This is a nightly release of Vibepollo and contains several bug fixes and may contain new features. Check the commit log for more information.
Windows installer · Linux (Arch x86_64)
Nightly Windows installers are unsigned and include self-signed gamepad components. They may cause false-positive antivirus alerts.
Source: 0d62c962e081
Since the preceding stable release Commit log
2.0.0: compare exact sources.
feat(plugin): Converted powershell plugin to C# DLL
Copying Vibepollo version over to Vibeshine
- From `Noklef/vibeshine/tree/playnite-plugin-conversion`
fix(plugin): Rename references to Vibepollo + copied re-wiring of plugin processes from vibeshine repo's PR
fix(playnite): restart Playnite for plugin updates
fix(linux): allow display rotations through session broker
fix(steam): use content-hashed portraits for newer apps
Newer Steam apps cache their portrait as
librarycache/<appid>/<hash>/library_600x900.jpg and publish it on the CDN
only under the same <hash> directory. Discovery only looked for
library_capsule.* in hashed directories, so it fell through to the
460x215 library_header.jpg, and the fixed-path CDN fallback returned 404.
Discovery now also accepts library_600x900.* in hashed directories, and
when the fixed CDN path is missing the artwork sync retries the CDN under
the local file's 40-hex hash directory.
Fixes #554
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
fix(playnite): make plugin shutdown and upgrades reliable
Prevent late connections and queued UI work from surviving connector shutdown.
Allow Playnite to finish closing before replacing its loaded plugin, while
keeping forced cleanup bounded. Restore SDK discovery and legacy upgrade
visibility, with regression coverage for lifecycle races and exit handling.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
feat(playnite): replace PowerShell connector with compiled plugin (#513)
Convert the Playnite 10 connector to a packaged .NET plugin while preserving snapshots, game status and launcher handoff. Fence connection admission and queued UI work during shutdown, give Playnite a bounded graceful exit before plugin replacement, and restore SDK discovery and legacy upgrade visibility.
Validated the .NET Framework plugin build, both production web bundles, the local release build and all 128 CTest tests. Native Windows Playnite runtime behavior was not exercised on the Linux validation host.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
Merge pull request #548 from HarryAnkers/fix/linux-restore-rotation-allowlist
fix(linux): allow display rotations through session broker
fix(steam): request the hashed CDN file that matches the local name
Hashed cache directories hold either library_600x900.jpg or
library_capsule.jpg, and the CDN serves <name>_2x.jpg from the same
directory. Requesting library_600x900_2x.jpg for a library_capsule
directory returned 404, leaving those apps at 300x450.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Merge pull request #555 from HarryAnkers/fix/steam-hashed-portrait
fix(steam): use content-hashed portraits for newer apps
feat(release): add gated daily prereleases, safety contracts and exact nightly notes
ci: forbid self-hosted runners for daily builds
feat(release): expose validated Moonlight Windows product version
ci: use reviewed primary sources and bounded Linux resources
feat(installer): require exact-certificate consent for newer self-signed gamepads
fix(linux): restore displays asynchronously without stalling Web UI
Display cleanup and KScreen queries could block the HTTPS event loop after
resume. Dispatch restores through the session helper, keep status queries
passive, and move display-layout queries off the listener.
Bound helper replies and fence uncertain compositor mutations while retaining
saved topology and canceling stale restores when ownership changes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 3ed6deafe2d98bcfb0d2a8f64e6014975fc764a1)
ci(linux): reuse verified CUDA and compiler caches on bounded hosted runners
Avoid duplicate recursive source checkout, shallow pinned submodules, retain native package tests and Pascal checks, and provide an exact-source artifact-only validation lane without signing or package installation.
feat(focus): share managed application focus across platforms
Linux managed launches lacked Playnite's foreground focus behavior.
Add shared focus settings and platform adapters for Steam, Lutris and
Playnite, preserving legacy preferences and cancelling pending focus
when the application session ends. Pass zero values explicitly so
turning focus off also disables the Windows launcher defaults.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit fb7f6c85fb5d3c7de018dadbd280cdae1de9fc22)
feat(pyrowave): add optional hybrid block reuse and LZ4 transport
Negotiate version 1 of the opt-in hybrid transport with compatible clients.
Reuse only acknowledged immutable coefficient blocks, explicitly clear removed
blocks, and send changes with sampled raw/XOR LZ4 compression. Keep the image
budget stable and fall back to native payloads for incompressible frames.
Bound reference caches and acknowledgement handling, preserve critical FEC,
and recover from missing references with full refreshes. Disable optional
detail FEC for hybrid envelopes. Canonicalize unused GPU sign bits and record
padding without changing decoded pixels, with a reproducible shader patch.
Bundle LZ4 and its packaged license, document the protocol, and fix the minimal
SteamOS Vulkan include and CUDA-disabled capture guards required by the build.
Validation: full PyroWave-enabled Linux container build and help smoke test;
25 codec cases and all seven client/PyroWave checks passed. Independent
ASan/UBSan mutation and CRC32C checks passed. Windows execution and live
streaming latency remain unverified.
(cherry picked from commit 0a050bdba002170c5c21311c3ce2c773a67ca565)
fix(migration): preserve Apollo broker metadata call contract
Keep the empty metadata arguments required by the Apollo session broker when launching managed focus, and retain source-only environment rejection assertions alongside Apollo environment requirements.
Generated with Codex (https://openai.com/codex/)
Model: GPT-6.1 Sol Ultra
fix(migration): classify Apollo broker mutation completion
Use the Apollo machine-host flag when interpreting exit 125, so cancelled compositor mutations fence subsequent display changes until restart. Guard the destination-specific completion classification in the Linux contract.
Generated with Codex (https://openai.com/codex/)
Model: GPT-6.1 Sol Ultra
ci(linux): isolate exact-source validation in registered manual workflow
Skip release selection and ordinary Windows/Arch/signing-summary jobs when hosted Linux validation is requested; preserve default behavior and dispatch only the no-key artifact route with tests enabled.
feat(windows): add opt-in DualSense waveform audio hooks
Native waveform sinks need a Sony-matched four-channel audio endpoint that
Windows virtual controllers alone do not provide. Add per-app WASAPI emulation
and a helper that verifies hook readiness before game entry without a debugger.
Forward actuator PCM through the existing haptics transport. Direct native x64
launches are supported; native Windows gameplay remains unverified.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Medium
(cherry picked from commit b2126c332124d009ac752e8faf82dbac1423031a)
fix(pyrowave): replace hybrid references with independent LZ4 compression
Keep the native coarse prefix and compress bounded independent detail groups. Remove frame references and ACKs, preserve partial-frame recovery and adaptive detail FEC, and fall back to native frames when compression is unavailable.
