Commit Graph

1003 Commits

Author SHA1 Message Date
roboomp a90dfe0dca fix(bash): preserved unicode in drive-alias translation
Translated the /c and /mnt/c tail per char over the valid UTF-8 suffix instead of copying raw bytes as chars, so non-ASCII path components no longer mojibake. Removed the now-unused byte separator helper and added a non-ASCII regression.

Fixes #8355
2026-08-12 19:26:59 +00:00
roboomp 87a4cd739c fix(bash): normalized msys paths in ls runtime
Applied brush-core's shell path normalizer in LsRuntime and added an end-to-end Windows regression for listing an MSYS drive alias.

Fixes #8355
2026-08-12 19:20:55 +00:00
roboomp d1b9c55495 fix(bash): resolved msys drive paths in utility builtins
Normalized utility operands through brush-core's shared shell path resolver so /c and /mnt/c aliases address the live Windows drive. Added Windows-only regression coverage at the Host boundary.

Fixes #8355
2026-08-12 19:15:20 +00:00
can1357 5481d8b9b0 chore: bump version to 17.2.15 2026-08-12 03:26:12 +02:00
can1357 e5ebb2aee0 chore: bump version to 17.2.14 2026-08-11 20:43:02 +02:00
can1357 2157becbe9 chore: bump version to 17.2.13 2026-08-11 16:03:05 +02:00
can1357 311c32eaf5 fix(natives): repaired win32 build and bazel feature drift
- Synced pi-builtins bazel crate_features with cargo's resolved default
  set: bazel features are literal, so the meta-features never expanded
  and the procs/rg cluster (nohup, pgrep, pidwait, pkill, proc-match,
  ps, rg, sleep, timeout, top) was silently compiled out, leaving the
  process builtins unregistered under bazel and failing pi-shell tests.
- Repaired windows compilation of pi-builtins: cfg-gated the
  uucore::mode import in mkdir, imported std::env in sort's non-unix
  locale probe, mapped ProcInfo::pid through a closure in kill, brought
  MetadataExt into scope in wc, and replaced stat's unstable
  windows_by_handle metadata with a stable GetFileInformationByHandle
  query (volume serial, link count, file index, no-dereference aware).
- Imported HashSet for pi-shell's windows-only PATH merge.
- Added a clippy-ported bazel config + CI bucket so pi-builtins keeps
  its manifest-declared clippy allows under the bazel aspect while rustc
  warnings stay denied, and zeroed the remaining windows-target rustc
  warnings (unused params/imports in find, mv, rm, proc_match, ps).
2026-08-09 03:17:34 +02:00
can1357 896bf5f33e fix(natives): repaired linux pi-builtins release build
- Added util.procs to the bazel crate_features: cargo resolves the
  builtin.kill -> util.procs implication automatically, but bazel
  crate_features are literal, so kill.rs failed with E0432 on
  proc_snapshot once HostProcesses became unconditional.
- Imported std::os::fd::AsFd in the linux/android splice path of the wc
  builtin (E0405); the import is target-gated like its callers.
- Verified with cargo check -p pi-builtins --no-default-features using
  the exact bazel feature list on both the host and (via zig cc)
  x86_64-unknown-linux-gnu targets.
2026-08-08 21:06:10 +02:00
can1357 6fb07028fd chore: bump version to 17.2.12 2026-08-08 20:57:55 +02:00
can1357 731c051733 feat(pi-shell/minimizer): implemented length threshold and empty preservation
- Add minimum character threshold to bypass minimization for short outputs.
- Add preserve-if-empty configuration and pipeline support for filters.
- Update test fixtures and integration tests to meet length thresholds.
2026-08-08 16:27:03 +02:00
can1357 d1eafe7a62 feat(pi-builtins): prevented kill builtin from targeting ancestor processes
- Added `HostProcesses` snapshot and `ChainNode` validation to track ancestry and prevent pid recycling.
- Updated process matching and signal handling to refuse signalling the shell or its ancestor processes.
- Added regression tests verifying that kill builtins safely block ancestor targeting while permitting unrelated processes.
- Added the `smallvec` dependency to support efficient process snapshot tracking.
2026-08-08 10:42:55 +02:00
can1357 2ee9943563 refactor: unify builtins in one place 2026-08-08 10:19:25 +02:00
can1357 4dc97f89ab fix(natives): backticked RemoteDesktop in portal doc comments
clippy-strict doc_markdown (-D warnings) rejects the bare identifier;
these two docs were the remaining rust_validate errors on main.
2026-08-07 23:51:43 +02:00
can1357 81e0c3f6bf fix(voice): dropped redundant pub(crate) in private device module
clippy-strict (nursery redundant_pub_crate, -D warnings) rejects pub(crate)
items inside the crate-private device module; plain pub is equivalent there.
Applied across all platform backends since CI only lints the linux cfg.
2026-08-07 23:46:48 +02:00
can1357 055a5d4f26 chore: bump version to 17.2.11 2026-08-07 23:38:40 +02:00
can1357 7cae7ef3f5 feat(voice): replaced miniaudio with native platform audio backends
- Replaced the miniaudio dependency with custom OS audio device abstractions and backends.
- Implemented platform-specific audio playback and capture for macOS (Audio Queue), Windows (WASAPI), and Linux (PulseAudio/ALSA).
- Added a fallback stub backend returning errors for unsupported platforms.
- Updated audio stream handling with reliable fill guard wakeups and streamlined rate validation.
2026-08-07 23:38:27 +02:00
can1357 bc5eee4e24 fix(build): activated zune-jpeg log feature and widened test compat type
- zune-jpeg 0.5.15 (image 0.25's JPEG decoder) cannot compile with its
  non-default log feature off: zune-core's no-log warn! stub is not
  expression-safe. A feature-activation-only workspace dep on
  zune-jpeg { features = ["log"] } fixes the cold build; log stays 0.4.33.
- model-registry-default-config's local ModelSnapshot type gains the optional
  streamIdleTimeoutMs the Bedrock watchdog compat now emits.
2026-08-07 23:38:27 +02:00
roboomp 216fc3ca2d fix(computer): waited for all granted libei devices
- Tracked pointer and keyboard grants from the RemoteDesktop response.
- Drained asynchronous EIS announcements after the first resumed device.
- Covered GNOME's keyboard-before-pointer ordering with a regression test.

