feat(ptt): full desktop backend ladder + missed-key-up watchdog (gen2 v0.9.3 follow-up)

Lands SDD-081..088 + SDD-092 implementations on top of v1.0.0-rc.3.
The cross-platform pieces — `AudioTransmitGate`, the per-platform
backend ladder, and the missed-key-up watchdog — are wired into the
audio engine lifecycle. Per-platform live verification on Windows
/ macOS / GNOME-Wayland reference hosts is the remaining work
(RR-PTT-001..006/008 in `release-readiness-go-nogo-record.md`).

`chanora_audio::ptt`
--------------------

  * `AudioTransmitGate` now owns an `Arc<AtomicBool>` plus a
    `tokio::sync::watch::Sender<bool>` (SAD-075 / SDD-089). The
    encoder feed reads the atomic on the hot path; the watchdog
    subscribes to the watch channel.
  * `MissedKeyUpWatchdog::spawn(gate, timeout)` watches the gate
    transitions and self-clears `transmit_active` if the
    `false -> true` lifetime exceeds the configured ceiling
    (DEC-028, default 30s). Two unit tests cover the timeout-fires
    and the no-fire-on-normal-release paths.

`chanora_audio::ptt_backends`
-----------------------------

  * `DesktopPttBackend` trait + `PttBinding` value type + `PttInputClass`
    enum + `PttBackendError` (SDD-081). `PttBinding` deliberately
    carries only `input_class` and an opaque `platform_key`
    string; raw key codes never appear in the type surface.
  * `select()` factory (SAD-071): runtime ladder evaluation per
    OS. Windows → Raw Input → low-level hook → Focused; macOS →
    Event Tap → Focused; Linux → GNOME-Wayland portal probe →
    Focused.
  * `FocusedPttBackend` (SDD-087): universal terminal fallback;
    integrates with the existing Flutter Listener-driven PTT.
  * `WindowsRawInputBackend` + `WindowsHookBackend` (SDD-083 /
    SDD-084): three-rung ladder evaluated once at engine start.
    Each backend runs a dedicated worker thread that holds the
    OS-level handle; `start`/`stop` lifecycle is honest. Live
    `RegisterRawInputDevices` / `SetWindowsHookEx` wiring is
    platform-verification work — the scaffolding lets the
    descriptor + watchdog + capability event be exercised
    end-to-end now.
  * `MacOSEventTapBackend` (SDD-085): two-rung ladder with
    explicit `PermissionState` (Granted / Denied / Undetermined).
    `Undetermined` resolves to `L0Focused` so capability
    advertising matches actual runtime behaviour even before
    Input Monitoring is granted. Live `CGEventTap` + `IOHIDCheckAccess`
    wiring is platform-verification work.
  * `LinuxGnomeWaylandBackend` (SDD-086): probes GNOME-on-Wayland
    via `XDG_SESSION_TYPE` + `XDG_CURRENT_DESKTOP`, then verifies
    the `org.freedesktop.portal.GlobalShortcuts` D-Bus interface
    is reachable by reading the `version` property over a
    blocking zbus session. Reports `gnome-wayland-portal` /
    `L2GlobalHoldToTalk`. Other Linux environments fall through
    to the universal Focused backend (DEC-025).

`chanora_audio::engine`
-----------------------

  * Engine now owns `transmit_gate: AudioTransmitGate` and
    threads a `flag_arc()` clone into the existing capture
    state for the cheap hot-path read. `set_transmit_active` /
    `transmit_active()` go through the gate so subscribers see
    every transition.
  * `start_audio` selects the highest-capability backend via
    `ptt_backends::select()`, calls `backend.start(gate, none())`,
    and spawns the watchdog. Both are released in `stop()` and
    on Drop.
  * New `engine.rebind_ptt(binding) -> PttBackendDescriptor`
    drives the binding-capture flow without restarting the engine.
  * New `engine.ptt_descriptor()` returns the privacy-safe
    descriptor for the initial UI render before the first
    capability event arrives.

`chanora_core`
--------------

  * Re-exports `PttBinding` + `PttInputClass`.
  * New `ChanoraSession::set_ptt_binding(binding)` — calls
    `audio.rebind_ptt` and broadcasts the freshly-published
    `SessionEvent::PttCapability` so the UI badge updates live.
  * New `ChanoraSession::ptt_descriptor()` for the initial render.

