The participant row right-anchors [name | space | share | mute | indicator],
with the status indicator ([Idle]/[Speaking]/[Muted]/[Connecting…]) as the
rightmost element. Those labels differ in width, so when a peer started
speaking the indicator grew and pushed the whole right cluster — including the
mute button — leftward, making the mute icon visibly jump.
Fix: render the indicator in a fixed-width (124px), right-aligned slot sized
for the longest label, so its left edge (and the mute button beside it) stays
put across state changes.
Build + clippy clean. Layout-only; visual confirmation wants a 2-machine call.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The gossip bootstrap list was derived solely from the ticket: a client
dialed the host, but "we are the host" produced an EMPTY list. So when the
room CREATOR rejoined their own room (their ticket names themselves as host)
they dialed nobody and never re-entered the swarm — the remaining peer stayed
stuck until it too left and rejoined. (First 2-human field test, 2026-06-14;
user-confirmed call-breaking, P1.)
Fix: retain the peers seen in the current room across leave (core
`known_peers`, updated by the event task; reset only when the joined ticket
changes) and pass them to `RoomState::join` as extra bootstrap targets. The
new pure `compute_bootstrap` seam unions the ticket host + retained peers,
drops self, and de-dups; address resolution rides the persistent lookup.
- `RoomState::join` gains `extra_bootstrap: Vec<EndpointAddr>` (test_net
callers pass vec![]).
- +4 unit tests on `compute_bootstrap`, incl. the host-rejoin regression case.
Tests-green (208 lib + 6 + 4 integration), clippy clean. NOT yet 2-machine
field-verified — needs a live host leave→rejoin call.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add an "Echo cancellation" checkbox to the in-call control column (beside
Push-to-Talk). It binds to the same config.echo_cancellation_enabled flag and
ToggleEchoCancellation message as the Settings checkbox, so the two stay in
sync automatically (single source of truth; iced re-renders from it). A tooltip
is explicit that it applies on the NEXT room join — the current PipeWire-module
AEC is wired at join time and isn't hot-swappable mid-call. (A true live in-call
toggle falls out for free once the in-process EchoCanceller lands — AEC Stage E.)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- The top-bar room-layout button was an icon-only canvas with no label or
tooltip, while the Settings button beside it is labeled — a discoverability
and consistency gap. Wrap it in the existing tooltip pattern ("Room layout",
Position::Bottom) so its purpose is discoverable on hover.
- The Audio Devices input/output columns used spacing(4) while every other
Settings section uses spacing(8); bump both to 8 for an even vertical rhythm.
Pure presentational changes. Build + clippy clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The sticky Settings header centered its title with two horizontal_space()
flanks plus a hardcoded 90px right spacer guessing the Back button's width —
off-center if the button's rendered width drifted (documented follow-up).
Replace with equal-width Fill flanks: the Back button sits in a left Fill
segment (left-aligned), an empty Fill segment balances the right, so the
center title is geometrically centered regardless of button width. No magic
constant. Pure layout change.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add Geigel double-talk detection so the adaptive filter stops diverging when
the near-end talks over the far-end (the failure the Stage B demo exposed:
ERLE went negative as the filter mistook near-end voice for echo).
- src/dsp/aec.rs: DoubleTalkDetector — Geigel test (mic level vs a sliding-
window peak of the far-end, via an O(1) monotonic-deque max) with a hangover
latch. EchoCanceller — wraps Nlms + the detector, freezing adaptation while
double-talk is declared; reports the double-talk rate; DTD can be toggled off
for A/B. 5 aec tests (detector fires on near-end not echo; DTD protects a
converged filter through double-talk, +15 dB over raw NLMS).
- specview aec: now uses EchoCanceller with tunable --dtd-threshold / --hangover
/ --near-onset / --no-dtd, and prints the double-talk %.
Tuning found with the harness (white far-end, -12 dB echo, near-end onset
mid-call): DTD threshold 0.5 is the sweet spot — late-call ERLE +29.6 dB with
DTD vs -4.0 dB without (a 33 dB swing); 0.35 over-triggers (never learns), 0.7
under-triggers (drifts). Default set to 0.5. Also documents the false-positive
/miss tradeoff and that correlated (pink/speech) far-ends converge slower.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Stage A+B of the in-process AEC: a Normalized LMS adaptive-filter echo
canceller and a synthetic echo-path simulator, driven end-to-end by a new
`specview aec` command so cancellation can be measured fully headless on
conjured signals (no speakers/mic needed).
