cai
2026-08-25 caeed9acdc676aa10f788e81edf45892b8cdcc8e
src/main.rs
@@ -6,6 +6,7 @@
    borrow::Cow,
    collections::HashSet,
    env, fs,
    future::Future,
    path::{Path, PathBuf},
    sync::{
        Arc,
@@ -30,7 +31,7 @@
    options::TrackPublishOptions,
    prelude::{
        DataPacket, LocalAudioTrack, LocalTrack, ParticipantIdentity, RemoteAudioTrack,
        RemoteTrack, Room, RoomEvent, RoomOptions,
        RemoteParticipant, RemoteTrack, Room, RoomEvent, RoomOptions,
    },
};
use reqwest::Client;
@@ -59,6 +60,623 @@
const STREAM_TIMING_FIRST_CHUNK: u64 = 1;
const STREAM_TIMING_MAX_ELAPSED_MS: u64 = 5_000;
const STREAM_TIMING_SOURCE: &str = "stream_anchor_monotonic";
const CONTROLLED_FIXTURE_PROBE_TOPIC: &str = "controlled_fixture_attribute_probe";
const CONTROLLED_FIXTURE_ACK_TOPIC: &str = "controlled_fixture_attribute_ack";
const CONTROLLED_FIXTURE_PROTOCOL_VERSION: u64 = 1;
const CONTROLLED_FIXTURE_GENERATION: u64 = 1;
const CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY: Duration = Duration::from_millis(25);
const CONTROLLED_FIXTURE_PROBE_TTL: Duration = Duration::from_millis(250);
const CONTROLLED_FIXTURE_POST_EXPIRY_WINDOW: Duration = Duration::from_millis(2_000);
const CONTROLLED_FIXTURE_ACK_RESULTS: [&str; 4] =
    ["observed", "rejected", "timeout", "publish_failed"];
const CONTROLLED_FIXTURE_REJECT_REASONS: [&str; 16] = [
    "missing_attributes",
    "wrong_source",
    "missing_sequence",
    "wrong_sequence",
    "wrong_participant",
    "expired",
    "duplicate_or_old_sequence",
    "no_current_participant",
    "ack_publish_failed",
    "missing_generation",
    "invalid_generation",
    "wrong_generation",
    "invalid_language",
    "incomplete_metadata",
    "invalid_source_or_sequence",
    "unknown",
];
#[derive(Debug, Deserialize)]
#[serde(rename_all = "camelCase")]
struct ControlledFixtureAttributeProbe {
    #[serde(rename = "type")]
    message_type: String,
    protocol_version: u64,
    call_id_hash: String,
    call_trace_id_hash: String,
    generation: u64,
    client_fixture_sequence: String,
}
#[derive(Debug, Serialize)]
#[serde(rename_all = "camelCase")]
struct ControlledFixtureAttributeAck {
    #[serde(rename = "type")]
    message_type: &'static str,
    protocol_version: u64,
    call_id_hash: String,
    call_trace_id_hash: String,
    generation: u64,
    client_fixture_sequence: String,
    result: &'static str,
    #[serde(skip_serializing_if = "Option::is_none")]
    input_source_category: Option<&'static str>,
    #[serde(skip_serializing_if = "Option::is_none")]
    reject_reason: Option<&'static str>,
}
#[derive(Clone, Debug)]
struct PendingControlledFixtureProbe {
    sender: ParticipantIdentity,
    call_id_hash: String,
    call_trace_id_hash: String,
    generation: u64,
    sequence: String,
    received_at: Instant,
    expires_at: Instant,
}
#[derive(Debug, PartialEq, Eq)]
struct ControlledFixtureVisibilityEvidence {
    first_visible_bucket: &'static str,
    visibility_source: &'static str,
    visibility_result: &'static str,
    binding_matched: bool,
}
#[derive(Debug, PartialEq, Eq)]
struct ControlledFixtureAckPublishOutcome {
    observed: bool,
    published: bool,
}
fn sha256_hex(value: &str) -> String {
    let mut digest = Sha256::new();
    digest.update(value.as_bytes());
    digest
        .finalize()
        .iter()
        .map(|byte| format!("{byte:02x}"))
        .collect()
}
fn controlled_fixture_ack_classification(
    decision: Result<(), &'static str>,
) -> (&'static str, Option<&'static str>, bool) {
    match decision {
        Ok(()) => ("observed", None, true),
        Err("timeout") => ("timeout", Some("expired"), false),
        Err(reason) if CONTROLLED_FIXTURE_REJECT_REASONS.contains(&reason) => {
            ("rejected", Some(reason), false)
        }
        Err(_) => ("rejected", Some("unknown"), false),
    }
}
fn record_controlled_fixture_probe_event(
    runtime_call_id: &str,
    runtime_trace_id: &str,
    stage: &'static str,
    call_id_hash: &str,
    trace_id_hash: &str,
    generation: u64,
    sequence: &str,
    observed: bool,
    ack_result: Option<&'static str>,
    reject_reason: Option<&'static str>,
) {
    debug_assert!(ack_result.is_none_or(|value| CONTROLLED_FIXTURE_ACK_RESULTS.contains(&value)));
    debug_assert!(
        reject_reason.is_none_or(|value| CONTROLLED_FIXTURE_REJECT_REASONS.contains(&value))
    );
    println!(
        "{}",
        controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            stage,
            call_id_hash,
            trace_id_hash,
            generation,
            sequence,
            observed,
            ack_result,
            reject_reason,
        )
    );
}
fn controlled_fixture_probe_event(
    runtime_call_id: &str,
    runtime_trace_id: &str,
    stage: &'static str,
    call_id_hash: &str,
    trace_id_hash: &str,
    generation: u64,
    sequence: &str,
    observed: bool,
    ack_result: Option<&'static str>,
    reject_reason: Option<&'static str>,
) -> serde_json::Value {
    json!({
        "type": "cv_activity",
        "callId": runtime_call_id,
        "traceId": runtime_trace_id,
        "turnId": null,
        "eventName": "controlled_fixture_attribute_probe",
        "eventWallTimeMs": current_time_millis(),
        "result": "ok",
        "reasonCode": null,
        "retryable": null,
        "extension": {
            "stage": stage,
            "observed": observed,
            "ack_result": ack_result,
            "reject_reason": reject_reason,
            "call_id_hash": call_id_hash,
            "trace_id_hash": trace_id_hash,
            "generation": generation,
            "sequence_hash": sha256_hex(sequence),
        },
    })
}
fn record_controlled_fixture_attribute_decision(
    decision: Result<(), &'static str>,
    runtime_call_id: &str,
    runtime_trace_id: &str,
    call_id_hash: &str,
    trace_id_hash: &str,
    generation: u64,
    sequence: &str,
) -> (&'static str, Option<&'static str>, bool) {
    let classification = controlled_fixture_ack_classification(decision);
    record_controlled_fixture_probe_event(
        runtime_call_id,
        runtime_trace_id,
        "attributes_classified",
        call_id_hash,
        trace_id_hash,
        generation,
        sequence,
        classification.2,
        Some(classification.0),
        classification.1,
    );
    classification
}
async fn complete_controlled_fixture_ack_publish<F, E>(
    publish: F,
    runtime_call_id: &str,
    runtime_trace_id: &str,
    observed: bool,
    ack_result: &'static str,
    reject_reason: Option<&'static str>,
    call_id_hash: &str,
    trace_id_hash: &str,
    generation: u64,
    sequence: &str,
    acknowledged_probe_sequences: &mut HashSet<(u64, String)>,
) -> ControlledFixtureAckPublishOutcome
where
    F: Future<Output = Result<(), E>>,
{
    if publish.await.is_ok() {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "ack_publish_completed",
            call_id_hash,
            trace_id_hash,
            generation,
            sequence,
            observed,
            Some(ack_result),
            reject_reason,
        );
        acknowledged_probe_sequences.insert((generation, sequence.to_string()));
        ControlledFixtureAckPublishOutcome {
            observed,
            published: true,
        }
    } else {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "ack_publish_completed",
            call_id_hash,
            trace_id_hash,
            generation,
            sequence,
            false,
            Some("publish_failed"),
            Some("ack_publish_failed"),
        );
        ControlledFixtureAckPublishOutcome {
            observed: false,
            published: false,
        }
    }
}
fn controlled_fixture_ack_from_probe(
    probe: &PendingControlledFixtureProbe,
    observed: bool,
    reject_reason: Option<&'static str>,
) -> ControlledFixtureAttributeAck {
    ControlledFixtureAttributeAck {
        message_type: CONTROLLED_FIXTURE_ACK_TOPIC,
        protocol_version: CONTROLLED_FIXTURE_PROTOCOL_VERSION,
        call_id_hash: probe.call_id_hash.clone(),
        call_trace_id_hash: probe.call_trace_id_hash.clone(),
        generation: probe.generation,
        client_fixture_sequence: probe.sequence.clone(),
        result: if observed { "observed" } else { "rejected" },
        input_source_category: observed.then_some("controlled_fixture"),
        reject_reason,
    }
}
fn controlled_fixture_probe(
    payload: &[u8],
    call_id: &str,
    trace_id: &str,
    sender: &ParticipantIdentity,
    expected_participant: Option<&str>,
) -> Option<PendingControlledFixtureProbe> {
    if !is_bound_user_participant(sender.as_str(), expected_participant) {
        return None;
    }
    let probe: ControlledFixtureAttributeProbe = serde_json::from_slice(payload).ok()?;
    if probe.message_type != CONTROLLED_FIXTURE_PROBE_TOPIC
        || probe.protocol_version != CONTROLLED_FIXTURE_PROTOCOL_VERSION
        || !valid_input_generation(probe.generation)
        || probe.call_id_hash != sha256_hex(call_id)
        || probe.call_trace_id_hash != sha256_hex(trace_id)
        || probe.client_fixture_sequence.trim().is_empty()
    {
        return None;
    }
    let received_at = Instant::now();
    Some(PendingControlledFixtureProbe {
        sender: sender.clone(),
        call_id_hash: probe.call_id_hash,
        call_trace_id_hash: probe.call_trace_id_hash,
        generation: probe.generation,
        sequence: probe.client_fixture_sequence,
        received_at,
        expires_at: received_at + CONTROLLED_FIXTURE_PROBE_TTL,
    })
}
fn controlled_fixture_probe_binding_decision(
    probe_sender: &str,
    current_audio_participant: Option<&str>,
    expected_participant: Option<&str>,
) -> Result<(), &'static str> {
    if !is_bound_user_participant(probe_sender, expected_participant) {
        return Err("wrong_participant");
    }
    let Some(current_audio_participant) = current_audio_participant else {
        return Err("no_current_participant");
    };
    if current_audio_participant != probe_sender
        || !is_bound_user_participant(current_audio_participant, expected_participant)
    {
        return Err("wrong_participant");
    }
    Ok(())
}
fn controlled_fixture_visibility_bucket(elapsed: Duration) -> &'static str {
    if elapsed <= Duration::from_millis(250) {
        "lte_250ms"
    } else if elapsed <= Duration::from_millis(500) {
        "250_500ms"
    } else if elapsed <= Duration::from_millis(1_000) {
        "500_1000ms"
    } else {
        "1000_2000ms"
    }
}
async fn observe_controlled_fixture_post_expiry_views<F, G>(
    received_at: Instant,
    observation_deadline: Instant,
    held_participant: &str,
    expected_participant: Option<&str>,
    requested_sequence: &str,
    lifecycle_active: Arc<AtomicBool>,
    mut read_held_attributes: F,
    mut read_current_participant: G,
) -> Option<ControlledFixtureVisibilityEvidence>
where
    F: FnMut() -> std::collections::HashMap<String, String>,
    G: FnMut() -> Option<(String, std::collections::HashMap<String, String>)>,
{
    loop {
        if !lifecycle_active.load(Ordering::Acquire) {
            return None;
        }
        let now = Instant::now();