Validated with a Linux release build and smoke check, CPU compression/loss tests, four-format Vulkan decode and sustained detail-loss checks, ordinary framing/SDP/RTP/UDP tests, and exact reconstruction benchmarks.
(cherry picked from commit a88e04eb0fce195c11ef9514b70b06a23e9cc2fc)
fix(pyrowave): fit stream traffic within the wire bandwidth budget
Reserve critical FEC, packet headers, audio parity and control traffic before
assigning the image budget so the selected bitrate bounds actual wire usage.
Cap negotiation and pacing at the slower known host/client link, and keep
runtime bitrate updates within that cap. Preserve coarse-data protection
when record padding cannot fit, on both Linux and Windows encoder paths.
Validation: full optimized Linux build with both web bundles; all 116 CTests
passed, including PyroWave policy and Linux GPU coverage.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High
(cherry picked from commit 1eb4b2997bf336e45b1d0bc5fac1eac64caf8a7e)
fix(ci): scope native container Git trust to the verified workspace
The hosted Arch submodule checkout failed after checkout action restored its temporary Git configuration. Apply safe.directory only to that exact workspace and invocation, retaining the pinned SHA and rejecting wildcard/global trust in workflow contracts.
fix(migration): preserve legacy haptics configuration parsing
Read DualSense haptics with the existing Apollo JSON boolean compatibility helper so legacy string values do not cause the application loader to discard an entry.
Generated with Codex (https://openai.com/codex/)
Model: GPT-6.1 Sol Ultra
fix(pyrowave): remove ineffective LZ4 compression transport
Remove the unsuccessful compression path and bundled LZ4 dependency so
PyroWave sends native frames without the extra CPU compression pass.
Retire compression negotiation while preserving framing, FEC, and wire budgets.
Validated with the Linux release build and all 116 tests, including GPU validation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6-Astra Medium
(cherry picked from commit d1c93a155f540eb27061ae680d878689d0044559)
feat(playnite): allow users to select the installation directory
When URI detection fails, users can select and save the Playnite directory in either web interface. Use that location for plugin installation and game/fullscreen launches while preserving installed and portable extension layouts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit a67bda59748db6a8ea2271fa4c561f8c573da9ee)
fix(pyrowave): enable Intel D3D11 encoder compatibility
The broad upstream interop probe rejected Intel GPUs for sharing modes the Windows host never uses. Check only the plane texture format and D3D fence imports required by the encoder.
Add Windows GPU encode/decode coverage for changing frames, both bit depths and chroma modes. Validated on Intel UHD 770 and NVIDIA RTX 4090; PyroWave policy and GPU tests pass.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit ff41bda9aa107990826d3ee0cf0a5d1c015c1902)
fix(ci): validate Linux packages with the verified nonzero source version
Preserve package downgrade protection and use each fork current source base with a validation prerelease suffix in both isolated hosted entry points.
fix(playnite): support waveform haptics without launch deadlocks
Playnite waveform launches were rejected, and failure cleanup could deadlock all later connections.
Prepare scoped hooks before Playnite and 64-bit Steam start the game, refresh mappings on reconnect, and defer configuration writes until the launch read lock is released.
Require connector 0.4.15; seven focused validation checks passed.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 07589be637871884562a0c29fc135af6733fb7be)
fix(playnite): prepare Steam haptics from 32-bit hosts
32-bit Playnite could not load the 64-bit audio hook and cancelled game launches. Prepare Steam through the native helper instead, and install connector 0.4.16. Six focused checks and two live Steam preparations passed.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 6d8fc5acba69426441400536598be7b58c74eb0a)
fix(ci): fetch both pinned Linux driver sources before package configuration
The shallow initial checkout omitted DualSense source templates required by configure-only packaging. Fetch only libvirtualdisplay and libvirtualgamepad, verify their required files, and keep existing policy guards and package-source preparation.
fix(display): retain virtual displays through capture teardown
Windows normal-display capture references were Linux-only, so app exit could
retire a per-client virtual display while encoder threads were still draining.
Hold RTSP and WebRTC references through their joins, reject fresh capture while
an ended display generation drains, and rearm retained-display recovery only
after Resume admission. Retire paused recovery at capture idle while preserving
live and Remote Monitor peers. Keep deferred Windows stream-start work pending
when the lifecycle gate is busy so launch-owned teardown cannot deadlock while
joining control polling.
Addresses Nonary/Vibepollo#413
Addresses Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Ultra
(cherry picked from commit 830b8187b0eaff31c7200f9d68770e4b5ede8f6a)
fix(ci): honor signed installed GCC14 during Arch dependency resolution
Check exact compiler package versions, synchronize only dependencies reported missing by pacman deptest, then require the full dependency set to pass before fingerprinting the installed ABI. Exercise wrong-compiler, sync-failure and unsatisfied-version fixtures.
fix(hdr): handle live color changes without permanent HDR forcing
The session HDR override kept clients in HDR after the host switched to SDR.
Observe display color events with background polling fallback, fence helper
mutations, and finish optional HDR blanking before capture admission.
Publish HDR state after encoder readiness while preserving negotiated Main10,
per-generation metadata caching, and client message deduplication.
Adapt the lifecycle contract assertion to the current launch API argument.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 52e647330669d81f8b493c6cb6b69ac94cff35a0)
feat(pyrowave): add paced UDP bandwidth calibration probe
(cherry picked from commit c1a9f5dfb78f8f4f63813004331596d5f28dd27e)
feat(playnite): port compiled connector from Vibepollo #513
Replace the script connector with the reviewed .NET plugin, bounded shutdown
and safe plugin updates. Adapt the payload and signing paths to Vibeshine,
while preserving waveform preparation, reconnect mappings and launcher acknowledgments.
Source: Nonary/Vibepollo#513, merge f1cf988fb35a2a4fa779a261c6d6c455d8010cae
Validated the release and plugin builds, both web bundles and all 121 local tests.
Co-authored-by: Noklef <281545466+Noklef@users.noreply.github.com>
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
(cherry picked from commit f6697e8971edf7d381c5ba4d69ddb266a0a9f7d3)
feat(display): allow up to eight virtual display clients
Remote Monitor was limited to four identities despite the driver's eight
slots. Share a bounded global client limit with normal streams and retain
existing owners when it falls. Count provisioned Linux managed outputs and
explicit connected physical/dummy connectors without duplicate or missing
names. Explain shared capacity in both UIs and deliver the eight-output
helper without rebuilding live four-output pools.
Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 5596183265edde9c6138f8eab5536dbd9f092695)
fix(linux): admit client modes on all eight virtual outputs
The eight-output pool exposed connectors rejected by older four-name gates.
