"All apps except selected" previously captured the complement of a frozen app snapshot in INCLUDE mode (missed late-launched apps and system sounds, wasted captures on silent windows). It now opens a single ProcessLoopbackCapture in EXCLUDE mode (AUDIOCLIENT_PROCESS_LOOPBACK_MODE_EXCLUDE_TARGET_PROCESS_TREE) of the one chosen app — true system-mix-minus-one, dynamic so apps launched after sharing starts are included. The picker enforces single-selection in exclude mode (the activation params take one target PID). Adds an "Exclude VoiceCat's own audio (prevents echo)" checkbox (default on, entire-desktop only) that routes the desktop capture through the same EXCLUDE path targeting our own process id, killing the whole-device self-echo loop. No C++/ABI changes. Updates voice.md and PROGRESS.md. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
VoiceCat — Windows client
WinForms (.NET 10 LTS) UI over voicecat.dll (MinGW-built libvoicecat shared library).
Prerequisites
| Tool | Version | Notes |
|---|---|---|
| .NET SDK | 10.0.x | dotnet --version should report 10.0.* |
| CMake | 3.25+ | For building the C++ DLL |
| MinGW-w64 / MSYS2 UCRT64 | GCC 13+ | C:\tools\msys64\ucrt64 is the expected location |
| vcpkg | any | VCPKG_ROOT env var must point to a bootstrapped clone |
Build order
1. Build the server (for testing)
cmake --preset dev
cmake --build --preset dev --target voicecat-server
2. Build the DLL
cmake --preset windows-client
cmake --build --preset windows-client
Output: build/windows-client/bin/voicecat.dll
Verify no MinGW runtime dependencies remain:
& "C:\tools\msys64\ucrt64\bin\objdump.exe" -p build/windows-client/bin/voicecat.dll |
Select-String "DLL Name"
Expected: only Windows system DLLs (KERNEL32.dll, WS2_32.dll, BCRYPT.dll, etc.).
If libgcc_s_seh-1.dll, libstdc++-6.dll, or libwinpthread-1.dll appear, the
-static-libgcc -static-libstdc++ -static -lwinpthread link flags in core/CMakeLists.txt
are not taking effect — check the CMake log for the VOICECAT_BUILD_SHARED+WIN32 branch.
3. Build the C# solution
cd clients/windows
dotnet build VoiceCat.slnx
The app's Directory.Build.props copies voicecat.dll from ../../build/windows-client/bin/
into the output directory automatically on every build.
Running manually
# Terminal 1 — start the server
./build/dev/bin/voicecat-server.exe --name "My Server"
# Terminal 2 — launch the client
dotnet run --project clients/windows/VoiceCat.App/VoiceCat.App.csproj
On first connect to a new server:
- Enter
127.0.0.1as the host (notlocalhost— Windows resolveslocalhostto::1first, and while the server now dual-stacks,127.0.0.1is cleaner for local testing). - The server identity dialog will appear. The TLS leaf-cert SHA-256 fingerprint is shown; accept to pin it. Subsequent connects to the same server will be silent (MATCHED).
M5 — Moderation & admin UI
The WinForms client now exposes all M5 operations through the main menu and context menus:
- Admin → Server accounts… — create, reset password, and delete server accounts
(requires
can_admin_accounts). - Channel tree right-click — create, edit, and delete channels. The edit dialog exposes the full per-channel Opus configuration: mono/stereo, sample rate, bitrate, frame size, application mode, FEC, expected packet loss, DTX, and complexity.
- User list right-click — move, kick, ban, server mute/deafen, and set permissions (items are gated by your own permissions).
- Activity log shows async
GenericResultfeedback for every moderation request. - User list shows text indicators for self-mute, self-deafen, server-mute, and server-deafen states.
These operations require an admin-provisioned account with the appropriate permissions; the connect dialog already supports username/password auth.
Known limitations
- PTT is focus-scoped — the push-to-talk key only works while the VoiceCat window has
focus. A system-wide
WH_KEYBOARD_LLhook is not used in v1 (permissions + AV risk). - Receive-side noise reduction checkbox in per-user tuning is wired end-to-end but is a
passthrough no-op until a real APM/NS backend is built (no working Windows/MSVC port of
webrtc-audio-processingupstream — seedocs/tech-stack.md §1). - TOFU pins the TLS leaf cert, not the declared Ed25519 identity fingerprint. Both are
shown in the identity dialog, but the cert fingerprint is the value that is actually
verified on reconnect. See
docs/security.md §1.1.