Files
punktfunk/scripts/wincheck.sh
T
enricobuehlerandClaude Opus 5 995cac5d03 fix(vdisplay): the three hardest FFI calls were exempt from the crate's own unsafe-proof rule
`#![deny(clippy::undocumented_unsafe_blocks)]` cannot see an unsafe operation that
sits directly in an `unsafe fn` body — in edition 2021 `unsafe_op_in_unsafe_fn` is
allow-by-default, so a bare call inside such a body needs no block and therefore
carries no proof. The file headers claim "every unsafe block carries a SAFETY
proof", and that was true; it just did not cover the calls that needed it most.

Turning the lint on named exactly three: `DeviceIoControl` and the `ioctl` wrapper
in pf_vdisplay.rs — the whole host<->driver control channel — and
`restore_displays_ccd` in manager.rs, the call the teardown path depends on to give
the operator their physical panels back. Each now carries a real proof, and `ioctl`
and `set_render_adapter` grew the `# Safety` heading their callers were owed.

Also teaches scripts/wincheck.sh to cover pf-vdisplay, which is what let the above
be compile-verified rather than reasoned: the crate's Windows half is ~3,400 lines
that Linux CI never compiles. That needed a stub pf-encode (the real one drags
ffmpeg-sys, and the admission gate calls exactly one predicate from it) and
CompositorPref on the stub core. Verified non-vacuous with a planted type error.

pf-win-display's half of the same lint is a separate change — it flags 62 further
operations, and they want proofs written one at a time, not in bulk.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-28 19:45:11 +02:00

