chore(release): bump workspace version to 0.25.0 #56

Open
enricobuehler wants to merge 3 commits from worktree-release-0250 into main
Owner

Prepares v0.25.0 — now 136 commits since v0.24.0 (main moved from 8983ec04 to 35ba64ca while this sat open; merged in and the notes rewritten to match). Four files, the same bump surface as every prior cut: Cargo.toml, Cargo.lock, docs/releases/v0.25.0.md, docs/releases/whatsnew/v0.25.0.txt.

The version was not a judgment call: scripts/ci/pf-version.sh prints PF_BASE=0.25.0, derived from the tags, and canary has been publishing against it all along.

🚫 Do not tag yet — one real defect, two broken runners

1. The flatpak has not built since 35ba64ca. Fixed by #65 — merge that first.
PR #64 declared vkroots twice; flatpak-builder clones submodules by default, so the second source tries to copy a bare mirror onto a gitlink file and cp refuses. Extraction dies before any build command runs. flatpak.yml runs on tags: ['v*'] and that step gates the bundle export, the registry publish, the OSTree push and the release-asset attach — a tag cut today ships with no Linux/Steam Deck flatpak at all, on the release whose headline Linux change is Deck HDR. It reached main because flatpak.yml has no pull_request: trigger, so #64's checks were green without ever building the flatpak.

2. Both Linux runner hosts are misconfigured, in different ways (infra, unom/infra):

  • home-runner-2 is missing 192.168.1.58:5011 in its Docker insecure-registries, so builder-image pushes fail with http: server gave HTTP response to HTTPS client. The failures split strictly by runner, not by image — every 1-* green, every 2-* red. Degrades a tag: the Tag for release step sits after the failing login, so v0.25.0 builder-image tags never get minted.
  • home-runner-1's Docker cannot pull any image — LAN or Docker Hub (No such image: fedora:43 on a public image). act_runner swallows the pull error and dies at create, which is why jobs report failure with every step cancelled in 4 seconds. ci.yml has no tags: trigger so it can't fail the fan-out directly, but every Linux tag workflow starts by pulling a container image on this same fleet.

3. There is currently no green rust / rust-arm64 result on main's tip. Those jobs have never executed a step on 35ba64ca — the workspace there is untested, not known-good. Worth one clean run before tagging.

The earlier windows-msix red remains benign: the identical commit's arm64 leg was re-run and passed, and windows.yml went green on that SHA building the same crates for both arches. Known runner flake — on tag day, re-run a failed leg rather than blocking.

⚠️ A release-content call that is yours

The headline feature has never run on hardware. PR #23's own final commit (d27e62f7) says it plainly: "Still owed: on-glass. This is a hardware feature and none of it has been on a real DualSense since the merge." Its entire verification is unit tests and compile checks. Since a vX.Y.Z tag publishes to Google Play production at 100%, that ships to real users unverified. The notes describe it accurately — wired DualSense only, Windows host with Steam only, Android and the desktop session client only — and say the verification gap outright. Softening or cutting the claim is a one-file edit.

What the notes now cover

A new ## Before you update section, because the security review landed changes that need the reader to act and would not survive being buried in a Fixed bullet:

  • Linux users of the virtual Steam Deck pad must sudo usermod -aG punktfunk "$USER" and log back in, or it stops attaching — the capability moved off the input group (which every gamepad guide says to join) onto its own, since it can emulate arbitrary USB hardware.
  • Plugin UIs moved to their own origin on PORT + 1: a self-signed console needs the new port trusted once, and custom firewalls/proxies must open it.
  • Saving a custom launch command re-confirms the console password; add-ons may no longer set launch/pre-launch commands at all — a real break for third-party add-ons that did.
  • A fresh install now runs the plugin runner by default (upgrades untouched).
  • The Deck setup script left the generated console password world-readable — rotating it is worth a sentence.

