Closing the coverage gaps the review flagged as blind spots we'd be relying on at
release:
4. RELAY LOGIC TESTS. server/test_relay.py (stdlib unittest + a FakeSocket, no network)
covers the address-proof end to end: cookie issued on join, wrong cookie rejected,
right cookie verifies once; enforce mode WITHHOLDS forwarding from an unverified
address then delivers after it proves itself; watch-only forwards but records
would-block; the per-IP cap counts across BOTH v1 and v2; a NAT-rebind clears
verification (spoof-takeover guard); a forged BYE from another address can't evict
the victim; and bad/short/unknown-version headers are refused. Wired into
run-tests.ps1 (Start-Process from server\, SKIPs loudly if no Python) so a relay
change can no longer ship past the gate untested. The relay had ZERO automated
coverage before and auto-updates every user.
5. UPDATER SIGNATURE ENFORCEMENT. Extracted the two refusal branches into a pure
VerifyStagedRelease gate and added UpdaterRefusesUnsignedRelease: no-sig refused,
wrong-key refused, garbage refused, tamper (good sig over changed bytes) refused,
genuine release accepted. ReleaseSigning only proved the crypto; this proves the
updater actually REFUSES - the hijacked-release-stream threat.
6. STREAMING PASSWORD STRENGTHENING. The accept decision is now a pure
ProfilePasswordDialog.RejectionAdviceFor shared by BOTH password dialogs (also
fixes the App-review trim inconsistency - manager dialog compared untrimmed). Test
pins the load-bearing rule: requireStrong DISABLES the unchanged-exemption so an
existing weak "Games" can't keep streaming, while casual mode still grandfathers an
unchanged password and blocks a new weak one, trim-safe.
Plus the NVDA-hang cache assertions in PasswordRules (miss->hit, same-instance repeat,
Prewarm, empty/weak = no work).
Gate 71/71 + 7 relay tests.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Reworks the per-peer shaping tab (held for next release):
* Renamed the tab to "Volume, pan and EQ for peers"; the Preferences toggle now defaults ON.
* Collapsed the two master switches (Enable EQ / Enable pan) into ONE: "Enable volume, pan and
EQ for all peers" (Alt+E). Volume now obeys it too. PeerDspChain.Build takes a single enabled
flag; Profile.EnableAllPeerShaping replaces the two bools (old ones kept for load-migration).
* Peer picker is now a CheckedListBox: ticking a peer shapes them (per-peer bypass via new
PeerShaping.Enabled, default true); the focused row is the one the controls edit. Effective
shaping = master switch AND that peer's tick. Letter-nav suppressed so keys never toggle a tick.
* Three EQ modes, renamed: "3 band simple EQ", "12 band advanced graphic EQ", and the new
"16 band parametric EQ" (PeerEqMode.Parametric16Band).
* Parametric EQ: up to 16 user bands, each a boost/cut across a start->end range (PeerShaping
.ParametricBands; ParametricToPeaking maps range -> peaking centre+Q, shared by DSP and curve).
Add band dialog (spin-or-type, numeric-only, live preview, OK/Escape); Bands list sorted
bass->treble reading "X Hz to Y Hz, plus/minus N dB"; Delete key / Delete button, multi-select.
Set peer EQ to default clears the parametric list too.
* dB now spoken as words ("plus 3 dB" / "minus 6 dB" / "flat") on the graphic sliders and the
parametric list, since NVDA users typically have punctuation off and never hear a "+".
* New unbound machine-wide global shortcut "Toggle volume, pan and EQ for all peers" (not stored
in any profile) via the hotkey controller + settings store.
* Renamed the Inputs/outputs "Set volume for all received audio" to "Master receive volume".
* Added EqCurveControl: a purely-visual EQ response graph (not focusable, invisible to NVDA).
* Full manual sweep (readme.html + regenerated MANUAL.md).
Build clean; --selftest passes. Deployed to both test folders. Held for next release.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>