github Nonary/Vibepollo daily-2026-10-11
Nightly 2026-10-11

latest release: daily-2026-10-11.2
pre-release4 hours ago

This is a nightly release of Vibepollo and contains several bug fixes and may contain new features. Check the commit log for more information.

Windows installer · Linux (Arch x86_64)

Nightly Windows installers are unsigned and include self-signed gamepad components. They may cause false-positive antivirus alerts.

Commit log

Source: 0d62c962e081

Since the preceding stable release 2.0.0: compare exact sources.

fcc65abe88d0

feat(plugin): Converted powershell plugin to C# DLL

Copying Vibepollo version over to Vibeshine
- From `Noklef/vibeshine/tree/playnite-plugin-conversion`

cccb8ac101a9

fix(plugin): Rename references to Vibepollo + copied re-wiring of plugin processes from vibeshine repo's PR

e6824ad9f9d5

fix(playnite): restart Playnite for plugin updates

9b0dea2d0e9e

fix(linux): allow display rotations through session broker

26b1fa3a1c8e

fix(steam): use content-hashed portraits for newer apps

Newer Steam apps cache their portrait as
librarycache/<appid>/<hash>/library_600x900.jpg and publish it on the CDN
only under the same <hash> directory. Discovery only looked for
library_capsule.* in hashed directories, so it fell through to the
460x215 library_header.jpg, and the fixed-path CDN fallback returned 404.

Discovery now also accepts library_600x900.* in hashed directories, and
when the fixed CDN path is missing the artwork sync retries the CDN under
the local file's 40-hex hash directory.

Fixes #554

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

048c9e734ea9

fix(playnite): make plugin shutdown and upgrades reliable

Prevent late connections and queued UI work from surviving connector shutdown.
Allow Playnite to finish closing before replacing its loaded plugin, while
keeping forced cleanup bounded. Restore SDK discovery and legacy upgrade
visibility, with regression coverage for lifecycle races and exit handling.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

f1cf988fb35a

feat(playnite): replace PowerShell connector with compiled plugin (#513)

Convert the Playnite 10 connector to a packaged .NET plugin while preserving snapshots, game status and launcher handoff. Fence connection admission and queued UI work during shutdown, give Playnite a bounded graceful exit before plugin replacement, and restore SDK discovery and legacy upgrade visibility.

Validated the .NET Framework plugin build, both production web bundles, the local release build and all 128 CTest tests. Native Windows Playnite runtime behavior was not exercised on the Linux validation host.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

6c4a3e1e0d74

Merge pull request #548 from HarryAnkers/fix/linux-restore-rotation-allowlist

fix(linux): allow display rotations through session broker

e8e6f69da3ea

fix(steam): request the hashed CDN file that matches the local name

Hashed cache directories hold either library_600x900.jpg or
library_capsule.jpg, and the CDN serves <name>_2x.jpg from the same
directory. Requesting library_600x900_2x.jpg for a library_capsule
directory returned 404, leaving those apps at 300x450.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

f00782887f00

Merge pull request #555 from HarryAnkers/fix/steam-hashed-portrait

fix(steam): use content-hashed portraits for newer apps

348aa8b57988

feat(release): add gated daily prereleases, safety contracts and exact nightly notes

a6ffd060a1db

ci: forbid self-hosted runners for daily builds

d36f135d06fc

feat(release): expose validated Moonlight Windows product version

2b1e9c5a8319

ci: use reviewed primary sources and bounded Linux resources

d51449a41831

feat(installer): require exact-certificate consent for newer self-signed gamepads

fc68663a4e34

fix(linux): restore displays asynchronously without stalling Web UI

Display cleanup and KScreen queries could block the HTTPS event loop after
resume. Dispatch restores through the session helper, keep status queries
passive, and move display-layout queries off the listener.
Bound helper replies and fence uncertain compositor mutations while retaining
saved topology and canceling stale restores when ownership changes.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 3ed6deafe2d98bcfb0d2a8f64e6014975fc764a1)

70634900fd05

ci(linux): reuse verified CUDA and compiler caches on bounded hosted runners

Avoid duplicate recursive source checkout, shallow pinned submodules, retain native package tests and Pascal checks, and provide an exact-source artifact-only validation lane without signing or package installation.

7f62b3b54270

feat(focus): share managed application focus across platforms

Linux managed launches lacked Playnite's foreground focus behavior.
Add shared focus settings and platform adapters for Steam, Lutris and
Playnite, preserving legacy preferences and cancelling pending focus
when the application session ends. Pass zero values explicitly so
turning focus off also disables the Windows launcher defaults.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit fb7f6c85fb5d3c7de018dadbd280cdae1de9fc22)

205eb31216fc

feat(pyrowave): add optional hybrid block reuse and LZ4 transport

Negotiate version 1 of the opt-in hybrid transport with compatible clients.
Reuse only acknowledged immutable coefficient blocks, explicitly clear removed
blocks, and send changes with sampled raw/XOR LZ4 compression. Keep the image
budget stable and fall back to native payloads for incompressible frames.

Bound reference caches and acknowledgement handling, preserve critical FEC,
and recover from missing references with full refreshes. Disable optional
detail FEC for hybrid envelopes. Canonicalize unused GPU sign bits and record
padding without changing decoded pixels, with a reproducible shader patch.

Bundle LZ4 and its packaged license, document the protocol, and fix the minimal
SteamOS Vulkan include and CUDA-disabled capture guards required by the build.

Validation: full PyroWave-enabled Linux container build and help smoke test;
25 codec cases and all seven client/PyroWave checks passed. Independent
ASan/UBSan mutation and CRC32C checks passed. Windows execution and live
streaming latency remain unverified.

(cherry picked from commit 0a050bdba002170c5c21311c3ce2c773a67ca565)

b48e27c76143

fix(migration): preserve Apollo broker metadata call contract

Keep the empty metadata arguments required by the Apollo session broker when launching managed focus, and retain source-only environment rejection assertions alongside Apollo environment requirements.

Generated with Codex (https://openai.com/codex/)

Model: GPT-6.1 Sol Ultra

ea4ae2e8c15b

fix(migration): classify Apollo broker mutation completion

Use the Apollo machine-host flag when interpreting exit 125, so cancelled compositor mutations fence subsequent display changes until restart. Guard the destination-specific completion classification in the Linux contract.

Generated with Codex (https://openai.com/codex/)

Model: GPT-6.1 Sol Ultra

957a3e7a8e63

ci(linux): isolate exact-source validation in registered manual workflow

Skip release selection and ordinary Windows/Arch/signing-summary jobs when hosted Linux validation is requested; preserve default behavior and dispatch only the no-key artifact route with tests enabled.

7f4349c40bb9

feat(windows): add opt-in DualSense waveform audio hooks

Native waveform sinks need a Sony-matched four-channel audio endpoint that
Windows virtual controllers alone do not provide. Add per-app WASAPI emulation
and a helper that verifies hook readiness before game entry without a debugger.
Forward actuator PCM through the existing haptics transport. Direct native x64
launches are supported; native Windows gameplay remains unverified.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Medium

(cherry picked from commit b2126c332124d009ac752e8faf82dbac1423031a)

8be9df906fe6

fix(pyrowave): replace hybrid references with independent LZ4 compression

Keep the native coarse prefix and compress bounded independent detail groups. Remove frame references and ACKs, preserve partial-frame recovery and adaptive detail FEC, and fall back to native frames when compression is unavailable.

