github Nonary/vibeshine daily-2026-10-11
Nightly 2026-10-11

latest release: daily-2026-10-11.2
pre-release4 hours ago

This is a nightly release of Vibeshine and contains several bug fixes and may contain new features. Check the commit log for more information.

Windows installer · Linux (Arch x86_64)

Nightly Windows installers are unsigned and include self-signed gamepad components. They may cause false-positive antivirus alerts.

Commit log

Source: aaa39188cc78

Since the preceding stable release 2.0.0: compare exact sources.

3ed6deafe2d9

fix(linux): restore displays asynchronously without stalling Web UI

Display cleanup and KScreen queries could block the HTTPS event loop after
resume. Dispatch restores through the session helper, keep status queries
passive, and move display-layout queries off the listener.
Bound helper replies and fence uncertain compositor mutations while retaining
saved topology and canceling stale restores when ownership changes.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

fb7f6c85fb5d

feat(focus): share managed application focus across platforms

Linux managed launches lacked Playnite's foreground focus behavior.
Add shared focus settings and platform adapters for Steam, Lutris and
Playnite, preserving legacy preferences and cancelling pending focus
when the application session ends. Pass zero values explicitly so
turning focus off also disables the Windows launcher defaults.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

a4c777d6dc71

docs: clarify 2.0.0 client requirements and gamepad features

3ff03b545c86

fix(release): rebuild Arch indexes from the verified package

Avoid repo-add deleting an old package that a wildcard will try to read later in the same publication. Rebuild both signed indexes from the exact verified release payload and remove obsolete product packages only after signing succeeds.

Compare package metadata literally and cover fresh, repeated, stale, and missing-payload publication with real repo-add and disposable GPG fixtures.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

0a050bdba002

feat(pyrowave): add optional hybrid block reuse and LZ4 transport

Negotiate version 1 of the opt-in hybrid transport with compatible clients.
Reuse only acknowledged immutable coefficient blocks, explicitly clear removed
blocks, and send changes with sampled raw/XOR LZ4 compression. Keep the image
budget stable and fall back to native payloads for incompressible frames.

Bound reference caches and acknowledgement handling, preserve critical FEC,
and recover from missing references with full refreshes. Disable optional
detail FEC for hybrid envelopes. Canonicalize unused GPU sign bits and record
padding without changing decoded pixels, with a reproducible shader patch.

Bundle LZ4 and its packaged license, document the protocol, and fix the minimal
SteamOS Vulkan include and CUDA-disabled capture guards required by the build.

Validation: full PyroWave-enabled Linux container build and help smoke test;
25 codec cases and all seven client/PyroWave checks passed. Independent
ASan/UBSan mutation and CRC32C checks passed. Windows execution and live
streaming latency remain unverified.

b2126c332124

feat(windows): add opt-in DualSense waveform audio hooks

Native waveform sinks need a Sony-matched four-channel audio endpoint that
Windows virtual controllers alone do not provide. Add per-app WASAPI emulation
and a helper that verifies hook readiness before game entry without a debugger.
Forward actuator PCM through the existing haptics transport. Direct native x64
launches are supported; native Windows gameplay remains unverified.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Medium

a88e04eb0fce

fix(pyrowave): replace hybrid references with independent LZ4 compression

Keep the native coarse prefix and compress bounded independent detail groups. Remove frame references and ACKs, preserve partial-frame recovery and adaptive detail FEC, and fall back to native frames when compression is unavailable.

Validated with a Linux release build and smoke check, CPU compression/loss tests, four-format Vulkan decode and sustained detail-loss checks, ordinary framing/SDP/RTP/UDP tests, and exact reconstruction benchmarks.

1eb4b2997bf3

fix(pyrowave): fit stream traffic within the wire bandwidth budget

Reserve critical FEC, packet headers, audio parity and control traffic before
assigning the image budget so the selected bitrate bounds actual wire usage.
Cap negotiation and pacing at the slower known host/client link, and keep
runtime bitrate updates within that cap. Preserve coarse-data protection
when record padding cannot fit, on both Linux and Windows encoder paths.

Validation: full optimized Linux build with both web bundles; all 116 CTests
passed, including PyroWave policy and Linux GPU coverage.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High

d1c93a155f54

fix(pyrowave): remove ineffective LZ4 compression transport

Remove the unsuccessful compression path and bundled LZ4 dependency so
PyroWave sends native frames without the extra CPU compression pass.
Retire compression negotiation while preserving framing, FEC, and wire budgets.

Validated with the Linux release build and all 116 tests, including GPU validation.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6-Astra Medium

a67bda59748d

feat(playnite): allow users to select the installation directory

When URI detection fails, users can select and save the Playnite directory in either web interface. Use that location for plugin installation and game/fullscreen launches while preserving installed and portable extension layouts.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

ff41bda9aa10

fix(pyrowave): enable Intel D3D11 encoder compatibility

The broad upstream interop probe rejected Intel GPUs for sharing modes the Windows host never uses. Check only the plane texture format and D3D fence imports required by the encoder.

