This repository has no description

media: refresh isolated workers' manifest so pre-live → live takes effect master

Fixes a regression on --isolated-ingest: a streamer goes live but stays stuck "pre-live" (live HLS never populates, viewers get "segment is not published"). Root cause: "published" is baked into each segment's signed C2PA manifest (a c2pa.published action, added once the streamer has a live livestream record). The in-process signer rebuilds the manifest FRESH per GoP from the model, so a pre-live → live transition shows up mid-stream. The isolated worker has no model, so buildWorkerConfig froze the manifest at spawn (pre-live) and workerSignStream reused it forever — re-introducing exactly the "sealed at connection start" bug the in-process path fixed. Fix: main pushes manifest refreshes to the worker over the existing socket and the worker signs each GoP with the latest. - ingestframe.Manifest: a main→worker control frame (reverse of the segment stream). - Worker holds the manifest in a manifestHolder (init = the spawn manifest); workerSignStream reads it per GoP; serveFrameSocket reads control frames from main and swaps the holder on a Manifest frame. - Main rebuilds the manifest from NewManifestBuilder(model, cli).BuildManifest for the streamer DID — needs only the model + cli, no signing key — and pushes on change (pushManifestUpdates, fixed start so only real changes diff). Wired through ConsumeWorkerSocket for MKVIngestDetached, WHIPIngestDetached, and ResumeDetachedWorkers (DID from the sidecar — so a worker that outlived a main restart gets refreshed too, no signer reconstruction). Also drops the fd-4 non-hijack fallback: it has no back-channel for manifest updates and would stay stuck pre-live, so a non-hijackable push now errors (use WHIP). The only real MKV/RTMP client is a co-located MistServer pushing HTTP/1.1 over localhost, which always hijacks. MKVIngestIsolated stays for its tests but is no longer wired into the API. Tests: pushManifestUpdates emits on change only; serveFrameSocket applies a pushed Manifest; and TestRunMKVIngestWorkerSignsWithSuppliedManifest proves end to end that the worker signs unpublished vs published segments purely from the manifest the getter returns. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>