`clippy::undocumented_unsafe_blocks` is what makes the SAFETY convention a rule rather than a habit,
and three crates had never adopted it — pf-client-core (91 unsafe items), pf-presenter (123) and
punktfunk-core (167) — while every other subsystem crate denied it. That gap is why the decoders'
`unsafe impl Send`s carried a one-line aside instead of an argument: nothing required one.
pf-client-core and pf-ffvk now deny it, with a proof written for all 58 + 3 sites they had.
⚠️ 44 of those 58 were WINDOWS-ONLY — `clipboard.rs` 24 and `video_d3d11.rs` 20 — and invisible to
the Linux measurement that sized this work at 14. Same trap as the E0133 sweep: a Linux-only survey
of a cross-platform crate undercounts by whatever the `cfg` hides, here by 3x. Landing the deny on
the strength of that number alone would have re-broken Windows CI, which is exactly the mistake this
session already made once with the `warn`-that-was-really-`deny`.
The proofs say what is actually load-bearing rather than restating the call. In `clipboard.rs` that
is the ownership split Win32 requires and nothing in the code stated: `GetClipboardData` returns a
handle BORROWED from the clipboard (never freed here), while `GlobalAlloc` + `SetClipboardData`
TRANSFERS ownership to it (which is why nothing frees that one either) — two opposite rules, three
lines apart. In `video_d3d11.rs` the recurring one is that libav's `get_format` list is
NUL-terminated by `AV_PIX_FMT_NONE`, which is what keeps the walk in bounds.
Remaining: punktfunk-core (~146, of which `abi.rs` is 141) and pf-presenter (~108). Both want the
"state the contract once" treatment — abi.rs's sites are a handful of repeating shapes (`opt_cstr`
on caller C strings, null-guarded out-param writes, forwarding calls), not 141 distinct arguments.
Note the vendored `fec-rs` (18 sites) is a separate path-dependency crate, so it is out of scope
rather than something to prove.
Verified: Linux .21 fmt + both CI clippy steps rc=0; Windows .47 `-p pf-client-core` clippy
`-D warnings` rc=0 (the only place the 44 are visible), plus the full Windows CI clippy set and
pf-capture's 18 tests.
82 lines
3.7 KiB
Rust
82 lines
3.7 KiB
Rust
//! Shared, UI-agnostic client plumbing, extracted verbatim from the GTK client
|
|
//! (design: punktfunk-planning `linux-client-rearchitecture.md`, Phase 0) so the desktop
|
|
//! shells and the Vulkan session binary build on one implementation — on Linux AND
|
|
//! Windows (the session binary runs on both; macOS stays `wol`-only, clients/apple is
|
|
//! the client there).
|
|
//!
|
|
//! Nothing here may depend on a UI toolkit: the presenter contract is `session`'s
|
|
//! channels (`SessionHandle`) and `video`'s `DecodedImage` (RGBA bytes, dmabuf fds +
|
|
//! plane layout, or a decoded VkImage) — how frames reach the screen is the consumer's
|
|
//! business.
|
|
//!
|
|
//! Audio is the one per-OS module swap: `audio.rs` (PipeWire) on Linux,
|
|
//! `audio_wasapi.rs` (WASAPI) on Windows — same public surface, picked here by `#[path]`
|
|
//! so `crate::audio` is the only name the session pump ever sees. `keymap` (evdev-keyed)
|
|
//! stays Linux: the session path uses pf-presenter's SDL-scancode table instead.
|
|
|
|
// Unsafe-proof program: every `unsafe {}` / `unsafe impl` in this crate carries a `// SAFETY:`
|
|
// proof of why it is sound. This crate held ~91 unsafe items with NO enforcement while every
|
|
// other subsystem crate denied it — the decoders' `unsafe impl Send`s had a one-line aside
|
|
// instead of an argument precisely because nothing required one.
|
|
#![deny(clippy::undocumented_unsafe_blocks)]
|
|
|
|
#[cfg(target_os = "linux")]
|
|
pub mod audio;
|
|
#[cfg(windows)]
|
|
#[path = "audio_wasapi.rs"]
|
|
pub mod audio;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod discovery;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod gamepad;
|
|
#[cfg(target_os = "linux")]
|
|
pub mod keymap;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod library;
|
|
// The `punktfunk://` grammar (design/client-deep-links.md §2): one parser/emitter for the
|
|
// shells, the session and the CLI, held to the Swift/Kotlin ports by a shared vector file.
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod deeplink;
|
|
// The brain layer (design/client-architecture-split.md §3): what a connect is, the wake
|
|
// state machine every front-end drives, and the session spawn + stdout contract.
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod orchestrate;
|
|
// Client settings profiles: the override catalog + the one connect-time resolver
|
|
// (design/client-settings-profiles.md §4). Sits beside `trust`, which owns the host records
|
|
// the bindings live on.
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod profiles;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod session;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod trust;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod video;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
mod video_color;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
mod video_software;
|
|
// libav ownership helpers shared by the hardware decoders below (`AvBuffer`).
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
mod video_libav;
|
|
#[cfg(target_os = "linux")]
|
|
mod video_vaapi;
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
mod video_vulkan;
|
|
// The OS-clipboard bridge for the shared clipboard (design/clipboard-and-file-transfer.md §5).
|
|
// Built everywhere the session client is; the platform seam inside is Windows-real,
|
|
// stub elsewhere.
|
|
#[cfg(any(target_os = "linux", windows))]
|
|
pub mod clipboard;
|
|
// PyroWave decode — Linux + Windows (plan §4.5; the Apple Metal port is its own phase).
|
|
// Windows joined once its client moved to the SAME spawned Vulkan session presenter as
|
|
// Linux's: the decoder is plain Vulkan compute on the presenter's device (no fds, no
|
|
// dmabuf, no D3D11 interop), so the old "Windows present-path decision" that gated it
|
|
// resolved itself — the present path is now literally the same code.
|
|
#[cfg(windows)]
|
|
pub mod video_d3d11;
|
|
#[cfg(all(any(target_os = "linux", windows), feature = "pyrowave"))]
|
|
pub mod video_pyrowave;
|
|
|
|
pub mod wol;
|