The safety half of the rust-safety programme's §8.4: `std::env::set_var`/`remove_var` are
`unsafe fn` in edition 2024, converting the class of bug the programme found the hard way
(the 972af299 environ data race lived in a file with ZERO occurrences of the word
`unsafe`) from invisible to counted and compiler-enforced.
Manifests: [workspace.package] edition 2021→2024, rust-version 1.82→1.85 (the pinned
toolchain is 1.96.0, so no toolchain bump — only the declared floor rises); the 13 crates
pinning `edition = "2021"` literally now inherit it (Trap 1: the root bump alone reaches
only `edition.workspace = true` crates and would have left pf-encode/pf-capture/pf-inject
et al. on 2021 while reading as complete); pf-driver-proto's stale rust-version 1.82 pin
now inherits; pf-vkhdr-layer (a separate workspace, inherits nothing) bumped to 2024. The
four vendored crates (fec-rs, cros-codecs, usbip-sim, the patched ndk) stay on 2021
deliberately — upstream code stays pristine. The excluded usbip-poc standalone PoC is
untouched.
Mechanical, done textually across ALL cfg branches so no platform's half is left behind
(Trap 3 — 44% of the host's unsafe is Windows-only and a one-platform `cargo fix` misses
it): 148 `#[no_mangle]` → `#[unsafe(no_mangle)]` (83 in abi.rs); 12 bare extern blocks →
`unsafe extern`; `gen` is a reserved keyword, so pf-vdisplay's generation stamps
(registry.rs, windows/manager.rs) and the WinUI shell's animation counters rename
gen → generation (internal identifiers only, no serde/wire surface); two
match-ergonomics patterns take the compiler's suggested reference form.
env mutation: every `set_var`/`remove_var` site (20 files) now sits in an `unsafe` block
whose SAFETY comment states the real serialization argument (pf-vdisplay's ENV_LOCK,
CONFIG_DIR_TEST_LOCK, ART_ROOTS_LOCK, vkdecode's gpu_lock, the `--test-threads=1`
contracts of the hardware spikes, or single-threaded startup). Two genuine hazards
surfaced en route — exactly the WP3b-class finds this migration exists to make visible —
and are fixed here:
- windows/service.rs spawned the network-profile warner thread BEFORE `load_host_env()`,
so a child-spawning thread (child spawn snapshots the env block) was live while
`set_var` ran in a loop; the load now precedes the spawn.
- pf-console-ui's `fake_home()` re-set HOME outside its OnceLock on EVERY call, so two
parallel tests could race the write; the set now happens exactly once inside
`get_or_init`.
cbindgen (Trap 2): 0.29.4 parses `#[unsafe(no_mangle)]` — verified empirically; the
header regenerates byte-identical. The ci.yml drift check could never catch "failed to
regenerate" (build.rs demotes a cbindgen failure to a warning and writes nothing, leaving
the checked-in header untouched and the diff clean), so the step now first asserts the
"punktfunk-core: wrote" line and the absence of "cbindgen failed" (sh -e safe: no `!`
pipeline, no tee-masked exit).
rustfmt: style_edition pinned to 2021 at the root — edition 2024 would otherwise flip the
style edition and reformat ~370 untouched files inside this same commit, burying the
migration diff. The drivers workspace pins its already-current 2024 style. Adopting the
2024 style tree-wide is its own future one-line-plus-reformat commit.
Census: the primary metric moves UP BY DESIGN — 2435 → 2453 operations, unsafe blocks
1534 → 1577, and env_set_var is now a counted category (45 ops). The newly counted env
sites are a truer number, not a regression; baseline snapshot saved as punktfunk-planning
design/rust-safety-census-baseline-2026-08-12-edition-2024.txt. Gate C's env ratchet is
now compiler-enforced (the hygiene-script header says so); the two shrunk file counts
(nvenc_cuda 49→2 via the test helpers, shell/tests 2→1) are lowered in the same commit
per the gate's own rule.
Drop order (the semantic change most likely to bite this codebase): the migration lint
`-W tail-expr-drop-order` reports zero findings on the macOS-visible halves of
pf-encode / pf-zerocopy / pf-capture / pf-frame; the Linux and Windows halves run the
same lint on the gate boxes. The four #[ignore]d alloc/drop-cycle tests on the hardware
boxes remain owed, as before this change.
96 lines
4.4 KiB
Rust
96 lines
4.4 KiB
Rust
//! punktfunk Android client — the JNI bridge ("nativecore") over `punktfunk-core`.
|
|
//!
|
|
//! Architecture: the **Rust-heavy** client model (like `punktfunk-client-linux`, *not* the
|
|
//! thin-native-over-C-ABI Apple model). This `cdylib` links `punktfunk-core` directly and drives
|
|
//! the whole `punktfunk/1` protocol through [`punktfunk_core::client::NativeClient`]; Kotlin owns
|
|
//! only the Android-framework surface (Compose UI, `SurfaceView` lifecycle, input capture, the
|
|
//! Wi-Fi `MulticastLock` + permission UX, Keystore). The JNI seam below is the one place the two
|
|
//! languages meet.
|
|
//!