Add Windows GPU encode/decode coverage for changing frames, both bit depths and chroma modes. Validated on Intel UHD 770 and NVIDIA RTX 4090; PyroWave policy and GPU tests pass.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

07589be63787

fix(playnite): support waveform haptics without launch deadlocks

Playnite waveform launches were rejected, and failure cleanup could deadlock all later connections.
Prepare scoped hooks before Playnite and 64-bit Steam start the game, refresh mappings on reconnect, and defer configuration writes until the launch read lock is released.
Require connector 0.4.15; seven focused validation checks passed.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

6d8fc5acba69

fix(playnite): prepare Steam haptics from 32-bit hosts

32-bit Playnite could not load the 64-bit audio hook and cancelled game launches. Prepare Steam through the native helper instead, and install connector 0.4.16. Six focused checks and two live Steam preparations passed.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

830b8187b0ea

fix(display): retain virtual displays through capture teardown

Windows normal-display capture references were Linux-only, so app exit could
retire a per-client virtual display while encoder threads were still draining.
Hold RTSP and WebRTC references through their joins, reject fresh capture while
an ended display generation drains, and rearm retained-display recovery only
after Resume admission. Retire paused recovery at capture idle while preserving
live and Remote Monitor peers. Keep deferred Windows stream-start work pending
when the lifecycle gate is busy so launch-owned teardown cannot deadlock while
joining control polling.

Addresses Nonary/Vibepollo#413
Addresses Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol Ultra

52e647330669

fix(hdr): handle live color changes without permanent HDR forcing

The session HDR override kept clients in HDR after the host switched to SDR.
Observe display color events with background polling fallback, fence helper
mutations, and finish optional HDR blanking before capture admission.
Publish HDR state after encoder readiness while preserving negotiated Main10,
per-generation metadata caching, and client message deduplication.
Adapt the lifecycle contract assertion to the current launch API argument.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

c1a9f5dfb78f

feat(pyrowave): add paced UDP bandwidth calibration probe

f6697e8971ed

feat(playnite): port compiled connector from Vibepollo #513

Replace the script connector with the reviewed .NET plugin, bounded shutdown
and safe plugin updates. Adapt the payload and signing paths to Vibeshine,
while preserving waveform preparation, reconnect mappings and launcher acknowledgments.

Source: Nonary/Vibepollo#513, merge f1cf988fb35a2a4fa779a261c6d6c455d8010cae
Validated the release and plugin builds, both web bundles and all 121 local tests.

Co-authored-by: Noklef <281545466+Noklef@users.noreply.github.com>
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

2373d7211e05

fix(linux): allow display rotations through session broker

5596183265ed

feat(display): allow up to eight virtual display clients

Remote Monitor was limited to four identities despite the driver's eight
slots. Share a bounded global client limit with normal streams and retain
existing owners when it falls. Count provisioned Linux managed outputs and
explicit connected physical/dummy connectors without duplicate or missing
names. Explain shared capacity in both UIs and deliver the eight-output
helper without rebuilding live four-output pools.

Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

781c2b7fc4b0

fix(linux): admit client modes on all eight virtual outputs

The eight-output pool exposed connectors rejected by older four-name gates.
Admit exactly Virtual-1..8 in the host and SteamOS broker while retaining
mode and lease checks. Retire a capacity-rejected client's prepared connector
so rejected launches do not consume an extra output beside active peers.

Addresses Nonary/Vibepollo#519
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

a4549a366ae6

fix(display): preserve Windows and saved client arrangements

Extended sessions overwrote VerifyOnly and reset client placement to the
right. Preserve CCD origins and active peers, and apply saved placement
rules only to the connecting target. Expose directional and manual
arrangement with previews; selection keeps saved rules while only actual
drags place a display and keyboard edits follow the focused client.

Addresses Nonary/Vibepollo#531

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

7bbf111bc90d

fix(display): include the Windows topology capture declaration

Extended-layout requests capture the current display topology. Include its
owning integration header so Windows builds resolve the new call without
relying on unrelated transitive declarations.

Refs: Nonary/Vibepollo#531
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

52b8bf548898

fix(display): retry authoritative golden restore after fallback

Primary-only session fallbacks renewed the restore cooldown on every
poll, preventing a golden-first baseline from restoring a returning
monitor. Retry the configured golden baseline immediately when its
devices return, while preserving the default session-restore cooldown.

Addresses Nonary/Vibepollo#518

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

c9b1f431ee04

test(display): compare restored origin coordinates directly

The restore-engine component links only display-device headers. Compare
both restored coordinates to keep the cooldown regression's origin coverage
without requiring the library's out-of-line Point equality operator.

Refs: Nonary/Vibepollo#518
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

cadef93fe106

fix(wgc): cancel helper handshakes before capture joins

A pending WGC handshake could outlast the ten-second video join watchdog
because stopping the capture queue did not stop helper initialization.
Cancel only the retiring capture generation between IPC waits, including
anonymous pipe handoff, and release borrowed display references before join.
Keep healthy startup budgets and native teardown unchanged; add production
regressions for cancellation, resume, ownership, handoff and session isolation.

Addresses Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

59e4fa755ee7

test(wgc): use native CRT string helpers on Windows

MinGW defines _TRUNCATE in the CRT, so declaring the portable substitute
breaks the anonymous-handshake fixture. Keep the substitute string helper
on non-Windows hosts and use the native CRT when compiling for Windows.

Refs: Nonary/vibeshine#276
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

ef4c0e2dd109

fix(display): Preserve physical returns across recovery feedback

A powered-off baseline monitor can return during recovery or its quiet
period and leave an exhausted restore lease asleep. Retain that evidence
until settling and reopen bounded recovery only when an authoritative
physical baseline member becomes enumerable. Preserve existing backoff
and disabled outputs, and keep retired debounce owners from hiding a
replacement owner's display events.

Addresses Nonary/Vibepollo#516
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

8aa2abe3d600

fix(display): Honor golden-first recovery after session fallback

A confirmed session fallback kept rearming golden's cooldown and prevented a
returned baseline monitor from being restored. Explicit golden-first recovery
now retries that baseline while session-first keeps its cooldown.
Exercise the actual fallback and reopened recovery in regressions, and declare
the Windows test fixture's algorithm dependency.

