Round 3 audited the round-1/2 fix commits rather than trusting them, and found
three defects in that new code. This is why the pin moves each round.
1. LICENCE REGRESSION, and it was mine. Reverting the "distinguish a failed key
source" commit also restored a verbatim reference-decoder table citation in
src/mux/codec/dts.rs, because both changes were in that one commit. The MIT
licence cleanup was silently undone at HEAD and nothing caught it.
The citation is replaced with ETSI TS 102 114 §5.3.1 again, and — more
importantly — the rule now lives in the leak gate instead of in my memory.
scan-secrets.sh gains LICENCE_RE, which flags ff_dca*, dcadec, l-smash,
libav*, and bare ffmpeg/FFmpeg as REF-IMPL-CITATION. `no ffmpeg` is
explicitly allowed via negative lookbehind: stating what this project does
NOT depend on carries no risk and is a genuine selling point. Verified by
re-introducing the citation (gate fails) and removing it (gate clean).
2. TsMuxer armed params_written even when the avcC/hvcC parser returned None, so
a track whose codec_private exists but will not parse was muxed to BD-TS with
no VPS/SPS/PPS ever emitted — undecodable video, reported as success, with no
log line. Last round's fix corrected WHICH parser is used and left this half
untouched. Arming the flag is still right (retrying identical bytes cannot
succeed) but it is no longer silent: it now warns with the track, codec and
codec_private length.
3. test_aes_cbc_roundtrip defined a LOCAL fn aes_cbc_encrypt that SHADOWED the
production primitive, so it round-tripped a copy of the algorithm against
itself and never touched crypto::aes_cbc_encrypt — the function this cycle
added. Any mutation to the shipped code passed it. The shadow is deleted and
the test now calls the real primitive; verified by mutating
crypto::aes_cbc_encrypt, which now fails it and previously would not have.