Changelog
Private pilot: public downloads and payments are not available. Entries below describe source/implementation history, not public release availability.
Unreleased security follow-up — 2026-10-04
Section titled “Unreleased security follow-up — 2026-10-04”Household mode no longer automatically enables unsafe browser controllers or adds users to the kernel uinput device group. The explicit legacy unsafe controller opt-in remains available for compatibility, but it is excluded from the multi-user release until a session-authenticated path exists. Keyboard and pointer input continue through Wayland.
0.9.0-beta.1 — 2026-09-26
Section titled “0.9.0-beta.1 — 2026-09-26”The first release aimed at people rather than at the test suite: households that want their gaming PC’s desktops in any browser, and owners who want to give an AI agent a desktop of its own.
AI agents
Section titled “AI agents”- An AI agent is a locked Unix account with its own desktop and its own
Chromium, owned by a Darpan user (
services.darpan.aiAgents.<name>.owner, or--ai-agent <name>=<owner>). POST /mcp: a Streamable HTTP MCP server with 31 tools — screenshots, pointer, keyboard (any Unicode), shell, windows, clipboard, and a browser driven over the DevTools protocol (snapshots with element references, click, type, press, eval, tabs, history, wait).- Per-agent bearer tokens (
dpn_…), shown once and stored as digests, with a per-token rate limit. - Pause (the agent can look but not act), a task board the owner writes and the agent updates, and an activity log that records what the agent did but never what it typed, ran or read.
- Watch & take over: the owner opens the agent’s desktop live and uses it. The gateway renders that page itself — only eight boolean flags are taken from the agent’s session — and leaves the agent’s desktop its own size.
- The agent’s Chromium never offers to save passwords or autofill what the agent types.
Dashboard
Section titled “Dashboard”- Sign-in lands on
/home: your desktop with resume/end, and a card per agent with a live thumbnail, status, tokens with ready-to-paste MCP client configuration, the task board and the activity feed.
Gaming
Section titled “Gaming”- Game mode in the page (Ctrl+Alt+Shift+G) and a stats overlay (Ctrl+Alt+Shift+S); keyboard lock and raw mouse in full screen.
- A desktop game mode (Alt+Shift+G) that turns off every compositor shortcut; the destructive Alt bindings moved to Alt+Shift.
services.darpan.gaming.enable(Steam, gamescope, GameMode, MangoHud) andservices.darpan.household.enable(controllers on, for hosts where every account is trusted).- The desktop follows the viewer’s refresh rate up to 144 Hz, and the encoder is told the rate frames are really captured at.
- Touch input for phones and tablets, and an on-screen keyboard.
- Congestion control never adapted: the transport-wide-cc header extension was not negotiated, so the bandwidth estimator got no feedback.
- A raised bitrate ceiling never took effect while the estimator was attached; an encoder reporting bitrate 0 started at 500 kbps.
- Every reconnect added another copy of the page’s input handlers, so mouse motion was sent once more per reconnect.
- Gamepad X and Y were swapped in SDL and Steam games.
- One mouse-wheel notch scrolled about ten steps in games; releasing one Shift while holding the other released both.
- A desktop wider than 4096 pixels (an ultrawide in fit mode) wedged the session; sizes are now capped at what H.264 can encode.
- VA-API encoders sent a keyframe every second.
- A browser that declined the video took the whole session agent down.
- The local cursor could stay invisible after a game hid and re-showed it.
- The pipeline now runs on the system clock, the fix for the audio dropout under investigation.
- Security: one client cycling through invented usernames could lock every other person out of signing in; a restarted gateway left desktops counted as watched forever; an agent’s name was refused faster than a wrong password; the session process is no longer readable by other processes of its own user.
- The documented static TURN configuration now reaches every desktop; the media ports can be opened without the gateway’s cleartext port.
Project
Section titled “Project”- Darpan is proprietary;
LICENSEandTHIRD_PARTY_NOTICES.mdadded. - Rust 1.96 pinned in
rust-toolchain.toml; every binary answers--version. - New end-to-end suites that run without systemd:
test/e2e-stack.sh(the real gateway and agents behind a stand-in launcher),test/control.sh,test/browser.sh,test/page.sh,test/home.mjs, andtest/nix/eval.shfor the NixOS module.