Admit exactly Virtual-1..8 in the host and SteamOS broker while retaining
mode and lease checks. Retire a capacity-rejected client's prepared connector
so rejected launches do not consume an extra output beside active peers.
Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 781c2b7fc4b07466d861eb46b26903900ea20aa4)
fix(display): preserve Windows and saved client arrangements
Extended sessions overwrote VerifyOnly and reset client placement to the
right. Preserve CCD origins and active peers, and apply saved placement
rules only to the connecting target. Expose directional and manual
arrangement with previews; selection keeps saved rules while only actual
drags place a display and keyboard edits follow the focused client.
Addresses Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit a4549a366ae60af36139ade51a72c0e27d493333)
fix(display): include the Windows topology capture declaration
Extended-layout requests capture the current display topology. Include its
owning integration header so Windows builds resolve the new call without
relying on unrelated transitive declarations.
Refs: Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 7bbf111bc90dcc3e97a1a40a596059683550556d)
fix(display): retry authoritative golden restore after fallback
Primary-only session fallbacks renewed the restore cooldown on every
poll, preventing a golden-first baseline from restoring a returning
monitor. Retry the configured golden baseline immediately when its
devices return, while preserving the default session-restore cooldown.
Addresses Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 52b8bf548898d2b232b34f6a3873a0713d1d278c)
test(display): compare restored origin coordinates directly
The restore-engine component links only display-device headers. Compare
both restored coordinates to keep the cooldown regression's origin coverage
without requiring the library's out-of-line Point equality operator.
Refs: Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit c9b1f431ee04dfeef23173f480a9c8724945c8b1)
fix(wgc): cancel helper handshakes before capture joins
A pending WGC handshake could outlast the ten-second video join watchdog
because stopping the capture queue did not stop helper initialization.
Cancel only the retiring capture generation between IPC waits, including
anonymous pipe handoff, and release borrowed display references before join.
Keep healthy startup budgets and native teardown unchanged; add production
regressions for cancellation, resume, ownership, handoff and session isolation.
Addresses Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit cadef93fe106dbb5b31c9aa85a8778c5d27a4b09)
test(wgc): use native CRT string helpers on Windows
MinGW defines _TRUNCATE in the CRT, so declaring the portable substitute
breaks the anonymous-handshake fixture. Keep the substitute string helper
on non-Windows hosts and use the native CRT when compiling for Windows.
Refs: Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 59e4fa755ee75794b7c094002cc75c15327653b5)
fix(display): Preserve physical returns across recovery feedback
A powered-off baseline monitor can return during recovery or its quiet
period and leave an exhausted restore lease asleep. Retain that evidence
until settling and reopen bounded recovery only when an authoritative
physical baseline member becomes enumerable. Preserve existing backoff
and disabled outputs, and keep retired debounce owners from hiding a
replacement owner's display events.
Addresses Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit ef4c0e2dd109578154ccbee01e539d6c95006544)
fix(display): Honor golden-first recovery after session fallback
A confirmed session fallback kept rearming golden's cooldown and prevented a
returned baseline monitor from being restored. Explicit golden-first recovery
now retries that baseline while session-first keeps its cooldown.
Exercise the actual fallback and reopened recovery in regressions, and declare
the Windows test fixture's algorithm dependency.
Refs: Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 8aa2abe3d600a99f4266d982e20a6720caff325d)
test(display): Keep recovery assertions within component linkage
Whole-snapshot comparisons instantiate display-device equality operators that
these isolated test targets do not link. Use the existing fieldwise snapshot
comparison so the declared Windows source lists remain sufficient while
retaining full baseline and primary checks.
Refs: Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 90cd49e46abaa180eb0f72c3e61a4042f39360b6)
fix(linux): preserve child status and crash restore intent
Competing waitpid sweeps could abort app teardown while rejected rotation
arguments blocked KScreen restore. Reap only detached children, preserve
unknown exit status, and admit the eight supported rotation values.
Persist session-bound desktop state before hotplug and refresh idle intent.
Recover orphan connectors through capture-verified asynchronous restoration,
preserving intentionally disabled monitors when no safe baseline survives.
Addresses Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit a429aa68ce10f46e9f723386e15ed3bbdfbf4bed)
fix(linux): preserve idle layouts and bound group polling
Check the owned child first and bound positive process-group scans to avoid
adding procfs work to every control input event while preserving exit status.
Keep idle baselines unarmed, restore only acquired or orphaned displays, and
clear saved intent after verified recovery so later layouts stay authoritative.
Only uncertain mutating helper completion fences future display changes.
Refs: Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 691c40ba996d8e8e7ddd7022bc36ec7cd477fddf)
fix(linux): resume marked restores after connector retirement
An interrupted handoff can leave the private connector gone while the final
physical layout and durable restore marker still need completion. Prioritize
armed recovery at startup before refreshing idle preferences. Keep fieldless
legacy idle baselines unarmed unless an active private output needs recovery.
Refs: Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 31b3bcf4cef762edba5de039d4128bb6e8a4ae2e)
fix(display): preserve restore task opt-outs and explain recovery
User-disabled logon recovery tasks could be recreated enabled, and recovery
controls hid automation requirements or retained stale saved-policy gates.
Preserve disabled tasks and remove enabled legacy orphans without snapshots.
Show session snapshots, task state and helper engine in both interfaces.
Refresh snapshot and reset availability after settings saves without a reload
or implicitly starting the helper.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 8749cac09d6355d49a54c54fcd4530be7bc2b02f)
fix(i18n): preserve Apollo crash bundle descriptions
fix(display): keep legacy recovery controls visible
Recovery settings became hidden inside a native HTML template. Render the
section normally even when automation is disabled, retaining its explanation.
Load restore-task COM headers after the Windows/Winsock prelude so Windows
release builds do not fail the include-order warning-as-error check.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit e9eb03244dc054ad300c949319b9b57747bca519)
fix(ui): allow retrying unavailable display recovery status
A failed status fetch disabled its own Retry action when maintenance was
unavailable. Keep read-only retries usable while retaining the existing
snapshot capture policy and blocking overlapping status requests.
Cover repeated status failures and recovery without mutation requests.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 1f41888cd5d465bcebb22ad5a8cdf86176aef43c)
fix(ui): share recovered display maintenance status
Retrying display status updated the snapshot card but left capture and reset
blocked by stale parent state. Publish each fetch's unknown or saved-policy
result to SettingsView so a successful retry restores both recovery actions.
Cover repeated failures followed by available and automation-off responses.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit c1b60490af085667b89084e7a1ca5b3a2ff46ff5)
fix(linux): fit complete multi-output broker requests
Eight managed HDR-capable outputs plus three physical displays need
65 properties and exceeded both session helper argument caps.
