BLOCKER: media track parser has no nesting bound #816

Open
opened 2026-10-02 13:15:01 +00:00 by kayg · 6 comments
Owner

Round 7b review, tracking #427. Branch job/voicefiles-620, head b7ef7a2ab57f45b5d46cd19b4560215acae918e3.

P1 availability risk. Merge blocker under the owner crash/DoS rule.

Evidence:

  • crates/calternal-media/src/lib.rs:358 parses a media container header with iso_box_tracks. At lines 366–367, it calls itself for nested container boxes. There is no depth argument, shared traversal budget, or grammar state that limits nesting.
  • The 16 MiB header cap at lines 343–350 limits heap input. The loop bound at line 361 restarts in each call. Neither limit gives a safe stack bound.
  • crates/plugins/files/src/index.rs:1105–1106 invokes the parser for indexed media files. Lines 1164–1169 run it in a blocking task. crates/calternal-search/src/indexer.rs:2628–2631 invokes the same parser during Search indexing. Both read User-controlled file bytes through the safe Root handle.

Impact: nested malformed media headers can exhaust the process stack during indexing. A stack overflow can terminate the server and interrupt other Users. Moving the parser to a blocking task does not make a stack overflow recoverable. This is a static source finding; no crash payload, live attack, or crash threshold was measured.

Expected: every parser of User-controlled bytes has a small, explicit nesting bound and a shared total work budget. Unsupported or malformed media must retain the MIME guess without a crash.

Repair: validate the container hierarchy with a finite grammar or use an iterative traversal with explicit depth and node limits. Keep the existing input byte cap. Apply the bound to the shared parser so both callers use it.

Regression test idea: test valid audio and video headers, malformed hierarchy, the chosen depth boundary, and total work budget. Verify that excessive nesting returns the fallback result, and the indexing worker remains usable. Add tests after the bound is implemented; no unbounded crash reproduction is required.

Duplicate check: searched all states for media and recursion. #519 reports an older, unisolated worker stack overflow; #785 concerns DAV XML depth. Neither tracks this new media parser. No matching repair issue found.

Round 7b review, tracking #427. Branch `job/voicefiles-620`, head `b7ef7a2ab57f45b5d46cd19b4560215acae918e3`. P1 availability risk. Merge blocker under the owner crash/DoS rule. Evidence: - `crates/calternal-media/src/lib.rs:358` parses a media container header with `iso_box_tracks`. At lines 366–367, it calls itself for nested container boxes. There is no depth argument, shared traversal budget, or grammar state that limits nesting. - The 16 MiB header cap at lines 343–350 limits heap input. The loop bound at line 361 restarts in each call. Neither limit gives a safe stack bound. - `crates/plugins/files/src/index.rs:1105–1106` invokes the parser for indexed media files. Lines 1164–1169 run it in a blocking task. `crates/calternal-search/src/indexer.rs:2628–2631` invokes the same parser during Search indexing. Both read User-controlled file bytes through the safe Root handle. Impact: nested malformed media headers can exhaust the process stack during indexing. A stack overflow can terminate the server and interrupt other Users. Moving the parser to a blocking task does not make a stack overflow recoverable. This is a static source finding; no crash payload, live attack, or crash threshold was measured. Expected: every parser of User-controlled bytes has a small, explicit nesting bound and a shared total work budget. Unsupported or malformed media must retain the MIME guess without a crash. Repair: validate the container hierarchy with a finite grammar or use an iterative traversal with explicit depth and node limits. Keep the existing input byte cap. Apply the bound to the shared parser so both callers use it. Regression test idea: test valid audio and video headers, malformed hierarchy, the chosen depth boundary, and total work budget. Verify that excessive nesting returns the fallback result, and the indexing worker remains usable. Add tests after the bound is implemented; no unbounded crash reproduction is required. Duplicate check: searched all states for media and recursion. #519 reports an older, unisolated worker stack overflow; #785 concerns DAV XML depth. Neither tracks this new media parser. No matching repair issue found.
Author
Owner

The pending media parser port and finite grammar/node budget are committed. Final calternal-media clippy passed and all six Cargo unit tests passed. Head: bd6e97e09b. Full handoff and verbatim output are on #779. No push or deploy.

