This is a nightly release of Vibeshine and contains several bug fixes and may contain new features. Check the commit log for more information.
Windows installer · Linux (Arch x86_64)
Nightly Windows installers are unsigned and include self-signed gamepad components. They may cause false-positive antivirus alerts.
Source: aaa39188cc78
Since the preceding stable release Commit log
2.0.0: compare exact sources.
fix(linux): restore displays asynchronously without stalling Web UI
Display cleanup and KScreen queries could block the HTTPS event loop after
resume. Dispatch restores through the session helper, keep status queries
passive, and move display-layout queries off the listener.
Bound helper replies and fence uncertain compositor mutations while retaining
saved topology and canceling stale restores when ownership changes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
feat(focus): share managed application focus across platforms
Linux managed launches lacked Playnite's foreground focus behavior.
Add shared focus settings and platform adapters for Steam, Lutris and
Playnite, preserving legacy preferences and cancelling pending focus
when the application session ends. Pass zero values explicitly so
turning focus off also disables the Windows launcher defaults.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
docs: clarify 2.0.0 client requirements and gamepad features
fix(release): rebuild Arch indexes from the verified package
Avoid repo-add deleting an old package that a wildcard will try to read later in the same publication. Rebuild both signed indexes from the exact verified release payload and remove obsolete product packages only after signing succeeds.
Compare package metadata literally and cover fresh, repeated, stale, and missing-payload publication with real repo-add and disposable GPG fixtures.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
feat(pyrowave): add optional hybrid block reuse and LZ4 transport
Negotiate version 1 of the opt-in hybrid transport with compatible clients.
Reuse only acknowledged immutable coefficient blocks, explicitly clear removed
blocks, and send changes with sampled raw/XOR LZ4 compression. Keep the image
budget stable and fall back to native payloads for incompressible frames.
Bound reference caches and acknowledgement handling, preserve critical FEC,
and recover from missing references with full refreshes. Disable optional
detail FEC for hybrid envelopes. Canonicalize unused GPU sign bits and record
padding without changing decoded pixels, with a reproducible shader patch.
Bundle LZ4 and its packaged license, document the protocol, and fix the minimal
SteamOS Vulkan include and CUDA-disabled capture guards required by the build.
Validation: full PyroWave-enabled Linux container build and help smoke test;
25 codec cases and all seven client/PyroWave checks passed. Independent
ASan/UBSan mutation and CRC32C checks passed. Windows execution and live
streaming latency remain unverified.
feat(windows): add opt-in DualSense waveform audio hooks
Native waveform sinks need a Sony-matched four-channel audio endpoint that
Windows virtual controllers alone do not provide. Add per-app WASAPI emulation
and a helper that verifies hook readiness before game entry without a debugger.
Forward actuator PCM through the existing haptics transport. Direct native x64
launches are supported; native Windows gameplay remains unverified.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Medium
fix(pyrowave): replace hybrid references with independent LZ4 compression
Keep the native coarse prefix and compress bounded independent detail groups. Remove frame references and ACKs, preserve partial-frame recovery and adaptive detail FEC, and fall back to native frames when compression is unavailable.
Validated with a Linux release build and smoke check, CPU compression/loss tests, four-format Vulkan decode and sustained detail-loss checks, ordinary framing/SDP/RTP/UDP tests, and exact reconstruction benchmarks.
fix(pyrowave): fit stream traffic within the wire bandwidth budget
Reserve critical FEC, packet headers, audio parity and control traffic before
assigning the image budget so the selected bitrate bounds actual wire usage.
Cap negotiation and pacing at the slower known host/client link, and keep
runtime bitrate updates within that cap. Preserve coarse-data protection
when record padding cannot fit, on both Linux and Windows encoder paths.
Validation: full optimized Linux build with both web bundles; all 116 CTests
passed, including PyroWave policy and Linux GPU coverage.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High
fix(pyrowave): remove ineffective LZ4 compression transport
Remove the unsuccessful compression path and bundled LZ4 dependency so
PyroWave sends native frames without the extra CPU compression pass.
Retire compression negotiation while preserving framing, FEC, and wire budgets.
Validated with the Linux release build and all 116 tests, including GPU validation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6-Astra Medium
feat(playnite): allow users to select the installation directory
When URI detection fails, users can select and save the Playnite directory in either web interface. Use that location for plugin installation and game/fullscreen launches while preserving installed and portable extension layouts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(pyrowave): enable Intel D3D11 encoder compatibility
The broad upstream interop probe rejected Intel GPUs for sharing modes the Windows host never uses. Check only the plane texture format and D3D fence imports required by the encoder.
Add Windows GPU encode/decode coverage for changing frames, both bit depths and chroma modes. Validated on Intel UHD 770 and NVIDIA RTX 4090; PyroWave policy and GPU tests pass.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(playnite): support waveform haptics without launch deadlocks
Playnite waveform launches were rejected, and failure cleanup could deadlock all later connections.
Prepare scoped hooks before Playnite and 64-bit Steam start the game, refresh mappings on reconnect, and defer configuration writes until the launch read lock is released.
