Skip to content

merge upstream v1.5.7 (+6 master fixes) and feat: add SRTO_PERIODICNAKGATE (1.5.7+ceralive.2) - #24

Closed
andrescera wants to merge 17 commits into
masterfrom
feat/bonded-path-convergence
Closed

andrescera wants to merge 17 commits into
masterfrom
feat/bonded-path-convergence

Conversation

@andrescera

@andrescera andrescera commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Summary

Release PR for 1.5.7+ceralive.2 (tag srt-v1.5.7+ceralive.2, owner tags after merge). Version, tag and asset names come from the sender repo's docs/evidence/bpc/srt-release.json; nothing was decided or hardcoded here.

Merge as a normal merge (do not squash): the history shape is the upstream v1.5.7 merge commit, then the option commits, then the post-tag fold merge, then this release commit. Two true merge commits must survive.

Upstream merge: Haivision v1.5.7

379d129 is a true two-parent merge of Haivision 899348d ("Change to version 1.5.7") onto 1615b82. It brings:

  • KMREQ / encryption-state validation, ACK and DROPREQ validation, FEC bounds checks, bonding BACKUP lifetime (UAF) fix, and sample-tool path validation (6f817b6, fcae571).
  • Upstream CI/ABI checker fixes (a13859e).

Conflicts were confined to workflows, encryption test storage and test_main helpers; the fork's SRTO_REORDERFREEZE and deterministic socket teardown merged cleanly and are retained.

The patch: SRTO_PERIODICNAKGATE (opt-in, default off)

Receiver-side bool socket option (SRTO_R_PRE, inherited by accepted sockets, URI periodicnakgate). When on, checkNAKTimer subtracts the m_FreshLoss ranges (packets still inside the packet-count reorder window) from the loss array before building the periodic NAK report, so only losses that have outlived the reorder window are re-reported. On a bonded SRTLA path the periodic report is otherwise dominated by packets that are merely late, and each re-report requests a retransmission that is about to arrive anyway.

  • Ports the subtraction hunk of onsmith/srt b5690bc (2026-07-05) without its SRTLAPATCHES build switch; adapted to v1.5.7's FixedArray<int32_t> / one-arg getLossArray, static comparator for C++03.
  • Scope: periodic-report gating only. Immediate loss report, unlose, NAK scheduling, LiveCC interval floor and reorder-tolerance decay are untouched. Default-off is byte-for-byte upstream behavior. Independent of SRTO_REORDERFREEZE and SRTO_NAKREPORT.
  • Commits: 5bd9a23 (plumbing + URI rows), ca14c8b (behavior), 8f33e0e (+ceralive.1 release: docs, package contract, enum value fix, ABI evidence), c70586b (+ceralive.2 release: fold docs + version bump).
  • Docs: docs/CERALIVE-PATCHES.md §2 and AGENTS.md → SANCTIONED CERALIVE PATCHES, including the fork-reserved value band, collision policy and upstream-proposal status (deferred, field-evidence gated).

Post-tag master fixes folded (new in 1.5.7+ceralive.2)

Six Haivision master commits landed after the v1.5.7 tag (899348d). They are folded here as a second true two-parent merge (12426a3, parents 8f33e0e + 1078f2f): built as a linear git cherry-pick -x series onto 899348d, then merged with --no-ff and no strategy flag. Every commit keeps its (cherry picked from commit <full-sha>) trailer, so the original upstream SHAs survive review.

PR SHA Files Why
#3366 922a890 srtcore/buffer_tools.cpp Potential division by zero in CSndRateEstimator
#3371 73d8cd6 srtcore/buffer_rcv.{cpp,h}, test/test_buffer_rcv.cpp Potential crash and wrong receive-buffer state from outdated positionals
#3369 8b852eb srtcore/api.cpp, srtcore/queue.h Fixes for rough cleanup actions
#3333 abf708d srtcore/{api,core,group,packet}.cpp, srtcore/packet.h, test/test_bonding.cpp, testing/*, configure-data.tcl, scripts/* Collection of small detailed fixes and cleanups
#3330 03fae0e srtcore/core.{cpp,h}, examples/fork-test/* Simplified socket close on fork cleanup, prevents potential deadlocks
#3351 cae8f62 test/test_file_transmission.cpp UnitTest: file transmission interrupted by an immediately closed socket

srtcore/srt.h is untouched by all six, so no installed public header moves.