Refs: Nonary/Vibepollo#516

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

90cd49e46aba

test(display): Keep recovery assertions within component linkage

Whole-snapshot comparisons instantiate display-device equality operators that
these isolated test targets do not link. Use the existing fieldwise snapshot
comparison so the declared Windows source lists remain sufficient while
retaining full baseline and primary checks.

Refs: Nonary/Vibepollo#516

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

a429aa68ce10

fix(linux): preserve child status and crash restore intent

Competing waitpid sweeps could abort app teardown while rejected rotation
arguments blocked KScreen restore. Reap only detached children, preserve
unknown exit status, and admit the eight supported rotation values.
Persist session-bound desktop state before hotplug and refresh idle intent.
Recover orphan connectors through capture-verified asynchronous restoration,
preserving intentionally disabled monitors when no safe baseline survives.

Addresses Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

691c40ba996d

fix(linux): preserve idle layouts and bound group polling

Check the owned child first and bound positive process-group scans to avoid
adding procfs work to every control input event while preserving exit status.
Keep idle baselines unarmed, restore only acquired or orphaned displays, and
clear saved intent after verified recovery so later layouts stay authoritative.
Only uncertain mutating helper completion fences future display changes.

Refs: Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

31b3bcf4cef7

fix(linux): resume marked restores after connector retirement

An interrupted handoff can leave the private connector gone while the final
physical layout and durable restore marker still need completion. Prioritize
armed recovery at startup before refreshing idle preferences. Keep fieldless
legacy idle baselines unarmed unless an active private output needs recovery.

Refs: Nonary/Vibepollo#497

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

8749cac09d63

fix(display): preserve restore task opt-outs and explain recovery

User-disabled logon recovery tasks could be recreated enabled, and recovery
controls hid automation requirements or retained stale saved-policy gates.
Preserve disabled tasks and remove enabled legacy orphans without snapshots.
Show session snapshots, task state and helper engine in both interfaces.
Refresh snapshot and reset availability after settings saves without a reload
or implicitly starting the helper.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

e9eb03244dc0

fix(display): keep legacy recovery controls visible

Recovery settings became hidden inside a native HTML template. Render the
section normally even when automation is disabled, retaining its explanation.
Load restore-task COM headers after the Windows/Winsock prelude so Windows
release builds do not fail the include-order warning-as-error check.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

1f41888cd5d4

fix(ui): allow retrying unavailable display recovery status

A failed status fetch disabled its own Retry action when maintenance was
unavailable. Keep read-only retries usable while retaining the existing
snapshot capture policy and blocking overlapping status requests.
Cover repeated status failures and recovery without mutation requests.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

c1b60490af08

fix(ui): share recovered display maintenance status

Retrying display status updated the snapshot card but left capture and reset
blocked by stale parent state. Publish each fetch's unknown or saved-policy
result to SettingsView so a successful retry restores both recovery actions.
Cover repeated failures followed by available and automation-off responses.

Addresses Nonary/vibeshine#282

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

6d7c7dbca9fb

fix(linux): fit complete multi-output broker requests

Eight managed HDR-capable outputs plus three physical displays need
65 properties and exceeded both session helper argument caps.
Share a fixed 448-property budget for complete 64-output transactions,
retaining the 128 KiB frame, property allowlist and identity controls.
Cover composed requests and exact argument and byte rejection bounds.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Max

ce6d9e8588a3

fix(linux): reliably restore desktop after stream teardown

Establish a verified saved scanout before retiring private connectors, wait
for each hotplug to settle, and strictly verify the complete desktop before
clearing recovery state. Keep failed cleanup recoverable, release drained
desktop ownership, and protect paused apps and retained Remote Monitors.

Resolve remapped mode IDs from current catalog semantics and use bounded,
noninteractive Wayland readiness probes. Rearm failed preparation cleanup,
preserve unpublished admitted connectors, and permit supported rotation
tokens through the session broker.

Validation: 205 regression tests under ASan/UBSan, 39 under ThreadSanitizer,
broker policy checks, and affected production translation-unit compilation.
Live physical-monitor validation remains outstanding.

4225211b8e13

fix(display): verify snapshot modes before saving restored layout

Use exact temporary mode restoration in both helpers, wait for the full legacy topology, compare rational refresh rates numerically, and retain current snapshots after previous-tier recovery. Pin libdisplaydevice with corrected topology and validation flags.

Validation: eight portable regression tests passed. Windows mock tests and physical 120 Hz retention remain unverified on this macOS host.

fd9b59ff1591

fix(linux): honor explicit capture methods for virtual displays

Prefer KMS for automatic virtual display capture, preserve explicit backend selections, and align service overrides, UI warnings, documentation, and policy coverage.

4b2ba5fc07c2

feat(pyrowave): advertise critical FEC overhead to paired clients

Expose the configured critical-block parity percentage in serverinfo and document how client bandwidth calibration accounts for parity and wire overhead.

19e80502ff23

test(input): add host-only virtual gamepad lifecycle probe

Add a standalone Windows controller creation and teardown probe with HID and XInput inventory, explicit destroy and owner-close cleanup, and reproduction instructions for Steam and SDL tracking.

757a3657ad91

fix(display): ship the wide-gamut HDR driver correction

Pin the corrected libvirtualdisplay source and v1.6.4 Windows package so
installed virtual displays advertise BT.2020/D65 for HDR. Keep SDR EDIDs
unchanged; client image-quality acceptance remains pending.

