cai
2026-08-12 a640ced9a412100b50b5d9ea0566204b33519bf1
src/main.rs
@@ -127,6 +127,7 @@
struct ControlledFixtureVisibilityEvidence {
    first_visible_bucket: &'static str,
    visibility_source: &'static str,
    visibility_result: &'static str,
    binding_matched: bool,
}
@@ -356,6 +357,25 @@
    })
}
fn controlled_fixture_probe_binding_decision(
    probe_sender: &str,
    current_audio_participant: Option<&str>,
    expected_participant: Option<&str>,
) -> Result<(), &'static str> {
    if !is_bound_user_participant(probe_sender, expected_participant) {
        return Err("wrong_participant");
    }
    let Some(current_audio_participant) = current_audio_participant else {
        return Err("no_current_participant");
    };
    if current_audio_participant != probe_sender
        || !is_bound_user_participant(current_audio_participant, expected_participant)
    {
        return Err("wrong_participant");
    }
    Ok(())
}
fn controlled_fixture_visibility_bucket(elapsed: Duration) -> &'static str {
    if elapsed <= Duration::from_millis(250) {
        "lte_250ms"
@@ -368,48 +388,74 @@
    }
}
async fn observe_controlled_fixture_post_expiry<F>(
async fn observe_controlled_fixture_post_expiry_views<F, G>(
    received_at: Instant,
    observation_deadline: Instant,
    actual_participant: &str,
    held_participant: &str,
    expected_participant: Option<&str>,
    requested_sequence: &str,
    lifecycle_active: Arc<AtomicBool>,
    mut read_attributes: F,
    mut read_held_attributes: F,
    mut read_current_participant: G,
) -> Option<ControlledFixtureVisibilityEvidence>
where
    F: FnMut() -> std::collections::HashMap<String, String>,
    G: FnMut() -> Option<(String, std::collections::HashMap<String, String>)>,
{
    loop {
        if !lifecycle_active.load(Ordering::Acquire) {
            return None;
        }
        let now = Instant::now();
        let decision = classify_controlled_fixture_attributes(
            actual_participant,
        let held_decision = classify_controlled_fixture_attributes(
            held_participant,
            expected_participant,
            &read_attributes(),
            &read_held_attributes(),
            requested_sequence,
        );
        match decision {
        match held_decision {
            Ok(()) => {
                return Some(ControlledFixtureVisibilityEvidence {
                    first_visible_bucket: controlled_fixture_visibility_bucket(
                        now.saturating_duration_since(received_at),
                    ),
                    visibility_source: "participant_attributes_poll",
                    visibility_result: "held_visible",
                    binding_matched: true,
                });
            }
            Err("missing_attributes") if now < observation_deadline => {}
            Err("missing_attributes") => {
                return Some(ControlledFixtureVisibilityEvidence {
                    first_visible_bucket: "never_visible_within_observation_window",
                    visibility_source: "participant_attributes_poll",
                    binding_matched: true,
                });
            }
            Err("missing_attributes") => {}
            Err(_) => return None,
        }
        let Some((current_identity, current_attributes)) = read_current_participant() else {
            return None;
        };
        match classify_controlled_fixture_attributes(
            &current_identity,
            expected_participant,
            &current_attributes,
            requested_sequence,
        ) {
            Ok(()) => {
                return Some(ControlledFixtureVisibilityEvidence {
                    first_visible_bucket: controlled_fixture_visibility_bucket(
                        now.saturating_duration_since(received_at),
                    ),
                    visibility_source: "current_room_lookup",
                    visibility_result: "held_stale_current_visible",
                    binding_matched: true,
                });
            }
            Err("missing_attributes") => {}
            Err(_) => return None,
        }
        if now >= observation_deadline {
            return Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "never_visible_within_observation_window",
                visibility_source: "held_and_current_room_lookup",
                visibility_result: "unavailable_both",
                binding_matched: true,
            });
        }
        sleep(CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY).await;
    }
@@ -435,6 +481,7 @@
            "stage": "post_expiry_visibility",
            "first_visible_bucket": evidence.first_visible_bucket,
            "visibility_source": evidence.visibility_source,
            "visibility_result": evidence.visibility_result,
            "binding_matched": evidence.binding_matched,
            "call_id_hash": probe.call_id_hash,
            "trace_id_hash": probe.call_trace_id_hash,
@@ -448,6 +495,7 @@
fn spawn_controlled_fixture_post_expiry_observation(
    probe: PendingControlledFixtureProbe,
    participant: RemoteParticipant,
    room: Arc<Room>,
    expected_participant: Option<String>,
    lifecycle_active: Arc<AtomicBool>,
    runtime_call_id: String,
@@ -455,7 +503,7 @@
) {
    tokio::spawn(async move {
        let participant_identity = participant.identity().to_string();
        let evidence = observe_controlled_fixture_post_expiry(
        let evidence = observe_controlled_fixture_post_expiry_views(
            probe.received_at,
            probe.received_at + CONTROLLED_FIXTURE_POST_EXPIRY_WINDOW,
            &participant_identity,
@@ -463,6 +511,11 @@
            &probe.sequence,
            lifecycle_active.clone(),
            || participant.attributes(),
            || {
                room.remote_participants()
                    .get(&probe.sender)
                    .map(|current| (current.identity().to_string(), current.attributes()))
            },
        )
        .await;
        if lifecycle_active.load(Ordering::Acquire) {
@@ -1376,6 +1429,18 @@
                }
                current_user_participant = Some(participant_for_probe);
            }
            RoomEvent::TrackUnsubscribed {
                track: RemoteTrack::Audio(_),
                publication: _,
                participant,
            } => {
                if current_user_participant
                    .as_ref()
                    .is_some_and(|current| current.identity() == participant.identity())
                {
                    current_user_participant = None;
                }
            }
            RoomEvent::DataReceived {
                payload,
                topic: Some(topic),
@@ -1550,16 +1615,25 @@
        );
        return Some(false);
    }
    let decision = observe_controlled_fixture_attributes(
        probe.expires_at,
        &participant.identity().to_string(),
    let decision = controlled_fixture_probe_binding_decision(
        probe.sender.as_str(),
        Some(participant.identity().as_str()),
        expected_participant,
        &probe.sequence,
        || participant.attributes(),
    )
    .await;
    );
    if let Err(reason) = decision {
        record_controlled_fixture_attribute_decision(
            Err(reason),
            runtime_call_id,
            runtime_trace_id,
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
        );
        return Some(false);
    }
    let (ack_result, reject_reason, observed) = record_controlled_fixture_attribute_decision(
        decision,
        Ok(()),
        runtime_call_id,
        runtime_trace_id,
        &probe.call_id_hash,
@@ -1609,6 +1683,7 @@
        spawn_controlled_fixture_post_expiry_observation(
            probe,
            participant.clone(),
            sink.room.clone(),
            expected_participant.map(str::to_string),
            lifecycle_active,
            runtime_call_id.to_string(),
@@ -4877,35 +4952,42 @@
    #[derive(Debug)]
    enum PreAudioOrderEvent {
        DataReceived {
            sender: String,
            sequence: String,
        },
        TrackSubscribed {
            participant: String,
            attributes: HashMap<String, String>,
        },
        DataReceived { sender: String, sequence: String },
        TrackSubscribed { participant: String },
    }
    fn drive_pre_audio_order_test_seam(events: &[PreAudioOrderEvent]) -> Vec<&'static str> {
        let mut pending_sequence = None;
        let call_id = "production-order-call";
        let trace_id = "production-order-trace";
        let mut pending_probe = None;
        let mut effects = Vec::new();
        for event in events {
            match event {
                PreAudioOrderEvent::DataReceived { sender, sequence } if sender == "user-1" => {
                    pending_sequence = Some(sequence.as_str());
                PreAudioOrderEvent::DataReceived { sender, sequence } => {
                    let payload = serde_json::to_vec(&json!({
                        "type": CONTROLLED_FIXTURE_PROBE_TOPIC,
                        "protocolVersion": CONTROLLED_FIXTURE_PROTOCOL_VERSION,
                        "callIdHash": sha256_hex(call_id),
                        "callTraceIdHash": sha256_hex(trace_id),
                        "generation": CONTROLLED_FIXTURE_GENERATION,
