Skip to content

Orbiscreen v0.30.0

Choose a tag to compare

@shadow-x78 shadow-x78 released this 30 Sep 05:49
· 52 commits to main since this release
v0.30.0
e92cafc

Full-project audit, security fixes, bug fixes, and dead-code/comment cleanup.

Security

  • Token bootstrap restricted (S1): GET /client/config.json now serves the live shared token only to loopback peers (USB AOA bridge, adb reverse) or requests already presenting a valid credential; remote LAN peers receive 401 authentication required instead of the token. Added regression tests covering loopback, remote-unauthenticated, and credential paths.
  • mDNS token broadcast removed (S1): the service TXT record no longer publishes the shared token; no client consumed it (Android DiscoveryService resolves host/port only).
  • Token fragments removed from logs (S2): auth-failure logs no longer include supplied/expected token prefixes; daemon startup logs no longer print token prefix/length; Android HostApi no longer logs token prefixes.

Bug Fixes

  • Android input ordering (B1-B3): VirtualCursor bounds now update on resize under the same lock; pending trackpad deltas flush before click snapshots; delivery serialized through a single bounded ordered channel with motion-only coalescing, release events are never dropped. 10 new input regression tests (65 unit tests green).
  • Wrong-tablet input fallback (B4): DisplayCommand::Input no longer falls back to an arbitrary active/first session; input requires an unambiguous session match (fail closed with multi-session).
  • Resize no longer displayless on failure (B5): display session resize opens the replacement before closing the old output, preserves viewer/attach counters, and initializes the idle deadline; rollback on open failure. Regression tests added.
  • Host pointer semantics (B3-host): mouse buttons 6-8 map to distinct BTN_SIDE/BTN_EXTRA/... codes instead of falling through to BTN_LEFT (regression test); release_tools now releases all mouse buttons and keycodes plus the tablet on disconnect (no stuck keys/buttons); resize recreates the touchscreen/tablet uinput devices with fresh ABS axis ranges instead of only updating stored dimensions.

Changed

  • MSRV (Pkg1): workspace rust-version raised from 1.75 to 1.92, matching the locked gstreamer 0.25.3 requirement (cargo previously refused builds on declared MSRV).
  • PPA source build (Pkg2): debian/rules now builds from source (cargo build --release --workspace --locked) instead of expecting prebuilt binaries, installs only artifacts that exist, and runs the test suite; debian/control declares Rust/GStreamer build-deps; the PPA workflow installs the build deps and verifies a source build + tests before upload.
  • Packaging omissions (Pkg3): clients/web/annexb.js (loaded by index.html) is now shipped by the PKGBUILD, Debian rules, and RPM spec; duplicate pkgver line removed from PKGBUILD; RPM packaging rebuilds from the current tree (no stale binaries) and the spec's GUI file list is conditional on the GUI binary being staged; verified end-to-end with a real rpmbuild producing a content-checked RPM.
  • USB udev rules: device nodes tightened from MODE="0666" to MODE="0660" with uaccess (console-user scoped instead of world-writable).

Cleanup

  • Removed the stale #[allow(dead_code)] on StreamQuery (field is read); adb.rs verified live (adb::supervisor in the USB path) and kept.
  • .gitignore now covers local .android/ and scratch/ scratch state.
  • Stripped non-GPL comments across Rust, Kotlin, and web-client sources and unified config file headers (GPL license headers retained; vendored mpegts.js untouched).