Adds dev-release.yml (publishes on every push to dev) and beta-release.yml
(publishes on a beta-v* tag), mirroring the pattern landing in
bread-ecosystem/bread. Also creates the dev branch for this repo, which
didn't exist before — see bread-ecosystem/docs/release-channels.md for the
three-track policy.
Mirrors tonight's breadbox migration (same shared crate, same duplicated
patterns):
- position.rs's raw socket1 client -> bread_utils::hypr (file removed
entirely, its logic now lives in the shared crate)
- toggle_or_continue's TOCTOU-prone PID-file dance -> bread_utils::singleton
- the layer-shell window setup, Up/Down visible-row navigation, and
click-outside-close gesture -> bread_utils::gtk_popup
- breadclip-core's data_dir(): replaced the buggy
`dirs::data_local_dir().unwrap_or_else(|| PathBuf::from("~/.local/share"))`
fallback (flagged but never fixed in tonight's earlier audit pass —
PathBuf never expands `~`) with bread_utils::xdg::data_dir, which
resolves a real $HOME before ever falling back.
Builds and tests clean across the whole breadclip workspace.
- history.db and images/*.png are now created with 0600 permissions
(owner-only) instead of default umask, since clipboard history can
contain plaintext passwords/tokens.
- breadclipd never persists clipboard content flagged with the
x-kde-passwordManagerHint MIME type (the convention KeePassXC,
Bitwarden, etc. use to mark content they own).
- Replaced breadclipd's 500ms busy-poll loop (2-3 wl-paste forks per
cycle, forever) with wl-paste --watch, so it only reacts on actual
clipboard changes.
- Documented both behaviors in the README.
GitHub Actions self-hosted runners need per-repo registration on a
personal account; Forgejo Actions' runner already serves every repo
with zero setup. Moves release publishing there (dl.breadway.dev stays
the primary bakery target; GitHub release upload is kept as the
fallback via an explicit token, since Forgejo Actions has no ambient
GITHUB_TOKEN) and adds a mirror workflow to keep GitHub in sync
automatically.