[
  {
    "Area": "Source ingest",
    "Status": "COMPLETE",
    "Evidence": "src/ingest.rs; src/protocol.rs; streaming: raw/framed/Expect/hostile/inactivity tests",
    "Limitation": "PUT raw/Content-Length/chunked; SOURCE raw ICE/1.0/HTTP; static configured mounts; no takeover",
    "Action": "Keep supported encoder regression gates."
  },
  {
    "Area": "Source ownership/reconnect",
    "Status": "COMPLETE",
    "Evidence": "src/mounts.rs; simultaneous_source_claims_have_one_owner; old_cleanup_cannot_release_successor; delayed_admin_target_cannot_kill_successor",
    "Limitation": "Listeners belong to one generation and terminate on source loss; reconnect can reject while retired references consume reservations",
    "Action": "No required change."
  },
  {
    "Area": "Continuous GET/HEAD and accounting",
    "Status": "COMPLETE",
    "Evidence": "src/server.rs; src/listener.rs; src/transport.rs; fanout, idle disconnect, native management TCP tests",
    "Limitation": "Public unauthenticated listeners; HTTP/1.0 close-delimited audio; HEAD has no lease; socket writes are not playback proof",
    "Action": "Validate intended player/proxy settings."
  },
  {
    "Area": "Slow consumers and isolation",
    "Status": "COMPLETE",
    "Evidence": "stopped_socket_does_not_backpressure_source_or_healthy_listener; ring eviction/property tests; ICY integration",
    "Limitation": "A slow peer is disconnected, never replayed across generations; finite ring is not archival buffering",
    "Action": "Keep explicit stopped-socket test, not only short load runs."
  },
  {
    "Area": "MP3",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/media.rs; src/ring.rs; milestone-5 media-delivery-final/report.json",
    "Limitation": "Layer III MPEG-1/2/2.5 indexed bitrate joins; no free-format/layer I/II join support; decoder reservoir recovery possible",
    "Action": "Accept declared subset; certify target players."
  },
  {
    "Area": "AAC ADTS",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "frame_headers_and_split_boundaries; adts_passthrough_and_frame_aligned_late_join; six-case decode capture",
    "Limitation": "audio/aac and audio/aacp; no raw AAC/LATM/LOAS/PCE join; AACp fixture proves AAC-LC, not HE-AAC certification",
    "Action": "Add HE-AAC evidence only if required by a target workflow."
  },
  {
    "Area": "Ogg Vorbis",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/media/ogg.rs; ogg_late_join_headers_chains_and_corruption_isolation; decode capture",
    "Limitation": "Sequential single logical streams/chains; bounded init; no multiplexing or comment rewriting; container validation only",
    "Action": "Accept supported mapping; validate live players."
  },
  {
    "Area": "Ogg Opus",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "real_streams_split_headers_pages_and_chains; corruption_truncation_multiplex_and_header_ceiling; decode capture",
    "Limitation": "Mono/stereo mapping family 0; no multichannel families; ICY suppressed",
    "Action": "Accept supported mapping."
  },
  {
    "Area": "ICY metadata and update ingress",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/icy.rs; src/listener.rs; icy_titles_authentication_clearing_and_generation_reset; icy_boundary_inside_single_ingress_allocation; milestone-4 verification",
    "Limitation": "16,000 audio-byte interval; UTF-8 title <=1,024 bytes; semicolon/control rejected; apostrophe/backslash verbatim per reference; Ogg in-band only",
    "Action": "Retain narrow client compatibility and clarify restrictions in operator guide."
  },
  {
    "Area": "HLS typed production/publication",
    "Status": "COMPLETE",
    "Evidence": "src/hls/http.rs; src/hls/store.rs; typed_hls_upload_publication_and_independent_lifecycles; revision-race tests",
    "Limitation": "External producer supplies TS plus typed descriptions; authenticated internal producer API, separate from native inspection",
    "Action": "No continuous/HLS conversion."