Share a fixed 448-property budget for complete 64-output transactions,
retaining the 128 KiB frame, property allowlist and identity controls.
Cover composed requests and exact argument and byte rejection bounds.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
(cherry picked from commit 6d7c7dbca9fbc23781b277635d7e6bbbf34c00f6)
fix(linux): reliably restore desktop after stream teardown
Establish a verified saved scanout before retiring private connectors, wait
for each hotplug to settle, and strictly verify the complete desktop before
clearing recovery state. Keep failed cleanup recoverable, release drained
desktop ownership, and protect paused apps and retained Remote Monitors.
Resolve remapped mode IDs from current catalog semantics and use bounded,
noninteractive Wayland readiness probes. Rearm failed preparation cleanup,
preserve unpublished admitted connectors, and permit supported rotation
tokens through the session broker.
Validation: 205 regression tests under ASan/UBSan, 39 under ThreadSanitizer,
broker policy checks, and affected production translation-unit compilation.
Live physical-monitor validation remains outstanding.
(cherry picked from commit ce6d9e8588a33242891065c8acde00bb4001bfa4)
fix(display): verify snapshot modes before saving restored layout
Use exact temporary mode restoration in both helpers, wait for the full legacy topology, compare rational refresh rates numerically, and retain current snapshots after previous-tier recovery. Pin libdisplaydevice with corrected topology and validation flags.
Validation: eight portable regression tests passed. Windows mock tests and physical 120 Hz retention remain unverified on this macOS host.
(cherry picked from commit 4225211b8e13e1a6ba59276ce9fef8d3b4514eab)
docs: describe durable Linux restoration intent
fix(linux): honor explicit capture methods for virtual displays
Prefer KMS for automatic virtual display capture, preserve explicit backend selections, and align service overrides, UI warnings, documentation, and policy coverage.
(cherry picked from commit fd9b59ff15918dbd69ee7c7ae666266968309b4b)
test(display): use valid modes in snapshot fixtures
Give the shared fake snapshot a positive resolution and 60/1 refresh rate so the updated display library can compare it. Preserve every existing assertion and the production rejection of invalid refresh rates. All 103 state-machine cases and the snapshot/restore targets pass against the exact producer headers.
feat(pyrowave): advertise critical FEC overhead to paired clients
Expose the configured critical-block parity percentage in serverinfo and document how client bandwidth calibration accounts for parity and wire overhead.
(cherry picked from commit 4b2ba5fc07c2fa075430234a15005aac4d4f939a)
test(input): add host-only virtual gamepad lifecycle probe
Add a standalone Windows controller creation and teardown probe with HID and XInput inventory, explicit destroy and owner-close cleanup, and reproduction instructions for Steam and SDL tracking.
(cherry picked from commit 19e80502ff2327437d1036aba1a3181fac71818f)
fix(linux): skip automatic portal consent after KMS selection
Prevent automatic managed KMS startup from opening an interactive portal probe. Explicit portal capture remains allowed, and X11 fallback enumeration is preserved. Cover the capture policy with four hardware-free regression cases.
Fail Linux component builds early and reuse verified package sources
Declare the routed-link Boost.Asio interface, compile configured component targets before host and CUDA work, seed validation sources from the exact verified shallow checkout, and retain only verified dependency/compiler cache work after trusted manual build failures.
fix(display): ship the wide-gamut HDR driver correction
Pin the corrected libvirtualdisplay source and v1.6.4 Windows package so
installed virtual displays advertise BT.2020/D65 for HDR. Keep SDR EDIDs
unchanged; client image-quality acceptance remains pending.
Addresses Nonary/vibeshine#270
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 757a3657ad91344222bc68acbdb235c3b0a425a8)
fix(audio): Retain role recovery after visibility failures
Steam visibility failures discarded captured role recovery before disconnected
HDMI endpoints could return. Keep guarded direct restoration after a failed
fallback, including the endpoint selected before a failed show. Retire roles
changed during the visibility RPC while retaining recovery for other roles.
Preserve newer defaults, successor ownership and shutdown cleanup, with
production-function coverage for return and failure ordering.
Addresses Nonary/Vibepollo#470
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 9f8aabeeb0b8d6d548845ea75458bd2f3b62e85c)
fix(hdr): Ship the Vulkan layer for 32-bit Windows games
32-bit Vulkan games miss HDR formats because the released payload contains
only the x64 layer. Build the x86 layer from pinned source during package
refresh, validate its exports and architecture, and include it in MSI signing.
Register and check each manifest in its own registry view, preserving other
layers and removing partial registrations when disabled.
Addresses Nonary/Vibepollo#418
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 4f02a037372ec0e96cdccda7e33094332c216c2e)
fix(input): Bound Windows desktop recovery and own bindings
Persistent injection failures could retry indefinitely as desktop handles
changed, blocking the input worker. Retry once after successful attachment,
retain the assigned handle, and release superseded bindings safely.
Replay eleven production-source scenarios; seven fail before the repair.
Physical-monitor game window disappearance remains a separate unresolved cause.
Addresses Nonary/Vibepollo#415
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit c5e1cd731230746e10e31ace74d6baeeb2b6217e)
Model early component validation in the CUDA policy fixture
Stub the external component helper explicitly and verify configure, component and full-build ordering while retaining private CUDA and Pascal assertions. Normalize fixture paths so the same policy checks run on Windows and hosted Linux.
feat(windows): make automatic service startup optional
The installed host lacked an app control for automatic Windows startup.
Add authenticated startup toggles to both maintenance interfaces backed
by the fixed own-service configuration. Off selects Manual, preserving
manual launch and current sessions; report actual mode and permission errors.
Addresses Nonary/Vibepollo#411
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 235a32e495dfe3e374244d0fc3af04e1ed31f737)
fix(kms): read AMD virtual frames on the physical renderer
Display-only KMS cards cannot initialize GL readback, and their advertised
RA24/BA24 framebuffers were rejected by the linear upload fallback or sampled
with the wrong Vulkan channels. Use the selected physical render node for
software capture and preserve packed RGB/alpha ordering in both conversions.
Addresses Nonary/vibeshine#291
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 3e8cfdc0c6ff55ba3f055ae4d5914429c52bc2d8)
fix(input): preserve Xbox client profiles on the VHF backend
Xbox-type clients with motion sensors or touchpads could become DualSense
controllers under VHF, disagreeing with ViGEm and Steam's expected handling.
Honor the client-reported Xbox type before capability preferences while
preserving explicit overrides. Exercise the shared production selection
policy for plain VHF and Automatic fallback in regression tests.