        let held_decision = classify_controlled_fixture_attributes(
            held_participant,
            expected_participant,
            &read_held_attributes(),
            requested_sequence,
        );
        match held_decision {
            Ok(()) => {
                return Some(ControlledFixtureVisibilityEvidence {
                    first_visible_bucket: controlled_fixture_visibility_bucket(
                        now.saturating_duration_since(received_at),
                    ),
                    visibility_source: "participant_attributes_poll",
                    visibility_result: "held_visible",
                    binding_matched: true,
                });
            }
            Err("missing_attributes") => {}
            Err(_) => return None,
        }
        let Some((current_identity, current_attributes)) = read_current_participant() else {
            return None;
        };
        match classify_controlled_fixture_attributes(
            &current_identity,
            expected_participant,
            &current_attributes,
            requested_sequence,
        ) {
            Ok(()) => {
                return Some(ControlledFixtureVisibilityEvidence {
                    first_visible_bucket: controlled_fixture_visibility_bucket(
                        now.saturating_duration_since(received_at),
                    ),
                    visibility_source: "current_room_lookup",
                    visibility_result: "held_stale_current_visible",
                    binding_matched: true,
                });
            }
            Err("missing_attributes") => {}
            Err(_) => return None,
        }
        if now >= observation_deadline {
            return Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "never_visible_within_observation_window",
                visibility_source: "held_and_current_room_lookup",
                visibility_result: "unavailable_both",
                binding_matched: true,
            });
        }
        sleep(CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY).await;
    }
}
fn controlled_fixture_visibility_event(
    runtime_call_id: &str,
    runtime_trace_id: &str,
    probe: &PendingControlledFixtureProbe,
    evidence: &ControlledFixtureVisibilityEvidence,
) -> serde_json::Value {
    json!({
        "type": "cv_activity",
        "callId": runtime_call_id,
        "traceId": runtime_trace_id,
        "turnId": null,
        "eventName": "controlled_fixture_attribute_probe",
        "eventWallTimeMs": current_time_millis(),
        "result": "ok",
        "reasonCode": null,
        "retryable": null,
        "extension": {
            "stage": "post_expiry_visibility",
            "first_visible_bucket": evidence.first_visible_bucket,
            "visibility_source": evidence.visibility_source,
            "visibility_result": evidence.visibility_result,
            "binding_matched": evidence.binding_matched,
            "call_id_hash": probe.call_id_hash,
            "trace_id_hash": probe.call_trace_id_hash,
            "generation": probe.generation,
            "sequence_hash": sha256_hex(&probe.sequence),
            "evidence_count": 1,
        },
    })
}
fn spawn_controlled_fixture_post_expiry_observation(
    probe: PendingControlledFixtureProbe,
    participant: RemoteParticipant,
    room: Arc<Room>,
    expected_participant: Option<String>,
    lifecycle_active: Arc<AtomicBool>,
    runtime_call_id: String,
    runtime_trace_id: String,
) {
    tokio::spawn(async move {
        let participant_identity = participant.identity().to_string();
        let evidence = observe_controlled_fixture_post_expiry_views(
            probe.received_at,
            probe.received_at + CONTROLLED_FIXTURE_POST_EXPIRY_WINDOW,
            &participant_identity,
            expected_participant.as_deref(),
            &probe.sequence,
            lifecycle_active.clone(),
            || participant.attributes(),
            || {
                room.remote_participants()
                    .get(&probe.sender)
                    .map(|current| (current.identity().to_string(), current.attributes()))
            },
        )
        .await;
        if lifecycle_active.load(Ordering::Acquire) {
            if let Some(evidence) = evidence {
                println!(
                    "{}",
                    controlled_fixture_visibility_event(
                        &runtime_call_id,
                        &runtime_trace_id,
                        &probe,
                        &evidence,
                    )
                );
            }
        }
    });
}
fn classify_controlled_fixture_attributes(
    actual_participant: &str,
    expected_participant: Option<&str>,
    attributes: &std::collections::HashMap<String, String>,
    requested_sequence: &str,
) -> Result<(), &'static str> {
    if !is_bound_user_participant(actual_participant, expected_participant) {
        return Err("wrong_participant");
    }
    let source = attributes
        .get("inputSourceCategory")
        .map(String::as_str)
        .unwrap_or("");
    if source != "controlled_fixture" {
        return Err(if source.is_empty() {
            "missing_attributes"
        } else {
            "wrong_source"
        });
    }
    let sequence = attributes
        .get("clientFixtureSequence")
        .map(String::as_str)
        .unwrap_or("");
    if sequence.trim().is_empty() {
        return Err("missing_sequence");
    }
    if sequence != requested_sequence {
        return Err("wrong_sequence");
    }
    Ok(())
}
fn controlled_fixture_probe_attribute_decision(
    actual_participant: &str,
    expected_participant: Option<&str>,
    attributes: &std::collections::HashMap<String, String>,
    probe: &PendingControlledFixtureProbe,
) -> Result<(), &'static str> {
    if !is_bound_user_participant(actual_participant, expected_participant) {
        return Err("wrong_participant");
    }
    let metadata = match AudioIngressMetadata::from_participant(attributes) {
        Ok(Some(metadata)) => metadata,
        Ok(None) => return Err("missing_attributes"),
        Err(reason) => return Err(reason),
    };
    if metadata.client_fixture_sequence != probe.sequence {
        return Err("wrong_sequence");
    }
    if metadata.input_generation != probe.generation {
        return Err("wrong_generation");
    }
    Ok(())
}
async fn observe_controlled_fixture_probe_attributes<F>(
    expires_at: Instant,
    actual_participant: &str,
    expected_participant: Option<&str>,
    probe: &PendingControlledFixtureProbe,
    mut read_attributes: F,
) -> Result<(), &'static str>
where
    F: FnMut() -> std::collections::HashMap<String, String>,
{
    loop {
        if Instant::now() > expires_at {
            return Err("timeout");
        }
        match controlled_fixture_probe_attribute_decision(
            actual_participant,
            expected_participant,
            &read_attributes(),
            probe,
        ) {
            Ok(()) => return Ok(()),
            Err("missing_attributes") | Err("missing_generation") => {
                sleep(CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY).await;
            }
            Err(reason) => return Err(reason),
        }
    }
}
async fn observe_controlled_fixture_attributes<F>(
    expires_at: Instant,
    actual_participant: &str,
    expected_participant: Option<&str>,
    requested_sequence: &str,
    mut read_attributes: F,
) -> Result<(), &'static str>
where
    F: FnMut() -> std::collections::HashMap<String, String>,
{
    loop {
        if Instant::now() > expires_at {
            return Err("timeout");
        }
        let decision = classify_controlled_fixture_attributes(
            actual_participant,
            expected_participant,
            &read_attributes(),
            requested_sequence,
        );
        if decision.is_ok() || !matches!(decision, Err("missing_attributes")) {
            return decision;
        }
        let Some(next_check) = Instant::now().checked_add(CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY)
        else {
            return Err("timeout");
        };
        if next_check > expires_at {
            return Err("timeout");
        }
        sleep(CONTROLLED_FIXTURE_PROBE_RECHECK_DELAY).await;
    }
}
fn controlled_fixture_observer_gate(pending_probe: bool, probe_result: Option<bool>) -> bool {
    !pending_probe || probe_result == Some(true)
}
fn start_observer_after_controlled_fixture_probe<F>(
    pending_probe: bool,
    probe_result: Option<bool>,
    spawn: F,
) -> bool
where
    F: FnOnce(),
{
    if !controlled_fixture_observer_gate(pending_probe, probe_result) {
        return false;
    }
    spawn();
    true
}
#[tokio::main(flavor = "multi_thread")]
async fn main() -> Result<()> {
@@ -737,6 +1355,14 @@
    })
}
fn is_bound_user_participant(identity: &str, expected: Option<&str>) -> bool {
    expected.is_none_or(|value| identity == value)
}
fn valid_input_generation(generation: u64) -> bool {
    generation > 0
}
async fn observe_user_audio_events(
    mut events: UnboundedReceiver<RoomEvent>,
    call_id: String,
@@ -764,6 +1390,11 @@
        "runtime helper user_track_subscribe_requested"
    );
    let mut current_user_participant: Option<RemoteParticipant> = None;
    let mut pending_probe: Option<PendingControlledFixtureProbe> = None;
    let mut acknowledged_probe_sequences = HashSet::new();
    let controlled_fixture_lifecycle_active = Arc::new(AtomicBool::new(true));
    while let Some(event) = events.recv().await {
        match event {
            RoomEvent::TrackSubscribed {
@@ -771,25 +1402,15 @@
                publication: _,
                participant,
            } => {
                if user_participant_identity
                    .as_deref()
                    .is_some_and(|expected| participant.identity().to_string() != expected)
                {
                if !is_bound_user_participant(
                    &participant.identity().to_string(),
                    user_participant_identity.as_deref(),
                ) {
                    warn!(call_id = %call_id, trace_id = %trace_id,
                        metadata_status = "wrong_participant",
                        "runtime helper ignored non-user audio participant");
                    continue;
                }
                let ingress_metadata =
                    match AudioIngressMetadata::from_participant(&participant.attributes()) {
                        Ok(value) => value,
                        Err(reason) => {
                            warn!(call_id = %call_id, trace_id = %trace_id,
                            metadata_status = "invalid", reason = reason,
                            "runtime helper ignored invalid audio ingress metadata");
                            None
                        }
                    };
                let participant_alias = redact(&participant.identity().to_string());
                let track_sid_alias = redact(&track.sid().to_string());
                let track_name = track.name();
@@ -801,24 +1422,146 @@
                    track_sid_alias = %track_sid_alias,
                    track_name = %track_name,
                    track_source = %track_source,
