Merge main into flat2vr-mods

# Conflicts:
#	README.md
#	ui/index.html
#	ui/server.py
This commit is contained in:
saphid committed 2026-09-29 13:07:33 +10:00
commit daf30515b1
295 files changed
+79525 -454

No files matched your search

+53
View File
@@ -0,0 +1,53 @@
"""APK sources: every place Frame Control can find and download APKs.
One module per source kind in this package. Each module exposes the same small
interface so ``search.py`` can query them all and show where every result came
from. Python stdlib only; must run on Python 3.9.
Module interface
----------------
KIND = 'sidequest' # stable id of the source kind
def sources() -> list[dict] # configured sources of this kind (a kind can have
# several, e.g. one per F-Droid-format repo)
def search(source, query, limit=50) -> list[dict] # Entry dicts, best first
def details(source, entry_id) -> dict # Entry with 'versions'
def download(source, entry_id, version_code=None) -> dict
# {'apk': local path, 'obb': [paths], 'sha256': hex or None, 'verified': bool}
# Raise SourceError with a user-readable message on failure.
Source dict
-----------
{'id': 'sidequest', 'kind': KIND, 'name': 'SideQuest', 'url': 'https://...',
'builtin': True, 'enabled': True, 'trust': 'official' | 'community' | 'user'}
Entry dict (missing facts are None, never guessed)
----------
{'source': source id, 'id': source-local id, 'package': 'org.example.app' or None,
'name': str, 'summary': str, 'icon': url or None, 'page': url or None,
'version': '1.2', 'version_code': 12, 'min_sdk': 24, 'abis': ['arm64-v8a'],
'vr': True/False/None, 'size': bytes, 'free': True, 'license': 'GPL-3.0' or None,
'updated': 'YYYY-MM-DD', 'downloadable': bool, # False = open page only
'versions': [ {version, version_code, min_sdk, size, updated}, ... ]} # details() only
Rules
-----
- Only sources that distribute APKs with the developer's consent: free listings,
never paid apps re-hosted, no licence or entitlement workarounds.
- Honour each site's terms and robots rules; if automated download isn't allowed,
return entries with 'downloadable': False and a 'page' link instead.
- Cache indexes under frame_host.cache_dir('apk-sources'); send a clear
User-Agent ('FrameControl/<version>'); keep requests modest.
- Tests use recorded fixtures, never the network.
"""
class SourceError(Exception):
"""User-readable failure from a source (network, format, verification)."""
class SourceLimited(SourceError):
"""The source's host asked us to slow down; retry_after is in seconds."""
def __init__(self, message, retry_after=None):
super().__init__(message)
self.retry_after = retry_after
+34
View File
@@ -0,0 +1,34 @@
"""Opt-in local store fixtures: FRAME_APK_SEARCH_DEMO=1. Never downloads."""
import json
from pathlib import Path
from apk_sources import SourceError
KIND = 'demo'
FIXTURES = Path(__file__).resolve().parents[2] / 'tests' / 'fixtures' / 'apk-search'
def sources():
return [{'id': 'demo-' + key, 'kind': KIND, 'name': name, 'enabled': True,
'builtin': True, 'trust': trust, 'url': 'https://example.invalid'}
for key, name, trust in [('github', 'GitHub', 'official'), ('fdroid', 'F-Droid', 'community'),
('sidequest', 'SideQuest', 'official'), ('itch', 'itch.io', 'community')]]
def search(source, query, limit=50):
if source['id'] == 'demo-itch':
raise SourceError('Source temporarily unavailable')
entries = json.loads((FIXTURES / 'store.json').read_text())
if source['id'] == 'demo-sidequest':
entries = [e for e in entries if e['vr']]
if source['id'] == 'demo-fdroid':
entries = [e for e in entries if not e['vr']]
return [dict(e, verified=source['id'] in ('demo-github', 'demo-fdroid')) for e in entries
if query.lower() in (e['name'] + ' ' + e['summary']).lower()][:limit]
def details(source, entry_id):
return next(e for e in search(source, '') if e['id'] == entry_id)
def download(source, entry_id, version_code=None):
raise SourceError('Preview sources cannot download or install apps')
+196
View File
@@ -0,0 +1,196 @@
"""Bounded artwork cache. Only source-provided URLs get opaque image handles."""
from collections import OrderedDict
import http.client
import ipaddress
import secrets
import socket
import ssl
import threading
import time
from urllib.parse import urljoin, urlsplit
from apk_sources import SourceError
_lock = threading.Lock()
_urls = OrderedDict()
_cache = OrderedDict()
MAX_IMAGE = 8 * 1024 * 1024
MAX_CACHE = 64 * 1024 * 1024
def valid_url(url):
try:
p = urlsplit(url)
return (p.scheme in ('https', 'http') and bool(p.hostname) and not p.username and not p.password
and p.port in (None, 80, 443) and len(url) <= 4096)
except (ValueError, TypeError):
return False
def register(url):
if not isinstance(url, str) or not valid_url(url):
return None
with _lock:
for token, known in _urls.items():
if known == url:
_urls.move_to_end(token)
return '/source-image/' + token
token = secrets.token_urlsafe(24)
_urls[token] = url
while len(_urls) > 4096:
_urls.popitem(last=False)
return '/source-image/' + token
def artwork(entry):
images = entry.get('images') or {}
if not isinstance(images, dict):
images = {}
return {'icon': register(images.get('icon') or entry.get('icon')),
'banner': register(images.get('banner')),
'screenshots': [path for path in (register(u) for u in (images.get('screenshots') or [])[:12]) if path]}
def image_type(data):
if data.startswith(b'\x89PNG\r\n\x1a\n'):
return 'image/png'
if data.startswith(b'\xff\xd8\xff'):
return 'image/jpeg'
if data.startswith((b'GIF87a', b'GIF89a')):
return 'image/gif'
if data[:4] == b'RIFF' and data[8:12] == b'WEBP':
return 'image/webp'
raise SourceError('Artwork is not a supported image')
def fetch(url, redirects=3, deadline=None, limit=MAX_IMAGE):
"""deadline: time.monotonic() value by which the whole fetch, redirects included, must finish."""
data = get(url, {'Accept': 'image/png,image/jpeg,image/webp,image/gif'}, redirects, deadline, limit)
return data, image_type(data)
# Lookups that outlast their deadline keep running; cap them so they can't pile up.
_resolvers = threading.BoundedSemaphore(4)
def _resolve(host, port, timeout):
# getaddrinfo has no timeout of its own; a thread keeps a slow resolver inside the budget.
if not _resolvers.acquire(blocking=False):
raise SourceError('Too many slow artwork name lookups are still running; try again shortly')
found = {}
def run():
try:
found['addresses'] = socket.getaddrinfo(host, port, type=socket.SOCK_STREAM)
except OSError as e:
found['error'] = e
finally:
_resolvers.release()
try:
worker = threading.Thread(target=run, daemon=True)
worker.start()
except BaseException:
_resolvers.release() # the worker never ran, so it can't release its slot
raise
worker.join(timeout)
if 'error' in found:
raise found['error']
if 'addresses' not in found:
raise SourceError('Artwork download took too long')
return found['addresses']
def get(url, headers=None, redirects=3, deadline=None, limit=MAX_IMAGE):
"""GET a public HTTP(S) URL within an overall deadline (default 60 s), redirects included.
A watchdog shuts the socket at the deadline, so a server trickling bytes can't outlast it."""
deadline = time.monotonic() + 60 if deadline is None else deadline
def left():
remaining = deadline - time.monotonic()
if remaining <= 0:
raise SourceError('Artwork download took too long')
return remaining
if not valid_url(url):
raise SourceError('Artwork URL is not allowed')
p = urlsplit(url)
port = p.port or (443 if p.scheme == 'https' else 80)
addresses = _resolve(p.hostname, port, left())
if not addresses or any(not ipaddress.ip_address(a[4][0]).is_global for a in addresses):
raise SourceError('Private network artwork is not allowed')
# Connect to the checked IP, never resolve again between validation and use.
live = [socket.create_connection((addresses[0][4][0], port), timeout=min(10, left()))]
def expire():
try: # the plain socket method: it also ends a TLS handshake in progress
socket.socket.shutdown(live[0], socket.SHUT_RDWR)
except OSError:
pass
watchdog = threading.Timer(left(), expire)
watchdog.daemon = True
watchdog.start()
conn = http.client.HTTPConnection(p.hostname, port, timeout=10)
try:
if p.scheme == 'https':
# Handshake only once the watchdog can reach the TLS socket, within the remaining time.
live[0] = ssl.create_default_context().wrap_socket(live[0], server_hostname=p.hostname,
do_handshake_on_connect=False)
live[0].settimeout(min(10, left()))
live[0].do_handshake()
conn.sock = live[0]
path = p.path or '/'
if p.query:
path += '?' + p.query
conn.request('GET', path, headers={'User-Agent': 'FrameControl/0.3.1', **(headers or {})})
live[0].settimeout(min(10, left()))
response = conn.getresponse()
if response.status in (301, 302, 303, 307, 308) and redirects:
target = urljoin(url, response.getheader('Location', ''))
conn.close()
return get(target, headers, redirects - 1, deadline, limit)
if response.status != 200:
raise SourceError('Artwork is unavailable')
data = b''
while len(data) <= limit:
live[0].settimeout(min(10, left()))
chunk = response.read1(min(16384, limit + 1 - len(data))) # one receive at most
if not chunk:
break
data += chunk
if len(data) > limit:
raise SourceError('Artwork is too large')
left()
return data
except (OSError, http.client.HTTPException) as e:
if time.monotonic() >= deadline:
raise SourceError('Artwork download took too long') from e
raise
finally:
watchdog.cancel()
conn.close()
live[0].close()
def remember(url, data):
value = (data, image_type(data))
if len(data) > MAX_IMAGE:
raise SourceError('Artwork is too large')
with _lock:
_cache[url] = value
_cache.move_to_end(url)
while sum(len(v[0]) for v in _cache.values()) > MAX_CACHE:
_cache.popitem(last=False)
return value
def image(token):
with _lock:
url = _urls.get(token)
if not url:
raise SourceError('Unknown artwork')
cached = _cache.get(url)
if cached:
_cache.move_to_end(url)
return cached
data, _ = fetch(url)
return remember(url, data)
+236
View File
@@ -0,0 +1,236 @@
"""Small HTTPS cache and APK downloader for public publisher sources."""
import hashlib, os, shutil, tempfile, threading, time, urllib.error, urllib.parse, urllib.request, zipfile
from email.utils import parsedate_to_datetime
import frame_host
from . import SourceError, SourceLimited
UA = 'FrameControl/0.1'
APK_CAP = 2 * 1024 ** 3 # cached APKs across all sources, least recently used go first
RECENT = 3600 # an APK used this recently may be about to be installed; never pruned
_use_lock = threading.Lock() # pruning's final check and delete vs touch()/claim()
_in_use = {} # APK path -> installs using it
def touch(path):
"""Mark a cached APK as just used; False if pruning already removed it."""
with _use_lock:
try:
os.utime(str(path))
return True
except FileNotFoundError:
return False
def claim(path):
"""Protect a downloaded APK from pruning until release(path)."""
path = os.path.abspath(str(path))
with _use_lock:
os.utime(path) # raises if it has gone
_in_use[path] = _in_use.get(path, 0) + 1
def release(path):
path = os.path.abspath(str(path))
with _use_lock:
if _in_use.get(path, 0) > 1:
_in_use[path] -= 1
else:
_in_use.pop(path, None)
BACKOFF = 600 # seconds to leave a host alone after 403/429 without Retry-After
_limited = {} # host -> time.time() before which we don't contact it
_limited_lock = threading.Lock()
def _host(url):
return (urllib.parse.urlsplit(url).hostname or '').lower()
def throttle(url, headers=None):
"""Remember that url's host asked us to back off; return the delay in seconds."""
headers = headers or {}
now, delay = time.time(), None
value = (headers.get('Retry-After') or '').strip()
if value.isdigit():
delay = int(value)
elif value:
try:
delay = parsedate_to_datetime(value).timestamp() - now
except (TypeError, ValueError, OverflowError):
pass
reset = headers.get('X-RateLimit-Reset') or ''
if delay is None and headers.get('X-RateLimit-Remaining') == '0' and reset.isdigit():
delay = int(reset) - now # GitHub
delay = min(max(delay if delay is not None else BACKOFF, 1), 6 * 3600)
with _limited_lock:
_limited[_host(url)] = max(_limited.get(_host(url), 0), now + delay)
return delay
def wait_time(url):
with _limited_lock:
return max(0, _limited.get(_host(url), 0) - time.time())
def limited_error(name, seconds, hint=''):
minutes = max(1, int(round(seconds / 60)))
return SourceLimited('%s is limiting requests; try again in %d minute%s%s'
% (name, minutes, '' if minutes == 1 else 's', hint), seconds)
def cache():
path = frame_host.cache_dir('apk-sources', 'publisher')
os.makedirs(path, exist_ok=True)
return str(path)
def prune():
"""Trim the download caches: APKs to APK_CAP by mtime, orphaned .part/temp files, old listings.
Only the long-running app prunes (at start and after store downloads): claim() is
in-process, so the CLIs never prune and so can't delete an APK the app is installing.
"""
now, apks = time.time(), []
for folder in (str(frame_host.cache_dir('apk-sources')), cache()):
try:
names = os.listdir(folder)
except OSError:
continue
for name in names:
path = os.path.join(folder, name)
try:
st = os.lstat(path)
age = now - st.st_mtime
if os.path.isdir(path) and not os.path.islink(path):
if name.startswith('tmp') and age > 86400: # an interrupted F-Droid index download
shutil.rmtree(path, ignore_errors=True)
elif (name.endswith('.part') and age > 86400) or (name.endswith('.data') and age > 7 * 86400):
os.remove(path)
elif name.endswith('.apk'):
apks.append((st.st_mtime, st.st_size, path))
except OSError:
pass
total = sum(size for _, size, _ in apks)
for _, size, path in sorted(apks):
if total <= APK_CAP:
break
with _use_lock: # the scan is old news: check again right before deleting
try:
if os.path.abspath(path) in _in_use or time.time() - os.stat(path).st_mtime < RECENT:
continue
os.remove(path)
total -= size
except OSError:
pass
def checked_url(url, hosts):
try:
p = urllib.parse.urlsplit(url)
port = p.port
except (ValueError, TypeError) as e:
raise SourceError('Source returned an invalid URL') from e
if p.scheme != 'https' or p.username or p.password or port not in (None, 443) or p.hostname not in hosts:
raise SourceError('Source returned an unexpected download URL')
return url
class Redirect(urllib.request.HTTPRedirectHandler):
def __init__(self, hosts):
self.hosts = hosts
def redirect_request(self, req, fp, code, msg, headers, newurl):
checked_url(newurl, self.hosts)
result = super().redirect_request(req, fp, code, msg, headers, newurl)
if result:
result.remove_header('Authorization')
return result
def open_url(url, hosts, headers=None):
checked_url(url, hosts)
return urllib.request.build_opener(Redirect(hosts)).open(
urllib.request.Request(url, headers={'User-Agent': UA, **(headers or {})}), timeout=60)
def read(url, hosts, headers=None, ttl=3600, name=None, hint=''):
path = os.path.join(cache(), hashlib.sha256(url.encode()).hexdigest() + '.data')
name = name or _host(url) or 'The source'
def cached():
if os.path.isfile(path): # throttled: an older copy beats no results
with open(path, 'rb') as f:
return f.read()
try:
if os.path.isfile(path) and time.time() - os.path.getmtime(path) < ttl:
with open(path, 'rb') as f:
return f.read()
wait = wait_time(url)
if wait:
data = cached()
if data is None:
raise limited_error(name, wait, hint)
return data
with open_url(url, hosts, headers) as r:
data = r.read(8 * 1024 * 1024 + 1)
if len(data) > 8 * 1024 * 1024:
raise SourceError('Source index is too large')
fd, tmp = tempfile.mkstemp(dir=cache(), suffix='.part')
try:
with os.fdopen(fd, 'wb') as f:
f.write(data)
os.replace(tmp, path)
finally:
if os.path.exists(tmp):
os.remove(tmp)
return data
except urllib.error.HTTPError as e:
if e.code in (403, 429):
delay = throttle(url, e.headers)
data = cached()
if data is None:
raise limited_error(name, delay, hint) from e
return data
raise SourceError('Source HTTP error: ' + str(e.code)) from e
except (OSError, ValueError) as e:
raise SourceError('Could not read source: ' + str(e)) from e
def apk(url, hosts, digest=None, name=None):
tmp = None
name = name or _host(url)
wait = wait_time(url)
if wait:
raise limited_error(name, wait)
try:
fd, tmp = tempfile.mkstemp(dir=cache(), suffix='.part')
h = hashlib.sha256()
with os.fdopen(fd, 'wb') as f, open_url(url, hosts) as r:
size = 0
while True:
chunk = r.read(1 << 20)
if not chunk:
break
size += len(chunk)
if size > 2 * 1024 ** 3:
raise SourceError('APK exceeds the 2 GiB download limit')
h.update(chunk)
f.write(chunk)
actual = h.hexdigest()
if digest and actual != digest:
raise SourceError('SHA-256 mismatch; download discarded')
with zipfile.ZipFile(tmp) as z:
if 'AndroidManifest.xml' not in z.namelist():
raise SourceError('Download is not an APK')
path = os.path.join(cache(), actual + '.apk')
os.replace(tmp, path)
return {'apk': path, 'obb': [], 'sha256': actual, 'verified': bool(digest)}
except urllib.error.HTTPError as e:
if e.code in (403, 429):
raise limited_error(name, throttle(url, e.headers)) from e
raise SourceError('Could not download APK: HTTP error ' + str(e.code)) from e
except (OSError, ValueError, zipfile.BadZipFile) as e:
raise SourceError('Could not download APK: ' + str(e)) from e
finally:
if tmp and os.path.exists(tmp):
os.remove(tmp)
+720
View File
@@ -0,0 +1,720 @@
"""Signed F-Droid repositories. CLI: add|remove|list|search|download."""
import argparse
import base64
import contextlib
import errno
import hashlib
from html.parser import HTMLParser
import json
import os
from pathlib import Path
import re
import sys
import tempfile
import threading
import time
import urllib.error
import urllib.parse
import urllib.request
import zipfile
if __package__ in (None, ''):
sys.path.insert(0, str(Path(__file__).resolve().parents[1]))
from apk_sources import SourceError, SourceLimited, _web
import frame_host
from frame_apk_sign import _der_parts, _cert_key, der
from frame_catalog import _IndexReader, _reduce_index, _sha256
KIND = 'fdroid'
CACHE_VERSION = 2
_LOCK = threading.RLock() # settings only; never held while downloading
_load_locks = {}
_refreshing = {} # source id -> background refresh thread
_retry_at = {} # source id -> time before which a failed refresh isn't retried
_stale = set() # source ids currently served from an expired index
MAX_AGE = 86400
# Published by the repository operators; a user repository without a pin uses TOFU.
FDROID_PIN = '43238d512c1e5eb2d6569f4a3afbf5523418b82e0a3ed1552770abb9a9c9ccab'
IZZY_PIN = '3bf0d6abfeae2f401707b6d966be743bf0eee49c2561b9ba39073711f628937a'
_DIGESTS = {
'608648016503040201': ('sha256', '3031300d060960864801650304020105000420'),
'608648016503040202': ('sha384', '3041300d060960864801650304020205000430'),
'608648016503040203': ('sha512', '3051300d060960864801650304020305000440'),
'2b0e03021a': ('sha1', '3021300906052b0e03021a05000414'),
}
def _fingerprint(value):
value = re.sub(r'[:\s]', '', value or '').lower()
if not re.fullmatch('[0-9a-f]{64}', value):
raise SourceError('fingerprint must be a SHA-256 certificate fingerprint (64 hex digits)')
return value
def _url(url, fingerprint=None):
if url.startswith('fdroidrepos://'):
url = 'https://' + url[len('fdroidrepos://'):]
p = urllib.parse.urlsplit(url)
if p.scheme != 'https' or not p.hostname or p.username or p.password or p.fragment:
raise SourceError('repository URL must use HTTPS without credentials or a fragment')
params = urllib.parse.parse_qs(p.query)
pins = params.pop('fingerprint', [])
if params or len(pins) > 1:
raise SourceError('only one fingerprint query parameter is supported')
pin = _fingerprint(fingerprint) if fingerprint else None
if pins:
linked = _fingerprint(pins[0])
if pin and pin != linked:
raise SourceError('conflicting fingerprints')
pin = linked
return urllib.parse.urlunsplit(('https', p.netloc.lower(), p.path.rstrip('/') + '/', '', '')), pin
def _child(base, name):
name = str(name).lstrip('/')
decoded = urllib.parse.unquote(name)
if not name or '\\' in decoded or any(x in ('.', '..') for x in decoded.split('/')):
raise SourceError('unsafe repository file name')
if '?' in decoded or urllib.parse.urlsplit(decoded).scheme:
raise SourceError('repository file is outside its repository')
url = urllib.parse.urljoin(base, urllib.parse.quote(decoded, safe='/')) # names may contain '#' or spaces
if not url.startswith(base) or urllib.parse.urlsplit(url).query or urllib.parse.urlsplit(url).fragment:
raise SourceError('repository file is outside its repository')
return url
class _HTTPSRedirect(urllib.request.HTTPRedirectHandler):
def redirect_request(self, req, fp, code, msg, headers, newurl):
if urllib.parse.urlsplit(newurl).scheme != 'https':
raise SourceError('refusing non-HTTPS redirect')
return super().redirect_request(req, fp, code, msg, headers, newurl)
def _fetch(url, path, maximum):
host = urllib.parse.urlsplit(url).hostname
wait = _web.wait_time(url)
if wait:
raise _web.limited_error(host, wait)
request = urllib.request.Request(url, headers={'User-Agent': 'FrameControl/1.0'})
try:
with urllib.request.build_opener(_HTTPSRedirect()).open(request, timeout=60) as r, open(path, 'wb') as f:
total = 0
while True:
chunk = r.read(1 << 20)
if not chunk:
break
total += len(chunk)
if total > maximum:
raise SourceError('repository file exceeds size limit')
f.write(chunk)
except urllib.error.HTTPError as e:
if e.code in (403, 429):
raise _web.limited_error(host, _web.throttle(url, e.headers)) from e
raise
def _limited(source, error):
return _web.limited_error(source['name'], error.retry_after or _web.BACKOFF)
def _children(item):
return _der_parts(item[1])
def _cms(data, content, strong=False):
outer = _der_parts(data)
if len(outer) != 1:
raise ValueError('invalid CMS wrapper')
wrapper = _children(outer[0])
if wrapper[0][1].hex() != '2a864886f70d010702':
raise ValueError('not CMS SignedData')
fields = _children(_children(wrapper[1])[0])
certs = next(_children(f) for f in fields[3:] if f[0] == 0xa0)
signers = _children(fields[-1])
if len(signers) != 1:
raise ValueError('exactly one repository signer required')
signer = _children(signers[0])
sid = _children(signer[1])
matching = []
for cert in certs:
tbs = _children(_children(cert)[0])
offset = 1 if tbs[0][0] == 0xa0 else 0
if tbs[offset][1] == sid[1][1] and tbs[offset + 2][2] == sid[0][2]:
matching.append(cert[2])
if len(matching) != 1:
raise ValueError('missing or ambiguous signer certificate')
cert = matching[0]
digest, prefix = _DIGESTS[_children(signer[2])[0][1].hex()]
if strong and digest == 'sha1':
raise ValueError('SHA-1 signatures are not accepted for v2 indexes')
at, signed = 3, content
if signer[at][0] == 0xa0:
attrs = {}
for attr in _children(signer[at]):
pair = _children(attr)
oid = pair[0][1].hex()
if oid in attrs:
raise ValueError('duplicate CMS attribute')
attrs[oid] = _children(pair[1])
if attrs['2a864886f70d010904'][0][1] != hashlib.new(digest, content).digest():
raise ValueError('CMS content digest mismatch')
if attrs['2a864886f70d010903'][0][1].hex() != '2a864886f70d010701':
raise ValueError('unexpected CMS content type')
signed = der(0x31, signer[at][1])
at += 1
algorithm = _children(signer[at])[0][1].hex()
allowed = {'sha1': '2a864886f70d010105', 'sha256': '2a864886f70d01010b',
'sha384': '2a864886f70d01010c', 'sha512': '2a864886f70d01010d'}
if algorithm not in ('2a864886f70d010101', allowed[digest]):
raise ValueError('unsupported repository signature algorithm (RSA PKCS#1 required)')
n, e, _ = _cert_key(cert)
sig = signer[at + 1][1]
size = (n.bit_length() + 7) // 8
if not 256 <= size <= 1024 or n % 2 != 1 or not 3 <= e <= 0xffffffff or e % 2 != 1 or len(sig) != size or int.from_bytes(sig, 'big') >= n:
raise ValueError('invalid RSA signature/key size')
value = bytes.fromhex(prefix) + hashlib.new(digest, signed).digest()
expected = b'\0\1' + b'\xff' * (size - len(value) - 3) + b'\0' + value
if pow(int.from_bytes(sig, 'big'), e, n).to_bytes(size, 'big') != expected:
raise ValueError('repository RSA signature mismatch')
return hashlib.sha256(cert).hexdigest()
def _sections(data):
sections = []
for block in re.split(b'\r?\n\r?\n', data):
if not block:
continue
attrs = {}
for line in re.sub(b'\r?\n ', b'', block).splitlines():
key, value = line.decode('utf-8').split(': ', 1)
key = key.lower()
if key in attrs:
raise ValueError('duplicate manifest attribute')
attrs[key] = value
sections.append(attrs)
return sections
def _digest_check(attrs, suffix, content, strong=False):
for label, digest in (('sha-512', 'sha512'), ('sha-384', 'sha384'), ('sha-256', 'sha256'), ('sha1', 'sha1'), ('sha-1', 'sha1')):
if label + suffix in attrs and not (strong and digest == 'sha1'):
if base64.b64decode(attrs[label + suffix], validate=True) != hashlib.new(digest, content).digest():
raise ValueError('JAR digest mismatch')
return
raise ValueError('missing supported JAR digest')
def _jar(path, member, pin, strong=False):
"""strong: SHA-2 only (v2 entry.jar); index-v1.jar may still be SHA-1 signed."""
try:
with zipfile.ZipFile(path) as z:
names = z.namelist()
if len(names) > 64 or len(names) != len(set(names)) or any(
i.file_size > (1024 * 1024 if i.filename.upper().startswith('META-INF/') else 256 * 1024 * 1024)
for i in z.infolist()):
raise ValueError('duplicate or oversized JAR member')
blocks = [n for n in names if n.upper().startswith('META-INF/') and n.upper().endswith('.RSA')]
if len(blocks) != 1:
raise ValueError('exactly one RSA JAR signer required')
sf = z.read(blocks[0][:-4] + '.SF')
fingerprint = _cms(z.read(blocks[0]), sf, strong)
if pin and fingerprint != pin:
raise ValueError('repository fingerprint mismatch')
manifest = z.read('META-INF/MANIFEST.MF')
_digest_check(_sections(sf)[0], '-digest-manifest', manifest, strong)
entries = [s for s in _sections(manifest)[1:] if s.get('name') == member]
if len(entries) != 1:
raise ValueError('index is not uniquely signed')
content = z.read(member)
_digest_check(entries[0], '-digest', content, strong)
return content, fingerprint
except (ValueError, KeyError, IndexError, StopIteration, RuntimeError, NotImplementedError, zipfile.BadZipFile) as e:
raise SourceError('invalid signed repository: ' + str(e)) from e
def _storage():
return frame_host.data_dir('apk-repos.json')
def _read():
try:
settings = json.loads(_storage().read_text())
if not isinstance(settings, dict) or not isinstance(settings.get('repos'), list) or not isinstance(settings.get('enabled'), dict):
raise ValueError('invalid settings structure')
return settings
except FileNotFoundError:
return {'repos': [], 'enabled': {}}
except (OSError, ValueError) as e:
raise SourceError('cannot read repository settings: ' + str(e)) from e
def _write(path, value):
path.parent.mkdir(parents=True, exist_ok=True)
fd, tmp = tempfile.mkstemp(dir=str(path.parent), suffix='.part')
try:
with os.fdopen(fd, 'w') as f:
json.dump(value, f, separators=(',', ':'))
os.replace(tmp, path)
finally:
if os.path.exists(tmp):
os.unlink(tmp)
def _state_path():
return frame_host.data_dir('apk-repo-state.json')
def _states():
try:
states = json.loads(_state_path().read_text())
if not isinstance(states, dict):
raise ValueError('invalid state structure')
return states
except FileNotFoundError:
return {}
except (OSError, ValueError) as e:
raise SourceError('cannot read repository state: ' + str(e)) from e
def _state(source):
"""Newest accepted index timestamp and whether a v2 index was ever accepted (rollback protection)."""
with _LOCK:
state = _states().get(source['id'])
return state if isinstance(state, dict) and state.get('url') == source['url'] else {}
@contextlib.contextmanager
def _state_file_lock():
"""Inter-process lock: the CLI and the app must not publish indexes out of order."""
path = frame_host.data_dir('apk-repo-state.lock')
path.parent.mkdir(parents=True, exist_ok=True)
with open(str(path), 'a+b') as f:
if os.name == 'nt':
import msvcrt
while True:
try:
f.seek(0)
msvcrt.locking(f.fileno(), msvcrt.LK_LOCK, 1)
break
except OSError as e: # LK_LOCK gives up after ~10 s of contention; keep waiting
if e.errno not in (errno.EACCES, errno.EDEADLK):
raise
try:
yield
finally:
f.seek(0)
msvcrt.locking(f.fileno(), msvcrt.LK_UNLCK, 1)
else:
import fcntl
fcntl.flock(f.fileno(), fcntl.LOCK_EX)
try:
yield
finally:
fcntl.flock(f.fileno(), fcntl.LOCK_UN)
def _check_timestamp(source, timestamp):
last = _state(source).get('timestamp')
if last is not None and (type(timestamp) is not int or timestamp < last):
raise SourceError('repository index is older than the one already accepted (possible rollback); refused')
def _accept(source, timestamp, v2):
with _LOCK:
states = _states()
state = _state(source)
states[source['id']] = {'url': source['url'], 'v2': bool(v2 or state.get('v2')),
'timestamp': timestamp if type(timestamp) is int else state.get('timestamp')}
_write(_state_path(), states)
def user_repos():
with _LOCK:
return _read()['repos']
def sources():
builtins = [('fdroid', 'F-Droid', 'https://f-droid.org/repo/', FDROID_PIN),
('fdroid-archive', 'F-Droid archive', 'https://f-droid.org/archive/', FDROID_PIN),
('izzyondroid', 'IzzyOnDroid', 'https://apt.izzysoft.de/fdroid/repo/', IZZY_PIN)]
settings = _read()
return [dict(id=i, kind=KIND, name=n, url=u, fingerprint=p, builtin=True,
# The archive only holds superseded versions; it clutters search unless asked for.
enabled=settings['enabled'].get(i, i != 'fdroid-archive'), trust='community')
for i, n, u, p in builtins] + settings['repos']
def _text(value):
if isinstance(value, dict):
return value.get('en-US') or next((v for v in value.values() if v), '')
return value or ''
class _PlainText(HTMLParser):
def __init__(self):
super().__init__(convert_charrefs=True)
self.parts, self.hidden = [], 0
def handle_starttag(self, tag, attrs):
if tag in ('script', 'style'):
self.hidden += 1
elif tag in ('br', 'p', 'div', 'li'):
self.parts.append(' ')
def handle_endtag(self, tag):
if tag in ('script', 'style'):
self.hidden = max(0, self.hidden - 1)
elif tag in ('p', 'div', 'li'):
self.parts.append(' ')
def handle_data(self, data):
if not self.hidden:
self.parts.append(data)
def _summary(value):
parser = _PlainText()
parser.feed(_text(value))
parser.close()
return ' '.join(''.join(parser.parts).split())
def _images(meta, base):
def url(file):
name = file.get('name') if isinstance(file, dict) else file
try:
return _child(base, name) if isinstance(name, str) and name else None
except SourceError:
return None # one odd image name mustn't hide the app
icon = url(_text(meta.get('icon')))
banner = url(_text(meta.get('featureGraphic')))
screenshots = []
groups = meta.get('screenshots') or {}
for device, legacy in (('phone', 'phoneScreenshots'), ('sevenInch', 'sevenInchScreenshots')):
files = _text(groups.get(device)) or _text(meta.get(legacy)) or []
for file in files if isinstance(files, list) else []:
image = url(file)
if image and image not in screenshots:
screenshots.append(image)
if len(screenshots) == 6:
break
if len(screenshots) == 6:
break
return {'icon': icon, 'banner': banner, 'screenshots': screenshots}
def _reduce(path, source):
compatible = _reduce_index(path)
result = {}
with open(path, encoding='utf-8') as f:
reader = _IndexReader(f)
for key in reader.members():
if key != 'packages':
reader.value()
continue
for pkg in reader.members():
item = reader.value()
if pkg not in compatible:
continue
meta = item.get('metadata', {})
files = {v['file'].get('name'): v for v in item.get('versions', {}).values()
if isinstance(v, dict) and isinstance(v.get('file'), dict)}
versions = []
for v in compatible[pkg]:
original = files[v['name']]
versions.append(dict(v, size=original['file'].get('size'), updated=_date(original.get('added'))))
versions.sort(key=lambda v: (v['version_code'], v['abis'] == ['arm64-v8a']), reverse=True)
latest = versions[0]
images = _images(meta, source['url'])
result[pkg] = dict(source=source['id'], id=pkg, package=pkg,
name=_text(meta.get('name')) or pkg, summary=_summary(meta.get('summary')),
icon=images['icon'], images=images, developer=_text(meta.get('authorName')) or None,
page=meta.get('webSite') or source['url'], vr=None, free=True,
license=meta.get('license'), downloadable=bool(latest.get('sha256')),
versions=versions, **{k: latest[k] for k in ('version', 'version_code', 'min_sdk', 'abis', 'size', 'updated')})
return result
def _date(value):
return time.strftime('%Y-%m-%d', time.gmtime(value / 1000)) if isinstance(value, (int, float)) else None
def _v1(content, path):
index = json.loads(content)
apps = {a['packageName']: a for a in index['apps']}
packages = {}
for pkg, builds in index['packages'].items():
app = apps.get(pkg, {})
localized = app.get('localized', {})
meta = {k: _text({locale: fields[k] for locale, fields in localized.items() if fields.get(k)}) or app.get(k)
for k in ('name', 'summary', 'license', 'webSite', 'authorName')}
for field in ('icon', 'featureGraphic', 'phoneScreenshots', 'sevenInchScreenshots'):
images = {}
for locale, fields in localized.items():
value = fields.get(field)
if not value:
continue
prefix = pkg + '/' + locale + '/'
if field.endswith('Screenshots'):
images[locale] = [{'name': prefix + field + '/' + name} for name in value[:6]]
else:
images[locale] = {'name': prefix + value}
meta[field] = images
if not meta['icon'] and app.get('icon'):
meta['icon'] = {'en-US': {'name': 'icons/' + app['icon']}}
versions = {}
for i, v in enumerate(builds):
versions[str(i)] = {'manifest': {'versionName': v.get('versionName'), 'versionCode': v['versionCode'],
'usesSdk': {'minSdkVersion': v.get('minSdkVersion', 1)}, 'nativecode': v.get('nativecode', [])},
'file': {'name': v['apkName'], 'sha256': v.get('hash') if v.get('hashType') == 'sha256' else None,
'size': v.get('size')}, 'added': v.get('added')}
packages[pkg] = {'metadata': meta, 'versions': versions}
path.write_text(json.dumps({'packages': packages}))
return (index.get('repo') or {}).get('timestamp')
def _cached(source, cache):
"""(apps, pin, expired) from a cache matching this source, or None."""
try:
saved = json.loads(cache.read_text())
if (saved.get('version') == CACHE_VERSION and saved.get('fingerprint') == source.get('fingerprint')
and saved.get('url') == source['url']):
return saved['apps'], saved['fingerprint'], time.time() - cache.stat().st_mtime >= MAX_AGE
except (OSError, ValueError, KeyError, AttributeError):
pass
return None
def stale(source):
"""True while results come from an expired index that is being (or failed to be) refreshed."""
return source['id'] in _stale
def _refresh_later(source):
with _LOCK:
if source['id'] in _refreshing or time.time() < _retry_at.get(source['id'], 0):
return
def run():
try:
_load(source, force=True)
except Exception:
with _LOCK:
_retry_at[source['id']] = time.time() + 600
finally:
with _LOCK:
_refreshing.pop(source['id'], None)
_refreshing[source['id']] = thread = threading.Thread(target=run, daemon=True)
thread.start()
def _source_lock(source_id):
with _LOCK:
return _load_locks.setdefault(source_id, threading.Lock())
def _load(source, force=False):
if not re.fullmatch(r'[a-z0-9-]+', source['id']):
raise SourceError('invalid source id')
_url(source['url'], source.get('fingerprint'))
cache = frame_host.cache_dir('apk-sources', source['id'] + '.json')
found = None if force else _cached(source, cache)
if found:
if found[2]: # expired: serve it now, marked stale, and refresh without blocking anyone
_stale.add(source['id'])
_refresh_later(source)
return found[:2]
with _source_lock(source['id']):
found = None if force else _cached(source, cache) # another caller may have just loaded it
if found and not found[2]:
return found[:2]
cache.parent.mkdir(parents=True, exist_ok=True)
try:
with tempfile.TemporaryDirectory(dir=str(cache.parent)) as tmp:
jar, raw = Path(tmp) / 'index.jar', Path(tmp) / 'index.json'
v2 = True
try:
_fetch(source['url'] + 'entry.jar', jar, 8 * 1024 * 1024)
except urllib.error.HTTPError as e:
if e.code not in (404, 410):
raise
if _state(source).get('v2'):
raise SourceError('repository no longer serves its signed v2 index; '
'refusing to fall back to the older v1 index') from e
v2 = False
_fetch(source['url'] + 'index-v1.jar', jar, 256 * 1024 * 1024)
content, pin = _jar(jar, 'index-v1.json', source.get('fingerprint'))
timestamp = _v1(content, raw)
_check_timestamp(source, timestamp)
else:
content, pin = _jar(jar, 'entry.json', source.get('fingerprint'), strong=True)
signed = json.loads(content)
timestamp, entry = signed.get('timestamp'), signed['index']
_check_timestamp(source, timestamp)
_fetch(_child(source['url'], entry['name']), raw, 512 * 1024 * 1024)
if _sha256(raw) != entry['sha256'] or (entry.get('size') is not None and raw.stat().st_size != entry['size']):
raise SourceError('index SHA-256 or size mismatch')
apps = _reduce(raw, source)
with _state_file_lock(): # recheck: another process may have accepted a newer index meanwhile
_check_timestamp(source, timestamp)
if not v2 and _state(source).get('v2'): # a v2 index was accepted while we fetched v1
raise SourceError('repository now has a signed v2 index; refusing the older v1 index')
_write(cache, {'version': CACHE_VERSION, 'url': source['url'], 'fingerprint': pin, 'apps': apps})
_accept(source, timestamp, v2)
_stale.discard(source['id'])
return apps, pin
except SourceLimited as e:
raise _limited(source, e) from e
except SourceError:
raise
except (OSError, ValueError, KeyError, TypeError, IndexError) as e:
raise SourceError('cannot load repository: ' + str(e)) from e
def add_repo(url, fingerprint=None, name=None):
url, pin = _url(url, fingerprint)
with _LOCK:
existing = next((s for s in _read()['repos'] if s['url'] == url), None)
if existing:
if pin and pin != existing['fingerprint']:
raise SourceError('repository already has a different pinned fingerprint; remove it first')
pin = existing['fingerprint']
source = dict(id='fdroid-user-' + hashlib.sha256(url.encode()).hexdigest()[:20], kind=KIND,
name=name or (existing or {}).get('name') or urllib.parse.urlsplit(url).hostname,
url=url, builtin=False, enabled=True, trust='user', fingerprint=pin)
_, source['fingerprint'] = _load(source, force=True) # network work outside the settings lock
source['trust_on_first_use'] = existing.get('trust_on_first_use', False) if existing else pin is None
with _LOCK:
settings = _read()
current = next((s for s in settings['repos'] if s['id'] == source['id']), None)
if current and current['fingerprint'] != source['fingerprint']:
raise SourceError('repository already has a different pinned fingerprint; remove it first')
settings['repos'] = [s for s in settings['repos'] if s['id'] != source['id']] + [source]
_write(_storage(), settings)
return source
def remove_repo(source_id):
with _LOCK:
settings = _read()
if not any(s['id'] == source_id for s in settings['repos']):
raise SourceError('unknown user repository')
settings['repos'] = [s for s in settings['repos'] if s['id'] != source_id]
_write(_storage(), settings)
with _state_file_lock(), _LOCK: # lock order: state file, then _LOCK
states = _states()
if states.pop(source_id, None) is not None: # re-adding is a deliberate new trust decision
_write(_state_path(), states)
def set_enabled(source_id, enabled):
if not isinstance(enabled, bool):
raise SourceError('enabled must be a boolean')
with _LOCK:
settings = _read()
source = next((s for s in sources() if s['id'] == source_id), None)
if not source:
raise SourceError('unknown repository')
if source['builtin']:
settings['enabled'][source_id] = enabled
else:
for s in settings['repos']:
if s['id'] == source_id:
s['enabled'] = enabled
_write(_storage(), settings)
def search(source, query, limit=50):
if not source.get('enabled', True):
return []
apps, _ = _load(source)
words = query.casefold().split()
found = [a for a in apps.values() if all(w in (a['id'] + ' ' + a['name'] + ' ' + a['summary']).casefold() for w in words)]
found.sort(key=lambda a: (a['id'].casefold() != query.casefold(), a['name'].casefold()))
return [{k: v for k, v in a.items() if k != 'versions'} for a in found[:max(0, limit)]]
def details(source, entry_id):
if not source.get('enabled', True):
raise SourceError('repository is disabled')
apps, _ = _load(source)
if entry_id not in apps:
raise SourceError('app has no Lepton-compatible version in this repository')
return apps[entry_id]
def download(source, entry_id, version_code=None):
entry = details(source, entry_id)
version = next((v for v in entry['versions'] if version_code is None or str(v['version_code']) == str(version_code)), None)
if not version or not re.fullmatch('[0-9a-f]{64}', version.get('sha256') or ''):
raise SourceError('version is missing or has no SHA-256 digest')
sha = version['sha256']
path = frame_host.cache_dir('apk-sources', sha + '.apk')
try:
reuse = False
if _web.touch(path): # before hashing: a just-used APK is never pruned
try:
reuse = _sha256(path) == sha
except FileNotFoundError: # removed anyway (e.g. by hand): download again
pass
if not reuse:
path.parent.mkdir(parents=True, exist_ok=True)
fd, tmp = tempfile.mkstemp(dir=str(path.parent), suffix='.part')
os.close(fd)
try:
_fetch(_child(source['url'], version['name']), tmp, 4 * 1024 ** 3)
if _sha256(tmp) != sha:
raise SourceError('APK SHA-256 mismatch; download discarded')
os.replace(tmp, path)
finally:
if os.path.exists(tmp):
os.unlink(tmp)
return {'apk': str(path), 'obb': [], 'sha256': sha, 'verified': True}
except SourceLimited as e:
raise _limited(source, e) from e
except OSError as e:
raise SourceError('cannot download APK: ' + str(e)) from e
def main():
parser = argparse.ArgumentParser(description=__doc__)
sub = parser.add_subparsers(dest='command', required=True)
add = sub.add_parser('add')
add.add_argument('url')
add.add_argument('--fingerprint')
add.add_argument('--name')
sub.add_parser('list')
remove = sub.add_parser('remove')
remove.add_argument('source')
for command in ('search', 'download'):
p = sub.add_parser(command)
p.add_argument('source')
p.add_argument('query' if command == 'search' else 'package')
args = parser.parse_args()
try:
_cli(parser, args)
finally:
for thread in list(_refreshing.values()): # daemon refreshes would die with the CLI, even on errors
thread.join()
def _cli(parser, args):
try:
if args.command == 'add':
result = add_repo(args.url, args.fingerprint, args.name)
elif args.command == 'list':
result = sources()
elif args.command == 'remove':
result = remove_repo(args.source)
else:
source = next((s for s in sources() if s['id'] == args.source), None)
if not source:
raise SourceError('unknown repository id; use list')
result = search(source, args.query) if args.command == 'search' else download(source, args.package)
print(json.dumps(result, indent=2))
except SourceError as e:
parser.exit(1, 'error: ' + str(e) + '\n')
if __name__ == '__main__':
main()
+117
View File
@@ -0,0 +1,117 @@
"""Curated publisher releases; optional topic discovery is page-only."""