Require connector 0.4.15; seven focused validation checks passed.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(playnite): prepare Steam haptics from 32-bit hosts
32-bit Playnite could not load the 64-bit audio hook and cancelled game launches. Prepare Steam through the native helper instead, and install connector 0.4.16. Six focused checks and two live Steam preparations passed.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(display): retain virtual displays through capture teardown
Windows normal-display capture references were Linux-only, so app exit could
retire a per-client virtual display while encoder threads were still draining.
Hold RTSP and WebRTC references through their joins, reject fresh capture while
an ended display generation drains, and rearm retained-display recovery only
after Resume admission. Retire paused recovery at capture idle while preserving
live and Remote Monitor peers. Keep deferred Windows stream-start work pending
when the lifecycle gate is busy so launch-owned teardown cannot deadlock while
joining control polling.
Addresses Nonary/Vibepollo#413
Addresses Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Ultra
fix(hdr): handle live color changes without permanent HDR forcing
The session HDR override kept clients in HDR after the host switched to SDR.
Observe display color events with background polling fallback, fence helper
mutations, and finish optional HDR blanking before capture admission.
Publish HDR state after encoder readiness while preserving negotiated Main10,
per-generation metadata caching, and client message deduplication.
Adapt the lifecycle contract assertion to the current launch API argument.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
feat(pyrowave): add paced UDP bandwidth calibration probe
feat(playnite): port compiled connector from Vibepollo #513
Replace the script connector with the reviewed .NET plugin, bounded shutdown
and safe plugin updates. Adapt the payload and signing paths to Vibeshine,
while preserving waveform preparation, reconnect mappings and launcher acknowledgments.
Source: Nonary/Vibepollo#513, merge f1cf988fb35a2a4fa779a261c6d6c455d8010cae
Validated the release and plugin builds, both web bundles and all 121 local tests.
Co-authored-by: Noklef <281545466+Noklef@users.noreply.github.com>
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
fix(linux): allow display rotations through session broker
feat(display): allow up to eight virtual display clients
Remote Monitor was limited to four identities despite the driver's eight
slots. Share a bounded global client limit with normal streams and retain
existing owners when it falls. Count provisioned Linux managed outputs and
explicit connected physical/dummy connectors without duplicate or missing
names. Explain shared capacity in both UIs and deliver the eight-output
helper without rebuilding live four-output pools.
Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(linux): admit client modes on all eight virtual outputs
The eight-output pool exposed connectors rejected by older four-name gates.
Admit exactly Virtual-1..8 in the host and SteamOS broker while retaining
mode and lease checks. Retire a capacity-rejected client's prepared connector
so rejected launches do not consume an extra output beside active peers.
Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(display): preserve Windows and saved client arrangements
Extended sessions overwrote VerifyOnly and reset client placement to the
right. Preserve CCD origins and active peers, and apply saved placement
rules only to the connecting target. Expose directional and manual
arrangement with previews; selection keeps saved rules while only actual
drags place a display and keyboard edits follow the focused client.
Addresses Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(display): include the Windows topology capture declaration
Extended-layout requests capture the current display topology. Include its
owning integration header so Windows builds resolve the new call without
relying on unrelated transitive declarations.
Refs: Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(display): retry authoritative golden restore after fallback
Primary-only session fallbacks renewed the restore cooldown on every
poll, preventing a golden-first baseline from restoring a returning
monitor. Retry the configured golden baseline immediately when its
devices return, while preserving the default session-restore cooldown.
Addresses Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
test(display): compare restored origin coordinates directly
The restore-engine component links only display-device headers. Compare
both restored coordinates to keep the cooldown regression's origin coverage
without requiring the library's out-of-line Point equality operator.
Refs: Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(wgc): cancel helper handshakes before capture joins
A pending WGC handshake could outlast the ten-second video join watchdog
because stopping the capture queue did not stop helper initialization.
Cancel only the retiring capture generation between IPC waits, including
anonymous pipe handoff, and release borrowed display references before join.
Keep healthy startup budgets and native teardown unchanged; add production
regressions for cancellation, resume, ownership, handoff and session isolation.
Addresses Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
test(wgc): use native CRT string helpers on Windows
MinGW defines _TRUNCATE in the CRT, so declaring the portable substitute
breaks the anonymous-handshake fixture. Keep the substitute string helper
on non-Windows hosts and use the native CRT when compiling for Windows.
Refs: Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(display): Preserve physical returns across recovery feedback
A powered-off baseline monitor can return during recovery or its quiet
period and leave an exhausted restore lease asleep. Retain that evidence
until settling and reopen bounded recovery only when an authoritative
physical baseline member becomes enumerable. Preserve existing backoff
and disabled outputs, and keep retired debounce owners from hiding a
replacement owner's display events.
Addresses Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(display): Honor golden-first recovery after session fallback
A confirmed session fallback kept rearming golden's cooldown and prevented a
returned baseline monitor from being restored. Explicit golden-first recovery
now retries that baseline while session-first keeps its cooldown.
Exercise the actual fallback and reopened recovery in regressions, and declare
the Windows test fixture's algorithm dependency.
