Files
XC_VM/docs
Divarion_D 151c8e7bda feat(streaming): P2/B — encrypted HLS served from the daemon (Phase F prereq)
Close Phase B's unencrypted-only limitation: encrypted HLS is now served from
the daemon's in-RAM segmenter too, so encrypt_hls streams no longer need the
legacy tmpfs .enc path — one of the two prerequisites for dropping the
streaming tmpfs (Phase F).

- StreamProcess: generate the stream's HLS key/iv BEFORE registering the daemon
  ingest (moved writeStreamKeyIv up) and, when encrypt_hls is on, hand the hex
  key/iv to the daemon at FanoutClient::registerIngest so it encrypts the HLS
  segments it serves.
- FanoutClient::registerIngest: optional key/iv passed in the ingest PUT body.
- HLSGenerator::tokenizeDaemonPlaylist: prepend #EXT-X-KEY (URI /key/<token>,
  IV from <id>_.iv) for encrypted streams, matching generateHLS.
- live.php m3u8: drop the !encrypt_hls gate — daemon HLS now covers both.
- segment.php unchanged: the daemon-segment X-Accel already returns the
  daemon's (now-encrypted) bytes.

Box-validated: encrypt_hls=1 → 569.m3u8 has #EXT-X-KEY + tokenized daemon
segments; a segment decrypts (stream key + playlist IV) to a valid TS. Daemon
crypto is byte-identical to openssl. PHPStan clean, 443 tests. Daemon 0.6.0.

Refs ADR 0003 (Phase B encrypted). Daemon: XC_VM_Binaries 0.6.0.
2026-08-16 19:52:07 +03:00
..