Files
punktfunk/packaging/winget/unom.PunktfunkHost.locale.en-US.yaml
T
enricobuehler 94b7a834cb
apple / swift (push) Successful in 3m19s
decky / build-publish (push) Successful in 35s
windows-host / package (push) Successful in 18m44s
windows-host / winget-source (push) Skipped
rpm / build-publish (44, fedora-44, punktfunk-fedora44-rpm) (push) Successful in 22m27s
rpm / build-publish (43, bazzite, punktfunk-fedora-rpm) (push) Successful in 17m15s
apple / screenshots (push) Successful in 23m24s
ci / web (push) Successful in 58s
ci / docs-site (push) Successful in 1m27s
ci / bench (push) Successful in 7m15s
ci / rust-arm64 (push) Successful in 11m47s
deb / build-publish-client-arm64 (push) Successful in 10m21s
android / android (push) Failing after 11m52s
deb / build-publish-host (push) Successful in 11m34s
docker / build-push (., web/Dockerfile, punktfunk-web) (push) Successful in 1m42s
deb / build-publish (push) Successful in 17m34s
docker / build-push (docs-site, docs-site/Dockerfile, punktfunk-docs) (push) Successful in 3m6s
docker / build-push (ci, ci/rust-ci-noble.Dockerfile, punktfunk-rust-ci-noble) (push) Successful in 8m30s
arch / build-publish (push) Successful in 18m29s
docker / build-push (ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora-rpm) (push) Successful in 13m59s
docker / build-push (--build-arg FEDORA_VERSION=44, ci, ci/fedora-rpm.Dockerfile, punktfunk-fedora44-rpm) (push) Successful in 14m36s
docker / build-push (ci, ci/rust-ci.Dockerfile, punktfunk-rust-ci) (push) Successful in 13m1s
docker / deploy-docs (push) Successful in 35s
ci / rust (push) Successful in 30m15s
docker / build-push-arm64cross (push) Successful in 9m8s
fix(installer/windows): GameStream is opt-in, not on by default
A user found this in their log and had never been offered a choice:

  WARN GameStream/Moonlight compat ENABLED (--gamestream): its pairing runs over
  plain HTTP and its legacy control encryption can reuse GCM nonces
  (security-review #5/#9) — an on-path LAN attacker could MITM pairing or
  recover input. Enable only on a TRUSTED network.

They were right. The `gamestream` task carried no `Flags: unchecked`, so it was
pre-ticked; and since a silent install takes the wizard's own task defaults
(1839d756), a winget install turned it on with no checkbox ever shown. The host
warns that this plane is a security downgrade on every single start, so having
the installer enable it by default cannot be squared with our own advice — least
of all on the path where nobody sees a wizard.

Now unchecked, matching `allowpublicfw`, the other task with a security
consequence. A default install therefore lands `PUNKTFUNK_HOST_CMD=serve`, the
native-only host; Punktfunk's own clients are unaffected, since the native
punktfunk/1 plane is always on. Unattended opt-in is `/MERGETASKS=gamestream`.

Scope, deliberately: this changes FRESH installs only. `GamestreamParam` already
omits the flag entirely unless `FreshHostInstall`, so no existing host has its
choice touched by an upgrade, and anyone relying on Moonlight today keeps it.
`DEFAULT_HOST_CMD` (the service's fallback when host.env carries no
PUNKTFUNK_HOST_CMD line at all) is deliberately NOT flipped here: the installer
always writes the line explicitly, so it does not affect a normal install, and
inverting it would silently disable Moonlight for anyone whose host.env lost that
line — a runtime regression that belongs in its own change, if at all.

Docs corrected everywhere they stated the old default, since three of them now
told users the opposite of what ships: the winget Agreement shown BEFORE install
(it said "enabled by default" and gave the opt-OUT override), the Windows
packaging README, and host.env.example. The `--override` example in the installer
manifest is inverted with it (`/MERGETASKS=gamestream` to add, `!` to remove).

