PyroWave encodes on the same GPU shader cores the game saturates, and an elevated VK_KHR_global_priority queue is the compute-preemption lever for it — measured on .21 (RTX 5070 Ti, GRID 2 loop): encode p99 6.4 -> 4.4 ms. Every driver refuses every priority class without CAP_SYS_NICE, on NVIDIA and on RADV alike, so the lever is decoration on a packaged host. 0.26.0-1 granted that capability to punktfunk-host and killed desktop streaming on every KDE box: KWin identifies a client by resolving /proc/<pid>/exe and matching an installed .desktop's Exec=, the kernel refuses that readlink to a reader whose effective set is not a superset of the target's PERMITTED set (cap_ptrace_access_check), and KWin holds no capabilities. #136 revoked it everywhere. The capability therefore cannot live in the process that fronts KWin. It lives in a new, deliberately small binary — punktfunk-encode-worker — which owns the priority-elevated Vulkan device and talks to nothing but the socket its parent spawned it on: no Wayland, no D-Bus, no network, no plugins. It is a SEPARATE FILE and must stay one; a hardlink or a hidden host subcommand shares the inode, hence the capability, and silently re-creates the incident. That rule is written where someone would break it, in the worker crate's own Cargo.toml. `open_inner` is reused verbatim in the worker — the same REALTIME->HIGH->none ladder, the same refusal-never-fails-open invariant, the same PUNKTFUNK_PERF split — so the A/B stays comparable with PW1. The only in-process change is a flag for whether THIS process prints the INERT warn, plus an out-parameter reporting the class that was granted. Three things the design did not anticipate: * An AU cannot ride in the message body. MAX_MSG is 64 KiB and bodies are serde_json, which renders a Vec<u8> as one decimal per byte: a 1080p60 AU is ~333 KB of JSON and 4K ~3.3 MB, and the minimum per-frame budget is already 64 KiB. So the AU crosses on a memfd the worker creates once and pwrites each frame; the fd crosses once, in Ready. A test pins the arithmetic so nobody "simplifies" the memfd away. Cursor bitmaps take the same route, only when their serial changes. * set_wire_chunking has to cross the wire even though poll_chunk does not. Chunking changes the AU BYTES, not merely how they are handed out — it feeds rate_budget()'s deflation and build_au's windowed framing — so a proxy-local copy would have the host cutting dense AUs at boundaries that are not window boundaries. Forwarded and mirrored. poll_chunk itself needs no protocol: the identical AuChunker runs host-side on the whole AU the worker returns. * CPU-backed frames really do reach this encoder (force_cpu_for_nvenc_444, and the raw-dmabuf degrade latch), and a 1080p BGRA frame is ~8 MB. The first non-dmabuf frame pins the session in-process with one warn rather than putting 480 MB/s on a socket. Every rung falls back to the in-process encoder exactly as today with one warn and never a dead session: PUNKTFUNK_ENCODE_WORKER=off, binary missing, spawn failure, handshake timeout, proto or workspace-version skew (host and worker are different files now, so that check is load-bearing), InitErr, a refused frame, and socket EOF mid-session — which respawns once, then pins inline. Also: recv retries EINTR with the REMAINING deadline, not a fresh one. With SO_RCVTIMEO the kernel returns EINTR rather than restarting, so a signal would otherwise read as a dead worker; re-arming with the full budget would instead let a steady signal rate defer a real hang forever.
40 lines
2.0 KiB
TOML
40 lines
2.0 KiB
TOML
# The capability-carrying PyroWave encode worker (design/gpu-priority-capability-worker.md).
|
|
#
|
|
# 🛑 This is a SEPARATE BINARY on purpose, and it must stay one. It is the only Punktfunk file that
|
|
# may carry `cap_sys_nice=ep`; `punktfunk-host` carries no capability on any channel, ever, because
|
|
# a capped process cannot be identified by KWin (`cap_ptrace_access_check` refuses
|
|
# `/proc/<pid>/exe` to a reader whose effective set is not a superset of the target's PERMITTED
|
|
# set) and therefore never gets `zkde_screencast_unstable_v1` — that was 0.26.0-1, and it killed
|
|
# every KDE desktop session. A hardlink to the host, or a hidden host subcommand, shares the inode
|
|
# and so shares the capability: same incident, silently. Never do either.
|
|
#
|
|
# All the logic lives in `pf-encode::worker`; this crate is the file, not the code.
|
|
[package]
|
|
name = "punktfunk-encode-worker"
|
|
version.workspace = true
|
|
edition = "2021"
|
|
rust-version.workspace = true
|
|
license = "MIT OR Apache-2.0"
|
|
description = "punktfunk PyroWave encode worker: owns the priority-elevated Vulkan device so the host never carries a capability."
|
|
publish = false
|
|
|
|
[[bin]]
|
|
name = "punktfunk-encode-worker"
|
|
path = "src/main.rs"
|
|
|
|
[dependencies]
|
|
# `features = ["pyrowave"]` unconditionally rather than through a feature of this crate: packaging
|
|
# builds this with `cargo build -p punktfunk-encode-worker` and default features, and a worker
|
|
# built without the codec would be a binary that hands every session straight back to the
|
|
# in-process fallback while still carrying the capability. (No extra cost to the workspace:
|
|
# punktfunk-host already has `default = ["pyrowave"]`, so a workspace build resolves it anyway.)
|
|
pf-encode = { path = "../pf-encode", features = ["pyrowave"] }
|
|
tracing = "0.1"
|
|
# The worker's stderr is inherited from the host that spawned it, so its lines land in the same
|
|
# journal — but it is a fresh process with no subscriber of its own, and without one the
|
|
# device-pick and priority-ladder lines would go nowhere.
|
|
tracing-subscriber = { version = "0.3", features = ["env-filter"] }
|
|
|
|
[lints]
|
|
workspace = true
|