The pending media parser port and finite grammar/node budget are committed. Final calternal-media clippy passed and all six Cargo unit tests passed. Head: bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36. Full handoff and verbatim output are on #779. No push or deploy.
Author
Owner

Read-only review started on job/rev2-mediafix, base 440e19dce23040ac8ebaae88f0469b6535b1afcb. Target: job/mediafix at bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36. I will inspect source and tests only. The LIGHT job rule excludes builds, tests, servers, and browsers.

Read-only review started on `job/rev2-mediafix`, base `440e19dce23040ac8ebaae88f0469b6535b1afcb`. Target: `job/mediafix` at `bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36`. I will inspect source and tests only. The LIGHT job rule excludes builds, tests, servers, and browsers.
Author
Owner

Additional static evidence from the independent #720 review, target 0668a70f2 on job/audiophotos-720:

P1 remains present at crates/calternal-media/src/lib.rs:398-399: iso_box_tracks recursively enters container boxes with no depth limit or shared node budget. The 16 MiB byte cap at lines 376-378 and per-call loop cap at line 393 do not give a safe stack bound. The caller at crates/plugins/files/src/index.rs:1105-1106 still runs this parser during indexing.

Use the single repair in #816 for both #620 and #720. Add a finite grammar or an iterative traversal with explicit depth and node limits, then test safe boundaries. No crash payload or live attack was used. LIGHT review rules prohibit builds and tests.

Additional static evidence from the independent #720 review, target `0668a70f2` on `job/audiophotos-720`: P1 remains present at `crates/calternal-media/src/lib.rs:398-399`: `iso_box_tracks` recursively enters container boxes with no depth limit or shared node budget. The 16 MiB byte cap at lines 376-378 and per-call loop cap at line 393 do not give a safe stack bound. The caller at `crates/plugins/files/src/index.rs:1105-1106` still runs this parser during indexing. Use the single repair in #816 for both #620 and #720. Add a finite grammar or an iterative traversal with explicit depth and node limits, then test safe boundaries. No crash payload or live attack was used. LIGHT review rules prohibit builds and tests.
Author
Owner

Independent read-only review complete. Request changes for F1. The #816 parser repair has a finite stack bound; the wider mediafix branch has one P1 and two P2 findings.

Reviewed target: bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36.
Review HEAD: c49aa865d0019a6c66e8c9324146c682413e5f32 on job/rev2-mediafix.
Files built: review-mediafix.md and audit-findings.md. These are review documents only. No product code changed.

Findings and concrete repairs follow. Duplicate searches found existing owners: #802 for F1/F2, and #852 for F3. Evidence was added to those issues. No issue was closed.

Media review findings

Target: bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36.
Review method: source and test inspection only. No build or test ran.

F1 — P1: restart cleanup can reject an existing Home tree

Evidence: crates/calternal-fs/src/journal.rs:276 builds the full child path.
Line 279 opens that full path. Line 282 returns every error except NotFound.
The new traversal has no depth or path bound. Each level also retains a
Dir descriptor (:287). crates/calternal-server/src/wire.rs:1100 propagates
recovery failure before server startup.

A directory tree can exist with a descendant path longer than the kernel's
single-call path limit. Moving a directory changes its descendants' full
paths without opening them. crates/calternal-fs/src/file_ops.rs:29 validates
the source and destination, but does not validate every descendant path.
The former cleanup skipped excessive depth; the new full scan attempts each
full path. An overlong descendant path therefore makes recovery fail and
prevents the Instance from starting. A low inherited descriptor limit also
makes the retained directory stack fail. No startup failure was reproduced.

Rule: owner availability rule; DESIGN §2; #802 cleanup must use bounded work
and safe directory handles.

Fix: open each child relative to the held parent with the existing resolve
flags. Set an explicit descriptor budget. Resume traversal without retaining
one open descriptor per unbounded level. Do not fail all startup because an
optional abandoned-file sweep encounters a tree it cannot scan.

Test idea: use a small inert directory tree with a long total path, created
through directory handles, and a separate test process with a small descriptor
limit. Recovery must return successfully, preserve ordinary files, and clean
abandoned names in reachable directories. Do not alter existing expectations.

Duplicate search: recovery/depth and ENAMETOOLONG. #802 owns this shared
cleanup fix; add this evidence there.

