From 77dd077491aea50e71e21e0d17555a2f91cf818b Mon Sep 17 00:00:00 2001 From: Christophe Besson Date: Mon, 7 Sep 2026 17:45:54 +0200 Subject: refactor(mnp)!: remove stream_seg, the last unencrypted content message MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit `stream_seg` answered with an MPEG-TS segment as base64 with no encryption at all — the one message on the content plane that never went through a GEK-derived key. Live on both transports, answering any authenticated member. It predates `stream_data`, which does the same job properly (`chunk_ciphertext`, keyed per segment, AES-256-GCM) and has since Phase 12. Its only browser caller, `fetchStreamSegment`, was defined and never once invoked — a plaintext media endpoint with no client. Removed rather than repaired. Gone with it: `_extract_segment` and the ffmpeg semaphore in quic_server, the `fetch_stream_segment` QUIC client method, and `_b64decode` in transport.js, which had no other caller. The H6 regression test lived on this handler — it pinned `_do_stream_segment_async` to a coroutine so `subprocess.run` could not stall the event loop for thirty seconds per request. It is replaced by the property that outlives the handler: no transport carries media outside an AEAD, asserted on `stream_seg` and `data_b64` across all three transport modules. The half of H6 that survives — the live streaming path still spawns ffmpeg — keeps its own test. BREAKING CHANGE: `stream_seg` is no longer answered on either transport. No shipping client sends it. Recorded as part of MNP 2.0, whose other half — the sealed upload — carries the version bump. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01AsoWC3GmhNdwVFomW3QjH3 --- docs/devel-phases-next.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) (limited to 'docs/devel-phases-next.md') diff --git a/docs/devel-phases-next.md b/docs/devel-phases-next.md index e842b62..7a4ee24 100644 --- a/docs/devel-phases-next.md +++ b/docs/devel-phases-next.md @@ -503,7 +503,7 @@ Browser Node - No seeking beyond buffered range (user must wait for data to arrive) - No adaptive bitrate (single quality stream) -- Requires ffmpeg/ffprobe on the node (already a dependency for the old STREAM_SEGMENT handler) +- Requires ffmpeg/ffprobe on the node (already a dependency for the live streaming path) --- -- cgit v1.2.3