|
|
//! Why Rust-heavy: Kotlin cannot `import` the cbindgen C header the way Swift can, so a native
|
|
//! bridge is unavoidable. Writing it in Rust lets the Android client reuse the Linux client's
|
|
//! orchestration verbatim — audio jitter ring, the VK keymap inverse, latency/skew math, the
|
|
//! input capture state machine, trust/pairing logic, **mDNS discovery** ([`discovery`], the same
|
|
//! `mdns-sd` browse the Linux/Windows clients use) — instead of re-porting it into Kotlin. Kotlin
|
|
//! keeps only the Android-framework surface it must (Compose UI, `SurfaceView`, input capture, the
|
|
//! Wi-Fi `MulticastLock` + permission UX, Keystore identity).
|
|
//!
|
|
//! JNI symbols map to `io.unom.punktfunk.kit.NativeBridge` in the `:kit` Gradle module
|
|
//! (`clients/android`). The surface: the native-link proof (`abiVersion`/`coreVersion`), mDNS host
|
|
//! discovery ([`discovery`]), and the session lifecycle in [`session`] — connect/pair + the trust
|
|
//! surface, the per-plane pumps (video → AMediaCodec, audio ↔ AAudio, mic uplink), input, and
|
|
//! rumble/HID feedback ([`feedback`]). Mode renegotiation is still TODO (see [`session`]).
|
|
|
|
use jni::objects::JObject;
|
|
use jni::sys::jint;
|
|
use jni::JNIEnv;
|
|
|
|
#[cfg(target_os = "android")]
|
|
mod adpf;
|
|
#[cfg(target_os = "android")]
|
|
mod audio;
|
|
#[cfg(target_os = "android")]
|
|
mod decode;
|
|
// Ungated: pure `mdns-sd` + `jni`, so the browse + its JNI seam link into the host workspace build
|
|
// (and its unit test runs there) exactly like `session`/`stats`. Kotlin only ever calls it on device.
|
|
mod discovery;
|
|
mod feedback;
|
|
#[cfg(target_os = "android")]
|
|
mod mic;
|
|
/// Tier-A DualSense pad audio: the 0xD1 plane rendered on the pad's own USB endpoint.
|
|
mod pad_audio;
|
|
mod session;
|
|
mod stats;
|
|
// Ungated like `discovery`: pure `jni` + `punktfunk_core::wol` (no Android framework), so it links
|
|
// into the host workspace build too. Kotlin only ever calls it on device.
|
|
mod wol;
|
|
// Ungated like `wol`: pure `jni` + `punktfunk_core::client` (the reachability probe). Kotlin calls
|
|
// it off the main thread to light saved-host "online" pips independently of mDNS.
|
|
mod probe;
|
|
|
|
/// Initialize `android_logger` once when the JVM loads the library. Logs land in logcat under the
|
|
/// `punktfunk` tag. Core `tracing` events (transport warnings: socket-buffer clamp, QoS failures)
|
|
/// arrive here too: tracing's "log" feature — declared explicitly in Cargo.toml rather than relied
|
|
/// on via quinn's defaults — forwards them as `log` records since no tracing subscriber is ever
|
|
/// installed. Android-only — there is no JVM (and no logcat) on the host build.
|
|
#[cfg(target_os = "android")]
|
|
#[unsafe(no_mangle)]
|
|
pub extern "system" fn JNI_OnLoad(
|
|
_vm: *mut jni::sys::JavaVM,
|
|
_reserved: *mut std::ffi::c_void,
|
|
) -> jint {
|
|
android_logger::init_once(
|
|
android_logger::Config::default()
|
|
.with_max_level(log::LevelFilter::Info)
|
|
.with_tag("punktfunk"),
|
|
);
|
|
log::info!(
|
|
"punktfunk_android loaded (core ABI v{})",
|
|
punktfunk_core::ABI_VERSION
|
|
);
|
|
jni::sys::JNI_VERSION_1_6
|
|
}
|
|
|
|
/// `NativeBridge.abiVersion(): Int` — the core's C-ABI version. A non-error return is the
|
|
/// scaffold's proof that `System.loadLibrary` found the `.so`, the JNI symbol resolved, and the
|
|
/// linked `punktfunk-core` is the one we expect.
|
|
#[unsafe(no_mangle)]
|
|
pub extern "system" fn Java_io_unom_punktfunk_kit_NativeBridge_abiVersion(
|
|
_env: JNIEnv,
|
|
_this: JObject,
|
|
) -> jint {
|
|
punktfunk_core::ABI_VERSION as jint
|
|
}
|
|
|
|
/// `NativeBridge.coreVersion(): String` — the crate version, proving JNI string marshaling works.
|
|
#[unsafe(no_mangle)]
|
|
pub extern "system" fn Java_io_unom_punktfunk_kit_NativeBridge_coreVersion<'local>(
|
|
env: JNIEnv<'local>,
|
|
_this: JObject<'local>,
|
|
) -> jni::sys::jstring {
|
|
match env.new_string(env!("CARGO_PKG_VERSION")) {
|
|
Ok(s) => s.into_raw(),
|
|
Err(_) => JObject::null().into_raw(),
|
|
}
|
|
}
|