- src/dsp/echo_path.rs: EchoPath — synthetic acoustic echo (bulk delay +
exponentially-decaying diffuse RIR, energy-normalized to a target
attenuation) convolved over a far-end signal. Gives ground-truth echo.
- src/dsp/aec.rs: Nlms — sample-at-a-time NLMS adaptive FIR (ring-buffered
reference history, energy-normalized update, freezable for double-talk).
Cleaned output = mic minus the learned echo estimate.
- specview aec: far -> sim echo -> (+ optional near-end) -> cancel -> measure.
ERLE via oracle residual (cleaned - near), broadband + early/late
(convergence) + per voice band, optional before/after spectrograms.
- 6 new tests (path delay/attenuation, NLMS convergence >20 dB on a known
path, frozen-filter no-op, near-end passthrough). 33 dsp tests total.
Verified: single-talk pink-noise echo cancels +14.5 -> +32.0 dB ERLE as the
filter converges; double-talk (no DTD yet) drives ERLE negative as the filter
diverges onto the near-end tone — the motivating result for Stage C (DTD).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a dependency-free signal-analysis toolkit and a `specview` dev CLI to
evaluate audio (especially echo cancellation) with objective numbers and a
terminal spectrogram instead of ear alone.
- src/dsp/: hand-written radix-2 FFT, Hann window, STFT, seeded test-signal
generators (sine/log-sweep/white/pink/impulse), metrics (RMS/dBFS/peak/ERLE/
per-band energy), minimal WAV read+write, and a 24-bit-ANSI half-block
spectrogram renderer (magma colormap, freq/time axes, dB legend, ASCII
fallback). Pure layers have no I/O; only `wav` touches the filesystem.
- src/bin/specview.rs: `gen` (conjure a test signal -> WAV), `show` (spectrogram
+ per-band energy summary), `erle` (broadband + per-band echo-return-loss
between a before/after pair).
- 27 unit tests (FFT correctness, ERLE landmarks, WAV round-trip, render shape).
Verified end-to-end: log sweep renders as the expected exponential curve;
a 20 dB-quieter copy reads +20.0 dB ERLE broadband and per band.
Measurement substrate for upcoming AEC refinement (no shipped-path changes).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Adds the "Recording" category to the Settings page so the recording mode is
selectable from the UI (config + core wiring already existed from Stage 2).
- AppMessage::RecordingModeSelected → persists config + sends SetRecordingMode
(takes effect on the next recording start). recording_mode_hint copy.
- iced 0.14 pick_list can't host per-option tooltips, so the three modes are
RADIO BUTTONS each wrapped in a `tooltip` (hover explains that mode) — chosen
over a dropdown so each option is self-documenting. Placed after Microphone,
using the shared section_header; output-dir note below.
- +1 config test (recording_mode round-trip + is_multitrack classification).
User-verified live (Both mode writes the expected WAVs; radios + tooltips
approved). Senior-written — Gemini's unsanctioned Stage 3 attempt was discarded.
179 tests (169 lib +1 ign, 6 reconnect, 4 transport), clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Wires MultitrackRecorder into the live audio path, behind a recording_mode.
- config: RecordingMode { Mixed, Multitrack, Both } + AppConfig.recording_mode
(serde-default Mixed, back-compat); CoreCommand::SetRecordingMode, sent at
app startup from config.
- multitrack.rs: mic now arrives async via push_mic into an internal FIFO,
drained one frame per end_cycle (mirrors recorder.rs) so the mic track tracks
the cycle clock; added dir() accessor. mic is a plain WavWriter now.
- core: parallel `multitrack` slot + `is_multitrack` fast-path gate (exactly one
of the mixed/multitrack recorders is active). SetRecording start branches on
mode: Mixed → single-file Recorder (unchanged); Multitrack/Both → a per-session
dir, MultitrackRecorder, and registers everyone already in the room (named,
silence-aligned from t=0). The mixer taps each peer's RAW frame (pre-volume/
mute/limiter) into stems and writes peer stems + mix (Both) + end_cycle per
cycle; the capture thread pushes mic to whichever recorder; PeerJoined adds a
late joiner's stem track. stop_recording finalizes both.