199 lines
7.8 KiB
Bash
Executable File

#!/usr/bin/env bash
#
# Type-check and lint punktfunk's WINDOWS-only Rust from a Linux dev box.
#
# scripts/wincheck.sh # clippy -D warnings, the default
# scripts/wincheck.sh check # cargo check instead
# scripts/wincheck.sh clippy --fix # extra args are passed through to cargo
#
# Linux CI never compiles `#[cfg(target_os = "windows")]` code, so a Windows-side edit is otherwise
# unverifiable until the Windows CI job runs (minutes) or someone tests on a real box. This gets the
# same answer in ~1 s warm, against the WORKING TREE — the generated workspace symlinks each `src`
# at the real crate directory, so there is nothing to keep in sync and no copies to go stale.
#
# WHY A SEPARATE WORKSPACE — the obvious in-tree command
#
# cargo check --target x86_64-pc-windows-msvc -p pf-capture
#
# fails, and NOT because of the Windows code: it dies in build scripts that compile C for the
# target. `audiopus_sys` first (cmake wants a Visual Studio generator), then `ring` (needs an MSVC C
# compiler plus the Windows SDK headers; clang-cl and lld-link exist locally but there is no SDK).
# Both enter the graph through `punktfunk-core`'s `quic` feature. Stubbing opus with a fake
# `opus.pc` gets past audiopus but not ring.
#
# The whole Windows capture stack uses exactly FOUR items from punktfunk-core — `quic::HdrMeta`,
# `Mode`, `CompositorPref` and its `as_str`, all plain data (re-verify with:
# `grep -rho 'punktfunk_core::[A-Za-z_:]*' crates/pf-{capture,frame,win-display,vdisplay}/src | sort -u`).
# So this script generates a ~50-line stub core carrying just those, and rustls/ring/opus never
# enter the graph at all. Every path dep that is NOT a generated member points at the REAL crate by
# absolute path, so their own relative deps and `version.workspace` inheritance still resolve.
#
# pf-encode is stubbed for the same reason and needs the same care: pf-vdisplay's admission gate
# calls exactly ONE item from it (`can_open_another_session`, admission.rs), but the real crate
# drags ffmpeg-sys — whose build script wants a Windows FFmpeg tree this box does not have. The
# stub is a `cfg(windows) -> bool`; if admission ever consults a second encoder fact, mirror it
# here or the cross-check stops covering that call.
#
# Note: `cargo fmt` needs none of this — rustfmt follows `mod`/`#[path]` without evaluating cfg, so
# it already reaches Windows-only files. Mechanical edits can be normalised with plain `cargo fmt`.
set -euo pipefail
REPO="$(cd "$(dirname "$(readlink -f "$0")")/.." && pwd)"
OUT="${WINCHECK_DIR:-$REPO/target/wincheck}"
TARGET=x86_64-pc-windows-msvc
# The generated members: crates whose Windows code we lint, plus the stub core they share. A path
# dep naming one of these must stay RELATIVE (resolving to the generated member); anything else is
# rewritten to the real crate. Getting that backwards silently drags the real punktfunk-core — and
# with it ring and opus — back in through pf-frame, which is the entire thing this avoids.
MEMBERS_RE='punktfunk-core|pf-encode|pf-frame|pf-win-display|pf-capture|pf-vdisplay'
REAL_MEMBERS=(pf-frame pf-win-display pf-capture pf-vdisplay)
cmd="${1:-clippy}"
[ $# -gt 0 ] && shift
case "$cmd" in
check | clippy) ;;
*)
echo "usage: $(basename "$0") [check|clippy] [extra cargo args...]" >&2
exit 2
;;
esac
if ! rustc --print target-list | grep -qx "$TARGET"; then
echo "wincheck: rustc does not know $TARGET" >&2
exit 1
fi
if ! rustup target list --installed 2>/dev/null | grep -qx "$TARGET"; then
echo "wincheck: target $TARGET not installed for the active toolchain — run:" >&2
echo " rustup target add $TARGET" >&2
exit 1
fi
rm -rf "$OUT"
mkdir -p "$OUT"
# Mirror the real [workspace.package] so the members' `version.workspace = true` resolves.
{
echo '# GENERATED by scripts/wincheck.sh — do not edit; re-run the script.'
echo '[workspace]'
echo 'resolver = "2"'
echo 'members = ["punktfunk-core", "pf-encode", "pf-frame", "pf-win-display", "pf-capture", "pf-vdisplay"]'
echo
echo '[workspace.package]'
sed -n '/^\[workspace\.package\]/,/^$/p' "$REPO/Cargo.toml" | sed '1d;/^$/d'
} > "$OUT/Cargo.toml"
mkdir -p "$OUT/punktfunk-core/src"
cat > "$OUT/punktfunk-core/Cargo.toml" <<'EOF'
# GENERATED by scripts/wincheck.sh — a STUB, not the real crate.
[package]
name = "punktfunk-core"
version.workspace = true
edition = "2021"
rust-version.workspace = true
[features]
default = []
# Present so dependents' `features = ["quic"]` resolves; carries no quinn/rustls/opus.
quic = []
EOF
# Field layout and derives must match the real definitions, or the cross-check goes stale exactly
# where it matters (the capture code builds HdrMeta literally and compares Modes).
cat > "$OUT/punktfunk-core/src/lib.rs" <<'EOF'
//! GENERATED by scripts/wincheck.sh — a STUB of punktfunk-core carrying only the two items the
//! Windows capture stack uses. Mirrors crates/punktfunk-core: `Mode` from config.rs, `HdrMeta`
//! from quic/datagram.rs. If either grows a field, mirror it here.
/// Mirrors `punktfunk_core::Mode`.
#[repr(C)]
#[derive(Clone, Copy, Debug, PartialEq, Eq)]
pub struct Mode {
pub width: u32,
pub height: u32,
pub refresh_hz: u32,
}
/// Mirrors `punktfunk_core::CompositorPref` (config.rs). pf-vdisplay matches on every variant and
/// calls `as_str`, so both the variant set and the strings must stay in step with the real enum.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Default)]
pub enum CompositorPref {
#[default]
Auto,
Kwin,
Wlroots,
Mutter,
Gamescope,
}
impl CompositorPref {
pub fn as_str(self) -> &'static str {
match self {
CompositorPref::Auto => "auto",
CompositorPref::Kwin => "kwin",
CompositorPref::Wlroots => "wlroots",
CompositorPref::Mutter => "mutter",
CompositorPref::Gamescope => "gamescope",
}
}
}
pub mod quic {
/// Mirrors `punktfunk_core::quic::HdrMeta`.
#[derive(Clone, Copy, Debug, PartialEq, Eq, Default)]
pub struct HdrMeta {
pub display_primaries: [[u16; 2]; 3],
pub white_point: [u16; 2],
pub max_display_mastering_luminance: u32,
pub min_display_mastering_luminance: u32,
pub max_cll: u16,
pub max_fall: u16,
}
}
EOF
mkdir -p "$OUT/pf-encode/src"
cat > "$OUT/pf-encode/Cargo.toml" <<'EOF'
# GENERATED by scripts/wincheck.sh — a STUB, not the real crate.
[package]
name = "pf-encode"
version.workspace = true
edition = "2021"
rust-version.workspace = true
EOF
cat > "$OUT/pf-encode/src/lib.rs" <<'EOF'
//! GENERATED by scripts/wincheck.sh — a STUB of pf-encode carrying only the one item pf-vdisplay's
//! admission gate uses. The real crate pulls ffmpeg-sys, whose build script needs a Windows FFmpeg
//! tree; nothing in the display path needs the encoder itself, only this predicate.
/// Mirrors `pf_encode::can_open_another_session` (lib.rs, `#[cfg(target_os = "windows")]`).
#[cfg(target_os = "windows")]
pub fn can_open_another_session() -> bool {
true
}
EOF
for name in "${REAL_MEMBERS[@]}"; do
mkdir -p "$OUT/$name"
# Park the member paths behind a sentinel first: a plain self-substitution would be a no-op and
# the next rule would rewrite them to absolute along with everything else.
{
echo "# GENERATED by scripts/wincheck.sh from crates/$name/Cargo.toml — src/ is a symlink."
sed -E "s#path = \"\.\./($MEMBERS_RE)\"#path = \"@@M@@\1\"#g; \
s#path = \"\.\./([A-Za-z0-9_-]+)\"#path = \"$REPO/crates/\1\"#g; \
s#path = \"@@M@@#path = \"../#g" "$REPO/crates/$name/Cargo.toml"
} > "$OUT/$name/Cargo.toml"
ln -sfn "$REPO/crates/$name/src" "$OUT/$name/src"
done
cd "$OUT"
for name in "${REAL_MEMBERS[@]}"; do
echo "=== $cmd $name ($TARGET) ==="
if [ "$cmd" = clippy ]; then
cargo clippy --target "$TARGET" -p "$name" --all-targets "$@" -- -D warnings
else
cargo check --target "$TARGET" -p "$name" --all-targets "$@"
fi
done