Skip to content

MISB ST 1402.2 requirement trace

This trace is bound to the official 27 October 2016 publication with SHA-256 52a3b32a7314d2884d421c74718b808402f9cc5c852168b0c84f872b773100e0. The edition contains exactly 22 active numbered requirements and four requirements explicitly marked deprecated. MPEG-2 TS syntax is cross-checked against the aligned ITU-T H.222.0 (10/2014) text, equivalent to ISO/IEC 13818-1:2015.

Requirement/area Implementation/test State
ST 1402-01, integer TS packets per UDP datagram transport.udp packetizer/validator and arbitrary-chunk/truncation/sync/bound tests Verified
ST 1402-02, recurring PAT and PMT exact-timeline validator, PCR-bracketed recording validator, scheduler, timed LiveTransportTransformer, unit tests, independent blackout corpus Writer/live receiver plus conservative finite-recording verification proven
ST 1402-03, asynchronous KLVA registration identifier asynchronous_klv_stream, PMT validator, malformed and wrong-identifier tests Verified
ST 1402-04, synchronous metadata follows ISO/IEC 13818-1 transport.metadata, transport.metadata_stream, transport.std, and H.222.0 trace Applicable metadata PES/AU/STD branch verified; this is not a claim over unrelated ISO Systems profiles
ST 1402-07, every synchronous PES carries PTS synchronous mux and strict receiver tests Verified
ST 1402-08, synchronous PTS_DTS_flags is 10 PES encoder/parser plus missing-PTS and forbidden-DTS receiver tests Verified
ST 1402-09, synchronous PES begins at a Metadata AU Cell data-alignment, cell parsing, fragmentation, and malformed-boundary tests Verified
ST 1402-10, PES PTS applies to every contained AU multi-cell decode events preserve one PES PTS Verified
ST 1402-11, PTS signals AU relevance time MetadataStreamDecoder and bounded FrameMetadataCorrelator policies Verified as transport relevance time; sensor timing truth is producer-owned
ST 1402-12, synchronous STD delay no greater than one second exact finite and conservative live STD models plus verifier Verified where arrival timing is provable from PCR; ambiguity remains explicit
ST 1402-13, add metadata to an existing synchronous stream LiveTransportTransformer reuse and duplicate-stream rejection tests Verified producer policy
ST 1402-14, synchronous metadata is a separate stream in the imagery program PMT builder and validate_st1402_metadata_program same-program tests Verified
ST 1402-15, one metadata descriptor per service unique multi-service builder, duplicate-service validator, mux/receiver declaration checks Verified
ST 1402-16, metadata descriptors are in the elementary-stream loop PMT validator checks misplaced descriptors even when a valid stream descriptor also exists Verified
ST 1402-17, exactly one metadata STD descriptor typed codec plus missing/duplicate/malformed PMT tests Verified
ST 1402-18, asynchronous carriage follows SMPTE RP 217 async mux/receiver and clause trace Transport-stream branch verified; Program Stream is outside this TS standard's profile
ST 1402-20, alignment set at a KLV beginning multi-PES writer and receiver boundary tests Verified
ST 1402-21, alignment clear away from a KLV beginning continuation, empty-PES, and contradictory-flag tests Verified
ST 1402-22, asynchronous PES carries neither PTS nor DTS writer and strict receiver rejection tests Verified
ST 1402-24, asynchronous metadata is a separate stream in the imagery program PMT builder and expected-carriage validator Verified
ST 1402-25, registration descriptor is in the elementary-stream loop PMT validator checks absence, identity, and misplaced program-loop registration Verified
ST 1402.1-26, synchronous metadata format identifier is KLVA typed descriptor decoder and PMT validator Verified
Section 7, 188-byte TS packet framing transport.mpegts, test_mpegts.py Strict parsing, exact construction, and parsed-packet rebuilds verified against H.222.0 packet syntax
§7.2, PCR at least once every 100 ms transport.pcr.PCRCadenceValidator Inclusive boundary, one-tick overrun, per-program, rollover, PID-change, and discontinuity tests verified
§7.2, PCR insertion TransportMuxer.mux_pcr, ProgramClockScheduler Parser/demux round trip, non-advancing payload continuity, exact rational schedule, actual-time clock derivation, rollover, skipped-slot, and late-gap tests verified
§7.2 plus H.222.0 §2.4.2.2, output-rate shaping and retained PCR rewrite transport.rate.TransportRateShaper arbitrary chunks, exact rational packet slots, bounded null fill, PCR-base-byte sample position, OPCR/packet preservation, and malformed/truncated input tests verified
§7.3, successive PTS difference no greater than 0.7 s per elementary stream transport.pts.PTSCadenceValidator, FMVVerifier Exact boundary, one-tick overrun, 33-bit rollover, reordering, per-stream isolation, and discontinuity tests verified
H.222.0 §2.7.5, first-AU PTS and video PTS/AU alignment transport.access_unit_timing.VideoAccessUnitPTSValidator, audio verifier MPEG-1/2 Video, AVC, HEVC, Layer II, and AAC-LC first-AU detection, split-boundary attribution, bounded deferred alignment, discontinuity, finite completion, and report tests verified
§7.3 PTS on every Motion Imagery frame MISB usability recommendation, intentionally not reported as a mandatory error
§7.3/§9.1 cross-stream PTS synchronization transport.timing unwraps 33-bit PTS values against per-program forward watermarks with explicit half-epoch ambiguity rejection Timeline primitive verified

