Windows half of the sweep — the reap bug, a panic that poisons two locks, and a round of unsafe
reduction.
* **The ghost reap selected the wrong devices.** It filtered `Status -ne 'OK'`, a HEALTH field: that
matches devices that are PRESENT but in Error/Degraded/Unknown, not the ABSENT ones the reap is
for — and it handed them to `pnputil /remove-device`, contradicting its own documented contract.
It runs from `add_monitor`'s mid-session slot-exhaustion recovery, so the blast radius is a live
session. Now filters on `-not $_.Present`.
* **`ensure_pinger` still used the panicking `thread::spawn` while holding two locks**, poisoning
both — the un-fixed twin of a fix that already landed for `ensure_exclusive_watch`. Same shape
applied.
Unsafe reduction, continuing the program that made pf-win-display's CCD helpers safe fns:
* `resolve_target_gdi` and `reisolate_after_swap` were `unsafe fn`s containing zero unsafe
operations, and the three call-site SAFETY proofs described FFI they no longer perform. Both are
now safe fns and those blocks are gone.
* `VdisplayDriver::open`'s `# Safety` section named no caller obligation — the same empty shape an
earlier phase already removed from `open_device`.
* `(*detail).DevicePath.as_ptr()` derived a pointer from a `[u16; 1]` field and handed it to
`CreateFileW`, which reads the whole flexible-array path beyond it. Now taken with `&raw const`
from the full struct, so the pointer carries the provenance of the bytes actually read — the same
correction already made for `MONITORINFOEXW` in ddc.rs.
Comment fixes, all verified against the code: three intra-doc links to a type this crate does not
have; a doc-comment run merged so that `shrink_action` — the gate that keeps a `Primary` group's
physical panels lit — read as undocumented while its rationale sat on an unrelated polling helper;
and the backend module header, which documented itself against a `sudovda` module that does not
exist and a fallback the crate says was removed.
Adds the first tests for `knobs.rs`, `instance.rs` and `driver.rs` — including `is_privileged_sid`,
the security-relevant predicate that decides whether an existing single-instance name is another
host or a squat, which had no coverage on any platform.