  },
  {
    "Area": "HLS storage/lifecycle/visibility",
    "Status": "COMPLETE",
    "Evidence": "HLS budget, immutable-backing, stale-generation, retention, discontinuity, inspection and shutdown tests",
    "Limitation": "Memory only; end retains final playlists, delete/grace/final references reclaim; staging expires; bounded capacity can reject new work",
    "Action": "Producer must recover/repopulate after process restart."
  },
  {
    "Area": "HLS public playback/cache",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/hls/http.rs; milestone-6/http-playback-final-source/report.json; GET/HEAD/ETag/CORS tests",
    "Limitation": "MPEG-TS whole objects; Range returns 416; recorded FFmpeg playback disables seeking/persistence; generic browser/native defaults unproven",
    "Action": "Certify target HLS players. Reclassify Range only if an actual required player cannot operate."
  },
  {
    "Area": "Native management API",
    "Status": "COMPLETE",
    "Evidence": "src/management.rs; docs/management-api.md; authentication/error/inspection/pagination tests; real source/listener control TCP tests",
    "Limitation": "Ephemeral live pages, max200; lexical random IDs; asynchronous disconnect; observational snapshots; nested mount paths supported",
    "Action": "Operators re-read state after actions and restart."
  },
  {
    "Area": "Admission and limits",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "Config validation; global/local semaphores; concurrent_mount_admission_never_exceeds_limit; HLS capacities/budget failure tests",
    "Limitation": "TCP/handshake exhaustion closes before routing; domain exhaustion returns503; admin/public share global capacity; allocation budgets are not RSS caps",
    "Action": "Reserve connection headroom and size OS/proxy resources."
  },
  {
    "Area": "Accepting/draining/shutdown",
    "Status": "COMPLETE",
    "Evidence": "src/lifecycle.rs; src/server.rs; drain commit-race tests; three drain TCP tests; docs/drain-lifecycle-review.md",
    "Limitation": "One-way drain, explicit shutdown; admitted work can finish after drain; HLS new mutations blocked, existing objects playable; no automatic drain deadline/resume",
    "Action": "Use documented admission boundary and explicit shutdown."
  },
  {
    "Area": "Health/readiness",
    "Status": "COMPLETE",
    "Evidence": "server routing; drain_preserves_streams_inspection_health_and_administrative_controls",
    "Limitation": "Process readiness checks acceptance, not encoder availability or end-to-end audio; management listener closes during shutdown",
    "Action": "External monitoring checks source/playback separately."
  },
  {
    "Area": "Metrics/stats/logging",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/metrics.rs; src/logging.rs; stopped_sink_drops_bounded_records_without_waiting; native stats tests",
    "Limitation": "Fixed labels; structured tracing fields, not promised JSON/durable audit; lossy4096-byte records; Unix nonregular stdout required",
    "Action": "Provide draining collector; use metrics for aggregate monitoring."
  },
  {
    "Area": "Proxy/network deployment",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/client.rs; forwarding_contract; docs/architecture.md and management-api.md",
    "Limitation": "External TLS/private admin; explicit trusted XFF IP/CIDR; no HTTP/2/native TLS; raw SOURCE may need TCP pass-through; live buffering/timeouts must be configured",
    "Action": "Validate actual proxy; never publicly forward admin indiscriminately."
  },
  {
    "Area": "Static configuration/startup",
    "Status": "COMPLETE",
    "Evidence": "src/config.rs; src/hls/config.rs; configuration tests; config/quikcast.example.toml",
    "Limitation": "Bounded TOML; deny unknown fields; secret-file support; restart to alter settings; Unix CLI logging prerequisite",
    "Action": "No runtime reload required for current scope."
  },
  {
    "Area": "Security boundaries",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "src/auth.rs; protocol canonicalization/duplicate rejection; credential/proxy/hostile/HLS tests; no secret Debug/response fields",
    "Limitation": "TLS and private exposure external; no RBAC/rate-limiting system; source/HLS secret reuse forbidden; management secret separation is operator-enforced",
    "Action": "Use generated distinct secrets, restrictive files and trusted ingress."