No UI yet to pick the mode (Stage 3) — defaults to Mixed, so behaviour is
unchanged until then; set recording_mode in config.json to exercise stems.
168 lib tests, clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Scopes the differentiating "record every peer to their own synced track"
feature and lands its pure, isolated core (no live-audio wiring yet).
- docs/multitrack-recording-plan.md: scope contract + locked decisions
(raw stems pre-volume/mute, stems + a mixed track, silence-pad late joiners).
- src/audio/multitrack.rs: MultitrackRecorder over the existing WavWriter.
One master clock = the mixer cycle; every end_cycle() appends exactly
FRAME_SAMPLES to every track (silence where idle) so all stems stay
sample-aligned. add_peer back-pads a late joiner to cycle 0; track_filename
gives fs-safe `<slug>-<shortid>.wav` (reuses sanitize_name). Optional mix
track for "Both" mode.
- +5 unit tests: equal length across tracks, late-joiner leading silence,
stems-only omits mix, fit() pad/truncate, filename slugging/disambiguation.
Stage 2 (wire into the mixer) is next, behind a checkpoint. 168 lib tests,
clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Reorganize Settings into six clearly-headed categories with a reusable
section_header (color_blue size-16 title + thin full-width divider): Audio
Devices, Microphone, Network & Privacy, Room Layout, Theme, Notifications &
Sounds. Splits the old shared Mic|Network row, drops the inconsistent inline
size-14 sublabels, and removes the hardcoded "Theme" title from theme_section
so it's rendered by the same header helper as every other section. Left-aligns
the content (was centered) so headers, dividers, and hints line up.
Presentational only; no message/logic changes. User-verified live.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The gossip `author` field was self-asserted, so an in-room member could forge
it to impersonate (chat), force-evict (Leave), or poison presence + the address
book (Announce). Now every GossipPayload is signed with the node's ed25519
secret key and verified on receipt; a forged author can't validate because the
attacker lacks the victim's key.
Done as the complete fix (forgery + replay):
- GossipPayload gains `ts` (sender-stamped) + `sig` (iroh::Signature, serde-64B);
Debug is hand-written since Signature has none.
- Signature covers domain tag + room topic_id + author + ts + msg
(`signable_bytes`): topic binding blocks cross-room replay, ts + a 2-min
freshness window block temporal replay (within-window replays are byte-
identical and de-duped by the swarm), author binding makes spoofing fail.
- New pure seams `sign_gossip` / `verify_gossip` (+ `GossipReject`); all four
outgoing broadcasts sign, the receive loop verifies-then-trusts (drops
unauthenticated/stale before any peer-map / event / address-book action).
- IrohGossipState now holds the node SecretKey + active topic bytes; callers
(core, test_net) updated.
NOTE: breaking gossip wire change — all peers must run this build (the staged
friend release + dopedart need rebuild). Node identity is ephemeral, so no
migration concern beyond rebuild.
+5 unit tests (genuine accept; forged author, tampered msg, cross-room, stale/
future all rejected). 163 lib tests (was 158), clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Three findings from the first security pass:
- S3 (Medium): the peer-supplied screen-share ticket was passed to pixelpass
as the first positional CLI arg with no end-of-options guard, so a ticket
starting with `-`/`--` could be reinterpreted as a flag (argument injection).
New pure `viewer_args()` puts flags first, then a `--` guard, then the ticket
positionally; spawn_viewer uses it. +2 tests.
- S4 (Medium): peer presence display-names (gossip `Announce`, untrusted and
spoofable) were rendered unsanitized/unbounded, unlike the chat path. New
`sanitize::sanitize_name` strips bidi/zero-width format chars + control chars,
collapses whitespace, and caps at 48 chars; applied at the gossip ingest point
so every consumer gets a safe value. +4 tests.
- S1 (Low): `&id[..8]` byte-slices could panic on a short/non-ASCII id. New
panic-free `short_id()` (char-based take) replaces both slices. +1 test.