Validated with a Linux release build and smoke check, CPU compression/loss tests, four-format Vulkan decode and sustained detail-loss checks, ordinary framing/SDP/RTP/UDP tests, and exact reconstruction benchmarks.

(cherry picked from commit a88e04eb0fce195c11ef9514b70b06a23e9cc2fc)

5e4a4bd502b8

fix(pyrowave): fit stream traffic within the wire bandwidth budget

Reserve critical FEC, packet headers, audio parity and control traffic before
assigning the image budget so the selected bitrate bounds actual wire usage.
Cap negotiation and pacing at the slower known host/client link, and keep
runtime bitrate updates within that cap. Preserve coarse-data protection
when record padding cannot fit, on both Linux and Windows encoder paths.

Validation: full optimized Linux build with both web bundles; all 116 CTests
passed, including PyroWave policy and Linux GPU coverage.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High

(cherry picked from commit 1eb4b2997bf336e45b1d0bc5fac1eac64caf8a7e)

82a3bea805f1

fix(ci): scope native container Git trust to the verified workspace

The hosted Arch submodule checkout failed after checkout action restored its temporary Git configuration. Apply safe.directory only to that exact workspace and invocation, retaining the pinned SHA and rejecting wildcard/global trust in workflow contracts.

ebf8c8fac50c

fix(migration): preserve legacy haptics configuration parsing

Read DualSense haptics with the existing Apollo JSON boolean compatibility helper so legacy string values do not cause the application loader to discard an entry.

Generated with Codex (https://openai.com/codex/)

Model: GPT-6.1 Sol Ultra

ed0544d7aee4

fix(pyrowave): remove ineffective LZ4 compression transport

Remove the unsuccessful compression path and bundled LZ4 dependency so
PyroWave sends native frames without the extra CPU compression pass.
Retire compression negotiation while preserving framing, FEC, and wire budgets.

Validated with the Linux release build and all 116 tests, including GPU validation.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6-Astra Medium

(cherry picked from commit d1c93a155f540eb27061ae680d878689d0044559)

b0dc574e968c

feat(playnite): allow users to select the installation directory

When URI detection fails, users can select and save the Playnite directory in either web interface. Use that location for plugin installation and game/fullscreen launches while preserving installed and portable extension layouts.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit a67bda59748db6a8ea2271fa4c561f8c573da9ee)

2c637402d8a1

fix(pyrowave): enable Intel D3D11 encoder compatibility

The broad upstream interop probe rejected Intel GPUs for sharing modes the Windows host never uses. Check only the plane texture format and D3D fence imports required by the encoder.

Add Windows GPU encode/decode coverage for changing frames, both bit depths and chroma modes. Validated on Intel UHD 770 and NVIDIA RTX 4090; PyroWave policy and GPU tests pass.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit ff41bda9aa107990826d3ee0cf0a5d1c015c1902)

9cc098479a42

fix(ci): validate Linux packages with the verified nonzero source version

Preserve package downgrade protection and use each fork current source base with a validation prerelease suffix in both isolated hosted entry points.

cc66aaa11293

fix(playnite): support waveform haptics without launch deadlocks

Playnite waveform launches were rejected, and failure cleanup could deadlock all later connections.
Prepare scoped hooks before Playnite and 64-bit Steam start the game, refresh mappings on reconnect, and defer configuration writes until the launch read lock is released.
Require connector 0.4.15; seven focused validation checks passed.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 07589be637871884562a0c29fc135af6733fb7be)

45695fddaa85

fix(playnite): prepare Steam haptics from 32-bit hosts

32-bit Playnite could not load the 64-bit audio hook and cancelled game launches. Prepare Steam through the native helper instead, and install connector 0.4.16. Six focused checks and two live Steam preparations passed.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 6d8fc5acba69426441400536598be7b58c74eb0a)

b726e1c77664

fix(ci): fetch both pinned Linux driver sources before package configuration

The shallow initial checkout omitted DualSense source templates required by configure-only packaging. Fetch only libvirtualdisplay and libvirtualgamepad, verify their required files, and keep existing policy guards and package-source preparation.

589c4726c6f6

fix(display): retain virtual displays through capture teardown

Windows normal-display capture references were Linux-only, so app exit could
retire a per-client virtual display while encoder threads were still draining.
Hold RTSP and WebRTC references through their joins, reject fresh capture while
an ended display generation drains, and rearm retained-display recovery only
after Resume admission. Retire paused recovery at capture idle while preserving
live and Remote Monitor peers. Keep deferred Windows stream-start work pending
when the lifecycle gate is busy so launch-owned teardown cannot deadlock while
joining control polling.

Addresses Nonary/Vibepollo#413
Addresses Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Ultra

(cherry picked from commit 830b8187b0eaff31c7200f9d68770e4b5ede8f6a)

85009a8edbc6

fix(ci): honor signed installed GCC14 during Arch dependency resolution

Check exact compiler package versions, synchronize only dependencies reported missing by pacman deptest, then require the full dependency set to pass before fingerprinting the installed ABI. Exercise wrong-compiler, sync-failure and unsatisfied-version fixtures.

6e43b62c25b2

fix(hdr): handle live color changes without permanent HDR forcing

The session HDR override kept clients in HDR after the host switched to SDR.
Observe display color events with background polling fallback, fence helper
mutations, and finish optional HDR blanking before capture admission.
Publish HDR state after encoder readiness while preserving negotiated Main10,
per-generation metadata caching, and client message deduplication.
Adapt the lifecycle contract assertion to the current launch API argument.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 52e647330669d81f8b493c6cb6b69ac94cff35a0)

11b9eb37e900

feat(pyrowave): add paced UDP bandwidth calibration probe

(cherry picked from commit c1a9f5dfb78f8f4f63813004331596d5f28dd27e)

50f3644a664f

feat(playnite): port compiled connector from Vibepollo #513

Replace the script connector with the reviewed .NET plugin, bounded shutdown
and safe plugin updates. Adapt the payload and signing paths to Vibeshine,
while preserving waveform preparation, reconnect mappings and launcher acknowledgments.

Source: Nonary/Vibepollo#513, merge f1cf988fb35a2a4fa779a261c6d6c455d8010cae
Validated the release and plugin builds, both web bundles and all 121 local tests.

Co-authored-by: Noklef <281545466+Noklef@users.noreply.github.com>
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

(cherry picked from commit f6697e8971edf7d381c5ba4d69ddb266a0a9f7d3)

f2e90b37bba8

feat(display): allow up to eight virtual display clients

Remote Monitor was limited to four identities despite the driver's eight
slots. Share a bounded global client limit with normal streams and retain
existing owners when it falls. Count provisioned Linux managed outputs and
explicit connected physical/dummy connectors without duplicate or missing
names. Explain shared capacity in both UIs and deliver the eight-output
helper without rebuilding live four-output pools.

Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 5596183265edde9c6138f8eab5536dbd9f092695)

8adb446db819

fix(linux): admit client modes on all eight virtual outputs

The eight-output pool exposed connectors rejected by older four-name gates.
Admit exactly Virtual-1..8 in the host and SteamOS broker while retaining
mode and lease checks. Retire a capacity-rejected client's prepared connector
so rejected launches do not consume an extra output beside active peers.

Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 781c2b7fc4b07466d861eb46b26903900ea20aa4)

2b9941fc4908

fix(display): preserve Windows and saved client arrangements

Extended sessions overwrote VerifyOnly and reset client placement to the
right. Preserve CCD origins and active peers, and apply saved placement
rules only to the connecting target. Expose directional and manual
arrangement with previews; selection keeps saved rules while only actual
drags place a display and keyboard edits follow the focused client.

Addresses Nonary/Vibepollo#531

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit a4549a366ae60af36139ade51a72c0e27d493333)

c6811df7310e

fix(display): include the Windows topology capture declaration

Extended-layout requests capture the current display topology. Include its
owning integration header so Windows builds resolve the new call without
relying on unrelated transitive declarations.

Refs: Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 7bbf111bc90dcc3e97a1a40a596059683550556d)

1ae5297d9a9e

fix(display): retry authoritative golden restore after fallback

Primary-only session fallbacks renewed the restore cooldown on every
poll, preventing a golden-first baseline from restoring a returning
monitor. Retry the configured golden baseline immediately when its
devices return, while preserving the default session-restore cooldown.

Addresses Nonary/Vibepollo#518

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 52b8bf548898d2b232b34f6a3873a0713d1d278c)

ad89e80fd953

test(display): compare restored origin coordinates directly

The restore-engine component links only display-device headers. Compare
both restored coordinates to keep the cooldown regression's origin coverage
without requiring the library's out-of-line Point equality operator.

Refs: Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit c9b1f431ee04dfeef23173f480a9c8724945c8b1)

2f683820a81a

fix(wgc): cancel helper handshakes before capture joins

A pending WGC handshake could outlast the ten-second video join watchdog
because stopping the capture queue did not stop helper initialization.
Cancel only the retiring capture generation between IPC waits, including
anonymous pipe handoff, and release borrowed display references before join.
Keep healthy startup budgets and native teardown unchanged; add production
regressions for cancellation, resume, ownership, handoff and session isolation.

Addresses Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit cadef93fe106dbb5b31c9aa85a8778c5d27a4b09)

7f3027fe97c3

test(wgc): use native CRT string helpers on Windows

MinGW defines _TRUNCATE in the CRT, so declaring the portable substitute
breaks the anonymous-handshake fixture. Keep the substitute string helper
on non-Windows hosts and use the native CRT when compiling for Windows.

Refs: Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 59e4fa755ee75794b7c094002cc75c15327653b5)

1b16c599bbf8

fix(display): Preserve physical returns across recovery feedback

A powered-off baseline monitor can return during recovery or its quiet
period and leave an exhausted restore lease asleep. Retain that evidence
until settling and reopen bounded recovery only when an authoritative
physical baseline member becomes enumerable. Preserve existing backoff
and disabled outputs, and keep retired debounce owners from hiding a
replacement owner's display events.

Addresses Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit ef4c0e2dd109578154ccbee01e539d6c95006544)

a5076bfdea8d

fix(display): Honor golden-first recovery after session fallback

A confirmed session fallback kept rearming golden's cooldown and prevented a
returned baseline monitor from being restored. Explicit golden-first recovery
now retries that baseline while session-first keeps its cooldown.
Exercise the actual fallback and reopened recovery in regressions, and declare
the Windows test fixture's algorithm dependency.

Refs: Nonary/Vibepollo#516

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 8aa2abe3d600a99f4266d982e20a6720caff325d)

9dfab0bc09d8

test(display): Keep recovery assertions within component linkage

Whole-snapshot comparisons instantiate display-device equality operators that
these isolated test targets do not link. Use the existing fieldwise snapshot
comparison so the declared Windows source lists remain sufficient while
retaining full baseline and primary checks.

Refs: Nonary/Vibepollo#516

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 90cd49e46abaa180eb0f72c3e61a4042f39360b6)

85a21ca5621d

fix(linux): preserve child status and crash restore intent

Competing waitpid sweeps could abort app teardown while rejected rotation
arguments blocked KScreen restore. Reap only detached children, preserve
unknown exit status, and admit the eight supported rotation values.
Persist session-bound desktop state before hotplug and refresh idle intent.
Recover orphan connectors through capture-verified asynchronous restoration,
preserving intentionally disabled monitors when no safe baseline survives.

Addresses Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit a429aa68ce10f46e9f723386e15ed3bbdfbf4bed)

b36758365e5c

fix(linux): preserve idle layouts and bound group polling

Check the owned child first and bound positive process-group scans to avoid
adding procfs work to every control input event while preserving exit status.
Keep idle baselines unarmed, restore only acquired or orphaned displays, and
clear saved intent after verified recovery so later layouts stay authoritative.
Only uncertain mutating helper completion fences future display changes.

Refs: Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 691c40ba996d8e8e7ddd7022bc36ec7cd477fddf)

4dca376c3de3

fix(linux): resume marked restores after connector retirement

An interrupted handoff can leave the private connector gone while the final
physical layout and durable restore marker still need completion. Prioritize
armed recovery at startup before refreshing idle preferences. Keep fieldless
legacy idle baselines unarmed unless an active private output needs recovery.

Refs: Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 31b3bcf4cef762edba5de039d4128bb6e8a4ae2e)

695d98662f06

fix(display): preserve restore task opt-outs and explain recovery

User-disabled logon recovery tasks could be recreated enabled, and recovery
controls hid automation requirements or retained stale saved-policy gates.
Preserve disabled tasks and remove enabled legacy orphans without snapshots.
Show session snapshots, task state and helper engine in both interfaces.
Refresh snapshot and reset availability after settings saves without a reload
or implicitly starting the helper.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 8749cac09d6355d49a54c54fcd4530be7bc2b02f)

92cdd477b673

fix(i18n): preserve Apollo crash bundle descriptions

e563025001b9

fix(display): keep legacy recovery controls visible

Recovery settings became hidden inside a native HTML template. Render the
section normally even when automation is disabled, retaining its explanation.
Load restore-task COM headers after the Windows/Winsock prelude so Windows
release builds do not fail the include-order warning-as-error check.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit e9eb03244dc054ad300c949319b9b57747bca519)

aaef0ef7b903

fix(ui): allow retrying unavailable display recovery status

A failed status fetch disabled its own Retry action when maintenance was
unavailable. Keep read-only retries usable while retaining the existing
snapshot capture policy and blocking overlapping status requests.
Cover repeated status failures and recovery without mutation requests.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 1f41888cd5d465bcebb22ad5a8cdf86176aef43c)

6cbfc9fcd75b

fix(ui): share recovered display maintenance status

Retrying display status updated the snapshot card but left capture and reset
blocked by stale parent state. Publish each fetch's unknown or saved-policy
result to SettingsView so a successful retry restores both recovery actions.
Cover repeated failures followed by available and automation-off responses.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit c1b60490af085667b89084e7a1ca5b3a2ff46ff5)

75be816064fb

fix(linux): fit complete multi-output broker requests

Eight managed HDR-capable outputs plus three physical displays need
65 properties and exceeded both session helper argument caps.
Share a fixed 448-property budget for complete 64-output transactions,
retaining the 128 KiB frame, property allowlist and identity controls.
Cover composed requests and exact argument and byte rejection bounds.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

(cherry picked from commit 6d7c7dbca9fbc23781b277635d7e6bbbf34c00f6)

d2d6bdf47050

fix(linux): reliably restore desktop after stream teardown

Establish a verified saved scanout before retiring private connectors, wait
for each hotplug to settle, and strictly verify the complete desktop before
clearing recovery state. Keep failed cleanup recoverable, release drained
desktop ownership, and protect paused apps and retained Remote Monitors.

