This repository has no description

media: complete dual-codec inside the ingest worker master

Fuse the transcode into the worker so it emits finished dual-codec (Opus+AAC) signed segments, instead of single-codec source that main then has to complete. The worker feeds each signed source segment into a per-stream transcoder running in its OWN process; the completion callback frames the finished segment. main's ValidateMP4 then sees already-dual-codec input and distributes it directly — the whole mux + sign + transcode chain now lives in the isolated worker, and the node only does memory-safe validate + distribute. Mechanics: the worker gets the node transcode key + broadcaster host in the fd-3 handshake (main from mm.transcodeSigner(); absent → worker emits single-codec, logged). The transcoder runs on a context.WithoutCancel so draining the signer doesn't kill it; its ~1-GoP tail is flushed by Close before the worker signals End. Because one worker == one session, the per-DID transcoder-reuse hazard (the reconnect/timeline bug) structurally cannot occur here — a reconnect is a brand-new process. TestRunMKVIngestWorkerProducesValidSignedFrames now supplies a node key and asserts every emitted segment verifies and carries BOTH the source Opus and a worker-transcoded AAC track. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>