import fnmatch, json, os, re, urllib.parse
from . import SourceError, _web
KIND = 'github'
API = 'https://api.github.com'
TOPICS = ('oculus-quest', 'openxr', 'quest')
HOSTS = ('github.com', 'release-assets.githubusercontent.com', 'objects.githubusercontent.com')
def sources():
return [{'id': KIND, 'kind': KIND, 'name': 'GitHub releases', 'url': 'https://github.com',
'builtin': True, 'enabled': True, 'trust': 'community'}]
def _curated():
with open(os.path.join(os.path.dirname(__file__), 'github_curated.json')) as f:
return json.load(f)
def _api(path):
headers = {'Accept': 'application/vnd.github+json', 'X-GitHub-Api-Version': '2022-11-28'}
token = os.environ.get('FRAME_GITHUB_TOKEN')
if token:
headers['Authorization'] = 'Bearer ' + token
try:
return json.loads(_web.read(API + path, ('api.github.com',), headers, name='GitHub',
hint='' if token else ' (set FRAME_GITHUB_TOKEN to raise the limit)'))
except (ValueError, TypeError) as e:
raise SourceError('Invalid GitHub response') from e
def _entry(source, c, approved=True):
artwork = c.get('images') or {}
icon = artwork.get('icon') or c.get('icon') or 'https://github.com/' + c['repo'].split('/')[0] + '.png'
images = {'icon': icon,
# No GitHub social-preview card: it's repo text and stats, not art; the UI draws a fallback.
'banner': artwork.get('banner'),
'screenshots': list(artwork.get('screenshots') or [])}
return {'source': source['id'], 'id': c['repo'], 'package': None,
'name': c['name'], 'summary': c.get('summary') or '', 'icon': icon,
'images': images,
'page': 'https://github.com/' + c['repo'], 'version': None, 'version_code': None,
'min_sdk': None, 'abis': None, 'vr': c.get('vr'), 'size': None,
'free': True if approved else None, 'license': c.get('license'), 'updated': None,
'downloadable': approved}
def search(source, query, limit=50):
limit = max(0, min(int(limit), 100))
if not limit:
return []
if query.startswith('topic:'):
topic = query[6:].strip()
if topic not in TOPICS:
raise SourceError('Choose topic:oculus-quest, topic:openxr or topic:quest')
data = _api('/search/repositories?' + urllib.parse.urlencode(
{'q': 'topic:' + topic + ' archived:false', 'sort': 'stars', 'per_page': limit}))
curated = {c['repo'].lower(): c for c in _curated()}
out = []
for repo in data.get('items', []):
c = curated.get(repo['full_name'].lower())
entry = _entry(source, c or {'repo': repo['full_name'], 'name': repo['name'],
'summary': repo.get('description'), 'vr': True,
'icon': (repo.get('owner') or {}).get('avatar_url')}, bool(c))
out.append(entry)
return out
words = query.lower().split()
return [_entry(source, c) for c in _curated()
if all(w in (c['name'] + ' ' + c['repo'] + ' ' + c['summary']).lower()
for w in words)][:limit]
def details(source, entry_id):
c = next((c for c in _curated() if c['repo'].lower() == entry_id.lower()), None)
if not c:
if not re.fullmatch(r'[A-Za-z0-9_.-]+/[A-Za-z0-9_.-]+', entry_id):
raise SourceError('Invalid GitHub repository')
entry = _entry(source, {'repo': entry_id, 'name': entry_id}, False)
return {**entry, 'versions': []}
entry = _entry(source, c)
releases = _api('/repos/' + c['repo'] + '/releases?per_page=10')
versions = []
for release in releases:
if release.get('draft') or (release.get('prerelease') and not c.get('allow_prerelease')):
continue
assets = [a for a in release.get('assets', []) if
fnmatch.fnmatch(a['name'].lower(), c['asset_pattern'].lower())]
for asset in assets:
digest = asset.get('digest') or ''
versions.append({'version': release['tag_name'], 'version_code': None,
'asset_id': asset['id'], 'name': asset['name'], 'min_sdk': None,
'prerelease': bool(release.get('prerelease')),
'size': asset.get('size'), 'updated': release.get('published_at'),
'url': asset['browser_download_url'],
'sha256': digest[7:] if re.fullmatch(r'sha256:[0-9a-f]{64}', digest) else None})
entry['versions'] = versions
entry['downloadable'] = bool(versions)
if versions:
entry.update({k: versions[0][k] for k in ('version', 'size', 'updated')})
return entry
def download(source, entry_id, version_code=None):
entry = details(source, entry_id)
versions = entry['versions']
if not versions:
raise SourceError('No approved APK release; open the publisher page')
# GitHub asset IDs and tags are not Android version codes.
if version_code is not None:
raise SourceError('GitHub does not publish Android version codes; download the latest release')
v = versions[0]
expected = 'https://github.com/' + entry['id'] + '/releases/download/'
if not v['url'].startswith(expected):
raise SourceError('APK URL does not belong to the curated publisher')
return _web.apk(v['url'], HOSTS, v['sha256'], name='GitHub')
+72
View File
@@ -0,0 +1,72 @@
[
{
"repo": "KhronosGroup/OpenXR-SDK-Source",
"name": "hello_xr",
"summary": "A simple VR scene for checking that OpenXR graphics and controllers work.",
"license": "Apache-2.0",
"vr": true,
"asset_pattern": "hello_xr-Vulkan-*.apk",
"allow_prerelease": false,
"images": {
"icon": "https://raw.githubusercontent.com/KhronosGroup/OpenXR-SDK-Source/3ed64d0f9bb680f24b80a085091e5c8fab38f7b7/src/tests/hello_xr/android_resources/vulkan/mipmap-xxxhdpi/ic_helloxr_launcher.png",
"banner": null,
"screenshots": []
},
"icon": "https://raw.githubusercontent.com/KhronosGroup/OpenXR-SDK-Source/3ed64d0f9bb680f24b80a085091e5c8fab38f7b7/src/tests/hello_xr/android_resources/vulkan/mipmap-xxxhdpi/ic_helloxr_launcher.png"
},
{
"repo": "icosa-foundation/open-brush",
"name": "Open Brush",
"summary": "Paint in the air and create colorful 3D artwork in VR.",
"license": "Apache-2.0",
"vr": true,
"asset_pattern": "*Quest*.apk",
"allow_prerelease": true,
"images": {
"icon": "https://raw.githubusercontent.com/icosa-foundation/open-brush/56acbce831c7e9f257bfee9e21853da99773787b/Assets/Resources/DefaultImages/OpenBrushLogo.png",
"banner": "https://raw.githubusercontent.com/icosa-foundation/open-brush/56acbce831c7e9f257bfee9e21853da99773787b/open-brush.png",
"screenshots": [
"https://shared.akamai.steamstatic.com/store_item_assets/steam/apps/1634870/ss_785ea37d63378146dfe0f0ffa3f1d5c155ca978f.1920x1080.jpg",
"https://shared.akamai.steamstatic.com/store_item_assets/steam/apps/1634870/ss_0a9c208e26a43cf34879c2ca361d4c8f18af8cba.1920x1080.jpg",
"https://shared.akamai.steamstatic.com/store_item_assets/steam/apps/1634870/ss_19b25b86ef55c0d8769a65135d60eaae8fa40553.1920x1080.jpg"
]
},
"icon": "https://raw.githubusercontent.com/icosa-foundation/open-brush/56acbce831c7e9f257bfee9e21853da99773787b/Assets/Resources/DefaultImages/OpenBrushLogo.png"
},
{
"repo": "SgtBilko76/SuperTux-3D",
"name": "SuperTux 3D",
"summary": "Run and jump through Tux\u2019s platform adventure on a layered 3D screen in VR.",
"license": "GPL-3.0",
"vr": true,
"asset_pattern": "*Quest*.apk",
"allow_prerelease": true,
"images": {
"icon": "https://raw.githubusercontent.com/SgtBilko76/SuperTux-3D/1955493ee6f1000e048c58db40d4904df827210e/data/images/engine/icons/supertux-256x256.png",
"banner": "https://www.supertux.org/images/0_7_0/github_preview.png",
"screenshots": [
"https://www.supertux.org/images/0_7_0/github_preview.png"
]
},
"icon": "https://raw.githubusercontent.com/SgtBilko76/SuperTux-3D/1955493ee6f1000e048c58db40d4904df827210e/data/images/engine/icons/supertux-256x256.png"
},
{
"repo": "arpruss/OpenSaberPlus",
"name": "Open Saber Plus",
"summary": "Slash glowing blocks to the beat with two lightsabers, with songs from BeatSaver.",
"license": "MIT",
"vr": true,
"asset_pattern": "OpenSaberPlus.apk",
"allow_prerelease": false,
"images": {
"icon": "https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/icon.png",
"banner": "https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/doc/images/OS0.4.0_1.gif",
"screenshots": [
"https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/doc/images/OS0.4.0_1.gif",
"https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/doc/images/OS0.4.0_2.gif",
"https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/doc/images/OS0.4.0_3.gif"
]
},
"icon": "https://raw.githubusercontent.com/arpruss/OpenSaberPlus/8c5295cdaadf02ea7418b0c6cbea20240ba913af/icon.png"
}
]
+72
View File
@@ -0,0 +1,72 @@
"""Free Android VR RSS listings. Download pages stay in the publisher's UI."""
import html, re, urllib.parse, xml.etree.ElementTree as ET
from email.utils import parsedate_to_datetime
from . import SourceError, _web
KIND = 'itch'
FEEDS = ('openxr', 'oculus-quest')
def sources():
return [{'id': KIND if tag == 'openxr' else 'itch-quest', 'kind': KIND,
'name': 'itch.io (' + tag + ')', 'url': 'https://itch.io', 'tag': tag,
'builtin': True, 'enabled': True, 'trust': 'community'} for tag in FEEDS]
def _parse(source, data):
try:
root = ET.fromstring(data)
except ET.ParseError as e:
raise SourceError('Invalid itch.io RSS feed') from e
entries = []
for item in root.findall('./channel/item'):
page = item.findtext('link') or ''
p = urllib.parse.urlsplit(page)
if p.scheme != 'https' or not (p.hostname or '').endswith('.itch.io') or p.username or ':' in p.netloc:
continue
if item.findtext('price') != '$0.00' or item.findtext('platforms/android') != 'yes':
continue
cover = item.findtext('imageurl') or None
if cover and not cover.startswith('https://img.itch.zone/'):
cover = None
updated = None
try:
updated = parsedate_to_datetime(item.findtext('updateDate')).date().isoformat()
except (ValueError, TypeError, AttributeError):
pass
entries.append({'source': source['id'], 'id': page, 'package': None,
'name': item.findtext('plainTitle') or item.findtext('title') or page,
'summary': html.unescape(re.sub('<[^>]*>', '', item.findtext('description') or '')).strip(),
'icon': cover, 'images': {'icon': cover, 'banner': cover, 'screenshots': []},
'page': page, 'version': None, 'version_code': None, 'min_sdk': None,
'abis': None, 'vr': True, 'size': None, 'free': True, 'license': None,
'updated': updated, 'downloadable': False})
return entries
def search(source, query, limit=50):
limit = max(0, min(int(limit), 100))
if not limit:
return []
entries = {}
tag = source.get('tag', 'openxr')
if tag not in FEEDS:
raise SourceError('Unsupported itch.io feed')
url = 'https://itch.io/games/free/platform-android/tag-' + tag + '.xml'
for entry in _parse(source, _web.read(url, ('itch.io',), name='itch.io')):
entries.setdefault(entry['id'], entry)
words = query.lower().split()
return [e for e in entries.values() if all(w in (e['name'] + ' ' + e['summary']).lower()
for w in words)][:limit]
def details(source, entry_id):
entry = next((e for e in search(source, '', 100) if e['id'] == entry_id), None)
if not entry:
raise SourceError('Game is not in the current free Android VR feed; open its publisher page')
return {**entry, 'versions': []}
def download(source, entry_id, version_code=None):
raise SourceError('Open the itch.io publisher page to download; automated download pages are disallowed by robots rules')
+349
View File
@@ -0,0 +1,349 @@
"""Parallel APK search and source selection. No device access during searches.
Optional store metadata: images {icon, banner, screenshots}, developer,
description, popularity, open_source, requires_meta_services, frame_tested.
Only an explicit frame_tested=True produces a working-on-Frame verdict.
"""
import importlib
import inspect
import json
import os
import pkgutil
import re
import threading
import time
import unicodedata
import frame_host
from apk_sources import SourceError, SourceLimited
_lock = threading.RLock()
_running = {}
_pending = {} # source id -> newest query waiting for the running one
_game_data = {} # package -> downloaded OBB paths waiting for "Add game data"
_status = {}
TIMEOUT = 12
def modules():
import apk_sources
found, errors = [], []
for item in pkgutil.iter_modules(apk_sources.__path__):
if item.name == 'search' or item.name.startswith('_'):
continue
try:
module = importlib.import_module('apk_sources.' + item.name)
if getattr(module, 'KIND', None):
found.append(module)
except Exception as e:
errors.append({'id': item.name, 'name': item.name, 'enabled': False,
'trust': 'unknown', 'status': 'error', 'error': str(e)})
if os.environ.get('FRAME_APK_SEARCH_DEMO') == '1':
found.append(importlib.import_module('apk_sources._demo'))
return found, errors
def settings_path():
return frame_host.data_dir('apk-sources', 'enabled.json')
def overrides():
try:
return json.loads(settings_path().read_text())
except FileNotFoundError:
return {}
def registry():
result = []
mods, errors = modules()
with _lock:
enabled = overrides()
for module in mods:
try:
for source in module.sources():
source = dict(source)
source['enabled'] = enabled.get(source['id'], source.get('enabled', True))
source.update(_status.get(source['id'], {'status': 'not searched'}))
result.append((module, source))
except Exception as e:
errors.append({'id': module.KIND, 'name': module.KIND, 'enabled': False,
'trust': 'unknown', 'status': 'error', 'error': str(e)})
return result, errors
def sources():
items, errors = registry()
return [s for _, s in items] + errors
def resolve(source_id):
for module, source in registry()[0]:
if source['id'] == source_id:
return module, source
raise SourceError('Unknown source')
def set_enabled(source_id, enabled):
module, source = resolve(source_id)
if hasattr(module, 'set_enabled'):
module.set_enabled(source_id, enabled) # never call into a source while holding _lock
with _lock:
values = overrides()
values[source_id] = enabled
path = settings_path()
path.parent.mkdir(parents=True, exist_ok=True)
tmp = path.with_suffix('.tmp')
tmp.write_text(json.dumps(values))
tmp.replace(path)
return {'message': source['name'] + (' enabled' if enabled else ' disabled')}
def repo_module():
module = next((m for m in modules()[0] if m.KIND == 'fdroid'), None)
if module is None or not hasattr(module, 'add_repo'):
raise SourceError('User repositories are not available in this build')
return module
def manage_repo(action, **kwargs):
module = repo_module()
if not hasattr(module, action):
raise SourceError('User repositories are not available in this build')
return getattr(module, action)(**kwargs)
def normalise(name):
return ' '.join(re.findall(r'\w+', unicodedata.normalize('NFKC', name or '').casefold()))
def fit(entry):
sdk, abis = entry.get('min_sdk'), entry.get('abis')
reasons = []
blocked = (sdk is not None and sdk > 30) or (abis is not None and bool(abis) and 'arm64-v8a' not in abis)
if sdk is not None and sdk > 30:
reasons.append('Needs Android API %s; Lepton supports 30' % sdk)
if abis and 'arm64-v8a' not in abis:
reasons.append('No arm64-v8a build')
known = sdk is not None and abis is not None
hints = ' '.join(str(entry.get(k) or '') for k in ('engine', 'vr_engine', 'vr_hints', 'vr_issues')).lower()
if 'vrapi' in hints:
reasons.append('Legacy VrApi requires a translator')
if 'godot' in hints:
reasons.append('Older Godot builds can crash on the missing clipboard service')
if 'openxr' in hints:
reasons.append('OpenXR candidate; required extensions still need checking')
if entry.get('vr'):
reasons.append('VR runtime compatibility is not guaranteed')
return {'installable': False if blocked else True if known else None,
'verdict': "Won't install" if blocked else 'Installable' if known else 'Compatibility unknown',
'reasons': reasons}
def verdict(entry):
compatibility = fit(entry)
hints = ' '.join(str(entry.get(k) or '') for k in ('engine', 'vr_engine', 'vr_hints', 'vr_issues')).lower()
if entry.get('requires_meta_services') is True:
return {'label': "Needs Meta Quest services; won't run", 'tone': 'blocked'}
if entry.get('min_sdk') is not None and entry['min_sdk'] > 30:
return {'label': 'Might not work: needs a newer Android than the Frame has', 'tone': 'blocked'}
if compatibility['installable'] is False:
return {'label': "This version isn't made for the Frame", 'tone': 'blocked'}
if 'vrapi' in hints:
return {'label': "Made for older Quest headsets; won't run on the Frame", 'tone': 'blocked'}
if entry.get('frame_tested') is True:
return {'label': 'Works on the Frame', 'tone': 'works'}
if compatibility['installable'] is True:
return {'label': 'Ready to try on the Frame', 'tone': 'ready'}
return {'label': 'Not yet checked on the Frame', 'tone': 'unknown'}
def decorate(entry):
from apk_sources import _images
return dict(entry, fit=fit(entry), verdict=verdict(entry), artwork=_images.artwork(entry))
def details(source_id, entry_id):
module, source = resolve(source_id)
return decorate(dict(module.details(source, entry_id), source=source_id,
source_name=source['name'], trust=source.get('trust')))
def offer_rank(entry):
compatible = entry['fit']['installable'] is True
return (entry.get('downloadable') is True and entry['fit']['installable'] is not False,
entry.get('verified') is True, compatible,
str(entry.get('updated') or '') if compatible else '',
(entry.get('version_code') or 0) if compatible else 0,
entry.get('trust') == 'official')
def group(entries, query='', vr=None, installable=False):
groups = {}
for entry in entries:
entry = decorate(entry)
if vr is not None and (entry.get('vr') is True) != vr: # unknown counts as flat
continue
if installable and entry['fit']['installable'] is not True:
continue
key = ('package', entry['package']) if entry.get('package') else ('name', normalise(entry.get('name')))
if not key[1]:
key = ('id', entry['source'], entry['id'])
groups.setdefault(key, []).append(entry)
result = []
for offers in groups.values():
offers.sort(key=offer_rank, reverse=True)
best = offers[0]
result.append({'name': best.get('name'), 'package': best.get('package'),
'summary': best.get('summary'), 'offers': offers})
q = normalise(query)
def browse(a): # a headset store: VR first, then apps with artwork, newest first
o = a['offers'][0]
art = o.get('images') or {}
return (o.get('vr') is not True, not art.get('banner'), not art.get('screenshots'),
''.join(chr(0x10ffff - ord(c)) for c in str(o.get('updated') or '')))
if not q:
# Unknown fit stays in the VR-first order; only apps known not to install sink.
result.sort(key=lambda a: (all(o['fit']['installable'] is False for o in a['offers']),) + browse(a))
return result
result.sort(key=lambda a: (not any(normalise(o.get('name')) == q for o in a['offers']),
not any(o['fit']['installable'] is True for o in a['offers']),
not any(normalise(o.get('name')).startswith(q) for o in a['offers']),
a['offers'][0].get('vr') is not True,
normalise(a['name'])))
return result
def _launch(module, source, query, limit):
"""One search per source at a time; the newest different query runs next."""
key = source['id']
task = {'event': threading.Event(), 'query': (query, limit), 'started': time.monotonic(),
'job': (module, source)}
with _lock:
old = _running.get(key)
if old and not old['event'].is_set():
if old['query'] == task['query']:
return old
queued = _pending.get(key)
if queued and queued['query'] == task['query']:
return queued
_pending[key] = task
return task
_running[key] = task
_start(key, task)
return task
def _start(key, task):
module, source = task['job']
query, limit = task['query']
def run():
queued = None
try:
task['entries'] = [dict(e, source=key, source_name=source['name'], trust=source.get('trust'))
for e in module.search(source, query, limit=limit) if e.get('free') is True]
task['stale'] = bool(getattr(module, 'stale', lambda s: False)(source))
except Exception as e:
task['error'] = str(e)
task['limited'] = isinstance(e, SourceLimited)
finally:
with _lock: # completion and queue handover are one step for _launch
queued = _pending.pop(key, None)
if queued:
_running[key] = queued
task['event'].set()
if queued:
_start(key, queued)
threading.Thread(target=run, daemon=True).start()
def search(query='', vr=None, source=None, installable=False, timeout=TIMEOUT, limit=50):
items, errors = registry()
if source and source not in [s['id'] for _, s in items]:
raise SourceError('Unknown source')
chosen = [(m, s) for m, s in items if s['enabled'] and (not source or s['id'] == source)]
# Page-only sources (SideQuest) can't be searched; offer a link to browse them instead.
elsewhere = [{'name': s['name'], 'url': s['url']} for m, s in chosen if s.get('page_only')]
tasks = [(s, _launch(m, s, query, limit)) for m, s in chosen if not s.get('page_only')]
entries, statuses = [], list(errors)
for s, task in tasks:
status = {'id': s['id'], 'name': s['name']}
if not task['event'].wait(max(0, task['started'] + timeout - time.monotonic())):
# Still working (e.g. first download of a large index); it keeps going and fills the cache.
status.update(status='loading')
elif 'error' in task:
status.update(status='limited' if task.get('limited') else 'error', error=task['error'])
else:
status.update(status='ok', stale=task['stale'])
entries.extend(task['entries'])
statuses.append(status)
with _lock:
_status[s['id']] = {k: v for k, v in status.items() if k not in ('id', 'name')}
return {'apps': group(entries, query, vr, installable), 'sources': statuses, 'elsewhere': elsewhere}
def warm():
"""Start every enabled source's index download in the background (server start, new repo)."""
from apk_sources import _web
_web.prune()
items, _ = registry()
for m, s in items:
if s['enabled'] and not s.get('page_only'):
_launch(m, s, '', 50) # same as the first browse, so that search reuses it
def install(source_id, entry_id, version_code=None, progress=None):
import frame_android
module, source = resolve(source_id)
if not source['enabled']:
raise SourceError('This source is disabled')
entry = module.details(source, entry_id)
if entry.get('free') is not True or entry.get('downloadable') is not True:
raise SourceError('This app must be obtained from its developer page')
if progress:
progress('Downloading', None)
downloaded = module.download(source, entry_id, version_code=version_code)
obb = downloaded.get('obb') or entry.get('obb') or []
if obb and not hasattr(frame_android, 'install_obb'):
raise SourceError('This app needs OBB data; this build cannot install it yet')
kwargs = {'name': entry.get('name'), 'icon_png': downloaded.get('icon_png') or entry.get('icon_png'),
'source': source['name']}
if 'artwork' in inspect.signature(frame_android.install).parameters:
# The source's own image URLs (not the UI's /source-image/ proxy paths) become Steam library art.
images = entry.get('images') if isinstance(entry.get('images'), dict) else {}
art = {'icon': images.get('icon') or entry.get('icon'), 'banner': images.get('banner'),
'screenshots': [u for u in images.get('screenshots') or [] if u][:4]}
kwargs['artwork'] = downloaded.get('artwork') or {k: v for k, v in art.items() if v} or None
if progress:
progress('Installing', None)
from apk_sources import _web
try:
_web.claim(downloaded['apk']) # no cache pruning while it installs
except OSError as e:
raise SourceError('The downloaded APK disappeared before installing; try again') from e
try:
_web.prune() # the app is the only pruner (see _web.prune)
result = frame_android.install(downloaded['apk'], **kwargs)
finally:
_web.release(downloaded['apk'])
if obb:
# OBB files go into the app's own instance, which only exists while the app runs.
with _lock:
_game_data[result['package']] = list(obb)
result = dict(result, game_data=True, message='Installed ' + (entry.get('name') or result['package']) +
'. It also needs its game data: open it once on the Frame, then choose Add game data.')
return result
def add_game_data(package):
import frame_android
with _lock:
paths = _game_data.get(package)
if not paths:
raise SourceError('No downloaded game data is waiting for this app; install it again from the store')
result = frame_android.install_obb(package, paths)
with _lock:
_game_data.pop(package, None)
return dict(result, message='Game data added')
+39
View File
@@ -0,0 +1,39 @@
"""SideQuest page links only: its terms do not authorise third-party scraping.
No API calls, cached listings or automated downloads. See docs/sidequest.md.
"""
from . import SourceError
KIND = 'sidequest'
URL = 'https://sidequestvr.com'
REASON = ('SideQuest is page-only: its terms restrict scraping and unauthorised '
'access. Browse and download with SideQuest, then import a developer-provided APK.')
def sources():
return [{'id': KIND, 'kind': KIND, 'name': 'SideQuest', 'url': URL,
'builtin': True, 'enabled': True, 'trust': 'community',
'page_only': True, 'reason': REASON}]
def search(source, query, limit=50):
# Do not invent catalogue results or interpret a query as a verified free app.
return []
def details(source, entry_id):
entry_id = str(entry_id)
if not entry_id.isascii() or not entry_id.isdecimal() or len(entry_id) > 12:
raise SourceError('SideQuest listing ids must be numeric')
return {'source': source['id'], 'id': entry_id, 'package': None,
'name': 'SideQuest listing ' + entry_id, 'summary': REASON,
'icon': None, 'page': URL + '/app/' + entry_id, 'version': None,
'version_code': None, 'min_sdk': None, 'abis': None, 'vr': None,
'size': None, 'free': None, 'license': None, 'updated': None,
'downloadable': False, 'versions': [], 'tags': [], 'headsets': [],
'images': {'icon': None, 'banner': None, 'screenshots': []}}
def download(source, entry_id, version_code=None):
entry = details(source, entry_id)
raise SourceError(REASON + ' ' + entry['page'])
+30
View File
@@ -0,0 +1,30 @@
// Uses index.html's api(), which sends the X-Frame-UI key every /api call needs.
(() => {
const get=id=>document.getElementById(id), status=get('steamGridStatus');
function show(data) {
status.textContent=data.environment?'SteamGridDB key is set by an environment variable.':
data.steamgriddb_configured?'SteamGridDB key saved.':'No key configured. Source images and generated art are enabled.';
}
async function save(value) {
try {show(await api('/api/settings/artwork',{steamgriddb_api_key:value}));get('steamGridKey').value='';}
catch(e) {status.textContent=e.message;}
}
get('saveSteamGridKey').onclick=()=>save(get('steamGridKey').value.trim());
get('clearSteamGridKey').onclick=()=>save('');
get('refreshAndroidArt').onclick=async()=>{
const button=get('refreshAndroidArt');button.disabled=true;
try {
const result=await runJob('Refresh library artwork','library-artwork',()=>api('/api/android',{action:'refresh-art',all:true}));
if (result) {
const items=[...(result.apps||[]),...(result.titles||[])];
const failed=items.filter(a=>a.error);
status.textContent=failed.length?`${failed.length} of ${items.length} failed: ${failed.map(a=>(a.package||a.id)+': '+a.error).join('; ')}`:
`Refreshed artwork for ${items.length} apps and titles.`;
if (typeof loadAndroid==='function') loadAndroid();
if (typeof loadTitles==='function') loadTitles();
}
} catch(e) {status.textContent=e.message;}
finally {button.disabled=false;}
};
api('/api/settings/artwork').then(show).catch(e=>{status.textContent=e.message;});
})();
+92
View File
@@ -0,0 +1,92 @@
<!doctype html>
<html lang="en">
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Frame Control · Assistant</title>
<style>
:root { color-scheme:dark; font:20px/1.5 system-ui,sans-serif; background:#171d25; color:#e4e9ef }
* { box-sizing:border-box } body { max-width:1050px; margin:0 auto; padding:28px }
h1 { font-size:30px; margin:0 } h2 { font-size:24px } p { color:#b8c6d5 }
a { color:#70c9ff } section { background:#202d3c; border:1px solid #425268; border-radius:12px; padding:24px; margin:22px 0 }
label { display:block; margin:14px 0 } input:not([type=checkbox]),textarea { display:block; width:100%; margin-top:6px; padding:12px; background:#101923; color:inherit; border:1px solid #728398; border-radius:6px; font:inherit }
input[type=checkbox] { width:24px; height:24px; vertical-align:middle; margin-right:10px } button { font:inherit; padding:12px 24px; min-height:52px; border:1px solid #728398; border-radius:6px; background:#30445b; color:white; cursor:pointer; margin:6px 12px 6px 0 }
button.primary { background:#176b9c } button:disabled { opacity:.5; cursor:wait } :focus-visible { outline:3px solid #70c9ff; outline-offset:3px }
summary { overflow-wrap:anywhere; cursor:pointer }
pre { white-space:pre-wrap; overflow-wrap:anywhere; font:inherit; max-height:380px; overflow:auto } [hidden] { display:none!important } #status { min-height:1.5em } small { color:#b8c6d5 }
</style>
<header><h1>Frame Control · Assistant</h1><a href="/">Back to Frame Control</a></header>
<section id="approval" hidden aria-labelledby="approval-title">
<h2 id="approval-title">An agent wants to change your Frame</h2>
<p>Review the exact action below. Approve only if you asked for it. Approval expires after five minutes and works once.</p>
<pre id="action"></pre><button id="approve" class="primary">Approve this action</button><button id="reject">Reject</button>
<p id="approval-status" role="status"></p>
</section>
<section aria-labelledby="chat-title">
<h2 id="chat-title">Ask your chosen model</h2>
<p>Nothing is sent until you opt in and press Send. Each request sends only the message below and, if selected, a fresh headset screenshot. Replies cannot operate your Frame.</p>
<form id="chat">
<details id="settings" open><summary id="settings-label">Endpoint and model settings</summary>
<label>Chat-completions endpoint<input id="endpoint" type="url" placeholder="http://127.0.0.1:1234/v1/chat/completions" required autocomplete="off"></label>
<small>Use an OpenAI-compatible endpoint. Loopback means the computer running Frame Control. Remote endpoints require HTTPS.</small>
<label>Model<input id="model" required placeholder="Model name from your endpoint" autocomplete="off"></label>
<label>API key (optional)<input id="key" type="password" autocomplete="off"></label>
<small>Settings, keys and messages stay in this page’s memory. Reload or close to clear them. No analytics, saved chat history or automatic model discovery.</small></details>
<label><input id="consent" type="checkbox">I allow sending this message to the endpoint shown above.</label>
<label><input id="screenshot" type="checkbox">Also send one headset screenshot with this message. It may contain private information.</label>
<label>Message<textarea id="prompt" rows="3" maxlength="32000" required></textarea></label>
<button id="send" class="primary" type="submit">Send message</button><button id="clear" type="button">Clear everything</button>
</form>
<p id="status" role="status" aria-live="polite"></p><pre id="reply" aria-label="Model reply"></pre>
</section>
<script>
'use strict';
const $ = id => document.getElementById(id);
const key = __FRAME_KEY__;
let generation = 0;
async function api(path, body) {
const response = await fetch(path, {method:body === undefined ? 'GET' : 'POST',
headers:{'X-Frame-UI':key,'Content-Type':'application/json'},
body:body === undefined ? undefined : JSON.stringify(body)});
const data = await response.json();
if (!response.ok) throw new Error(data.error || 'Request failed');
return data;
}
function revoke() { $('consent').checked = false; $('screenshot').checked = false; }
$('endpoint').addEventListener('input', revoke);
$('model').addEventListener('input', revoke);
$('clear').onclick = () => { generation++; $('chat').reset(); $('settings').open = true; $('settings-label').textContent = 'Endpoint and model settings'; $('reply').textContent = ''; $('status').textContent = 'Cleared. A request already sent cannot be recalled.'; };
$('chat').onsubmit = async event => {
event.preventDefault();
if (!$('consent').checked) { $('status').textContent = 'Opt in before sending a message.'; return; }
const current = ++generation;
const body = Object.fromEntries(['endpoint','model','key','prompt'].map(id => [id,$(id).value]));
Object.assign(body, {consent:true,screenshot:$('screenshot').checked});
$('settings-label').textContent = body.model + ' at ' + body.endpoint; $('settings').open = false; $('send').disabled = true; $('reply').textContent = ''; $('status').textContent = 'Sending to ' + body.endpoint + '…'; revoke();
try { const data = await api('/api/assistant/chat', body); if (current === generation) { $('reply').textContent = data.reply; $('status').textContent = 'Reply received.'; } }
catch (error) { if (current === generation) $('status').textContent = error.message; }
finally { $('send').disabled = false; }
};
let confirmation, approvalGeneration = 0;
async function loadApproval() {
const current = ++approvalGeneration;
confirmation = new URLSearchParams(location.hash.slice(1)).get('confirm');
$('approval').hidden = !confirmation;
if (!confirmation) return;
$('approve').disabled = $('reject').disabled = true;
try {
const data = await api('/api/agent/approval?confirmation=' + encodeURIComponent(confirmation));
if (current !== approvalGeneration) return;
$('action').textContent = JSON.stringify(data.action, null, 2);
$('approval-status').textContent = data.approved ? 'Already approved. Ask the agent to retry.' : '';
$('approve').disabled = data.approved; $('reject').disabled = false;
} catch (error) { if (current === approvalGeneration) { $('action').textContent = ''; $('approval-status').textContent = error.message; } }
}
for (const [id, accept] of [['approve',true],['reject',false]]) $(id).onclick = async () => {
const current = approvalGeneration;
$('approve').disabled = $('reject').disabled = true;
try { const data = await api('/api/agent/approval', {confirmation,accept}); if (current !== approvalGeneration) return; $('approval-status').textContent = data.message + (accept ? '. Ask the agent to retry now.' : '.'); }
catch (error) { if (current === approvalGeneration) $('approval-status').textContent = error.message; }
};
window.addEventListener('hashchange', loadApproval); loadApproval();
</script>
</html>
+145
View File
@@ -0,0 +1,145 @@
"""Agent actions and one-use human approvals. No model SDK or network calls here."""
import hashlib
import os
from pathlib import Path
import secrets
import shlex
import shutil
import subprocess
import threading
import time
class Approvals:
def __init__(self):
self.pending = {}
self.lock = threading.Lock()
def request(self, action):
with self.lock:
now = time.monotonic()
self.pending = {k: v for k, v in self.pending.items() if v['expires'] > now}
if len(self.pending) >= 100:
raise ValueError('Too many pending approvals; wait five minutes')
token = secrets.token_urlsafe(24)
self.pending[token] = {'action': action, 'approved': False, 'expires': now + 300}
return {'confirmation': token, 'action': action, 'approvalPath': '/assistant#confirm=' + token,
'message': 'Ask the user to review and approve this action in Frame Control, then retry with confirmation. Expires in five minutes.'}
def entry(self, token):
entry = self.pending.get(token)
if not entry or entry['expires'] <= time.monotonic():
raise ValueError('Approval expired or unknown; request a new one')
return entry
def inspect(self, token):
with self.lock:
entry = self.entry(token)
return {'action': entry['action'], 'approved': entry['approved']}
def decide(self, token, accept):
with self.lock:
entry = self.entry(token)
if accept is True:
entry['approved'] = True
else:
del self.pending[token]
return {'message': 'Approved for one use' if accept is True else 'Rejected'}
def consume(self, token, action):
with self.lock:
entry = self.entry(token)
if entry['action'] != action or not entry['approved']:
raise ValueError('This exact action needs approval in Frame Control')
del self.pending[token] # consume before starting, including on failure
approvals = Approvals()
def validate(name, args):
fields = {
'launch': {'appid'}, 'install': {'id'}, 'uninstall': {'id'},
'send_text': {'text'}, 'send_file': {'path'}, 'panel': {'id'},
'power': {'action'}, 'keep_awake': {'action'},
}
if name not in fields or not isinstance(args, dict) or set(args) != fields[name]:
raise ValueError('Unknown action or arguments')
if any(not isinstance(v, str) or not v or len(v) > 65536 for v in args.values()):
raise ValueError('Arguments must be nonempty strings (maximum 65536 characters)')
if name == 'power' and args['action'] not in ('suspend', 'reboot', 'poweroff'):
raise ValueError('Unknown power action')
if name == 'keep_awake' and args['action'] not in ('on', 'off', 'status'):
raise ValueError('Expected on, off or status')
action = {'name': name, 'arguments': dict(args)}
if name == 'send_file':
path = Path(args['path']).expanduser().resolve(strict=True)
if not path.is_file() or path.stat().st_size > 16 * 1024**2:
raise ValueError('Choose a regular file of at most 16 MiB')
# Bind approval to bytes, not just a mutable filename.
with path.open('rb') as stream:
data = stream.read(16 * 1024**2 + 1)
if len(data) > 16 * 1024**2:
raise ValueError('File grew beyond 16 MiB')
action['arguments']['path'] = str(path)
action['sha256'] = hashlib.sha256(data).hexdigest()
action['bytes'] = len(data)
return action
def call(server, body):
name, args = body.get('name'), body.get('arguments', {})
action = validate(name, args)
if name in ('install', 'uninstall', 'panel') and not server.FLATPAK_ID.fullmatch(args['id']):
raise ValueError('Expected a Flatpak application ID')
if name == 'launch' and not server.APPID.fullmatch(args['appid']):
raise ValueError('Expected a Steam app ID')
if name == 'keep_awake' and args['action'] == 'status':
return keep_awake(server, 'status')
token = body.get('confirmation')
if not token:
return approvals.request(action)
approvals.consume(token, action)
if name == 'launch':
return server.launch(args)
if name in ('install', 'uninstall'):
return server.flatpak({**args, 'action': name})
if name == 'send_text':
return server.clipboard(args)
if name == 'send_file':
# Stage the reviewed bytes before the existing transfer helper reads them.
import tempfile
with tempfile.TemporaryDirectory(prefix='frame-agent-') as tmp:
source = Path(action['arguments']['path'])
with source.open('rb') as stream:
data = stream.read(16 * 1024**2 + 1)
if hashlib.sha256(data).hexdigest() != action['sha256']:
raise ValueError('File changed after approval')
staged = Path(tmp) / source.name
staged.write_bytes(data)
return {'message': server.push_file(staged)}
if name == 'power':
if server.LOCAL:
raise ValueError('Use the Frame Control power controls to enter the password; MCP never takes passwords')
return server.open_thing({'what': args['action']})
if name == 'keep_awake':
return keep_awake(server, args['action'])
return run_script(server, 'panel-on-frame.sh', [args['id']])
def run_script(server, name, args):
script = server.HERE.parent / 'scripts' / name
if not script.exists() or not shutil.which('zsh') or server.LOCAL:
raise ValueError(name + ' requires a computer with zsh and the matching script installed')
# The headset the server is routed to, not whatever `frame` means in ~/.ssh/config.
env = {**os.environ, 'FRAME_ALIAS': server.FRAME,
'FRAME_SSH_OPTS': shlex.join(server.SSH[1:])}
result = subprocess.run(['zsh', str(script), *args], capture_output=True, text=True, timeout=60, env=env)
if result.returncode:
raise ValueError(result.stderr.strip() or 'Script failed')
return {'message': result.stdout.strip()}
def keep_awake(server, action):
# PR #16 owns this interface. Never silently change timers or claim a lease.
return run_script(server, 'keep-awake.sh', [action])
+311 -28
View File
@@ -6,12 +6,20 @@ apps, the lepton-show-flatscreen marker; plus a non-Steam shortcut, so it shows
in the Steam library and gets its own SteamVR panel. Nothing goes through
Lepton Development, which wipes its apps on exit. See docs/apks.md.
Python stdlib only. CLI: python3 ui/frame_android.py {info APK|versions APK-or-PKG|install APK|list|launch PKG|stop PKG|remove PKG|probe PKG}
Python stdlib only. CLI: python3 ui/frame_android.py
install APK [--vr|--flat] [--no-xr-compat] | info APK | versions APK-or-PKG
install-obb PKG OBB [OBB ...] | backup-data PKG ARCHIVE | restore-data PKG ARCHIVE
refresh-art PKG|--all | patch SRC DST [--add NAME=PATH ...] | list | launch PKG | stop PKG | remove PKG | probe PKG
"""
import json, os, re, shlex, shutil, subprocess, sys, threading, time, zlib
import base64, json, os, re, shlex, shutil, struct, subprocess, sys, threading, time, zlib
import frame_apk
import frame_artwork
import frame_host
import tempfile
import zipfile
from frame_apk_vr import add_launcher_category
from frame_apk_sign import repack
ROOT = os.path.dirname(os.path.dirname(os.path.abspath(__file__)))
FRAME = os.environ.get('FRAME_ALIAS', 'frame')
@@ -20,6 +28,13 @@ COMPAT = '.local/share/Steam/steamapps/compatdata'
SHADERS = '.local/share/Steam/steamapps/shadercache'
LAUNCHER = os.path.join(ROOT, 'frame', 'android', 'lepton-app.sh')
SHORTCUTS = os.path.join(ROOT, 'frame', 'android', 'steam_shortcuts.py')
# OpenXR API layer that lets OpenXR 1.1 apps run on SteamVR's 1.0-only Android
# runtime (frame/openxr-compat, docs/vr-apks.md). Injected into VR APKs.
XR_COMPAT = os.path.join(ROOT, 'frame', 'openxr-compat')
XR_COMPAT_FILES = {
'assets/openxr/1/api_layers/implicit.d/XrApiLayer_FRAME_compat.json': 'XrApiLayer_FRAME_compat.json',
'lib/arm64-v8a/libXrApiLayer_FRAME_compat.so': 'prebuilt/arm64-v8a/libXrApiLayer_FRAME_compat.so',
}
PKG_RE = re.compile(r'^[A-Za-z][\w]*(\.[A-Za-z_][\w]*)+$')
SSH_OPTS = ['-o', 'BatchMode=yes', '-o', 'ConnectTimeout=8']
@@ -43,8 +58,12 @@ def ssh(cmd, input=None, timeout=120):
def shortcut_tool(*args, timeout=60):
with open(SHORTCUTS) as f:
return ssh('python3 - ' + ' '.join(shlex.quote(a) for a in args), input=f.read(),
timeout=timeout).strip()
script = f.read()
if args and args[0] == 'render':
with open(os.path.join(ROOT, 'frame/android/library_artwork.js')) as f:
script = 'ART_RENDERER = ' + repr(f.read()) + '\n' + script
return ssh('python3 - ' + ' '.join(shlex.quote(a) for a in args), input=script,
timeout=timeout).strip()
def instance_id(pkg):
@@ -65,6 +84,22 @@ def apk_info(path):
raise FrameError(f'{os.path.basename(path)}: {e}')
def xr_compat_files(apk_path):
"""The layer's files to add, or {} if the APK has no OpenXR loader or already has the layer."""
with zipfile.ZipFile(apk_path) as z:
names = set(z.namelist())
if 'lib/arm64-v8a/libopenxr_loader.so' not in names or names & set(XR_COMPAT_FILES):
return {}
add = {}
for entry, rel in XR_COMPAT_FILES.items():
try:
with open(os.path.join(XR_COMPAT, rel), 'rb') as f:
add[entry] = f.read()
except OSError:
raise FrameError("the OpenXR compatibility layer isn't built; run frame/openxr-compat/build.sh")
return add
def check_installable(info):
if info['min_sdk'] and info['min_sdk'] > 30:
raise FrameError(f"{info['label']} needs Android API {info['min_sdk']}; Lepton is Android 11 (API 30)")
@@ -106,49 +141,97 @@ def _write_meta(d, meta):
ssh(f'cat > {d}/meta.json.tmp && mv {d}/meta.json.tmp {d}/meta.json', input=json.dumps(meta, indent=1))
def install(apk_path, flatscreen=True, name=None, source=None, icon_png=None):
info = apk_info(apk_path)
if icon_png:
info['icon_png'] = icon_png
check_installable(info)
pkg = info['package']
if not PKG_RE.match(pkg):
raise FrameError(f'unexpected package name {pkg!r}')
with _install_lock:
return _install(apk_path, info, pkg, flatscreen, name, source)
# Called after every install, worked or not, as fn(info, meta, error, seconds):
# info is None if the APK couldn't be read, meta None and error set if it failed.
install_hooks = []
def _install(apk_path, info, pkg, flatscreen, name, source):
def install(apk_path, flatscreen=None, name=None, source=None, icon_png=None, xr_compat=None, artwork=None):
start, info = time.time(), None
try:
info = apk_info(apk_path)
if icon_png:
info['icon_png'] = icon_png
check_installable(info)
pkg = info['package']
if not PKG_RE.match(pkg):
raise FrameError(f'unexpected package name {pkg!r}')
if flatscreen is None:
flatscreen = not info['vr']
# VR apps get the OpenXR compatibility layer unless told otherwise; it only
# changes calls SteamVR would otherwise reject.
add = xr_compat_files(apk_path) if (info['vr'] if xr_compat is None else xr_compat) else {}
with _install_lock:
if add or info['repairable']:
with tempfile.TemporaryDirectory(prefix='frame-vr-') as tmp:
patched = os.path.join(tmp, 'app.apk')
info['patched'] = patch(apk_path, patched, add)['patched']
info['launchable'] = True
meta = _install(patched, info, pkg, flatscreen, name, source or os.path.basename(apk_path), artwork)
else:
meta = _install(apk_path, info, pkg, flatscreen, name, source, artwork)
except FrameError as e:
_after_install(info, None, e, start)
raise
_after_install(info, meta, None, start)
return meta
def _after_install(info, meta, error, start):
for hook in install_hooks:
try:
hook(info, meta, error, time.time() - start)
except Exception:
pass # reporting must never change an install's outcome
def _install(apk_path, info, pkg, flatscreen, name, source, artwork=None):
try:
images, art_warnings = frame_artwork.prepare(name or info['label'], info.get('icon_png'), artwork)
except (ValueError, OSError) as e:
raise FrameError(f'could not prepare artwork: {e}') from e
iid = instance_id(pkg)
d = f'{APPS_DIR}/{pkg}'
existing = read_meta(pkg)
ok = False
ok, created = False, None
try:
ssh(f'mkdir -p {d}')
_copy(apk_path, f'{d}/app.apk.part')
_copy(LAUNCHER, f'{d}/launch.sh', executable=True, timeout=120)
icon = ''
if info['icon_png']:
ssh(f'cat > {d}/icon.png', input=info['icon_png'])
icon = f'$HOME/{d}/icon.png'
marker = f'touch {d}/lepton-show-flatscreen' if flatscreen else f'rm -f {d}/lepton-show-flatscreen'
ssh(f'mv {d}/app.apk.part {d}/app.apk && echo {iid} > {d}/instance.id && {marker}')
home = ssh('echo $HOME').strip()
shortcut = _int((existing or {}).get('shortcut'))
if not shortcut or shortcut not in _shortcut_ids():
reply = shortcut_tool('add', name or info['label'], f'{home}/{d}/launch.sh', f'{home}/{d}',
icon.replace('$HOME', home))
'')
shortcut = _int(reply.strip().splitlines()[-1] if reply.strip() else None)
if not shortcut:
raise FrameError(f'Steam did not return a shortcut id (got {reply[:80]!r})')
created = shortcut
presentation = apply_library(shortcut, name or info['label'], d, images,
vr=not flatscreen, home=home,
exe=f'{home}/{d}/launch.sh', start_dir=f'{home}/{d}',
details={'package': pkg, 'version': info['version'],
'source': source or os.path.basename(apk_path)})
presentation['warnings'] = art_warnings + presentation.get('warnings', [])
meta = {'package': pkg, 'label': name or info['label'], 'version': info['version'],
'instance': iid, 'shortcut': shortcut, 'game_id': game_id(shortcut),
'vr': info.get('vr', False), 'vr_issues': info.get('vr_issues', []),
'launchable': info.get('launchable', False), 'patched': info.get('patched', []),
'flatscreen': flatscreen, 'installed': time.strftime('%Y-%m-%dT%H:%M:%S'),
'source': source or os.path.basename(apk_path)}
'source': source or os.path.basename(apk_path),
'library_warnings': presentation.get('warnings', []),
'artwork': presentation.get('artwork', {}), 'library_version': 2}
_write_meta(d, meta)
ok = True
return meta
finally:
if not ok and created:
try:
shortcut_tool('remove', str(created))
except FrameError:
pass
if not ok and not existing:
# A first install that failed part-way: don't leave an orphan folder behind.
try:
@@ -157,6 +240,121 @@ def _install(apk_path, info, pkg, flatscreen, name, source):
pass
def apply_library(shortcut, label, directory, images, vr=None, home=None, exe='', start_dir='', details=None,
category='Android', fill_only=False):
"""Mandatory for every sideload: render all five slots before reporting success.
vr None leaves Steam's VR flag as it is (devkit titles declare their own). fill_only (automatic
backfill) sets only slots Steam has no art for, and never the name, exe or flags."""
home = home or ssh('echo $HOME').strip()
d = directory
ssh(f'mkdir -p {shlex.quote(d)}/artwork')
paths = {}
for slot, (ext, data) in images.items():
path = f'{d}/artwork/source-{slot}.{ext}'
ssh(f'cat > {shlex.quote(path)}', input=data)
paths[slot] = f'{home}/{path}' if not path.startswith('/') else path
manifest = {'label': label, 'images': paths}
plan = f'{d}/artwork/input.json'
ssh(f'cat > {shlex.quote(plan)}', input=json.dumps(manifest))
absolute = f'{home}/{plan}' if not plan.startswith('/') else plan
# The Frame retries once with generated art, each attempt allowed 75 s.
rendered = json.loads(shortcut_tool('render', absolute, timeout=200))
art = rendered['paths']
if set(art) != set(frame_artwork.SLOTS):
raise FrameError('Steam artwork renderer did not produce every slot')
result = json.loads(shortcut_tool('configure', str(shortcut), label, exe, start_dir, art['icon'],
'' if vr is None else '1' if vr else '0', json.dumps(art),
json.dumps({'category': category, 'details': details or {},
'fill_only': fill_only}), timeout=120))
result['warnings'] = rendered.get('warnings', []) + result.get('warnings', [])
result['artwork'] = art
if category == 'Android':
ssh(f'cat > {shlex.quote(d)}/shortcut.id', input=str(int(shortcut)))
return result
def cached_art_script(d):
"""Frame-side Python that loads the source images kept beside d's last render into `cached`."""
return f"""import base64, json, os
cached = {{}}
directory = os.path.realpath({d!r})
try:
with open(os.path.join(directory, 'artwork/input.json')) as f:
plan = json.load(f)
for slot, path in plan.get('images', {{}}).items():
if os.path.commonpath([os.path.realpath(path), directory]) != directory:
continue
with open(path, 'rb') as f:
data = f.read(12 * 1024 * 1024 + 1)
if len(data) <= 12 * 1024 * 1024:
cached[slot] = base64.b64encode(data).decode()
except (OSError, ValueError, TypeError, AttributeError):
pass
"""
def art_missing(m):
"""True when a Frame Control install has no complete Steam artwork on record."""
return set((m or {}).get('artwork') or {}) != set(frame_artwork.SLOTS)
def refresh_art(pkg=None, artwork=None, fill_only=False):
"""Refresh existing APK library entries without reinstalling or stopping them.
