# Changelog

## Score

- CAI 65 → 66 (+0.8)
- Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

## Lenses

- Code Health 77 → 78 (+0.5)
- Architecture 97 → 98 (+1.3)
- Maturity 61 → 61 (+0.1)
- Readiness 83 → 66 (-16.3)
- Security 56 → 63 (+6.6)
- Event Sourcing 100 → 100 (+0.0)
- Performance 100 (new)

## Resolved (7)

- Change-coupling hub: connection.rs → builtin_schema.rs, hand_gestures.rs, props.rs (alvr/server_core/src/connection.rs)
- Documentation: no installation or build instructions (README.md)
- Documentation: no usage examples (README.md)
- Hotspot: alvr/client_openxr/src/stream.rs (alvr/client_openxr/src/stream.rs)
- Hotspot: alvr/server_core/src/c_api.rs (alvr/server_core/src/c_api.rs)
- InteractionContext::new (cognitive 17) (alvr/client_openxr/src/interaction.rs)
- Off-boarding risk: anonymized user #1

## New (41)

- Change coupling: connection.rs ↔ hand_gestures.rs (alvr/server_core/src/connection.rs)
- Change coupling: connection.rs ↔ props.rs (alvr/server_core/src/connection.rs)
- Change coupling: main.rs ↔ lib.rs (alvr/client_mock/src/main.rs)
- Duplicate intent between `VideoStreamingCapabilities` and `ClientCapabilities`. Both types contain nearly identical properties: `default_view_resolution`, `max_view_resolution`, `refresh_rates`, `foveated_encoding`, `encoder_high_profile`, `encoder_10_bits`, `encoder_av1`, `prefer_10bit`, `preferred_encoding_gamma`, `prefer_hdr`. `VideoStreamingCapabilities` is used in network packets, while `ClientCapabilities` is used in the core client context. This duplication increases maintenance burden and risk of desync.
- End-of-life runtime: Rust 1.97
- EyeTrackedFoveation::update (cognitive 41) (alvr/server_openvr/src/foveated_encoding.rs)
- EyeTrackedFoveation::update (cyclomatic 23) (alvr/server_openvr/src/foveated_encoding.rs)
- Inconsistent naming convention for C API conversions. Most pairs use 'to_capi_' and 'from_capi_' prefixes, but the module itself is named 'c_api'. While this is internally consistent within the module, it differs from common Rust FFI patterns (e.g., 'into_*'/'from_*' or 'to_*'/'from_*') and creates a slight cognitive load compared to standard library conventions. More critically, the existence of both `AlvrFov` (C API) and `Fov` (Primitives) with identical structures suggests a lack of a unified type system for cross-boundary data, forcing manual conversion functions for every primitive type.
- Medium vulnerability: RUSTSEC-2026-0285 (Cargo.lock)
- Off the main sequence: alvr_common
- Off the main sequence: alvr_filesystem
- Off the main sequence: alvr_packets
- Off the main sequence: alvr_session
- Off-boarding risk: anonymized user #1
- Outdated: anyhow
- Outdated: bytemuck
- Outdated: cc
- Outdated: chrono
- Outdated: encoding_rs_io
- Outdated: env_logger
- …and 21 more

## Changes since last survey

- 6 commits — 2 feature/other, 4 fixes

## By area

- alvr/server_openvr — 3 commits
- alvr/audio — 1 commit
- alvr/client_core — 1 commit
- alvr/xtask — 1 commit

## Notable commits

- fix: fix(android): batch startup permission requests (#3400)
- fix: fix(audio): correct 5.1 to stereo downmix channel map (#3403)
- fix: fix(ci): install cargo-msrv with locked dependencies (#3392)
- fix: fix(server_openvr): use AV1 bitrate properties instead of HEVC on AMF (#3401)
- change: feat(foveation): drive per-frame centers from headset eye tracking (#3394)
- change: feat(foveation): synchronize encoder-aligned centers per frame (#3388)
