Address several stream socket review findings on the transport, its
consumer client and the wire protocol:
- ParseAllowedUids rejects negative, out-of-range and non-round-tripping
uids instead of wrapping or truncating them (e.g. 2^32 no longer
becomes uid 0).
- StreamSocketClient backs off after a connection the producer closes
before any message, so a rejected consumer (uid allow-list, client
limit) no longer busy-loops; a rejection is not reported as a
disconnect.
- SendMedia drops packets for a stream that has no announced HELLO, and
ClearAudioParams forgets a previously announced audio stream (bumping
the generation and re-issuing the surviving video HELLO), so a stale
audio HELLO is never replayed and media never precedes its HELLO.
- Header pts_us is encoded as signed (two's-complement) microseconds so
negative and AV_NOPTS_VALUE timestamps survive the wire; the dump tool
decodes it as signed and tracks sequence gaps per generation so a
generation reset is not mistaken for packet loss.
Tests cover the uid rejections, the audio HELLO clearing and media
guard, the connection-rejection backoff, and signed pts round-trips.
refs #5143
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01T4UcdJLt1bxwdpcigGxZRD
BuildHello cast extradata_size to the u16 TLV length, so extradata over
64 KiB was sent truncated with a length that happened to match, and a
consumer would try to use a cut-off parameter set. Parameter sets are a
few hundred bytes, so anything that large is unusable anyway: warn and
leave the tag out, which keeps the HELLO valid. Name the TLV limit and
use it for the string clamp too.
Tests: extradata one byte over the limit is omitted and the HELLO still
parses; exactly the limit travels intact.
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
Add MessageType::Event (0x06) and StreamId::Monitor (0x02) to the v1
stream socket protocol, with an event-code + TLV payload (BuildEvent/
ParseEvent) for the monitor lifecycle channel. Event codes cover the
capture-fault edges (connection/prime/capture failed and restored), a
state_changed transition, and a snapshot sent on consumer connect. TLV
tags carry wall-clock microseconds, a human-readable message, current and
previous state id, an errno/ffmpeg detail code, a state name, and a health
code that a snapshot uses to report the active fault.
The framing is unchanged and length-prefixed, so the new type is
forward-compatible: a pre-event consumer skips it by length, a pre-event
zmc never emits one. No protocol version bump.
Adds round-trip, unknown-tag-skip, and truncation tests. Ran
./tests/tests 'stream_socket::*': 93 assertions in 14 cases pass.
refs #2875
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
First part of the monitor stream socket series: a length-prefixed binary
protocol (version 1) intended to replace the per-monitor media FIFO text
framing. Pure encode/decode functions with no I/O.
- 24-byte fixed header (little-endian): length, version, type, stream,
flags, sequence, generation, pts_us
- Message types HELLO/MEDIA/KEYFRAME/STATS/BYE
- HELLO payload is a TLV list built from AVCodecParameters, carrying
codec id, extradata (SPS/PPS/VPS, AAC AudioSpecificConfig, AV1
sequence header), dimensions, frame rate, sample rate, channels,
profile and level; unknown tags are skipped by parsers
- STATS payload carries per-client sent/dropped counters
Tests: 8 new Catch2 test cases (header roundtrip and boundary/reject
cases, HELLO video/audio/no-extradata roundtrips, unknown-tag skip,
malformed-TLV rejection, STATS roundtrip). Full suite: 90/90 pass
locally via ctest with BUILD_TEST_SUITE=ON.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>