Merge needed no conflict resolution — and that was verified, not assumed

None of the six touch checkNAKTimer, so the // CERALIVE periodic-nak-ttl block and both // CERALIVE reorder-freeze gates are untouched; upstream's core.cpp edits land in unrelated functions. Because nothing was hand-resolved, the result was proven by git patch-id --stable in both directions:

  • diff 8f33e0e..12426a3 == diff 899348d..1078f2f (33aa6cd5…) — the merge adds exactly the six upstream commits, nothing more, nothing less.
  • diff 1078f2f..12426a3 == diff 899348d..8f33e0e (8b650f79…) — every CeraLive change survives intact.

Deliberately excluded (2 of the 8 commits in range)

PR SHA Why excluded
#3380 ff8ab25 Public-header signature change. Deprecates the public UDPSOCKET typedef and retypes srt_bind_acquire's 2nd parameter to SYSSOCKET. Public-API churn with no functional fix → out of scope for a runtime-fork release. Measured, see the control below.
#3355 500b1c8 ABI-lane rewrite. Rewrites shared CI into scripts/workflows/** and rewrites abi.yml itself, which would replace the CeraLive ccache contract and the pinned SRT_BASE: srt-v1.5.6+ceralive.1. A CI decision, not a source fix; must not ride along in a source release.

The exclusion is verified exactly, not by omission: the fold tip differs from upstream cae8f62 by precisely 500b1c8's patch-id (f66a5c1a…), and git diff --stat over srtcore/ test/ apps/ common/ haicrypt/ examples/ testing/ CMakeLists.txt between them is empty — zero source drift.

Falsifiability control for the #3380 exclusion

ff8ab25 was cherry-picked onto a throwaway branch and run through the identical ABI procedure. Result, recorded as measured rather than as predicted:

Binary compatibility: 100%   Source compatibility: 100%
Total binary compatibility problems: 0, warnings: 2     (the fold: warnings: 0)
ABI_CHECKER_EXIT=0

Two Low-severity symbol problems — srt_bind_acquire (srt.h) and UDT::bind2 (udt.h), "Type of 2nd parameter has been changed from UDPSOCKET to SYSSOCKET… may indicate a change in its semantic meaning". On Linux both typedefs are int, so binary compatibility stays 100% and the checker exits 0.

So #3380 would not have failed the lane. It is excluded as out-of-scope public-API churn, not as an ABI break — the "would break ABI" framing is withdrawn, and the fold without it is strictly cleaner (warnings: 0 vs 2). Throwaway branch deleted after the run.

Test evidence

ABI result (baseline unchanged: srt-v1.5.6+ceralive.1)

Re-ran the abi.yml procedure (Debug, BONDING/PKTINFO/MAXREXMITBW, abi-dumper 1.2, abi-compliance-checker 2.3, public installed headers) in Ubuntu 24.04 against the baseline tag; baseline dump hash identical to the one used for the merge decision.

  • First candidate (SRTO_PERIODICNAKGATE = 121): FAIL, 97.2% binary, one Medium problem: SRTO_E_SIZE moved 121 → 122 (the auto-valued public sentinel). The new member itself was "No effect".
  • Fix in the option, not the lane: SRTO_PERIODICNAKGATE = 119, placed below the frozen band top SRTO_REORDERFREEZE = 120, so SRTO_E_SIZE stays 121. Fork options are now allocated downward (111-120), which keeps the sentinel fixed for every future fork option.
  • Result: 100% binary / 100% source, 0 problems, 0 warnings, checker exit 0. Only "other change": member added with value 119, no effect.
  • Re-run on the fold (12426a3): still 100% / 100%, 0 problems, 0 warnings, exit 0. Baseline dump hash identical to the earlier runs (1756e5be…), so the comparison target is provably unchanged. The only reported change remains our own SRTO_PERIODICNAKGATE = 119 ("No effect") — the six folded commits add zero ABI surface, which is what srt.h being untouched predicts.

abi.yml's SRT_BASE was NOT advanced and the lane was NOT silenced; advancing to srt-v1.5.7+ceralive.2 is a separate PR after the owner publishes the tag.

