docs(openspec): archive gateway audit remediation
This commit is contained in:
+1
-1
@@ -21,4 +21,4 @@
|
|||||||
## 4. Immutable Freeze
|
## 4. Immutable Freeze
|
||||||
|
|
||||||
- [x] 4.1 Pin and verify a separately published never-reused Protocol version from an empty cache
|
- [x] 4.1 Pin and verify a separately published never-reused Protocol version from an empty cache
|
||||||
- [ ] 4.2 Freeze all normative inputs and run the corrected Section 7 qualification exactly once
|
- [x] 4.2 Freeze all normative inputs and run the corrected Section 7 qualification exactly once
|
||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# apollo-stream-policy Specification
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
TBD - created by archiving change phase3c-gateway-audit-remediation. Update Purpose after archive.
|
||||||
|
## Requirements
|
||||||
|
### Requirement: Apollo launch consumes the effective policy
|
||||||
|
The native Apollo backend SHALL derive ANNOUNCE resolution, frame rate, supported codec, selected bitrate, and audio profile from authenticated `ProviderSessionWork`, and MUST NOT substitute local defaults.
|
||||||
|
|
||||||
|
#### Scenario: Supported HEVC policy reaches Apollo
|
||||||
|
- **WHEN** provider work selects HEVC at 2560×1440, 120 FPS, 40000 Kbps, with audio enabled
|
||||||
|
- **THEN** the encrypted ANNOUNCE carries those settings and the source-backed HEVC and bitrate attributes
|
||||||
|
|
||||||
|
### Requirement: Provider policy cannot downgrade
|
||||||
|
The gateway MUST use the generated Protocol intersection to select only a registered profile compatible with the immutable policy. It MUST reject invalid, unsupported, no-overlap, downgrade, audio-disabled, AV1, or provider/source-mismatched Apollo policy before `/applist`, `/launch`, or provider readiness because the current native path cannot truthfully honor those combinations.
|
||||||
|
|
||||||
|
#### Scenario: Unsupported policy fails closed
|
||||||
|
- **WHEN** authenticated provider work selects audio disabled, AV1, a codec outside the registered peer intersection, or a resolution, frame rate, bitrate, audio, or codec combination outside source-backed Apollo support
|
||||||
|
- **THEN** setup fails before application discovery or launch without falling back to H.264, stereo, a cap, or another local default
|
||||||
|
|
||||||
|
#### Scenario: Independent peers negotiate one registered profile
|
||||||
|
- **WHEN** a production gateway and independent client advertise overlapping registered H.264 or HEVC profiles
|
||||||
|
- **THEN** admission selects the first policy-compatible common profile using shared Protocol behavior
|
||||||
|
|
||||||
@@ -0,0 +1,12 @@
|
|||||||
|
# audio-fec-resilience Specification
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
TBD - created by archiving change phase3c-gateway-audit-remediation. Update Purpose after archive.
|
||||||
|
## Requirements
|
||||||
|
### Requirement: Bounded audio FEC state advances after loss
|
||||||
|
The Apollo audio recovery window SHALL remain bounded and SHALL evict the oldest incomplete block when accepting a newer block would otherwise be rejected.
|
||||||
|
|
||||||
|
#### Scenario: Newer complete block follows sustained loss
|
||||||
|
- **WHEN** more than the bounded number of permanently incomplete audio blocks arrive before a complete newer block
|
||||||
|
- **THEN** the oldest stale state is dropped, drop telemetry advances, and the newer encoded payload is relayed unchanged
|
||||||
|
|
||||||
@@ -0,0 +1,26 @@
|
|||||||
|
# gateway-heartbeat-telemetry Specification
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
TBD - created by archiving change phase3c-gateway-audit-remediation. Update Purpose after archive.
|
||||||
|
## Requirements
|
||||||
|
### Requirement: Heartbeat egress is observed
|
||||||
|
Authenticated gateway heartbeat telemetry SHALL calculate egress from monotonic transmitted-byte deltas over monotonic elapsed time and MUST NOT report configured capacity as measured traffic.