158 lib tests (was 151), clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Move the Settings "Back" button out of the scrollable (where it sat as the
last child and scrolled off the bottom of a long page) into a fixed header
bar that stays pinned at the top while content scrolls. The header is a
styled bar with the Back button on the left and a centered "Settings" title;
the old top title and bottom Back button inside the scrollable are removed.
Pure layout change, still dispatches AppMessage::NavigateBack.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The playback worker thread looped `while running { rx.recv() }`. A blocking
recv() never re-checks the `running` flag — it only wakes on a new frame or the
sender being dropped. So when stop() set running=false and called
worker_handle.join(), the worker stayed parked in recv() and join() hung until
the frame Sender happened to be dropped. audio_probe reproduced this every run
(it calls backend.stop() while its tx is still in scope), hanging on exit; the
GUI could hang on shutdown on any teardown path that stops audio before dropping
the sender.
Fix: extract a `drain_loop` seam that uses recv_timeout(WORKER_POLL=100ms) so
the loop re-checks `running` at least every 100ms even when idle, and returns
promptly on Disconnected. stop() now joins within one poll interval regardless
of the sender's lifetime. +3 unit tests (151 lib): exits on running-flip with
the sender still alive (the exact hang case, asserted via is_finished), returns
on disconnect, and delivers frames. Verified: audio_probe now self-exits cleanly
(exit 0, "done.", no lingering process). clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The playback RT callback pinned the PipeWire buffer to exactly one 1024-frame
quantum (the 2026-05-31 crackle fix). That is only correct when the machine's
clock.quantum is 1024 — on hardware running quantum 512 or 2048 the pinned
slice mismatches the device's per-cycle demand and the crackle returns. We just
shipped a release to a friend whose quantum is unknown, so this was P1.
Fix: enable the pipewire `v0_3_49` feature (exposes Buffer::requested(), the
graph's per-cycle quantum) and fill exactly that many frames each callback via a
new pure `frames_to_produce()` seam, with a safe ≤1024 fallback when the graph
reports 0 (never the whole slice — over-pulling past the ring depth is the
original crackle). Relax the Buffers size pin from a hard 1024 to a generous
8192-frame max so the mapped slice fits any plausible quantum; requested(), not
the buffer size, now governs per-cycle output.
Verified locally with `pw-metadata clock.force-quantum` + audio_probe at forced
quanta 512/1024/2048: each shows `underrun +0` steady, `quantum=` matching the
forced value, and callbacks/s ≈ rate/quantum — proving requested() is live (the
health line would otherwise read the 1024 fallback). +4 unit tests on
frames_to_produce (148 lib tests, clippy --all-targets clean).
Still pending (field test): one real desktop<->dopedart call through the fix.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The UI was hardcoded to one Catppuccin Mocha palette (color literals in
view() + theme() pinned to Dark). It now sources colours from a chosen
theme's palette, selectable in Settings.
- theme.rs (NEW): Palette (13 semantic colour roles) + AppTheme enum
(Catppuccin Mocha/Macchiato/Frappe/Latte, Dracula, Nord, Tokyo Night,
Gruvbox Dark, Solarized Light, Gruvbox Light). Pure palette()/label()/
ALL/base_theme()/is_dark() + WCAG relative_luminance()/contrast_ratio().
- config: theme: AppTheme field (serde-default Mocha) + backward-compat.
- app: theme() returns config.theme.base_theme() (iced widget chrome);
view() + with_layout_picker() source colours from the palette; new
ThemeSwatch canvas widget; a Theme section of clickable swatches in
Settings; SelectTheme applies live + persists. Canvas widgets already
take colours as data, so they re-theme for free.
Tests written alongside (+7 theme, +2 config; 135 -> 144 lib): every
palette clears WCAG AA text-on-base contrast (4.5:1) with subtext/accent
>= 3:1, is_dark matches luminance direction, variants distinct/labeled,
serde round-trips, default = Mocha.
