MISB ST 1402.2 requirement trace¶
This trace is bound to the official 27 October 2016 publication with SHA-256
52a3b32a7314d2884d421c74718b808402f9cc5c852168b0c84f872b773100e0.
The edition contains exactly 22 active numbered requirements and four
requirements explicitly marked deprecated. MPEG-2 TS syntax is cross-checked
against the aligned ITU-T H.222.0 (10/2014) text, equivalent to ISO/IEC
13818-1:2015.
| Requirement/area | Implementation/test | State |
|---|---|---|
| ST 1402-01, integer TS packets per UDP datagram | transport.udp packetizer/validator and arbitrary-chunk/truncation/sync/bound tests |
Verified |
| ST 1402-02, recurring PAT and PMT | exact-timeline validator, PCR-bracketed recording validator, scheduler, timed LiveTransportTransformer, unit tests, independent blackout corpus |
Writer/live receiver plus conservative finite-recording verification proven |
ST 1402-03, asynchronous KLVA registration identifier |
asynchronous_klv_stream, PMT validator, malformed and wrong-identifier tests |
Verified |
| ST 1402-04, synchronous metadata follows ISO/IEC 13818-1 | transport.metadata, transport.metadata_stream, transport.std, and H.222.0 trace |
Applicable metadata PES/AU/STD branch verified; this is not a claim over unrelated ISO Systems profiles |
| ST 1402-07, every synchronous PES carries PTS | synchronous mux and strict receiver tests | Verified |
ST 1402-08, synchronous PTS_DTS_flags is 10 |
PES encoder/parser plus missing-PTS and forbidden-DTS receiver tests | Verified |
| ST 1402-09, synchronous PES begins at a Metadata AU Cell | data-alignment, cell parsing, fragmentation, and malformed-boundary tests | Verified |
| ST 1402-10, PES PTS applies to every contained AU | multi-cell decode events preserve one PES PTS | Verified |
| ST 1402-11, PTS signals AU relevance time | MetadataStreamDecoder and bounded FrameMetadataCorrelator policies |
Verified as transport relevance time; sensor timing truth is producer-owned |
| ST 1402-12, synchronous STD delay no greater than one second | exact finite and conservative live STD models plus verifier | Verified where arrival timing is provable from PCR; ambiguity remains explicit |
| ST 1402-13, add metadata to an existing synchronous stream | LiveTransportTransformer reuse and duplicate-stream rejection tests |
Verified producer policy |
| ST 1402-14, synchronous metadata is a separate stream in the imagery program | PMT builder and validate_st1402_metadata_program same-program tests |
Verified |
| ST 1402-15, one metadata descriptor per service | unique multi-service builder, duplicate-service validator, mux/receiver declaration checks | Verified |
| ST 1402-16, metadata descriptors are in the elementary-stream loop | PMT validator checks misplaced descriptors even when a valid stream descriptor also exists | Verified |
| ST 1402-17, exactly one metadata STD descriptor | typed codec plus missing/duplicate/malformed PMT tests | Verified |
| ST 1402-18, asynchronous carriage follows SMPTE RP 217 | async mux/receiver and clause trace | Transport-stream branch verified; Program Stream is outside this TS standard's profile |
| ST 1402-20, alignment set at a KLV beginning | multi-PES writer and receiver boundary tests | Verified |
| ST 1402-21, alignment clear away from a KLV beginning | continuation, empty-PES, and contradictory-flag tests | Verified |
| ST 1402-22, asynchronous PES carries neither PTS nor DTS | writer and strict receiver rejection tests | Verified |
| ST 1402-24, asynchronous metadata is a separate stream in the imagery program | PMT builder and expected-carriage validator | Verified |
| ST 1402-25, registration descriptor is in the elementary-stream loop | PMT validator checks absence, identity, and misplaced program-loop registration | Verified |
ST 1402.1-26, synchronous metadata format identifier is KLVA |
typed descriptor decoder and PMT validator | Verified |
| Section 7, 188-byte TS packet framing | transport.mpegts, test_mpegts.py |
Strict parsing, exact construction, and parsed-packet rebuilds verified against H.222.0 packet syntax |
| §7.2, PCR at least once every 100 ms | transport.pcr.PCRCadenceValidator |
Inclusive boundary, one-tick overrun, per-program, rollover, PID-change, and discontinuity tests verified |
| §7.2, PCR insertion | TransportMuxer.mux_pcr, ProgramClockScheduler |
Parser/demux round trip, non-advancing payload continuity, exact rational schedule, actual-time clock derivation, rollover, skipped-slot, and late-gap tests verified |
| §7.2 plus H.222.0 §2.4.2.2, output-rate shaping and retained PCR rewrite | transport.rate.TransportRateShaper |
arbitrary chunks, exact rational packet slots, bounded null fill, PCR-base-byte sample position, OPCR/packet preservation, and malformed/truncated input tests verified |
| §7.3, successive PTS difference no greater than 0.7 s per elementary stream | transport.pts.PTSCadenceValidator, FMVVerifier |
Exact boundary, one-tick overrun, 33-bit rollover, reordering, per-stream isolation, and discontinuity tests verified |
| H.222.0 §2.7.5, first-AU PTS and video PTS/AU alignment | transport.access_unit_timing.VideoAccessUnitPTSValidator, audio verifier |
MPEG-1/2 Video, AVC, HEVC, Layer II, and AAC-LC first-AU detection, split-boundary attribution, bounded deferred alignment, discontinuity, finite completion, and report tests verified |
| §7.3 PTS on every Motion Imagery frame | — | MISB usability recommendation, intentionally not reported as a mandatory error |
| §7.3/§9.1 cross-stream PTS synchronization | transport.timing unwraps 33-bit PTS values against per-program forward watermarks with explicit half-epoch ambiguity rejection |
Timeline primitive verified |
The KLVA format identifiers required by ST 1402-03 and ST 1402.1-26 are recognized in asynchronous registration descriptors and synchronous metadata descriptors respectively. The carriage implementations validate the surrounding requirements as one profile rather than treating either identifier as sufficient on its own.