|
||||||
|
|
||||||
|
#### Scenario: Controlled byte delta is sampled
|
||||||
|
- **WHEN** transmitted bytes increase by a known amount during a known interval
|
||||||
|
- **THEN** heartbeat egress equals the measured rate while configured capacity remains a separate registration value
|
||||||
|
|
||||||
|
### Requirement: Required telemetry remains bounded and low cardinality
|
||||||
|
The established authenticated path SHALL expose observed bytes, packets, drops, RTT, loss, jitter, queue delay, processing delay, pacing, reconnect, and provider state without session, route, credential, or payload labels.
|
||||||
|
|
||||||
|
#### Scenario: Telemetry snapshot is published
|
||||||
|
- **WHEN** the gateway emits a heartbeat after forwarding traffic
|
||||||
|
- **THEN** it carries the bounded process-level observations and no high-cardinality or secret-bearing value
|
||||||
|
|
||||||
|
### Requirement: Production delays have disjoint sample semantics
|
||||||
|
Queue delay SHALL measure provider-queue residence, processing delay SHALL measure provider recovery plus framing and QUIC handoff work excluding queue and pacing, and pacing delay SHALL measure scheduler waiting only. The gateway SHALL advance processing samples once per complete provider media unit even when it emits multiple Verse frames.
|
||||||
|
|
||||||
|
#### Scenario: Known production waits
|
||||||
|
- **WHEN** one provider media unit has controlled enqueue, processing, and pacing intervals and fragments across multiple frames
|
||||||
|
- **THEN** each cumulative total reports only its intended interval and exactly one processing sample is retained through authenticated Server persistence
|
||||||
|
|
||||||
@@ -5,63 +5,37 @@ Define the deterministic processing, impairment, pacing, and evidence boundaries
|
|||||||
for qualifying a frozen Phase 3C gateway candidate.
|
for qualifying a frozen Phase 3C gateway candidate.
|
||||||
## Requirements
|
## Requirements
|
||||||
### Requirement: Fixed media processing qualification
|
### Requirement: Fixed media processing qualification
|
||||||
The qualification harness SHALL run 1080p60 H.264 at 20 Mbps, 1440p120 HEVC
|
The qualification harness SHALL drive pinned-mTLS Apollo management, encrypted RTSP, ENet, and provider UDP through native source validation, `readUDPMedia`, recovery/FEC, bounded production queues, the production fair pacer, Verse framing/QUIC, and a public or independent client decoder for 1080p60 H.264 at 20 Mbps, 1440p120 HEVC at 50 Mbps, and 4K60 HEVC at 80 Mbps. After a recorded warm-up, the frozen candidate SHALL run each profile for ten wall-clock minutes, preserve encoded payload bytes, retain every monotonic processing sample plus bounded CPU, memory, goroutine, allocation, and provider-queue observations, and report count, min, median, p90, p95, p99, max, mean, standard deviation, timing overhead, and observed bitrate. Processing begins at complete provider-unit receipt and ends at QUIC handoff, excluding client transit. Any bypass, payload mutation, wall-duration violation, bitrate outside both lower and upper bounds, or p95 above 5 ms SHALL fail.
|
||||||
at 50 Mbps, and 4K60 HEVC at 80 Mbps for ten wall-clock minutes each after a
|
|
||||||
recorded warm-up. It SHALL preserve encoded payload bytes, record every
|
|
||||||
monotonic processing sample, report count, min, median, p90, p95, p99, max,
|
|
||||||
mean, standard deviation, timing overhead, and observed bitrate, and fail when
|
|
||||||
any p95 exceeds 5 ms.
|
|
||||||
|
|
||||||
#### Scenario: Healthy fixed profile
|
#### Scenario: Healthy fixed profile
|
||||||
- **WHEN** a frozen candidate runs one fixed profile for the normative duration
|
- **WHEN** a frozen candidate runs one fixed profile for the normative duration
|
||||||
- **THEN** the harness emits compressed raw samples and a summary tied to the
|
- **THEN** the harness emits compressed raw path and resource samples plus a summary tied to the exact command, topology, source commit, immutable Protocol version, environment, and payload hash
|
||||||
exact source commit, Protocol version, environment, and payload hash.
