- Extracted audio capture and playback implementations, along with the WebRTC peer engine, from `pi-natives` into a new `pi-voice` library crate.
- Updated `pi-natives` bindings to consume the extracted `pi_voice` audio streams and live peer core.
- Added release validation gate jobs, parallelized Linux binary builds, and introduced a concurrent macOS release build job in the CI workflow.
- Updated Bazel workspace configurations, Cargo manifests, and documentation to include the new `pi-voice` crate and its dependencies.
The 17.1.6 Bazel migration dropped maudio's generate-bindings feature, so
the darwin addon shipped maudio-sys's Linux-shaped pregenerated miniaudio
bindings. Those bindings omit the MA_SUPPORT_COREAUDIO backend-state union
members that the macOS build of miniaudio.c actually contains, producing a
Rust/C ABI mismatch: capture callbacks saw zero channels and yielded no PCM.
Re-enable generate-bindings for apple targets only. Patch maudio-sys's build
script to branch on Cargo's TARGET rather than the build-script host, so a
macOS-hosted Linux/Windows cross-build keeps target-family pregenerated
bindings instead of incorrectly running Darwin bindgen. Repin the Bazel graph
to apply the patch and gate bindgen behind the apple target selects.
Fixes#6846
- Enhance CI workflows to build and reuse native addon artifacts instead of recompiling.
- Update bazel cache actions with selective backend detection and separate remote and disk modes.
- Add `--source` CLI option to install prebuilt native targets without requiring Bazel.
- Increase Kata runner memory configuration from 12Gi to 24Gi.
- Add conditional attributes to silence dead-code warnings on platform-specific code and fields.
- Update target dependencies in pi-walker/Cargo.toml with explicit windows-sys feature sets.
- Simplify time cast expressions in linux_reflink and rcopy modules.
build-bindings.ts built the failure error from captured stderr only, but
napi-rs/cargo route much of the failure detail to stdout (e.g. `cargo
metadata exited with code 101 ...`). When stderr was empty the thrown
error collapsed to a bare "napi build failed", hiding the real cause.
Attach the exit code plus tail-capped stdout and stderr sections to the
thrown error so the actionable output survives on the error object.
Fixes#6796
- Replaced the napi-cli/cargo-zigbuild/cargo-xwin/sccache build path with
Bazel: rules_rust + crate_universe over Cargo.lock, hermetic zig cc
toolchains (linux-gnu pinned to glibc 2.17, linux-musl), host Xcode for
darwin, and a repo-local hermetic clang-cl + llvm-ml + xwin toolchain for
windows-msvc (bazel/toolchains/msvc).
- All eight shipped addons build as //:natives-<target> via the release
transition in bazel/defs.bzl (opt, thin LTO, cgu=16, stripped, canonical
.node naming); scripts/bazel-natives.ts is the single driver for local
dev and CI.
- Rust validation moved to bazel test + clippy aspects (strict workspace
policy for opted-in crates, default lints elsewhere, mirroring cargo
semantics) and the rustfmt aspect; cargo stays as the dev-iteration
surface, with brush-core/brush-builtins promoted to workspace members
and excluded from cargo dev tasks to keep their historical scope.
- CI caches through an in-cluster bazel-remote action cache (TLS + basic
auth, cluster-internal only); GitHub-hosted runners never touch the
infrastructure and use an actions/cache-backed disk cache instead.
- Deleted the hand-rolled caching machinery: ci-target-cache,
ci-native-artifact-cache, ci-build-native, native-source-hash,
find-native-artifacts, restore-linux-native, native-prewarm workflow,
ensure-* toolchain actions, and all sccache/Swatinem wiring.
- Warm native rebuilds drop from ~20 minutes to seconds; a cold client
with a warm remote cache rebuilds the linux x64 pair in ~2.5 minutes.
Returning end-of-input from chunks::read on a disconnected receiver
also masked a panicking ext_sort sorter thread (comparator or Rayon
panic in sort_by), letting sort exit 0 with truncated or empty output.
Retain the sorter JoinHandle and join it after read_write_loop, mapping
a thread panic to an error; drop the sorted-chunk receiver first so a
still-running sorter unblocks instead of deadlocking the join. Added an
external multi-chunk sort test covering the spill-to-files join path.
Fixes#6736
The vendored uu-sort reader unwrapped the chunk-channel send at
chunks.rs:248, panicking with `SendError(..)` whenever the receiver
disconnected early (a consumer thread stopping after an error or a
closed output). Diverge from upstream: on a failed send, stop reading
gracefully and report end-of-input, matching the pattern already used
by the sorter thread. Added a regression test that drives read against
a dropped receiver.
Fixes#6736
Drive desktop batches from a shared action, settle, and capture sequence so the regression test exercises the same ordering as DesktopWorker::execute. Add external contributor attribution to the unreleased changelog entry.
