Remaining work and continuation guide¶
This page records the work that remains after the 0.3.0 release.
It separates verified capability from future scope so another developer or agent
can resume without reconstructing project history.
Paused handoff¶
Development was intentionally paused after commit bc3f722 while the project
seeks user traction and representative integration partners. That commit adds
bounded RFC 4566 SDP descriptions for the implemented ST 0804 MPEG-2
Transport Stream over RTP profile. The worktree and origin/main were clean and
synchronized at the pause point.
The next standards investigation was MISB ST 2101, Core Identifier for Class 1 and Class 2 Motion Imagery. Current MISP requirements use it to correlate an identifier embedded in compressed imagery with the corresponding metadata Core Identifier already represented by the library's ST 1204 support. Before writing implementation code:
- Obtain and record an authoritative ST 2101 edition in the standards manifest.
- Confirm its applicability to contemporary Class 1 H.262, AVC, and HEVC workflows and distinguish it from the STANAG 4609 Edition 5 / MISP-2019.1 baseline where necessary.
- Extract a checksum-bound requirement inventory and official vectors or build independently reviewable vectors directly from the normative text.
- Start with failing tests for exact read/write, placement, malformed input, bounded incremental parsing, and video-to-ST 1204 metadata correlation.
- Implement only the evidence-backed profile and label it as a current-MISP extension until the conformance evidence supports a stronger claim.
ST 2101 is a candidate, not a commitment. Apply the practical stopping rule in
the repository AGENTS.md: if authoritative text, credible demand, or adequate
test evidence is unavailable, leave the boundary documented and select the next
traced contemporary interoperability gap instead.
The objective completion audit maps the original release goal to current evidence. The narrowed library-readiness scope is complete; the production-readiness audit states the exact verdict and the items below are extensions or deployment-specific evidence.
Proven release baseline¶
- The full unit suite exceeds the configured 90% branch-coverage gate.
- Public integration tests cover H.264 with asynchronous KLVA, H.264/AAC with synchronous KLVA, and browser asset preparation with geospatial samples.
- An independently published 21-file negative-conformance corpus is pinned; 20 members prove fault-specific verifier diagnostics after per-member hash authentication. The sole unasserted PCR/PTS-drift member stays inside the applicable published timing bound and is retained as an explicit non-claim.
- The ArcGIS raw-video/CSV workflow generates MPEG-2 video, Layer II audio, and 866 synchronous ST 0601 packets; its structural verifier report is clean and every packet appears in the player timeline.
- Distribution builds, console entry points, strict documentation, and fresh wheel/source installs are release gates rather than manual assumptions.
See public fixtures for reproducible identities and the important negative-conformance expectations.
Highest-priority protocol work¶
- Complete MISP-2019.1 software-verifiable image-profile checks. Embedded ST 0604 timestamps are now parsed and count-audited for H.262/AVC/HEVC, with checksum-bound exact accounting for all 15 active and 11 deprecated ST 0604.6 requirements; every declared video stream is checked against the three approved Class 1 codec families while non-profile stream types remain losslessly preservable; H.262/AVC/HEVC dimensions, display/timing fields, scan signalling, and codec exact non-reserved profile/level signalling and the Class 1 eight-bit-per-band limit are now inspected across every observed sequence property set, so an early profile, scan, or bit-depth violation cannot be hidden by a later sequence. H.262 enforces its Main-profile 4:2:0 and constrained-flag signalling, Main/High Level sampling-density, padded-luminance-rate, declared bit-rate, and VBV-buffer limits, plus the zero frame-rate-extension rule for defined profiles; AVC and HEVC enforce Annex A coded-picture dimensions and available sequence-signalled sample throughput. Timestamp messages are now associated with recognized compressed access units using H.262 picture, AVC prefix-SEI, and HEVC prefix/suffix-SEI placement; broader whole-bitstream codec certification remains. All 86 active and 34 deprecated requirement identifiers now have checksum-bound exact inventory and human-readable disposition; the verifier also enforces MISP-2015.1-49 single-mechanism Security Metadata carriage. Producer-supplied source aspect ratio, source/conversion scan history, and analog/digital provenance are now checked directly for MISP-2015.1-01/-02/-05/-06 instead of being inferred from encoded display properties.
