forked from unom/punktfunk
Follow-ups left open by the security-review pass. The Windows client had the deep-link fix's enforcement but not its UX: a name- or address-resolved link was REFUSED with a note pointing at the host list, marked in-code as degraded, because that shell had no prompt surface wired up. It has one — `ContentDialog`, already used for "Remove saved host?" and "Delete profile?" — so the link now asks, naming the host and anything it wants to launch, and on confirm runs the identical dial the id-referenced path runs. Same wake, trust and error surfaces; confirming is one click in front of the same code. The supply-chain pins only covered the jobs the report cited. deb.yml (a signing-key job) and arch.yml still piped bun's installer into bash; flatpak.yml still took the deploy host key on first contact while holding FLATPAK_GPG_PRIVATE_KEY. deb now takes the same pinned, SHA-256-checked bun asset as rpm and windows-host; arch takes bun from pacman, which verifies package signatures; flatpak verifies the host key from DEPLOY_KNOWN_HOSTS through the fail-open-through-setup preflight it already had. Found while sweeping, worse than the cited sites: flatpak.yml fetched flatpak-cargo-generator.py from a mutable `master` and ran it in the job holding the GPG key — third-party Python deciding which crate sources the signed build vendors. Pinned to a commit and checksummed. pf-zerocopy's EGL bindings declared glShaderSource/glGetUniformLocation as `*const i8`, but `CStr::as_ptr()` yields `*const c_char` — i8 on x86_64, u8 on aarch64. So the crate did not compile for aarch64 at all, and CI is x86_64-only and could never see it. Verified both directions: with c_char `cargo check -p pf-zerocopy --target aarch64-unknown-linux-gnu` passes, and the old spelling still fails E0308 there. Docs: the note saying Windows has no prompt is gone, and the first-connect sentence put Windows in the wrong group — it pre-fills its trust prompt from the link like Linux and Android; only the Apple apps show a notice. Corrected an Apple comment claiming it seeds the add sheet with the address and fingerprint when it only sets a notice string.