Addresses Nonary/vibeshine#270
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

9f8aabeeb0b8

fix(audio): Retain role recovery after visibility failures

Steam visibility failures discarded captured role recovery before disconnected
HDMI endpoints could return. Keep guarded direct restoration after a failed
fallback, including the endpoint selected before a failed show. Retire roles
changed during the visibility RPC while retaining recovery for other roles.
Preserve newer defaults, successor ownership and shutdown cleanup, with
production-function coverage for return and failure ordering.

Addresses Nonary/Vibepollo#470

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

4f02a037372e

fix(hdr): Ship the Vulkan layer for 32-bit Windows games

32-bit Vulkan games miss HDR formats because the released payload contains
only the x64 layer. Build the x86 layer from pinned source during package
refresh, validate its exports and architecture, and include it in MSI signing.
Register and check each manifest in its own registry view, preserving other
layers and removing partial registrations when disabled.

Addresses Nonary/Vibepollo#418

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

c5e1cd731230

fix(input): Bound Windows desktop recovery and own bindings

Persistent injection failures could retry indefinitely as desktop handles
changed, blocking the input worker. Retry once after successful attachment,
retain the assigned handle, and release superseded bindings safely.

Replay eleven production-source scenarios; seven fail before the repair.
Physical-monitor game window disappearance remains a separate unresolved cause.

Addresses Nonary/Vibepollo#415
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

235a32e495df

feat(windows): make automatic service startup optional

The installed host lacked an app control for automatic Windows startup.
Add authenticated startup toggles to both maintenance interfaces backed
by the fixed own-service configuration. Off selects Manual, preserving
manual launch and current sessions; report actual mode and permission errors.

Addresses Nonary/Vibepollo#411

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

3e8cfdc0c6ff

fix(kms): read AMD virtual frames on the physical renderer

Display-only KMS cards cannot initialize GL readback, and their advertised
RA24/BA24 framebuffers were rejected by the linear upload fallback or sampled
with the wrong Vulkan channels. Use the selected physical render node for
software capture and preserve packed RGB/alpha ordering in both conversions.

Addresses Nonary/vibeshine#291

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

cbe1f348a73a

fix(input): preserve Xbox client profiles on the VHF backend

Xbox-type clients with motion sensors or touchpads could become DualSense
controllers under VHF, disagreeing with ViGEm and Steam's expected handling.
Honor the client-reported Xbox type before capability preferences while
preserving explicit overrides. Exercise the shared production selection
policy for plain VHF and Automatic fallback in regression tests.

Addresses Nonary/vibeshine#286
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

1594f8a7e5e2

fix(display): recover legacy layouts after broken connections

Recent display-helper disconnects discarded restore intent, allowing
liveness-only reconnects to leave an old layout armed for later login.
Retain recovery until a live stream renews its deadline, reject stale
owner pings, and preserve that deadline across repeated disconnects.
Let disabling automation finish cleanup without bypassing display owners.
Cover recovery, ownership and disabled-policy regressions.

Addresses Nonary/vibeshine#282
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

f0fb1ea585ef

merge(prerelease): reconcile display recovery on vibe-test

Preserve both local and remote prerelease improvements while integrating
the legacy recovery fix. Keep durable desktop snapshots and eight-output
support alongside the newer guarded restore transaction and HDR colors.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

e42f9ae462be

fix(linux): preserve console rendering on multi-GPU hosts

The bridge's PCI spoofing and ambiguous NVIDIA selection could break Virtio
console output and leave private displays unavailable. Pin the isolated GBM
route with a stable PCI default, early SHM import safeguards and truthful PRIME
layout metadata. Reject CPU fallback for managed unknown layouts rather than
reading tiled storage as linear; keep native and explicit linear fallbacks.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

efc8c77ba5b9

fix(linux): admit globally numbered private display names

A Virtio console can consume Virtual-1 before the managed display pool.
Pin the explicit DRM-to-configfs mapping and admit valid global connector
IDs for requested modes, while the broker verifies actual pool membership.
Cover shifted names without expanding the pool or guessing an offset.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

d9e54d8b57ab

fix(steamos): share managed connector mapping in the local broker

The local broker shadowed the shared handlers with fixed connector IDs
and public-name lease paths. Shifted DRM names could connect one pool slot
then request modes on another. Inherit the canonical mapped handlers and
cover sparse public names, logical leases and cross-user mode rejection.

Refs: Nonary/Vibepollo#526
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

36dd4caa378f

fix(linux): make filesystem validation locale-independent

- stop comparing localized stat %F strings
- use -f/-d/-S for object type validation
- retain stat only for ownership and mode
- use C.UTF-8 for machine-host child processes

845beffcc324

fix(steam): normalize Pressure Vessel /run/host Proton paths

- translate /run/host/... metadata to host namespace paths
- apply normalization to Proton and Steam client paths
- support system-wide CachyOS Proton direct launches

99e137e81c7b

fix(linux): skip read-only Proton tools for global policy injection

- don't try to write hooks into root-owned compatibility tools
- keep user-owned Proton tool injection unchanged
- report skipped tools instead of PermissionError

6f417283999c

fix(packaging): verify installed private host capabilities in installer

- assert private host executable has cap_sys_admin,cap_sys_nice=p after install
- prevent unsafe executable status when host capabilities were not applied

b35e9d1b69fb

fix(display): serialize remote monitor teardown

Keep display ownership alive through capture joins and close WebRTC before
topology cleanup. Fence monitor generations across rejected activations,
reconcile deferred releases, and retain failed native cleanup for retry.
Drain WGC frame callbacks before releasing capture-manager resources.

