Skip to content

feat(local): managed desktop viewer channel — local wire v5 - #47

Merged
rldyourmnd merged 2 commits into
mainfrom
w2-4-managed-desktop
Sep 27, 2026
Merged

rldyourmnd merged 2 commits into
mainfrom
w2-4-managed-desktop

Conversation

@rldyourmnd

Copy link
Copy Markdown
Contributor

Summary

W2.4's viewer-manager API: a managed desktop channel on local IPC v5.

  • rds-core::local v5: Command::Desktop/Reply::DesktopOpened plus the
    DesktopDown/DesktopUp body enums. Frame payloads travel beside
    postcard framing (header message + u32 length + raw bytes ≤ 32 MiB)
    because one postcard message is bound to 64 KiB.
  • rds-desktop relay mode (SessionOpts::relay_encoded): sequence and
    stale-frame checks still run session-side while encoded payloads publish
    to a bounded tap — the manager never links a codec. control_sender/
    send_control forward verbatim controls; viewer-side RelayDecoder
    reapplies keyframe/broken-chain discipline with a 500 ms NeedIdr rate
    limit.
  • rds-client: desktop::serve pumps both directions until Finished/EOF/
    remote-end/error and drops the session (releasing the shared stream
    permit); Client::desktop returns ManagedDesktop with a split socket
    and a cloneable serialized ManagedControl (input/heartbeat/IDR/
    bitrate).
  • rds-cli: rds desktop and session desktop default to the managed
    channel with viewer-side decode and IDR forwarding; --direct keeps
    native in-process sessions.

Test plan

  • rds-core: v5 enum round-trips, payload bound, proptest decode-safety
  • rds-client: framing bounds/truncation/Finished/EOF/concurrent-sender
    unit tests; three real-loopback serve e2e tests
  • rds-desktop: relay-mode transport e2e against the synthetic serving
    harness (both feature lanes)
  • rds-agent: real-agent managed open → clean Rejected(Remote) refusal,
    no stream-permit leak
  • cargo fmt/clippy (both lanes)/workspace tests: all green locally

Generated with Devin

Local IPC moves to version 5: Command::Desktop opens a remote DesktopV2
session on the pinned managed connection in the new relay mode, replies
DesktopOpened, then the socket speaks DesktopDown/DesktopUp — postcard
control messages plus u32-length-prefixed raw encoded payloads bounded
at 32 MiB, deliberately beside the 64 KiB frame bound.

rds-desktop gains SessionOpts::relay_encoded: the session keeps
sequence/stale-frame and transport IDR discipline but publishes
EncodedDelivery (header + encoded Bytes) to a bounded tap instead of
decoding, so the manager never links a codec and stays buildable
headless. control_sender()/send_control() forward viewer controls
verbatim; the viewer-side RelayDecoder reapplies wait-for-keyframe and
broken-chain discipline with the same 500 ms NeedIdr rate limit the
in-session path uses.

rds-client serves the channel: the pump forwards encoded frames,
events and controls until viewer Finished/EOF, remote end or body
error, then drops the session and releases the shared stream permit.
Client::desktop returns ManagedDesktop — split-socket receive plus a
cloneable ManagedControl that serializes postcard writes so concurrent
senders cannot interleave.

rds-cli defaults `rds desktop` and adds `session desktop` to the
managed path with RelayDecoder decode and IDR forwarding; --direct
keeps native in-process sessions.

Tests: wire v5 enum round-trips and proptest decoders; payload bounds,
truncation, Finished/EOF and concurrent-sender unit tests; three
real-loopback serve e2e tests (frames + heartbeat echo + clean finish,
remote drop, caller EOF); a relay-mode transport e2e; and a real-agent
managed open asserting clean refusal without permit leaks.

Refs: remediation-plan W2.4 (viewer manager API)
local-sessions.md documents the v5 managed desktop body channel
(header-then-payload shape, Finished markers, permit accounting,
manager/viewer ownership split and --direct), the capability matrix
gains service:desktop-managed, and the plan/progress ledgers record
the implemented viewer API with installed-binary migration left open.
@rldyourmnd
rldyourmnd merged commit 26ca19b into main Sep 27, 2026
28 of 29 checks passed
@rldyourmnd
rldyourmnd deleted the w2-4-managed-desktop branch September 27, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant