This repository has no description

Sign segments via muxl-sign wasm instead of uniffi c2pa-rs master

Replace MediaSignerLocal.SignMP4's uniffi-based c2pa flow with a per-GoP invocation of muxl-sign's sign-per-track subcommand running under wazero. Each segment gets a fresh manifest (with its own start time) written to a tempdir alongside the cert+key; the wasm reads those via an FS mount and writes the signed wrapper+ingredient flat MP4 back, which Go reads off disk and returns. SignConcatMP4 (clip combine) and ValidateMP4Media stay on the existing iroh-streamplace uniffi path for now — they need a c2pa Reader Streamplace doesn't have a non-uniffi binding for, and the broadcaster's clip-combine signer can be a PKCS11 hardware key with no exportable PEM. Other notes: - Compiled wazero modules are now cached per-wasm; instantiation per signer call is cheap, compilation is not. - Signer wasm gets the host's real wall clock, nanotime, and rand source — c2pa-rs rejects signatures whose cert isn't valid at signing time and uses real randomness for COSE nonces. Segmenter wasm intentionally keeps wazero's deterministic clock so test byte counts stay stable. - New MarshalES256KPrivateKeyPEM helper emits PKCS#8 PEM that round-trips with openssl and k256::SecretKey::from_pkcs8_pem. - SmearAudio is gone — handled upstream now. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>