                        "clientFixtureSequence": sequence,
                    }))
                    .expect("production probe payload");
                    pending_probe = controlled_fixture_probe(
                        &payload,
                        call_id,
                        trace_id,
                        &ParticipantIdentity(sender.clone()),
                        Some("user-1"),
                    );
                }
                PreAudioOrderEvent::TrackSubscribed {
                    participant,
                    attributes,
                } => {
                    let pending = pending_sequence.is_some();
                    let probe_result = pending_sequence.map(|sequence| {
                        classify_controlled_fixture_attributes(
                            participant,
                PreAudioOrderEvent::TrackSubscribed { participant } => {
                    let pending = pending_probe.is_some();
                    let probe_result = pending_probe.as_ref().map(|probe| {
                        controlled_fixture_probe_binding_decision(
                            probe.sender.as_str(),
                            Some(participant),
                            Some("user-1"),
                            attributes,
                            sequence,
                        )
                        .is_ok()
                    });
@@ -4923,9 +5005,8 @@
                    if observer_started {
                        effects.push("observer_started");
                    }
                    pending_sequence = None;
                    pending_probe = None;
                }
                PreAudioOrderEvent::DataReceived { .. } => {}
            }
        }
        effects
@@ -5855,7 +5936,7 @@
                published: true,
            }
        );
        let evidence = observe_controlled_fixture_post_expiry(
        let evidence = observe_controlled_fixture_post_expiry_views(
            started_at,
            started_at + CONTROLLED_FIXTURE_POST_EXPIRY_WINDOW,
            "user-1",
@@ -5869,6 +5950,7 @@
                    HashMap::new()
                }
            },
            || Some(("user-1".to_string(), HashMap::new())),
        )
        .await;
        assert_eq!(acknowledged.len(), 1);
@@ -5877,13 +5959,14 @@
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "250_500ms",
                visibility_source: "participant_attributes_poll",
                visibility_result: "held_visible",
                binding_matched: true,
            })
        );
        let never_started_at = Instant::now();
        assert_eq!(
            observe_controlled_fixture_post_expiry(
            observe_controlled_fixture_post_expiry_views(
                never_started_at,
                never_started_at + Duration::from_millis(40),
                "user-1",
@@ -5891,17 +5974,19 @@
                "fixture-01",
                Arc::new(AtomicBool::new(true)),
                HashMap::new,
                || Some(("user-1".to_string(), HashMap::new())),
            )
            .await,
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "never_visible_within_observation_window",
                visibility_source: "participant_attributes_poll",
                visibility_source: "held_and_current_room_lookup",
                visibility_result: "unavailable_both",
                binding_matched: true,
            })
        );
        assert_eq!(
            observe_controlled_fixture_post_expiry(
            observe_controlled_fixture_post_expiry_views(
                Instant::now(),
                Instant::now() + Duration::from_millis(50),
                "cross-call-user",
@@ -5909,6 +5994,7 @@
                "fixture-01",
                Arc::new(AtomicBool::new(true)),
                || expected.clone(),
                || Some(("user-1".to_string(), expected.clone())),
            )
            .await,
            None
@@ -5916,7 +6002,7 @@
        let inactive = Arc::new(AtomicBool::new(false));
        assert_eq!(
            observe_controlled_fixture_post_expiry(
            observe_controlled_fixture_post_expiry_views(
                Instant::now(),
                Instant::now() + Duration::from_millis(50),
                "user-1",
@@ -5924,6 +6010,7 @@
                "fixture-01",
                inactive,
                HashMap::new,
                || Some(("user-1".to_string(), HashMap::new())),
            )
            .await,
            None
@@ -5959,6 +6046,7 @@
                "sequence_hash",
                "stage",
                "trace_id_hash",