fill_only: the automatic backfill; it only fills empty Steam slots (see apply_library)."""
if pkg is None:
results = []
for app in list_apps():
try:
results.append(refresh_art(app['package'], artwork, fill_only))
except Exception as e: # one app's failure must not stop the others
results.append({'package': app['package'], 'label': app.get('label'), 'error': str(e) or type(e).__name__})
return results
with _install_lock: # shared with install and remove: a removed app is never recreated
m = _meta_or_fail(pkg)
d = f'{APPS_DIR}/{pkg}'
# Parse the APK on the Frame, transferring only its icon/label, not the APK.
modules = {}
for module in ('frame_apk', 'frame_apk_vr'):
with open(os.path.join(ROOT, 'ui', module + '.py')) as f:
modules[module] = f.read()
script = 'import sys, types, json, base64\n'
for module, source in modules.items():
script += f'm = types.ModuleType({module!r}); sys.modules[{module!r}] = m; exec({source!r}, m.__dict__)\n'
script += f"info = sys.modules['frame_apk'].apk_info({(d + '/app.apk')!r})\n"
script += "info['icon_png'] = base64.b64encode(info.get('icon_png') or b'').decode()\n"
script += cached_art_script(d) + "info['artwork'] = cached\nprint(json.dumps(info))\n"
info = json.loads(ssh('python3 -', input=script))
icon = base64.b64decode(info['icon_png'])
cached = {k: base64.b64decode(v) for k, v in info.get('artwork', {}).items()}
images, warnings = frame_artwork.prepare(m['label'], icon, artwork if artwork is not None else cached)
home = ssh('echo $HOME').strip()
created = False
if not m['shortcut'] or m['shortcut'] not in _shortcut_ids():
m['shortcut'] = _int(shortcut_tool('add', m['label'], f'{home}/{d}/launch.sh', f'{home}/{d}'))
if not m['shortcut']:
raise FrameError('Steam did not create the missing shortcut')
m['game_id'] = game_id(m['shortcut'])
created = True
try:
result = apply_library(m['shortcut'], m['label'], d, images, vr=not m.get('flatscreen', True),
home=home, exe=f'{home}/{d}/launch.sh', start_dir=f'{home}/{d}', details=m,
fill_only=fill_only and not created)
except Exception:
if created:
try:
shortcut_tool('remove', str(m['shortcut']))
except FrameError:
pass # keep the render error, not the cleanup's
raise
m.update(artwork=result.get('artwork', {}), library_version=2, art_pending=False)
m['library_warnings'] = warnings + result.get('warnings', [])
m['artwork_refreshed'] = time.strftime('%Y-%m-%dT%H:%M:%S')
_write_meta(d, m)
return m
def _int(v):
try:
n = int(v)
@@ -205,6 +403,7 @@ def list_apps():
continue
if m:
m['running'] = f"lepton-steamlaunch-{m['instance']}" in running
m['art_missing'] = art_missing(m)
apps.append(m)
return sorted(apps, key=lambda m: m['label'].lower())
@@ -228,18 +427,30 @@ def launch(pkg):
def stop(pkg):
m = _meta_or_fail(pkg)
if m['shortcut']:
try:
shortcut_tool('stop', str(int(m['shortcut'])))
except FrameError:
pass # Steam unavailable: the container stop also ends its waiting launcher.
ssh(f"podman stop -t 5 lepton-steamlaunch-{int(m['instance'])} >/dev/null 2>&1 || true", timeout=60)
return m
def remove(pkg, keep_data=False):
with _install_lock: # never while an install or artwork refresh of any app is writing
return _remove(pkg, keep_data)
def _remove(pkg, keep_data):
m = _meta_or_fail(pkg)
stop(pkg)
if m['shortcut']:
# Best effort: Steam may not be running, and the files must still go.
try:
shortcut_tool('remove', str(int(m['shortcut'])))
except FrameError:
pass # already gone from Steam
result = json.loads(shortcut_tool('remove', str(int(m['shortcut']))) or '{}')
m['library_warnings'] = result.get('warnings', [])
except (FrameError, ValueError, AttributeError) as e:
m['library_warnings'] = [f'Steam shortcut not removed: {e}']
iid = int(m['instance'])
extra = '' if keep_data else f' {COMPAT}/{iid} {SHADERS}/{iid}'
ssh(f'rm -rf {APPS_DIR}/{pkg}{extra}')
@@ -273,28 +484,100 @@ def probe(pkg, wait=20):
'container_up': ctr in running_instances()}
def patch(src, dst, add=None):
try:
info = apk_info(src)
with zipfile.ZipFile(src) as z:
original = frame_apk._read(z, 'AndroidManifest.xml', frame_apk.MAX_MANIFEST)
manifest = add_launcher_category(original) if info['repairable'] else original
if not info['launchable'] and not info['repairable']:
raise FrameError('APK has no MAIN/LAUNCHER activity that Frame Control can patch')
repack(src, dst, replace={'AndroidManifest.xml': manifest}, add=add)
result = apk_info(dst)
result.pop('icon_png', None)
result['patched'] = (['launcher'] if manifest != original else []) + \
(['openxr-compat'] if add and set(XR_COMPAT_FILES) <= set(add) else [])
return result
except (OSError, ValueError, IndexError, struct.error, zipfile.BadZipFile, frame_apk.ApkError) as e:
raise FrameError(str(e)) from e
def install_obb(pkg, paths):
import frame_android_data
return frame_android_data.install_obb(pkg, paths)
def backup_data(pkg, destination):
import frame_android_data
return frame_android_data.backup_data(pkg, destination)
def restore_data(pkg, archive):
import frame_android_data
return frame_android_data.restore_data(pkg, archive)
def main():
cmd, *args = sys.argv[1:] or ['help']
try:
if cmd in ('info', 'versions'):
import frame_apk_versions
if cmd == 'info':
print(frame_apk_versions.describe(apk_info(args[0])))
info = apk_info(args[0])
print(frame_apk_versions.describe(info))
fix = '; Frame Control adds the LAUNCHER entry Lepton needs' if info.get('repairable') else ''
if info.get('vr') or fix:
print(('VR app' if info.get('vr') else 'Android app') + fix)
for note in info.get('vr_issues', []):
print(note)
return
info = apk_info(args[0]) if os.path.isfile(args[0]) or args[0].lower().endswith('.apk') else None
r = frame_apk_versions.alternatives(
info['package'] if info else args[0], info.get('version_code') if info else None)
elif cmd == 'install':
r = install(args[0], flatscreen='--vr' not in args)
r = install(args[0], flatscreen=False if '--vr' in args else True if '--flat' in args else None,
xr_compat=False if '--no-xr-compat' in args else None)
elif cmd == 'refresh-art':
if len(args) != 1:
raise FrameError('usage: refresh-art PACKAGE or refresh-art --all')
r = refresh_art(None if args[0] == '--all' else args[0])
if isinstance(r, list) and any('error' in item for item in r):
print(json.dumps(r, indent=1))
raise SystemExit(1)
elif cmd == 'patch':
import argparse
parser = argparse.ArgumentParser(description='Patch and v2-sign an APK locally')
parser.add_argument('src')
parser.add_argument('dst')
parser.add_argument('--add', action='append', default=[], metavar='NAME=PATH')
opts = parser.parse_args(args)
additions = {}
for item in opts.add:
if '=' not in item:
raise FrameError('--add requires NAME=PATH')
entry, path = item.split('=', 1)
with open(path, 'rb') as f:
additions[entry] = f.read()
r = patch(opts.src, opts.dst, additions)
elif cmd == 'install-obb':
if len(args) < 2:
raise FrameError('install-obb requires PACKAGE OBB [OBB ...]')
r = install_obb(args[0], args[1:])
elif cmd in ('backup-data', 'restore-data'):
if len(args) != 2:
raise FrameError(cmd + ' requires PACKAGE ARCHIVE.tar.gz')
r = (backup_data if cmd == 'backup-data' else restore_data)(*args)
elif cmd == 'list':
r = list_apps()
if any(a['art_missing'] for a in r):
print('Some apps have no Steam artwork: python3 ui/frame_android.py refresh-art --all', file=sys.stderr)
elif cmd in ('launch', 'stop', 'probe'):
r = globals()[cmd](args[0])
elif cmd == 'remove':
r = remove(args[0], keep_data='--keep-data' in args)
else:
sys.exit(__doc__)
except FrameError as e:
except (FrameError, OSError) as e:
sys.exit(f'error: {e}')
print(json.dumps(r, indent=1))
+133
View File
@@ -0,0 +1,133 @@
"""Expansion files and stopped-instance private-data backups. Python stdlib only."""
import hashlib
import json
import os
from pathlib import Path
import re
import runpy
import shlex
import subprocess
import tempfile
import uuid
import frame_android as android
REMOTE = Path(android.ROOT) / 'frame/android/app-data.py'
def _stream(command, src=None, dst=None):
try:
result = subprocess.run(['ssh', *android.SSH_OPTS, android.FRAME, command],
stdin=src if src else subprocess.DEVNULL,
stdout=dst if dst else subprocess.PIPE,
stderr=subprocess.PIPE, timeout=1800)
except subprocess.TimeoutExpired:
raise android.FrameError('app-data transfer timed out')
except OSError as error:
raise android.FrameError('app-data transfer failed: ' + str(error))
if result.returncode:
raise android.FrameError(result.stderr.decode(errors='replace').strip()[-600:] or
'app-data transfer failed')
return result.stdout
def _sha256(path):
digest = hashlib.sha256()
with open(path, 'rb') as src:
for chunk in iter(lambda: src.read(1024 * 1024), b''):
digest.update(chunk)
return digest.hexdigest()
def _meta(package):
if not android.PKG_RE.fullmatch(package or ''):
raise android.FrameError('invalid package name')
meta = android._meta_or_fail(package)
if meta['package'] != package:
raise android.FrameError('installed app metadata has a different package')
return meta
def install_obb(package, paths):
if not android.PKG_RE.fullmatch(package or ''):
raise android.FrameError('invalid package name')
paths = [Path(p).resolve() for p in paths]
if not paths:
raise android.FrameError('select at least one OBB file')
names = set()
for path in paths:
if (not re.fullmatch(r'(main|patch)\.[0-9]+\.' + re.escape(package) + r'\.obb', path.name)
or not path.is_file() or path.stat().st_size == 0 or path.name in names):
raise android.FrameError('OBB must be a nonempty main/patch.<version>.' + package + '.obb file')
names.add(path.name)
with android._install_lock:
meta = _meta(package)
container = 'lepton-steamlaunch-' + str(int(meta['instance']))
# No implicit launch. Android resolves /sdcard, never an assumed host path.
running = android.ssh('podman ps --format "{{.Names}}"').splitlines()
if container not in running:
raise android.FrameError('start this app instance before installing OBB data')
dest = '/sdcard/Android/obb/' + package
results = []
for path in paths:
digest = _sha256(path)
part = dest + '/.frame-' + uuid.uuid4().hex + '.part'
target = dest + '/' + path.name
script = (f'set -eu; mkdir -p {dest}; umask 002; '
f'trap "rm -f {part}" EXIT; cat > {part}; '
f'test "$(sha256sum {part} | cut -d " " -f 1)" = {digest}; '
f'chmod 664 {part}; mv {part} {target}')
command = shlex.join(['podman', 'exec', '-i', container, '/system/bin/sh', '-c', script])
with path.open('rb') as src:
_stream(command, src=src)
results.append({'name': path.name, 'path': target, 'sha256': digest})
return {'package': package, 'instance': meta['instance'], 'obb': results,
'verified': True}
def _data_command(action, meta):
container = 'lepton-steamlaunch-' + str(int(meta['instance']))
# Fail closed if podman cannot enumerate containers; don't mistake errors for stopped.
guard = ('running=$(podman ps --format "{{.Names}}") || exit 1; '
f'if printf "%s\\n" "$running" | grep -Fxq {shlex.quote(container)}; then '
'echo "stop the app before backup or restore" >&2; exit 1; fi; ')
return guard + shlex.join(['podman', 'unshare', 'python3', '-c', REMOTE.read_text(),
action, meta['package'], str(int(meta['instance']))])
def backup_data(package, destination):
destination = Path(destination).expanduser().absolute()
if destination.exists():
raise android.FrameError('backup destination already exists')
with android._install_lock:
meta = _meta(package)
fd, temporary = tempfile.mkstemp(prefix='.frame-backup-', dir=str(destination.parent))
try:
with os.fdopen(fd, 'wb') as dst:
_stream(_data_command('backup', meta), dst=dst)
result = _inspect(temporary, meta)
# Exclusive publication: a concurrently created backup is never overwritten.
os.link(temporary, str(destination))
return dict(result, path=str(destination), sha256=_sha256(destination))
finally:
os.unlink(temporary)
def _inspect(path, meta):
import tarfile
try:
return runpy.run_path(str(REMOTE))['inspect_archive'](path, meta['package'], int(meta['instance']))
except (OSError, EOFError, ValueError, tarfile.TarError) as error:
raise android.FrameError('invalid app-data backup: ' + str(error))
def restore_data(package, archive):
with android._install_lock:
meta = _meta(package)
_inspect(archive, meta)
with open(archive, 'rb') as src:
result = _stream(_data_command('restore', meta), src=src)
try:
return json.loads(result)
except (ValueError, TypeError):
raise android.FrameError('could not read restore result; inspect app data before retrying')
+11 -3
View File
@@ -10,7 +10,8 @@ import zipfile
# android: attribute resource ids; names can be stripped by shrinkers, ids can't.
ATTR = {0x01010001: 'label', 0x01010002: 'icon', 0x01010003: 'name',
0x0101021b: 'versionCode', 0x0101021c: 'versionName', 0x0101020c: 'minSdkVersion'}
0x01010024: 'value', 0x0101021b: 'versionCode', 0x0101021c: 'versionName', 0x0101020c: 'minSdkVersion',
0x01010202: 'targetActivity'}
T_REF, T_STRING, T_INT_DEC, T_INT_HEX = 0x01, 0x03, 0x10, 0x11
# APKs can come from websites (install links), so nothing read from one may be
# unbounded. zipfile stops at a member's declared size, so checking it is enough.
@@ -215,8 +216,11 @@ def apk_info(path):
if 'AndroidManifest.xml' not in names:
raise ApkError('not an APK: no AndroidManifest.xml')
try:
elements = manifest_elements(_read(z, 'AndroidManifest.xml', MAX_MANIFEST))
manifest_data = _read(z, 'AndroidManifest.xml', MAX_MANIFEST)
elements = manifest_elements(manifest_data)
res = Resources(_read(z, 'resources.arsc', MAX_ARSC) if 'resources.arsc' in names else b'')
from frame_apk_vr import detection
vr_info = detection(manifest_data, names)
except (struct.error, IndexError, zipfile.BadZipFile) as e:
raise ApkError(f'could not read the APK manifest: {e}')
tags = {}
@@ -236,6 +240,7 @@ def apk_info(path):
'min_sdk': min_sdk[1] if min_sdk and min_sdk[0] in (T_INT_DEC, T_INT_HEX) else None,
'icon_png': None,
}
info.update(vr_info)
try:
info['icon_png'] = _icon_png(z, names, _icons(app.get('icon'), res))
except Exception: # noqa: BLE001 - any unreadable icon just means no icon
@@ -250,7 +255,10 @@ def _icon_png(z, names, icons):
# Adaptive icons are XML; fall back to the largest launcher PNG.
pngs = sorted((n for n in names if n.endswith('.png') and 'ic_launcher' in n and 'foreground' not in n),
key=lambda n: z.getinfo(n).file_size)
return _read(z, pngs[-1], MAX_ICON) if pngs else None
if pngs:
return _read(z, pngs[-1], MAX_ICON)
# Godot exports can keep only an adaptive launcher plus the project icon.
return _read(z, 'assets/icon.png', MAX_ICON) if 'assets/icon.png' in names else None
if __name__ == '__main__':
+361
View File
@@ -0,0 +1,361 @@
"""Lossless ZIP repacking and APK v2 RSA/SHA-256 signing, Python 3.9 stdlib.
Spec: https://source.android.com/docs/security/features/apksigning/v2
Sections: APK Signing Block; APK Signature Scheme v2 Block; Integrity-protected
contents; Verification. No verity algorithm is used, so no verity padding.
"""
import hashlib
import io
import json
import math
import os
from pathlib import Path
import re
import secrets
import struct
import tempfile
import zipfile
import zlib
import frame_host
MAGIC = b'APK Sig Block 42'
V2 = 0x7109871a
ALG = 0x0103
SHA256_DER = bytes.fromhex('3031300d060960864801650304020105000420')
def u32(n):
return struct.pack('<I', n)
def lp(b):
return u32(len(b)) + b
def der(tag, b):
n = len(b)
length = bytes([n]) if n < 128 else bytes([128 + (n.bit_length() + 7) // 8]) + n.to_bytes((n.bit_length() + 7) // 8, 'big')
return bytes([tag]) + length + b
def integer(n):
b = n.to_bytes((n.bit_length() + 7) // 8 or 1, 'big')
return der(2, (b'\0' if b[0] & 128 else b'') + b)
def sequence(*items):
return der(0x30, b''.join(items))
RSA_ALG = bytes.fromhex('300d06092a864886f70d0101010500')
CERT_ALG = bytes.fromhex('300d06092a864886f70d01010b0500')
def public_key(key):
return sequence(RSA_ALG, der(3, b'\0' + sequence(integer(key['n']), integer(key['e']))))
def encoded_hash(data, size):
digest = SHA256_DER + hashlib.sha256(data).digest()
return b'\0\1' + b'\xff' * (size - len(digest) - 3) + b'\0' + digest
def rsa_sign(data, key):
size = (key['n'].bit_length() + 7) // 8
return pow(int.from_bytes(encoded_hash(data, size), 'big'), key['d'], key['n']).to_bytes(size, 'big')
def rsa_verify(data, sig, n, e):
size = (n.bit_length() + 7) // 8
if len(sig) != size or int.from_bytes(sig, 'big') >= n:
raise ValueError('invalid RSA signature size/value')
actual = pow(int.from_bytes(sig, 'big'), e, n).to_bytes(size, 'big')
if actual != encoded_hash(data, size):
raise ValueError('RSA signature mismatch')
def certificate(key):
name = sequence(der(0x31, sequence(bytes.fromhex('0603550403'), der(12, b'Frame Control APK signer'))))
validity = sequence(der(0x17, b'200101000000Z'), der(0x18, b'21200101000000Z'))
tbs = sequence(der(0xa0, integer(2)), integer(1), CERT_ALG, name, validity, name, public_key(key))
return sequence(tbs, CERT_ALG, der(3, b'\0' + rsa_sign(tbs, key)))
def _prime(bits):
small = (3, 5, 7, 11, 13, 17, 19, 23, 29, 31, 37, 41, 43, 47)
while True:
n = secrets.randbits(bits) | (3 << (bits - 2)) | 1
if any(n % p == 0 for p in small) or (n - 1) % 65537 == 0:
continue
d, s = n - 1, 0
while d % 2 == 0:
d //= 2
s += 1
for _ in range(40): # Miller-Rabin error bound <= 2^-80
x = pow(secrets.randbelow(n - 3) + 2, d, n)
if x in (1, n - 1):
continue
for _ in range(s - 1):
x = pow(x, 2, n)
if x == n - 1:
break
else:
break
else:
return n
def signing_key(path=None):
"""Persistent identity in app data, never an evictable cache. Atomic publication.
Hard-linking a fully written private temp file prevents concurrent first-use
callers from selecting different identities or reading a partial key.
"""
path = Path(path) if path is not None else frame_host.data_dir('apk-signing-key.json')
if not path.exists():
p, q = _prime(1024), _prime(1024)
while q == p:
q = _prime(1024)
key = {'n': p * q, 'e': 65537, 'd': pow(65537, -1, math.lcm(p - 1, q - 1))}
path.parent.mkdir(parents=True, exist_ok=True)
fd, tmp = tempfile.mkstemp(prefix='.apk-key-', dir=str(path.parent))
try:
with os.fdopen(fd, 'w') as f:
json.dump(key, f)
f.flush()
os.fsync(f.fileno())
try:
os.link(tmp, path) # never replaces a key another process wrote first
except FileExistsError:
pass
except OSError: # no hard links (FAT/exFAT): plain rename
if not path.exists():
os.replace(tmp, path)
finally:
if os.path.exists(tmp):
os.unlink(tmp)
os.chmod(path, 0o600) # Windows ignores this; the per-user app-data folder is the protection there
key = json.loads(path.read_text())
if key['n'].bit_length() != 2048 or key['e'] != 65537:
raise ValueError(f'invalid cached APK signing key; delete {path} to make a new one '
'(re-signed apps then need reinstalling)')
rsa_verify(b'key check', rsa_sign(b'key check', key), key['n'], key['e'])
return key
def _eocd(data):
# ZIP comments can contain the EOCD signature; accept only an exact EOF fit.
for at in range(len(data) - 22, max(-1, len(data) - 65558), -1):
if data[at:at + 4] == b'PK\5\6' and at + 22 + struct.unpack_from('<H', data, at + 20)[0] == len(data):
disk, cd_disk, count_disk, count, size, cd = struct.unpack_from('<HHHHII', data, at + 4)
if disk or cd_disk or count_disk != count or count == 65535 or cd + size != at:
raise ValueError('multi-disk/ZIP64 or invalid APK directory')
return at, cd
raise ValueError('missing ZIP end record')
def content_digest(sections):
chunks = []
for section in sections:
for off in range(0, len(section), 1024 * 1024):
part = section[off:off + 1024 * 1024]
chunks.append(hashlib.sha256(b'\xa5' + u32(len(part)) + part).digest())
return hashlib.sha256(b'\x5a' + u32(len(chunks)) + b''.join(chunks)).digest()
def sign_apk(data, key):
eo, cd = _eocd(data)
digest = content_digest((memoryview(data)[:cd], memoryview(data)[cd:eo], data[eo:]))
signed = lp(lp(u32(ALG) + lp(digest))) + lp(lp(certificate(key))) + lp(b'')
signer = lp(signed) + lp(lp(u32(ALG) + lp(rsa_sign(signed, key)))) + lp(public_key(key))
value = lp(lp(signer))
pair = struct.pack('<Q', 4 + len(value)) + u32(V2) + value
size = len(pair) + 24
block = struct.pack('<Q', size) + pair + struct.pack('<Q', size) + MAGIC
end = bytearray(data[eo:])
struct.pack_into('<I', end, 16, cd + len(block))
return data[:cd] + block + data[cd:eo] + end
def _parts(data):
result, off = [], 0
while off < len(data):
if off + 4 > len(data):
raise ValueError('truncated length prefix')
size = struct.unpack_from('<I', data, off)[0]
off += 4
if off + size > len(data):
raise ValueError('length prefix outside block')
result.append(data[off:off + size])
off += size
return result
def _der_parts(data):
result, off = [], 0
while off < len(data):
start = off
tag, size = data[off:off + 2]
off += 2
if size & 128:
count = size & 127
if not count or count > 4:
raise ValueError('invalid DER length')
size = int.from_bytes(data[off:off + count], 'big')
off += count
if off + size > len(data):
raise ValueError('truncated DER')
result.append((tag, data[off:off + size], data[start:off + size]))
off += size
return result
def _cert_key(cert):
outer = _der_parts(cert)
if len(outer) != 1 or outer[0][0] != 0x30:
raise ValueError('invalid certificate')
fields = _der_parts(outer[0][1])
tbs = _der_parts(fields[0][1])
spki = tbs[6 if tbs[0][0] == 0xa0 else 5][2]
pub = _der_parts(_der_parts(spki)[0][1])
if pub[0][2] != RSA_ALG or pub[1][1][:1] != b'\0':
raise ValueError('certificate is not RSA')
numbers = _der_parts(_der_parts(pub[1][1][1:])[0][1])
n, e = [int.from_bytes(item[1], 'big') for item in numbers]
return n, e, spki
def verify(path):
"""Verify this v2-only format; return True or raise ValueError on corruption.
A valid signature establishes integrity, not trust in the APK publisher.
"""
data = Path(path).read_bytes()
try:
eo, cd = _eocd(data)
if data[cd - 16:cd] != MAGIC:
raise ValueError('no APK signing block')
size = struct.unpack_from('<Q', data, cd - 24)[0]
start = cd - size - 8
if start < 0 or struct.unpack_from('<Q', data, start)[0] != size:
raise ValueError('invalid signing block size')
off, values = start + 8, []
while off < cd - 24:
length = struct.unpack_from('<Q', data, off)[0]
if length < 4 or off + 8 + length > cd - 24:
raise ValueError('invalid signing pair')
ident = struct.unpack_from('<I', data, off + 8)[0]
if ident == V2:
values.append(data[off + 12:off + 8 + length])
off += 8 + length
if off != cd - 24 or len(values) != 1:
raise ValueError('missing or duplicate v2 signer block')
end = bytearray(data[eo:])
struct.pack_into('<I', end, 16, start)
digest = content_digest((memoryview(data)[:start], memoryview(data)[cd:eo], end))
wrappers = _parts(values[0])
if len(wrappers) != 1:
raise ValueError('invalid signers sequence')
signers = _parts(wrappers[0])
if not signers:
raise ValueError('no signers')
for signer in signers:
signed, signatures, pub = _parts(signer)
digests, certs, attrs = _parts(signed)
cert = _parts(certs)[0]
n, e, cert_pub = _cert_key(cert)
if cert_pub != pub:
raise ValueError('public key differs from certificate')
sigs, digs = _parts(signatures), _parts(digests)
if len(sigs) != 1 or len(digs) != 1 or sigs[0][:4] != u32(ALG) or digs[0][:4] != u32(ALG):
raise ValueError('unsupported signature algorithm')
if _parts(digs[0][4:]) != [digest]:
raise ValueError('APK content digest mismatch')
sig = _parts(sigs[0][4:])
if len(sig) != 1:
raise ValueError('invalid signature sequence')
rsa_verify(signed, sig[0], n, e)
return True
except (IndexError, struct.error, OverflowError) as exc:
raise ValueError('malformed APK signature: ' + str(exc)) from exc
def repack(src, dst, replace=None, add=None, sign=True):
"""Copy raw compressed members; reconstruct ZIP headers without descriptors.
Reject ZIP64/encrypted archives. Output is atomically replaced after signing.
"""
replace, add = dict(replace or {}), dict(add or {})
central, output = [], io.BytesIO()
with open(src, 'rb') as raw, zipfile.ZipFile(raw) as archive:
names = archive.namelist()
if len(set(names)) != len(names):
raise ValueError('duplicate ZIP member names')
if set(replace) - set(names) or set(add) & set(names) or set(add) & set(replace):
raise ValueError('replace must exist and add must be new')
items = archive.infolist() + [zipfile.ZipInfo(name) for name in add]
for info in items:
name = info.filename
if re.match(r'^META-INF/(?:[^/]+\.(?:SF|RSA|EC|DSA)|MANIFEST\.MF)$', name, re.I):
continue
if info.flag_bits & 1 or info.compress_type not in (0, 8):
raise ValueError('unsupported ZIP encryption/compression')
method = info.compress_type
content = add.get(name) if name in add else replace.get(name)
if content is None:
raw.seek(info.header_offset)
header = raw.read(30)
if header[:4] != b'PK\3\4':
raise ValueError('invalid local ZIP header')
nl, el = struct.unpack_from('<HH', header, 26)
raw.seek(nl + el, 1)
compressed = raw.read(info.compress_size)
crc, usize = info.CRC, info.file_size
if len(compressed) != info.compress_size:
raise ValueError('truncated ZIP member')
else:
crc, usize = zlib.crc32(content), len(content)
if method == 8:
compressor = zlib.compressobj(6, zlib.DEFLATED, -15)
compressed = compressor.compress(content) + compressor.flush()
else:
compressed = content
encoded = name.encode('utf-8')
offset = output.tell()
align = 16384 if name.endswith('.so') else 4
needs_alignment = method == 0 or name.endswith('.so')
padding = (-(offset + 30 + len(encoded) + 6) % align) if needs_alignment else 0
# Android zipalign extra: alignment (uint16), then padding bytes.
extra = struct.pack('<HHH', 0xd935, padding + 2, align) + bytes(padding) if needs_alignment else b''
dt = info.date_time
dos_time = (dt[3] << 11) | (dt[4] << 5) | (dt[5] // 2)
dos_date = ((dt[0] - 1980) << 9) | (dt[1] << 5) | dt[2]
csize = len(compressed)
if max(offset, csize, usize) >= 0xffffffff:
raise ValueError('ZIP64 APKs are unsupported')
output.write(struct.pack('<IHHHHHIIIHH', 0x04034b50, 20, 0x800, method, dos_time, dos_date,
crc, csize, usize, len(encoded), len(extra)) + encoded + extra + compressed)
central.append(struct.pack('<IHHHHHHIIIHHHHHII', 0x02014b50, 0x314, 20, 0x800, method,
dos_time, dos_date, crc, csize, usize, len(encoded), 0, len(info.comment),
0, info.internal_attr, info.external_attr, offset) + encoded + info.comment)
cd = output.tell()
directory = b''.join(central)
if len(central) >= 65535 or cd + len(directory) >= 0xffffffff:
raise ValueError('ZIP64 APKs are unsupported')
output.write(directory)
output.write(struct.pack('<IHHHHIIH', 0x06054b50, 0, 0, len(central), len(central), len(directory), cd, len(archive.comment)) + archive.comment)
data = output.getvalue()
if sign:
data = sign_apk(data, signing_key())
dst = Path(dst)
fd, tmp = tempfile.mkstemp(prefix='.apk-', dir=str(dst.parent))
try:
with os.fdopen(fd, 'wb') as f:
f.write(data)
if sign:
verify(tmp)
os.replace(tmp, dst)
finally:
if os.path.exists(tmp):
os.unlink(tmp)
+128
View File
@@ -0,0 +1,128 @@
"""Binary-manifest VR inspection and minimal launcher repair (stdlib only)."""
import struct
import frame_apk
MAIN = 'android.intent.action.MAIN'
LAUNCHER = 'android.intent.category.LAUNCHER'
VR = {'com.oculus.intent.category.VR', 'org.khronos.openxr.intent.category.IMMERSIVE_HMD'}
def inspect(data):
elements = iter(frame_apk.manifest_elements(data))
stack, filters, samsung = [], [], False
current, owner, package = None, None, ''
for kind, hs, off, size in frame_apk._chunks(data, 8, len(data)):
if kind == 0x0102:
tag, attrs = next(elements)
value = attrs.get('name', (None, None, None))[2]
if tag == 'manifest':
package = attrs.get('package', (None, None, None))[2] or ''
if tag in ('activity', 'activity-alias'):
owner = attrs.get('targetActivity', (None, None, None))[2] if tag == 'activity-alias' else value
if owner and '.' not in owner: # PackageParser.buildClassName: bare names are relative too
owner = '.' + owner
owner = package + owner if owner and owner.startswith('.') else owner
if tag == 'intent-filter' and stack and stack[-1] in ('activity', 'activity-alias'):
current = {'actions': set(), 'categories': set(), 'templates': [], 'alias': stack[-1] == 'activity-alias', 'activity': owner}
if current is not None and stack and stack[-1] == 'intent-filter':
if tag == 'action':
current['actions'].add(value)
if tag == 'category':
current['categories'].add(value)
current['templates'].append((off, size, hs))
if tag == 'meta-data' and stack and stack[-1] == 'application':
samsung |= value == 'com.samsung.android.vr.application.mode' and attrs.get('value', (0, 0, None))[2] == 'vr_only'
stack.append(tag)
elif kind == 0x0103 and stack:
tag = stack.pop()
if tag == 'intent-filter' and current is not None:
current['end'] = off
filters.append(current)
current = None
mains = [f for f in filters if MAIN in f['actions']]
vr_filters = [f for f in mains if VR & f['categories']]
# Lepton's apk-info-extractor ignores <activity-alias>; Godot 4 puts LAUNCHER only there.
real = [f for f in mains if not f['alias']]
targets = [f for f in real if VR & f['categories']]
if not targets and any(LAUNCHER in f['categories'] or VR & f['categories'] for f in mains if f['alias']):
aimed = {f['activity'] for f in mains if f['alias'] and (LAUNCHER in f['categories'] or VR & f['categories'])}
targets = [f for f in real if f['templates']] # the patch copies an existing <category>
targets = [f for f in targets if f['activity'] in aimed] or targets
launchable = any(LAUNCHER in f['categories'] for f in real)
return {'launchable': launchable, 'repairable': not launchable and bool(targets),
'vr_activity': bool(vr_filters), 'vr': bool(vr_filters) or samsung}, targets
def _append_string(chunk, text):
_, hs, size, count, styles, flags, start, style_start = struct.unpack_from('<HHIIIIII', chunk)
strings_end = style_start or size
encoded = text.encode('utf-8' if flags & 0x100 else 'utf-16-le')
# LAUNCHER is short enough for both single-unit length encodings.
new = (bytes([len(text), len(encoded)]) + encoded + b'\0' if flags & 0x100
else struct.pack('<H', len(text)) + encoded + b'\0\0')
string_data = chunk[start:strings_end] + new
string_data += bytes(-len(string_data) % 4)
header = bytearray(chunk[:hs])
new_start = start + 4
new_styles = new_start + len(string_data) if style_start else 0
body = (chunk[hs:hs + count * 4] + struct.pack('<I', strings_end - start)
+ chunk[hs + count * 4:start] + string_data + (chunk[style_start:] if style_start else b''))
struct.pack_into('<IIIII', header, 8, count + 1, styles, flags & ~1, new_start, new_styles)
struct.pack_into('<I', header, 4, len(header) + len(body))
return bytes(header) + body, count
def add_launcher_category(axml_bytes):
info, filters = inspect(axml_bytes)
if info['launchable']:
return axml_bytes
if not filters:
raise frame_apk.ApkError('no activity with a MAIN intent filter that Frame Control can patch')
target = filters[0]
chunks = list(frame_apk._chunks(axml_bytes, 8, len(axml_bytes)))
pool = next(c for c in chunks if c[0] == 1)
_, _, po, ps = pool
new_pool, index = _append_string(axml_bytes[po:po + ps], LAUNCHER)
off, size, hs = target['templates'][0]
start = bytearray(axml_bytes[off:off + size])
attr_start, attr_size, count = struct.unpack_from('<HHH', start, hs + 8)
strings = frame_apk._string_pool(axml_bytes, po)
resmap = []
for kind, header_size, offset, chunk_size in chunks:
if kind == 0x180:
resmap = struct.unpack_from('<%dI' % ((chunk_size - header_size) // 4),
axml_bytes, offset + header_size)
for i in range(count):
a = hs + attr_start + i * attr_size
name = struct.unpack_from('<I', start, a + 4)[0]
if (name < len(resmap) and resmap[name] == 0x01010003) or strings[name] == 'name':
struct.pack_into('<I', start, a + 8, index)
struct.pack_into('<HBBI', start, a + 12, 8, 0, 3, index)
break
else:
raise frame_apk.ApkError('category has no name attribute')
end = struct.pack('<HHI', 0x0103, hs, hs + 8) + start[8:hs] + start[hs:hs + 8]
result = bytearray(axml_bytes[:8])
for _, _, off, size in chunks:
if off == target['end']:
result += start + end
result += new_pool if off == po else axml_bytes[off:off + size]
struct.pack_into('<I', result, 4, len(result))
result = bytes(result)
if not inspect(result)[0]['launchable']:
raise frame_apk.ApkError('launcher repair failed verification')
return result
def detection(data, names):
info, _ = inspect(data)
issues = []
if 'lib/arm64-v8a/libvrapi.so' in names:
issues.append("Uses Meta's legacy VrApi, which the Frame doesn't have; it won't run.")
if any(n.endswith('/libovrplatformloader.so') for n in names):
issues.append("Uses Meta's platform SDK; if it checks your Quest store licence it will quit.")
if 'lib/arm64-v8a/libopenxr_loader.so' in names:
info['vr'] = True
issues.append('Uses OpenXR (good).')
info['vr_issues'] = issues
return info
+160
View File
@@ -0,0 +1,160 @@
"""Bounded artwork inputs for Steam library canvas rendering."""
import struct
import time
import zlib
SLOTS = {'grid': (600, 900), 'wide': (920, 430), 'hero': (3840, 1240),
'logo': (1280, 480), 'icon': (256, 256)}
MAX_IMAGE = 12 * 1024 * 1024
MAX_PIXELS = 4096 * 4096 # a 4K screenshot; Chromium decodes it on the Frame
PNG = b'\x89PNG\r\n\x1a\n'
def chunk(kind, data):
return struct.pack('>I', len(data)) + kind + data + struct.pack('>I', zlib.crc32(kind + data))
def png_size(data):
"""IHDR dimensions of a PNG of any bit depth or interlace; Steam's Chromium decodes the pixels."""
if len(data) < 33 or data[12:16] != b'IHDR' or struct.unpack_from('>I', data, 8)[0] != 13:
raise ValueError('invalid PNG header')
if zlib.crc32(data[12:29]) != struct.unpack_from('>I', data, 29)[0]:
raise ValueError('invalid PNG checksum')
w, h, depth, color = struct.unpack_from('>IIBB', data, 16)
if color not in (0, 2, 3, 4, 6) or depth not in (1, 2, 4, 8, 16):
raise ValueError('unsupported PNG encoding')
if not w or not h or w * h > MAX_PIXELS or w > 8192 or h > 8192:
raise ValueError('PNG dimensions exceed limits')
return w, h
def _gif_blocks(data, pos):
"""Position after a run of GIF data sub-blocks and its terminator."""
while True:
if pos >= len(data):
raise ValueError('truncated GIF')
size = data[pos]
pos += 1 + size
if not size:
return pos
def gif_frame(data):
"""A GIF's first frame as a minimal single-frame GIF, so no frame count or oversized frame
reaches the Frame's Chromium. Raises ValueError for anything malformed or out of bounds."""
if data[:6] not in (b'GIF87a', b'GIF89a') or len(data) < 13:
raise ValueError('invalid GIF')
sw, sh, flags = struct.unpack_from('<HHB', data, 6)
if not sw or not sh or sw * sh > MAX_PIXELS or max(sw, sh) > 4096:
raise ValueError('artwork GIF has unsupported dimensions')
pos = 13 + (3 << ((flags & 7) + 1) if flags & 0x80 else 0)
head, control = data[:pos], b''
if len(head) != pos:
raise ValueError('truncated GIF')
while True:
if pos >= len(data):
raise ValueError('truncated GIF')
if data[pos] == 0x21 and pos + 1 < len(data): # extension: keep the frame's graphic control
end = _gif_blocks(data, pos + 2)
if data[pos + 1] == 0xf9 and end - pos == 8 and data[pos + 2] == 4: # GIF89a: fixed 4-byte payload
control = data[pos:end]
pos = end
elif data[pos] == 0x2c and pos + 10 <= len(data): # the first image
x, y, w, h, local = struct.unpack_from('<HHHHB', data, pos + 1)
if not w or not h or x + w > sw or y + h > sh:
raise ValueError('artwork GIF frame exceeds its screen')
if not flags & 0x80 and not local & 0x80:
raise ValueError('GIF has no colour table')
start = pos
pos += 10 + (3 << ((local & 7) + 1) if local & 0x80 else 0)
if pos >= len(data) or not 2 <= data[pos] <= 8: # the LZW minimum code size
raise ValueError('invalid GIF image data')
end = _gif_blocks(data, pos + 1)
if end - pos <= 2: # code size then the terminator: no pixels at all
raise ValueError('invalid GIF image data')
return head + control + data[start:end] + b'\x3b'
else:
raise ValueError('invalid GIF block')
def image_type(data):
if not isinstance(data, bytes) or len(data) > MAX_IMAGE:
raise ValueError('artwork must be image bytes or an HTTP(S) URL, at most 12 MiB')
if data.startswith(PNG):
png_size(data)
return 'png'
if data[:6] in (b'GIF87a', b'GIF89a'):
gif_frame(data)
return 'gif'
if data.startswith(b'\xff\xd8'):
# Check JPEG SOF dimensions without depending on an image library; trailing padding is fine.
pos = 2
while pos + 4 <= len(data) and data[pos] == 255:
marker = data[pos + 1]
pos += 2
if marker == 255:
pos -= 1
continue
size = struct.unpack_from('>H', data, pos)[0]
if size < 2 or pos + size > len(data):
break
if 0xc0 <= marker <= 0xcf and marker not in (0xc4, 0xc8, 0xcc) and size >= 8:
h, w = struct.unpack_from('>HH', data, pos + 3)
if w and h and w * h <= MAX_PIXELS and max(w, h) <= 8192:
return 'jpg'
break
pos += size
raise ValueError('artwork must be a supported PNG, JPEG or GIF')
def fetch(value, deadline=None):
if isinstance(value, str):
from apk_sources import _images
# Public addresses only, at most three redirects, within the overall deadline.
value = _images.fetch(value, deadline=deadline, limit=MAX_IMAGE)[0]
kind = image_type(value)
return kind, gif_frame(value) if kind == 'gif' else value
def prepare(label, icon_png=None, artwork=None, budget=90):
"""Gather inputs; the Frame's Chromium canvas renders every final slot.
Every source is optional: any failure falls back to generated art, within budget seconds overall."""
import frame_steamgriddb
artwork = artwork or {}
allowed = set(SLOTS) | {'banner', 'feature_graphic', 'screenshots', 'screenshot'}
if not isinstance(artwork, dict) or set(artwork) - allowed:
raise ValueError('unknown artwork slot')
deadline = time.monotonic() + budget
supplied, warnings = {}, []
def get(value):
try:
return fetch(value, deadline)
except Exception: # an optional source never blocks the install; generated art covers it
return None
for slot, value in artwork.items():
values = value if slot == 'screenshots' and isinstance(value, (list, tuple)) else [value]
for candidate in values[:4]:
image = get(candidate)
if image:
supplied['screenshot' if slot == 'screenshots' else slot] = image
break
else:
warnings.append('Source ' + slot + ' unavailable; using fallback art')
if 'icon' not in supplied and icon_png:
image = get(icon_png)
if image:
supplied['icon'] = image
try:
provider, provider_warnings = frame_steamgriddb.lookup(label, deadline)
except Exception:
provider, provider_warnings = {}, ['SteamGridDB unavailable; using source or generated art']
warnings.extend(provider_warnings)
for slot, value in provider.items():
image = get(value)
if image:
supplied[slot] = image
else:
warnings.append('SteamGridDB ' + slot + ' download failed; using fallback art')
return supplied, warnings
+53
View File
@@ -0,0 +1,53 @@
"""Explicit, per-request forwarding to a user-chosen chat-completions endpoint."""
import base64
import json
from urllib.parse import urlsplit
from urllib.request import HTTPRedirectHandler, ProxyHandler, Request, build_opener
class NoRedirect(HTTPRedirectHandler):
def redirect_request(self, *args, **kwargs):
raise ValueError('Endpoint redirected; enter its final URL explicitly')
def chat(body, screenshot):
if body.get('consent') is not True:
raise ValueError('Opt in before sending a message')
endpoint, model, prompt = (body.get(k) for k in ('endpoint', 'model', 'prompt'))
if any(not isinstance(v, str) or not v.strip() for v in (endpoint, model, prompt)):
raise ValueError('Endpoint, model and message are required')
if len(prompt) > 32000 or len(model) > 200 or len(endpoint) > 2048:
raise ValueError('Message, model or endpoint is too long')
url = urlsplit(endpoint)
if not url.hostname or url.username or url.password or url.fragment or url.query:
raise ValueError('Use an endpoint URL without credentials, query or fragment')
if url.scheme != 'https' and not (url.scheme == 'http' and url.hostname in ('localhost', '127.0.0.1', '::1')):
raise ValueError('Use HTTPS, or HTTP on loopback for a local model')
key = body.get('key', '')
if not isinstance(key, str) or len(key) > 4096 or '\n' in key or '\r' in key:
raise ValueError('Invalid API key')
content = prompt
if body.get('screenshot') is True:
png = screenshot()
if len(png) > 12 * 1024**2:
raise ValueError('Screenshot is too large')
content = [{'type': 'text', 'text': prompt}, {'type': 'image_url', 'image_url': {
'url': 'data:image/png;base64,' + base64.b64encode(png).decode()}}]
payload = {'model': model, 'messages': [{'role': 'user', 'content': content}], 'stream': False}
headers = {'Content-Type': 'application/json'}
if key:
headers['Authorization'] = 'Bearer ' + key
request = Request(endpoint, data=json.dumps(payload).encode(), headers=headers)
# No environment proxy or redirects: credentials/context go only to the chosen URL.
try:
with build_opener(ProxyHandler({}), NoRedirect()).open(request, timeout=60) as response:
raw = response.read(2 * 1024**2 + 1)
if len(raw) > 2 * 1024**2:
raise ValueError('Endpoint response is too large')
answer = json.loads(raw)['choices'][0]['message']['content']
if not isinstance(answer, str):
raise ValueError('Expected a text reply')
except Exception:
# Provider error bodies and URLs can contain credentials or echoed prompts.
raise ValueError('Endpoint request failed or returned an unsupported reply; check URL, model and credentials') from None
return {'reply': answer}
+264
View File
@@ -0,0 +1,264 @@
"""Opt-in session worker ON the Frame; no root, extra apps, or power actions.
One worker per user, shared by desktop and phone. State survives companion
connections, not headset reboots. See docs/family-comfort.md for guarantees.
"""
import contextlib
import json
import os
from pathlib import Path
import subprocess
import sys
import time
import uuid
from frame_steam import Page
from frame_status import battery, thermal_alerts, activity_level
ROOT = Path.home() / '.local/state/frame-control/comfort'
VRCMD = '/opt/steamvr/bin/linuxarm64/vrcmd'
HOME_JS = """(async () => {
SteamUIStore.Navigate('/library/home');
await SteamClient.OpenVR.VROverlay.ShowDashboard('valve.steam.gamepadui.main');
if (!await SteamClient.OpenVR.VROverlay.IsDashboardVisible()) throw Error('Steam dashboard did not open');
return {path: location.pathname};
})()"""
def clock():
# CLOCK_BOOTTIME includes headset suspend; wall-clock corrections don't alter limits.
return time.clock_gettime(time.CLOCK_BOOTTIME)
def boot():
return Path('/proc/sys/kernel/random/boot_id').read_text().strip()
def validate(body):
if not isinstance(body, dict) or body.get('action') not in ('status', 'start', 'cancel'):
raise ValueError('Choose status, start or cancel')
if body['action'] == 'start':
for key, low, high in (('minutes', 1, 240), ('breakMinutes', 0, 120), ('stillMinutes', 0, 240)):
n = body.get(key)
if type(n) is not int or not low <= n <= high:
raise ValueError(f'{key} must be a whole number from {low} to {high}')
for key in ('batteryAlert', 'heatAlert'):
if type(body.get(key)) is not bool:
raise ValueError(f'{key} must be true or false')
return body
def new_session(body, now, boot_id):
return {'id': uuid.uuid4().hex, 'boot': boot_id, 'active': True,
'options': {k: body[k] for k in ('minutes', 'breakMinutes', 'stillMinutes', 'batteryAlert', 'heatAlert')},
'started': now, 'deadline': now + body['minutes'] * 60, 'lastSample': now,
'used': 0, 'nextBreak': body['breakMinutes'] * 60, 'stillSent': False,
'warned': None, 'events': [], 'seq': 0, 'latched': [], 'error': None}
def event(s, kind, message):
s['seq'] += 1
s['events'].append({'id': s['id'] + ':' + str(s['seq']), 'kind': kind,
'message': message, 'time': time.time()})
s['events'] = s['events'][-40:]
def notify(message):
r = subprocess.run([VRCMD, '--notify', 'Frame Control: ' + message],
capture_output=True, text=True, timeout=20)
if r.returncode or 'succeeded' not in r.stdout:
raise RuntimeError('SteamVR could not show the reminder: ' + (r.stderr or r.stdout)[-300:])
def home():
# A total process deadline also bounds a CDP peer that keeps sending events
# without completing the request. Keep cancellation ordered after this action.
r = subprocess.run([sys.executable, str(Path(__file__).resolve()), '--home'],
capture_output=True, text=True, timeout=15)
if r.returncode:
raise RuntimeError('Steam Home failed: ' + (r.stdout or r.stderr)[-300:])
def open_home():
page = Page()
try:
result = page.eval(HOME_JS)
if result.get('path') != '/routes/library/home':
raise RuntimeError('Steam did not navigate Home')
finally:
page.sock.close()
def tick(s, now, sample, warn=notify, go_home=home, read_clock=clock):
"""One deterministic step; injected actions/samples also exercise a fake Frame."""
if not s.get('active'):
return
o = s['options']
s['heartbeat'] = now
delta = max(0, min(30, now - s['lastSample']))
s['lastSample'] = now
level = sample.get('activity')
b = sample.get('battery') or {}
s['unavailable'] = []
if o['batteryAlert'] and b.get('percent') is None:
s['unavailable'].append('battery')
if o['heatAlert'] and sample.get('thermal') is None:
s['unavailable'].append('temperature')
if (o['breakMinutes'] or o['stillMinutes']) and level is None:
s['unavailable'].append('activity')
s['activity'] = level
if level in (1, 2):
s['used'] += delta
elif level is not None:
s['used'] = 0
s['nextBreak'] = o['breakMinutes'] * 60
s['stillSent'] = False
# Missing samples never count as time worn. No catch-up burst after a disconnect.
if now >= s['deadline'] - 60 and s['warned'] is None:
warn('One minute left. Save your progress; Steam Home will open.')
s['warned'] = max(now, read_clock())
event(s, 'warning', 'One minute left. Save your progress; Steam Home will open.')
if s['warned'] is not None and now >= max(s['deadline'], s['warned'] + 60):
go_home()
s['active'] = False
event(s, 'finished', 'Session ended: Steam Home opened. Your game is still running.')
return
if o['breakMinutes'] and s['used'] >= s['nextBreak']:
warn('Time for a break. Take off the headset and rest your eyes.')
event(s, 'break', 'Time for a break. Take off the headset and rest your eyes.')
s['nextBreak'] = s['used'] + o['breakMinutes'] * 60
if o['stillMinutes'] and not s['stillSent'] and s['used'] >= o['stillMinutes'] * 60:
event(s, 'still', f"Headset still active after {o['stillMinutes']} active minute(s). Check in with the wearer.")
s['stillSent'] = True
low = b.get('percent') is not None and b['percent'] <= 15 and b.get('status') == 'Discharging'
hot = sample.get('thermal')
for kind, enabled, value, message in (
('battery', o['batteryAlert'], low if b else None, 'Frame battery is low (15% or less).'),
('heat', o['heatAlert'], bool(hot) if hot is not None else None,
'Frame reports a hot/critical thermal trip or battery overheat. Ask the wearer to take a break.')):
if enabled and value and kind not in s['latched']:
event(s, kind, message)
s['latched'].append(kind)
elif value is False and kind in s['latched']:
# Battery hysteresis prevents repeated alerts around 15%.
if kind != 'battery' or b.get('status') == 'Charging' or (b.get('percent') or 0) >= 20:
s['latched'].remove(kind)
@contextlib.contextmanager
def locked(name='state.lock', nonblocking=False):
import fcntl # only needed ON the Linux headset, not by desktop validation/tests
ROOT.mkdir(parents=True, exist_ok=True, mode=0o700)
with (ROOT / name).open('a') as f:
fcntl.flock(f, fcntl.LOCK_EX | (fcntl.LOCK_NB if nonblocking else 0))
yield f
def read_state():
try:
state = json.loads((ROOT / 'session.json').read_text())
if not isinstance(state, dict):
raise ValueError('Saved session must be an object')
return state
except FileNotFoundError:
return {'active': False, 'events': []}
except (ValueError, UnicodeDecodeError):
# Preserve the unreadable state for diagnosis, then allow a new session.
(ROOT / 'session.json').replace(ROOT / ('session-unreadable-' + uuid.uuid4().hex + '.json'))
return {'active': False, 'events': [],
'error': 'Saved session was unreadable. Start a new session.'}
def save(s):
p = ROOT / 'session.tmp'
p.write_text(json.dumps(s))
p.chmod(0o600)
p.replace(ROOT / 'session.json')
def current(s, now):
if s.get('active') and s.get('boot') != boot():
s['active'] = False
s['error'] = 'Headset restarted. Start a new session.'
out = dict(s)
out['time'] = time.time() # event age uses the Frame's clock, not the phone's
out['remaining'] = max(0, max(s.get('deadline', now), (s.get('warned') or 0) + 60) - now) if s.get('active') else 0
beat = s.get('heartbeat', s.get('started', now)) # a hand-edited state may lack either
if s.get('active') and now - beat > 90:
out['error'] = 'Session worker is not responding. Timer enforcement is unverified; cancel and start again.'
return out
def watch():
try:
with locked('worker.lock', nonblocking=True) as worker:
while True:
with locked():
s = current(read_state(), clock())
if not s.get('active'):
save(s)
# Release ownership before state.lock: a concurrent start
# cannot miss the gap between an old worker and its exit.
import fcntl
fcntl.flock(worker, fcntl.LOCK_UN)
return
try:
b = battery()
hot = thermal_alerts()
if b and b.get('health') == 'Overheat':
hot = (hot or []) + ['battery']
tick(s, clock(), {'battery': b, 'thermal': hot, 'activity': activity_level()})
s['error'] = None
except Exception as e:
error = str(e)
if s.get('error') != error:
event(s, 'error', 'Session action failed: ' + error)
s['error'] = error
save(s)
time.sleep(5)
except BlockingIOError:
pass # another connection already started the single worker
def command(body):
validate(body)
with locked():
s = current(read_state(), clock())
if body['action'] == 'start':
if s.get('active'):
raise ValueError('A session is already running. Cancel it before starting another.')
s = new_session(body, clock(), boot())
event(s, 'started', 'Session started. Steam Home opens at the limit; games are not closed.')
elif body['action'] == 'cancel':
s['active'] = False
s['error'] = None
if s.get('id'):
event(s, 'cancelled', 'Session timer and monitoring cancelled.')
save(s)
if body['action'] == 'start':
try:
subprocess.Popen([sys.executable, str(Path(__file__).resolve()), '--watch'],
stdin=subprocess.DEVNULL, stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL,
start_new_session=True, close_fds=True)
except OSError as e:
s['active'] = False
s['error'] = 'Could not start session worker: ' + str(e)
event(s, 'error', s['error'])
save(s)
raise
return current(s, clock())
if __name__ == '__main__':
if sys.argv[1:] == ['--watch']:
watch()
else:
try:
if sys.argv[1:] == ['--home']:
open_home()
print(json.dumps({'home': True}))
else:
print(json.dumps(command(json.loads(sys.argv[1]))))
except Exception as e:
print(json.dumps({'error': str(e)}))
sys.exit(1)
+155 -1
View File
@@ -8,12 +8,18 @@ New reports go to a local outbox first and are sent from there, so nothing is
lost offline. A mirror of every report is kept for offline reads. Both live in
frame_host.data_dir('compat-db'). Python stdlib only.
CLI: python3 ui/frame_compat_db.py {count|export FILE|import FILE|flush}
Everyone else can opt in to sharing (the Privacy panel): their reports then
also go to PostHog as compat_report events (frame_telemetry.py), and the
maintainer's `sync` pulls them into the database, at most SYNC_DAILY_CAP per
reporter per day, marked via=community[-probe|-install].
CLI: python3 ui/frame_compat_db.py {count|export FILE|import FILE|flush|sync}
(import restores a backup; reports already in the database are skipped.)
"""
import json, os, subprocess, sys, threading, time, urllib.error, urllib.parse, urllib.request, uuid
import frame_host
import frame_telemetry
URL = os.environ.get('FRAME_COMPAT_DB_URL', 'https://frame-compat.lakebed.app')
KEYCHAIN = ('frame-control-compat-db', 'app-key')
@@ -228,11 +234,153 @@ def add(report):
if shared():
flush()
_mem['at'] = 0 # refetch on next load
else:
frame_telemetry.compat_report(r) # only if this person opted in to sharing
except Exception:
pass # stays queued; load() shows it and a later call sends it
return r
# ---- community reports: PostHog -> the database (maintainer only) ---------------
POSTHOG_KEYCHAIN = ('frame-control-posthog', 'personal-api-key')
SYNC_STATE = os.path.join(STATE, 'posthog-sync.json')
SYNC_DAILY_CAP = 30
COMMUNITY_VIA = {'user': 'community', 'probe': 'community-probe', 'install': 'community-install'}
def posthog_personal_key():
k = os.environ.get('POSTHOG_PERSONAL_API_KEY')
if k:
return k
if frame_host.MAC:
p = subprocess.run(['security', 'find-generic-password', '-s', POSTHOG_KEYCHAIN[0], '-a',
POSTHOG_KEYCHAIN[1], '-w'], capture_output=True, text=True)
if p.returncode == 0 and p.stdout.strip():
return p.stdout.strip()
raise DBError('No PostHog personal API key (set POSTHOG_PERSONAL_API_KEY, or on macOS the Keychain '
f'item service {POSTHOG_KEYCHAIN[0]}, account {POSTHOG_KEYCHAIN[1]})')
def _posthog_query(sql):
cfg = frame_telemetry.config()
project = os.environ.get('FRAME_CONTROL_POSTHOG_PROJECT') or cfg.get('project')
if not project:
raise DBError('No PostHog project id (ui/telemetry.json "project", or FRAME_CONTROL_POSTHOG_PROJECT)')
# The query API lives on the app host (us.posthog.com), not the ingestion host (us.i.posthog.com).
host = cfg['host'].replace('.i.posthog.com', '.posthog.com')
req = urllib.request.Request(f'{host}/api/projects/{urllib.parse.quote(str(project))}/query/', method='POST',
data=json.dumps({'query': {'kind': 'HogQLQuery', 'query': sql}}).encode(),
headers={'authorization': 'Bearer ' + posthog_personal_key(),
'content-type': 'application/json'})
try:
with _opener.open(req, timeout=60) as r:
return json.loads(r.read())
except urllib.error.HTTPError as e:
raise DBError(f'PostHog said HTTP {e.code}: {e.read()[:300]!r}')
except (urllib.error.URLError, TimeoutError, OSError, ValueError) as e:
raise DBError(f"can't reach PostHog: {e}")
SYNC_OVERLAP_DAYS = 30 # re-read this far back: offline copies send late, with their original time
SYNC_PAGE = 5000
def community_rows(events, state, cap=SYNC_DAILY_CAP):
"""(reports, skipped): compat_report events as database rows. `state` ({"seen": {id: day},
"counts": {"reporter|day": n}}) persists between syncs, so an event read twice is handled
once and each reporter gets at most `cap` reports a day in total."""
seen, counts = state.setdefault('seen', {}), state.setdefault('counts', {})
out, skipped = [], []
for props, reporter, ts in events:
if isinstance(props, str):
try:
props = json.loads(props)
except ValueError:
props = None
if not isinstance(props, dict):
skipped.append((None, 'unreadable properties'))
continue
bad = [k for k in (*FIELDS, 'id') if props.get(k) is not None and not isinstance(props[k], (str, int, float))]
if bad:
skipped.append((str(props.get('id'))[:60], f'bad field {bad[0]}'))
continue
r = {k: (str(props[k]) if props.get(k) is not None else None) for k in FIELDS}
r['id'] = str(props['id']) if props.get('id') is not None else None
if r['id'] in seen:
continue # handled in an earlier sync (or earlier in this one)
r['via'] = COMMUNITY_VIA.get(r.get('via') or 'user', 'community')
why = problem(r)
if why:
skipped.append((r.get('id'), why))
continue
day = str(ts)[:10]
seen[r['id']] = day
key_ = f'{reporter}|{day}'
if counts.get(key_, 0) >= cap:
skipped.append((r['id'], 'over the daily limit for one reporter'))
continue
counts[key_] = counts.get(key_, 0) + 1
out.append(r)
return out, skipped
def _sync_state():
try:
with open(SYNC_STATE) as f:
s = json.load(f)
return s if isinstance(s, dict) else {}
except (OSError, ValueError):
return {}
def _save_sync_state(s):
"""Forget ids and counts older than the overlap window (plus a margin)."""
cutoff = time.strftime('%Y-%m-%d', time.gmtime(time.time() - (SYNC_OVERLAP_DAYS + 15) * 86400))
s['seen'] = {k: d for k, d in s.get('seen', {}).items() if d >= cutoff}
s['counts'] = {k: n for k, n in s.get('counts', {}).items() if k.rsplit('|', 1)[-1] >= cutoff}
os.makedirs(STATE, exist_ok=True)
with open(SYNC_STATE + '.tmp', 'w') as f:
json.dump(s, f)
os.replace(SYNC_STATE + '.tmp', SYNC_STATE)
def sync(dry_run=False):
"""Pull community reports from PostHog into the database. Returns (added, skipped).
Reads the last SYNC_OVERLAP_DAYS each time, since events carry the time they were
made, not when they arrived; the saved state keeps that from adding anything twice."""
key() # the maintainer's copy only
state = _sync_state()
since = time.strftime('%Y-%m-%d %H:%M:%S', time.gmtime(time.time() - SYNC_OVERLAP_DAYS * 86400))
events, after = [], f"timestamp >= toDateTime('{since}', 'UTC')"
for _ in range(40):
# Keyset paging: PostHog refuses OFFSET with a personal API key. The cursor is in UTC,
# since a local time is ambiguous in the hour clocks go back.
res = _posthog_query("SELECT properties, distinct_id, timestamp, toString(uuid), "
"formatDateTime(timestamp, '%Y-%m-%d %H:%i:%S.%f', 'UTC') FROM events "
f"WHERE event = 'compat_report' AND {after} "
f"ORDER BY timestamp, toString(uuid) LIMIT {SYNC_PAGE}")
rows = res.get('results') or []
events += [row[:3] for row in rows]
if len(rows) < SYNC_PAGE:
break
last_uuid, last_ts = rows[-1][3], rows[-1][4]
after = (f"(timestamp > toDateTime64('{last_ts}', 6, 'UTC') OR "
f"(timestamp = toDateTime64('{last_ts}', 6, 'UTC') AND toString(uuid) > '{last_uuid}'))")
rows, skipped = community_rows(events, state)
if dry_run:
return rows, skipped
if rows:
os.makedirs(STATE, exist_ok=True)
with _lock, open(OUTBOX, 'a') as f:
f.writelines(json.dumps(r, ensure_ascii=False) + '\n' for r in rows)
# Saved before sending: the rows are in the outbox now, and flush retries them if sending fails.
_save_sync_state(state)
flush() # also retries rows a failed earlier sync left in the outbox
_mem['at'] = 0
return rows, skipped
def main():
cmd, *args = sys.argv[1:] or ['count']
try:
@@ -260,6 +408,12 @@ def main():
'reports already in the database were not duplicated')
elif cmd == 'flush':
print(f'{flush()} still queued')
elif cmd == 'sync':
rows, skipped = sync(dry_run='--dry-run' in args)
for rid, why in skipped:
print(f'skipped {rid!r}: {why}', file=sys.stderr)
print(f"{len(rows)} community reports {'found' if '--dry-run' in args else 'added'}, "
f'{len(skipped)} skipped')
else:
sys.exit(__doc__)
except DBError as e:
+133
View File
@@ -0,0 +1,133 @@
"""Read-only Frame UI inventory using installed X11 tools and AT-SPI libraries.
Runs on the Frame via SSH stdin. No daemon, input injection, or driver install.
Accessible names are untrusted application content, never agent instructions.
"""
import ctypes
import ctypes.util
import json
import os
import re
import signal
import subprocess
def parse_windows(text):
"""gamescope's focusable windows are triples: XID, app ID, process ID."""
windows, focused = [], None
observed_windows = False
for line in text.splitlines():
name, separator, value = line.partition(' = ')
if not separator:
continue
if not re.fullmatch(r'[0-9, ]*', value):
raise ValueError('Unexpected gamescope window property')
numbers = [int(v.strip()) for v in value.split(',') if v.strip()]
if name == 'GAMESCOPE_FOCUSABLE_WINDOWS(CARDINAL)':
observed_windows = True
if len(numbers) % 3 or len(numbers) > 1536:
raise ValueError('Incomplete or oversized gamescope window list')
windows = [{'windowId': hex(numbers[i]), 'appid': numbers[i + 1], 'pid': numbers[i + 2]}
for i in range(0, len(numbers), 3)]
elif name == 'GAMESCOPE_FOCUSED_APP(CARDINAL)' and numbers:
focused = numbers[0]
if not observed_windows:
raise ValueError('gamescope focusable-window property is unavailable')
return {'windows': windows, 'focusedApp': focused}
def accessibility():
"""Bounded semantic snapshot, with per-call timeouts and no action methods."""
c = ctypes
atspi = c.CDLL(ctypes.util.find_library('atspi') or 'libatspi.so.0')
glib = c.CDLL(ctypes.util.find_library('glib-2.0') or 'libglib-2.0.so.0')
obj = c.CDLL(ctypes.util.find_library('gobject-2.0') or 'libgobject-2.0.so.0')
def function(lib, name, result, args):
fn = getattr(lib, name)
fn.restype, fn.argtypes = result, args
return fn
init = function(atspi, 'atspi_init', c.c_int, [])
finish = function(atspi, 'atspi_exit', c.c_int, [])
timeout = function(atspi, 'atspi_set_timeout', None, [c.c_int, c.c_int])
desktop = function(atspi, 'atspi_get_desktop', c.c_void_p, [c.c_int])
count = function(atspi, 'atspi_accessible_get_child_count', c.c_int, [c.c_void_p, c.c_void_p])
child = function(atspi, 'atspi_accessible_get_child_at_index', c.c_void_p, [c.c_void_p, c.c_int, c.c_void_p])
name = function(atspi, 'atspi_accessible_get_name', c.c_void_p, [c.c_void_p, c.c_void_p])
role = function(atspi, 'atspi_accessible_get_role_name', c.c_void_p, [c.c_void_p, c.c_void_p])
pid = function(atspi, 'atspi_accessible_get_process_id', c.c_uint, [c.c_void_p, c.c_void_p])
free = function(glib, 'g_free', None, [c.c_void_p])
unref = function(obj, 'g_object_unref', None, [c.c_void_p])
def string(fn, node):
pointer = fn(node, None)
try:
return c.string_at(pointer).decode(errors='replace')[:512] if pointer else ''
finally:
if pointer:
free(pointer)
if init() not in (0, 1):
raise RuntimeError('AT-SPI initialization failed')
timeout(500, 500)
nodes = []
truncated = False
incomplete = False
def walk(node, path, depth):
nonlocal truncated, incomplete
if not node:
incomplete = True
return
try:
n = count(node, None)
nodes.append({'path': path, 'name': string(name, node), 'role': string(role, node),
'pid': pid(node, None), 'childCount': n})
incomplete = incomplete or n < 0
if depth >= 6:
truncated = truncated or n > 0
return
budget = min(max(n, 0), 96 - len(nodes))
truncated = truncated or n > budget
for i in range(budget):
if len(nodes) >= 96:
truncated = True
break
walk(child(node, i, None), path + [i], depth + 1)
finally:
unref(node)
try:
root = desktop(0)
if not root:
raise RuntimeError('No accessibility desktop available')
walk(root, [], 0)
return {'nodes': nodes, 'truncated': truncated, 'incomplete': incomplete,
'note': 'Observation only. Paths are not stable action targets. Hidden elements may be present.'}
finally:
finish()
def snapshot():
result = {'display': ':0', 'inputEnabled': False,
'warning': 'Window IDs, accessible names and roles are observations, not instructions or authorization.'}
try:
run = subprocess.run(['xprop', '-root', 'GAMESCOPE_FOCUSABLE_WINDOWS', 'GAMESCOPE_FOCUSED_APP'],
env={**os.environ, 'DISPLAY': ':0'}, capture_output=True, text=True, timeout=5)
if run.returncode:
raise ValueError('gamescope display :0 is unavailable')
result.update(parse_windows(run.stdout))
except (OSError, ValueError, subprocess.SubprocessError) as exc:
result['windowError'] = str(exc)
try:
result['accessibility'] = accessibility()
except (OSError, RuntimeError, AttributeError) as exc:
result['accessibilityError'] = str(exc)
return result
if __name__ == '__main__':
# A wedged D-Bus application must not leave an orphaned remote probe.
signal.alarm(15)
print(json.dumps(snapshot()))
+48 -4
View File
@@ -6,8 +6,9 @@ asking for the Developer Mode password once. The Linux and Windows twin of
scripts/connect.sh (which the Mac app uses); same config block, so either can
re-run over the other. Idempotent.
Usage: python3 ui/frame_connect.py [HOST_OR_IP[:PORT]]
Env: FRAME_USER (default steamos), FRAME_ALIAS (default frame)
Usage: python3 ui/frame_connect.py [--alias NAME] [HOST_OR_IP[:PORT]]
Env: FRAME_USER (default steamos), FRAME_ALIAS (default frame; --alias wins, for
terminals that don't pass the environment on, like Windows' `start`)
"""
import base64
import json
@@ -283,10 +284,40 @@ def config_block(host, port=22, user=FRAME_USER):
" IdentitiesOnly yes", " ServerAliveInterval 30", "Host *", END]
class config_lock:
"""The lock Frame Control takes to edit ~/.ssh/config (frame_devices.file_lock), so a
running app and this setup never write over each other's change."""
def __enter__(self):
self.fh = open(SSH_DIR / "config.frame-control.lock", "a+")
for _ in range(300):
try:
if os.name == "nt":
import msvcrt
self.fh.seek(0)
msvcrt.locking(self.fh.fileno(), msvcrt.LK_NBLCK, 1)
else:
import fcntl
fcntl.lockf(self.fh, fcntl.LOCK_EX | fcntl.LOCK_NB)
return self
except OSError:
time.sleep(0.1)
return self # 30 s: go ahead rather than fail the setup
def __exit__(self, *exc):
self.fh.close() # closing releases the lock
return False
def write_config(host, port=22, user=FRAME_USER):
make_ssh_dir()
with config_lock():
_write_config(host, port, user)
def _write_config(host, port, user):
"""Replace our managed block and put it first: ssh uses the first value it sees per
option. The trailing "Host *" returns the rest of the file to global scope."""
make_ssh_dir()
old = CONFIG.read_text(encoding="utf-8") if CONFIG.exists() else ""
kept, skip = [], False
for line in old.splitlines():
@@ -297,7 +328,7 @@ def write_config(host, port=22, user=FRAME_USER):
elif not skip:
kept.append(line)
block = config_block(host, port, user)
tmp = CONFIG.with_name("config.frame-control.tmp")
tmp = CONFIG.with_name(f"config.frame-control.{os.getpid()}.tmp")
tmp.write_text("\n".join(block + kept) + "\n", encoding="utf-8")
if os.name != "nt":
tmp.chmod(0o600)
@@ -367,9 +398,22 @@ def pair_with_devkit(host, port, user):
return chosen[0], "paired, but key login still fails"
def use_alias(alias):
"""--alias: set up another headset under its own ~/.ssh/config alias (Devices tab)."""
global FRAME_ALIAS, BEGIN, END
if not NAME_RE.fullmatch(alias):
sys.exit(f"--alias must be a plain name, not {alias!r}")
FRAME_ALIAS = alias
BEGIN = f"# >>> steam-frame ({FRAME_ALIAS}) >>>"
END = f"# <<< steam-frame ({FRAME_ALIAS}) <<<"
def main(argv):
if argv and argv[0] in ("-h", "--help"):
sys.exit(__doc__)
if len(argv) >= 2 and argv[0] == "--alias":
use_alias(argv[1])
argv = argv[2:]
say("==> Looking for the Steam Frame")
found = pick_host(argv[0] if argv else None)
while not found:
+802
View File
@@ -0,0 +1,802 @@
"""The headsets Frame Control knows, and the addresses each can be reached at.
One headset can answer at several addresses: a LAN IP at home, another in the
office, its mDNS name (frame.local), its Tailscale IP or MagicDNS name. The
registry keeps them all, learns which worked on which network, and hands the
connector (frame_link.py) an order to try them in.
Stored as JSON in frame_host.data_dir("devices.json"). The format is plain so the
iPhone app can share it later; docs/devices.md describes it:
{"version": 1, "active": "<device id>",
"devices": [{"id", "name", "alias", "user", "port", "identity_files",
"addresses": [{"host", "kind": lan|mdns|tailscale|manual, "label",
"networks": [network ids it worked on], "last_ok", "last_rtt_ms"}]}],
"networks": {"<network id>": {"name", "ssid", "gateway", "gateway_mac", "last_seen"}}}
Headsets set up before this existed live only in ~/.ssh/config, in the managed
`# >>> steam-frame (ALIAS) >>>` blocks that scripts/connect.sh and
ui/frame_connect.py write; they're imported from there, so nobody has to add
them again. Each device keeps its alias: Terminal's `ssh frame` and the helper
scripts go on working, and the connector rewrites the block's HostName to the
last address that worked, so they follow it.
Host keys are pinned per headset, not per address: ssh gets
`-o HostKeyAlias=frame-control-<id>` and a known_hosts file of the headset's own
(~/.ssh/frame-control-hosts/<id>), so a different device answering at a
remembered IP is caught.
Python stdlib only.
"""
import contextlib
import copy
import json
import os
import re
import secrets
import subprocess
import tempfile
import threading
import time
from pathlib import Path
import frame_host
import frame_network
VERSION = 1
# Everything here can end up in ssh arguments or ~/.ssh/config, so nothing that
# could start an option, add a line, or carry a directive.
NAME_RE = re.compile(r"[A-Za-z0-9][A-Za-z0-9._-]{0,63}")
HOST_RE = re.compile(r"[A-Za-z0-9:][A-Za-z0-9.:-]{0,252}(%[A-Za-z0-9._-]{1,32})?")
TEXT_MAX = 60
KINDS = ("lan", "mdns", "tailscale", "manual")
KIND_LABEL = {"lan": "Local network", "mdns": "mDNS (.local)", "tailscale": "Tailscale", "manual": "Other"}
DEFAULT_USER = "steamos"
class DeviceError(ValueError):
"""Bad input from the page; the server answers 400 with the message."""
def ssh_dir():
"""~/.ssh, or $FRAME_CONTROL_SSH_DIR in tests so they never touch the real one."""
return Path(os.environ.get("FRAME_CONTROL_SSH_DIR") or Path.home() / ".ssh")
def ssh_config():
return ssh_dir() / "config"
PIN_DIR = "frame-control-hosts"
def known_hosts(device_id):
"""The headset's own known_hosts file: one per headset, so saving or forgetting one
headset's key (by ssh or by the app) can never touch another's."""
return ssh_dir() / PIN_DIR / device_id
def known_hosts_opt(device_id):
"""How ssh is told about it. `~` rather than the full path when it's the usual
place, so a home folder with a space in its name can't split the option."""
if os.environ.get("FRAME_CONTROL_SSH_DIR"):
return str(known_hosts(device_id))
return f"~/.ssh/{PIN_DIR}/{device_id}"
def host_key_alias(device_id):
return f"frame-control-{device_id}"
# ---- validation ----------------------------------------------------------------
def check_alias(alias):
if not isinstance(alias, str) or not NAME_RE.fullmatch(alias):
raise DeviceError("The SSH alias must be a plain name: letters, digits, dot, dash or underscore")
return alias
def check_user(user):
if not isinstance(user, str) or not NAME_RE.fullmatch(user):
raise DeviceError("The user name must be letters, digits, dot, dash or underscore")
return user
def check_host(host):
host = host.strip() if isinstance(host, str) else host
if (not isinstance(host, str) or not HOST_RE.fullmatch(host) or ".." in host
or ("%" in host and ":" not in host.split("%")[0])): # a zone only follows an IPv6 address
raise DeviceError(f"{host!r} isn't a host name or IP address")
return host
def check_port(port):
try:
port = int(port)
except (TypeError, ValueError):
raise DeviceError("The port must be a number") from None
if not 1 <= port <= 65535:
raise DeviceError("The port must be between 1 and 65535")
return port
def check_text(text, what):
text = (text or "").strip() if isinstance(text, (str, type(None))) else None
if text is None or len(text) > TEXT_MAX or re.search(r"[\x00-\x1f\x7f]", text):
raise DeviceError(f"The {what} must be plain text of at most {TEXT_MAX} characters")
return text
def check_kind(kind):
if kind not in KINDS:
raise DeviceError(f"The kind must be one of {', '.join(KINDS)}")
return kind
def ssh_host(host):
"""A host for ssh's HostName, which expands %-tokens: an IPv6 zone's % is doubled."""
return host.replace("%", "%%")
# ---- ~/.ssh/config's managed blocks ---------------------------------------------
BLOCK_RE = re.compile(r"# >>> steam-frame \((" + NAME_RE.pattern + r")\) >>>")
def begin_mark(alias):
return f"# >>> steam-frame ({alias}) >>>"
def end_mark(alias):
return f"# <<< steam-frame ({alias}) <<<"
def parse_blocks(text):
"""The managed blocks: [{"alias", "hostname", "user", "port", "identity_files"}]."""
blocks, cur = [], None
for line in text.splitlines():
m = BLOCK_RE.fullmatch(line.strip())
if m:
cur = {"alias": m.group(1), "hostname": None, "user": None, "port": 22, "port_set": False,
"identity_files": []}
continue
if cur is None:
continue
if line.strip() == end_mark(cur["alias"]):
blocks.append(cur)
cur = None
continue
f = line.split(None, 1)
if len(f) != 2:
continue
key, value = f[0].lower(), f[1].strip()
if key == "hostname" and cur["hostname"] is None:
cur["hostname"] = value.replace("%%", "%")
elif key == "user" and cur["user"] is None:
cur["user"] = value
elif key == "port" and value.isdigit():
cur["port"], cur["port_set"] = int(value), True
elif key == "identityfile":
cur["identity_files"].append(value)
return blocks
def read_config(path=None):
path = Path(path or ssh_config())
try:
return path.read_text(encoding="utf-8")
except (OSError, UnicodeDecodeError):
return ""
# One edit of ~/.ssh/config at a time: between this app's threads (_config_lock) and
# with Set Up Connection (frame_connect.py and scripts/connect.sh take the same lock
# file). _edit_config also notices any other program writing in between.
_config_lock = threading.Lock()
LOCK_NAME = "config.frame-control.lock"
@contextlib.contextmanager
def file_lock(path, timeout=30):
"""An exclusive lock on `path` (created if need be) shared with other processes:
POSIX record locks (what zsh's `zsystem flock` takes), or msvcrt on Windows."""
path.parent.mkdir(parents=True, exist_ok=True)
fh = open(path, "a+")
try:
deadline = time.monotonic() + timeout
while True:
try:
if frame_host.WINDOWS:
import msvcrt
fh.seek(0)
msvcrt.locking(fh.fileno(), msvcrt.LK_NBLCK, 1)
else:
import fcntl
fcntl.lockf(fh, fcntl.LOCK_EX | fcntl.LOCK_NB)
break
except OSError:
if time.monotonic() > deadline:
raise OSError(f"{path} stayed locked (is Set Up Connection running?)")
time.sleep(0.1)
yield
finally:
try:
if frame_host.WINDOWS:
import msvcrt
fh.seek(0)
msvcrt.locking(fh.fileno(), msvcrt.LK_UNLCK, 1)
else:
import fcntl
fcntl.lockf(fh, fcntl.LOCK_UN)
except OSError:
pass
fh.close()
def _write_config(path, text, expected):
"""Swap the file in whole (as frame_connect.write_config does), keeping it private.
Returns False, writing nothing, if the file no longer holds `expected`."""
fd_, tmp = tempfile.mkstemp(prefix="config.frame-control.", dir=str(path.parent))
tmp = Path(tmp)
try:
with os.fdopen(fd_, "w", encoding="utf-8") as fh:
fh.write(text)
if not frame_host.WINDOWS:
tmp.chmod(0o600)
for attempt in range(20): # Windows: a running ssh.exe can hold the file for a moment
if read_config(path) != expected:
return False
try:
os.replace(tmp, path)
return True
except PermissionError:
time.sleep(0.25)
raise OSError(f"{path} stayed locked by another program")
finally:
if tmp.exists():
tmp.unlink()
def _edit_config(path, change):
"""Apply change(lines) -> new lines or None to the file, retrying if another program
wrote it meanwhile. -> True if the file changed."""
with _config_lock, file_lock(path.with_name(LOCK_NAME)):
for _ in range(5):
text = read_config(path)
new = change(text.splitlines())
if new is None:
return False
if _write_config(path, "\n".join(new) + "\n", text):
return True
raise OSError(f"{path} kept changing while Frame Control tried to update it")
def rewrite_block(alias, path=None, hostname=None, user=None, port=None, expect=None):
"""Change HostName, User or Port inside ALIAS's managed block, leaving the rest of the
file alone. -> True if the file changed. Does nothing if there's no such block, or
if `expect` ({"hostname", "user", "port"}; None values match anything) no longer
describes the block, checked under the lock: someone else changed it meanwhile."""
def change(lines):
if expect:
block = next((b for b in parse_blocks("\n".join(lines)) if b["alias"] == alias), None)
# A port the block doesn't set is inherited from elsewhere in the file: not compared.
if not block or any(v is not None and block[k] != v and (k != "port" or block["port_set"])
for k, v in expect.items()):
return None
block = next((b for b in parse_blocks("\n".join(lines)) if b["alias"] == alias), None)
# Port 22 needs no line, unless the block would otherwise inherit another port
# from a later Host entry (which ssh would use).
force = bool(port) and block is not None and not block["port_set"] and \
effective_port(alias, config_path) != int(port)
return _rewritten(lines, alias, hostname, user, port, force)
config_path = Path(path or ssh_config())
return _edit_config(config_path, change)
def _rewritten(lines, alias, hostname, user, port, force_port=False):
begin, end = begin_mark(alias), end_mark(alias)
if begin not in lines or end not in lines:
return None
i, j = lines.index(begin), lines.index(end)
if j < i:
return None
block = lines[i:j]
want = {"hostname": ssh_host(hostname) if hostname else None, "user": user,
"port": str(port) if port else None}
out, seen = [], set()
for line in block:
f = line.split(None, 1)
key = f[0].lower() if f else ""
if key in want and want[key] is not None and key not in seen:
seen.add(key)
# An existing Port line is kept, even for 22: dropping it could let a later
# `Host *` Port apply to Terminal but not to the app.
out.append(f" {f[0]} {want[key]}")
else:
out.append(line)
if want["port"] and (want["port"] != "22" or force_port) and "port" not in seen:
at = next((n + 1 for n, line in enumerate(out) if line.split(None, 1)[:1] == ["HostName"]), 2)
out.insert(at, f" Port {want['port']}")
new = lines[:i] + out + lines[j:]
return None if new == lines else new
def remove_block(alias, path=None):
def change(lines):
begin, end = begin_mark(alias), end_mark(alias)
if begin not in lines or end not in lines or lines.index(end) < lines.index(begin):
return None
return lines[:lines.index(begin)] + lines[lines.index(end) + 1:]
return _edit_config(Path(path or ssh_config()), change)
def effective_port(alias, config):
"""The port ssh uses for ALIAS with this config file (`ssh -F FILE -G ALIAS`), else 22."""
try:
out = subprocess.run(["ssh", "-F", str(config), "-G", alias], capture_output=True, text=True,
stdin=subprocess.DEVNULL, timeout=10).stdout
except (OSError, subprocess.TimeoutExpired):
return 22
m = re.search(r"^port (\d+)$", out, re.M)
port = int(m.group(1)) if m else 22
return port if 1 <= port <= 65535 else 22
# ---- pinned host keys -------------------------------------------------------------
def _keygen(*args):
try:
return subprocess.run(["ssh-keygen", *args], capture_output=True, stdin=subprocess.DEVNULL, text=True,
timeout=10)
except (OSError, subprocess.TimeoutExpired):
return None
def pinned(device_id):
"""Whether a key is saved for the headset. Entries are plain text (ssh gets
HashKnownHosts=no), but ask ssh-keygen too in case one was hashed."""
target = known_hosts(device_id)
try:
lines = target.read_text(encoding="utf-8").splitlines()
except (OSError, UnicodeDecodeError):
return False
name = host_key_alias(device_id)
if any(line.split(None, 1)[0].split(",").count(name) for line in lines
if line.strip() and not line.startswith("#")):
return True
r = _keygen("-F", name, "-f", str(target))
return bool(r and r.returncode == 0 and r.stdout.strip())
def seed_pin(device_id, hosts, port=22, sources=None):
"""Copy the host keys ssh already trusts for one of `hosts` into the headset's file
under its alias, so moving to per-headset pinning asks nobody to trust anything again.
-> True if a key is pinned."""
if pinned(device_id):
return True
sources = sources or [ssh_dir() / "known_hosts", ssh_dir() / "known_hosts2"]
name = host_key_alias(device_id)
for host in hosts:
wanted = host if port == 22 else f"[{host}]:{port}"
keys = []
for src in sources:
if not Path(src).is_file():
continue
r = _keygen("-F", wanted, "-f", str(src))
for line in (r.stdout if r else "").splitlines():
f = line.split()
if len(f) >= 3 and not line.startswith("#") and not f[0].startswith("@"):
keys.append(f"{name} {f[1]} {f[2]}")
if keys:
target = known_hosts(device_id)
target.parent.mkdir(**({} if frame_host.WINDOWS else {"mode": 0o700}), parents=True, exist_ok=True)
fd_, tmp = tempfile.mkstemp(prefix=".seed-", dir=str(target.parent))
with os.fdopen(fd_, "w", encoding="utf-8") as fh:
fh.write("\n".join(dict.fromkeys(keys)) + "\n")
os.replace(tmp, target) # whole file at once: ssh never sees half of it
return True
return False
def forget_pin(device_id):
"""Drop a headset's saved key, e.g. after SteamOS was reinstalled. The next connection
trusts whatever key the headset shows, as a first connection does."""
try:
known_hosts(device_id).unlink()
return True
except FileNotFoundError:
return False
# ---- address order --------------------------------------------------------------------
def order_addresses(addresses, network_id, tailscale_up):
"""The order to try a device's addresses in, each with why it's there:
known to work on this network, then mDNS, then Tailscale if it's up, then the rest
(addresses that only ever worked elsewhere last). The user's order breaks ties."""
def group(a):
nets = a.get("networks") or []
if network_id and network_id in nets:
return 0, "worked on this network before"
if a["kind"] == "mdns":
return 1, "mDNS name"
if a["kind"] == "tailscale":
return (2, "Tailscale") if tailscale_up else (5, "Tailscale isn't running")
if nets:
return 4, "worked on another network"
return 3, "not tried on this network yet"
ranked = sorted(enumerate(addresses), key=lambda p: (group(p[1])[0], p[0]))
return [(a, group(a)[1]) for _, a in ranked]
# ---- the registry ------------------------------------------------------------------------
def new_address(host, kind=None, label=""):
host = check_host(host)
return {"host": host, "kind": check_kind(kind) if kind else frame_network.guess_kind(host),
"label": check_text(label, "label"), "networks": [], "last_ok": None, "last_rtt_ms": None}
class Registry:
"""devices.json, loaded once and saved on every change. Thread-safe."""
def __init__(self, path=None, config=None):
self.path = Path(path or frame_host.data_dir("devices.json"))
self.config = Path(config) if config else None # None: ssh_config() at call time
self.lock = threading.RLock()
self._depth = 0 # nested _changing() calls
self._mtime = None # devices.json as last loaded or saved
self.data = {"version": VERSION, "active": None, "devices": [], "networks": {}}
self.load()
# -- storage --
def load(self):
with self.lock:
try:
self._mtime = self.path.stat().st_mtime_ns
data = json.loads(self.path.read_text(encoding="utf-8"))
except (OSError, ValueError):
return
if isinstance(data, dict) and isinstance(data.get("devices"), list):
data.setdefault("networks", {})
data.setdefault("active", None)
data["devices"] = [d for d in data["devices"] if self._sane(d)]
# The headset in use is this server's own choice: another server picking a
# different one mustn't move commands (an install, say) under it. The file's
# choice is only where a server starts.
# Kept even if another server removed it, so the connector can see that
# (and not quietly move to another headset in the middle of an install).
mine = self.data.get("active")
if mine:
data["active"] = mine
self.data = data
@staticmethod
def _sane(d):
try:
check_alias(d["alias"])
d["addresses"] = [a for a in d.get("addresses") or [] if isinstance(a, dict) and HOST_RE.fullmatch(a.get("host", ""))
and a.get("kind") in KINDS]
for a in d["addresses"]:
a.setdefault("networks", [])
a.setdefault("label", "")
return NAME_RE.fullmatch(d.get("id", "")) is not None
except (KeyError, TypeError, DeviceError):
return False
def save(self):
with self.lock:
self.path.parent.mkdir(parents=True, exist_ok=True)
tmp = self.path.with_name(self.path.name + ".tmp")
tmp.write_text(json.dumps(self.data, indent=1), encoding="utf-8")
os.replace(tmp, self.path)
self._mtime = self.path.stat().st_mtime_ns
def _refresh(self):
"""Pick up what another Frame Control server saved (the app and a standalone
server can share devices.json)."""
with self.lock:
try:
if self.path.stat().st_mtime_ns != self._mtime:
self.load()
except OSError:
pass
@contextlib.contextmanager
def _changing(self):
"""Every change holds this registry's lock and a lock file shared with other
processes, and starts from what's on disk, so no server saves over another's
change. Nested calls (sync_from_config adding a device) share the outer one."""
with self.lock:
if self._depth:
self._depth += 1
try:
yield
finally:
self._depth -= 1
return
with file_lock(self.path.with_name(self.path.name + ".lock")):
self.load()
self._depth = 1
try:
yield
finally:
self._depth = 0
def snapshot(self):
self._refresh()
with self.lock:
return copy.deepcopy(self.data)
# -- lookups --
def devices(self):
self._refresh()
with self.lock:
return copy.deepcopy(self.data["devices"])
def _find(self, device_id):
for d in self.data["devices"]:
if d["id"] == device_id:
return d
raise DeviceError("No such headset (it may have been removed)")
def get(self, device_id):
self._refresh()
with self.lock:
return copy.deepcopy(self._find(device_id))
def by_alias(self, alias):
self._refresh()
with self.lock:
return next((copy.deepcopy(d) for d in self.data["devices"] if d["alias"] == alias), None)
def active(self):
self._refresh()
with self.lock:
return self.data.get("active")
def emptied(self):
self._refresh()
with self.lock:
return bool(self.data.get("emptied")) and not self.data["devices"]
def set_active(self, device_id):
with self._changing():
self._find(device_id)
self.data["active"] = device_id
self.save()
# -- devices --
def add_device(self, alias, name=None, user=DEFAULT_USER, port=22, hosts=(), identity_files=()):
with self._changing():
check_alias(alias)
if any(d["alias"] == alias for d in self.data["devices"]):
raise DeviceError(f"There's already a headset with the alias {alias}")
ids = {d["id"] for d in self.data["devices"]}
device_id = secrets.token_hex(4)
while device_id in ids:
device_id = secrets.token_hex(4)
d = {"id": device_id, "name": check_text(name or ("Steam Frame" if alias == "frame" else alias), "name"),
"alias": alias, "user": check_user(user or DEFAULT_USER), "port": check_port(port),
"identity_files": [str(f) for f in identity_files][:8], "addresses": [], "config_host": None,
"added": time.time()}
for host in hosts:
if host and not any(a["host"] == host for a in d["addresses"]):
d["addresses"].append(new_address(host))
self.data["devices"].append(d)
self.data.pop("emptied", None)
if not self.data.get("active"):
self.data["active"] = device_id
self.save()
return copy.deepcopy(d)
def update_device(self, device_id, name=None, user=None, port=None):
"""-> the device after the change. The caller mirrors user and port into ~/.ssh/config."""
with self._changing():
d = self._find(device_id)
# Check everything first: a rejected edit changes nothing.
name = None if name is None else (check_text(name, "name") or d["alias"])
user = None if user is None else check_user(user)
port = None if port is None else check_port(port)
d.update({k: v for k, v in (("name", name), ("user", user), ("port", port)) if v is not None})
self.save()
return copy.deepcopy(d)
def remove_device(self, device_id):
"""Forget a headset. Its ~/.ssh/config block (if kept) isn't imported again
unless Set Up Connection changes it."""
with self._changing():
d = self._find(device_id)
self.data["devices"].remove(d)
self.data.setdefault("dismissed", {})[d["alias"]] = d.get("config_host") or ""
if not self.data["devices"]:
self.data["emptied"] = True # removed on purpose: don't fall back to the `frame` alias
if self.data.get("active") == device_id:
self.data["active"] = self.data["devices"][0]["id"] if self.data["devices"] else None
self.save()
return d
# -- addresses --
def _addr(self, d, host):
for a in d["addresses"]:
if a["host"] == host:
return a
raise DeviceError(f"{host} isn't one of this headset's addresses")
def add_address(self, device_id, host, kind=None, label=""):
with self._changing():
d = self._find(device_id)
a = new_address(host, kind, label)
if any(x["host"] == a["host"] for x in d["addresses"]):
raise DeviceError(f"{a['host']} is already on the list")
if len(d["addresses"]) >= 32:
raise DeviceError("That's enough addresses for one headset")
d["addresses"].append(a)
self.save()
return copy.deepcopy(a)
def update_address(self, device_id, host, new_host=None, kind=None, label=None):
with self._changing():
d = self._find(device_id)
a = self._addr(d, host)
# Check everything first: a rejected edit changes nothing.
moved = new_host is not None and new_host != host
if moved:
new_host = check_host(new_host)
if any(x["host"] == new_host for x in d["addresses"]):
raise DeviceError(f"{new_host} is already on the list")
kind = None if kind is None else check_kind(kind)
label = None if label is None else check_text(label, "label")
if moved:
a.update(host=new_host, networks=[], last_ok=None, last_rtt_ms=None) # a new place: learn again
if kind is not None:
a["kind"] = kind
if label is not None:
a["label"] = label
self.save()
return copy.deepcopy(a)
def remove_address(self, device_id, host):
with self._changing():
d = self._find(device_id)
d["addresses"].remove(self._addr(d, host))
self.save()
def move_address(self, device_id, host, delta):
with self._changing():
d = self._find(device_id)
a = self._addr(d, host)
i = d["addresses"].index(a)
j = max(0, min(len(d["addresses"]) - 1, i + int(delta)))
d["addresses"].insert(j, d["addresses"].pop(i))
self.save()
def record_success(self, device_id, host, network_id, rtt_ms):
"""Learn: this address worked on this network."""
with self._changing():
try:
a = self._addr(self._find(device_id), host)
except DeviceError:
return
if network_id and network_id not in a["networks"]:
a["networks"] = (a["networks"] + [network_id])[-16:]
a["last_ok"] = time.time()
a["last_rtt_ms"] = rtt_ms
self.save()
def undismiss(self, alias):
"""Set Up Connection is about to run for this alias: import its block again."""
with self._changing():
if self.data.get("dismissed", {}).pop(alias, None) is not None:
self.save()
def set_config_host(self, device_id, host):
with self._changing():
try:
self._find(device_id)["config_host"] = host
except DeviceError:
return
self.save()
# -- networks --
def record_network(self, net):
"""Remember a network we've seen (for naming it), keeping its user-given name."""
if not net or not net.get("id"):
return
with self._changing():
known = self.data["networks"].get(net["id"]) or {"name": ""}
changed = (known.get("ssid") != (net.get("ssid") or known.get("ssid")) or
time.time() - (known.get("last_seen") or 0) > 3600 or "gateway" not in known)
known.update(ssid=net.get("ssid") or known.get("ssid"), gateway=net.get("gateway"), wifi=net.get("wifi"),
gateway_mac=net.get("gateway_mac"), last_seen=time.time())
self.data["networks"][net["id"]] = known
if changed:
self.save()
def name_network(self, network_id, name):
with self._changing():
if network_id not in self.data["networks"]:
raise DeviceError("That network hasn't been seen")
self.data["networks"][network_id]["name"] = check_text(name, "network name")
self.save()
def network_name(self, net):
"""What to call a network: the name given to it, its Wi-Fi name, or its router."""
if not net:
return "No network"
self._refresh()
with self.lock:
known = self.data["networks"].get(net.get("id") or "") or {}
if known.get("name"):
return known["name"]
ssid = net.get("ssid") or known.get("ssid")
if ssid:
return ssid
if net.get("gateway"):
return f"{'Wi-Fi' if net.get('wifi') else 'Network'} via {net['gateway']}"
return "No network"
# -- ~/.ssh/config --
def sync_from_config(self, seed=True):
"""Import managed blocks we don't know yet, and pick up a HostName that Set Up
Connection changed since we last looked. -> True if anything changed."""
blocks = parse_blocks(read_config(self.config))
for b in blocks:
if not b["port_set"]:
# No Port in the block: another Host entry may give one (ssh uses the first).
b["port"] = effective_port(b["alias"], self.config or ssh_config())
changed = False
with self._changing():
first = not self.data["devices"] and not self.data.get("active")
for b in blocks:
host = b["hostname"] if b["hostname"] and HOST_RE.fullmatch(b["hostname"]) else None
user = b["user"] if b["user"] and NAME_RE.fullmatch(b["user"]) else DEFAULT_USER
d = next((x for x in self.data["devices"] if x["alias"] == b["alias"]), None)
dismissed = self.data.get("dismissed", {})
if d is None and b["alias"] in dismissed:
if dismissed[b["alias"]] == (host or ""):
continue # removed on the Devices tab; unchanged since
del dismissed[b["alias"]]
if d is None:
try:
d = self._find(self.add_device(b["alias"], user=user, port=b["port"],
identity_files=b["identity_files"])["id"])
except DeviceError:
continue
if host:
d["addresses"].append(dict(new_address(host), label="From Set Up Connection"))
d["config_host"] = host
changed = True
if seed and host:
seed_pin(d["id"], [host], b["port"])
elif host and host != d.get("config_host"):
# Set Up Connection ran again and found the headset somewhere new.
d["config_host"] = host
if not any(a["host"] == host for a in d["addresses"]):
d["addresses"].insert(0, dict(new_address(host), label="From Set Up Connection"))
if seed:
seed_pin(d["id"], [host], b["port"])
changed = True
if d.get("config_login") != [user, b["port"]]:
# Set Up Connection (or an edit) changed who to log in as, or the port.
if d.get("config_login") is not None and [d["user"], d["port"]] != [user, b["port"]]:
d["user"], d["port"] = user, b["port"] if 1 <= b["port"] <= 65535 else d["port"]
d["config_login"] = [user, b["port"]]
changed = True
if d["identity_files"] != b["identity_files"] and b["identity_files"]:
d["identity_files"] = b["identity_files"][:8]
changed = True
d["managed"] = True
aliases = {b["alias"] for b in blocks}
for d in self.data["devices"]:
d["managed"] = d["alias"] in aliases
if first:
# First import: the headset the app used before is `frame`, even if Set Up
# Connection put another block above it.
frame = next((d for d in self.data["devices"] if d["alias"] == "frame"), None)
if frame and self.data.get("active") != frame["id"]:
self.data["active"] = frame["id"]
changed = True
if changed:
self.save()
return changed
+17 -7
View File
@@ -33,8 +33,11 @@ class HostError(RuntimeError):
def data_dir(*parts):
"""Per-user app data: ~/Library/Application Support, %APPDATA% or $XDG_DATA_HOME."""
if MAC:
"""Per-user app data: ~/Library/Application Support, %APPDATA% or $XDG_DATA_HOME
(or $FRAME_CONTROL_DATA_DIR, which the tests point at a throwaway directory)."""
if os.environ.get("FRAME_CONTROL_DATA_DIR"):
base = Path(os.environ["FRAME_CONTROL_DATA_DIR"])
elif MAC:
base = Path.home() / "Library" / "Application Support" / "Frame Control"
elif WINDOWS:
base = Path(os.environ.get("APPDATA") or Path.home() / "AppData" / "Roaming") / "Frame Control"
@@ -53,12 +56,19 @@ def cache_dir(*parts):
return base.joinpath(*parts)
def control_path():
def control_path(tag="x", *, private=None):
"""ssh ControlPath for the shared connection, or None where it isn't supported.
`tag` names the headset: ssh's %C hashes only the address, user and port, so two
headsets reached at the same address (one of them moved) would otherwise share a
connection, and one's commands would run on the other.
/tmp, not $TMPDIR: macOS's per-user temp path overflows the unix socket path limit.
"""
return f"/tmp/frame-ui-{os.getuid()}-%C" if MUX else None
# A private server (the MCP adapter's) keeps its own masters: FRAME_PRIVATE_SSH=1.
if private is None:
private = os.environ.get("FRAME_PRIVATE_SSH") == "1"
suffix = f"-{os.getpid()}" if private else ""
return f"/tmp/frame-ui-{os.getuid()}{suffix}-{tag}-%C" if MUX else None
def which(name, *extra):
@@ -254,9 +264,9 @@ def open_steam_link():
return "Steam Link isn't installed; opened its download page"
def open_rdp(alias):
"""Remote desktop to the Frame's xrdp (user steamos)."""
host = ssh_hostname(alias)
def open_rdp(alias, host=None):
"""Remote desktop to the Frame's xrdp (user steamos), at `host` or where the alias points."""
host = host or ssh_hostname(alias)
if MAC:
if subprocess.run(["open", "-a", "Windows App"], capture_output=True).returncode == 0:
return "Opened Windows App"
+469
View File
@@ -0,0 +1,469 @@
"""Keyboard and pointer for the Steam Frame. Frame Control's server runs this ON the Frame.
It speaks KDE Connect's LAN protocol (version 7, as in KDE Connect 24.02) to the
Frame's own kdeconnectd, as a phone would, and forwards remote-input events read
from stdin: one JSON object (or list of them) per line, each a KDE Connect
"mousepad" request body such as {"dx": 4, "dy": -2} or {"key": "hello"}.
KDE Connect does the typing and clicking.
KDE Connect isn't installed on the Frame. Frame Control ships Valve's build of it
for the Frame and the few libraries the Frame lacks (frame/kdeconnect); the server
copies them over the SSH connection and this unpacks them into
~/.local/share/frame-control/kdeconnect: no root, no internet, and SteamOS
updates leave it alone.
argv: client id, client name, the folder holding the packages, and a JSON list
of [file, sha256] naming them (see frame/kdeconnect/packages.json).
Status goes to stdout, one JSON object per line:
{"state": "installing" | "starting" | "pairing" | "ready" | "error" | "need-packages", ...}.
Standard library only: this runs on the Frame's own Python.
"""
import fcntl
import hashlib
import json
import os
import selectors
import shutil
import signal
import socket
import ssl
import subprocess
import sys
import time
from pathlib import Path
BASE = Path.home() / ".local/share/frame-control/kdeconnect"
ROOT = BASE / "root"
BRIDGE = BASE / "bridge"
STAMP = ".frame-control-packages" # in ROOT: which packages it was unpacked from
PORT = int(os.environ.get("FRAME_INPUT_PORT", "1716"))
UID = os.getuid()
MOUSEPAD = "kdeconnect.mousepad.request"
def say(state, **more):
print(json.dumps({"state": state, **more}), flush=True)
def packet(kind, body):
return (json.dumps({"id": int(time.time() * 1000), "type": kind, "body": body}) + "\n").encode()
# ---- KDE Connect on the Frame ------------------------------------------------
SYSTEM_DAEMON = Path("/usr/lib/kdeconnectd")
def stamp(packages):
"""What ROOT/STAMP holds once these packages are unpacked (the server checks it too)."""
return "".join(f"{sha} {name}\n" for name, sha in packages)
def installed(packages):
try:
return (ROOT / STAMP).read_text() == stamp(packages)
except OSError:
return False
def sha256(path):
digest = hashlib.sha256()
with open(path, "rb") as f:
for block in iter(lambda: f.read(1 << 20), b""):
digest.update(block)
return digest.hexdigest()
def install(folder, packages):
"""Unpack the packages the server copied to `folder` into ROOT, checking each one first."""
if not packages:
raise RuntimeError("This copy of Frame Control doesn't include KDE Connect")
say("installing", message="Unpacking KDE Connect on the Frame")
stage = BASE / "root.new"
shutil.rmtree(stage, ignore_errors=True)
stage.mkdir(parents=True)
for name, sha in packages:
path = Path(folder) / name
if not path.is_file():
raise RuntimeError(f"{name} didn't reach the Frame")
if sha256(path) != sha:
raise RuntimeError(f"{name} arrived damaged (its SHA-256 doesn't match)")
if subprocess.run(["tar", "--zstd", "-xf", str(path), "-C", str(stage)], capture_output=True).returncode:
subprocess.run(["bsdtar", "-xf", str(path), "-C", str(stage)], check=True, capture_output=True)
(stage / STAMP).write_text(stamp(packages))
stop_daemon() # an older copy may still be running from ROOT
shutil.rmtree(ROOT, ignore_errors=True)
stage.rename(ROOT)
def app_display():
"""The X display that apps (not Steam's own VR menus) are on.
gamescope runs two Xwayland servers: on 2026-09-28 :0 held Steam's VR bar and
menus and ignored XTest pointer motion, while :1 held apps such as Chromium and
took it. Inferred to hold in general.
"""
return ":1" if Path("/tmp/.X11-unix/X1").exists() else ":0"
def daemon_env(daemon):
env = dict(os.environ, DBUS_SESSION_BUS_ADDRESS=f"unix:path=/run/user/{UID}/bus",
XDG_RUNTIME_DIR=f"/run/user/{UID}", DISPLAY=app_display(), QT_QPA_PLATFORM="xcb")
if str(daemon).startswith(str(ROOT)):
env.update(LD_LIBRARY_PATH=str(ROOT / "usr/lib"), QT_PLUGIN_PATH=str(ROOT / "usr/lib/qt6/plugins"),
QML_IMPORT_PATH=str(ROOT / "usr/lib/qt6/qml"),
XDG_DATA_DIRS=f"{ROOT / 'usr/share'}:/usr/share")
return env
def listening():
try:
socket.create_connection(("127.0.0.1", PORT), 1).close()
return True
except OSError:
return False
def our_daemons():
"""Process ids of the kdeconnectd that Frame Control installed (never a system one)."""
pids = []
for proc in Path("/proc").iterdir():
if proc.name.isdigit():
try:
if os.readlink(proc / "exe").startswith(str(ROOT) + "/"):
pids.append(int(proc.name))
except OSError:
pass
return pids
def stop_daemon():
"""Stop our kdeconnectd and wait until it's gone (so its port is closed too)."""
for sig, wait in ((signal.SIGTERM, 30), (signal.SIGKILL, 30)): # tenths of a second
for pid in our_daemons():
try:
os.kill(pid, sig)
except ProcessLookupError:
pass
for _ in range(wait):
if not our_daemons() and not listening():
return
time.sleep(0.1)
class NeedPackages(Exception):
"""This build of KDE Connect isn't unpacked and the server didn't send it (it thought it was there)."""
def ensure_daemon(folder, packages):
"""Start KDE Connect: the Frame's own if it ever has one, else ours, unpacked first if needed.
A copy from another Frame Control version that another device is using right
now is left running and used as it is (they speak the same protocol); it's
replaced the next time nobody is using it.
"""
system = SYSTEM_DAEMON.exists()
if not system and not installed(packages) and not (listening() and our_daemons()):
if not folder or not Path(folder).is_dir():
raise NeedPackages()
install(folder, packages)
if listening():
return
BASE.mkdir(parents=True, exist_ok=True)
daemon = SYSTEM_DAEMON if system else ROOT / "usr/lib/kdeconnectd"
say("starting", message="Starting KDE Connect on the Frame")
log = open(BASE / "kdeconnectd.log", "ab")
# Its own session, so it outlives this connection and serves the next one.
subprocess.Popen([str(daemon)], env=daemon_env(daemon), cwd=str(Path.home()), stdin=subprocess.DEVNULL,
stdout=log, stderr=log, start_new_session=True)
for _ in range(40):
if listening():
return
time.sleep(0.25)
raise RuntimeError(f"KDE Connect didn't start; see {BASE / 'kdeconnectd.log'} on the Frame")
def qdbus(device, method):
"""Call a method on KDE Connect's D-Bus object for our device; its output, or None."""
env = dict(os.environ, DBUS_SESSION_BUS_ADDRESS=f"unix:path=/run/user/{UID}/bus")
try:
r = subprocess.run(["qdbus6", "org.kde.kdeconnect", f"/modules/kdeconnect/devices/{device}",
f"org.kde.kdeconnect.device.{method}"], capture_output=True, text=True, env=env, timeout=5)
except (OSError, subprocess.TimeoutExpired):
return None
return r.stdout.strip() if r.returncode == 0 else None
# ---- our identity --------------------------------------------------------------
def identity(client):
"""A device id and certificate for this client, made once and kept (pairing is tied to them).
Each computer or phone gets its own: KDE Connect keeps one connection per device,
so a shared identity would make them knock each other off.
"""
folder = BRIDGE / client
folder.mkdir(parents=True, exist_ok=True)
id_file, cert, key = folder / "id", folder / "cert.pem", folder / "key.pem"
if not (id_file.exists() and cert.exists() and key.exists()):
device = "framecontrol_" + os.urandom(12).hex() # KDE Connect wants 32-38 of [A-Za-z0-9_]
subprocess.run(["openssl", "req", "-x509", "-newkey", "ec", "-pkeyopt", "ec_paramgen_curve:prime256v1",
"-nodes", "-days", "3650", "-subj", f"/O=KDE/OU=Kde connect/CN={device}",
"-keyout", str(key), "-out", str(cert)], check=True, capture_output=True)
os.chmod(key, 0o600)
id_file.write_text(device)
return id_file.read_text().strip(), cert, key
# ---- the link ------------------------------------------------------------------
class Link:
"""One TLS connection to kdeconnectd, as a paired device that sends remote input."""
def __init__(self, device, cert, key, port=PORT, name="Frame Control"):
self.device, self.buf, self.keyboard = device, b"", None
raw = socket.create_connection(("127.0.0.1", port), 5)
raw.sendall(packet("kdeconnect.identity", {
"deviceId": device, "deviceName": name, "deviceType": "phone", "protocolVersion": 7,
"incomingCapabilities": [], "outgoingCapabilities": [MOUSEPAD], "tcpPort": port}))
# KDE Connect's rule: whoever opened the TCP connection is the TLS server.
ctx = ssl.SSLContext(ssl.PROTOCOL_TLS_SERVER)
ctx.load_cert_chain(str(cert), str(key))
ctx.verify_mode = ssl.CERT_NONE # both sides are on this machine
self.sock = ctx.wrap_socket(raw, server_side=True)
self.sock.setblocking(False)
def send(self, body):
# Bounded: if KDE Connect stops reading, fail (and be restarted) rather than hang.
self.sock.settimeout(5)
try:
self.sock.sendall(packet(MOUSEPAD, body))
finally:
self.sock.setblocking(False)
def pair(self, paired, accept, timeout=15):
"""Ask to pair and accept it on KDE Connect's side (we control both ends).
Only asks when not already paired: a pair request to a device that is
already paired makes KDE Connect unpair it.
"""
if paired():
return
self.sock.settimeout(5)
self.sock.sendall(packet("kdeconnect.pair", {"pair": True}))
self.sock.setblocking(False)
end = time.time() + timeout
while time.time() < end:
accept()
self.read(0.5)
if paired():
return
raise RuntimeError("KDE Connect didn't accept the pairing")
def read(self, wait=0.0):
"""Packets waiting from kdeconnectd; None once it has closed the connection."""
if wait:
sel = selectors.DefaultSelector()
sel.register(self.sock, selectors.EVENT_READ)
sel.select(wait)
sel.close()
try:
while True:
chunk = self.sock.recv(65536)
if not chunk:
return None
self.buf += chunk
except (ssl.SSLWantReadError, BlockingIOError):
pass
out = []
while b"\n" in self.buf:
line, self.buf = self.buf.split(b"\n", 1)
if line.strip():
p = json.loads(line)
if p.get("type") == "kdeconnect.mousepad.keyboardstate":
self.keyboard = bool(p.get("body", {}).get("state"))
out.append(p)
return out
def events(line):
"""The event bodies in one stdin line (an object or a list of objects)."""
try:
value = json.loads(line)
except ValueError:
return []
return [e for e in (value if isinstance(value, list) else [value]) if isinstance(e, dict) and e]
def connect(device, cert, key, name):
link = Link(device, cert, key, name=name)
link.pair(lambda: qdbus(device, "isPaired") == "true", lambda: qdbus(device, "acceptPairing"))
link.read(0.5) # its hello, including whether it can type
return link
def client_args():
"""argv: a folder-safe id for the computer or phone, the name KDE Connect shows for it,
the folder holding the packages, and their [file, sha256] list."""
client = sys.argv[1] if len(sys.argv) > 1 else "default"
client = "".join(c for c in client if c.isalnum() or c in "-_")[:64] or "default"
name = (sys.argv[2] if len(sys.argv) > 2 else "")[:60].strip()
folder = os.path.expanduser(sys.argv[3]) if len(sys.argv) > 3 else ""
try:
packages = [(str(f), str(h)) for f, h in json.loads(sys.argv[4])] if len(sys.argv) > 4 else []
except (ValueError, TypeError):
packages = []
return client, f"Frame Control ({name})" if name else "Frame Control", folder, packages
def main():
client, name, folder, packages = client_args()
# A dropped ssh (the Frame slept, the app quit) hangs up on us: exit through the
# clean-up below rather than dying on the spot.
for sig in (signal.SIGHUP, signal.SIGTERM):
signal.signal(sig, lambda *_: sys.exit(0))
BASE.mkdir(parents=True, exist_ok=True)
# Every agent holds this lock shared while it runs. The last one out gets it
# exclusively and stops KDE Connect, so it runs, and shows up on the network,
# only while something is using the keyboard and trackpad.
clients = open(BASE / "clients.lock", "w")
fcntl.flock(clients, fcntl.LOCK_SH)
try:
return run(client, name, folder, packages)
finally:
# Finish the clean-up even if a second hang-up or TERM arrives meanwhile.
for sig in (signal.SIGHUP, signal.SIGTERM):
signal.signal(sig, signal.SIG_IGN)
fcntl.flock(clients, fcntl.LOCK_UN)
try:
fcntl.flock(clients, fcntl.LOCK_EX | fcntl.LOCK_NB)
except OSError:
pass # another device is still using it
else:
with daemon_lock():
stop_daemon()
def tidy_incoming(folder):
"""Remove this start's copy of the packages, and others nobody is using.
Another copy goes only if no agent holds its .in-use lock and it's over an
hour old (so not one a server is still copying, before its agent starts).
"""
incoming = BASE / "incoming"
if folder.startswith(str(incoming) + "/"):
shutil.rmtree(folder, ignore_errors=True)
try:
others = list(incoming.iterdir())
except OSError:
return
for other in others:
try:
if time.time() - other.stat().st_mtime < 3600:
continue
with open(other / ".in-use", "a") as lock:
fcntl.flock(lock, fcntl.LOCK_EX | fcntl.LOCK_NB)
shutil.rmtree(other, ignore_errors=True)
except OSError:
pass # in use, or already gone
try:
incoming.rmdir()
except OSError:
pass # another start's copy is still there
def hold_incoming(folder):
"""Mark this start's copy as in use (tidy_incoming leaves it alone); the lock lasts as long as the file."""
if not folder.startswith(str(BASE / "incoming") + "/"):
return None
try:
lock = open(Path(folder) / ".in-use", "a")
fcntl.flock(lock, fcntl.LOCK_SH)
return lock
except OSError:
return None
class daemon_lock:
"""Installing, starting and restarting KDE Connect happen one agent at a time."""
def __enter__(self):
self.file = open(BASE / "daemon.lock", "w")
fcntl.flock(self.file, fcntl.LOCK_EX)
def __exit__(self, *_):
self.file.close()
def run(client, name, folder, packages):
"""Set up, pair and forward events. This start's copy of the packages stays
until it ends, however it ends: restarting KDE Connect may need to unpack it."""
held = hold_incoming(folder)
try:
return serve(client, name, folder, packages)
finally:
if held:
held.close()
tidy_incoming(folder)
def serve(client, name, folder, packages):
try:
with daemon_lock():
ensure_daemon(folder, packages)
device, cert, key = identity(client)
say("pairing")
seen = our_daemons()
try:
link = connect(device, cert, key, name)
except (OSError, RuntimeError):
if not seen:
raise
# Ours, but not answering (KDE Connect 24.02 can hang, for one after
# unpairing a device that's offline): start it afresh, once. If another
# agent already replaced it, just use the new one.
say("starting", message="Restarting KDE Connect on the Frame")
with daemon_lock():
if set(our_daemons()) & set(seen):
stop_daemon()
ensure_daemon(folder, packages)
link = connect(device, cert, key, name)
except NeedPackages:
say("need-packages") # the server copies them and starts again
return 1
except (OSError, RuntimeError, subprocess.SubprocessError) as e:
say("error", message=str(e))
return 1
say("ready", keyboard=link.keyboard is not False)
stdin, pending = sys.stdin.fileno(), b""
sel = selectors.DefaultSelector()
sel.register(stdin, selectors.EVENT_READ)
sel.register(link.sock, selectors.EVENT_READ)
while True:
for key_, _ in sel.select(30):
if key_.fileobj == stdin:
chunk = os.read(stdin, 65536) # raw reads: a buffered readline could strand lines select can't see
if not chunk: # the server went away
return 0
*lines, pending = (pending + chunk).split(b"\n")
try:
for line in lines:
for body in events(line):
link.send(body)
except OSError as e:
say("error", message=f"Lost KDE Connect: {e}")
return 1
else:
packets = link.read()
if packets is None:
say("error", message="KDE Connect closed the connection")
return 1
if any(p.get("type") == "kdeconnect.pair" and not p.get("body", {}).get("pair") for p in packets):
say("error", message="KDE Connect unpaired Frame Control")
return 1
if __name__ == "__main__":
sys.exit(main())
+1232
View File
File diff suppressed because it is too large. Load diff
+490
View File
@@ -0,0 +1,490 @@
"""Mac in the headset: stream Mac windows or displays into the Steam Frame as
panels you can place anywhere, with the laser, wheel and keys driving the Mac.
Runs on the Mac, inside Frame Control's server. The pieces:
- mac/bin/frame-mac-view (Swift, built from mac/frame-mac-view): captures with
ScreenCaptureKit, encodes with VideoToolbox, serves ui/mac-view.html and one
WebSocket per stream on 127.0.0.1, and plays input back with CGEvent.
- An `ssh -R` tunnel, so the Frame reaches the agent on its own 127.0.0.1.
Every request carries a random token, so other programs on the Frame
(Android apps included) can't watch or drive the Mac.
- A Chromium app window on the Frame per stream, on gamescope's X display
with its own STEAM_GAME id, which makes it its own SteamVR panel (see
docs/panels.md). Chromium XR (~/chromium-xr) is preferred because it's
built with H.264; Flathub Chromium is the fallback.
Stdlib only. MacView gets a plain ssh argv for the tunnel (its own
connection) and the server's `run(remote, stdin=, timeout=)` for commands.
"""
import json
import os
import re
import secrets
import shutil
import socket
import subprocess
import sys
import threading
import time
import urllib.error
import urllib.request
import zlib
from pathlib import Path
from urllib.parse import quote, urlencode # %20, not +: the agent's URLComponents keeps +
HERE = Path(__file__).resolve().parent
ROOT = HERE.parent
PAGE = HERE / "mac-view.html"
SOURCES = ROOT / "mac" / "frame-mac-view"
AGENT = Path(os.environ.get("FRAME_MAC_VIEW") or ROOT / "mac" / "bin" / "frame-mac-view")
REMOTE_PORTS = range(47900, 47920)
SUPPORTED = sys.platform == "darwin"
# Stream settings by name: long side in pixels, frames per second, H.264 bits
# per pixel per frame, codec. JPEG is for a Frame browser without H.264.
QUALITY = {
"sharp": {"max": 2560, "fps": 60, "bpp": 0.14, "codec": "h264"},
"balanced": {"max": 1920, "fps": 60, "bpp": 0.1, "codec": "h264"},
"light": {"max": 1280, "fps": 30, "bpp": 0.08, "codec": "h264"},
"compatible": {"max": 1280, "fps": 20, "bpp": 0.1, "codec": "jpeg"},
}
# Extra Chromium flags for viewers (see docs/mac-in-headset.md, "Measuring").
BROWSER_FLAGS = []
# Viewer windows are fitted inside a panel's size. gamescope made a 1280x720
# request 1920x1080 anyway (verified 2026-09-28, build 20260925.6191901).
PANEL_BOX = (1920, 1080)
# Opens one viewer on gamescope's X display and gives its window its own panel
# id. Args: appid url width height tag [browser flags...]. The page puts "[tag]" in its title at
# once, which is how its X window is found (Chromium may hand the URL to an
# instance that's already running, so there's no process to follow).
LAUNCH = r"""set -u
appid=$1 url=$2 w=$3 h=$4 tag=$5
shift 5
export DISPLAY=:0 LC_ALL=C.UTF-8
unset WAYLAND_DISPLAY
if ! xprop -root GAMESCOPE_FOCUSABLE_WINDOWS >/dev/null 2>&1; then
echo "The headset isn't showing anything (gamescope's display :0 isn't up). Wake it and try again." >&2
exit 2
fi
common=(--ozone-platform=x11 --force-device-scale-factor=1 --no-first-run --no-default-browser-check
--password-store=basic --disable-session-crashed-bubble --noerrdialogs --disable-infobars
--disable-features=Translate,MediaRouter --autoplay-policy=no-user-gesture-required
"--window-size=$w,$h" "$@" "--app=$url")
if [ -x "$HOME/chromium-xr/chrome" ]; then
cmd=("$HOME/chromium-xr/chrome" "--user-data-dir=$HOME/.local/share/frame-control/mac-view" "${common[@]}")
elif flatpak info org.chromium.Chromium >/dev/null 2>&1; then
cmd=(flatpak run org.chromium.Chromium
"--user-data-dir=$HOME/.var/app/org.chromium.Chromium/data/frame-mac-view" "${common[@]}")
else
echo "NO_BROWSER"
exit 3
fi
log=/tmp/frame-mac-view.log
setsid nohup "${cmd[@]}" >>"$log" 2>&1 </dev/null &
for _ in $(seq 1 60); do
sleep 0.5
# xprop, not xwininfo: in a C locale xwininfo can't print a non-ASCII title
# at all, while xprop escapes those bytes and leaves the ASCII tag readable.
for win in $(xwininfo -root -children 2>/dev/null | awk '/^ +0x/ {print $1}'); do
xprop -id "$win" _NET_WM_NAME WM_NAME 2>/dev/null | grep -qF "[$tag]" || continue
if xprop -id "$win" -f STEAM_GAME 32c -set STEAM_GAME "$appid" 2>/dev/null; then
echo "panel valve.steam.desktopgame.$appid window $win"
exit 0
fi
done
done
echo "The viewer started, but its window didn't appear within 30 s. Chromium's log:" >&2
tail -n 15 "$log" >&2
exit 1
"""
class MacViewError(Exception):
pass
def panel_id(src):
"""A stable panel id per source, in the range panel-on-frame.sh uses."""
return 2_001_000_000 + zlib.crc32(f"mac:{src}".encode()) % 1_000_000
def fit(w, h, box=PANEL_BOX):
s = min(box[0] / max(w, 1), box[1] / max(h, 1))
return max(320, round(w * s)), max(200, round(h * s))
class MacView:
def __init__(self, tunnel_ssh, run, frame, track=None):
self.tunnel_ssh = list(tunnel_ssh)
self.run = run
self.frame = frame
self.host_opts = [] # the headset in use and how to reach it (see retarget)
# Short, never held across ssh: retarget() and publishing a new tunnel check and
# change the headset together (self.lock is held while a tunnel is being opened).
self.route_lock = threading.Lock()
self.track = track or (lambda proc: None) # the server ends these on exit
self.lock = threading.Lock()
self.token = secrets.token_urlsafe(24)
self.agent = None
self.port = None
self.tunnel = None
self.remote_port = None
self.supervisor = None
self.closing = False
self.shows = 0 # counts Show presses, so a late cleanup can't close a new viewer
self.launching = 0 # Shows in progress (one may be replacing its own stream)
# Held by a Show while it counts itself in, and by the cleanup for its
# check and its pkill together, so a Show can't start in between.
self.viewer_lock = threading.Lock()
# Use the Frame's USB-C network when it's plugged into this Mac (see
# _usb_route); FRAME_MACVIEW_USB=0 turns that off.
self.prefer_usb = os.environ.get("FRAME_MACVIEW_USB") != "0"
self.route = "network"
self.shown = set() # sources with a viewer out there, connected or retrying
self.browser_flags = list(BROWSER_FLAGS)
# ---- the agent on this Mac ----
def unavailable(self):
"""Why this can't work here, or None."""
if not SUPPORTED:
return "Streaming your computer into the headset needs macOS."
if not AGENT.exists() and not (SOURCES.exists() and shutil.which("xcrun")):
return "The Mac streaming helper is missing from this copy of Frame Control."
return None
def build(self):
if AGENT.exists() and not self._stale():
return
if not (SOURCES / "build.sh").exists():
if AGENT.exists():
return
raise MacViewError("The Mac streaming helper is missing.")
r = subprocess.run(["/bin/sh", str(SOURCES / "build.sh"), str(AGENT)], capture_output=True, text=True,
stdin=subprocess.DEVNULL, timeout=600)
if r.returncode != 0:
raise MacViewError("Couldn't build the Mac streaming helper: " + (r.stderr or r.stdout).strip()[-400:])
def _stale(self):
try:
built = AGENT.stat().st_mtime
return any(p.stat().st_mtime > built for p in (SOURCES / "Sources").glob("*.swift"))
except OSError:
return False
def ensure_agent(self):
with self.lock:
if self.agent and self.agent.poll() is None:
return
reason = self.unavailable()
if reason:
raise MacViewError(reason)
self.build()
env = {**os.environ, "FRAME_MAC_VIEW_TOKEN": self.token}
# The same port as before when restarting, so a running tunnel still
# fits; otherwise (or if it's gone) whatever the system gives.
for port in dict.fromkeys([self.port or 0, 0]):
self.agent = subprocess.Popen([str(AGENT), "serve", "--port", str(port), "--page", str(PAGE),
"--exit-on-eof"], env=env, stdin=subprocess.PIPE,
stdout=subprocess.PIPE, stderr=subprocess.STDOUT, text=True)
line = self.agent.stdout.readline()
m = re.search(r"listening on 127\.0\.0\.1:(\d+)", line)
if m:
break
self.agent.kill()
else:
raise MacViewError(f"The Mac streaming helper didn't start: {line.strip() or 'no output'}")
if self.port != int(m.group(1)):
self._drop_tunnel()
self.port = int(m.group(1))
self.track(self.agent)
threading.Thread(target=self.agent.stdout.read, daemon=True).start() # drain
def call(self, path, method="GET", **query):
"""A request to the agent; starts it if needed."""
self.ensure_agent()
url = f"http://127.0.0.1:{self.port}{path}?{urlencode({**query, 'k': self.token}, quote_via=quote)}"
req = urllib.request.Request(url, method=method, data=b"" if method == "POST" else None)
try:
with urllib.request.urlopen(req, timeout=10) as r:
return json.load(r)
except (urllib.error.URLError, OSError, ValueError) as e:
raise MacViewError(f"The Mac streaming helper didn't answer: {e}")
# ---- the tunnel from the Frame ----
def _drop_tunnel(self):
if self.tunnel and self.tunnel.poll() is None:
self.tunnel.terminate()
self.tunnel = None
def tunnel_up(self):
return self.tunnel is not None and self.tunnel.poll() is None
def ensure_tunnel(self, allow_new_port=False):
"""Open the tunnel, on the port viewers already use if there is one.
A new port only when nobody is watching, since viewers can't move."""
with self.lock:
if self.tunnel_up():
return
last = ""
ports = [self.remote_port] if self.remote_port else list(REMOTE_PORTS)
if self.remote_port and allow_new_port:
ports += [p for p in REMOTE_PORTS if p != self.remote_port]
usb = self._usb_route()
# USB-C first when it's there; if that fails (unplugged just now,
# something else at that address), the normal path.
for via in ([usb, []] if usb else [[]]):
self.route = "usb" if via else "network"
if self._open_tunnel(via, ports):
return
last = self._last_tunnel_error
raise MacViewError(f"Couldn't open a tunnel from {self.frame} to this Mac: {last or 'no answer through it'}")
def retarget(self, alias, host_opts):
"""The server now reaches the headset as `alias` with `host_opts` (another address,
or another headset). Only the short route_lock, never self.lock: this runs while
the server routes, which a tunnel being opened may be waiting on."""
# host_opts is "-o", "Name=value" pairs; the tunnel keeps its own connection,
# not the shared master.
opts = [x for flag, value in zip(host_opts[::2], host_opts[1::2])
if not value.startswith("ControlPath=") for x in (flag, value)]
with self.route_lock:
moved = alias != self.frame
self.frame, self.host_opts = alias, opts
tunnel = self.tunnel
if moved and tunnel is not None:
# Another headset: its viewers can't be the old one's. The supervisor
# reopens a tunnel to the new one if anything is being shown.
self.tunnel, self.remote_port = None, None
if moved and tunnel is not None and tunnel.poll() is None:
tunnel.terminate()
def _open_tunnel(self, via, ports):
"""Tries the ports on one route; True once the tunnel answers. With self.lock held."""
last = ""
for port in ports:
with self.route_lock:
target = (self.frame, self.host_opts) # retarget() may change these meanwhile
# `via` first: ssh keeps the first value of an option, so USB-C's HostName wins
# while the headset's pinned identity (in host_opts) still checks it.
proc = subprocess.Popen([*self.tunnel_ssh, "-o", "ControlPath=none", *via, *target[1],
"-o", "ExitOnForwardFailure=yes",
"-o", "ServerAliveInterval=5", "-o", "ServerAliveCountMax=3", "-N",
"-R", f"127.0.0.1:{port}:127.0.0.1:{self.port}", target[0]],
stdin=subprocess.DEVNULL, stdout=subprocess.DEVNULL,
stderr=subprocess.PIPE, text=True)
# A taken port makes ssh exit once it's connected; a working
# tunnel answers the agent's status from the Frame's side.
ok = False
for _ in range(15):
time.sleep(0.4)
if proc.poll() is not None:
break
if self._probe(port):
ok = True
break
if ok:
with self.route_lock: # checked and published together, so a switch can't slip between
ok = target[0] == self.frame # else the app switched headset while this connected
if ok:
self.tunnel, self.remote_port = proc, port
if ok:
self.track(proc)
self._supervise()
return True
if proc.poll() is None:
proc.terminate()
proc.wait()
last = (proc.stderr.read() or "").strip()
if "forward" not in last.lower():
break # not a port clash: the Frame is unreachable this way
self._last_tunnel_error = last
return False
def _usb_route(self):
"""ssh options to reach the Frame over its USB-C network, or [].
Plugged into a Mac, the Frame is a USB network device (macOS lists it
as "Steam Frame"): the Frame's usb0 answers at about 1 ms, with none
of Wi-Fi's stalls. Measured 2026-09-28: content latency 7 ms instead
of 10, click to screen 17 ms instead of 27 (docs/mac-in-headset.md).
The host key is the same, so it's checked against the usual name."""
if not self.prefer_usb:
return []
try:
out = self.run("ip -4 -o addr show usb0 2>/dev/null", timeout=8)
except Exception:
return []
m = re.search(r"inet (\d+\.\d+\.\d+\.\d+)/", out or "")
if not m:
return []
ip = m.group(1)
try:
socket.create_connection((ip, 22), timeout=1).close()
except OSError:
return [] # not plugged into this Mac
if any(o.startswith("HostKeyAlias=") for o in self.host_opts):
return ["-o", f"HostName={ip}"] # checked against the headset's own pinned key
alias = self.frame
try:
cfg = subprocess.run(["ssh", "-G", self.frame], capture_output=True, text=True, timeout=5).stdout
opts = dict(line.split(None, 1) for line in cfg.splitlines() if " " in line)
alias = opts.get("hostkeyalias") or opts.get("hostname") or alias # a configured alias wins
except (OSError, subprocess.SubprocessError):
pass
return ["-o", f"HostName={ip}", "-o", f"HostKeyAlias={alias}"]
def _supervise(self):
"""Reopen the tunnel on the same port after the headset sleeps or the
network drops, so viewers that are retrying find the Mac again."""
if self.supervisor and self.supervisor.is_alive():
return
def loop():
while not self.closing:
time.sleep(5)
if self.closing or self.tunnel_up() or not (self.agent and self.agent.poll() is None):
continue
try:
self.ensure_tunnel()
except MacViewError:
pass # still unreachable; try again shortly
self.supervisor = threading.Thread(target=loop, daemon=True)
self.supervisor.start()
def _probe(self, port):
"""Whether the Frame reaches the agent through the tunnel on `port`."""
# /ping needs no key, so none appears on the Frame's command lines.
cmd = f"curl -s -m 2 'http://127.0.0.1:{port}/ping'"
try:
return self.run(cmd, timeout=8).strip() == "frame-mac-view"
except Exception: # noqa: BLE001 - the server's Failure, timeouts: all mean "not yet"
return False
# ---- viewers on the Frame ----
def show(self, src, quality="balanced", width=None, height=None):
with self.viewer_lock:
self.launching += 1
try:
return self._show(src, quality, width, height)
finally:
with self.viewer_lock:
self.launching -= 1
def _show(self, src, quality, width, height):
if src != "test" and not src.startswith(("window:", "display:", "separate:")):
raise MacViewError("Pick a window or display to show.")
self.shows += 1
q = QUALITY.get(quality) or QUALITY["balanced"]
state = self.call("/status")
if src != "test" and not state.get("screen"):
raise MacViewError("Frame Control needs Screen Recording permission first (Allow… under Mac in the headset).")
if src.startswith("separate:") and not state.get("accessibility"):
raise MacViewError("A window on its own display needs the Accessibility permission too, to move it "
"(Allow… under Mac in the headset).")
self.shown -= set(state.get("finished", [])) # their Mac windows closed
if src in self.shown or any(st.get("src") == src for st in state.get("streams", [])):
# Showing it again replaces the old viewer, connected or not: this
# revokes its keys so it can't come back alongside the new one.
self.stop(src)
# Viewers that lost the tunnel keep retrying its old port, even though
# the agent no longer counts them, so only move when none are out there.
others = self.shown - {src}
self.ensure_tunnel(allow_new_port=not others)
appid = panel_id(src)
# Unique per launch, so a new window is never confused with an old one.
tag = "fc" + secrets.token_hex(4)
# A single-use ticket for this source, not Frame Control's key: the URL
# is visible in the Frame's process list.
ticket = self.call("/ticket", method="POST", src=src)["ticket"]
params = {"src": src, "t": ticket, "tag": tag, "codec": q["codec"], "max": q["max"], "fps": q["fps"],
"bpp": q["bpp"]}
url = f"http://127.0.0.1:{self.remote_port}/view?{urlencode(params)}"
w, h = fit(width or 1280, height or 720)
args = " ".join(_quote(str(a)) for a in (appid, url, w, h, tag, *self.browser_flags))
try:
out = self.run("bash -s -- " + args, stdin=LAUNCH, timeout=60)
except Exception as e: # noqa: BLE001 - the server's Failure carries the Frame's words
if "NO_BROWSER" in (getattr(e, "stdout", "") or ""):
raise MacViewError("The Frame needs a browser for this: install Chromium (Tools → Linux apps, "
"org.chromium.Chromium) or Chromium XR.")
raise MacViewError(str(e))
self.shown.add(src)
return {"panel": f"valve.steam.desktopgame.{appid}", "src": src, "detail": out.strip()}
def stop(self, src=None):
if src:
self.shown.discard(src)
else:
self.shown.clear()
if not (self.agent and self.agent.poll() is None):
return {"closed": 0}
out = self.call("/close", method="POST", **({"src": src} if src else {}))
if not self.shown:
threading.Thread(target=self._end_viewer_browser, args=(self.shows,), daemon=True).start()
return out
def _end_viewer_browser(self, shows):
"""Chromium on the Frame outlives its last viewer window (verified
2026-09-28), so once nothing is shown, end it. It runs with a profile
of its own, so nothing else is touched."""
time.sleep(2) # the viewers close their windows first
with self.viewer_lock:
if self.shown or self.shows != shows or self.launching:
return
try:
self.run("pkill -f '[f]rame-control/mac-view|[d]ata/frame-mac-view' || true", timeout=10)
except Exception:
pass
def state(self):
reason = self.unavailable()
if reason:
return {"available": False, "reason": reason}
status = self.call("/status")
windows = self.call("/windows").get("windows", []) if status.get("screen") else []
displays = self.call("/displays").get("displays", [])
return {"available": True, "screen": status.get("screen", False),
"accessibility": status.get("accessibility", False), "streams": status.get("streams", []),
"windows": windows, "displays": displays, "tunnel": self.tunnel_up(),
"route": self.route}
def restart_agent(self):
"""Only if it's missing a permission: a running stream would stop."""
with self.lock:
if not (self.agent and self.agent.poll() is None):
return
status = self.call("/status")
if status.get("screen") and status.get("accessibility"):
return
with self.lock:
self.agent.terminate()
self.agent.wait(5)
def request_permissions(self):
return self.call("/permissions", method="POST")
def shutdown(self):
self.closing = True
try:
self.stop()
except MacViewError:
pass
for proc in (self.tunnel, self.agent):
if proc and proc.poll() is None:
proc.terminate()
# The helper puts separated windows back before it exits (about 1 s).
if self.agent:
try:
self.agent.wait(3)
except subprocess.TimeoutExpired:
self.agent.kill()
def _quote(s):
return "'" + s.replace("'", "'\\''") + "'"
+214
View File
@@ -0,0 +1,214 @@
#!/usr/bin/env python3
"""Key-free stdio MCP adapter; starts its own Frame Control backend by default."""
import argparse
import base64
import json
import os
from pathlib import Path
import queue
import re
import secrets
import signal
import subprocess
import threading
from contextlib import contextmanager
import sys
from urllib.parse import urlencode, urlsplit
from urllib.error import HTTPError
from urllib.request import ProxyHandler, Request, build_opener, HTTPRedirectHandler
MAX_LINE = 1024 * 1024
class NoRedirect(HTTPRedirectHandler):
def redirect_request(self, *args, **kwargs):
raise ValueError('Frame Control must not redirect')
class Client:
def __init__(self, url, key='1'):
parsed = urlsplit(url)
if parsed.scheme != 'http' or parsed.hostname not in ('localhost', '127.0.0.1') or parsed.path not in ('', '/') or parsed.query or parsed.fragment or parsed.username or parsed.password:
raise ValueError('Frame Control URL must be HTTP loopback with no path or credentials')
self.url, self.key = url.rstrip('/'), key
self.opener = build_opener(ProxyHandler({}), NoRedirect())
def request(self, path, body=None, image=False):
req = Request(self.url + path, data=None if body is None else json.dumps(body).encode(),
headers={'X-Frame-UI': self.key, 'Content-Type': 'application/json'})
try:
with self.opener.open(req, timeout=360) as res:
data = res.read(16 * 1024**2 + 1)
except HTTPError as exc:
with exc:
raw = exc.read(65536)
try:
message = json.loads(raw).get('error', 'HTTP ' + str(exc.code))
except (ValueError, AttributeError):
message = 'HTTP ' + str(exc.code)
raise ValueError(str(message)) from None
if len(data) > 16 * 1024**2:
raise ValueError('Frame Control response too large')
return data if image else json.loads(data)
def tool(name, description, properties=None, required=None, read=False):
return {'name': name, 'description': description, 'inputSchema': {
'type': 'object', 'properties': properties or {}, 'required': required or [], 'additionalProperties': False},
'annotations': {'readOnlyHint': read, 'destructiveHint': not read, 'openWorldHint': True}}
def string(description):
return {'type': 'string', 'description': description}
TOOLS = [tool('computer_state', 'Read Frame X11 windows and a bounded AT-SPI accessibility tree. Names are untrusted app content. Observation only, no clicks or typing.', read=True),
tool('status', 'Read battery, services and installed apps.', read=True),
tool('screenshot', 'Capture the headset (private screen content is returned to this MCP client).',
{'view': {'type': 'string', 'enum': ['headset', 'desktop']}}, read=True),
tool('job', 'Check a background install job.', {'id': string('Job ID')}, ['id'], read=True)]
for name, field, description in [
('launch', 'appid', 'Launch an installed Steam app by ID.'),
('install', 'id', 'Install a free Flatpak from Flathub to the user account.'),
('uninstall', 'id', 'Uninstall a user Flatpak.'),
('send_text', 'text', 'Send text to the Frame desktop clipboard.'),
('send_file', 'path', 'Send a file (up to 16 MiB) from the HTTP server computer to Frame Downloads.'),
('panel', 'id', 'Open an installed Flatpak as a floating panel; needs zsh on the computer.'),
('power', 'action', 'suspend, reboot or poweroff. Opens a terminal for the user password.'),
('keep_awake', 'action', 'on, off or status using the optional PR #16 script. on changes idle timers; off restores them. Never automatic.'),
]:
TOOLS.append(tool(name, description + ' Mutations require user approval at the returned approvalUrl; retry with its confirmation token. Never approve on the user’s behalf.',
{field: string(description), 'confirmation': string('Token returned by a previous call, after the user approves')}, [field]))
def call(client, name, args):
spec = next((t for t in TOOLS if t['name'] == name), None)
if not spec or not isinstance(args, dict):
raise ValueError('Unknown tool or invalid arguments')
schema = spec['inputSchema']
if set(args) - set(schema['properties']) or set(schema['required']) - set(args):
raise ValueError('Unknown or missing arguments')
if any(not isinstance(v, str) for v in args.values()):
raise ValueError('Arguments must be strings')
if name == 'screenshot':
view = args.get('view', 'headset')
if view not in ('headset', 'desktop'):
raise ValueError('Unknown screenshot view')
png = client.request('/api/screenshot?' + urlencode({'view': view}), image=True)
return {'content': [{'type': 'image', 'mimeType': 'image/png', 'data': base64.b64encode(png).decode()}]}
if name == 'computer_state':
result = client.request('/api/computer/state')
elif name in ('status', 'job'):
result = client.request('/api/' + name + ('?' + urlencode(args) if args else ''))
else:
args = dict(args)
confirmation = args.pop('confirmation', None)
result = client.request('/api/agent/call', {'name': name, 'arguments': args, 'confirmation': confirmation})
if 'approvalPath' in result:
result['approvalUrl'] = client.url + result['approvalPath']
return {'content': [{'type': 'text', 'text': json.dumps(result)}]}
def dispatch(client, message):
if not isinstance(message, dict) or message.get('jsonrpc') != '2.0' or not isinstance(message.get('method'), str):
return {'jsonrpc': '2.0', 'id': None, 'error': {'code': -32600, 'message': 'Invalid request'}}
if 'id' not in message:
return None
method, params = message['method'], message.get('params', {})
response = {'jsonrpc': '2.0', 'id': message['id']}
if not isinstance(params, dict):
return {**response, 'error': {'code': -32602, 'message': 'Invalid params'}}
if method == 'initialize':
requested = params.get('protocolVersion')
result = {'protocolVersion': requested if requested in ('2024-11-05', '2025-03-26', '2025-06-18') else '2025-06-18',
'capabilities': {'tools': {}}, 'serverInfo': {'name': 'frame-control', 'version': '1.0.0'}}
elif method == 'ping':
result = {}
elif method == 'tools/list':
result = {'tools': TOOLS}
elif method == 'tools/call':
try:
result = call(client, params.get('name'), params.get('arguments', {}))
except Exception as exc:
result = {'isError': True, 'content': [{'type': 'text', 'text': 'Frame Control: ' + str(exc)}]}
else:
return {**response, 'error': {'code': -32601, 'message': 'Method not found'}}
return {**response, 'result': result}
@contextmanager
def backend(url=None):
"""Own one private HTTP backend per MCP process, or use an explicit existing one."""
if url:
yield Client(url, os.environ.get('FRAME_UI_KEY', '1'))
return
key = secrets.token_urlsafe(32)
env = {**os.environ, 'FRAME_UI_KEY': key, 'DO_NOT_TRACK': '1', 'FRAME_PRIVATE_SSH': '1'}
proc = subprocess.Popen([sys.executable, str(Path(__file__).with_name('server.py')),
'--port', '0', '--exit-on-eof'],
env=env, stdin=subprocess.PIPE, stdout=subprocess.PIPE,
stderr=sys.stderr, text=True)
lines = queue.Queue()
def read_banner():
lines.put(proc.stdout.readline())
threading.Thread(target=read_banner, daemon=True).start()
try:
try:
banner = lines.get(timeout=10)
except queue.Empty:
raise RuntimeError('Frame Control backend did not start within 10 seconds') from None
match = re.fullmatch(r'Frame Control on (http://127\.0\.0\.1:[0-9]+) .*\n?', banner)
if not match:
raise RuntimeError('Frame Control backend failed to start; see stderr')
yield Client(match.group(1), key)
finally:
# Closing stdin asks server.py to clean up its SSH master and jobs.
proc.stdin.close()
try:
proc.wait(timeout=10)
except subprocess.TimeoutExpired:
proc.terminate()
try:
proc.wait(timeout=5)
except subprocess.TimeoutExpired:
proc.kill()
proc.wait()
proc.stdout.close()
def serve(client):
while True:
line = sys.stdin.buffer.readline(MAX_LINE + 1)
if not line:
break
if len(line) > MAX_LINE:
print('MCP request too large', file=sys.stderr)
return 1
try:
response = dispatch(client, json.loads(line))
except (ValueError, UnicodeError):
response = {'jsonrpc': '2.0', 'id': None, 'error': {'code': -32700, 'message': 'Parse error'}}
if response is not None:
print(json.dumps(response), flush=True)
return 0
def main():
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument('--url', help='Use an existing HTTP server instead of starting a private backend')
args = parser.parse_args()
signal.signal(signal.SIGTERM, lambda *_: (_ for _ in ()).throw(KeyboardInterrupt))
try:
with backend(args.url) as client:
return serve(client)
except KeyboardInterrupt:
return 0
except (OSError, RuntimeError) as exc:
print(str(exc), file=sys.stderr)
return 1
if __name__ == '__main__':
sys.exit(main())
+67
View File
@@ -0,0 +1,67 @@
"""Media planning shared by Frame Control and its own Frame-side player.