F2 — P2: thumbnail temporary files bypass active cleanup ownership

Evidence: crates/calternal-fs/src/thumbnails.rs:133 creates a
.calternal-tmp- file directly. ThumbnailTemp (:90) stores no
TemporaryGuard. The new recovery sweep at journal.rs:265 deletes such
regular files unless the temporary registry contains their parent and name.
The creation does not register them. publish_thumbnail_for (:175) can
also return on a sync or rename error without removing the temporary.

The documented concurrent-recovery invariant therefore excludes an active
thumbnail. Recovery can remove its name before publication. Publication can
then fail despite intact rendered bytes. An I/O failure can also leave the
name until the next recovery. This affects Derived data, not content files.
No concurrent failure was reproduced.

Rule: #802; DESIGN §39; reuse gate.

Fix: create thumbnail temporaries through Root::temp and retain its guard
inside ThumbnailTemp until publication or discard. Keep the existing WebP
validation and cache identity. Use the same registry lock as other writers.

Test idea: create a thumbnail temporary, run recovery through a second Root
in the same process, then write and publish it. Assert the final bytes. Inject
a publication failure and assert that Drop removes the private name.

Duplicate search: temporary and recovery/depth. Add evidence to #802.

F3 — P2: progressive HLS callbacks block Tokio workers

Evidence: crates/plugins/files/src/media.rs:496 invokes the stream sink
inside an async pipe-read loop. crates/plugins/video/src/transcode.rs:766
connects that sink to HlsWork::write_stream; metadata calls
publish_progress. crates/calternal-fs/src/quota.rs:58 performs synchronous
statvfs and write_all under the shared operation mutex. hls.rs:89 performs
stream fsync, playlist write, rename, and directory fsync synchronously.
The parent repeats playlist parsing on each stdout chunk (transcode.rs:766),
even when metadata has not changed.

Slow disk work occupies a Tokio worker and competes with unrelated request
work. Repeated parsing adds CPU cost as an event playlist grows. This is a
source-level performance finding, not a measured outage or a merge blocker.

Rule: performance-first owner rule; #663 interactive-path rules.

Fix: use one bounded blocking sink worker per rendition. Send chunks and
playlist updates with backpressure. Parse each metadata version once, retain
its required stream boundary, and publish only when that boundary is synced.
Keep reservation ordering, byte limits, cleanup, and progressive playback.

Test idea: block an inert sink while an unrelated runtime task completes.
Assert bounded queued bytes, cancellation cleanup, and publication only after
all declared ranges exist. Compare long-playlist work with the existing profile.

Duplicate search: HLS. #852 owns this publication cost fix; add evidence there.

Verification: LIGHT rule; no builds, tests, servers, browsers, benchmarks, or adversarial runs. No build/test gate output exists. git diff --check exited 0; its verbatim stdout/stderr were empty.

Known gaps: all findings are static. No runtime failure or latency was measured. The new parser has no Files/Search caller at this target; the combined voicefiles branch must use the bounded crate. F1/F2 need focused regression tests. The committed review lists exact merge-round gate and native-media/adversarial commands.

Decisions: applied the specific LIGHT rule instead of the generic build/merge steps; reused existing repair issues; used #663's recorded performance rules because DESIGN §58 at this target covers agent discovery. No product design decision was made.

UX gaps closed: none. UX gaps left: UI was outside this read-only review. No UI artifacts apply. No push, deploy, or merge ran.