Refs: Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
test(display): Keep recovery assertions within component linkage
Whole-snapshot comparisons instantiate display-device equality operators that
these isolated test targets do not link. Use the existing fieldwise snapshot
comparison so the declared Windows source lists remain sufficient while
retaining full baseline and primary checks.
Refs: Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(linux): preserve child status and crash restore intent
Competing waitpid sweeps could abort app teardown while rejected rotation
arguments blocked KScreen restore. Reap only detached children, preserve
unknown exit status, and admit the eight supported rotation values.
Persist session-bound desktop state before hotplug and refresh idle intent.
Recover orphan connectors through capture-verified asynchronous restoration,
preserving intentionally disabled monitors when no safe baseline survives.
Addresses Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(linux): preserve idle layouts and bound group polling
Check the owned child first and bound positive process-group scans to avoid
adding procfs work to every control input event while preserving exit status.
Keep idle baselines unarmed, restore only acquired or orphaned displays, and
clear saved intent after verified recovery so later layouts stay authoritative.
Only uncertain mutating helper completion fences future display changes.
Refs: Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(linux): resume marked restores after connector retirement
An interrupted handoff can leave the private connector gone while the final
physical layout and durable restore marker still need completion. Prioritize
armed recovery at startup before refreshing idle preferences. Keep fieldless
legacy idle baselines unarmed unless an active private output needs recovery.
Refs: Nonary/Vibepollo#497
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(display): preserve restore task opt-outs and explain recovery
User-disabled logon recovery tasks could be recreated enabled, and recovery
controls hid automation requirements or retained stale saved-policy gates.
Preserve disabled tasks and remove enabled legacy orphans without snapshots.
Show session snapshots, task state and helper engine in both interfaces.
Refresh snapshot and reset availability after settings saves without a reload
or implicitly starting the helper.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(display): keep legacy recovery controls visible
Recovery settings became hidden inside a native HTML template. Render the
section normally even when automation is disabled, retaining its explanation.
Load restore-task COM headers after the Windows/Winsock prelude so Windows
release builds do not fail the include-order warning-as-error check.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(ui): allow retrying unavailable display recovery status
A failed status fetch disabled its own Retry action when maintenance was
unavailable. Keep read-only retries usable while retaining the existing
snapshot capture policy and blocking overlapping status requests.
Cover repeated status failures and recovery without mutation requests.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(ui): share recovered display maintenance status
Retrying display status updated the snapshot card but left capture and reset
blocked by stale parent state. Publish each fetch's unknown or saved-policy
result to SettingsView so a successful retry restores both recovery actions.
Cover repeated failures followed by available and automation-off responses.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(linux): fit complete multi-output broker requests
Eight managed HDR-capable outputs plus three physical displays need
65 properties and exceeded both session helper argument caps.
Share a fixed 448-property budget for complete 64-output transactions,
retaining the 128 KiB frame, property allowlist and identity controls.
Cover composed requests and exact argument and byte rejection bounds.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max
fix(linux): reliably restore desktop after stream teardown
Establish a verified saved scanout before retiring private connectors, wait
for each hotplug to settle, and strictly verify the complete desktop before
clearing recovery state. Keep failed cleanup recoverable, release drained
desktop ownership, and protect paused apps and retained Remote Monitors.
Resolve remapped mode IDs from current catalog semantics and use bounded,
noninteractive Wayland readiness probes. Rearm failed preparation cleanup,
preserve unpublished admitted connectors, and permit supported rotation
tokens through the session broker.
Validation: 205 regression tests under ASan/UBSan, 39 under ThreadSanitizer,
broker policy checks, and affected production translation-unit compilation.
Live physical-monitor validation remains outstanding.
fix(display): verify snapshot modes before saving restored layout
Use exact temporary mode restoration in both helpers, wait for the full legacy topology, compare rational refresh rates numerically, and retain current snapshots after previous-tier recovery. Pin libdisplaydevice with corrected topology and validation flags.
Validation: eight portable regression tests passed. Windows mock tests and physical 120 Hz retention remain unverified on this macOS host.
fix(linux): honor explicit capture methods for virtual displays
Prefer KMS for automatic virtual display capture, preserve explicit backend selections, and align service overrides, UI warnings, documentation, and policy coverage.
feat(pyrowave): advertise critical FEC overhead to paired clients
Expose the configured critical-block parity percentage in serverinfo and document how client bandwidth calibration accounts for parity and wire overhead.
test(input): add host-only virtual gamepad lifecycle probe
Add a standalone Windows controller creation and teardown probe with HID and XInput inventory, explicit destroy and owner-close cleanup, and reproduction instructions for Steam and SDL tracking.
fix(display): ship the wide-gamut HDR driver correction
Pin the corrected libvirtualdisplay source and v1.6.4 Windows package so
installed virtual displays advertise BT.2020/D65 for HDR. Keep SDR EDIDs
unchanged; client image-quality acceptance remains pending.
