The Rail · Reference & analysis

V3 Stage channel integration

The channel adapter consumes a narrow StageRenderedCatalogPort, not the V3 GA constants or Calliope test fixtures.

10sections12 minread1table

On this page

Audit date: 2026-07-17

Decision: the Rail channel's technical identity is v3.stage, with the working display name V3 Stage. Existing V3 tenant packages, contracts, Unreal paths, and database models retain their historical Saraswati names; they are not renamed in place. The separate @saraswati/* family is an industrial-technology domain covering EVs, batteries, manufacturing, robotics, health hardware, IoT, and related infrastructure. It is not a media or performance dependency.

Calliope Stage is the normative concert-design and performance-programming reference for V3 Stage. V3 does not currently import it at runtime. V3 owns the tenant-specific persona, rights, catalog, recorded-evidence authoring, quality, provenance, and Unreal contract seams. A future cook composition root should combine those V3 release gates with selected Calliope stage outputs, then require a separately rendered and verified playable artifact. Neither system may be treated as a media renderer merely because it produces an asset id, protocol plan, or VOD package description.

Audited source map#

Concern Existing source What is real today Rail decision
V3 tenant and release ownership libs/v3/saraswati-stage, especially concert-authoring-pipeline.ts, discography-release-flow.ts, and track-c2pa-manifests.ts Persona/catalog/rights state and ten deterministic authoring gates exist. Recorded evidence can drive speech review, rehearsal, choreography, and cadence; a declared drill is explicitly labeled and cannot publish unless a caller opts into a drill-only receipt. Use V3's recorded-evidence and release decisions as required inputs. Never admit GA inventory or a declared-drill receipt to the playable catalog.
V3 export quality libs/v3/concert-quality Scene quality, corpus diversity, provenance/consent, signoff, and the authoring release state compose into a real fail-closed export report. The shared Ed25519 content signer backs track C2PA. Require a passing export report and verified provenance for every first-party item. A report is evidence about authored content, not proof that video bytes exist.
V3 Unreal concert contract ConcertMaster.v3sequence.json, V3Cinematics, and V3Audio The repository carries a JSON concert-master binding contract and thin module registration seams. The .uasset path is JSON text rather than a cooked LevelSequence; there is no checked-in rendered concert or music-video media. A cook job may invoke an injected Unreal render/export port, but cannot claim a render from the contract file. Local UE verification must use the checked-in UE5.5 tree when that job lands.
Calliope concert specification libs/calliope/stage, especially types/live-performance.ts and its 30 deterministic services Typed, test-covered concept, setlist, stage, lighting, screens, choreography, venue, cameras, VFX, spatial-audio, audience, streaming, and VOD-package designs are substantially complete. Cross-object refinements reject mismatched artist, concept, setlist, venue, camera, and audience identities. Cite Calliope as the normative stage specification and compose only the needed cook-time outputs. Do not duplicate its setlist/venue/camera/streaming-plan types in the channel.
Calliope streaming output streaming-integration-layer.ts It deterministically describes destinations, ingest/output protocols, quality profiles, moderated chat, and four VOD package plans. It does not emit a stream URL, media manifest, object-store artifact, checksum, or playback receipt. Use its pacing, perspective, and packaging metadata after render. Never convert a planned hls, ll_hls, webrtc, or VOD package label into a playable source.
V3 Pixel Streaming libs/v3/lilith-web-pxstream A real browser client can match a worker, connect the Epic UE5.5 frontend, enforce first-frame/input-probe budgets, and reconnect. This is an interactive session path, not a scheduled progressive/VOD catalog. Phase A stays VOD/progressive as required. Do not create a live concert dependency or use a Pixel Streaming signalling URL as a VOD item.
Namespace collision libs/saraswati/README.md @saraswati/* is the advanced-technology intelligence domain: manufacturing, energy, mobility, health hardware, telecom, robotics, and IoT. It shares only the name with the V3 virtual-artist tenant. Reserve v3.stage and rail-channel-stage for this Rail channel. Keep @oshun/tenant-saraswati-stage as the legacy V3 implementation package and list any final public brand choice under HG-7.

Phase A programming path#

The channel adapter consumes a narrow StageRenderedCatalogPort, not the V3 GA constants or Calliope test fixtures. An eligible item must bind:

  1. a stable performance/version id and first-party/generated rights status;
  2. a V3 recorded-evidence authoring receipt and passing concert-export report;
  3. a real progressive/VOD delivery object plus duration, byte size, media type, SHA-256 digest, and a successful playback-verification observation;
  4. a separately playable paired audio source for the one-holder lane-coupling path;
  5. truthful artwork metadata whose referenced asset is also delivery-verified;
  6. Calliope-derived energy, set section, camera perspective, and pacing metadata when the cook used those plans.