Refs: Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Luna High

fbbd99073406

merge(prerelease): add capture-safe display teardown

Retain display ownership through capture teardown, fence stale monitor
requests, and drain WGC callbacks before releasing capture resources.
Preserve the current configurable capacity and Linux idle-cleanup policy.

Refs: Nonary/Vibepollo#414

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

a1e0142043fa

merge(prerelease): accept Linux hardening from PR 302

Merge the contributor's locale, Proton path and packaging fixes into vibe-test.
Reconcile the stable fixes already in the PR ancestry while preserving newer
wire-budget handling, display teardown and application focus behavior.
Update metadata fixtures and retain unsafe Xauthority rejection coverage.

Closes #302

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

3eab00353959

fix(linux): recover machine setup after locale and cwd failures

Valid machine profiles were rejected when service-account commands inherited
an inaccessible caller directory or metadata checks used a translated locale.
Run those commands from / and stabilize native package lifecycle checks.
Retry machine setup in the installer, including older-controller locale recovery,
and stop on failed recovery while preserving existing profiles and pairings.

Addresses Nonary/Vibepollo#514

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

73b28e555cd7

build(gamepad): ship the DualSense identity fix from beta.7

Pin the released driver 0.1.0.48 so GameInput and HIDAPI identify the
same virtual DualSense. Keep the source, archive checksum, CI, installer
checks, and bundled payload aligned with the verified beta.7 release.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Low

a2c548d1faaf

fix(pyrowave): establish UDP return paths before calibration

Windows streaming works through outbound UDP exchanges, but calibration
previously sent unsolicited packets to a fresh receiver port. Announce the
sender port over paired HTTPS and verify the client's UDP token before the
measured transfer, without firewall changes. Bound the handshake and exclude
warmups from results while preserving legacy clients.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 5.6-Sol High

8ff20328ed83

fix(linux): exclude virtual outputs from monitor restore snapshots

Retained streaming outputs could become the saved desktop and prevent TV
restoration when their requested modes changed. Keep new and legacy restore
snapshots physical-only, require a physical restore guard, and retire virtual
connectors even when older snapshots included them, matching Windows behavior.

Validated by a full build, 134 passing tests (one skipped), and user-confirmed
TV restoration after native installation.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

c3bf29e52715

feat(display): add the virtual display killswitch on Linux

Linux hosts lacked the UI and API recovery action available on Windows.
Expose confirmed termination in Maintenance, attempt physical layout restore,
and disconnect every managed kernel output despite active ownership.
Verify removal and report restoration separately while preserving mutation fences.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

e5481d5d58c7

fix(display): honor refresh overrides and older Windows limits

Match refresh mappings against stream FPS before automatic promotion so
60 FPS sessions can advertise and apply explicit 480/1000 Hz modes.
Resolve creation, apply and recovery consistently, preserving fractional
rates and capping pre-24H2 Windows modes at the resolution's 1 MHz scan limit.

Validation: Linux release build and both web bundles passed; 135 tests
passed, 2 skipped. Windows build and live streaming remain unqualified.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

67c17bfdd4f1

fix(ui): restore a focused Everyday settings workflow

Everyday buried Vibeshine's distinctive features among generic controls.
Put virtual screens, smoothness, PyroWave and Remote Monitor together,
with pacing integrations, visible library links and grouped tuning.
Correct Windows limiter choices and FEC bounds while preserving old drafts.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

748b53db57b2

fix(display): terminate remote monitors despite restore failure

Disconnect Monitor must remove its Windows screen even when the remaining
display topology cannot be restored. Use exact-owner native termination,
retain capture and peer ownership guards, and report removal failures.

Refs: Nonary/Vibepollo#568

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

fef077c021b5

feat(input): emulate wired USB DualSense haptics on Windows

Expose controller and audio interfaces together so games can send native
waveform haptics through the existing Moonlight feedback path. Add an opt-in
installer component using unmodified, verified usbip-win2 drivers; preserve
shared installs and wait for HID/audio readiness before per-app launches.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Ultra

7af5c387b63d

feat(ui): add dashboard virtual screen recovery

Make emergency recovery reachable when a virtual screen leaves the PC blank.
Add a first-visit guide and confirmed dashboard action, removing virtual
outputs before trying the saved layout and a connected physical monitor.
Validation: Linux build, 33 browser checks, and 10 targeted policy tests.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

13c99d514f2c

feat(display): recover orphan virtual screens on monitor events

Stuck virtual screens can survive failed desktop restoration. Use monitor
wake/topology events to recheck failure and remove only captured orphans
when physical output is verified and all display owners are gone.
Keep recovery tied to its session and generation without periodic probes
or time-based expiry. Preserve the current physical desktop layout.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol X-High

c2a651beebd2

fix(hdr): wait for display setup before starting capture

Capture could probe HDR during the helper's temporary SDR window.
Require verified display setup before launch, resume, and WebRTC
capture, then follow real HDR/SDR changes through normal reinit.
Remove mutation fencing, frame holds, color generations, and settling timers.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol High

306d11d17079

fix(hdr): preserve driver-owned calibration profiles

Host profile edits competed with the Vibeshine driver's retained calibration.
Leave those associations intact while keeping explicit assignment for SudoVDA.
Prevent rejected activation from leaving registry-only profiles, avoid duplicate
activation, and remove UI guidance requesting redundant client assignment.
Validated the full local build and CTest suite: 154 passed, one skipped.