The library-sources work is written as groundwork, deliberately: all six built-in scanners still ship and stay on, nothing is removed, and none of the replacement add-ons are published yet, so the migration offer appears as they arrive. Promising otherwise would repeat the v0.22.3 mistake of notes describing a build nobody is getting.

Two honesty items worth flagging: the Android stats-overlay entry states outright that the stream did not get faster and the headline number only shrank because it stopped counting the compositor's wait; and the Windows non-C: settings entry says plainly that nothing is recoverable, because those writes never reached disk.

Kept out of user-facing notes: 56adb470 (verified not an ancestor of v0.24.0 — repairs a Windows build break in never-shipped code, folds into the pad-audio feature) and 19f637ea (CI only).

Version facts (verified against source and the generated header)

  • Wire protocol 2 — unchanged. Every addition is optional or capability-gated: an optional trailing max_shard_payload on Hello, the 0x08/0x09 renegotiation pair, the 0xD1 controller-audio plane, the 0xD2 redundant desktop-audio plane, MAX_DATAGRAM_BYTES 2048 → 9216.
  • C ABI 14 → 16, in two steps. 15 retroactively declares the floor guaranteeing the rumble policy engine's C surface (it shipped while the constant still read 7; no code changed with the bump). 16 adds the controller-audio surface and mirrors its capability bits.
  • Four new capability bits: audio redundancy client 0x04 / host 0x20; controller audio client 0x08 / host 0x40. ⚠️ Commit ed3d236a's message says 0x04/0x20 for pad audio — stale, rebased when AUDIO_RED took those. quic/caps.rs is authoritative.
  • ⚠️ host_caps is down to its last free bit (0x80). video_caps remains full from 0.23.0, so the standing "next video cap needs a second byte and an ABI bump" note still holds.
  • Unchanged: virtual-display driver protocol 6, Windows gamepad channel 3 — pf-driver-proto is byte-for-byte identical to v0.24.0.
  • Breaking for C embedders: 149 unprefixed macros are now PUNKTFUNK_-prefixed. Cannot break silently — the old spellings cease to exist, so it is always an undeclared-identifier error rather than the wrong value a colliding #define used to produce.

Gates run locally (re-run after the merge)

  • cargo metadata --locked resolves — 35 members; fec-rs, pf-driver-proto, usbip-sim keep their own versions by design.
  • Lock diff against origin/main versions-only, 32/32. Last cut's wasapi counting trap does not apply — it sits at 0.23.0 and was never a candidate.
  • cargo fmt --all --check clean in both the main and packaging/windows/drivers workspaces.
  • Doc lazy-continuation scanner: 0 hits over 521 files — the exact defect that made the first v0.23.0 tag go red on Windows clippy, and no Windows leg runs on a main push, so main being green proves nothing about the tag fan-out.
  • Notes body voice check: 0 internal-vocabulary hits above ## Under the hood.
  • Play "What's new": 494/500 chars by android.yml's own gate logic, including the byte-identical check. Left unchanged — there is no room, and the only Android-facing additions since are worth less to a phone user than any line already in it.

Also worth deciding

api/openapi.json is deliberately left at 0.23.0, as in every prior cut. It will be two releases behind once this ships.

After merge

Merge #65 → get one green ci.yml on main → tag → wait for every platform green → dispatch announce with the tag. That last step publishes the signed stable update manifest, i.e. the moment every host's update check learns about the release. (0.24.0's manifest is live and correct, so the ritual is known-good.)

