-in motion patterns, funscript conversion, tip-to-pattern triggers, and live commands for Lovense, Buttplug/Intiface, Kiiroo, Handy, OhMiBod, and T-Code serial devices. Media is neither ingested nor delivered; only the Handy/funscript features conceptually synchronize an external actuator with content time.
State and integration reality. Several protocol classes contain genuine HTTP, WebSocket, Intiface, and serial-port translations. The composed service does not connect REST pairing to them: devices/credentials are held in one module-level memory map, patterns and triggers in singleton memory managers, and live sessions/devices in another memory graph. The WebSocket manager constructs each shared protocol handler with an empty config, so user tokens, Handy keys, serial paths, and cloud endpoints captured by REST never reach it. Consequently most cloud discovery returns empty, while local-network/Intiface/serial discovery runs on the server host rather than the remote user's machine. The listed database dependency is unused and all pairing/trigger/custom-pattern/session state vanishes on restart. Disconnected sessions are retained indefinitely.
Sixty-six tests cover extensive REST shapes and signed WebSocket identity, but there is no vendor contract, hardware-in-loop, REST/socket composition, safety stop, reconnect, or payment-event authenticity coverage. Several protocol success responses mean only that a command was sent, not acknowledged by a device. The HTTP health surface does not probe a device bridge or durable store.
Security and tenancy. Socket identity fails closed and comes from a signed
token, but carries only a global user ID/roles. REST operations trust an
arbitrary x-user-id header. The Socket.IO server defaults to wildcard CORS.
Most critically, the authenticated device owner can submit an arbitrary
tip:process event, including its amount and recipient, and thereby activate
hardware without an authoritative payment event. Shared protocol-handler maps
and global tip callbacks also lack an explicit tenant/owner partition.
Generic vs tenant-specific. A generic live-media substrate may publish authenticated timecode, stream-lifecycle, or monetization-domain events through narrow hooks. Vendor pairing, intimate-hardware commands, patterns, consent and intensity limits, funscript semantics, and tip automation are a separate high- risk Aphrodite product domain. Moving them into streaming core would expand both the safety boundary and every other tenant's dependency surface.
Reuse verdict: retain tenant control plane. Do not extract this service into the streaming substrate. Aphrodite should first move hardware control to an appropriate user-local bridge, persist consent/pairing/trigger policy, replace spoofable REST identity, consume payment events only from a verified service, and prove fail-safe stop/reconnect behavior. The shared substrate should expose only optional tenant-tagged session/timecode hooks; this app remains one consumer and cannot influence ingest, playback authorization, or core session lifecycle.
10. apps/aphrodite/mobile-broadcaster#
Role and boundary. This package is a React Native creator application: it contains home, stream setup, camera/control, chat/moderation, analytics, and settings screens plus client-side portrait, face-tracking, notification, and background-image bridges. Capture and encoding necessarily run on the creator device, but this surface is not a server-side ingest, session, or delivery organ. Its adult categories, tips/revenue display, chat policy, beauty effects, and creator workflow are Aphrodite presentation and product behavior.
Execution and integration reality. The repository explicitly records the
package as TypeScript-only: there is no Android or iOS project, app registry,
Metro/Babel setup, Detox configuration, or end-to-end test. The declared React
Native build and Detox targets therefore cannot run. More importantly, every
publisher method in StreamingService is an empty native-module stub, including
permissions, camera preview, encoder configuration, RTMP connection,
publish/mute/stop, health collection, adaptive bitrate, effects, snapshots, and
local recording. These no-ops still advance the local session to live and
return constant healthy metrics, so the state machine can falsely report a
successful broadcast without capturing or sending a frame.
There is no control-plane provisioning path. StreamScreen initializes both the
stream key and RTMP URL to permanent null values and exposes no setter;
StreamSetupScreen collects settings but neither configures the service nor
passes data and only navigates backward. No route calls an API to create a
stream, obtain a scoped ingest grant, acknowledge connection, discover playback,
or stop the server session. The on-screen camera area is a text placeholder. The
chat service similarly marks itself connected while all Socket.IO connect, send,
moderation, poll, ping, and persistence hooks are no-ops. Analytics is the sole
real network client, hard-coded to https://api.aphrodite.app, but its bearer
token initializer is never called, so it sends Bearer null and silently falls
back to empty data after failures. Several auxiliary native bridges have
explicit JS fallbacks, but there is no native shell that could supply their
modules.
Evidence and risk. Ninety-three tests cover only background-image, depth,
face-tracking, notification, portrait-segmentation, and their service wrappers.
There is no automated coverage for the publisher, stream screens, credential
lifecycle, chat transport, analytics authentication, or a runnable mobile flow.
The screen cleanup also captures the initial idle status in an
empty-dependency effect, so unmount does not reliably end a later live session.
In-memory stream keys are included in returned session objects without a modeled
secure-storage or redaction boundary. These facts make this scaffold neither
working- publisher evidence nor an equivalence oracle for extraction.
Generic vs tenant-specific. A reusable client contract should obtain a short-lived tenant/session-bound ingest grant, configure an actual platform publisher, report authoritative connection/health transitions, reconcile stop and reconnect with the control plane, and keep credentials out of logs and durable client state. Its platform-specific implementation may be delivered as a shared broadcaster SDK/adapter consumed by multiple apps. Screen layout, adult categories and access settings, tips, moderation controls, creator analytics, visual effects, and notification presentation remain Aphrodite-owned.
Reuse verdict: client of substrate. Do not move this React Native app or its
simulated services into the server substrate. Replace StreamingService with a
real, fail-closed publisher adapter behind the shared client contract and have
an authenticated Aphrodite control-plane adapter provision/revoke the substrate
session. Only then can native-shell builds, device/simulator automation, network
interruption tests, and server-observed media/lifecycle assertions establish
equivalence. The shared substrate owns the grant and authoritative session;
Aphrodite continues to own this creator experience and its product policy.
11. apps/aphrodite/mobile-viewer#
Role and boundary. This package is intended to be Aphrodite's React Native viewer client, with local service abstractions for adaptive playback, chat, tipping, offline downloads/background playback, and cardboard/WebXR viewing. It contains no deployable server or server-side media mechanics. Viewer presentation, mature/subscriber labels, tips and gifts, emotes, offline UX, and VR controls are tenant product concerns; playback-session acquisition and health reporting are its potential shared-client boundary.
Execution and composition reality. Only five service classes and type files
exist. There is no App.tsx, screen, navigator, app registry, native bridge,
Android/iOS project, Metro/Babel configuration, or Detox configuration, even
though the copied scaffolding note says that app/screens/bridges exist and the
Nx targets advertise native and end-to-end builds. The package is therefore
neither a runnable app nor an integration of the services it exports.
StreamingService accepts an arbitrary caller-supplied streamUrl and then
implements every player operation as a no-op: load/play/pause/seek/quality,
PiP/background mode, low-latency catch-up, progress, buffer, latency, and retry.
It reports playing, returns successful PiP, reports zero latency, and starts
timers over empty buffer/progress data without invoking react-native-video.
The local ABR algorithm never receives a bandwidth sample because its update
method has no caller. There is no authenticated discovery request, scoped
playback grant, entitlement/age/subscriber enforcement, manifest validation, DRM
license exchange, or server-observed viewer lifecycle. The mature and
subscriber-only fields are descriptive booleans only.
Chat likewise "connects" using only caller-supplied user and stream IDs while
all transport, status, emote, message, vote, and heartbeat methods are stubs.
Tipping returns client-manufactured success, locally subtracts a zero/default
balance, exposes a placeholder payment secret, and confirms payment without a
processor or server. Offline download code fetches a hard-coded example segment
but its file, persistence, storage, background-audio, metadata, manifest, and
subtitle operations are simulated; it can register an in-memory offline item
without writing media or enforcing the declared DRM key/expiry. The VR class
contains standalone geometry and sensor calculations but uses browser globals
(navigator, window, document, WebXR) inside a nominal React Native package
and never binds a video texture or the playback service.
Evidence and risk. There are no unit, integration, component, native, or end-to-end tests; Vitest is configured to pass with zero tests while the Nx and package test commands invoke Jest without a local configuration. No flow proves authorized playback, rendition switching, interruption recovery, latency, offline bytes/DRM, commerce authenticity, chat identity, or VR rendering. As with the broadcaster scaffold, local success states must not become shared contract evidence.
Generic vs tenant-specific. A reusable viewer SDK may acquire a tenant- and session-bound playback grant, pass signed manifest/license data to a real platform player, surface native quality/buffer/latency events, report lifecycle, and fail closed on entitlement or expiry. A separate reusable renderer adapter could consume decoded frames for flat or immersive clients. Aphrodite still owns discovery, adult eligibility and subscription policy, tipping/gifts, chat presentation, downloads policy, and viewer/VR UX; authoritative commerce stays outside a media client.
Reuse verdict: client of substrate. Do not extract this package's simulated state machines into the server substrate. Define the shared playback/session client contract independently, then make an authenticated Aphrodite app consume it through a real native player and policy adapter. Equivalence requires a runnable native shell plus device automation that observes authorized manifests, decoded media, true player telemetry, revocation/expiry, reconnect, and cross- tenant denial. This package currently supplies vocabulary and risk inventory, not reusable implementation proof.
12. apps/aphrodite/notifications#
Role and boundary. This Hono notification application models in-app, FCM push, SendGrid email, and nominal SMS delivery, including preferences, quiet hours, aggregation, deduplication, retry queues, expiry cleanup, and Socket.IO fan-out. Its event taxonomy is Aphrodite product policy: follows, tips, shows, tickets, messages, subscriptions, gifts, creators going live, announcements, system notices, and moderation. It consumes lifecycle/business events after the fact; it is not part of ingest, media processing, playback, or synchronous session signaling.
State and delivery reality. The core has several genuine reusable mechanics.
PostgresNotificationRepository supplies schema-backed notifications,
preferences, and SKIP LOCKED queue claims; FCM and SendGrid adapters call real
provider surfaces through injectable ports; transport failures are retried and
are no longer fabricated as successful sends. Ninety-four tests cover the core
queue, SQL generation/mapping, push batches and invalid tokens, email templates/
signatures/provider errors, app email wiring, and socket handshake identity.
The deployable composition does not use that durable path. createApp always
constructs in-memory notification and push-subscription repositories and offers
no repository injection option. No route registers device subscriptions. The
package start command executes dist/index.js, but src/index.ts is only an
export barrel: it binds no HTTP listener, constructs no Socket.IO server, calls
neither initialization nor shutdown, and never installs the exported WebSocket
handler. There is also no bootstrap that reads database, Firebase, SendGrid,
recipient-directory, CORS, or stable unsubscribe-secret configuration. In the
default graph, push sees zero process-local devices and treats that as a
successful no-op, email has no address resolver/deliverer, SMS has no deliverer,
and every notification/preference/queue entry disappears on restart.
Security and tenancy. Every HTTP create, batch, read, stats, read-all, dismiss, delete, and preference route is unauthenticated and accepts arbitrary user IDs; notification-by-ID responses expose the complete payload. The socket handshake correctly fails closed and derives a user from a signed envelope, but the token has no tenant claim. Its item-level mark-read, dismiss, and delete handlers call ID-only service methods and never check that the notification belongs to the authenticated user. Neither in-memory nor SQL rows carry a tenant key. Provider payload metadata and action URLs therefore cannot safely be accepted from the current public producer boundary.
Generic vs tenant-specific. Durable outbox/queue claiming, provider ports, retry/error accounting, device-subscription storage, and authenticated in-app fan-out are broadly reusable notification infrastructure, but they form a separate asynchronous messaging subsystem rather than a media organ. Notification types, templates, channel selection, quiet-hours semantics, adult-show/tip/ moderation content, recipient resolution, and audience policy belong to the tenant. The streaming substrate should only emit a versioned tenant-tagged session/lifecycle event that an authorized notification adapter may translate.
Reuse verdict: retain tenant control plane. Keep this service outside the
streaming substrate and have Aphrodite consume shared stream.live, ended, or
similar lifecycle events through a narrow, idempotent adapter. Before it can do
so in production, add a real bootstrap, durable repository/subscription
composition, authenticated producer and owner-scoped consumer routes, tenant
keys and cross-tenant denial tests, stable secret/provider configuration,
Socket.IO composition, and durable event/idempotency handling. Provider
mechanics may later move to a general notification platform package, but RB.3
must not couple the media stack to Aphrodite's messaging policy.
13. apps/aphrodite/payment#
Role and boundary. This runnable port-4000 Hono service owns Aphrodite token purchases and balances, tips and creator goals, subscription tiers, payouts, derived transactions/earnings, and signed provider/internal webhooks. These are commerce and entitlement-source domains, not media transport. A stream ID is optional attribution on tips/show transactions; no ingest, playback, manifest, or live-session operation is performed here.
State and implementation reality. Unlike many audited scaffolds, production
routes lazily compose real @aphrodite/database SQL stores. Tip debits, fee
splits, creator credits, and goal updates are transactional; payout request/
cancel and purchase completion/refund move ledger state atomically; subscription
stores enforce tier and lifecycle constraints; provider and internal webhook
paths fail closed when signing secrets are absent. Unmodeled transfer, hold,
refund, billing-history, payout-method, tax, verification, fraud-review, and
report-file surfaces generally return explicit 501 responses rather than
invented records.
Important money flows are still incomplete. Purchase initiation writes a pending
row but does not create a checkout with CCBill, Segpay, Stripe, PayPal, or
return a provider URL. PayPal verification is explicitly a shared-secret HMAC
stop-gap rather than PayPal's server-side verification protocol; CCBill and
Segpay similarly assume local raw-body HMAC conventions. Payout requests only
reserve internal tokens; no payout-provider worker is composed. Most critically,
the subscription route immediately inserts/reactivates an ACTIVE subscription
and increments subscriber counts without debiting tokens, creating a provider
charge/session, or waiting for a verified payment event. Such a row cannot
authorize subscriber-only playback.
Security and tenancy. There is no authentication or authorization middleware
anywhere in the app. The tests' x-user-id header is unused; routes instead
trust path and body IDs. A public caller can spend another viewer's balance by
sending a tip, create or cancel another viewer's subscription, create or mutate
a creator's tiers/goals/tip menu, request or cancel a broadcaster's payout, and
read balances, earnings, subscribers, payout details, and ledgers. Optional
stream IDs on tips are not checked for existence, tenant, entitlement, or
broadcaster ownership. No row or principal includes a tenant dimension, and the
advertised idempotency header is never consumed, so duplicate client money
requests are not protected by an API idempotency key.
Evidence. One hundred six route tests exercise broad behavior, honest model gaps, fee arithmetic, lifecycle guards, webhook signatures/replay tolerance, and memory-store idempotence. Despite the integration filename, the suite injects memory stores for every money domain and mocks database health. It does not execute SQL stores against Postgres, any provider sandbox/contract, payout worker, authenticated owner/capability checks, idempotency races, or cross- tenant denials. The type ratchet is clean, but that is not financial or entitlement equivalence evidence.
Generic vs tenant-specific. The substrate needs only a narrow, tenant-bound entitlement decision/grant input and may emit authenticated session facts for billing adapters. Token economics, adult private/group/spy show purchases, tips, intimate-device triggers, subscription tiers, revenue share, provider choice, payouts, tax/compliance, and dispute policy remain Aphrodite commerce. Even reusable payment-ledger/provider mechanics belong in a separate commerce platform, never in the synchronous media core.
Reuse verdict: retain tenant control plane. Keep this service outside the streaming substrate. After adding verified principals/capabilities, owner- and tenant-scoped SQL, real checkout/payout/provider verification, API idempotency, and database/provider/negative-security tests, Aphrodite may issue a short-lived entitlement assertion through the substrate's configured policy adapter. The substrate must fail closed and independently bind that assertion to tenant, principal, stream, access mode, and expiry; it must not trust today's public subscription rows or client-authored tip/stream associations.
14. apps/aphrodite/realtime-analytics#
Role and boundary. This runnable port-3450 HTTP/WebSocket service tracks live viewer sessions/counts, revenue, chat/tip/reaction engagement, trends, and dashboard snapshots. Viewer session accounting and bounded live operational metrics are close to the shared streaming plane. Revenue, top tippers, subscriber/follower signals, sentiment, and creator engagement are Aphrodite product projections layered on those session facts.
State and integration reality. All viewer sessions, unique-viewer sets,
transactions, creator revenue, engagement windows, trend histories, socket
clients, and IP counts live in singleton process memory. Restart loses every
fact; multiple replicas compute divergent counts. Redis-capable pub/sub exists
as a separate event bus, but the service classes emit only on their own
EventEmitters and never publish into it. Conversely, EventBus.subscribe()
never calls subscribeRedis(), and no composition code does, so the Redis
subscriber joins no channels. The WebSocket forwarders therefore do not receive
HTTP-ingested service events through that bus; only periodic socket snapshots
read the local maps.
The HTTP ingestion routes are the sole source for viewer, transaction, chat,
tip, and reaction facts, and callers supply every identity and classification.
Viewer join trusts isAuthenticated, isSubscriber, tier, country, creator,
stream, viewer, and session ID. Reusing a session ID can overwrite the global
session while leaving a stale entry in the former stream map; heartbeat ignores
the submitted viewer/stream relationship. Revenue has no transaction-ID
deduplication, so retries double-count and a refund finds only the first match.
No route reconciles against an actual stream/session, edge connection, payment,
chat, or durable analytics ledger.
Security and accuracy. HTTP reads and event writes have no authentication, authorization, rate limit, tenant, or resource membership check. WebSocket connections likewise accept a caller-selected client ID and arbitrary stream/ creator subscriptions. The handler casts messages instead of applying the declared subscription schema, so the 100 ms minimum interval is unenforced and an attacker can create extremely tight timers. Revenue and per-creator data are public. Production CORS falls back to wildcard with credentials when the origin allowlist is empty. WebSocket stream snapshots also hard-code a healthy 4.5 Mbps, 30 fps, 1% drop rate, and 2.5-second latency plus zero duration rather than reading a media pipeline; health endpoints label every singleton healthy without probing Redis or an authoritative source.
Evidence. Twenty-five tests cover only engagement sentiment/reaction
classification and provider fallback behavior. There is no automated coverage
for viewer session lifecycle, duplicate/reordered events, revenue/refunds, HTTP
authorization, event-bus/Redis delivery, WebSocket validation/isolation,
multi-node aggregation, restart recovery, or synthetic media-health claims. The
declared @aphrodite/analytics dependency is not composed into durability or
reconciliation.
Generic vs tenant-specific. Authoritative join/leave/heartbeat accounting, tenant/session-tagged operational events, bounded recent windows, distributed aggregation, and scoped live-metric subscriptions are reusable streaming mechanics. Revenue sources, supporter rankings, adult commerce, chat sentiment, creator dashboards, country/tier presentation, and engagement scoring stay in Aphrodite projections. Media health must originate from ingest/packager/player telemetry, not a reporting default.
Reuse verdict: extract organ. Extract the viewer/session and operational telemetry contract, not this public singleton deployment. Require authenticated internal producers, server-issued session IDs, tenant/resource binding, idempotent sequence/event IDs, durable or reconstructable state, a real distributed aggregation design, schema-validated authorized subscriptions, and authoritative pipeline health. Bridge shared events to Aphrodite's revenue and engagement projections outside the organ. Preserve current pure calculations only where new replay, cross-tenant, multi-node, reconnect, and lifecycle equivalence tests prove them.
15. apps/aphrodite/streaming#
Role and boundary. This runnable port-3003 Hono application is named as the
core streaming service, but its implemented production boundary is an Aphrodite
SQL control/read API. It creates and edits streams rows, rotates and validates
ingest keys, applies a stored lifecycle state machine, handles RTMP server
auth/publish callbacks, reads provisioned playback/thumbnail URLs and completed
recordings, and exposes Aphrodite discovery queries. It does not run an RTMP
server, WebRTC SFU, encoder, packager, origin/CDN, recorder, frame capture
worker, or media-observability pipeline. Those route families generally return
explicit 501 gaps; the advertised gRPC and graceful media shutdown paths are
TODOs. The declared @aphrodite/streaming-core dependency is unused.
State and media reality. The production route seams lazily construct real
@aphrodite/database stores. The stream state machine validates the current SQL
row, CSPRNG stream keys replace the earlier accept-any-key scaffold, RTMP auth
joins broadcaster status, catalog queries and completed-recording reads are
real, and readiness probes Postgres while marking Redis, Kafka, MediaSoup, and
transcoding unprobed. Those are useful control-plane mechanics, not evidence of
a media path. start, stop, and publish callbacks only mutate SQL state; no
provisioning or teardown is attempted and no media observation proves a stream
live. HLS, WebRTC, and thumbnail routes merely echo nullable URL columns that
some external system must populate. The fixed ABR ladder has no worker behind
it, while ingest selection, transport negotiation, transcoding jobs, playlist
and token generation, recording/export/DVR, thumbnails, and QoE all fail loud.
The separate /metrics tree is actively misleading: it returns fabricated zero
counters and labels the database, Redis, Kafka, MediaSoup, transcoding, and the
service healthy without probing any of them, contradicting /health/ready and
/health/stats. Stream/viewer statistics otherwise mix stored counters and
view_sessions/chat rows rather than authoritative edge/player sessions.
Security and tenancy. The global middleware recognizes an internal API key
only by setting isInternalCall; no route checks that flag, bearer identity,
role, ownership, or capability. As a result, public callers can create streams
for any broadcaster, read or edit full stream records, change lifecycle state,
rotate or retrieve keys, invoke ingest publish/done callbacks, delete
recordings, read storage/catalog data, and enumerate playback assets. Full
stream records include the plaintext streamKey; SQL stores the key plaintext
and compares it directly. Publish callbacks accept only a caller-supplied stream
ID and are not bound to a successful auth decision or trusted edge. No schema,
context, query, or event contains a tenant key. The process-local rate limiter
keys on a spoofable service/forwarded header and cannot supply either
authorization or distributed protection.
Evidence. Thirty-seven tests cover the memory-store stream state machine, exact-key matching, broadcaster-status gating, catalog and recording reads, stored asset reads, explicit infrastructure gaps, and the honest health routes. Despite the integration filename, the main suite injects memory stores and mocks database health. No test exercises Postgres, authenticated ownership or internal-callback capabilities, secret redaction/storage, tenant isolation, concurrent transitions, a media server callback contract, provisioned media, playback, recording artifacts, or real metrics. The suite also codifies returning the ingest key in ordinary create responses without testing who may receive it.
Generic vs tenant-specific. Tenant-bound ingest grants, authoritative media lifecycle events, publisher/session control, provisioned playback endpoints, rendition and artifact metadata, recorder control, health, and operational telemetry belong in the shared substrate. Aphrodite broadcaster/category/tag/ maturity discovery, catalog ranking, product stream metadata, viewer and tip rollups, completed-content policy, and database projection remain tenant control plane. A shared organ should issue hashed or otherwise safely managed, scoped, revocable ingest credentials and signed playback grants rather than expose this row model.
Reuse verdict: thin tenant adapter. Keep this app as the Aphrodite catalog and policy adapter, but replace its self-declared lifecycle/key/media route behavior with authenticated, tenant-parameterized substrate commands, queries, and events. Do not extract the current route graph or SQL status mutations as a media organ: they are a consumer-side projection with no underlying media implementation. Extraction should instead converge on the adjacent reusable media libraries and a new shared contract, then prove publisher-to-player, revocation, callback authenticity, artifact, telemetry, failure, and cross- tenant equivalence before Aphrodite delegates authority to it.
16. apps/aphrodite/viewer#
Role and boundary. This runnable port-3002 Hono service is Aphrodite's viewer-facing backend-for-frontend. It combines live catalog/search, SQL view sessions and stored playback URLs with chat/DMs, tips, follows/subscription reads, viewer settings, interactive-device commands, private/group shows, viewing history, and notifications. It composes real SQL stores lazily by default and generally returns explicit model/domain gaps instead of fabricating unsupported player, ticket, clip, push-delivery, or account behavior. It is therefore a substantive tenant application, but it neither plays nor delivers media and should not become the shared viewer service wholesale.