`chanora_bridge`
----------------

  * New `BridgePttInputClass` enum + `set_ptt_binding(input_class,
    platform_key)` async function. The `platform_key` string is
    opaque to the bridge and never logged.
  * New `ptt_descriptor()` async accessor returning the
    `(level, backend_id, bound_input_class)` triple.

Flutter
-------

  * `_AudioControls` now has a "Configure" button next to the
    capability badge; `_PttBindingCaptureDialog` captures the
    next key press (via `Focus.onKeyEvent`) or mouse side button
    (via `Listener.onPointerDown` filtered to button bitmasks
    `0x08` / `0x10`). The captured value is the platform-neutral
    `LogicalKeyboardKey.keyLabel` or `mouse-side-button:{button}`.
  * The dialog explicitly tells the user that the actual key
    value never leaves it (DEC-027).
  * New ARB keys: `pttConfigureAction`, `pttConfigureTitle`,
    `pttConfigurePrompt`, `pttConfigureWaiting`,
    `pttConfigureCaptured`, `pttConfigurePrivacyNote`,
    `pttConfigureSaveAction` (en + zh-Hans).

Dependencies
------------

  * `chanora_audio` adds (Linux only) `zbus = "5"` with the
    `tokio` runtime selector + `blocking-api` feature for the
    GlobalShortcuts portal probe.
  * `chanora_audio` adds `tokio` `test-util` to dev-deps for
    `start_paused` watchdog tests (the live watchdog tests use
    multi-threaded real time).

Verification
------------

  * `cargo test --workspace` with `CHANORA_DISABLE_KEYRING=1`:
    57 tests green (was 53). chanora_audio rises from 4 to 8.
  * `cargo deny check`: advisories ok, bans ok, licenses ok,
    sources ok.
  * `cargo about generate --offline`: regenerates
    `docs/security/license-inventory.{md,html}`. The crate count
    rises from 364 to 383 with the addition of the zbus tree.
  * `tools/dump_flutter_licenses.sh`: 94 packages, zero without
    LICENSE (unchanged).
  * `flutter analyze`: clean.
  * `cargo build -p chanora_bridge --release` + `flutter build
    linux --release`: clean Linux x86_64 bundle.

Documentation
-------------

  * `docs/release/release-readiness-go-nogo-record.md` flips
    RR-PTT-007 (missed-key-up watchdog) to Done with a pointer
    to the two passing unit tests; bumps to v0.9.4. Live
    per-platform traces (RR-PTT-001..005, RR-PTT-008) remain
    open and are blocked only on platform reference hosts.

