The other half of the audio-substrate decision (spikes S2+S3 green, minted
endpoints landed in the previous commit): stop bundling a third-party
kernel driver the host no longer needs.
installer the VB-CABLE task, payload, silent-install run and the
donationware notice are gone; a suppressible notice tells
a Steam-less box that audio needs Steam INSTALLED (never
running) and that installing it later just works. A cable
from an older install is still deliberately not removed.
packer + CI -VbCableDir/VBCABLE_DIR, the staged-payload check and the
runner provisioning download are gone; SBOM drops the
redistributed-driver component.
winget the VB-Audio bundling-grant agreement becomes the honest
Steam requirement (surfaced on the unattended path where
no wizard is on screen).
docs windows-host/uninstall/security/echo say what actually
ships: no kernel-mode driver of our own, endpoints minted
from Valve's vendor-signed drivers, VB-CABLE mentioned
only as the historical fallback that keeps working.
host wording the mic-open guidance and module headers lead with Steam;
the NAME ladder itself is untouched — demoting 'cable
input' was considered and rejected (on a box where minting
transiently fails, the SSM would outrank an installed
cable, steal the silent sink, and make audio host-audible).
CRA Annex I Part II groundwork (see punktfunk-planning design/cra-readiness.md, Phase 1):
* sbom.yml + scripts/ci/gen-sbom.sh: every vX.Y.Z release gets a CycloneDX
SBOM attached — syft over both Cargo.locks, all Bun/pnpm trees and the
Swift Package.resolved (2,667 components), merged with
compliance/sbom/manual-components.cdx.json for what no lockfile records
(pyrowave/Granite/volk/Vulkan-Headers pins, libvpl, FFmpeg, SDL3,
VB-CABLE, punktfunk-gamescope).
* audit.yml: bun audit now covers sdk + plugin-kit (not just web), decky's
pnpm tree is scanned, and docs-site runs non-blocking until its known
CMS-chain advisories are cleared. All shipping trees verified green today.
* license-gate: about.toml's allowlist claim is finally enforced —
cargo-about 0.9.1 with --fail over BOTH workspaces. The old [crate.clarify]
license-only syntax fails to deserialize under 0.9; migrated ring to a
per-crate accepted extension and dropped the stale aws-lc-sys entry
(workspace is ring-only). Both gates validated green locally.
* drivers/Cargo.lock: sync the pf-dualsense→pf-gamepad rename — the crate
rename updated the manifest but the Windows-only lockfile was never
regenerated; cargo-about's metadata pass caught it.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>