Files
punktfunk/include
enricobuehler c7d0fd2e03
apple / swift (pull_request) Successful in 1m59s
apple / distribute (pull_request) Skipped
apple / screenshots (pull_request) Skipped
ci / bun-nix (pull_request) Successful in 18s
android / android (pull_request) Successful in 11m19s
ci / rust-arm64 (pull_request) Successful in 7m47s
windows-client / client (arm64, --no-default-features, aarch64-pc-windows-msvc, C:\t-a64) (pull_request) Successful in 3m18s
ci / web (pull_request) Successful in 10m42s
windows-client / client (x64, , x86_64-pc-windows-msvc, C:\t) (pull_request) Successful in 6m53s
ci / docs-site (pull_request) Successful in 11m14s
nix / flake (pull_request) Successful in 15m44s
ci / rust (pull_request) Successful in 1h0m25s
release: 0.28.0 — version bump, notes, CHANGELOG, Play notes
180 commits since v0.27.0. Cut from origin/main 9c133350.

THE NUMBER: 0.28.0, not 0.27.1. The CHANGELOG's in-development section was
titled "v0.27.1", which the release does not support — 17 `feat(...)` commits,
a packager-visible default flip (GameStream opt-in on every route), the
edition-2024 MSRV rise, and now a genuinely BREAKING host change (the built-in
library scanners are deleted). `scripts/ci/pf-version.sh`'s canary rule agrees
independently: CI already stamps canaries `0.28.<run>`.

TWO DEFECTS FOUND AND FIXED WHILE PREPARING, both pre-existing on main:

1. C ABI_VERSION was stale at 18. Two exported symbols landed since v0.27.0
   without a bump — punktfunk_connection_note_frame_index_ex and
   punktfunk_reanchor_gate_arm_expecting_drops (72 -> 74 declarations in
   include/punktfunk_core.h). The constant's own doc history makes the rule
   explicit: v17 and v18 each bumped for adding exactly one symbol. Bumped to 19
   with its doc entry; the header is regenerated (cbindgen, CI-gated) and the
   C ABI harness passes printing abi_version=19.

2. docs-site/public/openapi.json had drifted to 0.21.0 against api/openapi.json,
   missing five endpoints. The copy is a documented manual step that nothing in
   CI enforces (CONTRIBUTING.md says so outright). Re-synced — and then it
   DRIFTED AGAIN inside this same cycle when the scanner-removal regen updated
   api/openapi.json alone, so it is re-synced a second time and the CHANGELOG
   now says to treat the copy as part of regenerating, not a follow-up.

 The final docs batch also invalidated a line in this CHANGELOG: the identity
section still said the P-256 key was "generated by ring via rcgen", which contradicted
this same document's "ring is gone from the tree entirely". Corrected to "rcgen on the
workspace's aws-lc-rs backend", matching 92db6651.

api/openapi.json stays stamped 0.27.0: it cannot be regenerated here
(punktfunk-host does not compile on macOS) and does not need to be — the drift
test normalizes info.version, so only the SURFACE is gated, and the surface is
current.

CHANGELOG: retitled to v0.28.0, gained the version table (wire 2 unchanged; C
ABI 18->19; edition 2021->2024 and MSRV 1.82->1.85; driver protocol 6 and
gamepad channel 3 unchanged; plugin-kit 0.4.0->0.4.1), a breaking-changes
section, and ~29 topics the in-development text predated — including the four
that landed last: the scanner->plugin migration, the Mutter rebuild
serialization, the KWin <=60 Hz readback, and the Apple/Android de-prime fuse.

 THE BREAKING ONE, stated plainly in both halves: the six built-in library
scanners are DELETED and the library is assembled entirely by plugins. There is
deliberately no migration — a plugin claims its store and republishes each title
under the same `<store>:<external_id>` id, so entry ids, GameStream app ids, art
caches, Moonlight pins, per-source toggles and per-entry hides all keep working.
The one visible consequence, and the whole upgrade note: a host with NO library
plugins installed has an empty grid.

 The Mutter two-client segfault this release now fixes (a5c9b7b8) is the one
found during THIS release's on-glass validation: chaining two clients through a
kept display killed gnome-shell in meta_monitor_manager_rebuild. It was A/B'd on
.21 against the released 0.27.0 and shown byte-identical there, so it was never
a 0.28.0 regression — and the fix's own commit message cites that A/B.

GATES RUN, all green on this commit (re-run after the rebase onto 86cbbea0):
  cargo fmt --all --check            clean
  cargo metadata --locked            OK against the new dependency tree
  Cargo.lock                         versions-only vs origin/main, 36/36 lines
  cargo test -p punktfunk-core       210 passed
  c_abi harness                      PASS, abi_version=19 (needs LIBRARY_PATH
                                     for opus on macOS; a link path, not a defect)
  docs-site build                    exit 0 (bun install --frozen-lockfile + build)
  Play notes gate                    440/500 CHARACTERS, not byte-identical to
                                     any other release (`•` is 3 bytes — count
                                     characters, as the gate does)
  notes voice check                  0 hits above `## For developers`; TL;DR at
                                     6 bullets (README caps it at six)

ON-GLASS (against the canary of 14425716, code-identical bar ABI_VERSION):
Windows .173 0.28.13309 + Android and iPad, Linux .21 0.28.0-0.00013300 +
iPhone — both PASS. The idle sleep-blocker fix is proven before/after on .173
(`powercfg /requests` SYSTEM: the mic devnode -> "Keine."), and the GameStream
flip is proven at the socket level on .21 (47984/47989/47999 absent by default,
restored by PUNKTFUNK_GAMESTREAM=1). Old-client compat holds: Android 0.26.0
streams against the 0.28.0 host.

 NOT re-validated: the Mutter fix itself. .21 (VM 103) is stopped — it and
home-bazzite-2 (VM 119, currently running) share one passed-through GPU, so
bringing .21 up would stop the other VM. Owed once .21 is free; the repro is
iPhone 2868x1320 -> SIGTERM -> Android 2800x1260, and the marker to confirm the
build carries the fix is the string "mutter: waited out a monitor-topology
rebuild before releasing the lock".

NOT INCLUDED: the 14 unpushed pf-capture/pf-vdisplay sweep commits on the local
main. Never through CI; pushing them is the user's call.
2026-08-13 18:06:18 +02:00
..