Add the enforcement layer on top of server-observed monitoring: a revocation
kill switch that stops any stream within ~120s and keeps it dead, plus an async
over-cap enforcer that drives kills off the live monitoring picture — entirely
off the per-segment hot path and with no client-protocol change.
- internal/streamrevoke: the central kill list. IsRevoked is a pure in-memory
lookup safe on the request hot path; a Redis pub/sub + poll mirror keeps edge
caches current, and a Postgres durable mirror lets kills survive a server
restart AND a Redis flush so a restart-resilient stream cannot be reconstructed
and re-served after being killed. A user revocation is a cutoff (kills tokens
minted before it, spares post-reauth tokens), not a 24h ban.
- internal/streamenforcer: async over-cap brain — reads the monitoring snapshot
and per-user limits, selects victims, and collapses every reason (exceeded
limit, admin terminate, abuse) to the same action: write a revocation.
- Edge + native + jellycompat enforcement: proxy refuses revoked sessions on
every request and cuts long direct-play/remux pours mid-stream; the transcode
node guards both serve and the reconstruct path so a killed session is never
re-spawned after a node restart; jellycompat serve surfaces close their
kill-switch coverage holes.
- streamtoken.IssuedTime exposes the token iat the user-kill cutoff compares
against; token IssuedTime + revocation guards wire through router, downloads,
and admin terminate-by-id (with admin-list dedupe).
- Restore sendfile zero-copy on direct-play/remux byte counting so the monitor's
served-byte accounting does not cost the sendfile fast path.
- migrations/sql: stream_revocations durable table.
Part of the stream monitoring & kill-switch epic.