Commit Graph

991 Commits

Author SHA1 Message Date
can1357 4dc97f89ab fix(natives): backticked RemoteDesktop in portal doc comments
clippy-strict doc_markdown (-D warnings) rejects the bare identifier;
these two docs were the remaining rust_validate errors on main.
2026-08-07 23:51:43 +02:00
can1357 81e0c3f6bf fix(voice): dropped redundant pub(crate) in private device module
clippy-strict (nursery redundant_pub_crate, -D warnings) rejects pub(crate)
items inside the crate-private device module; plain pub is equivalent there.
Applied across all platform backends since CI only lints the linux cfg.
2026-08-07 23:46:48 +02:00
can1357 055a5d4f26 chore: bump version to 17.2.11 2026-08-07 23:38:40 +02:00
can1357 7cae7ef3f5 feat(voice): replaced miniaudio with native platform audio backends
- Replaced the miniaudio dependency with custom OS audio device abstractions and backends.
- Implemented platform-specific audio playback and capture for macOS (Audio Queue), Windows (WASAPI), and Linux (PulseAudio/ALSA).
- Added a fallback stub backend returning errors for unsupported platforms.
- Updated audio stream handling with reliable fill guard wakeups and streamlined rate validation.
2026-08-07 23:38:27 +02:00
can1357 bc5eee4e24 fix(build): activated zune-jpeg log feature and widened test compat type
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
  non-default log feature off: zune-core's no-log warn! stub is not
  expression-safe. A feature-activation-only workspace dep on
  zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
  streamIdleTimeoutMs the Bedrock watchdog compat now emits.
2026-08-07 23:38:27 +02:00
roboomp 216fc3ca2d fix(computer): waited for all granted libei devices
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.

Fixes #7926
2026-08-07 23:38:25 +02:00
can1357 084fbb683f Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp)
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
2026-08-07 14:52:56 +02:00
roboomp 2567db01df fix(computer): removed orphaned wayland remote-desktop token
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.

Fixes #7884
2026-08-07 12:43:37 +00:00
roboomp 539906e25c fix(computer): bounded consent-denied portal close inline
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.

Fixes #7884
2026-08-07 12:39:05 +00:00
can1357 215040966e fix(natives): satisfied clippy on merged macos input rewrite 2026-08-07 13:47:03 +02:00
can1357 531ae04b3b Merge PR #7887: fix(natives): port wayland capture to pipewire 0.9 Rc handle API (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 3cda312165 Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 a37b70dc2e fix(natives): make macOS input backend sendable 2026-08-07 13:37:56 +02:00
roboomp cf5bd72877 fix(computer): bounded portal close and closed leaked session
Bounded the RemoteDesktop close in Libei::drop with CLOSE_TIMEOUT so an unresponsive xdg-desktop-portal cannot hang worker teardown past the surrounding close budget.

Closed the portal session when ei::Context::new fails after Start/ConnectToEIS, the one init path that previously dropped the session without revoking the grant.

Fixes #7884
2026-08-07 11:12:04 +00:00
roboomp 71cf826aeb merge(natives): integrated shared wayland portal runtime
Merged PR #7889 into the lazy Wayland input branch. Portal sessions retain the shared process runtime, the portal module remains available in shipped builds, and only PipeWire token helpers are feature-gated.
2026-08-07 08:24:58 +00:00
roboomp 12d1ade665 fix(computer): shared the wayland portal runtime
Kept the portal module available in shipped builds while feature-gating only PipeWire token storage. Libei portal sessions now retain the shared process runtime and still close explicitly on teardown.
2026-08-07 08:22:03 +00:00
roboomp 30264cb151 fix(natives): port wayland capture to pipewire 0.9 Rc handle API
capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.

Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.

Fixes #7885
2026-08-07 08:19:56 +00:00
roboomp 8d6ed17811 fix(computer): lazily requested wayland input permission
Deferred libei and RemoteDesktop setup until the first native input operation. Read-only capability, window, display, and AX calls no longer request keyboard or pointer access.