The KLVA format identifiers required by ST 1402-03 and ST 1402.1-26 are recognized in asynchronous registration descriptors and synchronous metadata descriptors respectively. The carriage implementations validate the surrounding requirements as one profile rather than treating either identifier as sufficient on its own.

ST 1402-05, ST 1402-06, ST 1402-19, and ST 1402-23 are explicitly deprecated by this edition because their stream IDs and stream types are already required by ISO/IEC 13818-1. The implementation still enforces those wire values through the H.222.0 profile, but they are not counted as active ST 1402.2 requirements.

validate_st1402_metadata_program produces structured, requirement-labelled diagnostics for an entire PMT. It verifies that metadata shares a program with a recognized motion-imagery stream, checks carriage-specific stream types and descriptor-loop placement, requires asynchronous KLVA registration, and checks synchronous metadata descriptor identity/service prefixes plus the single metadata-STD-descriptor rule. It rejects program-loop placement even when an elementary-stream descriptor also exists and rejects duplicate service IDs. The typed descriptor codec enforces the three reserved-bit-prefixed 22-bit fields and exposes the H.222.0 physical units of 400 bits/s and 1,024 bytes without rounding. An explicit PID-to-carriage declaration lets it diagnose a stream whose own broken identifier prevents automatic discovery.

The packet parser is intentionally streaming: arbitrary input chunks are accepted, completed packets are emitted immediately, memory remains bounded to the caller's chunk plus one partial packet, and recovery reports every byte it discards. Adaptation fields expose PCR/OPCR, elementary-stream priority, signed splice countdowns, bounded private data, and typed legal-time-window, piecewise-rate, and seamless-splice extension fields; malformed lengths, markers, reserved bits, or stuffing fail structurally and surface through the FMV verifier. Canonical adaptation-field encoders support typed construction and modification of the same complete structure, including explicit outer and extension stuffing; exact-byte tests verify the writer against the strict reader. Complete packet builders calculate adaptation control, length, and outer stuffing while preserving header and payload fields during deliberate parsed-packet modifications. PMT decoding exposes every video, audio, and private-data elementary stream without assuming a fixed PID. Bounded PES reconstruction, PTS/DTS decoding, continuity, PSI cadence, PCR cadence, and metadata carriage checks are integrated. The program-aware live demuxer composes TS framing, PAT/PMT discovery, and per-PID PES reconstruction across arbitrary input chunk boundaries. It emits immutable events classified as video, audio, KLVA, or other data, atomically activates complete multi-section PAT cycles, permits several program-map sections on one PMT PID, and removes stale routes on current PAT updates. Remaining work is explicitly scoped in the H.222.0 requirement trace rather than treated as an unbounded ISO audit.

The writer builds deterministic, CRC-valid PAT/PMT sections and bounded PES packets, then packetizes them with independent per-PID continuity counters. An asynchronous KLVA writer uses stream ID 0xBD, omits PTS/DTS, asserts data alignment only where the PES payload begins the KLV item, and requires a matching KLVA registration in the PMT. One large KLV item may span multiple bounded PES packets; continuation packets clear the alignment indicator and the incremental receiver validates the inverse rule at every non-empty boundary. Empty PES packets seen in deployed FMV streams are tolerated because they have no first data byte and cannot alter parser alignment. The writer first validates that its input is exactly one complete Universal KLV item. This behavior is tested end to end against the demuxer. The acquired publisher copy of SMPTE RP 217 is now traced clause by clause in the RP 217 requirement trace. The writer and strict receiver additionally enforce non-zero PES length and a clear ESCR flag.

