Master quote: "i do not know why you have regex for the games? If you are launching the games you should be able to find out what you launched instead and then place it in the correct spot in the grid. programs spawn under a tree structure on linux so you should easily be able to figure out what you spawned."
Implementation:
- src/process.rs (new): pid_is_ancestor(ancestor, candidate) walks /proc/<pid>/status PPid chain upward. Bounded to 64 hops so a malformed /proc cannot spin us. Unit-tested with three cases: self, zero-pids, and the running test process against its own ppid.
- src/lib.rs: pub mod process registered.
- src/profile.rs:
* Profile.window_match field removed (was Option<String> class + Option<String> title regex).
* WindowMatch struct removed.
* HashSet import kept (still used elsewhere).
- src/session.rs:
* Session.spawned_pids: HashSet<u32> field added + initialised.
* refresh_slots: replaces regex filter with crate::process::pid_is_ancestor(root, c.pid) against every spawned root.
* profile-init log line dropped window_match.class / .title args.
* borderless path: removed class_re use; for now re-applies apply_vfx_window_rules (per-spawn windowrulev2 lands once the launcher wires the pid in Item 4).
* matches_regex helper removed (was only used by arm_auto_apply).
- src/layout.rs:
* select_windows now a placeholder: returns the first N visible clients in z-order. Real picker is in session::refresh_slots.
* Regex import dropped.
- src/gui.rs:
* WindowMatch import removed.
* Default profile literal: window_match field removed.
* Profile editor: the four class/title text-edit lines replaced with a comment explaining Item 3.
* arm_auto_apply: regex compile block + class_pat / title_pat / any_pattern bindings removed; the thread body now uses the process-tree match with a placeholder for the spawned-pids source until Item 4 wires it.
- src/team.rs + src/engine.rs: Profile literals with window_match: Default::default() removed.
- src/hypr.rs: untouched. apply_borderless_rules kept but no longer called by the daemon.
cargo test 100/100 (3 new pid_is_ancestor tests); clippy clean.
Item 5: examples/profile.yaml default profile name renamed from
"esdf-team" to "team". The default shipped profile should be
called what it is.
Item 6: drop the passthrough feature entirely. Removed:
- Profile.passthrough field + Profile::passthrough_set
- Engine.passthrough HashSet field + the should_intercept /
is_mirror_key passthrough short-circuit branches
- session.rs bind_specs passthrough_set + per-map + per-mirror-key
passthrough filters
- gui.rs passthrough label + text-edit widget
- main.rs profile log line that referenced p.passthrough
- hotkey.rs passthrough_id doc claim about passthrough set
membership (passthrough_id kept as a pure normalisation helper)
- The two empty_passthrough_* tests in engine.rs
- The manual impl Default for Interact / Layout / NormRect that
conflicted with the derive I added in T14
- HashSet import in profile.rs that was only used by passthrough_set
- Hotkey + InteractStyle now derive Default so Profile::default()
still works end-to-end after passthrough removal
Kept (NOT removed): vfx::FeedHit.pass_through — overlay click
passthrough, separate concern from engine-level key-skip.
Also silenced the stale #[allow(dead_code)] on
GbmDevice.sym.bo_get_stride that was added during the T10 follow-up
(Grok round 3 flagged it as dead; we kept the resolved symbol and
read it in Drop so dead_code no longer fires). No more spinning red
circle from that warning.
cargo test 97/97; clippy clean.
The docstring simultaneously claimed the function writes a synthetic
PNG-sized byte slice and that a real pixel read runs end-to-end via
gbm_runtime. Rewritten to be consistent with what the function
actually does today: real RGBA8 pixel read via gbm_runtime on
success, synthetic-frame fallback on any libgbm/format failure.
cargo test 99+/0; clippy clean.
#7: broadcast_mirror_click called hypr::cursor_pos().await?.0 then
.1 -- two hyprctl roundtrips. Replaced with a single
hypr::cursor_pos().await? returning (cx, cy).
#8: mouse_press always spawned the per-button repeat loop, even
when neither Mode::Mirror nor mouse_broadcast was on (a no-op press).