Resolve remapped mode IDs from current catalog semantics and use bounded,
noninteractive Wayland readiness probes. Rearm failed preparation cleanup,
preserve unpublished admitted connectors, and permit supported rotation
tokens through the session broker.

Validation: 205 regression tests under ASan/UBSan, 39 under ThreadSanitizer,
broker policy checks, and affected production translation-unit compilation.
Live physical-monitor validation remains outstanding.

(cherry picked from commit ce6d9e8588a33242891065c8acde00bb4001bfa4)

9e0f393e2c0e

fix(display): verify snapshot modes before saving restored layout

Use exact temporary mode restoration in both helpers, wait for the full legacy topology, compare rational refresh rates numerically, and retain current snapshots after previous-tier recovery. Pin libdisplaydevice with corrected topology and validation flags.

Validation: eight portable regression tests passed. Windows mock tests and physical 120 Hz retention remain unverified on this macOS host.
(cherry picked from commit 4225211b8e13e1a6ba59276ce9fef8d3b4514eab)

7b07ab767e8f

docs: describe durable Linux restoration intent

adfa63d1402e

fix(linux): honor explicit capture methods for virtual displays

Prefer KMS for automatic virtual display capture, preserve explicit backend selections, and align service overrides, UI warnings, documentation, and policy coverage.

(cherry picked from commit fd9b59ff15918dbd69ee7c7ae666266968309b4b)

a176cb7b9966

test(display): use valid modes in snapshot fixtures

Give the shared fake snapshot a positive resolution and 60/1 refresh rate so the updated display library can compare it. Preserve every existing assertion and the production rejection of invalid refresh rates. All 103 state-machine cases and the snapshot/restore targets pass against the exact producer headers.

e212a4a8d872

feat(pyrowave): advertise critical FEC overhead to paired clients

Expose the configured critical-block parity percentage in serverinfo and document how client bandwidth calibration accounts for parity and wire overhead.

(cherry picked from commit 4b2ba5fc07c2fa075430234a15005aac4d4f939a)

c078a2dbc954

test(input): add host-only virtual gamepad lifecycle probe

Add a standalone Windows controller creation and teardown probe with HID and XInput inventory, explicit destroy and owner-close cleanup, and reproduction instructions for Steam and SDL tracking.

(cherry picked from commit 19e80502ff2327437d1036aba1a3181fac71818f)

1e2338e8b275

fix(linux): skip automatic portal consent after KMS selection

Prevent automatic managed KMS startup from opening an interactive portal probe. Explicit portal capture remains allowed, and X11 fallback enumeration is preserved. Cover the capture policy with four hardware-free regression cases.

ad3a2a54f44c

Fail Linux component builds early and reuse verified package sources

Declare the routed-link Boost.Asio interface, compile configured component targets before host and CUDA work, seed validation sources from the exact verified shallow checkout, and retain only verified dependency/compiler cache work after trusted manual build failures.

dad32b95f442

fix(display): ship the wide-gamut HDR driver correction

Pin the corrected libvirtualdisplay source and v1.6.4 Windows package so
installed virtual displays advertise BT.2020/D65 for HDR. Keep SDR EDIDs
unchanged; client image-quality acceptance remains pending.

Addresses Nonary/vibeshine#270
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit 757a3657ad91344222bc68acbdb235c3b0a425a8)

41ce9c1c5f17

fix(audio): Retain role recovery after visibility failures

Steam visibility failures discarded captured role recovery before disconnected
HDMI endpoints could return. Keep guarded direct restoration after a failed
fallback, including the endpoint selected before a failed show. Retire roles
changed during the visibility RPC while retaining recovery for other roles.
Preserve newer defaults, successor ownership and shutdown cleanup, with
production-function coverage for return and failure ordering.

Addresses Nonary/Vibepollo#470

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 9f8aabeeb0b8d6d548845ea75458bd2f3b62e85c)

12e939847908

fix(hdr): Ship the Vulkan layer for 32-bit Windows games

32-bit Vulkan games miss HDR formats because the released payload contains
only the x64 layer. Build the x86 layer from pinned source during package
refresh, validate its exports and architecture, and include it in MSI signing.
Register and check each manifest in its own registry view, preserving other
layers and removing partial registrations when disabled.

Addresses Nonary/Vibepollo#418

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 4f02a037372ec0e96cdccda7e33094332c216c2e)

0e1c6b4bc654

fix(input): Bound Windows desktop recovery and own bindings

Persistent injection failures could retry indefinitely as desktop handles
changed, blocking the input worker. Retry once after successful attachment,
retain the assigned handle, and release superseded bindings safely.

Replay eleven production-source scenarios; seven fail before the repair.
Physical-monitor game window disappearance remains a separate unresolved cause.

Addresses Nonary/Vibepollo#415
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit c5e1cd731230746e10e31ace74d6baeeb2b6217e)

fd0aa245009e

Model early component validation in the CUDA policy fixture

Stub the external component helper explicitly and verify configure, component and full-build ordering while retaining private CUDA and Pascal assertions. Normalize fixture paths so the same policy checks run on Windows and hosted Linux.

20c3d2eea972

feat(windows): make automatic service startup optional

The installed host lacked an app control for automatic Windows startup.
Add authenticated startup toggles to both maintenance interfaces backed
by the fixed own-service configuration. Off selects Manual, preserving
manual launch and current sessions; report actual mode and permission errors.

Addresses Nonary/Vibepollo#411

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 235a32e495dfe3e374244d0fc3af04e1ed31f737)

859d64a22435

fix(kms): read AMD virtual frames on the physical renderer

Display-only KMS cards cannot initialize GL readback, and their advertised
RA24/BA24 framebuffers were rejected by the linear upload fallback or sampled
with the wrong Vulkan channels. Use the selected physical render node for
software capture and preserve packed RGB/alpha ordering in both conversions.

Addresses Nonary/vibeshine#291

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit 3e8cfdc0c6ff55ba3f055ae4d5914429c52bc2d8)

b19e08ee8b80

fix(input): preserve Xbox client profiles on the VHF backend

Xbox-type clients with motion sensors or touchpads could become DualSense
controllers under VHF, disagreeing with ViGEm and Steam's expected handling.
Honor the client-reported Xbox type before capability preferences while
preserving explicit overrides. Exercise the shared production selection
policy for plain VHF and Automatic fallback in regression tests.