Addresses Nonary/vibeshine#270
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(audio): Retain role recovery after visibility failures
Steam visibility failures discarded captured role recovery before disconnected
HDMI endpoints could return. Keep guarded direct restoration after a failed
fallback, including the endpoint selected before a failed show. Retire roles
changed during the visibility RPC while retaining recovery for other roles.
Preserve newer defaults, successor ownership and shutdown cleanup, with
production-function coverage for return and failure ordering.
Addresses Nonary/Vibepollo#470
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(hdr): Ship the Vulkan layer for 32-bit Windows games
32-bit Vulkan games miss HDR formats because the released payload contains
only the x64 layer. Build the x86 layer from pinned source during package
refresh, validate its exports and architecture, and include it in MSI signing.
Register and check each manifest in its own registry view, preserving other
layers and removing partial registrations when disabled.
Addresses Nonary/Vibepollo#418
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(input): Bound Windows desktop recovery and own bindings
Persistent injection failures could retry indefinitely as desktop handles
changed, blocking the input worker. Retry once after successful attachment,
retain the assigned handle, and release superseded bindings safely.
Replay eleven production-source scenarios; seven fail before the repair.
Physical-monitor game window disappearance remains a separate unresolved cause.
Addresses Nonary/Vibepollo#415
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
feat(windows): make automatic service startup optional
The installed host lacked an app control for automatic Windows startup.
Add authenticated startup toggles to both maintenance interfaces backed
by the fixed own-service configuration. Off selects Manual, preserving
manual launch and current sessions; report actual mode and permission errors.
Addresses Nonary/Vibepollo#411
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(kms): read AMD virtual frames on the physical renderer
Display-only KMS cards cannot initialize GL readback, and their advertised
RA24/BA24 framebuffers were rejected by the linear upload fallback or sampled
with the wrong Vulkan channels. Use the selected physical render node for
software capture and preserve packed RGB/alpha ordering in both conversions.
Addresses Nonary/vibeshine#291
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(input): preserve Xbox client profiles on the VHF backend
Xbox-type clients with motion sensors or touchpads could become DualSense
controllers under VHF, disagreeing with ViGEm and Steam's expected handling.
Honor the client-reported Xbox type before capability preferences while
preserving explicit overrides. Exercise the shared production selection
policy for plain VHF and Automatic fallback in regression tests.
Addresses Nonary/vibeshine#286
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
fix(display): recover legacy layouts after broken connections
Recent display-helper disconnects discarded restore intent, allowing
liveness-only reconnects to leave an old layout armed for later login.
Retain recovery until a live stream renews its deadline, reject stale
owner pings, and preserve that deadline across repeated disconnects.
Let disabling automation finish cleanup without bypassing display owners.
Cover recovery, ownership and disabled-policy regressions.
Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
merge(prerelease): reconcile display recovery on vibe-test
Preserve both local and remote prerelease improvements while integrating
the legacy recovery fix. Keep durable desktop snapshots and eight-output
support alongside the newer guarded restore transaction and HDR colors.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(linux): preserve console rendering on multi-GPU hosts
The bridge's PCI spoofing and ambiguous NVIDIA selection could break Virtio
console output and leave private displays unavailable. Pin the isolated GBM
route with a stable PCI default, early SHM import safeguards and truthful PRIME
layout metadata. Reject CPU fallback for managed unknown layouts rather than
reading tiled storage as linear; keep native and explicit linear fallbacks.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(linux): admit globally numbered private display names
A Virtio console can consume Virtual-1 before the managed display pool.
Pin the explicit DRM-to-configfs mapping and admit valid global connector
IDs for requested modes, while the broker verifies actual pool membership.
Cover shifted names without expanding the pool or guessing an offset.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(steamos): share managed connector mapping in the local broker
The local broker shadowed the shared handlers with fixed connector IDs
and public-name lease paths. Shifted DRM names could connect one pool slot
then request modes on another. Inherit the canonical mapped handlers and
cover sparse public names, logical leases and cross-user mode rejection.
Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(linux): make filesystem validation locale-independent
- stop comparing localized stat %F strings
- use -f/-d/-S for object type validation
- retain stat only for ownership and mode
- use C.UTF-8 for machine-host child processes
fix(steam): normalize Pressure Vessel /run/host Proton paths
- translate /run/host/... metadata to host namespace paths
- apply normalization to Proton and Steam client paths
- support system-wide CachyOS Proton direct launches
fix(linux): skip read-only Proton tools for global policy injection
- don't try to write hooks into root-owned compatibility tools
- keep user-owned Proton tool injection unchanged
- report skipped tools instead of PermissionError
fix(packaging): verify installed private host capabilities in installer
- assert private host executable has cap_sys_admin,cap_sys_nice=p after install
- prevent unsafe executable status when host capabilities were not applied
fix(display): serialize remote monitor teardown
Keep display ownership alive through capture joins and close WebRTC before
topology cleanup. Fence monitor generations across rejected activations,
reconcile deferred releases, and retain failed native cleanup for retry.
Drain WGC frame callbacks before releasing capture-manager resources.
Refs: Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Luna High
merge(prerelease): add capture-safe display teardown
Retain display ownership through capture teardown, fence stale monitor
requests, and drain WGC callbacks before releasing capture resources.
