Quikcast Help

Continuous relay milestone review

Date: 2026-10-07. Original status: IMPLEMENTED AND AUTOMATED CHECKS PASSED — feature-freeze review and comprehensive manual validation remain pending.

Follow-up: feature freeze was declared on 2026-10-08. Comprehensive manual validation remains pending; this review preserves the milestone’s original evidence and review status.

The user's approval to start the feature roadmap authorized its single next milestone: bounded continuous relay sources with native lifecycle management. This delivery completes that implementation scope and operator documentation. It does not promote fallback/source-policy features, change the permanent media boundary, or authorize optimization.

Result and architecture

Static HTTP/HTTPS continuous relays now feed Mount::claim/SourceLease::start/publish/finish, the same concrete source domain used by raw/framed encoder adapters. Codec/container parsing, generation reservations, rings, safe joins, listener limits and fanout remain owned by the existing components. Relay HTTP, ICY demultiplexing, retries, deadlines and operator desired state are isolated under src/relay/.

Dedicated relay mounts reject authenticated encoder source claims even when stopped. Upstream Basic auth is independently loaded from a bounded secret file; URLs/userinfo and credentials are omitted from relay snapshots/logs. Native GET/POST/DELETE relay resources support full mount paths and revision-guarded controls; source DELETE also atomically suppresses retries. /api/stats and fixed-label Prometheus counters include relay observations.

A single supervised worker per relay owns one attempt and one bounded exponential-backoff timer. Per-attempt DNS/HTTP driver tasks run on Tokio in an explicitly bounded task scope, cancelled and joined before retry. The DNS runtime adapter delegates socket/timer/execution to Tokio; it supplies task ownership/capacity, not a new executor. DNS/connect/TLS and header timeouts are finite; encoded-audio inactivity is separate from incoming metadata traffic. Stable-connection duration resets backoff. Stop, stale commands, drain and shutdown preserve generation ownership. Drain keeps an existing admitted relay connection and blocks new attempts/reconnects.

Remote MP3/AAC ICY is demultiplexed after HTTP framing, bounded independently from local ICY output, validated into existing generation track state and reserialized for local listeners. Invalid text is skipped without damaging audio; incomplete framing closes the attempt. Ogg remains in-band and uses the existing parser/initialization path. Reconnect closes the old generation/listeners; seamless continuity is excluded.

The README now describes standalone Quikcast. The relay contract and operator runbook, native API guide, and example configuration (config--quikcast.example.toml) describe setup and lifecycle behavior without relying on RadioPlatform.

Dependency choices

Hyper's existing dependency gains its client feature for maintained HTTP/1 framing and explicit response-header/read bounds. Hickory Resolver 0.25.2 supplies async DNS with no blocking OS lookup jobs; its Tokio provider hook lets attempt ownership cap, cancel and join driver tasks. Tokio Rustls 0.26.6 supplies certificate-validating outbound TLS with the ring/TLS 1.2 features and default features disabled. WebPKI Roots 1.0.9 supplies public trust anchors. These are feature dependencies, not runtime media engines. Exact transitive resolution is pinned in Cargo.lock.

Hickory and Tokio Rustls declare MIT OR Apache-2.0; WebPKI Roots declares CDLA-Permissive-2.0. No custom TLS verifier, inbound TLS listener, DNS-over-HTTPS feature, general-purpose pooled HTTP client, compression or HTTP/2 stack was added. Supporting documentation inspected: Hyper client HTTP/1 builder, Hickory resolver builder, Tokio Rustls. This milestone does not claim production qualification or a dependency security certification.

Executed validation

Final current-tree automated results:

  • cargo test --locked --all: 57 unit/property/concurrency tests, 11 relay integration tests and 20 existing transport integration tests passed (88 total, zero failures). Empty binary/doc-test suites add no coverage.

  • cargo fmt --all --check: passed.

  • cargo clippy --locked --all-targets --all-features -- -D warnings: passed.

  • cargo check --locked --all-targets: passed.

  • cargo build --locked: passed (debug build).

  • git diff --check: passed.

  • Smoke-script Python syntax and the report's local document links were checked.