Verified live: the Settings swatch grid renders all 10 palettes and the
whole UI re-themes (screenshot-checked Latte light + Dracula dark).
clippy --all-targets clean.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
X11 sessions now persist and restore the window position (window_x/y) in
addition to size. Gated to X11: Wayland's xdg-shell gives clients no way
to self-position, so we center there (and iced never emits Moved on
Wayland, so window_x/y stay None). No drift across save/restore — iced's
Moved event and Position::Specific both use the window's outer position.
Also confirmed peerspeak already runs on X11 out of the box (winit
compiles both backends and auto-selects via WAYLAND_DISPLAY/DISPLAY) and
documented X11/Wayland support in FEATURES.md.
- config: window_x/window_y: Option<i32> (serde-default None).
- app: is_wayland() + pure initial_window_position() helper; a Moved
handler records position; the close path persists it.
- tests: +3 initial_window_position (X11 restore / Wayland centers /
partial-or-missing centers), +2 config (round-trip incl. negative
coords; backward-compat load without the new fields). 130 -> 135 lib.
Verified live on X11/XWayland: saved an off-center position, the window
reopened there (not centered). clippy clean incl. --all-targets.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Building packaging/PKGBUILD in place leaves scratch dirs (src/, pkg/,
peerspeak/ clone), the built *.pkg.tar.* and makepkg *.log behind, and
also rewrites pkgver in PKGBUILD. Ignore the scratch outputs so an
in-tree `makepkg` no longer pollutes git status. (Cleanest is still to
build from a copy outside the repo.)
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a desktop/taskbar identity and a system package for PeerSpeak.
- assets/icons/peerspeak.svg: master app icon — the in-app mic glyph
over a P2P mesh of peer nodes, Catppuccin Mocha palette. Rendered to
the hicolor raster sizes (16..512) committed alongside it.
- Window/taskbar icon: embed a 128x128 straight-RGBA blob and load it
via iced from_rgba (keeps us off iced's heavy `image` feature). Set
the Wayland/X11 app_id to "peerspeak" so compositors match the window
to the .desktop launcher and show the icon natively.
- packaging/peerspeak.desktop: launcher (StartupWMClass=peerspeak).
- packaging/PKGBUILD: peerspeak-git VCS package — cargo --frozen build,
--lib check, installs the binary, .desktop, and hicolor icons.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The window always opened at the hardcoded 900x760 because the size was never
persisted: run_gui hardcoded it, AppConfig had no size fields, and the Resized
handler only kept the size in memory (for divider clamping) while
exit_on_close_request:true quit before anything could save.
- AppConfig gains window_width/window_height (serde-default 900/760).
- run_gui restores them as the initial window size.
- The Resized handler mirrors the live size into config (guarded against bogus
tiny sizes); divider positions on load now clamp against the restored size
rather than a hardcoded default.
- exit_on_close_request:false + a CloseRequested handler writes the final size
once, then iced::exit() — no per-resize disk thrash.
Verified empirically that KWin/Wayland honors a client-requested initial size
(requested 1150x680 -> window reported 1150x680). Window *position* is not
restored: xdg-shell gives Wayland clients no way to set their own position.
+1 config test (default + round-trip).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add an 18-icon set drawn on iced canvas (no image/font dep, recolors with the
theme) — consistent with the existing LayoutThumb/GateMeter/Divider widgets.
Icons: mic, mic-off, headphones, deafen, speaker, speaker-off, monitor (share),
eye (watch), record, stop, chat, people, clock, settings, copy, leave, create,
live. Each authored in a 24x24 space, scaled to the widget, stroked with round
caps/joins.
Wired throughout the UI in place of emoji + added to the icon-less primary
buttons (mute/deafen/leave/copy/settings/create): self + peer cards (live badge,
watch, per-peer speaker mute), header (participants/timer/REC), controls
(mute/deafen/record/share/leave), launch (create/settings), settings (test mic),
drawer chat toggle.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Surface pixelpass screen-sharing from inside a peerspeak room. peerspeak owns
voice, pixelpass owns pixels — they're never Cargo deps of each other; the
contract is pixelpass's CLI flags + its `--output json` stdout stream.
Modelled on Discord: multiple simultaneous sharers, a 🔴 Live badge + 👁 Watch
on each sharing peer's card, and in-progress shares visible to late joiners.