Preserve the current configurable capacity and Linux idle-cleanup policy.
Refs: Nonary/Vibepollo#414
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
merge(prerelease): accept Linux hardening from PR 302
Merge the contributor's locale, Proton path and packaging fixes into vibe-test.
Reconcile the stable fixes already in the PR ancestry while preserving newer
wire-budget handling, display teardown and application focus behavior.
Update metadata fixtures and retain unsafe Xauthority rejection coverage.
Closes #302
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
fix(linux): recover machine setup after locale and cwd failures
Valid machine profiles were rejected when service-account commands inherited
an inaccessible caller directory or metadata checks used a translated locale.
Run those commands from / and stabilize native package lifecycle checks.
Retry machine setup in the installer, including older-controller locale recovery,
and stop on failed recovery while preserving existing profiles and pairings.
Addresses Nonary/Vibepollo#514
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
build(gamepad): ship the DualSense identity fix from beta.7
Pin the released driver 0.1.0.48 so GameInput and HIDAPI identify the
same virtual DualSense. Keep the source, archive checksum, CI, installer
checks, and bundled payload aligned with the verified beta.7 release.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Low
fix(pyrowave): establish UDP return paths before calibration
Windows streaming works through outbound UDP exchanges, but calibration
previously sent unsolicited packets to a fresh receiver port. Announce the
sender port over paired HTTPS and verify the client's UDP token before the
measured transfer, without firewall changes. Bound the handshake and exclude
warmups from results while preserving legacy clients.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High
fix(linux): exclude virtual outputs from monitor restore snapshots
Retained streaming outputs could become the saved desktop and prevent TV
restoration when their requested modes changed. Keep new and legacy restore
snapshots physical-only, require a physical restore guard, and retire virtual
connectors even when older snapshots included them, matching Windows behavior.
Validated by a full build, 134 passing tests (one skipped), and user-confirmed
TV restoration after native installation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
feat(display): add the virtual display killswitch on Linux
Linux hosts lacked the UI and API recovery action available on Windows.
Expose confirmed termination in Maintenance, attempt physical layout restore,
and disconnect every managed kernel output despite active ownership.
Verify removal and report restoration separately while preserving mutation fences.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
fix(display): honor refresh overrides and older Windows limits
Match refresh mappings against stream FPS before automatic promotion so
60 FPS sessions can advertise and apply explicit 480/1000 Hz modes.
Resolve creation, apply and recovery consistently, preserving fractional
rates and capping pre-24H2 Windows modes at the resolution's 1 MHz scan limit.
Validation: Linux release build and both web bundles passed; 135 tests
passed, 2 skipped. Windows build and live streaming remain unqualified.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
fix(ui): restore a focused Everyday settings workflow
Everyday buried Vibeshine's distinctive features among generic controls.
Put virtual screens, smoothness, PyroWave and Remote Monitor together,
with pacing integrations, visible library links and grouped tuning.
Correct Windows limiter choices and FEC bounds while preserving old drafts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
fix(display): terminate remote monitors despite restore failure
Disconnect Monitor must remove its Windows screen even when the remaining
display topology cannot be restored. Use exact-owner native termination,
retain capture and peer ownership guards, and report removal failures.
Refs: Nonary/Vibepollo#568
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
feat(input): emulate wired USB DualSense haptics on Windows
Expose controller and audio interfaces together so games can send native
waveform haptics through the existing Moonlight feedback path. Add an opt-in
installer component using unmodified, verified usbip-win2 drivers; preserve
shared installs and wait for HID/audio readiness before per-app launches.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
feat(ui): add dashboard virtual screen recovery
Make emergency recovery reachable when a virtual screen leaves the PC blank.
Add a first-visit guide and confirmed dashboard action, removing virtual
outputs before trying the saved layout and a connected physical monitor.
Validation: Linux build, 33 browser checks, and 10 targeted policy tests.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
feat(display): recover orphan virtual screens on monitor events
Stuck virtual screens can survive failed desktop restoration. Use monitor
wake/topology events to recheck failure and remove only captured orphans
when physical output is verified and all display owners are gone.
Keep recovery tied to its session and generation without periodic probes
or time-based expiry. Preserve the current physical desktop layout.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
fix(hdr): wait for display setup before starting capture
Capture could probe HDR during the helper's temporary SDR window.
Require verified display setup before launch, resume, and WebRTC
capture, then follow real HDR/SDR changes through normal reinit.
Remove mutation fencing, frame holds, color generations, and settling timers.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High
fix(hdr): preserve driver-owned calibration profiles
Host profile edits competed with the Vibeshine driver's retained calibration.
Leave those associations intact while keeping explicit assignment for SudoVDA.
Prevent rejected activation from leaving registry-only profiles, avoid duplicate
activation, and remove UI guidance requesting redundant client assignment.
Validated the full local build and CTest suite: 154 passed, one skipped.
Refs #301
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
docs(release): document 2.0.0-stable.1 changes
Explain the stable delta from 2.0.0 with user-facing outcomes and setup details.