Verified: [Tasks] + [Code] compile with ISCC 6.7.1 on the windows-amd64 runner
(all optional features defined), and the winget catalogue rebuilds and passes
29/29 with the edited manifests.
2026-07-27 12:26:47 +02:00

74 lines
3.8 KiB
YAML

# yaml-language-server: $schema=https://aka.ms/winget-manifest.defaultLocale.1.6.0.schema.json
PackageIdentifier: unom.PunktfunkHost
PackageVersion: 0.19.2
PackageLocale: en-US
Publisher: unom
PublisherUrl: https://git.unom.io/unom/punktfunk
PublisherSupportUrl: https://git.unom.io/unom/punktfunk/issues
PackageName: Punktfunk Host
PackageUrl: https://docs.punktfunk.unom.io/docs/windows-host
License: MIT OR Apache-2.0
LicenseUrl: https://git.unom.io/unom/punktfunk/src/branch/main/LICENSE-MIT
Copyright: Copyright (c) unom
ShortDescription: Low-latency game-streaming host — stream your PC's games to any Punktfunk or Moonlight client.
Description: |-
Punktfunk Host turns a Windows 11 PC into a low-latency game-streaming server. It captures the
desktop or a dedicated virtual display, encodes with NVENC / AMF / QSV / Vulkan, and streams over
its native QUIC protocol to Punktfunk clients on Windows, macOS, iOS, tvOS, Android and Linux —
or over GameStream to stock Moonlight clients.
The installer bundles the pf-vdisplay virtual display driver (native-resolution and HDR streaming
without a physical monitor), virtual DualSense / DualShock 4 / Xbox 360 gamepads, and a web
management console served on port 47992.
Moniker: punktfunk-host
Tags:
- game-streaming
- remote-desktop
- moonlight
- gamestream
- streaming
- remote-play
ReleaseNotesUrl: https://git.unom.io/unom/punktfunk/src/branch/main/docs/releases/v0.19.2.md
Documentations:
- DocumentLabel: Windows Host Setup
DocumentUrl: https://docs.punktfunk.unom.io/docs/windows-host
# Shown BEFORE download/install; the user must accept or the install does not proceed. This is what
# carries — on the unattended path, where no wizard page is on screen — the disclosures the wizard
# puts in its task text. VB-Audio's bundling grant specifically requires the end user to see
# VB-CABLE's origin + donationware status at install time.
Agreements:
- AgreementLabel: Bundled virtual audio (VB-CABLE by VB-Audio)
Agreement: >-
Punktfunk's streaming microphone uses VB-CABLE by VB-Audio (www.vb-cable.com), which this
installer bundles and installs. VB-CABLE is donationware — all participations welcome. It is
redistributed under VB-Audio's bundling grant; the full notice is installed to
%ProgramFiles%\punktfunk\licenses\VB-CABLE-NOTICE.txt.
AgreementUrl: https://vb-audio.com/Cable/
- AgreementLabel: GameStream (Moonlight) compatibility is OFF by default
Agreement: >-
Punktfunk's own clients work out of the box. Support for stock Moonlight clients is a separate,
opt-in plane, because it pairs over legacy plain HTTP and is intended for trusted LANs only. To
install WITH it, use --override "/VERYSILENT /SUPPRESSMSGBOXES /NORESTART /SP-
/MERGETASKS=gamestream", or run --interactive and tick the GameStream checkbox. It can also be
turned on later with `punktfunk-host service install --gamestream=on` (or via
PUNKTFUNK_HOST_CMD in %ProgramData%\punktfunk\host.env), followed by a service restart.
AgreementUrl: https://docs.punktfunk.unom.io/docs/windows-host
# Displayed after the install completes. The console password is generated per install, so it can
# only be pointed at, never printed here — this text is fixed at publish time.
InstallationNotes: |-
Web management console: https://<this-PC>:47992
The login password was generated during installation and is stored in
%ProgramData%\punktfunk\web-password (edit that file to change it).
Configuration: %ProgramData%\punktfunk\host.env
Logs: %ProgramData%\punktfunk\logs\
The host service starts automatically at boot. `punktfunk-host` is on the machine PATH — run
`punktfunk-host service status` from an elevated prompt to check it.
ManifestType: defaultLocale
ManifestVersion: 1.6.0