Viewing and state reality. join checks that a stream row is live, applies
the Aphrodite sensual-tier opt-in and broadcaster ban, inserts a view_sessions
row, increments denormalized viewer counters, and returns the row's nullable
HLS/WebRTC URLs. leave closes the most recent matching row and updates watch
time. There is no substrate/edge call, signed playback grant, entitlement or
access-mode decision, session lease/heartbeat, URL expiry, license/DRM binding,
media confirmation, or player telemetry. Missing URLs still produce a successful
join. Session insert and counter update are separate queries rather than a
transaction; repeat joins create multiple open sessions, abandoned sessions have
no expiry/reconciliation path, and leave closes only one. The declared chat,
payment, device-protocol, and core package dependencies are unused—the app
directly duplicates database-domain logic instead of composing their
authoritative services.
Identity, authorization, and tenancy. The middleware verifies an HS256
signature only when a local shared secret is configured and puts JWT sub in a
variable named userId. The Aphrodite auth service signs users.id as sub.
Settings correctly selects viewers.user_id, but nearly every other SQL store
uses the same value directly as viewers.id/viewer_id. Production tokens
therefore address the wrong identifier for sessions, chat, tips, follows,
notifications, devices, history, and show participation; memory tests hide the
mismatch by using one interchangeable string. The verifier does not enforce
issuer, audience, role, tenant, or the auth service's process-local revocation
state. No tenant key exists in request context or SQL predicates.
Even after identity mapping is corrected, join does not check viewer status,
ban/age state, subscription or paid-show participation, and chat send does not
require a live stream or active viewing session. Any authenticated viewer can
inspect and command any broadcaster device whose global allow_viewer_control
flag is set; no stream/session or tip grant is required. Tips are at least
atomically debited and split, but lack API idempotency. Show request/join flows
split balance deduction, request/participation insertion, and compensating
refund across independent operations; failures and races can strand or duplicate
funds, and extensions debit without recording the extra entitlement. These are
tenant commerce/control defects, not mechanics to extract into media.
Evidence. One hundred thirty-one tests cover broad route behavior, memory store lifecycle and policy calculations, owner-scoped reads, model gaps, and database-health branching. No test instantiates a SQL store or Postgres, and the integration suite injects a token verifier plus memory stores. It does not test the real auth-token-to-viewer-row mapping, revocation/issuer/audience, tenant isolation, transactional session races, abandoned-session reconciliation, entitlement or grant expiry, signed manifests, media playback, viewer QoE, database commerce atomicity, or a device bridge. The breadth is useful product regression evidence but not publisher-to-viewer equivalence.
Generic vs tenant-specific. Authenticated tenant/principal resolution, entitlement evaluation, short-lived playback grants, server-issued leased view sessions, authoritative join/leave/reconnect events, playback endpoint and rendition metadata, and scoped viewer telemetry are reusable substrate contracts. Aphrodite's discovery ranking, sensual-tier preference, broadcaster bans, chat/DM presentation, token/tip/show economics, follows, notifications, device-control policy, schedules/VOD catalog, profiles, and history projections remain tenant control plane. Shared chat/session organs can expose narrow ports; they must not inherit this database schema or commerce coupling.
Reuse verdict: thin tenant adapter. Retain this deployable as Aphrodite's
authenticated viewer API and policy composer. Replace direct playback URL and
session authority with a tenant-bound substrate join/heartbeat/leave flow after
resolving users.id to the tenant's viewer principal and obtaining a real
entitlement decision. Project authoritative substrate events back into Aphrodite
history, discovery, notifications, and commerce. Do not extract its combined
route graph: only the generic viewer-session/grant contract belongs in the
shared stack, proven with SQL identity, duplicate/reconnect, expiry/ revocation,
cross-tenant denial, real player, and failure-path tests.
17. apps/aphrodite/vr#
Role and boundary. This runnable port-3008 Hono/Socket.IO service presents VR capture configuration, projection/stereo/spatial-audio metadata, headset capabilities, playback-session state, head tracking, interactions, settings, and adaptive-quality calculations. Its domain vocabulary is largely generic immersive media, making it the most direct candidate for a shared VR organ. The current implementation, however, is a control-plane simulation: it never opens a camera, stitches frames, encodes video/audio, publishes ingest, provisions a VR rendition, obtains a manifest, decodes/renders media, or applies tracking to viewport/foveated delivery.
State and media reality. Capture initializes a metadata record in process
memory, optionally mirrors JSON to an injected Redis port, installs a spatial-
audio configuration object, and accepts caller-authored encoder statistics. Its
audio module performs vector/source calculations but no audio processing.
Playback similarly creates memory sessions for any supplied stream ID, stores
client tracking/interactions/metrics, and changes a string quality preset; no
stream existence, grant, asset, rendition, player, or edge is consulted. Manual
WebSocket quality selection merely echoes quality:changed without changing
session state. Session statistics hard-code 90% active viewing, zero pauses and
quality switches, and 60 fps. The HTTP preset routes return empty lists despite
an in-package preset catalog.
Redis and database dependencies are listed but production constructs both
services with only a logger, so every stream, session, setting, interaction,
tracking sample, and metric is process-local and lost on restart. Even if Redis
were injected, per-stream session indexes and several local histories are not
reconstructed consistently across replicas. Local EventEmitter events have no
durable bus. Readiness is unconditionally true; detailed health labels service
objects healthy without probing their functionality.
Security and tenancy. Every HTTP capture/playback route is public. A caller
can create, enumerate, mutate, or stop another claimed user's stream; read or
overwrite any user's settings; start, inspect, pause, alter, or end arbitrary
sessions; retrieve head tracking/device capabilities; and inject metrics,
interactions, or capture statistics. This includes sensitive IPD, headset,
tracking, optional location, and device data. Stream and user IDs are entirely
client asserted, and there is no entitlement, ownership, resource membership,
rate limit, or tenant dimension. Production HTTP and WebSocket CORS default to
* while HTTP credentials are enabled, and the global error handler returns raw
exception messages.
The Socket.IO boundary is better: its short-lived HMAC envelope now fails closed
and derives userId from the signature instead of session:start. However, the
shared envelope has no tenant, audience, issuer, or resource grant; roles are
ignored here. Any signed user can start a session for an arbitrary or
nonexistent stream. Socket event payloads bypass the HTTP Zod schemas and lack
runtime validation/rate bounds, so tracking batches and metrics are trusted.
Evidence. Four tests cover only token round-trip/failure, rejection without a valid verifier, signed-user selection, and missing-secret fail-closed behavior using fake Socket.IO/services. There are no tests for capture/playback services, HTTP routes, Redis behavior, multi-node/restart recovery, projection/audio or quality correctness, authorization/ownership/tenancy, payload abuse, health, actual encoding, an immersive manifest, decoded frames, head-tracked rendering, comfort/latency, or hardware/WebXR. The Vitest comment still says no tests exist and permits that condition, underscoring the absence of media equivalence.
Generic vs tenant-specific. VR projection/stereo/spatial-audio descriptors, validated rendition capabilities, headset capability normalization, safe quality recommendations, viewport/tracking telemetry schemas, and immersive asset/ session negotiation are reusable substrate concerns. Preset tables and pure math can seed that organ after standards/hardware validation. Aphrodite still owns adult eligibility and entitlement, content metadata/location disclosure, viewer privacy/consent, settings presentation, interaction semantics, discovery, and product analytics. Headset detection, comfort settings, and rendering logic primarily belong in shared client SDK adapters, not a server pretending to play media.
Reuse verdict: extract organ. Extract the generic immersive media contract and independently verified pure capability/projection/quality logic, not this public memory deployment. Fold VR descriptors and rendition negotiation into the one shared ingest-to-playback substrate; require tenant-bound publisher and viewer grants, real capture/encoder/packager/player adapters, authoritative telemetry, bounded schema-validated tracking, durable/distributed session semantics, privacy controls, and honest health. Keep a thin Aphrodite adapter for policy and metadata. Equivalence must observe real 180°/360° stereo and spatial-audio playback on supported hardware or a credible automated harness, including reconnect, downgrade, revocation, failure, and cross-tenant denial.
Increment 7j implementation update (2026-07-19). The insecure deployment
described above is no longer mounted: apps/aphrodite/vr now serves only an
explicit 410, no-store retirement gateway with default-deny CORS and honest
retired health. Its old exports remain temporarily source-compatible but its
entry point constructs no simulated capture, playback, tracking, or Socket.IO
authority. The reusable implementation moved into the canonical substrate:
@oshun/live-media/browser now renders protected equirectangular 180°/360°
mono/SBS/top-bottom video through WebGL in bounded flat/cardboard modes, uses
pointer/keyboard/device-orientation input, and measures Web Audio plus non-black
pixel and changed-view evidence. Aphrodite Viewer composes that client with the
durable aphrodite.immersive.v1 adapter over migration 00020 and the exact
succeeded browser-player/viewer/publication binding. Real FFmpeg/Chromium HLS
and DASH automation covers 360° device orientation, 180° pointer orientation,
two distinct non-black eye buffers on paused source frames, stereo audio, axe,
mobile/reduced motion, privacy, and ordered teardown. The real PostgreSQL gate
covers restart replay, expired-lease recovery, stale-worker fencing, RLS tenant
denial, revocation-driven release, and durable credential/raw-tracking
non-disclosure. This supersedes the earlier evidence paragraph for the deployed
VR app, but it does not claim camera/stitching, cubemap/EAC, ambisonics, WebXR,
OpenXR, visionOS, comfort certification, or physical headset validation.
Adjacent-library scope and method#
libs/aphrodite contains 192 top-level package directories. Reading all 192 as
if they were media infrastructure would obscure the extraction boundary with
payments, identity, games, ritual, compliance, production planning, rendering,
and product UI. The adjacent pass therefore included each package that owns or
claims one of the following responsibilities: ingest/publisher capture,
composition, encoding or recording, media delivery, viewer sessions, live chat,
presence, notification/telemetry hooks, media storage, content protection, or
immersive-media capture/playback. That rule selected the 36 packages below.
The pass read package/build manifests, public exports, implementation files, production defaults, external-I/O use, and tests. A package with many tests or media-shaped types was not treated as a working organ unless its runtime actually moves media or durable authoritative state. Conversely, genuine browser processing and low-level codec/container code are recorded as reusable client or execution kernels even when they do not belong in a server control plane.
The remaining 156 directories are out of the initial synchronous substrate by responsibility, not silently unaudited by name. Examples include:
- tenant control planes and policy:
age-verification,compliance*,consent-engine,content-takedown,database,payment*,ppv,revenue-sharing, andsafety*; - production and presentation:
production,audience-experience,immersive-theater,virtual-rooms,auteur-camera,cinematic-camera,performer-camera, scene packages, and avatar/VFX packages; - post-live/VOD products:
archiveandvod-chaptering; and - peripherals and tenant experiences:
device-*,haptics*,vr-haptics, games, gifts, tips, and venue packages.
Those packages may consume versioned live-media events or client frame APIs. They do not get authority over ingest, playback grants, viewer leases, media objects, or core session state merely because they react to a live stream.
Adjacent library extraction map#
| Package | Runtime reality | Extraction decision |
|---|---|---|
analytics |
Repository-port event/viewer/performance services; concrete persistence is external and product/revenue schemas are mixed in. | Seed the minimal tenant-tagged live telemetry contract and batching behavior; keep creator/revenue projections in Aphrodite. |
analytics-warehouse |
Real Postgres analytics_events append/query adapter, but the schema and every aggregate lack a tenant dimension. |
Migrate behind a tenant-required telemetry store with isolation tests; do not reuse the current schema unchanged. |
cache |
Real wrapper over @oshun/cache, but keys/channels use a fixed aphrodite namespace. Presence joins overcount repeats, mutations are non-atomic, and presence TTL differs from count TTL. |
Depend on existing shared cache through atomic, tenant-scoped lease/presence ports; do not extract this wrapper. |
chat |
Types/Zod/version facade; room, message, WebSocket, and moderation files explicitly defer implementation to service migration. | Reject as a second chat stack. Migrate the deployable chat service and useful chat-core behavior into one implementation. |
chat-core |
Feature-rich message/room/DM/moderation/presence engines entirely backed by Map/EventEmitter; no transport, durability, or tenant. |
Behavior/contract seed only. Fix fail-open subscription/follower checks and add durable tenant adapters before authority moves. |
chat-entertainment |
Process-local trivia, story, voting, and minigame engines with timers and random variation; no chat transport or persistence. | Keep as an optional Aphrodite product consumer of shared chat events. |
chat-moderation |
Real third-party toxicity provider calls plus process-local rules/dashboard state; the moderator and provider error paths allow messages. | Optional tenant policy hook/provider adapter after durable audit semantics; never the synchronous shared fail-open default. |
cloud-recording |
Recording, encoding, segment, upload, checksum, and completion behavior is fabricated with timers and generated metadata; no encoder or object store. | Retain vocabulary/FFmpeg argument ideas only; build recording from real pipeline/storage adapters. |
drm |
Useful CSPRNG/HKDF/key-wrap/PSSH/CKC-shaped primitives and injectable stores, but defaults are in-memory and unscoped. Widevine returns base64 JSON and PlayReady uses simplified XML rather than vendor/CDM-compatible signed licenses. | Optional hardened content-protection adapter with KMS/HSM, tenant isolation, vendor SDK/proxy, durable sessions, and conformance fixtures; not core delivery evidence. |
e2e-encryption |
Real AES-GCM/CTR frame and segment transforms, key derivation, rotation, and insertable-stream helpers. Raw keys, sessions, and timers live in process memory; there is no tenant, durable key custody, authenticated distributor, or player/packager integration. | Reuse reviewed crypto primitives behind a tenant/session key service; do not extract the current stateful service or claim DRM/SRTP interoperability from helper strings. |
event-publisher |
Real wrapper over shared Redis event bus, but Aphrodite's event ID/timestamp/user/session envelope is discarded and reconstructed with different identity on subscribe; no tenant or outbox. | Use @oshun/event-bus directly with a versioned tenant/resource envelope; keep Aphrodite taxonomy mapping in its adapter. |
eye-tracking |
Client-side gaze acquisition/normalization/foveation analytics with injectable WebGazer/WebXR/native/simulated backends; simulation is opt-in. It owns no media/session transport. | Optional privacy-bounded immersive client adapter and telemetry producer, not a server organ. |
gaussian-splatting |
Pure/in-memory Gaussian data, math, optimization, and rendering-oriented structures; no capture source, transport, storage, or tenant boundary. | Specialized immersive execution kernel only; compose after the base live path works. |
highlight-clipping |
Clip encoding, CDN URLs, thumbnails, sizes, and signal collection are simulated; Bitly/custom shortener HTTP adapters are real. | Keep domain types/detection heuristics as optional post-live inputs; build clips through real recording/encoding/storage. |
multi-performer |
Extensive performance/scene/quality/spatial/presence math and state, but no peer connection, SFU/MCU, TURN traffic, socket, persistence, or media transport. | Reuse selected pure formulas only; do not treat it as conferencing or presence infrastructure. |
multi-source |
Real browser camera/screen/canvas capture, Web Audio mixing, layouts, transitions, and auto-switching. Declared recording/RTMP/WebRTC outputs are unused, and the OffscreenCanvas branch does not copy its rendered frames to the captured transfer canvas. | Candidate shared broadcaster/composition client SDK after output wiring and browser E2E tests; not server ingest. |
neural-rendering |
In-memory image/rendering math and enhancement/artistic pipelines; no model runtime, media transport, storage, or tenant. | Optional client/GPU execution library outside the initial substrate. |
notification-intelligence |
Timing/content/channel/learning calculators backed by local arrays, maps, timers, and random exploration; no push/email/SMS/browser delivery or queue. | Expose a notification hook/event from the substrate; retain this Aphrodite decision engine outside it. |
performer-compositor |
Layout, transitions, feed metadata, adaptive rules, and pipeline timing are real calculations, but output explicitly contains descriptors rather than composite pixels. | Pure behavior seed for a broadcaster SDK; no claim of a working compositor until frames are rendered and published. |
performer-presence |
Constellation/avatar/minimap/particle/PiP presentation and math; no WebSocket, Redis, session lease, or server presence. | Keep in tenant clients; it is not the viewer-count organ. |
platform-analytics |
In-memory formula engines for venue, audience, performer, revenue, culture, prediction, reporting, and dashboards; no authoritative store/transport/tenant. | Keep tenant projections outside synchronous telemetry. |
recording-prevention |
Browser API hooks and video-element deterrents are heuristic client code. DMCA requests are process-local, and the configured API submission method emits an event without making an HTTP call. | Optional tenant client/policy layer only; never an authorization, DRM, or server media guarantee. |
remote-guest |
Real browser WebSocket signaling client, RTCPeerConnection, ICE/data channels, capture, Web Audio mixing, layouts, and stats. There is no signaling/SFU service, tenant, or message-schema enforcement; token is placed in the socket query and reconnect timer is unmanaged. Its copied declaration file hides most runtime classes. |
Strong client SDK input after protocol validation, credential transport, cleanup, and a real tenant-aware signaling service. |
spatial-audio |
Real browser Web Audio graph, audio fetch/decode, HRTF/SOFA parsing/convolution, room math, and process-local voice-zone routing. It has no voice transport/session service; the copied declaration surface exposes only a subset of runtime APIs. | Optional shared immersive client renderer after public API repair; voice transport and authorization remain separate substrate ports. |
storage |
Wrapper over existing @oshun/storage S3/MinIO signing/multipart APIs. Aphrodite metadata/events are process-local, paths encode product policy, direct-upload confirmation trusts caller metadata, and lifecycle tier changes do not change S3 storage class. |
Use existing shared storage behind a tenant/resource media-object port; keep Aphrodite path/visibility policy in its adapter. |
stream-content-analysis |
Real OpenAI-compatible, Google Vision, AWS Rekognition, Azure, and custom analyzers over supplied image buffers; no frame sampler, media pipeline, tenant, or durable audit state. | Optional asynchronous tenant moderation hook after ingest; not part of the lossless media path. |
stream-upscaling |
Real browser WebGL shaders and quality math. The AI catalog is metadata only, no model loads/inference or server call occurs, and bandwidth/loss/RTT are simulated without samples. Copied declarations hide the runtime manager API. | Optional client enhancement after API repair and visual/browser tests; not a transcode organ. |
stream-watermarking |
Real DCT/audio/frame transforms and crypto-backed payload helpers with process-local sessions. Video PSNR compares the already-mutated frame with the same output buffer, so reported quality is not an oracle; there is no encoder/container integration, tenant, key custody, or durability. | Optional reviewed pipeline transform after robustness/quality fixtures and tenant key management; not initial ingest/delivery. |
streaming-core |
HLS/LL-HLS playlist/DVR text and state, RTMP key/URL/auth/FFmpeg-argument helpers, WebRTC SDP/stat helpers, and a process-local stream manager. It has no RTMP listener, FFmpeg process lifecycle, segment writer/store, packager, peer/SFU, or multi-node state; its only tests target the stream manager. | Primary Aphrodite contract/helper seed, but pair it with real execution adapters and remove product policy from shared types. |
thumbnail-generation |
Real OpenAI moderation provider; image/frame selection, processing, composition, cache, and quality behavior are largely heuristic/in-memory without Sharp/FFmpeg. | Optional post-frame hook; do not place in core delivery. |
video-effects |
Real browser canvas/WebGL effects and captureStream output; face/background detection is local heuristic code and there is no publisher or tenant/session connection. |
Candidate broadcaster client transform after visual and browser media-stream E2E coverage. |
viewer-avatars |
Process-local avatar, seating, LOD, crowd, appearance, and emote simulation with an update loop; no session/presence transport. | Tenant presentation client only. |
viewer-interactions |
Process-local VR/social/proximity/follow/block/group activity state; no authoritative transport, storage, identity, or tenant. | Tenant product client only. |
volumetric-capture |
Large pure/in-memory 3DGS, renderer, container/compression, multi-camera, mocap, and editing toolset. Its headline single-/multi-camera pipelines simulate depth, segmentation, face/body inference and network delivery; the streaming format genuinely serializes/chunks/reconstructs supplied Gaussian frames but opens no transport. | Reuse tested codecs/container/math as an optional immersive modality; real sensors/models/transport and tenant grants must be adapters to the common substrate. |
vr-core |
Useful validated descriptors, tracking/controller/audio math, device tables, and ABR calculations. Playback and capture managers only mutate maps and complete via simulation timers; no WebXR/player/camera/encoder/transport. | Extract pure immersive contracts/client utilities, not the simulated managers. |
vr-quest |
Quest/WebXR hand/controller/haptic facade; support detection is real but session start comments out navigator.xr.requestSession. |
Optional Quest client adapter after a real WebXR session/render loop and playback integration. |
Increment 7k implementation update (2026-07-19). The remote-guest row
above records the pre-extraction audit and is now superseded at its production
boundary. The unsafe token-in-query, tenantless, schema-free networking runtime
has been removed from @aphrodite/remote-guest; that package is now a small
compatibility facade over the canonical shared contracts/client plus its pure
legacy layout calculations. Its generated declaration comes from the real source
graph, and no copied declaration or alternate signaling authority remains.
@oshun/live-media now owns strict remote-guest registration, provision,
signaling, operation, evidence, and release contracts. Its clean
@oshun/live-media/browser/remote-guest entry supplies a real
one-host/one-guest RTCPeerConnection runtime and a restrained full-bleed
studio surface. One-use invitation and signaling capabilities never enter URLs;
the ticket travels in Sec-WebSocket-Protocol, the exact same-operation path is
enforced, and all bounded signaling messages are role/schema/sequence checked.
SDP and ICE remain transient. Readiness requires both browsers to submit
positive reciprocal RTP evidence, with the guest outbound and host inbound video
flow linked by a SHA-256 of the negotiated SSRC.
Aphrodite Broadcaster is the tenant-fixed HTTP and WebSocket composition. Host
authority derives from the existing authenticated stream-owner boundary; the
guest receives only a scoped Guest lease. Migration
00021_live_media_remote_guests and aphrodite.remote-guest.v1 provide one
active operation per exact publisher grant/stream, forced RLS, digest-only
secret custody, atomic one-use exchange/consumption, database-clock invitation
and lifecycle expiry, semantic idempotency, reclaimable execution leases,
restart replay, stale-writer fencing, and repeat-safe release. Durable rows
exclude raw secrets, SDP, ICE, addresses, codec strings, device labels, and
captured media.
Single-worker Chromium automation proves actual reciprocal audio/video between two independent browser contexts, the matching SSRC link, third-participant rejection, URL/DOM/durable credential non-disclosure, invite-fragment scrubbing, explicit mic/camera/leave controls, axe, keyboard behavior, mobile fit, reduced-motion elimination, proof visibility, and ordered teardown. The real PostgreSQL/MediaMTX gate proves migration, secret rotation and one-use replay denial, durable signal/secret absence, restart replay, RLS isolation, database-clock expiry, abandoned-lease recovery, stale-fence rejection, idempotent release, and cleanup. This is a bounded direct browser peer path; it does not claim SFU/MCU, TURN availability, multi-party rooms, screen share, end-to-end media encryption, native/mobile clients, or multi-node signaling.
Increment 7l implementation update (2026-07-20). The multi-source and
performer-compositor rows above remain accurate pre-extraction audits, but
their missing bounded production path no longer applies to the canonical
substrate. @oshun/live-media/browser now renders one to four caller-owned live
sources through Canvas 2D, mixes optional audio through Web Audio, captures the
derived stream, and publishes it with the already-proven WHIP client. It owns
strict single, grid, and two-source picture-in-picture layouts, bounded output
profiles and evidence, an accessible full-stage surface, and teardown that does
not stop caller-owned tracks. Aphrodite supplies only authenticated no-store
control routes and the forced-RLS aphrodite.composition.v1 lifecycle. Success
is joined to the exact succeeded browser/WebRTC publisher and independently
observed positive MediaMTX ingress. Chromium and PostgreSQL/MediaMTX gates prove
real changing pixels, audio, RTP, durable replay/recovery/fencing, tenant
isolation, privacy, and cleanup. The legacy packages were not promoted as
alternate authorities, and custom/transition/GPU/native/distributed composition
remains outside this bounded claim.