Independent read-only review complete. Request changes for F1. The #816 parser repair has a finite stack bound; the wider mediafix branch has one P1 and two P2 findings. Reviewed target: `bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36`. Review HEAD: `c49aa865d0019a6c66e8c9324146c682413e5f32` on `job/rev2-mediafix`. Files built: `review-mediafix.md` and `audit-findings.md`. These are review documents only. No product code changed. Findings and concrete repairs follow. Duplicate searches found existing owners: #802 for F1/F2, and #852 for F3. Evidence was added to those issues. No issue was closed. # Media review findings Target: `bd6e97e09b56c8df6ae770f5bb440aaf2d9d8f36`. Review method: source and test inspection only. No build or test ran. ## F1 — P1: restart cleanup can reject an existing Home tree Evidence: `crates/calternal-fs/src/journal.rs:276` builds the full child path. Line 279 opens that full path. Line 282 returns every error except NotFound. The new traversal has no depth or path bound. Each level also retains a `Dir` descriptor (`:287`). `crates/calternal-server/src/wire.rs:1100` propagates recovery failure before server startup. A directory tree can exist with a descendant path longer than the kernel's single-call path limit. Moving a directory changes its descendants' full paths without opening them. `crates/calternal-fs/src/file_ops.rs:29` validates the source and destination, but does not validate every descendant path. The former cleanup skipped excessive depth; the new full scan attempts each full path. An overlong descendant path therefore makes recovery fail and prevents the Instance from starting. A low inherited descriptor limit also makes the retained directory stack fail. No startup failure was reproduced. Rule: owner availability rule; DESIGN §2; #802 cleanup must use bounded work and safe directory handles. Fix: open each child relative to the held parent with the existing resolve flags. Set an explicit descriptor budget. Resume traversal without retaining one open descriptor per unbounded level. Do not fail all startup because an optional abandoned-file sweep encounters a tree it cannot scan. Test idea: use a small inert directory tree with a long total path, created through directory handles, and a separate test process with a small descriptor limit. Recovery must return successfully, preserve ordinary files, and clean abandoned names in reachable directories. Do not alter existing expectations. Duplicate search: recovery/depth and ENAMETOOLONG. #802 owns this shared cleanup fix; add this evidence there. ## F2 — P2: thumbnail temporary files bypass active cleanup ownership Evidence: `crates/calternal-fs/src/thumbnails.rs:133` creates a `.calternal-tmp-` file directly. `ThumbnailTemp` (`:90`) stores no `TemporaryGuard`. The new recovery sweep at `journal.rs:265` deletes such regular files unless the temporary registry contains their parent and name. The creation does not register them. `publish_thumbnail_for` (`:175`) can also return on a sync or rename error without removing the temporary. The documented concurrent-recovery invariant therefore excludes an active thumbnail. Recovery can remove its name before publication. Publication can then fail despite intact rendered bytes. An I/O failure can also leave the name until the next recovery. This affects Derived data, not content files. No concurrent failure was reproduced. Rule: #802; DESIGN §39; reuse gate. Fix: create thumbnail temporaries through `Root::temp` and retain its guard inside `ThumbnailTemp` until publication or discard. Keep the existing WebP validation and cache identity. Use the same registry lock as other writers. Test idea: create a thumbnail temporary, run recovery through a second Root in the same process, then write and publish it. Assert the final bytes. Inject a publication failure and assert that Drop removes the private name. Duplicate search: temporary and recovery/depth. Add evidence to #802. ## F3 — P2: progressive HLS callbacks block Tokio workers Evidence: `crates/plugins/files/src/media.rs:496` invokes the stream sink inside an async pipe-read loop. `crates/plugins/video/src/transcode.rs:766` connects that sink to `HlsWork::write_stream`; metadata calls `publish_progress`. `crates/calternal-fs/src/quota.rs:58` performs synchronous `statvfs` and `write_all` under the shared operation mutex. `hls.rs:89` performs stream fsync, playlist write, rename, and directory fsync synchronously. The parent repeats playlist parsing on each stdout chunk (`transcode.rs:766`), even when metadata has not changed. Slow disk work occupies a Tokio worker and competes with unrelated request work. Repeated parsing adds CPU cost as an event playlist grows. This is a source-level performance finding, not a measured outage or a merge blocker. Rule: performance-first owner rule; #663 interactive-path rules. Fix: use one bounded blocking sink worker per rendition. Send chunks and playlist updates with backpressure. Parse each metadata version once, retain its required stream boundary, and publish only when that boundary is synced. Keep reservation ordering, byte limits, cleanup, and progressive playback. Test idea: block an inert sink while an unrelated runtime task completes. Assert bounded queued bytes, cancellation cleanup, and publication only after all declared ranges exist. Compare long-playlist work with the existing profile. Duplicate search: HLS. #852 owns this publication cost fix; add evidence there. Verification: LIGHT rule; no builds, tests, servers, browsers, benchmarks, or adversarial runs. No build/test gate output exists. `git diff --check` exited 0; its verbatim stdout/stderr were empty. Known gaps: all findings are static. No runtime failure or latency was measured. The new parser has no Files/Search caller at this target; the combined voicefiles branch must use the bounded crate. F1/F2 need focused regression tests. The committed review lists exact merge-round gate and native-media/adversarial commands. Decisions: applied the specific LIGHT rule instead of the generic build/merge steps; reused existing repair issues; used #663's recorded performance rules because DESIGN §58 at this target covers agent discovery. No product design decision was made. UX gaps closed: none. UX gaps left: UI was outside this read-only review. No UI artifacts apply. No push, deploy, or merge ran.
Author
Owner

Starting the independent review fixes on branch job/mediafix.

