Implements the core of SPEC.md — the manifest exchange, less audio-tier
matching (§3) and federation (§9a), both of which the spec sequences as
later work.
- §2 Jmanifest format and series bundles
- §3 cut matching: exact / runtime / loose tiers
- §4 API, less POST /manifests/search
- §5 rate limiting; §5a trust model, anonymous bearer tokens
- §6 upload validation, all four stages
- §7 relational storage, no JSON blob on the write path
- §8 Rust + Axum + SQLite, single serialized writer, in-process job queue
- §9a content addressing, computed on upload
Reconciled against the system spec:
- anneal_sec removed, withdrawn upstream by AR-012/AR-013. Presence follows
track extent, so a track survives its own gaps and there is nothing to
anneal. Its successor extinction_sec and the new gallery_scope are accepted
and stored; scope enters the §7 ranking. A manifest still carrying
anneal_sec is a hard 400, not silently ignored — it came from a pipeline
whose window semantics differ from what this server assumes.
- Audio signature: media under 120 s now emits no signature at all, matching
scene-actor-extraction IR-007. The earlier §3 draft allowed a shortened
window under 150 s, which was the weaker rule — a caller-varying length is
the property SR-004 forbids.
- UR IDs regularised to UR-nnn; docs/requirements.md registers 32
requirements, each tracing to an SR-nnn or PR-nnn.
189 tests: unit, end-to-end through the real router, and an injection suite
covering SQL, JSON, header and Unicode payloads. Writing that suite found two
real gaps, both fixed here: compatibility homoglyphs passed the §5a character
class, and a one-frame audio signature was accepted on a feature-length item.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>