                    metadata_status = if ingress_metadata.is_some() { "bound" } else { "absent" },
                    metadata_source = ingress_metadata.as_ref().map(|_| "controlled_fixture"),
                    metadata_sequence_present = ingress_metadata.is_some(),
                    "runtime helper user_track_subscribed"
                );
                spawn_user_audio_frame_observer(
                    track,
                    call_id.clone(),
                    trace_id.clone(),
                    participant_alias,
                    track_sid_alias,
                    simple_vad_enabled,
                    simple_vad_config.clone(),
                    vad_enabled_gate.clone(),
                    turn_bridge_config.clone(),
                    http.clone(),
                    sink.clone(),
                let pending_binding = pending_probe.clone();
                let participant_for_probe = participant.clone();
                let probe_result = process_controlled_fixture_probe(
                    &mut pending_probe,
                    &mut acknowledged_probe_sequences,
                    Some(&participant_for_probe),
                    &sink,
                    user_participant_identity.as_deref(),
                    &call_id,
                    &trace_id,
                    controlled_fixture_lifecycle_active.clone(),
                )
                .await;
                let observer_started = start_observer_after_controlled_fixture_probe(
                    pending_binding.is_some(),
                    probe_result,
                    || {
                        spawn_user_audio_frame_observer(
                            track,
                            call_id.clone(),
                            trace_id.clone(),
                            participant_alias,
                            track_sid_alias,
                            simple_vad_enabled,
                            simple_vad_config.clone(),
                            vad_enabled_gate.clone(),
                            turn_bridge_config.clone(),
                            http.clone(),
                            sink.clone(),
                            user_participant_identity.clone(),
                            participant,
                        );
                    },
                );
                if let Some(probe) = pending_binding.as_ref() {
                    let (ack_result, reject_reason, observed) = match probe_result {
                        Some(true) => (Some("observed"), None, true),
                        Some(false) => (Some("rejected"), Some("unknown"), false),
                        None => (None, Some("no_current_participant"), false),
                    };
                    record_controlled_fixture_probe_event(
                        &call_id,
                        &trace_id,
                        if observer_started {
                            "audio_observer_allowed"
                        } else {
                            "audio_observer_blocked"
                        },
                        &probe.call_id_hash,
                        &probe.call_trace_id_hash,
                        probe.generation,
                        &probe.sequence,
                        observed,
                        ack_result,
                        reject_reason,
                    );
                }
                if !observer_started {
                    warn!(
                        call_id = %call_id,
                        trace_id = %trace_id,
                        "runtime helper withheld audio observer until controlled fixture ACK"
                    );
                    continue;
                }
                current_user_participant = Some(participant_for_probe);
            }
            RoomEvent::TrackUnsubscribed {
                track: RemoteTrack::Audio(_),
                publication: _,
                participant,
            } => {
                if current_user_participant
                    .as_ref()
                    .is_some_and(|current| current.identity() == participant.identity())
                {
                    current_user_participant = None;
                }
            }
            RoomEvent::DataReceived {
                payload,
                topic: Some(topic),
                participant: Some(sender),
                ..
            } if topic == CONTROLLED_FIXTURE_PROBE_TOPIC => {
                if let Ok(probe) =
                    serde_json::from_slice::<ControlledFixtureAttributeProbe>(&payload)
                {
                    if acknowledged_probe_sequences
                        .contains(&(probe.generation, probe.client_fixture_sequence.clone()))
                    {
                        record_controlled_fixture_probe_event(
                            &call_id,
                            &trace_id,
                            "data_received",
                            &probe.call_id_hash,
                            &probe.call_trace_id_hash,
                            probe.generation,
                            &probe.client_fixture_sequence,
                            false,
                            Some("rejected"),
                            Some("duplicate_or_old_sequence"),
                        );
                        continue;
                    }
                }
                pending_probe = controlled_fixture_probe(
                    &payload,
                    &call_id,
                    &trace_id,
                    &sender.identity(),
                    user_participant_identity.as_deref(),
                );
                if let Some(probe) = pending_probe.as_ref() {
                    record_controlled_fixture_probe_event(
                        &call_id,
                        &trace_id,
                        "data_received",
                        &probe.call_id_hash,
                        &probe.call_trace_id_hash,
                        probe.generation,
                        &probe.sequence,
                        false,
                        None,
                        None,
                    );
                }
                process_controlled_fixture_probe(
                    &mut pending_probe,
                    &mut acknowledged_probe_sequences,
                    current_user_participant.as_ref(),
                    &sink,
                    user_participant_identity.as_deref(),
                    &call_id,
                    &trace_id,
                    controlled_fixture_lifecycle_active.clone(),
                )
                .await;
            }
            RoomEvent::TrackSubscribed {
                track: RemoteTrack::Video(track),
@@ -859,6 +1602,162 @@
            _ => {}
        }
    }
    controlled_fixture_lifecycle_active.store(false, Ordering::Release);
}
async fn process_controlled_fixture_probe(
    pending_probe: &mut Option<PendingControlledFixtureProbe>,
    acknowledged_probe_sequences: &mut HashSet<(u64, String)>,
    participant: Option<&RemoteParticipant>,
    sink: &BotAudioOutputSink,
    expected_participant: Option<&str>,
    runtime_call_id: &str,
    runtime_trace_id: &str,
    lifecycle_active: Arc<AtomicBool>,
) -> Option<bool> {
    let Some(probe) = pending_probe.take() else {
        return None;
    };
    if acknowledged_probe_sequences.contains(&(probe.generation, probe.sequence.clone())) {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "attributes_classified",
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
            false,
            Some("rejected"),
            Some("duplicate_or_old_sequence"),
        );
        return Some(false);
    }
    if Instant::now() > probe.expires_at {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "attributes_classified",
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
            false,
            Some("timeout"),
            Some("expired"),
        );
        return Some(false);
    }
    let Some(participant) = participant else {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "attributes_classified",
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
            false,
            None,
            Some("no_current_participant"),
        );
        *pending_probe = Some(probe);
        return None;
    };
    if participant.identity() != probe.sender {
        record_controlled_fixture_probe_event(
            runtime_call_id,
            runtime_trace_id,
            "attributes_classified",
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
            false,
            Some("rejected"),
            Some("wrong_participant"),
        );
        return Some(false);
    }
    let decision = observe_controlled_fixture_probe_attributes(
        probe.expires_at,
        participant.identity().as_str(),
        expected_participant,
        &probe,
        || participant.attributes(),
    )
    .await;
    if let Err(reason) = decision {
        record_controlled_fixture_attribute_decision(
            Err(reason),
            runtime_call_id,
            runtime_trace_id,
            &probe.call_id_hash,
            &probe.call_trace_id_hash,
            probe.generation,
            &probe.sequence,
        );
        return Some(false);
    }
    let (ack_result, reject_reason, observed) = record_controlled_fixture_attribute_decision(
        Ok(()),
        runtime_call_id,
        runtime_trace_id,
        &probe.call_id_hash,
        &probe.call_trace_id_hash,
        probe.generation,
        &probe.sequence,
    );
    let ack = controlled_fixture_ack_from_probe(&probe, observed, reject_reason);
    let payload = match serde_json::to_vec(&ack) {
        Ok(payload) => payload,
        Err(_) => return Some(false),
    };
    let local_participant = sink.room.local_participant();
    record_controlled_fixture_probe_event(
        runtime_call_id,
        runtime_trace_id,
        "ack_publish_started",
        &probe.call_id_hash,
        &probe.call_trace_id_hash,
        probe.generation,
        &probe.sequence,
        observed,
        Some(ack_result),
        reject_reason,
    );
    let publish = local_participant.publish_data(DataPacket {
        payload,
        topic: Some(CONTROLLED_FIXTURE_ACK_TOPIC.to_string()),
        reliable: true,
        destination_identities: vec![probe.sender.clone()],
    });
    let outcome = complete_controlled_fixture_ack_publish(
        publish,
        runtime_call_id,
        runtime_trace_id,
        observed,
        ack_result,
        reject_reason,
        &probe.call_id_hash,
        &probe.call_trace_id_hash,
        probe.generation,
        &probe.sequence,
        acknowledged_probe_sequences,
    )
    .await;
    if outcome.published && ack_result == "timeout" && reject_reason == Some("expired") {
        spawn_controlled_fixture_post_expiry_observation(
            probe,
            participant.clone(),
            sink.room.clone(),
            expected_participant.map(str::to_string),
            lifecycle_active,
            runtime_call_id.to_string(),
            runtime_trace_id.to_string(),
        );
    }
    Some(outcome.observed)
}
async fn handle_finished_turn(
@@ -2929,6 +3828,8 @@