|
|
||||||
|
|
||||||
#### Scenario: Processing gate failure
|
#### Scenario: Processing gate failure
|
||||||
- **WHEN** payload integrity fails or measured p95 exceeds 5 ms
|
- **WHEN** any production path stage lacks a per-traversal observation, payload integrity fails, duration or bitrate bounds fail, or measured p95 exceeds 5 ms
|
||||||
- **THEN** the qualification command exits unsuccessfully without recording a
|
- **THEN** the qualification command exits unsuccessfully without recording a passing candidate
|
||||||
passing candidate.
|
|
||||||
|
|
||||||
### Requirement: Bounded impairment qualification
|
### Requirement: Bounded impairment qualification
|
||||||
The harness SHALL run exactly the baseline, latency, jitter, loss, reorder,
|
The harness SHALL run exactly the baseline, latency, jitter, loss, reorder, and constrained Section 7.2 profiles once by applying impairment at the source-shaped provider UDP boundary while traffic traverses the production gateway path. Baseline SHALL cover all three media profiles and the other profiles SHALL cover 1080p60. Each artifact SHALL retain raw impairment and queue observations and record tool version, exact command/configuration, environment, candidate commit, immutable Protocol version, direction, queue discipline, topology, fixed seed, and observed RTT, jitter, loss, reorder, throughput, drops, and capacity-step statistics.
|
||||||
and constrained Section 7.2 profiles once. Baseline SHALL cover all three
|
|
||||||
media profiles and the other profiles SHALL cover 1080p60. Each artifact SHALL
|
|
||||||
record tool version, exact command/configuration, direction, queue discipline,
|
|
||||||
topology, fixed seed, and observed RTT, jitter, loss, reorder, throughput,
|
|
||||||
drops, and capacity-step statistics.
|
|
||||||
|
|
||||||
#### Scenario: Complete six-profile run
|
#### Scenario: Complete six-profile run
|
||||||
- **WHEN** the frozen candidate runs impairment qualification
|
- **WHEN** the frozen candidate runs impairment qualification
|
||||||
- **THEN** one result exists for each named profile, with no Cartesian
|
- **THEN** one result exists for each named profile, with no Cartesian expansion and with raw observed rather than configured statistics from the real traversal
|
||||||
expansion and with observed rather than configured statistics.
|
|
||||||
|
|
||||||
#### Scenario: Unsupported or unbounded configuration
|
#### Scenario: Unsupported or unbounded configuration
|
||||||
- **WHEN** a profile name, packet count, queue bound, loss, reorder, or
|
- **WHEN** a profile name, packet count, queue bound, loss, reorder, or bandwidth step falls outside the fixed catalog
|
||||||
bandwidth step falls outside the fixed catalog
|
- **THEN** the harness rejects it before allocating or running traffic
|
||||||
- **THEN** the harness rejects it before allocating or running the simulation.
|
|
||||||
|
|
||||||
### Requirement: Fairness and cap qualification
|
### Requirement: Fairness and cap qualification
|
||||||
The harness SHALL exercise the production fair pacer with eight equal-tier
|
The harness SHALL exercise the production fair pacer with eight equal-tier synthetic sessions for the required 60-second virtual interval, retain every per-flow and aggregate observation, report every share error and Jain's fairness index, and fail above 10% share error. It SHALL apply 25% and 50% capacity steps, measure convergence of observed allocation rather than first delivery, fail convergence beyond ten virtual seconds, and fail aggregate egress above 105% of the cap over any rolling five-second window.
|
||||||
synthetic sessions for the required 60-second virtual interval, report every
|
|
||||||
share error and Jain's fairness index, and fail above 10% share error. It SHALL
|
|
||||||
apply 25% and 50% capacity steps, fail convergence beyond ten virtual seconds,
|
|
||||||
and fail aggregate egress above 105% of the cap over any rolling five-second
|
|
||||||
window.