Prepares **v0.25.0** — now **136 commits** since v0.24.0 (main moved from `8983ec04` to `35ba64ca` while this sat open; merged in and the notes rewritten to match). Four files, the same bump surface as every prior cut: `Cargo.toml`, `Cargo.lock`, `docs/releases/v0.25.0.md`, `docs/releases/whatsnew/v0.25.0.txt`. The version was not a judgment call: `scripts/ci/pf-version.sh` prints `PF_BASE=0.25.0`, derived from the tags, and canary has been publishing against it all along. ## 🚫 Do not tag yet — one real defect, two broken runners **1. The flatpak has not built since `35ba64ca`. Fixed by #65 — merge that first.** PR #64 declared `vkroots` twice; flatpak-builder clones submodules by default, so the second source tries to copy a bare mirror onto a gitlink file and `cp` refuses. Extraction dies before any build command runs. `flatpak.yml` runs on `tags: ['v*']` and that step gates the bundle export, the registry publish, the OSTree push and the release-asset attach — **a tag cut today ships with no Linux/Steam Deck flatpak at all**, on the release whose headline Linux change is Deck HDR. It reached main because `flatpak.yml` has no `pull_request:` trigger, so #64's checks were green without ever building the flatpak. **2. Both Linux runner hosts are misconfigured, in different ways** (infra, `unom/infra`): - `home-runner-2` is missing `192.168.1.58:5011` in its Docker `insecure-registries`, so builder-image pushes fail with `http: server gave HTTP response to HTTPS client`. The failures split strictly by runner, not by image — every `1-*` green, every `2-*` red. Degrades a tag: the `Tag for release` step sits after the failing login, so `v0.25.0` builder-image tags never get minted. - `home-runner-1`'s Docker cannot pull *any* image — LAN or Docker Hub (`No such image: fedora:43` on a public image). act_runner swallows the pull error and dies at `create`, which is why jobs report failure with every step `cancelled` in 4 seconds. `ci.yml` has no `tags:` trigger so it can't fail the fan-out directly, but every Linux tag workflow starts by pulling a container image on this same fleet. **3. There is currently no green `rust` / `rust-arm64` result on main's tip.** Those jobs have never executed a step on `35ba64ca` — the workspace there is *untested*, not known-good. Worth one clean run before tagging. The earlier `windows-msix` red remains benign: the identical commit's arm64 leg was re-run and passed, and `windows.yml` went green on that SHA building the same crates for both arches. Known runner flake — on tag day, re-run a failed leg rather than blocking. ## ⚠️ A release-content call that is yours **The headline feature has never run on hardware.** PR #23's own final commit (`d27e62f7`) says it plainly: *"Still owed: on-glass. This is a hardware feature and none of it has been on a real DualSense since the merge."* Its entire verification is unit tests and compile checks. Since a `vX.Y.Z` tag publishes to **Google Play production at 100%**, that ships to real users unverified. The notes describe it accurately — wired DualSense only, Windows host with Steam only, Android and the desktop session client only — and say the verification gap outright. Softening or cutting the claim is a one-file edit. ## What the notes now cover A new **`## Before you update`** section, because the security review landed changes that need the reader to *act* and would not survive being buried in a Fixed bullet: - **Linux users of the virtual Steam Deck pad must `sudo usermod -aG punktfunk "$USER"` and log back in**, or it stops attaching — the capability moved off the `input` group (which every gamepad guide says to join) onto its own, since it can emulate arbitrary USB hardware. - Plugin UIs moved to their own origin on `PORT + 1`: a self-signed console needs the new port trusted once, and custom firewalls/proxies must open it. - Saving a custom launch command re-confirms the console password; add-ons may no longer set launch/pre-launch commands at all — a real break for third-party add-ons that did. - A fresh install now runs the plugin runner by default (upgrades untouched). - The Deck setup script left the generated console password world-readable — rotating it is worth a sentence. The **library-sources** work is written as groundwork, deliberately: all six built-in scanners still ship and stay on, nothing is removed, and none of the replacement add-ons are published yet, so the migration offer appears as they arrive. Promising otherwise would repeat the v0.22.3 mistake of notes describing a build nobody is getting. Two honesty items worth flagging: the Android stats-overlay entry states outright that **the stream did not get faster** and the headline number only shrank because it stopped counting the compositor's wait; and the Windows non-C: settings entry says plainly that **nothing is recoverable**, because those writes never reached disk. Kept out of user-facing notes: `56adb470` (verified not an ancestor of v0.24.0 — repairs a Windows build break in never-shipped code, folds into the pad-audio feature) and `19f637ea` (CI only). ## Version facts (verified against source and the generated header) - **Wire protocol 2 — unchanged.