    turn_bridge_config: TurnBridgeConfig,
    http: Client,
    sink: Arc<BotAudioOutputSink>,
    expected_participant_identity: Option<String>,
    participant: RemoteParticipant,
) -> JoinHandle<()> {
    tokio::spawn(async move {
        let mut stream = NativeAudioStream::new(
@@ -3007,6 +3908,8 @@
            None
        };
        let mut realtime_asr_upload: Option<RealtimeAsrUpload> = None;
        let mut last_fixture_sequence: Option<String> = None;
        let mut last_fixture_generation: Option<u64> = None;
        while let Some(drained) = frame_rx.recv().await {
            let frame = drained.frame;
@@ -3040,8 +3943,11 @@
            if let Some(vad) = simple_vad.as_mut() {
                if vad_enabled_gate.load(Ordering::Acquire) {
                    let was_in_speech = vad.in_speech;
                    let turn = vad.observe_frame(
                    let participant_identity = participant.identity().to_string();
                    let (was_in_speech, is_in_speech, turn) = observe_bound_participant_frame(
                        &participant_identity,
                        expected_participant_identity.as_deref(),
                        vad,
                        &call_id,
                        &trace_id,
                        &participant_alias,
@@ -3049,41 +3955,16 @@
                        frame_count,
                        elapsed_ms,
                        &frame,
                        http.clone(),
                        turn_bridge_config.realtime_asr_config(),
                        || participant.attributes(),
                        &mut realtime_asr_upload,
                        &mut last_fixture_sequence,
                        &mut last_fixture_generation,
                        turn_bridge_config.asr_realtime_enabled,
                    );
                    let is_in_speech = vad.in_speech;
                    if !was_in_speech && is_in_speech {
                        let turn_id = format!("turn-{:04}", vad.turn_index);
                        match RealtimeAsrUpload::start(
                            http.clone(),
                            turn_bridge_config.realtime_asr_config(),
                            &call_id,
                            &trace_id,
                            &turn_id,
                            &vad.speech_samples,
                            ingress_metadata.as_ref(),
                        ) {
                            Ok(upload) => {
                                info!(
                                    call_id = %call_id,
                                    trace_id = %trace_id,
                                    turn_id = %turn_id,
                                    "runtime helper asr_realtime_session_started"
                                );
                                realtime_asr_upload = Some(upload);
                            }
                            Err(error) if turn_bridge_config.asr_realtime_enabled => {
                                warn!(
                                    call_id = %call_id,
                                    trace_id = %trace_id,
                                    turn_id = %turn_id,
                                    error = %safe_error(&error.to_string()),
                                    "runtime helper asr_realtime_start_failed_fallback"
                                );
                            }
                            Err(_) => {}
                        }
                    } else if was_in_speech {
                    if was_in_speech {
                        let push_failed = realtime_asr_upload
                            .as_mut()
                            .and_then(|upload| upload.push_48k_samples(frame.data.as_ref()).err());
@@ -3200,6 +4081,201 @@
            "runtime helper user_audio_stream_ended"
        );
    })
}
fn observe_frame_and_start_session<F>(
    vad: &mut SimpleVad,
    call_id: &str,
    trace_id: &str,
    participant_alias: &str,
    track_sid_alias: &str,
    frame_count: u64,
    elapsed_ms: u64,
    frame: &AudioFrame<'_>,
    http: Client,
    config: RealtimeAsrConfig,
    read_attributes: F,
    upload_slot: &mut Option<RealtimeAsrUpload>,
    last_fixture_sequence: &mut Option<String>,
    last_fixture_generation: &mut Option<u64>,
    realtime_enabled: bool,
) -> (bool, bool, Option<FinishedSpeechTurn>)
where
    F: FnOnce() -> std::collections::HashMap<String, String>,
{
    let was_in_speech = vad.in_speech;
    let turn = vad.observe_frame(
        call_id,
        trace_id,
        participant_alias,
        track_sid_alias,
        frame_count,
        elapsed_ms,
        frame,
    );
    let is_in_speech = vad.in_speech;
    if !was_in_speech && is_in_speech {
        start_realtime_session_for_new_speech(
            http,
            config,
            call_id,
            trace_id,
            vad,
            read_attributes,
            upload_slot,
            last_fixture_sequence,
            last_fixture_generation,
            realtime_enabled,
        );
    }
    (was_in_speech, is_in_speech, turn)
}
fn observe_bound_participant_frame<F>(
    participant_identity: &str,
    expected_participant: Option<&str>,
    vad: &mut SimpleVad,
    call_id: &str,
    trace_id: &str,
    participant_alias: &str,
    track_sid_alias: &str,
    frame_count: u64,
    elapsed_ms: u64,
    frame: &AudioFrame<'_>,
    http: Client,
    config: RealtimeAsrConfig,
    read_attributes: F,
    upload_slot: &mut Option<RealtimeAsrUpload>,
    last_fixture_sequence: &mut Option<String>,
    last_fixture_generation: &mut Option<u64>,
    realtime_enabled: bool,
) -> (bool, bool, Option<FinishedSpeechTurn>)
where
    F: FnOnce() -> std::collections::HashMap<String, String>,
{
    if !is_bound_user_participant(participant_identity, expected_participant) {
        warn!(
            "audioIngressOriginStatus" = "wrong_participant_or_track",
            "runtime helper rejected audio participant before VAD/session"
        );
        return (vad.in_speech, vad.in_speech, None);
    }
    observe_frame_and_start_session(
        vad,
        call_id,
        trace_id,
        participant_alias,
        track_sid_alias,
        frame_count,
        elapsed_ms,
        frame,
        http,
        config,
        read_attributes,
        upload_slot,
        last_fixture_sequence,
        last_fixture_generation,
        realtime_enabled,
    )
}
fn start_realtime_session_for_new_speech(
    http: Client,
    config: RealtimeAsrConfig,
    call_id: &str,
    trace_id: &str,
    vad: &SimpleVad,
    read_attributes: impl FnOnce() -> std::collections::HashMap<String, String>,
    upload_slot: &mut Option<RealtimeAsrUpload>,
    last_fixture_sequence: &mut Option<String>,
    last_fixture_generation: &mut Option<u64>,
    realtime_enabled: bool,
) {
    let turn_id = format!("turn-{:04}", vad.turn_index);
    let attributes = read_attributes();
    let origin_status = AudioIngressMetadata::origin_status(&attributes);
    let metadata = match AudioIngressMetadata::from_participant(&attributes) {
        Ok(metadata) => metadata,
        Err(reason) => {
            warn!(call_id = %call_id, trace_id = %trace_id, turn_id = %turn_id,
                reason, audioIngressOriginStatus = %AudioIngressMetadata::rejected_origin_status(
                    reason, &attributes
                ),
                "runtime helper asr_realtime_metadata_rejected");
            return;
        }
    };
    if let Some(metadata) = metadata.as_ref() {
        if !fixture_binding_is_new(
            last_fixture_sequence.as_deref(),
            *last_fixture_generation,
            &metadata.client_fixture_sequence,
            metadata.input_generation,
        ) {
            warn!(call_id = %call_id, trace_id = %trace_id, turn_id = %turn_id,
                audioIngressOriginStatus = "sequence_replayed_or_regressed",
                "runtime helper asr_realtime_metadata_sequence_rejected");
            return;
        }
    }
    match RealtimeAsrUpload::start(
        http,
        config,
        call_id,
        trace_id,
        &turn_id,
        &vad.speech_samples,
        metadata.as_ref(),
    ) {
        Ok(upload) => {
            if let Some(metadata) = metadata {
                *last_fixture_sequence = Some(metadata.client_fixture_sequence);
                *last_fixture_generation = Some(metadata.input_generation);
            }
            info!(call_id = %call_id, trace_id = %trace_id, turn_id = %turn_id,
                origin_status, "runtime helper asr_realtime_session_started");
            *upload_slot = Some(upload);
        }
        Err(error) if realtime_enabled => {
            warn!(call_id = %call_id, trace_id = %trace_id, turn_id = %turn_id,
                error = %safe_error(&error.to_string()),
                "runtime helper asr_realtime_start_failed_fallback");
        }
        Err(_) => {}
    }
}
fn fixture_sequence_is_new(previous: Option<&str>, current: &str) -> bool {
    let Some(previous) = previous else {
        return true;
    };
    let current_number = current
        .rsplit_once('-')
        .and_then(|(_, value)| value.parse::<u64>().ok());
    let previous_number = previous
        .rsplit_once('-')
        .and_then(|(_, value)| value.parse::<u64>().ok());
    match (previous_number, current_number) {
        (Some(previous), Some(current)) => current > previous,
        _ => previous != current,
    }
}
fn fixture_binding_is_new(
    previous_sequence: Option<&str>,
    previous_generation: Option<u64>,
    current_sequence: &str,
    current_generation: u64,
) -> bool {
    if !valid_input_generation(current_generation) {
        return false;
    }
    match previous_generation {
        Some(previous) if current_generation < previous => false,
        Some(previous) if current_generation > previous => true,
        Some(_) => fixture_sequence_is_new(previous_sequence, current_sequence),
        None => true,
    }
}
struct DrainedUserAudioFrame {
@@ -3954,12 +5030,522 @@
#[cfg(test)]
mod tests {
    use super::{
        ReplyChunkMarker, ReplyChunkMarkerState, RuntimeTurnDeviceOutput, RuntimeTurnStreamEvent,
        RuntimeTurnStreamState, RuntimeTurnStreamTimingPhase, runtime_session_nonce_hash,
        should_publish_device_output,
    use super::*;
    use std::{
        collections::{HashMap, HashSet},
        io::{Read, Write},
        net::TcpListener,
        sync::{
            Arc,
            atomic::{AtomicUsize, Ordering},
            mpsc,
        },
        thread,
        time::Duration,
    };
    use std::collections::HashSet;
    #[derive(Debug)]
    enum PreAudioOrderEvent {
        DataReceived { sender: String, sequence: String },
        TrackSubscribed { participant: String },
    }
    fn drive_pre_audio_order_test_seam(events: &[PreAudioOrderEvent]) -> Vec<&'static str> {
        let call_id = "production-order-call";
        let trace_id = "production-order-trace";
        let mut pending_probe = None;
        let mut effects = Vec::new();
        for event in events {
            match event {
                PreAudioOrderEvent::DataReceived { sender, sequence } => {
                    let payload = serde_json::to_vec(&json!({