No viewer dependencies. Filename hints are suggestions, never guesses from
resolution. Explicit layout wins; conflicting hints require a choice.
"""
import re
from pathlib import Path
LAYOUTS = ('auto', 'mono', 'sbs', 'ou', 'full-sbs', 'full-ou')
VIDEO = {'.mp4', '.mkv', '.mov', '.webm', '.m4v'}
PHOTO = {'.png', '.jpg', '.jpeg'}
def plan(name, layout='auto', metadata=None):
if layout not in LAYOUTS:
raise ValueError('Choose auto, mono, sbs, ou, full-sbs or full-ou')
suffix = Path(name).suffix.lower()
if suffix in {'.heic', '.heif', '.avif', '.mpo'}:
raise ValueError('Native spatial-photo containers are not supported yet; export both eyes as SBS or OU PNG/JPEG')
if suffix == '.splat':
return {'kind': 'splat', 'layout': 'sbs', 'source': 'renderer'}
if suffix not in VIDEO | PHOTO:
raise ValueError('Use MP4/MKV/MOV/WebM video, PNG/JPEG stereo photos, or a .splat file')
source = 'explicit'
if layout == 'auto':
tokens = set(re.split(r'[^a-z0-9]+', Path(name).stem.lower()))
hints = set()
for value, tags in [('full-sbs', {'fsbs'}), ('full-ou', {'fou', 'ftb'}),
('sbs', {'sbs', 'hsbs', 'lr'}), ('ou', {'ou', 'hou', 'tb', 'htb'})]:
if tokens & tags:
hints.add(value)
if len(hints) > 1:
raise ValueError('Conflicting stereo filename tags; choose the layout explicitly')
layout = next(iter(hints), None)
source = 'filename'
if not layout:
# Matroska StereoMode/FFmpeg stereo_mode: only known left-first modes.
mode = (metadata or {}).get('stereo_mode')
layout = {'left_right': 'full-sbs', 'top_bottom': 'full-ou', 'mono': 'mono'}.get(mode)
source = 'metadata'
if mode and layout is None:
raise ValueError('Unsupported stereo metadata; choose the eye order/layout explicitly')
if not layout:
raise ValueError('No stereo layout found; choose mono, SBS or OU (left/top eye first)')
return {'kind': 'video' if suffix in VIDEO else 'photo', 'layout': layout, 'source': source}
def geometry(width, height, layout):
"""Bound transfer to 1920x1080; return packed dimensions and texel aspect."""
if not 0 < width <= 32768 or not 0 < height <= 32768:
raise ValueError('Invalid media dimensions')
if layout not in LAYOUTS[1:]:
raise ValueError('Resolve the layout before playback')
scale = min(1, 1920 / width, 1080 / height)
w, h = max(2, int(width * scale) // 2 * 2), max(2, int(height * scale) // 2 * 2)
return w, h, {'mono': 1, 'sbs': 2, 'ou': .5, 'full-sbs': 1, 'full-ou': 1}[layout]
def stereo_pixels(data, width, height, layout):
"""Normalize top/bottom to OpenVR's left/right texture; preserve eye order."""
if len(data) != width * height * 4:
raise ValueError('Incomplete RGBA frame')
if layout not in ('ou', 'full-ou'):
return data, width, height
stride, half = width * 4, height // 2
return b''.join(data[y*stride:(y+1)*stride] +
data[(y+half)*stride:(y+half+1)*stride] for y in range(half)), width*2, half
+46
View File
@@ -0,0 +1,46 @@
#!/usr/bin/env python3
"""Send local media to Frame Control's own OpenVR player."""
import argparse
import json
from pathlib import Path
import sys
sys.path.insert(0, str(Path(__file__).resolve().parent))
import frame_media
import server
def main():
ap = argparse.ArgumentParser(description=__doc__)
ap.add_argument('files', nargs='*', type=Path)
ap.add_argument('--launch', action='store_true', help='play the one file being sent')
ap.add_argument('--layout', choices=frame_media.LAYOUTS, default='auto')
ap.add_argument('--theatre', action='store_true', help='bigger screen and dark surround')
ap.add_argument('--list', action='store_true')
ap.add_argument('--stop', action='store_true')
args = ap.parse_args()
if args.launch and len(args.files) != 1:
ap.error('--launch needs exactly one file')
if not args.files and not (args.list or args.stop):
ap.error('choose files, --list or --stop')
for path in args.files:
if not path.is_file():
ap.error('not a file: %s' % path)
frame_media.plan(path.name, 'mono')
if args.stop:
print(json.dumps(server.media({'action': 'stop'})))
for path in args.files:
result = server.push_media(path.resolve())
print(json.dumps(result))
if args.launch:
print(json.dumps(server.media({'action': 'play', 'id': result['id'],
'layout': args.layout, 'theatre': args.theatre})))
if args.list:
print(json.dumps(server.media({'action': 'list'})))
if __name__ == '__main__':
try:
main()
except (ValueError, server.Failure) as e:
sys.exit(str(e))
+279
View File
@@ -0,0 +1,279 @@
#!/usr/bin/env python3
"""Frame Control's local-media OpenVR player. Runs on the Frame, no third-party app.
SteamOS ffmpeg does hardware video decoding, scaling and audio output. OpenVR
owns only our screen and optional black surround. Exiting destroys both.
"""
import argparse
import ctypes as C
import json
import os
from pathlib import Path
import signal
import subprocess
import time
import frame_media
import frame_splat
LIB = '/opt/steamvr/bin/linuxarm64/libopenvr_api.so'
H = C.c_uint64
# Slots from Valve's openvr_capi.h, IVROverlay_028. Fail closed on another ABI.
SLOTS = {
'CreateOverlay': (1, [C.c_char_p, C.c_char_p, C.POINTER(H)]),
'DestroyOverlay': (3, [H]),
'SetOverlayFlag': (11, [H, C.c_int, C.c_bool]),
'SetOverlayAlpha': (16, [H, C.c_float]),
'SetOverlayTexelAspect': (18, [H, C.c_float]),
'SetOverlaySortOrder': (20, [H, C.c_uint32]),
'SetOverlayWidthInMeters': (22, [H, C.c_float]),
'SetOverlayTransformTrackedDeviceRelative': (35, [H, C.c_uint32, C.c_void_p]),
'ShowOverlay': (43, [H]),
'SetOverlayRaw': (62, [H, C.c_void_p, C.c_uint32, C.c_uint32, C.c_uint32]),
}
class OverlayBusy(RuntimeError):
"""SetOverlayRaw's RequestFailed (23): SteamVR isn't taking frames, e.g. the
unworn headset is in standby (verified 2026-09-29). Transient, not fatal."""
# A screen that can't take a frame for this long is broken, not asleep.
BUSY_LIMIT = 300
class Overlay:
def __init__(self):
self.handles = []
self.vr = C.CDLL(LIB)
self.vr.VR_InitInternal2.argtypes = [C.POINTER(C.c_int), C.c_int, C.c_char_p]
self.vr.VR_GetGenericInterface.argtypes = [C.c_char_p, C.POINTER(C.c_int)]
self.vr.VR_GetGenericInterface.restype = C.c_void_p
err = C.c_int()
self.vr.VR_InitInternal2(C.byref(err), 2, None)
if err.value:
raise RuntimeError('SteamVR init failed: %s' % err.value)
ptr = self.vr.VR_GetGenericInterface(b'FnTable:IVROverlay_028', C.byref(err))
if not ptr or err.value:
self.vr.VR_ShutdownInternal()
raise RuntimeError('SteamVR needs IVROverlay_028: %s' % err.value)
self.table = C.cast(ptr, C.POINTER(C.c_void_p))
def call(self, name, *values):
slot, args = SLOTS[name]
rc = C.CFUNCTYPE(C.c_int, *args)(self.table[slot])(*values)
if rc == 23 and name == 'SetOverlayRaw':
raise OverlayBusy('SteamVR is not accepting frames (standby?)')
if rc:
raise RuntimeError('OpenVR %s failed: %s' % (name, rc))
def create(self, key, width, distance, stereo=False, aspect=1, order=1):
handle = H()
self.call('CreateOverlay', key.encode(), b'Frame Control media', C.byref(handle))
self.handles.append(handle)
self.call('SetOverlayWidthInMeters', handle, width)
self.call('SetOverlaySortOrder', handle, order)
self.call('SetOverlayTexelAspect', handle, aspect)
if stereo:
self.call('SetOverlayFlag', handle, 1024, True) # SideBySide_Parallel
matrix = (C.c_float * 12)(1, 0, 0, 0, 0, 1, 0, 0, 0, 0, 1, -distance)
self.call('SetOverlayTransformTrackedDeviceRelative', handle, 0, matrix)
return handle
def pixels(self, handle, data, width, height):
buf = C.create_string_buffer(data)
self.call('SetOverlayRaw', handle, buf, width, height, 4)
self.call('ShowOverlay', handle)
def close(self):
# Best effort: SteamVR removes a disconnected client's overlays anyway,
# and a teardown error must not overwrite a finished playback's status.
for h in reversed(self.handles):
try:
self.call('DestroyOverlay', h)
except RuntimeError:
pass
self.vr.VR_ShutdownInternal()
def probe(path):
result = subprocess.run(['ffprobe', '-v', 'error', '-show_streams', '-of', 'json', str(path)],
capture_output=True, text=True, timeout=30)
if result.returncode:
raise ValueError(result.stderr[-2000:] or 'Cannot read media')
streams = json.loads(result.stdout)['streams']
video = next((s for s in streams if s['codec_type'] == 'video'), None)
if not video:
raise ValueError('No image or video stream')
return video, any(s['codec_type'] == 'audio' for s in streams)
def decoder_command(path, info, width, height, audio, photo=False):
cmd = ['ffmpeg', '-nostdin', '-hide_banner', '-loglevel', 'error']
if not photo:
cmd += ['-re', '-readrate_initial_burst', '0']
codec = {'h264': 'h264_v4l2m2m', 'hevc': 'hevc_v4l2m2m'}.get(info['codec_name'])
if not codec:
raise ValueError('Hardware playback currently supports H.264 and H.265 only')
cmd += ['-c:v', codec]
cmd += ['-i', str(path), '-map', '0:v:0', '-vf', 'scale=%s:%s' % (width, height),
'-pix_fmt', 'rgba']
if photo:
cmd += ['-frames:v', '1']
else:
cmd += ['-r', '30']
cmd += ['-f', 'rawvideo', 'pipe:1']
if audio and not photo:
cmd += ['-map', '0:a:0', '-f', 'pulse', 'Frame Control Media']
return cmd
def ignore_signals():
signal.signal(signal.SIGTERM, signal.SIG_IGN)
signal.signal(signal.SIGINT, signal.SIG_IGN)
def write_status(path, **values):
tmp = path.with_suffix('.tmp')
tmp.write_text(json.dumps(values))
tmp.replace(path)
def play(args):
path = Path(args.file).resolve(strict=True)
status = Path(args.status)
splat = path.suffix.lower() == '.splat'
if splat:
data, width, height = frame_splat.render(path)
plan = frame_media.plan(path.name)
aspect, photo, command = 1, True, None
else:
info, audio = probe(path)
plan = frame_media.plan(path.name, args.layout, info.get('tags'))
width, height, aspect = frame_media.geometry(info['width'], info['height'], plan['layout'])
photo = plan['kind'] == 'photo'
command = decoder_command(path, info, width, height, audio, photo)
vr, proc, frames, started = None, None, 0, time.monotonic()
dropped, busy_since, pending = 0, None, []
def show(handle, data, w, h, video=False):
"""Submit a frame. During standby return False; a video frame is dropped."""
nonlocal dropped, busy_since
try:
vr.pixels(handle, data, w, h)
except OverlayBusy:
if not video:
return False # stills and the surround just wait; nothing is lost
dropped += 1
busy_since = busy_since or time.monotonic()
if time.monotonic() - busy_since > BUSY_LIMIT:
raise RuntimeError('SteamVR stopped accepting frames for %d s' % BUSY_LIMIT)
return False
if video:
busy_since = None
drain()
return True
def drain():
"""Re-send anything that arrived during standby (e.g. the theatre surround)."""
while pending:
item = pending.pop(0)
try:
vr.pixels(*item)
except OverlayBusy:
pending.insert(0, item)
return
def hold(handle, data, w, h):
"""Keep a still (photo or splat) up until Stop, retrying through standby."""
shown = False
while True:
if shown:
drain()
else:
shown = show(handle, data, w, h)
time.sleep(1)
# systemd sends SIGTERM to the whole unit, including ffmpeg. Python unwinds
# ownership; no unrelated Steam/SteamVR process or setting is touched.
def stop(signum, frame):
raise InterruptedError('Stopped')
signal.signal(signal.SIGTERM, stop)
signal.signal(signal.SIGINT, stop)
try:
vr = Overlay()
if args.theatre:
surround = vr.create('framecontrol.media.surround', 40, 4, order=0)
vr.call('SetOverlayAlpha', surround, .85)
if not show(surround, b'\x00\x00\x00\xff', 1, 1):
pending.append((surround, b'\x00\x00\x00\xff', 1, 1))
screen = vr.create('framecontrol.media.screen', 3 if args.theatre else 1.6, 2,
plan['layout'] != 'mono', aspect)
if splat:
write_status(status, state='playing', file=path.name, frames=1, **plan)
hold(screen, data, width, height)
proc = subprocess.Popen(command, stdout=subprocess.PIPE)
video_start = time.monotonic()
while True:
data = proc.stdout.read(width * height * 4)
if not data:
break
data, outw, outh = frame_media.stereo_pixels(data, width, height, plan['layout'])
if not photo:
time.sleep(max(0, video_start + frames/30 - time.monotonic()))
if photo:
still = data, outw, outh
else:
show(screen, data, outw, outh, video=True)
frames += 1
if frames == 1 or frames % 30 == 0:
write_status(status, state='playing', file=path.name, frames=frames,
dropped=dropped, seconds=time.monotonic()-started, **plan)
if not photo:
time.sleep(max(0, video_start + frames/30 - time.monotonic()))
rc = proc.wait(timeout=10)
if rc:
raise RuntimeError('ffmpeg exited %s; see media log' % rc)
if not frames:
raise RuntimeError('Decoder produced no frames')
if photo:
hold(screen, *still)
# From here on a Stop can't change the outcome; don't let it turn
# 'ended' into an error while we write status and clean up.
ignore_signals()
write_status(status, state='ended', frames=frames, dropped=dropped,
seconds=time.monotonic()-started)
except InterruptedError:
ignore_signals()
write_status(status, state='stopped', frames=frames, dropped=dropped)
finally:
ignore_signals()
if proc:
if proc.poll() is None:
proc.terminate()
try:
proc.wait(timeout=5)
except subprocess.TimeoutExpired:
proc.kill()
proc.wait()
proc.stdout.close()
if vr:
vr.close()
def main():
ap = argparse.ArgumentParser(description=__doc__)
ap.add_argument('file')
ap.add_argument('--layout', choices=frame_media.LAYOUTS, default='auto')
ap.add_argument('--theatre', action='store_true')
ap.add_argument('--status', required=True)
args = ap.parse_args()
try:
play(args)
except Exception as e:
write_status(Path(args.status), state='error', error=str(e))
raise
if __name__ == '__main__':
main()
+109
View File
@@ -0,0 +1,109 @@
"""Frame-side library and process ownership for Frame Control media.
Only the dedicated systemd user unit is controlled. No SteamVR settings change.
"""
import argparse
import json
from pathlib import Path
import re
import subprocess
import sys
import frame_media
from frame_media_player import probe
ROOT = Path.home() / 'Videos' / 'FrameControl'
RUNTIME = Path.home() / '.local' / 'share' / 'frame-control' / 'media'
UNIT = 'frame-control-media.service'
STATUS = RUNTIME / 'status.json'
def media_path(identity):
if not isinstance(identity, str) or '\\' in identity or '\x00' in identity:
raise ValueError('Invalid media id')
parts = Path(identity).parts
if len(parts) != 2 or not re.fullmatch('[0-9a-f]{32}', parts[0]) or parts[1].startswith('.'):
raise ValueError('Invalid media id')
candidate = ROOT / identity
if candidate.is_symlink() or candidate.parent.is_symlink():
raise ValueError('Media links are not supported')
path = candidate.resolve(strict=True)
if not path.is_file() or ROOT.resolve() not in path.parents:
raise ValueError('Media file is outside the library')
return path
def active():
return subprocess.run(['systemctl', '--user', 'is-active', '--quiet', UNIT]).returncode == 0
def status():
running = active()
try:
state = json.loads(STATUS.read_text())
except (OSError, ValueError):
state = {'state': 'idle'}
if not running and state.get('state') in ('playing', 'starting', 'paused'):
state = {'state': 'stopped', 'message': 'Player exited; check the media log if this was unexpected'}
return dict(state, running=running)
def run(body):
action = body.get('action')
if action == 'list':
files = []
if ROOT.exists():
for folder in sorted(ROOT.iterdir()):
if not re.fullmatch('[0-9a-f]{32}', folder.name) or not folder.is_dir() or folder.is_symlink():
continue
for path in sorted(folder.iterdir()):
if path.is_file() and not path.is_symlink() and not path.name.startswith('.'):
files.append({'id': folder.name+'/'+path.name, 'name': path.name, 'bytes': path.stat().st_size})
return {'files': files, 'player': status()}
if action == 'status':
return status()
if action == 'stop':
# --collect unloads the unit after it exits; systemctl then exits 5
# ("not loaded", verified on the Frame). That's a finished player, not an error.
stopped = subprocess.run(['systemctl', '--user', 'stop', UNIT], capture_output=True, text=True, timeout=15)
if stopped.returncode not in (0, 5):
raise RuntimeError('Could not stop the media player: ' + (stopped.stderr.strip() or 'exit %s' % stopped.returncode))
return {'message': 'Media player stopped', **status()}
if action != 'play':
raise ValueError('Media action must be list, status, play or stop')
path = media_path(body.get('id'))
if type(body.get('theatre', False)) is not bool:
raise ValueError('theatre must be true or false')
info = {} if path.suffix.lower() == '.splat' else probe(path)[0]
plan = frame_media.plan(path.name, body.get('layout', 'auto'), info.get('tags'))
if active():
raise ValueError('Stop the current media before starting another file')
# systemd owns the process group and refuses a concurrent start of this name.
# The runtime cap also cleans up if the controlling computer disconnects.
subprocess.run(['systemctl', '--user', 'reset-failed', UNIT], stdout=subprocess.DEVNULL,
stderr=subprocess.DEVNULL, timeout=10)
STATUS.write_text(json.dumps({'state': 'starting', 'file': path.name}))
command = ['systemd-run', '--user', '--quiet', '--collect', '--unit='+UNIT,
'--property=RuntimeMaxSec=14400', '--property=TimeoutStopSec=8',
'--property=StandardOutput=append:'+str(RUNTIME/'player.log'),
'--property=StandardError=append:'+str(RUNTIME/'player.log'),
'python3', str(RUNTIME/'frame_media_player.py'), str(path),
'--layout', body.get('layout', 'auto'), '--status', str(STATUS)]
if body.get('theatre'):
command.append('--theatre')
started = subprocess.run(command, capture_output=True, text=True, timeout=15)
if started.returncode:
raise RuntimeError('Could not start the media player: ' + (started.stderr.strip() or 'systemd-run exited %s' % started.returncode))
return {'message': 'Starting Frame Control media', 'plan': plan}
def main():
try:
print(json.dumps(run(json.load(sys.stdin))))
except Exception as e:
print(json.dumps({'error': str(e)}))
sys.exit(1)
if __name__ == '__main__':
main()
+310
View File
@@ -0,0 +1,310 @@
"""Which network this computer is on, and whether Tailscale is up.
Frame Control remembers which of a headset's addresses worked on which network,
so it needs a stable name for "this network". The Wi-Fi name (SSID) is the
friendly one, but macOS 14+ hides it from apps without Location permission, and
wired networks have none. So every network is identified by a fingerprint of
its default gateway: the router's IP and MAC address, which stay the same for a
given home or office network. The user can give a fingerprint a name.
Runs on this computer (macOS, Linux, Windows). Python stdlib only; every probe
is a short command with a timeout, and each parser has fixtures in
tests/test_network.py.
"""
import hashlib
import ipaddress
import json
import os
import re
import socket
import subprocess
import time
import frame_host
TIMEOUT = 3
def run(argv, timeout=TIMEOUT):
"""A command's stdout, or "" if it's missing, fails or takes too long."""
try:
r = subprocess.run(argv, capture_output=True, stdin=subprocess.DEVNULL, timeout=timeout,
**({"creationflags": subprocess.CREATE_NO_WINDOW} if frame_host.WINDOWS else {}))
except (OSError, subprocess.TimeoutExpired):
return ""
return r.stdout.decode("utf-8", "replace") if r.returncode == 0 else ""
def valid_ip(text):
try:
ipaddress.ip_address(text)
return True
except ValueError:
return False
def norm_mac(text):
""""b4:fb:e4:1:87:3f" or "B4-FB-E4-01-87-3F" -> "b4:fb:e4:01:87:3f"; None if it isn't a MAC."""
parts = re.split(r"[:-]", (text or "").strip())
if len(parts) != 6 or not all(re.fullmatch(r"[0-9A-Fa-f]{1,2}", p) for p in parts):
return None
mac = ":".join(p.lower().zfill(2) for p in parts)
return None if mac in ("00:00:00:00:00:00", "ff:ff:ff:ff:ff:ff") else mac
# ---- default gateway -------------------------------------------------------
def parse_route_macos(text):
"""`route -n get default` -> (gateway, interface)."""
gw = re.search(r"^\s*gateway:\s*(\S+)", text, re.M)
iface = re.search(r"^\s*interface:\s*(\S+)", text, re.M)
gateway = gw.group(1) if gw and valid_ip(gw.group(1)) else None
return gateway, iface.group(1) if iface else None
def parse_route_linux(text):
"""`ip -4 route show default` -> (gateway, interface) of the lowest-metric route."""
best = None
for line in text.splitlines():
m = re.search(r"^default via (\S+) dev (\S+)", line.strip())
if not m or not valid_ip(m.group(1)):
continue
metric = re.search(r"\bmetric (\d+)", line)
key = int(metric.group(1)) if metric else 0
if best is None or key < best[0]:
best = (key, m.group(1), m.group(2))
return (best[1], best[2]) if best else (None, None)
def parse_route_windows(text):
"""`route print -4 0.0.0.0` -> (gateway, local IP of the interface), lowest metric wins."""
best = None
for line in text.splitlines():
f = line.split()
if len(f) == 5 and f[0] == "0.0.0.0" and f[1] == "0.0.0.0" and valid_ip(f[2]) and f[4].isdigit():
if best is None or int(f[4]) < best[0]:
best = (int(f[4]), f[2], f[3])
return (best[1], best[2]) if best else (None, None)
# ---- the gateway's MAC address ----------------------------------------------
def parse_arp_macos(text, ip):
"""`arp -n IP` -> MAC ("? (192.168.1.1) at b4:fb:e4:b5:67:55 on en0 ifscope [ethernet]")."""
m = re.search(r"\(" + re.escape(ip) + r"\) at (\S+)", text)
return norm_mac(m.group(1)) if m else None
def parse_neigh_linux(text, ip):
"""`ip neigh show IP` -> MAC ("192.168.1.1 dev wlan0 lladdr b4:fb:... REACHABLE")."""
for line in text.splitlines():
f = line.split()
if f and f[0] == ip and "lladdr" in f:
return norm_mac(f[f.index("lladdr") + 1]) if f.index("lladdr") + 1 < len(f) else None
return None
def parse_arp_windows(text, ip):
"""`arp -a IP` -> MAC (" 192.168.1.1 b4-fb-e4-b5-67-55 dynamic")."""
for line in text.splitlines():
f = line.split()
if len(f) >= 2 and f[0] == ip:
return norm_mac(f[1])
return None
# ---- Wi-Fi name --------------------------------------------------------------
def parse_summary_macos(text):
"""`ipconfig getsummary IFACE` -> (ssid, is_wifi). macOS prints "<redacted>" without Location permission."""
kind = re.search(r"^\s*InterfaceType\s*:\s*(\S+)", text, re.M)
ssid = re.search(r"^\s*SSID\s*:\s*(.+?)\s*$", text, re.M)
name = ssid.group(1) if ssid else None
if name in ("<redacted>", ""):
name = None
return name, (kind.group(1).lower() == "wifi") if kind else None
def parse_nmcli(text):
"""`nmcli -t -f active,ssid dev wifi` -> the active SSID (colons in names come escaped as \\:)."""
for line in text.splitlines():
if line.startswith("yes:"):
return line[4:].replace("\\:", ":") or None
return None
def parse_netsh(text):
"""`netsh wlan show interfaces` -> the connected SSID (not the BSSID line)."""
state = re.search(r"^\s*State\s*:\s*(\S+)", text, re.M)
ssid = re.search(r"^\s*SSID\s*:\s*(.+?)\s*$", text, re.M)
if not ssid or (state and state.group(1).lower() != "connected"):
return None
return ssid.group(1)
# ---- Tailscale -----------------------------------------------------------------
def tailscale_cli():
extra = []
if frame_host.MAC:
extra.append("/Applications/Tailscale.app/Contents/MacOS/Tailscale")
elif frame_host.WINDOWS:
for base in (os.environ.get("ProgramFiles"), os.environ.get("ProgramFiles(x86)")):
if base:
extra.append(os.path.join(base, "Tailscale", "tailscale.exe"))
return frame_host.which("tailscale", *extra)
def parse_tailscale(text):
"""`tailscale status --json` -> {"up", "ip", "name", "tailnet", "peers": [...]}.
Each peer: {"name", "dns" (MagicDNS name, no trailing dot), "ips", "os", "online"}.
"""
try:
data = json.loads(text)
except ValueError:
return {"up": False, "peers": []}
if not isinstance(data, dict):
return {"up": False, "peers": []}
me = data.get("Self") or {}
tailnet = (data.get("CurrentTailnet") or {}).get("Name") if isinstance(data.get("CurrentTailnet"), dict) else None
out = {"up": data.get("BackendState") == "Running",
"ip": next((ip for ip in me.get("TailscaleIPs") or [] if "." in ip), None),
"name": (me.get("DNSName") or "").rstrip(".") or None,
"tailnet": tailnet, "peers": []}
for p in (data.get("Peer") or {}).values():
if not isinstance(p, dict):
continue
out["peers"].append({"name": p.get("HostName") or "", "dns": (p.get("DNSName") or "").rstrip("."),
"ips": [ip for ip in p.get("TailscaleIPs") or [] if isinstance(ip, str)],
"os": p.get("OS") or "", "online": bool(p.get("Online"))})
return out
def tailscale_status():
cli = tailscale_cli()
if not cli:
return {"up": False, "installed": False, "peers": []}
out = parse_tailscale(run([cli, "status", "--json"], timeout=4) or "{}")
out["installed"] = True
return out
TAILNET_V4 = ipaddress.ip_network("100.64.0.0/10")
TAILNET_V6 = ipaddress.ip_network("fd7a:115c:a1e0::/48")
def is_tailscale(host):
host = host.lower().rstrip(".")
if host.endswith(".ts.net"):
return True
try:
ip = ipaddress.ip_address(host)
except ValueError:
return False
return ip in (TAILNET_V4 if ip.version == 4 else TAILNET_V6)
def guess_kind(host):
"""What sort of address a host is: mdns, tailscale, lan or manual."""
h = host.lower().rstrip(".")
if h.endswith(".local"):
return "mdns"
if is_tailscale(h):
return "tailscale"
try:
ip = ipaddress.ip_address(h.split("%")[0])
if ip.is_private or ip.is_link_local:
return "lan"
except ValueError:
pass
return "manual"
# ---- putting it together ----------------------------------------------------------
def network_id(gateway, mac):
"""A short, stable id for a network: its gateway's IP and MAC. None until both are known."""
if not gateway or not mac:
return None
return "n-" + hashlib.sha1(f"{gateway}|{mac}".encode()).hexdigest()[:10]
def local_ip(towards="192.0.2.1"):
"""This computer's address on the default route (UDP connect sends nothing)."""
try:
with socket.socket(socket.AF_INET, socket.SOCK_DGRAM) as s:
s.connect((towards, 9))
return s.getsockname()[0]
except OSError:
return None
def gateway():
"""(gateway IP, interface) of the default route."""
if frame_host.MAC:
return parse_route_macos(run(["route", "-n", "get", "default"]))
if frame_host.WINDOWS:
return parse_route_windows(run(["route", "print", "-4", "0.0.0.0"]))
return parse_route_linux(run(["ip", "-4", "route", "show", "default"]))
def gateway_mac(ip):
if frame_host.MAC:
return parse_arp_macos(run(["arp", "-n", ip]), ip)
if frame_host.WINDOWS:
return parse_arp_windows(run(["arp", "-a", ip]), ip)
return parse_neigh_linux(run(["ip", "neigh", "show", ip]), ip)
def poke(ip):
"""Make the system look up the gateway's MAC (an ARP entry can expire)."""
try:
with socket.create_connection((ip, 53), timeout=0.3):
pass
except OSError:
pass
def wifi(interface):
"""(ssid or None, is_wifi or None) for the default route's interface."""
if frame_host.MAC:
if interface:
ssid, is_wifi = parse_summary_macos(run(["ipconfig", "getsummary", interface]))
if ssid or is_wifi is False:
return ssid, is_wifi
m = re.search(r"Current Wi-Fi Network: (.+)", run(["networksetup", "-getairportnetwork", interface]))
return (m.group(1).strip() if m else None), is_wifi
return None, None
if frame_host.WINDOWS:
ssid = parse_netsh(run(["netsh", "wlan", "show", "interfaces"]))
return ssid, True if ssid else None
if frame_host.which("nmcli"):
ssid = parse_nmcli(run(["nmcli", "-t", "-f", "active,ssid", "dev", "wifi"]))
else:
ssid = run(["iwgetid", "-r"]).strip() or None
return ssid, True if ssid else (interface.startswith(("wl", "wlan")) if interface else None)
def fingerprint():
"""The cheap part, polled every few seconds: (gateway, interface, gateway MAC)."""
gw, iface = gateway()
mac = None
if gw:
mac = gateway_mac(gw)
if not mac:
poke(gw)
mac = gateway_mac(gw)
return gw, iface, mac
def current_network(fp=None, with_tailscale=True):
"""Everything the connection status shows about this computer's network."""
gw, iface, mac = fp or fingerprint()
ssid, is_wifi = wifi(iface) if gw else (None, None)
net = {"id": network_id(gw, mac), "gateway": gw, "gateway_mac": mac, "interface": iface,
"ssid": ssid, "wifi": is_wifi, "local_ip": local_ip(gw) if gw else None, "checked": time.time()}
if with_tailscale:
ts = tailscale_status()
net["tailscale"] = {k: ts.get(k) for k in ("up", "installed", "ip", "name", "tailnet")}
return net
+261
View File
@@ -0,0 +1,261 @@
"""Panel switcher. Runs on the Frame, either piped over SSH or installed with
--open for its loopback-only headset page. Uses Valve's shipped vrcmd and
Chromium, not an overlay app. Spatial layout limitations: docs/panels.md.
"""
import argparse
import hmac
import json
import os
from pathlib import Path
import re
import secrets
import signal
import subprocess
import sys
import time
from http.server import BaseHTTPRequestHandler, HTTPServer
VRCMD = '/opt/steamvr/bin/linuxarm64/vrcmd'
PANEL_ID = 2000999030
PANEL_KEY = 'valve.steam.desktopgame.' + str(PANEL_ID)
KEY = re.compile(r'[A-Za-z0-9_.:-]{1,200}\Z')
class PanelError(Exception):
pass
def run(args):
try:
p = subprocess.run(args, capture_output=True, text=True, timeout=10,
env={**os.environ, 'DISPLAY': ':0', 'LC_ALL': 'C.UTF-8'})
except (OSError, subprocess.TimeoutExpired) as e:
raise PanelError('The panel service did not answer: ' + str(e))
if p.returncode:
raise PanelError((p.stderr or p.stdout).strip()[-400:] or 'Panel command failed')
return p.stdout
def parse_overlays(text):
"""Only main dashboard panels, never their thumbnails, layers or cursors.
vrcmd output verified on SteamVR 2.18.1, BUILD_ID 20260925.6191901.
"""
if '---- OVERLAYS ----' not in text:
raise PanelError('SteamVR did not return its panel list. Is the headset awake?')
panels = []
for line in text.splitlines():
m = re.fullmatch(r"'([^']+)' -- '(.*)', (.*?) VROverlayType_Dashboard_Main\s*", line)
if m and KEY.fullmatch(m[1]):
panels.append({'key': m[1], 'title': 'Panel switcher' if m[1] == PANEL_KEY else m[2] or m[1],
'visible': 'not_visible' not in m[3]})
return panels
def state():
return {'panels': parse_overlays(run([VRCMD, '--overlays']))}
def focus(key):
if not isinstance(key, str) or not KEY.fullmatch(key):
raise PanelError('Choose an open panel.')
if key not in {p['key'] for p in state()['panels']}:
raise PanelError('That panel has closed. Refresh the list.')
run([VRCMD, '--showdashboard', key])
# vrcmd acknowledges dispatch, not final focus (a game or the user can
# switch again). Do not report a focus success without observing it.
return {'requested': key, 'message': 'Asked SteamVR to show the panel.'}
PAGE = '''<!doctype html><html lang="en"><meta charset="utf-8">
<meta name="viewport" content="width=device-width,initial-scale=1"><title>Panel switcher [fc-panels]</title>
<style>body{background:#101b27;color:#eee;font:24px system-ui;margin:36px;max-width:1000px}
h1{font-size:36px}button{font:inherit;padding:16px 24px;border:1px solid #546574;border-radius:10px;
background:#23384b;color:white;cursor:pointer}button:focus-visible{outline:4px solid #66c0f4}
#panels{display:grid;gap:14px;margin:24px 0}#panels button{text-align:left}p{color:#bac8d5}</style>
<h1>Panel switcher</h1><p>Choose a panel to show it. Open this panel again from Steam's dashboard.</p>
<button id="refresh">Refresh</button> <button id="close">Close switcher</button>
<p id="status" role="status"></p><div id="panels"></div>
<script>
const token=location.hash.slice(1)||sessionStorage.getItem('panelKey')||'';
if(token)sessionStorage.setItem('panelKey',token);history.replaceState(null,'',location.pathname);
async function api(path,body){const r=await fetch(path,{method:body?'POST':'GET',
headers:{'X-Panel-Key':token,'Content-Type':'application/json'},body:body?JSON.stringify(body):undefined});
const s=await r.json();if(!r.ok)throw Error(s.error||'Panel request failed');return s;}
const status=document.getElementById('status');
async function refresh(){try{const s=await api('/panels');const list=document.getElementById('panels');list.replaceChildren();
for(const p of s.panels){const b=document.createElement('button');b.textContent=p.title;
b.onclick=async()=>{b.disabled=true;try{const r=await api('/focus',{key:p.key});status.textContent=r.message;}
catch(e){status.textContent=e.message;}finally{b.disabled=false;}};list.append(b);}
status.textContent=s.panels.length?'':'No open panels.';}catch(e){status.textContent=e.message;}}
document.getElementById('refresh').onclick=refresh;
document.getElementById('close').onclick=async()=>{try{await api('/close',{});window.close();}catch(e){status.textContent=e.message;}};
refresh();
</script></html>'''
class Handler(BaseHTTPRequestHandler):
def setup(self):
super().setup()
self.connection.settimeout(5)
def log_message(self, *args):
pass # never log the page's access key
def reply(self, code, value, html=False):
data = value.encode() if html else json.dumps(value).encode()
self.send_response(code)
self.send_header('Content-Type', 'text/html; charset=utf-8' if html else 'application/json')
self.send_header('Content-Length', str(len(data)))
self.send_header('Cache-Control', 'no-store')
self.send_header('X-Content-Type-Options', 'nosniff')
self.send_header('Referrer-Policy', 'no-referrer')
self.send_header('Content-Security-Policy', "default-src 'none'; script-src 'unsafe-inline'; style-src 'unsafe-inline'; connect-src 'self'; frame-ancestors 'none'")
self.end_headers()
self.wfile.write(data)
def allowed(self):
host = '127.0.0.1:' + str(self.server.server_port)
origin = self.headers.get('Origin')
return (self.headers.get('Host') == host and
(origin is None or origin == 'http://' + host) and
hmac.compare_digest(self.headers.get('X-Panel-Key', '').encode(), self.server.key.encode()))
def do_GET(self):
if self.path == '/':
return self.reply(200, PAGE, html=True) # no data or access key in the page
if not self.allowed():
return self.reply(403, {'error': 'Open the switcher from Frame Control.'})
try:
if self.path == '/panels':
return self.reply(200, state())
self.reply(404, {'error': 'Not found'})
except PanelError as e:
self.reply(502, {'error': str(e)})
def do_POST(self):
if not self.allowed():
return self.reply(403, {'error': 'Forbidden'})
try:
size = int(self.headers.get('Content-Length', '0'))
if not 0 < size <= 1024:
raise ValueError('Invalid request size')
body = json.loads(self.rfile.read(size))
if not isinstance(body, dict):
raise ValueError('Expected an object')
if self.path == '/focus':
return self.reply(200, focus(body.get('key')))
if self.path == '/close':
self.server.closing = True
return self.reply(200, {'closed': True})
self.reply(404, {'error': 'Not found'})
except (ValueError, PanelError) as e:
self.reply(400, {'error': str(e)})
def serve():
"""Own only our Chromium profile and process group. No changes to Steam,
SteamVR, other Chromium sessions, or global power settings.
"""
import fcntl # only on the Frame; module/tests also import on Windows
folder = Path.home() / '.local/share/frame-control/panels'
folder.mkdir(parents=True, exist_ok=True, mode=0o700)
with (folder / 'lock').open('w') as lock:
try:
fcntl.flock(lock, fcntl.LOCK_EX | fcntl.LOCK_NB)
except BlockingIOError:
print(json.dumps(focus(PANEL_KEY)), flush=True)
return
chrome = Path.home() / 'chromium-xr/chrome'
if chrome.is_file():
command = [str(chrome)]
profile = folder / 'chromium'
elif Path('/usr/bin/chromium').is_file():
command = ['/usr/bin/chromium']
profile = folder / 'chromium'
elif subprocess.run(['flatpak', 'info', 'org.chromium.Chromium'],
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL, timeout=10).returncode == 0:
command = ['flatpak', 'run', 'org.chromium.Chromium']
profile = Path.home() / '.var/app/org.chromium.Chromium/data/frame-panel-switcher'
else:
raise PanelError('The headset switcher needs Chromium. The companion switcher still works.')
server = HTTPServer(('127.0.0.1', 0), Handler)
server.key = secrets.token_urlsafe(32)
server.closing = False
server.timeout = .5
url = 'http://127.0.0.1:%d/#%s' % (server.server_port, server.key)
env = {**os.environ, 'DISPLAY': ':0'}
env.pop('WAYLAND_DISPLAY', None)
browser = subprocess.Popen([*command, '--ozone-platform=x11',
'--user-data-dir=' + str(profile),
'--no-first-run', '--no-default-browser-check',
'--password-store=basic', '--window-size=1200,800', '--app=' + url],
env=env, start_new_session=True, stdin=subprocess.DEVNULL,
stdout=subprocess.DEVNULL, stderr=subprocess.DEVNULL)
def stop(signum, frame):
server.closing = True
signal.signal(signal.SIGTERM, stop)
win = None
try:
deadline = time.monotonic() + 30
while not win and time.monotonic() < deadline and browser.poll() is None:
server.handle_request() # Chromium must fetch the page before it has a title
for line in run(['xwininfo', '-root', '-children']).splitlines():
m = re.match(r'\s*(0x[0-9a-fA-F]+) .*\[fc-panels\]', line)
if m:
win = m[1]
break
if not win:
raise PanelError('The switcher window did not appear within 30 seconds.')
run(['xprop', '-id', win, '-f', 'STEAM_GAME', '32c', '-set', 'STEAM_GAME', str(PANEL_ID)])
print(json.dumps({'message': 'Opened the panel switcher in the headset.'}), flush=True)
# Caller reads exactly one line, then disconnects; no more stdout.
while not server.closing and browser.poll() is None:
server.handle_request()
# Closing the last app window need not exit Chromium.
if win not in run(['xwininfo', '-root', '-children']):
break
finally:
server.server_close()
if browser.poll() is None:
os.killpg(browser.pid, signal.SIGTERM)
try:
browser.wait(timeout=5)
except subprocess.TimeoutExpired:
os.killpg(browser.pid, signal.SIGKILL)
browser.wait()
def open_switcher():
# This command runs from an installed path, never from the SSH stdin copy.
proc = subprocess.Popen([sys.executable, str(Path(__file__).resolve()), '--serve'],
stdin=subprocess.DEVNULL, stdout=subprocess.PIPE, stderr=subprocess.DEVNULL,
text=True, start_new_session=True)
line = proc.stdout.readline()
proc.stdout.close()
if not line:
raise PanelError('The headset switcher could not start.')
result = json.loads(line)
if 'error' in result:
raise PanelError(result['error'])
return result
def main():
parser = argparse.ArgumentParser(description=__doc__)
parser.add_argument('--focus')
parser.add_argument('--open', action='store_true')
parser.add_argument('--serve', action='store_true')
args = parser.parse_args()
try:
if args.serve:
serve()
else:
print(json.dumps(open_switcher() if args.open else focus(args.focus) if args.focus else state()))
except (PanelError, OSError) as e:
print(json.dumps({'error': str(e)}), flush=True)
return 1
return 0
if __name__ == '__main__':
sys.exit(main())
+161
View File
@@ -0,0 +1,161 @@
"""Report a problem from inside Frame Control. Python stdlib only.
The page's Report a problem dialog shows the diagnostics below before anything
is sent, then this sends the report privately to Frame Control's PostHog
project as a `problem_report` event: only the maintainer can read it, and
nothing is published. It is sent whatever the analytics settings are, because
the person sends it deliberately. Diagnostics are scrubbed first
(frame_telemetry.scrub); the person's own words are sent as written.