** Every addition is optional or capability-gated: an optional trailing `max_shard_payload` on `Hello`, the `0x08`/`0x09` renegotiation pair, the `0xD1` controller-audio plane, the `0xD2` redundant desktop-audio plane, `MAX_DATAGRAM_BYTES` 2048 → 9216. - **C ABI 14 → 16, in two steps.** 15 retroactively declares the floor guaranteeing the rumble policy engine's C surface (it shipped while the constant still read 7; no code changed with the bump). 16 adds the controller-audio surface and mirrors its capability bits. - **Four new capability bits:** audio redundancy client `0x04` / host `0x20`; controller audio client `0x08` / host `0x40`. ⚠️ Commit `ed3d236a`'s message says `0x04`/`0x20` for pad audio — **stale**, rebased when AUDIO_RED took those. `quic/caps.rs` is authoritative. - ⚠️ **`host_caps` is down to its last free bit (`0x80`).** `video_caps` remains full from 0.23.0, so the standing "next video cap needs a second byte and an ABI bump" note still holds. - **Unchanged:** virtual-display driver protocol 6, Windows gamepad channel 3 — `pf-driver-proto` is byte-for-byte identical to v0.24.0. - **Breaking for C embedders:** 149 unprefixed macros are now `PUNKTFUNK_`-prefixed. Cannot break silently — the old spellings cease to exist, so it is always an undeclared-identifier error rather than the wrong value a colliding `#define` used to produce. ## Gates run locally (re-run after the merge) - `cargo metadata --locked` resolves — 35 members; `fec-rs`, `pf-driver-proto`, `usbip-sim` keep their own versions by design. - Lock diff against `origin/main` **versions-only, 32/32**. Last cut's `wasapi` counting trap does not apply — it sits at 0.23.0 and was never a candidate. - `cargo fmt --all --check` clean in **both** the main and `packaging/windows/drivers` workspaces. - **Doc lazy-continuation scanner: 0 hits over 521 files** — the exact defect that made the first v0.23.0 tag go red on Windows clippy, and no Windows leg runs on a main push, so main being green proves nothing about the tag fan-out. - Notes body voice check: **0 internal-vocabulary hits** above `## Under the hood`. - Play "What's new": **494/500 chars** by `android.yml`'s own gate logic, including the byte-identical check. Left unchanged — there is no room, and the only Android-facing additions since are worth less to a phone user than any line already in it. ## Also worth deciding `api/openapi.json` is deliberately left at 0.23.0, as in every prior cut. It will be two releases behind once this ships. ## After merge Merge #65 → get one green `ci.yml` on main → tag → wait for every platform green → dispatch `announce` with the tag. That last step publishes the signed stable update manifest, i.e. the moment every host's update check learns about the release. (0.24.0's manifest is live and correct, so the ritual is known-good.)
enricobuehler added 1 commit 2026-08-05 05:48:56 +00:00
chore(release): bump workspace version to 0.25.0
apple / swift (pull_request) Successful in 1m20s
apple / screenshots (pull_request) Skipped
ci / web (pull_request) Successful in 1m14s
ci / docs-site (pull_request) Successful in 1m19s
android / android (pull_request) Successful in 5m33s
ci / rust-arm64 (pull_request) Successful in 5m21s
ci / rust (pull_request) Failing after 5m56s
windows / build (aarch64-pc-windows-msvc) (pull_request) Failing after 41s
windows / build (x86_64-pc-windows-msvc) (pull_request) Failing after 43s
f702f27bd3
A minor bump: 98 commits since v0.24.0. The headline is DualSense pad audio
(PR #23) — a wired DualSense playing a game's voice-coil haptics and its own
speaker, streamed from the host, on Android and the desktop session client
against a Windows host with Steam's driver present. Behind it: the haptics
sweep's twelve milestones closing more than twenty controller faults across
every client and both hosts; the audio quality/latency work (256 kbps stereo,
the Steam Streaming Microphone endpoint root cause, and the de-jitter ratchet
that left audio permanently behind the picture); and MTU resilience plus
mid-session shard renegotiation, which turns the silent all-black stream on a
sub-1330-byte path into a diagnosed warning that heals itself. Plus the Decky
plugin reduced to a launcher, system-button routing with hold-Select, gamepad-UI
profiles on all three UIs, `discover`/`launch --request-access` in the CLI, and
the Sunshine false-conflict and crashed-host display-restore fixes.