                        "type": CONTROLLED_FIXTURE_PROBE_TOPIC,
                        "protocolVersion": CONTROLLED_FIXTURE_PROTOCOL_VERSION,
                        "callIdHash": sha256_hex(call_id),
                        "callTraceIdHash": sha256_hex(trace_id),
                        "generation": CONTROLLED_FIXTURE_GENERATION,
                        "clientFixtureSequence": sequence,
                    }))
                    .expect("production probe payload");
                    pending_probe = controlled_fixture_probe(
                        &payload,
                        call_id,
                        trace_id,
                        &ParticipantIdentity(sender.clone()),
                        Some("user-1"),
                    );
                }
                PreAudioOrderEvent::TrackSubscribed { participant } => {
                    let pending = pending_probe.is_some();
                    let probe_result = pending_probe.as_ref().map(|probe| {
                        controlled_fixture_probe_binding_decision(
                            probe.sender.as_str(),
                            Some(participant),
                            Some("user-1"),
                        )
                        .is_ok()
                    });
                    let mut ack_observed = false;
                    let mut observer_started = false;
                    start_observer_after_controlled_fixture_probe(pending, probe_result, || {
                        if pending && probe_result == Some(true) {
                            ack_observed = true;
                        }
                        observer_started = true;
                    });
                    if ack_observed {
                        effects.push("ack_observed");
                    }
                    if observer_started {
                        effects.push("observer_started");
                    }
                    pending_probe = None;
                }
            }
        }
        effects
    }
    #[test]
    fn production_vad_session_boundary_reads_updated_attributes() {
        let config = SimpleVadConfig {
            rms_threshold: 0.001,
            peak_threshold: 0.01,
            start_frames: 2,
            end_silence_ms: 100,
            min_speech_ms: 1,
            max_turn_ms: 1_000,
            initial_ignore_ms: 0,
        };
        let mut vad = SimpleVad::new(config);
        let samples = vec![1_000i16; 160];
        let frame = AudioFrame {
            data: samples.as_slice().into(),
            sample_rate: 16_000,
            num_channels: 1,
            samples_per_channel: 160,
        };
        let mut attributes = std::collections::HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
            ("inputGeneration".to_string(), "1".to_string()),
            ("language".to_string(), "ja-JP".to_string()),
        ]);
        let mut starts = Vec::new();
        for (session_index, sequence) in [(1, "fixture-01"), (2, "fixture-02")] {
            let was_in_speech = vad.in_speech;
            vad.observe_frame(
                "call-001",
                "trace-001",
                "participant",
                "track",
                session_index * 2 - 1,
                1_000 * session_index,
                &frame,
            );
            vad.observe_frame(
                "call-001",
                "trace-001",
                "participant",
                "track",
                session_index * 2,
                1_000 * session_index + 10,
                &frame,
            );
            let is_in_speech = vad.in_speech;
            assert!(!was_in_speech && is_in_speech);
            attributes.insert("clientFixtureSequence".to_string(), sequence.to_string());
            attributes.insert("language".to_string(), "ja-JP".to_string());
            let metadata = AudioIngressMetadata::from_participant(&attributes)
                .expect("valid participant attributes")
                .expect("controlled fixture metadata");
            let session_line = asr_realtime::session_start_line(
                "call-001",
                "trace-001",
                &format!("turn-{session_index:04}"),
                "nonce-001",
                Some(&metadata),
            )
            .expect("session start line");
            let session_json: serde_json::Value =
                serde_json::from_slice(&session_line).expect("session start json");
            assert_eq!(sequence, session_json["clientFixtureSequence"]);
            assert_eq!("ja-JP", session_json["language"]);
            starts.push(metadata.client_fixture_sequence);
            vad.reset_current_turn();
        }
        assert_eq!(vec!["fixture-01", "fixture-02"], starts);
        attributes.insert("inputSourceCategory".to_string(), "other".to_string());
        assert!(AudioIngressMetadata::from_participant(&attributes).is_err());
        assert!(
            AudioIngressMetadata::from_participant(&std::collections::HashMap::new())
                .expect("missing attributes is absent")
                .is_none()
        );
        attributes.insert(
            "clientFixtureSequence".to_string(),
            "fixture-01".to_string(),
        );
        assert!(AudioIngressMetadata::from_participant(&attributes).is_err());
    }
    #[test]
    fn production_observer_rejects_wrong_participant_before_vad_session() {
        assert!(!is_bound_user_participant(
            "participant-other",
            Some("participant-user")
        ));
        assert!(is_bound_user_participant(
            "participant-user",
            Some("participant-user")
        ));
        assert!(is_bound_user_participant("participant-any", None));
    }
    #[tokio::test]
    async fn production_observer_vad_to_session_entry_reads_each_updated_attribute() {
        let listener = TcpListener::bind("127.0.0.1:0").expect("bind local ASR fixture");
        let address = listener.local_addr().expect("fixture address");
        let (request_tx, request_rx) = mpsc::channel::<String>();
        let captured_count = Arc::new(AtomicUsize::new(0));
        let captured_count_for_server = Arc::clone(&captured_count);
        let server = thread::spawn(move || {
            for _ in 0..2 {
                let (mut stream, _) = listener.accept().expect("accept ASR session");
                stream
                    .set_read_timeout(Some(Duration::from_secs(2)))
                    .expect("set fixture timeout");
                let mut bytes = Vec::new();
                let mut buffer = [0_u8; 4096];
                loop {
                    match stream.read(&mut buffer) {
                        Ok(0) => break,
                        Ok(size) => {
                            bytes.extend_from_slice(&buffer[..size]);
                            if bytes.windows(7).any(|window| window == b"0\r\n\r\n") {
                                break;
                            }
                        }
                        Err(_) => break,
                    }
                }
                request_tx
                    .send(String::from_utf8_lossy(&bytes).into_owned())
                    .expect("capture ASR request");
                captured_count_for_server.fetch_add(1, Ordering::SeqCst);
                stream
                    .write_all(b"HTTP/1.1 200 OK\r\ncontent-type: application/json\r\ncontent-length: 39\r\nconnection: close\r\n\r\n{\"code\":0,\"data\":{\"status\":\"ok\"}}")
                    .expect("write fixture response");
            }
        });
        let mut vad = SimpleVad::new(SimpleVadConfig {
            rms_threshold: 0.001,
            peak_threshold: 0.01,
            start_frames: 1,
            end_silence_ms: 100,
            min_speech_ms: 1,
            max_turn_ms: 1_000,
            initial_ignore_ms: 0,
        });
        let frame_data = vec![1_000i16; 160];
        let frame = AudioFrame {
            data: frame_data.as_slice().into(),
            sample_rate: 16_000,
            num_channels: 1,
            samples_per_channel: 160,
        };
        let mut attrs = std::collections::HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
            ("inputGeneration".to_string(), "1".to_string()),
            ("language".to_string(), "ja-JP".to_string()),
        ]);
        let mut upload = None;
        let mut last_fixture_sequence = None;
        let mut last_fixture_generation = None;
        let config = RealtimeAsrConfig {
            enabled: true,
            url: Some(format!("http://{address}/runtime/asr/realtime")),
            runtime_token: Some("test".to_string()),
            runtime_session_nonce: Some("test".to_string()),
            chunk_duration_ms: 200,
        };
        let (was, is, turn) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            1,
            1_000,
            &frame,
            Client::new(),
            config.clone(),
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(!was && is && turn.is_none());
        assert!(upload.is_some());
        upload.take().unwrap().cancel("test").await;
        vad.reset_current_turn();
        attrs.insert(
            "clientFixtureSequence".to_string(),
            "fixture-02".to_string(),
        );
        attrs.insert("inputGeneration".to_string(), "2".to_string());
        attrs.insert("language".to_string(), "zh-CN".to_string());
        let (was, is, turn) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            2,
            2_000,
            &frame,
            Client::new(),
            config.clone(),
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(!was && is && turn.is_none());
        assert!(upload.is_some());
        upload.take().unwrap().cancel("test").await;
        let first_request = request_rx
            .recv_timeout(Duration::from_secs(2))
            .expect("first session request");
        let second_request = request_rx
            .recv_timeout(Duration::from_secs(2))
            .expect("second session request");
        assert!(first_request.contains("\"clientFixtureSequence\":\"fixture-01\""));
        assert!(second_request.contains("\"clientFixtureSequence\":\"fixture-02\""));
        assert!(first_request.contains("\"callId\":\"call-001\""));
        assert!(first_request.contains("\"traceId\":\"trace-001\""));
        assert!(second_request.contains("\"callId\":\"call-001\""));
        assert!(second_request.contains("\"traceId\":\"trace-001\""));
        assert!(first_request.contains("\"inputSourceCategory\":\"controlled_fixture\""));
        assert!(second_request.contains("\"inputSourceCategory\":\"controlled_fixture\""));
        assert!(first_request.contains("\"inputGeneration\":1"));
        assert!(second_request.contains("\"inputGeneration\":2"));
        assert!(first_request.contains("\"language\":\"ja-JP\""));
        assert!(second_request.contains("\"language\":\"zh-CN\""));
        assert!(
            first_request.contains("\"audioIngressOriginStatus\":\"controlled_fixture_bound\"")
        );
        assert!(
            second_request.contains("\"audioIngressOriginStatus\":\"controlled_fixture_bound\"")
        );
        // The same production boundary rejects a wrong participant before VAD/session creation.