Fixes #7926
2026-08-07 23:38:25 +02:00
can1357 084fbb683f Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp)
Follow-up head of the same PR, merged after the sweep landed cf5bd72877:
bounds the consent-denied portal close inline (a nested block_on would panic)
and removes the world-readable pre-#7884 RemoteDesktop restore token.
2026-08-07 14:52:56 +02:00
roboomp 2567db01df fix(computer): removed orphaned wayland remote-desktop token
Pre-#7884 builds wrote a world-readable RemoteDesktop restore token under $XDG_STATE_HOME/omp/remote-desktop-token during read-only calls, and nothing on the fixed tree reads, rewrites, or removes it. WaylandBackend::new now unlinks it best-effort on construction so the stale credential does not survive the upgrade.

Fixes #7884
2026-08-07 12:43:37 +00:00
roboomp 539906e25c fix(computer): bounded consent-denied portal close inline
The SelectDevices/Start/ConnectToEIS failure arm closes the RemoteDesktop session from inside runtime.block_on, so it cannot use close_session (a nested block_on panics). Bounded it with an inline tokio::time::timeout(CLOSE_TIMEOUT, ...) so a frozen xdg-desktop-portal on the ordinary denied-consent path no longer hangs the worker thread.

Fixes #7884
2026-08-07 12:39:05 +00:00
can1357 215040966e fix(natives): satisfied clippy on merged macos input rewrite 2026-08-07 13:47:03 +02:00
can1357 531ae04b3b Merge PR #7887: fix(natives): port wayland capture to pipewire 0.9 Rc handle API (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 3cda312165 Merge PR #7890: fix(computer): lazily request wayland input permission (@roboomp) 2026-08-07 13:37:56 +02:00
can1357 a37b70dc2e fix(natives): make macOS input backend sendable 2026-08-07 13:37:56 +02:00
roboomp cf5bd72877 fix(computer): bounded portal close and closed leaked session
Bounded the RemoteDesktop close in Libei::drop with CLOSE_TIMEOUT so an unresponsive xdg-desktop-portal cannot hang worker teardown past the surrounding close budget.

