- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
Routed sed -f script files and the in-script r/w/s///w file paths through brush-core's shell path normalizer, so /c and /mnt/c aliases open the live Windows drive instead of a phantom current-drive path. Added a Windows -f regression.
Fixes#8355
Translated the /c and /mnt/c tail per char over the valid UTF-8 suffix instead of copying raw bytes as chars, so non-ASCII path components no longer mojibake. Removed the now-unused byte separator helper and added a non-ASCII regression.
Fixes#8355
Normalized utility operands through brush-core's shared shell path resolver so /c and /mnt/c aliases address the live Windows drive. Added Windows-only regression coverage at the Host boundary.
Fixes#8355
The leak regression waited only 100ms while the leaked job could not write its marker until a 1s sleep elapsed, so the pre-fix path passed vacuously. Wait past the delay; verified the test fails when the drop-time abort is neutralized.
Fixes#8341
Abort shell-internal background tasks when their owning session is dropped, and propagate task abortion into blocking utility cancellation so infinite writers stop.
Fixes#8341
- Synced pi-builtins bazel crate_features with cargo's resolved default
set: bazel features are literal, so the meta-features never expanded
and the procs/rg cluster (nohup, pgrep, pidwait, pkill, proc-match,
ps, rg, sleep, timeout, top) was silently compiled out, leaving the
process builtins unregistered under bazel and failing pi-shell tests.
- Repaired windows compilation of pi-builtins: cfg-gated the
uucore::mode import in mkdir, imported std::env in sort's non-unix
locale probe, mapped ProcInfo::pid through a closure in kill, brought
MetadataExt into scope in wc, and replaced stat's unstable
windows_by_handle metadata with a stable GetFileInformationByHandle
query (volume serial, link count, file index, no-dereference aware).
- Imported HashSet for pi-shell's windows-only PATH merge.
- Added a clippy-ported bazel config + CI bucket so pi-builtins keeps
its manifest-declared clippy allows under the bazel aspect while rustc
warnings stay denied, and zeroed the remaining windows-target rustc
warnings (unused params/imports in find, mv, rm, proc_match, ps).
- Added util.procs to the bazel crate_features: cargo resolves the
builtin.kill -> util.procs implication automatically, but bazel
crate_features are literal, so kill.rs failed with E0432 on
proc_snapshot once HostProcesses became unconditional.
- Imported std::os::fd::AsFd in the linux/android splice path of the wc
builtin (E0405); the import is target-gated like its callers.
- Verified with cargo check -p pi-builtins --no-default-features using
the exact bazel feature list on both the host and (via zig cc)
x86_64-unknown-linux-gnu targets.
- Add minimum character threshold to bypass minimization for short outputs.
- Add preserve-if-empty configuration and pipeline support for filters.
- Update test fixtures and integration tests to meet length thresholds.
- Added `HostProcesses` snapshot and `ChainNode` validation to track ancestry and prevent pid recycling.
- Updated process matching and signal handling to refuse signalling the shell or its ancestor processes.
- Added regression tests verifying that kill builtins safely block ancestor targeting while permitting unrelated processes.
- Added the `smallvec` dependency to support efficient process snapshot tracking.
clippy-strict (nursery redundant_pub_crate, -D warnings) rejects pub(crate)
items inside the crate-private device module; plain pub is equivalent there.
Applied across all platform backends since CI only lints the linux cfg.
- Replaced the miniaudio dependency with custom OS audio device abstractions and backends.
- Implemented platform-specific audio playback and capture for macOS (Audio Queue), Windows (WASAPI), and Linux (PulseAudio/ALSA).
- Added a fallback stub backend returning errors for unsupported platforms.
- Updated audio stream handling with reliable fill guard wakeups and streamlined rate validation.
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
non-default log feature off: zune-core's no-log warn! stub is not
expression-safe. A feature-activation-only workspace dep on
zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
streamIdleTimeoutMs the Bedrock watchdog compat now emits.
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.
Fixes#7926
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.
Fixes#7884
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.
Fixes#7884
Bounded the RemoteDesktop close in Libei::drop with CLOSE_TIMEOUT so an unresponsive xdg-desktop-portal cannot hang worker teardown past the surrounding close budget.
Closed the portal session when ei::Context::new fails after Start/ConnectToEIS, the one init path that previously dropped the session without revoking the grant.
Fixes#7884
Merged PR #7889 into the lazy Wayland input branch. Portal sessions retain the shared process runtime, the portal module remains available in shipped builds, and only PipeWire token helpers are feature-gated.
Kept the portal module available in shipped builds while feature-gating only PipeWire token storage. Libei portal sessions now retain the shared process runtime and still close explicitly on teardown.
capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.
Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.
Fixes#7885
Deferred libei and RemoteDesktop setup until the first native input operation. Read-only capability, window, display, and AX calls no longer request keyboard or pointer access.
Used non-persistent portal grants and retained the portal session so backend teardown closes it explicitly.
Fixes#7884
ashpd caches a process-global D-Bus connection whose I/O tasks bind to whichever runtime first creates it. Libei::portal_context() built a short-lived current_thread runtime and dropped it when Libei::new() returned, orphaning that connection; capture() then built its own runtime and reused the dead connection, so PipeWire capture never delivered a frame whenever libei input init ran first.
Route both portal_context() and capture() through a shared long-lived multi-thread runtime held in a LazyLock, keeping the cached connection's I/O alive for the process lifetime.
Fixes#7886
Configured Quartz event sources to permit local hardware events in both suppression states and replaced Enigo-backed global posting with the configured source.
Added a macOS regression test for the event-source suppression settings.
Fixes#7872
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.
All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.
Fixes#7701
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.
Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.
Fixes#7702
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.
Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.
Fixes#7700