The canary base is already 0.25 — scripts/ci/pf-version.sh derives it as one
minor ahead of the latest stable tag — so this is the version canary has been
publishing against all along.

Wire protocol stays at 2: every addition this cycle is optional or
capability-gated (an optional trailing max_shard_payload on Hello, the 0x08/0x09
renegotiation pair, the 0xD1 pad-audio plane, the 0xD2 redundant desktop-audio
plane, MAX_DATAGRAM_BYTES 2048 -> 9216). C ABI moves 14 -> 16 in two steps: 15
retroactively declares the floor that guarantees the rumble policy engine's C
surface (which shipped while the constant still read 7), and 16 adds the
pad-audio surface and mirrors its two capability bits. Four new capability bits
land in the client/host bytes (audio redundancy 0x04/0x20, pad audio 0x08/0x40);
the video-caps byte was NOT touched and stays full from 0.23.0, so the standing
"next video cap needs a second byte and an ABI bump" note still holds. host_caps
is now down to its last free bit (0x80). Virtual-display driver protocol 6 and
the Windows gamepad channel 3 are untouched — pf-driver-proto is byte-for-byte
identical to v0.24.0. The generated header is in sync (ABI 16, both cap mirrors).

Breaking for C embedders: 149 unprefixed macros are now PUNKTFUNK_-prefixed
(139 #defines renamed in the checked-in header). Mechanical to fix, and it
cannot break silently — the old spellings cease to exist, so it is always an
undeclared-identifier error rather than the wrong value a colliding #define
used to produce.

Lock touched for the 32 workspace members only, via `cargo update --workspace`:
diff against origin/main is versions-only, 32 insertions and 32 deletions. Unlike
the last cut there is no third-party crate sitting on the outgoing version to
trip the count — `wasapi` is at 0.23.0 and was never a candidate. `cargo metadata
--locked` resolves (35 members; fec-rs, pf-driver-proto and usbip-sim keep their
own versions by design). `cargo fmt --all --check` clean in both the main and
packaging/windows/drivers workspaces. Doc lazy-continuation scanner: 0 hits over
521 files — that regex is the exact defect that made the first v0.23.0 tag go red
on Windows clippy, and no Windows leg runs on a main push, so main being green
proves nothing about the tag fan-out.

api/openapi.json is deliberately left at 0.23.0: it tracks API edits and lags,
as in every prior cut. It is now two releases behind and worth a look.

Notes at docs/releases/v0.25.0.md, per docs/releases/README.md — authored with
the bump so CI's ensure_release seeds the release body at tag creation. Body
voice checked programmatically: 0 internal-vocabulary hits above `## Under the
hood`. Play's "What's new" at docs/releases/whatsnew/v0.25.0.txt (494/500 chars),
verified by running android.yml's gate logic verbatim against it, including the
byte-identical-to-another-release check.
enricobuehler added 2 commits 2026-08-05 22:45:33 +00:00
docs(release): the 0.25.0 notes cover the 37 commits since the bump
ci / docs-site (pull_request) Successful in 1m13s
ci / web (pull_request) Successful in 1m15s
apple / swift (pull_request) Successful in 1m27s
apple / screenshots (pull_request) Skipped
ci / rust-arm64 (pull_request) Successful in 3m14s
android / android (pull_request) Successful in 4m34s
windows / build (aarch64-pc-windows-msvc) (pull_request) Successful in 6m45s
windows / build (x86_64-pc-windows-msvc) (pull_request) Successful in 4m27s
ci / rust (pull_request) Successful in 14m5s
1535d69852
main moved from 8983ec04 to 35ba64ca while this branch sat open, taking the
release from 98 commits to 135. Merged in and folded the new work into the notes.