Closed the portal session when ei::Context::new fails after Start/ConnectToEIS, the one init path that previously dropped the session without revoking the grant.

Fixes #7884
2026-08-07 11:12:04 +00:00
roboomp 71cf826aeb merge(natives): integrated shared wayland portal runtime
Merged PR #7889 into the lazy Wayland input branch. Portal sessions retain the shared process runtime, the portal module remains available in shipped builds, and only PipeWire token helpers are feature-gated.
2026-08-07 08:24:58 +00:00
roboomp 12d1ade665 fix(computer): shared the wayland portal runtime
Kept the portal module available in shipped builds while feature-gating only PipeWire token storage. Libei portal sessions now retain the shared process runtime and still close explicitly on teardown.
2026-08-07 08:22:03 +00:00
roboomp 30264cb151 fix(natives): port wayland capture to pipewire 0.9 Rc handle API
capture.rs still constructed the PipeWire main loop and context via the
0.8 owning constructors (MainLoop::new / Context::new / connect_fd),
which pipewire 0.9.2 removed in favour of the Rc handle types. The
migration was partial — StreamBox::new was already 0.9 — so the
wayland-pipewire feature failed to compile with E0599.

Switch to MainLoopRc::new / ContextRc::new(&loop, None) / connect_fd_rc.
The downstream call sites are unchanged: MainLoopRc derefs to MainLoop
(run/quit/clone), ContextRc derefs to Context, and CoreRc derefs to
Core so StreamBox::new(&core, ...) still coerces.

Fixes #7885
2026-08-07 08:19:56 +00:00
roboomp 8d6ed17811 fix(computer): lazily requested wayland input permission
Deferred libei and RemoteDesktop setup until the first native input operation. Read-only capability, window, display, and AX calls no longer request keyboard or pointer access.

Used non-persistent portal grants and retained the portal session so backend teardown closes it explicitly.

Fixes #7884
2026-08-07 06:50:16 +00:00
roboomp 81d3456af0 fix(natives): share one runtime across wayland portal paths
ashpd caches a process-global D-Bus connection whose I/O tasks bind to whichever runtime first creates it. Libei::portal_context() built a short-lived current_thread runtime and dropped it when Libei::new() returned, orphaning that connection; capture() then built its own runtime and reused the dead connection, so PipeWire capture never delivered a frame whenever libei input init ran first.

Route both portal_context() and capture() through a shared long-lived multi-thread runtime held in a LazyLock, keeping the cached connection's I/O alive for the process lifetime.

Fixes #7886
2026-08-07 06:47:03 +00:00
roboomp 62b007295a fix(natives): prevented macos input suppression
Configured Quartz event sources to permit local hardware events in both suppression states and replaced Enigo-backed global posting with the configured source.

Added a macOS regression test for the event-source suppression settings.

Fixes #7872
2026-08-07 03:02:49 +00:00
can1357 43c1b245e7 chore: bump version to 17.2.10 2026-08-06 13:32:34 +02:00
can1357 86375c130a style: reflowed window id doc comment with cargo fmt 2026-08-05 22:19:57 +02:00
can1357 ee026fa2e3 Merge PR #7704: fix(natives): gate wayland capture capability on pipewire feature (@roboomp)
# Conflicts:
#	crates/pi-natives/src/desktop/linux/wayland/mod.rs
2026-08-05 22:16:16 +02:00
can1357 307ba8b9f3 Merge PR #7711: fix(computer): correct Wayland foreground delivery (@roboomp) 2026-08-05 22:15:47 +02:00
roboomp 2ef15378f6 fix(computer): accept backend-minted window ids in wayland capture
The Capture request arm of Worker::process pre-parsed every window
target as a u64 before consulting the backend, so composite AT-SPI ids
minted by the Wayland backend's own windows() (e.g.
atspi::1.31:/org/a11y/atspi/accessible/1) could never pass the gate,
making per-window capture unreachable on Wayland in every build.