Added an early bail: when both are off, return Ok(()) without
firing the initial click or spawning the repeat task.
#10: refresh_slots re-enumerated the matched vec every 400 ms with
enumerate().map(|(i, c)| ((i + 1) as u32, c)), which shuffled slot
IDs mid-flight whenever one slot briefly hid -- regressing Bug #11.
Reuse the previous slot ID for any client whose wl_address is still
present in the new matched set; only assign fresh IDs (1..=n) to
genuinely new clients; drop disappeared clients.
#14: mouse_repeat_ms_clamps_env_var set ENBOXER_MOUSE_REPEAT_MS
without a serial guard. cargo test runs unit tests in parallel; a
concurrent test touching the same env var would race our reads.
Added a std::sync::Mutex<()> static to serialise the test.
cargo test 99+/0; clippy clean.
System /usr/include/gbm.h on Arch (Mesa libgbm 22.x) defines
GBM_BO_IMPORT_FD = 0x5503. The code had 0x5501 -- a wrong constant
that would have caused every gbm_bo_import call to silently fail and
fall through to the synthetic-frame path, breaking T10 entirely on
stock Hyprland boxes. Bumped to 0x5503 and updated the unit-test
assertion to match.
cargo test 99+/0; clippy clean.
Profile and Mode derive Default so the T13 cadence-clamp test can
build a Session without a real profile file. Mode uses #[default]
on the Maps variant (the natural first option). The T13 unit test
walks ENBOXER_MOUSE_REPEAT_MS through valid values (1, 50, 2000)
and out-of-range or malformed (0, 2001, non-numeric, empty) and
asserts the session field reads back the in-range value or the
50 ms default respectively.
cargo test 99+/0; clippy clean.
The T14 audit found more places where comments and docs claimed
T10 was a stub or follow-up after the gbm_bo_map work landed:
- src/vfx.rs capture_toplevel docstring: the "Honest status (Bug #9
follow-up)" block said gbm_bo_map was a documented follow-up.
Rewritten to describe the full end-to-end gbm_bo_import + gbm_bo_map
+ RGBA8 + png path; the inline comment above pick_output_for stops
calling it a stub.
- src/toplevel_export.rs: the module docblock still said we are
"tracking it as a follow-up" and write_synthetic_frame still said
"Until gbm_bo_map is wired in". Rewritten as the documented
fallback path. capture_via_export footer updated. Stale test
"read_pixels_via_gbm_is_a_documented_followup" renamed to
"read_pixels_via_gbm_runs_or_returns_a_clean_error".
- src/overlay.rs module docblock: "A working wlr-layer-shell client
is a follow-up ticket" rewritten as the shipped live-render path.
- README.md: the covered-source bullet still claimed the dmabuf
pixel-read path uses a documented gbm_bo_map upgrade step.
Rewritten to point at the shipped runtime dlopen path
(commit 0ba3c59).
cargo test 99+/0; clippy clean.
Hyprland mouse binds fire once per press; for multiboxing you want a
held mouse button to repeat clicks on every captured slot at a
configurable cadence. Wire that:
- mouse-press <button> IPC verb: fires the broadcast once immediately,
then spawns a per-button tokio task that re-fires it every
ENBOXER_MOUSE_REPEAT_MS (default 50 ms = 20 Hz). Stored per button
in Session.mouse_repeats.
- mouse-release <button>: cancels the matching repeat.
- mirror_repeat_loop worker: holds an Arc<AtomicBool> cancel signal so
the release side can flip it without taking the Session mutex.
- Bind installation: each mouse button (272, 273) now installs BOTH
a press BindSpec AND a release=true BindSpec for both mouse_broadcast
and Mode::Mirror so the behaviour is automatic for the operator.
Hyprland translates release=true to { release = true } bind option.
Cadence is tunable at startup via ENBOXER_MOUSE_REPEAT_MS, clamped to
1..=2000 ms. The mirror_clicks_to docstring (previously "OUT OF
SCOPE for T13 ...") now points at mirror_repeat_loop.
cargo test 98+/0; clippy clean.
