refactor(host/W6.1): extract secret/config-dir helpers into the pf-paths leaf crate

Second de-coupling for the host crate carve (plan §W6.1 leaf). config_dir /
create_private_dir / write_secret_file (+ the Windows DACL helpers) were pub(crate) in the
gamestream junk drawer, yet consumed by vdisplay, stats, gpu, library, mgmt_token,
native_pairing and the Windows service — many of which become pf-media / pf-vdisplay, for
which crate::gamestream would be an illegal upward edge. New leaf crate pf-paths (pure std
+ tracing) owns them; ~40 call sites across 14 files repoint to pf_paths::. gamestream
keeps only its own concerns.

Verified: Linux (home-worker-5) clippy -p pf-paths -p punktfunk-host --all-targets
-D warnings + tests (347 pass, incl. secrets_are_written_owner_only); Windows
(192.168.1.158) clippy --features nvenc,amf-qsv --all-targets green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
2026-07-17 01:07:26 +02:00
co-authored by Claude Opus 4.8
parent 2e3208f75e
commit c42ce88921
19 changed files with 248 additions and 218 deletions
+3 -3
View File
@@ -206,10 +206,10 @@ impl HooksStore {
/// changes only if the disk write succeeds.
pub fn set(&self, cfg: HooksConfig) -> Result<()> {
if let Some(dir) = self.path.parent() {
crate::gamestream::create_private_dir(dir)?;
pf_paths::create_private_dir(dir)?;
}
let tmp = self.path.with_extension("json.tmp");
crate::gamestream::write_secret_file(&tmp, &serde_json::to_vec_pretty(&cfg)?)?;
pf_paths::write_secret_file(&tmp, &serde_json::to_vec_pretty(&cfg)?)?;
std::fs::rename(&tmp, &self.path)?;
*self.cur.lock().unwrap() = Some(cfg);
Ok(())
@@ -219,7 +219,7 @@ impl HooksStore {
/// The process-wide hooks store (`<config_dir>/hooks.json`), loaded once on first access.
pub fn store() -> &'static HooksStore {
static STORE: OnceLock<HooksStore> = OnceLock::new();
STORE.get_or_init(|| HooksStore::load_from(crate::gamestream::config_dir().join("hooks.json")))
STORE.get_or_init(|| HooksStore::load_from(pf_paths::config_dir().join("hooks.json")))
}
// ------------------------------------------------------------------------- runner