- Close the remaining contextual and cross-item ST 0601.19 conformance gaps, especially producer-supplied time-of-birth/precision facts. The child standards share a checksum-bound complete ST 0107.5 baseline for KLV, value encoding, UTF-8, and Report-on-Change semantics. The child standards embedded by Items 48, 73, 94, 95, 97, 98, 99, and 102 now have typed bridges; Item 48 has checksum-bound exact ST 0102.12 accounting plus complete Universal/Local Set conversion and policy-context enforcement for its software-verifiable profile; Item 73 has checksum-bound exact ST 0806.4 requirement accounting and producer-supplied time-of-birth validation; Item 94 has checksum-bound exact ST 1204.3 requirement accounting plus standalone KLV, checked text, XML, multi-sensor, and window-derivation support for its complete software-verifiable profile; Item 95 additionally has checksum-bound exact ST 1206.1 requirement accounting and effective-PRF/RCS exploitation helpers; Item 98 additionally has parallel Amend/MSID Report-on-Change resolution, and rejects Item 9/10 uncertainty arrays that lack their dimensionally compatible Item 4/5/8 source geometry, with checksum-bound exact ST 1601.2 requirement accounting for its complete software-verifiable profile; Item 99 has cross-branch policy validation and checksum-bound exact ST 1602.2 requirement accounting for its complete software-verifiable profile; Item 97 includes checksum-bound exact ST 1002.3 requirement accounting, caller-dimension SPRM center defaults, plane subtraction, and reconstruction for its complete software-verifiable profile. Every active root item is typed, and verifier summaries quantify which packets received birth-time, IMAP-precision, VMTI frame, and exact/tolerance-aware field ground-truth context, including every occurrence of multi-use root tags through order-independent matching; retain lossless unknown-item behavior for future extensions. The shared ST 1201.5 IMAP dependency now has checksum-bound exact requirement accounting and complete official-vector coverage. The shared ST 1303.2 multidimensional-array dependency likewise has checksum-bound exact requirement accounting and complete software-verifiable algorithm coverage.
- Expand ST 0903.6 beyond the implemented VMTI/VTarget/VTracker/VMask/VChip, ontology, algorithm, and geospatial slices with independent real-stream vectors. All 65 active and 78 deprecated identifiers now have checksum-bound exact accounting; remaining limitations are explicit contextual, producer-owned, or interoperability-evidence boundaries.
- Broaden independently reviewed ST 0902.8 policy profiles beyond the now implemented caller-supplied classification, country, handling, country-code-vocabulary, and minimum-version checks; policy authorship and authoritative dated code-list selection remain external.
- Broaden ST 1001.1-labelled audio conformance fixtures while keeping codec scope focused on common Layer II and AAC profiles.
- Add a redistributable real ST 0903/VMTI FMV fixture. Current positive VMTI
coverage is synthetic and standards-vector driven; it is not yet
independently sourced recorded-media interoperability evidence. Three
checksum-pinned
libmisbklvvectors now prove strict rejection of independent packets with contradictory target counts or missing mandatory standalone context, but those hand-authored negative vectors do not close this gap. The public ImpleoTV negative corpus and OpenSensorHub sample stream were inspected and contain no VMTI. OGC Testbed-16 identifies JSILS05.tsandS06.tsas ST 0903.3 VMTI recordings, but its published download location requires OGC member access; seek a lawful public mirror or contributor-provided stream.
Transport and live deployment¶
- ST 1402.2 now has checksum-bound exact accounting for all 22 active and four deprecated numbered requirements, including strict descriptor-loop placement and unique synchronous service declarations. Continue the broader ISO Systems audit through the deliberately scoped H.222.0 trace rather than treating the ST 1402 profile as whole-standard MPEG certification.
- Extend the ST 0804.4 MPEG-2 TS-over-RTP core only where deployments need it. Count-bounded sequence reordering plus strict RTCP Sender Report read/write and exact RTP/NTP synchronization are implemented. SR/RR-first compound validation, typed SDES CNAME, and packetizer sender counters/emission are implemented too. Bounded RFC 4566 SDP read/write now describes the supported RTP/AVP MP2T destination for VLC and similar receivers. Adaptive cadence, participant/collision/BYE state, native elementary-stream RTP, and RTSP remain separate profiles, not implied by multiplexed-TS support.