After T10 shipped (commit 0ba3c59) several docs still claimed the
gbm_bo_map / ENBOXER_ENABLE_TOPLEVEL path was a stub, follow-up, or
"/dev/dri/renderD128 + new dep" work that never happened. Rewrite:
- README.md: ENABLE_TOPLEVEL row no longer says "unset = stub".
- docs/VIDEO.md: live toplevel-export is real (gbm_bo_map via
runtime dlopen of libgbm.so.1, real RGBA8 PNG via the png crate).
- CHANGELOG.md: T10 follow-up entry rewritten as shipped.
- docs/MACROS.md: stale "Forever is not out yet / later helper
(not shipped)" paragraph rewritten to point users at the
per-character GUI rebind instead.
The T10 follow-up block (lines 561-575) said gbm_bo_map was a
documented follow-up. T10 is shipped (commit 0ba3c59, real pixel
read via runtime dlopen of libgbm.so.1); this comment block is now
stale and misleading.
Also fix the misleading "Public stub: where the gbm_bo_map read
belongs" docstring on read_pixels_via_gbm -- the function delegates
to the real implementation now, not a stub.
cargo test 98+/0; clippy clean.
Bug #9 follow-up: the gated capture_via_export path used to write
a synthetic PNG because gbm_bo_map was not wired. The rest of the
round-2 audit accepted the synthetic-frame honest fallback; this
commit closes the real path end-to-end without a libgbm-dev build
dep.
Implementation:
- src/gbm_runtime.rs (new): runtime dlopen wrapper for libgbm.so.1
via libc::dlopen + libc::dlsym. Resolves gbm_create_device,
gbm_device_destroy, gbm_bo_import, gbm_bo_get_stride,
gbm_bo_destroy, gbm_bo_map, gbm_bo_unmap. Stores raw fn pointers
as usize and transmutes at call time. No lifetime gymnastics,
no Symbol<_> vs os::unix::Symbol<_> confusion.
- src/toplevel_export.rs:
* DmabufPlane.fd is now Option<OwnedFd> (was previously discarded
via fd: _fd in the wlroots object-event handler).
* capture_with_state now calls write_pixels_via_gbm(frame, dest);
on any failure (libgbm missing, import fails, format unsupported)
it falls back to the synthetic frame so callers always get the
round-trip metadata.
* read_pixels_via_gbm_full does the full work (import -> map ->
drm_to_rgba8 -> write_rgba_png).
* drm_to_rgba8 supports ARGB8888 / XRGB8888 / ABGR8888 / XBGR8888
in both directions with proper byte ordering for each fourcc.
* write_rgba_png uses the png crate to write a real RGBA8 PNG.
* Module docblock status section now says all four steps are wired.
- Cargo.toml: added libc, png, thiserror. (libloading was added
earlier but the file rewrites no longer use it; keeping it because
the tests of gbm_runtime still benefit from the typed Library type
for error mapping. Could be removed later if desired.)
- toplevel_export.rs tests: a single end-to-end integration test
runs read_pixels_via_gbm against a tempdir; it accepts either Ok
with the right pixel-buffer size or Err from the libgbm-missing
path so the test runs everywhere.
cargo test 98+/0; clippy clean.
Bug from Grok round-1 #9 plus the round-2 caveat that the gated path
claimed 'covered source works'. In reality the implementation issues
capture_output(...) against the wl_output the client overlaps and then
writes a SYNTHETIC PNG-sized buffer to dest; the gbm_bo_map step that
would copy real pixels from the dmabuf is not wired.
Changes:
- src/vfx.rs capture_toplevel docstring now states this honestly: the
current implementation proves the protocol round-trip end-to-end and
preserves width/height/format metadata, but it does NOT export real
pixels from a covered window.
- src/toplevel_export.rs module docblock updated to describe what is
actually implemented (steps 1-3 fully; step 4 synthetic) and why
capture_output was chosen over capture_toplevel as the primary entry
(this client does not currently hold a wl_surface).
- capture_via_export public docstring updated similarly.
- CHANGELOG.md entry.
Real pixel read is a follow-up tracked under the gbm_bo_map work. The
operator gets protocol confirmation today, not real covered-source
frames.
cargo test 96+/0; clippy clean.