        assert!(!is_bound_user_participant(
            "participant-other",
            Some("participant-user")
        ));
        assert_eq!(0, request_rx.try_iter().count());
        vad.reset_current_turn();
        attrs.insert(
            "clientFixtureSequence".to_string(),
            "fixture-03".to_string(),
        );
        attrs.insert("inputGeneration".to_string(), "1".to_string());
        let (_, is_old_generation, old_generation_turn) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            3,
            3_000,
            &frame,
            Client::new(),
            config.clone(),
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(is_old_generation && old_generation_turn.is_none() && upload.is_none());
        vad.reset_current_turn();
        attrs.insert(
            "clientFixtureSequence".to_string(),
            "fixture-04".to_string(),
        );
        let (_, is_wrong, wrong_turn) = observe_bound_participant_frame(
            "participant-other",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            3,
            3_000,
            &frame,
            Client::new(),
            RealtimeAsrConfig {
                enabled: true,
                url: Some(format!("http://{address}/runtime/asr/realtime")),
                runtime_token: Some("test".to_string()),
                runtime_session_nonce: Some("test".to_string()),
                chunk_duration_ms: 200,
            },
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(!is_wrong && wrong_turn.is_none() && upload.is_none());
        vad.reset_current_turn();
        attrs.insert(
            "clientFixtureSequence".to_string(),
            "fixture-01".to_string(),
        );
        let (_, _, _) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            4,
            4_000,
            &frame,
            Client::new(),
            RealtimeAsrConfig {
                enabled: true,
                url: Some(format!("http://{address}/runtime/asr/realtime")),
                runtime_token: Some("test".to_string()),
                runtime_session_nonce: Some("test".to_string()),
                chunk_duration_ms: 200,
            },
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(upload.is_none());
        vad.reset_current_turn();
        let (_, _, _) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            5,
            5_000,
            &frame,
            Client::new(),
            RealtimeAsrConfig {
                enabled: true,
                url: Some(format!("http://{address}/runtime/asr/realtime")),
                runtime_token: Some("test".to_string()),
                runtime_session_nonce: Some("test".to_string()),
                chunk_duration_ms: 200,
            },
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(upload.is_none());
        vad.reset_current_turn();
        attrs.remove("clientFixtureSequence");
        let (_, _, missing_sequence_turn) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-user",
            "track-001",
            6,
            6_000,
            &frame,
            Client::new(),
            RealtimeAsrConfig {
                enabled: true,
                url: Some(format!("http://{address}/runtime/asr/realtime")),
                runtime_token: Some("test".to_string()),
                runtime_session_nonce: Some("test".to_string()),
                chunk_duration_ms: 200,
            },
            || attrs.clone(),
            &mut upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(missing_sequence_turn.is_none() && upload.is_none());
        assert_eq!(
            "sequence_absent",
            AudioIngressMetadata::rejected_origin_status("incomplete_metadata", &attrs)
        );
        assert_eq!(2, captured_count.load(Ordering::SeqCst));
        vad.reset_current_turn();
        attrs.insert("inputSourceCategory".to_string(), "other".to_string());
        let mut invalid_upload = None;
        let (_, _, invalid_turn) = observe_bound_participant_frame(
            "participant-user",
            Some("participant-user"),
            &mut vad,
            "call-001",
            "trace-001",
            "participant-other",
            "track-001",
            3,
            3_000,
            &frame,
            Client::new(),
            RealtimeAsrConfig {
                enabled: true,
                url: Some("http://127.0.0.1:9".to_string()),
                runtime_token: Some("test".to_string()),
                runtime_session_nonce: Some("test".to_string()),
                chunk_duration_ms: 200,
            },
            || attrs,
            &mut invalid_upload,
            &mut last_fixture_sequence,
            &mut last_fixture_generation,
            true,
        );
        assert!(invalid_turn.is_none());
        assert!(invalid_upload.is_none());
        assert_eq!(2, captured_count.load(Ordering::SeqCst));
        assert_eq!(0, request_rx.try_iter().count());
        server.join().expect("fixture server");
    }
    #[test]
    fn reply_chunk_marker_state_emits_turn_first_once_and_later_segment_first_once() {
@@ -4089,4 +5675,782 @@
            assert!(published.is_empty());
        }
    }
    #[test]
    fn controlled_fixture_probe_requires_bound_hashes_and_protocol() {
        let call_id = "call-ack-1";
        let trace_id = "trace-ack-1";
        let payload = serde_json::to_vec(&json!({
            "type": CONTROLLED_FIXTURE_PROBE_TOPIC,
            "protocolVersion": CONTROLLED_FIXTURE_PROTOCOL_VERSION,
            "callIdHash": sha256_hex(call_id),
            "callTraceIdHash": sha256_hex(trace_id),
            "generation": CONTROLLED_FIXTURE_GENERATION,
            "clientFixtureSequence": "fixture-01"
        }))
        .unwrap();
        let sender = ParticipantIdentity("user-1".to_string());
        let pending =
            controlled_fixture_probe(&payload, call_id, trace_id, &sender, Some("user-1"))
                .expect("valid probe");
        assert_eq!(pending.sequence, "fixture-01");
        assert_eq!(pending.call_id_hash, sha256_hex(call_id));
        assert_eq!(pending.call_trace_id_hash, sha256_hex(trace_id));
        assert_eq!(pending.generation, CONTROLLED_FIXTURE_GENERATION);
        assert!(
            controlled_fixture_probe(&payload, call_id, "other-trace", &sender, Some("user-1"),)
                .is_none()
        );
        assert!(
            controlled_fixture_probe(
                &payload,
                call_id,
                trace_id,
                &ParticipantIdentity("other-user".to_string()),
                Some("user-1"),
            )
            .is_none()
        );
    }
    #[test]
    fn controlled_fixture_attributes_ack_only_on_exact_current_sequence() {
        let mut attributes = std::collections::HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        assert!(
            classify_controlled_fixture_attributes(
                "user-1",
                Some("user-1"),
                &attributes,
                "fixture-01"
            )
            .is_ok()
        );
        attributes.insert(
            "clientFixtureSequence".to_string(),
            "fixture-02".to_string(),
        );
        assert_eq!(
            classify_controlled_fixture_attributes(
                "user-1",
                Some("user-1"),
                &attributes,
                "fixture-01"
            ),
            Err("wrong_sequence")
        );
        attributes.remove("clientFixtureSequence");
        assert_eq!(
            classify_controlled_fixture_attributes(
                "user-1",
                Some("user-1"),
                &attributes,
                "fixture-01"
            ),
            Err("missing_sequence")
        );
        assert_eq!(
            classify_controlled_fixture_attributes(
                "other-user",
                Some("user-1"),
                &attributes,
                "fixture-01"
            ),
            Err("wrong_participant")
        );
    }
    #[test]
    fn controlled_fixture_probe_runtime_projection_binds_request_hashes_and_audio_gate() {
        let call_id = "private-call-value";
        let trace_id = "private-trace-value";
        let sequence = "private-sequence-value";
        let call_id_hash = sha256_hex(call_id);
        let trace_id_hash = sha256_hex(trace_id);
        let mut observer_starts = 0;
        let (ack_result, reject_reason, observed) =
            controlled_fixture_ack_classification(Err("wrong_source"));
        let stages = [
            ("data_received", None, None),
            ("attributes_classified", Some(ack_result), reject_reason),
            ("ack_publish_started", Some(ack_result), reject_reason),
            ("ack_publish_completed", Some(ack_result), reject_reason),
            ("audio_observer_blocked", Some(ack_result), reject_reason),
        ];
        for (stage, result, reason) in stages {
            let event = controlled_fixture_probe_event(
                call_id,
                trace_id,
                stage,
                &call_id_hash,
                &trace_id_hash,
                CONTROLLED_FIXTURE_GENERATION,
                sequence,
                observed,
                result,
                reason,
            );
            assert_eq!(event["type"], "cv_activity");
            assert_eq!(event["eventName"], "controlled_fixture_attribute_probe");
            assert_eq!(event["extension"]["call_id_hash"], call_id_hash);
            assert_eq!(event["extension"]["trace_id_hash"], trace_id_hash);
            assert_eq!(event["extension"]["stage"], stage);
            let output = event.to_string();
            assert!(!output.contains(sequence));
        }
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(observed),
            || observer_starts += 1,
        ));
        assert_eq!(observer_starts, 0);
        let (ack_result, reject_reason, observed) = controlled_fixture_ack_classification(Ok(()));
        let allowed = controlled_fixture_probe_event(
            call_id,
            trace_id,
            "audio_observer_allowed",
            &call_id_hash,
            &trace_id_hash,
            CONTROLLED_FIXTURE_GENERATION,
            sequence,
            observed,
            Some(ack_result),
            reject_reason,
        );
        assert_eq!(allowed["extension"]["trace_id_hash"], trace_id_hash);
        assert!(start_observer_after_controlled_fixture_probe(