Used non-persistent portal grants and retained the portal session so backend teardown closes it explicitly.

Fixes #7884
2026-08-07 06:50:16 +00:00
roboomp 81d3456af0 fix(natives): share one runtime across wayland portal paths
ashpd caches a process-global D-Bus connection whose I/O tasks bind to whichever runtime first creates it. Libei::portal_context() built a short-lived current_thread runtime and dropped it when Libei::new() returned, orphaning that connection; capture() then built its own runtime and reused the dead connection, so PipeWire capture never delivered a frame whenever libei input init ran first.

Route both portal_context() and capture() through a shared long-lived multi-thread runtime held in a LazyLock, keeping the cached connection's I/O alive for the process lifetime.

Fixes #7886
2026-08-07 06:47:03 +00:00
roboomp 62b007295a fix(natives): prevented macos input suppression
Configured Quartz event sources to permit local hardware events in both suppression states and replaced Enigo-backed global posting with the configured source.

Added a macOS regression test for the event-source suppression settings.

Fixes #7872
2026-08-07 03:02:49 +00:00
can1357 43c1b245e7 chore: bump version to 17.2.10 2026-08-06 13:32:34 +02:00
can1357 86375c130a style: reflowed window id doc comment with cargo fmt 2026-08-05 22:19:57 +02:00
can1357 ee026fa2e3 Merge PR #7704: fix(natives): gate wayland capture capability on pipewire feature (@roboomp)
# Conflicts:
#	crates/pi-natives/src/desktop/linux/wayland/mod.rs
2026-08-05 22:16:16 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00
roboomp 2ef15378f6 fix(computer): accept backend-minted window ids in wayland capture
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.

All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.

Fixes #7701
2026-08-05 11:06:54 +00:00
roboomp ea887b00a9 fix(computer): corrected Wayland foreground delivery
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.

Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.

Fixes #7702
2026-08-05 10:57:25 +00:00
roboomp dc4725e626 fix(natives): gate wayland capture capability on pipewire feature
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.

Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.

Fixes #7700
2026-08-05 10:45:57 +00:00
can1357 f7f8e040ee chore: bump version to 17.2.9 2026-08-05 03:07:47 +02:00
can1357 b0a94a8fc0 chore: cleanup 2026-08-05 03:07:16 +02:00
can1357 f3cf3b926d test(fuzzy-find): prove bounded large-corpus ranking 2026-08-05 01:11:58 +02:00
can1357 0897725394 Merge PR #7536: perf(fuzzy-find): retain only the bounded top-K scored matches (@Mustaqeem66) 2026-08-05 01:11:58 +02:00
can1357 003bb5548c chore: bump version to 17.2.8 2026-08-04 05:53:35 +02:00
can1357 a5090f1f81 chore: bump version to 17.2.7 2026-08-04 01:19:36 +02:00
can1357 1cf919099e style(pi-shell): wrapped long command string in test
- Split a long command string across multiple lines in shell test.
2026-08-03 23:41:07 +02:00
can1357 dce12984f2 fix(pi-shell): parsed state format specifier correctly in ps builtin
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
2026-08-03 19:01:09 +02:00
can1357 451eb9842c fix: mapped tail builtin broken pipe to silent exit 141
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
2026-08-03 18:53:14 +02:00
can1357 cdd1d13079 feat(pi-shell): extended ps builtin format specifiers and process metrics
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
2026-08-03 18:51:23 +02:00
Muhammad Mustaqeem 60187c9ba9 refactor(fuzzy-find): release the heap borrow before evicting
Comparing against the heap root inside an `if let` binding keeps the shared
borrow of `heap` alive across the `pop`/`push` in the same block. Fold the
comparison into the condition instead, so the borrow ends with the
condition expression and eviction takes a clean mutable borrow.