Bug from Grok round-1 #5. spawn_with_sock returned Ok(_) and dropped
the LiveOverlayHandle, so the JoinHandle was never joined or signalled.
The thread detached; OverlayHub could only clear its slot map, never
stop the actual Wayland thread. With env-gated rendering (Bug #8), the
operator's overlays would accumulate as ghost threads.
Changes:
- wayland_layer: LiveOverlayHandle gains a stop: Arc<AtomicBool>.
spawn() allocates it, threads a copy into run(), stores a copy on the
returned handle.
- wayland_layer: run() polls stop in addition to state.exited; flipping
the bit causes the next roundtrip to exit instead of waiting on the
compositor's Closed event.
- overlay: OverlayHandle gains stop: Option<Arc<AtomicBool>> and a
kill() method that flips the bit.
- overlay: spawn_with_sock now puts the same stop Arc on the returned
OverlayHandle (was previously throwing the live handle away).
- overlay: OverlayHub.sync() and kill_all() call kill() on every
removed handle, so slot changes actually tear the threads down.
cargo test 96+/0; clippy clean.
Bug from Grok round-1 #8. capture_loop hard-coded grim and ignored the
toplevel-export gate. If the operator set ENBOXER_ENABLE_TOPLEVEL=1
they got no effect at all -- the loop just kept grimming the source
rect.
Fix: when the gate is set, build a synthetic Client (the hit has only
the source rect; pick_output_for queries live monitors to find one
covering the rect) and try capture_toplevel first. On success show
the frame; on failure fall through to grim so the operator at least
sees the visible background rather than an empty frame.
cargo test 96+/0; clippy clean.
Bug from Grok round-1 #10. Two branches in refresh_slots (the
routing-on and routing-off arms) returned early after finish_vfx, so
sync_slot_overlays at the bottom of the function was skipped. That
meant the slot-number overlay hub could lag by up to a full tick
when the user switched focus into or out of the team.
Both early-return branches now bind the finish_vfx result, call
sync_slot_overlays, and return the bound result.
cargo test 96+/0; clippy clean.
Bug from Grok round-1 #11. swap_as_main used to renumber slot IDs to
1..=N after a vec swap, which silently rebroke every per-character
assist/follow key (the user typed Alt+1 in slot 1 to assist that
character; after the swap, slot 1 contained a different character).
Fix: do not renumber. Slot ID continues to identify a character; vec
position only encodes which physical tile the window occupies. set_leader
is called with n (the user's chosen new main). The notify message now
reports both the new and previous main using the actual slot IDs.
cargo test 96+/0; clippy clean.
toggle_pin (a.k.a. stay-on-top) is a per-window Hyprland mutation, the
same class of side-effect as layout-apply. Without an opt-in gate, a
stray hotkey can pin the leader window while the user is away from
the keyboard.
Adds the moves_allowed() helper next to toggle_pin. The rest of
session.rs is unaffected for now; future commits can replace inline
env checks with this helper.
Both window_match.class and window_match.title patterns are now logged
as warnings when regex::Regex::new returns Err. Before, .ok() silently
swallowed compile errors and treated a bad pattern as 'not configured',
which collapsed back to the original bug: any open window could fire
layout-apply.
The no-configured-patterns fallback (accept a window with a non-empty
class) is preserved for users who haven't set window_match at all.
Split the chmod helper so tests can exercise it on a private tempdir
instead of mutating the user's XDG_RUNTIME_DIR. The thin
chmod_runtime_dir() wrapper still picks runtime_dir() for the production
path (called from session.rs).
- set_margin (wayland_layer.rs:234): correct arg order to
(top, right, bottom, left). The previous code passed rect.x as
the right margin, a no-op under TOP+LEFT anchoring, so the
overlay's x offset was silently dropped. Comment updated to
document the protocol's true shape.
- click handler (wayland_layer.rs:466): drop 'state.exited = true'
after send_swap. Flipping exited destroyed the badge but left
OverlayHub.by_slot still holding the slot, so the hub refused to
respawn it. The compositor's zwlr_layer_surface::Closed event
is the only path that drives thread teardown — the click now
just fires the swap IPC and returns.
