Three additions, all of them plumbing for a bitrate that something actually decides. `BootDescriptor` gains `VideoLimits`. It rides the boot document rather than a kernel command line because `nesinit` handles `Boot` by mounting and *then* bringing the stack up, so the value is in hand before `neshub` is spawned -- no parsing, no window where the service is running without its configuration. It is on the descriptor rather than a launch because its consumer is a service that comes up with the box; geometry went the other way for the same reason, its consumer being started per launch. `bitrate_kbps` is an `Option` and the distinction is load-bearing. "Nobody said" is not zero and is not unlimited, and a reader that conflates the first with the last reproduces the bug exactly: every session offered 10 Mbps because no number had ever been chosen and the encoder's own default stood in for one. `neshub` now says which it got, and falls back to something modest rather than to whatever it finds. Note what `deny_unknown_fields` means here, since it is deliberate: a host that sends `video` to a guest too old to know the field is refused rather than quietly served. That is the right direction to fail -- the alternative is a box that boots, streams, and ignores its ceiling -- and it means the guest image is rebuilt before a host starts sending one. `MSG_RECEIVER_REPORT` carries what a second looked like from the far end: goodput actually released to the decoder, frames released, incomplete and never-arrived, and the receiver's own RTT. The hub cannot work any of this out for itself. Its own view was measured saying the path was healthy while almost nothing was arriving, and one reason is structural -- `send_datagram` evicts the oldest queued datagrams and returns `Ok`, so the send side has no backpressure signal at all. `MSG_CONTROL_MODE` says who is choosing the bitrate. Manual exists because it is how this class of bug gets found: the original report said the bitrate had already been lowered, and the only way anyone established otherwise was by setting one by hand and watching the picture come back. Both decoders refuse what they cannot read rather than guessing. `loss()` returns `None` for a second that accounted for no frames at all, because a second with nothing sent and a second with nothing arriving are indistinguishable from there, and answering either 0% or 100% would tell a controller something nobody knows. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
crates/
Shared Rust: a library another crate in this repo depends on. A binary someone
runs goes in apps/; shared JS/TS goes in
packages/. The split is by what a thing is, not by what
language it is written in — same rule on both sides of the repo.
Empty today. Components move here one at a time as they are opened.
Two rules
Every version is pinned in the root Cargo.toml. A member writes
tokio.workspace = true and never a version, so two crates in this tree cannot
disagree about a dependency.
Nothing here may depend on anything closed, or name it. This repo is public. A crate that needs a private component is in the wrong repo, and a comment explaining who calls this wants a category noun — "the caller", "a supervising agent" — rather than a name. The requirement is the interesting part; who currently satisfies it is not.