docs: close Phase 6 signal qualification

This commit is contained in:
2026-08-21 21:00:38 -04:00
parent bf6d0e47b5
commit d72271bd2e
2 changed files with 53 additions and 9 deletions
+32 -4
View File
@@ -19,10 +19,10 @@ construction gates are built, validated and committed locally in PixelPass (`6be
**The independent Row 6a/6b/6c refusal gates are built, validated and committed locally in
PixelPass (`956534f`).** **The revised Row 9 positive/negative late-arrival partition is built,
validated and committed locally in PixelPass (`7b11827`).** The deterministic Phase 6
link-manager matrix is complete; its production-path three-arm leak qualification, plus phases
79, is not built — nothing
released to date changes the feature's user-visible behaviour. **Phase 6 remains the current
front.**
link-manager matrix is complete. **The production-path three-arm AEC leak qualification is
built, validated and committed locally in PixelPass (`e027bc6`), completing Phase 6.** Phases
79 are not built — nothing released to date changes the feature's user-visible behaviour.
**Phase 7 is now the current front.**
**Date:** 2026-07-21 (v4); status line refreshed 2026-08-21
**Design of record:** [`screenshare-audio-exclusion-plan.md`](screenshare-audio-exclusion-plan.md) v3.8, round 11.
**Scope:** *ordering, gates and acceptance criteria only.*
@@ -787,6 +787,34 @@ ancestry becoming unsafe.
> link-manager matrix is now complete. Phase 6 remains open on its production-path three-arm AEC
> leak measurement re-run, whose naive positive control must exist only behind a test seam.
> **Production-path three-arm AEC leak qualification — built, validated and committed locally as
> PixelPass `e027bc6` on 2026-08-21. Phase 6 is complete.** A `#[cfg(test)]` policy can re-admit
> only the exact configured `aec-identity` candidate; the unsafe policy, constructor and field do
> not exist in a production build. A focused controller gate proves safe mode retains only the
> ordinary stereo pair while the deliberately naive mode adds exactly the AEC playback pair.
>
> The ignored serialized live gate drives the hidden `DesktopExcluding` selector through the real
> connection-owned sink, registry observer, taint controller, native link manager and
> `<sink>.monitor` Pulse source. It loads one exact-ID WebRTC echo-cancel module per arm, filters
> `media.class=Stream/Output/Audio` before matching `pulse.module.id`, retains and reports every
> child stderr stream, verifies the exact graph links, and records 48 kHz stereo s16le with
> `parec`. The guarded and naive arms inject a PeerSpeak-owned 1500 Hz stream into the real AEC
> sink; all arms retain an ordinary 440 Hz desktop stream.
>
> Two complete runs passed the thresholds declared in the test. Desktop 440 Hz stayed between
> -32.84 and -34.05 dBFS. The guarded arm's 1500 Hz result (-75.76 to -78.03 dBFS) never rose more
> than 3 dB above its run's control floor, while the naive positive control measured -33.80 to
> -33.92 dBFS, comparable to its desktop tone and at least 18 dB above both control and guarded.
> The supported conclusion is deliberately narrow: **no incremental 1500 Hz energy was detectable
> above the control floor at this analysis resolution**; this is not a claim that remote audio is
> absent. Phase 9 still owns the PN/MLS intelligibility rig and field variance.
>
> Final PixelPass validation: 346 passed, 0 failed and 13 ignored; strict all-target Clippy,
> formatting, `git diff --check`, `pixelpass --doctor`, and all four serialized Phase 6 live audio
> gates pass. The final Pulse/PipeWire/process/temp-file residue scan is empty. Nix is unavailable,
> so validation used system Rust 1.96.1. The next implementation front is Phase 7's public mode
> selector and versioned capability advertisement.
Failure ⇒ report the stream unsupported. **Never** fall back to the default monitor — and after
0d that fallback is unconstructible in this mode, by either path.