                "visibility_result",
                "visibility_source",
            ]
        );
@@ -5971,6 +6059,105 @@
            "\"audio\":",
        ] {
            assert!(!encoded.contains(forbidden));
        }
    }
    #[tokio::test]
    async fn production_post_expiry_observation_distinguishes_held_stale_from_current_room_view() {
        let started_at = Instant::now();
        let current_attributes = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        let mut acknowledged = HashSet::new();
        let expired_ack = complete_controlled_fixture_ack_publish(
            async { Ok::<(), ()>(()) },
            "runtime-call-current-view",
            "runtime-trace-current-view",
            false,
            "timeout",
            Some("expired"),
            "call-current-view",
            "trace-current-view",
            CONTROLLED_FIXTURE_GENERATION,
            "fixture-01",
            &mut acknowledged,
        )
        .await;
        let evidence = observe_controlled_fixture_post_expiry_views(
            started_at,
            started_at + Duration::from_millis(100),
            "user-1",
            Some("user-1"),
            "fixture-01",
            Arc::new(AtomicBool::new(true)),
            HashMap::new,
            || Some(("user-1".to_string(), current_attributes.clone())),
        )
        .await;
        assert_eq!(
            expired_ack,
            ControlledFixtureAckPublishOutcome {
                observed: false,
                published: true,
            }
        );
        assert_eq!(acknowledged.len(), 1);
        assert_eq!(
            evidence,
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "lte_250ms",
                visibility_source: "current_room_lookup",
                visibility_result: "held_stale_current_visible",
                binding_matched: true,
            })
        );
        let mut observer_starts = 0;
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(expired_ack.observed),
            || observer_starts += 1,
        ));
        assert_eq!(observer_starts, 0);
        for current_view in [
            None,
            Some(("cross-call-user".to_string(), current_attributes.clone())),
            Some((
                "user-1".to_string(),
                HashMap::from([
                    (
                        "inputSourceCategory".to_string(),
                        "controlled_fixture".to_string(),
                    ),
                    (
                        "clientFixtureSequence".to_string(),
                        "fixture-old".to_string(),
                    ),
                ]),
            )),
        ] {
            assert_eq!(
                observe_controlled_fixture_post_expiry_views(
                    Instant::now(),
                    Instant::now() + Duration::from_millis(20),
                    "user-1",
                    Some("user-1"),
                    "fixture-01",
                    Arc::new(AtomicBool::new(true)),
                    HashMap::new,
                    || current_view.clone(),
                )
                .await,
                None
            );
        }
    }
@@ -6033,24 +6220,13 @@
    #[test]
    fn production_event_order_probe_then_track_publishes_ack_before_observer() {
        let attributes = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        let effects = drive_pre_audio_order_test_seam(&[
            PreAudioOrderEvent::DataReceived {
                sender: "user-1".to_string(),
                sequence: "fixture-01".to_string(),
                sequence: "1".to_string(),
            },
            PreAudioOrderEvent::TrackSubscribed {
                participant: "user-1".to_string(),
                attributes,
            },
        ]);
        assert_eq!(effects, ["ack_observed", "observer_started"]);
@@ -6058,19 +6234,13 @@
    #[test]
    fn production_event_order_negative_probe_has_no_observer_or_session_effect() {
        let mut invalid = HashMap::new();
        invalid.insert(
            "inputSourceCategory".to_string(),
            "ordinary_mic".to_string(),
        );
        let effects = drive_pre_audio_order_test_seam(&[
            PreAudioOrderEvent::DataReceived {
                sender: "user-1".to_string(),
                sequence: "fixture-01".to_string(),
                sequence: "1".to_string(),
            },
            PreAudioOrderEvent::TrackSubscribed {
                participant: "user-1".to_string(),
                attributes: invalid,
                participant: "cross-call-user".to_string(),
            },
        ]);
        assert!(effects.is_empty());