Milestone 1 review package
Historical milestone 1 review package, subsequently approved. At this gate there were no production Rust modules. The current implementation is described in milestone 2.
What to review
Architecture: concrete boundaries, all ten hard invariants, source generations, bounded fanout, task supervision/shutdown, narrow ICY design, and independent HLS lifecycle.
Engineering contracts: typed config/error model, limits, admission reservations, backing-allocation/copy accounting, dependency rationale, observability, tests/benchmarks and milestone gates.
Protocol evidence: observed behavior versus chosen Quikcast behavior and unresolved coverage.
Machine-readable compatibility matrix (fixtures--icecast--compatibility.json): 20 classified cases with actual fixture links.
Reproduction instructions (tools--icecast-reference--README.md): isolated reference builds/runs and evidence verification.
The approved amendments are retained: no custom SHA-256 credential storage; high-entropy configured machine secrets with constant-time comparison; temporary opaque MP3 joining followed by minimal framing; HLS MPEG-TS only with a configurable 2 MiB ceiling; typed publication revisions; no generic playlist/file upload; no decoding/media processes in the server; no broad Icecast admin compatibility.
Evidence affecting implementation
Chunked admission is not audio correctness. Icecast 2.4.4 admits the request but relays chunk markers; 2.5.0 removes them correctly. Quikcast must preserve audio by decoding transport framing.
PUT reply timing differs. 2.4.4 sends early final acceptance; 2.5.0's raw PUT streams can be active with only 100 Continue or no source reply observed. The proposed contract explicitly separates framed HTTP completion from early raw/legacy acceptance.
Empty song behavior differs. Both accept metadata updates, but only 2.4.4 cleared the tested title with song=. Quikcast's explicit-empty-field clearing is deliberate.
Metadata can trail retained audio history. Short reads missed accepted updates. Extended captures demonstrate actual delivery. Quikcast samples latest normalized metadata at listener interval boundaries, rather than cloning Icecast's historical metadata storage architecture.
Real external clients were exercised. FFmpeg 8.1.2 and Liquidsoap 2.1.3 produced listenable reference streams on both releases. Curl finite uploads produced version-dependent outcomes; they are not described as universal live compatibility.
Validation and boundaries
The reference interpreter has unit tests for interim/final response handling, empty/padded/incomplete ICY blocks, and no-metadata responses. The verifier checks fixture manifests, image/binary/tone provenance, event byte offsets, summary extraction, ICY blocks, audio comparisons, and matrix evidence links. The matrix generator independently verifies FFmpeg's captured audio after its muxer-added ID3 tag.
Validation completed: five interpreter unit tests passed; nine capture datasets containing 178 raw dialogues passed manifest/event/extraction verification; all 20 compatibility classifications have verified evidence links. The 178 dialogues include bounded readiness probes and preserved diagnostic runs, not 178 distinct protocol features. Capture artifacts occupy approximately 7.2 MB. All Python tools passed syntax inspection.
Primary, focused, and Liquidsoap captures are retained with their exact harness snapshots. Initial short metadata and too-early Liquidsoap reads are preserved as diagnostic datasets, not represented as successful probes. Reference containers/client tasks are stopped and joined/removed by their owning harness; tested images and ignored source archives remain available for reproduction.
No cargo fmt/clippy/test/check/audit results are claimed: there is intentionally no Cargo project in this milestone. No Quikcast CPU, RSS, listener-count, or performance claim is made. Rust quality gates apply starting with milestone 2.
Unresolved reference coverage: truly absent source Authorization, large/slow finite Content-Length bodies, ICY maximum-size/embedded-delimiter/charset cases, and broader encoder/player versions. These are explicitly recorded; ambiguous ICY details require additional captures before milestone 4. Finite-body behavior requires incremental-delivery tests in milestone 2. No unresolved observation is converted to a presumed pass.
Review gate
Review this package before production code. The next authorized implementation milestone is the MP3 vertical slice only: source auth/admission, static mounts, bounded fanout, source generations, multiple listeners, disconnect/slow-reader handling, shutdown, metrics and integration tests.
Do not begin ICY, codec expansion, HLS implementation or performance optimization until their preceding correctness/compatibility/resource gates pass. Keep the implementation order MP3 → proof → ICY → AAC/Ogg → MPEG-TS HLS.