Synchronous metadata construction is grounded in ST 1402.2 and the official ITU-T H.222.0 (10/2014), which contains the aligned ISO/IEC 13818-1 Metadata AU Cell syntax and fragment semantics. The writer emits stream type 0x15, stream ID 0xFC, KLVA metadata and metadata-STD descriptors, PTS-only PES headers, five-byte Metadata AU Cell headers, wrapping sequence counters, and correct complete/first/middle/last fragmentation. MetadataDelayValidator bounds each synchronous PES arrival between adjacent program PCR samples. It reports only delays that are certainly greater than one second or certainly late, accepts only ranges entirely inside [0, 1], and counts boundary-straddling or unbracketed arrivals instead of converting uncertainty into a pass. SynchronousMetadataSTDModel applies the descriptor leak rate and buffer size to every exact transport byte, including the fixed 512-byte TBn, PES overhead in Bn, access-unit-only delay, instantaneous PTS removal, aggregate occupancy, underflow/overflow, and the one-second emptying rule. The PCR/PES adapter derives t(i) with H.222.0 equations 2-4 and 2-5 and rejects missing brackets or discontinuities. MetadataSTDStreamValidator retains buffer fullness across PCR windows, retires processed events at exact watermarks, bounds every pending state dimension, and is integrated into the CLI alongside the conservative delay validator.

AsynchronousMetadataSTDModel and its bounded incremental counterpart implement the H.222.0 continuous-output branch when an application supplies input leak, output leak, and buffer parameters. The aggregate PCR/PES adapter derives exact byte arrivals without PTS. MetadataSTDStreamValidator and FMVVerifier apply the same model continuously across bounded PCR windows when given a per-program/PID descriptor mapping; absent mappings remain explicit unverifiable coverage. ST 1402 RP 217 signalling ordinarily supplies only the KLVA registration descriptor, so the verifier does not fabricate absent STD parameters or claim this optional audit automatically.

MetadataStreamDecoder is the inverse live path: it validates carriage-specific PES rules, incrementally reconstructs asynchronous KLV, parses synchronous AU wrappers, rejects undeclared metadata service IDs, verifies sequence continuity, bounds and reassembles fragments, and returns complete KLV events carrying their PID, program, PTS, service ID, and typed ST 0601/ST 0903 value where recognized.

FrameMetadataCorrelator implements the receiver-side relevance policy for synchronous KLV. Equal video and metadata PTS values form an exact match; latest-relevant and nearest policies require an explicit maximum delta and optional configured sampling offset. PTS unwrapping is isolated per program. Asynchronous KLV is never auto-associated because §9.4.2 says its synchronization cannot be guaranteed through decoding.

UdpTransportPacketizer implements the delivery boundary in Section 8. It groups arbitrary byte chunks into UDP payloads containing only complete 188-byte TS packets, defaults to the recommended seven packets for a 1,500-byte Ethernet MTU, emits a smaller integral final payload, and rejects partial or misaligned input. validate_udp_datagram provides the corresponding receiver check. The maximum configuration is bounded by the UDP payload limit.

PSICadenceValidator audits current PAT and every PAT-announced program's PMT on a caller-selected monotonic timeline. It treats an interval equal to 250 ms as a violation because ST 1402-02 requires a frequency greater than four times per second, exposes the recommended 125 ms interval, detects initially missing tables when given a program-start baseline, and retains independent deadlines across PAT reconfiguration. Multi-section PAT instances count only after every section in the cycle has arrived; H.222.0 PMT section numbers are required to be zero. The checker is clock-source agnostic so live applications can use a monotonic host clock while file audits can use exact PCR-derived fractions. ProgramTableScheduler supplies the writer side at the recommended exact 125 ms interval. It emits immediately, advances PAT/PMT continuity through the muxer, avoids drift, and exposes late polls, skipped slots, and strict-interval violations. Timed LiveTransportTransformer calls use the scheduler directly and provide an explicit idle-loop poll; the application remains responsible for invoking that poll frequently enough.

PCRCadenceValidator audits the separate §7.2 clock-reference requirement directly from the demuxer's program-aware PCR events. It accepts exactly 100 ms, reports a one-tick overrun, unwraps the composite 33-bit-base plus 9-bit- extension PCR epoch, and keeps independent state when programs share a clock PID. A declared time-base discontinuity or PCR PID change reanchors the program; an undeclared regression is a distinct diagnostic. This validates observed spacing, not the H.222.0 PCR accuracy/jitter or T-STD model.

ProgramClockScheduler supplies the live writer side when the application has an authoritative monotonic output timeline. It anchors a caller-supplied 27 MHz encoder clock, uses a drift-free rational schedule, emits PCR sampled from the actual poll instant, follows a reconfigured PMT clock PID, and exposes skipped slots and any gap beyond 100 ms. Its default 50 ms interval is an operational headroom choice rather than a second standards claim. The application must still poll and write packets on the stated timeline.

PTSCadenceValidator audits §7.3 independently for each program/PID pair. It accepts exactly 0.7 seconds, reports a one-tick overrun, uses nearest-epoch 33-bit PTS unwrapping, tolerates small presentation-order regressions, and reanchors on a declared discontinuity or changed stream type. The FMV verifier feeds every completed PES event into this validator. This is an encoded- timestamp cadence check, not a decoder-buffer or per-frame PTS-presence model.