Existing shared stacks and canonical home#
The remote branch already contains libs/shared/streaming, published internally
as @oshun/streaming. It is a Kafka/schema-registry/exactly-once
event-streaming library used for data/training pipelines, backpressure, temporal
correlation, and latency tiers. Renaming its semantics or mixing media session
authority into its topics would create an ambiguous package and risk unrelated
consumers. It remains a dependency where Kafka event streaming is appropriate;
it is not the live-media substrate named by RB.3.
The repo also has active libs/neith/stream-* packages. These are not merely
names: stream-encoder runs FFmpeg reference encoders and probes hardware
backends, while stream-transport has live WebRTC RTP/DataChannel, SRT, QUIC,
multi-path QUIC, RIST, TLS fallback, and traversal code with loopback tests.
Other Neith packages cover game-stream input, QoE, security, client, and GPU/
title session orchestration. They are valuable execution kernels, but their
contracts are cloud-game/domain-shaped and do not provide the tenant-scoped
RTMP/SRT-to-HLS/DASH live-broadcast control plane, durable viewer leases, chat,
presence, or delivery grants required here.
Canonical decision: create the consolidation boundary at
libs/shared/live-media, package @oshun/live-media. This avoids collision
with Kafka @oshun/streaming and makes the media meaning explicit. It owns the
tenant-neutral contracts and orchestration exactly once, and depends on—not
copies—@oshun/cache, @oshun/storage, @oshun/event-bus, selected Neith
encoder/transport kernels, and provider adapters. Aphrodite, Veritas, V3 Stage,
and the Rail may only enter through tenant adapters. No implementation belongs
under apps/v10 or libs/v10.
Target substrate boundary#
Every durable resource, cache key, event, credential, request context, metric,
and log correlation must carry a non-optional tenantId plus the relevant
substrate resource ID. A caller-supplied product user/creator/stream ID is an
external reference, not global identity. The shared boundary should be divided
into the following independently replaceable organs:
- Contracts and authorization: verified principal/capability input, tenant/resource IDs, lifecycle state machine, typed errors, idempotency, versioned events, and cross-tenant denial before any provider call.
- Ingest control and edge: short-lived hashed publisher grants, effective rotation/revocation, RTMP/SRT/WebRTC adapters, authoritative connect/ disconnect health, and reconciliation with the control plane.
- Media pipeline and delivery: real encoder/transcoder execution, rendition/manifest packaging, media-object persistence, origin/CDN publication, signed playback grants, teardown, and honest readiness.
- Viewer sessions and presence: entitlement-decision input, expiring playback grants, idempotent leased join/heartbeat/leave, multi-node atomic counts, reconnect semantics, and QoE reporting.
- Live chat: tenant/resource rooms, schema-validated socket messages, durable history, moderation and entitlement ports, idempotency/rate limits, and distributed presence without Aphrodite product roles.
- Hooks and telemetry: notification, audit, moderation, operational metric, and event ports. Provider failure policy is explicit; hooks cannot silently turn media or authorization failures into success.
- Client and optional media adapters: browser/native publisher and player, remote guest/composition, DRM/encryption/watermarking, content analysis, and immersive descriptors/renderers. These extend the same grant/session model; they do not create alternate stacks.
The substrate deliberately does not own Aphrodite identity issuance, age or adult policy, payments/tips/shows, creator discovery, intimate devices, moderation case management, notification copy, dashboards, avatar/social presentation, or VR privacy preferences. Tenant adapters make those decisions and pass narrow authenticated results to the shared organs.
Incremental extraction and equivalence order#
- Establish
@oshun/live-mediacontracts, tenant/resource ID types, dependency direction checks, and negative cross-tenant contract tests. - Extract ingest credential/lifecycle behavior from the broadcaster and streaming services. Compose a real edge and Neith/FFmpeg execution adapter; prove key rotation/revocation and authoritative connect/disconnect.
- Add rendition packaging, shared storage/CDN delivery, signed playback grants, and a deterministic local test stream. No simulated URL is accepted as evidence.
- Move the viewer app to leased join/heartbeat/leave and reconcile counts through an atomic shared cache/durable ledger. Preserve Aphrodite policy in its adapter and test duplicate joins, crashes, expiry, and reconnect.
- Move chat room/message/presence mechanics behind the same tenant/resource identity, retaining the existing deployable service as the Aphrodite adapter and behavior oracle.
- Introduce tenant-tagged operational telemetry and notification/moderation hooks, migrating the warehouse schema before production reads or writes.
- Add immersive, encryption/DRM, watermarking, content-analysis, recording, and client composition adapters only after the flat-video path passes.
- Connect Veritas and V3 Stage as tenants #2/#3, then make the Rail's
first-party-liveclass consume real HLS/DASH as tenant #4. Add the consolidation guard and run one supervised ingest-to-Rail E2E at a time.
For each move, the current Aphrodite route/store tests remain the product behavior oracle, while new substrate tests prove the generic contract. Required new evidence includes SQL identity mapping, tenant isolation, idempotency, multi-node/restart behavior, credential expiry/revocation, provider failures, real encoded bytes/manifests, decoded player media, QoE/lifecycle telemetry, and teardown. Hash-derived dashboards, memory-only success, generated URLs, timer-completed state, or helper argument arrays are explicitly insufficient.
Extraction progress (through 2026-07-22)#
- Increment 1 is implemented at
@oshun/live-media: tenant/resource contracts, capability authorization, lifecycle semantics, dependency-direction checks, publisher-grant service/store ports, and negative cross-tenant tests. - The credential half of increment 2 is implemented. Aphrodite has a durable
RLS-protected, digest-only grant adapter and a tenant-fixed control facade;
broadcaster and streaming stores issue, rotate, revoke, and authenticate the
same shared grants while preserving their HTTP response shapes. The legacy
streams.stream_keycolumn contains only a constrainedgrant-managed:<stream UUID>compatibility sentinel. - MediaMTX external auth now binds a grant to the exact stream path, and connect/disconnect callbacks require a separately configured shared secret before changing lifecycle state. Route-equivalence, ownership-isolation, SQL-boundary, migration, and real PostgreSQL checks cover this increment.
- The publisher-edge half of increment 2 is implemented. The shared substrate now owns tenant-scoped publisher observations, exact connection identity, idempotent refresh/replacement/disconnect semantics, provider-error types, and authoritative reconciliation. Aphrodite persists the current publisher in an RLS-protected table and rejects stale disconnects after replacement.
- The MediaMTX provider consumes the paginated v3 Control API, supports current and legacy readiness/byte fields, and maps RTMP, SRT, WebRTC, and RTSP publisher sources without admitting unmanaged paths. The streaming service reconciles immediately and periodically without overlapping polls; failed snapshots are retried and never treated as empty state.
- A gated local E2E runs a digest-pinned MediaMTX 1.19.2 container and a real FFmpeg SRT publisher. It proves forged-grant rejection, exact-stream auth, nonzero encoded-byte observation, HLS generation and decoded H.264 probing, durable control-plane restart behavior, and missed-disconnect reconciliation.
- The encoder half of increment 2 is implemented without adding an app-owned
media stack.
@oshun/live-mediaowns a tenant/resource-scoped execution contract that authorizeslive-media:stream:operatebefore invoking a provider. The server-only Neith provider accepts only credential-free allow-listed inputs and exact<root>/<tenant>/<stream>/<execution>.tsoutputs, rejects canonical path escapes, symlink aliases, and pre-existing output, atomically reserves the execution path, removes partial media on failure/cancellation, spawns a shell-free runner argument vector, bounds process diagnostics, and exposes idempotent TERM/KILL cancellation. Success is accepted only after the output is a nonempty file and ffprobe measures the requested H.264/AAC codecs and dimensions. neith-stream-transcoderis a compiled Rust runner in the existing Neith encoder crate. Its validated plan executes FFmpeg with bounded dimensions, frame rate, bitrates, and duration; low-latency H.264 High/AAC MPEG-TS; deterministic two-second GOP/CFR settings; and TCP media transport for RTSP. On Unix it replaces itself with FFmpeg so worker signals govern the real encoder rather than an orphan wrapper. Aphrodite supplies only a tenant-fixed internal worker facade.- The same gated E2E now reads the live MediaMTX stream over RTSP through that compiled Neith runner, produces a 640x360 rendition, and independently proves nonzero duration/bytes plus decoded H.264/AAC output. Contract/provider tests cover cross-tenant denial before execution, unsafe protocol and path denial, process failure, mismatched output, and idempotent cancellation.
- Increment 2 is complete. Its real execution adapter feeds the durable job and publication composition completed in increment 3; no route fabricates worker or media state.
- Increment 3's publication/delivery foundation is implemented in the same
shared organ. Tenant-authorized publication contracts reserve immutable object
prefixes and persist exact source measurements, rendition identity, lifecycle
revision, failure state, and the verified object ledger. Aphrodite's
PostgreSQL adapter uses a per-publication advisory lock and forced RLS for
publishing/ready/failed/revoked transitions; its facade fixes the
aphroditesubstrate tenant and never accepts a caller-selected namespace. - The server implementation packages real Neith output into HLS MPEG-TS and DASH fragmented MP4, probes H.264/AAC and dimensions through both manifests, publishes segments before manifests to create-only local or official AWS S3/MinIO storage, and verifies stored checksums. HMAC-SHA256 bearer grants bind one entitlement decision to one publication prefix and exact object ledger; every origin authorization re-reads durable ready state, making revocation immediate across service restarts.
- Durable transcode/publication orchestration is now part of the same shared
organ.
MediaPipelineJobhas bounded validated requests, idempotent enqueue, cancellation, retry/backoff, expiring database-clock leases, renewal, and fencing. Its Aphrodite SQL store usesFOR UPDATE SKIP LOCKED, forced RLS, tenant/stream-scoped identities, and a composite resource foreign key from a successful job to its immutable publication. The shared worker and attempt executor connect the real Neith transcode, HLS/DASH packager, object publisher, and publication state machine without app-owned encoding logic. - Aphrodite streaming now composes that store, control facade, and supervised
scheduler only under explicit complete production configuration. Exact
INTERNAL_API_KEYauthentication protects real enqueue/list/read/cancel routes; disabled or invalid runtime configuration returns an explicit 503. Restart, expired-lease recovery, retry, cancellation, concurrent claim, and stale-worker fencing are covered at the shared, SQL-adapter, route, and real PostgreSQL boundaries. - Aphrodite viewer now maps the authenticated JWT
subthroughviewers.user_id, evaluates account, age, sensual-tier, block, subscription/private-show, stream-state, and ready-publication policy in a read-only repeatable-read SQL transaction, then issues a short-lived grant. The route accepts no caller-selected tenant, publication, object prefix, entitlement decision, or key. Auth access tokens carry and verify fixed issuer/audience claims; the remaining process-local JTI revocation limitation is documented rather than presented as distributed security. - Streaming exposes a production authorization-subrequest endpoint for an external private-bucket origin proxy. It verifies the exact requested object against the signed ledger and re-reads durable publication and viewer-lease state on every request, so revocation, expiry, reconnect fencing, and leave remain immediate across process restarts. It does not pretend to serve S3/CDN bytes; deployment must keep the bucket private and enforce the returned authorization decision at the proxy.
- Increment 4's viewer-session/presence organ is implemented in the shared package. Its tenant-scoped service owns entitlement-bounded idempotent join, rotating digest-only lease credentials, heartbeat, explicit leave, crash expiry, reconnect fencing, exact active-session/unique-viewer presence, and immutable bounded QoE samples. The playback-grant format now binds the viewer session and refuses both issuance and origin authorization without an active lease.
- Aphrodite's forced-RLS PostgreSQL adapter uses database time, per-resource
advisory serialization, exact token-digest checks, durable lifecycle/QoE
ledgers, lazy expiry, and SQL-derived multi-node counts. Viewer identity and
entitlement stay in the existing policy adapter; the Viewer app is a thin
composition over canonical leased playback, heartbeat, leave, and presence
routes. Its legacy direct playback-URL/counter mutation routes return
410and no longer form a competing authority. - The supervised local E2E runs digest-pinned MediaMTX 1.19.2 and PostgreSQL 16
containers plus real FFmpeg/ffprobe. It applies canonical migrations
00005–00010in sequence against the existing text stream IDs; proves forged publisher denial, exact-stream auth, live encoded bytes, durable job idempotency, concurrent claiming, process reconstruction, expired-lease recovery, stale-worker fencing, retry-safe publication, forced-RLS isolation, SQL age-policy denial/allowance, idempotent session refresh, two-store presence aggregation, exact QoE persistence, lifecycle ordering, crash expiry, reconnect token fencing, and leave; then it decodes protected H.264/AAC through both HLS and DASH before proving object denial after viewer-session invalidation and durable publication revocation, followed by publisher teardown. MediaMTX is configured entirely through environment variables from an empty working directory, so this gate does not consume a host configuration-file watcher. - Increment 4's release evidence includes green shared (106), Aphrodite adapter (59), database/migration (207), Viewer (177), and Streaming (73) test suites; direct library/app/spec typechecks; targeted lint; both application builds; Prisma schema validation; and the separately enabled real edge E2E (1). The known Vite warnings are missing source maps for pre-existing generated shared database JavaScript and do not represent test failures.
- Increment 4 is complete at the code and local release-gate boundary.
- Increment 5's live-chat organ is implemented in
@oshun/live-media. The tenant/resource-scoped contract owns durable memberships, leased presence, bounded history, idempotent sends, rate limits, room clears, and ordered join/leave/message/delete/clear events. Client messages are text-only; validated attributed tips and system notices are server-only capabilities. - Aphrodite's forced-RLS PostgreSQL adapter binds every join, heartbeat, send, and history read to the exact allowed entitlement, subject, viewer session, resource, and database-clock validity window. Composite membership/sender foreign keys and message-shape checks independently reject forged senders, client-shaped tips, invalid amounts, and attributed text. Per-resource advisory serialization makes message sequence allocation, clears, and event commits deterministic across nodes.
- The existing Chat deployable remains the thin Aphrodite tenant composition. REST and Socket.IO share canonical UUID identity, entitlement policy, viewer-session admission, durable history, sanctions, content filters, and moderation revocation. Socket membership is joined only after the durable lease succeeds; cross-node PostgreSQL polling fans committed events out in order, while expiry, explicit leave, bans, and entitlement revocation evict the same canonical identity.
- The digest-pinned PostgreSQL 16 gate applies migrations through
00011, exercises forced-RLS tenant isolation, restart/reconstruction, two-store fanout and presence, reconnect fencing, policy and moderation denial, invalid tip rejection, compatibility history reads, and externally held advisory-lock contention. No message or event becomes visible before commit, and committed event sequence matches serialized message order. - Increment 5's release evidence includes green shared live-media (126),
Aphrodite adapter (76), database/migration (210), and Chat (57) test suites,
plus the separately enabled real PostgreSQL E2E (1). Strict library, spec, and
application typechecks; the Chat typecheck ratchet; targeted lint; Prisma
validation; direct affected Nx builds; the Chat production build; and diff
validation pass. The only lint diagnostics are eight existing Chat console
warnings; test source-map warnings refer to pre-existing generated shared
database JavaScript. A dependency-inclusive adapter build additionally reaches
an unrelated pre-existing TypeScript 6
baseUrldeprecation failure in@aphrodite/core; the adapter's direct build and strict typecheck pass. The affected pre-commit typecheck likewise passes every increment-5 owner but is blocked by Aphrodite Payment's pre-existing ratchet backlog, including its own root-directory and webhook/store errors. - Increment 5 is complete at the code and local release-gate boundary. The parent RB.3 extraction item remains open for hooks/telemetry, increments 7–8, Veritas/V3/Rail tenant equivalence, the consolidation guard, and the final supervised ingest-to-Rail E2E.
- Increment 6's operational-telemetry organ is implemented in
@oshun/live-media. Its strict versioned envelope requires the exact tenant and stream resource, bounded attributes and finite measurements, event source, occurrence and correlation identity, and an idempotency key. Separate capabilities authorize resource-exact write, read, and hook dispatch. The substrate taxonomy covers publisher, stream, pipeline, publication, viewer, QoE, chat, and moderation lifecycle facts; it does not bless Aphrodite's unauthenticated, tenantless legacyanalytics_eventstaxonomy as shared telemetry or move product/revenue reporting into the substrate. - The new
00012_live_media_operational_telemetrymigration precedes production composition and creates a dedicated event ledger plus atomic hook outbox. Composite tenant identities, resource/idempotency uniqueness, bounded vocabulary and payload checks, forced RLS, claim and expired-lease indexes, and durable attempt/availability/lease/provider state make the database—not a process map—the authority. Aphrodite's tenant-fixed SQL adapter uses an advisory idempotency lock, database time,FOR UPDATE SKIP LOCKED, proposed lease tokens, and current-lease fencing. Provider errors retry with bounded backoff and become explicit dead letters; an unacknowledged final attempt also dead-letters when its lease expires instead of looping or disappearing. - Notification, moderation, and audit are reusable hook kinds. The shared worker dispatches only a matching registered hook and cannot change media, authorization, or telemetry success. Aphrodite supplies thin notification and moderation adapters: stream lifecycle becomes a tenant product notification seam without generic copy/audience policy, while moderation denial becomes a tenant case seam without message content. Provider references and failures are preserved in the outbox. Creator targeting, notification copy, audience resolution, sanctions, and case management remain Aphrodite-owned.
- Aphrodite's publisher edge, Viewer runtime, and canonical Chat runtime now record production-path lifecycle events through the same tenant-fixed SQL writer. Refresh and duplicate paths replay stable semantic envelopes into the idempotent ledger without inflating counts; publisher connection/revision, viewer session/reconnect, QoE sample, stable chat membership/message, and committed clear-event identities provide exact idempotency. Durable Chat polling reprojects committed events after restart to repair any post-commit fanout gap. Chat projections contain only bounded identity/status/count metadata—never message bodies—and product moderation records durable/filter/ duplicate denial reasons without copying rejected content.
- The digest-pinned PostgreSQL 16 Chat gate applies migrations through
00012before starting the production composition. It proves durable chat and moderation telemetry, pending moderation outbox state, absence of filtered content, process reconstruction, two concurrent workers claiming one audit delivery exactly once, real provider failure followed by retry and terminal dead letter, persisted attempts/error detail, and forced-RLS denial to another tenant. The deterministic memory oracle additionally matches SQL behavior for an expired final-attempt lease. - Increment 6's release evidence includes green shared live-media (141),
Aphrodite adapter (91), database/migration (213), Chat (59), Viewer (177), and
Streaming (73) test suites, plus the separately enabled real PostgreSQL E2E
(1). Strict library/spec/application typechecks, Chat's zero-backlog ratchet,
targeted production and test lint, Prisma validation, isolated shared,
adapter, and database builds, all three affected application builds, and diff
validation pass. The known Vite diagnostics remain missing source maps for
pre-existing generated shared-database JavaScript. The dependency-inclusive
adapter build still reaches the unrelated
@aphrodite/coreTypeScript 6baseUrldeprecation; the adapter's own build and strict typecheck pass. The repository pre-commit typecheck also passes every affected project before stopping on ten unrelated, pre-existingapps/aphrodite/paymentratchet errors; the commit therefore uses the documented typecheck bypass after the direct strict affected checks above. - Increment 6 is complete at the code and local release-gate boundary. The parent RB.3 extraction item remains open for optional adapters in increment 7, Veritas/V3/Rail tenant composition in increment 8, the consolidation guard, tenant equivalence, and the final supervised ingest-to-Rail E2E.
- Increment 7a establishes the optional-media/client extension boundary without registering any simulated legacy package as a production provider. The shared contract enumerates immersive, segment-encryption, DRM, watermark, content-analysis, recording, publisher-client, player-client, remote-guest, and composition adapters. Every operation has an exact tenant/stream resource, semantic idempotency key, bounded adapter identity, and the relevant publication, viewer-session, playback-grant, publisher-grant, or authoritative publisher-connection references. Raw keys, ingest/playback secrets, DRM challenges, media URLs, and client/device fingerprints are not admitted.
- The optional-adapter service denies tenant or capability mismatches before binding verification or provider access. A mandatory authority port must prove exactly the active bindings for that operation; unrelated or incomplete evidence fails closed. Readiness must be fresh, internally coherent, and declare every kind-specific media source, object store, key-custody, vendor/executable, client-runtime, or edge-observation dependency. Provider failure remains failure rather than a local success state.
- Successful adapters must return the authorized operation identity, kind-specific conformance proofs, and the expected measured artifact. Server artifacts require a nonzero byte count and SHA-256 digest; immersive/player paths require decoded-media evidence, publisher/guest/composition paths require real edge or peer/render evidence, DRM requires vendor-license plus key-custody proof, and teardown is an explicit resource-matched operation. Strict immersive descriptors validate projection, stereo layout, geometry, codec, bounded runtime capability negotiation, and mono/stereo/binaural/ACN ambisonic channel invariants without accepting headset serial, location, gaze, or other product privacy data.
- Increment 7a's shared library/spec typechecks, focused lint, formatting, and all 151 shared live-media tests pass. This is the reusable contract foundation, not completion of increment 7: real durable providers, pipeline/client composition, media and vendor conformance fixtures, browser/native automation, provider-failure recovery, and teardown evidence remain actionable. In particular, the audited timer/generated cloud recorder, non-conformant DRM license facades, process-keyed encryption/watermark services, and no-op mobile publisher/player managers remain excluded.
- Increment 7b adds the first real optional provider without changing that
exclusion policy:
aphrodite.content-analysis.v1is a thin Aphrodite tenant composition over the shared optional-adapter boundary. A trusted internal control fixes tenant, adapter, capability, and advisory policy; its authority verifier accepts only the exact checksum of a ready publication's MPEG-TS or fragmented-MP4 video object. Callers cannot upload a frame, choose a provider credential, supply a media URL, select another tenant, or request automatic policy action. - The provider reads the bounded published object through a checksum-verifying
local/S3 port, extracts and measures a JPEG using the real FFmpeg executable,
and calls the audited OpenAI-compatible
StreamAnalyzerpath. HTTPS is mandatory outside loopback. Both auto-age-gating and automatic policy action are forced off. The immutable JSON artifact keeps only bounded advisory category, age, policy, object, face-count, and text-region-count evidence; it excludes raw samples, OCR bodies, biometric identifiers, and the legacy provider's automatic-action recommendation. - Migration
00013_live_media_content_analysiscreates a publication-FK-bound, forced-RLS operation ledger with semantic idempotency, bounded attempts, create-only result evidence, and fenced leases. PostgreSQL's clock—not request time—owns claim, renewal, expiry, and settlement. A heartbeat renews slow FFmpeg/vendor work; renewal loss prevents both success and stale failure settlement. Exact succeeded retries replay the durable result after process reconstruction without another sample or vendor call. - Aphrodite Streaming composes the provider only when every S3, FFmpeg, vendor, policy, worker, lease, and size setting is valid. Its probe, execute, and one-shot teardown routes require the existing internal API key plus a bounded service identity. Unit/integration coverage exercises strict binding, checksum and media-type denial, absolute readiness freshness, privacy non-disclosure, retryable provider failure, lease renewal/loss, configuration, route authorization, teardown, real FFmpeg sampling, and a real loopback OpenAI-compatible HTTP exchange.