- Remove uniform language inference requirement, allowing mixed-language paths to rewrite each file in its own language.
- Update `ast_edit_blocking` in `crates/pi-natives/src/ast.rs` to compile rewrite rules per language and skip unsupported languages gracefully.
- Update `ast-edit.md` prompt documentation to reflect mixed-language path support.
- Add test coverage verifying mixed-language tree rewrites.
clang-cl enforces per-function target features unlike MSVC, so opus' silk/x86 SSE4.1 units fail under cargo-xwin. The win32 x64 addon floor is x86-64-v2 (SSE4.2 inclusive), so enable it for all C deps via CFLAGS_<target>.
- Added ensure-cmake action installing pinned cmake/ninja on omp-kata pods; audiopus_sys builds bundled libopus via CMake (Ninja for MSVC cross).
- Set CMAKE_POLICY_VERSION_MINIMUM=3.5 globally and in build-native.ts: the bundled opus tree declares cmake_minimum_required below 3.5, which CMake 4.x refuses.
- Dropped the -C target-cpu=native fallback for non-x64 native builds: it baked build-host CPU features into shipped darwin arm64 addons and trips ring 0.17's aarch64-apple const assertion.
- Switched from `miniaudio` to `maudio` Rust crate and added `AudioCapture` and `AudioPlayback` native classes.
- Removed browser-side audio infrastructure including Web Audio API, audio worklet processor, and WebRTC runtime.
- Migrated STT recorder and transcriber modules to use native `AudioCapture` with callback-based streaming.
- Replaced streaming audio player with native `AudioPlayback` that writes PCM directly without TypeScript intermediaries.
- Removed ffmpeg, wav, and platform-specific playback commands from the audio toolchain.
- Replaced puppeteer-based WebRTC with native LiveWebRtcPeer for cross-platform live audio delivery.
- Added cross-platform microphone capture via miniaudio and Opus codec integration for live encoding/decoding.
- Added Apple DeviceCheck attestation token generation via raw Objective-C FFI for macOS.
- Updated live session model to "gpt-live-1-codex" and default voice to "sol" across protocol and controller.
- Added LiveWebRtcPeer and deviceCheckGenerateToken to the public native bindings API.
- Replaced the separate GUI-linked pi_natives.desktop.linux-x64 addon with
a pure-Rust X11 backend (x11rb RustConnection capture via RandR/GetImage,
XTest input with keysym mapping) compiled into the core addon on every
published target; Linux arm64 and musl are now supported and headless
hosts load the addon unaffected.
- Removed the native-desktop-linux cargo feature, desktop_unsupported.rs,
lazy desktop loader, second napi build, desktop packaging/CI steps, GUI
build dependencies, and the now-unreferenced vendored libspa crate;
reverted setup-system-deps to main.
- Preserved the desktop input hardening semantics on the unified backend:
XTest layouts reject negative origins and coordinates beyond 0..=32767,
batch coordinates stay bound to the frame last returned to JS with
intermediate screenshots deferred, coordinate input requires a
previously returned frame, and failed chord releases still release
every held key.
- Enforced a 60s worker-side execute deadline (DESKTOP_DEADLINE_EXCEEDED):
no input is emitted after expiry and wait-heavy batches are rejected
upfront.
- Added int32 fail-closed validation for coordinates, drag points, and
scroll deltas at the JS ingress and gateway schema.
- Exposed computer to models without native OpenAI computer-use support as
a regular function tool with a typed GA action schema across OpenAI,
Azure, and Codex Responses providers, including named forced choice.
- Added the /computer slash command (on/off/status/toggle) for
session-only enablement via runtime tool registration in SessionTools.
- Updated docs, changelogs, and contract tests accordingly.
- Implemented native UTF-16 text processing in Rust diff module with support for unpaired surrogates.
- Removed `similar` crate from Rust workspace and `diff` npm package from coding-agent, hashline, and natives.
- Removed jsdiff fallback wrappers and `isWellFormed()` guards from TypeScript diff implementations.
- Added comprehensive test suite for native diff functions covering random inputs and edge cases including surrogates and emoji.
- Renamed model `codex-auto-review` to `gpt-5.3-codex-spark` with updated pricing and context window.
- An eval-worktree cherry-pick swept 16 packages/*/node_modules symlinks into the index; 'node_modules/' with a trailing slash only matches directories, so symlinked installs bypassed the ignore. Dropped the slash and removed the tracked links.
- Promoted union-merge strays back under [Unreleased] and merged duplicate headings across ai, catalog, coding-agent, natives, and tui changelogs (scripts/fix-changelogs.ts --since 7b141199d5).
- Restored the pi-ai changelog entry for #6139 that its fix commit missed.