Addresses Nonary/vibeshine#286
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit cbe1f348a73a75923ecf8f6d2d736598adda88ee)

7405eedf3849

fix(display): recover legacy layouts after broken connections

Recent display-helper disconnects discarded restore intent, allowing
liveness-only reconnects to leave an old layout armed for later login.
Retain recovery until a live stream renews its deadline, reject stale
owner pings, and preserve that deadline across repeated disconnects.
Let disabling automation finish cleanup without bypassing display owners.
Cover recovery, ownership and disabled-policy regressions.

Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit 1594f8a7e5e27055594919f6bb3655561687c5e2)

f0a360a02a33

merge(prerelease): reconcile display recovery on vibe-test

Preserve both local and remote prerelease improvements while integrating
the legacy recovery fix. Keep durable desktop snapshots and eight-output
support alongside the newer guarded restore transaction and HDR colors.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit f0fb1ea585efc17ece16811c741854bcd0945991)

8f2542d2ef50

fix(linux): preserve console rendering on multi-GPU hosts

The bridge's PCI spoofing and ambiguous NVIDIA selection could break Virtio
console output and leave private displays unavailable. Pin the isolated GBM
route with a stable PCI default, early SHM import safeguards and truthful PRIME
layout metadata. Reject CPU fallback for managed unknown layouts rather than
reading tiled storage as linear; keep native and explicit linear fallbacks.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit e42f9ae462be157ef3bf12c0cf8e8b319b1666ed)

bfad5a255138

fix(linux): admit globally numbered private display names

A Virtio console can consume Virtual-1 before the managed display pool.
Pin the explicit DRM-to-configfs mapping and admit valid global connector
IDs for requested modes, while the broker verifies actual pool membership.
Cover shifted names without expanding the pool or guessing an offset.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit efc8c77ba5b955a57ebde0b40fe7af750bd4b05c)

89a2b3bf2b55

fix(steamos): share managed connector mapping in the local broker

The local broker shadowed the shared handlers with fixed connector IDs
and public-name lease paths. Shifted DRM names could connect one pool slot
then request modes on another. Inherit the canonical mapped handlers and
cover sparse public names, logical leases and cross-user mode rejection.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit d9e54d8b57ab2dde10ad758463b874d4faab2d33)

1934cd8267dc

Declare display helper component Boost and JSON dependencies

(cherry picked from commit c98b7c5422853db362c76242ac6d49a5c447fe0e)

9038cb0d386c

Compile fast policy targets alongside component tests before Linux packaging

Discover both configured test categories through the CMake codemodel while keeping the required routed-link gate and excluding unrelated app targets.

(cherry picked from commit 6ea72f0dd1ccc1ed8e593cd29196592620b3f390)

4996c9f70deb

fix(linux): make filesystem validation locale-independent

- stop comparing localized stat %F strings
- use -f/-d/-S for object type validation
- retain stat only for ownership and mode
- use C.UTF-8 for machine-host child processes

(cherry picked from commit 36dd4caa378f8560fda94267d37967d36184d0d0)

0f4986a3d534

fix(steam): normalize Pressure Vessel /run/host Proton paths

- translate /run/host/... metadata to host namespace paths
- apply normalization to Proton and Steam client paths
- support system-wide CachyOS Proton direct launches

(cherry picked from commit 845beffcc32457955c825661c65d818976dd0330)

d50e84b674b3

fix(linux): skip read-only Proton tools for global policy injection

- don't try to write hooks into root-owned compatibility tools
- keep user-owned Proton tool injection unchanged
- report skipped tools instead of PermissionError

(cherry picked from commit 99e137e81c7b58aef25a7f8d2fb47548733c5a8d)

323eed1f4814

fix(packaging): verify installed private host capabilities in installer

- assert private host executable has cap_sys_admin,cap_sys_nice=p after install
- prevent unsafe executable status when host capabilities were not applied

(cherry picked from commit 6f417283999c42ca231ac4332a622e575401b832)

3d074f1a9955

fix(display): serialize remote monitor teardown

Keep display ownership alive through capture joins and close WebRTC before
topology cleanup. Fence monitor generations across rejected activations,
reconcile deferred releases, and retain failed native cleanup for retry.
Drain WGC frame callbacks before releasing capture-manager resources.

Refs: Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Luna High

(cherry picked from commit b35e9d1b69fb42fda05ba07c3c76500e1ec1f204)

364c39c9ffbe

merge(prerelease): add capture-safe display teardown

Retain display ownership through capture teardown, fence stale monitor
requests, and drain WGC callbacks before releasing capture resources.
Preserve the current configurable capacity and Linux idle-cleanup policy.

Refs: Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit fbbd99073406f1a09ed132e78736261eb27f57c0)

caeae58070f7

merge(prerelease): accept Linux hardening from PR 302

Merge the contributor's locale, Proton path and packaging fixes into vibe-test.
Reconcile the stable fixes already in the PR ancestry while preserving newer
wire-budget handling, display teardown and application focus behavior.
Update metadata fixtures and retain unsafe Xauthority rejection coverage.

Closes #302

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit a1e0142043faaffa16b6c9729917e4e60a8c2585)

b3e33b89e87d

ci(windows): opt in to compile and run tests without daily signing

Expose a default-off build_tests input on artifact-only Windows validation
and forward it to the reusable build. Execute CTest whenever tests are built,
with empty suites and test failures blocking success. Keep daily artifact
signing gated solely by daily_unsigned and pass no signing secrets from the
validation wrapper.

Add a workflow regression fixture for compile/CTest input alignment, hosted
artifact-only defaults, and independent daily signing guards. All three
fixture cases, actionlint, and whitespace checks pass. Full hosted application
compilation and CTest execution remain pending; no local machine changes ran.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 19a4165016aaa3de3ade55fa24eba5a4f334c7e6)

5023aeaec033

fix(linux): recover machine setup after locale and cwd failures

Valid machine profiles were rejected when service-account commands inherited
an inaccessible caller directory or metadata checks used a translated locale.
Run those commands from / and stabilize native package lifecycle checks.
Retry machine setup in the installer, including older-controller locale recovery,
and stop on failed recovery while preserving existing profiles and pairings.

Addresses Nonary/Vibepollo#514

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 3eab003539596881446922c7ffb1619a23c23f22)

749f39b0045c

build(gamepad): ship the DualSense identity fix from beta.7

Pin the released driver 0.1.0.48 so GameInput and HIDAPI identify the
same virtual DualSense. Keep the source, archive checksum, CI, installer
checks, and bundled payload aligned with the verified beta.7 release.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Low

(cherry picked from commit 73b28e555cd7cff6205d837f5bf7c797bdf823f4)

35812b130436

fix(pyrowave): establish UDP return paths before calibration

Windows streaming works through outbound UDP exchanges, but calibration
previously sent unsolicited packets to a fresh receiver port. Announce the
sender port over paired HTTPS and verify the client's UDP token before the
measured transfer, without firewall changes. Bound the handshake and exclude
warmups from results while preserving legacy clients.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High

(cherry picked from commit a2c548d1faaff16223b88109aafb78b9f675040c)

2e808e48e13c

fix(linux): exclude virtual outputs from monitor restore snapshots

Retained streaming outputs could become the saved desktop and prevent TV
restoration when their requested modes changed. Keep new and legacy restore
snapshots physical-only, require a physical restore guard, and retire virtual
connectors even when older snapshots included them, matching Windows behavior.