Refs #301
Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

9f7fbdd1a05b

docs(release): document 2.0.0-stable.1 changes

Explain the stable delta from 2.0.0 with user-facing outcomes and setup details.
Cover display recovery, controller haptics, HDR, PyroWave, and Linux fixes while
excluding withdrawn experiments and intermediate prerelease fixes.

Generated with [Codex](https://openai.com/codex/)
Model: GPT 6.1-Sol Medium

9ab0b3132abf

fix(display): keep locked desktops reachable during setup failures

Mandatory display setup rejected reboot and lock-screen connections with 503 before users could remotely unlock Windows. Continue launch, resume, and WebRTC with existing display settings when setup fails or times out, and preserve deferred setup across app startup for retry after unlock.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

1647ef50309f

fix(webui): keep the interface responsive while streams pause

Display capability discovery could block the HTTPS event loop and keep the UI loading while a paused app retained its display. Isolate metadata work, open the UI after authentication, and let stalled status requests time out and retry. Remove the dashboard metadata wait and cover startup and recovery with a browser regression test.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

91d4c5917d1e

feat(input): boost DualSense haptics while preserving contrast

Make streamed haptics easier to feel without hard clipping or flattening waveforms.
Add configurable strength lift on Windows and Linux, preserving actuator peak gaps with recent-peak headroom control and per-controller smoothing.
Keep 1.0 as unchanged output and support per-client overrides.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol X-High

19f4527c3eba

fix(input): preserve DualSense audio across Moonlight pauses

Disconnecting the virtual controller invalidated the game's haptics audio endpoint. Honor Moonlight gcpersist by retaining the composite DualSense while the app runs and rebinding feedback on resume. Release retained devices when the app ends and preserve teardown when persistence is disabled.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

68f381b0396a

feat(pyrowave): Calibrate pacing with frame-shaped UDP probes

Negotiated link speed can exceed what a receiver absorbs in video bursts.
Add frame-shaped probes and client-calibrated pacing, using 80% link headroom by default while accounting for stream demand and wire overhead.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

ec427d602085

fix(stream): Bound UDP retries and account for failed frames

Socket pressure must not block streaming or silently leave holes in frames counted as delivered.
Bound nonblocking sends, stop failed fallback sends, preserve sequence reservations and traffic accounting, and limit failure logging.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

74d38edf022f

fix(input): Use USB audio for automatically selected DualSense

DualSense waveform haptics need the composite audio function outside application opt-in scopes too.
Select it when DualSense is chosen and the transport is available, retain client capability checks, and keep diagnostics quiet.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

a12c83debc4b

fix(dualsense): Locate readiness by USB host and imported port

The released USB transport can generate instance IDs that do not match the requested serial.
Find the controller under the opened host and imported port before checking HID and audio readiness, avoiding unrelated devices.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

af13dd441d31

fix(display): Correct helper linkage and include x86 HDR manifest

Display cleanup helpers need external linkage and the Sunshine identity helper needs its namespace qualifier.
Correct both references and include the x86 Vulkan HDR manifest already required by installer and packaging contracts.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

68f38d8b5c37

fix(deps): Update virtual gamepad report and initialization fixes

Use the virtual gamepad fixes for deferred HID report ownership and quiet Switch controller initialization.
Advance the submodule to the two dedicated driver fixes without including local test-signing payloads.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

639551256349

feat(release): add gated daily prereleases, safety contracts and exact nightly notes

3723916ce309

ci: forbid self-hosted runners for daily builds

ffecf5d118b9

feat(release): expose validated Moonlight Windows product version

505fd780e60a

ci: use reviewed primary sources and bounded Linux resources

f2e0f95662d0

feat(installer): require exact-certificate consent for newer self-signed gamepads

09e537ed8be9

Default to verified prerelease notifications and preserve stable-only choices

(cherry picked from commit 57fc027ee71594d909f0df1cee5c4c64fe493c6b)

f2c6624fe542

fix: align gamepad source pin with verified producer package

Use the immutable beta.7 source already required by the release archive lock. The previous gitlink pointed to an unpublished divergent driver branch while packaging still consumed beta.7; its public client and protocol blobs are identical, but its two driver-only fixes cannot ship through the beta.7 DLL. Preserve the producer revision/hash/DriverVer gate and defer those unreleased driver changes to a separately tested producer release.

69d4f9051349

ci(linux): reuse verified CUDA and compiler caches on bounded hosted runners

Avoid duplicate recursive source checkout, shallow pinned submodules, retain native package tests and Pascal checks, and provide an exact-source artifact-only validation lane without signing or package installation.

f2d0a88ac246

ci(linux): isolate exact-source validation in registered manual workflow

Skip release selection and ordinary Windows/Arch/signing-summary jobs when hosted Linux validation is requested; preserve default behavior and dispatch only the no-key artifact route with tests enabled.

4ef8af606b90

fix(ci): scope native container Git trust to the verified workspace

The hosted Arch submodule checkout failed after checkout action restored its temporary Git configuration. Apply safe.directory only to that exact workspace and invocation, retaining the pinned SHA and rejecting wildcard/global trust in workflow contracts.

33d496630197

fix(ci): validate Linux packages with the verified nonzero source version

Preserve package downgrade protection and use each fork current source base with a validation prerelease suffix in both isolated hosted entry points.

2b9497f78761

fix(ci): fetch both pinned Linux driver sources before package configuration

The shallow initial checkout omitted DualSense source templates required by configure-only packaging. Fetch only libvirtualdisplay and libvirtualgamepad, verify their required files, and keep existing policy guards and package-source preparation.