Owner actions after merge

  1. Tag srt-v1.5.7+ceralive.2 on the merge result.
  2. Run publish-release.yml (default version already 1.5.7+ceralive.2) to produce libsrt1.5-ceralive_1.5.7+ceralive.2_{amd64,arm64}.deb.
  3. Separately, advance abi.yml SRT_BASE to the new tag.

ethouris and others added 17 commits July 30, 2026 14:17
…on (Haivision#3349)

* Fixed gcov rule. Fixed ABI compliance checker to use local installation

* Removed codecov for C++03. Fixed wrong call path for gdb after tests

* Fixed crypto tests build break when encryption disabled

* Fixed CI on macos. Tracking a problem on ABI

* Refactored TestEnforcedEncryption to simplify initialization

* Fixed ABI. Fixed mac warn build break on ENC=no

* Added missing ASH variable to output

* Tracking problem with ABI

* Changed abi compliance checker to official package. Fixed options in configure-data

* Preserved RES up until the end to prevent error blocking report download

* Changed command call to swallow error result (prevents premature interrupt of the step)

* Fixed uploading HTML report for ABI

* I hate YAML

* Using Create Browser Link instead

* Changed ABI reporting to uploading html with no zipping

* Updated Ubuntu packages before installing

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
…#3323)

* [core] Added checks to prevent rogue CMD MSG to sneak thru

* [core] Fixed OOB read in ACK payload parsing.

* Added protection against rogue DROPREQ. Added status return for cmd dispatchers. Changed tests for cmd dispatchers to work on a connected socket. Added protection against rogue DROP in receiver buffer

* Fixed codespell

* Wrong keyword for CUnit in tests

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
* Fixed vulnerabilities reported as SRTX-61

* Next portion of fixes from SRTX-62

* Fixed #11 for SRTX-62

* Added MD5 check to the dependency installer scripts

* Applied safety fixes for Windows installer scripts

* Post-review fixes for vulnerability issues

* Post-review fixes, take 3

* Remaining parts of Take 3

* Fixes, take 4. Fixed ASSERT usage in FEC tests

* Take 5, possibly final

* Fixed build break with --disable-encryption

* Fixed codespell

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
Updated link to SRT Alliance Deployment Guide
Co-authored-by: Clément Gérouville <cgerouville@haivision.com>
Release cutover for the bonded-path convergence line (version read from the
sender repo's docs/evidence/bpc/srt-release.json, not decided here).

- docs/CERALIVE-PATCHES.md + AGENTS.md: two sanctioned socket-option patches
  (SRTO_REORDERFREEZE, SRTO_PERIODICNAKGATE), each with scope discipline and
  upstream-proposal status (deferred); fork-reserved value band and collision
  policy; version contract moved to 1.5.7+ceralive.1.
- packaging: build-deb.sh default 1.5.7+ceralive.1, Provides (= 1.5.7);
  package-contract.sh now also asserts the deb prefix == Provides == CMake
  SRT_VERSION and rejects stale 1.5.5/1.5.6 workflow references;
  publish-release.yml default and runtime-package.yml verify path updated.
- srt.h: SRTO_PERIODICNAKGATE renumbered 121 -> 119, below the frozen band top
  SRTO_REORDERFREEZE = 120, so SRTO_E_SIZE stays 121. Measured in the abi.yml
  procedure against srt-v1.5.6+ceralive.1: at 121 the moved sentinel scored
  97.2% binary (1 Medium problem); at 119 it is 100%/100% with zero problems.
  Fork options are now allocated downward (111-120) so the sentinel never
  moves again. ABI baseline unchanged.

