Files
zyt/deployment/followup-audio-runtime/README.md
T

4.1 KiB

Follow-up preview runtime (2026-10-09)

This is an opt-in, diagnosis-ID-scoped preview. It never permits clinical adoption; full audio/semantic verification remains false. Do not use a preview fingerprint as full verification. Preview-origin tasks remain non-adoptable after configuration changes.

Dedicated media tools

The CentOS 7 Webhost needs a private FFmpeg/FFprobe path, not a system upgrade. Installed location is /opt/followup-audio-tools/ffmpeg-9.0.2/ (no PATH or OS package changes). Source was downloaded from https://ffmpeg.org/releases/ffmpeg-9.0.2.tar.xz, SHA256 8c3850283eb25fa026482078a04051e0be17347b09ef81a0849bec15a96e002e, with detached PGP signature verified against the official release key FCF986EA15E6E293A5644F10B4322F04D67658D8.

It was built on the AI host using GCC 12, nice -n 19 make -j1, static libc, generic x86-64 / Linux 3.2 baseline, without network protocols or optional external codec libraries. Build flags:

./configure --prefix=/opt/followup-audio-tools/ffmpeg-9.0.2 \
 --disable-autodetect --disable-shared --enable-static --extra-cflags=-O2 --extra-ldflags=-static \
 --disable-x86asm --disable-doc --disable-debug --disable-network --disable-everything \
 --enable-ffmpeg --enable-ffprobe --enable-avcodec --enable-avformat --enable-avfilter --enable-swresample \
 --enable-protocol=file,pipe --enable-demuxer=mov,mp3,wav,amr,aac \
 --enable-parser=aac,aac_latm,mpegaudio \
 --enable-decoder=mp3,mp3float,mp3adu,mp3adufloat,mp3on4,mp3on4float,aac,aac_latm,amrnb,amrwb,pcm_s16le,pcm_s16be,pcm_u8,pcm_s24le,pcm_s32le,pcm_f32le,pcm_f64le \
 --enable-encoder=pcm_s16le --enable-muxer=wav \
 --enable-filter=aresample,pan,anull,aformat,atrim,asetpts,abuffer,abuffersink
nice -n 19 make -j1 ffmpeg ffprobe

Binary SHA256: ffmpeg a2c81c9049a5e919d8f5ce9c246580f9f6cf8a38aaece8c79ed0fd893c35453e; ffprobe af8f5eb67ea87beca9ec7fb27f3355cf918fabee0d88a7db628bf511c691a680. Both executed successfully on the Webhost; synthetic stereo WAV was decoded and split. This minimal build is for the PCM two-stage driver, not an assertion that legacy MP3 re-encoding, all media encodings, or real hour-long ASR has passed.

Dify and TLS

Use the isolated App provisioned by ../followup-audio-dify/, HTTPS only. On this host PHP cURL/NSS rejects the current certificate; native PHP OpenSSL verifies it successfully. Set the feature's explicit HTTP_TRANSPORT=openssl_stream, not TLS verification off and not automatic fallback. The controlled child process maintains parent authorization/lease heartbeats. Other application HTTP clients are unchanged.

The Dify App owns model/generation parameters. Configure both explicit stage protocols, expected models and binding revisions; changing App/default/provider configuration requires a new revision and preview verification. Keep extraction thinking unset locally and EXTRACTION_RESPONSE_FORMAT=prompt_json; no claim that local OpenAI response_format/max_tokens are transmitted through Dify.

Release constraints

  • ENABLED=true only with PREVIEW_ONLY=true, explicit TEST_DIAGNOSIS_IDS, fresh preview fingerprint, stable private encryption key; AUDIO_VERIFIED=false.
  • Use an independent followup-audio-preview consumer, concurrency 1. Do not restart prescription workers, PHP, Dify or GPU services.
  • Back up source/env/static assets and affected schema/data. Additive DDL must use a bounded session lock budget; prefer explicit INSTANT columns and fail instead of silently table-copying.
  • Keep existing untracked production overlays. Coordinate the two existing auto-pull lock files; never reset/clean the live repository.
  • Build with vite build only. Copy new hashed assets additively, retain old assets for active browsers, then atomically replace index.html; do not invoke the destructive release.mjs on the live directory.
  • Rollback stops only the new consumer and disables preview, restores changed source/index/env with hashes, and retains additive tables/columns/audit. Never roll back the entire business database or rewrite remote master to undo a release.
  • Keep API credentials, raw recordings, clinical snapshots and runtime state outside Git. Application cleanup does not imply Dify copies were deleted.