  },
  {
    "Area": "Fifteen-step operator workflow",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "Implementation paths and workflow evidence map in audit report; native TCP controls and drain tests",
    "Limitation": "Viable through static TOML/HTTP/signals/restart; integrated real-client/proxy rehearsal outstanding",
    "Action": "Perform scoped real traffic rehearsal; no product feature missing."
  },
  {
    "Area": "Real encoder/player compatibility",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "Historical curl/FFmpeg/Liquidsoap captures; six MIME decode cases; user-reported BUTT session, README local setup",
    "Limitation": "Captures predate management/drain; no sealed BUTT/version/playback capture; decode success is not universal player certification",
    "Action": "Repeat target encoder/player checks on selected profiling baseline."
  },
  {
    "Area": "Architecture/resource ownership",
    "Status": "COMPLETE",
    "Evidence": "Concrete runtime/mount/generation/HLS types; leases, JoinSet, bounded ring and stores; source review",
    "Limitation": "Synchronous lock/scan cost bounded but needs profiling; no material refactor prerequisite found",
    "Action": "Measure before changing architecture."
  },
  {
    "Area": "Performance architecture",
    "Status": "COMPLETE_WITH_LIMITATION",
    "Evidence": "Bytes sharing, cursor ring, flush gate, immutable charged HLS; milestone-3 load/resource evidence",
    "Limitation": "No zero-copy or production capacity claim; current management/drain build lacks new dedicated-host mixed workload measurements",
    "Action": "Proceed to reproducible profiling, preserving correctness gates."
  },
  {
    "Area": "Operator documentation consolidation",
    "Status": "OPTIONAL",
    "Evidence": "README; docs/protocol.md; milestone-2/4/5/6; management API; drain review",
    "Limitation": "README still describes RadioPlatform identity; historical proposal/remaining-work statements can mislead; complete guide distributed across milestones",
    "Action": "Consolidate standalone runbook/navigation and mark historical statements; documentation completion, not a missing server feature."
  },
  {
    "Area": "Additional Icecast compatibility",
    "Status": "OPTIONAL",
    "Evidence": "Captured 2.4.4/2.5.0 behavior and supported producer tests",
    "Limitation": "No demonstrated client need for XML admin parity/status-json/directory/config syntax/all historical quirks",
    "Action": "Add only for concrete supported-client requirement."
  },
  {
    "Area": "Operational tooling/enhancements",
    "Status": "OPTIONAL",
    "Evidence": "Native HTTP API/static restart workflow already sufficient",
    "Limitation": "No CLI/dashboard/frozen pages/persistent history/audit store/reload/rotation",
    "Action": "Separate optional backlog; no new core milestone justified."
  },
  {
    "Area": "Relays/fallback/takeover/distribution",
    "Status": "DEFERRED",
    "Evidence": "Explicit scope boundary; current duplicate-source policy",
    "Limitation": "No relays, fallback, replacement/priorities/failover/chaining/edge-origin",
    "Action": "Remain deferred; future relay maps continuous remote stream to local continuous mount only."
  },
  {
    "Area": "Additional media/HLS/deployment features",
    "Status": "DEFERRED",
    "Evidence": "Explicit intended identity and tested subsets",
    "Limitation": "Additional codecs, CMAF/fMP4/raw-AAC HLS, LL-HLS/encryption, native TLS/PROXY protocol",
    "Action": "Remain deferred unless actual target workflow changes scope."
  },
  {
    "Area": "Platform integration and conversion",
    "Status": "DEFERRED",
    "Evidence": "Independent continuous and HLS modules; runtime dependencies only Rust server libraries",
    "Limitation": "No RadioPlatform integration, DB/accounts, AutoDJ, encode/decode/transcode/remux/media processes",
    "Action": "Preserve boundary; conversion/AutoDJ remain outside identity."
  }
]