The programming compiler is deterministic. It filters ineligible or unplayable rows, chooses an explicit daypart pacing target, scores energy and cut density distance, penalizes recent repetition, and orders ties by stable item id. It compiles a bounded horizon without shuffle or a seed catalog. Empty input produces no program.

Implemented 2026-07-17: libs/v10/rail-channel-stage now owns this strict catalog projection and compiler. It caps catalog reads, rejects duplicate ids, requires current exact-size/SHA-256 video, audio, and artwork observations, and keeps follows/favorites exclusive to the player-face score. Stable program ids derive from the selected versioned rows and schedule rather than randomness.

The cook job is a composition root: read a release candidate, require recorded V3 evidence and export gates, select the cited Calliope specification outputs, invoke an injected render/export port, store immutable media, and verify the stored bytes before publishing the catalog row. A renderer that is not configured fails closed. Licensed third-party catalog expansion remains HG-2; first-party/generated artifacts are the agent-actionable Phase A path.

Implemented 2026-07-17: StageRenderedMediaCookJob supplies this composition root through injected source, V3 release-gate, render, immutable-store, delivery-verifier, and catalog-writer ports. It hashes the renderer-returned bytes itself, rejects changed store or delivery receipts, and publishes no catalog row on any missing or blocked boundary. The repository still contains no production renderer binding or rendered Stage catalog row, so the job does not create fictitious availability.

Playback and premiere truth#

Phase A items are VOD/progressive. The video-lane source may offer its paired audio through one coupled-holder operation; the channel must never acquire the audio lane independently and create two effective holders. Concert slots are premieres of scheduled VOD items. They may request a scheduled Rail live moment with preannouncement, but their copy and payload must say premiere, not live. A genuine live class is deferred until RB.4 supplies a verified live delivery path.

Implemented 2026-07-17: the shared contract now distinguishes first-party-vod from first-party-live. CoupledMediaLaneArbiter accepts one digest-derived media identity through an offer/withdraw-only channel port, rolls back partial offers, preflights both lanes, and commits or releases video and audio at one validated Rail instant. publishStagePlayback reads and compiles the verified catalog, then offers the exact progressive video/audio URIs without selecting them. stagePremiereElevationRequest produces a preannounced scheduled moment whose customer title, glance copy, and event payload all say V3 Stage premiere. No Stage path declares the unavailable live class.

Presence faces and native playback#

createStageManifest registers the calm v3.stage spectator and player faces. StageTileRenderer accepts only an injected, strict StageProgram: positions and timestamps must be contiguous, the requested instant must resolve to one item, and spectator items cannot carry player preference signals. It emits the current verified artwork/title/artist, the next scheduled item, a state-derived text-only summary, and a contextual V3 Stage deep link. The spectator compiler ignores follows and favorites; the player compiler may use them to shape the program and labels that signal without leaking it to the public face.

The shared V10 PresenceTile renders one restrained artwork plane with an explicit now-playing/up-next hierarchy and no media or autoplay motion. The web video panel mounts a selected first-party-vod progressive URI in a native <video> element, muted and paused. Only the user Play button invokes HTMLMediaElement.play(); pause and mute remain explicit 44-pixel controls. Unsupported non-progressive VOD fails visibly instead of entering a provider or live fallback.

Vitest covers the strict Stage boundary and native user-action invariant. Playwright runs the real renderer projection for both faces and text-only mode, plus actual encoded test-only WebM bytes, in desktop and mobile Chromium. The encoded browser fixture proves native playback behavior only; it is not a V3 catalog row or production render artifact.

Shared live-media production authority#

Implemented 2026-07-21: libs/v10/rail-channel-stage/src/production.ts now supplies the V3 Stage tenant-#3 product composition over the canonical shared media substrate. Pipeline jobs, publisher grants and resource mapping, leased viewer sessions, signed playback grants, and protected playback all fix tenant v3-stage after injected options. Product-owned principals, v3.stage:<stream UUID> external identities, v3-stage.player-client.v1, v3-stage.immersive.v1, and the bounded identity denial are not caller replaceable.

Contract tests exercise the wrappers against the real shared controls with the same stream, job, publication, viewer-session, and entitlement identities used by a sibling Veritas tenant. Scopes, resource mappings, principals, adapter selection, and results remain tenant-isolated. This composes production authority without claiming that a Stage renderer, content catalog, scheduler, publisher host, or player host has been deployed.

Immutable rendered delivery#

Implemented 2026-07-21: V3StageImmutableDeliveryAdapter binds the existing cook to the canonical @oshun/live-media create-only object-store contract. Every object key is tenant-fixed below live-media.v1/v3-stage/catalog/v1/<item>/versions/<version>, and only the closed Stage progressive video, paired-audio, and artwork MIME matrix is accepted. Exact pre-existing bytes replay idempotently; changed bytes at the same immutable key, role/MIME substitution, oversized objects, credentialed or non-HTTPS origins, redirects, and object-path escape all fail closed.

Verification is delivery evidence rather than a storage assertion. The adapter rechecks the stored object, retrieves the exact public HTTPS URI without credentials or redirects, requires HTTP 200 plus matching content type, length, and SHA-256, and passes the bounded returned bytes to FfprobeStageStoredMediaProbe. That probe uses a private transient file and requires a decodable video/audio stream with positive duration or artwork with positive dimensions before the cook may publish. The Streaming release-gate test generates real MP4, M4A, and PNG bytes with FFmpeg and carries all three through the create-only store, public-delivery boundary, real ffprobe, and full Stage cook into an in-memory catalog writer. These generated gate bytes are test evidence, not V3 content inventory.

Recorded V3 release authority#

Implemented 2026-07-21: the dedicated @oshun/v10-rail-channel-stage/release entry point exposes V3StageRecordedReleaseGateAdapter without pulling V3 authoring/export dependencies through the browser-facing channel root. It binds the cook's release port to the authoritative @oshun/tenant-saraswati-stage recorded authoring state and @oshun/v3-concert-quality export-readiness contract. It requires exact item, version, and concert identity; every recorded authoring gate; the published Sequencer receipt; full provenance attachment; GA cadence; and a fresh v3_concert_export report whose non-human results each retain their exact-subject canonical proof and proof verdict. Duplicate, expired, wrong-subject, wrong-type, or detached proofs cannot be projected as ready.

When the export suite declares a human-signoff gate, readiness additionally requires its exact fresh promotion record and canonical human_approval proof, bound to the same artifact, content hash, signer, decision, and evidence. A declared-drill authoring result always projects as blocked even if its planning fixture passed. This closes the release-evidence adapter only: it does not invent a durable candidate repository, Calliope selection, rendered bytes, or a catalog row.

Durable V3/Calliope candidate source#

Implemented 2026-07-21: the server-only release entry now also exposes SqlV3StageCookCandidateRepository. Migration 20260721190000_v10_stage_cook_candidates adds immutable, versioned candidate projection rows to the canonical OSHUN PostgreSQL schema. A partial unique index admits only one ready revision for a candidate; exact retries are idempotent, newer versions transactionally supersede the current row, and withdrawal is terminal for that version. Bounded cook reads recompute the projection SHA-256 and rebind every indexed identity before returning a candidate.

The projection embeds values validated by the owning V3 persona, concert, setlist, and track schemas and by Calliope's setlist, virtual-camera, and streaming-layer schemas. It additionally requires one recording-authorized V3 concert, exact V3 track coverage and duration, a bijective Calliope-slot/V3-track join with matching titles, and exact Calliope artist, concept, setlist, camera, and venue identities. A selected programming anchor must exist in the setlist, camera coverage, and VOD package plans. Energy, section, and perspective derive from those selected plans; numeric cut density remains a separately cited editorial measurement because Calliope carries only a prose cadence rule. Neither the migration nor its real-PostgreSQL restart test seeds a production candidate or treats a VOD package as playable media.

Durable rendered catalog#

Implemented 2026-07-21: the server-only release entry exposes SqlV3StageRenderedCatalogRepository as both the cook's catalog writer and the programming reader. Migration 20260721230000_v10_stage_rendered_catalog adds immutable, versioned catalog items to canonical OSHUN PostgreSQL with a canonical item SHA-256, indexed artist/concert identity, explicit lifecycle evidence, an identity/JSON update fence, and a partial unique index admitting only one active revision per item.

Publication is transactional and requires increasing versions and publication times. Exact active retries are idempotent, a newer version supersedes the former active row, and explicit withdrawal is terminal for that version. Bounded reads select only due active rows, rebind every indexed identity, recompute the complete item hash, and reject conflicting active ids. Unit and schema coverage plus a disposable full-migration PostgreSQL gate prove restart, direct tamper rejection, concurrent exact retry, supersession, withdrawal, and resurrection denial. No migration or test seeds a production catalog row.

Explicit gaps#

  • No playable rendered Stage performance or music-video artifact was found in the repository.
  • No V3 or Calliope output currently includes a verified progressive/HLS/DASH delivery URI for a concert VOD.
  • No production composition-root binding currently supplies the implemented cook with an Unreal renderer and real candidate/catalog inventory. The durable candidate/Calliope source, recorded-release, immutable-store, exact public-delivery verifier, and durable catalog writer/reader now exist, but no production candidate or catalog row has been authored.
  • No deployed long-running V3 Stage scheduler, publisher host, or playback-route host binds the new tenant-fixed shared-media controls.
  • The Calliope fixture builders and V3 GA inventories are test/design inputs, not catalog content.
  • Licensed third-party music-video rights are a human/business gate (HG-2).

The cook, catalog contract, deterministic compiler, coupled lane adapter, presence faces, and native progressive renderer now exist, but these production-content gaps still prevent v3.stage from claiming an available program. They do not justify a sample playlist, invented media URL, or a fake-live concert.