- Extend the implemented bounded MPTS-to-selected-SPTS transform with a separate whole-multiplex rewriting API if deployments require unrelated programs to remain in the same output transport.
- Extend the measured low-latency fragmented-MP4/MSE reference gateway from complete 148–371-second real-FMV runs to a published multi-hour paced campaign and production-scale concurrent viewers. The first-party JSON benchmark now proves bounded late-join histories and 8.44–17.68× finite-file headroom on three pinned fixtures. A separate first-party soak command performs average-bitrate-paced replay through isolated gateway/FFmpeg process epochs, preserves a failed epoch in its versioned JSON, and returns a failing status; a multi-hour published result remains outstanding. Prior-epoch SSE cursors reset into retained metadata immediately, while the Chromium-proven client rebuilds its MediaSource after prior-epoch media cursors fail without long-polling. Eight simultaneous HTTP viewers and three consecutive browser media rejoins are deterministic CI gates; larger and sustained fan-out remains deployment evidence. Sub-second targets, multi-viewer fan-out, adaptive bitrate, and WebRTC/HLS remain production deployment profiles.
- Extend the published live-player performance and memory method to sustained UDP, file demux, mux, verifier, and sidecar workloads when representative deployment data is available. This is not a blocker for bounded library APIs.
- The verifier PMT-validation cache is now proven bounded to one active identity per program across 128 changing revisions; extend the same measurement discipline to end-to-end throughput and resident memory.
- Extend deterministic fault injection into wall-clock network and subprocess campaigns. The unit suite now drives 20,000 RTP packets across sequence wrap with repeated loss, bounded reordering, and duplicates while proving exact output/accounting and the configured memory ceiling. A controlled 2,000-write gateway campaign proves that downstream pipe pressure reaches and stops the sole producer without a hidden queue. Real socket jitter, operating-system buffer pressure, FFmpeg stalls, and multi-hour impairment remain deployment evidence. Explicit reconnect boundaries already discard and report every partial TS/PSI/PES/KLV structure before rediscovery.
Developer experience and assurance¶
- Add external-link checking and broader executable documentation snippets to CI. Generated API targets, the shipped player JavaScript syntax, strict site build, and a deterministic Chromium interaction job for playback, seeking, synchronized static/SSE metadata, reconnects, diagnostics, overlays, and map rendering are already gated.
- Seek authoritative profile evidence before assigning any failure to the sole unasserted ImpleoTV PCR/PTS-drift member. Its observed H.264 timing remains within ST 1402 §7.4, so a corpus filename is not a conformance requirement.
- Test the optional GStreamer example in a dedicated dependency job. PyAV
already has a dedicated audio/video adapter job,
all-ST-1001-codec decode coverage, and real AAC FMV acceptance coverage. ONNX
Runtime has a dependency-installed job that builds a real graph, creates a CPU
InferenceSession, and executes it through the first-party adapter. Separate Triton HTTP and gRPC jobs construct official input/output objects and execute complete adapter requests against subclassed official AsyncIO clients; live server/model interoperability remains deployment-specific evidence. The Ultralytics job builds a real YOLO runtime model, executes CPU prediction and persistent ByteTrack through the adapter, and requires tracker initialization without downloading weights. - Add verified, version-specific interoperability results for Esri and other FMV consumers instead of predicting compatibility.
- Expand the first real UI/CLI tutorial captures with upgrade guides and
deployment-specific benchmark results before a stable
1.0API claim.
How to resume¶
- Read development method, conformance, and standards provenance.
- Pick one traced requirement or integration outcome and write its failing test first.
- Keep core dependencies empty; adapters own optional runtimes.
- Add the implementation, requirement-trace evidence, limitation change, and runnable example in the same small conventional commit.
- Run the full release gates in releasing before a tag.
Do not mark the overall library “fully STANAG 4609 conformant” until every applicable normative requirement has an auditable trace and independent fixture coverage. Pre-1.0 releases are useful integration milestones, not certification.