The largest addition is a new `## Before you update` section, because this batch
carries changes that need the reader to DO something and they were not going to
survive being buried in a Fixed bullet:

  * Linux users of the virtual Steam Deck pad must `usermod -aG punktfunk` and
    log back in, or it stops attaching — the capability moved off the `input`
    group (which every gamepad guide tells you to join) onto its own, because it
    can emulate arbitrary USB hardware.
  * Plugin UIs moved to their own origin on PORT+1, so a self-signed console
    needs the new port trusted once, and custom firewalls/proxies need it opened.
  * Saving a custom launch command re-confirms the console password, and add-ons
    may no longer set launch/pre-launch commands at all — a real break for any
    third-party add-on that populated them.
  * A fresh install now runs the plugin runner by default (upgrades untouched).
  * The Deck setup script used to leave the generated console password
    world-readable, so rotating it is worth a sentence.

The library-sources work is written as GROUNDWORK, deliberately. All six built-in
scanners still ship, still on by default, and nothing is removed — and none of
the replacement add-ons are published yet, so the migration banner only appears
as they arrive. Promising a user they can move Steam to an add-on today would be
the v0.22.3 mistake again: notes describing a build nobody is getting.

Two other honesty items. The Android HUD entry says outright that the stream did
not get faster and the headline number only got smaller because it stopped
counting the compositor's wait — otherwise every reader takes it for a speed-up.
The Windows non-C: settings entry says plainly that nothing is recoverable,
because the writes never reached disk, so there is no orphaned copy to restore
and the reader has to re-enter their preferences once.

`56adb470` (pad-audio WASAPI module path) is deliberately NOT a user-facing Fixed
entry: verified it is not an ancestor of v0.24.0, so it repairs a Windows build
break in code that has never shipped. It folds into the pad-audio feature. Same
for `19f637ea`, which is CI-only.

Under the hood gained the origin-isolation mechanism, the allowlist authorization
gate that fails the build on an unclassified route, store claims and the v2
library.json shape, the registry auth work, the config-writer fallback, send
pacing, and the vendored Deck WSI layer. The unverified list grew too: the origin
split has not been in a real browser, the packaging default-on changes have had
no installer run, and no launcher tile has ever been clicked.

Re-verified after the merge, all green: lock diff versions-only 32/32 against
origin/main, `cargo metadata --locked` resolves (35 members), `cargo fmt
--all --check` clean in both workspaces, doc lazy-continuation scanner 0 hits
over 521 files, notes body 0 internal-vocabulary hits above `## Under the hood`,
Play notes still 494/500 by android.yml's own gate logic. Wire 2, C ABI 16, and
the capability bytes are all unchanged from the bump commit — host_caps still has
exactly one free bit (0x80).

Play's "What's new" is left as it stands: at 494/500 there is no room, and the
only Android-facing additions here (the stats-overlay measurement change and a
certificate-strictness fix) are both worth less to a phone user than any line
already in it.
All checks were successful
ci / docs-site (pull_request) Successful in 1m13s
ci / web (pull_request) Successful in 1m15s
apple / swift (pull_request) Successful in 1m27s
apple / screenshots (pull_request) Skipped
ci / rust-arm64 (pull_request) Successful in 3m14s
android / android (pull_request) Successful in 4m34s
windows / build (aarch64-pc-windows-msvc) (pull_request) Successful in 6m45s
windows / build (x86_64-pc-windows-msvc) (pull_request) Successful in 4m27s
ci / rust (pull_request) Successful in 14m5s
You are not authorized to merge this pull request.
This pull request can be merged automatically.
This branch is out-of-date with the base branch
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin worktree-release-0250:worktree-release-0250
git checkout worktree-release-0250
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: unom/punktfunk#56