            true,
            Some(observed),
            || observer_starts += 1,
        ));
        assert_eq!(observer_starts, 1);
    }
    #[test]
    fn controlled_fixture_probe_observed_and_failure_enums_are_stable() {
        assert_eq!(
            controlled_fixture_ack_classification(Ok(())),
            ("observed", None, true)
        );
        assert_eq!(
            controlled_fixture_ack_classification(Err("timeout")),
            ("timeout", Some("expired"), false)
        );
        for reason in [
            "missing_attributes",
            "wrong_source",
            "missing_sequence",
            "wrong_sequence",
            "wrong_participant",
        ] {
            assert_eq!(
                controlled_fixture_ack_classification(Err(reason)),
                ("rejected", Some(reason), false)
            );
        }
        assert_eq!(
            controlled_fixture_ack_classification(Err("unclassified")),
            ("rejected", Some("unknown"), false)
        );
    }
    #[test]
    fn production_probe_binding_drives_rejected_and_observed_ack_without_local_rehash() {
        let request_call_hash = "aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa";
        let request_trace_hash = "bbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbbb";
        let probe = PendingControlledFixtureProbe {
            sender: ParticipantIdentity("user-1".to_string()),
            call_id_hash: request_call_hash.to_string(),
            call_trace_id_hash: request_trace_hash.to_string(),
            generation: CONTROLLED_FIXTURE_GENERATION,
            sequence: "fixture-01".to_string(),
            received_at: Instant::now(),
            expires_at: Instant::now() + CONTROLLED_FIXTURE_PROBE_TTL,
        };
        let (ack_result, reject_reason, observed) =
            controlled_fixture_ack_classification(Err("wrong_sequence"));
        let rejected_ack = controlled_fixture_ack_from_probe(&probe, observed, reject_reason);
        let rejected_json = serde_json::to_value(&rejected_ack).unwrap();
        let mut rejected_observer_starts = 0;
        assert_eq!(ack_result, "rejected");
        assert_eq!(rejected_json["callIdHash"], request_call_hash);
        assert_eq!(rejected_json["callTraceIdHash"], request_trace_hash);
        assert_eq!(rejected_json["rejectReason"], "wrong_sequence");
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(observed),
            || rejected_observer_starts += 1,
        ));
        assert_eq!(rejected_observer_starts, 0);
        let (ack_result, reject_reason, observed) = controlled_fixture_ack_classification(Ok(()));
        let observed_ack = controlled_fixture_ack_from_probe(&probe, observed, reject_reason);
        let observed_json = serde_json::to_value(&observed_ack).unwrap();
        let mut observed_observer_starts = 0;
        assert_eq!(ack_result, "observed");
        assert_eq!(observed_json["callIdHash"], request_call_hash);
        assert_eq!(observed_json["callTraceIdHash"], request_trace_hash);
        assert!(observed_json.get("rejectReason").is_none());
        assert!(start_observer_after_controlled_fixture_probe(
            true,
            Some(observed),
            || observed_observer_starts += 1,
        ));
        assert_eq!(observed_observer_starts, 1);
    }
    #[tokio::test]
    async fn production_ack_publish_failure_keeps_observer_session_and_audio_closed() {
        let mut acknowledged = HashSet::new();
        let probe_result = complete_controlled_fixture_ack_publish(
            async { Err::<(), ()>(()) },
            "runtime-call-publish-failure",
            "runtime-trace-publish-failure",
            true,
            "observed",
            None,
            "call-publish-failure",
            "trace-publish-failure",
            CONTROLLED_FIXTURE_GENERATION,
            "fixture-01",
            &mut acknowledged,
        )
        .await;
        let mut observer_starts = 0;
        let mut session_starts = 0;
        let mut audio_starts = 0;
        let mut speaking_starts = 0;
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(probe_result.observed),
            || {
                observer_starts += 1;
                session_starts += 1;
                audio_starts += 1;
                speaking_starts += 1;
            },
        ));
        assert_eq!(
            probe_result,
            ControlledFixtureAckPublishOutcome {
                observed: false,
                published: false,
            }
        );
        assert!(acknowledged.is_empty());
        assert_eq!(observer_starts, 0);
        assert_eq!(session_starts, 0);
        assert_eq!(audio_starts, 0);
        assert_eq!(speaking_starts, 0);
        let observed_result = complete_controlled_fixture_ack_publish(
            async { Ok::<(), ()>(()) },
            "runtime-call-publish-success",
            "runtime-trace-publish-success",
            true,
            "observed",
            None,
            "call-publish-success",
            "trace-publish-success",
            CONTROLLED_FIXTURE_GENERATION,
            "fixture-02",
            &mut acknowledged,
        )
        .await;
        let mut successful_observer_starts = 0;
        assert!(start_observer_after_controlled_fixture_probe(
            true,
            Some(observed_result.observed),
            || successful_observer_starts += 1,
        ));
        assert_eq!(
            observed_result,
            ControlledFixtureAckPublishOutcome {
                observed: true,
                published: true,
            }
        );
        assert!(acknowledged.contains(&(CONTROLLED_FIXTURE_GENERATION, "fixture-02".to_string())));
        assert_eq!(successful_observer_starts, 1);
    }
    #[tokio::test]
    async fn production_attribute_observation_accepts_server_visibility_within_probe_ttl() {
        let expected = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        let mut reads = 0;
        let result = observe_controlled_fixture_attributes(
            Instant::now() + CONTROLLED_FIXTURE_PROBE_TTL,
            "user-1",
            Some("user-1"),
            "fixture-01",
            || {
                reads += 1;
                if reads <= 3 {
                    HashMap::new()
                } else {
                    expected.clone()
                }
            },
        )
        .await;
        assert_eq!(result, Ok(()));
        assert_eq!(reads, 4);
    }
    #[tokio::test]
    async fn production_probe_waits_for_generation_attribute_before_binding() {
        let received_at = Instant::now();
        let probe = PendingControlledFixtureProbe {
            sender: ParticipantIdentity("user-1".to_string()),
            call_id_hash: "call-hash".to_string(),
            call_trace_id_hash: "trace-hash".to_string(),
            generation: 2,
            sequence: "fixture-02".to_string(),
            received_at,
            expires_at: received_at + CONTROLLED_FIXTURE_PROBE_TTL,
        };
        let expected = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-02".to_string(),
            ),
            ("inputGeneration".to_string(), "2".to_string()),
        ]);
        let mut reads = 0;
        let result = observe_controlled_fixture_probe_attributes(
            probe.expires_at,
            "user-1",
            Some("user-1"),
            &probe,
            || {
                reads += 1;
                if reads == 1 {
                    HashMap::new()
                } else {
                    expected.clone()
                }
            },
        )
        .await;
        assert_eq!(result, Ok(()));
        assert_eq!(reads, 2);
    }
    #[tokio::test]
    async fn production_attribute_observation_rejects_wrong_sequence_without_audio_effect() {
        let attributes = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-02".to_string(),
            ),
        ]);
        let result = observe_controlled_fixture_attributes(
            Instant::now() + CONTROLLED_FIXTURE_PROBE_TTL,
            "user-1",
            Some("user-1"),
            "fixture-01",
            || attributes.clone(),
        )
        .await;
        let mut observer_starts = 0;
        assert_eq!(result, Err("wrong_sequence"));
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(result.is_ok()),
            || observer_starts += 1,
        ));
        assert_eq!(observer_starts, 0);
    }
    #[tokio::test]
    async fn production_post_expiry_observation_records_bounded_visibility_without_second_ack() {
        let started_at = Instant::now();
        let active = Arc::new(AtomicBool::new(true));
        let expected = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        let mut acknowledged = HashSet::new();
        let expired_ack = complete_controlled_fixture_ack_publish(
            async { Ok::<(), ()>(()) },
            "runtime-call-post-expiry",
            "runtime-trace-post-expiry",
            false,
            "timeout",
            Some("expired"),
            "call-post-expiry",
            "trace-post-expiry",
            CONTROLLED_FIXTURE_GENERATION,
            "fixture-01",
            &mut acknowledged,
        )
        .await;
        assert_eq!(
            expired_ack,
            ControlledFixtureAckPublishOutcome {
                observed: false,
                published: true,
            }
        );
        let evidence = observe_controlled_fixture_post_expiry_views(
            started_at,
            started_at + CONTROLLED_FIXTURE_POST_EXPIRY_WINDOW,
            "user-1",
            Some("user-1"),
            "fixture-01",
            active,
            || {
                if started_at.elapsed() >= Duration::from_millis(300) {
                    expected.clone()
                } else {
                    HashMap::new()
                }
            },
            || Some(("user-1".to_string(), HashMap::new())),
        )
        .await;
        assert_eq!(acknowledged.len(), 1);
        assert_eq!(
            evidence,
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "250_500ms",
                visibility_source: "participant_attributes_poll",
                visibility_result: "held_visible",
                binding_matched: true,
            })
        );
        let never_started_at = Instant::now();
        assert_eq!(
            observe_controlled_fixture_post_expiry_views(
                never_started_at,