- New `src/screenshare` module: pure `parse_pixelpass_event` seam + `pixelpass_path`
discovery (13 unit tests), async `spawn_host` (→ ticket) and `spawn_viewer`
(→ parse connected{url} → open mpv, vlc fallback). No new deps.
- Sharing rides presence: `PeerState.sharing: Option<ticket>` (serde-defaulted),
so the existing gossip re-announce delivers the offer to late joiners for free
and a PeerUpdated fires on start/stop — no separate gossip message needed.
- core: Start/Stop/ViewShare commands; host + viewer children tracked in the
session, killed on stop/leave (kill_on_drop backstop). Viewer limit left to
pixelpass's bandwidth-measured cap.
- UI: Share/Stop button (graceful "needs pixelpass" disabled state), Live badge
+ Watch on peer cards, Sharing badge on the self card. Verified by screenshot.
- config: optional `pixelpass_path` override (hand-editable).
Tests-green; the 2-machine gossip/remote path is not yet field-verified.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Approach B: peerspeak spawns pixelpass --host --output json, scrapes the
ticket from its JSON stdout, and distributes it over the existing gossip
plane as a ScreenShareOffer; peers get a one-click pixelpass viewer.
Mutually optional, runtime-only coupling -- neither tool is a Cargo
dependency of the other; the contract is pixelpass's CLI + JSON protocol.
Video-only, separate viewer window, PATH binary discovery. Not yet built.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Capability list of what PeerSpeak already does, companion to
ARCHITECTURE.md, so the feature surface doesn't have to be re-derived
from the code each session. Marks each row verified / tests-green /
plumbing, and collects the outstanding 2-machine field-test debt.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add three in-call room layouts — 3-Column (Participants | Chat | Controls),
Bottom Dock (Participants+Controls over a full-width Chat strip), and Drawer
(Participants | Controls with a collapsible Chat panel) — chosen via one
persisted RoomLayout config setting and applied live.
Picker UX: a square layout button (drawn LayoutIcon glyph) in the top bar of the
launch and in-call screens opens a popup gallery (dimmed click-to-dismiss
backdrop + centered panel) of clickable schematic thumbnails; the Settings screen
shows the same thumbnails inline (no button). Thumbnails are drawn with the
canvas widget (new LayoutThumb program — colored panel boxes, blue border on the
selected one), so no image-decoding dependency is added.
Each layout's panel boundaries are draggable (DividerKind gains Controls +
ChatDrawer for the 3-column right divider and the drawer's left edge; new
clamp_controls_width / clamp_chat_drawer_width, persisted + re-clamped on resize).
Participants width is shared across layouts but capped per layout at render time
so a fixed panel can't starve the Fill panel (e.g. a wide Participants width set
in the dock layout won't collapse Chat in 3-column or Controls in the drawer).
The Drawer layout adds a header chat-toggle. +1 clamp test (now 127 tests).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Remember last nickname: a new serde-default AppConfig.username field is
pre-filled into the launch-screen nickname field, and saved when a room is
joined or created (i.e. when the name is actually used), so it carries across
launches.
Sanitize chat: a pure sanitize_chat() drops control characters (ANSI escapes,
NUL, stray CR/LF/TAB), collapses whitespace runs to single spaces, trims, and
caps length (2000 chars). Applied to our outgoing text on submit AND to incoming
peer messages on receive — peer content is untrusted, so the sender's name and
text are both sanitized before display; empty-after-sanitize messages are
dropped. Unit tests for sanitize_chat (control/whitespace/unicode/empty + length
cap) and a config backward-compat assertion for username.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add a reusable Divider canvas widget and place two in the room screen: a
vertical divider between the Participants and Controls panels (drag to resize
the Participants width) and a horizontal divider between the main row and the
Chat dock (drag to resize the dock height). The Participants panel and Chat dock
size from persisted config values; the Controls panel and main row fill the rest.
The widget reports drag motion as a pixel delta along its axis (mirroring the
GateMeter drag handling, so a drag continues past the thin strip). update()
applies the delta and clamps it: clamp_participants_width / clamp_chat_height
keep both sides of each divider above a minimum. Sizes are re-clamped on window
resize (window size tracked from window::Event::Resized) and clamped again on
load (a size saved under a different window could be out of range).