Base SHA: 440e19dce23040ac8ebaae88f0469b6535b1afcb (origin/dev at the prior merge). I am checking the review findings and related issue comments, then I will merge the current origin/dev before code changes and focused gates.

Starting the independent review fixes on branch `job/mediafix`. Base SHA: `440e19dce23040ac8ebaae88f0469b6535b1afcb` (`origin/dev` at the prior merge). I am checking the review findings and related issue comments, then I will merge the current `origin/dev` before code changes and focused gates.
Author
Owner

Completed review fixes

Head SHA: 3cf6c5f6f97e35c0e0616583a9d0ad56ec9f2161

Built:

  • Bounded startup recovery traversal to 24 open directory handles. Long paths stay directory-handle-relative; unreadable or deeper branches do not block startup.
  • Registered thumbnail cache temporaries so recovery preserves active work and failed publication removes the temporary. Added suffix validation.
  • Moved synchronous media sinks to one blocking worker behind a capacity-2 queue so slow sinks do not stall Tokio workers.
  • Parse each exact-distinct HLS playlist frame once and publish only fully written ranges.

Files: crates/calternal-fs/src/journal.rs, crates/calternal-fs/src/root.rs, crates/calternal-fs/src/thumbnails.rs, crates/plugins/files/src/media.rs, crates/plugins/video/src/transcode.rs.

Commits: b5d95ced (#802 recovery), dcd502df (#802 thumbnail cleanup), d23da1a3 (#852 sink worker), ab3a5753 (#852 HLS frame cache), 6be6c42f (files clippy simplification), 3cf6c5f6 (filesystem clippy layout).

Gates

cargo fmt --all -- --check

exit_code=0

cargo clippy -p calternal-plugin-files --all-targets -- -D warnings

    Checking calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/files)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 04s
exit_code=0

cargo test -p calternal-plugin-files -- --test-threads=2 was stopped after more than eight minutes compiling during shared-host contention:

   Compiling calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/files)
exit_code=130

Its focused slow-sink regression passed (1 passed); the full video plugin suite passed (15 passed), including the native HLS integration (1 passed).

cargo clippy -p calternal-fs --all-targets -- -D warnings

    Checking calternal-fs v0.1.0 (/home/kayg/Developer/calternal-wt/mediafix/crates/calternal-fs)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.13s
exit_code=0

cargo test -p calternal-fs

test result: ok. 72 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 45.59s
test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.72s
test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s
exit_code=0

cargo clippy -p calternal-plugin-video --all-targets -- -D warnings

    Checking calternal-plugin-video v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/video)
    Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 56s
exit_code=0

cargo clean

     Removed 9893 files, 4.1GiB total
exit_code=0

Known gaps

  • The full files plugin test did not finish; only its focused regression ran. Run cargo test -p calternal-plugin-files in the merge round.
  • The perf VM SSH timed out. I did not add or run a profile for Rust callback scheduling or HLS frame parsing. Existing bench/media_hls.py measures native HLS output but does not cover those Rust paths.
  • The adversarial media probes were not run in this job, per the merge-round verification policy.

Decisions not specified by DESIGN

  • Recovery holds at most 24 directory handles. Deeper and unreadable branches remain for later recovery rather than blocking startup.
  • The media queue holds two events and uses one blocking sink worker.
  • Temporary suffixes are empty or a dot followed by ASCII alphanumeric characters.
  • Playlist deduplication uses exact frame bytes, and publication retains the range-end boundary.

UX gaps

Backend-only changes; UI and UX gaps are not applicable.