ST 1402-05, ST 1402-06, ST 1402-19, and ST 1402-23 are explicitly deprecated by this edition because their stream IDs and stream types are already required by ISO/IEC 13818-1. The implementation still enforces those wire values through the H.222.0 profile, but they are not counted as active ST 1402.2 requirements.
validate_st1402_metadata_program produces structured, requirement-labelled
diagnostics for an entire PMT. It verifies that metadata shares a program with
a recognized motion-imagery stream, checks carriage-specific stream types and
descriptor-loop placement, requires asynchronous KLVA registration, and
checks synchronous metadata descriptor identity/service prefixes plus the single
metadata-STD-descriptor rule. It rejects program-loop placement even when an
elementary-stream descriptor also exists and rejects duplicate service IDs.
The typed descriptor codec enforces the three
reserved-bit-prefixed 22-bit fields and exposes the H.222.0 physical units of
400 bits/s and 1,024 bytes without rounding. An explicit PID-to-carriage
declaration lets it diagnose a stream whose own broken identifier prevents
automatic discovery.
The packet parser is intentionally streaming: arbitrary input chunks are accepted, completed packets are emitted immediately, memory remains bounded to the caller's chunk plus one partial packet, and recovery reports every byte it discards. Adaptation fields expose PCR/OPCR, elementary-stream priority, signed splice countdowns, bounded private data, and typed legal-time-window, piecewise-rate, and seamless-splice extension fields; malformed lengths, markers, reserved bits, or stuffing fail structurally and surface through the FMV verifier. Canonical adaptation-field encoders support typed construction and modification of the same complete structure, including explicit outer and extension stuffing; exact-byte tests verify the writer against the strict reader. Complete packet builders calculate adaptation control, length, and outer stuffing while preserving header and payload fields during deliberate parsed-packet modifications. PMT decoding exposes every video, audio, and private-data elementary stream without assuming a fixed PID. Bounded PES reconstruction, PTS/DTS decoding, continuity, PSI cadence, PCR cadence, and metadata carriage checks are integrated. The program-aware live demuxer composes TS framing, PAT/PMT discovery, and per-PID PES reconstruction across arbitrary input chunk boundaries. It emits immutable events classified as video, audio, KLVA, or other data, atomically activates complete multi-section PAT cycles, permits several program-map sections on one PMT PID, and removes stale routes on current PAT updates. Remaining work is explicitly scoped in the H.222.0 requirement trace rather than treated as an unbounded ISO audit.
The writer builds deterministic, CRC-valid PAT/PMT sections and bounded PES
packets, then packetizes them with independent per-PID continuity counters. An
asynchronous KLVA writer uses stream ID 0xBD, omits PTS/DTS, asserts data
alignment only where the PES payload begins the KLV item, and requires a
matching KLVA registration in the PMT. One large KLV item may span multiple
bounded PES packets; continuation packets clear the alignment indicator and the
incremental receiver validates the inverse rule at every non-empty boundary.
Empty PES packets seen in deployed FMV streams are tolerated because they have
no first data byte and cannot alter parser alignment. The writer
first validates that its input is exactly one complete Universal KLV item. This
behavior is tested end to end against the demuxer. The acquired publisher copy
of SMPTE RP 217 is now traced clause by clause in
the RP 217 requirement trace. The writer and strict
receiver additionally enforce non-zero PES length and a clear ESCR flag.
Synchronous metadata construction is grounded in ST 1402.2 and the official
ITU-T H.222.0 (10/2014), which contains the aligned ISO/IEC 13818-1 Metadata AU
Cell syntax and fragment semantics. The writer emits stream type 0x15, stream
ID 0xFC, KLVA metadata and metadata-STD descriptors, PTS-only PES headers,
five-byte Metadata AU Cell headers, wrapping sequence counters, and correct
complete/first/middle/last fragmentation. MetadataDelayValidator bounds each
synchronous PES arrival between adjacent program PCR samples. It reports only
delays that are certainly greater than one second or certainly late, accepts
only ranges entirely inside [0, 1], and counts boundary-straddling or
unbracketed arrivals instead of converting uncertainty into a pass.