- The digest-pinned supervised MediaMTX/PostgreSQL gate applies migration
00013atop the real publication pipeline, samples an actual published transport segment, verifies its immutable evidence, reconstructs the database and provider, proves exact no-reexecution replay, serializes two concurrent claims, recovers the expired lease, fences the stale writer, denies a second tenant under RLS, and tears down cleanly. Increment 7b is therefore complete at the code and local release-gate boundary. At this point increment 7 still requires the recording and remaining immersive, encryption/DRM, watermarking, publisher/player, remote-guest, and composition providers plus their applicable browser/native automation. - Increment 7c adds
aphrodite.recording.v1as a second real optional provider. A trusted internal control fixes tenant, adapter, capability, worker, object namespace, and retention-policy custody while accepting only a bounded asynchronous request. The exact publisher connection must agree between the forced-RLS edge-session ledger and a fresh MediaMTX Control API observation; the RTSP(S) input is derived from operator configuration, never supplied by a caller. Interactive stop, DVR, segment tracking, export, and cleanup jobs remain explicit501gaps rather than simulated controls. - The executor runs real shell-free FFmpeg stream-copy capture with a hard
duration/deadline, abort-driven TERM/KILL shutdown, canonical private attempt
directories, bounded diagnostics, and cleanup before terminal success. FFprobe
must measure the requested MP4 or Matroska container, a decodable video
stream, dimensions, duration, and optional audio. The output is hashed through
an open descriptor, staged durably, uploaded create-only through the shared
streaming-safe local/S3 object store, re-read by exact checksum/length, and
returned with the shared
recorded-mediaandobject-persistenceproofs plus a byte-bearing recording artifact. - Migration
00014_live_media_recordingsupplies a forced-RLS, stream-FK-bound queue with semantic idempotency, unique recording identity, bounded attempts/backoff, database-clock leases, heartbeat renewal, lease-token fencing, exact terminal evidence, and a staged artifact descriptor. A restarted worker settles an already-uploaded object without recapturing the publisher; an expired final-attempt lease becomes an explicit terminal failure rather than a stranded processing row. Provider, object, cleanup, or shutdown failures remain retryable only while the current lease can record that outcome. - Streaming composes the recording control and supervised worker only when the
base durable pipeline/S3 custody plus MediaMTX control/RTSP, absolute private
workspace, retention, FFmpeg/FFprobe, lease, retry, and worker settings are
complete. Auth-first
POSTenqueue returns202; exact operation status and readiness reads require the deployment internal key and a bounded service identity. Unit, SQL, route, configuration, scheduler, and executor coverage proves binding disagreement/freshness denial, strict request shape, restart settlement, retry/backoff, final-attempt recovery, stale-writer fencing, result-to-staged-object equality, shutdown cancellation, and tenant denial. - The digest-pinned supervised MediaMTX/PostgreSQL gate applies migration
00014, reconciles the real SRT publisher into SQL, captures its RTSP stream with FFmpeg, independently FFprobes the immutable MP4 as H.264/AAC, verifies exact object checksum/length, reconstructs the database/source/provider, proves result replay without a second FFmpeg call, serializes concurrent claims, recovers an expired lease, fences the stale writer, denies another tenant under RLS, and tears down the publisher and both containers. Increment 7c's release evidence includes green shared live-media (156), Aphrodite adapter (123), database/migration (219), and Streaming (87, with the separately enabled real edge E2E also green) suites; the explicit Streaming integration target adds 18 green tests. Strict source/spec typechecks, affected lint, Prisma validation, isolated and dependency-inclusive builds, formatting, and diff validation pass. The dependency graph now emits declarations for stream-content-analysis under TypeScript 6, so the previously blocked@aphrodite/core→ content-analysis → adapter → Streaming Nx build chain also passes; the prerequisite core (421) and content-analysis (140) suites remain green. The affected pre-commit typecheck passes every increment-7c owner before stopping on the same ten unrelated, pre-existing Aphrodite Payment ratchet errors recorded above; the commit therefore uses the hook's documented typecheck bypass after the direct strict checks. Increment 7c is complete at the code and local release-gate boundary. Increment 7 remains open for immersive, encryption/DRM, watermarking, publisher/player, remote-guest, and composition providers plus applicable browser/native automation. - Increment 7d adds
aphrodite.segment-encryption.v1as the first real content-protection provider. It deliberately implements only standards-based HLS AES-128 segment protection: CENC and CBCS are rejected before binding or queue mutation, and no vendor DRM/CDM license compatibility is claimed. A tenant-fixed policy selects one public key reference/version, while callers may name only an exact ready publication and semantic operation identity. - The provider reads the publication ledger's complete authoritative HLS graph, accepts canonical VOD manifests and complete MPEG-TS segments only, rejects traversal/remote/range/map/i-frame/encrypted/orphan/duplicate inputs, and enforces per-object and total byte bounds. It encrypts each segment with AES-128-CBC plus PKCS#7 padding and the HLS media-sequence IV, re-reads and independently decrypts every create-only object back to the exact source bytes, writes media manifests with internal key URIs, then writes the master and a key-free checksummed descriptor last. A retry accepts an existing object only when checksum, length, and media type agree exactly.
- Key custody composes the audited Neith PKCS#11 KMS backend with an operator-provisioned, nonextractable RSA-3072 KEK. Each operation creates one random 256-bit data key, derives its 128-bit content key under a domain-separated HMAC bound to the complete request context, wraps only the data key, and zeroes plaintext buffers. Durable custody includes public key policy, HSM object identity, wrapped bytes, context and recovery-verification digests, output namespace, and internal key URI; neither PostgreSQL nor the publication descriptor admits plaintext/content/key-byte fields. Recovery rejects wrong policy/context and tampered wrapped data before returning exactly 16 bytes.
- Migration
00015_live_media_segment_encryptionsupplies the composite publication FK, forced RLS, semantic idempotency, bounded custody/artifact JSON, database-clock backoff, expiring renewable leases, lease-token fencing, staged custody/publication recovery, and exact terminal evidence. The protected-publication descriptor is staged durably before its own create-only object is committed, so a restarted provider settles the same output without minting another data key or changing ciphertext. Expired attempts are recoverable and stale workers cannot renew, stage, succeed, or release them. - Aphrodite Streaming composes the provider and supervised worker only when the
base publication/object store, worker, fixed key policy, internal key base
URI, PKCS#11 module/token/PIN/tooling, HSM KEK, lease, retry, object-count,
and byte bounds are complete. Auth-first internal routes expose readiness,
202enqueue, exact durable status, and succeeded-only raw key delivery. The key response is exactly 16 bytes withno-store, zero-age,Pragma: no-cache, octet-stream, fixed content length, andnosniff; the recovered control buffer is zeroed after the response owns a copy. - Unit, SQL, migration, route, configuration, and provider coverage proves
policy and authority denial, authoritative graph validation, independent
ciphertext round-trip, key-free descriptors, wrapped-key tamper detection,
restart replay, backoff, expired-lease recovery, stale-token fencing, staged
result equality, concurrent claim serialization, and tenant denial. The
supervised real gate applies migration
00015to PostgreSQL, provisions a nonextractable RSA KEK in SoftHSM, protects the FFmpeg-produced HLS, confirms no raw key material in SQL, rejects unauthenticated key delivery, and has an independent authenticated FFprobe client decode H.264/AAC through the protected manifest and key route. It then reconstructs the database, PKCS#11 custody, store, and provider for exact terminal replay; recovers an expired lease; fences the stale token; and proves forced-RLS denial to another tenant. - Increment 7d's release evidence includes green Aphrodite adapter (137), database/migration (222), Streaming (93, plus the separately enabled real edge E2E), Neith vault-engine/SoftHSM (40), and shared optional-media contract (11) suites. Strict source/spec/application typechecks, affected lint, Prisma validation, dependency-inclusive adapter/database builds, the Streaming production build, formatting, and diff validation pass. Increment 7d is complete at the code and local release-gate boundary. Increment 7 remains open for CENC/CBCS and vendor DRM, immersive, watermarking, publisher/player, remote-guest, composition, protected-object/key cleanup, viewer integration, and applicable browser/native conformance automation.
- Increment 7e adds
aphrodite.watermark.v1as a real optional-media provider, while deliberately limiting its claim to a visible keyed marker. The trusted control fixes the tenant, adapter,aphrodite.visible-grid.v1profile, public key reference/version, output namespace, and worker. Callers name only an exact operation/idempotency identity, ready publication, publishedvideo/mp2tsource key/digest, and optional viewer session. The payload reference is derived from the publication or viewer session and cannot be supplied independently. - The binding and execution paths both require the exact ready publication and source object. A non-null viewer session must still be active, entitlement-valid, and tenant/resource exact according to database time. The source must be real H.264/AAC MPEG-TS within configured byte limits. Remote, caller-selected, mismatched, unready, released, or differently encoded inputs fail before they can become successful evidence.
- The shell-free FFmpeg executor encodes an opaque keyed 8x8 black/white grid into the top-right picture region, preserving H.264 video and AAC audio in an MPEG-TS output. Verification decodes the actual output, samples all 64 cell centers from exact pixels, recomputes the expected bits, and measures luma PSNR against the decoded source outside the complete grid bounding box. The output is accepted only when extraction and the operator PSNR floor pass. Evidence names this visible-grid behavior and expressly makes no invisible or forensic-robustness claim.
- Custody reuses the generic PKCS#11 media-key boundary introduced by segment encryption. Each operation creates a random 256-bit data key, wraps it under an operator-provisioned nonextractable RSA-3072 KEK, and derives the 64-bit grid token by domain-separated HMAC over the complete request context. The durable record admits only wrapped bytes, fixed policy/HSM identity, and context/data-key/token verification digests. Plaintext data-key and token buffers are zeroed and never enter PostgreSQL, output media, or evidence JSON.
- Migration
00016_live_media_watermarkadds a composite publication foreign key, optional viewer-session foreign key, forced tenant RLS, semantic idempotency, database-clock backoff, renewable expiring leases, lease-token fencing, bounded staged custody/artifact JSON, exact terminal replay, and a durable release timestamp. The provider writes create-only media before its checksummed descriptor; a restart verifies exact existing bytes and settles staged state without another encode. Teardown removes both fixed objects before release, is repeat-safe, and prevents the same operation identity from recreating deleted media. - Auth-first internal Streaming routes expose dependency readiness,
202enqueue, durable status, and destructive release only when the base pipeline, fixed policy, FFmpeg/FFprobe, object store, queue, and complete PKCS#11/HSM configuration are present. Unit, SQL, migration, route, runtime, and provider coverage proves fixed policy/payload derivation, viewer denial, exact source binding, secret non-disclosure, pixel extraction and PSNR enforcement, create-only crash recovery without re-encoding, database-clock backoff, expired-lease recovery, stale-token fencing, tenant isolation, and release fencing. The separately enabled real edge gate applies migration00016to PostgreSQL, reuses a real nonextractable SoftHSM RSA KEK, transforms an actual FFmpeg H.264/AAC segment, inspects durable wrapped-only custody, reconstructs the store/provider for exact replay, recovers and fences an abandoned lease, proves forced-RLS denial, and deletes both artifacts before durable release. - The production dependency remains narrow:
neith-vault-engineadvertises an auditedcapability:kmsboundary and a build/type gate, the Aphrodite adapter owns the provider-neutral PKCS#11 factory, and the Streaming app imports only that custody facade. Increment 7e's release evidence includes green Neith vault-engine (40), Aphrodite adapter (151), database/migration (225), and Streaming (98 plus the separately enabled real edge E2E) suites. Strict source/spec/application typechecks, targeted module-boundary lint, Prisma validation, the dependency-inclusive adapter/database build, the Streaming production build, frozen lockfile validation, formatting, and diff validation pass. - Increment 7e is complete at the code and local release-gate boundary. Increment 7 remains open for CENC/CBCS and vendor DRM, immersive, publisher/player, remote-guest, composition, segment-encryption viewer and cleanup wiring, and applicable browser/native conformance automation.
- Increment 7f adds
aphrodite.player-client.v1as the first real client-side optional provider and deliberately limits the claim to authenticated browser HLS. Protected playback reserves one credential-free operation for the exact ready publication, active viewer session, issued playback grant, client instance, and protocol. DASH registration returns no player operation and the provider rejects non-HLS execution; native and immersive clients remain open. - Migration
00017_live_media_player_clientadds a forced-RLS operation ledger with composite publication, viewer-session, and QoE-event foreign keys, semantic idempotency, one active operation per viewer session, database-clock lifecycle expiry, expiring reclaimable execution leases, immutable first evidence, and repeat-safe durable release. Refresh releases the superseded grant operation. A succeeded result requires a previously committedplayingQoE row whoseplaybackGrantId, session, resource, protocol, and positive decoded-frame count all match. Evidence and result constraints reject bearer, credential, lease-token, and token fields. @oshun/live-media/browsernow exports the same-origin Aphrodite join, heartbeat, and leave client plus an HLS.js/MSE player. It rejects cacheable control responses and cross-origin APIs, never sends the media Bearer to the application API, opens only media URLs under the grant's exact origin and publication prefix, and has no unsafe native-HLS fallback. Readiness requires measured video dimensions, a positive decoded-frame count, durable QoE acceptance, and the exact first succeeded player-operation proof. Later heartbeats retain that immutable proof; fatal loader, authorization, decode, or heartbeat failure destroys media, clears the credential, and releases the viewer session.- The player surface follows the mandatory frontend workflow: decoded media is the dominant near-black stage, status and controls are compact, focus and accessible names are explicit, controls recede during playback, mobile layout remains usable, reduced motion removes transitions, and authorization or publication-boundary failure is never rendered as success. The Playwright gate generates H.264/AAC HLS with real FFmpeg and Chromium, then proves decode, repeated heartbeats, exact-prefix authorization, cross-publication blocking before bearer disclosure, revocation, durable release, axe conformance, responsive layout, and reduced motion.
- The digest-pinned MediaMTX/PostgreSQL gate applies migration
00017, creates and refreshes real protected viewer grants, proves superseded-operation release, commits exact decoded QoE into a succeeded operation after process reconstruction, inspects the conformance proofs, confirms the Bearer is absent from SQL, denies a second tenant under forced RLS, reconnects, and durably releases on leave. Increment 7f's release evidence includes green shared live-media (174), Aphrodite adapter (162), database/migration (228), Viewer (182), and Streaming (98 plus the separately enabled real edge E2E) suites; four FFmpeg/Chromium Playwright scenarios; strict source/spec/application typechecks; all five affected lint targets; five scoped production builds; frozen lockfile, formatting, and diff validation. - Increment 7f is complete at the code and local release-gate boundary. At that boundary, parent increment 7 and RB.3 remained open for DASH/native players, immersive rendering, CENC/CBCS and vendor DRM, publisher-client, remote-guest, composition, protected-media viewer/cleanup wiring, remaining client conformance/recovery automation, tenant equivalence, the consolidation guard, and the complete ingest-to-Rail flow.
- Increment 7g extends the same real
aphrodite.player-client.v1provider to authenticated browser DASH without adding a second player stack. The control registers only browser device sessions, binds persisted QoE to the exact HLS or DASH protocol, and emitsaphrodite.browser-hls.v1oraphrodite.browser-dash.v1runtime proof accordingly. The SQL reservation and execution binding independently requiredevice_type = 'browser'; the real PostgreSQL gate rejects a TV session even when its publication, session, client instance, and protocol otherwise match. @oshun/live-media/browsernow selects HLS.js or dash.js from the protocol returned by the authenticated join. Both clients attach the Bearer only after the exact publication-prefix check. DASH uses asynchronous request and response interceptors, omits ambient cookies, permits CORS to the protected media origin, maps HTTP 401/403 before dash.js reduces the response to a generic download error, reports representation/throughput/buffer/live-latency QoE, and destroys the runtime plus credential on every terminal path. The protocol-neutral surface retains the same accessible near-black stage; the HLS class and mount names remain compatibility aliases, not a duplicate UI.- The FFmpeg/Chromium gate now generates real H.264/AAC MPEG-TS HLS and fragmented-MP4 DASH and runs eight one-worker cases: decode, repeated durable heartbeat proof, exact-prefix credential containment, malicious cross-publication blocking before disclosure, authorization loss, release, axe conformance, mobile layout, and reduced motion for both protocols. The supervised MediaMTX/PostgreSQL gate commits exact DASH QoE and the DASH runtime proof after reconstruction, denies non-browser registration and another tenant, proves secret non-disclosure, independently decodes protected HLS and DASH, and exercises DASH expiry, reconnect, tamper, leave, and publication revocation.
- Increment 7g's release evidence includes green shared live-media (179), Aphrodite adapter (164), Viewer (184), and Streaming (98 plus the separately enabled real edge E2E) suites; eight FFmpeg/Chromium Playwright scenarios; strict source, spec, and application typechecks; all four affected lint scopes; four scoped production builds and their declared dependencies; and filtered frozen-lockfile, formatting, and diff validation.
- Increment 7g is complete at the code and local release-gate boundary. The parent increment 7 and RB.3 checkboxes remain open for native players, immersive rendering, CENC/CBCS and vendor DRM, publisher-client, remote-guest, composition, protected-media viewer/cleanup wiring, remaining client conformance/recovery automation, tenant equivalence, the consolidation guard, and the complete ingest-to-Rail flow.
- Increment 7h adds the real
aphrodite.publisher-client.v1provider and limits its runtime claim to authenticated browser WHIP. Broadcaster provisioning rotates one short-lived publisher grant and reserves the grant ID as the exact operation ID for one tenant stream, browser client instance, and WebRTC protocol. The application control API and media endpoint remain separate: only the exact secure MediaMTX/whipendpoint receives the memory-only Bearer; plain HTTP is admitted solely for loopback testing. - MediaMTX external auth treats a WebRTC OPTIONS request as a credentialed capability probe but does not invent a source identity. The subsequent WHIP POST binds that same active grant to MediaMTX's exact source connection ID and edge. Browser heartbeats persist only monotonic outbound bytes, packets, and encoded frames; success requires positive inbound bytes independently observed on that same connected edge row. The provider emits separate client-runtime and edge-observation proofs plus a client-session artifact without receiving or persisting the Bearer, SDP, ICE addresses, or device details.
- Migration
00018_live_media_publisher_clientadds a forced-RLS operation ledger with an exact composite grant/resource foreign key, semantic idempotency, one active publisher operation per stream, database-clock expiry, expiring reclaimable execution leases, immutable success evidence, and repeat-safe release. Unknown-operation deletion is checked before grant revocation, and storage conditionally revokes only the operation's exact grant ID. A valid-but-unrelated or superseded operation therefore cannot invalidate a newer live grant. Release durably fences the requested operation. @oshun/live-media/browsernegotiates send-only audio/video through WHIP, validates the returned session location inside the same endpoint boundary, samples real outbound WebRTC statistics, rejects counter regression, and reports publishing only after the exact durable edge/client proof. Stop and every failed-start path attempt WHIP DELETE, peer/media shutdown, and durable release; combined cleanup failures remain explicitTEARDOWN_FAILEDerrors.- Unit, SQL migration, route, provider, and store coverage proves exact binding,
monotonic evidence, connection replacement rejection, no edge-free success,
restart replay, unknown-operation safety, lease fencing, tenant denial, and
teardown aggregation. The digest-pinned MediaMTX/PostgreSQL gate applies
migration
00018around the existing real SRT publisher, reconciles positive edge ingress, reconstructs the provider for exact replay, inspects secret-free SQL, denies another tenant, and releases all resources. The separate real MediaMTX/Chromium gate distinguishes the WebRTC OPTIONS probe from the WHIP source ID, publishes real encoded video, validates Bearer containment and durable readiness, and exercises authorization and failed-start cleanup alongside the existing FFmpeg-backed HLS/DASH player scenarios. - Increment 7h's release evidence includes green shared live-media, Aphrodite adapter, database/migration, Broadcaster, and Streaming suites; the separately enabled real edge E2E; ten one-worker FFmpeg/Chromium Playwright scenarios; strict source, spec, and application typechecks; all five affected lint scopes; five scoped production builds; Prisma, filtered frozen-lockfile, formatting, and diff validation.
- Increment 7h is complete at the code and local release-gate boundary. The parent increment 7 and RB.3 checkboxes remain open for native publisher and player clients, immersive rendering, CENC/CBCS and vendor DRM, remote-guest, composition, protected-media viewer/cleanup wiring, remaining client conformance/recovery automation, Veritas/V3/Rail tenant equivalence, the consolidation guard, and the complete ingest-to-Rail flow.
- Increment 7i adds an explicit
browser/nativeruntime discriminator to the player and publisher contracts, provider identities, operation fingerprints, and SQL reconstruction boundaries. Migration00019_live_media_native_clientsbackfills the existing browser operations, makes the runtime columns mandatory, and constrains native publisher operations to RTMP or SRT while retaining the protocol-specific provider checks. Session-device compatibility is enforced before a player operation can be registered, and publisher provisioning rejects a runtime/protocol mismatch before rotating the active grant. - Broadcaster can now provision native SRT publishers. The response separates a
credential-free SRT resource URL and username from the optional encryption
secret, sets
no-store, and requires a 10–79-character printable ASCII AES-256 passphrase whenever the endpoint is not loopback. Clear SRT therefore exists only for local integration. The native TypeScript wrapper passes the operation to an isolated Rust executable over standard input; its FFmpeg child receives no publisher credential or passphrase, and MPEG-TS is sent by an in-process, unsafe-code-denying pure-Rust SRT implementation advertising protocol version 1.4.4. Measured send counters must still be corroborated by positive MediaMTX ingress on the exact durable operation before readiness. @oshun/live-media/nativenow supplies a Linux-native HLS/DASH playback component. A memory-only exact-publication-prefix loopback proxy holds the Bearer and gives FFmpeg or ffplay only a one-time local capability. It constrains manifest redirects and every fetch-bearing HLS/DASH reference, filters forwarded headers, streams media without buffering whole segments, bounds redacted diagnostics, and clears its credential buffer during teardown. Actual FFmpeg decode produces the QoE heartbeat evidence; the same proxy also supports an ffplay render session. External DASH XML namespace and schema identifiers remain metadata rather than being rewritten as playable media.- Increment 7i's release evidence includes green shared live-media, Aphrodite adapter, database/migration, Broadcaster, Viewer, and Streaming suites; a real encrypted cross-implementation SRT socket test; ten one-worker FFmpeg/Chromium Playwright scenarios; strict Rust/TypeScript checks; all six affected lint scopes; six scoped production builds; and Prisma, filtered frozen-lockfile, formatting, and diff validation. The digest-pinned MediaMTX/PostgreSQL edge gate publishes real H.264/AAC MPEG-TS through the Rust SRT client, observes edge ingress, reconstructs and replays the durable publisher operation, decodes protected HLS and DASH through the credential proxy, persists measured QoE, renders HLS with ffplay under Xvfb, and requires non-black captured pixels. The claim is a reusable Linux native execution component for application-shell integration, not a complete mobile application or Tauri UI.
- Increment 7i is complete at the code and local release-gate boundary. The parent increment 7 and RB.3 checkboxes remain open for immersive rendering, CENC/CBCS and vendor DRM, remote-guest, composition, protected-media viewer/cleanup wiring, remaining client conformance/recovery automation, Veritas/V3/Rail tenant equivalence, the consolidation guard, and the complete ingest-to-Rail flow.
- Increment 7j replaces the public process-local VR simulation with a
fail-closed retirement gateway and adds the first real bounded immersive
client path to the shared organ.
