Commit Graph

732 Commits

Author SHA1 Message Date
can1357 0d50c53d4c Merge PR #8715: fix(snapcompact): disambiguate digit zero from letter O in frame fonts (@roboomp) 2026-08-19 01:36:03 +02:00
can1357 0a912cc467 chore: bump version to 17.3.7 2026-08-17 22:29:25 +03:00
can1357 54e1a8c900 chore: bump version to 17.3.6 2026-08-17 17:16:40 +03:00
roboomp 70af5c300b fix(snapcompact): disambiguate digit zero from letter O in frame fonts
The default snapcompact frame fonts (X.org 8x13 for every provider, plus the selectable 6x12 and legacy 5x8) drew digit zero as a bare oval visually indistinguishable from letter O. Image-based compaction OCRs the frames back, so 0 and O were mixed up and compacted identifiers (e.g. Slack IDs) got corrupted.

Zero now carries a disambiguating interior mark the O lacks: an ascending slash in 8x13 and a center bar in 6x12/5x8. unscii-8 (8x8/6x6u shapes) already shipped a slashed zero and is unchanged.

Fixes #8713
2026-08-16 10:34:48 +00:00
can1357 37eee71978 chore: bump version to 17.3.5 2026-08-16 10:21:05 +03:00
can1357 02cd22dc9b feat: added live tracking and stale status warnings for agent activity snapshots
- Added live tracking and stale status warnings for agent activity snapshots.
- Fixed text wrapping with ANSI escape sequences to defer style open sequences after whitespace.
- Added VirtualRenderScheduler for deterministic virtual-clock rendering tests.
2026-08-16 10:18:56 +03:00
roboomp e4b5b3f795 fix(tui): stopped inline code color bleed at soft wraps
- Kept ANSI sequences after visible content with the current wrap token so closing resets cannot migrate into discarded whitespace.
- Added a regression for a codespan ending exactly at the wrap width.

Fixes #8582
2026-08-14 21:18:40 +00:00
can1357 ffd53ff92a chore: bump version to 17.3.4 2026-08-14 14:38:16 +02:00
can1357 42d5ca5128 fix(pi-natives): backticked DeviceCheck in doc comment for clippy doc-markdown 2026-08-14 14:13:54 +02:00
can1357 c0ad44b6fc Merge PR #8533: fix(pi-natives): guard DeviceCheck token generation on GUI session (@roboomp) 2026-08-14 14:11:51 +02:00
can1357 04fab5ecb4 feat: replaced custom mupdf wasm pipeline with native function
- Replaced the custom MuPDF-WASM PDF extraction and rendering pipeline with the new `pdfToMarkdown` native function from `@oh-my-pi/pi-natives`.
- Removed legacy MuPDF extraction modules, WASM embedding scripts, and PDF image extraction tools.
- Added OCR warnings and browser/text redirection for unsupported PDF image reads.
- Updated native package definitions, documentation, and test suites for the new PDF inspection capability.
2026-08-14 14:08:28 +02:00
roboomp 988ccc8268 fix(pi-natives): guard DeviceCheck token generation on GUI session
-[DCDevice isSupported] synchronously opens an XPC connection to the per-user DeviceCheck metadata daemon, which exists only in an interactive GUI login session. From a session without graphic access (SSH, launchd LaunchDaemon, CI runner, service account, sandbox) the connection setup hits _xpc_api_misuse and aborts the process with SIGTRAP before any completion handler runs, so the promise never rejects and every openai-codex/* OAuth model becomes unusable.

Check the caller's security session for the sessionHasGraphicAccess attribute via SessionGetInfo before touching DeviceCheck; resolve { supported: false, error } when it is absent, mirroring the non-macOS stub and letting the caller send an error-coded attestation instead of dying.

Fixes #8353
2026-08-14 08:49:26 +00:00
can1357 039728ad80 chore: bump version to 17.3.3 2026-08-14 05:44:05 +02:00
can1357 ae2d3d6ea1 chore: bump version to 17.3.2 2026-08-14 00:28:43 +02:00
can1357 0bc2c342f4 chore: bump version to 17.3.1 2026-08-13 19:39:21 +02:00
roboomp 246dda7f1c fix(natives): static-link win32 MSVC CRT so addon needs no VC++ redist
The shipped win32-x64 pi_natives addon linked the dynamic MSVC CRT (/MD)
and imported VCRUNTIME140.dll from the Visual C++ Redistributable, which
is absent on a clean Windows install. LoadLibrary of the extracted .node
then failed with error 126 ("The specified module could not be found"),
so omp could not start after a fresh `irm install.ps1 | iex`.

Static-link the CRT for the win32 addon: +crt-static for rustc (crate
BUILD select) plus the static_link_msvcrt cc feature enabled for win32 in
the native_addon transition, so its C deps (opus/cmake, tree-sitter,
blake3, ring) compile /MT in lock-step. The rebuilt .node imports only
core Windows system DLLs -- no VCRUNTIME140.dll, no api-ms-win-crt-*.

