feat(audio): align a fetched manifest to the local file before storing
The signature had a producer and a reader but no consumer, so nothing ever fingerprinted anything. `ManifestAligner` runs on the fetch path, before the windows are stored. A local alignment supersedes the server's offset. The server has never seen this file — its offset is a runtime-difference inference at best, while the local comparison is against the media the windows will actually be drawn over. It also needs no round trip, so no signature leaves the instance. This is what jRay's spec already meant by matching being a consumer concern: the server never rewrites a manifest, so one stored manifest serves every trim of the same cut. The offset has two terms and only one is in the server's pseudocode. Both windows are centred on their own file's midpoint, so unequal runtimes start them at different absolute times; a release with 40 s of extra head material recovers 20 s from the slide and 20 s from the anchor difference. Using the slide alone is wrong by half the runtime difference on every shifted release. Degradation, never failure. Signatures off, no manifest signature, media under the window, a `v2:` producer, a missing binary, a decode error — each applies the server's offset rather than refusing, because a signature is an enhancement to cut matching and must never break a fetch. "Un-comparable" and "does not match" are kept distinct, which a test caught: `Compare` returns null for both, and conflating them would report a 90-second extra as content disagreeing with its own manifest. A genuine disagreement is stored anyway — the audio may legitimately differ, a different language track being the obvious case — and surfaced as a caveat that outranks the tier's, since it is the stronger statement. The applied offset, score, slide and the local file's own signature are written beside the truth file: the offset is otherwise unrecoverable once the windows are shifted, and the stored signature lets a later fetch align without decoding again. Provenance is never injected into the truth file, so the bytes served back stay the producer's (JR-004). `docs/audio-alignment.md` documents the mechanism end to end. TRACES: JR-047 | SR-003
This commit is contained in:
@@ -74,6 +74,18 @@ public class TruthProvenance
|
||||
[JsonPropertyName("offset_sec")]
|
||||
public double OffsetSec { get; set; }
|
||||
|
||||
/// <summary>
|
||||
/// Gets or sets how the applied offset was arrived at, or null for local
|
||||
/// sources and for fetches made before alignment was recorded.
|
||||
/// </summary>
|
||||
/// <remarks>
|
||||
/// <see cref="OffsetSec"/> says what was applied; this says why, and keeps
|
||||
/// the local file's own signature so a later fetch can re-align without
|
||||
/// decoding the media again (JR-047).
|
||||
/// </remarks>
|
||||
[JsonPropertyName("alignment")]
|
||||
public TruthAlignment? Alignment { get; set; }
|
||||
|
||||
/// <summary>
|
||||
/// Gets or sets a human-readable caveat to surface with the overlay, or
|
||||
/// null when the claim needs none.
|
||||
|
||||
Reference in New Issue
Block a user