No behavior change.
2026-08-03 21:09:01 +05:00
Muhammad Mustaqeem 2cf0a47d6a perf(fuzzy-find): retain only the bounded top-K scored matches
fuzzyFind returns at most maxResults matches (100 by default), but it
allocated a scored match for every fuzzy hit and full-sorted the complete
hit set before truncating.

Score every eligible entry exactly once into a bounded worst-first
BinaryHeap of at most maxResults candidates, while still counting every
nonzero-score hit for the exact totalMatches contract. RankedMatch orders
candidates as the exact inverse of the final comparator (score descending,
then path_depth ascending, then path ascending), so the heap root is the
first candidate to evict and into_sorted_vec yields the final order
directly. path_depth is now computed once per retained candidate instead of
repeatedly inside the sort comparator.

The scoring stage also consumes the walker outcome as an iterator, so the
all-entry intermediate Vec is gone and the match path is moved instead of
cloned.

Walker request construction, cache policy, scoring rules, query
normalization, symlink handling, the maxResults == 0 and empty-query early
returns, the cancellation heartbeat and error mapping are unchanged.
2026-08-03 21:06:17 +05:00
can1357 01c1f91ff5 chore: bump version to 17.2.6 2026-08-03 16:44:19 +02:00
can1357 74c346623b chore: clippy 2026-08-03 16:43:59 +02:00
can1357 455493dfad feat: introduced native file lock bindings for cross-process advisory locking
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
2026-08-03 16:09:09 +02:00
can1357 6ca4d0a753 style: applied rustfmt to pcre2 jit statics 2026-08-03 15:26:46 +02:00
can1357 ce408bf9bb feat(grep): added OMP_PCRE2_JIT override for the macos jit gate
- OMP_PCRE2_JIT=1 forces PCRE2 JIT on (macOS opt-in), 0/false forces it off;
  unset keeps JIT on everywhere except macOS (issue #7399).
2026-08-03 15:14:40 +02:00
can1357 0f83baa3b6 Merge PR #7469: fix(grep): disable pcre2 jit on macos (@roboomp) 2026-08-03 15:12:03 +02:00
can1357 3eb89ef4e3 Merge PR #7453: fix(pi-shell): spare host process from run-cancellation sweeps (@roboomp) 2026-08-03 14:46:24 +02:00
roboomp dc1c98f46d fix(grep): disabled pcre2 jit on macos
- Kept PCRE2 matching interpreted on macOS across native grep, embedded grep, and embedded rg while preserving JIT elsewhere.

- Added regressions for both reported PCRE2-only crash patterns.

Fixes #7399
2026-08-03 07:56:17 +00:00
can1357 c53b85aaf4 chore: bump version to 17.2.5 2026-08-03 05:53:12 +02:00
roboomp dc22ea5dad fix(pi-shell): kept recycled targets killable
Protect only the harness pid during cancellation sweeps. The host recorded parent pid can be stale on Windows and recycled onto the hung command; adding that raw pid to the protected set spared the cancellation target and pruned its whole subtree from cleanup.

Keep protected-subtree pruning rooted at the harness itself, which still spares its real workers while allowing the timed-out target to be reaped.

Fixes #7452
2026-08-03 03:47:32 +00:00
roboomp e5f954b0fe fix(pi-shell): prune protected subtrees from cancellation sweeps
The flattened descendant list can contain a protected node (the
harness, on a Windows PID-reuse false-descendant) together with that
node's real children, collected by recursing through it. Skipping only
the exact protected pid kept omp alive but still TerminateProcess'd its
unrelated worker/tool subprocesses.

signal_tree/terminate_tree now drop every node whose recorded parent
chain within the enumerated set passes through a protected pid, so a
false descendant of the harness can no longer drag the harness's real
children into the kill set.

Fixes #7452
2026-08-03 03:42:50 +00:00