                never_started_at + Duration::from_millis(40),
                "user-1",
                Some("user-1"),
                "fixture-01",
                Arc::new(AtomicBool::new(true)),
                HashMap::new,
                || Some(("user-1".to_string(), HashMap::new())),
            )
            .await,
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "never_visible_within_observation_window",
                visibility_source: "held_and_current_room_lookup",
                visibility_result: "unavailable_both",
                binding_matched: true,
            })
        );
        assert_eq!(
            observe_controlled_fixture_post_expiry_views(
                Instant::now(),
                Instant::now() + Duration::from_millis(50),
                "cross-call-user",
                Some("user-1"),
                "fixture-01",
                Arc::new(AtomicBool::new(true)),
                || expected.clone(),
                || Some(("user-1".to_string(), expected.clone())),
            )
            .await,
            None
        );
        let inactive = Arc::new(AtomicBool::new(false));
        assert_eq!(
            observe_controlled_fixture_post_expiry_views(
                Instant::now(),
                Instant::now() + Duration::from_millis(50),
                "user-1",
                Some("user-1"),
                "fixture-01",
                inactive,
                HashMap::new,
                || Some(("user-1".to_string(), HashMap::new())),
            )
            .await,
            None
        );
        assert_eq!(acknowledged.len(), 1);
        let probe = PendingControlledFixtureProbe {
            sender: ParticipantIdentity("user-1".to_string()),
            call_id_hash: "call-post-expiry".to_string(),
            call_trace_id_hash: "trace-post-expiry".to_string(),
            generation: CONTROLLED_FIXTURE_GENERATION,
            sequence: "fixture-01".to_string(),
            received_at: started_at,
            expires_at: started_at + CONTROLLED_FIXTURE_PROBE_TTL,
        };
        let event = controlled_fixture_visibility_event(
            "runtime-call-post-expiry",
            "runtime-trace-post-expiry",
            &probe,
            &evidence.unwrap(),
        );
        let extension = event["extension"].as_object().unwrap();
        let mut keys = extension.keys().map(String::as_str).collect::<Vec<_>>();
        keys.sort_unstable();
        assert_eq!(
            keys,
            vec![
                "binding_matched",
                "call_id_hash",
                "evidence_count",
                "first_visible_bucket",
                "generation",
                "sequence_hash",
                "stage",
                "trace_id_hash",
                "visibility_result",
                "visibility_source",
            ]
        );
        let encoded = event.to_string();
        for forbidden in [
            "\"participant\":",
            "\"room\":",
            "\"track\":",
            "\"payload\":",
            "\"audio\":",
        ] {
            assert!(!encoded.contains(forbidden));
        }
    }
    #[tokio::test]
    async fn production_post_expiry_observation_distinguishes_held_stale_from_current_room_view() {
        let started_at = Instant::now();
        let current_attributes = HashMap::from([
            (
                "inputSourceCategory".to_string(),
                "controlled_fixture".to_string(),
            ),
            (
                "clientFixtureSequence".to_string(),
                "fixture-01".to_string(),
            ),
        ]);
        let mut acknowledged = HashSet::new();
        let expired_ack = complete_controlled_fixture_ack_publish(
            async { Ok::<(), ()>(()) },
            "runtime-call-current-view",
            "runtime-trace-current-view",
            false,
            "timeout",
            Some("expired"),
            "call-current-view",
            "trace-current-view",
            CONTROLLED_FIXTURE_GENERATION,
            "fixture-01",
            &mut acknowledged,
        )
        .await;
        let evidence = observe_controlled_fixture_post_expiry_views(
            started_at,
            started_at + Duration::from_millis(100),
            "user-1",
            Some("user-1"),
            "fixture-01",
            Arc::new(AtomicBool::new(true)),
            HashMap::new,
            || Some(("user-1".to_string(), current_attributes.clone())),
        )
        .await;
        assert_eq!(
            expired_ack,
            ControlledFixtureAckPublishOutcome {
                observed: false,
                published: true,
            }
        );
        assert_eq!(acknowledged.len(), 1);
        assert_eq!(
            evidence,
            Some(ControlledFixtureVisibilityEvidence {
                first_visible_bucket: "lte_250ms",
                visibility_source: "current_room_lookup",
                visibility_result: "held_stale_current_visible",
                binding_matched: true,
            })
        );
        let mut observer_starts = 0;
        assert!(!start_observer_after_controlled_fixture_probe(
            true,
            Some(expired_ack.observed),
            || observer_starts += 1,
        ));
        assert_eq!(observer_starts, 0);
        for current_view in [
            None,
            Some(("cross-call-user".to_string(), current_attributes.clone())),
            Some((
                "user-1".to_string(),
                HashMap::from([
                    (
                        "inputSourceCategory".to_string(),
                        "controlled_fixture".to_string(),
                    ),
                    (
                        "clientFixtureSequence".to_string(),
                        "fixture-old".to_string(),
                    ),
                ]),
            )),
        ] {
            assert_eq!(
                observe_controlled_fixture_post_expiry_views(
                    Instant::now(),
                    Instant::now() + Duration::from_millis(20),
                    "user-1",
                    Some("user-1"),
                    "fixture-01",
                    Arc::new(AtomicBool::new(true)),
                    HashMap::new,
                    || current_view.clone(),
                )
                .await,
                None
            );
        }
    }
    #[test]
    fn controlled_fixture_ack_payload_is_reliable_and_redacted() {
        let ack = ControlledFixtureAttributeAck {
            message_type: CONTROLLED_FIXTURE_ACK_TOPIC,
            protocol_version: CONTROLLED_FIXTURE_PROTOCOL_VERSION,
            call_id_hash: sha256_hex("call-1"),
            call_trace_id_hash: sha256_hex("trace-1"),
            generation: CONTROLLED_FIXTURE_GENERATION,
            client_fixture_sequence: "fixture-01".to_string(),
            result: "observed",
            input_source_category: Some("controlled_fixture"),
            reject_reason: None,
        };
        let encoded = serde_json::to_vec(&ack).unwrap();
        let decoded: serde_json::Value = serde_json::from_slice(&encoded).unwrap();
        assert_eq!(decoded["type"], CONTROLLED_FIXTURE_ACK_TOPIC);
        assert_eq!(
            decoded["protocolVersion"],
            CONTROLLED_FIXTURE_PROTOCOL_VERSION
        );
        assert_eq!(decoded["result"], "observed");
        assert!(decoded.get("callId").is_none());
        assert!(decoded.get("traceId").is_none());
        assert!(decoded.get("participantIdentity").is_none());
        assert!(decoded.get("audio").is_none());
    }
    #[test]
    fn controlled_fixture_probe_does_not_create_session_or_audio_side_effects() {
        let attributes = std::collections::HashMap::new();
        assert_eq!(
            classify_controlled_fixture_attributes(
                "user-1",
                Some("user-1"),
                &attributes,
                "fixture-01"
            ),
            Err("missing_attributes")
        );
        assert_eq!(
            CONTROLLED_FIXTURE_PROBE_TOPIC,
            "controlled_fixture_attribute_probe"
        );
        assert_eq!(
            CONTROLLED_FIXTURE_ACK_TOPIC,
            "controlled_fixture_attribute_ack"
        );
    }
    #[test]
    fn controlled_fixture_probe_must_be_observed_before_audio_observer() {
        assert!(controlled_fixture_observer_gate(false, None));
        assert!(controlled_fixture_observer_gate(true, Some(true)));
        assert!(!controlled_fixture_observer_gate(true, Some(false)));
        assert!(!controlled_fixture_observer_gate(true, None));
    }
    #[test]
    fn production_event_order_probe_then_track_publishes_ack_before_observer() {
        let effects = drive_pre_audio_order_test_seam(&[
            PreAudioOrderEvent::DataReceived {
                sender: "user-1".to_string(),
                sequence: "1".to_string(),
            },
            PreAudioOrderEvent::TrackSubscribed {
                participant: "user-1".to_string(),
            },
        ]);
        assert_eq!(effects, ["ack_observed", "observer_started"]);
    }
    #[test]
    fn production_event_order_negative_probe_has_no_observer_or_session_effect() {
        let effects = drive_pre_audio_order_test_seam(&[
            PreAudioOrderEvent::DataReceived {
                sender: "user-1".to_string(),
                sequence: "1".to_string(),
            },
            PreAudioOrderEvent::TrackSubscribed {
                participant: "cross-call-user".to_string(),
            },
        ]);
        assert!(effects.is_empty());
    }
    #[test]
    fn production_audio_branch_orders_probe_before_spawn_callsite() {
        let source = include_str!("main.rs");
        let branch = source
            .find("RoomEvent::TrackSubscribed {\n                track: RemoteTrack::Audio")
            .expect("audio TrackSubscribed production branch");
        let branch_source = &source[branch..];
        let probe = branch_source
            .find("let probe_result = process_controlled_fixture_probe")
            .expect("probe must be processed in audio branch");
        let spawn = branch_source
            .find("start_observer_after_controlled_fixture_probe")
            .expect("spawn must use shared order entry");
        assert!(
            probe < spawn,
            "probe must precede shared observer spawn entry"
        );
    }
}