Validated by a full build, 134 passing tests (one skipped), and user-confirmed
TV restoration after native installation.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 8ff20328ed83d7e18db1d9ca63344c8cf33146ce)

3c636bd7fc1b

feat(display): add the virtual display killswitch on Linux

Linux hosts lacked the UI and API recovery action available on Windows.
Expose confirmed termination in Maintenance, attempt physical layout restore,
and disconnect every managed kernel output despite active ownership.
Verify removal and report restoration separately while preserving mutation fences.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit c3bf29e52715d9bca3c77c9ad2fe95a5953ade30)

5909a15489ef

fix(ui): retain Apollo identity in Linux recovery text

c219f2c0b4ba

fix(display): honor refresh overrides and older Windows limits

Match refresh mappings against stream FPS before automatic promotion so
60 FPS sessions can advertise and apply explicit 480/1000 Hz modes.
Resolve creation, apply and recovery consistently, preserving fractional
rates and capping pre-24H2 Windows modes at the resolution's 1 MHz scan limit.

Validation: Linux release build and both web bundles passed; 135 tests
passed, 2 skipped. Windows build and live streaming remain unqualified.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit e5481d5d58c74a05f7c0fa03c844678d0c772bd4)

909a5855a183

fix(ui): restore a focused Everyday settings workflow

Everyday buried Vibeshine's distinctive features among generic controls.
Put virtual screens, smoothness, PyroWave and Remote Monitor together,
with pacing integrations, visible library links and grouped tuning.
Correct Windows limiter choices and FEC bounds while preserving old drafts.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 67c17bfdd4f19309538b62d8f555110f073e4b54)

1b7f3166eb52

fix(display): terminate remote monitors despite restore failure

Disconnect Monitor must remove its Windows screen even when the remaining
display topology cannot be restored. Use exact-owner native termination,
retain capture and peer ownership guards, and report removal failures.

Refs: Nonary/Vibepollo#568

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit 748b53db57b248e89bc8d27677d747a1e173f2c2)

c0321beaee86

fix(ui): complete Everyday parity and Apollo text resolution

be452d2cceb9

ci(linux): cache only the verified CUDA installer

Caching the full CUDA SDK plus installer exceeds the standard shared cache budget. Restore and save only the pinned installer under a new cuda-installer-v2 key, with no fallback to SDK archives. Each fresh job still installs and patches the complete CUDA 12.9 toolkit.

Exercise checksum rejection, two fresh toolkit jobs, unchanged trusted-failure eligibility, and final Pascal/CTest/package gates. Keep the prepare helper, package recipe, and release validation unchanged.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 708a2e0362ff81ab6b2570dc3fcd898925e47c2c)

3a1e77da777e

fix(ui): remove duplicated migrated Everyday groups

ad99106947a5

fix(display): preserve exact Apollo stream refresh at policy boundary

9706c690c06c

feat(input): emulate wired USB DualSense haptics on Windows

Expose controller and audio interfaces together so games can send native
waveform haptics through the existing Moonlight feedback path. Add an opt-in
installer component using unmodified, verified usbip-win2 drivers; preserve
shared installs and wait for HID/audio readiness before per-app launches.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

(cherry picked from commit fef077c021b56430ac41366d2f1fcf1eb135e142)

c0167e201275

feat(ui): add dashboard virtual screen recovery

Make emergency recovery reachable when a virtual screen leaves the PC blank.
Add a first-visit guide and confirmed dashboard action, removing virtual
outputs before trying the saved layout and a connected physical monitor.
Validation: Linux build, 33 browser checks, and 10 targeted policy tests.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

(cherry picked from commit 7af5c387b63df8ff1fcc7b55a1bfb29fc946bc4a)

abf7c00cd699

feat(display): recover orphan virtual screens on monitor events

Stuck virtual screens can survive failed desktop restoration. Use monitor
wake/topology events to recheck failure and remove only captured orphans
when physical output is verified and all display owners are gone.
Keep recovery tied to its session and generation without periodic probes
or time-based expiry. Preserve the current physical desktop layout.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

(cherry picked from commit 13c99d514f2c9c933a1cefea3a7988da47368adf)

2772fc128021

fix(web): remove inert legacy Playnite extension directory default

The source migration replaces the old extension-path editor with playnite_install_dir. No backend reads playnite_extensions_dir; retaining its dead serialized default breaks the dynamic legacy/v2 settings parity contract. Keep the real install directory and extensions_dir response metadata.

Validation: actual settings behavior tests pass all 12 cases.

151a05e3ed9d

fix(web): scope display recovery guidance to Vibepollo

Keep Apollo first-visit recovery guidance independent from a Vibeshine dismissal at the same browser origin. Shared driver/protocol identities are unaffected.

Validation: actual utility storage read/write passes against isolated localStorage; independent batch 23 review finding.

d0c26b3db88e

fix(hdr): wait for display setup before starting capture

Capture could probe HDR during the helper's temporary SDR window.
Require verified display setup before launch, resume, and WebRTC
capture, then follow real HDR/SDR changes through normal reinit.
Remove mutation fencing, frame holds, color generations, and settling timers.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

(cherry picked from commit c2a651beebd28190474adf595ea805a3928b06eb)

5ccf1b761936

fix(web): expose the Linux display picker description

Historical Apollo import 35571f969 added the modern source description but left a later fallback key shadowing it. Remove that preexisting stale duplicate and four identical driver-key repetitions without losing any unique locale path or offline guidance.

Validation: exact f007/source68 path-aware audit preserves 2170 unique leaf paths; zero main English duplicates remain; only effective picker description changes.

08f8ed337230

fix(hdr): preserve driver-owned calibration profiles

Host profile edits competed with the Vibeshine driver's retained calibration.
Leave those associations intact while keeping explicit assignment for SudoVDA.
Prevent rejected activation from leaving registry-only profiles, avoid duplicate
activation, and remove UI guidance requesting redundant client assignment.
Validated the full local build and CTest suite: 154 passed, one skipped.

Refs #301
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit 306d11d1707928da43a1d7798da62e3b5050f54f)

062e37277af6

test(playnite): isolate SDK discovery hints inside the CMake fixture

Clear DOTNET_ROOT and ProgramFiles in the generated CMake child script before
running unchanged production discovery. Windows may retain its well-known
ProgramFiles environment value despite a subprocess override, allowing a
host-installed SDK hint to mask the fake PATH SDK and fail the exact-path test.
Remove inherited case variants before setting child environment values and
include expected/found paths in the failure diagnostic.