7438d51afb92

fix(ci): honor signed installed GCC14 during Arch dependency resolution

Check exact compiler package versions, synchronize only dependencies reported missing by pacman deptest, then require the full dependency set to pass before fingerprinting the installed ABI. Exercise wrong-compiler, sync-failure and unsatisfied-version fixtures.

d50046c73d81

fix(updates): use the tray callback ABI without redirecting old notifications

Keep the captured release URL in notification text and leave updater toasts nonclickable because the tray C API lacks notification context. Preserve Web UI links, prerelease opt-out, delivered-version suppression and state persistence. Compile and exercise the production delivery method with SUNSHINE_TRAY=1 against system_tray.h.

cdeeabcc4c6f

fix(display): verify the reviewed producer source and payload

Lock the v1.6.4 archive, evidence, source revision, actual INF DriverVer and every producer file. Reject changed fresh downloads and unverified caches before package refresh, including explicit prebuilt roots, while preserving the later Linux source pin and installer trust policy.

Validate with mocked fresh/cache tamper tests, Windows PowerShell 5.1, the mandatory driver safety suite, read-only public artifact fetch/cache verification, actionlint and the CMake lock declaration.

6faa42231709

Fail Linux component builds early and reuse verified package sources

Declare the routed-link Boost.Asio interface, compile configured component targets before host and CUDA work, seed validation sources from the exact verified shallow checkout, and retain only verified dependency/compiler cache work after trusted manual build failures.

64153c623203

Model early component validation in the CUDA policy fixture

Stub the external component helper explicitly and verify configure, component and full-build ordering while retaining private CUDA and Pascal assertions. Normalize fixture paths so the same policy checks run on Windows and hosted Linux.

d5488f78f1d2

fix(linux): avoid automatic portal consent after KMS selection

Skip probing the desktop portal when automatic capture has already selected
KMS or the native compositor. This prevents unattended private-display
startup from opening a portal consent prompt while retaining explicit portal
requests and the existing X11/NvFBC fallback paths.

Cover automatic and explicit selection in the existing pure policy fixture.
Validated all four fixture cases through a native assertion harness, all 16
policy truth rows, and the actual production guard with a mocked verifier.
Full hosted Linux compilation remains a follow-up validation step.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 35a68dd28e653aabe7915ddb5b2d20b42629b54e)

06e7534ac29e

test(display): give snapshot fixtures valid resolution and refresh

Use 1920x1080 at 60/1 in the shared fake snapshot instead of a zero-sized
mode with a zero refresh denominator. This lets the pinned display library
compare realistic snapshots while preserving every existing assertion and
production validity check.

Validated 103 state-machine, 37 restore-engine, and 8 snapshot-restore cases
against the source worktree and exact pinned display headers. No live display
operations ran.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 838f10575ad65db79116914b042c1c37483c5b91)

ee619de4675a

test(updater): register the standalone release selection policy

Expose the existing metadata, version, and package-selection regression
harness as test_fast_update_release so BUILD_TESTS and fast test runs
exercise the updater policy. Link only its JSON dependency and retain
assertions in Release with the compiler-specific NDEBUG undefine option.

Validated the actual standalone harness through the production target helper
in Release: build and CTest fast-label run pass, with -UNDEBUG after -DNDEBUG.
Disabling fast tests skips the target cleanly. Preserve the existing tray
interface component registration without importing Apollo-only state helpers.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit ea5c86f4d1174213288f0554da72a52e603cac91)

2135676efe27

Declare display helper component Boost and JSON dependencies

(cherry picked from commit c98b7c5422853db362c76242ac6d49a5c447fe0e)

bcde319ad27e

Compile fast policy targets alongside component tests before Linux packaging

Discover both configured test categories through the CMake codemodel while keeping the required routed-link gate and excluding unrelated app targets.

(cherry picked from commit 6ea72f0dd1ccc1ed8e593cd29196592620b3f390)

46dbd6ada217

Declare the DualSense component Boost Format interface

Link the production stat-tracker header dependency explicitly and verify the pinned modular Boost headers with positive and missing-interface compile probes.

Model: GPT-6.1 (medium).

84b1bef178cf

ci(windows): opt in to compile and run tests without daily signing

Expose a default-off build_tests input on artifact-only Windows validation
and forward it to the reusable build. Execute CTest whenever tests are built,
with empty suites and test failures blocking success. Keep daily artifact
signing gated solely by daily_unsigned and pass no signing secrets from the
validation wrapper.

Add a workflow regression fixture for compile/CTest input alignment, hosted
artifact-only defaults, and independent daily signing guards. All three
fixture cases, actionlint, and whitespace checks pass. Full hosted application
compilation and CTest execution remain pending; no local machine changes ran.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 19a4165016aaa3de3ade55fa24eba5a4f334c7e6)

708a2e0362ff

ci(linux): cache only the verified CUDA installer

Caching the full CUDA SDK plus installer exceeds the standard shared cache budget. Restore and save only the pinned installer under a new cuda-installer-v2 key, with no fallback to SDK archives. Each fresh job still installs and patches the complete CUDA 12.9 toolkit.

Exercise checksum rejection, two fresh toolkit jobs, unchanged trusted-failure eligibility, and final Pascal/CTest/package gates. Keep the prepare helper, package recipe, and release validation unchanged.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium

e1bc927ac871

test(updater): match release fixtures to the build platform

Linux CTest rejected the standalone harness Windows-only installer before comparing stable respins. Supply the real build-platform package family and architecture in fixtures while preserving production completeness and version-selection policy.

