diff --git a/docs/screenshare-audio-exclusion-impl-plan.md b/docs/screenshare-audio-exclusion-impl-plan.md index d7d7016..9091f80 100644 --- a/docs/screenshare-audio-exclusion-impl-plan.md +++ b/docs/screenshare-audio-exclusion-impl-plan.md @@ -19,10 +19,10 @@ construction gates are built, validated and committed locally in PixelPass (`6be **The independent Row 6a/6b/6c refusal gates are built, validated and committed locally in PixelPass (`956534f`).** **The revised Row 9 positive/negative late-arrival partition is built, validated and committed locally in PixelPass (`7b11827`).** The deterministic Phase 6 -link-manager matrix is complete; its production-path three-arm leak qualification, plus phases -7–9, is not built — nothing -released to date changes the feature's user-visible behaviour. **Phase 6 remains the current -front.** +link-manager matrix is complete. **The production-path three-arm AEC leak qualification is +built, validated and committed locally in PixelPass (`e027bc6`), completing Phase 6.** Phases +7–9 are not built — nothing released to date changes the feature's user-visible behaviour. +**Phase 7 is now the current front.** **Date:** 2026-07-21 (v4); status line refreshed 2026-08-21 **Design of record:** [`screenshare-audio-exclusion-plan.md`](screenshare-audio-exclusion-plan.md) v3.8, round 11. **Scope:** *ordering, gates and acceptance criteria only.* @@ -787,6 +787,34 @@ ancestry becoming unsafe. > link-manager matrix is now complete. Phase 6 remains open on its production-path three-arm AEC > leak measurement re-run, whose naive positive control must exist only behind a test seam. +> **Production-path three-arm AEC leak qualification — built, validated and committed locally as +> PixelPass `e027bc6` on 2026-08-21. Phase 6 is complete.** A `#[cfg(test)]` policy can re-admit +> only the exact configured `aec-identity` candidate; the unsafe policy, constructor and field do +> not exist in a production build. A focused controller gate proves safe mode retains only the +> ordinary stereo pair while the deliberately naive mode adds exactly the AEC playback pair. +> +> The ignored serialized live gate drives the hidden `DesktopExcluding` selector through the real +> connection-owned sink, registry observer, taint controller, native link manager and +> `.monitor` Pulse source. It loads one exact-ID WebRTC echo-cancel module per arm, filters +> `media.class=Stream/Output/Audio` before matching `pulse.module.id`, retains and reports every +> child stderr stream, verifies the exact graph links, and records 48 kHz stereo s16le with +> `parec`. The guarded and naive arms inject a PeerSpeak-owned 1500 Hz stream into the real AEC +> sink; all arms retain an ordinary 440 Hz desktop stream. +> +> Two complete runs passed the thresholds declared in the test. Desktop 440 Hz stayed between +> -32.84 and -34.05 dBFS. The guarded arm's 1500 Hz result (-75.76 to -78.03 dBFS) never rose more +> than 3 dB above its run's control floor, while the naive positive control measured -33.80 to +> -33.92 dBFS, comparable to its desktop tone and at least 18 dB above both control and guarded. +> The supported conclusion is deliberately narrow: **no incremental 1500 Hz energy was detectable +> above the control floor at this analysis resolution**; this is not a claim that remote audio is +> absent. Phase 9 still owns the PN/MLS intelligibility rig and field variance. +> +> Final PixelPass validation: 346 passed, 0 failed and 13 ignored; strict all-target Clippy, +> formatting, `git diff --check`, `pixelpass --doctor`, and all four serialized Phase 6 live audio +> gates pass. The final Pulse/PipeWire/process/temp-file residue scan is empty. Nix is unavailable, +> so validation used system Rust 1.96.1. The next implementation front is Phase 7's public mode +> selector and versioned capability advertisement. + Failure ⇒ report the stream unsupported. **Never** fall back to the default monitor — and after 0d that fallback is unconstructible in this mode, by either path. diff --git a/docs/screenshare-audio-exclusion-plan.md b/docs/screenshare-audio-exclusion-plan.md index 7dad197..40ec569 100644 --- a/docs/screenshare-audio-exclusion-plan.md +++ b/docs/screenshare-audio-exclusion-plan.md @@ -10,7 +10,10 @@ The four versioned causal status events are built, validated and committed local `5a65f50`. Capture-sink replacement and successful all-channel relinking are built, validated and committed locally in PixelPass `d09ee9b`. The Row 1 mutation-edge identity gate and Row 8d/8e fail-closed construction gates are built, validated and committed locally in PixelPass -`6be07ef`. +`6be07ef`. The independent Row 6 refusal gates (`956534f`) and revised Row 9 partition +(`7b11827`) complete the deterministic link-manager matrix. The production-path three-arm AEC +leak qualification is built, validated and committed locally in PixelPass `e027bc6`; **Phase 6 +is complete and Phase 7 is the current implementation front.** **Date:** 2026-08-21 (v1: 07-19 · v2: 07-20 · Option C 07-20 · v3.1 r4 · v3.2 r5 · v3.3 r6 · v3.4 r7 · v3.5 r8 · v3.6 r9 · v3.7 r10 · v3.8 r11 2026-08-21) **Origin:** Joe's suggestion — "whitelist all audio except audio coming from peerspeak." @@ -1428,10 +1431,23 @@ is 345 passed and 12 ignored; strict Clippy, all three serialized live Phase 6 m diagnostics and residue checks pass. This completes the deterministic link-manager matrix, not Phase 6's separate live signal qualification. -1. **Continue Phase 6:** build and run the production-path three-arm AEC leak measurement re-run, - keeping its deliberately naive positive control behind a test-only seam. -2. Preserve the new live mutation slice's ownership, serial-revalidation, fail-closed, - exact-channel, all-links-active and crash-cleanup gates while finishing the phase. +PixelPass commit `e027bc6` completes Phase 6's separate live signal qualification. Its +deliberately unsafe predicate is wholly `#[cfg(test)]` and re-admits only the exact configured +`aec-identity` candidate. The live test drives the hidden selector through the real sink, +observer, taint controller, native link manager and Pulse monitor recording path; filters +`media.class` before the exact module ID; preserves child stderr; and verifies the intended +links in PipeWire before recording with `parec`. + +Two complete runs kept the guarded 1500 Hz result at or below the run's control floor within the +declared 3 dB tolerance, while the naive arm captured 1500 Hz at desktop level and at least 18 dB +above control and guarded. The supported result is **no incremental 1500 Hz energy detectable +above the control floor at this analysis resolution**, not proof of absence. Full validation is +346 passed and 13 ignored; strict Clippy, all four serialized Phase 6 live audio gates, +`pixelpass --doctor` and residue checks pass. + +1. **Continue with Phase 7:** publish the mode selector and versioned capability from PixelPass, + preserving the old-PeerSpeak/new-PixelPass compatibility gate. +2. Then complete Phase 8's capability-gated PeerSpeak argv, picker, UI and causal status path. Still owed beyond that, unchanged: the §9.2 rig upgrade before any exclusion claim is published, and **field-test §12** — nothing in this design has been tested over the real