Addresses Nonary/vibeshine#286
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit cbe1f348a73a75923ecf8f6d2d736598adda88ee)
fix(display): recover legacy layouts after broken connections
Recent display-helper disconnects discarded restore intent, allowing
liveness-only reconnects to leave an old layout armed for later login.
Retain recovery until a live stream renews its deadline, reject stale
owner pings, and preserve that deadline across repeated disconnects.
Let disabling automation finish cleanup without bypassing display owners.
Cover recovery, ownership and disabled-policy regressions.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 1594f8a7e5e27055594919f6bb3655561687c5e2)
merge(prerelease): reconcile display recovery on vibe-test
Preserve both local and remote prerelease improvements while integrating
the legacy recovery fix. Keep durable desktop snapshots and eight-output
support alongside the newer guarded restore transaction and HDR colors.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit f0fb1ea585efc17ece16811c741854bcd0945991)
fix(linux): preserve console rendering on multi-GPU hosts
The bridge's PCI spoofing and ambiguous NVIDIA selection could break Virtio
console output and leave private displays unavailable. Pin the isolated GBM
route with a stable PCI default, early SHM import safeguards and truthful PRIME
layout metadata. Reject CPU fallback for managed unknown layouts rather than
reading tiled storage as linear; keep native and explicit linear fallbacks.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit e42f9ae462be157ef3bf12c0cf8e8b319b1666ed)
fix(linux): admit globally numbered private display names
A Virtio console can consume Virtual-1 before the managed display pool.
Pin the explicit DRM-to-configfs mapping and admit valid global connector
IDs for requested modes, while the broker verifies actual pool membership.
Cover shifted names without expanding the pool or guessing an offset.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit efc8c77ba5b955a57ebde0b40fe7af750bd4b05c)
fix(steamos): share managed connector mapping in the local broker
The local broker shadowed the shared handlers with fixed connector IDs
and public-name lease paths. Shifted DRM names could connect one pool slot
then request modes on another. Inherit the canonical mapped handlers and
cover sparse public names, logical leases and cross-user mode rejection.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit d9e54d8b57ab2dde10ad758463b874d4faab2d33)
Declare display helper component Boost and JSON dependencies
(cherry picked from commit c98b7c5422853db362c76242ac6d49a5c447fe0e)
Compile fast policy targets alongside component tests before Linux packaging
Discover both configured test categories through the CMake codemodel while keeping the required routed-link gate and excluding unrelated app targets.
(cherry picked from commit 6ea72f0dd1ccc1ed8e593cd29196592620b3f390)
fix(linux): make filesystem validation locale-independent
- stop comparing localized stat %F strings
- use -f/-d/-S for object type validation
- retain stat only for ownership and mode
- use C.UTF-8 for machine-host child processes
(cherry picked from commit 36dd4caa378f8560fda94267d37967d36184d0d0)
fix(steam): normalize Pressure Vessel /run/host Proton paths
- translate /run/host/... metadata to host namespace paths
- apply normalization to Proton and Steam client paths
- support system-wide CachyOS Proton direct launches
(cherry picked from commit 845beffcc32457955c825661c65d818976dd0330)
fix(linux): skip read-only Proton tools for global policy injection
- don't try to write hooks into root-owned compatibility tools
- keep user-owned Proton tool injection unchanged
- report skipped tools instead of PermissionError
(cherry picked from commit 99e137e81c7b58aef25a7f8d2fb47548733c5a8d)
fix(packaging): verify installed private host capabilities in installer
- assert private host executable has cap_sys_admin,cap_sys_nice=p after install
- prevent unsafe executable status when host capabilities were not applied
(cherry picked from commit 6f417283999c42ca231ac4332a622e575401b832)
fix(display): serialize remote monitor teardown
Keep display ownership alive through capture joins and close WebRTC before
topology cleanup. Fence monitor generations across rejected activations,
reconcile deferred releases, and retain failed native cleanup for retry.
Drain WGC frame callbacks before releasing capture-manager resources.
Refs: Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Luna High
(cherry picked from commit b35e9d1b69fb42fda05ba07c3c76500e1ec1f204)
merge(prerelease): add capture-safe display teardown
Retain display ownership through capture teardown, fence stale monitor
requests, and drain WGC callbacks before releasing capture resources.
Preserve the current configurable capacity and Linux idle-cleanup policy.
Refs: Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit fbbd99073406f1a09ed132e78736261eb27f57c0)
merge(prerelease): accept Linux hardening from PR 302
Merge the contributor's locale, Proton path and packaging fixes into vibe-test.
Reconcile the stable fixes already in the PR ancestry while preserving newer
wire-budget handling, display teardown and application focus behavior.
Update metadata fixtures and retain unsafe Xauthority rejection coverage.
Closes #302
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit a1e0142043faaffa16b6c9729917e4e60a8c2585)
ci(windows): opt in to compile and run tests without daily signing
Expose a default-off build_tests input on artifact-only Windows validation
and forward it to the reusable build. Execute CTest whenever tests are built,
with empty suites and test failures blocking success. Keep daily artifact
signing gated solely by daily_unsigned and pass no signing secrets from the
validation wrapper.
Add a workflow regression fixture for compile/CTest input alignment, hosted
artifact-only defaults, and independent daily signing guards. All three
fixture cases, actionlint, and whitespace checks pass. Full hosted application
compilation and CTest execution remain pending; no local machine changes ran.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 19a4165016aaa3de3ade55fa24eba5a4f334c7e6)
fix(linux): recover machine setup after locale and cwd failures
Valid machine profiles were rejected when service-account commands inherited
an inaccessible caller directory or metadata checks used a translated locale.
Run those commands from / and stabilize native package lifecycle checks.
Retry machine setup in the installer, including older-controller locale recovery,
and stop on failed recovery while preserving existing profiles and pairings.
Addresses Nonary/Vibepollo#514
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 3eab003539596881446922c7ffb1619a23c23f22)
build(gamepad): ship the DualSense identity fix from beta.7
Pin the released driver 0.1.0.48 so GameInput and HIDAPI identify the
same virtual DualSense. Keep the source, archive checksum, CI, installer
checks, and bundled payload aligned with the verified beta.7 release.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Low
(cherry picked from commit 73b28e555cd7cff6205d837f5bf7c797bdf823f4)
fix(pyrowave): establish UDP return paths before calibration
Windows streaming works through outbound UDP exchanges, but calibration
previously sent unsolicited packets to a fresh receiver port. Announce the
sender port over paired HTTPS and verify the client's UDP token before the
measured transfer, without firewall changes. Bound the handshake and exclude
warmups from results while preserving legacy clients.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High
(cherry picked from commit a2c548d1faaff16223b88109aafb78b9f675040c)
fix(linux): exclude virtual outputs from monitor restore snapshots
Retained streaming outputs could become the saved desktop and prevent TV
restoration when their requested modes changed. Keep new and legacy restore
snapshots physical-only, require a physical restore guard, and retire virtual
connectors even when older snapshots included them, matching Windows behavior.