Preserve PATH, empty-cache, and explicit discovery cases plus compiled upgrade
and filesystem cleanup policies. A temporary competing SDK reproduces the
original failure; clearing hints restores the exact PATH result with both
MSYS2 and native CMake. All full fixture checks pass with both tools and the
actual UCRT64 compiler. No production code or machine configuration changes.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 6acc22f63402a9e16d8fe6d37cff2cf1472063b0)

9c73ad9421d4

docs(release): document 2.0.0-stable.1 changes

Explain the stable delta from 2.0.0 with user-facing outcomes and setup details.
Cover display recovery, controller haptics, HDR, PyroWave, and Linux fixes while
excluding withdrawn experiments and intermediate prerelease fixes.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

(cherry picked from commit 9f7fbdd1a05b89e084d1a7574895e48ec5d346d3)

6f0ddcb024a4

fix(hdr): Preserve driver calibration without monitor metadata

A permanent Sunshine monitor selected through the physical output route could receive a client profile when optional enumeration failed or omitted its identity. Recognize the resolved default driver hardware-ID families before enumeration, preserving physical and SudoVDA overrides and the existing custom-metadata fallback. Add policy boundary tests and regressions extracted from the actual production guard.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra
(cherry picked from commit 508da3612fe59fe27275756d9267dfce5929d471)

7d39c6905223

fix(display): keep locked desktops reachable during setup failures

Mandatory display setup rejected reboot and lock-screen connections with 503 before users could remotely unlock Windows. Continue launch, resume, and WebRTC with existing display settings when setup fails or times out, and preserve deferred setup across app startup for retry after unlock.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 9ab0b3132abfe0b3768c3f46580b0979082fef74)

29ba3febe73e

fix(webui): keep the interface responsive while streams pause

Display capability discovery could block the HTTPS event loop and keep the UI loading while a paused app retained its display. Isolate metadata work, open the UI after authentication, and let stalled status requests time out and retry. Remove the dashboard metadata wait and cover startup and recovery with a browser regression test.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 1647ef50309f67f911c7f87520f1cf2d50285149)

52d1a2c5a02c

feat(input): boost DualSense haptics while preserving contrast

Make streamed haptics easier to feel without hard clipping or flattening waveforms.
Add configurable strength lift on Windows and Linux, preserving actuator peak gaps with recent-peak headroom control and per-controller smoothing.
Keep 1.0 as unchanged output and support per-client overrides.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol X-High
(cherry picked from commit 91d4c5917d1ed1f557350adc44938ae7dbb98360)

a462e6393792

fix(input): preserve DualSense audio across Moonlight pauses

Disconnecting the virtual controller invalidated the game's haptics audio endpoint. Honor Moonlight gcpersist by retaining the composite DualSense while the app runs and rebinding feedback on resume. Release retained devices when the app ends and preserve teardown when persistence is disabled.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 19f4527c3ebaf5b650a905818a77058e6830bcb3)

0883f8ca3f8a

feat(pyrowave): Calibrate pacing with frame-shaped UDP probes

Negotiated link speed can exceed what a receiver absorbs in video bursts.
Add frame-shaped probes and client-calibrated pacing, using 80% link headroom by default while accounting for stream demand and wire overhead.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 68f381b0396abdf300eb6a5a5ae748ecd0299ac7)

e2b8c3505f0f

fix(stream): Bound UDP retries and account for failed frames

Socket pressure must not block streaming or silently leave holes in frames counted as delivered.
Bound nonblocking sends, stop failed fallback sends, preserve sequence reservations and traffic accounting, and limit failure logging.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit ec427d602085a8eb5706269976d96f9a3972a2bd)

5846a78671c6

fix(input): Use USB audio for automatically selected DualSense

DualSense waveform haptics need the composite audio function outside application opt-in scopes too.
Select it when DualSense is chosen and the transport is available, retain client capability checks, and keep diagnostics quiet.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 74d38edf022f98f7f4d01fe3564d6456e8143d1b)

374e88101a72

fix(dualsense): Locate readiness by USB host and imported port

The released USB transport can generate instance IDs that do not match the requested serial.
Find the controller under the opened host and imported port before checking HID and audio readiness, avoiding unrelated devices.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit a12c83debc4b7f2704c5c28627de5f528fc2570b)

71bb84b72091

fix(display): Correct helper linkage and include x86 HDR manifest

Display cleanup helpers need external linkage and the Sunshine identity helper needs its namespace qualifier.
Correct both references and include the x86 Vulkan HDR manifest already required by installer and packaging contracts.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit af13dd441d3114646b41b011d4a5e2eefc46686c)

4a494ccc4bbb

fix(deps): Update virtual gamepad report and initialization fixes

Use the virtual gamepad fixes for deferred HID report ownership and quiet Switch controller initialization.
Advance the submodule to the two dedicated driver fixes without including local test-signing payloads.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 68f38d8b5c37c7c06817698c0c91f872f70c3325)

e704d1ddf467

Default to verified prerelease notifications and preserve stable-only choices

Adapt the host updater to Apollo's package names, repository, paired-state
storage and both Web UIs. Enable prerelease notifications only when the setting
is missing; preserve explicit opt-out, interval-zero suppression, forced retry,
session lifecycle, exact release links and existing macOS architecture support.
Share one verified release selector and dismissal identity across both UIs.

Include the reviewed tray ABI correction before the first reviewable updater
commit: OS notifications carry the captured exact release URL in text with a
null callback; Web release links remain clickable. Preserve delivered-history
suppression and save state after releasing the notification lock. Keep pairing
validation intact and persist destination history before clearing migrated
source keys, including failure recovery.

Register the actual policy, history and production tray regressions. Preserve
standalone assertions in Release builds and isolate mocked browser requests
from external network access.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra

Additional-source-correction: d50046c73d81ac5d60903e33b29c52c3ed7ffeed
(cherry picked from commit 57fc027ee71594d909f0df1cee5c4c64fe493c6b)

ad02a61834d7

test(updater): match release fixtures to the build platform

Linux CTest rejected the standalone harness Windows-only installer before comparing stable respins. Supply the real build-platform package family and architecture in fixtures while preserving production completeness and version-selection policy.

Cover stable respin ordering, older rejection, wrong-platform and wrong-architecture assets, empty or pending packages, and missing nightly checksums. Keep assertions enabled explicitly and reject assertion-disabled harness builds.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

Adapt the regression fixture to Apollo package names and retain its existing
macOS architecture compatibility. Preserve the real production selector and
the registered Release assertion guards; add the reviewed stable-respin and
incomplete/wrong-platform package coverage without weakening policy.

(cherry picked from commit 8383852aceadf7acf7cf1722089fdecaa03972b0)

15ee1ae960cc

Preserve the reviewed Apollo daily validation chain after the core migration

Merge the independently reviewed CI, installer and Linux validation changes
after the complete source-primary migration and corrected Apollo updater.
Retain the original eighteen candidate commits and explicitly reconcile
the installer consent/USBIP controls and Windows producer configuration.

Keep hosted runners, signing-independent test validation, version-first
driver safeguards, exact-certificate consent and Apollo package identity.
Preserve all updater registrations, recovery behavior and x86 Vulkan/AMF
validation. Atomic producer reconciliation and combined build qualification
follow this internal checkpoint; daily publication remains disabled.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra

a87701e6e340

fix(display): verify the reviewed producer source and payload

Lock the v1.6.4 archive, evidence, source revision, actual INF DriverVer and every producer file. Reject changed fresh downloads and unverified caches before package refresh, including explicit prebuilt roots, while preserving the later Linux source pin and installer trust policy.

Validate with mocked fresh/cache tamper tests, Windows PowerShell 5.1, the mandatory driver safety suite, read-only public artifact fetch/cache verification, actionlint and the CMake lock declaration.

Apollo adaptation: Preserve Apollo x86 Vulkan, AMF, ValidateOnly and recovered Linux display source1b852. Restore the shipping gamepad gitlink to the audited beta.7 producer9edbce11 with its existing matching archive/DriverVer/protocol locks. Driver-only7f8d23fc and a7389b46 remain deferred until a real tested producer increments DriverVer above0.1.0.48.

(cherry picked from commit 824099413c4cb92d668361801e2385b008ebb935)

af094ba95425

test(packaging): expect the audited libvirtualdisplay v1.6.4 release

Correct the stale typed contract expectation without changing the producer lock or runtime policy. Verify the exact reviewed source revision, archive hash and INF version, and evaluate the real CMake contract against the same release.

Validation: two focused provenance tests and git diff --check passed. No driver, trust or installer operations ran.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

Apollo adaptation: Retain the audited Apollo Windows display1.6.4 source/digest/component contract and align the actual typed fixture without weakening assertions.

(cherry picked from commit 78660a102ec51119893d35fc02cd8dc69e85161d)

b94be0f3315b

test(display): preserve Boost headers in wake recovery fixtures

Direct Python compiler calls lost the modular Boost include requirements, breaking the observer and its mandatory backend regression. Pass the evaluated Boost::algorithm header closure through both fixtures without changing production code or assertions.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

Apollo adaptation: Preserve Apollo wake-observer and recovery behavior while declaring the evaluated modular Boost algorithm include interface. Keep updater registrations and Release assertions.

(cherry picked from commit 1959e585676ab819e85fe833887d3eddfce333b0)

5d72c24a7a3c

Declare the DualSense component Boost Format interface

Link the production stat-tracker header dependency explicitly and verify the pinned modular Boost headers with positive and missing-interface compile probes.

Model: GPT-6.1 (medium).

Apollo adaptation: Declare the direct Boost format interface for the migrated DualSense component, retaining the real modular positive/negative header fixture and all existing target interfaces.

(cherry picked from commit 46dbd6ada217fdccc2bfeaddd41b401fbf7683f5)

615b83d65f6f

Match configured-adapter regression to the actual snapshot routing

Keep configured physical-adapter and no-substitution coverage while checking the actual physical.display_names predicate argument used by both backend functions.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra

883b63209422

test(display): use valid modes in snapshot roundtrip fixture

Zero-initialized refresh rates fail the pinned mode-verification equality contract, so the storage roundtrip test failed despite preserving its data. Supply valid 1920x1080 at 60/1 modes for both displays while keeping every assertion and production check unchanged.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 5d4b7a53e45450dee0cee96169910f046a2ae1cf)

284ce200073b

Keep the UDP probe measurement open until its fixed deadline

A Windows timer can return early from the final wait, producing a measured
probe window below 2000 ms even though all expected packets were sent. Recheck
the original steady-clock deadline after each return through the existing
injected waiter. Do not restart the duration or change packet pacing, retry
budgets, handshake validation, burst scheduling, or overload bounds.

Add deterministic fake-clock coverage for repeated early returns, completed
deadlines, and waiter exception propagation. Preserve the original elapsed,
packet count, sequence, token, and pacing assertions.

Validation: the unmodified native loopback test reproduced 1999.4009 ms on
iteration 4 of 5. The corrected Release native suite passed all 9 GTests,
and the unchanged paced loopback regression passed 10 consecutive runs.
Compiled with GCC 16.2 and -UNDEBUG using cached Boost/GTest dependencies.
Full hosted application validation remains an integration check.

Source-first implementation based on 0ea017a8db1b653921e73a3ee45f1d5506c7fbb4.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 92b51649ae43547dd6a081af607fc2e95618202f)

e574025fe572

fix(web): Accept CRLF checkouts when verifying design tokens

Windows Git checkouts convert the generated token files to CRLF, causing check mode to reject otherwise current outputs. Accept that checkout conversion only during comparison, preserving strict content checks and the existing LF generation and print behavior.

Exercise the real generator in isolated fixtures covering equivalent line endings, genuine drift, missing files, unchanged check/print inputs and deterministic generation.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra
(cherry picked from commit 489fffa883d5d027cdb56636babe9c86af3898be)

637672d327ba

Keep legacy updater link checks independent of decorative icon labels

Match the final Download and Release Notes words within the update notice, require one link each and retain exact Apollo release URLs and all ordering, dismissal and reload coverage.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra

394a2795d124

fix(web): keep Apollo compatibility settings within narrow forms

Restore the missing compatibility labels and constrain their layout so the Add Application page reflows at 320px without horizontal scrolling. Preserve the unchanged browser viewport assertions.

55aa86240ea2

fix(ci): reuse one pinned nightly gamepad signing identity

Replace per-run certificate generation with scoped encrypted CI inputs and an exact public thumbprint. Reject invalid or expiring identities, export only the public certificate, and retain consent, producer provenance, numeric driver-version and no-trust-mutation contracts. Two actual disposable signing passes reused identical certificates.

(cherry picked from commit d641a8fa235ac831d38fd01b6969afc2385a4d33)

7e24ae17f85a

fix(build): remove obsolete Apollo display session helper

8c3a44da5266

test(video): bound readiness shutdown extraction to its admission block

(cherry picked from commit 43505570675a39244628271afc1d0e26b456678e)

379817e3c8ac

test(playnite): retain the selected SDK framework during restore

(cherry picked from commit 84ed23f6a1e9d4089cafe86c528cbddc41ba8407)

0dcec31a5d89

fix(test): declare Apollo colorspace JSON header dependency

6d5c0295bf25

fix(ci): align certificate identity checks with the persistent nightly signer

(cherry picked from commit 94315bea114ac57be326940fa6cb40ecf3c1f9aa)

254623617451

fix(test): propagate Apollo JSON headers to the USB/IP backend fixture

ee47da91ac27

fix(test): supply replay dependencies and product-scoped helper fixtures

(cherry picked from commit 1fd1ecbbe610556814e53540acaa0f90e335909c)

a48b9c0292c4

fix(display): synchronize dispatcher shutdown with idle waits

Protect both stop predicates with the corresponding condition-variable mutex to prevent shutdown losing its notification. Exercise 1000 idle shutdowns under a bounded component timeout. Preserve the shared helper directory when redirecting Linux lifecycle fixtures.

(cherry picked from commit 5ade938d15fb59a14bb42014e6f8e3e4d2dec1ce)

db35f052a36e

fix(test): stage owned units for Apollo lifecycle retirement

Run the existing boot-link retirement guard against fixture-owned unit files and obsolete links before locale-sensitive configure/start checks. Keep the production guard and every lifecycle assertion; assert that the obsolete fixture links are removed.

0d62c962e081

fix(ci): fetch full ancestry for nightly version resolution

Don't miss a new Vibepollo release

NewReleases is sending notifications on new releases.