"""
import os
import platform
import sys
import time
import uuid
import frame_host
import frame_telemetry
KINDS = ('bug', 'idea', 'question', 'other')
TEXT_MAX = 5000 # the person's own text, in JavaScript (UTF-16) units like the page's maxlength
DIAG_MAX = 8000 # the diagnostics block
LOG_LINES = 60
ACTIVITY_LINES = 25
frame = {} # the Frame's last known SteamOS build, set by server.status()
def u16(s):
"""Length as the website's validator counts it (JavaScript strings are UTF-16)."""
return len(s.encode('utf-16-le')) // 2
def cut(s, n):
"""s shortened to at most n UTF-16 units, never splitting a character."""
while u16(s) > n:
s = s[:max(0, len(s) - max(1, (u16(s) - n) // 2))]
return s
def _log_tail():
"""The last lines of the server log the app writes (FRAME_CONTROL_LOG), newest first."""
path = os.environ.get('FRAME_CONTROL_LOG')
if not path:
return []
try:
with open(path, 'rb') as f:
f.seek(0, os.SEEK_END)
f.seek(max(0, f.tell() - 64 * 1024))
lines = f.read().decode('utf-8', 'replace').splitlines()
except OSError:
return []
# Request lines ("GET /api/status ...") are noise; keep what went wrong.
keep = [ln for ln in lines if ln.strip() and not ln.startswith(('GET ', 'POST '))]
return list(reversed(keep[-LOG_LINES:]))
def diagnostics(activity=(), include_logs=False, limit=DIAG_MAX):
"""What a report includes, scrubbed and at most `limit` UTF-16 units. Always the versions
and builds; recent activity and the server log only when asked for, since they can name
files. Sections are filled in order of use, newest lines first, so trimming drops the oldest."""
t = frame_telemetry.state()
levels = ', '.join(f"{name} {'on' if on else 'off'}" for name, on in
(('usage', t['usage']), ('compat', t['compat']), ('error details', t['diagnostics'])))
env = [
f"Frame Control {frame_telemetry.app_version()}"
f"{' (built app)' if os.environ.get('FRAME_CONTROL_PACKAGED') else ' (source checkout)'}",
f"Computer: {frame_host.NAME} {platform.release()} {platform.machine()}, Python {'%d.%d.%d' % sys.version_info[:3]}",
f"SteamOS: {frame.get('build') or 'unknown'} ({frame.get('version') or 'not connected since start'})",
f"Analytics: {levels}",
f"Report time: {time.strftime('%Y-%m-%d %H:%M %Z')}",
]
out = frame_telemetry.scrub('\n'.join(env), limit=limit)
if not include_logs:
return cut(out, limit)
sections = [('Recent activity (newest first):', [str(a)[:300] for a in list(activity)[:ACTIVITY_LINES] if isinstance(a, str)]),
('Server log (newest first):', _log_tail())]
for title, lines in sections:
if not lines:
continue
block = '\n\n' + title
if u16(out + block) > limit:
break
out += block
for line in lines:
line = '\n' + frame_telemetry.scrub(line, 300)
if u16(out + line) > limit:
break
out += line
return out
def compose(body):
"""(title, text, diagnostics): the diagnostics exactly as the dialog previewed them (passed
back, scrubbed again and bounded here)."""
title = ' '.join(str(body.get('title') or '').split())
text = str(body.get('message') or '').strip()
if len(title) < 5:
raise ValueError('give it a short title (at least 5 characters)')
if len(text) < 10:
raise ValueError('say a little more about what happened (at least 10 characters)')
diag = body.get('diagnostics')
diag = cut(frame_telemetry.scrub(diag, 40000), DIAG_MAX) if isinstance(diag, str) and diag.strip() else ''
return cut(title, 120), cut(text, TEXT_MAX), diag
def send(body):
"""Send the report to PostHog. Returns {"id", "message"}; raises ReportError."""
kind = body.get('kind') if body.get('kind') in KINDS else 'bug'
title, text, diag = compose(body)
ref = uuid.uuid4().hex[:8].upper()
props = {**frame_telemetry.common(), 'kind': kind, 'title': title, 'message': text,
'contact': str(body.get('contact') or '').strip()[:120], 'diagnostics': diag,
'report_id': ref, 'steamos': str(frame.get('build') or '')[:120], 'level': 'report'}
# Its own random id: a report can carry contact details, so it isn't linked to this copy's analytics.
event = {'event': 'problem_report', 'distinct_id': str(uuid.uuid4()), 'uuid': str(uuid.uuid4()),
'timestamp': time.strftime('%Y-%m-%dT%H:%M:%SZ', time.gmtime()), 'properties': props}
try:
frame_telemetry.post([event], timeout=30)
except frame_telemetry.SendError as e:
raise ReportError(str(e))
try:
frame_telemetry.record_sent([event])
except OSError:
pass # it was sent; failing to log it here mustn't make the person send it again
return {'id': ref, 'message': f'Sent privately to the Frame Control developer (report {ref}).'}
class ReportError(RuntimeError):
pass
def inbox(days=30):
"""The maintainer's recent reports from PostHog, newest first (needs the personal API key
frame_compat_db.sync uses)."""
import frame_compat_db
res = frame_compat_db._posthog_query(
"SELECT timestamp, properties.report_id, properties.kind, properties.title, properties.message, "
"properties.contact, properties.app_version, properties.os, properties.steamos, properties.diagnostics "
f"FROM events WHERE event = 'problem_report' AND timestamp > now() - INTERVAL {int(days)} DAY "
"ORDER BY timestamp DESC LIMIT 200")
return res.get('results') or []
def main():
cmd, *args = sys.argv[1:] or ['inbox']
if cmd != 'inbox':
sys.exit('usage: frame_report.py inbox [days]')
for row in inbox(*(args[:1] or [30])):
if not isinstance(row, list) or len(row) != 10:
continue
ts, ref, kind, title, text, contact, version, osname, steamos, diag = (str(v or '') for v in row)
print(f"== {ts[:16].replace('T', ' ')} {ref} [{kind}] {title}")
print(f" {version} on {osname}, SteamOS {steamos or 'unknown'}{', reply to ' + contact if contact else ''}")
print(' ' + text.replace('\n', '\n '))
if diag:
print(' --- diagnostics\n ' + diag.replace('\n', '\n '))
print()
if __name__ == '__main__':
main()
+83
View File
@@ -0,0 +1,83 @@
"""Small, bounded CPU Gaussian-splat preview renderer (Frame Control-owned).
Reads the common 32-byte .splat record: position/scale float32 triplets,
RGBA bytes, then normalized quaternion bytes (wxyz). Two perspective cameras,
projected 3D covariance, back-to-front alpha compositing. This is a stationary
stereo preview, not a six-degree-of-freedom scene or a large-scene renderer.
"""
import math
from pathlib import Path
import struct
MAX_SPLATS = 20000
RECORD = struct.Struct('<6f8B')
def read(path):
size = Path(path).stat().st_size
if not size or size % RECORD.size or size > MAX_SPLATS * RECORD.size:
raise ValueError('Use a 32-byte .splat file with 1–20,000 Gaussians; PLY/SPZ and larger scenes are not supported yet')
values = []
with open(path, 'rb') as stream:
for row in RECORD.iter_unpack(stream.read(MAX_SPLATS * RECORD.size + 1)):
xyz, scales = row[:3], row[3:6]
if not all(math.isfinite(v) and abs(v) <= 1e6 for v in row[:6]) or min(scales) <= 0:
raise ValueError('Invalid splat position or scale')
q = [(v - 128) / 128 for v in row[10:14]]
length = math.sqrt(sum(v*v for v in q))
if length < .01:
raise ValueError('Invalid splat quaternion')
w, x, y, z = [v / length for v in q]
rotation = ((1-2*(y*y+z*z), 2*(x*y-z*w), 2*(x*z+y*w)),
(2*(x*y+z*w), 1-2*(x*x+z*z), 2*(y*z-x*w)),
(2*(x*z-y*w), 2*(y*z+x*w), 1-2*(x*x+y*y)))
cov = [[sum(rotation[i][k]*rotation[j][k]*scales[k]**2 for k in range(3))
for j in range(3)] for i in range(3)]
values.append((xyz, cov, row[6:10]))
return values
def render(path, width=320, height=240):
values = read(path)
lo = [min(p[0][i] for p in values) for i in range(3)]
hi = [max(p[0][i] for p in values) for i in range(3)]
center = [(a+b)/2 for a, b in zip(lo, hi)]
radius = max(max(b-a for a, b in zip(lo, hi))/2, .01)
# Normalize captures to a two-metre box. Source units are not assumed metres.
normalized = [([(xyz[i]-center[i])/radius for i in range(3)],
[[v/radius**2 for v in row] for row in cov], color)
for xyz, cov, color in values]
normalized.sort(key=lambda p: p[0][2]) # camera is at z=3; farthest first
focal = width * .8
eyes = []
for eye in (-.032, .032):
pixels = bytearray(b'\x00\x00\x00\xff' * (width*height))
for (x, y, z), cov, color in normalized:
x -= eye
depth = 3-z
px, py = width/2+focal*x/depth, height/2-focal*y/depth
jac = ((focal/depth, 0, focal*x/depth**2),
(0, -focal/depth, -focal*y/depth**2))
screen = [[sum(jac[i][a]*cov[a][b]*jac[j][b] for a in range(3) for b in range(3))
for j in range(2)] for i in range(2)]
a, b, c = screen[0][0]+.3, screen[0][1], screen[1][1]+.3
det = a*c-b*b
if det <= 0 or not math.isfinite(det):
raise ValueError('Splat covariance is not renderable')
# A footprint cap bounds work on malformed or oversized Gaussians.
rx, ry = min(32, math.ceil(3*math.sqrt(a))), min(32, math.ceil(3*math.sqrt(c)))
for sy in range(max(0, int(py)-ry), min(height, int(py)+ry+1)):
dy = sy+.5-py
for sx in range(max(0, int(px)-rx), min(width, int(px)+rx+1)):
dx = sx+.5-px
power = (c*dx*dx-2*b*dx*dy+a*dy*dy)/det
if power > 9:
continue
alpha = color[3]/255 * math.exp(-.5*power)
offset = (sy*width+sx)*4
for k in range(3):
pixels[offset+k] = round(color[k]*alpha+pixels[offset+k]*(1-alpha))
eyes.append(pixels)
stride = width*4
return b''.join(eyes[0][y*stride:(y+1)*stride]+eyes[1][y*stride:(y+1)*stride]
for y in range(height)), width*2, height
+157 -25
View File
@@ -1,9 +1,12 @@
"""Runs ON the Steam Frame (piped over SSH as `python3 -`); prints one JSON object.
Read-only. Every probe is best effort: a missing tool or file gives null, not an
error. Paths verified on SteamOS 0.3.0 (vr), build 20260922.
error. Sensor paths verified on SteamOS 0.3.0; OpenVR timing on 0.4.1
(build 20260925.6191901). See docs/vr-utilities.md.
"""
import ctypes as C
import glob
import math
import json
import os
import re
@@ -156,27 +159,156 @@ def flatpaks():
return out
uptime = read("/proc/uptime")
procs = process_names()
print(json.dumps({
"time": time.time(),
"hostname": socket.gethostname(),
"os": os_release(),
"uptime": float(uptime.split()[0]) if uptime else None,
"battery": battery(),
"power": power_source(),
"disk": {"root": disk("/"), "home": disk("/home")},
"memory": memory(),
"temp": max_temp(),
"wifi": wifi(),
"ip": ip_addr(),
"volume": volume(),
"services": {
"steamvr": "vrserver" in procs,
"desktop": "plasmashell" in procs,
"lepton": port_listening(5555),
"rdp": "xrdp" in procs,
},
"games": games(),
"flatpaks": flatpaks(),
}))
def thermal_alerts():
"""Use the kernel's per-zone hot/critical trips, never a guessed chip limit."""
alerts, known = [], False
for z in glob.glob("/sys/class/thermal/thermal_zone*"):
t = num(z + "/temp", 0.001)
for trip in glob.glob(z + "/trip_point_*_type"):
if read(trip) not in ("hot", "critical"):
continue
limit = num(trip[:-4] + "temp", 0.001)
if t is not None and limit is not None and limit > 0:
known = True
if t >= limit:
alerts.append({"zone": read(z + "/type"), "tempC": t, "limitC": limit})
return alerts if known else None
def activity_level():
try:
rows = json.loads(run("/opt/steamvr/bin/linuxarm64/vrcmd", "--stats"))
if not isinstance(rows, list):
return None
return next((r.get("activity_level") for r in rows
if isinstance(r, dict) and r.get("operation") == "status"), None)
except (ValueError, TypeError):
return None
# OpenVR C ABI, ValveSoftware/openvr headers/openvr_capi.h (IVRCompositor_029).
# Exact interface version: never guess an index against a different table.
class Pose(C.Structure):
_fields_ = [('matrix', C.c_float * 12), ('velocity', C.c_float * 3),
('angular', C.c_float * 3), ('result', C.c_int),
('valid', C.c_bool), ('connected', C.c_bool)]
class Timing(C.Structure):
_fields_ = [(n, C.c_uint32) for n in ('size', 'index', 'presents', 'mis', 'dropped', 'flags')] + [
('time', C.c_double)] + [(n, C.c_float) for n in (
'gpuPre', 'gpuPost', 'gpu', 'compositorGpu', 'compositorCpu', 'idleCpu', 'interval',
'presentCpu', 'waitCpu', 'submit', 'posesCalled', 'posesReady', 'frameReady',
'updateStart', 'updateEnd', 'renderStart')] + [
('pose', Pose), ('ready', C.c_uint32), ('first', C.c_uint32), ('transfer', C.c_float)]
class OpenVR:
def __enter__(self):
self.lib = C.CDLL('/opt/steamvr/bin/linuxarm64/libopenvr_api.so')
self.lib.VR_InitInternal2.argtypes = [C.POINTER(C.c_int), C.c_int, C.c_char_p]
self.lib.VR_GetGenericInterface.argtypes = [C.c_char_p, C.POINTER(C.c_int)]
self.lib.VR_GetGenericInterface.restype = C.c_void_p
err = C.c_int()
self.lib.VR_InitInternal2(C.byref(err), 3, None) # background: never start or keep SteamVR running
if err.value:
raise RuntimeError(f'SteamVR unavailable (init {err.value})')
return self
def __exit__(self, *args):
self.lib.VR_ShutdownInternal()
def function(self, interface, index, result, *args):
err = C.c_int()
ptr = self.lib.VR_GetGenericInterface(('FnTable:' + interface).encode(), C.byref(err))
if err.value or not ptr:
raise RuntimeError(f'{interface} unavailable ({err.value})')
return C.CFUNCTYPE(result, *args)(C.cast(ptr, C.POINTER(C.c_void_p))[index])
def cpu_ticks():
line = (read('/proc/stat') or '').splitlines()
if not line or not line[0].startswith('cpu '):
return None
try:
# guest/guest_nice are already included in user/nice.
ticks = [int(x) for x in line[0].split()[1:9]]
return sum(ticks), ticks[3] + ticks[4]
except (ValueError, IndexError):
return None
def cpu_percent(before, after):
if before is None or after is None or after[0] <= before[0]:
return None
return round(max(0, min(100, 100 * (1 - (after[1] - before[1]) / (after[0] - before[0])))), 1)
def positive(value):
return round(value, 2) if math.isfinite(value) and value > 0 else None
def timing_values(before, after):
dt, frames = after.time - before.time, after.index - before.index
if dt <= 0 or frames <= 0 or frames / dt > 1000:
return {} # standby or old data; never present stale timings as live
return {'compositorFps': positive(frames / dt),
'frameMs': positive(1000 * dt / frames),
'appFps': positive(1000 / after.interval) if after.interval > 0 else None,
'gpuMs': positive(after.gpu), 'compositorCpuMs': positive(after.compositorCpu)}
def performance():
out = {'compositorFps': None, 'frameMs': None, 'appFps': None,
'gpuMs': None, 'compositorCpuMs': None, 'cpuPercent': None,
'gpuMHz': num('/sys/class/devfreq/3d00000.gpu/cur_freq', 1e-6)}
before = cpu_ticks()
try:
with OpenVR() as vr:
get = vr.function('IVRCompositor_029', 10, C.c_bool, C.POINTER(Timing), C.c_uint32)
a, b = Timing(), Timing()
a.size = b.size = C.sizeof(Timing)
first = get(C.byref(a), 0)
time.sleep(0.2)
if first and get(C.byref(b), 0):
out.update(timing_values(a, b))
except (OSError, RuntimeError, AttributeError): # AttributeError: a SteamVR build without these exports
time.sleep(0.2)
out['cpuPercent'] = cpu_percent(before, cpu_ticks())
return out
def status():
uptime = read("/proc/uptime")
procs = process_names()
return {
"time": time.time(),
"performance": performance(),
"hostname": socket.gethostname(),
"os": os_release(),
"uptime": float(uptime.split()[0]) if uptime else None,
"battery": battery(),
"power": power_source(),
"disk": {"root": disk("/"), "home": disk("/home")},
"memory": memory(),
"temp": max_temp(),
"wifi": wifi(),
"ip": ip_addr(),
"volume": volume(),
"services": {
"steamvr": "vrserver" in procs,
"desktop": "plasmashell" in procs,
"lepton": port_listening(5555),
"rdp": "xrdp" in procs,
},
"games": games(),
"flatpaks": flatpaks(),
}
def main():
print(json.dumps(status()))
if __name__ == "__main__":
main()
+21
View File
@@ -141,6 +141,21 @@ OWNED_JS = r"""
})()
"""
# Software has app_type 2, so utility ownership must not use OWNED_JS's games filter.
# Steam prices checked 2026-09-28: OVR Advanced Settings is paid on Steam too.
UTILITY_IDS = (1009850, 1173510, 1068820, 908520, 1494460)
FREE_UTILITIES = (1494460,)
UTILITIES_JS = """(() => {
const apps = appStore.allApps;
if (!apps || !apps.length) throw new Error("Steam library is not loaded; ownership is unknown");
return [1009850,1173510,1068820,908520,1494460].map(id => {
const a = apps.find(a => a.appid === id);
return {id, owned: !!a, installed: !!a?.local_per_client_data?.installed,
frame: a ? (a.steam_hw_compat_category_packed >> 8) & 3 : 0};
});
})()"""
WIZARD_JS = """SteamClient.Installs.GetInstallManagerInfo().then(i => ({
state: i?.eInstallState ?? 0, app: i?.currentAppID ?? 0, need: i?.nDiskSpaceRequired || 0,
free: i?.nDiskSpaceAvailable || 0, error: i?.eAppError, detail: i?.errorDetail }))"""
@@ -158,6 +173,10 @@ def owned():
def install(appid):
page = Page()
if appid in UTILITY_IDS and appid not in FREE_UTILITIES:
rows = page.eval(UTILITIES_JS)
if not any(r['id'] == appid and r['owned'] for r in rows):
raise Fail("This paid utility is not owned by the Frame account. No install or store action was taken.")
app = page.eval(f"(a => a && {{name: a.display_name, installed: !!a.local_per_client_data?.installed}})"
f"(appStore.GetAppOverviewByAppID({appid}))")
if app and app["installed"]:
@@ -216,6 +235,8 @@ def main():
cmd = sys.argv[1] if len(sys.argv) > 1 else ""
if cmd == "owned":
out = owned()
elif cmd == "utilities":
out = {"utilities": Page().eval(UTILITIES_JS)}
elif cmd in ("install", "store") and len(sys.argv) == 3 and sys.argv[2].isdigit():
out = (install if cmd == "install" else store)(int(sys.argv[2]))
else:
+105
View File
@@ -0,0 +1,105 @@
"""Optional SteamGridDB artwork. Credentials stay on the host, never in app metadata."""
import json
import os
import re
import tempfile
import time
import unicodedata
import urllib.parse
import frame_host
API = 'https://www.steamgriddb.com/api/v2'
MAX_JSON = 2 * 1024 * 1024
def settings_path():
return frame_host.data_dir('artwork-settings.json')
def api_key():
env = os.environ.get('STEAMGRIDDB_API_KEY') or os.environ.get('FRAME_STEAMGRIDDB_API_KEY')
if env:
return env.strip()
try:
return str(json.loads(settings_path().read_text()).get('steamgriddb_api_key') or '')
except (OSError, ValueError, AttributeError):
return ''
def settings():
return {'steamgriddb_configured': bool(api_key()),
'environment': bool(os.environ.get('STEAMGRIDDB_API_KEY') or os.environ.get('FRAME_STEAMGRIDDB_API_KEY'))}
def save_settings(body):
key = body.get('steamgriddb_api_key')
if not isinstance(key, str) or len(key) > 200 or (key and not re.fullmatch(r'[A-Za-z0-9_-]+', key)):
raise ValueError('enter a valid SteamGridDB API key, or an empty value to remove it')
path = settings_path()
path.parent.mkdir(parents=True, exist_ok=True)
fd, temp = tempfile.mkstemp(prefix='.artwork-', dir=str(path.parent))
try:
with os.fdopen(fd, 'w') as f:
json.dump({'steamgriddb_api_key': key}, f)
os.replace(temp, path)
finally:
if os.path.exists(temp):
os.remove(temp)
return settings()
def _get(path, key, deadline=None):
from apk_sources import _images
# No redirects: the credential never goes anywhere but the API. Errors never contain it.
data = _images.get(API + path, {'Authorization': 'Bearer ' + key, 'Accept': 'application/json'}, redirects=0,
deadline=time.monotonic() + 12 if deadline is None else min(deadline, time.monotonic() + 12),
limit=MAX_JSON)
result = json.loads(data)
if not isinstance(result, dict) or not result.get('success') or not isinstance(result.get('data'), list):
raise ValueError('SteamGridDB lookup failed')
return result['data']
def _name(value):
# Letters and digits of any script, so a CJK title never normalises to ''.
return ''.join(c for c in unicodedata.normalize('NFKC', str(value or '')).casefold() if c.isalnum())
def lookup(name, deadline=None):
"""Best-voted art per slot for an exact title match; unrelated games are never guessed."""
key = api_key()
if not key:
return {}, []
try:
names = {_name(name), _name(re.sub(r'\s+VR$', '', name, flags=re.I))} - {''}
if not names:
return {}, []
matches = _get('/search/autocomplete/' + urllib.parse.quote(name, safe=''), key, deadline)
game = next((g for g in matches if isinstance(g, dict) and _name(g.get('name')) in names), None)
if not game:
return {}, []
gid = int(game['id'])
result, warnings = {}, []
for slot, kind, dimensions in [('grid', 'grids', '600x900'), ('wide', 'grids', '920x430'),
('hero', 'heroes', ''), ('logo', 'logos', ''), ('icon', 'icons', '')]:
try:
# Logos and icons only come as PNG (or WebP/ICO); asking for JPEG there is rejected outright.
mimes = 'image/png,image/jpeg' if kind in ('grids', 'heroes') else 'image/png'
query = {'types': 'static', 'nsfw': 'false', 'humor': 'false', 'mimes': mimes}
if dimensions:
query['dimensions'] = dimensions
records = _get('/' + kind + '/game/' + str(gid) + '?' + urllib.parse.urlencode(query), key, deadline)
records = [r for r in records if isinstance(r, dict) and str(r.get('url', '')).startswith('https://')
and not r.get('nsfw')]
if dimensions:
w, h = map(int, dimensions.split('x'))
records = [r for r in records if (r.get('width'), r.get('height')) == (w, h)]
records.sort(key=lambda r: (int(r.get('score') or 0), int(r.get('upvotes') or 0)), reverse=True)
if records:
result[slot] = records[0]['url']
except Exception: # HTTPException, odd JSON: this slot falls back
warnings.append('SteamGridDB ' + slot + ' unavailable; using source or generated art')
return result, warnings
except Exception:
return {}, ['SteamGridDB unavailable; using source or generated art']
+545
View File
@@ -0,0 +1,545 @@
"""Anonymous analytics for Frame Control, sent to PostHog. Python stdlib only.
Three levels, each chosen in the page's Privacy panel (docs/privacy.md lists
every event and property):
- usage (on by default, after the first-run notice has been shown): installs of
Frame Control, daily opens, updates, which tabs are used, and whether installs
on the Frame worked, with an error category from a fixed list. Never file
names, paths, hostnames, IP addresses, window titles or account data.
- compat (opt-in): Android compatibility reports, the same fields the Report
dialog shows, so they reach the shared database (frame_compat_db.py). The
maintainer's sync (python3 ui/frame_compat_db.py sync) moves them there.
- diagnostics (opt-in): error messages and Python tracebacks, scrubbed of
home folders, user names, addresses and keys.
The first-run notice offers compat and diagnostics together, and the page's
Report a problem dialog (frame_report.py) sends bug reports privately to the
same project whatever is chosen here.
Events are identified by a random id made on first run, not by the person or
computer, and sent without person profiles or GeoIP. Nothing is sent without a
project key (ui/telemetry.json or $FRAME_CONTROL_POSTHOG_KEY), from a source
checkout unless $FRAME_CONTROL_TELEMETRY=1, or when $DO_NOT_TRACK=1 or
$FRAME_CONTROL_TELEMETRY=0.
Events wait in an outbox file and are sent in batches from a background thread,
so going offline loses nothing. The last SENT_KEEP sent events are kept on this
computer so the page can show exactly what left it.
"""
import ipaddress
import json
import os
import platform
import re
import sys
import threading
import time
import traceback
import urllib.error
import urllib.request
import uuid
from pathlib import Path
from urllib.parse import urlsplit
import frame_host
HERE = Path(__file__).resolve().parent
STATE = frame_host.data_dir('telemetry')
SETTINGS = STATE / 'settings.json'
OUTBOX = STATE / 'outbox.jsonl'
SENT = STATE / 'sent.jsonl'
SENT_KEEP = 200
OUTBOX_MAX = 2000 # events kept while offline; the oldest go first
FLUSH_EVERY = 60
REPEAT_WINDOW = 600 # the same diagnostic error is sent at most once in this many seconds
DEFAULT_HOST = 'https://us.i.posthog.com'
LEVELS = ('usage', 'compat', 'diagnostics')
# Events the page may send through /api/telemetry, and the properties each may carry.
PAGE_EVENTS = {'tab_viewed': {'tab'}, 'update_offered': {'to_version'},
'update_started': {'to_version'}, 'update_failed': {'to_version', 'error_category'}}
TABS = {'home', 'games', 'android', 'tools'}
_lock = threading.RLock()
_send_lock = threading.Lock() # held while sending; consent changes wait for it
_seen_errors = {}
_flusher = None
_wake = threading.Event()
# ---- configuration and settings -------------------------------------------------
def config():
"""PostHog host and project key: the environment, else ui/telemetry.json."""
try:
with open(HERE / 'telemetry.json') as f:
c = json.load(f)
except (OSError, ValueError):
c = {}
host = os.environ.get('FRAME_CONTROL_POSTHOG_HOST') or c.get('host') or DEFAULT_HOST
key = os.environ.get('FRAME_CONTROL_POSTHOG_KEY') or c.get('key') or ''
project = os.environ.get('FRAME_CONTROL_POSTHOG_PROJECT') or c.get('project') or ''
return {'host': host.rstrip('/'), 'key': key, 'project': str(project)}
def blocked():
"""Why nothing may be sent at all, whatever the settings say, or None."""
if os.environ.get('DO_NOT_TRACK') == '1' or os.environ.get('FRAME_CONTROL_TELEMETRY') == '0':
return 'turned off by DO_NOT_TRACK or FRAME_CONTROL_TELEMETRY=0'
if not config()['key']:
return 'no PostHog project key in this build'
if not os.environ.get('FRAME_CONTROL_PACKAGED') and os.environ.get('FRAME_CONTROL_TELEMETRY') != '1':
return 'running from a source checkout (set FRAME_CONTROL_TELEMETRY=1 to send)'
return None
def _defaults():
return {'id': str(uuid.uuid4()), 'usage': True, 'compat': False, 'diagnostics': False,
'notice_shown': False, 'installed_sent': False, 'last_version': None, 'last_open_day': None,
'frames_seen': [], 'compat_sent': []}
def settings():
with _lock:
s = _defaults()
try:
with open(SETTINGS) as f:
saved = json.load(f)
if isinstance(saved, dict):
s.update({k: v for k, v in saved.items() if k in s})
except (OSError, ValueError):
pass
if not SETTINGS.exists():
_save(s) # keep the id stable from the first call
return s
def _save(s):
try:
STATE.mkdir(parents=True, exist_ok=True)
tmp = SETTINGS.with_suffix('.tmp')
tmp.write_text(json.dumps(s, indent=1))
os.replace(tmp, SETTINGS)
except OSError:
pass
def enabled(level):
"""Whether events of this level are collected: never when sending is blocked, so a
source checkout or a test run leaves nothing behind."""
if blocked():
return False
return bool(settings().get(level))
def update_settings(changes):
"""Apply the page's choices. Turning a level off drops its unsent events; a send already
under way finishes first, so nothing leaves after this returns."""
with _send_lock, _lock:
s = settings()
if 'noticeShown' in changes:
s['notice_shown'] = bool(changes['noticeShown']) or s['notice_shown']
for level in LEVELS:
if level in changes:
s[level] = bool(changes[level])
s['notice_shown'] = True
_save(s)
_drop_unwanted(s)
if changes.get('compat'):
backfill_compat()
_wake.set()
return state()
def state():
"""What the page shows: the choices, why sending is blocked, and what was sent."""
s = settings()
return {'usage': s['usage'], 'compat': s['compat'], 'noticeShown': s['notice_shown'],
'diagnostics': s['diagnostics'],
'blocked': blocked(), 'id': s['id'], 'queued': len(_read_lines(OUTBOX)),
'sent': list(reversed(_read_lines(SENT)))[:50]}
# ---- scrubbing and error categories ---------------------------------------------
def _user_names():
names = set()
for v in (os.environ.get('USER'), os.environ.get('USERNAME'), Path.home().name):
if v and len(v) > 2:
names.add(v)
return names
URL_RE = re.compile(r'[A-Za-z][A-Za-z0-9+.-]*://[^\s\'"<>]+')
SCRUBS = [
(re.compile(r'ssh-(?:rsa|ed25519|dss)\s+\S+'), '<ssh-key>'),
(re.compile(r'-----BEGIN [^-]+-----.*?-----END [^-]+-----', re.S), '<pem>'),
(re.compile(r'\b(?:phc|phx|ghp|gho|ghu|ghs|github_pat|sk|pk|rk|xox[abpr])[_-][A-Za-z0-9_-]{12,}'), '<token>'),
(re.compile(r'(?i)\b(token|key|secret|password|passwd|pwd|auth|signature|sig)=[^\s&]+'), r'\1=<redacted>'),
(re.compile(r'[\w.+-]+@[\w-]+(?:\.[\w-]+)+'), '<email>'),
(re.compile(r'\b(?:\d{1,3}\.){3}\d{1,3}\b'), '<ip>'),
(re.compile(r'\b(?:[0-9a-fA-F]{2}[:-]){5}[0-9a-fA-F]{2}\b'), '<mac>'),
(re.compile(r'\b7656119\d{10}\b'), '<steamid>'),
(re.compile(r'\b(?:[\w-]+\.)+(?:local|lan|home|internal|localdomain|ts\.net)\b'), '<host>'),
(re.compile(r'\b[0-9a-fA-F]{32,}\b'), '<hex>'),
]
IPV6_RE = re.compile(r'(?<![\w:])[0-9A-Fa-f]{0,4}(?::[0-9A-Fa-f]{0,4}){2,7}(?:%\w+)?(?![\w:])')
def _ipv6(m):
try:
ipaddress.IPv6Address(m.group(0).split('%')[0])
return '<ip>'
except ValueError:
return m.group(0)
def public_host(host):
"""A host name that's safe to send: not an address, not a private or single-label name."""
host = (host or '').lower().rstrip('.')
if not host or '.' not in host:
return None
try:
ipaddress.ip_address(host.strip('[]'))
return None
except ValueError:
pass
if re.search(r'\.(?:local|lan|home|internal|localdomain|ts\.net|arpa)$', host) or not re.fullmatch(r'[a-z0-9.-]+', host):
return None
return host
def _scrub_url(u):
"""Only the scheme and a public host name of a URL; never user names, passwords, ports,
paths or queries."""
try:
parts = urlsplit(u)
host = public_host(parts.hostname)
except ValueError:
host = None
return f'{parts.scheme}://{host}/…' if host else '<url>'
def scrub(text, limit=2000):
"""Text with URLs, home folders, user names, addresses, hosts, ids and keys replaced."""
if text is None:
return None
t = URL_RE.sub(lambda m: _scrub_url(m.group(0)), str(text)) # first, before anything splits a URL
home = str(Path.home())
if len(home) > 3:
t = t.replace(home, '~')
t = re.sub(r'(/Users/|/home/|[A-Za-z]:\\Users\\)[^/\\\s]+', r'\1<user>', t)
for pattern, repl in SCRUBS:
t = pattern.sub(repl, t)
t = IPV6_RE.sub(_ipv6, t)
for name in _user_names():
t = re.sub(r'\b%s\b' % re.escape(name), '<user>', t)
return t[:limit]
# From the most to the least specific; the first match wins.
CATEGORIES = [
('android_installer', re.compile(r'INSTALL_(?:FAILED|PARSE_FAILED)_[A-Z_]+')),
('apk_needs_newer_android', re.compile(r'needs Android API')),
('apk_wrong_abi', re.compile(r'no arm64-v8a build')),
('apk_unreadable', re.compile(r'(?i)not a zip|bad apk|AndroidManifest|ApkError|unexpected package name')),
('cant_run_on_frame', re.compile(r"can't run on the Frame")),
('steam_shortcut', re.compile(r'(?i)steam did not return a shortcut|shortcut list|no Steam shortcut')),
('frame_not_set_up', re.compile(r'(?i)Could not resolve hostname|no "?frame"? (?:SSH )?alias')),
('frame_auth', re.compile(r'(?i)Permission denied|Host key verification failed')),
('frame_unreachable', re.compile(r'(?i)timed out|Connection (?:refused|reset|closed)|No route to host|'
r'Network is unreachable|Operation timed out|asleep|kex_exchange')),
('frame_disk_full', re.compile(r'(?i)No space left|disk full|ENOSPC')),
('download_failed', re.compile(r'(?i)HTTP (?:Error )?\d{3}|URLError|download|certificate verify failed')),
('flatpak', re.compile(r'(?i)flatpak|flathub')),
('cancelled', re.compile(r'(?i)cancel')),
('lepton', re.compile(r'(?i)lepton|podman|instance')),
]
def categorize(message):
"""(category, detail): a fixed category name, plus an Android installer code when there is one."""
text = str(message or '')
for name, pattern in CATEGORIES:
m = pattern.search(text)
if m:
return name, (m.group(0) if name == 'android_installer' else None)
return 'other', None
# ---- capturing ------------------------------------------------------------------
def common():
return {'app_version': app_version(), 'os': frame_host.NAME, 'arch': platform.machine().lower(),
'python': '%d.%d' % sys.version_info[:2], '$lib': 'frame-control',
# Anonymous events: no person profile, no location lookup, and a placeholder address,
# since PostHog stores the sender's IP unless an event gives one.
'$process_person_profile': False, '$geoip_disable': True, '$ip': '0.0.0.0'}
def app_version():
v = os.environ.get('FRAME_CONTROL_VERSION')
if v:
return v
try:
with open(HERE.parent / 'app' / 'package.json') as f:
return json.load(f).get('version') or 'dev'
except (OSError, ValueError):
return 'dev'
def capture(event, props=None, level='usage'):
"""Queue an event if its level is on. Never raises."""
try:
if level not in LEVELS or not enabled(level):
return False
s = settings()
e = {'event': event, 'distinct_id': s['id'], 'uuid': str(uuid.uuid4()),
'timestamp': time.strftime('%Y-%m-%dT%H:%M:%SZ', time.gmtime()),
'properties': {**common(), **(props or {}), 'level': level}}
with _lock:
lines = _read_lines(OUTBOX) + [e]
_write_lines(OUTBOX, lines[-OUTBOX_MAX:])
return True
except Exception:
return False
def page_event(body):
"""An event from the page, checked against PAGE_EVENTS."""
name = body.get('event')
allowed = PAGE_EVENTS.get(name)
if allowed is None:
raise ValueError('unknown event')
props = {k: str(v)[:40] for k, v in (body.get('properties') or {}).items() if k in allowed}
if name == 'tab_viewed' and props.get('tab') not in TABS:
raise ValueError('unknown tab')
return {'queued': capture(name, props)}
def app_started():
"""Once per server start: first install, an update, and one open a day."""
if blocked():
return
with _lock:
s = settings()
version, today = app_version(), time.strftime('%Y-%m-%d')
if not s['installed_sent']:
capture('app_installed')
s['installed_sent'] = True
elif s['last_version'] and s['last_version'] != version:
capture('app_updated', {'from_version': s['last_version']})
if s['last_open_day'] != today:
capture('app_opened')
s['last_open_day'] = today
s['last_version'] = version
_save(s)
def frame_seen(build, version):
"""The Frame's SteamOS build, once per build (public build numbers)."""
key = f'{build}/{version}'
with _lock:
s = settings()
if not build or key in s['frames_seen']:
return
s['frames_seen'] = (s['frames_seen'] + [key])[-20:]
_save(s)
capture('frame_connected', {'steamos_build': str(build)[:40], 'steamos_version': str(version or '')[:40]})
def install_finished(kind, ok, seconds=None, error=None, **props):
"""kind: apk, flatpak, steam, title or web. props must already be public (no file names)."""
p = {'kind': kind, 'ok': bool(ok), **{k: v for k, v in props.items() if v is not None}}
if seconds is not None:
p['seconds'] = round(seconds, 1)
if error is not None:
p['error_category'], code = categorize(error)
if code:
p['installer_code'] = code
capture('install_finished', p)
if error is not None and not ok:
diagnostic(f'{kind} install failed', error)
def diagnostic(where, error, tb=None):
"""An error for the opt-in diagnostics level: scrubbed text, and a traceback if there is one."""
if not enabled('diagnostics'):
return
message = scrub(error)
fingerprint = f'{where}|{message[:120]}'
now = time.time()
with _lock:
if now - _seen_errors.get(fingerprint, 0) < REPEAT_WINDOW:
return
_seen_errors[fingerprint] = now
exc_type = type(error).__name__ if isinstance(error, BaseException) else 'Error'
frames = []
if tb is None and isinstance(error, BaseException):
tb = error.__traceback__
for fs in traceback.extract_tb(tb) if tb else []:
frames.append({'filename': os.path.basename(fs.filename), 'lineno': fs.lineno, 'function': fs.name,
'in_app': True, 'platform': 'python'})
capture('$exception', {'$exception_list': [{'type': exc_type, 'value': message,
'mechanism': {'handled': True, 'type': 'generic'},
'stacktrace': {'type': 'raw', 'frames': frames[-30:]}}],
'$exception_type': exc_type, '$exception_message': message,
'where': scrub(where, 200), 'error_category': categorize(error)[0]},
level='diagnostics')
COMPAT_FIELDS = ('package', 'version', 'result', 'rating', 'notes', 'via', 'date', 'steamos', 'lepton',
'runtime', 'label', 'source', 'id')
def compat_report(report):
"""A compatibility report for the shared database (compat level only). Free text is
scrubbed; the source is kept only as F-Droid or a public download host."""
if not report.get('id') or not enabled('compat'):
return False
p = {k: report.get(k) for k in COMPAT_FIELDS if report.get(k) not in (None, '')}
for k, n in (('notes', 1000), ('label', 120), ('version', 80)):
if k in p:
p[k] = scrub(p[k], n)
src = str(p.pop('source', '') or '')
if src == 'F-Droid':
p['source'] = src
elif src.startswith(('http://', 'https://')) and _scrub_url(src) != '<url>':
p['source'] = _scrub_url(src)
return capture('compat_report', p, level='compat')
def backfill_compat():
"""On opting in, share the reports this computer kept before (not ones already sent or queued)."""
try:
import frame_compat_db
if frame_compat_db.shared():
return 0 # the maintainer's copy writes to the database directly
done = set(settings()['compat_sent'])
done |= {e['properties'].get('id') for e in _read_lines(OUTBOX) if e.get('event') == 'compat_report'}
n = 0
for r in frame_compat_db._outbox():
if r.get('id') not in done and compat_report(r):
n += 1
return n
except Exception:
return 0
# ---- the outbox -----------------------------------------------------------------
def _read_lines(path):
try:
with open(path) as f:
out = []
for line in f:
try:
out.append(json.loads(line))
except ValueError:
pass
return out
except OSError:
return []
def _write_lines(path, rows):
STATE.mkdir(parents=True, exist_ok=True)
tmp = Path(str(path) + '.tmp')
with open(tmp, 'w') as f:
f.writelines(json.dumps(r, ensure_ascii=False) + '\n' for r in rows)
os.replace(tmp, path)
def _drop_unwanted(s):
"""Unsent events whose level is now off never leave the computer."""
keep = {level: s[level] for level in LEVELS}
rows = _read_lines(OUTBOX)
kept = [e for e in rows if keep.get(e.get('properties', {}).get('level'), False)]
if len(kept) != len(rows):
_write_lines(OUTBOX, kept)
def post(batch, timeout=20):
"""Send events to PostHog now. Raises SendError if they weren't accepted."""
cfg = config()
if not cfg['key']:
raise SendError('no PostHog project key in this build')
for e in batch: # also events queued by versions that didn't add the placeholder address
e.setdefault('properties', {})['$ip'] = '0.0.0.0'
body = json.dumps({'api_key': cfg['key'], 'batch': batch}).encode()
req = urllib.request.Request(cfg['host'] + '/batch/', data=body, method='POST',
headers={'content-type': 'application/json',
'user-agent': f'FrameControl/{app_version()}'})
try:
with urllib.request.urlopen(req, timeout=timeout) as r:
r.read()
except urllib.error.HTTPError as e:
e.close()
raise SendError(f'PostHog said HTTP {e.code}')
except (urllib.error.URLError, OSError, ValueError) as e:
raise SendError(f"couldn't reach PostHog: {e}")
def record_sent(events):
"""Add events sent outside the outbox to the log the page shows."""
with _lock:
_write_lines(SENT, (_read_lines(SENT) + list(events))[-SENT_KEEP:])
class SendError(RuntimeError):
pass
def flush(timeout=20):
"""Send what's queued. Returns how many were sent; on failure they stay queued."""
with _send_lock:
if blocked() or not settings()['notice_shown']:
return 0
with _lock:
_drop_unwanted(settings())
batch = _read_lines(OUTBOX)[:100]
if not batch:
return 0
try:
post(batch, timeout)
except SendError:
return 0
sent_ids = {e['uuid'] for e in batch}
with _lock:
_write_lines(OUTBOX, [e for e in _read_lines(OUTBOX) if e.get('uuid') not in sent_ids])
_write_lines(SENT, (_read_lines(SENT) + batch)[-SENT_KEEP:])
compat = [e['properties'].get('id') for e in batch if e.get('event') == 'compat_report']
if compat: # remembered only once PostHog has them, so an opt-out before sending can't lose them
s = settings()
s['compat_sent'] = (s['compat_sent'] + compat)[-5000:]
_save(s)
return len(batch)
def start():
"""Record this start and send in the background from now on."""
global _flusher
try:
app_started()
except Exception:
pass
if _flusher:
return
def loop():
while True:
try:
while flush() == 100: # a full batch: there may be more
pass
except Exception:
pass
_wake.wait(FLUSH_EVERY)
_wake.clear()
_flusher = threading.Thread(target=loop, name='telemetry', daemon=True)
_flusher.start()
def wake():
_wake.set()
+146 -10
View File
@@ -16,9 +16,9 @@ checked on a headset; see docs/sideloading.md.
Python stdlib only. CLI:
python3 ui/frame_titles.py inspect PATH
python3 ui/frame_titles.py install PATH [--name N] [--exe REL] [--runtime R]
python3 ui/frame_titles.py list | launch ID | remove ID
python3 ui/frame_titles.py list | launch ID | remove ID | refresh-art ID|--all
"""
import hashlib, json, os, posixpath, re, shlex, shutil, stat, struct, subprocess, sys, tempfile, threading, time, zipfile
import base64, hashlib, json, os, posixpath, re, shlex, shutil, stat, struct, subprocess, sys, tempfile, threading, time, zipfile
import frame_android
import frame_host
@@ -632,7 +632,7 @@ def _rsync():
_install_lock = threading.Lock()
def install(path, name=None, exe=None, runtime=None, progress=None):
def install(path, name=None, exe=None, runtime=None, progress=None, artwork=None):
"""Sideload a .zip, folder or executable as a Devkit Game; returns the title dict.
name: the Steam name (sanitised to the title id), default from the file name.
@@ -643,12 +643,12 @@ def install(path, name=None, exe=None, runtime=None, progress=None):
"""
plan = inspect(path, name)
try:
return install_plan(plan, name=name, exe=exe, runtime=runtime, progress=progress)
return install_plan(plan, name=name, exe=exe, runtime=runtime, progress=progress, artwork=artwork)
finally:
discard(plan)
def install_plan(plan, name=None, exe=None, runtime=None, progress=None):
def install_plan(plan, name=None, exe=None, runtime=None, progress=None, artwork=None):
"""Install an inspect() plan, optionally with another name, target or runtime."""
if name:
plan['name'], plan['id'] = name, title_id(name)
@@ -656,13 +656,21 @@ def install_plan(plan, name=None, exe=None, runtime=None, progress=None):
_choose(plan, exe or plan['target'], runtime)
step = progress or (lambda *a: None)
with _install_lock:
return _install(plan, step)
return _install(plan, step, artwork)
def _install(plan, step):
def _install(plan, step, artwork=None):
gid = plan['id']
if not NEW_ID_RE.match(gid) or gid.lower() in RESERVED_IDS:
raise FrameError(f'bad title id {gid!r}')
icon = None
for filename in ('icon.png', 'logo.png'):
path = os.path.join(plan['root'], filename)
if os.path.isfile(path):
with open(path, 'rb') as f:
icon = f.read(frame_android.frame_artwork.MAX_IMAGE + 1)
break
images, warnings = frame_android.frame_artwork.prepare(plan['name'], icon, artwork)
step("Syncing Valve's devkit tools to the Frame", 0.02)
ensure_utils()
existed = ssh(f'test -d {GAMES}/{gid} && echo yes || true', timeout=30).strip() == 'yes'
@@ -672,6 +680,7 @@ def _install(plan, step):
if not DIR_RE.match(directory) or not directory.endswith(f'/{GAMES}/{gid}'):
raise FrameError(f'steamos-prepare-upload returned an unexpected folder {directory!r}')
registered = False
library_ready, shortcut, steam_registered = False, None, False
try:
step(f"Copying {plan['size'] / 1e6:.0f} MB to the Frame", 0.1)
if _rsync():
@@ -687,17 +696,40 @@ def _install(plan, step):
reply = _json_out(ssh(f'{PY}steam-client-create-shortcut --parms {shlex.quote(json.dumps(parms))}',
timeout=90), 'steam-client-create-shortcut')
meta = {'id': gid, 'name': plan['name'], 'target': plan['target'], 'runtime': plan['runtime'],
'source': plan['source'], 'size': plan['size'], 'installed': time.strftime('%Y-%m-%dT%H:%M:%S')}
'source': plan['source'], 'size': plan['size'], 'installed': time.strftime('%Y-%m-%dT%H:%M:%S'),
# Until art is applied: the only entries automatic backfill may touch.
'art_pending': True}
ssh(f'cat > {GAMES}/{gid}-framecontrol.json', input=json.dumps(meta, indent=1), timeout=30)
registered = True # the files stay: Steam registers them once it's running
if 'error' in reply:
err = str(reply['error']).strip().rstrip('.')
hint = ' With Steam running on the Frame, install it again.' if 'not running' in err else ''
raise FrameError(f"Uploaded, but Steam didn't register it: {err}.{hint}")
steam_registered = True
shortcut = _library_shortcut(gid, directory)
if not shortcut:
raise FrameError('Steam registered the title but its shortcut is not available for mandatory artwork; retry install')
result = frame_android.apply_library(shortcut, plan['name'], directory + '/.frame-artwork', images,
category='Sideloaded', details={'source': plan['source']})
meta.update(shortcut=shortcut, artwork=result.get('artwork', {}), art_pending=False,
library_warnings=warnings + result.get('warnings', []))
ssh(f'cat > {GAMES}/{gid}-framecontrol.json', input=json.dumps(meta, indent=1), timeout=30)
library_ready = True
step('Done', 1.0)
meta.update(runtime_label=RUNTIMES[plan['runtime']]['label'], steam=str(reply.get('success', '')).strip())
return meta
finally:
if steam_registered and not library_ready and not existed:
# A newly registered title must not remain as a blank library tile. Cleanup
# failures are swallowed so the error that got us here is the one reported.
try:
if shortcut:
frame_android.shortcut_tool('remove', str(shortcut))
else:
ssh(f'{PY}steamos-delete --delete-title {gid}', timeout=120)
except FrameError:
pass
registered = False
if not registered and not existed:
# A first install that failed part-way: don't leave an orphan folder behind.
try:
@@ -706,6 +738,90 @@ def _install(plan, step):
pass
def _library_shortcut(gid, directory):
"""The Steam shortcut of title gid, only ever one that is provably this title's.
Steam's app overviews don't expose devkit_gameid (checked 2026-09-28, build 20260925.6191901),
so after the saved id this matches the shortcut's executable or start folder inside directory.
Never by display name: another non-Steam shortcut could share it and would be renamed or deleted.
