Compare commits

..
Author SHA1 Message Date
Bailey Dixon 5d9624e2ef release(server): server-v1.8.0 2026-08-14 14:35:01 -04:00
Bailey Dixon 4b063d3fd7 Merge pull request #349 from Codename-11/release/desktop-0.4.0-beta.2
release(desktop): desktop-v0.4.0-beta.2
2026-08-14 12:56:04 -04:00
Bailey Dixon 9b9d7b654c release(desktop): desktop-v0.4.0-beta.2 2026-08-14 12:45:56 -04:00
Bailey Dixon a26e17e72c Merge pull request #348 from Codename-11/fix/cua-windows-health-compat
feat(desktop): enhance activity and control diagnostics
2026-08-14 12:38:12 -04:00
Bailey Dixon a3a6a9bb13 fix(desktop): satisfy tray release lint 2026-08-14 12:36:46 -04:00
Bailey Dixon 169bd09559 merge: sync desktop activity work with dev
# Conflicts:
#	CHANGELOG.md
2026-08-14 11:32:56 -04:00
Bailey Dixon 45d631e7ac feat(desktop): enhance activity and control diagnostics 2026-08-14 11:30:36 -04:00
Bailey Dixon eb6a6c95d2 merge: integrate official desktop relay plugin 2026-08-14 07:58:10 -04:00
Bailey Dixon 3b102663c2 feat(plugin): add official desktop relay surface 2026-08-14 07:56:26 -04:00
Bailey Dixon 0e5fc4c606 Merge branch 'fix/android-proactive-thread-entry' into dev 2026-08-14 07:50:07 -04:00
Bailey Dixon c3189f2cbb fix(android): open proactive messages as threads 2026-08-14 07:49:39 -04:00
Bailey Dixon 06d88ad40a Merge pull request #345 from Codename-11/release/desktop-0.4.0-beta.1
release(desktop): desktop-v0.4.0-beta.1
2026-08-13 21:11:57 -04:00
Bailey Dixon 8ae5b3fbc2 release(desktop): desktop-v0.4.0-beta.1 2026-08-13 21:04:07 -04:00
Bailey Dixon 39b7a8f108 Merge pull request #344 from Codename-11/fix/desktop-updater-cua-hardening
feat(desktop): adopt CUA as primary control backend
2026-08-13 20:57:50 -04:00
Bailey Dixon af6e167692 fix(desktop): normalize Windows installer paths 2026-08-13 20:51:17 -04:00
Bailey Dixon 274bd6ae98 fix(desktop): honor CUA health schema 2026-08-13 20:45:58 -04:00
Bailey Dixon 9fc55b379a fix(desktop): clarify CUA readiness fallback 2026-08-13 20:34:45 -04:00
Bailey Dixon 559a0ffdc8 feat(desktop): make CUA the primary control backend 2026-08-13 20:16:03 -04:00
Bailey Dixon 75bcd9180f feat(desktop): add optional CUA control engine 2026-08-13 19:33:11 -04:00
Bailey Dixon 9c995a443d fix(desktop): harden bundle updates 2026-08-13 19:06:25 -04:00
Bailey Dixon a88539bc59 fix(android): dequeue reach frames compatibly 2026-08-13 16:56:54 -04:00
Bailey Dixon b2ccfdc500 fix(security): carry secure link trust anchor 2026-08-13 16:49:44 -04:00
Bailey Dixon 481c62ac59 fix(desktop): bind pinned secure link probes 2026-08-13 16:42:37 -04:00
Bailey Dixon 5d415fbaf0 fix(android): use compatible reach buffer removal 2026-08-13 16:39:26 -04:00
Bailey Dixon 074b715055 fix(android): complete secure route translations 2026-08-13 16:37:32 -04:00
Bailey Dixon f63ee8721e release(desktop): desktop-v0.4.0-alpha.8 2026-08-13 16:21:51 -04:00
Bailey Dixon 777bc80bcc release(server): server-v1.7.0 2026-08-13 16:21:50 -04:00
Bailey Dixon 9539975bb5 merge: integrate native secure routes 2026-08-13 15:41:46 -04:00
Bailey Dixon 2863a1bc8f merge: reconcile native secure routes with dev 2026-08-13 15:31:53 -04:00
Bailey Dixon b0a7cf0494 feat: add self-hosted secure connection routes 2026-08-13 15:31:46 -04:00
Bailey Dixon 76b4084310 merge: integrate Android and Relay upstream work 2026-08-13 13:24:32 -04:00
Bailey Dixon 2ace70c4fc test: close integration verification gaps 2026-08-13 13:24:02 -04:00
Bailey Dixon 4f52f371ba fix(ops): fail closed on unsafe certification state 2026-08-13 11:16:27 -04:00
Bailey Dixon 064c89bda4 docs: record Android and Relay integration 2026-08-13 11:08:27 -04:00
Bailey Dixon 0cb1e3642f feat(android): add gateway-native profile editor 2026-08-13 11:03:10 -04:00
Bailey Dixon cf4bf87242 fix(android): honor upstream routing contracts 2026-08-13 11:00:39 -04:00
Bailey Dixon 9cbed21014 fix(android): preserve durable gateway rewinds 2026-08-13 10:58:55 -04:00
Bailey Dixon ce75c0fa01 docs: add controlled runtime safety preflight 2026-08-13 10:50:52 -04:00
Bailey Dixon bf2aece6e6 docs: reconcile upstream architecture evaluations 2026-08-13 10:50:14 -04:00
Bailey Dixon 198da78fc8 fix(android): honor upstream approval and compression outcomes 2026-08-13 10:50:14 -04:00
Bailey Dixon 986ce3b12b fix(plugin): isolate profile-owned registrations 2026-08-13 10:50:14 -04:00
Bailey Dixon b53f757830 fix(plugin): support strict phone targets 2026-08-13 10:50:14 -04:00
Bailey Dixon cdeccd69e4 feat: add secure relay route selection 2026-08-12 20:10:41 -04:00
Bailey Dixon bb72516bb5 Merge pull request #340 from Codename-11/chore/backmerge-server-1.6.4
chore: back-merge server-v1.6.4 hotfix
2026-08-12 18:43:50 -04:00
Bailey Dixon 3a51644342 chore: merge server-v1.6.4 release history into dev
# Conflicts:
#	docs/decisions.md
#	user-docs/desktop/tools.md
2026-08-12 18:43:39 -04:00
Bailey Dixon 51c0c7dee9 Merge pull request #338 from Codename-11/fix/server-multidevice-hotfix
fix(server): release targeted multi-desktop routing
2026-08-12 18:39:31 -04:00
Bailey Dixon 7ef2420c85 release(server): server-v1.6.4 2026-08-12 18:38:32 -04:00
Bailey Dixon 6a810c850b fix(server): route concurrent desktop clients explicitly 2026-08-12 18:38:02 -04:00
Bailey Dixon d383002583 Merge pull request #336 from Codename-11/release/server-1.6.4
release(server): server-v1.6.4
2026-08-12 18:35:31 -04:00
Bailey Dixon e3aae829e1 release(server): server-v1.6.4 2026-08-12 18:35:16 -04:00
Bailey Dixon 5207ed4193 Merge pull request #335 from Codename-11/fix/desktop-placement-device-identity
feat(desktop): support targeted multi-device control
2026-08-12 18:32:06 -04:00
Bailey Dixon b46bb00ea8 test(desktop): serialize cross-platform suite 2026-08-12 18:31:50 -04:00
Bailey Dixon b8dde409c5 merge: synchronize desktop management with dev
# Conflicts:
#	CHANGELOG.md
#	docs/decisions.md
2026-08-12 18:26:20 -04:00
Bailey Dixon ca7ded3939 test(server): prove concurrent desktop routing 2026-08-12 18:24:44 -04:00
Bailey Dixon db85a26c68 feat(desktop): add contextual approvals and UI pairing 2026-08-12 18:24:43 -04:00
Bailey Dixon aa2595629d feat(desktop): expand tray management controls 2026-08-12 17:55:56 -04:00
Bailey Dixon d79146dc90 feat(desktop): add ask every time access preset 2026-08-12 17:13:51 -04:00
Bailey Dixon eabc4dd328 refactor(desktop): clarify access navigation 2026-08-12 16:57:50 -04:00
Bailey Dixon e165bfeff3 feat(desktop): animate bidirectional relay traffic 2026-08-12 15:42:43 -04:00
Bailey Dixon 40bcd796d1 refactor(desktop): simplify host access presets 2026-08-12 13:29:29 -04:00
Bailey Dixon 57ae0c9456 feat(desktop): unify capabilities and activity drilldown 2026-08-12 13:06:34 -04:00
Bailey Dixon 9b31a16c89 fix(desktop): preserve Hermes shortcut icons 2026-08-12 11:44:17 -04:00
Bailey Dixon f97bbdd395 feat(desktop): add host-wide raw USB control 2026-08-12 11:38:09 -04:00
Bailey Dixon 722a294947 feat(desktop): adopt compact capability ledger 2026-08-12 11:13:50 -04:00
Bailey Dixon bbfb57b462 feat(desktop): harden targeted remote management 2026-08-12 10:37:12 -04:00
Bailey Dixon 6db12a0bec merge: complete upstream app and Relay workflows 2026-08-12 09:24:24 -04:00
Bailey Dixon f1de957848 fix(android): translate Manage workflows 2026-08-12 09:08:31 -04:00
Bailey Dixon cc01d9c8ad test(android): compile upstream workflow fixtures 2026-08-12 09:00:04 -04:00
Bailey Dixon d574182d84 fix(android): wire Manage workflow dialogs 2026-08-12 08:46:10 -04:00
Bailey Dixon a328763da3 fix(android): localize backup completion 2026-08-12 08:46:05 -04:00
Bailey Dixon f53db68e7d feat(android): complete upstream Manage workflows 2026-08-12 07:45:55 -04:00
Bailey Dixon eb9e570fc0 feat(android): show session repository and PR state 2026-08-12 07:41:35 -04:00
Bailey Dixon 260f119637 fix(voice): align upstream auth and transport 2026-08-12 07:39:42 -04:00
Bailey Dixon d0fa2ea39d fix(android): preserve clarify selection semantics 2026-08-12 07:37:28 -04:00
Bailey Dixon a1c74b1567 fix(plugin): enumerate phone home target 2026-08-12 07:34:19 -04:00
Bailey Dixon 7c45acd38d chore: merge server-v1.6.3 release history into dev 2026-08-11 22:03:36 -04:00
Bailey Dixon 4605b87c10 Merge pull request #333 from Codename-11/dev
release(server): server-v1.6.3
2026-08-11 22:00:43 -04:00
Bailey Dixon 6a91d6ee7e fix(android): complete upstream feature translations 2026-08-11 21:46:45 -04:00
Bailey Dixon 95a2813efe fix(server): validate translated media path components 2026-08-11 21:37:54 -04:00
Bailey Dixon 2ecf521c8c chore: merge main release history into dev 2026-08-11 21:35:40 -04:00
Bailey Dixon 7752c5c404 release(server): server-v1.6.3 2026-08-11 21:35:05 -04:00
Bailey Dixon e1d3764cd2 feat(android): browse sessions across profiles 2026-08-11 20:50:36 -04:00
Bailey Dixon e34171b5ad feat(android): add gateway message reactions 2026-08-11 20:48:09 -04:00
Bailey Dixon 8040cac39a feat(android): redirect running subagents 2026-08-11 20:45:33 -04:00
Bailey Dixon aab70520ca feat(android): open referenced Hermes sessions 2026-08-11 20:40:27 -04:00
Bailey Dixon 5a0cd8123c feat(android): expand Hermes management surfaces 2026-08-11 20:37:03 -04:00
Bailey Dixon 4370d9a925 feat(android): adopt richer gateway chat contracts 2026-08-11 20:30:38 -04:00
Bailey Dixon 726308d2ef fix: harden gateway recovery diagnostics 2026-08-11 20:26:05 -04:00
Bailey Dixon 1acc3a4c80 fix: align app and relay upstream contracts 2026-08-11 20:04:43 -04:00
Bailey Dixon 11ccbd6e5c Merge pull request #332 from Codename-11/dev
release(desktop): desktop-v0.4.0-alpha.7
2026-08-11 19:55:05 -04:00
Bailey Dixon d13af35357 chore: merge main release history into dev 2026-08-11 19:48:26 -04:00
Bailey Dixon e3752d43f3 release(desktop): desktop-v0.4.0-alpha.7 2026-08-11 19:48:24 -04:00
Bailey Dixon 97293b62c3 Merge pull request #331 from Codename-11/dev
release(desktop): desktop-v0.4.0-alpha.6
2026-08-11 19:33:13 -04:00
Bailey Dixon 454e770648 chore: merge main release history into dev 2026-08-11 19:26:15 -04:00
Bailey Dixon e18572e8e3 release(desktop): desktop-v0.4.0-alpha.6 2026-08-11 19:24:27 -04:00
Bailey Dixon 83f69725b9 Merge pull request #330 from Codename-11/dev
release: Desktop 0.4.0-alpha.5
2026-08-11 19:05:39 -04:00
Bailey Dixon 72aa7c3046 chore: merge main release history into dev 2026-08-11 18:59:06 -04:00
Bailey Dixon 3995c64493 release(desktop): desktop-v0.4.0-alpha.5 2026-08-11 18:59:04 -04:00
Bailey Dixon ce538ced3d Merge pull request #329 from Codename-11/dev
release: Desktop 0.4.0-alpha.4
2026-08-11 18:43:32 -04:00
Bailey Dixon 352bc5b439 chore: merge main release history into dev 2026-08-11 18:35:52 -04:00
Bailey Dixon 9ec163b27b release(desktop): desktop-v0.4.0-alpha.4 2026-08-11 18:35:32 -04:00
Bailey Dixon 7a3efa2c4d Merge pull request #328 from Codename-11/dev
release: Desktop 0.4.0-alpha.3 and Server 1.6.2
2026-08-11 18:19:36 -04:00
Bailey Dixon c28be7c92e style(desktop): format tray contract test 2026-08-11 18:03:02 -04:00
Bailey Dixon 8d1758ec8b fix(desktop): build tray assets before Rust checks 2026-08-11 18:01:17 -04:00
Bailey Dixon ce8b8702c3 test(desktop): make UI install coverage portable 2026-08-11 17:53:56 -04:00
Bailey Dixon ca0a9eb524 release(desktop): desktop-v0.4.0-alpha.3 2026-08-11 17:51:25 -04:00
Bailey Dixon b91d8c9a09 release(server): server-v1.6.2 2026-08-11 17:51:13 -04:00
Bailey Dixon bebd327816 Merge pull request #327 from Codename-11/feature/desktop-relay-management-release
feat: ship desktop management UI and paired-device identity
2026-08-11 17:49:18 -04:00
Bailey Dixon 8fa97e0b46 feat(desktop): add host management tray UI 2026-08-11 17:48:47 -04:00
Bailey Dixon 45dc82e573 feat(server): enrich paired device identity 2026-08-11 17:48:09 -04:00
dependabot[bot] 48b23f4d9e chore(deps): bump gradle-wrapper from 9.6.1 to 9.7.0 (#326)
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0.
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0)

---
updated-dependencies:
- dependency-name: gradle-wrapper
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:56:21 +00:00
dependabot[bot] f708ef3353 chore(deps): bump androidx.media3:media3-exoplayer from 1.10.1 to 1.11.0 (#325)
Bumps [androidx.media3:media3-exoplayer](https://github.com/androidx/media) from 1.10.1 to 1.11.0.
- [Release notes](https://github.com/androidx/media/releases)
- [Changelog](https://github.com/androidx/media/blob/release/RELEASENOTES.md)
- [Commits](https://github.com/androidx/media/compare/1.10.1...1.11.0)

---
updated-dependencies:
- dependency-name: androidx.media3:media3-exoplayer
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:55:39 +00:00
dependabot[bot] 3224595a46 chore(deps): bump gradle/actions from 6.2.0 to 6.3.0 (#324)
Bumps [gradle/actions](https://github.com/gradle/actions) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](https://github.com/gradle/actions/compare/v6.2.0...v6.3.0)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:55:08 +00:00
dependabot[bot] c0453f040d chore(deps): bump the testing group with 2 updates (#323)
Bumps the testing group with 2 updates: [io.github.takahirom.roborazzi:roborazzi](https://github.com/takahirom/roborazzi) and [io.github.takahirom.roborazzi:roborazzi-compose](https://github.com/takahirom/roborazzi).


Updates `io.github.takahirom.roborazzi:roborazzi` from 1.70.0 to 1.71.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.70.0...1.71.0)

Updates `io.github.takahirom.roborazzi:roborazzi-compose` from 1.70.0 to 1.71.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.70.0...1.71.0)

---
updated-dependencies:
- dependency-name: io.github.takahirom.roborazzi:roborazzi
  dependency-version: 1.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
- dependency-name: io.github.takahirom.roborazzi:roborazzi-compose
  dependency-version: 1.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:54:54 +00:00
Bailey Dixon 33a0ea3216 chore: merge main back after android-v1.8.1 2026-08-10 00:05:29 -04:00
Bailey Dixon cec05ceec2 Merge pull request #322 from Codename-11/dev
release(android): android-v1.8.1
2026-08-09 23:46:51 -04:00
Bailey Dixon 0e30699fff release(android): android-v1.8.1 2026-08-09 23:20:15 -04:00
Bailey Dixon d4041e4528 chore: merge main back after android-v1.8.0 2026-08-09 23:15:39 -04:00
Bailey Dixon c5ae402cd7 fix(android): align gateway and transcript contracts 2026-08-09 23:08:26 -04:00
Bailey Dixon 56eb213bbf Merge pull request #321 from Codename-11/dev
release(android): android-v1.8.0
2026-08-09 22:53:38 -04:00
Bailey Dixon 3165ebb8ce release(android): android-v1.8.0 2026-08-09 22:03:44 -04:00
Bailey Dixon a2457a39d4 Revert "Merge branch 'feature/hermes-management-profile-detail' into dev"
This reverts commit b481f1f337, reversing
changes made to 7b61ed4758.
2026-08-09 21:35:33 -04:00
Bailey Dixon c2799082b0 Revert "Merge branch 'feature/hermes-management-detail-surfaces' into dev"
This reverts commit 2a467bc03f, reversing
changes made to 44293030c9.
2026-08-09 21:35:33 -04:00
Bailey Dixon 2a467bc03f Merge branch 'feature/hermes-management-detail-surfaces' into dev 2026-08-09 21:13:35 -04:00
Bailey Dixon a30d3dc6ed feat(android): refine Hermes management surfaces 2026-08-09 21:13:29 -04:00
Bailey Dixon 44293030c9 fix(android): contain appearance header in viewport 2026-08-09 20:50:53 -04:00
Bailey Dixon 42ac8c5589 feat(marketing): refresh product screenshots 2026-08-09 20:08:42 -04:00
Bailey Dixon b481f1f337 Merge branch 'feature/hermes-management-profile-detail' into dev 2026-08-09 19:59:56 -04:00
Bailey Dixon 62c4017eeb feat(android): refine Hermes profile management detail 2026-08-09 19:59:40 -04:00
Bailey Dixon 7b61ed4758 Merge branch 'fix/hermes-management-detail-ui' into dev 2026-08-09 19:22:30 -04:00
Bailey Dixon 21259230b2 fix(android): restore Hermes management hub 2026-08-09 19:22:20 -04:00
Bailey Dixon 7ef1e93544 fix(android): reconcile profile shelf chat status 2026-08-09 19:13:34 -04:00
Bailey Dixon 61a50dc968 Merge branch 'feature/hermes-management-ui' into dev 2026-08-09 19:13:16 -04:00
Bailey Dixon 18b9ed005b chore(marketing): refresh production UI screenshots 2026-08-09 19:13:04 -04:00
Bailey Dixon c597187fa3 Merge branch 'feature/android-profile-shelf' into dev
# Conflicts:
#	CHANGELOG.md
#	DEVLOG.md
#	app/src/main/kotlin/com/hermesandroid/relay/ui/components/ConnectionInfoSheet.kt
#	app/src/main/kotlin/com/hermesandroid/relay/ui/components/MessageBubble.kt
#	app/src/main/kotlin/com/hermesandroid/relay/ui/screens/ChatScreen.kt
#	app/src/main/res/values-b+pt+BR/strings.xml
#	app/src/main/res/values-b+zh+Hans/strings.xml
#	app/src/main/res/values-de/strings.xml
#	app/src/main/res/values-es/strings.xml
#	app/src/main/res/values-ja/strings.xml
#	app/src/main/res/values-ru/strings.xml
2026-08-09 19:11:50 -04:00
Bailey Dixon c97f3a3359 feat(android): streamline Hermes management UI 2026-08-09 19:10:45 -04:00
Bailey Dixon 2d9ccd4712 Revert "Merge branch 'feature/agent-profile-defaults' into dev"
This reverts commit 93643be844, reversing
changes made to 1132fdf576.
2026-08-09 18:37:16 -04:00
Bailey Dixon 93643be844 Merge branch 'feature/agent-profile-defaults' into dev 2026-08-09 18:18:00 -04:00
Bailey Dixon b82ee95b8f feat(android): add profile defaults editor 2026-08-09 18:17:53 -04:00
Bailey Dixon 1132fdf576 fix(android): stabilize passport scrolling and model layout 2026-08-09 18:17:31 -04:00
Bailey Dixon 04c69cd15f fix(android): preserve gateway model during api catalog loads 2026-08-09 18:05:16 -04:00
Bailey Dixon b4edcad1e7 fix(android): keep passport catalog refresh read only 2026-08-09 17:54:08 -04:00
Bailey Dixon bef9579917 fix(android): keep passport controls session scoped 2026-08-09 17:11:24 -04:00
Bailey Dixon c84e037b77 fix(android): stop message narration safely 2026-08-09 16:38:27 -04:00
Bailey Dixon 3ad33691cb fix(android): recover persisted tool activity and chat speech 2026-08-09 16:21:40 -04:00
Bailey Dixon bb0a810798 fix(android): protect chat identity from pets 2026-08-09 16:09:09 -04:00
Bailey Dixon b675c1498c Merge branch 'feature/android-clean-activity' into dev 2026-08-09 15:46:02 -04:00
Bailey Dixon 6da1ad1a99 Merge branch 'fix/android-avatar-pet-regressions' into dev 2026-08-09 15:46:01 -04:00
Bailey Dixon 380b9e918d feat(android): clean up transcript activity 2026-08-09 15:44:05 -04:00
Bailey Dixon d531b4d377 fix(android): restore chat and pet interactions 2026-08-09 15:36:57 -04:00
Bailey Dixon 8cba61d2d8 Merge branch 'fix/android-chat-input-polish' into dev 2026-08-09 13:30:59 -04:00
Bailey Dixon 4106fd4b78 fix(android): polish chat message presentation 2026-08-09 13:30:53 -04:00
Bailey Dixon 47426db290 Merge branch 'feature/appearance-customization' into dev 2026-08-09 13:21:01 -04:00
Bailey Dixon b7945b072f feat(android): enhance appearance and visual assets 2026-08-09 13:20:53 -04:00
Bailey Dixon 3aead772a0 Merge branch 'fix/android-chat-input-polish' into dev 2026-08-09 12:41:22 -04:00
Bailey Dixon ccf94e1d9d feat(android): refine chat experience 2026-08-09 12:41:17 -04:00
Bailey Dixon 6b6edc1322 Merge branch 'fix/android-pet-ui-awareness' into dev 2026-08-09 12:31:28 -04:00
Bailey Dixon 2644b94fa9 fix(android): keep floating pets clear of UI 2026-08-09 12:31:14 -04:00
Bailey Dixon 440e3d5bb9 fix(android): unbox thinking status 2026-08-08 22:40:07 -04:00
Bailey Dixon 97158bc861 fix(android): stabilize server-default shelf avatar 2026-08-08 22:35:32 -04:00
Bailey Dixon d5a313ab5d feat(android): refine profile and chat handoffs 2026-08-08 20:27:01 -04:00
Bailey Dixon 3033e331b0 chore: backmerge Android 1.7.1 and Server 1.6.1 releases 2026-08-08 20:06:51 -04:00
Bailey Dixon 07bbb16671 feat(android): add profile shelf 2026-08-08 19:25:20 -04:00
439 changed files with 47041 additions and 3905 deletions
+4 -4
View File
@@ -63,7 +63,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -95,7 +95,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -139,7 +139,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -203,7 +203,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
+4 -2
View File
@@ -100,13 +100,15 @@ jobs:
with:
node-version: '22'
cache: npm
cache-dependency-path: desktop/package-lock.json
cache-dependency-path: |
desktop/package-lock.json
desktop/tray/package-lock.json
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Install deps
run: npm ci
run: npm ci && npm --prefix tray ci
- name: Check tray formatting
run: npm run tray:fmt
+1 -1
View File
@@ -76,7 +76,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+1 -1
View File
@@ -74,7 +74,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+2 -2
View File
@@ -125,7 +125,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
@@ -163,7 +163,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+149 -6
View File
@@ -168,7 +168,9 @@ jobs:
with:
node-version: '22'
cache: npm
cache-dependency-path: desktop/package-lock.json
cache-dependency-path: |
desktop/package-lock.json
desktop/tray/package-lock.json
- name: Setup Bun
uses: oven-sh/setup-bun@v2
@@ -179,7 +181,7 @@ jobs:
uses: dtolnay/rust-toolchain@stable
- name: Install deps
run: npm ci
run: npm ci && npm --prefix tray ci
- name: Type-check
run: npm run type-check
@@ -213,12 +215,153 @@ jobs:
$proc = Start-Process -FilePath tray/target/release/hermes-relay-tray.exe -WindowStyle Hidden -PassThru
Start-Sleep -Seconds 5
if ($proc.HasExited) { throw "tray app exited early with code $($proc.ExitCode)" }
$proc.Refresh()
if ($proc.MainWindowHandle -ne 0) { throw 'menu-only systray created an application window' }
$traySize = (Get-Item tray/target/release/hermes-relay-tray.exe).Length
if ($traySize -gt 5242880) { throw "tray executable exceeds 5 MiB: $traySize bytes" }
if ($traySize -le 0) { throw 'tray executable is empty' }
Stop-Process -Id $proc.Id -Force
Write-Host "menu-only tray launch smoke OK pid=$($proc.Id) bytes=$traySize"
Write-Host "management tray launch smoke OK pid=$($proc.Id) bytes=$traySize"
- name: Smoke-test packaged installer lifecycle
shell: pwsh
env:
EXPECTED_DESKTOP_VERSION: ${{ needs.validate-release.outputs.version }}
run: |
$ErrorActionPreference = 'Stop'
function Normalize-UserPath([string]$Value) {
return (@($Value -split ';' | Where-Object { $_ }) -join ';')
}
function Get-RawUserPath {
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment')
if ($null -eq $environmentKey) { return '' }
try {
return [string]$environmentKey.GetValue(
'Path',
'',
[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames
)
} finally {
$environmentKey.Dispose()
}
}
$setup = (Resolve-Path 'dist/tray/hermes-relay-windows-x64-setup.exe').Path
$smokeRoot = Join-Path $env:RUNNER_TEMP 'hermes-installer-lifecycle-smoke'
$smokeProfile = Join-Path $smokeRoot 'profile'
$installDir = Join-Path $smokeRoot 'installed files'
$sessionDir = Join-Path $smokeProfile '.hermes'
$sessionSentinel = Join-Path $sessionDir 'remote-sessions.json'
$uninstaller = Join-Path $installDir 'uninstall-hermes-relay.exe'
$uninstallKey = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Uninstall\HermesRelay'
$productKey = 'HKCU:\Software\HermesRelay'
$startupKey = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run'
$startMenuDir = Join-Path $env:APPDATA 'Microsoft\Windows\Start Menu\Programs\Hermes-Relay CLI'
$oldUserProfile = $env:USERPROFILE
$oldHomeEnv = $env:HOME
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
$hadUserPath = $environmentKey.GetValueNames() -contains 'Path'
$originalUserPath = Get-RawUserPath
$originalUserPathKind = if ($hadUserPath) { $environmentKey.GetValueKind('Path') } else { $null }
$userPathBefore = 'C:\Windows\System32'
$environmentKey.Dispose()
$startupBefore = (Get-ItemProperty -Path $startupKey -Name HermesRelayTray -ErrorAction SilentlyContinue).HermesRelayTray
if (Test-Path $uninstallKey) { throw 'installer smoke requires a clean HermesRelay uninstall registry key' }
if (Test-Path $productKey) { throw 'installer smoke requires a clean HermesRelay product registry key' }
if (Test-Path $smokeRoot) { Remove-Item -LiteralPath $smokeRoot -Recurse -Force }
New-Item -ItemType Directory -Force -Path $sessionDir | Out-Null
Set-Content -LiteralPath $sessionSentinel -Value '{"sentinel":"preserve-me"}' -Encoding UTF8
$env:USERPROFILE = $smokeProfile
$env:HOME = $smokeProfile
try {
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
$environmentKey.SetValue('Path', $userPathBefore, [Microsoft.Win32.RegistryValueKind]::String)
$environmentKey.Dispose()
$installProcess = Start-Process -FilePath $setup -ArgumentList @('/S', "/D=$installDir") -Wait -PassThru
if ($installProcess.ExitCode -ne 0) { throw "installer exited with code $($installProcess.ExitCode)" }
$expectedFiles = @(
'hermes-relay.exe',
'hermes-relay-tray.exe',
'hermes-relay-ui.cmd',
'hermes-relay-path.ps1',
'uninstall-hermes-relay.exe'
)
foreach ($name in $expectedFiles) {
$path = Join-Path $installDir $name
if (-not (Test-Path -LiteralPath $path -PathType Leaf)) {
throw "packaged installer did not create $path"
}
}
$cli = Join-Path $installDir 'hermes-relay.exe'
$versionOutput = (& $cli --version | Out-String).Trim()
if ($LASTEXITCODE -ne 0) { throw "installed CLI --version exited with code $LASTEXITCODE" }
if ($versionOutput -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "installed CLI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$versionOutput'"
}
$helpOutput = (& $cli --help | Out-String)
if ($LASTEXITCODE -ne 0 -or $helpOutput -notmatch 'Usage:') {
throw 'installed CLI --help smoke failed'
}
if (-not (Test-Path -LiteralPath $sessionSentinel -PathType Leaf)) {
throw 'installer removed profile session data'
}
$uninstallProcess = Start-Process -FilePath $uninstaller -ArgumentList '/S' -Wait -PassThru
if ($uninstallProcess.ExitCode -ne 0) { throw "uninstaller exited with code $($uninstallProcess.ExitCode)" }
$deadline = [DateTime]::UtcNow.AddSeconds(20)
while ((Test-Path -LiteralPath $uninstaller) -and [DateTime]::UtcNow -lt $deadline) {
Start-Sleep -Milliseconds 250
}
foreach ($name in $expectedFiles) {
$path = Join-Path $installDir $name
if (Test-Path -LiteralPath $path) { throw "uninstaller left owned artifact $path" }
}
if (Test-Path $uninstallKey) { throw 'uninstaller left the Installed Apps registry key' }
if (Test-Path $productKey) { throw 'uninstaller left the HermesRelay product registry key' }
if (Test-Path -LiteralPath $startMenuDir) { throw "uninstaller left Start-menu artifacts at $startMenuDir" }
if (-not (Test-Path -LiteralPath $sessionSentinel -PathType Leaf)) {
throw 'uninstaller removed preserved profile session data'
}
if ((Get-Content -LiteralPath $sessionSentinel -Raw) -notmatch 'preserve-me') {
throw 'installer lifecycle modified preserved profile session data'
}
# Compare the raw registry value so expandable entries such as
# %USERPROFILE% are not resolved against the isolated smoke profile.
$userPathAfter = Normalize-UserPath (Get-RawUserPath)
if ($userPathAfter -ne $userPathBefore) {
throw "uninstaller did not restore user PATH (before='$userPathBefore', after='$userPathAfter')"
}
$startupAfter = (Get-ItemProperty -Path $startupKey -Name HermesRelayTray -ErrorAction SilentlyContinue).HermesRelayTray
if ($startupAfter -ne $startupBefore) {
throw "installer lifecycle changed the pre-existing tray startup preference"
}
Write-Host "packaged installer lifecycle smoke OK version=$versionOutput install=$installDir"
} finally {
Get-Process -Name 'hermes-relay-tray' -ErrorAction SilentlyContinue |
Stop-Process -Force -ErrorAction SilentlyContinue
if (Test-Path -LiteralPath $uninstaller) {
Start-Process -FilePath $uninstaller -ArgumentList '/S' -Wait | Out-Null
}
$env:USERPROFILE = $oldUserProfile
$env:HOME = $oldHomeEnv
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
if ($hadUserPath) {
$environmentKey.SetValue('Path', $originalUserPath, $originalUserPathKind)
} else {
$environmentKey.DeleteValue('Path', $false)
}
$environmentKey.Dispose()
if (Test-Path -LiteralPath $smokeRoot) {
Remove-Item -LiteralPath $smokeRoot -Recurse -Force -ErrorAction SilentlyContinue
}
}
- name: Upload Windows tray release asset
uses: actions/upload-artifact@v4
+178 -2
View File
@@ -6,11 +6,187 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
### Added
- **Android can edit current Hermes profiles through the standard Gateway.** The Profile Inspector capability-gates `profiles.describe` and `profiles.configure`, keeps Relay-only memory editing and older-Hermes fallback intact, and reports partial section saves without discarding failed drafts.
- **Android sessions show their coding context when Hermes supplies it.** Session rows can display repository, Git branch, and the current state of the pull request created by that session while older hosts remain unchanged.
- Android Manage can now finish host-owned backup workflows, edit or remove learning nodes with explicit recovery guidance, configure and activate memory providers, and complete profile-scoped WhatsApp QR onboarding through the authenticated upstream Dashboard contracts.
### Fixed
- **Issue area labels require maintainer review.** The unreliable keyword-based auto-labeling workflow no longer assigns ownership from ambiguous issue text.
- **Android preserves authoritative Gateway outcomes.** Protected-file cards cannot offer forbidden persistent scopes, compression no-ops show the server result, bounded resume failures do not create context-free replacement sessions, and edit/regenerate retains durable row identities across consecutive rewinds.
- **Android routes and uploads against live upstream truth.** Multiplex API fallback trusts `served_profiles` instead of installed profiles, and generic documents carry the Gateway-issued `@file:` reference into ordinary and queued prompts.
- **Android clarify cards preserve upstream decision semantics.** Multi-select prompts keep independent selections and submit one exact list, while server expiry events—not an invented local deadline—retire unanswered cards.
- **Android keeps profile management and retained automation truthful.** Custom Endpoint list and mutation routes now follow the selected Hermes profile, while completed one-shot cron jobs show their retained outcome and expose only valid Runs/Delete actions.
- **Android and Relay recover more generated media reliably.** Android accepts upstream-valid wrapped, punctuated, adjacent, spaced, and Windows `MEDIA:` markers without consuming fenced examples, and Relay translates Docker-visible workspace, home, cache, and configured-mount paths before applying its existing credential, sandbox, and size checks.
## [1.8.0] - 2026-08-14
### Added
- **Official Hermes Desktop can surface Relay through its supported runtime Plugin SDK.** The unified plugin package now includes an opt-in, profile-scoped Desktop pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management. Loading, startup, reconnects, profile changes, and updates never open it; only labeled sidebar, status-bar, or command-palette actions register and reveal the movable native pane.
## [0.4.0-beta.2] - 2026-08-14
### Added
- **Desktop Activity now keeps inspectable local evidence.** Commands, files, devices, connection lifecycle, and computer control share a truthful event stepper with dedicated failure details; screenshot events can retain bounded local PNG evidence and open it in a larger borderless viewer. Settings controls retention as Off, 1 day, 7 days, or 30 days and shows local file usage.
### Fixed
- **Tunnel state stays responsive through interruption and retry.** The CLI UI distinguishes connected, reconnecting, and stopped states, exposes retry attempt/timing and a Retry now action, records connection failures and recovery in Activity, and shows compact connection cards only while the main UI is hidden.
- **Windows CUA readiness no longer depends on the flaky whole-desktop health scan.** Hermes-Relay verifies the canonical runtime, manifest, required tools, daemon, and safe permission mode before starting structured sessions, while accessibility health remains an explicit CLI/UI diagnostic that can be rechecked without forcing the compatibility backend. This temporary workaround is scoped to the upstream fixed-timeout issue and keeps individual actions fail-closed.
## [0.4.0-beta.1] - 2026-08-14
### Added
- **CUA Driver is the preferred Windows structured-control engine.** New local settings prefer a verified CUA runtime for window-targeted background actions, fresh snapshot tokens, and optional per-session animated agent cursors without moving the physical pointer; Windows Input is the explicit compatibility backend and backend choice is fixed for each control session. Full-display observation remains on the read-only system capture path. CLI and UI can explicitly install, check, or update the canonical CUA package after verifying the upstream release manifest and installer checksum; nothing is bundled or updated automatically, driver telemetry stays off for Hermes sessions, and activity records contain only bounded, redacted control metadata.
### Fixed
- **Windows bundle updates fail closed when installed processes retain a binary lock.** Setup waits for the invoking CLI, quiesces the tray and its short-lived CLI children, checks every payload extraction before writing release metadata, preserves custom install directories, and returns a failure instead of reporting a mixed-version installation.
- **CUA readiness follows the published driver contract.** Hermes accepts the documented `ok` health state, distinguishes an installed-but-degraded runtime from a missing installation, and constructs trusted Windows installer paths consistently across verification environments.
## [1.7.0] - 2026-08-13
### Added
- **Hermes Secure Link provides self-hosted pinned TLS ingress.** Relay, API, and Dashboard namespaces share one operator-owned TLS endpoint while retaining their native authentication boundaries, QR-carried certificate continuity, explicit rotation, and fail-closed route validation.
- **Hermes Reach is available for explicit experimentation.** The optional self-hosted rendezvous broker carries opaque Secure Link TLS records over outbound-only connections with bounded multiplexing, hashed credentials, replay protection, persistence, revocation, and no access to Hermes payloads.
- **Remote-access management exposes supported reachability clearly.** Dashboard status and pairing metadata distinguish Tailscale reachability, Secure Link transport protection, direct routes, and experimental Reach without presenting the broker as a replacement for authentication.
### Changed
- **Tailscale is the recommended remote route.** Pairing, Dashboard, documentation, and public site guidance present Tailscale as the easiest supported remote-access path; Reach remains disabled by default, advanced, and lower priority than supported routes.
- **Relay voice custom transports follow upstream provider security options.** Relay-owned OpenAI/xAI realtime and TTS clients honor custom headers, custom CA bundles, standard CA environment precedence, and an explicitly warned development-only verification override.
- **Voice Lab xAI sign-in uses device authorization.** The standalone login shows a verification URL and user code and polls for approval without requiring a loopback callback.
### Fixed
- **Phone delivery remains compatible with strict Hermes targets.** Version-tolerant parser and validator hooks retain older-host registration and exactly-once standalone delivery.
- **Profile-owned Relay registrations stay isolated.** Current Hermes uses profile-scoped ownership and context-local profile homes while legacy hosts retain a guarded compatibility path.
- **Phone is discoverable before its first historical session.** The Relay phone adapter publishes its configured home destination through Hermes' standard channel directory.
## [0.4.0-alpha.8] - 2026-08-13
### Added
- **Windows management separates each Relay host from this PC.** Host detail owns identity, pairing, access, capabilities, authorized clients, re-pairing, and guarded removal; Settings owns local daemon lifecycle, startup, privilege, terminal, logs, diagnostics, updates, and Help & About.
- **Desktop access uses clear host-scoped presets and capabilities.** Restricted, Ask Every Time, Standard, Full Access, and Custom remain explicit across commands, files, screen/input, USB, microphone, and camera controls.
- **Activity drilldown preserves bounded execution evidence.** Overview shows the latest three events and detail views expose request, output, result, exit, duration, and truncation metadata without copying sensitive inputs.
- **Connection presentation shows the live Agent-to-PC path.** Host selection, bidirectional packet motion, transition feedback, route details, and connection testing stay compact, responsive, and reduced-motion aware.
### Changed
- **Connect and disconnect remain responsive during daemon work.** Lifecycle calls and snapshot collection run outside the UI thread, transition status polls quickly without overlapping probes, and progress remains visible until authoritative daemon state arrives.
- **Tailscale is recommended for remote access.** Secure Link and direct TLS routes remain supported, while Hermes Reach is visibly experimental and lower priority.
### Fixed
- **Connection tests classify legacy private routes correctly.** A saved generic role is inferred from its actual endpoint, so LAN and Tailscale routes no longer appear as Custom VPN; results include reachability, latency, security, endpoint, and route count.
- **Ask-mode approval cards show the requested action.** A bounded preview appears in the compact card with full context and an Open in UI action.
- **Mixed capability policies are labeled Custom.** Overview no longer claims a preset when individual capability controls differ.
- **Tray placement follows the notification-area monitor and DPI.** Responsive popup geometry stays anchored above the tray icon across compact and high-DPI desktops.
- **PowerShell success output is complete and self-describing.** Scalar, pipeline, JSON, native stdout/stderr, exit status, and truncation metadata survive the desktop RPC response.
## [1.6.4] - 2026-08-12
### Added
- **Desktop tools support explicit host targeting.** Every client-routed desktop tool accepts a stable device ID or unambiguous computer name, and `/desktop/health` enumerates connected targets and their advertised tools.
- **USB operations retain both routing scopes.** Raw USB and ADB tools use `device` to select the desktop PC, while ADB operations continue to use `serial` to select hardware attached to that PC.
### Fixed
- **Multiple desktop clients remain connected simultaneously.** The Relay no longer replaces the previous desktop when another heartbeat arrives; concurrent requests are bound to their selected WebSockets, responses from another PC are ignored, and an untargeted call fails closed when several desktops are online.
- **Pairing another desktop preserves existing credentials.** Legacy placeholder device identifiers are treated as absent instead of shared ownership, preventing an unrelated PC from revoking the first desktop's session.
## [1.6.3] - 2026-08-11
### Fixed
- **Relay diagnostics distinguish a prior clean stop from a crash.** Doctor and `/relay/info` expose only bounded clean, unclean, or unknown gateway-exit state with an optional suspected out-of-memory hint, without returning raw log evidence.
- **Relay reconnects spread out after shared gateway restarts.** Ordinary exponential reconnect delays use full jitter while explicit reconnects and server-directed retry timing retain their exact behavior.
## [0.4.0-alpha.7] - 2026-08-11
### Fixed
- **Installer lifecycle validation uses an isolated Windows PATH fixture.** Release smoke tests now verify add/remove cleanup against a fixed registry value and restore the runner's original value afterward, independently of the temporary profile used for session-preservation checks.
## [0.4.0-alpha.6] - 2026-08-11
### Fixed
- **Installer cleanup validation compares the unexpanded Windows PATH.** Release smoke tests now read the raw user registry value, ensuring `%USERPROFILE%` entries are verified without temporary-profile expansion changing their apparent value.
## [0.4.0-alpha.5] - 2026-08-11
### Fixed
- **Installer cleanup validation handles expandable Windows PATH entries.** Release smoke tests restore the original profile environment before comparing user PATH, avoiding false failures when unchanged `%USERPROFILE%` entries are expanded inside an isolated test profile.
## [0.4.0-alpha.4] - 2026-08-11
### Fixed
- **Windows release validation waits for installer processes.** The packaged install/uninstall lifecycle smoke now captures GUI-subsystem process exit codes reliably before validating installed files, preserved sessions, registry state, and cleanup.
## [0.4.0-alpha.3] - 2026-08-11
### Added
- **Windows tray provides focused remote-access management.** The compact host-aware popup covers connection state, per-host Ask/Trusted/Full Access, pending grant dialogs, authorized-client revocation, activity, daemon controls, and settings without adding chat, terminal, plugin, voice, or session surfaces.
- **Desktop access policy is isolated per Hermes host.** `hermes-relay hosts` lists and selects local pairings and stores fail-closed access modes independently for each canonical relay URL.
- **Windows CLI installations can add or open the management UI directly.** `hermes-relay ui install|open|status` and the installed UI shim provide a supported lifecycle for optional UI setup, discovery, and activation.
### Changed
- **Daemon connectivity no longer requires a tool grant.** Ask mode can keep an authenticated daemon connected with zero desktop tools attached; Trusted enables command/file tools with task-scoped screen/input grants, while Full Access removes those task prompts only for the selected host.
- **Windows bundle updates preserve the desktop lifecycle.** The CLI and tray coordinate one verified installer launch, restore the daemon and UI after setup, and permit same-version UI add or repair without silently downgrading a newer CLI.
### Fixed
- **Background daemon start reports real readiness.** Detached startup now waits for the spawned process to authenticate and connect, and returns actionable log evidence for configuration, authentication, early-exit, and timeout failures.
- **Local and release tray builds embed the packaged UI.** Development installs use Tauri's production protocol instead of attempting to load a missing localhost development server, and release CI exercises a silent install/uninstall lifecycle.
- **Windows-trusted certificates work in the desktop CLI.** The packaged Windows binary and newer Node runtimes add the Windows certificate store without dropping bundled or operator-supplied roots, while TLS verification and Relay certificate pinning remain enforced.
## [1.6.2] - 2026-08-11
### Fixed
- **Paired sessions use recognizable device identities.** Relay sessions preserve a client-provided hostname as the primary name, retain model and platform details, and enrich valid reconnects without requiring users to pair again.
- **Long-lived session expiry is readable.** The Dashboard presents paired-session lifetime in days or weeks with the exact local deadline available in the detail view instead of accumulating hundreds of hours.
## [Android 1.8.1] - 2026-08-09
### Fixed
- **Android preserves complete long-session transcripts.** API-server and profile-scoped Dashboard history reads now use explicit bounded pagination, retain compatibility with older unpaginated responses, and keep edit, retry, sharing, and recovery anchors stable beyond Hermes' latest-500 default window.
- **Android follows authoritative Gateway turn contracts.** Submit rejections retain the server's message without silently falling through to SSE, event envelopes reconcile consistently, and edit-and-regenerate requests send the required truncation confirmation.
## [Android 1.8.0] - 2026-08-09
### Added
- **Android chat keeps work in context and makes live turns easier to read.** Draft text, edits, quotes, and attachments stay with their connection, profile, and session; conversation search and prompt-turn navigation jump by stable message identity; message actions reveal smoothly on tap; quoted replies use linked previews without placing markup in the composer; assistant replies retain their compact high-contrast bubbles; and pending attachments support preview, removal, and accessible reordering.
- **Android reasoning and tool activity use a quieter transcript.** Live thinking opens as an inline disclosure and settles to a collapsed Thought row, while consecutive routine reads, searches, commands, browser actions, and device actions share one live activity ticker or concise completed summary. Approvals, failures, generated media, file changes, output risks, and delegated work keep their own visible lifecycle surfaces even when ordinary tool progress is hidden.
- **Android Profile Shelf makes agent switching immediate without mixing conversations.** The Chat header expands a compact, accessible shelf with ordered profile avatars, a subtle Server-default home badge on the resolved identity, last-session restoration, display hiding, lock controls, and one full switcher shared with Agent Passport.
- **Android accepts shared text as a new Chat draft.** Hermes Relay now appears in the system sharesheet for text, opens the active profile in a fresh conversation, and fills the composer for review without sending automatically.
### Changed
- **Android appearance controls are more expressive and easier to preview.** Theme presets, accent and shape customization, imported Sphere skins, and custom pet creation share one live-preview workflow while preserving separate agent, background, and companion identities.
### Fixed
- **Android restores complete Gateway activity and makes settled replies speakable.** Successful Gateway turns reconcile structured persisted tool calls even when an upstream server omits live tool lifecycle events, and a configured voice can read a completed assistant reply from its message actions without requiring Voice Mode. While that narration is active, the same message actions expose Stop without cancelling an unrelated chat turn.
- **Android chat matches standard keyboard, scrolling, and photo behavior.** Sentence capitalization is enabled, physical Enter can send or insert a newline according to a device-level setting, Ctrl/Command+Enter always submits, directional keys stay with the text caret, expanded thinking and tool content retains bottom-follow until the user scrolls away, and portrait attachments honor their EXIF orientation in previews and message viewers.
- **Android distinguishes live-turn corrections from queued follow-ups.** The composer names its current action with visible text and accessible state, successful gateway redirects show a correction lifecycle marker, and attachment-bearing follow-ups always enter the session-owned queue because the upstream redirect operation is text-only.
- **Android visibly explains quiet startup work without an empty chat bubble.** The full-size thinking animation now sits directly in the conversation lane with a stable reviewable status until the first answer text arrives, while recovery keeps its explicit reconnecting state.
- **Android keeps pets and screen chrome inside safe interaction bounds.** Floating companions avoid agent identity rows and controls during scrolling, remain touchable for their menu, and settings headers respect edge-to-edge system insets.
## [Android 1.7.1] - 2026-08-08
### Fixed
@@ -496,7 +672,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Spoken-turn badges (chat).** Voice-mode replies now carry a "Voice" chip and realtime replies a "Realtime Agent" chip — both with a speaker glyph — so spoken turns are distinguishable from typed ones in the scrollback.
- **App themes.** A new theme picker in Settings → Appearance ships eight looks: the signature Hermes Relay brand (with full light/dark) plus ports of the Nous Hermes baselines — Hermes Teal, Nous Blue (light), Midnight, Ember, Mono, Cyberpunk, and Rosé. The whole app — brand chrome, accents, and chat background — follows the chosen theme. Light/Dark/Auto applies to themes that ship both modes; fixed-mode themes show their own complete look.
- **Hot-swappable agent sphere.** The orb is now a pluggable "skin": an Adaptive skin that recolors to match your theme, built-in Classic / Aurora / Solar / Mono looks, and support for **user-authored skins** loaded from a small JSON spec. Each skin declares which live signals it reacts to (voice, tool bursts, activity), shown as capability badges in the picker. See `docs/sphere-spec.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. A plugin-provided **Secure proxy** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. The optional plugin-provided **Hermes Secure Link** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Enhanced voice control (Gemini & xAI).** When the relay uses a Gemini or xAI voice provider, Voice Settings can now steer it: pick a Gemini voice and model and turn on expressive tone tags (with optional natural-language voice direction), or set an xAI voice with expressive speech tags. Expressive tags also apply to xAI on the streaming voice-output renderer. Standard (no-plugin) voice stays configured server-side.
- **Voice render-path visibility.** Voice Settings shows which path is rendering speech (streaming vs. basic), and Diagnostics records it each session, making voice issues easier to troubleshoot.
- **Agent pets — a living, swappable avatar.** The orb can be replaced with an animated "pet" that reacts to what the agent is doing: idle / thinking / writing / speaking / listening states, a distinct **working** pose during tool calls, one-shot **greet** / **celebrate** reactions, and a loop that quickens as output streams. Add or remove pets right in Settings → Appearance (no `adb` needed), with a live state preview, a playback-speed slider, and optional frame auto-stabilization; capability badges (Voice · Tools · Activity) show honestly what each pet actually reacts to. Pets are pure data — an AI authoring kit and a JSON schema let you generate one from sprite art. See `docs/pet-spec.md` and the custom-avatars guide.
+15 -19
View File
@@ -1,35 +1,31 @@
# Hermes-Relay-CLI v__VERSION__
# Hermes-Relay CLI v__VERSION__
**Release Date:** 2026-07-13
**Release Date:** 2026-08-14
This alpha makes the desktop direction explicit: Hermes-Relay is a real CLI/TUI with an optional Windows right-click systray—not a second desktop application. The old Tauri/WebView dashboard and its embedded windows are gone. The installed CLI remains the single source of behavior for pairing, TUI, daemon management, grants, audit, diagnostics, chat, voice, and tools.
This beta makes connection recovery and Activity evidence inspectable in the compact management UI, and keeps the preferred CUA control engine usable when its upstream whole-desktop accessibility probe times out.
**Experimental phase.** Assets are unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the optional native systray is Windows-only.
**Beta phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the management UI is Windows-only.
## What's changed
### Added
- **Persistent desktop-use control.** `hermes-relay computer-use status|enable|disable|cancel` stores one local preference, reports daemon privilege and active/pending grants, and can end an active task-scoped grant without relying on a GUI.
- **Headless grant review.** `hermes-relay grants` lists pending local computer-use requests and supports interactive review plus explicit `approve`, `reject`, and JSON forms for scripts.
- **Typed Relay chat option.** `chat --relay-chat` sends `chat.send` over WSS and renders typed `stream.event` v1 assistant, tool, artifact, memory, skill, and error lifecycles while preserving the existing gateway path as the default.
- **Release-parity verification.** One version contract now keeps the npm package, compiled CLI, Rust tray, lockfile, and installer metadata aligned. The Windows verification target covers TypeScript, compiled-binary smoke tests, Rust formatting/lint/check/tests, and installer packaging.
- **Inspectable Activity evidence.** Commands, files, device work, connection lifecycle, and computer control share a consistent event stepper with dedicated failure details.
- **Optional screenshot retention.** Screenshot events can keep bounded local PNG evidence for Off, 1 day, 7 days, or 30 days and open it in a larger borderless viewer. Evidence stays outside the JSON activity log.
### Changed
- **Menu-only Windows systray.** The optional tray is a small native Rust process with no application window, WebView, overlay, embedded terminal, chat view, voice view, or settings dashboard. Interactive actions open the installed CLI in a normal terminal.
- **State- and privilege-aware daemon control.** The menu reports PID-backed daemon state and User/Administrator privilege, disables invalid lifecycle actions, and requests UAC only when **Start/Restart daemon as Administrator…** is explicitly chosen. The tray itself remains unprivileged.
- **Visible desktop-use safety.** The tray shows enablement, active grant mode and expiry, warns when an Administrator control grant is active, raises a native alert for pending approvals, opens CLI grant review, and provides immediate cancellation and emergency stop.
- **Per-user Windows installation.** The default PowerShell installer downloads the checksum-verified NSIS package, installs the CLI and optional tray under `~/.hermes/bin`, adds Start-menu shortcuts and user PATH, and can start the tray at sign-in. CLI-only installation remains available with `HERMES_RELAY_INSTALL_SURFACE=cli`.
- **Connection state is live and actionable.** The UI distinguishes connected, reconnecting, and stopped states, shows retry timing, and offers Retry now without freezing the popup.
- **Connection notices stay out of the way.** Compact connect, disconnect, and reconnect cards appear only while the main management UI is hidden.
### Fixed
- **Installed-binary diagnostics.** `hermes-relay doctor` reports the physical Bun-compiled executable instead of a virtual embedded-module path, so PATH and install-directory checks describe the binary that actually launched.
- **Release guardrails.** CLI tag automation rejects version drift, tags not contained in `main`, oversized tray binaries, or a tray process that creates an application window.
- **CUA readiness no longer depends on the flaky global accessibility scan.** Hermes verifies the canonical runtime, required tools, daemon, and safe permission mode before structured control; explicit accessibility health remains available for diagnosis and individual actions still fail closed.
- **Connection errors retain useful context.** Activity records bounded retry and recovery evidence without flooding one event per backoff attempt.
## Install
**Windows CLI + optional systray (PowerShell):**
**Windows CLI + management tray (PowerShell):**
```powershell
irm https://raw.githubusercontent.com/Codename-11/hermes-relay/main/desktop/scripts/install.ps1 | iex
@@ -53,11 +49,11 @@ Pin this release with `HERMES_RELAY_VERSION=__TAG__`.
```text
hermes-relay --version
hermes-relay pair --remote ws://<host>:8767 --grant-tools
hermes-relay hosts list --json
hermes-relay daemon start
hermes-relay daemon status
hermes-relay daemon status --json
```
On Windows, open **Hermes Relay Systray** from the Start menu and right-click its notification-area icon. No separate desktop window is installed.
On Windows, click the Hermes-Relay CLI UI notification-area icon to open the management popup directly above it.
See the [CLI and systray guide](https://hermes-relay.dev/docs/desktop/) for installation, commands, desktop-use safety, and troubleshooting.
See the [CLI and tray guide](https://hermes-relay.dev/docs/desktop/) for installation, access modes, grants, and troubleshooting.
+130
View File
@@ -1,5 +1,135 @@
# Hermes-Relay — Dev Log
## 2026-08-09 — Gateway activity recovery and chat speech
Successful Android Gateway turns now reconcile against their profile-owned,
structured session history. This recovers persisted tool calls when an upstream
Gateway completes a turn without emitting live tool lifecycle events; assistant
prose is never inspected for inferred activity, and the recovered calls continue
through the existing Off, Compact, and Detailed display policy.
The Speak message action now follows configured voice readiness and idle output
state instead of active Voice Mode or presentation style. A settled assistant
reply can therefore be read aloud directly from chat, while live or provider
playback still prevents overlapping output. One-shot message narration owns its
completion state outside Voice Mode and replaces Speak with Stop while active;
stopping drains only that narration pipeline and does not cancel a chat turn
started while the response was playing.
## 2026-08-09 — Quiet reasoning and grouped tool activity
Android Chat now treats reasoning and routine tools as transcript scaffolding.
Visible live reasoning opens automatically without a tinted card, then collapses
to a quiet Thought disclosure when it settles unless the reader has explicitly
chosen its state. Empty reasoning remains absent and the existing first-token
status continues to own the waiting state.
Top-level routine calls retain their source order but render as consecutive
activity runs. A live run keeps one summary and one latest-activity ticker in a
stable footprint; a settled run becomes one collapsed summary that can disclose
the original identity-preserving tool rows. File edits, approval/question tools,
generated media, failures, output-risk findings, and delegated work split runs
and retain independent surfaces. Off hides only ordinary activity runs, Compact
uses compact disclosed rows, and Detailed preserves the full per-tool detail
surface on demand. Expansion still yields bottom-follow ownership, and each run
registers its measured bounds as Chat pet terrain.
## 2026-08-09 — Android chat experience and attachment polish
The Android composer now declares sentence capitalization and a Send IME
action. A device-level setting chooses whether unmodified physical Enter sends
or inserts a newline; Shift+Enter remains a newline and Ctrl/Command+Enter
always submits. Every submit route converges on the existing live-turn owner,
so the current gateway state still decides whether content steers the active
turn or queues behind it. Directional focus traversal is cancelled while the
editor owns focus so hardware arrow keys continue to move the caret and
selection.
Conversation bottom-follow now remains owned when thinking or tool details
expand. Only an actual drag ending above the bottom yields that ownership, and
a chat first measured while the IME is already visible now captures the same
resize-follow state as a keyboard opened after composition.
Bitmap-backed attachment surfaces now apply EXIF rotation and reflection before
display. Attachment reads and Base64 conversion also leave the UI thread, so
selecting a larger photo no longer performs the full ingestion path inside the
activity-result callback.
Composer drafts now belong to the stable connection, profile, and session
identity. Text, edit context, and pending attachments restore when returning to
a chat without persisting attachment bytes. Pending attachments expose bounded,
orientation-aware previews plus explicit remove and reorder controls.
Conversation overflow now opens transcript search with previous/next matches
and a prompt-turn rail, both keyed to the same stable UI identity as the message
list. Assistant prose retains the compact bubble and subtle edge treatment that
keeps it legible above the animated chat background. Tapping a message reveals
the existing copy, quote, speak, and edit actions with reduced-motion-aware
expansion and accessible targets.
Quotes are composer-owned structured references instead of raw blockquote text.
The composer and sent message render a linked, highlighted author preview; the
transport remains ordinary Markdown so unmodified Desktop and TUI clients show
a readable quoted reply. Thinking and top-level tools continue to use their
independent compact thought bubbles and configured compact or full tool cards,
without an aggregate completion card. The composer also names Correction and
Queue states with visible labels. Gateway redirects remain text-only:
follow-ups with attachments are forced through the existing destination-owned
queue so files cannot be left behind by a correction request.
## 2026-08-08 — Standalone Android thinking status
Blank streaming assistant rows now present the full-size working animation
directly in the conversation lane above the visible `Still working…` label,
without painting an empty assistant bubble around the status. The first answer
token replaces that standalone state with the normal response bubble, while
recovery retains the distinct `Reconnecting to your answer…` wording. The
status owns one stable TalkBack description and suppresses animated child
nodes, avoiding repeated announcements without claiming measurable progress.
## 2026-08-08 — Android text-share draft handoff
The shared Android manifest now advertises a `text/*` `ACTION_SEND` target for
both app flavors. `MainActivity` accepts only non-blank single-item text shares
and places them in a process-local, identity-fenced handoff that survives cold
Compose initialization. Once the configured chat context settles, the app root
navigates to Chat and delegates draft creation and composer prefill to
`ChatViewModel`.
The ViewModel reuses the existing new-chat lifecycle, preserving Gateway
background-turn reconciliation and the active connection/profile/transport
namespace. Composer prefills use a one-consumer conflated channel so an intent
received before Chat composition is delivered once. Shared text is never
routed through message sending; the user must review and submit it explicitly.
## 2026-08-08 — Android Profile Shelf and profile-context identity
Chat profile selection now lives in a collapsible shelf directly below the top
app bar. The header toggles the shelf, the active capsule opens Agent Passport,
inactive 48 dp avatars switch context, and a pinned overflow opens the same full
switcher used by Passport. Saved ordering and hidden state drive both surfaces;
the selected hidden profile remains disclosed, while a one-identity shelf stays
out of the layout. Long-press actions expose inspection, Passport, profile lock,
and hiding without adding activity or presence claims.
The shelf uses the chat surface instead of a second elevated toolbar. A neutral
active capsule, 36 dp avatar artwork inside 48 dp targets, compact spacing, and
a contained overflow affordance keep the row visually subordinate to Chat. When
Server default resolves to a concrete profile, that profile's avatar remains
the identity and a small home badge discloses its default routing role.
Local avatar lookup remains keyed to the Server-default presentation identity,
so an image customized while that row is selected appears consistently in both
the Chat header and shelf rather than being re-keyed to whichever explicit
profile is currently active.
The Server-default sentinel is now distinct from a profile literally named
`default`. Profile selection restores the last compatible connection/profile/
transport session, otherwise leaves a fresh draft. Gateway turns detach and
reconcile in their original session, live SSE turns keep switching disabled,
and every profile transition clears session-scoped model, provider, personality,
reasoning, approval, Fast, and YOLO state before the destination session seeds
its own values. Server sticky-default state is never written.
## 2026-08-08 — Streaming reply tail follow
Android's conversation-bottom follower now reads the current immutable message
+11 -5
View File
@@ -1,17 +1,22 @@
# Hermes-Relay-Server v__VERSION__
**Release Date:** August 8, 2026
**Release Date:** August 14, 2026
This patch makes the optional Dashboard plugin's Android setup handoff reliable for hosted Hermes connections.
This release adds an official, opt-in Relay pane for Hermes Desktop through the supported runtime Plugin SDK. It keeps Relay management profile-scoped and user-invoked without opening a pane during startup, reconnects, profile changes, or plugin updates.
Standard chat, session history, and Vanilla Hermes voice remain upstream-owned and do not require this plugin.
## What's changed
### Fixed
### Added
- **Canonical hosted-Hermes setup handoff.** The Dashboard plugin supplies the verified Dashboard address Android needs to continue through the official system-browser authentication flow.
- **Contained dialog focus behavior.** Mobile setup dialogs retain their own focus and keyboard handling without disrupting the surrounding Dashboard.
- **Official Hermes Desktop pane.** The unified plugin package registers a movable native pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management.
- **Explicit entry points.** Labeled sidebar, status-bar, and command-palette actions register and reveal the pane lazily; repeated opens reuse the same surface.
- **Profile-scoped state.** Cached Relay state follows the active Hermes profile and is disposed cleanly when the plugin unloads.
### Changed
- **Plugin loading stays passive.** Loading, startup, reconnects, profile changes, and updates never reveal the pane or perform pane-owned network work.
## Install / update
@@ -26,6 +31,7 @@ Standard chat, session history, and Vanilla Hermes voice remain upstream-owned a
## Verify
hermes relay doctor
# Agent/tool callers can use desktop_health to list desktop targets.
python scripts/check-plugin-version-sync.py --expect __VERSION__
---
+26 -3
View File
@@ -70,6 +70,21 @@ an HTTPS reverse proxy. The [full walkthrough](https://hermes-relay.dev/docs/gui
covers Windows, remote access, and dashboard authentication. You do not need to
enable the separate API server or invent an API key for the standard path.
For plugin-enabled setups, optional **Hermes Secure Link** presents Relay, API,
and Dashboard routes through one pairing-pinned TLS origin. It protects traffic
to the paired endpoint while each service keeps its own authentication; it does
not provide reachability or independently identify the physical host. You still
use LAN routing, Tailscale or another VPN, or an operator-managed public route
to reach the listener. Secure Link is off by default and requires a fresh QR
pairing after it is enabled. See the
[remote-access guide](https://hermes-relay.dev/docs/guide/remote-access/).
**Hermes Reach** is an experimental, advanced outbound-broker route. It remains
available for development and self-hosted evaluation, but it is disabled by
default, ordered after supported routes, and not recommended for normal remote
access. Use Tailscale for the easiest supported remote setup, or a public TLS
domain / Direct Secure Link when you want to own the complete network path.
### 3 · Connect and talk
Open the app, choose **Connect to Hermes**, and enter or discover the dashboard
@@ -138,7 +153,7 @@ Full server setup, TLS, and systemd details: [docs/relay-server.md](docs/relay-s
<table>
<tr>
<td align="center" width="25%"><img src="assets/screenshots/01_startup.png" alt="Cold start" width="100%"><br><sub><b>Cold start</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/01_voice_conversation.png" alt="Voice controls in chat" width="100%"><br><sub><b>Voice in chat</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/02_chat.png" alt="Streaming chat" width="100%"><br><sub><b>Streaming chat</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/03_voice.png" alt="Hands-free voice" width="100%"><br><sub><b>Hands-free voice</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/04_sessions.png" alt="Session history" width="100%"><br><sub><b>Session history</b></sub></td>
@@ -186,7 +201,7 @@ tracked independently so community corrections remain easy to contribute.
## Hands on any machine — the Hermes-Relay CLI&nbsp;<sub>(alpha)</sub>
> **Alpha.** Self-contained CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64 — no Node required. Windows also has an optional native, menu-only systray. Assets are unsigned during the experimental phase, so SmartScreen / Gatekeeper warnings are expected.
> **Alpha.** Self-contained CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64 — no Node required. Windows also has an optional compact management tray. Assets are unsigned during the experimental phase, so SmartScreen / Gatekeeper warnings are expected.
The agent's brain stays on the host; the CLI lets it call tools **on your machine** over the same WSS relay — `read_file`, `write_file`, `terminal`, `search_files`, `screenshot`, `clipboard`, `open_in_editor`, and more — behind a one-time consent gate, interactive diff approval for patches, and a `--no-tools` kill-switch.
@@ -202,7 +217,15 @@ hermes-relay update # self-update via GitHub Releases
It pairs against the **same relay and credential store** as the Android app — pair once from either, both work. Tagged on the `desktop-v*` [release track](https://github.com/Codename-11/hermes-relay/releases?q=desktop), with historical releases still visible under `cli-v*`.
On Windows, the default installer adds the optional right-click-only systray: no dashboard or app window, just TUI launch, User/Administrator-aware daemon controls, pairing, local grant review, audit, diagnostics, logs, desktop-use status/cancellation, sign-in startup, and emergency stop.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. It is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
Structured Windows computer control prefers a compatible local CUA Driver
runtime for window-targeted background actions and virtual per-session agent
cursors. It remains behind Hermes host policy, grants, targeting, audit, and
emergency stop; Windows input is an explicit compatibility backend. CUA is not
bundled or updated automatically, but the local CLI/UI can explicitly install,
check, or update its verified canonical package. It is never exposed as a raw
remote tool surface. See the [desktop tools guide](https://hermes-relay.dev/docs/desktop/tools.html#computer-use-engines).
- **Docs:** [CLI guide](https://hermes-relay.dev/docs/desktop/) · [`desktop/README.md`](desktop/README.md)
- **AI-agent setup recipe:** `/hermes-relay-desktop-setup`
+6 -3
View File
@@ -119,9 +119,9 @@ artifacts.
### CLI / tray versioning
`desktop/package.json` is the Desktop/CLI release track's source of truth. Its version
must match the generated CLI and native Windows systray metadata. The systray is
a menu-only controller for the installed CLI; it has no application window,
WebView, embedded terminal, or separate desktop product surface. The public
must match the generated CLI and Windows tray metadata. The tray is a compact
management popup over the installed CLI and shared state; it has no chat,
embedded terminal, plugins, voice, or separate desktop product surface. The public
release remains one `Hermes-Relay-Desktop` track containing CLI binaries plus the
optional Windows installer.
@@ -132,6 +132,9 @@ optional Windows installer.
| `desktop/src/version.ts` | compiled CLI runtime version |
| `desktop/tray/Cargo.toml` | native systray package version |
| `desktop/tray/Cargo.lock` | locked systray package version |
| `desktop/tray/tauri.conf.json` | tray application and bundle version |
| `desktop/tray/package.json` | tray UI package version |
| `desktop/tray/package-lock.json` | locked tray UI package version |
Prepare a new CLI version on `dev` without creating a tag or npm-generated
commit:
+13 -23
View File
@@ -1,10 +1,10 @@
# Hermes-Relay-Android v1.7.1
# Hermes-Relay-Android v1.8.1
**Release Date:** August 8, 2026
**Release Date:** August 9, 2026
## Download
> Installing on your phone? Download `hermes-relay-1.7.1-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
> Installing on your phone? Download `hermes-relay-1.8.1-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
The `.aab` file is a Play Console upload bundle and cannot be installed by tapping it on a phone.
@@ -12,32 +12,22 @@ Verify the download against `SHA256SUMS.txt`. See the [sideload guide](https://h
## Summary
This patch tightens Android chat ownership, interaction safety, session
durability, and hosted-Hermes onboarding after the 1.7.0 release.
This patch keeps long Hermes conversations complete and aligns Android's
Gateway behavior with current upstream turn contracts.
## Fixed
- Growing streamed replies stay visible while bottom-follow is owned, and
intentional scrollback still releases that ownership.
- Completed replies transition immediately from stable live text to rendered
Markdown without reopening the session.
- Queued follow-ups retain their originating connection, profile, session,
route, attachments, and voice context through concurrent session switches.
- Approval cards remain pending until an explicit labeled response or an
authoritative upstream expiry; scrolling, navigation, and later activity
cannot silently decide them.
- Session pins and archives persist through the owning Hermes profile, with
rollback when an update fails.
- Live tool cards retain stable identity and details while a run is active, and
duplicate model inventory rows are reconciled before rendering.
- Hosted Hermes addresses complete through the official Dashboard system-browser
sign-in flow and resume the verified connection after callback.
- Agent Passport safety controls use accessible full-width choices and a
reliable close or downward-swipe path.
- Complete transcript reads page explicitly across both API-server and
profile-scoped Dashboard routes, so sessions beyond Hermes' latest-500
default retain stable history, sharing, retry, edit, and recovery anchors.
- Gateway submit rejections preserve the authoritative server message without
silently falling through to SSE.
- Gateway event envelopes reconcile consistently, and edit-and-regenerate
requests send the required truncation confirmation.
## Install / Verify
- App version: **1.7.1** (versionCode **40**).
- App version: **1.8.1** (versionCode **42**).
- Standard Chat, sessions, Manage, and Vanilla Hermes voice continue to work
against unmodified upstream Hermes.
- The optional Relay plugin is not required for standard Android chat or hosted
+58 -5
View File
@@ -6,6 +6,40 @@ For shipped work, see `DEVLOG.md`. For architectural decisions, see `docs/decisi
---
## Certify the official Desktop Relay plugin
The unified `plugin/desktop/plugin.js` implementation is covered by source-level
SDK contract, packaging, explicit-open, no-auto-open, close, unload, and profile
cache-isolation tests. A physical official Hermes Desktop session is still
required before calling the UX live-certified:
- Test default and named local profiles, ordinary authenticated remote mode,
and SSH mode with differently named local/remote profile mapping.
- In two full app windows, prove enabling, registration, explicit open,
requests, close/reopen, hot reload, and disable/unload remain window-local.
- Prove startup, reconnect, profile change, layout restore/reset, update, and
background events never open or focus Relay.
- Drag and dock the pane across native zones, close it, reopen it from all three
labeled actions, and verify no private-hook fallback is needed.
- Exercise Relay running/unreachable, zero/one/multiple devices, pairing,
revocation, bridge activity, media, remote access, and renderer error logging
without exposing credentials, pairing payloads, filesystem paths, or tokens.
---
## Structured desktop hardware capabilities
Structured access and per-host USB policy now ship with typed, serial-bound ADB
list, shell, push, pull, install, and bounded logcat operations. Remaining work:
- Add microphone and camera only with backend readiness detection, bounded local
grants, active-use indicators, audit events, and immediate cancellation.
- Reconcile legacy `desktop_screenshot` with the task-granted computer screenshot
path so screen capture follows one policy.
- Extend capability policy beyond hardware only where a typed broker provides a
meaningfully stronger boundary than Structured mode already provides.
---
## Android Plugin Studio protocol follow-ups
The first live declarative Plugin lane is host-local: Relay tools create bounded
@@ -909,7 +943,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
- Live gateway must discover the plugin (`~/.hermes/plugins/hermes-relay` → `plugin/`) and `plugins.enabled` must include `hermes-relay` for the `phone` platform to register. Confirm `phone` appears in `hermes gateway status` with `PHONE_ENABLED=1`.
- End-to-end: with the app paired + "Let Hermes message me" on, run `send_message target=phone text=...` (and a cron `deliver=phone`) and confirm a notification on the device. Verify 503 (no phone) and the off-by-default gates.
- **Phase 2c reply round-trip — ✅ DONE (verified on-device 2026-06-29).** Confirmed: agent → phone notification → inline reply → drained through the relay's loopback `GET /phone/replies` (different process) → `handle_message` (`role_authorized=True`, no `PHONE_ALLOW_ALL_USERS`) → agent answer back in the *same* thread. Both fixes required (see DEVLOG / the Phase 2c bullet above).
- **FIX: cron `deliver=phone` / standalone send is broken.** Live testing: `hermes send --to phone` returns `{"error": "Unknown platform: phone"}`. The standalone (non-gateway) send path doesn't run a `kind=standalone` plugin's programmatic `ctx.register_platform`, so it never learns `phone` — only the running gateway (which loads `register()` at startup) does. The agent path (`send_message target=phone` in the gateway) works and was verified end-to-end on-device; the standalone/cron path needs the platform discoverable there too (declare it so the standalone loader picks it up, or route cron through the gateway). Until then `cron deliver=phone` won't work.
- **Cron `deliver=phone` live certification pending.** The plugin now registers its standalone sender and enumerates the canonical phone home through the upstream adapter channel-directory hook. Re-run the device scenario above on the deployed plugin to certify scheduled delivery, including the offline queue and opt-in gates.
- **FIX SHIPPED (2026-07-07) — installer + doctor guard against stale duplicate plugin copies; live-host verify pending.** Root cause of the 2026-06-29 round-trip failure: the gateway loader dedups discovered plugins by manifest `name`, so a second directory declaring `name: hermes-relay` (an old-installer backup copy, or a stray native install) could win the dedup and make the gateway load stale code — silently ignoring every later deploy. `plugin/doctor.py` now emits a `plugin-name-unique` warning when more than one directory under `~/.hermes/plugins/` declares the same plugin name (distinct real targets only — two links to the same target are deduped), and `install.sh` sweeps any such duplicate so only the canonical `hermes-relay` symlink survives. (Current `install.sh` already `rm -rf`s the old link rather than backing it up inside the plugins dir, so the original "back up outside the plugins dir" half is moot.) **Verify on the live host:** `hermes relay doctor` reports the `plugin-name-unique` check, and a reinstall leaves exactly one `hermes-relay` entry under `~/.hermes/plugins/`.
## Phone platform — usability roadmap (post device-verification, 2026-06-29)
@@ -922,7 +956,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
- **Outbound buffering — ✅ relay-side DONE (2026-06-29).** `ProactiveChannel.push()` now queues agent→phone messages in a bounded deque (drop-oldest, 24 h TTL) when no phone is subscribed and returns `{queued: true}` (not 503); `_flush_outbound` delivers FIFO on the next subscribe (stale pruned). Inspect/cancel via `peek_outbound`/`cancel_outbound` + loopback `GET`/`DELETE /phone/outbound`. **UI surfacing of the queued state** (host-side, since the queue exists while the phone is OFFLINE): (a) ✅ **desktop CLI `relay queue` / `relay queue --clear` / `--cancel <id>` DONE (2026-06-29)** over the new endpoints (loopback-only — run on the relay host); a dashboard Relay-tab view is the optional GUI equivalent; (b) **remaining** — in the threaded agent surface, mark messages that arrived-while-away, and show the user's OWN pending replies (the Phase 3 reply queue) with a sending/Cancel affordance — that's where phone-side "queued + cancel" belongs.
- **Threads surface (unified-session model — see ADR 12 + the Refinement above).** Build order, each shippable: **(1)** source tags in the session drawer (`source=phone` → clean **Threads** chip + thread-spool icon, NOT a phone glyph) — also delivers the "source attribution in Chat" goal; **(2)** open a Thread in Chat from its session-store history (reuse the existing message-history path); **(3)** route the live `proactive` push into the session view + notification + unread, demoting `ProactiveInboxStore` to cache/outbox; **(4)** reply from the Chat composer via `proactive.reply` + persist the user turn + local `Sending/Queued/Failed` status — **MVP**; **(5)** a **Threads capability row** in the best-path UI + a pinned **Threads** entry atop the drawer (thread-spool icon, shown only when relay-paired + opted-in) + retire `HermesInboxScreen`, re-point the notification deep-link + Settings "View messages"; **(6)** outbox/retry on reconnect; **(7)** relay `proactive.reply.ack` (honest Delivered) + `proactive.cancel`; **(8)** multi-thread `chat_id` (named/project Threads). **Verify gate before (1):** confirm the app's session-list/history path surfaces a `source=phone` session cleanly (upstream `session.list` returns all sources flat, so it should — but check whether the drawer currently filters it out). Honesty call: do NOT show "Delivered" until (7) lands (can't confirm it client-side before the ack).
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering** (an agent reply lands in the open Thread as an ASSISTANT bubble, suppressing the notification/inbox — `injectIntoThread`); **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`** (deleted; route + nav removed; notification tap + Settings "View messages" re-pointed to Chat; surface renamed "Hermes messages" → **"Threads"**); relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DEFERRED (reasons):** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **exact-Thread deep-link** from the notification (opens Chat today, not the specific thread — needs select-session-on-entry); **remove the now-orphaned `ProactiveInboxStore`** (viewer-less write-only log); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering**; **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`**; relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DONE (2026-08-14):** notification taps survive cold start and open the exact `chat_id`; agent-initiated outbound messages appear as connection-scoped provisional Threads backed by the bounded proactive store, then promote to the real `source=phone` session after the first reply. **DEFERRED:** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **User-created Threads (slice 8, Discord-style) — CODE-COMPLETE on `dev` (built + installed 2026-06-29; on-device behavior pending).** "+ New Thread" in the drawer's Threads view → name dialog → `ChatViewModel.startNewThread` mints a fresh `chat_id`; the first composer message opens it over `proactive.reply` (gateway auto-creates the `source=phone` session) → `switchToCreatedThread` polls + switches to the real session + applies the name. Existing-thread replies route by the `chat_id` parsed from the session id (`…:dm:<chat_id>`; opaque id → home fallback). **On-device verifies:** (1) a fresh-`chat_id` no-`reply_to` inbound creates a new `source=phone` session; (2) the phone session id carries the `…:dm:<chat_id>` form the client parses; (3) `renameSession` titles a phone session. **Remaining slice-8:** AGENT-initiated named Threads (the upstream `send_message` thread/chat_id param so the agent can open its own named Threads).
- **`chat_id` not exposed by `/api/sessions` (root cause of the 2026-06-29 on-device create-flow bugs — fixed client-side).** Confirmed on the host: a phone session's `id` is a timestamp (e.g. `20260629_204755_94f391d6`); the real `chat_id` lives in the `session_key` (`agent:main:phone:dm:<chat_id>`) and a `chat_id` column — but `/api/sessions` returns **neither `chat_id` nor `session_key`**, only `source` + the timestamp `id`. So the client could not map a session ↔ its `chat_id`, which broke create-thread switch/rename + reply routing + in-thread injection. **Client workaround shipped:** find a created thread by session-list **diff** (the new `source=phone` session), keep an in-memory `sessionId → chat_id` map (learned at creation + from incoming `phone.message`s) for reply routing, and inject by source (+ learned chat_id) rather than a parsed id. **Limitation:** for a thread the app didn't create *this* session (agent-created, another device, or after an app restart) `chat_id` is unknown until a message arrives while viewing it → its replies fall back to the home channel until then. **RESOLVED via the plugin (2026-06-29, per upstream-or-plugin policy):** the relay now exposes `GET /phone/threads` (`plugin/relay/session_store.py` reads the gateway store read-only → `[{session_id, chat_id, title}]`; `server.py` `handle_phone_threads`, bearer for the app / loopback for diag; 5 unit tests). The app (`RelayHttpClient.fetchPhoneThreads` → `ConnectionViewModel.phoneThreadChatIds` on every `auth.ok` → `ChatViewModel.seedThreadChatIds`, authoritative over the learned map) now routes replies correctly for **any** Thread — incl. ones it didn't create + after restart. Deployed + verified live. **Still-nice-to-have (lower priority): the upstream PR** to add `chat_id`/`session_key` to `/api/sessions` (the standard-path proper fix; the relay route then becomes redundant + the client prefers upstream when present).
- **Threads as named/project conversations (Discord-parity — folds into multi-thread #8).** A stable *named* `chat_id` per project = a persistent, agent-reachable project Thread (Discord named-thread parity for "persist a session for a project"). Enables: the agent **opening** a new named Thread for a background job/topic (a relay/gateway "open thread" affordance + a `send_message`-adjacent tool); cron/job updates landing in their own Thread; and replying to a Thread from any surface (desktop CLI / dashboard) since it is just a gateway session. Also evaluate per-Thread profile binding (a project Thread uses the "work" profile — ties to profile=contact).
@@ -942,7 +976,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
The gateway-platform model is the *correct + sufficient architecture* (the phone is a registered platform peer, so anything that routes to a platform — `send_message`, cron `deliver=`, channel directory, background jobs — can reach the phone). These are the concrete gaps between "architecturally a peer" and "I never open Discord":
- **Guaranteed background delivery (the biggest gap; no push today).** Delivery is **live-WSS-only** + a 24 h relay buffer; there is **no FCM/UnifiedPush** wake-up. If the app process is dead AND not holding a socket, a message waits for the next reconnect, and the relay buffer is ephemeral (lost on relay restart). Discord/Telegram feel instant because they wake the device via push even when the app is dead. Decide a **push transport**: **UnifiedPush/ntfy** (recommended — self-hostable, no Google dependency, upstream *already* ships an `ntfy` platform, on-brand for self-hosted) vs **FCM** (simplest UX but adds Play Services + a push relay; clashes with self-hosted ethos — at most the `googlePlay` flavor) vs **persistent foreground keep-alive service** holding the relay WSS (zero new infra, like `GatewayKeepAliveService`, but battery cost + Doze-fragile). Likely: UnifiedPush primary + foreground-keepalive fallback.
- **Cron / background-job delivery is BROKEN** (already tracked above): `deliver=phone` standalone path → `Unknown platform: phone`. This is load-bearing for "receiver of crons/background jobs" — fix is required, not optional, for the replacement goal.
- **Cron / background-job delivery needs live certification.** The standalone sender and channel-directory enumeration are implemented; certify `deliver=phone` against a deployed Relay and paired device, including reconnect delivery from the bounded offline queue.
- **Agent-initiated multi-thread creation remains.** The app already renders N
`source=phone` sessions, user-created Threads vary `chat_id`, and replies route
by `chat_id` + `reply_to`. The missing parity is letting the agent open/name a
@@ -951,7 +985,7 @@ The gateway-platform model is the *correct + sufficient architecture* (the phone
session store; the relay buffer is only the live/offline-delivery layer, not a
parallel history database.
- **Profile = contact mapping (new idea, fold in).** Multiple Hermes **profiles** (distinct agent personas/configs) could each be a distinct thread *source*/"contact" — DMing different agents. Maps cleanly onto the per-thread `chat_id` + source-attribution work; lets the app feel like a contact list of agents.
- **Per-thread notification controls + deep-link (Discord-parity affordances).** Per-thread notification channels, mute/DND/quiet-hours (Phase 3 partially), and a notification that **deep-links into the exact thread** (tap → land in that conversation) so dipping in/out while multitasking is frictionless.
- **Per-thread notification controls (Discord-parity affordances).** Exact-thread notification deep-linking is shipped. Remaining: per-thread notification channels and mute/DND/quiet-hours controls (Phase 3 partially).
- **Agent-initiated rich content.** Agent → phone thread with **images/cards** (relay media infra + `InboundAttachmentCard`/`HermesCardBubble` already exist on the chat side — reuse). Inbound (phone → agent) reply media stays deferred (text-first), but outbound rich content is low-cost parity.
- **In-thread "agent is working" indicator.** A typing/working state in the thread while the agent thinks/runs tools (Discord typing-dots parity) — the chat surface already has thinking indicators to reuse.
@@ -1217,6 +1251,25 @@ When the answer becomes clearer, this section becomes either an ADR in `docs/dec
## Smaller deferred items
- **Certify the preferred CUA Driver backend (ADR 56).** The canonical-runtime
probe, bounded adapter, server-owned control-session envelope, per-session
grant state, local engine/status controls, telemetry-off process environment,
and Hermes snapshot-token primitives now exist. Before graduating the engine,
finish end-to-end enforcement of app/display/folder scopes and sensitive
pixel/accessibility denial or redaction, harden the grant-bridge ACL and nonce
lifecycle, and complete live Windows certification proving the physical cursor and
foreground app stay unchanged, stale or cross-window tokens fail, two remote
control sessions receive isolated animated cursors, and foreground escalation
never happens implicitly. Exercise revoke on grant expiry, disconnect,
re-pair, policy downgrade, emergency stop, Windows-session change, and daemon
shutdown. The explicit local CUA install/update surface now verifies upstream
manifest identity and installer SHA-256; add Windows publisher verification
when upstream signs the installer. Keep raw CUA tools, configuration,
recording, replay, and JavaScript outside the remote agent surface.
Remove the temporary Windows readiness/health split once
[trycua/cua#3103](https://github.com/trycua/cua/issues/3103) ships in the
supported CUA range; restore a mandatory health gate only if the upstream
probe is bounded and cannot leave UI Automation falsely busy.
- **MediaProjection consent flow** — wired in MainActivity (2026-04-12), needs end-to-end test on a real device
- **WorkManager upgrade for auto-disable timer** — currently a coroutine `Job + delay()` in `AutoDisableWorker.kt`; documented at top of file. Upgrade when androidx.work joins the classpath
- **Wave 3 voice-bridge multi-turn confirmation** — currently a 5s TTS countdown with cancel; conversational confirmation is the follow-up
@@ -1274,7 +1327,7 @@ Follow-ups:
profile/skill-aware empty-state chips and the ~40-flow recomposition hotspot at
the top of `ChatScreen`.
- **Pet hot-load + in-app add/remove (shipped 2026-06-20).** Pets now live-refresh: an `avatarsRefreshTick` keys the avatar `produceState` in `RelayApp`, and Appearance re-scans `pets/` on open and after in-app import/delete — no app restart. Appearance gained "Add a pet" (SAF `.zip` import via `PetImporter`, zip-slip/zip-bomb guarded + validated through `toAvatar`) and an "Installed pets" list with per-pet remove (`PetLoader.deletePet`, confirm dialog, Sphere fallback). Remaining:
- **Sphere-skin parity.** Skins are still process-scoped + `adb push` only — the live tick and the importer cover pets, not skins. Extend the tick to `loadUserSkins` and add a `.json` skin import if hot-loading/adding skins in-app is wanted.
- **Sphere-skin parity (shipped 2026-08-09).** Appearance now imports a bounded, validated declarative `.json` skin through the system picker, hot-refreshes the shared sphere registry, and selects the imported skin without an app restart.
- `**adb push` into `Android/data` hangs on Samsung scoped storage.** Confirmed: pushing a pet pack to `/sdcard/Android/data/<pkg>/files/pets/` stalls (no bytes written) although `adb shell ls` of the dir works. In-app `.zip` import is the supported path; `/sdcard/Download` pushes fine. Consider softening `docs/pet-spec.md` + user-docs to lead with in-app import over adb.
- **On-device import/delete smoke.** Import `/sdcard/Download/lucy.zip` via Add a pet → confirm Lucy appears, selects, and animates all states; then remove it and confirm the avatar falls back to the Sphere.
- **Pet behavior model — richer state association (spec'd 2026-06-19, `docs/pet-spec.md` "Agent states &amp; pet behavior").** Shipped: the honesty clamp (declared reactivity ∩ `PET_RENDERER_CAPABILITIES`), the friendly `writing` alias, the `**working`/tool-use overlay** (pet-local sub-state from `toolCallBurst`; opt-in `working` clip drives both the swap and the Tools badge), the **one-shot reaction layer** (`greet`/`wake` on appear, `done`/`celebrate` on turn-finish — opt-in, play-once-then-revert, transition-derived; `ONE_SHOT_MAX_MS` backstop), and `**intensity` modulation** (opt-in `reactive.intensity` → live playback speedup ≤1.6× via `rememberUpdatedState`; un-clamps the Activity badge). Voice · Tools · Activity reactivity is now complete. Remaining:
+4 -2
View File
@@ -320,9 +320,11 @@ dependencies {
// Coil 3 — async image loading for generated images in chat
implementation(libs.coil.compose)
implementation(libs.coil.network.okhttp)
implementation(libs.exifinterface)
// QR Code scanning (ML Kit + CameraX)
implementation(libs.mlkit.barcode)
implementation(libs.zxing.core)
implementation(libs.camera.core)
implementation(libs.camera.camera2)
implementation(libs.camera.lifecycle)
@@ -369,8 +371,8 @@ dependencies {
// [POC] Roborazzi host-side screenshot rendering (src/test, Robolectric).
// Renders real composables on the JVM at an exact canvas — no device, no
// status bar, no clipping. See StoreScreenshotTest.
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.70.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.70.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.71.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.71.0")
testImplementation(libs.compose.ui.test.junit4)
testImplementation(libs.compose.ui.test.manifest)
testImplementation("androidx.test.ext:junit:1.3.0")
Binary file not shown.

Before

Width:  |  Height:  |  Size: 128 KiB

After

Width:  |  Height:  |  Size: 176 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 166 KiB

After

Width:  |  Height:  |  Size: 186 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 112 KiB

After

Width:  |  Height:  |  Size: 132 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 134 KiB

After

Width:  |  Height:  |  Size: 106 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 129 KiB

After

Width:  |  Height:  |  Size: 232 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 222 KiB

After

Width:  |  Height:  |  Size: 203 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 110 KiB

After

Width:  |  Height:  |  Size: 109 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 166 KiB

After

Width:  |  Height:  |  Size: 180 KiB

@@ -1 +1 @@
Growing replies now stay visible without overriding intentional scrollback, completed Markdown renders immediately, and queued follow-ups remain with their originating chat. Session pins and archives persist, approval cards require an explicit decision, Agent Passport controls are easier to use, and hosted Hermes setup completes through the official Dashboard sign-in flow.
Long sessions now retain complete history beyond Hermes' latest-500 default, keeping edit, retry, sharing, and recovery anchors stable. Gateway submit rejections preserve the server's message without unintended SSE fallback, while event envelopes and edit-and-regenerate requests follow current upstream contracts.
+7
View File
@@ -48,6 +48,13 @@
<action android:name="android.intent.action.MAIN" />
<category android:name="android.intent.category.LAUNCHER" />
</intent-filter>
<!-- User-mediated text handoff. The app opens a fresh Chat draft
and fills the composer; it never sends from an external intent. -->
<intent-filter>
<action android:name="android.intent.action.SEND" />
<category android:name="android.intent.category.DEFAULT" />
<data android:mimeType="text/*" />
</intent-filter>
<!-- The loopback native-PKCE result page uses this fixed, tokenless
link only to bring the installed flavor back to the foreground.
MainActivity intentionally does not interpret the URI as an auth
+56
View File
@@ -1,5 +1,61 @@
{
"versions": [
{
"version": "1.8.1",
"title": "Complete, reliable transcripts",
"date": "2026-08-09",
"sections": [
{
"header": "Keep long sessions complete",
"bullets": [
"Android pages explicitly through complete API-server and profile-scoped Dashboard history instead of silently stopping at Hermes' latest-500 default.",
"Sharing, retry, edit, and recovery retain stable transcript anchors while bounded safety limits keep unusually large reads controlled."
]
},
{
"header": "Follow Gateway truth",
"bullets": [
"Authoritative submit rejections preserve the server's message without an unintended SSE fallback.",
"Gateway event envelopes and edit-and-regenerate truncation confirmation now follow current upstream contracts."
]
}
]
},
{
"version": "1.8.0",
"title": "Conversations with more context",
"date": "2026-08-09",
"sections": [
{
"header": "Keep the whole turn together",
"bullets": [
"Quote, edit, search, and attach or reorder files without losing the active connection, profile, or session.",
"Share text from another Android app into a fresh Chat draft for review before sending."
]
},
{
"header": "See the work without the clutter",
"bullets": [
"Live thinking settles into a compact Thought disclosure, while routine tool activity groups into concise runs.",
"Approvals, failures, generated media, file changes, risks, and delegated work remain clearly distinct."
]
},
{
"header": "Switch agents, not identities",
"bullets": [
"The Profile Shelf switches agents from Chat while restoring each profile's last session.",
"Agent Passport model and reasoning controls remain scoped to the active session instead of rewriting server defaults."
]
},
{
"header": "Make it yours",
"bullets": [
"Preview theme accents and shapes, Sphere skins, and pets in one Appearance workflow.",
"Message speech controls, pet touch targets, scrolling terrain, image rotation, and edge-to-edge settings layout are more reliable."
]
}
]
},
{
"version": "1.7.1",
"title": "Safer, steadier conversations",
+5 -6
View File
@@ -1,7 +1,6 @@
v1.7.1 - Safer, steadier conversations
v1.8.1 - Complete, reliable transcripts
* Follow growing replies without overriding intentional scrollback.
* Render completed Markdown immediately and keep live tool details expandable.
* Keep queued follow-ups with their originating chat and persist session pins and archives.
* Require explicit approval decisions and improve Agent Passport controls.
* Complete hosted Hermes setup through the official Dashboard sign-in flow.
* Keep complete history in long sessions beyond Hermes' latest-500 default.
* Preserve stable edit, retry, sharing, and recovery anchors while paging history.
* Show authoritative Gateway rejection messages without an unintended fallback.
* Reconcile Gateway events and edit-and-regenerate requests with current upstream contracts.
@@ -25,6 +25,8 @@ import com.hermesandroid.relay.notifications.TurnCompleteNotifier
import com.hermesandroid.relay.notifications.InteractionRequestNotifier
import com.hermesandroid.relay.ui.RelayApp
import com.hermesandroid.relay.util.NavRouteRequest
import com.hermesandroid.relay.util.SharedTextRequest
import com.hermesandroid.relay.util.extractSharedText
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import kotlinx.coroutines.launch
import kotlinx.coroutines.flow.collect
@@ -127,6 +129,7 @@ class MainActivity : AppCompatActivity() {
// in RelayApp's NavRouteRequest collector — we just pump the request
// into the SharedFlow here.
consumeNavRouteIntent(intent)
consumeSharedTextIntent(intent)
val consumedAssistantActivation =
com.hermesandroid.relay.assistant.AssistantSessionProtocol.consumeActivation(
this,
@@ -153,6 +156,7 @@ class MainActivity : AppCompatActivity() {
// instead of onCreate. RelayApp's collector handles both cases.
setIntent(intent)
consumeNavRouteIntent(intent)
consumeSharedTextIntent(intent)
com.hermesandroid.relay.assistant.AssistantSessionProtocol.consumeActivation(this, intent)
// === END PHASE3-safety-rails-followup ===
}
@@ -163,6 +167,15 @@ class MainActivity : AppCompatActivity() {
NavRouteRequest.tryRequest(route)
}
private fun consumeSharedTextIntent(intent: Intent?) {
val sharedText = extractSharedText(
action = intent?.action,
mimeType = intent?.type,
text = intent?.getCharSequenceExtra(Intent.EXTRA_TEXT),
) ?: return
SharedTextRequest.tryRequest(sharedText)
}
private fun configureAssistantWindow(intent: Intent?) {
if (
intent?.getBooleanExtra(
@@ -1,9 +1,14 @@
package com.hermesandroid.relay.auth
import android.content.Context
import android.provider.Settings
import android.util.Log
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.BrokerEndpoint
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.replaceHermesReachCredential
import com.hermesandroid.relay.data.sameBrokerAuthority
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.network.relay.ChannelMultiplexer
@@ -14,6 +19,7 @@ import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
@@ -557,6 +563,12 @@ class AuthManager(
* Either way, we leave the previously-persisted list untouched.
*/
private var pendingEndpoints: List<EndpointCandidate>? = null
private var activeEndpointProvider: () -> EndpointCandidate? = { null }
/** Bind auth.ok route credentials to the transport that actually carried them. */
fun setActiveEndpointProvider(provider: () -> EndpointCandidate?) {
activeEndpointProvider = provider
}
/**
* Server-advertised agent profiles from the `auth.ok` payload's
@@ -631,7 +643,7 @@ class AuthManager(
val now = System.currentTimeMillis() / 1000L
val defaults = PairedSession(
token = token,
deviceName = android.os.Build.MODEL,
deviceName = relayDeviceName(),
expiresAt = null,
grants = emptyMap(),
transportHint = null,
@@ -651,7 +663,7 @@ class AuthManager(
val transportHint = obj["transport_hint"]?.jsonPrimitive?.contentOrNull
val firstSeen = obj["first_seen"]?.jsonPrimitive?.longOrNull ?: now
val deviceName = obj["device_name"]?.jsonPrimitive?.contentOrNull
?: android.os.Build.MODEL
?: relayDeviceName()
PairedSession(
token = token,
@@ -750,6 +762,26 @@ class AuthManager(
})
}
private fun JsonObjectBuilder.putRelayDeviceIdentity() {
val model = android.os.Build.MODEL.orEmpty().ifBlank { "Android device" }
val deviceName = relayDeviceName()
put("device_name", deviceName)
put("device_hostname", deviceName)
put("device_model", model)
put("device_platform", "Android ${android.os.Build.VERSION.RELEASE}")
put("client_surface", "android")
put("device_form_factor", "phone")
}
private fun relayDeviceName(): String {
val configured = runCatching {
Settings.Global.getString(context.contentResolver, "device_name")
}.getOrNull()?.trim().orEmpty()
return configured.ifBlank {
android.os.Build.MODEL.orEmpty().ifBlank { "Android device" }
}
}
/**
* Send auth envelope when connection is established.
*
@@ -784,7 +816,7 @@ class AuthManager(
put("refresh_token", refreshToken)
}
put("device_id", deviceId)
put("device_name", android.os.Build.MODEL)
putRelayDeviceIdentity()
putRelayClientSupports()
}
}
@@ -800,7 +832,7 @@ class AuthManager(
buildJsonObject {
put("pairing_code", codeToSend)
put("device_id", deviceId)
put("device_name", android.os.Build.MODEL)
putRelayDeviceIdentity()
putRelayClientSupports()
pendingTtlSeconds?.let { put("ttl_seconds", it) }
pendingGrants?.let { grants ->
@@ -1021,6 +1053,7 @@ class AuthManager(
}
if (token != null) {
applyBrokerRouteCredential(payload)
val s = store()
s.putString(KEY_SESSION_TOKEN, token)
val refreshToken = payload["refresh_token"]
@@ -1066,7 +1099,7 @@ class AuthManager(
val paired = PairedSession(
token = token,
deviceName = android.os.Build.MODEL,
deviceName = relayDeviceName(),
expiresAt = expiresAt,
grants = grantsMap,
transportHint = transportHint,
@@ -1129,6 +1162,40 @@ class AuthManager(
}
}
private suspend fun applyBrokerRouteCredential(payload: JsonObject) {
val active = activeEndpointProvider()?.takeIf { it.hasHermesReach() } ?: return
val current = active.broker ?: return
// Fresh pairing is scoped by pendingEndpoints; reconnect rotation is
// accepted only by this connection-scoped AuthManager's live session.
if (pendingEndpoints == null && _authState.value !is AuthState.Paired) return
val credential = payload["route_credential"] as? JsonObject ?: return
if (credential["kind"]?.jsonPrimitive?.contentOrNull != "broker_route") return
val brokerUrl = credential["broker_url"]?.jsonPrimitive?.contentOrNull ?: return
val hostId = credential["host_id"]?.jsonPrimitive?.contentOrNull ?: return
if (!sameBrokerAuthority(brokerUrl, current.url) || hostId != current.hostId) {
Log.w(TAG, "Ignoring broker route credential that does not match the active paired route")
return
}
val replacement = BrokerEndpoint(
url = current.url,
protocolVersion = current.protocolVersion,
hostId = current.hostId,
credentialKind = "route",
token = credential["token"]?.jsonPrimitive?.contentOrNull ?: return,
expiresAt = credential["expires_at"]?.jsonPrimitive?.longOrNull,
)
val validated = active.copy(broker = replacement).takeIf { it.hasHermesReach() } ?: return
val deviceId = getDeviceId()
val source = pendingEndpoints
?: PairingPreferences.getDeviceEndpoints(context, deviceId).first()
val updated = replaceHermesReachCredential(source, current, validated)
if (updated == source) return
if (pendingEndpoints != null) pendingEndpoints = updated
else PairingPreferences.setDeviceEndpoints(context, deviceId, updated)
Log.i(TAG, "Accepted a durable Hermes Reach route credential for the active paired route")
}
private fun handleAuthFail(envelope: Envelope) {
try {
val rawReason = envelope.payload["reason"]?.jsonPrimitive?.contentOrNull
@@ -90,12 +90,28 @@ class CertPinStore(private val context: Context) {
if (pins.isEmpty()) return CertificatePinner.DEFAULT
val builder = CertificatePinner.Builder()
for ((hostPort, pin) in pins) {
val host = hostPort.substringBefore(':')
val host = hostPort.substringBeforeLast(':')
builder.add(host, pin)
}
return builder.build()
}
/**
* Build a pinner for one exact URL authority. CertificatePinner keys by
* hostname only, so adding every stored host:port entry to one client
* accidentally lets a pin learned on one port govern another port.
*/
fun buildPinnerSnapshotFor(url: String): CertificatePinner {
val hostPort = hostPortFromUrl(url) ?: return CertificatePinner.DEFAULT
val pin = getPinsBlocking()[hostPort] ?: return CertificatePinner.DEFAULT
val host = runCatching { URI(url.trim()).host }.getOrNull()
?.takeIf { it.isNotBlank() }
?: return CertificatePinner.DEFAULT
return CertificatePinner.Builder()
.add(host, pin)
.build()
}
/**
* Record a pin for a host. Called from the WebSocket listener's `onOpen`
* when we have a successful connection and can read the peer certs from
@@ -74,6 +74,14 @@ data class PairedDeviceInfo(
val deviceName: String = "",
@SerialName("device_id")
val deviceId: String = "",
@SerialName("device_model")
val deviceModel: String = "",
@SerialName("device_platform")
val devicePlatform: String = "",
@SerialName("client_surface")
val clientSurface: String = "",
@SerialName("device_form_factor")
val deviceFormFactor: String = "",
@SerialName("created_at")
val createdAt: Double? = null,
@SerialName("last_seen")
@@ -3,10 +3,10 @@ package com.hermesandroid.relay.data
/**
* Shared profile/personality display and request identity helpers.
*
* A null profile name is the app's explicit "Server default" state. The
* relay also advertises the root Hermes config as a synthetic profile named
* "default"; for request/session identity that row is an alias of server
* default so it does not split chat, voice, or session scope.
* A null profile name is the app's explicit "Server default" state. It is
* intentionally distinct from a real profile whose name is literally
* `default`: the former follows the server's sticky default, while the latter
* explicitly addresses the root profile.
*/
object AgentDisplay {
const val SERVER_DEFAULT_PROFILE_KEY: String = "__server_default__"
@@ -16,17 +16,16 @@ object AgentDisplay {
"hermes agent",
)
// Only an EXPLICIT pick drives request/session identity. The advertised
// "default" profile is an alias for server default, so falling back to it
// here would split chat, voice, or session scope.
// Only an explicit pick drives request identity. Server default is the null
// selection; a named `default` profile is an ordinary explicit pick.
@Suppress("UNUSED_PARAMETER")
fun effectiveProfile(
selectedProfile: Profile?,
profiles: List<Profile>,
): Profile? = selectedProfile
// Display can use the synthetic default profile's metadata without making
// it a request/session override. Verbose SOUL summaries are filtered by
// Display can use the root default profile's metadata without making it a
// request/session override. Verbose SOUL summaries are filtered by
// profileDisplayName below, so this is safe for headers/cards.
fun effectiveDisplayProfile(
selectedProfile: Profile?,
@@ -39,7 +38,7 @@ object AgentDisplay {
?.let { activeName ->
profiles.firstOrNull { it.name.equals(activeName, ignoreCase = true) }
}
?: profiles.firstOrNull { isServerDefaultAlias(it.name) }
?: profiles.firstOrNull { it.name.equals("default", ignoreCase = true) }
}
// The NAME goes in the name slot. Non-default profiles use their profile
@@ -48,7 +47,7 @@ object AgentDisplay {
// verbose SOUL summary.
fun profileDisplayName(profile: Profile?): String? {
if (profile == null) return null
if (isServerDefaultAlias(profile.name)) {
if (profile.name.equals("default", ignoreCase = true)) {
return defaultProfileDisplayName(profile)
}
return when {
@@ -135,22 +134,18 @@ object AgentDisplay {
?.takeIf { it.isNotEmpty() }
?.takeUnless { it.lowercase() in GENERIC_MODEL_ALIASES }
fun isServerDefaultAlias(profileName: String?): Boolean =
profileName?.trim()?.equals("default", ignoreCase = true) == true
fun normalizeSelection(profile: Profile?): Profile? =
if (isServerDefaultAlias(profile?.name)) null else profile
fun normalizeSelection(profile: Profile?): Profile? = profile
fun profileRequestName(profileName: String?): String? =
profileName
?.trim()
?.takeIf { it.isNotEmpty() && !isServerDefaultAlias(it) }
?.takeIf { it.isNotEmpty() && it != SERVER_DEFAULT_PROFILE_KEY }
/**
* The profile name that owns chat sessions for the current UI selection.
*
* [selectedProfileName] is null (or the synthetic `default` alias) for the
* "Server default" row. That UI sentinel must remain distinct from the
* [selectedProfileName] is null for the "Server default" row. That UI
* sentinel must remain distinct from the
* server's sticky active profile: a dashboard launched under the root home
* may still report `active=victor`, in which case upstream Gateway and
* dashboard session calls must explicitly target `victor`. The resolved
@@ -0,0 +1,147 @@
package com.hermesandroid.relay.data
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.map
/**
* Immutable owner of one composer draft.
*
* Callers must supply stable ids rather than display labels. [sessionId] may be
* a server id or a stable client-generated id for a not-yet-created session.
* [draftId] separates the primary composer from any future named draft slot.
*/
data class ChatComposerDraftKey(
val connectionId: String,
val profileId: String,
val sessionId: String,
val draftId: String = PRIMARY_DRAFT_ID,
) {
init {
require(connectionId.isNotBlank()) { "connectionId must not be blank" }
require(profileId.isNotBlank()) { "profileId must not be blank" }
require(sessionId.isNotBlank()) { "sessionId must not be blank" }
require(draftId.isNotBlank()) { "draftId must not be blank" }
}
companion object {
const val PRIMARY_DRAFT_ID = "primary"
const val DEFAULT_PROFILE_ID = "default"
}
}
/** Message references associated with composer content. */
data class ChatComposerDraftContext(
val quotedMessageId: String? = null,
val editingMessageId: String? = null,
) {
internal fun normalized(): ChatComposerDraftContext = copy(
quotedMessageId = quotedMessageId?.takeIf(String::isNotBlank),
editingMessageId = editingMessageId?.takeIf(String::isNotBlank),
)
}
/**
* Complete restorable state for one composer.
*
* Selection offsets use the same start-inclusive/end-exclusive convention as
* Compose text fields. The store clamps them whenever the text changes so a
* restored selection can never address outside the restored string.
*/
data class ChatComposerDraft(
val text: String = "",
val selectionStart: Int = text.length,
val selectionEnd: Int = selectionStart,
val context: ChatComposerDraftContext = ChatComposerDraftContext(),
val attachments: List<Attachment> = emptyList(),
) {
val isEmpty: Boolean
get() = text.isEmpty() &&
context.quotedMessageId == null &&
context.editingMessageId == null &&
attachments.isEmpty()
internal fun normalized(): ChatComposerDraft {
val normalizedStart = selectionStart.coerceIn(0, text.length)
val normalizedEnd = selectionEnd.coerceIn(0, text.length)
return copy(
selectionStart = minOf(normalizedStart, normalizedEnd),
selectionEnd = maxOf(normalizedStart, normalizedEnd),
context = context.normalized(),
attachments = attachments.toList(),
)
}
}
/**
* Session-owned composer state.
*
* This store is deliberately memory-only: outbound [Attachment.content] can
* contain large Base64 payloads and must not enter Preferences DataStore. Keep
* one instance in the chat owner (normally its ViewModel) so drafts survive
* navigation and Activity recreation. Process death starts with empty drafts;
* a future durable implementation should persist URI grants, not attachment
* bytes.
*/
interface ChatComposerDraftStore {
fun observe(key: ChatComposerDraftKey): Flow<ChatComposerDraft>
fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft
fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft)
fun update(
key: ChatComposerDraftKey,
transform: (ChatComposerDraft) -> ChatComposerDraft,
)
fun remove(key: ChatComposerDraftKey)
fun removeSession(connectionId: String, profileId: String, sessionId: String)
fun clear()
}
class InMemoryChatComposerDraftStore : ChatComposerDraftStore {
private val drafts = MutableStateFlow<Map<ChatComposerDraftKey, ChatComposerDraft>>(emptyMap())
override fun observe(key: ChatComposerDraftKey): Flow<ChatComposerDraft> =
drafts
.map { it[key] ?: ChatComposerDraft() }
.distinctUntilChanged()
override fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft =
drafts.value[key] ?: ChatComposerDraft()
@Synchronized
override fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft) {
val normalized = draft.normalized()
drafts.value = if (normalized.isEmpty) {
drafts.value - key
} else {
drafts.value + (key to normalized)
}
}
@Synchronized
override fun update(
key: ChatComposerDraftKey,
transform: (ChatComposerDraft) -> ChatComposerDraft,
) {
save(key, transform(snapshot(key)))
}
@Synchronized
override fun remove(key: ChatComposerDraftKey) {
drafts.value = drafts.value - key
}
@Synchronized
override fun removeSession(connectionId: String, profileId: String, sessionId: String) {
drafts.value = drafts.value.filterKeys { key ->
key.connectionId != connectionId ||
key.profileId != profileId ||
key.sessionId != sessionId
}
}
@Synchronized
override fun clear() {
drafts.value = emptyMap()
}
}
@@ -0,0 +1,48 @@
package com.hermesandroid.relay.data
import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.map
/** Phone-local behavior for a physical keyboard's unmodified Enter key. */
enum class PhysicalKeyboardEnterBehavior(val storedValue: String) {
SendMessage("send_message"),
InsertNewline("insert_newline"),
;
companion object {
fun fromStoredValue(value: String?): PhysicalKeyboardEnterBehavior =
entries.firstOrNull { it.storedValue == value } ?: SendMessage
}
}
/** Device-level chat input preferences shared by every Hermes profile. */
class ChatInputPreferencesRepository(
private val dataStore: DataStore<Preferences>,
) {
constructor(context: Context) : this(context.relayDataStore)
companion object {
internal val KEY_PHYSICAL_KEYBOARD_ENTER =
stringPreferencesKey("physical_keyboard_enter_behavior")
}
val physicalKeyboardEnterBehavior: Flow<PhysicalKeyboardEnterBehavior> = dataStore.data
.map { preferences ->
PhysicalKeyboardEnterBehavior.fromStoredValue(
preferences[KEY_PHYSICAL_KEYBOARD_ENTER],
)
}
.distinctUntilChanged()
suspend fun setPhysicalKeyboardEnterBehavior(behavior: PhysicalKeyboardEnterBehavior) {
dataStore.edit { preferences ->
preferences[KEY_PHYSICAL_KEYBOARD_ENTER] = behavior.storedValue
}
}
}
@@ -112,12 +112,11 @@ data class ChatMessage(
*/
val clientOnly: Boolean = false,
/**
* Delivery state for a message the user sends into an agent **Thread** over
* the relay proactive channel ([com.hermesandroid.relay.viewmodel.ChatViewModel]
* routes `source=phone` sessions here instead of the normal chat send).
* `SENDING` until the relay acks (`proactive.reply.ack`) → `DELIVERED`;
* `FAILED` on a send error. Null for ordinary chat messages — those render
* no status affix.
* Delivery state for a user-authored message. Agent **Thread** replies use
* `SENDING` until the relay acks (`proactive.reply.ack`) → `DELIVERED`,
* with `FAILED` on a send error. Ordinary chat may additionally use
* `QUEUED` and `STEERED` to make active-turn routing visible. Null keeps the
* legacy behavior of rendering no status affix.
*/
val deliveryStatus: MessageDeliveryStatus? = null,
/**
@@ -142,6 +141,12 @@ data class ChatMessage(
* through `copy`, while [id] remains the authoritative lookup/wire id.
*/
val uiKey: String = id,
/**
* Durable Gateway transcript row identity for rewind/edit-regenerate.
* This is server-owned and can change after a truncating rewrite; it is
* never used as a Compose key or synthesized client-side.
*/
val rowId: Long? = null,
/**
* Mixture-of-Agents advisor responses surfaced during the live turn.
* Unavailable advisors retain only neutral state, never their raw failure
@@ -367,6 +372,8 @@ data class ToolCall(
* header can render without a separate lane registry.
*/
val taskLabel: String? = null,
/** Live upstream child id used by subagent.steer while this lane runs. */
val subagentId: String? = null,
/** Deterministic non-low output risk reported by upstream for this call. */
val outputRisk: String? = null,
/** Human-readable deterministic findings; rendered as untrusted metadata. */
@@ -388,15 +395,17 @@ enum class MessageRole {
}
/**
* Delivery state of a user reply sent into an agent Thread over the relay
* proactive channel. Only set on Thread replies; ordinary chat messages leave
* it null and show no status affix.
* Delivery state of a user-authored message. Thread replies use the relay ack
* lifecycle; ordinary chat can additionally expose queue and steer outcomes.
* Null preserves the legacy behavior of rendering no status affix.
*
* - [SENDING] handed to the relay; awaiting the per-reply ack.
* - [QUEUED] held client-side until the active turn completes.
* - [STEERED] accepted as a correction to the active turn.
* - [DELIVERED] the relay acked (`proactive.reply.ack`) — buffered for the agent.
* - [FAILED] the send errored (e.g. relay disconnected).
*/
enum class MessageDeliveryStatus { SENDING, DELIVERED, FAILED }
enum class MessageDeliveryStatus { SENDING, QUEUED, STEERED, DELIVERED, FAILED }
data class ChatSession(
val sessionId: String,
@@ -418,6 +427,14 @@ data class ChatSession(
/** Durable upstream session metadata, scoped by the owning connection/profile DB. */
val pinned: Boolean = false,
val archived: Boolean = false,
/** Optional newer-upstream workspace context; absent on legacy/API-only hosts. */
val workingDirectory: String? = null,
val gitBranch: String? = null,
val gitRepoRoot: String? = null,
val pullRequestNumber: Int? = null,
val pullRequestUrl: String? = null,
val pullRequestState: String? = null,
val pullRequestDraft: Boolean = false,
) {
val activityTimestamp: Long
get() = firstPositive(lastActivityAt, updatedAt, startedAt)
@@ -0,0 +1,66 @@
package com.hermesandroid.relay.data
import java.nio.charset.StandardCharsets
import java.util.Base64
/** Structured identity and preview for a quoted chat message. */
data class ChatQuoteReference(
val messageId: String,
val authorLabel: String,
val excerpt: String,
)
/** Parsed transport envelope: Android renders [reference] separately from [body]. */
data class ChatQuoteEnvelope(
val reference: ChatQuoteReference,
val body: String,
)
/**
* Serialize a structured quote as ordinary Markdown for unmodified Hermes clients.
* Android parses the same envelope back into a quote chip, while Desktop/TUI see
* a readable linked attribution instead of an Android-only marker.
*/
fun buildChatQuotedPrompt(body: String, reference: ChatQuoteReference?): String {
if (reference == null) return body
val encodedId = Base64.getUrlEncoder().withoutPadding().encodeToString(
reference.messageId.toByteArray(StandardCharsets.UTF_8),
)
val author = reference.authorLabel.normalizedQuoteText(MAX_AUTHOR_CHARS)
val excerpt = reference.excerpt.normalizedQuoteText(MAX_EXCERPT_CHARS)
if (encodedId.isBlank() || author.isBlank() || excerpt.isBlank()) return body
return "> **Replying to [@$author](hermes-message://$encodedId):** $excerpt\n\n$body"
}
/** Parse only the exact bounded envelope emitted by [buildChatQuotedPrompt]. */
fun parseChatQuotedPrompt(content: String): ChatQuoteEnvelope? {
val match = QUOTE_ENVELOPE.matchEntire(content) ?: return null
val author = match.groupValues[1]
val encodedId = match.groupValues[2]
val excerpt = match.groupValues[3]
val body = match.groupValues[4]
val messageId = runCatching {
String(Base64.getUrlDecoder().decode(encodedId), StandardCharsets.UTF_8)
}.getOrNull()?.takeIf { it.isNotBlank() && it.length <= MAX_MESSAGE_ID_CHARS } ?: return null
return ChatQuoteEnvelope(
reference = ChatQuoteReference(messageId, author, excerpt),
body = body,
)
}
private fun String.normalizedQuoteText(maxChars: Int): String =
replace(Regex("[\\p{Cc}\\s]+"), " ")
.replace("\\", "")
.replace("]", "")
.trim()
.take(maxChars)
private val QUOTE_ENVELOPE = Regex(
pattern = "^> \\*\\*Replying to \\[@([^]\\r\\n]{1,$MAX_AUTHOR_CHARS})]" +
"\\(hermes-message://([A-Za-z0-9_-]{1,512})\\):\\*\\* " +
"([^\\r\\n]{1,$MAX_EXCERPT_CHARS})\\n\\n([\\s\\S]*)$",
)
private const val MAX_AUTHOR_CHARS = 40
private const val MAX_EXCERPT_CHARS = 240
private const val MAX_MESSAGE_ID_CHARS = 512
@@ -129,6 +129,7 @@ data class ChatTurnAskCheckpoint(
val requestId: String? = null,
val text: String,
val choices: List<String>? = null,
val multiSelect: Boolean = false,
val smartDenied: Boolean = false,
val envVar: String? = null,
val timeoutSeconds: Int,
@@ -14,6 +14,9 @@ data class DashboardConnectionStatus(
val gatewayTicketAvailable: Boolean? = null,
val message: String? = null,
val gatewayMode: String? = null,
/** Profiles positively advertised by the live multiplex gateway. */
val servedProfiles: List<String> = emptyList(),
/** Installed profiles reported by the dashboard; never routing authority. */
val profiles: List<String> = emptyList(),
)
@@ -63,12 +63,8 @@ fun EndpointCandidate?.isEncryptedOverlayRoute(isTailscaleDetected: Boolean): Bo
val hint = security.orEmpty().lowercase()
return r == "tailscale" ||
(isTailscaleDetected && hint.contains("tailscale")) ||
r == "plugin_proxy" ||
r == "plugin-proxy" ||
hasSecureProxy() ||
hint.contains("wireguard") ||
hint.contains("https") ||
hint.contains("tls")
(!hasSecureProxy() && (hint.contains("https") || hint.contains("tls")))
}
/** Human label for the overlay mechanism encrypting a route. */
@@ -78,7 +74,6 @@ fun EndpointCandidate?.overlayMechanism(isTailscaleDetected: Boolean): String {
val hint = security.orEmpty().lowercase()
return when {
r == "tailscale" || (isTailscaleDetected && hint.contains("tailscale")) -> "Tailscale"
r == "plugin_proxy" || r == "plugin-proxy" || hasSecureProxy() -> "Proxy"
hint.contains("wireguard") -> "WireGuard"
hint.contains("https") || hint.contains("tls") -> "TLS"
else -> "Encrypted"
@@ -92,7 +87,10 @@ fun classifySurfaceSecurity(
activeEndpoint: EndpointCandidate?,
isTailscaleDetected: Boolean,
): SurfaceSecurity {
val secureLinkProtected = activeEndpoint.secureLinkProtects(label, url)
val (kind, mechanism) = when {
secureLinkProtected -> SurfaceSecurityKind.Tls to
if (activeEndpoint?.hasHermesReach() == true) "Hermes Reach" else "Hermes Secure Link"
isTlsUrl(url) -> SurfaceSecurityKind.Tls to "TLS"
activeEndpoint.isEncryptedOverlayRoute(isTailscaleDetected) ->
SurfaceSecurityKind.Overlay to activeEndpoint.overlayMechanism(isTailscaleDetected)
@@ -101,6 +99,33 @@ fun classifySurfaceSecurity(
return SurfaceSecurity(label = label, kind = kind, mechanism = mechanism, url = url)
}
private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): Boolean {
val candidate = this ?: return false
val routes = candidate.proxy?.takeIf { candidate.hasSecureProxy() }
?.let { proxy ->
val base = proxy.url.trim().trimEnd('/')
Triple(
"$base/dashboard",
"$base/api",
"wss://${base.substringAfter("://")}/relay/ws",
)
} ?: return false
val normalized = url.trim().trimEnd('/')
val service = when (label) {
"Chat & Manage" -> "dashboard"
"API / sessions" -> "api"
"Relay tools" -> "relay"
else -> return false
}
if (service !in candidate.secureLinkServices()) return false
val expected = when (service) {
"dashboard" -> routes.first
"api" -> routes.second
else -> routes.third
}
return normalized.equals(expected, ignoreCase = true)
}
/**
* Roll up the per-surface verdicts into one connection-level [ConnectionSecurity].
* Pure + side-effect free so it is unit-testable without Android.
@@ -45,8 +45,13 @@ data class EndpointCandidate(
val relay: RelayEndpoint? = null,
val dashboard: DashboardEndpoint? = null,
val proxy: ProxyEndpoint? = null,
/** Optional outbound rendezvous carrying the pinned [proxy] byte stream. */
val broker: BrokerEndpoint? = null,
val security: String? = null,
val recommended: Boolean = false,
val experimental: Boolean = false,
@SerialName("display_name")
val displayName: String? = null,
)
/**
@@ -110,6 +115,27 @@ data class ProxyEndpoint(
val transportHint: String? = null,
@SerialName("pin_sha256")
val pinSha256: String? = null,
/** Independently authenticated services carried by this pinned origin. */
val surfaces: List<String> = listOf("relay"),
)
/**
* Hermes Reach rendezvous metadata from an operator-reviewed pairing payload.
* The token authenticates only this broker route; Hermes service credentials
* remain inside the QR-pinned Secure Link TLS connection.
*/
@Serializable
data class BrokerEndpoint(
val url: String,
@SerialName("protocol_version")
val protocolVersion: Int = 1,
@SerialName("host_id")
val hostId: String,
@SerialName("credential_kind")
val credentialKind: String,
val token: String,
@SerialName("expires_at")
val expiresAt: Long? = null,
)
/**
@@ -123,7 +149,7 @@ data class ProxyEndpoint(
*/
fun EndpointCandidate.isKnownRole(): Boolean {
return when (role.lowercase()) {
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "https" -> true
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "outbound_broker", "https" -> true
else -> false
}
}
@@ -146,7 +172,8 @@ fun EndpointCandidate.displayLabel(): String {
"Public"
}
"https" -> "HTTPS"
"plugin_proxy", "plugin-proxy" -> "Plugin proxy"
"plugin_proxy", "plugin-proxy" -> "Hermes Secure Link"
"outbound_broker", "broker", "relay_broker" -> "Hermes Reach · Experimental"
else -> "Custom VPN ($role)"
}
}
@@ -177,7 +204,69 @@ fun EndpointCandidate.routeAuthority(): String? {
}
fun EndpointCandidate.hasSecureProxy(): Boolean =
proxy?.url?.startsWith("https://", ignoreCase = true) == true ||
proxy?.url?.startsWith("wss://", ignoreCase = true) == true ||
role.equals("plugin_proxy", ignoreCase = true) ||
role.equals("plugin-proxy", ignoreCase = true)
proxy?.isValidPinnedProxy() == true
/** Product-facing service inventory; wire identifiers remain unchanged. */
fun EndpointCandidate.secureLinkServices(): List<String> =
if (!hasSecureProxy()) emptyList() else proxy.orEmptySurfaces()
fun EndpointCandidate.secureLinkCoversAllServices(): Boolean =
secureLinkServices().containsAll(listOf("relay", "api", "dashboard"))
fun EndpointCandidate.presentationRouteUrl(): String? =
broker?.url?.takeIf { hasHermesReach() } ?: proxy?.url?.takeIf { hasSecureProxy() } ?: primaryRouteUrl()
fun EndpointCandidate.hasHermesReach(): Boolean =
role.lowercase() in setOf("outbound_broker", "broker", "relay_broker") &&
broker?.isValidHermesReach() == true && hasSecureProxy()
fun BrokerEndpoint.isValidHermesReach(): Boolean {
if (protocolVersion != 1 || !hostId.isCanonicalBase64Url(16) || !token.isCanonicalBase64Url(32)) return false
if (credentialKind !in setOf("bootstrap", "route")) return false
if (credentialKind == "bootstrap" && expiresAt?.let { it <= System.currentTimeMillis() / 1000L } == true) return false
val uri = runCatching { URI(url.trim()) }.getOrNull() ?: return false
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
return uri.rawPath.orEmpty().let { it.isEmpty() || it == "/" || it == "/v1/connect" }
}
private fun String.isCanonicalBase64Url(byteCount: Int): Boolean {
if (isBlank() || '=' in this) return false
val decoded = runCatching { java.util.Base64.getUrlDecoder().decode(this) }.getOrNull() ?: return false
return decoded.size == byteCount &&
java.util.Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == this
}
/** Exact host locator + broker authority replacement; never crosses devices. */
internal fun replaceHermesReachCredential(
source: List<EndpointCandidate>,
expected: BrokerEndpoint,
replacement: EndpointCandidate,
): List<EndpointCandidate> = source.map { candidate ->
if (candidate.broker?.hostId == expected.hostId &&
sameBrokerAuthority(candidate.broker.url, expected.url)
) replacement else candidate
}
internal fun sameBrokerAuthority(left: String, right: String): Boolean = runCatching {
val a = URI(left.trim())
val b = URI(right.trim())
fun port(uri: URI) = if (uri.port > 0) uri.port else 443
a.scheme.equals("wss", true) && b.scheme.equals("wss", true) &&
a.host.equals(b.host, true) && port(a) == port(b) &&
a.rawPath.orEmpty().trimEnd('/') == b.rawPath.orEmpty().trimEnd('/')
}.getOrDefault(false)
private fun ProxyEndpoint?.orEmptySurfaces(): List<String> = this?.surfaces.orEmpty()
.map { it.trim().lowercase() }
.filter { it in setOf("relay", "api", "dashboard") }
.distinct()
fun ProxyEndpoint.isValidPinnedProxy(): Boolean {
val uri = runCatching { URI(url.trim().trimEnd('/')) }.getOrNull() ?: return false
if (!uri.scheme.equals("https", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" }) return false
val pin = pinSha256?.trim()?.removePrefix("sha256/") ?: return false
return runCatching { java.util.Base64.getDecoder().decode(pin).size == 32 }.getOrDefault(false)
}
@@ -2,6 +2,8 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
/**
* A rich content card emitted inline in an assistant message via the
@@ -117,6 +119,8 @@ data class HermesCardInput(
val kind: String,
/** Quick-answer chips (clarify). Empty = no chip row. */
val choices: List<String> = emptyList(),
/** Choices toggle independently and require an explicit submit. */
val multiSelect: Boolean = false,
/** Render the inline free-text mini field under the chips. */
val allowFreeText: Boolean = false,
/** Password-style field: masked glyphs + reveal toggle (secret/sudo). */
@@ -124,7 +128,7 @@ data class HermesCardInput(
/** Submit is a 650ms hold-to-confirm press-fill instead of a tap (sudo). */
val holdToConfirm: Boolean = false,
/**
* Wall-clock expiry for timed asks (sudo 120s, clarify/secret 300s).
* Wall-clock expiry for asks with an advertised deadline.
* The renderer shows a countdown footer (Amber under 30s) and
* self-collapses to "Expired — not granted" past it. Null = no timeout
* (approval is session-scoped).
@@ -155,6 +159,10 @@ data class HermesCardInput(
}
}
/** Exact JSON-array wire value expected by upstream multi-select clarify. */
internal fun encodeClarifyMultiSelectAnswer(values: List<String>): String =
Json.encodeToString(values.map(String::trim).filter(String::isNotEmpty).distinct())
/**
* A label/value row inside a card. [value] is rendered as markdown so the
* agent can embed emphasis, inline code, or links.
@@ -34,6 +34,8 @@ data class ProactiveInboxEntry(
* field).
*/
val chatId: String? = null,
/** Owning saved connection. Null only for entries written by older builds. */
val connectionId: String? = null,
)
private val Context.proactiveInboxStore: DataStore<Preferences> by
@@ -49,10 +51,10 @@ private const val MAX_ENTRIES = 100
* newest-first, deduped by id (so a re-delivered message doesn't double up), and
* capped at [MAX_ENTRIES]. Survives app restart.
*
* Demoted (2026-06-29): the agent conversation now lives as a Thread in Chat (the
* gateway session is the durable history), so the in-app inbox view is retired.
* This store is only fed for messages NOT shown in an open Thread; it currently
* has no viewer and is fully retireable — see TODO.
* Demoted (2026-06-29): once a phone gateway session exists, it is the durable
* history. Outbound agent messages arrive before that session exists, so this
* bounded store also backs the provisional Thread until the user's first reply
* promotes it to a real `source=phone` session.
*/
class ProactiveInboxRepository(private val context: Context) {
@@ -136,3 +136,91 @@ data class ProfileMemoryUpdateResponse(
@SerialName("bytes_written")
val bytesWritten: Long,
)
/** Authoritative upstream `profiles.describe` snapshot. */
data class GatewayProfileDescription(
val name: String,
val description: String,
val soul: String,
val provider: String,
val model: String,
val skills: List<GatewayProfileSkill>,
val toolsets: List<GatewayProfileToolset>,
val toolsetsPinned: Boolean,
)
data class GatewayProfileSkill(val name: String, val enabled: Boolean)
data class GatewayProfileToolset(
val name: String,
val description: String,
val toolCount: Int,
val enabled: Boolean,
)
enum class GatewayProfileSection(val wireName: String) {
Description("description"),
Soul("soul"),
Model("model"),
Skills("skills"),
Toolsets("toolsets"),
}
/** Null leaves a section unchanged; empty lists retain upstream replace semantics. */
data class GatewayProfilePatch(
val description: String? = null,
val soul: String? = null,
val provider: String? = null,
val model: String? = null,
val disabledSkills: List<String>? = null,
val enabledToolsets: List<String>? = null,
) {
val requestedSections: Set<GatewayProfileSection>
get() = buildSet {
if (description != null) add(GatewayProfileSection.Description)
if (soul != null) add(GatewayProfileSection.Soul)
if (provider != null && model != null) add(GatewayProfileSection.Model)
if (disabledSkills != null) add(GatewayProfileSection.Skills)
if (enabledToolsets != null) add(GatewayProfileSection.Toolsets)
}
}
data class GatewayProfileConfigureResult(
val requested: Set<GatewayProfileSection>,
val applied: Set<GatewayProfileSection>,
) {
val failed: Set<GatewayProfileSection> get() = requested - applied
}
interface GatewayProfileEditorClient {
suspend fun describeProfile(profileName: String): Result<GatewayProfileDescription>
suspend fun configureProfile(
profileName: String,
patch: GatewayProfilePatch,
): Result<GatewayProfileConfigureResult>
}
class GatewayProfileEditorUnsupportedException : Exception(
"Profile editing is not supported by this gateway",
)
/** Relay fallback retained for older gateways and Relay-only memory files. */
interface LegacyProfileInspectorClient {
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse>
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse>
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse>
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse>
suspend fun updateSoul(profileName: String, content: String): Result<ProfileSoulUpdateResponse>
suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
): Result<ProfileMemoryUpdateResponse>
suspend fun updateSkillToggle(skillName: String, enabled: Boolean): Result<RelaySkillToggleResult>
suspend fun probeSkillToggleSupported(): Boolean
}
sealed interface RelaySkillToggleResult {
data object Ok : RelaySkillToggleResult
data object NotImplemented : RelaySkillToggleResult
}
@@ -26,7 +26,6 @@ object ProfilePresentationPolicy {
fun availableKeys(profiles: List<Profile>): List<String> = buildList {
add(AgentDisplay.SERVER_DEFAULT_PROFILE_KEY)
profiles.asSequence()
.filterNot { AgentDisplay.isServerDefaultAlias(it.name) }
.map(Profile::name)
.distinct()
.forEach(::add)
@@ -49,6 +48,12 @@ object ProfilePresentationPolicy {
): List<String> = orderedKeys(profiles, presentation).filter { key ->
key == selectedKey || key !in presentation.hidden
}
fun shouldShowShelf(
profiles: List<Profile>,
presentation: ProfilePresentation,
selectedKey: String,
): Boolean = visibleKeys(profiles, presentation, selectedKey).size > 1
}
class ProfilePresentationStore(
@@ -12,6 +12,7 @@ import com.hermesandroid.relay.auth.CertPinStore
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
import com.hermesandroid.relay.diagnostics.DiagnosticCategory
import com.hermesandroid.relay.diagnostics.DiagnosticSeverity
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
@@ -19,6 +20,7 @@ import com.hermesandroid.relay.diagnostics.NetworkDiagnosticGuidance
import com.hermesandroid.relay.network.relay.models.Envelope
import com.hermesandroid.relay.network.shared.EndpointResolver
import com.hermesandroid.relay.network.shared.EndpointSurface
import com.hermesandroid.relay.network.shared.fullJitterDelayMs
import com.hermesandroid.relay.network.shutdownOffMainThread
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
@@ -76,6 +78,9 @@ internal fun buildRelayRequestOrNull(url: String): Request? =
null
}
private fun EndpointCandidate.relayWebSocketUrl(): String? =
pluginProxyRoutesOrNull()?.relayWebSocketUrl ?: relay?.url
class ConnectionManager(
private val multiplexer: ChannelMultiplexer,
/**
@@ -139,6 +144,10 @@ class ConnectionManager(
* non-null — the manager falls back to the single-URL path.
*/
private val deviceIdProvider: (suspend () -> String?)? = null,
/** Random source for ordinary reconnect full-jitter; exact backoffs never use it. */
private val reconnectJitterUnit: () -> Double = { kotlin.random.Random.nextDouble() },
/** Exact-authority pinned client for a plugin-proxy WSS URL. */
private val proxyClientProvider: ((String) -> OkHttpClient?)? = null,
) {
private val supervisorJob = SupervisorJob()
private val scope = CoroutineScope(supervisorJob + Dispatchers.IO)
@@ -148,7 +157,7 @@ class ConnectionManager(
encodeDefaults = true
}
private fun buildClient(): OkHttpClient {
private fun buildClient(url: String? = null): OkHttpClient {
val builder = OkHttpClient.Builder()
// OkHttp's 10s default connectTimeout is LAN-tuned; a Tailscale
// DERP-relayed cold-start handshake can exceed it, and a failed
@@ -162,7 +171,9 @@ class ConnectionManager(
// that wipes a pin would still be subject to the pre-wipe rules.
certPinStore?.let { store ->
try {
builder.certificatePinner(store.buildPinnerSnapshot())
builder.certificatePinner(
url?.let(store::buildPinnerSnapshotFor) ?: store.buildPinnerSnapshot(),
)
} catch (e: Exception) {
Log.w(TAG, "CertificatePinner build failed: ${e.message}")
builder.certificatePinner(CertificatePinner.DEFAULT)
@@ -221,10 +232,12 @@ class ConnectionManager(
// Endpoints card in Settings.
private val _activeEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeEndpoint: StateFlow<EndpointCandidate?> = _activeEndpoint.asStateFlow()
private val _activeApiEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeApiEndpoint: StateFlow<EndpointCandidate?> = _activeApiEndpoint.asStateFlow()
/** Relay-only winner, deliberately separate from the standard route. */
@Volatile
private var activeRelayEndpoint: EndpointCandidate? = null
private val _activeRelayEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeRelayEndpoint: StateFlow<EndpointCandidate?> = _activeRelayEndpoint.asStateFlow()
/**
* Manual role override. When non-null, the resolver's output is replaced
@@ -345,11 +358,14 @@ class ConnectionManager(
// behavior for freshly-upgraded installs and for v1/v2 QRs where
// the synthesized list just collapses to the same URL anyway.
scope.launch {
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val resolvedRelayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
val resolvedRelayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
val targetUrl = resolvedRelayUrl ?: url.takeIf { it.isNotBlank() }
activeRelayEndpoint = relayResolved
_activeRelayEndpoint.value = relayResolved
_activeApiEndpoint.value = apiResolved
if (resolved != null) {
_activeEndpoint.value = resolved
Log.i(TAG, "connect: standard resolver picked role=${resolved.role} " +
@@ -376,7 +392,7 @@ class ConnectionManager(
Log.i(
TAG,
"connect: relay resolver picked role=${relayRoute.role} " +
"url=${relayRoute.relay?.url}",
"url=${relayRoute.relayWebSocketUrl()}",
)
}
if (targetUrl != null) {
@@ -531,7 +547,8 @@ class ConnectionManager(
* for any reason we don't block the connect loop forever.
*/
suspend fun resolveBestEndpoint(): EndpointCandidate? =
resolveBestEndpointSafe(EndpointSurface.Standard)
resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
private suspend fun resolveBestEndpointSafe(
surface: EndpointSurface,
@@ -609,7 +626,9 @@ class ConnectionManager(
suspend fun probeAndReconnectNow(): EndpointCandidate? {
endpointResolver?.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
@@ -618,8 +637,9 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
if (relayResolved != null) activeRelayEndpoint = relayResolved
val targetUrl = relayResolved?.relay?.url ?: current ?: return resolved
_activeApiEndpoint.value = apiResolved
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val targetUrl = relayResolved?.relayWebSocketUrl() ?: current ?: return resolved
val normalizedTarget = normalizeRelayUrl(targetUrl)
// Reconnect when the winner changed, and also when the socket is
// stale/disconnected on the same winner. The latter makes the
@@ -656,7 +676,9 @@ class ConnectionManager(
*/
suspend fun refreshActiveEndpoint(clearProbeCache: Boolean = false): EndpointCandidate? {
if (clearProbeCache) endpointResolver?.clearCache()
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
// (slow resume, mid-handoff blip) — keep publishing the live
@@ -665,6 +687,7 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
return resolved
}
@@ -681,7 +704,7 @@ class ConnectionManager(
fun getManualRoleOverride(): String? = _manualRoleOverride.value
private fun markActiveRelayEndpointUnreachable(reason: String) {
val active = activeRelayEndpoint ?: return
val active = _activeRelayEndpoint.value ?: return
endpointResolver?.markUnreachable(active, EndpointSurface.Relay)
Log.i(TAG, "marked endpoint role=${active.role} unreachable ($reason)")
}
@@ -707,7 +730,9 @@ class ConnectionManager(
// manages its own cache (clear + markUnreachable) and passes false.
if (wipeCache) endpointResolver.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null) {
// Hysteresis for the AUTOMATIC (network-callback) path. A
// transient cold-route probe miss must NOT null the published
@@ -744,6 +769,7 @@ class ConnectionManager(
}
sustainedLossDeclared = false
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
if (current == null) return@launch
// After an explicit disconnect() the route still publishes above
// (HTTP surfaces keep roaming), but no socket action: without
@@ -753,8 +779,8 @@ class ConnectionManager(
// the swap path never re-checked it.)
if (!shouldReconnect) return@launch
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (relayResolved != null) activeRelayEndpoint = relayResolved
val relayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val relayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
?: return@launch
if (isRelayRateLimitBackoffActive(
rateLimitBackoffUntilMs,
@@ -899,7 +925,8 @@ class ConnectionManager(
// the ViewModel on the next connection load.
_manualRoleOverride.value = null
_activeEndpoint.value = null
activeRelayEndpoint = null
_activeApiEndpoint.value = null
_activeRelayEndpoint.value = null
reconnectState.reset()
}
@@ -979,7 +1006,18 @@ class ConnectionManager(
// Every new socket starts unauthenticated — the send-gate stays closed
// (auth frame excepted) until this socket's own auth.ok arrives.
authenticated = false
client = buildClient()
val isPluginProxyUrl = _activeRelayEndpoint.value?.pluginProxyRoutesOrNull()
?.relayWebSocketUrl
?.equals(url, ignoreCase = true) == true
client = if (isPluginProxyUrl) {
proxyClientProvider?.invoke(url) ?: run {
Log.e(TAG, "Pinned plugin proxy client unavailable — refusing generic TLS fallback")
_connectionState.value = ConnectionState.Disconnected
return
}
} else {
buildClient(url)
}
val request = buildRelayRequestOrNull(url)
if (request == null) {
@@ -1213,8 +1251,9 @@ class ConnectionManager(
SLOW_POLL_BACKOFF_MS
}
else -> {
val ms = (BASE_BACKOFF_MS * (1L shl minOf(reconnectAttempt - 1, 4)))
val capMs = (BASE_BACKOFF_MS * (1L shl minOf(reconnectAttempt - 1, 4)))
.coerceAtMost(MAX_BACKOFF_MS)
val ms = fullJitterDelayMs(capMs, reconnectJitterUnit())
DiagnosticsLog.record(
category = DiagnosticCategory.Relay,
severity = DiagnosticSeverity.Info,
@@ -1236,7 +1275,7 @@ class ConnectionManager(
// during the retry window).
if (shouldReconnect && reconnectGate()) {
val resolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val targetUrl = resolved?.relay?.url
val targetUrl = resolved?.relayWebSocketUrl()
if (resolved != null) {
// Mirror scheduleNetworkReResolve: clear the sustained-loss
// latch on a successful resolve so a later transient miss
@@ -1244,7 +1283,7 @@ class ConnectionManager(
// in onLost's grace job but can be cleared on EITHER success
// edge — network-callback or relay-timer.)
sustainedLossDeclared = false
activeRelayEndpoint = resolved
_activeRelayEndpoint.value = resolved
}
if (targetUrl != null && normalizeRelayUrl(targetUrl) != url) {
Log.i(TAG, "scheduleReconnect: switching $url → ${normalizeRelayUrl(targetUrl)}")
@@ -61,8 +61,8 @@ class ProactiveMessageHandler(
/**
* Show an inbound message inline in the Chat **Thread** it belongs to, when
* that Thread is currently open. Returns true if it was shown there — in
* which case the message is NOT also notified or added to the inbox (you're
* already looking at the conversation). The unified-Threads counterpart of
* which case the message is persisted but not also notified (you're already
* looking at the conversation). The unified-Threads counterpart of
* [toSession]; wired after construction.
*/
var injectIntoThread: ((ProactiveMessage) -> Boolean)? = null,
@@ -94,13 +94,15 @@ class ProactiveMessageHandler(
/** Route a parsed message: into the open Thread if it belongs there, else
* the durable inbox log + the surface its hint selects. */
private fun dispatch(msg: ProactiveMessage) {
// Unified Threads: if this message belongs to the Thread currently open
// in Chat, render it inline there and STOP — no notification, no inbox
// entry (you're already looking at the conversation).
if (injectIntoThread?.invoke(msg) == true) return
// Otherwise the inbox is the durable log of agent-initiated messages and
// the surfacing hint selects the additional surface.
// Persist first even when the currently open Thread consumes the live
// message. Agent-initiated outbound sends do not create a gateway
// session until the phone replies, so this cache is the provisional
// Thread transcript during that gap.
toInbox?.invoke(msg)
// Unified Threads: if this message belongs to the Thread currently open
// in Chat, render it inline there and stop before raising a notification.
if (injectIntoThread?.invoke(msg) == true) return
// The surfacing hint selects the additional surface.
when (msg.surfacing?.lowercase()) {
"inbox" -> { /* inbox only — already recorded above */ }
"session" -> {
@@ -7,6 +7,8 @@ import com.hermesandroid.relay.data.ProfileSkillsResponse
import com.hermesandroid.relay.data.ProfileSoulResponse
import com.hermesandroid.relay.data.ProfileSoulUpdateResponse
import com.hermesandroid.relay.data.ProfileMemoryUpdateResponse
import com.hermesandroid.relay.data.LegacyProfileInspectorClient
import com.hermesandroid.relay.data.RelaySkillToggleResult
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import kotlinx.serialization.SerializationException
@@ -48,7 +50,7 @@ class RelayProfileInspectorClient(
private val okHttpClient: OkHttpClient,
private val relayUrlProvider: () -> String?,
private val sessionTokenProvider: suspend () -> String?,
) {
) : LegacyProfileInspectorClient {
companion object {
private const val TAG = "RelayProfileInspector"
@@ -79,19 +81,19 @@ class RelayProfileInspectorClient(
/** Fetch `GET /api/profiles/{name}/config`. */
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
override suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
get(profileName, "config", ProfileConfigResponse.serializer())
/** Fetch `GET /api/profiles/{name}/skills`. */
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
override suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
get(profileName, "skills", ProfileSkillsResponse.serializer())
/** Fetch `GET /api/profiles/{name}/soul`. */
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
override suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
get(profileName, "soul", ProfileSoulResponse.serializer())
/** Fetch `GET /api/profiles/{name}/memory`. */
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
override suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
get(profileName, "memory", ProfileMemoryResponse.serializer())
/**
@@ -108,7 +110,7 @@ class RelayProfileInspectorClient(
* would be a protocol violation; we send empty-string for an empty
* SOUL.
*/
suspend fun updateSoul(
override suspend fun updateSoul(
profileName: String,
content: String,
): Result<ProfileSoulUpdateResponse> = withContext(Dispatchers.IO) {
@@ -137,7 +139,7 @@ class RelayProfileInspectorClient(
* Used for both creating a new memory entry (the relay writes the
* file if missing) and updating an existing entry.
*/
suspend fun updateMemoryEntry(
override suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
@@ -270,10 +272,10 @@ class RelayProfileInspectorClient(
* server" snackbar and ghost out the toggle. When the real
* implementation lands server-side, this method needs no change.
*/
suspend fun updateSkillToggle(
override suspend fun updateSkillToggle(
skillName: String,
enabled: Boolean,
): Result<SkillToggleResult> = withContext(Dispatchers.IO) {
): Result<RelaySkillToggleResult> = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) {
return@withContext Result.failure(
@@ -319,8 +321,8 @@ class RelayProfileInspectorClient(
try {
okHttpClient.newCall(request).execute().use { response ->
when (response.code) {
in 200..299 -> Result.success(SkillToggleResult.Ok)
501 -> Result.success(SkillToggleResult.NotImplemented)
in 200..299 -> Result.success(RelaySkillToggleResult.Ok)
501 -> Result.success(RelaySkillToggleResult.NotImplemented)
401, 403 -> Result.failure(
IOException("Unauthorized — re-pair with the relay")
)
@@ -348,7 +350,7 @@ class RelayProfileInspectorClient(
* "not implemented" and any 2xx as "supported". The relay serves
* OPTIONS via aiohttp's CORS handling by default.
*/
suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
override suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) return@withContext false
val sessionToken = sessionTokenProvider() ?: return@withContext false
@@ -402,11 +404,6 @@ class RelayProfileInspectorClient(
* answered 501 — not implemented yet" without inventing magic
* error strings.
*/
sealed class SkillToggleResult {
data object Ok : SkillToggleResult()
data object NotImplemented : SkillToggleResult()
}
/**
* Best-effort pull of a `detail` or `error` string out of a relay
* 400 body. Falls back to the first 120 chars of the payload when
@@ -55,6 +55,8 @@ data class RouteProbeOutcome(
*/
enum class EndpointSurface {
Standard,
Dashboard,
Api,
Relay,
}
@@ -109,6 +111,8 @@ class EndpointResolver(
* expected path for plain JVM tests.
*/
private val context: Context? = null,
/** Route-aware client for pinned plugin proxy probes. */
private val clientForCandidate: ((EndpointCandidate) -> OkHttpClient?)? = null,
) {
/**
@@ -196,8 +200,13 @@ class EndpointResolver(
val authority = when (surface) {
EndpointSurface.Standard ->
candidate.routeAuthority() ?: candidate.primaryRouteUrl().orEmpty().lowercase()
EndpointSurface.Dashboard ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl ?: candidate.dashboard?.url).orEmpty()
EndpointSurface.Api ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.apiBaseUrl ?: candidate.api?.url).orEmpty()
EndpointSurface.Relay ->
routeAuthority(candidate.relay?.url).orEmpty()
candidate.pluginProxyRoutesOrNull()?.authority
?: routeAuthority(candidate.relay?.url).orEmpty()
}
return "${surface.name.lowercase()}|${candidate.role}|$authority"
}
@@ -239,11 +248,16 @@ class EndpointResolver(
val eligible = candidates.filter { probeTarget(it, surface) != null }
if (eligible.isEmpty()) return null
// Strict priority: sort ascending so priority-0 lands first. Grouping
// preserves emitted order within a priority class (DNS SRV parity).
val groups = eligible.groupBy { it.priority }.toSortedMap()
// Supported routes always run before experimental routes. Priority is
// strict inside each stability tier, so Reach remains available as a
// last-resort fallback without displacing Tailscale or direct TLS.
val supported = eligible.filterNot { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val experimental = eligible.filter { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val groups = (supported.groupBy { it.priority }.toSortedMap().values +
experimental.groupBy { it.priority }.toSortedMap().values)
for ((priority, group) in groups) {
for (group in groups) {
val priority = group.first().priority
Log.d(TAG, "probing priority=$priority group (size=${group.size})")
val winner = raceGroup(group, surface)
if (winner != null) {
@@ -356,6 +370,8 @@ class EndpointResolver(
val startedAtMs = clock()
val operation = when (surface) {
EndpointSurface.Standard -> "Dashboard or API route health probe"
EndpointSurface.Dashboard -> "Dashboard route health probe"
EndpointSurface.Api -> "API route health probe"
EndpointSurface.Relay -> "Relay route health probe"
}
val target = probeTarget(candidate, surface)
@@ -375,7 +391,7 @@ class EndpointResolver(
recordOutcome(candidate, surface, reachable = false, detail = "Invalid route URL")
return false
}
val fastClient = httpClient.newBuilder()
val fastClient = (clientForCandidate?.invoke(candidate) ?: httpClient).newBuilder()
.connectTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.readTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.writeTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
@@ -480,6 +496,29 @@ class EndpointResolver(
candidate: EndpointCandidate,
surface: EndpointSurface,
): ProbeTarget? {
if (surface == EndpointSurface.Dashboard) {
candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl?.let { base ->
return ProbeTarget(base, "$base/api/status", "/dashboard/api/status")
}
candidate.dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }?.let { base ->
return ProbeTarget(base, "$base/api/status", "/api/status")
}
return null
}
if (surface == EndpointSurface.Api) {
candidate.pluginProxyRoutesOrNull()?.apiBaseUrl?.let { base ->
return ProbeTarget(base, "$base/health", "/api/health")
}
candidate.api?.url?.let { base -> return ProbeTarget(base, "$base/health", "/health") }
return null
}
if (surface == EndpointSurface.Relay) candidate.pluginProxyRoutesOrNull()?.let { proxy ->
return ProbeTarget(
baseUrl = proxy.relayHttpUrl,
requestUrl = "${proxy.relayHttpUrl}/health",
path = "/relay/health",
)
}
if (surface == EndpointSurface.Relay) {
return relayProbeTarget(candidate)
}
@@ -529,6 +568,11 @@ class EndpointResolver(
return null
}
internal fun probeRequestUrlForTest(
candidate: EndpointCandidate,
surface: EndpointSurface,
): String? = probeTarget(candidate, surface)?.requestUrl
/**
* Map a probe exception to a short, actionable string for the Routes
* card. The TLS case is the headline: a route saved with `https://`
@@ -546,6 +590,8 @@ class EndpointResolver(
private fun EndpointSurface.diagnosticTarget(): String = when (this) {
EndpointSurface.Standard -> "Dashboard or API server"
EndpointSurface.Dashboard -> "Dashboard"
EndpointSurface.Api -> "API server"
EndpointSurface.Relay -> "Relay"
}
@@ -0,0 +1,402 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.isValidHermesReach
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.Response
import okhttp3.WebSocket
import okhttp3.WebSocketListener
import okio.ByteString
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.InetAddress
import java.net.InetSocketAddress
import java.net.Socket
import java.net.SocketAddress
import java.net.SocketException
import java.net.URI
import java.security.SecureRandom
import java.util.Base64
import java.util.ArrayDeque
import java.util.concurrent.CountDownLatch
import java.util.concurrent.TimeUnit
import javax.net.SocketFactory
private const val REACH_PROTOCOL_VERSION = 1
private const val REACH_MAX_FRAME_BYTES = 1024 * 1024
internal const val REACH_MAX_QUEUED_FRAMES = 32
internal const val REACH_MAX_QUEUED_BYTES = 8 * 1024 * 1024
private const val REACH_MATCH_TIMEOUT_MS = 10_000L
/**
* Connection metadata for Hermes Reach's outer WSS rendezvous.
*
* This is deliberately transport-only. The inner HTTPS/WSS origin and its
* pairing-authenticated SPKI pin continue to be owned by [PluginProxyRoutes],
* so broker reachability can never weaken Secure Link trust.
*/
data class HermesReachRoute(
val brokerUrl: String,
val hostId: String,
val credentialKind: String,
val token: String,
) {
fun tunnelUrlOrNull(): String? {
if (hostId.isBlank() || token.isBlank()) return null
if (credentialKind !in setOf("bootstrap", "route")) return null
val uri = runCatching { URI(brokerUrl.trim()) }.getOrNull() ?: return null
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" && it != "/v1/connect" }) return null
val authority = buildString {
append(if (':' in uri.host) "[${uri.host}]" else uri.host)
if (uri.port > 0 && uri.port != 443) append(":${uri.port}")
}
return "wss://$authority/v1/connect"
}
}
fun EndpointCandidate.hermesReachRouteOrNull(): HermesReachRoute? {
val metadata = broker?.takeIf { it.isValidHermesReach() } ?: return null
if (pluginProxyRoutesOrNull() == null) return null
return HermesReachRoute(
brokerUrl = metadata.url,
hostId = metadata.hostId,
credentialKind = metadata.credentialKind,
token = metadata.token,
)
}
/** Build the pinned inner Secure Link client over an outer Hermes Reach WSS. */
fun buildHermesReachClient(
baseBuilder: OkHttpClient.Builder,
outerClient: OkHttpClient,
candidate: EndpointCandidate,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
): OkHttpClient? {
val secureLink = candidate.pluginProxyRoutesOrNull() ?: return null
val reach = candidate.hermesReachRouteOrNull() ?: return null
return buildPluginProxyClient(
baseBuilder = baseBuilder,
routes = secureLink,
sessionTokenProvider = sessionTokenProvider,
includeRelaySessionHeader = includeRelaySessionHeader,
rawSocketFactory = HermesReachSocketFactory(outerClient, reach),
)
}
@Serializable
private data class ReachRegistration(
val type: String = "register",
@SerialName("protocol_version") val protocolVersion: Int = REACH_PROTOCOL_VERSION,
val role: String = "client",
@SerialName("host_id") val hostId: String,
@SerialName("connection_id") val connectionId: String,
@SerialName("credential_kind") val credentialKind: String,
val token: String,
)
@Serializable
private data class ReachControl(
val type: String? = null,
@SerialName("protocol_version") val protocolVersion: Int? = null,
@SerialName("stream_id") val streamId: String? = null,
val code: String? = null,
)
internal object HermesReachHandshake {
private val json = Json {
ignoreUnknownKeys = false
encodeDefaults = true
}
fun registration(route: HermesReachRoute, connectionId: String): String = json.encodeToString(
ReachRegistration(
hostId = route.hostId,
connectionId = connectionId,
credentialKind = route.credentialKind,
token = route.token,
),
)
fun validateMatched(payload: String): String? {
val control = runCatching { json.decodeFromString<ReachControl>(payload) }
.getOrElse { return "Hermes Reach returned an invalid match response" }
if (control.type == "error") {
return "Hermes Reach rejected the route (${control.code ?: "unknown"})"
}
val streamIdValid = control.streamId?.let(::isCanonicalId) == true
if (control.type != "matched" ||
control.protocolVersion != REACH_PROTOCOL_VERSION ||
!streamIdValid
) {
return "Hermes Reach returned a mismatched route response"
}
return null
}
private fun isCanonicalId(value: String): Boolean {
if (value.isBlank() || '=' in value) return false
val decoded = runCatching { Base64.getUrlDecoder().decode(value) }.getOrNull() ?: return false
return decoded.size == 16 && Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == value
}
}
/**
* Raw socket factory that carries bytes through Hermes Reach. OkHttp layers
* the normal Secure Link TLS socket factory over the returned socket, so SNI,
* hostname verification, and the QR SPKI pin all apply to the inner endpoint.
*/
class HermesReachSocketFactory(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : SocketFactory() {
init {
require(route.tunnelUrlOrNull() != null) { "Invalid Hermes Reach route" }
}
override fun createSocket(): Socket = HermesReachSocket(outerClient, route)
override fun createSocket(host: String?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(host: String?, port: Int, localHost: InetAddress?, localPort: Int): Socket =
createSocket().apply {
if (localHost != null) bind(InetSocketAddress(localHost, localPort))
connect(InetSocketAddress(host, port))
}
override fun createSocket(host: InetAddress?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(
address: InetAddress?,
port: Int,
localAddress: InetAddress?,
localPort: Int,
): Socket = createSocket().apply {
if (localAddress != null) bind(InetSocketAddress(localAddress, localPort))
connect(InetSocketAddress(address, port))
}
}
private class HermesReachSocket(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : Socket() {
private val inbound = ReachInputStream()
private val matchLatch = CountDownLatch(1)
private val connectionId = randomConnectionId()
@Volatile private var matchError: IOException? = null
@Volatile private var webSocket: WebSocket? = null
@Volatile private var connected = false
@Volatile private var closed = false
@Volatile private var matched = false
@Volatile private var remote: InetSocketAddress? = null
private var readTimeoutMs: Int = 0
private val outbound = object : OutputStream() {
override fun write(value: Int) = write(byteArrayOf(value.toByte()))
override fun write(bytes: ByteArray, offset: Int, length: Int) {
if (length == 0) return
if (!matched || closed) throw SocketException("Hermes Reach tunnel is not open")
var cursor = offset
var remaining = length
while (remaining > 0) {
val count = minOf(remaining, REACH_MAX_FRAME_BYTES)
val accepted = webSocket?.send(ByteString.of(*bytes.copyOfRange(cursor, cursor + count))) == true
if (!accepted) throw SocketException("Hermes Reach could not queue tunnel bytes")
cursor += count
remaining -= count
}
}
}
override fun connect(endpoint: SocketAddress?) = connect(endpoint, REACH_MATCH_TIMEOUT_MS.toInt())
override fun connect(endpoint: SocketAddress?, timeout: Int) {
if (connected) throw SocketException("Socket is already connected")
if (closed) throw SocketException("Socket is closed")
remote = endpoint as? InetSocketAddress
?: throw SocketException("Hermes Reach requires an internet socket target")
val request = Request.Builder().url(requireNotNull(route.tunnelUrlOrNull())).build()
webSocket = outerClient.newWebSocket(request, listener)
val waitMs = minOf(
timeout.takeIf { it > 0 }?.toLong() ?: REACH_MATCH_TIMEOUT_MS,
REACH_MATCH_TIMEOUT_MS,
)
if (!matchLatch.await(waitMs, TimeUnit.MILLISECONDS)) {
closeWithError(IOException("Hermes Reach host match timed out"))
}
matchError?.let { throw it }
if (!matched) throw IOException("Hermes Reach closed before matching the host")
connected = true
}
private val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
val registration = HermesReachHandshake.registration(route, connectionId)
if (!webSocket.send(registration)) {
closeWithError(IOException("Hermes Reach registration could not be sent"))
}
}
override fun onMessage(webSocket: WebSocket, text: String) {
if (matched) {
closeWithError(IOException("Hermes Reach sent text after matching"))
return
}
HermesReachHandshake.validateMatched(text)?.let { message ->
closeWithError(IOException(message))
return
}
matched = true
matchLatch.countDown()
}
override fun onMessage(webSocket: WebSocket, bytes: ByteString) {
if (!matched) {
closeWithError(IOException("Hermes Reach sent bytes before matching"))
return
}
if (bytes.size > REACH_MAX_FRAME_BYTES) {
closeWithError(IOException("Hermes Reach frame exceeds 1 MiB"))
return
}
if (!inbound.offer(bytes.toByteArray())) {
closeWithError(IOException("Hermes Reach receive queue exceeded its safe limit"))
}
}
override fun onClosing(webSocket: WebSocket, code: Int, reason: String) {
webSocket.close(code, null)
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (!matched) matchError = IOException("Hermes Reach closed before matching the host")
closed = true
inbound.close(matchError)
matchLatch.countDown()
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
closeWithError(IOException("Hermes Reach connection failed", t))
}
}
private fun closeWithError(error: IOException) {
matchError = error
closed = true
webSocket?.cancel()
inbound.close(error)
matchLatch.countDown()
}
override fun getInputStream(): InputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
inbound.readTimeoutMs = readTimeoutMs
return inbound
}
override fun getOutputStream(): OutputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
return outbound
}
override fun close() {
if (closed) return
closed = true
webSocket?.close(1000, null)
inbound.close(null)
matchLatch.countDown()
}
override fun isConnected(): Boolean = connected
override fun isClosed(): Boolean = closed
override fun getRemoteSocketAddress(): SocketAddress? = remote
override fun getInetAddress(): InetAddress? = remote?.address
override fun getPort(): Int = remote?.port ?: 0
override fun setSoTimeout(timeout: Int) { readTimeoutMs = timeout }
override fun getSoTimeout(): Int = readTimeoutMs
override fun setTcpNoDelay(on: Boolean) = Unit
override fun getTcpNoDelay(): Boolean = true
override fun setKeepAlive(on: Boolean) = Unit
override fun getKeepAlive(): Boolean = true
override fun setReuseAddress(on: Boolean) = Unit
override fun getReuseAddress(): Boolean = false
}
internal class ReachInputStream : InputStream() {
private val chunks = ArrayDeque<ByteArray>()
private var offset = 0
private var queuedBytes = 0
private var terminalError: IOException? = null
private var closed = false
@Volatile var readTimeoutMs: Int = 0
@Synchronized
fun offer(bytes: ByteArray): Boolean {
if (closed) return false
if (chunks.size >= REACH_MAX_QUEUED_FRAMES || queuedBytes + bytes.size > REACH_MAX_QUEUED_BYTES) {
return false
}
chunks.addLast(bytes)
queuedBytes += bytes.size
(this as java.lang.Object).notifyAll()
return true
}
@Synchronized
fun close(error: IOException?) {
if (closed) return
closed = true
terminalError = error
(this as java.lang.Object).notifyAll()
}
override fun read(): Int {
val one = ByteArray(1)
return if (read(one, 0, 1) < 0) -1 else one[0].toInt() and 0xff
}
@Synchronized
override fun read(target: ByteArray, targetOffset: Int, length: Int): Int {
if (length == 0) return 0
val started = System.nanoTime()
while (chunks.isEmpty() && !closed) {
val waitMs = if (readTimeoutMs > 0) {
val elapsed = TimeUnit.NANOSECONDS.toMillis(System.nanoTime() - started)
(readTimeoutMs - elapsed).coerceAtLeast(0)
} else 0L
if (readTimeoutMs > 0 && waitMs == 0L) throw java.net.SocketTimeoutException("Hermes Reach read timed out")
(this as java.lang.Object).wait(if (readTimeoutMs > 0) waitMs else 0L)
}
if (chunks.isEmpty()) {
terminalError?.let { throw it }
return -1
}
val chunk = chunks.first()
val count = minOf(length, chunk.size - offset)
chunk.copyInto(target, targetOffset, offset, offset + count)
offset += count
queuedBytes -= count
if (offset == chunk.size) {
chunks.remove(chunk)
offset = 0
}
return count
}
}
private fun randomConnectionId(): String {
val bytes = ByteArray(16).also(SecureRandom()::nextBytes)
return Base64.getUrlEncoder().withoutPadding().encodeToString(bytes)
}
@@ -0,0 +1,145 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.ProxyEndpoint
import com.hermesandroid.relay.data.isValidPinnedProxy
import okhttp3.CertificatePinner
import okhttp3.Interceptor
import okhttp3.OkHttpClient
import java.net.URI
import java.security.KeyStore
import java.security.MessageDigest
import java.security.SecureRandom
import java.security.cert.CertificateException
import java.security.cert.X509Certificate
import javax.net.ssl.SSLContext
import javax.net.ssl.TrustManagerFactory
import javax.net.ssl.X509TrustManager
import javax.net.SocketFactory
/** Runtime endpoints exposed beneath one plugin-owned pinned-TLS origin. */
data class PluginProxyRoutes(
val authority: String,
val host: String,
val port: Int,
val relayHttpUrl: String,
val relayWebSocketUrl: String,
val apiBaseUrl: String?,
val dashboardBaseUrl: String?,
val pinSha256: String,
)
/**
* Resolve and validate the pairing-advertised proxy contract. Invalid or
* incomplete advertisements are never treated as secure routes.
*/
fun ProxyEndpoint.toPluginProxyRoutesOrNull(): PluginProxyRoutes? {
if (!isValidPinnedProxy()) return null
val base = url.trim().trimEnd('/')
val uri = runCatching { URI(base) }.getOrNull() ?: return null
if (!uri.scheme.equals("https", ignoreCase = true)) return null
val host = uri.host?.lowercase()?.takeIf { it.isNotBlank() } ?: return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
val rawPath = uri.rawPath.orEmpty()
if (rawPath.isNotEmpty() && rawPath != "/") return null
val port = if (uri.port > 0) uri.port else 443
val pin = pinSha256!!.trim()
val authority = "$host:$port"
val wsBase = "wss://${formatHost(host)}${if (port == 443) "" else ":$port"}$rawPath"
.trimEnd('/')
val surfaces = surfaces.map(String::lowercase).toSet()
return PluginProxyRoutes(
authority = authority,
host = host,
port = port,
relayHttpUrl = "$base/relay",
relayWebSocketUrl = "$wsBase/relay/ws",
apiBaseUrl = "$base/api".takeIf { "api" in surfaces },
dashboardBaseUrl = "$base/dashboard".takeIf { "dashboard" in surfaces },
pinSha256 = pin,
)
}
fun EndpointCandidate.pluginProxyRoutesOrNull(): PluginProxyRoutes? =
proxy?.toPluginProxyRoutesOrNull()
private fun formatHost(host: String): String = if (':' in host) "[$host]" else host
/**
* Build a client that trusts the system normally, plus exactly the
* pairing-advertised SPKI for this proxy. The authority guard keeps a pin
* scoped to host *and port*; OkHttp's CertificatePinner alone is host-only.
*/
fun buildPluginProxyClient(
baseBuilder: OkHttpClient.Builder,
routes: PluginProxyRoutes,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
rawSocketFactory: SocketFactory? = null,
): OkHttpClient {
val expectedHost = routes.host
val expectedPort = routes.port
val systemTrust = systemTrustManager()
val pinnedTrust = PinnedOrSystemTrustManager(systemTrust, routes.pinSha256)
val sslContext = SSLContext.getInstance("TLS").apply {
init(null, arrayOf(pinnedTrust), SecureRandom())
}
if (rawSocketFactory != null) baseBuilder.socketFactory(rawSocketFactory)
return baseBuilder
.sslSocketFactory(sslContext.socketFactory, pinnedTrust)
.certificatePinner(
CertificatePinner.Builder().add(expectedHost, routes.pinSha256).build(),
)
.addNetworkInterceptor(Interceptor { chain ->
val requestUrl = chain.request().url
if (!requestUrl.host.equals(expectedHost, ignoreCase = true) ||
requestUrl.port != expectedPort
) {
throw java.io.IOException("Pinned proxy redirect left its paired authority")
}
val token = sessionTokenProvider().takeIf { includeRelaySessionHeader }
?.takeIf { it.isNotBlank() }
val request = if (token != null) {
chain.request().newBuilder()
.header("X-Hermes-Relay-Session", token)
.build()
} else {
chain.request()
}
chain.proceed(request)
})
.build()
}
private fun systemTrustManager(): X509TrustManager {
val factory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm())
factory.init(null as KeyStore?)
return factory.trustManagers.filterIsInstance<X509TrustManager>().single()
}
private class PinnedOrSystemTrustManager(
private val system: X509TrustManager,
private val expectedPin: String,
) : X509TrustManager {
override fun checkClientTrusted(chain: Array<out X509Certificate>?, authType: String?) =
system.checkClientTrusted(chain, authType)
override fun checkServerTrusted(chain: Array<out X509Certificate>?, authType: String?) {
val certificates = chain?.takeIf { it.isNotEmpty() }
?: throw CertificateException("Proxy supplied no certificate chain")
val systemAccepted = runCatching { system.checkServerTrusted(chain, authType) }.isSuccess
if (systemAccepted) return
val leaf = certificates.first()
leaf.checkValidity()
val actual = "sha256/" + java.util.Base64.getEncoder().encodeToString(
MessageDigest.getInstance("SHA-256").digest(leaf.publicKey.encoded),
)
if (!MessageDigest.isEqual(actual.toByteArray(), expectedPin.toByteArray())) {
throw CertificateException("Plugin proxy certificate does not match the paired pin")
}
}
override fun getAcceptedIssuers(): Array<X509Certificate> = system.acceptedIssuers
}
@@ -0,0 +1,13 @@
package com.hermesandroid.relay.network.shared
import kotlin.random.Random
/** Full-jitter retry delay in the inclusive range 0..[capMs]. */
internal fun fullJitterDelayMs(
capMs: Long,
unit: Double = Random.nextDouble(),
): Long {
if (capMs <= 0L) return 0L
val boundedUnit = unit.coerceIn(0.0, Math.nextDown(1.0))
return (boundedUnit * (capMs + 1.0)).toLong().coerceAtMost(capMs)
}
@@ -90,12 +90,9 @@ class ChatHandler {
// Fallback form (no relay): `MEDIA:/absolute/path` — relay wasn't
// reachable when the tool fired, so we render an "unavailable"
// placeholder instead of attempting a fetch.
private val mediaRelayRegex = Regex("""MEDIA:hermes-relay://([A-Za-z0-9_-]+)""")
// `/.+?` (not `/\S+`) so absolute paths containing spaces — e.g.
// `MEDIA:/mnt/media/Coralee Adshade/undressher.jpg` — still match. The
// trailing `\s*$` trims any trailing whitespace; non-greedy keeps the
// capture to the path. OkHttp re-encodes the space for /media/by-path.
private val mediaBarePathRegex = Regex("""^\s*MEDIA:(/.+?)\s*$""")
private val mediaRelayPayloadRegex = Regex("""^hermes-relay://([A-Za-z0-9_-]+)$""")
private val mediaMarkerPrefixRegex = Regex("MEDIA:")
private val windowsAbsoluteMediaPathRegex = Regex("""^[A-Za-z]:[\\/].+""")
// Rich card marker — single line, full JSON object payload.
//
// Agents emit:
@@ -188,6 +185,7 @@ class ChatHandler {
* post-stream finalize reconciliation pass.
*/
private var mediaLineBuffer = StringBuilder()
private var mediaFenceDelimiter: String? = null
private val dispatchedMediaMarkers = mutableSetOf<String>()
/**
@@ -526,6 +524,29 @@ class ChatHandler {
}
}
/**
* Rebind visible user turns after Gateway rewrites a truncated durable
* prefix. The response is positional in the same user-ordinal space used
* for edit/regenerate. Missing entries clear cached ids so a later rewind
* cannot accidentally send an archived pre-rewrite row id.
*/
fun rebindSurvivorUserRowIds(rowIds: List<Long?>) {
var ordinal = 0
_messages.update { messages ->
messages.map { message ->
if (!message.isGatewayRewindUser()) return@map message
val rebound = rowIds.getOrNull(ordinal)
ordinal += 1
if (message.rowId == rebound) message else message.copy(rowId = rebound)
}
}
}
private fun ChatMessage.isGatewayRewindUser(): Boolean =
role == MessageRole.USER &&
!id.startsWith("voice-intent-") &&
!id.startsWith("steer-")
fun replaceMessageContent(messageId: String, content: String) {
_messages.update { messages ->
messages.map { message ->
@@ -1176,12 +1197,14 @@ class ChatHandler {
// Drop any pending line buffers / dedupe state so a fresh session
// doesn't inherit leftovers from the previous one.
mediaLineBuffer.clear()
mediaFenceDelimiter = null
dispatchedMediaMarkers.clear()
annotationLineBuffer.clear()
activeAnnotationTools.clear()
cardLineBuffer.clear()
dispatchedCardMarkers.clear()
subagentLabels.clear()
subagentIds.clear()
}
/**
@@ -1497,6 +1520,7 @@ class ChatHandler {
// this as the same visible row across the post-turn reload.
prior.copy(
id = messageId,
rowId = item.rowId,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1527,6 +1551,7 @@ class ChatHandler {
// nothing local to carry).
ChatMessage(
id = messageId,
rowId = item.rowId,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1771,7 +1796,7 @@ class ChatHandler {
for (line in text.lines()) {
val t = line.trim()
if (t.isEmpty()) continue
if (mediaRelayRegex.containsMatchIn(t) || mediaBarePathRegex.containsMatchIn(t)) continue
if (parseMediaMarkerLine(t).isNotEmpty()) continue
if (PersistedImageReferenceParser.parse(t).paths.isNotEmpty()) continue
if (cardMarkerRegex.containsMatchIn(t)) continue
if (sb.isNotEmpty()) sb.append('\n')
@@ -1788,6 +1813,51 @@ class ChatHandler {
data class BarePath(val path: String) : MediaMarkerHit
}
/**
* Parse one marker-only line using upstream-compatible wrappers and
* boundaries. Prose and malformed examples remain ordinary text; a whole
* inline-code or emphasis wrapper is accepted, as are adjacent markers,
* sentence-final punctuation, POSIX paths, and Windows absolute paths.
*/
private fun parseMediaMarkerLine(line: String): List<MediaMarkerHit> {
val trimmed = line.trim()
if (trimmed.isEmpty() || trimmed.startsWith("```") || trimmed.startsWith("~~~")) {
return emptyList()
}
val starts = mediaMarkerPrefixRegex.findAll(trimmed).map { it.range.first }.toList()
if (starts.isEmpty()) return emptyList()
val prefix = trimmed.substring(0, starts.first())
if (prefix.any { !it.isWhitespace() && it !in "`*_~" }) return emptyList()
val hits = ArrayList<MediaMarkerHit>(starts.size)
for ((index, start) in starts.withIndex()) {
val payloadStart = start + "MEDIA:".length
val payloadEnd = starts.getOrNull(index + 1) ?: trimmed.length
val payload = trimmed.substring(payloadStart, payloadEnd)
.trim()
.trimEnd { it in "`*_~.,;:)}]" }
.trim()
if (payload.isEmpty()) return emptyList()
val relay = mediaRelayPayloadRegex.matchEntire(payload)
when {
relay != null -> hits += MediaMarkerHit.RelayToken(relay.groupValues[1])
payload.startsWith("/") || windowsAbsoluteMediaPathRegex.matches(payload) ->
hits += MediaMarkerHit.BarePath(payload)
else -> return emptyList()
}
}
return hits
}
private fun fenceDelimiter(line: String): String? {
val trimmed = line.trimStart()
return when {
trimmed.startsWith("```") -> "```"
trimmed.startsWith("~~~") -> "~~~"
else -> null
}
}
/**
* Scan loaded (non-streaming) message content line-by-line for media
* markers, append hits to [out], and return the content with matched
@@ -1800,24 +1870,20 @@ class ChatHandler {
out: MutableList<Pair<String, MediaMarkerHit>>,
): String {
var cleaned = content
var openFence: String? = null
for (rawLine in content.lines()) {
val trimmed = rawLine.trim()
if (trimmed.isEmpty()) continue
val relayMatch = mediaRelayRegex.find(trimmed)
if (relayMatch != null) {
out.add(messageId to MediaMarkerHit.RelayToken(relayMatch.groupValues[1]))
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
.replace("\n$rawLine", "")
.replace("$rawLine\n", "")
.replace(rawLine, "")
val delimiter = fenceDelimiter(rawLine)
if (delimiter != null) {
openFence = if (openFence == delimiter) null else if (openFence == null) delimiter else openFence
continue
}
if (openFence != null) continue
val bareMatch = mediaBarePathRegex.find(trimmed)
if (bareMatch != null) {
out.add(messageId to MediaMarkerHit.BarePath(bareMatch.groupValues[1]))
val hits = parseMediaMarkerLine(trimmed)
if (hits.isNotEmpty()) {
hits.forEach { out.add(messageId to it) }
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
.replace("\n$rawLine", "")
@@ -1909,6 +1975,37 @@ class ChatHandler {
}
}
/**
* Returns true when structured session history contains tool lifecycle
* state that the live transcript did not receive. This is a read-only
* preflight for Gateway completion reconciliation: healthy live turns keep
* their current StateFlow list and UI identity, while omitted upstream
* tool events opt into [loadMessageHistory]. Assistant prose is never
* inspected or interpreted here.
*/
fun hasMissingPersistedToolActivity(items: List<MessageItem>): Boolean {
val toolResults = items.filter { it.role == "tool" }
.associateBy { it.toolCallId }
val persistedCalls = coalesceRenderedHistoryItems(items)
.asSequence()
.filter { it.role == "assistant" }
.flatMap { parseToolCallsFromHistory(it.toolCalls, toolResults).asSequence() }
.toList()
if (persistedCalls.isEmpty()) return false
val localCalls = _messages.value.flatMap { it.toolCalls }
return persistedCalls.any { persisted ->
val local = persisted.id?.let { id -> localCalls.firstOrNull { it.id == id } }
?: localCalls.firstOrNull {
it.id == null && it.name == persisted.name && it.args == persisted.args
}
local == null ||
(persisted.isComplete && !local.isComplete) ||
(persisted.result != null && persisted.result != local.result) ||
(persisted.success != null && persisted.success != local.success)
}
}
// --- Session management ---
fun setSessionId(sessionId: String?) {
@@ -1964,6 +2061,13 @@ class ChatHandler {
hasModelConfig = item.hasModelConfig,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
)
}.sortedByDescending { it.activityTimestamp }
// Preserve the active session's optimistic row when the server list
@@ -2234,6 +2338,18 @@ class ChatHandler {
val trimmed = line.trim()
if (trimmed.isEmpty()) continue
fenceDelimiter(line)?.let { delimiter ->
mediaFenceDelimiter = if (mediaFenceDelimiter == delimiter) {
null
} else if (mediaFenceDelimiter == null) {
delimiter
} else {
mediaFenceDelimiter
}
continue
}
if (mediaFenceDelimiter != null) continue
if (tryDispatchMediaMarker(messageId, trimmed)) {
stripLineFromContent(messageId, trimmed)
}
@@ -2363,29 +2479,26 @@ class ChatHandler {
* Returns true when a marker was matched so the caller can strip the line.
*/
private fun tryDispatchMediaMarker(messageId: String, line: String): Boolean {
val relayMatch = mediaRelayRegex.find(line)
if (relayMatch != null) {
val token = relayMatch.groupValues[1]
val dedupeKey = "$messageId:relay:$token"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay): token=$token")
onMediaAttachmentRequested(messageId, token)
val hits = parseMediaMarkerLine(line)
for (hit in hits) {
when (hit) {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay): token=${hit.token}")
onMediaAttachmentRequested(messageId, hit.token)
}
}
is MediaMarkerHit.BarePath -> {
val dedupeKey = "$messageId:bare:${hit.path}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path): ${hit.path}")
onMediaBarePathRequested(messageId, hit.path)
}
}
}
return true
}
val bareMatch = mediaBarePathRegex.find(line)
if (bareMatch != null) {
val path = bareMatch.groupValues[1]
val dedupeKey = "$messageId:bare:$path"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path, unavailable): $path")
onMediaBarePathRequested(messageId, path)
}
return true
}
return false
return hits.isNotEmpty()
}
/**
@@ -2524,10 +2637,11 @@ class ChatHandler {
if (mediaLineBuffer.isNotEmpty()) {
val remaining = mediaLineBuffer.toString().trim()
mediaLineBuffer.clear()
if (remaining.isNotEmpty() && tryDispatchMediaMarker(messageId, remaining)) {
if (mediaFenceDelimiter == null && remaining.isNotEmpty() && tryDispatchMediaMarker(messageId, remaining)) {
stripLineFromContent(messageId, remaining)
}
}
mediaFenceDelimiter = null
// Post-stream reconciliation: re-scan the final content for markers
// that raced with stripLineFromContent during streaming.
@@ -2536,12 +2650,16 @@ class ChatHandler {
if (!msg.matchesIdentity(messageId) || msg.role != MessageRole.ASSISTANT) return@map msg
var cleaned = msg.content
var changed = false
var openFence: String? = null
for (rawLine in msg.content.lines()) {
val trimmed = rawLine.trim()
if (trimmed.isEmpty()) continue
if (mediaRelayRegex.containsMatchIn(trimmed) ||
mediaBarePathRegex.containsMatchIn(trimmed)
) {
val delimiter = fenceDelimiter(rawLine)
if (delimiter != null) {
openFence = if (openFence == delimiter) null else if (openFence == null) delimiter else openFence
continue
}
if (openFence == null && parseMediaMarkerLine(trimmed).isNotEmpty()) {
tryDispatchMediaMarker(messageId, trimmed)
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
@@ -2872,6 +2990,7 @@ class ChatHandler {
* [onStreamComplete] / [clearMessages].
*/
private val subagentLabels = mutableMapOf<Int, String>()
private val subagentIds = mutableMapOf<Int, String>()
/**
* Apply one gateway `subagent.*` lifecycle event to the streaming
@@ -2887,6 +3006,9 @@ class ChatHandler {
when (event.phase) {
GatewaySubagentEvent.Phase.START -> {
if (label != null) subagentLabels[event.taskIndex] = label
event.subagentId?.takeIf(String::isNotBlank)?.let {
subagentIds[event.taskIndex] = it
}
}
GatewaySubagentEvent.Phase.TOOL -> {
@@ -2901,6 +3023,8 @@ class ChatHandler {
isComplete = false,
taskIndex = event.taskIndex,
taskLabel = laneLabel,
subagentId = event.subagentId?.takeIf(String::isNotBlank)
?: subagentIds[event.taskIndex],
)
_messages.update { messages ->
val target = messages.findLast {
@@ -2940,6 +3064,7 @@ class ChatHandler {
// "interrupted" lanes never finished — not a success either.
val failed = event.status == "failed" || event.status == "interrupted"
val laneLabel = subagentLabels.remove(event.taskIndex) ?: label
val subagentId = subagentIds.remove(event.taskIndex) ?: event.subagentId
val summaryId = "subagent-${event.taskIndex}-${syntheticToolSeq++}"
_messages.update { messages ->
messages.map { msg ->
@@ -2972,6 +3097,7 @@ class ChatHandler {
completedAt = System.currentTimeMillis(),
taskIndex = event.taskIndex,
taskLabel = laneLabel,
subagentId = subagentId,
)
}
msg.copy(toolCalls = withSummary)
@@ -3229,6 +3355,7 @@ class ChatHandler {
}
}
subagentLabels.clear()
subagentIds.clear()
}
fun onStreamError(message: String) {
@@ -3258,6 +3385,7 @@ class ChatHandler {
}
}
subagentLabels.clear()
subagentIds.clear()
}
fun onThinkingDelta(messageId: String, delta: String) {
@@ -7,9 +7,12 @@ import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.MessageListResponse
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.network.upstream.models.SessionListResponse
import com.hermesandroid.relay.network.upstream.models.SessionPullRequest
import com.hermesandroid.relay.network.upstream.models.SessionPullRequestScanResponse
import com.hermesandroid.relay.network.upstream.models.SessionPruneFilters
import com.hermesandroid.relay.network.upstream.models.SessionPrunePreview
import com.hermesandroid.relay.network.upstream.models.SessionPruneResult
import com.hermesandroid.relay.network.upstream.models.RepositoryPullRequestListResponse
import com.hermesandroid.relay.auth.SecureStoreCache
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.buildRawTokenStore
@@ -35,13 +38,18 @@ import okhttp3.CookieJar
import okhttp3.HttpUrl
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.MultipartBody
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody
import okhttp3.RequestBody.Companion.toRequestBody
import okhttp3.Response
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.URLEncoder
import java.util.concurrent.TimeUnit
import okio.BufferedSink
// Status/session/provider snapshots are @Serializable so the Manage tab's
// disk cache (DashboardManageDiskCache) can persist Loaded entries verbatim.
@@ -67,6 +75,23 @@ data class DashboardGatewayTopology(
@SerialName("served_profiles") val servedProfiles: List<String> = emptyList(),
)
/**
* Return only profiles the launch gateway positively reports as served.
*
* `/api/status.profiles` is the installed-profile inventory. Selective
* multiplex serving can exclude an installed profile, so that list must never
* authorize construction of a `/p/<profile>` API fallback route.
*/
internal fun DashboardStatus.multiplexServedProfiles(): List<String> {
if (!gatewayMode.equals("multiplex", ignoreCase = true)) return emptyList()
return gateways.firstOrNull { it.profile.equals("default", ignoreCase = true) }
?.servedProfiles
.orEmpty()
.map(String::trim)
.filter(String::isNotBlank)
.distinct()
}
@Serializable
data class DashboardComponentHealthRollup(
val supported: Boolean = false,
@@ -173,6 +198,71 @@ data class DashboardCustomEndpointValidation(
val models: List<String>,
)
internal class BoundedStreamRequestBody(
private val declaredLength: Long?,
private val limitBytes: Long,
private val openStream: () -> InputStream,
) : RequestBody() {
init {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit."
}
}
override fun contentType() = "application/zip".toMediaType()
override fun contentLength(): Long = declaredLength ?: -1L
override fun writeTo(sink: BufferedSink) {
openStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit.")
}
sink.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being read.")
}
}
}
}
internal fun copyBounded(
input: InputStream,
output: OutputStream,
declaredLength: Long?,
limitBytes: Long,
): Long {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit."
}
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit.")
}
output.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being downloaded.")
}
return written
}
/** One entry from `GET /api/audio/elevenlabs/voices` — non-secret voice metadata. */
data class ElevenLabsVoice(
val voiceId: String,
@@ -206,8 +296,14 @@ class DashboardApiClient(
isLenient = true
coerceInputValues = true
},
private val nowMillis: () -> Long = System::currentTimeMillis,
) {
private val baseUrl: String = baseUrl.trim().trimEnd('/')
private val sessionPrScanLock = Any()
private val sessionPrScannedAt = mutableMapOf<String, Long>()
private val sessionPrScanWasTerminal = mutableMapOf<String, Boolean>()
private val sessionPullRequests = mutableMapOf<String, SessionPullRequest>()
private var sessionPrScanSupported: Boolean? = null
/**
* Resolve a request URL without ever throwing. okhttp's
@@ -500,6 +596,7 @@ class DashboardApiClient(
name: String,
cloneFromDefault: Boolean = true,
description: String? = null,
mcpServers: List<String> = emptyList(),
): Result<JsonObject> =
postJsonObject(
path = "/api/profiles",
@@ -507,9 +604,167 @@ class DashboardApiClient(
put("name", name)
put("clone_from_default", cloneFromDefault)
if (!description.isNullOrBlank()) put("description", description)
if (mcpServers.isNotEmpty()) {
put("mcp_servers", JsonArray(mcpServers.map(::JsonPrimitive)))
}
},
)
/** Create a host-owned Hermes backup, distinct from Android settings export. */
suspend fun createServerBackup(): Result<JsonObject> =
postJsonObject("/api/ops/backup")
/** Download only archives created inside upstream's guarded dashboard backup directory. */
suspend fun downloadServerBackup(
archive: String,
openOutput: () -> OutputStream,
): Result<String> = download(
path = "/api/ops/backup/download?archive=${queryValue(archive)}",
operation = "Hermes backup",
openOutput = openOutput,
)
/** Import a server-local archive path after the user confirms the destructive restore. */
suspend fun importServerBackup(archive: String): Result<JsonObject> =
postJsonObject(
path = "/api/ops/import",
payload = buildJsonObject { put("archive", archive) },
)
/** Upload an Android-selected zip to upstream's guarded staging directory and start import. */
suspend fun uploadServerBackup(
filename: String,
contentLength: Long?,
openStream: () -> InputStream,
force: Boolean = false,
): Result<JsonObject> = withContext(Dispatchers.IO) {
val path = "/api/ops/import-upload"
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val body = MultipartBody.Builder()
.setType(MultipartBody.FORM)
.addFormDataPart("force", force.toString())
.addFormDataPart(
"file",
filename.ifBlank { "hermes-backup.zip" },
runCatching {
BoundedStreamRequestBody(contentLength, MAX_BACKUP_TRANSFER_BYTES, openStream)
}.getOrElse { return@withContext Result.failure(it) },
)
.build()
executeJson(Request.Builder().url(httpUrl).post(body).build(), path)
}
suspend fun getLearningNode(id: String, profile: String? = null): Result<JsonObject> =
getJsonObject("/api/learning/node?id=${queryValue(id)}${profileQuerySuffix(profile)}")
suspend fun updateLearningNode(
id: String,
content: String,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
put("content", content)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun deleteLearningNode(id: String, profile: String? = null): Result<JsonObject> =
deleteJsonObjectWithBody(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun selectMemoryProvider(provider: String): Result<JsonObject> =
putJsonObject(
path = "/api/memory/provider",
payload = buildJsonObject { put("provider", provider) },
)
/** Activate an already-configured provider inside the selected upstream profile. */
suspend fun activateMemoryProvider(provider: String, profile: String? = null): Result<JsonObject> =
updateMemoryProviderConfig(provider, JsonObject(emptyMap()), profile)
suspend fun getMemoryProviderConfig(
provider: String,
profile: String? = null,
): Result<JsonObject> = getJsonObject(
"/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
)
suspend fun updateMemoryProviderConfig(
provider: String,
values: JsonObject,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
payload = buildJsonObject { put("values", values) },
)
suspend fun setupMemoryProvider(provider: String): Result<JsonObject> =
postJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/setup",
// Dependency installation is host-global upstream. Do not submit
// profile-owned values through this unscoped route.
payload = buildJsonObject { put("values", JsonObject(emptyMap())) },
)
suspend fun startWhatsAppOnboarding(
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/start",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun getWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
getJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun applyWhatsAppOnboarding(
pairingId: String,
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}/apply",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun cancelWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
deleteJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun setMessagingPlatformEnabled(
platform: String,
enabled: Boolean,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/messaging/platforms/${pathSegment(platform)}${profileQuery(profile)}",
payload = buildJsonObject {
put("enabled", enabled)
put("env", JsonObject(emptyMap()))
put("clear_env", JsonArray(emptyList()))
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun testMessagingPlatform(platform: String, profile: String? = null): Result<JsonObject> =
postJsonObject(
"/api/messaging/platforms/${pathSegment(platform)}/test${profileQuery(profile)}",
)
suspend fun setProfileDescription(name: String, description: String): Result<JsonObject> =
putJsonObject(
path = "/api/profiles/${pathSegment(name)}/description",
@@ -605,15 +860,16 @@ class DashboardApiClient(
)
}
suspend fun getCustomEndpoints(): Result<DashboardCustomEndpoints> =
getJsonObject("/api/providers/custom-endpoints")
suspend fun getCustomEndpoints(profile: String? = null): Result<DashboardCustomEndpoints> =
getJsonObject("/api/providers/custom-endpoints${profileQuery(profile)}")
.mapCatching(::parseCustomEndpoints)
suspend fun saveCustomEndpoint(
draft: DashboardCustomEndpointDraft,
profile: String? = null,
): Result<DashboardCustomEndpoints> =
postJsonObject(
"/api/providers/custom-endpoints",
"/api/providers/custom-endpoints${profileQuery(profile)}",
customEndpointPayload(draft),
).mapCatching(::parseCustomEndpoints)
@@ -634,13 +890,19 @@ class DashboardApiClient(
suspend fun activateCustomEndpoint(
id: String,
profile: String? = null,
): Result<JsonObject> =
postJsonObject("/api/providers/custom-endpoints/${pathSegment(id)}/activate")
postJsonObject(
"/api/providers/custom-endpoints/${pathSegment(id)}/activate${profileQuery(profile)}",
)
suspend fun deleteCustomEndpoint(
id: String,
profile: String? = null,
): Result<DashboardCustomEndpoints> =
deleteJsonObject("/api/providers/custom-endpoints/${pathSegment(id)}")
deleteJsonObject(
"/api/providers/custom-endpoints/${pathSegment(id)}${profileQuery(profile)}",
)
.mapCatching(::parseCustomEndpoints)
suspend fun installMcpCatalogEntry(
@@ -749,9 +1011,157 @@ class DashboardApiClient(
pageSessions.forEach { sessions.putIfAbsent(it.id, it) }
if (pageSessions.size < page.limit) break
}
Result.success(sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)))
Result.success(
enrichSessionWorkState(
sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)),
fixedProfile = profile?.trim()?.takeIf { it.isNotBlank() }
?: DEFAULT_SESSION_PROFILE_SCOPE,
),
)
}
/**
* Read the bounded, authoritative session window across every profile.
* Every usable row must retain its owning profile; rows without one are
* skipped rather than risking a cross-profile transcript or mutation.
