clippy-strict (nursery redundant_pub_crate, -D warnings) rejects pub(crate)
items inside the crate-private device module; plain pub is equivalent there.
Applied across all platform backends since CI only lints the linux cfg.
- Replaced the miniaudio dependency with custom OS audio device abstractions and backends.
- Implemented platform-specific audio playback and capture for macOS (Audio Queue), Windows (WASAPI), and Linux (PulseAudio/ALSA).
- Added a fallback stub backend returning errors for unsupported platforms.
- Updated audio stream handling with reliable fill guard wakeups and streamlined rate validation.
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
non-default log feature off: zune-core's no-log warn! stub is not
expression-safe. A feature-activation-only workspace dep on
zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
streamIdleTimeoutMs the Bedrock watchdog compat now emits.
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.
Fixes#7926
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.
Fixes#7884
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.
Fixes#7884
Bounded the RemoteDesktop close in Libei::drop with CLOSE_TIMEOUT so an unresponsive xdg-desktop-portal cannot hang worker teardown past the surrounding close budget.
Closed the portal session when ei::Context::new fails after Start/ConnectToEIS, the one init path that previously dropped the session without revoking the grant.
Fixes#7884
Merged PR #7889 into the lazy Wayland input branch. Portal sessions retain the shared process runtime, the portal module remains available in shipped builds, and only PipeWire token helpers are feature-gated.
Kept the portal module available in shipped builds while feature-gating only PipeWire token storage. Libei portal sessions now retain the shared process runtime and still close explicitly on teardown.
capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.
Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.
Fixes#7885
Deferred libei and RemoteDesktop setup until the first native input operation. Read-only capability, window, display, and AX calls no longer request keyboard or pointer access.
Used non-persistent portal grants and retained the portal session so backend teardown closes it explicitly.
Fixes#7884
ashpd caches a process-global D-Bus connection whose I/O tasks bind to whichever runtime first creates it. Libei::portal_context() built a short-lived current_thread runtime and dropped it when Libei::new() returned, orphaning that connection; capture() then built its own runtime and reused the dead connection, so PipeWire capture never delivered a frame whenever libei input init ran first.
Route both portal_context() and capture() through a shared long-lived multi-thread runtime held in a LazyLock, keeping the cached connection's I/O alive for the process lifetime.
Fixes#7886
Configured Quartz event sources to permit local hardware events in both suppression states and replaced Enigo-backed global posting with the configured source.
Added a macOS regression test for the event-source suppression settings.
Fixes#7872
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.
All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.
Fixes#7701
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.
Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.
Fixes#7702
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.
Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.
Fixes#7700
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
Comparing against the heap root inside an `if let` binding keeps the shared
borrow of `heap` alive across the `pop`/`push` in the same block. Fold the
comparison into the condition instead, so the borrow ends with the
condition expression and eviction takes a clean mutable borrow.
No behavior change.
fuzzyFind returns at most maxResults matches (100 by default), but it
allocated a scored match for every fuzzy hit and full-sorted the complete
hit set before truncating.
Score every eligible entry exactly once into a bounded worst-first
BinaryHeap of at most maxResults candidates, while still counting every
nonzero-score hit for the exact totalMatches contract. RankedMatch orders
candidates as the exact inverse of the final comparator (score descending,
then path_depth ascending, then path ascending), so the heap root is the
first candidate to evict and into_sorted_vec yields the final order
directly. path_depth is now computed once per retained candidate instead of
repeatedly inside the sort comparator.
The scoring stage also consumes the walker outcome as an iterator, so the
all-entry intermediate Vec is gone and the match path is moved instead of
cloned.
Walker request construction, cache policy, scoring rules, query
normalization, symlink handling, the maxResults == 0 and empty-query early
returns, the cancellation heartbeat and error mapping are unchanged.
- Added native `FileLock` bindings supporting cross-process advisory locking on Linux, Unix, and Windows.
- Replaced directory-based file locking and custom stale-lock reclamation with OS-backed native locks.
- Updated TypeScript declarations, native bindings, and package documentation for the new API.
- Added comprehensive unit tests and fixtures validating single-owner constraints and process death handoff.
- Kept PCRE2 matching interpreted on macOS across native grep, embedded grep, and embedded rg while preserving JIT elsewhere.
- Added regressions for both reported PCRE2-only crash patterns.
Fixes#7399
Protect only the harness pid during cancellation sweeps. The host recorded parent pid can be stale on Windows and recycled onto the hung command; adding that raw pid to the protected set spared the cancellation target and pruned its whole subtree from cleanup.
Keep protected-subtree pruning rooted at the harness itself, which still spares its real workers while allowing the timed-out target to be reaped.
Fixes#7452
The flattened descendant list can contain a protected node (the
harness, on a Windows PID-reuse false-descendant) together with that
node's real children, collected by recursing through it. Skipping only
the exact protected pid kept omp alive but still TerminateProcess'd its
unrelated worker/tool subprocesses.
signal_tree/terminate_tree now drop every node whose recorded parent
chain within the enumerated set passes through a protected pid, so a
false descendant of the harness can no longer drag the harness's real
children into the kill set.
Fixes#7452