For the merge round

  • bash tests/adversarial/test-media-sandbox.sh — probe hostile media inputs, malformed or oversized HLS frames, and sandbox protocol boundaries.
  • bash tests/adversarial/run.sh — exercise media upload behavior through the real server and the full adversarial API matrix.
  • cargo test -p calternal-plugin-files — complete the interrupted crate gate.
  • Add/run a perf profile that includes the Rust sink queue and HLS frame cache; record p50/p95, CPU, RSS, and largest realistic burst beside docs/perf/baseline.json. The existing native-only profile is not sufficient evidence for those changed Rust paths.
## Completed review fixes Head SHA: `3cf6c5f6f97e35c0e0616583a9d0ad56ec9f2161` Built: - Bounded startup recovery traversal to 24 open directory handles. Long paths stay directory-handle-relative; unreadable or deeper branches do not block startup. - Registered thumbnail cache temporaries so recovery preserves active work and failed publication removes the temporary. Added suffix validation. - Moved synchronous media sinks to one blocking worker behind a capacity-2 queue so slow sinks do not stall Tokio workers. - Parse each exact-distinct HLS playlist frame once and publish only fully written ranges. Files: `crates/calternal-fs/src/journal.rs`, `crates/calternal-fs/src/root.rs`, `crates/calternal-fs/src/thumbnails.rs`, `crates/plugins/files/src/media.rs`, `crates/plugins/video/src/transcode.rs`. Commits: `b5d95ced` (#802 recovery), `dcd502df` (#802 thumbnail cleanup), `d23da1a3` (#852 sink worker), `ab3a5753` (#852 HLS frame cache), `6be6c42f` (files clippy simplification), `3cf6c5f6` (filesystem clippy layout). ## Gates `cargo fmt --all -- --check` ```text exit_code=0 ``` `cargo clippy -p calternal-plugin-files --all-targets -- -D warnings` ```text Checking calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/files) Finished `dev` profile [unoptimized + debuginfo] target(s) in 2m 04s exit_code=0 ``` `cargo test -p calternal-plugin-files -- --test-threads=2` was stopped after more than eight minutes compiling during shared-host contention: ```text Compiling calternal-plugin-files v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/files) exit_code=130 ``` Its focused slow-sink regression passed (1 passed); the full video plugin suite passed (15 passed), including the native HLS integration (1 passed). `cargo clippy -p calternal-fs --all-targets -- -D warnings` ```text Checking calternal-fs v0.1.0 (/home/kayg/Developer/calternal-wt/mediafix/crates/calternal-fs) Finished `dev` profile [unoptimized + debuginfo] target(s) in 3.13s exit_code=0 ``` `cargo test -p calternal-fs` ```text test result: ok. 72 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 45.59s test result: ok. 42 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 17.72s test result: ok. 0 passed; 0 failed; 0 ignored; 0 measured; 0 filtered out; finished in 0.00s exit_code=0 ``` `cargo clippy -p calternal-plugin-video --all-targets -- -D warnings` ```text Checking calternal-plugin-video v0.0.1 (/home/kayg/Developer/calternal-wt/mediafix/crates/plugins/video) Finished `dev` profile [unoptimized + debuginfo] target(s) in 1m 56s exit_code=0 ``` `cargo clean` ```text Removed 9893 files, 4.1GiB total exit_code=0 ``` ## Known gaps - The full files plugin test did not finish; only its focused regression ran. Run `cargo test -p calternal-plugin-files` in the merge round. - The perf VM SSH timed out. I did not add or run a profile for Rust callback scheduling or HLS frame parsing. Existing `bench/media_hls.py` measures native HLS output but does not cover those Rust paths. - The adversarial media probes were not run in this job, per the merge-round verification policy. ## Decisions not specified by DESIGN - Recovery holds at most 24 directory handles. Deeper and unreadable branches remain for later recovery rather than blocking startup. - The media queue holds two events and uses one blocking sink worker. - Temporary suffixes are empty or a dot followed by ASCII alphanumeric characters. - Playlist deduplication uses exact frame bytes, and publication retains the range-end boundary. ## UX gaps Backend-only changes; UI and UX gaps are not applicable. ## For the merge round - `bash tests/adversarial/test-media-sandbox.sh` — probe hostile media inputs, malformed or oversized HLS frames, and sandbox protocol boundaries. - `bash tests/adversarial/run.sh` — exercise media upload behavior through the real server and the full adversarial API matrix. - `cargo test -p calternal-plugin-files` — complete the interrupted crate gate. - Add/run a perf profile that includes the Rust sink queue and HLS frame cache; record p50/p95, CPU, RSS, and largest realistic burst beside `docs/perf/baseline.json`. The existing native-only profile is not sufficient evidence for those changed Rust paths.
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kayg/calternal#816
No description provided.