Cover display recovery, controller haptics, HDR, PyroWave, and Linux fixes while
excluding withdrawn experiments and intermediate prerelease fixes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(display): keep locked desktops reachable during setup failures
Mandatory display setup rejected reboot and lock-screen connections with 503 before users could remotely unlock Windows. Continue launch, resume, and WebRTC with existing display settings when setup fails or times out, and preserve deferred setup across app startup for retry after unlock.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(webui): keep the interface responsive while streams pause
Display capability discovery could block the HTTPS event loop and keep the UI loading while a paused app retained its display. Isolate metadata work, open the UI after authentication, and let stalled status requests time out and retry. Remove the dashboard metadata wait and cover startup and recovery with a browser regression test.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
feat(input): boost DualSense haptics while preserving contrast
Make streamed haptics easier to feel without hard clipping or flattening waveforms.
Add configurable strength lift on Windows and Linux, preserving actuator peak gaps with recent-peak headroom control and per-controller smoothing.
Keep 1.0 as unchanged output and support per-client overrides.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High
fix(input): preserve DualSense audio across Moonlight pauses
Disconnecting the virtual controller invalidated the game's haptics audio endpoint. Honor Moonlight gcpersist by retaining the composite DualSense while the app runs and rebinding feedback on resume. Release retained devices when the app ends and preserve teardown when persistence is disabled.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
feat(pyrowave): Calibrate pacing with frame-shaped UDP probes
Negotiated link speed can exceed what a receiver absorbs in video bursts.
Add frame-shaped probes and client-calibrated pacing, using 80% link headroom by default while accounting for stream demand and wire overhead.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(stream): Bound UDP retries and account for failed frames
Socket pressure must not block streaming or silently leave holes in frames counted as delivered.
Bound nonblocking sends, stop failed fallback sends, preserve sequence reservations and traffic accounting, and limit failure logging.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(input): Use USB audio for automatically selected DualSense
DualSense waveform haptics need the composite audio function outside application opt-in scopes too.
Select it when DualSense is chosen and the transport is available, retain client capability checks, and keep diagnostics quiet.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(dualsense): Locate readiness by USB host and imported port
The released USB transport can generate instance IDs that do not match the requested serial.
Find the controller under the opened host and imported port before checking HID and audio readiness, avoiding unrelated devices.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(display): Correct helper linkage and include x86 HDR manifest
Display cleanup helpers need external linkage and the Sunshine identity helper needs its namespace qualifier.
Correct both references and include the x86 Vulkan HDR manifest already required by installer and packaging contracts.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
fix(deps): Update virtual gamepad report and initialization fixes
Use the virtual gamepad fixes for deferred HID report ownership and quiet Switch controller initialization.
Advance the submodule to the two dedicated driver fixes without including local test-signing payloads.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
feat(release): add gated daily prereleases, safety contracts and exact nightly notes
ci: forbid self-hosted runners for daily builds
feat(release): expose validated Moonlight Windows product version
ci: use reviewed primary sources and bounded Linux resources
feat(installer): require exact-certificate consent for newer self-signed gamepads
Default to verified prerelease notifications and preserve stable-only choices
(cherry picked from commit 57fc027ee71594d909f0df1cee5c4c64fe493c6b)
fix: align gamepad source pin with verified producer package
Use the immutable beta.7 source already required by the release archive lock. The previous gitlink pointed to an unpublished divergent driver branch while packaging still consumed beta.7; its public client and protocol blobs are identical, but its two driver-only fixes cannot ship through the beta.7 DLL. Preserve the producer revision/hash/DriverVer gate and defer those unreleased driver changes to a separately tested producer release.
ci(linux): reuse verified CUDA and compiler caches on bounded hosted runners
Avoid duplicate recursive source checkout, shallow pinned submodules, retain native package tests and Pascal checks, and provide an exact-source artifact-only validation lane without signing or package installation.
ci(linux): isolate exact-source validation in registered manual workflow
Skip release selection and ordinary Windows/Arch/signing-summary jobs when hosted Linux validation is requested; preserve default behavior and dispatch only the no-key artifact route with tests enabled.
fix(ci): scope native container Git trust to the verified workspace
The hosted Arch submodule checkout failed after checkout action restored its temporary Git configuration. Apply safe.directory only to that exact workspace and invocation, retaining the pinned SHA and rejecting wildcard/global trust in workflow contracts.
fix(ci): validate Linux packages with the verified nonzero source version
Preserve package downgrade protection and use each fork current source base with a validation prerelease suffix in both isolated hosted entry points.
fix(ci): fetch both pinned Linux driver sources before package configuration
The shallow initial checkout omitted DualSense source templates required by configure-only packaging. Fetch only libvirtualdisplay and libvirtualgamepad, verify their required files, and keep existing policy guards and package-source preparation.
fix(ci): honor signed installed GCC14 during Arch dependency resolution
Check exact compiler package versions, synchronize only dependencies reported missing by pacman deptest, then require the full dependency set to pass before fingerprinting the installed ABI. Exercise wrong-compiler, sync-failure and unsatisfied-version fixtures.
fix(updates): use the tray callback ABI without redirecting old notifications
Keep the captured release URL in notification text and leave updater toasts nonclickable because the tray C API lacks notification context. Preserve Web UI links, prerelease opt-out, delivered-version suppression and state persistence. Compile and exercise the production delivery method with SUNSHINE_TRAY=1 against system_tray.h.
fix(display): verify the reviewed producer source and payload
Lock the v1.6.4 archive, evidence, source revision, actual INF DriverVer and every producer file. Reject changed fresh downloads and unverified caches before package refresh, including explicit prebuilt roots, while preserving the later Linux source pin and installer trust policy.