All backends resolve capture targets by string-matching against the ids
they themselves minted, so the u64 gate was a leaked X11/Win32/macOS
assumption. Drop it and let the backend validate the id; unknown ids now
fail as WindowNotFound from the backend lookup instead of InvalidTarget.

Fixes #7701
2026-08-05 11:06:54 +00:00
roboomp ea887b00a9 fix(computer): corrected Wayland foreground delivery
Reported compositor-limited per-window input before reaching the AT-SPI focus path and stopped advertising foreground delivery on Wayland.

Removed the obsolete AT-SPI window-raise helper and updated public recovery guidance.

Fixes #7702
2026-08-05 10:57:25 +00:00
roboomp dc4725e626 fix(natives): gate wayland capture capability on pipewire feature
WaylandBackend::capabilities() hardcoded capture:true, but the PipeWire
screencast path is compiled only under the wayland-pipewire feature, which
is off by default and excluded from shipped Bazel addons (crate_features=[]).
Released builds therefore advertised capture the binary could never do:
every capture() call returned CaptureFailed, and callers trusting
capabilities() retried into a guaranteed failure.

Gate the capture flag and capture_permission on cfg!(feature =
"wayland-pipewire") so the report matches the compiled-in path, and align
docs/computer-use.md with what shipped builds actually support.

Fixes #7700
2026-08-05 10:45:57 +00:00
can1357 f7f8e040ee chore: bump version to 17.2.9 2026-08-05 03:07:47 +02:00
can1357 b0a94a8fc0 chore: cleanup 2026-08-05 03:07:16 +02:00
can1357 f3cf3b926d test(fuzzy-find): prove bounded large-corpus ranking 2026-08-05 01:11:58 +02:00
can1357 0897725394 Merge PR #7536: perf(fuzzy-find): retain only the bounded top-K scored matches (@Mustaqeem66) 2026-08-05 01:11:58 +02:00
can1357 003bb5548c chore: bump version to 17.2.8 2026-08-04 05:53:35 +02:00
can1357 a5090f1f81 chore: bump version to 17.2.7 2026-08-04 01:19:36 +02:00
can1357 1cf919099e style(pi-shell): wrapped long command string in test
- Split a long command string across multiple lines in shell test.
2026-08-03 23:41:07 +02:00
can1357 dce12984f2 fix(pi-shell): parsed state format specifier correctly in ps builtin
- Corrected the mapping of the "state" specifier to PsField::State in the ps format parser.
- Added a test to verify that the ps builtin successfully accepts tpgid and other job control columns.
2026-08-03 19:01:09 +02:00
can1357 451eb9842c fix: mapped tail builtin broken pipe to silent exit 141
- Handled broken pipe errors across tail output and follow paths by translating them to a silent SIGPIPE exit code.
- Prevented stderr noise when downstream pipeline readers exit early, matching native tail behavior.
2026-08-03 18:53:14 +02:00
can1357 cdd1d13079 feat(pi-shell): extended ps builtin format specifiers and process metrics
- Added support for extended ps format specifiers including tpgid, ruid, rgid, egid, pri, flags, min_flt, maj_flt, times, sz, s, ruser, rgroup, and tgid.
- Implemented group name resolution via `getgrgid_r` on Unix platforms.
- Suppressed broken pipe diagnostic output in the tail builtin to match standard tail behavior on downstream closure.
2026-08-03 18:51:23 +02:00
Muhammad Mustaqeem 60187c9ba9 refactor(fuzzy-find): release the heap borrow before evicting
Comparing against the heap root inside an `if let` binding keeps the shared
borrow of `heap` alive across the `pop`/`push` in the same block. Fold the
comparison into the condition instead, so the borrow ends with the
condition expression and eviction takes a clean mutable borrow.

No behavior change.
2026-08-03 21:09:01 +05:00