Local TCP/UDP test bindings require execution outside this workspace's restrictive socket sandbox. The initial sandbox-only attempts failed to bind; the completed checks used approved local socket access. Those permission failures were not streaming regressions. The complete existing suite remains intact, including its pre-existing connection-future size check; no result from that diagnostic drove code changes or performance work.

New meaningful coverage includes:

  • Raw/chunked response audio preserved exactly; dedicated mount ownership and fail-closed authentication.

  • Independent remote/local ICY contracts, arbitrary split reads, metadata change/clear, invalid/ambiguous UTF-8/title/padding, truncation, and arbitrary-byte bounded parsing.

  • MP3/AAC ADTS/Ogg Vorbis/Ogg Opus through the existing source domain, codec visibility and active Ogg late join. An Ogg EOS intentionally removes late-join initialization; the test withholds EOS to exercise an active chain rather than changing that contract.

  • HTTP errors/redirects, unsupported media, zero metadata intervals and ambiguous HTTP framing remain relay-local; other source admission, native management and independent HLS registration/inspection remain operational.

  • EOF recovery, capped exponential delay, reset after stable connection, old listener generation closure, administrative source-stop suppression, stale control revision, explicit reconnect, repeated stop during incomplete headers and shutdown.

  • Drain preserves already-connected playback and prevents retry/reconnect after failure; incomplete metadata traffic cannot defeat the encoded-audio inactivity timeout.

  • Untrusted TLS certificate rejection and successful HTTPS/authenticated framing with a test-only injected trust root; no test certificate is trusted by production configuration.

  • Repeated timed-out DNS attempts have their owned drivers aborted/joined before another attempt; secret-file CRLF handling and absence of upstream secrets/URLs/paths from snapshots.

Focused real-process/client smoke

Run the reproducible functional workflow with:

cargo build --locked python3 tools/proof/relay-smoke.py

The script launches two temporary localhost Quikcast processes (origin and relay edge), uses throwaway source/management secrets in a temporary configuration directory, streams the existing MP3 fixture into the origin, applies track metadata through its source-authenticated route, and listens through curl at the relay. It verifies contiguous encoded fixture bytes, station headers, track state and native administrative stop. It joins its owned test processes and leaves no running daemon. Runtime Quikcast invokes no subprocesses; process/client orchestration exists only in this external test tool.

The recorded smoke passed. Curl's exit 28 is expected because the script deliberately ends an otherwise continuous response using --max-time; encoded bytes and metadata assertions are the success criteria. Received byte count is evidence of functional delivery, not a throughput/capacity measurement. Generated JSON includes the binary SHA-256, curl version, workflow identity and assertions at evidence/relays/relay-smoke.json. Final validation/source identities are recorded in evidence/relays/validation.json; the existing repository policy ignores generated evidence directories. This local smoke does not certify arbitrary Icecast deployments, target native/browser players, public TLS proxies or production resources.

Remaining contracts and review gate

The implementation deliberately retains static configuration/restart rotation, volatile runtime state, external inbound TLS/private administration, existing supported codecs, and independent whole-object MPEG-TS HLS. Relays have no redirect-following, legacy ICY 200 OK status parser, custom/private CA configuration, client certificates, legacy metadata charset conversion, transparent generation migration, fallback/takeover/priorities/multi-upstream failover, clustering or platform-specific integration. Upstream/operator requirements outside this documented subset require a separate scope decision.

A configured conservative worker reservation and explicit buffers/task/input/cardinality limits are not a total RSS/kernel-memory claim. Public/admin inbound capacity remains shared without privileged admin capacity under saturation. Remote topology cycles through proxies or other servers remain an operator responsibility. Producers still repopulate volatile HLS after restart. These are accepted boundary conditions to validate for the intended deployment, not newly implied features.

Phase A implementation and operator documentation are delivered for review. Next is the roadmap's scope/compatibility closure and explicit feature-freeze review, then comprehensive manual encoder/upstream/player/proxy validation. Freeze has not been declared, and manual validation beyond the focused smoke is not claimed complete. No profiling, benchmarking, tuning, allocator/pool/executor/fanout rewrite, unsafe Quikcast code, production capacity work, or RadioPlatform integration was performed.

PERFORMANCE OPTIMIZATION REMAINS BLOCKED UNTIL FEATURE FREEZE.

08 October 2026