@oshun/live-media/browserprojects decoded protected media through WebGL for equirectangular 180°/360° flat/cardboard presentation, renders both cardboard eyes from mono/SBS/top-bottom sources, accepts pointer, keyboard, or permission-backed device orientation, and uses a Web Audio analyser plus HRTF/stereo panning. Success requires positive decoded/rendered/audio evidence, non-black readback, distinct initial/oriented frame hashes, and bounded orientation counts. Cubemap/EAC, ambisonics, native immersive clients, and WebXR without a real XR session/frame loop fail closed. - Aphrodite Viewer now exposes authenticated, no-store immersive
register/evidence/release routes under the existing viewer lease. The
aphrodite.immersive.v1control derives its operation identity and all bindings from the exact active succeeded browser player; it never accepts a caller-authored publication, player grant, or provider reference. Migration00020_live_media_immersive_sessionsadds exact player/publication/viewer foreign keys, one active operation per viewer session, forced RLS, database-clock lifecycle and worker leases, immutable bounded evidence, restart replay, reclaim, stale-writer fencing, and explicit release. Durable rows exclude the media Bearer, URLs, raw poses, gaze, location, and headset identifiers. - Increment 7j's browser release evidence uses generated 1920×960 H.264/AAC
stereo HLS and DASH. Single-worker Chromium automation proves real decoded
media, WebGL non-black pixels in two distinct eye buffers, view changes from
actual CDP device orientation and pointer input while the source is paused,
positive Web Audio samples, exact origin/grant containment, axe, mobile,
reduced motion, privacy, and ordered immersive/player teardown. The
digest-pinned MediaMTX/PostgreSQL gate applies migration
00020, inspects durable proof/secret absence, reconstructs the adapter for replay, recovers an expired execution lease, rejects the stale fence, denies a second tenant, releases on reconnect, and tears down explicitly. - Increment 7j is complete at the code and local release-gate boundary. The parent increment 7 and RB.3 checkboxes remain open for physical headset/WebXR/native immersive runtimes, capture/stitching and broader projection/audio formats, CENC/CBCS and vendor DRM, remote-guest, composition, protected-media cleanup wiring, Veritas/V3/Rail tenant equivalence, the consolidation guard, and the complete ingest-to-Rail flow.
- Increment 7k retires the unsafe legacy remote-guest network authority and
installs the shared, strict one-host/one-guest browser path described above.
Aphrodite Broadcaster remains a tenant adapter: it owns authentication,
exact-stream authorization, no-store HTTP composition, and the single-node
WebSocket gateway, while
@oshun/live-mediaowns the portable contracts, signaling hub, browser peer runtime, bounded evidence, and accessible studio surface. The forced-RLS adapter owns durable one-use capability digests, database-clock lifecycle, reciprocal evidence, replay, fencing, and release. - Increment 7k's release evidence includes green shared live-media (222), Aphrodite adapter (179), Broadcaster (83), legacy compatibility (6), and migration (3) unit suites; package/spec typechecks; all five affected lint scopes; shared, adapter, compatibility, and Broadcaster production builds; two single-worker Chromium desktop/mobile scenarios; and the supervised real PostgreSQL/MediaMTX integration. The browser gate proves actual reciprocal media and matching SSRC evidence across two browser contexts. The database gate proves one-use/rotation semantics, restart replay, forced RLS, database-clock expiry, lease recovery/fencing, durable secret/signaling non-disclosure, release, and teardown.
- Increment 7k is complete at the code and local release-gate boundary. Parent increment 7 and RB.3 remain open for SFU/TURN/multi-node or native remote-guest expansion if product requirements demand it, composition, CENC/CBCS and vendor DRM, protected-media cleanup wiring, broader immersive runtimes, Veritas/V3/Rail tenant equivalence, and the complete ingest-to-Rail flow.
- Increment 7l adds the first real composition provider and deliberately bounds
it to browser execution.
@oshun/live-media/browserowns the portable Canvas 2D/Web Audio compositor, exact one-to-four-source contract, deterministic single/grid/two-source picture-in-picture layouts, 640–1920-wide 16:9 output at 15–60 fps, optional audio mixing, derived-stream capture, existing WHIP publication, and accessible full-stage surface. Caller-owned source tracks remain caller-owned during teardown. Custom layouts, scene switching and transitions, GPU/OBS/native composition, SFU/MCU mixing, and multi-node orchestration are explicit non-claims. - Aphrodite remains a thin tenant control plane. Broadcaster's authenticated,
no-storeregister/evidence/release routes accept only bounded identifiers, output declarations, changed/non-black frame counts, source-region SHA-256 samples, and aggregate audio proof.aphrodite.composition.v1derives the exact tenant/stream/grant/client binding and succeeds only after the linked browser/WebRTC publisher has succeeded and its exact MediaMTX edge connection is connected with positive ingress. Raw pixels, raw audio, source media, Bearers, SDP, and ICE never enter the durable operation. Publisher teardown cascades composition release. - Migration
00022_live_media_compositionsinstalls the composite grant/publisher/resource-bound ledger with forced RLS, database-clock lifecycle, one active composition per publisher, semantic replay, reclaimable leases, stale-worker fencing, immutable proof, and repeat-safe release. The single-worker Chromium suite proves two independently changing Canvas sources, distinct non-black output regions, real oscillator evidence, real WHIP/MediaMTX RTP, exact durable binding, axe, keyboard, mobile, reduced-motion, denial, privacy, and ownership-correct teardown. The supervised PostgreSQL/MediaMTX gate applies the migration and proves exact publisher/edge joins, restart replay without attempt inflation, database-clock abandoned-lease recovery, stale-fence rejection, second-tenant denial, durable secret/raw-media absence, repeat-safe release, browser WHIP cleanup, and disconnected-edge reconciliation. All affected unit, integration, strict typecheck, lint, build, frozen-lockfile, and the complete 17-scenario browser suite pass. - Increment 7l is complete at the code and local release-gate boundary. Parent increment 7 and RB.3 remain open for broader composition runtimes if product requirements demand them, SFU/TURN/multi-node or native remote guests, CENC/CBCS and vendor DRM, broader immersive runtimes, Veritas/V3/Rail tenant equivalence, and the complete ingest-to-Rail flow.
- Increment 7m completes the bounded AES-128 protected-playback and destructive
cleanup path without claiming CENC/CBCS or a vendor DRM/CDM stack. Playback
grant requests now carry the viewer-selected HLS/DASH protocol. A forced-RLS
SQL view selects only the newest
active, succeeded encryption operation for the exact ready source publication. HLS grants retain the compatible signed-grant envelope while binding an immutable operation prefix, exact HLS manifest ledger, virtual key object, operation ID, and external key URI; DASH deliberately continues to issue only the clear source grant. - Browser HLS.js authorizes requests only inside that protected ledger or at the
exact signed key URI, including its query, and attaches the memory-only Bearer
only after the check. The native loopback proxy rewrites that one key URI to a
credential-free local capability and performs the upstream key request itself,
keeping the Bearer out of child arguments. Aphrodite Streaming exposes the
public
/media-origin/segment-keys/:operationId/keyboundary. It revalidates the active viewer lease, ready source publication, active protected operation, exact virtual key object, and current custody before recovering exactly 16 bytes. Missing, wrong, stale, releasing, and released requests all return an empty401; successful responses areno-store, fixed-length octet streams and the recovered control buffer is zeroed after the response owns a copy. - Migration
00023_live_media_protected_playback_cleanupadds anactive→releasing→releasedstate machine, database-clock release lease, durable exact object plan, release timestamps, custody digest, and partial active protected-publication index. The provider verifies its immutable descriptor, persists the plan and fences delivery before deletion, idempotently removes only those protected objects, and atomically shreds wrapped custody after deletion succeeds. A crashed cleaner can reclaim the expired lease without changing the plan; a completed release replays the original database time and the original encryption request cannot resurrect its objects. Source publication objects remain untouched. - Increment 7m's release evidence includes green shared live-media (229),
Aphrodite adapter (187), database/migration (243), Viewer (191), and Streaming
(108, with the separately enabled real edge E2E also green) suites; 10 focused
single-worker browser-player scenarios; strict source/application typechecks;
targeted lint; Prisma validation; Streaming and Viewer production bundles;
formatting; and diff validation. Browser automation generates and decodes real
AES-128 H.264/AAC HLS through the exact signed key URI and proves a sibling
URI is blocked before Bearer disclosure. The supervised
PostgreSQL/SoftHSM/FFmpeg/native gate applies migration
00023, reconstructs storage and HSM custody, decodes the protected HLS through the public key route, verifies the 16-byte key response, then proves immediate manifest/key denial, exact protected-object deletion, source preservation, custody shredding, repeat-safe release, and replay rejection. The gate now streams its migration batch overpsqlstdin so future schema growth is not bounded by the host's single-argument size limit. - Increment 7m is complete at the code and local release-gate boundary. Parent increment 7 and RB.3 remain open for CENC/CBCS and vendor DRM/CDM licensing, broader optional provider/client runtimes where product requirements demand them, Veritas/V3/Rail tenant equivalence, and the complete ingest-to-Rail flow.
- Increment 8a starts tenant onboarding at the missing identity boundary.
@oshun/live-medianow owns a strict, immutable, idempotent registry between its canonical tenant/resource UUID and a product-owned external identity. Registration requires the existing stream-create capability; reads and reverse resolution require stream-operate and are tenant-authorized before store access. The memory store and tenant-fixed PostgreSQL adapter reject both resource-side and external-identity conflicts. The registry deliberately has no second stream lifecycle: grants, publications, sessions, and product stream state remain the authorities for their own revocation and teardown. - Migration
00024_live_media_tenant_resource_registrycreates the forced-RLS registry, backfills canonical Aphrodite streams and any already-deployed tenant-tagged substrate rows, normalizes the early operational-event stream UUID to the shared TEXT contract, and replaces all 13 root shared-ledger one-columnstreams(id)foreign keys with composite(tenant_id, stream_id)references. The Aphrodite-owned chat-filter configuration remains directly product-bound. New Aphrodite publisher-grant issuance idempotently registers its exact stream UUID before the durable grant write. - Increment 8a's gated digest-pinned PostgreSQL test applies the complete
00005–00024chain and uses one identical substrate stream UUID across Aphrodite, Veritas, V3 Stage, and V10 Rail. It proves Aphrodite backfill, independent registration for the other three tenants without counterfeit Aphrodite stream rows, durable grant issuance and post-restart authentication, reverse mapping resolution, forced-RLS row visibility, mapping-conflict rejection, an unregistered-resource composite-FK failure, and the live constraint catalog's 13 composite references with no remaining shared-ledger reference tostreams. The full shared live-media (232), Aphrodite adapter (190 plus the separately enabled PostgreSQL gate), database (246), and Aphrodite Streaming (108) suites pass, as do focused lint, source and database-spec typechecks, library builds, Prisma validation, formatting, and diff validation. Existing whole-spec typecheck debt outside this change remains in older protected-playback/immersive fixtures and the Streaming E2E tsconfig boundary; the new registry sources and tests report no diagnostics. - Increment 8a is the SQL identity and credential-equivalence prerequisite, not completion of tenant equivalence. No Veritas/V3/Rail production adapter or Rail player path is claimed yet; the broader optional-provider scopes, full four-tenant behavior suite, and supervised ingest-to-Rail flow remain open.
- Increment 8b removes the remaining Aphrodite-only naming and adapter-ID
assumptions from the canonical shared browser and native client surface.
Playback, publisher, immersive, remote-guest, and composition descriptors now
accept only their kind-correct
{tenant}.*.vNadapter identity. Every browser control binds the adapter returned by its initial register or provision call and rejects an adapter swap during heartbeat, evidence, invite exchange, or release. Canonical functions, sessions, surfaces, mounts, and DOM roots use live-media names. The previousAphrodite*exports remain deprecated exact aliases, so Aphrodite still executes the same tenant-#1 implementation rather than a compatibility fork. - Contract coverage exercises Veritas playback and immersive identities plus V3 Stage publisher, composition, remote-guest, and native-publisher identities; native playback also accepts a non-Aphrodite tenant. Negative cases reject wrong-kind IDs and mid-lifecycle adapter replacement, while exact-identity assertions prove the old Aphrodite exports alias the canonical functions and classes. The full shared live-media suite passes 243 tests, the Aphrodite adapter passes 190 with one intentional skip, Broadcaster passes 86, Viewer passes 191, and Streaming passes 108 with one intentional skip. All 19 single-worker Chromium scenarios, all 14 V10 Phase A/consolidation cases, shared source and spec typing, affected adapter/application typechecks, package lint, and the dependency-inclusive shared production build pass.
- Increment 8b proves portable client contracts and Aphrodite compatibility; it does not create production Veritas/V3/Rail control planes, provider stores, or a Rail playback lane. Those tenant compositions, broader optional runtimes, and the supervised ingest-to-Rail equivalence gate remain open.
- Increment 8c extracts the media-pipeline command/query façade itself into the
canonical shared organ.
LiveMediaTenantPipelineJobControlaccepts a deployment-supplied canonical job service, fixes one validated tenant plus its operate/manage principals at construction, and exposes no caller-authored tenant or authority field. Aphrodite's previous control is now an exact thin tenant-#1 subclass, with an explicit full-result equivalence test across enqueue, semantic replay, get, list, and cancel. Veritas supplies the first production-shaped tenant-#2 subclass from its existing Rail channel package; runtime-cast Aphrodite options cannot replace itsveritastenant or principal prefix. - Increment 8c coverage runs Aphrodite and Veritas controls over one canonical pipeline with the same stream UUID and idempotency key, proving independent durable records plus cross-tenant get/list isolation, semantic replay, management authority, invalid-configuration rejection, and exact Veritas request scopes. The final gates pass 246 shared live-media tests, 191 Aphrodite adapter tests with one intentional skip, 86 Veritas channel tests, all 14 V10 Phase A/consolidation tests, source and spec typechecks, targeted lint, dependency-inclusive shared/adapter builds, frozen-lockfile validation, formatting, and diff checks.
- Increment 8c is a real reusable control-plane composition, not a media-byte
completion claim. The Veritas rehearsal ingest port is not yet backed by the
shared publisher/transcode/publication/viewer path, the V10
first-party-livegate remainsnot_configured, and V3 Stage plus the Rail playback lane still need production tenant compositions and the supervised ingest-to-playback equivalence gate. - Increment 8d moves the complete PostgreSQL media-pipeline job state machine
into the canonical server-only substrate as
SqlLiveMediaPipelineJobStore. The shared store accepts an injected canonical database transaction port and one immutable tenant while preserving forced transaction-local RLS, advisory idempotency serialization,SKIP LOCKEDclaims, database-clock scheduling and leases, lease-token fencing, cancellation, retry recovery, and terminal settlement. Product-specific configuration and error translation remain thin wrapper responsibilities; Aphrodite's existing constructor and exactTENANT_MISMATCHerror are preserved by a 37-line tenant-#1 subclass. - Increment 8d coverage composes Veritas's tenant-fixed control through the shared service and shared SQL store, proving exact tenant/RLS/advisory/insert bindings, and proves Aphrodite cross-tenant enqueue and list rejection before a transaction begins. The final gates pass 248 shared live-media tests, 191 Aphrodite adapter tests with one intentional skip, 86 Veritas channel tests, all 14 V10 Phase A/consolidation tests, five source/spec/standalone typechecks, targeted shared/adapter lint, dependency-inclusive shared/adapter builds, frozen-lockfile validation, and the digest-pinned real PostgreSQL plus MediaMTX persistence E2E.
- Increment 8d establishes reusable durable control-plane persistence; it does
not compose a deployed Veritas database adapter or move Veritas ingest bytes
through publication into an HLS viewer. The V10
first-party-livegate remainsnot_configured, and V3 Stage/Rail production compositions plus the supervised ingest-to-playback equivalence gate remain open. - Increment 8e moves the durable tenant/resource identity map and publisher
credential authority into the canonical server-only substrate as
SqlLiveMediaResourceRegistryStoreandSqlLiveMediaPublisherGrantStore. Both receive an injected database transaction port, validate and fix one tenant at construction, establish transaction-local forced-RLS context, and reject cross-tenant access before SQL. The registry preserves database-time immutable registration, one tenant-wide advisory lock, exact replay, and crossed-uniqueness conflict rejection. The grant store preserves per-resource advisory serialization, atomic prior-generation revocation, monotonic generation, digest-only lookup, and expected-grant revocation. Product-specific error translation remains an option; Aphrodite's prior constructors and exactTENANT_MISMATCHerrors are preserved by thin tenant-#1 subclasses. - Increment 8e coverage issues and authenticates a deterministic Veritas grant through the shared service and shared SQL port, proves exact RLS/advisory/ insert/digest bindings, registry replay/conflict/get/resolve behavior, and pre-transaction tenant rejection. The existing digest-pinned PostgreSQL gate now directly instantiates the two canonical stores for Aphrodite, Veritas, V3 Stage, and V10 Rail; it maps the same stream UUID, issues isolated grants, proves the full composite-FK catalog and forced-RLS visibility, reconstructs both stores, reauthenticates every secret, rejects an unregistered grant, and tears down. The full affected suites pass 254 shared live-media tests and 191 Aphrodite adapter tests with one intentional skip, plus 86 Veritas channel tests and all 14 V10 Phase A/consolidation tests. Four source/spec typechecks, Nx-aware shared/adapter lint, dependency-inclusive shared/adapter builds, formatting, diff checks, and the digest-pinned real PostgreSQL gate pass.
- Increment 8e removes the Aphrodite-named persistence dependency from the
four-tenant identity/credential E2E, but it is not a deployed Veritas/V3/Rail
publisher composition. Veritas rehearsal bytes still do not traverse shared
edge, publication, viewer, and Rail playback, so
first-party-liveremainsnot_configuredand the final tenant-equivalence gate remains open. - Increment 8f moves the durable publisher-edge and media-publication state
machines into the canonical server-only substrate as
SqlLiveMediaPublisherEdgeSessionStoreandSqlLiveMediaPublicationStore. Both accept the canonical database transaction port, fix one validated tenant, establish transaction-local forced-RLS context, and reject cross-tenant work before SQL. The edge store preserves resource-local advisory serialization, exact-connection refresh without revision inflation, atomic replacement, stale-disconnect rejection, and connected-session listing. The publication store preserves publication-local advisory serialization, exact-prefix reservation, durable source metadata, compare-and-swap ready/failed/revoked transitions, and exact terminal replay. Aphrodite's prior constructors, default database, and legacy mismatch messages remain thin tenant-#1 wrappers rather than duplicate state machines. - Increment 8f coverage exercises the canonical stores directly as Veritas, including exact RLS, advisory-lock, SQL-value, refresh, stale-connection, transition-replay, revocation, prefix, and pre-transaction tenant behavior. Aphrodite coverage additionally proves the exact legacy error classes and messages. The digest-pinned PostgreSQL gate now creates the same stream UUID for Aphrodite, Veritas, V3 Stage, and V10 Rail, then uses the canonical stores to issue a grant, record an SRT edge connection, and reserve an isolated publication for every tenant. Forced-RLS queries expose exactly one row from each authority per tenant; reconstructed store instances reauthenticate each grant and recover the exact connected edge and publishing reservation. The full gates pass 260 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests, plus four strict source/spec typechecks, Nx-aware shared/adapter lint, dependency-inclusive shared/adapter builds, and the real PostgreSQL gate.
- Increment 8f advances the durable media-byte-path boundary, but the gate does
not send real Veritas/V3/Rail bytes through MediaMTX or produce a ready
HLS/DASH object ledger. A deployed non-Aphrodite worker/viewer composition,
Rail playback, the final tenant-equivalence gate, and the
first-party-liveflip remain open. - Increment 8g moves the complete durable viewer-session, QoE, and presence
state machine into the canonical server-only substrate as
SqlLiveMediaViewerSessionStore. It fixes one validated tenant, establishes transaction-local forced-RLS context, serializes a resource with an advisory lock, takes lifecycle time from PostgreSQL, expires leases and entitlements before mutations, preserves join/refresh/reconnect idempotency, fences heartbeat/leave by the digest-only lease, commits ordered lifecycle events, rejects conflicting or non-monotonic QoE, and derives exact active-session and unique-viewer presence inside the same transaction. - The former hard dependency on Aphrodite's
streamstable is now an optional transaction-local presence-projection port. The canonical default owns no product table or counter; Aphrodite's thin tenant-#1 wrapper retains its default database, exact legacy mismatch error, and exact current/peak/total viewer projection. The existing eight Aphrodite SQL-behavior tests run through that wrapper unchanged, while direct Veritas coverage proves RLS/locking, exact insert values, projection delegation, QoE persistence, leave replay, database-time active authority, absence of a product-table mutation, and pre-transaction tenant rejection. - The digest-pinned PostgreSQL gate now creates an isolated active viewer lease
and presence snapshot alongside the resource, grant, edge, and publication
rows for Aphrodite, Veritas, V3 Stage, and V10 Rail. Forced-RLS queries expose
exactly one viewer row per current tenant; reconstructed canonical stores
recover each exact active session and a one-session/one-viewer presence
snapshot. The fixture's only
streamsrow remains the migration-managed Aphrodite product identity, and the canonical viewer store succeeds although that minimal product table has no viewer-counter columns. Final gates pass 264 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests, plus four strict source/spec typechecks, Nx-aware shared/adapter lint, dependency-inclusive shared/adapter builds, formatting, diff checks, and the real PostgreSQL gate. - Increment 8g establishes reusable durable viewer authority and presence, not
completed playback. The four publications remain in
publishing; no real non-Aphrodite bytes, ready HLS/DASH ledger, playback grant, decoded player, or Rail lane is claimed. Deployed Veritas/V3/Rail worker/viewer compositions, the final tenant-equivalence gate, andfirst-party-liveremain open. - Increment 8h moves the complete durable live-chat persistence state machine
into the canonical server-only substrate as
SqlLiveMediaChatStore. It fixes one validated tenant, establishes transaction-local forced-RLS context, takes lifecycle time from PostgreSQL, and serializes resource and ordered-event mutations with advisory locks. It preserves viewer-session- and entitlement-bound membership, digest-only rotating leases, join/heartbeat/ reconnect/leave/expiry/revocation, database-derived presence, bounded per-member rate limits, immutable message idempotency, moderation-bound text, server messages, deletion, room clearing, history, and the durable ordered event outbox/poll cursor. - Aphrodite's former store is now a thin tenant-#1 subclass that retains its default database, constructor, and exact legacy mismatch error. Its product-owned filter and policy configuration still supplies moderation decisions; it no longer owns a second SQL chat state machine. Four direct Veritas tests prove exact RLS and lock context, membership/presence/event SQL, moderated message replay without duplicate rate or event writes, database-time reads, durable event polling, and pre-transaction tenant rejection. All ten existing Aphrodite SQL behavior tests pass through the wrapper with exact error compatibility.
- The digest-pinned four-tenant PostgreSQL gate now joins an isolated active
membership and publishes a system message for Aphrodite, Veritas, V3 Stage,
and V10 Rail. Forced-RLS queries expose exactly one membership, one message,
and two ordered events for the current tenant. Reconstructed stores recover
the exact digest-authenticated message history, one-member/one-participant
presence, and ordered
membership_joinedthenmessage_createdcursor after database restart. The dedicated live-chat PostgreSQL concurrency/replay/ expiry/moderation/recovery gate also passes. Final gates pass 268 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 59 passing Aphrodite chat tests with one intentional skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests, plus five strict source/spec typechecks, shared/adapter/chat lint, dependency-inclusive shared/adapter/chat builds, formatting, diff checks, and both real PostgreSQL gates. - Increment 8h establishes reusable durable chat authority, not a completed
non-Aphrodite broadcast. The four publications remain in
publishing; no real Veritas/V3/Rail bytes, ready HLS/DASH ledger, playback grant, decoded player, or Rail lane is claimed. Operational chat hooks/telemetry remain Aphrodite-named, and deployed non-Aphrodite composition, final tenant equivalence, andfirst-party-liveremain open. - Increment 8i moves the complete durable operational event ledger and hook
outbox into the canonical server-only substrate as
SqlLiveMediaOperationalTelemetryStore. It fixes one validated tenant, establishes transaction-local forced-RLS context, atomically persists an event and its selected configured deliveries, and preserves advisory-lock semantic idempotency, conflict fingerprints, a monotonic database sequence, exact tenant/resource queries, database-clockSKIP LOCKEDclaim and reclaim, final-attempt-expiry dead-lettering, and lease-fenced completion, failure, and retry transitions. - Aphrodite's former telemetry store is now a thin tenant-#1 subclass retaining its default database, positional constructor, and exact legacy mismatch error. Aphrodite's notification/moderation hook registrations and providers remain product-owned, but it no longer owns a second SQL state machine. The extraction also removes stale UUID stream casts left after migration 00024 normalized the registry stream key to text. Five direct Veritas tests prove exact RLS, idempotency, query, claim, lease, and pre-SQL tenant behavior, including the text-key regression; all five existing Aphrodite SQL-behavior tests pass through the wrapper with exact error compatibility.
