- Replaced puppeteer-based WebRTC with native LiveWebRtcPeer for cross-platform live audio delivery.
- Added cross-platform microphone capture via miniaudio and Opus codec integration for live encoding/decoding.
- Added Apple DeviceCheck attestation token generation via raw Objective-C FFI for macOS.
- Updated live session model to "gpt-live-1-codex" and default voice to "sol" across protocol and controller.
- Added LiveWebRtcPeer and deviceCheckGenerateToken to the public native bindings API.
Replace mmap-backed native grep reads with bounded owned reads so concurrently rewritten files cannot fault the process or mutate captured search bytes.
Add a regression for oversized prefix snapshots and remove the direct memmap2 dependency. Fix existing pi-natives doc-markdown warnings so the native clippy gate passes.
Fixes#5205
- Integrated PCRE2 regex engine with automatic fallback for patterns unsupported by the standard Rust engine.
- Implemented structured JSON output, byte offset reporting, and match replacement functionality.
- Added support for advanced file traversal including Gitignore integration, decompression of archives, and path filtering.
- Updated crate dependencies to include support for expanded grep CLI options and printer utilities.
arboard's Windows reader feeds Qt-style CF_DIBV5 payloads (BI_RGB plus
alpha mask, rewritten to BI_BITFIELDS by its header tweak) to a
header-less BMP decode that mis-places the pixel offset for V4/V5
bitfield headers, so PixPin/Snipaste screenshots failed with
ConversionFailure. read_image_from_clipboard now falls back to reading
the raw CF_DIB clipboard bytes and decoding them through the BMP file
path with an explicit bfOffBits, keeping native Windows image paste off
the PowerShell bridge.
Fixes#3426
- Introduced parallel streaming grep with windowed result processing to enhance search performance and memory management.
- Implemented stateful parallel file walking with buffer pooling and directory entry record caching to minimize memory allocations.
- Optimized ignore state derivation by using directory entry names instead of stat probes.
- Added comprehensive unit and performance tests covering parallel traversal correctness, early termination, and streaming behavior.
napi-rs 3.9.4 registers async-work `execute` at src/async_work.rs:109 as
a plain `unsafe extern "C" fn` — not `extern "C-unwind"`. Any panic
inside a `Blocking::compute` closure unwound past that boundary and
force-aborted the host process under Rust's stabilized C-unwind rules
(RFC 2945, stable since 1.81), losing the JS Promise and session state.
Wrap the user closure in `std::panic::catch_unwind` inside
`Blocking::compute` and map the panic payload to
`Error::new(Status::GenericFailure, ...)` so it flows through napi-rs's
existing rejection path (`inner_task.reject` in `complete_impl`) and
surfaces as a rejected JS Promise instead of a host abort. Every
`task::blocking` caller (grep, ast, glob, listWorkspace, html-to-markdown,
snapcompact, fuzzy find, clipboard image read) inherits the guard.
Correct the root Cargo.toml `panic = "unwind"` comment — napi-rs's
per-call `catch_unwind` only covers the tokio-future path, not the
`Task`/`AsyncTask` async-work path we use here.
Regression test in `crates/pi-natives/src/task.rs` synchronously invokes
`Blocking::compute` with panicking closures (str literal, formatted,
`panic_any`, plus Ok/Err/double-invoke controls) and asserts the returned
`napi::Error` carries the tag and payload — proving the invariant: a
panicking closure MUST NOT unwind past this method.
Fixes#4071