feat(game): broadcast game presence (GOSSIP_PROTO 3) + per-game background
Steps 5-6 of game detection. BREAKING wire change — bump everyone. Wire (step 5): - PeerState.game: Option<String> (display label only — never appid/source). - SelfPresence.game + to_state carry it (single self-state builder). - GOSSIP_PROTO 2->3, GOSSIP_SIG_DOMAIN v3, version comment bumped together; Cargo MINOR 0.3.0 -> 0.4.0 per VERSIONING.md. v2/v3 isolate into different topics + signature domains, so a coordinated redeploy is required (same as the W4 avatar bump). - Gossip ingest sanitizes incoming game via sanitize_game_label (bidi/ control strip, 64-char/256-byte cap); empty -> None. - Bonus security fix (Codex find): reject inbound gossip frames over a 128KB cap BEFORE serde_json::from_slice — a legit Announce with a full 48KB avatar is ~49KB, so this bounds allocation abuse with headroom. Core wiring: - Spawns the detector at startup; consumes its watch channel in the main select. Detection runs continuously (for the local background); the broadcast is gated by game_presence_enabled (opt-in, default OFF). New commands: SetGamePresenceEnabled (immediate publish/clear, D8), SetGameOverride, SetGameProcessMap. New event: GameChanged. - game_presence_label sanitizes the outgoing label too. Background switch (step 6): - GUI handles GameChanged: stores current_game, swaps background to the per-game override (config.game_backgrounds[id]) or falls back to the W16 default; reuses the existing cached-handle path (no redraw flicker). 397 lib tests (all green), clippy --all-targets clean, full binary builds. Remaining: step 7 UI (opt-in toggle, roster 'Playing' text, manual override control, Settings game-backgrounds + process-map editors). Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -39,6 +39,15 @@ pub struct PeerState {
|
||||
/// peers/configs that predate the field still deserialize (→ monogram).
|
||||
#[serde(default)]
|
||||
pub avatar: crate::avatar::Avatar,
|
||||
/// The game this peer is currently playing, as a display string only (shown as
|
||||
/// `Playing <name>` next to their avatar). Opt-in and **untrusted** like
|
||||
/// `name`: sanitized + length-capped at the gossip ingest boundary. `None` when
|
||||
/// the peer isn't sharing a game (feature off / nothing detected). Only the
|
||||
/// display string rides the wire — never the appid or detection source, to
|
||||
/// avoid fingerprinting and coupling the protocol to detector internals.
|
||||
/// Defaulted so peers/configs predating the field still deserialize.
|
||||
#[serde(default)]
|
||||
pub game: Option<String>,
|
||||
}
|
||||
|
||||
/// The locally-owned, "sticky" pieces of our own presence: the identity fields
|
||||
@@ -56,6 +65,11 @@ pub struct PeerState {
|
||||
pub struct SelfPresence {
|
||||
pub name: String,
|
||||
pub avatar: crate::avatar::Avatar,
|
||||
/// The display label of the game we're currently broadcasting, or `None` when
|
||||
/// game presence is off / nothing is detected. Already sanitized + capped
|
||||
/// (see `crate::sanitize::sanitize_game_label`) before being stored here, so
|
||||
/// the outgoing announce carries a safe value.
|
||||
pub game: Option<String>,
|
||||
}
|
||||
|
||||
impl SelfPresence {
|
||||
@@ -74,6 +88,7 @@ impl SelfPresence {
|
||||
addr,
|
||||
sharing,
|
||||
avatar: self.avatar.clone(),
|
||||
game: self.game.clone(),
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -287,6 +302,7 @@ mod tests {
|
||||
addr,
|
||||
sharing: None,
|
||||
avatar: crate::avatar::Avatar::default(),
|
||||
game: None,
|
||||
}
|
||||
}
|
||||
|
||||
@@ -401,6 +417,7 @@ mod tests {
|
||||
let presence = SelfPresence {
|
||||
name: "Alice".to_string(),
|
||||
avatar: crate::avatar::Avatar::default(),
|
||||
game: Some("Half-Life 2".to_string()),
|
||||
};
|
||||
// Volatile fields come from the call; sticky fields from the struct.
|
||||
let muted = presence.to_state(true, addr.clone(), Some("ticket".to_string()));
|
||||
@@ -409,6 +426,7 @@ mod tests {
|
||||
assert_eq!(muted.addr.id, addr.id);
|
||||
assert_eq!(muted.sharing.as_deref(), Some("ticket"));
|
||||
assert_eq!(muted.avatar, crate::avatar::Avatar::default());
|
||||
assert_eq!(muted.game.as_deref(), Some("Half-Life 2"));
|
||||
// The same sticky presence yields different volatile fields per announce.
|
||||
let unmuted = presence.to_state(false, addr.clone(), None);
|
||||
assert!(!unmuted.is_muted);
|
||||
|
||||
Reference in New Issue
Block a user