- The digest-pinned four-tenant PostgreSQL gate now commits one isolated
publisher-connected event and one pending
rail.auditdelivery for Aphrodite, Veritas, V3 Stage, and V10 Rail. Forced-RLS queries expose exactly one event and one hook for the current tenant. Reconstructed canonical stores recover the exact event after restart, claim the matching delivery with a fresh lease, and complete it with its provider reference. The dedicated live-chat PostgreSQL gate also proves concurrent hook claiming, retry/dead-letter transitions, bounded body-free hook content, and cross-tenant rejection through the compatibility wrapper. Final gates pass 273 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 59 passing Aphrodite chat tests with one intentional skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests, plus five strict source/spec typechecks, shared/adapter/chat lint, dependency-inclusive shared/adapter/chat builds, formatting, diff checks, and both real PostgreSQL gates. - Increment 8i establishes reusable durable telemetry and hook authority, not
deployed Veritas/V3/Rail hook providers or a completed non-Aphrodite
broadcast. The four publications remain in
publishing; no real Veritas/V3/Rail bytes, ready HLS/DASH ledger, playback grant, decoded player, Rail lane, final tenant-equivalence gate, orfirst-party-liveflip is claimed. - Increment 8j moves the remaining viewer-session, operational-telemetry, and
playback-grant authority facades into the canonical substrate as
LiveMediaTenantViewerSessionControl,LiveMediaTenantOperationalTelemetryControl, and the server-onlyLiveMediaTenantPlaybackGrantControl. Each fixes and validates one tenant and principal at construction, mints exact request scopes internally, validates stream/publication identities, and exposes no runtime tenant or capability override. The viewer control preserves join, heartbeat/QoE, leave, active authority, presence, and semantic lifecycle telemetry over the canonical service/store ports. The operational control preserves strict event creation, configured durable hook selection, and idempotent replay. The playback control delegates only an allowed entitlement bound to the exact publication and viewer session. - Aphrodite's three prior controls are now constructor-compatible tenant-#1 wrappers over those shared facades. Its default SQL telemetry store, notification/moderation hook registrations, exact principals, viewer timing and random-ID seams, and playback service injection remain unchanged. Direct shared tests exercise V10 Rail viewer/QoE/telemetry and Veritas/V3/Rail grant delegation, same-stream cross-tenant isolation, idempotent hook creation, and invalid fixed authority. Existing Aphrodite operational, protected-playback, and 105-test viewer integration behavior remains green.
- The digest-pinned four-tenant PostgreSQL gate now enters viewer joins and restart active/presence reads through tenant-fixed viewer controls, and enters operational event/hook writes through tenant-fixed telemetry controls for Aphrodite, Veritas, V3 Stage, and V10 Rail. The existing canonical stores still prove forced-RLS visibility and restart recovery, claim, and completion. Final gates pass 279 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 59 passing Aphrodite chat tests with one intentional skip, 105 Aphrodite viewer integration tests, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Eight strict source/spec typechecks, graph-aware shared/adapter lint, dependency-inclusive shared/adapter builds, the direct viewer production bundle, formatting/diff checks, and both real PostgreSQL gates pass.
- Increment 8j establishes reusable tenant-fixed runtime entry points, not
deployed Veritas/V3/Rail viewer, grant, or hook-provider compositions. The
four publications remain
publishing; no real non-Aphrodite ingest bytes, ready HLS/DASH ledger, issued real playback grant, decoded Rail player, final tenant-equivalence gate, orfirst-party-liveflip is claimed. - Increment 8k moves publisher-grant issuance/registration and transcode
execution authority behind the canonical server-only
LiveMediaTenantPublisherGrantControlandLiveMediaTenantTranscodeExecutionControl. Each validates and fixes one tenant at composition time and exposes no runtime tenant or capability override. The publisher control also fixes the owning product and product-resource mapping, registers that immutable mapping before secret issuance, and binds authenticate/rotate/revoke to the same tenant. The transcode control fixes its worker principal and absolute operator-owned output root, then creates the operate scope, execution identity, exact tenant/resource, and tenant-namespaced file URI internally. - Aphrodite's publisher-grant and transcode controls are now thin constructor-compatible tenant-#1 wrappers. They retain the existing SQL defaults, optional injected registry behavior, exact owner mapping, principal, output-root error, clock, and random-ID seams used by streaming, broadcaster, and the MediaMTX release gate. Seven direct canonical tests exercise same-stream Veritas/V3 isolation, product mapping, V10 Rail management authority, invalid fixed configuration, and exact Veritas/V3/Rail transcode scope/output ownership. All existing Aphrodite compatibility, streaming, and broadcaster test targets remain green.
- The digest-pinned four-tenant PostgreSQL gate now enters resource registration plus grant issuance and restart authentication through a tenant-fixed publisher control for Aphrodite, Veritas, V3 Stage, and V10 Rail. It still proves forced-RLS visibility, immutable mapping conflict, unregistered-resource foreign-key rejection, and recovery of every downstream authority. The digest-pinned MediaMTX/PostgreSQL gate also passes through Aphrodite's thin transcode wrapper and its real worker/output path. Final gates pass 286 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, the full Aphrodite streaming and broadcaster test targets, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict source/spec/consumer typechecks, graph-aware shared/adapter lint, dependency-inclusive shared/adapter builds, direct streaming/broadcaster production bundles, formatting/diff checks, and both real container gates pass.
- Increment 8k completes reusable tenant-fixed publisher credential and
transcode execution entry points; it does not deploy Veritas/V3/Rail ingest or
workers. The four synthetic publications remain
publishing; real non-Aphrodite bytes, ready HLS/DASH ledger state, issued playback grants, decoded Rail playback, deployed tenant compositions, final tenant equivalence, and thefirst-party-liveflip remain open. - Increment 8l moves publisher-edge callback and reconciliation authority behind
the canonical
LiveMediaTenantPublisherEdgeControl. The control validates and fixes one tenant and edge principal at construction, parses every stream identity, creates operate scopes internally, and binds connect, disconnect, provider snapshot validation, and authoritative reconciliation to that tenant. Its optional telemetry writer preserves the established stable publisher/live and disconnected/ended event identities from the durable edge connection and revision. - Aphrodite's former publisher-edge implementation is now an exact thin tenant-#1 constructor wrapper. It retains the default forced-RLS SQL store, default operational telemetry, injected-service telemetry opt-out, principal, clock, request-ID seam, routes, and errors while inheriting all edge behavior from the shared control. Direct canonical tests prove same-stream Veritas/V3 isolation, duplicate telemetry identity, V10 Rail authoritative reconciliation, and invalid fixed authority. The four-tenant PostgreSQL gate now enters every durable publisher observation through a tenant-fixed edge control rather than calling the SQL store mutation directly.
- Increment 8l gates pass all 289 shared live-media tests and 192 passing Aphrodite adapter tests with one intentional skip, including the unchanged publisher-edge store and operational-emission oracles. The full Aphrodite Streaming target, 86 Veritas channel tests, and all 14 V10 Phase A/ consolidation tests pass. Six strict shared/adapter/Streaming/Veritas typechecks, graph-aware shared/adapter lint, dependency-inclusive shared and adapter builds, the direct Streaming production bundle, formatting and diff checks, the digest-pinned four-tenant PostgreSQL gate, and the digest-pinned real MediaMTX/PostgreSQL gate also pass.
- Increment 8l supplies a reusable edge-runtime entry point, not a deployed
Veritas/V3/Rail edge or complete broadcast composition. The synthetic
publications remain
publishing; real non-Aphrodite ingress bytes, ready HLS/DASH, playback grants, decoded Rail playback, tenant equivalence, and thefirst-party-liveflip remain open. - Increment 8m moves the remaining media-publication command/query authority
behind the canonical
LiveMediaTenantMediaPublicationControl. The control validates and fixes one tenant plus its worker, reader, and manager principals at construction, validates every stream/publication identity, generates request and publication identities internally, and binds publish, get, and revoke to that tenant. Its narrow operations port lets product compositions retain the canonical publication service without exposing a runtime tenant, resource, timestamp, or capability override. AphroditeMediaPublicationControlnow inherits publish/get/revoke behavior from that shared control as a tenant-#1 wrapper. Its existing constructor, deterministic clock/random seams, public method shapes, and legacyissuePlaybackGrantbehavior remain compatible; that grant method is marked deprecated and retained only as a transition shim. The current protected viewer path continues to use the separate protocol-awareAphroditePlaybackGrantControl, so the extraction does not create or loosen a second modern grant authority.- Three direct canonical tests drive a real in-process
MediaPublicationServiceand prove same-stream/same-publication-ID Veritas/V3 isolation through ready object ledgers and tenant-local revocation, fixed V10 Rail scopes and caller authority replacement, and invalid fixed-authority rejection. Increment 8m gates pass all 292 shared live-media tests and 192 passing Aphrodite adapter tests with one intentional skip, including the unchanged Aphrodite publication/grant compatibility oracle. The full Aphrodite Streaming target, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests pass. Six strict shared/adapter/Streaming/Veritas typechecks, graph-aware shared/adapter lint, dependency-inclusive shared and adapter builds, the direct Streaming production bundle, formatting and diff checks, the digest-pinned four-tenant PostgreSQL gate, and the digest-pinned real MediaMTX/PostgreSQL publication gate also pass. - Increment 8m supplies reusable tenant-fixed publication orchestration, not a
deployed Veritas/V3/Rail publication worker or a complete non-Aphrodite
broadcast. Its multi-tenant unit evidence uses deterministic packaged-object
metadata rather than real non-Aphrodite media bytes. Ready non-Aphrodite
HLS/DASH, issued playback grants, decoded Rail playback, deployed tenant
compositions, final tenant equivalence, and the
first-party-liveflip remain open. - Increment 8n moves the remaining live-chat command/query authority behind the
canonical
LiveMediaTenantLiveChatControl. The control validates and fixes one tenant plus its presence, system, payment-service, and fanout principals at construction; validates every stream/session/message/participant identity; creates request scopes internally; and binds join, viewer resolution, heartbeat, leave, moderation, messaging, deletion, clearing, presence, expiry, system/tip publication, and event polling to that tenant. Its operational telemetry projection preserves the established stable event identities and never includes message content. AphroditeLiveChatControlis now a thin tenant-#1 compatibility wrapper. It retains the existing constructor, exact Aphrodite error class/name/codes, SQL-backed participant identity, entitlement and moderator policy, content filter, service tuning, routes, socket runtime, and operational telemetry seams. Five direct canonical tests prove same-stream/session/message-key Veritas/V3 isolation over one store, tenant-local moderation, presence and event cursors, fixed V10 Rail system/tip principals, fixed policy scopes, content-free telemetry, invalid authority rejection, and typed denials. The Aphrodite runtime compatibility test additionally proves the wrapper still emits the exact product error instance.- Increment 8n gates pass all 297 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 60 passing Aphrodite Chat tests with one intentional skip, 86 Veritas channel tests, and all 14 V10 Phase A/ consolidation tests. Six strict shared/adapter/Chat/Veritas source, spec, and consumer typechecks, graph-aware shared/adapter/Chat lint, dependency- inclusive shared/adapter/Chat builds, formatting and diff checks, the dedicated real Chat/PostgreSQL policy-store gate, and the four-tenant durable PostgreSQL registry gate also pass.
- Increment 8n supplies reusable tenant-fixed chat orchestration, not deployed
Veritas/V3/Rail chat policies, socket runtimes, hook providers, or a complete
non-Aphrodite broadcast. No real non-Aphrodite chat use or media bytes, ready
HLS/DASH ledger, playback grant, decoded Rail playback, final tenant
equivalence, or
first-party-liveflip is claimed. - Increment 8o moves content-analysis probe, analyze, and teardown authority
behind the canonical
LiveMediaTenantContentAnalysisControl. The control validates and fixes one tenant and one adapter ID at construction, validates every principal/stream/publication/object/operation input, creates the exact operate scope and tenant resource internally, and reconstructs thecontent-analysisrequest so callers cannot replace tenant, adapter, kind, capability, or resource authority. The shared input schema and operations port keep provider, binding, storage, and advisory-policy composition replaceable without duplicating command authority. AphroditeContentAnalysisControlis now a thin tenant-#1 wrapper fixingaphrodite.content-analysis.v1. It retains the exact constructor, input schema/type exports, timing and request-ID seams, publication binding verifier, advisory policy, provider, forced-RLS queue, worker, and Streaming routes. The compatibility oracle supplies attempted Veritas tenant/adapter options and proves the wrapper still fixes Aphrodite before execution.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage providers. Equal stream, publication, operation, request, and idempotency identities reach only the fixed tenant/adapter/provider and binding, retain exact operate scopes, and tear down independently. V10 Rail caller-override attempts, unsafe principals, and malformed fixed tenant/adapter configuration fail before operations access. - Increment 8o gates pass all 300 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict shared/adapter/Streaming/Veritas source, spec, and consumer typechecks, graph-aware shared/adapter/Streaming lint, dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds, formatting/diff checks, and the digest-pinned real MediaMTX/ PostgreSQL/FFmpeg content-analysis gate also pass.
- Increment 8o supplies reusable content-analysis command authority, not a
deployed Veritas/V3/Rail analyzer, binding policy, durable queue, worker, or
real non-Aphrodite analysis. The real gate remains Aphrodite tenant #1. No
non-Aphrodite media bytes, ready HLS/DASH ledger, playback grant, decoded Rail
playback, final tenant equivalence, or
first-party-liveflip is claimed. - Increment 8p moves recording admission, query, and worker execution authority
behind the canonical
LiveMediaTenantRecordingControlandLiveMediaTenantRecordingWorker. Both validate and fix one tenant plus one adapter ID at construction. The control owns the strict input schema, exact operate scope/resource/request, publisher-connection binding check, readiness gate, canonical semantic fingerprint, bounded retry budget, durable queue reservation, and tenant-local operation read. The worker reparses every durable request and rejects a tenant or adapter mismatch before provider execution; its service principal, request identity, clock, and shutdown seam remain composition-owned. AphroditeRecordingControlandAphroditeRecordingWorkerare now thin tenant-#1 wrappers fixingaphrodite.recording.v1. They retain their exact constructors, input schema/type exports, forced-RLS record validation and queue, publisher-connection binding verifier, MediaMTX source authority, retention policy, FFmpeg executor, create-only object store, scheduler, routes, timing/ID seams, and cancellation behavior. The legacyaphroditeRecordingFingerprintnow delegates to the shared canonical fingerprint. Compatibility tests supply attempted Veritas tenant/adapter and parser overrides and prove Aphrodite remains fixed at admission and worker execution.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage recording providers and tenant views over one record map. Equal stream, operation, recording, publisher-connection, request, and idempotency identities remain isolated in queue keys, fingerprints, bindings, worker scopes, provider selection, and results. Caller authority overrides, unsafe principals, malformed fixed authority, and mismatched durable work fail before queue mutation or provider execution. The digest-pinned MediaMTX/PostgreSQL/FFmpeg gate now admits the real Aphrodite capture through the thin control and executes it through the thin worker before independently probing the resulting H.264/AAC MP4 and retaining the existing replay, lease-recovery, fencing, tenant-denial, and teardown evidence. - Increment 8p gates pass all 303 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict shared, adapter, Streaming, and Veritas source, spec, and consumer typechecks; graph-aware shared, adapter, and Streaming lint; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds, formatting/diff checks, and the digest-pinned real MediaMTX/PostgreSQL/FFmpeg recording gate also pass.
- Increment 8p establishes reusable recording command and worker authority, not
deployed Veritas/V3/Rail recording sources, retention policies, durable
stores, workers, or real non-Aphrodite capture. Its multi-tenant evidence uses
in-process providers; the real gate remains Aphrodite tenant #1. No ready
non-Aphrodite HLS/DASH, playback grant, decoded Rail playback, final tenant
equivalence, or
first-party-liveflip is claimed. - Increment 8q moves segment-encryption probe/admission/query, protected-key
delivery, repeat-safe release, and worker execution authority behind the
canonical
LiveMediaTenantSegmentEncryptionControlandLiveMediaTenantSegmentEncryptionWorker. Both validate and fix one tenant and adapter ID at construction. The control owns the strict input schema, exact operate scope/resource/request, static-policy and publication-binding checks, readiness gate, canonical semantic fingerprint, bounded retry budget, durable reservation/read, exact active-succeeded-custody key gate, and signed optional- adapter teardown. Every read and worker claim is reparsed and rejected when its operation/resource/tenant/adapter identity or durable fingerprint differs from the fixed composition, before custody recovery or provider execution. AphroditeSegmentEncryptionControlandAphroditeSegmentEncryptionWorkerare now thin tenant-#1 wrappers fixingaphrodite.segment-encryption.v1. They retain their exact constructors, input schema/type exports, product error class and codes, forced-RLS operation record parser/queue, static AES-128 policy, PKCS#11 custody, key-delivery and release routes, provider, scheduler, and timing/request-ID seams. The legacyaphroditeSegmentEncryptionFingerprintnow delegates to the shared canonical fingerprint. Existing compatibility tests still prove policy-before-binding, exact 128-bit active-custody delivery, releasing/released denial, signed repeat-safe teardown, and tenant-fixed worker scope.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage providers and tenant views over one record map. Equal stream, publication, operation, request, and idempotency identities remain isolated in queue keys, fingerprints, binding checks, worker scopes, provider selection, results, key URIs/bytes, and teardown. V10 Rail caller-authority overrides, unsafe principals, mismatched policy, malformed fixed authority, cross-tenant durable records, and stale fingerprints fail before queue mutation, custody recovery, or provider access. The digest-pinned MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate now admits the real ready Aphrodite HLS publication through the thin control and executes its AES-128 transform through the thin worker before independently decoding H.264/AAC playback. It retains reconstruction replay, exact viewer/key authorization and non-disclosure, sibling denial, lease recovery, stale-writer fencing, RLS tenant denial, source-preserving destructive cleanup, custody shredding, and clean teardown. - Increment 8q gates pass all 306 shared live-media tests, 192 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict shared, adapter, Streaming, and Veritas source/spec/consumer typechecks; graph-aware shared, adapter, and Streaming lint; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds; formatting/diff checks; and the supervised real container/media/ browser gate pass.
- Increment 8q establishes reusable segment-encryption command, key-delivery,
release, and worker authority, not deployed Veritas/V3/Rail key policies,
custody backends, queues, workers, or real non-Aphrodite encryption. Its
multi-tenant evidence uses in-process providers; the real gate remains
Aphrodite tenant #1. CENC, CBCS, external vendor DRM/CDM licensing, ready
non-Aphrodite HLS/DASH, playback grants, decoded Rail playback, final tenant
equivalence, and the
first-party-liveflip remain open. - Increment 8r moves visible-watermark probe/admission/query, repeat-safe
release, and worker execution authority behind the canonical
LiveMediaTenantWatermarkControlandLiveMediaTenantWatermarkWorker. Both validate and fix one tenant and adapter ID at construction. The control owns the strict input schema, exact operate scope/resource/request, policy-derived profile/payload/key references, publication and viewer binding checks, readiness gate, canonical semantic fingerprint, bounded retry budget, durable reservation/read, and signed optional-adapter teardown. Every returned record and worker claim is reparsed and rejected when its operation, resource, tenant, adapter, or fingerprint differs from the fixed composition, before release or provider execution. AphroditeWatermarkControlandAphroditeWatermarkWorkerare now thin tenant-#1 wrappers fixingaphrodite.watermark.v1. They retain their exact constructors, input schema/type exports, Aphrodite operation error class and codes, forced-RLS operation record parser/queue, visible-grid policy, PKCS#11 custody, FFmpeg transformer, binding verifier, routes, scheduler, and timing/request-ID seams. The legacyaphroditeWatermarkFingerprintdelegates to the shared canonical fingerprint. Compatibility tests retain policy- derived admission, durable release timestamps, authenticated worker scope, and the exact Aphrodite invalid-release error contract.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage watermark providers and tenant views over one record map. Equal stream, operation, publication, viewer-session, source-object, request, and idempotency identities remain isolated in queue keys, fingerprints, binding checks, worker scopes, provider selection, results, and teardown. V10 Rail caller-authority overrides, unsafe principals, mismatched policy, malformed fixed authority, cross-tenant durable records, and stale fingerprints fail before queue mutation, release, or provider access. The supervised MediaMTX/PostgreSQL/SoftHSM/FFmpeg gate now admits the real Aphrodite source through the thin control, applies its visible watermark through the thin worker, and performs destructive release through the reconstructed control. It retains real 64-cell extraction and luma-PSNR evidence, restart replay, lease recovery, stale-writer fencing, plaintext token/key non-disclosure, RLS tenant denial, exact output deletion, resurrection denial, and clean teardown. - Increment 8r gates pass all 309 shared live-media tests, 193 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict shared, adapter, Streaming, and Veritas source/spec/consumer typechecks; graph-aware shared, adapter, and Streaming lint; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds; formatting/diff checks; and the supervised real container/media gate pass.
- Increment 8r establishes reusable visible-watermark command, release, and
worker authority, not deployed Veritas/V3/Rail watermark policies, custody
backends, queues, workers, or real non-Aphrodite transforms. Its multi-tenant
evidence uses in-process providers; the real gate remains Aphrodite tenant #1.
The visible-grid profile is not invisible or forensically robust. Ready
non-Aphrodite HLS/DASH, playback grants, decoded Rail playback, final tenant
equivalence, and the
first-party-liveflip remain open. - Increment 8s moves player-grant registration, decoded-media observation,
synchronous provider execution, and release authority behind the canonical
LiveMediaTenantPlayerClientControl. The control validates and fixes one tenant, adapter, and service principal at construction. It reparses the playback grant, active leased viewer session, QoE sample, player request, and every durable queue result. Registration binds tenant, stream, session ID, subject, client instance, protocol, publication, grant, runtime, readiness, lease expiry, and a canonical exact-issuance fingerprint before reservation. Observation admits provider execution only after positive playing-state decoded-frame evidence is durably staged, then requires a matching succeeded record. Release likewise validates the active operation before teardown and requires its matching durable released state. Cast or unknown runtimes remain unsupported no-ops rather than fabricated clients. AphroditePlayerClientControlis now a thin tenant-#1 wrapper fixingaphrodite.player-client.v1and theaphrodite-player-client-serviceprincipal after caller options are spread. It retains its public constructor and operation alias, exact Aphrodite error factory, forced-RLS PostgreSQL operation store/parser, lease and fencing provider, positive-QoE evidence path, browser/native HLS/DASH runtime references, protected-playback composition, and routes. The legacyaphroditePlayerClientFingerprintnow delegates to the shared canonical implementation. An adversarial compatibility case proves runtime-only tenant, adapter, service-principal, parser, and descriptor overrides cannot weaken that wrapper authority, while repeat registration and product error behavior remain compatible.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage player providers and tenant queue views over one record map. Equal stream, publication, session, grant, QoE-event, operation, and request identities remain isolated in queue keys, fingerprints, binding verification, service scopes, provider selection, results, evidence, and release. Cross-tenant grant/session resources, subject mismatches, caller-injected authority, malformed fixed IDs, unsupported cast, wrong durable tenant/adapter records, and stale fingerprints fail before queue mutation or provider execution/teardown. The supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate exercises the reconstructed Aphrodite wrapper from protected-playback grant issuance and registration through positive decoded DASH QoE, synchronous execution, replacement release, durable proof, forced-RLS sibling denial, and final release while retaining the broader real-media, custody, recovery, fencing, and cleanup assertions. - Increment 8s gates pass all 312 shared live-media tests, 194 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Six strict shared, adapter, Streaming, and Veritas source/spec/consumer typechecks; graph-aware shared, adapter, and Streaming lint; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds; formatting/diff checks; and the supervised real container/media/browser gate pass.