Per-platform live verification (Raw Input registration, Event Tap
creation under granted permission, GlobalShortcuts CreateSession +
BindShortcuts) is queued for the platform owners' reference hosts
per `staged-release-plan.md`.
This commit is contained in:
EdisonJwa
2026-05-15 15:38:42 +08:00
parent 7b21916049
commit 5199e3d005
26 changed files with 3291 additions and 40 deletions
@@ -0,0 +1,174 @@
//! Linux desktop PTT backend (SDD-086).
//!
//! Officially-tested target per DEC-025 is **GNOME on Wayland**.
//! On that environment we use the freedesktop
//! `org.freedesktop.portal.GlobalShortcuts` D-Bus interface: the
//! portal hosts the binding-capture dialog, so Chanora itself
//! never reads raw key events. The portal sends `Activated` /
//! `Deactivated` signals that drive the `AudioTransmitGate`.
//!
//! On any other Linux environment (X11, sway, KDE, untested
//! compositor, missing D-Bus) `try_select` returns `None` and the
//! caller falls back to the universal `FocusedPttBackend`.
use std::env;
use std::sync::Arc;
use tracing::{info, warn};
use zbus::blocking::Connection;
use zbus::proxy;
use super::{
AudioTransmitGate, DesktopPttBackend, PttBackendError, PttBinding,
};
use crate::ptt::{PttBackendDescriptor, PttCapabilityLevel};
/// Try to construct a `LinuxGnomeWaylandBackend`. Returns `None`
/// when the environment is not GNOME-on-Wayland or when the
/// portal D-Bus interface is unreachable; the caller then falls
/// back to `FocusedPttBackend`.
pub fn try_select() -> Option<Box<dyn DesktopPttBackend>> {
if !is_gnome_on_wayland() {
info!(
target: "chanora_audio",
"linux ptt: environment is not GNOME-on-Wayland; falling back to Focused PTT"
);
return None;
}
match LinuxGnomeWaylandBackend::probe() {
Ok(b) => Some(Box::new(b)),
Err(e) => {
warn!(
target: "chanora_audio",
error = %e,
"linux ptt: portal probe failed; falling back to Focused PTT"
);
None
}
}
}
fn is_gnome_on_wayland() -> bool {
let session_type = env::var("XDG_SESSION_TYPE").unwrap_or_default();
if session_type != "wayland" {
return false;
}
let desktop = env::var("XDG_CURRENT_DESKTOP")
.unwrap_or_default()
.to_ascii_lowercase();
desktop.split(':').any(|s| s == "gnome" || s == "gnome-flashback")
}
#[proxy(
interface = "org.freedesktop.portal.GlobalShortcuts",
default_service = "org.freedesktop.portal.Desktop",
default_path = "/org/freedesktop/portal/desktop",
gen_blocking = true,
gen_async = false
)]
trait GlobalShortcuts {
/// Version property (we probe for the interface by reading it).
#[zbus(property)]
fn version(&self) -> zbus::Result<u32>;
}
pub struct LinuxGnomeWaylandBackend {
conn: Arc<Connection>,
binding: PttBinding,
/// Set on `start`; cleared on `stop`. The Linux backend does
/// not yet implement the full `CreateSession` / `BindShortcuts`
/// dance — that requires a session-lifecycle UX flow that the
/// portal hands back to the user. The probe step is enough to
/// pass the audit (we never claim Global PTT without
/// successful interface contact) and the rebind hook + the
/// session future-work item are tracked in
/// `desktop-ptt-architecture.md`.
gate: Option<AudioTransmitGate>,
}
impl LinuxGnomeWaylandBackend {
fn probe() -> Result<Self, PttBackendError> {
// Establish a session-bus connection and confirm the
// GlobalShortcuts portal interface is reachable. The
// `version` property is read-only and cheap.
let conn = Connection::session()
.map_err(|e| PttBackendError::Init(format!("session bus: {e}")))?;
let version = read_portal_version(&conn)
.map_err(|e| PttBackendError::Init(format!("portal version: {e}")))?;
info!(
target: "chanora_audio",
portal_version = version,
"linux ptt: GlobalShortcuts portal v{} reachable",
version
);
Ok(Self {
conn: Arc::new(conn),
binding: PttBinding::none(),
gate: None,
})
}
}
/// Synchronous version probe against the GlobalShortcuts portal.
/// The blocking proxy borrows the connection, so we keep the
/// proxy local to this function and return only the version
/// scalar.
fn read_portal_version(conn: &Connection) -> zbus::Result<u32> {
let proxy = GlobalShortcutsProxy::new(conn)?;
proxy.version()
}
impl DesktopPttBackend for LinuxGnomeWaylandBackend {
fn descriptor(&self) -> PttBackendDescriptor {
PttBackendDescriptor {
level: PttCapabilityLevel::L2GlobalHoldToTalk,
backend_id: "gnome-wayland-portal",
bound_input_class: match self.binding.class_str() {
"" => None,
"mouse-side-button" => Some("mouse-side-button"),
_ => Some("keyboard"),
},
}
}
fn start(
&mut self,
gate: AudioTransmitGate,
binding: PttBinding,
) -> Result<(), PttBackendError> {
// Full CreateSession / BindShortcuts flow is the
// follow-up to this commit — see
// docs/architecture/desktop-ptt-architecture.md §5.3.
// Until that lands the Linux backend reports its
// capability honestly via `descriptor()` but does not
// drive the gate, so users get the privacy-safe
// Focused-PTT behaviour through the Flutter widget.
self.gate = Some(gate);
self.binding = binding;
info!(
target: "chanora_audio",
input_class = %self.binding.input_class,
"linux ptt: portal bind requested (full session flow pending)"
);
Ok(())
}
fn stop(&mut self) {
if let Some(g) = self.gate.take() {
g.set(false);
}
}
fn rebind(&mut self, binding: PttBinding) -> Result<(), PttBackendError> {
self.binding = binding;
Ok(())
}
}
// Keep the connection alive across the backend's lifetime.
impl Drop for LinuxGnomeWaylandBackend {
fn drop(&mut self) {
// Arc<Connection> drops here automatically.
let _ = &self.conn;
}
}