Persistence: participants_width / chat_height are new serde-default AppConfig
fields; the divider publishes PersistConfig on drag release so the final
position is written once (not per pixel). 3 clamp unit tests (incl. a tiny-window
degenerate case) + config backward-compat assertions for the new fields.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add room text chat riding the existing iroh-gossip topic (same layer as the
presence roster). New GossipMessage::Chat { name, text, ts }; the gossip loop
forwards it as RoomEvent::ChatMessage, core relays it to the UI as
UiEvent::ChatMessage, and RoomState::send_chat broadcasts an authored line
(display name from self-state, ms timestamp). CoreCommand::SendChat sends; our
own author is suppressed by the existing self-echo guard, so the UI echoes our
sent line locally instead.
UI: a full-width chat dock along the bottom of the room (the chosen layout) —
bottom-anchored scrollback with per-sender name colouring (green = you), an
input with Enter-to-send + a Send button, history capped at 300 lines. The room
window default grows to 900x760 so the dock doesn't squeeze the controls column.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Opt-in recording of the full call as you experienced it. New dep-free
src/audio/recorder.rs: a canonical mono S16LE WavWriter (header patched on
finalize) plus a Recorder that buffers your transmitted mic in a bounded FIFO
and sums it, sample-aligned, with each incoming-mix frame the playout mixer
produces. The two independently-clocked streams stay aligned via the FIFO
(capped at ~200ms so drift lag can't grow without bound); silent stretches
record the incoming mix alone. Dep-free UTC timestamp -> sortable filename.
Wiring: CoreCommand::SetRecording toggles an Arc<Mutex<Option<Recorder>>> gated
by an is_recording flag (so the capture/mixer hot paths only lock while actually
recording); capture pushes post-gate mic, the mixer writes the pre-deafen mix.
Recording finalizes on stop, room leave, and room switch. UI: a Record/Stop
button in the controls and a red "● REC m:ss" pill in the room header;
core-confirmed Recording{Started,Stopped} events drive the UI flag so a failed
start can't lie. Files land in ~/peerspeak-recordings/.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Ten more cases pinning the SoftLimiter contract (Gemini, senior-audited):
sustained-loud ceiling both polarities, out_gain participation (boost + atten),
instant-attack no-overshoot, release direction/monotonicity + gradualness,
cross-call state continuity (split == continuous), empty input, extreme
i32::MIN/MAX magnitudes, and bit-exact transparency just under the ceiling.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the mixer's per-sample hard clamp with a lossless i32 bus sum fed
through a feed-forward soft limiter (instant attack, ~120ms release). Below
the ceiling it's transparent and sample-exact; loud multi-peer moments are
ridden down to the ceiling instead of shattering into hard-clip distortion.
State carries across frames so a sustained-loud stretch doesn't re-attack
every 20ms frame. The master output gain now applies inside the limiter so a
boost past the ceiling is limited too.
mix_frames now returns the lossless i32 sum (saturation responsibility moved
to the limiter); its tests assert losslessness, and the new limiter module
carries the saturation/transparency/release guarantees.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Add ARCHITECTURE.md Section 4 covering the jitter buffer's adaptive
playout delay: controller state/params, the grow/shrink/silence/overflow/
prime-timeout transitions, and a state diagram; note it in the Section 2
module map. Sections renumbered 4-7 -> 5-8 (no internal cross-refs).
Gemini-authored (junior) via the headless agy loop. Senior review caught +
fixed an inaccuracy: the original called the strategy "AIMD (multiplicative
decrease)" but the shrink is additive (-1, rate-limited by CLEAN_RUN_TO_SHRINK),
not multiplicative; reworded accordingly. Numbers fact-checked against
src/core/jitter.rs.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Two edge tests for the adaptive playout-delay controller:
- grown_target_requires_deeper_reprime: a disruption-grown target actually
gates the next re-prime (3 frames no longer enough once target is 4).
- overflow_resync_resets_clean_run: the MAX_BUFFERED overflow resync path
restarts the clean run.
Gemini-authored (junior), senior-reviewed against the real diff and
independently re-verified (cargo test --lib + clippy clean). Driven via the
headless agy --print --sandbox loop (resumed with --continue past the
orientation-tax timeout).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>