- Increment 8s establishes reusable player lifecycle authority, not deployed
Veritas/V3/Rail player providers, durable stores, policies, or decoded client
runtimes. Its multi-tenant evidence uses in-process providers; the real gate
remains Aphrodite tenant #1. Ready non-Aphrodite HLS/DASH, non-Aphrodite
playback grants, decoded Rail playback, final tenant equivalence, and the
first-party-liveflip remain open. - Increment 8t moves active publisher-grant registration, independently
authenticated edge binding, positive runtime-evidence staging, synchronous
provider execution, query, and repeat-safe release behind the canonical
LiveMediaTenantPublisherClientControl. The control validates and fixes one tenant, adapter, and service principal at construction. It reparses the non-revoked, unexpired publisher grant before readiness access; derives the exact resource and operation/grant identity; validates the browser/native runtime/protocol pair; and owns the canonical exact-issuance fingerprint, queue reservation, and durable replay validation. Authenticated binding strictly validates edge/connection identity, exact protocol, and a timestamp that cannot predate issuance while retaining the legacy unregistered-grant no-op. Observation always passes through durable evidence staging so the queue can revalidate independent grant and edge authority even for succeeded replay, then admits execution only after two-sided evidence and requires the matching durable succeeded state. Query and teardown likewise reparse and validate the fixed tenant, stream, adapter, operation/grant identity, and fingerprint before returning or invoking a provider. AphroditePublisherClientControlis now a thin tenant-#1 wrapper fixingaphrodite.publisher-client.v1, theaphrodite-publisher-client-serviceprincipal, product error factory, record parser, and descriptor after caller options are spread. It retains its public constructor and operation alias, exact Aphrodite errors, forced-RLS PostgreSQL queue, active-grant and authenticated MediaMTX edge binding, durable two-sided evidence, leasing/fencing provider, browser-WHIP and native-SRT runtime references, runtime composition, Streaming ingest routes, and Broadcaster store integration. The legacyaphroditePublisherClientFingerprintnow delegates to the shared canonical implementation. An adversarial compatibility case proves runtime-only tenant, adapter, principal, parser, descriptor, and error-factory overrides cannot weaken the wrapper while repeat registration, active-grant revalidation, product errors, and repeat-safe release remain compatible.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage publisher providers and tenant queue views over one record map. Equal stream, grant, client, edge, connection, sample, operation, and request identities remain isolated in queue keys, fingerprints, service scopes, binding verification, provider selection, evidence, results, query, and teardown. Cross-tenant, revoked, and expired grants; malformed fixed IDs and edge input; browser/SRT mismatch; wrong durable tenant/adapter records; and stale fingerprints fail before queue mutation, binding, execution, query, or teardown. The supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate exercises the reconstructed Aphrodite wrapper through native-SRT registration, independently authenticated exact edge binding, positive client/ingress evidence, synchronous execution, process reconstruction/replay, forced-RLS sibling denial, and release. The same gate retains browser-WHIP publication and the wider encrypted/watermarked/protected-media, recovery, fencing, and cleanup assertions. - Increment 8t gates pass all 315 shared live-media tests, 195 passing Aphrodite adapter tests with one intentional skip, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Broadcaster tests, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Eight strict shared, adapter, Streaming, Broadcaster, Veritas, and Phase A source, spec, and consumer typechecks; graph-aware lint for all six projects; dependency-inclusive shared (+6), adapter (+13), Streaming (+14), and Broadcaster (+16) builds; formatting/diff checks; and the supervised real container/media/browser gate pass.
- Increment 8t establishes reusable publisher lifecycle authority, not deployed
Veritas/V3/Rail publisher providers, durable stores, grant/edge integrations,
or browser/native client runtimes. Its multi-tenant evidence uses in-process
providers; the real gate remains Aphrodite tenant #1. Ready non-Aphrodite
HLS/DASH, playback grants, decoded Rail playback, final tenant equivalence,
and the
first-party-liveflip remain open. - Increment 8u moves host registration, one-use invitation exchange, signaling
authority, reciprocal transport-evidence staging, synchronous provider
execution, query, and repeat-safe release behind the canonical
LiveMediaTenantRemoteGuestControl. The control validates and fixes one tenant, adapter, service principal, and credential-free secure WebSocket base at construction. It generates operation/session identities and raw capabilities internally; owns the compatible canonical semantic registration and exact exchange fingerprints, readiness scope, digest-only queue boundary, role-correct two-sided evidence gate, and durable success/release validation; fixes signaling claims to its tenant; and reparses every returned record to reject a wrong tenant, stream, adapter, operation/session/grant/client identity, or fingerprint before returning a descriptor or invoking downstream authority. AphroditeRemoteGuestControlis now a thin tenant-#1 wrapper fixingaphrodite.remote-guest.v1, theaphrodite-remote-guest-serviceprincipal, product error factory, record parser, and descriptor after caller options are spread. It retains its public constructor and session aliases, exact Aphrodite error class/codes, forced-RLS PostgreSQL queue, active publisher grant binding, database-clock lifecycle, one-use invitation, ticket, and guest lease digest rotation, WebSocket hub, leasing/fencing provider, Broadcaster routes, and two-browser WebRTC runtime. The legacy registration and exchange fingerprints now delegate to their shared canonical implementations. An adversarial compatibility case proves runtime-only tenant, adapter, principal, parser, descriptor, and error-factory overrides cannot weaken the wrapper while released-registration replay still emits the exact product error.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage remote-guest providers and tenant queue views over one record map. Equal stream, grant, operation, session, host/guest client, invitation, signaling, evidence, and request identities remain isolated in queue keys, fingerprints, service scopes, binding verification, provider selection, signaling claims/events, reciprocal proof, results, query, and teardown. Safe registration replay rotates raw provision capabilities without replacing the durable operation. Malformed fixed authority, role-mismatched evidence, cross-tenant signaling claims, wrong durable tenant/adapter records, and stale fingerprints fail before the protected access. Two single-worker Chromium scenarios independently prove reciprocal audio/video and matching SSRC evidence across two contexts, third-participant denial, credential containment, accessibility, mobile/ reduced-motion behavior, and ordered teardown. The supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate exercises the reconstructed Aphrodite wrapper through registration replay and capability rotation, invitation exchange, exact signaling, reciprocal proof, restart replay, durable SDP/ICE/raw-secret non-disclosure, forced-RLS sibling denial, lease recovery and stale fencing, and repeat-safe release while retaining the wider protected-media assertions. - Increment 8u gates pass all 318 shared live-media tests, 196 passing Aphrodite adapter tests with one intentional skip, 6 Aphrodite remote-guest compatibility tests, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Broadcaster tests, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Eight strict shared, adapter, Streaming, Broadcaster, Veritas, and Phase A source/spec/consumer typechecks; graph-aware lint for all seven affected and guard projects; dependency- inclusive shared (+6), adapter (+13), remote-guest compatibility (+7), Streaming (+14), and Broadcaster (+16) builds; formatting/diff checks; the two focused browser scenarios; and the supervised real container/media/browser gate pass.
- Increment 8u establishes reusable remote-guest lifecycle and signaling
authority, not deployed Veritas/V3/Rail remote-guest providers, durable
stores, publisher-grant integrations, signaling gateways, or browser/native
runtimes. Its multi-tenant evidence uses in-process providers; the real gates
remain Aphrodite tenant #1. SFU/MCU, TURN availability, multi-node signaling,
ready non-Aphrodite HLS/DASH, playback grants, decoded Rail playback, final
tenant equivalence, and the
first-party-liveflip remain open. - Increment 8v moves protected-browser-player registration, compatible
descriptor/client admission, privacy-bounded render-evidence observation,
synchronous provider execution, and repeat-safe release behind the canonical
LiveMediaTenantImmersiveSessionControl. The control validates and fixes one tenant, immersive adapter, and service principal at construction. It reparses the succeeded player record/request and canonical player fingerprint; binds its exact tenant, stream, viewer session, grant/operation, publication, browser client, and unexpired lifecycle; rejects non-browser immersive runtimes or descriptors outside the measured client capabilities; owns the compatible canonical immersive fingerprint and readiness scope; and reparses every reserved, staged, succeeded, and released record. Render evidence must match the registered runtime, projection, field of view, stereo layout, source geometry, and audio format before queue mutation. Provider results and teardown responses must name the fixed tenant/resource, adapter, kind, and operation before the matching durable terminal record is accepted. AphroditeImmersiveSessionControlis now a thin tenant-#1 wrapper fixingaphrodite.immersive.v1and theaphrodite-immersive-session-serviceprincipal after caller options are spread. It retains its public constructor and operation alias, exact Aphrodite error class/codes, forced-RLS PostgreSQL player and immersive stores, database-clock lifecycle, leasing/fencing provider, flat/cardboard/WebXR references, Viewer composition/routes, and timing/request-ID seams. The legacyaphroditeImmersiveSessionFingerprintdelegates to the shared canonical implementation. An adversarial compatibility case proves runtime-only tenant, adapter, principal, parser, descriptor, and error-factory overrides cannot weaken the wrapper while wrong-operation and released-registration errors retain product identity.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage immersive providers and tenant queue views over one record map. Equal stream, publication, viewer session, grant/operation, client, evidence, and request identities remain isolated in protected-player lookup, queue keys, fingerprints, service scopes, binding verification, provider selection, proof, result, and teardown. Malformed fixed IDs, cross-tenant and stale-fingerprint player records, unsupported native runtimes, incompatible capabilities, mismatched render evidence, wrong durable adapters, and stale immersive fingerprints fail before queue mutation, execution, or teardown. Two single-worker Chromium cases independently prove real 360-degree HLS device-orientation and 180-degree DASH pointer rendering, privacy-bounded proof, accessibility, mobile/reduced-motion behavior, credential containment, and ordered release. The supervised MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate exercises the reconstructed Aphrodite wrapper from the exact succeeded protected player through registration, bounded render/audio/orientation evidence, provider proof, restart replay, recovery and stale fencing, forced-RLS sibling denial, and release while retaining the wider protected-media assertions. - Increment 8v gates pass all 321 shared live-media tests, 197 passing Aphrodite adapter tests with one intentional skip, the complete Aphrodite Viewer test target, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Eight strict shared, adapter, Viewer, Streaming, Veritas, and Phase A source/spec/consumer typechecks; graph-aware lint for all six affected/guard projects; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds; the direct Viewer production build; formatting/diff checks; the two focused browser scenarios; and the supervised real container, media, and browser gate pass.
- Increment 8v establishes reusable immersive lifecycle authority, not deployed
Veritas/V3/Rail immersive providers, durable stores, protected-player
integrations, or client runtimes. Its multi-tenant evidence uses in-process
providers and its real gates remain Aphrodite tenant #1. Native OpenXR/
visionOS and real-headset WebXR conformance, ready non-Aphrodite HLS/DASH,
playback grants, decoded Rail playback, final tenant equivalence, and the
first-party-liveflip remain open. - Increment 8w moves exact browser-publisher composition registration, bounded
render-evidence admission, synchronous provider execution, query,
publisher-cascade release, and repeat-safe direct release behind the canonical
LiveMediaTenantCompositionControl. The control validates and fixes one tenant, composition adapter, publisher-client adapter, and service principal at construction. It reparses the succeeded publisher record/request and canonical publisher fingerprint; binds its exact tenant, stream, grant/operation, adapter, browser/WebRTC client, and unexpired lifecycle; owns the compatible one-to-four-source browser registration schema, canonical composition fingerprint, and operate scope; and reparses every reserved, staged, queried, publisher-selected, succeeded, and released record. Render evidence must match the registered composition, client, runtime, layout, ordered sources, and output before queue mutation. Provider results and teardown responses must name the fixed tenant/resource, adapter, kind, operation, and provider reference before the matching durable terminal record is accepted. AphroditeCompositionControlis now a thin tenant-#1 wrapper fixingaphrodite.composition.v1,aphrodite.publisher-client.v1, and theaphrodite-composition-serviceprincipal after caller options are spread. It retains its public constructor, registration schema/type exports, exact Aphrodite error class/codes, forced-RLS PostgreSQL composition and publisher stores, independent positive-ingress edge join, database-clock lifecycle, leasing/fencing provider, Broadcaster composition/routes, timing/request-ID seams, and Canvas/Web Audio runtime. The legacyaphroditeCompositionFingerprintdelegates to the shared canonical implementation. An adversarial compatibility case proves runtime-only tenant, composition/publisher adapters, principal, parser, descriptor, and error-factory overrides cannot weaken the wrapper while released-registration replay retains product error identity.- Three direct canonical tests drive one real
LiveMediaOptionalAdapterServicewith independent in-process Veritas and V3 Stage composition providers and tenant queue views over one record map. Equal stream, publisher grant, operation/composition, client, evidence, and request identities remain isolated in publisher lookup, queue keys, fingerprints, service scopes, binding verification, provider selection, proof, result, query, and teardown. Malformed fixed IDs, cross-tenant and stale-fingerprint publisher records, inactive or expired publishers, mismatched render evidence, wrong durable adapters, stale composition fingerprints, and wrong provider or teardown identities fail before protected queue mutation, execution, or durable acceptance. Three single-worker Chromium cases independently prove real two-source Canvas composition, Web Audio mixing, WHIP publication, positive MediaMTX ingress, privacy-bounded evidence, accessibility, mobile/reduced- motion behavior, authorization denial, and ownership-correct teardown. The supervised MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate exercises the reconstructed Aphrodite wrapper from the exact succeeded browser publisher through registration, independently joined edge proof, render/audio evidence, provider result, restart replay, abandoned-lease recovery, stale fencing, forced-RLS sibling denial, and repeat-safe release while retaining the wider protected-media assertions. - Increment 8w gates pass all 324 shared live-media tests, 198 passing Aphrodite adapter tests with one intentional skip, the complete Aphrodite Broadcaster and Streaming test targets, 86 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Eight strict shared, adapter, Broadcaster, Streaming, Veritas, and Phase A source/spec/consumer typechecks; graph-aware lint for all six affected/guard projects; dependency-inclusive shared (+6), adapter (+13), Streaming (+14), and Broadcaster (+16) builds; formatting/diff checks; the three focused browser scenarios; and the supervised real container, media, and browser gate pass.
- Increment 8w establishes reusable browser-composition lifecycle authority, not
deployed Veritas/V3/Rail composition providers, durable stores, publisher
integrations, or client runtimes. Its multi-tenant evidence uses in-process
providers and its real gates remain Aphrodite tenant #1. Custom layouts,
transitions/switching, GPU/OBS/native or distributed mixing, ready
non-Aphrodite HLS/DASH, playback grants, decoded Rail playback, final tenant
equivalence, and the
first-party-liveflip remain open. - Increment 8x moves product-supplied entitlement-to-viewer-lease-to-playback-
grant orchestration, authenticated heartbeat/leave/immersive mutations,
optional player/immersive lifecycle sequencing, exact presence projection, and
compensating joined-lease cleanup behind the canonical
LiveMediaTenantProtectedPlaybackControl. The control validates and fixes one tenant, player adapter, immersive adapter, and identity-denial result at construction. It parses bounded join inputs and generic product entitlement decisions; validates the exact tenant, stream, subject, decision, timestamps, idempotency key, client, active status, lease token, and presence resource returned by viewer-session authority; and validates exact tenant, stream, publication, subject, session, lifetime ordering, and requested-protocol availability on each issued playback grant before optional client access. Player and immersive descriptors must retain fixed adapter, equal grant and operation identities, compatible runtime/protocol or render geometry, and transition-correct status. Authenticated heartbeats, terminal leaves, and presence cannot return a sibling resource. Grant or optional-lifecycle failure after a valid join triggers the compatible short-lease compensation. AphroditeProtectedPlaybackControlis now a thin tenant-#1 wrapper fixing theaphroditetenant,aphrodite.player-client.v1andaphrodite.immersive.v1adapters, and the compatibleidentity_or_stream_not_foundidentity denial. It retains its positional constructor; public result, input, mutation, and lifecycle types; all seven issue/session/immersive/presence methods; exact product entitlement reasons and SQL policy; external-user-to-viewer principal resolver; shared-backed viewer-session and playback-grant controls; optional player and immersive providers; Viewer routes/runtime; and Streaming real-edge composition. An adversarial compatibility case proves the positional wrapper rejects a sibling-tenant grant or player adapter before client access and still invokes the exact compensating viewer leave.- Three direct canonical tests compose independent Veritas and V3 Stage entitlement policies, principal resolvers, viewer-session authorities, playback issuers, and player/immersive lifecycle ports with equal user, stream, publication, decision, session, grant, QoE, and render-evidence identities. They prove isolated issue, heartbeat, immersive registration and evidence, leave, lifecycle release, and presence results. Malformed entitlement time bounds, cross-tenant session/grant authority, wrong player or immersive adapters, missing principals, mismatched heartbeat/presence, downstream-access ordering, compensation, and unconfigured immersive lifecycles fail closed. The real gate separately exercises the wrapper with its production-shaped SQL, canonical controls, optional providers, and media path.
- Increment 8x gates pass all 327 shared live-media tests, 199 passing Aphrodite adapter tests with one intentional skip, the complete Aphrodite Viewer target, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 86 Veritas channel tests, and all 14 V10 Phase A/ consolidation tests. Strict shared, adapter, Viewer, Streaming, Veritas, and Phase A source/spec/consumer typechecks; graph-aware lint for all six affected and guard projects; dependency-inclusive shared (+6), adapter (+13), and Streaming (+14) builds; the direct Viewer production build; formatting/diff checks; 12 single-worker Chromium HLS/DASH player and immersive scenarios; and the supervised real container/media/browser gate pass. The real gate traverses SQL entitlement, the exact leased viewer session and protected grant, player registration and decoded QoE, immersive registration and render evidence, restart/recovery and forced-RLS isolation, and final release through the reconstructed Aphrodite wrapper while retaining the wider protected-media assertions.
- Increment 8x establishes reusable protected-playback orchestration, not shared
product entitlement or identity policy and not deployed Veritas/V3/Rail
policies, issuers, sessions, stores, providers, or client runtimes. Its direct
multi-tenant evidence uses in-process ports and its real gate remains
Aphrodite tenant #1. Ready non-Aphrodite HLS/DASH, playback grants, decoded
Rail playback, final tenant equivalence, and the
first-party-liveflip remain open. - Increment 8y resolves a cross-tenant edge-identity gap found while following
the Veritas rehearsal seam toward a real provider. The durable shared stores
consistently key authority by tenant and stream UUID, but the MediaMTX path
adapter formerly accepted only a bare UUID and supplied its tenant from
constructor configuration. Two tenants using the same valid stream UUID would
therefore name the same edge path before SQL isolation could help. The
canonical root contract now owns a versioned
live-media.v1/<tenant>/<stream UUID>codec with strict parse and tenant-boundary resolution.MediaMtxEdgeProvideruses canonical paths by default, ignores unmanaged and sibling-tenant paths, and treats malformed paths inside its owned namespace as provider-protocol failure rather than guessing. Bare UUID discovery is available only through the explicitlegacy-stream-idmode. - Aphrodite's current production, pipeline, browser-test-server, and real-edge
provider compositions select
legacy-stream-idexplicitly, preserving tenant #1 behavior while its MediaMTX publisher URLs remain bare UUIDs. Its external authentication and publish-lifecycle callback schemas dual-read an exact canonical Aphrodite resource path and the legacy UUID, normalize both to the same stream authority, and reject a canonical Veritas path carrying the same UUID before grant lookup or publisher-edge mutation. This is a bounded migration seam, not a claim that the deployed Aphrodite edge has switched path formats. - The Veritas production-test stream, ingest request, and receipt contracts are
versioned to
.2. A product schedule source such assynthetic-bars-1is no longer misrepresented as a shared stream ID: the stream spec carries a separate UUID resource identity, the request derives the exactveritasresource and canonical media path, and the receipt must return both bindings. The receipt also supplies a validated publication UUID, and its ordered HLS and DASH URLs must resolve to the exact canonical publication object prefix; an arbitrary test-host manifest with a plausible suffix is insufficient. Rehearsal admission rechecks program/source/resource/path/byte/time authority before returning the still-unpublishable result. - Adversarial tests prove canonical codec round-trip, rejection of implicit legacy and malformed owned paths, explicit legacy compatibility, equal stream UUID sibling filtering in MediaMTX discovery, and Aphrodite rejection of a canonical sibling tenant before state mutation. Veritas tests reject malformed resource IDs, cross-tenant/resource/media-path receipts, publication IDs whose URLs retain another publication prefix, and protocol/host/credential/query/ path substitutions. All 328 shared live-media tests, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 92 Veritas channel tests, and all 14 V10 Phase A/consolidation tests pass. Shared source and spec, Streaming, and Veritas typechecks; graph-aware lint for all three affected projects; dependency-inclusive shared (+6) and Streaming (+14) builds; formatting/diff and adversarial stub scans; and the supervised digest-pinned MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium test also pass. The supervised gate retains real ingest, protected playback, lifecycle, persistence, fencing, isolation, and teardown coverage through Aphrodite's explicit legacy mode.
- Increment 8y establishes collision-free edge naming and exact Veritas
rehearsal identity contracts. It does not deploy a Veritas, V3 Stage, or Rail
MediaMTX publisher; create their ready HLS/DASH publications or playback
grants; decode Veritas media in the Rail; finish tenant equivalence; migrate
Aphrodite publishers to canonical paths; or flip
first-party-live. - Increment 8z moves the durable job-to-transcode-to-package-to-publish worker
assembly behind the server-only
createLiveMediaPipelineRuntimeboundary. A product host now supplies a fixed tenant, durable job and publication stores, execution/packaging/object-store adapters, and worker configuration; shared code alone constructs the job service, transcode execution service, publication service, attempt executor, and fenced worker. Tenant authority is parsed once and applied after caller worker options. Aphrodite's production pipeline and both real-gate process compositions use this factory while retaining Aphrodite controls and deployment adapters. - Direct shared tests execute the same factory for Aphrodite, Veritas, and V3 Stage over shared in-memory stores, using the same stream UUID and idempotency key. Each tenant reaches its own ready HLS/DASH publication and canonical immutable object prefix. An adversarial caller cannot replace the fixed Veritas tenant through worker options, and a relative server output root fails construction.
- The supervised real gate publishes that same stream UUID simultaneously on
Aphrodite's explicit legacy path and Veritas's canonical
live-media.v1/veritas/<stream UUID>path. Independent MediaMTX providers see only their configured tenant, the canonical Veritas HLS edge output decodes, and the shared SQL registry durably binds the Veritas resource. Shared SQL job/publication stores and the generic runtime then read the live canonical RTSP source, run the real Neith/FFmpeg H.264/AAC transcode, create and publish HLS plus DASH, persist a ready publication under the Veritas tenant, and independently ffprobe both stored manifests for decoded audio, video, dimensions, and positive duration. - Increment 8z gates pass all 330 shared live-media tests, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 92 Veritas channel tests, and all 14 Phase A/consolidation tests. Strict source/spec and consumer typechecks, graph-aware lint, dependency-inclusive shared and Streaming builds, formatting/diff checks, and the supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate pass.
- This proves one reusable production-shaped pipeline assembly and a real
canonical Veritas ingest-to-ready-media path. It does not yet connect the
Veritas rehearsal byte port to this runtime, deploy durable Veritas publisher
grants, issue Veritas viewer/playback authority, decode the result in Rail,
compose V3 Stage production runtime, migrate Aphrodite publishing to canonical
paths, complete tenant equivalence, or flip
first-party-live. - Increment 8aa connects the audited Veritas rehearsal byte port to that shared
runtime without widening it into a product upload API. The root contract now
defines a strict test MPEG-TS request/result and a 64-MiB ceiling. The
server-only
LiveMediaTestIngestRuntimefixes one tenant, admits only one-MiB-or-smaller non-empty chunks, writes a create-only temporary object, verifies exact declared length and SHA-256, fsyncs it, and retains one read-only content-addressed input under the canonical tenant/stream directory. Replays verify that immutable object and reuse the durable job and publication. Construction rejects a relative input root or pipeline-tenant mismatch; request tenant mismatch fails before consuming bytes; partial or corrupt input is removed; and a non-isolated tenant queue fails explicitly instead of returning another job's result. VeritasProductionSharedMediaTestIngestis a thin tenant-#2 adapter over that port. It reparses the exact v2 rehearsal request, binds the canonical Veritas resource and edge path, derives a deterministic job idempotency key, fixes a bounded H.264/AAC 360p rendition, and accepts only exact ready HLS/DASH object keys beneath a credential-free HTTPS.testor localhost origin. The existing rehearsal pipeline consumes the adapter unchanged and returns a deep-frozen v2 receipt while HG-3 andfirst-party-liveremain closed.- The supervised real-media gate now also generates a two-second MPEG-TS test pattern with FFmpeg, streams those actual bytes through the production rehearsal pipeline and shared SQL-backed Veritas job/publication runtime, runs the real Neith/FFmpeg transcode and HLS/DASH publication path, then independently ffprobes both durable manifests for H.264/AAC, 640x360 video, and positive duration. The simultaneous canonical Veritas RTSP publisher coverage from increment 8z remains in the same gate.