Gate: package-contract OK; deb build + verify-runtime-replacement green in
debian:bookworm; codespell 2.4.3 clean; full ctest 299/299 in an isolated
netns; ABI 100%/100% vs srt-v1.5.6+ceralive.1.
…3366)

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit 922a890)
…dated positionals (Haivision#3371)

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit 73d8cd6)
* Added stop() in CMultiplexer destructor to ensure closed threads before destroying

* Using cleanupAllSockets when all threads are expected to exit

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit 8b852eb)
…ision#3333)

* [core][build] A collection of small detailed fixes and cleanups

* Fixed related to mpbond testing

* Removed redundant false-init of atomic (causes build breaks on some gcc versions)

* Attempting to fix MSVC build break

* Attempting to fix MSVC build break (Take 2)

* Enforced stable compiler on Windows CI

* Enforced stable compiler on Windows CI (with no -G)

* Fixed a message

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit abf708d)
…otential deadlocks (Haivision#3330)

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit 03fae0e)
…iately closed socket (Haivision#3351)

* Fixed bug: keep the GC thread running, even if requested to close, if there are still uncollected sockets

* Fixed test: prevent flooding of error reports

---------

Co-authored-by: Mikolaj Malecki <mmalecki@haivision.com>
(cherry picked from commit cae8f62)
… bump to 1.5.7+ceralive.2

Six Haivision master commits that landed after the v1.5.7 tag are folded into this
line as a second true two-parent merge (12426a3): a linear `git cherry-pick -x`
series onto 899348d, merged with --no-ff and no strategy flag, so every original
upstream SHA survives in a cherry-pick trailer.

  Haivision#3366 922a890  div/0 in CSndRateEstimator
  Haivision#3371 73d8cd6  crash / wrong buffer state from outdated positionals
  Haivision#3369 8b852eb  rough cleanup actions
  Haivision#3333 abf708d  small detailed fixes and cleanups
  Haivision#3330 03fae0e  simplified socket close on fork cleanup (deadlocks)
  Haivision#3351 cae8f62  UnitTest: file transmission interrupted by an immediate close

Two commits in the same range are deliberately excluded: ff8ab25 (Haivision#3380) public-header
signature change, and 500b1c8 (Haivision#3355) ABI-lane rewrite. The exclusion is verified
exactly, not by omission — the fold tip differs from upstream cae8f62 by precisely
500b1c8's patch-id, with zero drift in srtcore/, test/ or apps/.

The merge needed no conflict resolution: none of the six touch checkNAKTimer, so the
CERALIVE periodic-nak-ttl and reorder-freeze gates are untouched. Correctness was
proven by patch-id in both directions — the merge adds exactly the six upstream
commits, and every CeraLive change survives intact.

srtcore/srt.h is untouched by the fold, so no public header moves.

Gate: full ctest 301/301 of 302 registered in an isolated netns (the fold adds exactly
two tests, CRcvBufferReadMsg.SmallNonOrderReadBuffer and
Transmission.FileUploadInterrupted; none removed); PeriodicNakGate 6/6 including the
option-off premature-NAK control; codespell 2.4.3 clean; package-contract OK.

ABI vs srt-v1.5.6+ceralive.1 (baseline NOT advanced, lane NOT silenced): 100% binary,
100% source, 0 problems, 0 warnings. The only reported change is our pre-existing
SRTO_PERIODICNAKGATE = 119 ("No effect"); the six commits add zero ABI surface.

Falsifiability control: ff8ab25 cherry-picked onto a throwaway branch and run through
the identical procedure scores 100%/100% with 2 Low-severity symbol problems
(warnings: 2) on srt_bind_acquire and UDT::bind2 — it would not have failed the lane,
so it is excluded as out-of-scope public-API churn rather than as an ABI break. That
correction is recorded in AGENTS.md; the throwaway branch was deleted.

Version read from the sender repo's docs/evidence/bpc/srt-release.json, not decided
here. Provides stays (= 1.5.7).
@andrescera andrescera changed the title merge upstream v1.5.7 and feat: add SRTO_PERIODICNAKGATE (1.5.7+ceralive.1) merge upstream v1.5.7 (+6 master fixes) and feat: add SRTO_PERIODICNAKGATE (1.5.7+ceralive.2) Sep 19, 2026
@andrescera

Copy link
Copy Markdown
Member Author

Closed unmerged: superseded by feat/srtla-options-1.5.7 (reset-to-master + minimal re-implementation, plan upstream-rebase-hard-fork). Branch retained as reference.

@andrescera andrescera closed this Sep 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants