Robotweax SRT 0.2.7 — Recovery and Runtime Hardening
Published on 2026-10-02 as v0.2.7.
Tag commit: 1f9cc7c045f84ba188a08677bfc57ce7424e5aff.
Project version: 0.2.7. Shared-library C ABI line: 0.2.
Compatible SRT API and srt_getversion(): 1.5.7. This is an implementation
maintenance release, not a new SRT wire-protocol version. OpenSSL/AES-CTR remains
the default; the explicit AES-GCM extension remains default-off. BCrypt remains
an experimental Windows backend.
Recovery and timing
- Correct ACK cadence and RTT sampling, File retransmission capability gating,
timestamp-origin handling and receive deadlines across idle periods and wrap. - Correct loss-list invariants, periodic NAK TTL handling and loss-range
reactivation after control coalescing and transient UDP backpressure. - Validate FEC geometry and bounded receive windows, preserve recovery across
sequence gaps and out-of-order loss, and avoid reporting settled FEC losses. - Validate directional TLPKTDROP behavior and encrypted drop-control sequence
plausibility. Preserve already buffered stream data when peer drops arrive. - Retain conservative loss-report and reordering policies where measurements
do not establish a general improvement.
Encryption and admission
- Harden optional-encryption state and negotiated cipher reporting, key-length
admission, rotation sequence budgets and transition/blackout recovery. - Preserve receive-key identity across refresh and bounded retired history,
including the later correction that protects a newer generation after it
has processed DATA. - Bound KM work and retry/preannounce timing. Long peer RTT requires a suitable
peer-idle configuration; retry mitigation does not authenticate ACK values. - Use random socket identities and strengthen handshake window and rejection
validation. These changes do not authenticate all runtime control packets.
Groups and runtime
- Correct Broadcast/Backup member option templates, late joins, send
backpressure, directional admission, state snapshots and logical readiness. - Preserve complete locally received unread messages when an old member is
explicitly closed. Receive-only retention is bounded to 8,192 packets,
11,927,552 payload bytes, 16 batches and 120 seconds of unread age.
Capacity, allocation and expiry failures become explicit connection errors;
missing or incomplete messages are not recovered by this retention queue. - Reject FILE and disabled TSBPD group configurations transactionally.
Member-specificGROUPMINSTABLETIMEOremains unsupported; the supported
group-wide value and other option limits are documented. - Correct edge-trigger send rearming, readable-deadline events, readiness-arm
recovery, close/backpressure lock ordering and shard drain completion. - Harden callback cleanup/reentry and inherited process teardown. Improve
readiness invalidation, bound closed-handle history and simplify group
member lookup/status storage without promising universal CPU or throughput
gains.
See encryption, connection groups,
epoll readiness, UDP backpressure,
File mode, pacer qualification,
host qualification and
group throughput for detailed contracts and evidence.
Compatibility and upgrading
The installed public C export inventory is unchanged from 0.2.6; the intended
C ABI line remains 0.2. Installed-consumer and export/ABI checks passed in the qualified
static/shared and platform configurations.
Existing support boundaries remain in the compatibility matrix.
Rebuild direct source-tree C++ consumers against matching headers and library.
Implementation layouts and signatures changed substantially after 0.2.6;
unchanged C exports do not establish C++ binary compatibility. Source-tree
implementation headers are outside the installed public API contract.
Qualification and remaining limits
The final main CI
and final tag CI
passed. The explicit complete ecosystem suite
executed the configured FFmpeg, GStreamer, VLC and OBS profiles successfully.
Optional live-timing and dedicated native ARM64/performance profiles remain
unmeasured; skipped profiles are not new qualification evidence.
The latest group retention correction passed 893 native tests, 72 final
sanitizer group tests and 24 bidirectional UDP prefix cases covering Clear,
CTR, GCM, Broadcast, Backup and explicit close/keep. These are functional
checks, not maximum-capacity or real-WAN guarantees.
- Issue #112 remains open.
Runtime control authentication and complete long-horizon KMREQ replay
protection are not implemented. Bounded defenses do not cover histories
after eviction. DATA AES-GCM does not authenticate control packets; CTR does
not provide payload authenticity. Independent cryptographic review remains
outstanding. No ACP1 wire/API profile ships in this release. - Native Linux/Windows performance and real-network-path campaigns remain
outstanding because dedicated target hosts are unavailable. Prepared lab
packages and macOS runs do not replace these measurements. - The earlier Windows lifecycle timeout root cause remains unresolved.
Current successful CI does not explain that earlier timeout; its original
five-second diagnostic deadline remains unchanged. - Additional sustained-load, failover and isolated CPU-cost measurements remain
outstanding. No general retry-policy superiority or capacity claim is made. - Package-manager coexistence/removal checks are not an upgrade/rollback
guarantee. No new PPA, COPR, vcpkg registry or application binary distribution
is promised.
Downloads and package qualification
Both Windows SDK installers are Authenticode-signed by Robotweax GmbH with
trusted timestamps. The final SDK workflow
built all twelve OpenSSL/BCrypt Win32/x64/ARM64 Debug/Release variants,
validated installation/coexistence/removal and retested the exact signed pair.
The downloaded release files match the qualified signed CI artifact byte for
byte; SHA256SUMS covers the final signed executables.
Post-signing SHA-256:
robotweax-srt-0.2.7-windows-sdk-openssl.exe:6c9d64f8df22b4bb170a1fab43bfa0d0286b145839e6f49d55a27dacc7dd20f2robotweax-srt-0.2.7-windows-sdk-bcrypt.exe:b636a03c69fd6ec66e9f870a78ff80b71ce7c98ea103362353e21a0519c61494
The immutable package product source is
f254dd2c0fe084f7965238756b1d3b96665d592b. Its 547 regular files and executable
bits were compared with the downloaded GitHub archive. Archive SHA-256:
7ba68805f66bca1da4e0d509d33aedab239a4de57ba9affb4db1481d4205c908.
The final tag package-manager run
qualified Homebrew and six vcpkg static/dynamic profiles;
Linux packages
qualified Ubuntu 24.04 and Fedora 44 package builds and consumers.
The experimental BCrypt candidate qualification
also passed.
The public Homebrew tap now supplies
0.2.7 with a qualified Apple Silicon macOS 15 (arm64_sequoia)
bottle.
The publication workflow
passed; the downloaded bottle matches the qualified native CI artifact byte
for byte, and the published formula records the same hash.
brew install robotweax/tap/robotweax-srtOther bottle platforms require their own native qualification.
The original tap run ignored a failed consumer test and produced no bottle;
that result is not accepted. The corrected native bottle run
passed with strict test and artifact checks. Original failure evidence remains
retained. Bottle SHA-256:
8f54dc38670715a6addc2292de1fda26cacdd7e1d618a2d8a571b8011b233202.