refactor(agent): hand the capture watchers a DeviceAccess
`gesture::spawn` and `keyboard::spawn` each took the four device-access handles as separate parameters, and each watcher then carried them in two more structs: its manager context, and the channels it hands every session (`SessionChannels`, `KeyboardSessionChannels`), with the receiver lease travelling beside them as a fifth argument through `reconcile` and `drain_for_shutdown`. Both take a `DeviceAccess` and keep it whole. The agent passes `shared.device_access()` to the gesture watcher and `shared.keyboard_access()` to the keyboard watcher, which is the one difference between them: which capture slot they publish into. The host-switch watcher is deliberately not part of this. Its `SessionServices` holds three of the handles and a `ChannelPool`, and no capture slot: it never publishes or reads one, and a `DeviceAccess` would hand it a slot it has no business touching. Guard: agent-device-access-owner flags a struct or a parameter list outside hardware.rs and orchestrator.rs that names both `CaptureChannelSlot` and `ChannelRegistry` (8 hits before the DeviceAccess consolidation, 6 on the parent tree, 0 here).
A
AprilNEA committed
4aa0eecf8b6557d771896b3e011ce5325427ff5a
Parent: 1453225