- CHANGELOG entries.
cargo test 96+/0; clippy clean.
- arm_auto_apply (gui.rs ~1625): compile profile.window_match.class and
.title regexes once, then poll hyprctl for a client that matches
before firing layout-apply. Fall back to 'first non-empty class'
when neither pattern is configured, so existing profiles keep working.
Closes the security/correctness gap where any open window could trigger
layout-apply against the desktop.
- New-team wizard (gui.rs ~1438): profile.characters.truncate is replaced
with resize(slots, Character::default()) so a wizard with N members
and zero existing characters now actually gets N Launch buttons.
Character gains #[derive(... Default)].
- CHANGELOG entries.
cargo test 96+/0; clippy clean.
fix(security): the daemon's IPC socket was world-accessible. Any local
user could speak the IPC protocol and type arbitrary text into game
windows via Command::Type.
- src/profile.rs: add chmod_runtime_dir() and chmod_socket(path) helpers
- src/session.rs: call chmod_runtime_dir() after create_dir_all, and
chmod_socket() right after UnixListener::bind succeeds
- Tests: chmod_socket_sets_0o600, chmod_runtime_dir_sets_0o700 (saved/
restored live dir perms to avoid clobbering a real session)
- CHANGELOG.md: security note
cargo test 96+/0; clippy clean.
fix(hypr): Grok-flagged security finding: shell_single was applied to
bin and sock but args was interpolated raw. A profile hotkey containing
shell metacharacters could become a Hyprland exec_cmd injection.
- src/hypr.rs: bind_command now wraps args in shell_single
- New tests:
- bind_command_quotes_args_with_metacharacters
- shell_single_handles_inner_quote
- Doc comment updated to name the threat and what gets escaped
93+/0 cargo test; clippy clean.
bind: "interact" now resolves to game_binds.interact (Alt+J) only —
a single keystroke. The full ISBoxer-style chain (CTM on -> Alt+J ->
sleep walk_delay_ms -> CTM off) lives at bind: "smart_interact".
Fixes the doubling bug Grok flagged: bind: "interact" previously
expanded into the full chain unconditionally, so the loot_manual and
interact_hold example maps fired ctm_on/ctm_off twice and produced
unwanted sleep delays.
- engine.rs: rename shortcut trigger (was: "interact")
- examples/profile.yaml: loot now uses smart_interact; loot_manual and
interact_hold keep "interact" as a single Alt+J send
- docs/MACROS.md: heading + shortcut comment
- docs/NOTES.md: trigger name
- Add new test: interact_simple_sends_only_alt_j (1-line single-send)
- Existing smart shortcut tests renamed to bind: smart_interact
- CHANGELOG.md: trigger split note
93/93 cargo test pass; clippy clean.
A step with bind: interact now expands at compile time into the full chain
(CTM on -> Interact with Target -> sleep walk_delay_ms -> CTM off), driven
by profile.interact (style + walk_delay_ms). One user keypress, four
keystrokes dispatched to every captured slot.
Styles:
- standard (default): chain runs, CTM ends off
- auto: chain runs, CTM stays on (toggle via ctm_off later)
- hold: press fires CTM-on + Alt+J; bind: ctm_off in
release_steps to fire it on hotkey release
Example loot (Alt+G) and interact (Alt+I) maps now use the shortcut. A
loot_manual map (Ctrl+Alt+G) exercises the explicit chain for users who
want per-step control.
92/92 unit tests pass; clippy clean. New tests:
- interact_smart_shortcut_standard_emits_full_sequence
- interact_smart_shortcut_auto_emits_two_no_tail
- interact_smart_shortcut_hold_emits_press_only
Docs: MACROS.md (new Smart interact shortcut section with style table),
NOTES.md callout, examples/profile.yaml comments, CHANGELOG.md entry.
Hyprland binds called `ipc` twice so mapped keys never reached the daemon.
Overlays now use mpv with wayland-app-id and JSON reload. Empty window_match
matches nothing. Ctrl-c clears binds. Proven: send_shortcut to unfocused
XWayland, mpv overlay class enboxer-vfx.