SynchronousMetadataSTDModel applies the descriptor leak rate and buffer size
to every exact transport byte, including the fixed 512-byte TBn, PES overhead
in Bn, access-unit-only delay, instantaneous PTS removal, aggregate occupancy,
underflow/overflow, and the one-second emptying rule. The PCR/PES adapter derives
t(i) with H.222.0 equations 2-4 and 2-5 and rejects missing brackets or
discontinuities. MetadataSTDStreamValidator retains buffer fullness across
PCR windows, retires processed events at exact watermarks, bounds every pending
state dimension, and is integrated into the CLI alongside the conservative
delay validator.
AsynchronousMetadataSTDModel and its bounded incremental counterpart implement
the H.222.0 continuous-output branch when an application supplies input leak,
output leak, and buffer parameters. The aggregate PCR/PES adapter derives exact
byte arrivals without PTS. MetadataSTDStreamValidator and FMVVerifier apply
the same model continuously across bounded PCR windows when given a per-program/PID
descriptor mapping; absent mappings remain explicit unverifiable coverage. ST 1402
RP 217 signalling ordinarily supplies only the KLVA registration descriptor,
so the verifier does not fabricate absent STD parameters or claim this optional
audit automatically.
MetadataStreamDecoder is the inverse live path: it validates carriage-specific
PES rules, incrementally reconstructs asynchronous KLV, parses synchronous AU
wrappers, rejects undeclared metadata service IDs, verifies sequence continuity,
bounds and reassembles fragments, and
returns complete KLV events carrying their PID, program, PTS, service ID, and
typed ST 0601/ST 0903 value where recognized.
FrameMetadataCorrelator implements the receiver-side relevance policy for
synchronous KLV. Equal video and metadata PTS values form an exact match;
latest-relevant and nearest policies require an explicit maximum delta and
optional configured sampling offset. PTS unwrapping is isolated per program.
Asynchronous KLV is never auto-associated because §9.4.2 says its
synchronization cannot be guaranteed through decoding.
UdpTransportPacketizer implements the delivery boundary in Section 8. It
groups arbitrary byte chunks into UDP payloads containing only complete
188-byte TS packets, defaults to the recommended seven packets for a 1,500-byte
Ethernet MTU, emits a smaller integral final payload, and rejects partial or
misaligned input. validate_udp_datagram provides the corresponding receiver
check. The maximum configuration is bounded by the UDP payload limit.
PSICadenceValidator audits current PAT and every PAT-announced program's PMT
on a caller-selected monotonic timeline. It treats an interval equal to 250 ms
as a violation because ST 1402-02 requires a frequency greater than four times
per second, exposes the recommended 125 ms interval, detects initially missing
tables when given a program-start baseline, and retains independent deadlines
across PAT reconfiguration. Multi-section PAT instances count only after every
section in the cycle has arrived; H.222.0 PMT section numbers are required to
be zero. The checker is clock-source
agnostic so live applications can use a monotonic host clock while file audits
can use exact PCR-derived fractions. ProgramTableScheduler supplies the writer
side at the recommended exact 125 ms interval. It emits immediately, advances
PAT/PMT continuity through the muxer, avoids drift, and exposes late polls,
skipped slots, and strict-interval violations. Timed LiveTransportTransformer
calls use the scheduler directly and provide an explicit idle-loop poll; the
application remains responsible for invoking that poll frequently enough.
PCRCadenceValidator audits the separate §7.2 clock-reference requirement
directly from the demuxer's program-aware PCR events. It accepts exactly 100 ms,
reports a one-tick overrun, unwraps the composite 33-bit-base plus 9-bit-
extension PCR epoch, and keeps independent state when programs share a clock
PID. A declared time-base discontinuity or PCR PID change reanchors the
program; an undeclared regression is a distinct diagnostic. This validates
observed spacing, not the H.222.0 PCR accuracy/jitter or T-STD model.
ProgramClockScheduler supplies the live writer side when the application has
an authoritative monotonic output timeline. It anchors a caller-supplied 27
MHz encoder clock, uses a drift-free rational schedule, emits PCR sampled from
the actual poll instant, follows a reconfigured PMT clock PID, and exposes
skipped slots and any gap beyond 100 ms. Its default 50 ms interval is an
operational headroom choice rather than a second standards claim. The
application must still poll and write packets on the stated timeline.
PTSCadenceValidator audits §7.3 independently for each program/PID pair. It
accepts exactly 0.7 seconds, reports a one-tick overrun, uses nearest-epoch
33-bit PTS unwrapping, tolerates small presentation-order regressions, and
reanchors on a declared discontinuity or changed stream type. The FMV verifier
feeds every completed PES event into this validator. This is an encoded-
timestamp cadence check, not a decoder-buffer or per-frame PTS-presence model.