The workspace pinned `ring` everywhere because aws-lc-sys 0.41.0 failed to C-compile on the Windows CI runner. Re-tested on that runner (.133) with aws-lc-sys 0.44.0: the `params.c` cl.exe failure does not reproduce under MSVC 14.44, and rustls's `aws_lc_rs` feature turns on `aws-lc-rs/prebuilt-nasm`, so no NASM is needed on the box either. That unblocks post-quantum TLS: `prefer-post-quantum` offers X25519MLKEM768 first on every TLS 1.3 handshake (mgmt API, native control plane, QUIC), which ring cannot do — it has no ML-KEM. Classical curves stay in the list, so older clients still connect. rustls, quinn, rcgen and tokio-rustls each select a backend independently, so all four had to move together; a single dissenter pulls a second crypto stack in via feature unification. The direct `ring` users (ed25519 in pf-update-check, SHA-256 in the Windows updater) moved to aws-lc-rs, whose API is ring-compatible. `ring` does NOT leave the tree: ureq 2 names `features = ["ring"]` in its own rustls dependency line and cargo features are additive, so no dependent can switch it off. Two backends compiled in means rustls refuses to infer one, and anything built via `ClientConfig::builder()` panics instead of picking — which is what ureq's default agent does on its first HTTPS request. `tls::install_default_provider()` makes the choice explicit; it runs at each binary's entry point and defensively in pf-client-core, which several binaries link. Dropping ring entirely needs the ureq 2 -> 3 upgrade (36 call sites), deliberately left out of this change. Verified on macOS: pf-update-check 32, punktfunk-core 385, c_abi 1 (the last with LIBRARY_PATH=/opt/homebrew/opt/opus/lib) — aws-lc-sys links into the C ABI harness, so the Swift/Kotlin embedders keep working. cargo fmt --all --check clean.
punktfunk — probe (reference client)
punktfunk-probe is the headless reference client for the punktfunk/1 protocol — a
command-line tool for testing, latency measurement, and validating host behavior. It's not a
streaming app you'd watch on; it connects, exercises a plane, and reports numbers. If you want to
actually stream, use the Linux, Windows,
Apple, or Android clients.
Because it links the same punktfunk-core as every other client, it's also the canonical
example of driving the protocol end to end: QUIC control plane, UDP data plane, and the side planes
(input, audio, rumble) over QUIC datagrams.
What it does
- Receives a real stream, writes a playable elementary stream (
.h265/.h264/.av1— the extension tracks the negotiated codec; the probe advertises all three and the host picks), and reports per-frame capture→received latency percentiles (the host stamps each frame with its capture clock). - Verification mode against a synthetic host — byte-checks deterministic test frames.
- Exercises every plane with scripted test traffic:
--input-test(mouse/keyboard),--mic-test(a 440 Hz Opus tone up to the host mic),--touch-test(a synthetic finger),--rich-input-test(DualSense touchpad + motion, logging the HID-output feedback that comes back). - Trust —
--pin <64-hex>pins the host fingerprint;--pair <PIN>runs the SPAKE2 pairing ceremony and prints the verified fingerprint to pin from then on. Without a pin it trusts on first use. - Discovery —
--discover [secs]browses the LAN for_punktfunk._udphosts and prints each (name, addr:port, pairing requirement, cert fingerprint), then exits. - Negotiation knobs —
--mode WxHxFPS,--remode(mid-stream mode change),--bitrate,--codec auto|h264|hevc|av1(preference; the host resolves),--audio-channels(stereo / 5.1 / 7.1),--compositor,--gamepad,--launch,--speed-test. Env:PUNKTFUNK_CLIENT_10BIT=1/PUNKTFUNK_CLIENT_444=1advertise the 10-bit / 4:4:4 client caps (for testing a host'sPUNKTFUNK_10BIT/PUNKTFUNK_444).
Usage
# stream 720p120 from a host, save the video, and print latency percentiles:
cargo run -p punktfunk-probe -- --mode 1280x720x120 --connect HOST:PORT --out /tmp/a.h265
# list hosts on the LAN:
cargo run -p punktfunk-probe -- --discover
# pair with a host that requires it (read the PIN off the host), then stream:
cargo run -p punktfunk-probe -- --connect HOST:PORT --pair 1234
cargo run -p punktfunk-probe -- --connect HOST:PORT --pin <64-hex> --input-test
Full flag reference is in the module doc-comment at the top of src/main.rs.
Related
- Project README — the host, the streaming clients, and the protocol
punktfunk-host punktfunk1-host— the persistent native-protocol listener to probe against (see the "Running on this box" section of the repo README /CLAUDE.md)