Validated by a full build, 134 passing tests (one skipped), and user-confirmed
TV restoration after native installation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 8ff20328ed83d7e18db1d9ca63344c8cf33146ce)
feat(display): add the virtual display killswitch on Linux
Linux hosts lacked the UI and API recovery action available on Windows.
Expose confirmed termination in Maintenance, attempt physical layout restore,
and disconnect every managed kernel output despite active ownership.
Verify removal and report restoration separately while preserving mutation fences.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit c3bf29e52715d9bca3c77c9ad2fe95a5953ade30)
fix(ui): retain Apollo identity in Linux recovery text
fix(display): honor refresh overrides and older Windows limits
Match refresh mappings against stream FPS before automatic promotion so
60 FPS sessions can advertise and apply explicit 480/1000 Hz modes.
Resolve creation, apply and recovery consistently, preserving fractional
rates and capping pre-24H2 Windows modes at the resolution's 1 MHz scan limit.
Validation: Linux release build and both web bundles passed; 135 tests
passed, 2 skipped. Windows build and live streaming remain unqualified.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit e5481d5d58c74a05f7c0fa03c844678d0c772bd4)
fix(ui): restore a focused Everyday settings workflow
Everyday buried Vibeshine's distinctive features among generic controls.
Put virtual screens, smoothness, PyroWave and Remote Monitor together,
with pacing integrations, visible library links and grouped tuning.
Correct Windows limiter choices and FEC bounds while preserving old drafts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 67c17bfdd4f19309538b62d8f555110f073e4b54)
fix(display): terminate remote monitors despite restore failure
Disconnect Monitor must remove its Windows screen even when the remaining
display topology cannot be restored. Use exact-owner native termination,
retain capture and peer ownership guards, and report removal failures.
Refs: Nonary/Vibepollo#568
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit 748b53db57b248e89bc8d27677d747a1e173f2c2)
fix(ui): complete Everyday parity and Apollo text resolution
ci(linux): cache only the verified CUDA installer
Caching the full CUDA SDK plus installer exceeds the standard shared cache budget. Restore and save only the pinned installer under a new cuda-installer-v2 key, with no fallback to SDK archives. Each fresh job still installs and patches the complete CUDA 12.9 toolkit.
Exercise checksum rejection, two fresh toolkit jobs, unchanged trusted-failure eligibility, and final Pascal/CTest/package gates. Keep the prepare helper, package recipe, and release validation unchanged.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 708a2e0362ff81ab6b2570dc3fcd898925e47c2c)
fix(ui): remove duplicated migrated Everyday groups
fix(display): preserve exact Apollo stream refresh at policy boundary
feat(input): emulate wired USB DualSense haptics on Windows
Expose controller and audio interfaces together so games can send native
waveform haptics through the existing Moonlight feedback path. Add an opt-in
installer component using unmodified, verified usbip-win2 drivers; preserve
shared installs and wait for HID/audio readiness before per-app launches.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit fef077c021b56430ac41366d2f1fcf1eb135e142)
feat(ui): add dashboard virtual screen recovery
Make emergency recovery reachable when a virtual screen leaves the PC blank.
Add a first-visit guide and confirmed dashboard action, removing virtual
outputs before trying the saved layout and a connected physical monitor.
Validation: Linux build, 33 browser checks, and 10 targeted policy tests.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
(cherry picked from commit 7af5c387b63df8ff1fcc7b55a1bfb29fc946bc4a)
feat(display): recover orphan virtual screens on monitor events
Stuck virtual screens can survive failed desktop restoration. Use monitor
wake/topology events to recheck failure and remove only captured orphans
when physical output is verified and all display owners are gone.
Keep recovery tied to its session and generation without periodic probes
or time-based expiry. Preserve the current physical desktop layout.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
(cherry picked from commit 13c99d514f2c9c933a1cefea3a7988da47368adf)
fix(web): remove inert legacy Playnite extension directory default
The source migration replaces the old extension-path editor with playnite_install_dir. No backend reads playnite_extensions_dir; retaining its dead serialized default breaks the dynamic legacy/v2 settings parity contract. Keep the real install directory and extensions_dir response metadata.
Validation: actual settings behavior tests pass all 12 cases.
fix(web): scope display recovery guidance to Vibepollo
Keep Apollo first-visit recovery guidance independent from a Vibeshine dismissal at the same browser origin. Shared driver/protocol identities are unaffected.
Validation: actual utility storage read/write passes against isolated localStorage; independent batch 23 review finding.
fix(hdr): wait for display setup before starting capture
Capture could probe HDR during the helper's temporary SDR window.
Require verified display setup before launch, resume, and WebRTC
capture, then follow real HDR/SDR changes through normal reinit.
Remove mutation fencing, frame holds, color generations, and settling timers.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
(cherry picked from commit c2a651beebd28190474adf595ea805a3928b06eb)
fix(web): expose the Linux display picker description
Historical Apollo import 35571f969 added the modern source description but left a later fallback key shadowing it. Remove that preexisting stale duplicate and four identical driver-key repetitions without losing any unique locale path or offline guidance.
Validation: exact f007/source68 path-aware audit preserves 2170 unique leaf paths; zero main English duplicates remain; only effective picker description changes.
fix(hdr): preserve driver-owned calibration profiles
Host profile edits competed with the Vibeshine driver's retained calibration.
Leave those associations intact while keeping explicit assignment for SudoVDA.
Prevent rejected activation from leaving registry-only profiles, avoid duplicate
activation, and remove UI guidance requesting redundant client assignment.
Validated the full local build and CTest suite: 154 passed, one skipped.
Refs #301
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 306d11d1707928da43a1d7798da62e3b5050f54f)
test(playnite): isolate SDK discovery hints inside the CMake fixture
Clear DOTNET_ROOT and ProgramFiles in the generated CMake child script before
running unchanged production discovery. Windows may retain its well-known
ProgramFiles environment value despite a subprocess override, allowing a
host-installed SDK hint to mask the fake PATH SDK and fail the exact-path test.
Remove inherited case variants before setting child environment values and
include expected/found paths in the failure diagnostic.
Preserve PATH, empty-cache, and explicit discovery cases plus compiled upgrade
and filesystem cleanup policies. A temporary competing SDK reproduces the
original failure; clearing hints restores the exact PATH result with both
MSYS2 and native CMake. All full fixture checks pass with both tools and the
actual UCRT64 compiler. No production code or machine configuration changes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 6acc22f63402a9e16d8fe6d37cff2cf1472063b0)
docs(release): document 2.0.0-stable.1 changes
Explain the stable delta from 2.0.0 with user-facing outcomes and setup details.
