feat(local): managed desktop viewer channel — local wire v5 - #47
Merged
Merged
Conversation
Local IPC moves to version 5: Command::Desktop opens a remote DesktopV2 session on the pinned managed connection in the new relay mode, replies DesktopOpened, then the socket speaks DesktopDown/DesktopUp — postcard control messages plus u32-length-prefixed raw encoded payloads bounded at 32 MiB, deliberately beside the 64 KiB frame bound. rds-desktop gains SessionOpts::relay_encoded: the session keeps sequence/stale-frame and transport IDR discipline but publishes EncodedDelivery (header + encoded Bytes) to a bounded tap instead of decoding, so the manager never links a codec and stays buildable headless. control_sender()/send_control() forward viewer controls verbatim; the viewer-side RelayDecoder reapplies wait-for-keyframe and broken-chain discipline with the same 500 ms NeedIdr rate limit the in-session path uses. rds-client serves the channel: the pump forwards encoded frames, events and controls until viewer Finished/EOF, remote end or body error, then drops the session and releases the shared stream permit. Client::desktop returns ManagedDesktop — split-socket receive plus a cloneable ManagedControl that serializes postcard writes so concurrent senders cannot interleave. rds-cli defaults `rds desktop` and adds `session desktop` to the managed path with RelayDecoder decode and IDR forwarding; --direct keeps native in-process sessions. Tests: wire v5 enum round-trips and proptest decoders; payload bounds, truncation, Finished/EOF and concurrent-sender unit tests; three real-loopback serve e2e tests (frames + heartbeat echo + clean finish, remote drop, caller EOF); a relay-mode transport e2e; and a real-agent managed open asserting clean refusal without permit leaks. Refs: remediation-plan W2.4 (viewer manager API)
local-sessions.md documents the v5 managed desktop body channel (header-then-payload shape, Finished markers, permit accounting, manager/viewer ownership split and --direct), the capability matrix gains service:desktop-managed, and the plan/progress ledgers record the implemented viewer API with installed-binary migration left open.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
W2.4's viewer-manager API: a managed desktop channel on local IPC v5.
rds-core::localv5:Command::Desktop/Reply::DesktopOpenedplus theDesktopDown/DesktopUpbody enums. Frame payloads travel besidepostcard framing (header message + u32 length + raw bytes ≤ 32 MiB)
because one postcard message is bound to 64 KiB.
rds-desktoprelay mode (SessionOpts::relay_encoded): sequence andstale-frame checks still run session-side while encoded payloads publish
to a bounded tap — the manager never links a codec.
control_sender/send_controlforward verbatim controls; viewer-sideRelayDecoderreapplies keyframe/broken-chain discipline with a 500 ms
NeedIdrratelimit.
rds-client:desktop::servepumps both directions until Finished/EOF/remote-end/error and drops the session (releasing the shared stream
permit);
Client::desktopreturnsManagedDesktopwith a split socketand a cloneable serialized
ManagedControl(input/heartbeat/IDR/bitrate).
rds-cli:rds desktopandsession desktopdefault to the managedchannel with viewer-side decode and IDR forwarding;
--directkeepsnative in-process sessions.
Test plan
unit tests; three real-loopback
servee2e testsharness (both feature lanes)
Rejected(Remote)refusal,no stream-permit leak
Generated with Devin