This repository has no description

media: worker-side self-watchdog for the detached/WHIP ingest paths master

Wedge containment had a hole: the supervisor watchdog (MKVIngestIsolated) only covers the fd-4 fallback. On the default detached path and WHIP, the worker is detached (not tied to main's context), so main can't kill a stuck one — and a wedged native pipeline (e.g. the 4-audio MKV that leaves matroskademux pads unlinked, never emits EOS, produces no frames) would run forever as an orphan. That's the exact failure isolation is supposed to contain. Add a worker-side watchdog: a FrameWriter wrapper kicks a timer on every frame the worker emits; going ingestWorkerWatchdog with no output means the pipeline is wedged, so it cancels the worker's context. muxlSignSegmentElem's ctx-done hook closes the signer pipe, so the worker actually returns and the process exits — the fault stays contained to the subprocess. Wired into both RunMKVIngestWorker and ServeWHIPIngestWorkerSocket (which kicks once after the SDP answer, so the first-segment clock starts post-negotiation; a pre-answer hang is already bounded by main's whipAnswerTimeout). The kick is mutex-guarded since a worker emits frames from more than one goroutine. This is additive on the fd-4 path (the supervisor watchdog still fires first there); it's the ONLY wedge containment on the detached/WHIP paths. Test: TestRunMKVIngestWorkerSelfWatchdog feeds the wedging MKV straight to RunMKVIngestWorker (no supervisor) and asserts it self-terminates rather than hanging. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>