capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.
Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.
Fixes#7885
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.
All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.
Fixes#7701
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.
Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.
Fixes#7702
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.
Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.
Fixes#7700
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
Comparing against the heap root inside an `if let` binding keeps the shared
borrow of `heap` alive across the `pop`/`push` in the same block. Fold the
comparison into the condition instead, so the borrow ends with the
condition expression and eviction takes a clean mutable borrow.
No behavior change.
fuzzyFind returns at most maxResults matches (100 by default), but it
allocated a scored match for every fuzzy hit and full-sorted the complete
hit set before truncating.
Score every eligible entry exactly once into a bounded worst-first
BinaryHeap of at most maxResults candidates, while still counting every
nonzero-score hit for the exact totalMatches contract. RankedMatch orders
candidates as the exact inverse of the final comparator (score descending,
then path_depth ascending, then path ascending), so the heap root is the
first candidate to evict and into_sorted_vec yields the final order
directly. path_depth is now computed once per retained candidate instead of
repeatedly inside the sort comparator.
The scoring stage also consumes the walker outcome as an iterator, so the
all-entry intermediate Vec is gone and the match path is moved instead of
cloned.
Walker request construction, cache policy, scoring rules, query
normalization, symlink handling, the maxResults == 0 and empty-query early
returns, the cancellation heartbeat and error mapping are unchanged.
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
- Kept PCRE2 matching interpreted on macOS across native grep, embedded grep, and embedded rg while preserving JIT elsewhere.
- Added regressions for both reported PCRE2-only crash patterns.
Fixes#7399
Protect only the harness pid during cancellation sweeps. The host recorded parent pid can be stale on Windows and recycled onto the hung command; adding that raw pid to the protected set spared the cancellation target and pruned its whole subtree from cleanup.
Keep protected-subtree pruning rooted at the harness itself, which still spares its real workers while allowing the timed-out target to be reaped.
Fixes#7452
The flattened descendant list can contain a protected node (the
harness, on a Windows PID-reuse false-descendant) together with that
node's real children, collected by recursing through it. Skipping only
the exact protected pid kept omp alive but still TerminateProcess'd its
unrelated worker/tool subprocesses.
signal_tree/terminate_tree now drop every node whose recorded parent
chain within the enumerated set passes through a protected pid, so a
false descendant of the harness can no longer drag the harness's real
children into the kill set.
Fixes#7452
On Windows the descendant tree used to reap a cancelled bash run is
built from raw th32ParentProcessID links that outlive their recorded
parent. A recycled pid matching the harness's stale parent pid could
surface omp itself (or an ancestor) as a false descendant, and
signal_tree TerminateProcess'd it — killing the session with no
cleanup and no session_exit record when a blocking command hit its
timeout.
Add host_protected_pids() (harness pid plus its resolvable ancestor
chain) and skip those pids in signal_tree and terminate_tree. The
guard is cross-platform: a no-op on Unix, where the descendant walk is
already identity-pinned, and the safety net that keeps a tool timeout
from ever taking down the harness on Windows.
Fixes#7452
- libc::ioctl takes c_ulong on glibc but c_int on musl; the hardcoded
c_ulong request type broke //:natives-linux-musl-{x64,arm64}. Verified
by cross-checking aarch64-unknown-linux-musl on the CI-pinned nightly.
- libspa-sys hard-links system libpipewire-0.3 via pkg-config, which no CI
or cross triple (musl, arm64) can satisfy; bazel addons already build with
crate_features = [], so shipping builds lose nothing. Linux devs opt in
with --features wayland-pipewire.
- Gated normalize_role_macos and the wayland capture helpers to the configs
that use them; handled the cfg(test) AxHandle variant in AtSpiAx::object.
- Fixed clippy-strict violations (redundant_pub_crate, missing_const_for_fn,
unnecessary_wraps, collapsible_if, map_unwrap_or, needless_return,
needless_pass_by_ref_mut) across the new linux desktop backend.
- Added the `ps` shell builtin with BSD and procps selection forms, custom formatting, and sorting capabilities.
- Implemented the `sanitize_process_command` helper to clean process command names and arguments.
- Updated the bash prompt template and package changelogs to document the new builtin.
- Refused background keyboard delivery for multi-window macOS applications to prevent ambiguous keystroke routing.
- Set `AXMain` and `AXFocused` attributes during foreground macOS input delivery to ensure proper window activation.
- Activated Chromium renderer accessibility trees lazily during window snapshots to avoid capturing only browser chrome.
- Used `AXDescription` as a fallback title for unnamed macOS accessibility controls in snapshots and queries.
- Replaced monolithic desktop native bindings and action batching with a modular cross-platform backend structure supporting Wayland, X11, macOS, and Win32.
- Updated the computer tool schema and supervisor to execute persistent JavaScript script runs with timeout clamping and asynchronous tool calling.
- Integrated accessibility (AX) tree snapshotting, node querying, and bounds-based hit testing across platform desktop layers.
- Added native clipboard bindings and updated coding-agent prompts, renderers, and tests to validate script-based computer workflows.
- Added window discovery, targeting, and frame validation for macOS, Windows, and Linux platforms.
- Updated computer tool and protocol definitions to support listing and targeting specific application windows.
- Refactored native computer tool exposure to function-only representation across models.
- Updated documentation and test suites to reflect window-scoped computer control capabilities.
- Raised probe-spawning logger tests to 30s timeouts; bun's 5s default
SIGTERMed probe children (exit 143) on shared-core CI runners, matching
the precedent documented in logger-contract.test.ts.
- Allowed clippy::unused_async_trait_impl on KillCommand::execute with an
unknown_lints guard for the pinned CI nightly that predates the lint.
pi-shell calls sys::signal::kill_process on the windows target; the
pub(crate) glob re-export made it invisible outside brush-core, unlike
the unix module where kill_process is pub. Mirrors unix visibility.
- Made infallible ProcInfo accessors const and annotated Option-returning
accessors with allow(unnecessary_wraps) since Option is the shared
cross-platform contract.
- Boxed ParseProcResult::Options to shrink the enum.
- Restructured kill signal resolution to bind signal once instead of
let-then-reassign sequences.
- Simplified liveness re-check with Option::is_none_or.
- Implemented new shell builtins including `top`, `pgrep`, `pkill`, `pidwait`, and `kill`.
- Added a cross-platform process snapshot module supporting Linux, macOS, and Windows.
- Extended job and process handling utilities with process iteration and handle termination methods.
- Replaced test mutex locks with thread-local counters to prevent test races in the minimizer engine.
- Update hashline block resolution formatting to correctly incorporate anchor lines within operation labels.
- Fix and update test assertions and mock contexts across coding agent tests.