|
|
||||||
|
|
||||||
#### Scenario: Equal-tier and capacity-step evidence
|
#### Scenario: Equal-tier and capacity-step evidence
|
||||||
- **WHEN** the frozen candidate runs scheduler qualification
|
- **WHEN** the frozen candidate runs scheduler qualification
|
||||||
- **THEN** the artifact contains per-flow bytes, share errors, Jain's index,
|
- **THEN** the artifact contains raw per-flow bytes, aggregate-cap series, share errors, Jain's index, measured allocation convergence, and rolling cap observations derived from the production pacer
|
||||||
step convergence, and rolling cap observations derived from the production
|
|
||||||
pacer.
|
|
||||||
|
|
||||||
### Requirement: Honest qualification boundary
|
### Requirement: Honest qualification boundary
|
||||||
Qualification artifacts SHALL contain no provider endpoint, credential,
|
Qualification artifacts SHALL contain no provider endpoint, credential, clipboard text, input payload, secret, or raw media content and SHALL make no claim of live Apollo/macOS/firewall interoperability. The harness SHALL add no codec operation, production dependency, cgo, sidecar, direct provider route, or duplicate processing/impairment simulator. Deterministic smoke evidence SHALL remain distinct from the single normative run on the frozen immutable consumer candidate.
|
||||||
clipboard text, input payload, secret, raw media content, or claim of live
|
|
||||||
Apollo/macOS/firewall interoperability. The harness SHALL add no codec
|
|
||||||
operation, production dependency, cgo, sidecar, or direct provider route.
|
|
||||||
|
|
||||||
#### Scenario: Deterministic evidence publication
|
#### Scenario: Deterministic evidence publication
|
||||||
- **WHEN** qualification completes
|
- **WHEN** qualification completes
|
||||||
- **THEN** the manifest labels fake-provider, virtual impairment, and local
|
- **THEN** the manifest labels fake-provider, path impairment, and local processing evidence separately and leaves live interoperability deferred-owner-e2e
|
||||||
processing evidence separately and leaves live interoperability
|
|
||||||
deferred-owner-e2e.
|
|
||||||
|
|||||||
@@ -0,0 +1,23 @@
|
|||||||
|
# provider-session-lifecycle Specification
|
||||||
|
|
||||||
|
## Purpose
|
||||||
|
TBD - created by archiving change phase3c-gateway-audit-remediation. Update Purpose after archive.
|
||||||
|
## Requirements
|
||||||
|
### Requirement: Provider terminal events end forwarding
|
||||||
|
Encrypted provider termination and unexpected provider disconnect SHALL quiesce provider ingestion and queued/new media forwarding before the existing reliable typed terminal event is delivered, close the Verse tunnel within a bounded interval, release the session reservation, and report the appropriate durable provider/session state. A fixed drain delay MUST NOT stand in for reliable control delivery.
|
||||||
|
|
||||||
|
#### Scenario: Host termination closes the tunnel
|
||||||
|
- **WHEN** the native provider emits an authenticated termination event
|
||||||
|
- **THEN** queued and newly injected media cannot cross the Verse transport after observation, and the client tunnel, reservation, and durable lifecycle transition complete
|
||||||
|
|
||||||
|
#### Scenario: Unexpected provider disconnect is reconnectable
|
||||||
|
- **WHEN** required provider transport disconnects without acknowledged termination
|
||||||
|
- **THEN** forwarding stops and the Server receives the existing reconnectable lifecycle state rather than a termination claim
|
||||||
|
|
||||||
|
### Requirement: Cleanup failure remains durable
|
||||||
|
Gateway cleanup MUST preserve `cleanup_pending` when provider input release, transport cleanup, authorized cancellation, or durable reporting fails.
|
||||||
|
|
||||||
|
#### Scenario: Terminal cleanup fails
|
||||||
|
- **WHEN** a provider terminal event is handled but required cleanup cannot complete
|
||||||
|
- **THEN** the session is not reported released or reusable and durable state remains cleanup pending
|
||||||
|
|
||||||
Reference in New Issue
Block a user