Fixes #8439
2026-08-13 16:00:33 +00:00
can1357 8b0f400d3c chore: bump version to 17.3.0 2026-08-13 08:28:43 +02:00
can1357 b60bef961c feat: introduced nix packaging and path-based binary resolution
- Add comprehensive Nix flake definitions, derivations, modules, and CI workflows.
- Update tests and executables to resolve binaries from PATH rather than absolute paths.
- Ensure byte reproducibility and zeroed timestamps in embedded dashboard archives.
- Add handling for Nix-managed installations in CLI update checks.
2026-08-13 03:52:47 +02:00
can1357 5481d8b9b0 chore: bump version to 17.2.15 2026-08-12 03:26:12 +02:00
can1357 e5ebb2aee0 chore: bump version to 17.2.14 2026-08-11 20:43:02 +02:00
can1357 2157becbe9 chore: bump version to 17.2.13 2026-08-11 16:03:05 +02:00
can1357 6fb07028fd chore: bump version to 17.2.12 2026-08-08 20:57:55 +02:00
can1357 2ee9943563 refactor: unify builtins in one place 2026-08-08 10:19:25 +02:00
can1357 4dc97f89ab fix(natives): backticked RemoteDesktop in portal doc comments
clippy-strict doc_markdown (-D warnings) rejects the bare identifier;
these two docs were the remaining rust_validate errors on main.
2026-08-07 23:51:43 +02:00
can1357 055a5d4f26 chore: bump version to 17.2.11 2026-08-07 23:38:40 +02:00
can1357 bc5eee4e24 fix(build): activated zune-jpeg log feature and widened test compat type
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
  non-default log feature off: zune-core's no-log warn! stub is not
  expression-safe. A feature-activation-only workspace dep on
  zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
  streamIdleTimeoutMs the Bedrock watchdog compat now emits.
2026-08-07 23:38:27 +02:00
roboomp 216fc3ca2d fix(computer): waited for all granted libei devices
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.

Fixes #7926
2026-08-07 23:38:25 +02:00
can1357 084fbb683f Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp)
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
2026-08-07 14:52:56 +02:00
roboomp 2567db01df fix(computer): removed orphaned wayland remote-desktop token
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.

Fixes #7884
2026-08-07 12:43:37 +00:00
roboomp 539906e25c fix(computer): bounded consent-denied portal close inline
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.

Fixes #7884
2026-08-07 12:39:05 +00:00
can1357 215040966e fix(natives): satisfied clippy on merged macos input rewrite 2026-08-07 13:47:03 +02:00
can1357 531ae04b3b Merge PR #7887: fix(natives): port wayland capture to pipewire 0.9 Rc handle API (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 3cda312165 Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 a37b70dc2e fix(natives): make macOS input backend sendable 2026-08-07 13:37:56 +02:00
roboomp cf5bd72877 fix(computer): bounded portal close and closed leaked session
Bounded the RemoteDesktop close in Libei::drop with CLOSE_TIMEOUT so an unresponsive xdg-desktop-portal cannot hang worker teardown past the surrounding close budget.

Closed the portal session when ei::Context::new fails after Start/ConnectToEIS, the one init path that previously dropped the session without revoking the grant.

Fixes #7884
2026-08-07 11:12:04 +00:00
roboomp 71cf826aeb merge(natives): integrated shared wayland portal runtime
Merged PR #7889 into the lazy Wayland input branch. Portal sessions retain the shared process runtime, the portal module remains available in shipped builds, and only PipeWire token helpers are feature-gated.
2026-08-07 08:24:58 +00:00
roboomp 12d1ade665 fix(computer): shared the wayland portal runtime
Kept the portal module available in shipped builds while feature-gating only PipeWire token storage. Libei portal sessions now retain the shared process runtime and still close explicitly on teardown.
2026-08-07 08:22:03 +00:00
roboomp 30264cb151 fix(natives): port wayland capture to pipewire 0.9 Rc handle API
capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.

Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.

Fixes #7885
2026-08-07 08:19:56 +00:00
roboomp 8d6ed17811 fix(computer): lazily requested wayland input permission
Deferred libei and RemoteDesktop setup until the first native input operation. Read-only capability, window, display, and AX calls no longer request keyboard or pointer access.

Used non-persistent portal grants and retained the portal session so backend teardown closes it explicitly.

Fixes #7884
2026-08-07 06:50:16 +00:00
roboomp 81d3456af0 fix(natives): share one runtime across wayland portal paths
ashpd caches a process-global D-Bus connection whose I/O tasks bind to whichever runtime first creates it. Libei::portal_context() built a short-lived current_thread runtime and dropped it when Libei::new() returned, orphaning that connection; capture() then built its own runtime and reused the dead connection, so PipeWire capture never delivered a frame whenever libei input init ran first.

Route both portal_context() and capture() through a shared long-lived multi-thread runtime held in a LazyLock, keeping the cached connection's I/O alive for the process lifetime.

Fixes #7886
2026-08-07 06:47:03 +00:00
roboomp 62b007295a fix(natives): prevented macos input suppression
Configured Quartz event sources to permit local hardware events in both suppression states and replaced Enigo-backed global posting with the configured source.

Added a macOS regression test for the event-source suppression settings.

Fixes #7872
2026-08-07 03:02:49 +00:00
can1357 43c1b245e7 chore: bump version to 17.2.10 2026-08-06 13:32:34 +02:00
can1357 86375c130a style: reflowed window id doc comment with cargo fmt 2026-08-05 22:19:57 +02:00
can1357 ee026fa2e3 Merge PR #7704: fix(natives): gate wayland capture capability on pipewire feature (@roboomp)
# Conflicts:
#	crates/pi-natives/src/desktop/linux/wayland/mod.rs
2026-08-05 22:16:16 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00
roboomp 2ef15378f6 fix(computer): accept backend-minted window ids in wayland capture
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.

All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.

Fixes #7701
2026-08-05 11:06:54 +00:00
roboomp ea887b00a9 fix(computer): corrected Wayland foreground delivery
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.

Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.

Fixes #7702
2026-08-05 10:57:25 +00:00
roboomp dc4725e626 fix(natives): gate wayland capture capability on pipewire feature
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.

Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.

Fixes #7700
2026-08-05 10:45:57 +00:00
can1357 f7f8e040ee chore: bump version to 17.2.9 2026-08-05 03:07:47 +02:00
can1357 b0a94a8fc0 chore: cleanup 2026-08-05 03:07:16 +02:00