Cover stable respin ordering, older rejection, wrong-platform and wrong-architecture assets, empty or pending packages, and missing nightly checksums. Keep assertions enabled explicitly and reject assertion-disabled harness builds.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 8383852aceadf7acf7cf1722089fdecaa03972b0)

e68504eb65c4

test(packaging): expect the audited libvirtualdisplay v1.6.4 release

Correct the stale typed contract expectation without changing the producer lock or runtime policy. Verify the exact reviewed source revision, archive hash and INF version, and evaluate the real CMake contract against the same release.

Validation: two focused provenance tests and git diff --check passed. No driver, trust or installer operations ran.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 78660a102ec51119893d35fc02cd8dc69e85161d)

2dc3d40ce254

test(display): preserve Boost headers in wake recovery fixtures

Direct Python compiler calls lost the modular Boost include requirements, breaking the observer and its mandatory backend regression. Pass the evaluated Boost::algorithm header closure through both fixtures without changing production code or assertions.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 1959e585676ab819e85fe833887d3eddfce333b0)

1272295df2d7

test(playnite): isolate SDK discovery hints inside the CMake fixture

Clear DOTNET_ROOT and ProgramFiles in the generated CMake child script before
running unchanged production discovery. Windows may retain its well-known
ProgramFiles environment value despite a subprocess override, allowing a
host-installed SDK hint to mask the fake PATH SDK and fail the exact-path test.
Remove inherited case variants before setting child environment values and
include expected/found paths in the failure diagnostic.

Preserve PATH, empty-cache, and explicit discovery cases plus compiled upgrade
and filesystem cleanup policies. A temporary competing SDK reproduces the
original failure; clearing hints restores the exact PATH result with both
MSYS2 and native CMake. All full fixture checks pass with both tools and the
actual UCRT64 compiler. No production code or machine configuration changes.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 6acc22f63402a9e16d8fe6d37cff2cf1472063b0)

0ea017a8db1b

fix(hdr): Preserve driver calibration without monitor metadata

A permanent Sunshine monitor selected through the physical output route could receive a client profile when optional enumeration failed or omitted its identity. Recognize the resolved default driver hardware-ID families before enumeration, preserving physical and SudoVDA overrides and the existing custom-metadata fallback. Add policy boundary tests and regressions extracted from the actual production guard.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra
(cherry picked from commit 508da3612fe59fe27275756d9267dfce5929d471)

592c2379fbb4

test(display): use valid modes in snapshot roundtrip fixture

Zero-initialized refresh rates fail the pinned mode-verification equality contract, so the storage roundtrip test failed despite preserving its data. Supply valid 1920x1080 at 60/1 modes for both displays while keeping every assertion and production check unchanged.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 5d4b7a53e45450dee0cee96169910f046a2ae1cf)

40870ffc51ed

Keep the UDP probe measurement open until its fixed deadline

A Windows timer can return early from the final wait, producing a measured
probe window below 2000 ms even though all expected packets were sent. Recheck
the original steady-clock deadline after each return through the existing
injected waiter. Do not restart the duration or change packet pacing, retry
budgets, handshake validation, burst scheduling, or overload bounds.

Add deterministic fake-clock coverage for repeated early returns, completed
deadlines, and waiter exception propagation. Preserve the original elapsed,
packet count, sequence, token, and pacing assertions.

Validation: the unmodified native loopback test reproduced 1999.4009 ms on
iteration 4 of 5. The corrected Release native suite passed all 9 GTests,
and the unchanged paced loopback regression passed 10 consecutive runs.
Compiled with GCC 16.2 and -UNDEBUG using cached Boost/GTest dependencies.
Full hosted application validation remains an integration check.

Source-first implementation based on 0ea017a8db1b653921e73a3ee45f1d5506c7fbb4.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Medium
(cherry picked from commit 92b51649ae43547dd6a081af607fc2e95618202f)

a618f3711b45

fix(web): Accept CRLF checkouts when verifying design tokens

Windows Git checkouts convert the generated token files to CRLF, causing check mode to reject otherwise current outputs. Accept that checkout conversion only during comparison, preserving strict content checks and the existing LF generation and print behavior.

Exercise the real generator in isolated fixtures covering equivalent line endings, genuine drift, missing files, unchanged check/print inputs and deterministic generation.

Generated with [Codex](https://openai.com/codex/)

Model: GPT 6.1-Sol Ultra
(cherry picked from commit 489fffa883d5d027cdb56636babe9c86af3898be)

d641a8fa235a

fix(ci): reuse one pinned nightly gamepad signing identity

Replace per-run certificate generation with scoped encrypted CI inputs and an exact public thumbprint. Reject invalid or expiring identities, export only the public certificate, and retain consent, producer provenance, numeric driver-version and no-trust-mutation contracts. Two actual disposable signing passes reused identical certificates.

43505570675a

test(video): bound readiness shutdown extraction to its admission block

84ed23f6a1e9

test(playnite): retain the selected SDK framework during restore

94315bea114a

fix(ci): align certificate identity checks with the persistent nightly signer

1fd1ecbbe610

fix(test): supply replay dependencies and product-scoped helper fixtures

5ade938d15fb

fix(display): synchronize dispatcher shutdown with idle waits

Protect both stop predicates with the corresponding condition-variable mutex to prevent shutdown losing its notification. Exercise 1000 idle shutdowns under a bounded component timeout. Preserve the shared helper directory when redirecting Linux lifecycle fixtures.

aaa39188cc78

fix(ci): fetch full ancestry for nightly version resolution

Don't miss a new vibeshine release

NewReleases is sending notifications on new releases.