Step 1 of the game-detection feature (game-presence-plan.md): all the
pure, I/O-free logic, tested first.
- src/game/mod.rs: DetectedGame + stable namespaced ids (steam:730 /
exe:hl2_linux, never the mutable name); ManualOverride; the priority
resolve() matcher (override -> Steam -> mapped process -> none); the
Debouncer (2-on/3-off, immediate bypass for manual override) that
stops a flapping detector re-announcing the ~48KB-avatar PeerState;
match_processes() over explicit user mappings with a launcher denylist
(never guesses a game from an arbitrary process).
- src/game/vdf.rs: a real recursive-descent KeyValues/VDF parser (not a
name-regex) for appmanifest/.acf, libraryfolders.vdf, registry.vdf —
depth-capped, escape-aware, never panics on malformed/truncated input.
- src/sanitize.rs: sanitize_game_label (64-char/256-byte cap, wider than
the 48-char name cap) sharing the bidi/zero-width cleaning.
- src/config.rs: additive game_presence_enabled (opt-in, default OFF),
game_backgrounds + game_process_map (BTreeMap, deterministic);
background_path generalized to hashed per-game files; explicit
legacy-config migration test (load() wipes on any deserialize error).
- src/background.rs: game_background_filename (FNV-1a hashed, fs-safe).
No wire/protocol change yet; no OS reads yet. 386 lib tests (+28).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Chat messages rendered URLs as plain text. Now http/https URLs render as
clickable links that open in the system browser (xdg-open).
- New pure `sanitize::linkify` splits an (already-sanitized) message into
text/URL segments: conservative — only http:// and https:// runs, ending at
whitespace, with trailing prose punctuation peeled back out; reassembling the
segments reproduces the input exactly. +6 unit tests.
- Chat render uses iced `rich_text` with link spans + `on_link_click`.
- `OpenUrl` handler re-validates the http(s) scheme (defence in depth) before
spawning xdg-open with the URL as a single argv entry (no shell, no injection).
Linkify only runs after `sanitize_chat`, so control/format chars are already
gone. 214 lib tests green, clippy clean. Manual check: send a message with a
URL, click it.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Three findings from the first security pass:
- S3 (Medium): the peer-supplied screen-share ticket was passed to pixelpass
as the first positional CLI arg with no end-of-options guard, so a ticket
starting with `-`/`--` could be reinterpreted as a flag (argument injection).
New pure `viewer_args()` puts flags first, then a `--` guard, then the ticket
positionally; spawn_viewer uses it. +2 tests.
- S4 (Medium): peer presence display-names (gossip `Announce`, untrusted and
spoofable) were rendered unsanitized/unbounded, unlike the chat path. New
`sanitize::sanitize_name` strips bidi/zero-width format chars + control chars,
collapses whitespace, and caps at 48 chars; applied at the gossip ingest point
so every consumer gets a safe value. +4 tests.
- S1 (Low): `&id[..8]` byte-slices could panic on a short/non-ASCII id. New
panic-free `short_id()` (char-based take) replaces both slices. +1 test.
158 lib tests (was 151), clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>