media: worker serves frames over a unix socket (detach transport) master
Wire the buffered frameServer into the worker as an alternate transport. When the handshake carries a SocketPath, ServeMKVIngestWorkerSocket listens on a per-session unix socket, serves the signed-segment stream over it (buffering across any main disconnect via frameServer), runs the full ingest, frames a trailing End/Error, then lingers until main has drained the buffer — bounded by workerDrainGrace — before closing the connection (clean EOF) and removing the socket. The ingest-worker subcommand selects this path on SocketPath; otherwise it keeps the Stage-1 fd-4 pipe. This is the worker half of the zero-downtime story: the socket + buffer let main disconnect for a restart and reconnect without the worker losing the segments it signs in the meantime. TestWorkerServesFramesOverSocket runs the real mux+sign+transcode pipeline and asserts a client reads valid signed dual-codec segments through to a clean End over the socket. (Buffer-across-restart correctness is covered deterministically by the frameServer reconnect tests.) Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>