molluskandClaude Opus 5 6ba763774d core/teardown: reap the screen-share children before the AEC unloads
Phase 0b, fixes 1-3 of design v3.4 §7.2 (decision D4). The invariant is that
the echo-cancel module must not unload while a pixelpass host is alive and
fanning out; two paths have to honour it and only one is code we get to run.

The explicit path: `ActiveSession::shutdown` now awaits
`ScreenshareTeardown::shutdown_children`, and the reliable command channel's
close arm tears the session down explicitly instead of letting it drop on the
way out of `run_core_loop`.

The drop/unwind path: the ordering-critical fields move out of `ActiveSession`
into `core::teardown::ScreenshareTeardown`, where `echo_cancel` is the LAST
declared field and therefore the last dropped. Previously it was declared
first (`:682`, ahead of `screenshare_host` at `:685`), so an unwind unloaded
the AEC while the host was still live — and unwind is reachable, the core is
full of `unwrap()` and has no `panic=abort` profile.

Killing is not enough. `kill_on_drop(true)` only signals: it hands the child to
the runtime's orphan queue and returns, which an unwinding runtime may never
drain. `ReapOnDrop` blocks on a bounded 250 ms budget until the child is really
gone, because a bounded stall beats unloading the AEC out from under a live
pixelpass.

Everything is generic over a narrow `ChildProcess` trait and over the guard
type, so ordering is unit-testable without spawning processes or loading
PipeWire modules — the seam idiom already used by `replace_viewer_index`.

Mutation-verified, and the plan's demand that mutations 4 and 5 prove
*different* defenses holds: reversing the field order fails only the
AEC-ordering tests and leaves the reap test green; removing the reap loop fails
only the reap tests and leaves the ordering test green. Removing the explicit
wait fails the explicit-path tests. 631 lib tests, clippy clean, fmt clean.

⚠️ Mutations 1 and 2 of the pinned matrix do not both exist: the best-effort
wake arm is unreachable by construction, twice over. Documented at the site;
adjudication owed in the impl plan.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-26 18:19:07 -04:00
2026-07-19 15:57:05 -04:00
2026-07-19 15:57:05 -04:00
2026-07-19 15:57:05 -04:00
2026-07-19 15:57:05 -04:00

PeerSpeak icon PeerSpeak

Decentralized, peer-to-peer voice chat — full-mesh, NAT-traversing, with no central server. Built in Rust on iroh (QUIC), PipeWire audio, the Opus codec, and an iced GUI.

Create a room, share the join ticket, and talk. Everyone connects directly to everyone else; relays are only used to punch through NATs when a direct path isn't available.


Screenshots

Launch screen In a room
Launch screen In a room
Settings
Settings

Features

Rooms & sessions

  • Create a room → shareable join ticket; join by pasting a ticket.
  • Full-mesh multi-peer rooms with live presence.
  • Recent-rooms list to hop back into a room someone's still in.
  • Remembered nickname and in-call duration timer.

Audio

  • PipeWire capture/playback, selectable input and output devices, per-app gain.
  • Opus codec (48 kHz mono, 20 ms frames) with an adaptive jitter buffer + packet-loss concealment.
  • Noise gate with a draggable threshold on a live mic meter (test your mic off-call too).
  • Mix-bus soft limiter and opt-in echo cancellation (PipeWire WebRTC AEC + noise suppression).

Voice controls

  • Self-mute, deafen, and rebindable push-to-talk.
  • Per-peer volume, local mute, and speaking indicators.

Text chat

  • In-room text chat over the gossip plane, with clickable links and inline image/audio attachments.
  • Drag-selectable, copyable messages; right-click context menu on all text fields.

Shared music listening

  • Build a personal playlist of local audio files with a full transport (play/pause, seek, reorder).
  • Let others tune in: peers stream your current track, timeline-synced and gapless, sitting under voice at their own volume.

Screen share (via pixelpass)

  • Share your screen; peers click 👁 Watch to open the stream in mpv (vlc fallback).
  • Live badges on sharing peers; per-app audio capture.

Recording & notifications

  • Local call recording (mic + incoming mix → WAV in ~/peerspeak-recordings/).
  • Desktop notifications and event chimes with per-event custom sound overrides.

UI & networking

  • Selectable room layouts (3-Column, Bottom Dock, Drawer) with draggable, persisted dividers.
  • 10 built-in themes (Catppuccin, Dracula, Nord, Tokyo Night, Gruvbox, Solarized…), all WCAG-AA checked.
  • Network mode picker (relay-no-discovery default, full n0, or direct-only); retained-address reconnect.
  • Config, window size/position, and all preferences persisted to ~/.config/peerspeak/.

See docs/FEATURES.md for the full inventory and field-test status, and docs/ARCHITECTURE.md for internals.

Roadmap

  • Contacts & invites — friends list with invite-notification one-click join (design in docs/contacts-plan.md).
  • Spatial audio & per-peer EQ.
  • Soundboard — play short clips into the call mix.
  • Room persistence / invite links beyond the raw ticket.
  • Windows support — cross-compiles and launches under Wine today; needs a real WASAPI audio pass (see docs/WINDOWS.md).

Building

PeerSpeak builds with a stable Rust toolchain (edition 2024). Install the system dependencies below, then:

cargo build --release
./target/release/peerspeak

System dependencies

Arch Linux

sudo pacman -S --needed rust pipewire opus pkgconf git

Debian / Ubuntu

sudo apt install build-essential pkg-config clang libclang-dev \
  libpipewire-0.3-dev libopus-dev libasound2-dev libxcb1-dev

Plus a Rust toolchain via rustup. clang/libclang are needed for the PipeWire bindings (bindgen).

At runtime you need a running PipeWire server. Screen sharing additionally requires pixelpass on your PATH, and mpv (or vlc) to watch a peer's share.

Packaging

  • Arch: cd packaging && makepkg -si (uses packaging/PKGBUILD).
  • Debian/Ubuntu: .deb is built with cargo-deb from the [package.metadata.deb] block in Cargo.toml. Build inside a Debian/Ubuntu environment so the binary links that distro's glibc.
  • Windows: see docs/WINDOWS.md.

License

PeerSpeak is licensed under the MIT License, © 2026 mollusk.

Third-party components bundled with PeerSpeak (the Rust dependency tree, the statically bundled Opus codec on some builds, and embedded fonts) are all under permissive licenses; their texts and a full dependency manifest are collected in THIRD_PARTY_LICENSES.

S
Description
No description provided
Readme MIT
15 MiB
2026-07-19 19:57:06 +00:00
Languages
Rust 98.8%
Shell 0.4%
Nix 0.4%
Python 0.2%
Inno Setup 0.2%