mirror of
https://github.com/Vateron-Media/XC_VM.git
synced 2026-10-03 20:02:29 +02:00
Close Phase B's unencrypted-only limitation: encrypted HLS is now served from the daemon's in-RAM segmenter too, so encrypt_hls streams no longer need the legacy tmpfs .enc path — one of the two prerequisites for dropping the streaming tmpfs (Phase F). - StreamProcess: generate the stream's HLS key/iv BEFORE registering the daemon ingest (moved writeStreamKeyIv up) and, when encrypt_hls is on, hand the hex key/iv to the daemon at FanoutClient::registerIngest so it encrypts the HLS segments it serves. - FanoutClient::registerIngest: optional key/iv passed in the ingest PUT body. - HLSGenerator::tokenizeDaemonPlaylist: prepend #EXT-X-KEY (URI /key/<token>, IV from <id>_.iv) for encrypted streams, matching generateHLS. - live.php m3u8: drop the !encrypt_hls gate — daemon HLS now covers both. - segment.php unchanged: the daemon-segment X-Accel already returns the daemon's (now-encrypted) bytes. Box-validated: encrypt_hls=1 → 569.m3u8 has #EXT-X-KEY + tokenized daemon segments; a segment decrypts (stream key + playlist IV) to a valid TS. Daemon crypto is byte-identical to openssl. PHPStan clean, 443 tests. Daemon 0.6.0. Refs ADR 0003 (Phase B encrypted). Daemon: XC_VM_Binaries 0.6.0.