Cover display recovery, controller haptics, HDR, PyroWave, and Linux fixes while
excluding withdrawn experiments and intermediate prerelease fixes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 9f7fbdd1a05b89e084d1a7574895e48ec5d346d3)
fix(hdr): Preserve driver calibration without monitor metadata
A permanent Sunshine monitor selected through the physical output route could receive a client profile when optional enumeration failed or omitted its identity. Recognize the resolved default driver hardware-ID families before enumeration, preserving physical and SudoVDA overrides and the existing custom-metadata fallback. Add policy boundary tests and regressions extracted from the actual production guard.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 508da3612fe59fe27275756d9267dfce5929d471)
fix(display): keep locked desktops reachable during setup failures
Mandatory display setup rejected reboot and lock-screen connections with 503 before users could remotely unlock Windows. Continue launch, resume, and WebRTC with existing display settings when setup fails or times out, and preserve deferred setup across app startup for retry after unlock.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 9ab0b3132abfe0b3768c3f46580b0979082fef74)
fix(webui): keep the interface responsive while streams pause
Display capability discovery could block the HTTPS event loop and keep the UI loading while a paused app retained its display. Isolate metadata work, open the UI after authentication, and let stalled status requests time out and retry. Remove the dashboard metadata wait and cover startup and recovery with a browser regression test.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 1647ef50309f67f911c7f87520f1cf2d50285149)
feat(input): boost DualSense haptics while preserving contrast
Make streamed haptics easier to feel without hard clipping or flattening waveforms.
Add configurable strength lift on Windows and Linux, preserving actuator peak gaps with recent-peak headroom control and per-controller smoothing.
Keep 1.0 as unchanged output and support per-client overrides.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
(cherry picked from commit 91d4c5917d1ed1f557350adc44938ae7dbb98360)
fix(input): preserve DualSense audio across Moonlight pauses
Disconnecting the virtual controller invalidated the game's haptics audio endpoint. Honor Moonlight gcpersist by retaining the composite DualSense while the app runs and rebinding feedback on resume. Release retained devices when the app ends and preserve teardown when persistence is disabled.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 19f4527c3ebaf5b650a905818a77058e6830bcb3)
feat(pyrowave): Calibrate pacing with frame-shaped UDP probes
Negotiated link speed can exceed what a receiver absorbs in video bursts.
Add frame-shaped probes and client-calibrated pacing, using 80% link headroom by default while accounting for stream demand and wire overhead.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 68f381b0396abdf300eb6a5a5ae748ecd0299ac7)
fix(stream): Bound UDP retries and account for failed frames
Socket pressure must not block streaming or silently leave holes in frames counted as delivered.
Bound nonblocking sends, stop failed fallback sends, preserve sequence reservations and traffic accounting, and limit failure logging.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit ec427d602085a8eb5706269976d96f9a3972a2bd)
fix(input): Use USB audio for automatically selected DualSense
DualSense waveform haptics need the composite audio function outside application opt-in scopes too.
Select it when DualSense is chosen and the transport is available, retain client capability checks, and keep diagnostics quiet.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 74d38edf022f98f7f4d01fe3564d6456e8143d1b)
fix(dualsense): Locate readiness by USB host and imported port
The released USB transport can generate instance IDs that do not match the requested serial.
Find the controller under the opened host and imported port before checking HID and audio readiness, avoiding unrelated devices.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit a12c83debc4b7f2704c5c28627de5f528fc2570b)
fix(display): Correct helper linkage and include x86 HDR manifest
Display cleanup helpers need external linkage and the Sunshine identity helper needs its namespace qualifier.
Correct both references and include the x86 Vulkan HDR manifest already required by installer and packaging contracts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit af13dd441d3114646b41b011d4a5e2eefc46686c)
fix(deps): Update virtual gamepad report and initialization fixes
Use the virtual gamepad fixes for deferred HID report ownership and quiet Switch controller initialization.
Advance the submodule to the two dedicated driver fixes without including local test-signing payloads.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 68f38d8b5c37c7c06817698c0c91f872f70c3325)
Default to verified prerelease notifications and preserve stable-only choices
Adapt the host updater to Apollo's package names, repository, paired-state
storage and both Web UIs. Enable prerelease notifications only when the setting
is missing; preserve explicit opt-out, interval-zero suppression, forced retry,
session lifecycle, exact release links and existing macOS architecture support.
Share one verified release selector and dismissal identity across both UIs.
Include the reviewed tray ABI correction before the first reviewable updater
commit: OS notifications carry the captured exact release URL in text with a
null callback; Web release links remain clickable. Preserve delivered-history
suppression and save state after releasing the notification lock. Keep pairing
validation intact and persist destination history before clearing migrated
source keys, including failure recovery.
Register the actual policy, history and production tray regressions. Preserve
standalone assertions in Release builds and isolate mocked browser requests
from external network access.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
Additional-source-correction: d50046c73d81ac5d60903e33b29c52c3ed7ffeed
(cherry picked from commit 57fc027ee71594d909f0df1cee5c4c64fe493c6b)
test(updater): match release fixtures to the build platform
Linux CTest rejected the standalone harness Windows-only installer before comparing stable respins. Supply the real build-platform package family and architecture in fixtures while preserving production completeness and version-selection policy.
Cover stable respin ordering, older rejection, wrong-platform and wrong-architecture assets, empty or pending packages, and missing nightly checksums. Keep assertions enabled explicitly and reject assertion-disabled harness builds.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
Adapt the regression fixture to Apollo package names and retain its existing
macOS architecture compatibility. Preserve the real production selector and
the registered Release assertion guards; add the reviewed stable-respin and
incomplete/wrong-platform package coverage without weakening policy.
(cherry picked from commit 8383852aceadf7acf7cf1722089fdecaa03972b0)
Preserve the reviewed Apollo daily validation chain after the core migration
Merge the independently reviewed CI, installer and Linux validation changes
after the complete source-primary migration and corrected Apollo updater.
Retain the original eighteen candidate commits and explicitly reconcile
the installer consent/USBIP controls and Windows producer configuration.
Keep hosted runners, signing-independent test validation, version-first
driver safeguards, exact-certificate consent and Apollo package identity.
Preserve all updater registrations, recovery behavior and x86 Vulkan/AMF
validation. Atomic producer reconciliation and combined build qualification
follow this internal checkpoint; daily publication remains disabled.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(display): verify the reviewed producer source and payload
Lock the v1.6.4 archive, evidence, source revision, actual INF DriverVer and every producer file. Reject changed fresh downloads and unverified caches before package refresh, including explicit prebuilt roots, while preserving the later Linux source pin and installer trust policy.