Validate with mocked fresh/cache tamper tests, Windows PowerShell 5.1, the mandatory driver safety suite, read-only public artifact fetch/cache verification, actionlint and the CMake lock declaration.
Fail Linux component builds early and reuse verified package sources
Declare the routed-link Boost.Asio interface, compile configured component targets before host and CUDA work, seed validation sources from the exact verified shallow checkout, and retain only verified dependency/compiler cache work after trusted manual build failures.
Model early component validation in the CUDA policy fixture
Stub the external component helper explicitly and verify configure, component and full-build ordering while retaining private CUDA and Pascal assertions. Normalize fixture paths so the same policy checks run on Windows and hosted Linux.
fix(linux): avoid automatic portal consent after KMS selection
Skip probing the desktop portal when automatic capture has already selected
KMS or the native compositor. This prevents unattended private-display
startup from opening a portal consent prompt while retaining explicit portal
requests and the existing X11/NvFBC fallback paths.
Cover automatic and explicit selection in the existing pure policy fixture.
Validated all four fixture cases through a native assertion harness, all 16
policy truth rows, and the actual production guard with a mocked verifier.
Full hosted Linux compilation remains a follow-up validation step.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 35a68dd28e653aabe7915ddb5b2d20b42629b54e)
test(display): give snapshot fixtures valid resolution and refresh
Use 1920x1080 at 60/1 in the shared fake snapshot instead of a zero-sized
mode with a zero refresh denominator. This lets the pinned display library
compare realistic snapshots while preserving every existing assertion and
production validity check.
Validated 103 state-machine, 37 restore-engine, and 8 snapshot-restore cases
against the source worktree and exact pinned display headers. No live display
operations ran.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 838f10575ad65db79116914b042c1c37483c5b91)
test(updater): register the standalone release selection policy
Expose the existing metadata, version, and package-selection regression
harness as test_fast_update_release so BUILD_TESTS and fast test runs
exercise the updater policy. Link only its JSON dependency and retain
assertions in Release with the compiler-specific NDEBUG undefine option.
Validated the actual standalone harness through the production target helper
in Release: build and CTest fast-label run pass, with -UNDEBUG after -DNDEBUG.
Disabling fast tests skips the target cleanly. Preserve the existing tray
interface component registration without importing Apollo-only state helpers.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit ea5c86f4d1174213288f0554da72a52e603cac91)
Declare display helper component Boost and JSON dependencies
(cherry picked from commit c98b7c5422853db362c76242ac6d49a5c447fe0e)
Compile fast policy targets alongside component tests before Linux packaging
Discover both configured test categories through the CMake codemodel while keeping the required routed-link gate and excluding unrelated app targets.
(cherry picked from commit 6ea72f0dd1ccc1ed8e593cd29196592620b3f390)
Declare the DualSense component Boost Format interface
Link the production stat-tracker header dependency explicitly and verify the pinned modular Boost headers with positive and missing-interface compile probes.
Model: GPT-6.1 (medium).
ci(windows): opt in to compile and run tests without daily signing
Expose a default-off build_tests input on artifact-only Windows validation
and forward it to the reusable build. Execute CTest whenever tests are built,
with empty suites and test failures blocking success. Keep daily artifact
signing gated solely by daily_unsigned and pass no signing secrets from the
validation wrapper.
Add a workflow regression fixture for compile/CTest input alignment, hosted
artifact-only defaults, and independent daily signing guards. All three
fixture cases, actionlint, and whitespace checks pass. Full hosted application
compilation and CTest execution remain pending; no local machine changes ran.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 19a4165016aaa3de3ade55fa24eba5a4f334c7e6)
ci(linux): cache only the verified CUDA installer
Caching the full CUDA SDK plus installer exceeds the standard shared cache budget. Restore and save only the pinned installer under a new cuda-installer-v2 key, with no fallback to SDK archives. Each fresh job still installs and patches the complete CUDA 12.9 toolkit.
Exercise checksum rejection, two fresh toolkit jobs, unchanged trusted-failure eligibility, and final Pascal/CTest/package gates. Keep the prepare helper, package recipe, and release validation unchanged.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
test(updater): match release fixtures to the build platform
Linux CTest rejected the standalone harness Windows-only installer before comparing stable respins. Supply the real build-platform package family and architecture in fixtures while preserving production completeness and version-selection policy.