"""
shortcuts = json.loads(frame_android.shortcut_tool('list'))
matches = [s for s in shortcuts if s.get('devkit_gameid') == gid]
if not matches:
try:
meta = json.loads(ssh(f'cat {GAMES}/{gid}-framecontrol.json 2>/dev/null || true') or 'null')
matches = [s for s in shortcuts if meta.get('shortcut') and s.get('appid') == meta.get('shortcut')]
except (ValueError, AttributeError):
pass
if not matches:
root = posixpath.normpath(directory)
def inside(path):
path = str(path or '').strip().strip('"')
return bool(path) and (posixpath.normpath(path) + '/').startswith(root + '/')
matches = [s for s in shortcuts if inside(s.get('exe')) or inside(s.get('start_dir'))]
if len(matches) > 1:
raise FrameError('ambiguous Steam shortcut for ' + gid)
return int(matches[0]['appid']) if matches else None
def _home():
return ssh('echo $HOME', timeout=30).strip()
def refresh_art(gid=None, artwork=None, fill_only=False):
"""Render and apply Steam artwork for Frame Control's titles (all of them when gid is None).
fill_only: the automatic backfill; it only fills empty Steam slots (see apply_library)."""
if gid is None:
results = []
for t in list_titles():
if not t['frame_control']:
continue
try:
results.append(refresh_art(t['id'], artwork, fill_only))
except Exception as e: # report each title; one failure doesn't stop the rest
results.append({'id': t['id'], 'name': t['name'], 'error': str(e) or type(e).__name__})
return results
with _install_lock:
gid = _check_id(gid)
try:
meta = json.loads(ssh(f'cat {GAMES}/{gid}-framecontrol.json', timeout=30))
except (FrameError, ValueError):
meta = None
if not isinstance(meta, dict):
raise FrameError(f'{gid} was not installed by Frame Control')
directory = f'{_home()}/{GAMES}/{gid}'
script = frame_android.cached_art_script(directory + '/.frame-artwork') + f"""
icon = ''
for name in ('icon.png', 'logo.png'):
try:
with open(os.path.join({directory!r}, name), 'rb') as f:
icon = base64.b64encode(f.read(12 * 1024 * 1024 + 1)).decode()
break
except OSError:
pass
print(json.dumps({{'artwork': cached, 'icon': icon}}))
"""
found = _json_out(ssh('python3 -', input=script, timeout=60), 'the title artwork')
cached = {k: base64.b64decode(v) for k, v in (found.get('artwork') or {}).items()}
icon = base64.b64decode(found.get('icon') or '') or None
name = str(meta.get('name') or gid)
images, warnings = frame_android.frame_artwork.prepare(name, icon, artwork if artwork is not None else cached)
shortcut = _library_shortcut(gid, directory)
if not shortcut:
raise FrameError(f"Steam hasn't registered {gid} yet; with Steam running on the Frame, refresh again")
result = frame_android.apply_library(shortcut, name, directory + '/.frame-artwork', images,
category='Sideloaded', details={'source': meta.get('source')},
fill_only=fill_only)
meta.update(shortcut=shortcut, artwork=result.get('artwork', {}), art_pending=False,
library_warnings=warnings + result.get('warnings', []),
artwork_refreshed=time.strftime('%Y-%m-%dT%H:%M:%S'))
ssh(f'cat > {GAMES}/{gid}-framecontrol.json', input=json.dumps(meta, indent=1), timeout=30)
return meta
LIST_SCRIPT = r'''
import json, os
root = os.path.expanduser('~/devkit-game')
@@ -741,7 +857,9 @@ def list_titles():
'runtime': alias, 'runtime_label': RUNTIMES.get(alias, {}).get('label', alias or 'not set'),
'source': str(meta.get('source') or ''), 'size': meta.get('size'),
'installed': meta.get('installed'), 'registered': t.get('settings') is not None,
'frame_control': bool(meta)})
'frame_control': bool(meta),
# Only a title whose install couldn't apply art; older installs have no flag and keep theirs.
'art_pending': bool(meta.get('art_pending')), 'art_missing': bool(meta.get('art_pending'))})
return titles
@@ -772,9 +890,20 @@ def remove(gid):
try:
gid = _check_id(gid)
ensure_utils()
# steamos-delete removes the folder and syncs Steam's shortcuts; its json files stay, so clear them too.
try:
shortcut = _library_shortcut(gid, f'{_home()}/{GAMES}/{gid}')
except (FrameError, ValueError):
shortcut = None
# steamos-delete removes the folder, the shortcut and its Proton prefix (found through the
# shortcut), so it runs first; its json files stay, so clear them too.
ssh(f'{PY}steamos-delete --delete-title {gid}', timeout=120)
ssh(f'rm -f {_json_files(gid)}', timeout=30)
# Then tidy what it leaves (artwork, collections); best effort.
if shortcut:
try:
frame_android.shortcut_tool('remove', str(shortcut))
except (FrameError, ValueError):
pass
return {'id': gid}
finally:
_install_lock.release()
@@ -815,8 +944,15 @@ def main():
progress=lambda text, _: print(text + '…', file=sys.stderr))
elif cmd == 'list':
r = list_titles()
if any(t['art_missing'] for t in r):
print('Some titles have no Steam artwork: python3 ui/frame_titles.py refresh-art --all', file=sys.stderr)
elif cmd in ('launch', 'remove') and args:
r = globals()[cmd](args[0])
elif cmd == 'refresh-art' and args:
r = refresh_art(None if args[0] == '--all' else args[0])
if isinstance(r, list) and any('error' in t for t in r):
print(json.dumps(r, indent=1))
raise SystemExit(1)
else:
sys.exit(__doc__)
except FrameError as e:
+446
View File
@@ -0,0 +1,446 @@
"""Touch and direct input for the Steam Frame's panels. Frame Control's server runs this ON the Frame.
gamescope, the Frame's compositor, serves Valve's own input injection: an EIS
socket (libei's server side), which Steam uses to feed it Remote Play input.
This connects to it with libei, which is on the SteamOS image, and points,
clicks, scrolls and types into the panel that has focus in the headset: the
one the wearer last used. No install, and it reaches every panel, on either
of gamescope's X displays (see docs/streaming.md).
python3 frame_touch.py focus print the focused panel as JSON
python3 frame_touch.py panels print every app panel as JSON, and which has focus
python3 frame_touch.py read events on stdin, one JSON object (or list) per line:
{"fx": 0.5, "fy": 0.2, "window": 123, "display": ":1"}
pointer to that fraction of that panel; any event can
name its panel, and goes nowhere if another has focus
{"dx": 4, "dy": -2} pointer by that much
{"button": "left", "down": true} left, right or middle; "down" false releases
{"scroll": [0, 120]} by pixels; positive y scrolls down
{"key": 30, "down": true} a Linux (evdev) key code, as the page maps KeyboardEvent.code
{"text": "hello"} printable ASCII, typed on a US layout
Status goes to stdout, one JSON object per line: {"state": "ready" | "error", ...}.
Standard library only (ctypes for libei), like the rest of what runs on the Frame.
"""
import ctypes
import json
import os
import select
import subprocess
import sys
import time
SOCKET = "/run/user/{uid}/gamescope-0-ei" # filled in on the Frame (Windows has no getuid; the tests import this)
BUTTONS = {"left": 0x110, "right": 0x111, "middle": 0x112} # BTN_LEFT, BTN_RIGHT, BTN_MIDDLE
SHIFT = 42 # KEY_LEFTSHIFT
# Printable ASCII on a US layout: character -> (evdev key code, shifted).
ROWS = [("1234567890-=", "!@#$%^&*()_+", 2), ("qwertyuiop[]", "QWERTYUIOP{}", 16),
("asdfghjkl;'`", 'ASDFGHJKL:"~', 30), ("\\zxcvbnm,./", "|ZXCVBNM<>?", 43)]
ASCII = {" ": (57, False), "\n": (28, False), "\t": (15, False)}
for plain, shifted, first in ROWS:
for i, (a, b) in enumerate(zip(plain, shifted)):
ASCII[a], ASCII[b] = (first + i, False), (first + i, True)
# libei's event types and device capabilities (libei.h, libei 1.4).
EV_CONNECT, EV_DISCONNECT, EV_SEAT_ADDED, EV_DEVICE_ADDED, EV_DEVICE_REMOVED = 1, 2, 3, 5, 6
EV_DEVICE_PAUSED, EV_DEVICE_RESUMED = 7, 8
CAP_POINTER, CAP_ABSOLUTE, CAP_KEYBOARD, CAP_SCROLL, CAP_BUTTON = 1, 2, 4, 16, 32
def say(state, **more):
print(json.dumps({"state": state, **more}), flush=True)
# ---- which panel has focus -----------------------------------------------------
def xprop_root(display, name):
try:
out = subprocess.run(["xprop", "-root", name], env=dict(os.environ, DISPLAY=display),
capture_output=True, text=True, timeout=5).stdout
except (OSError, subprocess.SubprocessError):
return []
values = out.split("=", 1)[1] if "=" in out else ""
return [int(v) for v in values.replace(",", " ").split() if v.isdigit()]
def window_info(display, window):
"""Name and geometry of a window on one X display, or None if it isn't there."""
try:
which = ["-root"] if window == "root" else ["-id", str(window)]
out = subprocess.run(["xwininfo", *which], env=dict(os.environ, DISPLAY=display),
capture_output=True, text=True, timeout=5).stdout
except (OSError, subprocess.SubprocessError):
return None
if "IsViewable" not in out:
return None
info = {}
for line in out.splitlines():
line = line.strip()
if line.startswith("xwininfo: Window id:"):
info["name"] = line.split('"', 1)[1].rsplit('"', 1)[0] if '"' in line else ""
for key, field in (("Absolute upper-left X:", "x"), ("Absolute upper-left Y:", "y"),
("Width:", "width"), ("Height:", "height")):
if line.startswith(key):
info[field] = int(line.split(":", 1)[1])
return info if "width" in info else None
def displays():
return sorted(f":{n[1:]}" for n in os.listdir("/tmp/.X11-unix") if n[1:].isdigit())
def window_pid(display, window):
try:
out = subprocess.run(["xprop", "-id", str(window), "_NET_WM_PID"], env=dict(os.environ, DISPLAY=display),
capture_output=True, text=True, timeout=5).stdout
except (OSError, subprocess.SubprocessError):
return None
value = out.rsplit("=", 1)[-1].strip() if "=" in out else ""
return int(value) if value.isdigit() else None
def locate(window, pid):
"""The display a focusable window is on, with its name and geometry.
Window ids are per X server, so :0 and :1 can both have one; the pid gamescope
lists with it (GAMESCOPE_FOCUSABLE_WINDOWS) tells them apart.
"""
found = []
for display in displays():
info = window_info(display, window)
if info:
found.append((display, info))
if len(found) > 1 and pid:
found = [f for f in found if window_pid(f[0], window) == pid] or found
if not found:
return None
display, info = found[0]
root = window_info(display, "root") or {}
return {"window": window, "display": display, **info,
"root": [root.get("width", info["width"]), root.get("height", info["height"])]}
def focusable():
"""gamescope's focusable windows as (window, app id, pid)."""
t = xprop_root(":0", "GAMESCOPE_FOCUSABLE_WINDOWS")
return [tuple(t[i:i + 3]) for i in range(0, len(t) - 2, 3)]
def focus_display():
"""The display of the focused window, from GAMESCOPE_FOCUS_DISPLAY on :0's root.
gamescope writes the name (":1") as 32-bit items, so its first four bytes land,
little-endian, in the first value: 12602 is 0x313A, ":1" (steamcompmgr.cpp;
seen 2026-09-29).
"""
values = xprop_root(":0", "GAMESCOPE_FOCUS_DISPLAY")
if not values:
return None
name = (values[0] & 0xFFFFFFFF).to_bytes(4, "little").split(b"\0", 1)[0].decode("ascii", "replace")
return name if name[:1] == ":" and name[1:].isdigit() else None
def focus_now():
"""Just which window and display have focus: two property reads, for checking a press."""
window = (xprop_root(":0", "GAMESCOPE_FOCUSED_WINDOW") or [0])[0]
return (window or None, focus_display() if window else None)
def focus():
"""The panel that has focus in the headset: window, display, name and sizes (gamescope
publishes the window and its display on :0's root)."""
window = (xprop_root(":0", "GAMESCOPE_FOCUSED_WINDOW") or [0])[0]
if not window:
return {"window": None}
app, pid = next(((a, p) for w, a, p in focusable() if w == window), (None, None))
display = focus_display()
info = window_info(display, window) if display else None
if info:
root = window_info(display, "root") or {}
panel = {"window": window, "display": display, **info,
"root": [root.get("width", info["width"]), root.get("height", info["height"])]}
else:
panel = locate(window, pid) # no display published: tell them apart by pid
return {**panel, "app": app} if panel else {"window": None}
def panels():
"""Every app panel (gamescope's focusable windows), for watching one that hasn't focus."""
now = focus()
found = []
for window, app, pid in focusable():
panel = locate(window, pid)
if panel and panel["width"] > 1 and panel["height"] > 1 and \
not any(f["window"] == window and f["display"] == panel["display"] for f in found):
panel.pop("root", None)
found.append({**panel, "app": app, "focused": (window, panel["display"]) ==
(now.get("window"), now.get("display"))})
return {"focus": now.get("window"), "focus_display": now.get("display"), "panels": found}
def to_root(panel, fx, fy):
"""A point given as a fraction of the panel, in the root coordinates gamescope's pointer uses.
gamescope fits each panel's window to its display, so a 1920x1080 window on a
1280x720 display takes pointer positions at two thirds scale (verified 2026-09-29).
"""
rw, rh = panel["root"]
w, h = panel["width"], panel["height"]
s = min(rw / w, rh / h)
ox, oy = (rw - w * s) / 2, (rh - h * s) / 2
fx, fy = min(max(fx, 0.0), 1.0), min(max(fy, 0.0), 1.0)
return ox + fx * (w * s - 1), oy + fy * (h * s - 1)
# ---- gamescope's input socket ----------------------------------------------------
def libei():
L = ctypes.CDLL("libei.so.1")
vp, c = ctypes.c_void_p, ctypes
sig = {
"ei_new_sender": (vp, [vp]), "ei_configure_name": (None, [vp, c.c_char_p]),
"ei_setup_backend_socket": (c.c_int, [vp, c.c_char_p]), "ei_get_fd": (c.c_int, [vp]),
"ei_dispatch": (None, [vp]), "ei_get_event": (vp, [vp]), "ei_event_get_type": (c.c_int, [vp]),
"ei_event_unref": (vp, [vp]), "ei_event_get_seat": (vp, [vp]), "ei_event_get_device": (vp, [vp]),
"ei_device_has_capability": (c.c_bool, [vp, c.c_int]), "ei_now": (c.c_uint64, [vp]),
"ei_device_start_emulating": (None, [vp, c.c_uint32]), "ei_device_stop_emulating": (None, [vp]),
"ei_device_frame": (None, [vp, c.c_uint64]),
"ei_device_pointer_motion": (None, [vp, c.c_double, c.c_double]),
"ei_device_pointer_motion_absolute": (None, [vp, c.c_double, c.c_double]),
"ei_device_button_button": (None, [vp, c.c_uint32, c.c_bool]),
"ei_device_scroll_delta": (None, [vp, c.c_double, c.c_double]),
"ei_device_keyboard_key": (None, [vp, c.c_uint32, c.c_bool]),
"ei_unref": (vp, [vp]),
}
for name, (res, args) in sig.items():
f = getattr(L, name)
f.restype, f.argtypes = res, args
return L
class Gamescope:
"""One connection to gamescope's EIS socket and its virtual input device."""
def __init__(self):
self.L = L = libei()
self.ei = L.ei_new_sender(None)
L.ei_configure_name(self.ei, b"Frame Control")
if L.ei_setup_backend_socket(self.ei, SOCKET.format(uid=os.getuid()).encode()) != 0:
raise RuntimeError("Couldn't reach gamescope's input socket. Is the headset on?")
self.fd = L.ei_get_fd(self.ei)
self.device, self.sequence, self.held, self.keys, self.alive = None, 0, set(), set(), True
def pump(self, wait=0.0):
"""Handle gamescope's events; False once it has disconnected."""
select.select([self.fd], [], [], wait)
self.L.ei_dispatch(self.ei)
alive = True
while True:
ev = self.L.ei_get_event(self.ei)
if not ev:
return alive
kind = self.L.ei_event_get_type(ev)
if kind == EV_SEAT_ADDED:
seat = self.L.ei_event_get_seat(ev)
# Variadic, ending in 0 (NULL): ask for everything we send.
self.L.ei_seat_bind_capabilities(ctypes.c_void_p(seat), *map(ctypes.c_int, (
CAP_POINTER, CAP_ABSOLUTE, CAP_BUTTON, CAP_SCROLL, CAP_KEYBOARD, 0)))
elif kind == EV_DEVICE_RESUMED:
device = self.L.ei_event_get_device(ev)
if self.L.ei_device_has_capability(device, CAP_ABSOLUTE):
self.sequence += 1
self.L.ei_device_start_emulating(device, self.sequence)
self.device = device
# Releases that arrived while it was paused were dropped: let go of
# everything now, so the headset and this agent agree nothing is held.
if self.held or self.keys:
self.release_all()
elif kind in (EV_DEVICE_PAUSED, EV_DEVICE_REMOVED):
if self.L.ei_event_get_device(ev) == self.device:
self.device = None
elif kind == EV_DISCONNECT:
self.device, alive, self.alive = None, False, False
self.L.ei_event_unref(ev)
def wait_ready(self, timeout=5):
end = time.time() + timeout
while self.device is None and time.time() < end:
if not self.pump(0.1):
break
if self.device is None:
raise RuntimeError("gamescope closed its input socket" if not self.alive
else "gamescope didn't offer an input device")
def frame(self):
self.L.ei_device_frame(self.device, self.L.ei_now(self.ei))
self.L.ei_dispatch(self.ei)
def move_to(self, x, y):
self.L.ei_device_pointer_motion_absolute(self.device, x, y)
self.frame()
def move_by(self, dx, dy):
self.L.ei_device_pointer_motion(self.device, dx, dy)
self.frame()
def button(self, name, down):
code = BUTTONS[name]
if down == (code in self.held):
return # already in that state
self.L.ei_device_button_button(self.device, code, down)
self.frame()
(self.held.add if down else self.held.discard)(code)
def scroll(self, dx, dy):
self.L.ei_device_scroll_delta(self.device, dx, dy)
self.frame()
def key(self, code, down):
self.L.ei_device_keyboard_key(self.device, code, down)
self.frame()
(self.keys.add if down else self.keys.discard)(code)
# Paced: a burst of keys can reach the app out of order (seen 2026-09-29).
time.sleep(0.008)
def text(self, text):
for ch in text:
if ch not in ASCII:
continue
code, shifted = ASCII[ch]
if shifted:
self.key(SHIFT, True)
self.key(code, True)
self.key(code, False)
if shifted:
self.key(SHIFT, False)
def release_all(self):
"""Let go of every button and key still down, so nothing stays held in the headset."""
for code in list(self.held):
name = next(n for n, c in BUTTONS.items() if c == code)
self.button(name, False)
for code in list(self.keys):
self.key(code, False)
# ---- events from the server --------------------------------------------------------
def events(line):
try:
data = json.loads(line)
except ValueError:
return []
return [e for e in (data if isinstance(data, list) else [data]) if isinstance(e, dict)]
def number(value, limit=100000.0):
if isinstance(value, bool) or not isinstance(value, (int, float)) or value != value:
raise ValueError("not a number")
return max(-limit, min(limit, float(value)))
STALE = [False] # whether the last status said a tap went nowhere
def aimed_elsewhere(event, panel):
"""Whether an event names a panel that isn't the one with focus now."""
if "window" not in event:
return False
return (panel.get("window"), panel.get("display")) != (event.get("window"), event.get("display"))
def apply(gs, event, panel):
"""Send one event; returns the focused panel it checked against (looked up at most once a second).
Positions and presses name the panel they were meant for. If focus has moved to
another panel since, they go nowhere, so a tap can't land on the wrong one;
releases always go, so nothing stays held.
"""
# Moves may use a focus reading up to a second old; anything that acts (a press, key,
# text or scroll) reads it afresh, so it can't land on a panel that took focus since.
acts = any(k in event for k in ("button", "key", "text", "scroll")) and event.get("down") is not False
if "window" in event:
if panel and acts and focus_now() == (panel.get("window"), panel.get("display")):
pass # still the same panel (its geometry is re-read on the usual one-second schedule)
elif acts or not panel or time.time() - panel.get("_at", 0) > 1 or aimed_elsewhere(event, panel):
panel = {**focus(), "_at": time.time()}
stale = aimed_elsewhere(event, panel) if "window" in event else False
if stale and not (event.get("down") is False and ("button" in event or "key" in event)):
say("ready", focus=panel.get("window"), display=panel.get("display"), stale=True) # the page re-syncs
STALE[0] = True
return panel
if STALE[0] and not stale:
# Anything that goes through (a trackpad move names no panel) means caught up: stop re-syncing.
STALE[0] = False
say("ready", focus=(panel or {}).get("window"), display=(panel or {}).get("display"))
if "fx" in event and panel and panel.get("window"):
gs.move_to(*to_root(panel, number(event["fx"], 1), number(event["fy"], 1)))
if "dx" in event or "dy" in event:
gs.move_by(number(event.get("dx", 0), 2000), number(event.get("dy", 0), 2000))
if event.get("button") in BUTTONS:
gs.button(event["button"], event.get("down") is not False)
if isinstance(event.get("scroll"), list) and len(event["scroll"]) == 2:
gs.scroll(number(event["scroll"][0], 5000), number(event["scroll"][1], 5000))
if isinstance(event.get("key"), int) and not isinstance(event["key"], bool) and 0 < event["key"] < 768:
gs.key(event["key"], event.get("down") is not False)
if isinstance(event.get("text"), str):
gs.text(event["text"][:500])
return panel
def main():
if sys.argv[1:] == ["focus"]:
print(json.dumps(focus()))
return 0
if sys.argv[1:] == ["panels"]:
print(json.dumps(panels()))
return 0
try:
gs = Gamescope()
gs.wait_ready()
except (OSError, RuntimeError) as e:
say("error", message=str(e))
return 1
say("ready", focus=focus().get("window"))
stdin, pending, panel = sys.stdin.fileno(), b"", None
try:
while True:
ready, _, _ = select.select([stdin, gs.fd], [], [], 30)
if gs.fd in ready and not gs.pump():
say("error", message="gamescope closed its input socket")
return 1
if stdin not in ready:
continue
chunk = os.read(stdin, 65536)
if not chunk:
return 0 # the server went away
*lines, pending = (pending + chunk).split(b"\n")
for line in lines:
waited = False
for event in events(line):
if gs.device is None and waited:
continue # still paused: don't wait again for each event of this batch
if gs.device is None:
waited = True
# Paused (gamescope can pause the device): wait a moment; drop this
# event if it doesn't come back. Only a disconnect ends the session.
try:
gs.wait_ready(2)
except RuntimeError:
if not gs.alive:
raise
continue
try:
panel = apply(gs, event, panel)
except (ValueError, KeyError, TypeError, OSError):
continue # the server checks events; skip anything odd
except RuntimeError as e:
say("error", message=str(e))
return 1
finally:
if gs.device is not None:
gs.release_all() # never leave a button held down in the headset
if __name__ == "__main__":
sys.exit(main())
+29
View File
@@ -0,0 +1,29 @@
"""Optional software, separate from Frame Control's own controls and HUD.
Public reports are attributed leads, never local verification. Compatibility
reports reuse the existing database with steam:<appid> package keys.
"""
REPORT = 'https://www.roadtovr.com/valve-steam-frame-review/'
UTILITIES = (
(1009850, 'OVR Advanced Settings', False, 'No verified Frame result. Steam edition is paid; the developer also publishes free source/releases.', 'https://github.com/OpenVR-Advanced-Settings/OpenVR-AdvancedSettings'),
(1173510, 'XSOverlay', False, 'Supplied research reports Proton support, but the linked review did not corroborate it on recheck. Untested.', REPORT),
(1068820, 'OVR Toolkit', False, 'Supplied research reports Proton support, but the linked review did not corroborate it on recheck. Untested.', REPORT),
(908520, 'fpsVR', False, 'No Frame-specific result established in the supplied public research. Untested here.', 'https://store.steampowered.com/app/908520/'),
(1494460, 'Desktop+', True, 'Free, developer-published software. No verified Frame result.', 'https://github.com/elvissteinjr/DesktopPlus'),
)
def catalogue(ownership, reports):
owned = {r['id']: r for r in ownership}
out = []
for appid, name, free, note, source in UTILITIES:
local = owned.get(appid, {})
matches = [r for r in reports if r.get('package') == f'steam:{appid}' and r.get('rating') in ('works', 'issues', 'broken')]
latest = max(matches, key=lambda r: r.get('date') or '') if matches else None
out.append({'id': appid, 'name': name, 'free': free, 'owned': local.get('owned'),
'installed': local.get('installed', False), 'frame': local.get('frame', 0),
'status': latest['rating'] if latest else 'untested',
'report': {k: latest.get(k) for k in ('notes', 'date', 'steamos', 'source')} if latest else None,
'note': note, 'source': source,
'canInstall': bool(free or local.get('owned'))})
return {'utilities': out}
+126
View File
@@ -0,0 +1,126 @@
"""Frame Control's optional performance HUD, using Frame platform tools only.
Controls remain blocked pending idle-headset verification; no playspace writes
are exposed. See docs/vr-utilities.md for the probe evidence and follow-up.
"""
import json
import os
from pathlib import Path
import re
import signal
import subprocess
import sys
import time
from frame_status import battery, max_temp, performance
ROOT = Path.home() / '.local/share/frame-control/vr'
APPID = '2000250025'
def validate(body):
action = body.get('action')
if action not in ('hud-start', 'hud-stop'):
raise ValueError('VR action must be hud-start or hud-stop; playspace controls are not yet verified')
return action
def save(path, data):
tmp = path.with_suffix('.tmp')
tmp.write_text(json.dumps(data))
os.replace(tmp, path)
def process_identity(pid):
try:
stat = Path(f'/proc/{pid}/stat').read_text().rsplit(')', 1)[1].split()
args = Path(f'/proc/{pid}/cmdline').read_bytes().split(b'\0')
if b'frame-control-hud' in args and b'xterm' in Path(f'/proc/{pid}/comm').read_bytes():
return stat[19] # field 22, starttime; protects against PID reuse
except OSError:
pass
return None
def panel(action):
path = ROOT / 'hud.json'
saved = json.loads(path.read_text()) if path.exists() else {}
pid = saved.get('pid')
running = bool(pid and saved.get('start') and process_identity(pid) == saved['start'])
if action == 'hud-stop':
if running:
os.kill(pid, signal.SIGTERM) # xterm closes the PTY; child exits on HUP
path.unlink(missing_ok=True)
return {'message': 'HUD closed.'}
if running:
return {'message': 'HUD is already open. Find Frame Control HUD in the SteamVR dashboard.'}
env = {**os.environ, 'DISPLAY': ':0'}
p = subprocess.Popen(['xterm', '-name', 'frame-control-hud', '-title', 'Frame Control HUD',
'-fa', 'Monospace', '-fs', '20', '-geometry', '56x16',
'-bg', '#171d25', '-fg', '#d6d7d8', '-e',
sys.executable, str(ROOT / 'frame_vr.py'), 'hud'],
env=env, stdin=subprocess.DEVNULL, stdout=subprocess.DEVNULL,
stderr=subprocess.DEVNULL, start_new_session=True)
try:
deadline = time.monotonic() + 8
while time.monotonic() < deadline and p.poll() is None:
tree = subprocess.check_output(['xwininfo', '-display', ':0', '-root', '-tree'],
text=True, timeout=2)
for w in re.findall(r'(0x[0-9a-f]+).*"frame-control-hud"', tree):
owner = subprocess.check_output(['xprop', '-display', ':0', '-id', w, '_NET_WM_PID'],
text=True, timeout=2)
if owner.strip().endswith('= ' + str(p.pid)):
subprocess.run(['xprop', '-display', ':0', '-id', w, '-f', 'STEAM_GAME', '32c',
'-set', 'STEAM_GAME', APPID], check=True, timeout=2)
identity = process_identity(p.pid)
if not identity:
raise RuntimeError('HUD process exited before its panel was ready')
save(path, {'pid': p.pid, 'start': identity})
return {'message': 'HUD opened. In SteamVR, select Frame Control HUD and Float in World or dock it to a controller.'}
time.sleep(.1)
raise RuntimeError('HUD did not create a window; is gamescope running?')
except BaseException:
if p.poll() is None:
p.terminate()
p.wait(timeout=3)
raise
def hud():
def fmt(v, unit=''):
return 'unavailable' if v is None else f'{v:.1f}{unit}'
while True:
p, b = performance(), battery() or {}
lines = ['FRAME CONTROL HUD', '',
'Compositor FPS ' + fmt(p['compositorFps']),
'Compositor period ' + fmt(p['frameMs'], ' ms'),
'Application FPS ' + fmt(p['appFps']),
'Render GPU time ' + fmt(p['gpuMs'], ' ms'),
'Compositor CPU ' + fmt(p['compositorCpuMs'], ' ms'),
'System CPU ' + fmt(p['cpuPercent'], '%'),
'GPU clock ' + fmt(p['gpuMHz'], ' MHz'),
'Hottest sensor ' + fmt(max_temp(), ' C'),
'Battery ' + fmt(b.get('percent'), '%'), '',
time.strftime('Updated %H:%M:%S'), 'Close this window to stop.']
print('\033[2J\033[H' + '\n'.join(lines), flush=True)
time.sleep(2)
def dispatch(body):
import fcntl # Frame only; validation is also imported by Windows hosts
action = validate(body)
ROOT.mkdir(parents=True, exist_ok=True, mode=0o700)
with (ROOT / 'control.lock').open('a') as lock:
fcntl.flock(lock, fcntl.LOCK_EX)
return panel(action)
if __name__ == '__main__':
if sys.argv[1:] == ['hud']:
hud()
else:
try:
print(json.dumps(dispatch(json.load(sys.stdin))))
except (OSError, ValueError, RuntimeError, subprocess.SubprocessError) as e:
print(json.dumps({'error': str(e)}))
sys.exit(1)
+2414 -61
View File
File diff suppressed because it is too large. Load diff
+398
View File
@@ -0,0 +1,398 @@
<!doctype html>
<!-- Frame Control: one Mac window (or display) inside the Steam Frame.
Served by the Mac's frame-mac-view agent through an SSH tunnel and opened
on the Frame as its own Chromium app window, which gamescope turns into a
SteamVR panel. Video arrives over a WebSocket (H.264 Annex B for
WebCodecs, or JPEG); pointer, wheel and keys go back the same way. -->
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>Mac</title>
<style>
html, body { margin: 0; height: 100%; background: #000; overflow: hidden; cursor: default; }
canvas { position: fixed; inset: 0; width: 100%; height: 100%; object-fit: contain; image-rendering: auto; }
#note { position: fixed; left: 50%; top: 16px; transform: translateX(-50%); max-width: 80%;
font: 15px/1.4 system-ui, sans-serif; color: #eee; background: rgba(20,22,26,.88);
padding: 8px 14px; border-radius: 10px; pointer-events: none; transition: opacity .4s; }
#note[hidden] { display: block; opacity: 0; }
#hud { position: fixed; left: 8px; top: 8px; font: 12px/1.35 ui-monospace, monospace; color: #dfe;
background: rgba(0,0,0,.72); padding: 6px 9px; border-radius: 6px; pointer-events: none; white-space: pre; }
</style>
</head>
<body>
<canvas id="c" width="16" height="9"></canvas>
<div id="note">Connecting to the Mac…</div>
<div id="hud" hidden></div>
<script>
"use strict";
const q = new URLSearchParams(location.search);
// t: a single-use ticket from Frame Control. After the first connection the
// Mac sends a reconnect key, kept only in memory.
const src = q.get("src") || "test", ticket = q.get("t") || "", tag = q.get("tag") || "";
let reconnectKey = "";
const c = document.getElementById("c"), ctx = c.getContext("2d", { alpha: false, desynchronized: true });
const note = document.getElementById("note");
// Counters for Frame Control's tests (read over DevTools).
const stats = window.stats = { frames: 0, keyFrames: 0, bytes: 0, dropped: 0, codec: "", errors: [], info: null };
// ---- timing: the Mac measures each frame's journey on its own clock ----
// Clock sync, NTP-style: the Mac's time minus ours, from the ping with the
// shortest round trip lately (the least queueing, so the least error).
const clock = { off: null, rtt: 0, samples: [], reported: 0 };
function toMac(ms) { return clock.off === null ? null : Math.round(ms * 1000 + clock.off); }
function onPong(m) {
const now = performance.now(), rtt = now - m.c;
clock.samples.push({ rtt, off: m.a - (m.c + now) / 2 * 1000 });
if (clock.samples.length > 16) clock.samples.shift();
const best = clock.samples.reduce((a, b) => (b.rtt < a.rtt ? b : a));
clock.off = best.off;
clock.rtt = best.rtt;
if (now - clock.reported > 1000) {
clock.reported = now;
send({ t: "clock", rtt: +best.rtt.toFixed(2), dec: `${decoderInfo}; ${glInfo}; raf ${rafHz} Hz` });
}
}
let pingTimer = 0;
function startPings() {
clearInterval(pingTimer);
clock.samples = [];
for (let i = 0; i < 10; i++) setTimeout(() => send({ t: "ping", c: performance.now() }), i * 40);
pingTimer = setInterval(() => send({ t: "ping", c: performance.now() }), 1000);
}
// Decoded, drawn and next-animation-frame times go back in batches.
let reports = [], dropsToReport = 0, shownPending = null, rafQueued = false;
setInterval(() => {
if (!reports.length && !dropsToReport) return;
send({ t: "fd", f: reports, drop: dropsToReport });
reports = [];
dropsToReport = 0;
}, 250);
function dropped() { stats.dropped++; dropsToReport++; }
// A drawn frame is on screen from the next animation frame, unless another
// replaces it first (then it was never seen).
function shown(seq, decodedAt, drawnAt) {
if (shownPending) reports.push([shownPending.seq, toMac(shownPending.dec), toMac(shownPending.drawn), 0]);
shownPending = { seq, dec: decodedAt, drawn: drawnAt };
if (rafQueued) return;
rafQueued = true;
requestAnimationFrame(() => {
rafQueued = false;
const p = shownPending, now = performance.now();
shownPending = null;
if (p && clock.off !== null) reports.push([p.seq, toMac(p.dec), toMac(p.drawn), toMac(now)]);
});
}
let decoderInfo = "";
// What this browser draws with, and how often it gives an animation frame
// when nothing else is going on (both only for the numbers).
let glInfo = "", rafHz = 0;
try {
const gl = document.createElement("canvas").getContext("webgl");
const ext = gl && gl.getExtension("WEBGL_debug_renderer_info");
glInfo = ext ? gl.getParameter(ext.UNMASKED_RENDERER_WEBGL) : gl ? "webgl" : "no webgl";
} catch (e) { glInfo = "?"; }
(function measureRaf() {
let n = 0, t0 = 0;
const tick = t => {
if (!t0) t0 = t;
if (t - t0 < 1000) { n++; return requestAnimationFrame(tick); }
rafHz = Math.round(n * 1000 / (t - t0));
};
requestAnimationFrame(tick);
})();
const hud = document.getElementById("hud");
function showHud(on) { hud.hidden = !on; }
function ms(o) { return o && o.p50 !== undefined ? `${o.p50}/${o.p95}` : "–"; }
function onStats(m) {
if (hud.hidden) return;
hud.textContent = `${m.size} ${m.fps} fps shown (${m.sentFps} sent) ${m.mbps} Mbit/s` +
(m.bitrate ? ` of ${(m.bitrate / 1e6).toFixed(1)}` : "") + (m.tier !== undefined ? ` tier ${m.tier}` : "") +
`\nlatency p50/p95 ms total ${ms(m.total)}\n capture ${ms(m.capture)} queue ${ms(m.queue)} encode ${ms(m.encode)}` +
`\n network ${ms(m.network)} decode ${ms(m.decode)} draw ${ms(m.draw)}` +
`\ninput→shown p50 ${m.input ? m.input.p50.toFixed(0) + " ms" : "–"} rtt ${m.rtt} ms` +
`\nskipped ${m.skipped}/${m.captured} dropped ${m.dropped} ${decoderInfo}`;
}
showHud(q.get("stats") === "1");
// Frame Control finds this window on the Frame by the tag in its title.
document.title = tag ? `Mac [${tag}]` : "Mac";
let failedStarts = 0;
let ws = null, dec = null, codecString = "", needKey = true, closing = false, retry = 0, noteTimer = 0, lastError = "";
function show(text, ms) {
note.textContent = text;
note.hidden = false;
clearTimeout(noteTimer);
if (ms) noteTimer = setTimeout(() => { note.hidden = true; }, ms);
}
function send(obj) { if (ws && ws.readyState === 1) ws.send(JSON.stringify(obj)); }
let lastKeyAsk = 0;
function askKeyFrame() {
const now = performance.now();
if (now - lastKeyAsk < 500) return;
lastKeyAsk = now;
send({ t: "key-frame" });
}
let hideNoteOnFrame = true; // "Connecting…"/"Reconnecting…" go once video flows again
function drawFrame(img, w, h, seq, decodedAt) {
if (c.width !== w || c.height !== h) { c.width = w; c.height = h; }
ctx.drawImage(img, 0, 0);
shown(seq, decodedAt, performance.now());
stats.frames++;
if (hideNoteOnFrame) { hideNoteOnFrame = false; note.hidden = true; }
}
// ---- H.264 ----
function startCode(b, i) { return b[i] === 0 && b[i + 1] === 0 && (b[i + 2] === 1 || (b[i + 2] === 0 && b[i + 3] === 1)); }
function spsCodec(au) {
for (let i = 0; i + 7 < au.length; i++) {
if (!startCode(au, i)) continue;
const n = au[i + 2] === 1 ? i + 3 : i + 4;
if ((au[n] & 0x1f) === 7) return "avc1." + [au[n + 1], au[n + 2], au[n + 3]].map(b => b.toString(16).padStart(2, "0")).join("");
i = n;
}
return "";
}
function makeDecoder() {
if (dec) try { dec.close(); } catch (e) {}
codecString = "";
dec = new VideoDecoder({
// The chunk's timestamp is the Mac's sequence number, to match reports up.
output: frame => { drawFrame(frame, frame.displayWidth, frame.displayHeight, frame.timestamp, performance.now()); frame.close(); },
error: e => {
stats.errors.push(String(e.message || e));
needKey = true;
makeDecoder();
askKeyFrame();
},
});
}
function onH264(isKey, seq, au) {
if (isKey) {
const cs = spsCodec(au);
if (cs && (cs !== codecString || dec.state !== "configured")) {
if (dec.state === "closed") makeDecoder();
dec.configure({ codec: cs, optimizeForLatency: true, hardwareAcceleration: "no-preference" });
codecString = stats.codec = cs;
}
stats.keyFrames++;
}
if (dec.state !== "configured" || (needKey && !isKey)) { dropped(); askKeyFrame(); return; }
// Far behind: skip to the next keyframe rather than show old pictures late.
// A few queued frames are fine: decoding catches up faster than a keyframe
// crosses a slow link, and only the newest decoded frame gets drawn.
if (!isKey && dec.decodeQueueSize > 10) { needKey = true; dropped(); askKeyFrame(); return; }
needKey = false;
dec.decode(new EncodedVideoChunk({ type: isKey ? "key" : "delta", timestamp: seq, data: au }));
}
// ---- JPEG ----
let jpegBusy = false;
function onJPEG(seq, data) {
if (jpegBusy) { dropped(); return; }
jpegBusy = true;
createImageBitmap(new Blob([data], { type: "image/jpeg" })).then(bmp => {
drawFrame(bmp, bmp.width, bmp.height, seq, performance.now());
bmp.close();
}).catch(e => stats.errors.push(String(e))).finally(() => { jpegBusy = false; });
}
async function pickCodec() {
const want = q.get("codec");
if (want === "jpeg") return "jpeg";
if (!("VideoDecoder" in window)) return "jpeg";
try {
const r = await VideoDecoder.isConfigSupported({ codec: "avc1.640028", optimizeForLatency: true });
if (!r.supported) return "jpeg";
// Whether this browser has a hardware H.264 decoder (for the numbers).
const hw = await VideoDecoder.isConfigSupported({ codec: "avc1.640028", hardwareAcceleration: "prefer-hardware" })
.catch(() => ({ supported: false }));
decoderInfo = hw.supported ? "h264 hardware" : "h264 software";
return "h264";
} catch (e) { return "jpeg"; }
}
async function connect() {
const codec = await pickCodec();
stats.codec = codec;
if (codec === "h264") makeDecoder();
needKey = true;
const p = new URLSearchParams({ src, codec, max: q.get("max") || "1920", fps: q.get("fps") || "60" });
if (reconnectKey) p.set("r", reconnectKey); else p.set("t", ticket);
if (q.get("bpp")) p.set("bpp", q.get("bpp"));
ws = new WebSocket(`ws://${location.host}/stream?${p}`);
ws.binaryType = "arraybuffer";
ws.onopen = () => { retry = 0; lastError = ""; startPings(); };
ws.onmessage = ev => {
if (typeof ev.data === "string") return control(JSON.parse(ev.data));
const now = performance.now(), b = new Uint8Array(ev.data);
stats.bytes += b.length;
if (b.length < 18) return;
// flags (1 = keyframe), pts µs, sequence number, input echoed; big-endian.
const v = new DataView(ev.data), isKey = (b[0] & 1) === 1, seq = v.getUint32(9);
send({ t: "rx", s: seq, r: toMac(now) });
const payload = b.subarray(17);
if (codec === "h264") onH264(isKey, seq, payload); else onJPEG(seq, payload);
};
ws.onclose = () => {
ws = null;
clearInterval(pingTimer);
if (closing) return;
// Refused before ever getting a key: the ticket expired or was revoked,
// and retrying can't help.
if (!reconnectKey && ++failedStarts >= 3) {
show("This view has expired. Press Show in Frame Control on the Mac to open it again.");
return;
}
hideNoteOnFrame = true;
// The Mac may be asleep or the tunnel restarting: keep trying.
retry = Math.min(retry + 1, 6);
// Keep the Mac's reason (a missing permission, a closed window) on screen.
show(lastError ? `${lastError} Retrying…` : "Lost the Mac. Reconnecting…");
setTimeout(connect, 500 * 2 ** retry);
};
}
function control(m) {
if (m.t === "pong") return onPong(m);
if (m.t === "stats") return onStats(m);
if (m.t === "bench") return bench(m);
if (m.t === "hello") {
reconnectKey = m.r;
send({ t: "ack" }); // the ticket is spent only now
} else if (m.t === "info") {
stats.info = m;
warmMs = Math.max(0, +m.warm || 0);
const name = m.title && m.app && m.title !== m.app ? `${m.title} — ${m.app}` : (m.title || m.app || "Mac");
document.title = tag ? `${name} [${tag}]` : name;
if (!m.input) {
hideNoteOnFrame = false; // a warning, not a connection notice: let it stay its 8 s
show("Clicks and keys need Accessibility permission on the Mac (Frame Control asks for it).", 8000);
}
} else if (m.t === "error") {
stats.errors.push(m.message);
lastError = m.message.replace(/\.?$/, ".");
show(m.message);
} else if (m.t === "close" || m.t === "closed") {
closing = true;
if (ws) ws.close();
show(m.reason ? `Stopped: ${m.reason}.` : "Stopped.");
window.close();
}
}
// ---- input ----
// Where the picture sits inside the window (object-fit: contain letterboxes it).
function toPicture(e) {
const r = c.getBoundingClientRect(), s = Math.min(r.width / c.width, r.height / c.height);
const w = c.width * s, h = c.height * s, left = r.left + (r.width - w) / 2, top = r.top + (r.height - h) / 2;
const x = (e.clientX - left) / w, y = (e.clientY - top) / h;
return { x, y, inside: x >= 0 && x <= 1 && y >= 0 && y <= 1 };
}
// Discrete input carries an id and when it happened (the Mac's clock), so
// the Mac can tag the first frame that could show its effect.
let inputId = 0;
// Keep the Frame's Wi-Fi awake for a few seconds after input, when the agent asks.
let warmMs = 0, warmUntil = 0, warmTimer = 0;
function keepWarm() {
if (!warmMs) return;
warmUntil = performance.now() + 5000;
if (warmTimer) return;
warmTimer = setInterval(() => {
if (performance.now() > warmUntil) { clearInterval(warmTimer); warmTimer = 0; return; }
send({ t: "w" });
}, warmMs);
}
function stamp(m, e) {
keepWarm();
m.i = ++inputId;
m.tv = toMac(e && e.timeStamp ? e.timeStamp : performance.now());
return m;
}
// Moves go at most every 8 ms, on a timer rather than the next animation frame:
// the Frame throttles a panel's animation frames to 15-36 Hz when it thinks
// nobody is looking, which would hold a move back by up to 60 ms.
let pendingMove = null, moveQueued = false, lastMove = 0;
function flushMove() {
moveQueued = false;
if (pendingMove) { send(pendingMove); lastMove = performance.now(); }
pendingMove = null;
}
addEventListener("pointermove", e => {
const p = toPicture(e);
if (!p.inside && !e.buttons) return;
pendingMove = { t: "m", e: "move", x: p.x, y: p.y };
if (moveQueued) return;
const wait = lastMove + 8 - performance.now();
if (wait <= 0) return flushMove();
moveQueued = true;
setTimeout(flushMove, wait);
});
addEventListener("pointerdown", e => {
const p = toPicture(e);
if (!p.inside) return;
if (e.pointerId !== undefined) try { c.setPointerCapture(e.pointerId); } catch (err) {}
pendingMove = null;
send(stamp({ t: "m", e: "down", b: e.button < 0 ? 0 : e.button, x: p.x, y: p.y }, e));
e.preventDefault();
});
addEventListener("pointerup", e => {
const p = toPicture(e);
send({ t: "m", e: "up", b: e.button < 0 ? 0 : e.button, x: p.x, y: p.y });
});
// Let go of any held button where the pointer is on the Mac, not at a corner.
addEventListener("pointercancel", () => send({ t: "release" }));
addEventListener("contextmenu", e => e.preventDefault());
addEventListener("wheel", e => {
const p = toPicture(e), unit = e.deltaMode === 1 ? 16 : e.deltaMode === 2 ? innerHeight : 1;
send(stamp({ t: "wheel", dx: e.deltaX * unit, dy: e.deltaY * unit, x: p.x, y: p.y }, e));
e.preventDefault();
}, { passive: false });
function mods(e) {
return ["shift", "ctrl", "alt", "meta"].filter(m => e[m + "Key"]);
}
function onKey(e, down) {
// Ctrl+Alt+Shift+S shows the numbers; it isn't sent to the Mac.
if (e.code === "KeyS" && e.ctrlKey && e.altKey && e.shiftKey) {
if (down) showHud(hud.hidden);
return e.preventDefault();
}
const m = { t: "k", e: down ? "down" : "up", code: e.code, key: e.key, mods: mods(e) };
send(down ? stamp(m, e) : m);
e.preventDefault();
}
// ---- benchmarks: the Mac asks the viewer to act as if someone did ----
function keyCode(ch) {
if (/[a-z]/i.test(ch)) return "Key" + ch.toUpperCase();
if (/[0-9]/.test(ch)) return "Digit" + ch;
return { " ": "Space", "\n": "Enter", ".": "Period", ",": "Comma" }[ch] || "";
}
function bench(m) {
if (m.action === "overlay") return showHud(m.on !== 0 && m.on !== "0");
if (m.action === "click") {
const at = { x: +m.x || 0.5, y: +m.y || 0.5 };
send(stamp({ t: "m", e: "down", b: 0, ...at }));
setTimeout(() => send({ t: "m", e: "up", b: 0, ...at }), 40);
} else if (m.action === "type") {
const text = String(m.text || ""), gap = +m.interval || 150;
[...text].forEach((ch, n) => setTimeout(() => {
const code = keyCode(ch);
if (!code) return send(stamp({ t: "text", s: ch }));
const mods = ch !== ch.toLowerCase() ? ["shift"] : [];
send(stamp({ t: "k", e: "down", code, key: ch, mods }));
setTimeout(() => send({ t: "k", e: "up", code, key: ch, mods }), 30);
}, n * gap));
}
}
addEventListener("keydown", e => onKey(e, true));
addEventListener("keyup", e => onKey(e, false));
addEventListener("blur", () => send({ t: "release" }));
show("Connecting to the Mac…");
connect();
</script>
</body>
</html>
+1185 -70
View File
File diff suppressed because it is too large. Load diff
+5
View File
@@ -0,0 +1,5 @@
{
"host": "https://us.i.posthog.com",
"key": "phc_qkmbgQBvl2oBXGUVzfV6gG52EpmJdeaQyaRIxHRoQoL",
"project": "343535"
}