Validate with mocked fresh/cache tamper tests, Windows PowerShell 5.1, the mandatory driver safety suite, read-only public artifact fetch/cache verification, actionlint and the CMake lock declaration.
Apollo adaptation: Preserve Apollo x86 Vulkan, AMF, ValidateOnly and recovered Linux display source1b852. Restore the shipping gamepad gitlink to the audited beta.7 producer9edbce11 with its existing matching archive/DriverVer/protocol locks. Driver-only7f8d23fc and a7389b46 remain deferred until a real tested producer increments DriverVer above0.1.0.48.
(cherry picked from commit 824099413c4cb92d668361801e2385b008ebb935)
test(packaging): expect the audited libvirtualdisplay v1.6.4 release
Correct the stale typed contract expectation without changing the producer lock or runtime policy. Verify the exact reviewed source revision, archive hash and INF version, and evaluate the real CMake contract against the same release.
Validation: two focused provenance tests and git diff --check passed. No driver, trust or installer operations ran.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
Apollo adaptation: Retain the audited Apollo Windows display1.6.4 source/digest/component contract and align the actual typed fixture without weakening assertions.
(cherry picked from commit 78660a102ec51119893d35fc02cd8dc69e85161d)
test(display): preserve Boost headers in wake recovery fixtures
Direct Python compiler calls lost the modular Boost include requirements, breaking the observer and its mandatory backend regression. Pass the evaluated Boost::algorithm header closure through both fixtures without changing production code or assertions.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
Apollo adaptation: Preserve Apollo wake-observer and recovery behavior while declaring the evaluated modular Boost algorithm include interface. Keep updater registrations and Release assertions.
(cherry picked from commit 1959e585676ab819e85fe833887d3eddfce333b0)
Declare the DualSense component Boost Format interface
Link the production stat-tracker header dependency explicitly and verify the pinned modular Boost headers with positive and missing-interface compile probes.
Model: GPT-6.1 (medium).
Apollo adaptation: Declare the direct Boost format interface for the migrated DualSense component, retaining the real modular positive/negative header fixture and all existing target interfaces.
(cherry picked from commit 46dbd6ada217fdccc2bfeaddd41b401fbf7683f5)
Match configured-adapter regression to the actual snapshot routing
Keep configured physical-adapter and no-substitution coverage while checking the actual physical.display_names predicate argument used by both backend functions.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
test(display): use valid modes in snapshot roundtrip fixture
Zero-initialized refresh rates fail the pinned mode-verification equality contract, so the storage roundtrip test failed despite preserving its data. Supply valid 1920x1080 at 60/1 modes for both displays while keeping every assertion and production check unchanged.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 5d4b7a53e45450dee0cee96169910f046a2ae1cf)
Keep the UDP probe measurement open until its fixed deadline
A Windows timer can return early from the final wait, producing a measured
probe window below 2000 ms even though all expected packets were sent. Recheck
the original steady-clock deadline after each return through the existing
injected waiter. Do not restart the duration or change packet pacing, retry
budgets, handshake validation, burst scheduling, or overload bounds.
Add deterministic fake-clock coverage for repeated early returns, completed
deadlines, and waiter exception propagation. Preserve the original elapsed,
packet count, sequence, token, and pacing assertions.
Validation: the unmodified native loopback test reproduced 1999.4009 ms on
iteration 4 of 5. The corrected Release native suite passed all 9 GTests,
and the unchanged paced loopback regression passed 10 consecutive runs.
Compiled with GCC 16.2 and -UNDEBUG using cached Boost/GTest dependencies.
Full hosted application validation remains an integration check.
Source-first implementation based on 0ea017a8db1b653921e73a3ee45f1d5506c7fbb4.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 92b51649ae43547dd6a081af607fc2e95618202f)
fix(web): Accept CRLF checkouts when verifying design tokens
Windows Git checkouts convert the generated token files to CRLF, causing check mode to reject otherwise current outputs. Accept that checkout conversion only during comparison, preserving strict content checks and the existing LF generation and print behavior.
Exercise the real generator in isolated fixtures covering equivalent line endings, genuine drift, missing files, unchanged check/print inputs and deterministic generation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 489fffa883d5d027cdb56636babe9c86af3898be)
Keep legacy updater link checks independent of decorative icon labels
Match the final Download and Release Notes words within the update notice, require one link each and retain exact Apollo release URLs and all ordering, dismissal and reload coverage.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(web): keep Apollo compatibility settings within narrow forms
Restore the missing compatibility labels and constrain their layout so the Add Application page reflows at 320px without horizontal scrolling. Preserve the unchanged browser viewport assertions.
fix(ci): reuse one pinned nightly gamepad signing identity
Replace per-run certificate generation with scoped encrypted CI inputs and an exact public thumbprint. Reject invalid or expiring identities, export only the public certificate, and retain consent, producer provenance, numeric driver-version and no-trust-mutation contracts. Two actual disposable signing passes reused identical certificates.
(cherry picked from commit d641a8fa235ac831d38fd01b6969afc2385a4d33)
fix(build): remove obsolete Apollo display session helper
test(video): bound readiness shutdown extraction to its admission block
(cherry picked from commit 43505570675a39244628271afc1d0e26b456678e)
test(playnite): retain the selected SDK framework during restore
(cherry picked from commit 84ed23f6a1e9d4089cafe86c528cbddc41ba8407)
fix(test): declare Apollo colorspace JSON header dependency
fix(ci): align certificate identity checks with the persistent nightly signer
(cherry picked from commit 94315bea114ac57be326940fa6cb40ecf3c1f9aa)
fix(test): propagate Apollo JSON headers to the USB/IP backend fixture
fix(test): supply replay dependencies and product-scoped helper fixtures
(cherry picked from commit 1fd1ecbbe610556814e53540acaa0f90e335909c)
fix(display): synchronize dispatcher shutdown with idle waits
Protect both stop predicates with the corresponding condition-variable mutex to prevent shutdown losing its notification. Exercise 1000 idle shutdowns under a bounded component timeout. Preserve the shared helper directory when redirecting Linux lifecycle fixtures.
(cherry picked from commit 5ade938d15fb59a14bb42014e6f8e3e4d2dec1ce)
fix(test): stage owned units for Apollo lifecycle retirement
Run the existing boot-link retirement guard against fixture-owned unit files and obsolete links before locale-sensitive configure/start checks. Keep the production guard and every lifecycle assertion; assert that the obsolete fixture links are removed.
fix(ci): fetch full ancestry for nightly version resolution