fix: harden stream socket transport and protocol from PR review

Address several stream socket review findings on the transport, its
consumer client and the wire protocol:

- ParseAllowedUids rejects negative, out-of-range and non-round-tripping
  uids instead of wrapping or truncating them (e.g. 2^32 no longer
  becomes uid 0).
- StreamSocketClient backs off after a connection the producer closes
  before any message, so a rejected consumer (uid allow-list, client
  limit) no longer busy-loops; a rejection is not reported as a
  disconnect.
- SendMedia drops packets for a stream that has no announced HELLO, and
  ClearAudioParams forgets a previously announced audio stream (bumping
  the generation and re-issuing the surviving video HELLO), so a stale
  audio HELLO is never replayed and media never precedes its HELLO.
- Header pts_us is encoded as signed (two's-complement) microseconds so
  negative and AV_NOPTS_VALUE timestamps survive the wire; the dump tool
  decodes it as signed and tracks sequence gaps per generation so a
  generation reset is not mistaken for packet loss.

Tests cover the uid rejections, the audio HELLO clearing and media
guard, the connection-rejection backoff, and signed pts round-trips.

refs #5143

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T4UcdJLt1bxwdpcigGxZRD
This commit is contained in:
Claude committed 2026-09-19 23:00:03 +00:00
1 parent 0e88b390c3
commit 281a7d967e
10 files changed
+263 -19

No files matched your search

+2 -2
View File
@@ -97,7 +97,7 @@ void SerializeHeader(const Header &header, uint8_t out[kHeaderSize]) {
out[7] = header.flags;
put_u32(out + 8, header.sequence);
put_u32(out + 12, header.generation);
put_u64(out + 16, header.pts_us);
put_u64(out + 16, static_cast<uint64_t>(header.pts_us)); // two's-complement
}
bool ParseHeader(const uint8_t in[kHeaderSize], Header &header) {
@@ -108,7 +108,7 @@ bool ParseHeader(const uint8_t in[kHeaderSize], Header &header) {
header.flags = in[7];
header.sequence = get_u32(in + 8);
header.generation = get_u32(in + 12);
header.pts_us = get_u64(in + 16);
header.pts_us = static_cast<int64_t>(get_u64(in + 16)); // two's-complement
if (header.version != kProtocolVersion)
return false;