Cover stable respin ordering, older rejection, wrong-platform and wrong-architecture assets, empty or pending packages, and missing nightly checksums. Keep assertions enabled explicitly and reject assertion-disabled harness builds.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 8383852aceadf7acf7cf1722089fdecaa03972b0)
test(packaging): expect the audited libvirtualdisplay v1.6.4 release
Correct the stale typed contract expectation without changing the producer lock or runtime policy. Verify the exact reviewed source revision, archive hash and INF version, and evaluate the real CMake contract against the same release.
Validation: two focused provenance tests and git diff --check passed. No driver, trust or installer operations ran.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 78660a102ec51119893d35fc02cd8dc69e85161d)
test(display): preserve Boost headers in wake recovery fixtures
Direct Python compiler calls lost the modular Boost include requirements, breaking the observer and its mandatory backend regression. Pass the evaluated Boost::algorithm header closure through both fixtures without changing production code or assertions.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 1959e585676ab819e85fe833887d3eddfce333b0)
test(playnite): isolate SDK discovery hints inside the CMake fixture
Clear DOTNET_ROOT and ProgramFiles in the generated CMake child script before
running unchanged production discovery. Windows may retain its well-known
ProgramFiles environment value despite a subprocess override, allowing a
host-installed SDK hint to mask the fake PATH SDK and fail the exact-path test.
Remove inherited case variants before setting child environment values and
include expected/found paths in the failure diagnostic.
Preserve PATH, empty-cache, and explicit discovery cases plus compiled upgrade
and filesystem cleanup policies. A temporary competing SDK reproduces the
original failure; clearing hints restores the exact PATH result with both
MSYS2 and native CMake. All full fixture checks pass with both tools and the
actual UCRT64 compiler. No production code or machine configuration changes.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 6acc22f63402a9e16d8fe6d37cff2cf1472063b0)
fix(hdr): Preserve driver calibration without monitor metadata
A permanent Sunshine monitor selected through the physical output route could receive a client profile when optional enumeration failed or omitted its identity. Recognize the resolved default driver hardware-ID families before enumeration, preserving physical and SudoVDA overrides and the existing custom-metadata fallback. Add policy boundary tests and regressions extracted from the actual production guard.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 508da3612fe59fe27275756d9267dfce5929d471)
test(display): use valid modes in snapshot roundtrip fixture
Zero-initialized refresh rates fail the pinned mode-verification equality contract, so the storage roundtrip test failed despite preserving its data. Supply valid 1920x1080 at 60/1 modes for both displays while keeping every assertion and production check unchanged.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 5d4b7a53e45450dee0cee96169910f046a2ae1cf)
Keep the UDP probe measurement open until its fixed deadline
A Windows timer can return early from the final wait, producing a measured
probe window below 2000 ms even though all expected packets were sent. Recheck
the original steady-clock deadline after each return through the existing
injected waiter. Do not restart the duration or change packet pacing, retry
budgets, handshake validation, burst scheduling, or overload bounds.
Add deterministic fake-clock coverage for repeated early returns, completed
deadlines, and waiter exception propagation. Preserve the original elapsed,
packet count, sequence, token, and pacing assertions.
Validation: the unmodified native loopback test reproduced 1999.4009 ms on
iteration 4 of 5. The corrected Release native suite passed all 9 GTests,
and the unchanged paced loopback regression passed 10 consecutive runs.
Compiled with GCC 16.2 and -UNDEBUG using cached Boost/GTest dependencies.
Full hosted application validation remains an integration check.
Source-first implementation based on 0ea017a8db1b653921e73a3ee45f1d5506c7fbb4.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium
(cherry picked from commit 92b51649ae43547dd6a081af607fc2e95618202f)
fix(web): Accept CRLF checkouts when verifying design tokens
Windows Git checkouts convert the generated token files to CRLF, causing check mode to reject otherwise current outputs. Accept that checkout conversion only during comparison, preserving strict content checks and the existing LF generation and print behavior.
Exercise the real generator in isolated fixtures covering equivalent line endings, genuine drift, missing files, unchanged check/print inputs and deterministic generation.
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra
(cherry picked from commit 489fffa883d5d027cdb56636babe9c86af3898be)
fix(ci): reuse one pinned nightly gamepad signing identity
Replace per-run certificate generation with scoped encrypted CI inputs and an exact public thumbprint. Reject invalid or expiring identities, export only the public certificate, and retain consent, producer provenance, numeric driver-version and no-trust-mutation contracts. Two actual disposable signing passes reused identical certificates.
test(video): bound readiness shutdown extraction to its admission block
test(playnite): retain the selected SDK framework during restore
fix(ci): align certificate identity checks with the persistent nightly signer
fix(test): supply replay dependencies and product-scoped helper fixtures
fix(display): synchronize dispatcher shutdown with idle waits
Protect both stop predicates with the corresponding condition-variable mutex to prevent shutdown losing its notification. Exercise 1000 idle shutdowns under a bounded component timeout. Preserve the shared helper directory when redirecting Linux lifecycle fixtures.
fix(ci): fetch full ancestry for nightly version resolution