- Increment 8aa gates pass all 332 shared live-media tests, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 94 Veritas channel tests, and all 14 Phase A/consolidation tests. Strict shared, Streaming, and Veritas typechecks; graph-aware lint for those projects and Phase A; dependency-inclusive shared and Streaming builds; a frozen-lockfile filtered install; formatting/diff and source-stub checks; and the supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate pass.
- This closes only the rehearsal-to-runtime byte wiring. The bridge is
synchronous and test-only and requires an isolated tenant queue. A deployed
long-running Veritas ingest/scheduler and durable publisher-grant service,
Veritas viewer session and playback grants, decoded Rail playback, V3 Stage
production composition, Aphrodite canonical-path migration, final tenant
equivalence, and the
first-party-liveflip remain open. - Increment 8ab exposes the injected
LiveMediaTenantPublisherGrantControlcontract from the canonical root while keeping its credential service and SQL stores server-only.VeritasProductionPublisherGrantControlis the tenant-#2 product composition: it fixes tenantveritas, owner productveritas, and external identityv1.veritas-liveafter spreading caller options. Product callers can therefore provide only an authenticated principal and stream UUID; create/manage scopes, exact resource construction, registry registration, and grant issue, authenticate, rotate, and revoke delegation stay canonical. - Direct Veritas tests exercise every operation and exact scope/resource/mapping projection. An adversarial caller that casts forbidden tenant, owner, or external-mapping options cannot widen the control, and malformed stream identity fails before registration or grant issuance.
- The supervised real-media gate no longer creates the Veritas credential in a
memory store. It issues through the product control into the shared forced-RLS
PostgreSQL resource registry and publisher-grant store, reconstructs the
control and SQL store before use, rejects an unknown valid-shaped secret, and
lets MediaMTX authenticate a real FFmpeg SRT publisher only on the canonical
live-media.v1/veritas/<stream UUID>path. The resulting edge HLS decodes as H.264 at the declared dimensions and continues into the existing real Veritas transcode/publication and rehearsal gates. After the database client is reconstructed, a newly composed Veritas control authenticates the same persisted grant and exact resource. - Increment 8ab gates pass all 332 shared live-media tests, 108 passing Aphrodite Streaming tests with one intentional real-edge skip, 96 Veritas channel tests, and all 14 V10 Phase A/consolidation tests. Strict shared, Streaming, Veritas, and Phase A typechecks; graph-aware lint; dependency- inclusive shared and Streaming builds; a frozen-lockfile filtered install; formatting/diff checks; and the supervised real MediaMTX/PostgreSQL/SoftHSM/FFmpeg/Chromium gate pass.
- This closes durable Veritas publisher-grant composition and real canonical
edge authentication at the code and local release-gate boundary. A deployed
long-running Veritas publisher/scheduler host, viewer-session and playback
grants, decoded Rail playback, V3 Stage production composition, Aphrodite
canonical-path migration, final tenant equivalence, HG-3, and the
first-party-liveflip remain open. - Increment 8ac adds the matching Veritas tenant-fixed viewer-session,
playback-grant, and protected-playback controls. Fixed tenant, service
principals,
veritas.player-client.v1,veritas.immersive.v1, and bounded identity denial are applied after every injected option; direct hostile-option tests and the real gate exercise the resulting authority without creating a V10-owned media stack. - The Rail's
FirstPartyLiveVideoGatecan now be constructed with one explicit shared-media authority for the exact HLS/DASH set while its exported default remains fail-closed. Channel registration, lane admission, and the web panel share that status. The panel mounts only the canonical surface from the narrow@oshun/live-media/browser/playerentry and requires the playback resolver's authority ID plus returned tenant, stream, protocol, API base, and manifest to match the selected source exactly, without bringing server-only controls or unrelated browser adapters into the Rail boundary. - The supervised real-media gate carries generated MPEG-TS rehearsal bytes
through the Veritas product pipeline into a durable SQL publication, issues a
signed viewer-bound grant through the Veritas composition, and drives the
actual Rail panel in Playwright-controlled Chromium for both HLS and DASH.
Success requires explicit start, positive decoded frames, a successful
heartbeat, persisted presence/QoE, credential-free DOM, no unexpected
browser/media failures, lane release, zero presence, and immediate
VIEWER_SESSION_INACTIVEdenial for the former token. Browser cancellation of an obsolete adaptive segment is bounded to the exact issued publication directory and is not treated as an origin failure. - This closes a local product-composed Veritas ingest-to-decoded-Rail slice, not
a deployment. The real gate's player lifecycle is intentionally in-memory; the
default Rail composition is still closed, and no durable Veritas player
adapter, playback-route host, long-running scheduler, V3 composition,
Aphrodite canonical migration, final tenant-equivalence result, HG-3, or
production
first-party-liveflip is claimed. The RB.3 parent and equivalence test checkboxes therefore remain open. - Increment 8ad removes Aphrodite's production
legacy-stream-idedge mode. Broadcaster WHIP and native-SRT provisioning expose one exact canonicallive-media.v1/aphrodite/<stream UUID>path; browser authorization is fenced to the full tenant/resource WHIP suffix, and the TypeScript/Rust native bridge validates and sends that path without putting credentials on argv. Production reconciliation, lifecycle hooks, pipeline recording authority, and RTSP source resolution now use the same namespace. The distinct legacy RTMP and lifecycle callback body shapes remain compatibility inputs, while a bare UUID MediaMTXpathfails before durable grant lookup. - Unit and browser adversarial coverage rejects bare paths, equal-UUID sibling tenants, mismatched native paths, and escaped WHIP sessions. The supervised MediaMTX gate additionally rejects a valid Aphrodite grant presented on a bare SRT path, then carries Aphrodite and equal-UUID Veritas publishers through canonical tenant-qualified SRT/WHIP, HLS, RTSP recording/transcode, protected playback, and teardown on the same edge. Affected shared, Aphrodite adapter, Streaming, and Broadcaster tests; four strict typechecks and lints; the Rust native publisher tests/build; dependency-inclusive builds; the 19-scenario single-worker Chromium gate; formatting/diff checks; and the supervised real gate pass.
- This completes Aphrodite's canonical edge-path migration at the code and local
release-gate boundary. It does not claim a deployed scheduler, durable Veritas
player host, V3 Stage production composition, final tenant equivalence, HG-3,
or the production
first-party-liveflip. RB.3 and its equivalence-test checkbox remain open. - Increment 8ae adds V3 Stage's tenant-#3 production authority composition in
@oshun/v10-rail-channel-stage. The product wrappers fix tenantv3-stage, pipeline/viewer/playback service principals, publisher owner andv3.stage:<stream UUID>external-resource mapping,v3-stage.player-client.v1,v3-stage.immersive.v1, and bounded identity denial after all injected options. Equal stream, job, publication, entitlement, and viewer-session identities remain isolated from a sibling Veritas composition through real shared controls; hostile tenant, principal, product, mapper, adapter, and denial options cannot weaken Stage authority. - The complete Stage unit suite, strict typecheck, lint, dependency-inclusive
build, Streaming regression checks, frozen-lockfile validation, formatting/
diff checks, and supervised real PostgreSQL/MediaMTX gate pass. The real gate
persists the equal stream UUID for V3 Stage and Veritas, resolves the exact
Stage product mapping, authenticates only the Stage grant in its tenant, and
proves reciprocal secret denial before revocation. This closes the missing V3
Stage tenant-fixed shared-media control composition at the code boundary. It
does not create a rendered Stage artifact or catalog row, bind the existing
cook to an Unreal renderer or durable catalog, or deploy a long-running
scheduler, publisher, or playback host. Final tenant equivalence and the
production
first-party-liveflip remain open. - Increment 8af supplies the missing Stage cook-to-immutable-delivery boundary
without creating a second media stack. The shared media-object MIME schema is
narrowly extended for progressive WebM, paired MP4/MP3/Ogg audio, and
JPEG/PNG/WebP/AVIF artwork, while the canonical root exposes only the
create-only object-store port type.
V3StageImmutableDeliveryAdapterfixes keys underlive-media.v1/v3-stage/catalog/v1, applies role-specific byte ceilings and immutable caching, and treats only an exact stored object as an idempotent replay. It rechecks storage, then fetches the credential-free exact HTTPS object with redirects disabled and requires matching HTTP status, content type, length, and SHA-256 before a catalog receipt can become usable.FfprobeStageStoredMediaProbewrites only to a private transient directory, invokes ffprobe without a shell, and requires a positive-duration decoded video/audio stream or positive artwork dimensions before returning. - Adversarial tests cover origin credentials, object-path escape, changed bytes
at one immutable key, role/MIME substitution, and exact replay. A full cook
contract test binds all three roles. The Streaming release gate generates real
H.264/AAC MP4, AAC M4A, and PNG bytes with FFmpeg, persists them through the
canonical local create-only store, retrieves their exact origin bytes, decodes
all three with real ffprobe, and publishes only to an in-memory test catalog.
This closes immutable storage and delivery verification, not a V3 render: no
recorded V3 candidate, Unreal render, production catalog row, durable catalog
writer, scheduler/publisher/player host, final tenant equivalence, or
first-party-liveflip is claimed. - Increment 8ag supplies the missing authoritative V3 release-evidence adapter
for the Stage cook through the dedicated
@oshun/v10-rail-channel-stage/releaseentry point, keeping its V3 authoring/export dependencies out of the browser-facing channel root.V3StageRecordedReleaseGateAdapterconsumes the actual Saraswati authoring-editor and V3 concert-export types through an injected repository, then fixes the returned bundle to the exact Stage item, version, and concert. Recorded readiness requires every authoring gate, the published Sequencer receipt, full provenance attachment, and GA cadence to agree. A ready export must be fresh and retain a unique canonical proof plus matching proof verdict for every non-human gate; wrong subject/type, duplicate, detached, expired, future, stale, or contradictory evidence fails closed. Suites that name human signoff additionally require the exact fresh promotion and its canonicalhuman_approvalproof, bound to the artifact, content hash, signer, decision, and evidence. Declared drills always project as blocked. - Contract coverage uses the real recorded Saraswati editor-state builder and
exercises exact mapping, drill denial, item/version/concert substitution,
stale export reports, proof substitution, missing/hostile human promotion, and
forged ready authoring state. This closes the release port, not its
deployment: no durable candidate repository, Calliope-plan projection, Unreal
renderer, production catalog row/writer, scheduler/publisher/player host,
final tenant equivalence, or
first-party-liveflip is claimed. - Increment 8ah supplies the durable V3/Calliope cook source without turning
either system's design state into playable media. The canonical OSHUN
PostgreSQL schema now carries immutable candidate revisions with an exact
projection SHA-256 and a partial unique index admitting only one current
readyversion.SqlV3StageCookCandidateRepositorytransactionally publishes increasing versions, accepts only an exact idempotent replay, supersedes the prior row, makes withdrawal terminal for that version, bounds cook reads, and rejects changed hashes or indexed/payload identity disagreement. - The projection reuses the owning V3 and Calliope schemas. It requires a
recording-authorized concert; one exact V3 persona, setlist, duration, and
track inventory; a bijective title-preserving Calliope-slot/V3-track join;
matching Calliope artist/concept/setlist/camera/venue identities; and a
programming anchor present in the selected setlist, camera plan, and VOD
package. Energy, section, and perspective derive from those real plan values;
numeric cut density requires a separately cited editorial measurement because
Calliope expresses cadence only as prose. Unit/adversarial coverage and a
disposable real-PostgreSQL migration/restart/supersession/withdrawal gate
pass. This closes the durable candidate and Calliope projection code boundary,
not content deployment: no candidate row, Unreal render, durable catalog row,
scheduler/publisher/player host, final equivalence, or
first-party-liveflip is claimed. - Increment 8ai supplies the durable rendered-catalog writer and playback reader
over the canonical OSHUN PostgreSQL client. Migration
20260721230000_v10_stage_rendered_catalogstores immutable versioned Stage items, their canonical SHA-256, indexed artist/concert identity, publication time, and explicit retirement evidence. Database constraints, an update trigger, and a partial unique index freeze item identity/JSON, permit only an active-to-superseded/withdrawn transition, and admit only one active revision per item. SqlV3StageRenderedCatalogRepositorytransactionally publishes monotonically increasing versions, accepts only an exact active replay, supersedes the previous row, and treats withdrawal as terminal. Bounded due-item reads admit active rows only, rebind all indexed identities, recompute the canonical item hash, reject duplicate active ids, and clone validated payloads. Focused adversarial tests and a disposable full-migration PostgreSQL gate prove restart reads, direct hash/identity mutation rejection, concurrent exact retries, supersession, withdrawal, and resurrection denial. This closes the durable catalog code boundary only: no row is seeded and no Unreal render, rendered artifact, deployed host, final equivalence, orfirst-party-liveflip is claimed.- Increment 8aj supplies the fail-closed V3 Stage Unreal render boundary and a
real local UE5.5 release gate.
V3/ue/StageRenderWorkeris a minimal headless editor project whose strict Python commandlet loads one persisted/Gamelevel and the exact published LevelSequence, resolves exactly one namedCineCameraActor, verifies that the sequence possesses that exact camera class/name, evaluates a bounded frame range, and emits contiguous PNGs plus a SHA-256 manifest. Its tiny native module finishes asynchronous assets, submits the loaded world's material shaders, waits for shader completion, and flushes rendering commands before capture and shutdown. This rejects the earlier black-frame/shader-cancellation failure instead of treating emitted files as success. - The server-only
V3StageUnrealRendererrebinds the durable candidate/version, concert, export hash, and Sequencer receipt to a strict injected V3 binding; launches Unreal without a shell under bounded process-group supervision and a safe environment allowlist; and independently validates the exact manifest, file set, contiguous indices, PNG signatures/dimensions, byte sizes, SHA-256 values, and observable frame variation. It rejects symbolic-link aliases and undeclared files, enforces configured pixel-frame and scratch-capacity budgets, copies the exact digest-authorized audio bytes into the private job, runs real FFmpeg H.264/AAC encoding, and requires FFprobe to observe one exact video/audio stream set, geometry, rate, frame count, and duration. Every outcome removes the transient job. - Sixteen focused tests cover exact success, release/binding substitution,
manifest identity/hash/geometry forgery, static frames, undeclared output,
changed or symlinked audio, forged FFprobe frame/duration evidence, nonzero
Unreal exit, resource exhaustion, and cross-user ownership. The complete Stage
suite passes 79 tests with three environment-gated tests skipped; strict
typecheck and lint pass. The explicit on-box gate builds the editor module,
authors an isolated two-second engine-primitive fixture, renders 24 distinct
640x360 RGBA PNGs through UE5.5/Lavapipe with exit 0, and then passes the
complete server adapter through real FFmpeg/FFprobe in 12.79 seconds. The
fixture is test-only and no candidate, binding, media object, or catalog row
is seeded. A production V3 binding repository/row, real first-party
performance render, deployed worker, final tenant equivalence, and
first-party-liveflip remain open. - The RB.3 consolidation guard is now complete in the existing V10 Phase A
invariant project. Its real-workspace scan covers both V10 ownership roots,
ignores generated directories and symlinks, and rejects a new
live-media/streaming/ingest/transcode package, direct Aphrodite/Neith media
control, the Kafka-shaped
@oshun/streamingpackage, direct HLS/DASH/WebRTC browser engines, canonical server/private subpaths, relative-path bypasses, and native FFmpeg/GStreamer/WebRTC/SRT crates. Package manifests and static, re-exported, import-equals, type,require, dynamic, renamed, target-specific, and Cargo table dependencies have adversarial fixtures. Only the canonical@oshun/live-mediacontract and browser/native client subpaths are admitted. Six focused guard cases, all fourteen Phase A tests, strict typecheck, and lint pass. This closes the guard only; it does not claim tenant equivalence or an ingest-to-Rail flow. - Increment 8ak closes the final local four-tenant equivalence and supervised
ingest-to-Rail test requirement without changing the canonical substrate.
apps/oshun/bff/src/v10/rail-live-media-controls.tsis the Rail server composition boundary: its pipeline, publisher-grant, viewer-session, playback-grant, and protected-playback controls fix tenantv10-rail, exact service principals,v10.rail:<stream UUID>product mapping,v10-rail.player-client.v1,v10-rail.immersive.v1, and the boundedidentity_or_source_not_founddenial after every injected option. V10-owned client/kernel packages still import no canonical server/private subpath and own no second media stack. - The focused cross-product suite runs Aphrodite tenant #1, Veritas tenant #2, V3 Stage tenant #3, and Rail tenant #4 against the same shared controls. Equal stream and job UUIDs produce exact tenant-local resources and service scopes; four real in-memory publisher grants authenticate only in their issuing tenant, reciprocal secret use fails closed, Rail revocation leaves the other three active, and leased viewer presence plus teardown remains isolated while a sibling lease is rejected. This product-composition evidence complements the existing forced-RLS four-tenant PostgreSQL gate rather than replacing it.
- Release evidence is green for 333 shared live-media tests, 199 Aphrodite adapter tests (one environment-gated case skipped), 79 Stage tests (three environment-gated cases skipped), 98 Veritas tests, all 21 Phase A tests, and four new BFF equivalence tests. The focused strict TypeScript configuration, targeted ESLint, Prettier, BFF production build, and dependency/lock importer checks pass. The separately enabled supervised PostgreSQL/MediaMTX/SoftHSM/FFmpeg/Chromium gate also passes: generated Veritas MPEG-TS becomes durable HLS/DASH, the actual Rail panel decodes both protocols, and heartbeat/presence/QoE, secret containment, release, revocation, and teardown are observed. Missing generated shared-database source maps remain Vite diagnostics only.
- This completes the RB.3 automated test checkbox and final local tenant
equivalence. It does not seed a first-party Stage candidate or catalog item,
deploy long-running tenant schedulers/workers/playback hosts, or flip the
exported production
first-party-livedefault. Those implementation and deployment requirements keep the parent extraction checkbox open. - Increment 8al removes the remaining test-fixture-only composition gap in the
Rail web app without declaring an unavailable production program. Deployment
may now supply one credential-free
NEXT_PUBLIC_RAIL_FIRST_PARTY_LIVE_CONFIGmanifest that binds an authority to exact channel/source/tenant/stream, protocol, manifest URL, and same-origin protected-playback API tuples. The actualRailAppconstructs both lane admission and the browser player from that one authority; missing configuration retainsnot_configured, while invalid, cross-origin, credentialed, partial, duplicate, or substituted bindings fail closed. The supervised Veritas ingest-to-Rail Chromium fixture now consumes this production composition rather than constructing its own resolver. The complete V10 web suite passes 188 tests, including new direct adversarial coverage, with strict typecheck and targeted lint. A dedicated Playwright path passes in desktop and mobile Chromium, proving exact lane admission, rendered authority identity, zero autoplay, and release cleanup; it mocks the player dependency and therefore makes no decoded-media claim. The Phase A ownership/consolidation suite also remains green. The production Next/static-PWA build passes with 37 revisioned assets, and the freshly rerun supervised PostgreSQL/MediaMTX/SoftHSM/FFmpeg/Chromium gate carries real Veritas test ingest through this composition to decoded Rail HLS/DASH with teardown (one test, 45.53 seconds); only the previously documented missing generated source-map diagnostics remain. This closes deploy-time client composition only. It does not seed content, install the same-origin server host, retain a production media receipt, or make an unconfigured deployment live; those requirements keep the parent open.
Audit conclusion#
The useful reusable surface is fragmented rather than absent: Aphrodite has substantial product behavior, SQL-backed service boundaries, browser media utilities, crypto/container primitives, and many tests; shared storage/cache/ events already exist; Neith has real codec and transport kernels. What does not yet exist is the complete durable, multi-tenant live-broadcast composition that connects this now-real ingest, signed manifest, leased viewer session, presence, decoded playback, live chat, and operational hooks/telemetry path to the remaining optional-adapter depths and deployed tenant hosts.
Accordingly, the 17-service/adjacent-library audit, increments 1–6, increment 7a's extension contract, increments 7b–7m's real content-analysis, recording, AES-128 HLS protection, visible-watermark, browser/native HLS/DASH player, browser-WHIP publisher, native-SRT publisher, browser immersive, and browser remote-guest, bounded browser-composition, and protected-HLS viewer/release paths, increment 8a's tenant/resource SQL identity boundary, and increment 8b's tenant-neutral shared client surface plus increment 8c's shared tenant-fixed pipeline control and Veritas tenant-#2 composition, increment 8d's shared durable SQL pipeline store, and increment 8e's shared durable identity and publisher-grant stores plus increment 8f's shared durable publisher-edge and publication stores plus increment 8g's shared durable viewer-session/presence store plus increment 8h's shared durable live-chat store, increment 8i's shared operational telemetry/hook store, increment 8j's tenant-fixed viewer, telemetry, and playback-grant controls, and increment 8k's tenant-fixed publisher-grant and transcode controls plus increment 8l's tenant-fixed publisher-edge control and increment 8m's tenant-fixed media-publication control plus increment 8n's tenant-fixed live-chat control and increment 8o's tenant-fixed content-analysis control plus increment 8p's tenant-fixed recording control and worker and increment 8q's tenant-fixed segment-encryption control and worker plus increment 8r's tenant-fixed visible-watermark control and worker plus increment 8s's tenant-fixed player-client lifecycle control and increment 8t's tenant-fixed publisher-client lifecycle control plus increment 8u's tenant-fixed remote guest lifecycle and signaling control plus increment 8v's tenant-fixed immersive session lifecycle control plus increment 8w's tenant-fixed browser-composition lifecycle control plus increment 8x's tenant-fixed protected-playback orchestration control and increment 8y's canonical tenant/resource edge-path and Veritas rehearsal identity boundary plus increment 8z's shared production pipeline assembly and real Veritas canonical ingest-to-ready-media gate and increment 8aa's bounded Veritas rehearsal-to-runtime byte bridge plus increment 8ab's durable Veritas publisher-grant composition and canonical real-edge authentication plus increment 8ac's tenant-fixed protected-playback composition and actual local Veritas HLS/DASH decode in the Rail plus increment 8ad's Aphrodite canonical edge-path migration plus increment 8ae's V3 Stage tenant-#3 production authority composition plus increment 8af's Stage immutable rendered- delivery boundary plus increment 8ag's recorded V3 release-evidence boundary are complete at their code and local release-gate boundaries. Increment 8ah's durable candidate/Calliope projection, increment 8ai's durable rendered-catalog repository, and increment 8aj's fail-closed Unreal/FFmpeg render boundary and real local UE5.5 release gate are likewise complete at those boundaries. Increment 8ak's four-tenant product-equivalence suite and supervised local ingest-to-Rail gate are complete as well. Increment 8al's exact deployment manifest and real Rail-app composition are complete at the client boundary. The broader increment 7 scopes, remaining deployed tenant hosts, and the parent RB.3 implementation checkbox remain open. The audit does not mark any simulated package as production, conflate direct WebRTC with an SFU/TURN service, conflate HLS encryption with vendor DRM, represent a visible marker as forensic protection, conflate bounded Canvas composition with GPU/OBS/native or distributed mixing, claim a complete desktop/mobile client UI, authorize a second stack, or treat local tenant equivalence as deployed production readiness.