*/
suspend fun listAllProfileSessions(
limit: Int = SESSION_LIST_WINDOW_LIMIT,
): Result<List<SessionItem>> = withContext(Dispatchers.IO) {
val boundedLimit = limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)
val result = getJson(
"/api/profiles/sessions?limit=$boundedLimit&offset=0&order=recent" +
"&min_messages=1&archived=include&profile=all",
).mapCatching { root ->
val parsed = json.decodeFromJsonElement(SessionListResponse.serializer(), root)
(parsed.sessions ?: parsed.items ?: parsed.data ?: emptyList())
.filter { it.id.isNotBlank() && !it.profile.isNullOrBlank() }
.distinctBy { "${it.profile}:${it.id}" }
.take(boundedLimit)
}
if (result.isFailure) return@withContext result
Result.success(enrichSessionWorkState(result.getOrThrow(), fixedProfile = null))
}
/**
* Attach the PR a coding session created using the current upstream
* transcript-backed endpoint. Repository and branch already arrive on the
* list row. Missing/older endpoints are deliberately ignored, leaving the
* original rows intact. Active misses retry on a bounded cadence; terminal
* rows get one final scan and resolved associations remain cached.
*/
private suspend fun enrichSessionWorkState(
sessions: List<SessionItem>,
fixedProfile: String?,
): List<SessionItem> {
val candidates = sessions.filter {
it.id.isNotBlank() &&
(!it.gitRepoRoot.isNullOrBlank() || !it.gitBranch.isNullOrBlank() || !it.cwd.isNullOrBlank())
}
val duplicateIds = if (fixedProfile == null) {
candidates.groupingBy { it.id }.eachCount().filterValues { it > 1 }.keys
} else {
emptySet()
}
val now = nowMillis()
val pending = synchronized(sessionPrScanLock) {
candidates.filter { session ->
if (session.id in duplicateIds) return@filter false
val key = sessionWorkKey(session, fixedProfile)
val scannedAt = sessionPrScannedAt[key]
val resolved = sessionPullRequests[key] != null
!resolved && when {
scannedAt == null -> true
session.endedAt != null -> sessionPrScanWasTerminal[key] != true
else -> now - scannedAt >= ACTIVE_SESSION_PR_MISS_TTL_MILLIS
}
}
}
val pendingIds = pending.map { it.id }.distinct()
if (pendingIds.isNotEmpty()) {
val payload = buildJsonObject {
put("ids", JsonArray(pendingIds.map { JsonPrimitive(it) }))
}
val scan = postJsonObject("/api/profiles/sessions/pull-requests", payload)
.mapCatching { root ->
json.decodeFromJsonElement(SessionPullRequestScanResponse.serializer(), root)
}
synchronized(sessionPrScanLock) {
// A legacy 404 is a compatibility outcome, not a session-list failure.
// Avoid hammering an unsupported host on every drawer refresh.
if (scan.isSuccess || sessionPrScanSupported == null) {
sessionPrScanSupported = scan.isSuccess
}
pending.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
sessionPrScannedAt[key] = now
sessionPrScanWasTerminal[key] = session.endedAt != null
scan.getOrNull()?.pullRequests?.get(session.id)?.takeIf {
it.number > 0 && it.url.isNotBlank()
}?.let { pullRequest ->
sessionPullRequests[key] = pullRequest
}
}
}
}
refreshPullRequestStates(candidates, fixedProfile)
val pullRequests = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
return sessions.map { session ->
session.copy(pullRequest = pullRequests[sessionWorkKey(session, fixedProfile)])
}
}
/** Refresh current PR lifecycle state using upstream's repo-scoped GitHub view. */
private suspend fun refreshPullRequestStates(
sessions: List<SessionItem>,
fixedProfile: String?,
) {
if (synchronized(sessionPrScanLock) { sessionPrScanSupported } != true) return
val known = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
sessions.groupBy { (it.gitRepoRoot ?: it.cwd).orEmpty().trim() }
.filterKeys { it.isNotBlank() }
.forEach { (path, repositorySessions) ->
val branches = repositorySessions.mapNotNull { it.gitBranch?.trim() }
.filter { it.isNotBlank() }
.distinct()
val numbers = repositorySessions.mapNotNull {
known[sessionWorkKey(it, fixedProfile)]?.number
}
.filter { it > 0 }
.distinct()
if (branches.isEmpty() && numbers.isEmpty()) return@forEach
val payload = buildJsonObject {
put("path", path)
put("branches", JsonArray(branches.map { JsonPrimitive(it) }))
put("numbers", JsonArray(numbers.map { JsonPrimitive(it) }))
}
val response = postJsonObject("/api/git/review/pr-list", payload)
.mapCatching { root ->
json.decodeFromJsonElement(RepositoryPullRequestListResponse.serializer(), root)
}
.getOrNull()
?: return@forEach
if (!response.ghReady) return@forEach
synchronized(sessionPrScanLock) {
repositorySessions.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
val recovered = sessionPullRequests[key]
val current = response.prs.firstOrNull { pr ->
recovered != null && pr.number == recovered.number
} ?: response.prs.firstOrNull { pr ->
!session.gitBranch.isNullOrBlank() && pr.branch == session.gitBranch
}
if (current != null && current.number > 0 && current.url.isNotBlank()) {
sessionPullRequests[key] = current
}
}
}
}
}
private fun sessionWorkKey(session: SessionItem, fixedProfile: String?): String =
"${fixedProfile ?: session.profile.orEmpty()}\u0000${session.id}"
/**
* A session's message history, scoped to its owning profile via the dashboard
* `GET /api/sessions/{id}/messages?profile=`. Required twin of [listSessions]:
@@ -763,12 +1173,24 @@ class DashboardApiClient(
suspend fun getSessionMessages(
sessionId: String,
profile: String? = null,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>> = withContext(Dispatchers.IO) {
val name = profile?.trim().orEmpty()
val query = if (name.isNotBlank()) "?profile=${pathSegment(name)}" else ""
getJson("/api/sessions/${pathSegment(sessionId)}/messages$query").mapCatching { root ->
val parsed = json.decodeFromJsonElement(MessageListResponse.serializer(), root)
parsed.messages ?: parsed.data ?: parsed.items ?: emptyList()
loadSessionMessages(mode) { page ->
val query = buildList {
add("limit=${page.limit}")
add("offset=${page.offset}")
add("order=${page.order}")
if (name.isNotBlank()) add("profile=${pathSegment(name)}")
}.joinToString(prefix = "?", separator = "&")
getJson("/api/sessions/${pathSegment(sessionId)}/messages$query").mapCatching { root ->
val parsed = json.decodeFromJsonElement(MessageListResponse.serializer(), root)
SessionMessagePage(
messages = parsed.messages ?: parsed.data ?: parsed.items ?: emptyList(),
pagination = parsed.pagination,
payloadChars = root.toString().length,
)
}
}
}
@@ -1062,8 +1484,44 @@ class DashboardApiClient(
}
}
private suspend fun download(
path: String,
operation: String,
openOutput: () -> OutputStream,
): Result<String> =
withContext(Dispatchers.IO) {
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val request = Request.Builder().url(httpUrl).get().build()
try {
okHttpClient.newCall(request).execute().use { response ->
if (!response.isSuccessful) return@withContext Result.failure(apiFailure(response, operation))
val disposition = response.header("Content-Disposition").orEmpty()
val filename = Regex("filename=\\\"?([^\\\";]+)").find(disposition)?.groupValues?.get(1)
?: "hermes-backup.zip"
val body = response.body
val declaredLength = body.contentLength().takeIf { it >= 0 }
if (declaredLength != null && declaredLength > MAX_BACKUP_TRANSFER_BYTES) {
throw IOException("Backup archive exceeds the ${MAX_BACKUP_TRANSFER_BYTES / (1024 * 1024)} MB download limit.")
}
openOutput().use { output ->
body.byteStream().use { input ->
copyBounded(input, output, declaredLength, MAX_BACKUP_TRANSFER_BYTES)
}
}
Result.success(filename)
}
} catch (e: Exception) {
Result.failure(e)
}
}
companion object {
private val JSON_MEDIA = "application/json; charset=utf-8".toMediaType()
private const val DEFAULT_SESSION_PROFILE_SCOPE = "__dashboard_default__"
internal const val ACTIVE_SESSION_PR_MISS_TTL_MILLIS = 60_000L
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
internal const val MAX_BACKUP_TRANSFER_BYTES = 100L * 1024L * 1024L
fun pathSegment(value: String): String =
URLEncoder.encode(value, "UTF-8").replace("+", "%20")
@@ -1121,6 +1579,11 @@ class DashboardApiClient(
return if (trimmed.isBlank()) "" else "?profile=${pathSegment(trimmed)}"
}
private fun profileQuerySuffix(profile: String?): String {
val trimmed = profile?.trim().orEmpty()
return if (trimmed.isBlank()) "" else "&profile=${queryValue(trimmed)}"
}
private fun profileLimitQuery(profile: String?, limit: Int): String {
val params = buildList {
val trimmed = profile?.trim().orEmpty()
@@ -1,6 +1,14 @@
package com.hermesandroid.relay.network.upstream
import android.util.Log
import com.hermesandroid.relay.data.GatewayProfileConfigureResult
import com.hermesandroid.relay.data.GatewayProfileDescription
import com.hermesandroid.relay.data.GatewayProfileEditorClient
import com.hermesandroid.relay.data.GatewayProfileEditorUnsupportedException
import com.hermesandroid.relay.data.GatewayProfilePatch
import com.hermesandroid.relay.data.GatewayProfileSection
import com.hermesandroid.relay.data.GatewayProfileSkill
import com.hermesandroid.relay.data.GatewayProfileToolset
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.UsageInfo
import com.hermesandroid.relay.util.AppForegroundTracker
@@ -18,10 +26,12 @@ import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
import kotlinx.coroutines.withTimeout
import com.hermesandroid.relay.network.shared.fullJitterDelayMs
import kotlinx.coroutines.withTimeoutOrNull
import kotlinx.serialization.builtins.ListSerializer
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonNull
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.booleanOrNull
@@ -86,9 +96,13 @@ class GatewayChatClient(
private val promptSubmitTimeoutMs: Long = PROMPT_SUBMIT_REQUEST_TIMEOUT_MS,
/** Test seam — idle-progress watchdog base. Production keeps [TURN_TIMEOUT_MS]. */
private val turnIdleTimeoutMs: Long = TURN_TIMEOUT_MS,
) {
/** Random source for ordinary reconnect full-jitter. */
private val reconnectJitterUnit: () -> Double = { kotlin.random.Random.nextDouble() },
) : GatewayProfileEditorClient {
/** Existing upstream rich-chat vocabulary; do not invent a Relay-only source. */
private val sessionSource = "webui"
@Volatile
private var profileEditorSupported: Boolean? = null
companion object {
private const val TAG = "GatewayChatClient"
@@ -509,6 +523,10 @@ class GatewayChatClient(
* into the session's USER messages (counted from the first user
* message). The server drops that message and everything after it
* before running [text] as a fresh turn.
* @param truncateBeforeRowId durable identity of the same target user row
* when current Gateway history supplied one. Sent alongside the ordinal
* so the server can fail closed if local position and durable identity
* diverge; omitted for older Gateway history without row ids.
* @param queuedFollowUp true only when Android is draining a prompt the
* user explicitly queued behind an active turn. Newer gateways use the
* additive `queued:true` marker to preserve run-after semantics while
@@ -526,7 +544,9 @@ class GatewayChatClient(
callbacks: GatewayTurnCallbacks,
attachments: List<GatewayAttachment> = emptyList(),
truncateBeforeUserOrdinal: Int? = null,
truncateBeforeRowId: Long? = null,
queuedFollowUp: Boolean = false,
onSurvivorUserRowIds: (List<Long?>) -> Unit = { },
onPreflightFailure: (reason: String) -> Unit,
): ActiveTurnHandle {
val turn = GatewayTurn(dispatchOn(callbacks))
@@ -548,21 +568,42 @@ class GatewayChatClient(
turn.tracer.mark("session")
}
if (turn.cancelled) return@launch
attachments.forEach { attachment ->
uploadAttachment(attachment).getOrElse { e ->
val attachmentRefs = attachments.mapNotNull { attachment ->
val upload = uploadAttachment(attachment).getOrElse { e ->
throw GatewayPreflightException("attachment upload failed: ${e.message}")
}
if (attachment.requiresPromptReference()) {
upload.stringField("ref_text")
?: throw GatewayPreflightException(
"attachment upload failed: Hermes returned no readable file reference",
)
} else {
null
}
}
if (turn.cancelled) return@launch
if (!awaitCancelledTurnDrain(turn, storedSessionId)) return@launch
activeTurn = turn
turn.armWatchdog()
// Generic `file.attach` uploads are staged artifacts, not
// session-owned image/PDF attachments. The gateway returns
// the exact workspace/sandbox-safe `@file:` reference that
// must accompany this prompt. Keep the user's prose last,
// matching upstream Desktop's context-reference contract.
val submittedText = (attachmentRefs + text)
.filter(String::isNotBlank)
.joinToString("\n\n")
val submitted = rpc(
"prompt.submit",
buildJsonObject {
put("session_id", liveSessionId ?: error("no live session"))
put("text", text)
truncateBeforeUserOrdinal?.let { put("truncate_before_user_ordinal", it) }
put("text", submittedText)
truncateBeforeUserOrdinal?.let { ordinal ->
put("truncate_before_user_ordinal", ordinal)
put("confirm_truncate", true)
if (ordinal == 0) put("confirm_empty_truncate", true)
}
truncateBeforeRowId?.let { put("truncate_before_row_id", it) }
if (queuedFollowUp) put("queued", true)
},
// Long-running RPC, not a generic 15s ack — see the
@@ -588,7 +629,7 @@ class GatewayChatClient(
if (activeTurn === turn) activeTurn = null
turn.disarmWatchdog()
val submitError = submitted.exceptionOrNull()
if ((submitError as? GatewayRpcException)?.code == ACTIVE_SESSION_CAP_REJECTION) {
if (submitError.isAuthoritativePromptSubmitRejection()) {
// Authoritative policy rejection: the gateway received
// the prompt and deliberately refused to create the
// first turn. Falling back to SSE would bypass the cap
@@ -597,7 +638,7 @@ class GatewayChatClient(
// through the normal failed-turn callback instead.
turn.tracer.done("submit-rejected")
turn.callbacks.onError(
submitError.message ?: "Hermes rejected the new session",
submitError?.message ?: "Hermes rejected the new session",
)
return@launch
}
@@ -605,12 +646,25 @@ class GatewayChatClient(
submitError?.message ?: "prompt.submit failed",
)
}
(submitted.getOrNull()?.get("survivor_user_row_ids") as? JsonArray)?.let { raw ->
val rebound = raw.map { element ->
(element as? JsonPrimitive)?.longOrNull
}
callbackDispatcher { onSurvivorUserRowIds(rebound) }
}
turn.tracer.mark("submit")
// One INFO line per turn so logcat shows which transport
// served a send — the SSE paths log their SSE events, and
// a silent happy path here made on-device verification a
// read-the-absence exercise.
Log.i(TAG, "Gateway turn submitted (session=$storedSessionId)")
} catch (e: GatewayAuthoritativeResumeException) {
if (activeTurn === turn) activeTurn = null
if (!turn.cancelled) {
turn.disarmWatchdog()
turn.tracer.done("resume-rejected")
turn.callbacks.onError(e.message ?: "Hermes could not resume this session")
}
} catch (e: Exception) {
if (activeTurn === turn) activeTurn = null
if (!turn.cancelled) {
@@ -1099,8 +1153,14 @@ class GatewayChatClient(
private fun JsonObject.toGatewayCompressResult(): GatewayCompressResult =
GatewayCompressResult(
status = stringField("status") ?: "completed",
output = stringField("output"),
status = stringField("status") ?: if (
(this["compressed"] as? JsonPrimitive)?.booleanOrNull == false
) {
"noop"
} else {
"completed"
},
output = stringField("output") ?: stringField("message"),
removed = (this["removed"] as? JsonPrimitive)?.intOrNull,
beforeMessages = (this["before_messages"] as? JsonPrimitive)?.intOrNull,
afterMessages = (this["after_messages"] as? JsonPrimitive)?.intOrNull,
@@ -1220,6 +1280,120 @@ class GatewayChatClient(
.onSuccess { commandsCatalogCache = it }
}
/**
* Capability probe and authoritative editor snapshot. A method-not-found
* response is sticky for this client so older Hermes builds keep using the
* existing Relay inspector without repeatedly sending unsupported RPCs.
*/
override suspend fun describeProfile(
profileName: String,
): Result<GatewayProfileDescription> {
if (profileEditorSupported == false) {
return Result.failure(GatewayProfileEditorUnsupportedException())
}
val name = profileName.trim()
if (name.isEmpty()) return Result.failure(IllegalArgumentException("profile name required"))
try {
connectMutex.withLock { ensureConnected() }
} catch (e: Exception) {
return Result.failure(e)
}
val response = rpc(
"profiles.describe",
buildJsonObject { put("name", name) },
)
val error = response.exceptionOrNull()
if (error.isMethodNotFound()) {
profileEditorSupported = false
return Result.failure(GatewayProfileEditorUnsupportedException())
}
return response.mapCatching { payload ->
parseProfileDescription(payload, expectedName = name)
}.onSuccess {
profileEditorSupported = true
}
}
/** Apply only fields explicitly present in [patch]; requires a successful describe first. */
override suspend fun configureProfile(
profileName: String,
patch: GatewayProfilePatch,
): Result<GatewayProfileConfigureResult> {
if (profileEditorSupported != true) {
return Result.failure(GatewayProfileEditorUnsupportedException())
}
val name = profileName.trim()
if (name.isEmpty()) return Result.failure(IllegalArgumentException("profile name required"))
if ((patch.provider == null) != (patch.model == null)) {
return Result.failure(IllegalArgumentException("provider and model must be saved together"))
}
val requested = patch.requestedSections
if (requested.isEmpty()) return Result.success(GatewayProfileConfigureResult(emptySet(), emptySet()))
val params = buildJsonObject {
put("name", name)
patch.description?.let { put("description", it) }
patch.soul?.let { put("soul", it) }
patch.provider?.let { put("provider", it) }
patch.model?.let { put("model", it) }
patch.disabledSkills?.let { names ->
put("disabled_skills", JsonArray(names.map(::JsonPrimitive)))
}
patch.enabledToolsets?.let { names ->
put("enabled_toolsets", JsonArray(names.map(::JsonPrimitive)))
}
}
return rpc("profiles.configure", params).mapCatching { payload ->
val appliedObject = payload["applied"] as? JsonObject
?: throw GatewayRpcException("profiles.configure returned no applied map")
val applied = requested.filterTo(linkedSetOf()) { section ->
(appliedObject[section.wireName] as? JsonPrimitive)?.booleanOrNull == true
}
GatewayProfileConfigureResult(requested = requested, applied = applied)
}
}
private fun parseProfileDescription(
payload: JsonObject,
expectedName: String,
): GatewayProfileDescription {
val name = payload.stringField("name")
?: throw GatewayRpcException("profiles.describe returned no profile name")
if (name != expectedName) {
throw GatewayRpcException("profiles.describe returned a different profile")
}
val model = payload["model"] as? JsonObject ?: JsonObject(emptyMap())
val skills = (payload["skills"] as? JsonArray).orEmpty().mapNotNull { item ->
val obj = item as? JsonObject ?: return@mapNotNull null
val skillName = obj.stringField("name")?.takeIf(String::isNotBlank)
?: return@mapNotNull null
GatewayProfileSkill(
name = skillName,
enabled = (obj["enabled"] as? JsonPrimitive)?.booleanOrNull ?: true,
)
}
val toolsets = (payload["toolsets"] as? JsonArray).orEmpty().mapNotNull { item ->
val obj = item as? JsonObject ?: return@mapNotNull null
val toolsetName = obj.stringField("name")?.takeIf(String::isNotBlank)
?: return@mapNotNull null
GatewayProfileToolset(
name = toolsetName,
description = obj.stringField("description").orEmpty(),
toolCount = (obj["tool_count"] as? JsonPrimitive)?.intOrNull ?: 0,
enabled = (obj["enabled"] as? JsonPrimitive)?.booleanOrNull ?: true,
)
}
return GatewayProfileDescription(
name = name,
description = payload.stringField("description").orEmpty(),
soul = payload.stringField("soul").orEmpty(),
provider = model.stringField("provider").orEmpty(),
model = model.stringField("default").orEmpty(),
skills = skills,
toolsets = toolsets,
toolsetsPinned = (payload["toolsets_pinned"] as? JsonPrimitive)?.booleanOrNull ?: false,
)
}
/**
* Fetch the upstream gateway's cropped preview for a Petdex pet.
*
@@ -1482,6 +1656,43 @@ class GatewayChatClient(
},
)
/**
* React to the newest message for a role without guessing a transcript row
* id. This follows the upstream gateway contract, which resolves the row
* atomically inside the active session. A null emoji removes the reaction.
*/
suspend fun reactToNewest(role: String, emoji: String?): Result<JsonObject> {
require(role == "user" || role == "assistant") { "unsupported reaction role" }
val sid = liveSessionId
?: return Result.failure(GatewayRpcException("no live session"))
return rpc(
"message.react",
buildJsonObject {
put("session_id", sid)
put("newest_role", role)
if (emoji == null) put("emoji", JsonNull) else put("emoji", emoji)
put("author", "user")
},
)
}
/** Redirect one running child agent without interrupting the parent turn. */
suspend fun steerSubagent(subagentId: String, text: String): Result<JsonObject> {
val sessionId = liveSessionId
?: return Result.failure(IllegalStateException("No live gateway session"))
if (subagentId.isBlank() || text.isBlank()) {
return Result.failure(IllegalArgumentException("Subagent and instruction are required"))
}
return rpc(
"subagent.steer",
buildJsonObject {
put("session_id", sessionId)
put("subagent_id", subagentId)
put("text", text.trim())
},
)
}
/** Fetch the session/global reasoning effort and display mode. */
suspend fun getReasoningSettings(): Result<GatewayReasoningSettings> {
if (webSocket == null || readySignal?.isCompleted != true) {
@@ -1948,6 +2159,12 @@ class GatewayChatClient(
},
)
val result = resumed.getOrNull()
val resumeError = resumed.exceptionOrNull()
if ((resumeError as? GatewayRpcException)?.code == 4130) {
throw GatewayAuthoritativeResumeException(
resumeError.message ?: "Session transcript exceeds the configured resume limit",
)
}
val live = result?.stringField("session_id")
if (live != null) {
liveSessionId = live
@@ -2090,6 +2307,42 @@ class GatewayChatClient(
return
}
// Upstream emits session.reclaimed process-wide, so it is identified
// by payload rather than params.session_id. Retire only an exact live
// runtime we own; preserve the durable id so the next send resumes it.
if (type == "session.reclaimed") {
val reclaimedLiveId = payload?.stringField("session_id")
val reclaimedStoredId = payload?.stringField("stored_session_id")
val reason = payload?.stringField("reason")
val supportedReason = reason in setOf("idle_timeout", "lru_evict", "ws_orphan_reap")
if (!reclaimedLiveId.isNullOrBlank() && supportedReason) {
val background = backgroundTurns.remove(reclaimedLiveId)
if (background != null) {
callbackDispatcher {
unmatchedTurnCompleteListener?.invoke(
GatewayBackgroundTurnCompletion(
storedSessionId = reclaimedStoredId?.takeIf(String::isNotBlank)
?: background.storedSessionId,
liveSessionId = reclaimedLiveId,
profile = background.profile,
expectedAssistantText = null,
),
)
}
}
if (reclaimedLiveId == liveSessionId) {
liveSessionId = null
reclaimedStoredId?.takeIf(String::isNotBlank)?.let { storedSessionId = it }
val turn = activeTurn
if (turn != null && !turn.ended) {
activeTurn = null
turn.failFromTransport("Gateway reclaimed the inactive session")
}
}
}
return
}
// read_terminal is a renderer query, not a user decision. Android has
// no xterm pane on the Gateway chat surface, so mirror upstream
// desktop's no-live-pane behavior and answer with empty text instead
@@ -2408,7 +2661,7 @@ class GatewayChatClient(
Log.i(TAG, "Gateway socket rejoined for ${backgroundTurns.size} detached turn(s)")
return
}
delay(backoffMs)
delay(fullJitterDelayMs(backoffMs, reconnectJitterUnit()))
backoffMs = (backoffMs * 2).coerceAtMost(5_000L)
}
}
@@ -2501,7 +2754,7 @@ class GatewayChatClient(
)
return
}
delay(backoffMs)
delay(fullJitterDelayMs(backoffMs, reconnectJitterUnit()))
backoffMs = (backoffMs * 2).coerceAtMost(5_000L)
}
if (activeTurn === turn) activeTurn = null
@@ -2602,6 +2855,11 @@ class GatewayChatClient(
}
}
private fun GatewayAttachment.requiresPromptReference(): Boolean {
val mime = contentType.substringBefore(';').trim().lowercase()
return !mime.startsWith("image/") && mime != "application/pdf"
}
/**
* Upload one image. Tries the upstream RPC name first; on method-not-found
* falls back ONCE per socket to the legacy dotted name (older builds
@@ -3080,11 +3338,24 @@ internal class GatewayPreflightException(message: String) : Exception(message)
/** One connect attempt failed; [GatewayChatClient] may retry with a fresh ticket. */
internal class GatewayConnectAttemptException(message: String) : Exception(message)
/** Server intentionally refused a durable resume; never create/fallback into a context-free turn. */
internal class GatewayAuthoritativeResumeException(message: String) : Exception(message)
/** [code] is the JSON-RPC error code when the failure came from the server (e.g. 4018, -32601). */
internal class GatewayRpcException(message: String, val code: Int? = null) : Exception(message)
private const val JSONRPC_METHOD_NOT_FOUND = -32601
private const val ACTIVE_SESSION_CAP_REJECTION = 4090
private val AUTHORITATIVE_PROMPT_SUBMIT_REJECTIONS = setOf(
4004, // malformed truncation target
4018, // durable/ordinal target is no longer present
4028, // first-turn truncate requires explicit empty-history confirmation
4029, // every destructive truncate requires explicit confirmation
4030, // durable row id and client ordinal disagree
4090, // active-session capacity policy
5008, // durable truncation could not be persisted
5070, // initial session persistence failed: storage full
5071, // other authoritative initial session persistence failure
)
private const val MAX_RECOVERED_CORRECTIONS = 32
private const val MAX_RECOVERED_CORRECTION_CHARS = 32_768
private const val PET_THUMB_DATA_PREFIX = "data:image/png;base64,"
@@ -3140,6 +3411,9 @@ private fun Throwable?.isMethodNotFound(): Boolean {
msg.contains("unknown method", ignoreCase = true)
}
private fun Throwable?.isAuthoritativePromptSubmitRejection(): Boolean =
(this as? GatewayRpcException)?.code in AUTHORITATIVE_PROMPT_SUBMIT_REJECTIONS
private fun Throwable?.isApprovalModeUnsupported(): Boolean {
val rpcError = this as? GatewayRpcException ?: return false
val message = rpcError.message.orEmpty()
@@ -207,7 +207,11 @@ class GatewayEventMapper(
}
else -> syntheticToolId(name)
}
val argsPreview = payload.string("args_text")
val argsPreview = payload?.get("args")
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
?: payload.string("args_text")
?.takeIf { it.isNotBlank() }
?: payload.string("context")?.takeIf { it.isNotBlank() }
callbacks.onToolCallStart(toolId, name, argsPreview)
@@ -294,6 +298,7 @@ class GatewayEventMapper(
// text; thinking/progress carry text only.
preview = payload.string("tool_preview") ?: payload.string("text"),
durationSeconds = payload.double("duration_seconds"),
subagentId = payload.string("subagent_id"),
),
)
}
@@ -439,15 +444,26 @@ class GatewayEventMapper(
}
fun interactionRequest(type: String, payload: JsonObject?): GatewayAsk? = when (type) {
"clarify.request" -> GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull }
?.takeIf { it.isNotEmpty() },
timeoutSeconds = CLARIFY_TIMEOUT_SECONDS,
)
"clarify.request" -> {
val choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.trim() }
?.filter { it.isNotEmpty() }
?.distinct()
?.take(MAX_CLARIFY_CHOICES)
?.takeIf { it.isNotEmpty() }
GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = choices,
multiSelect = payload.boolean("multi_select") == true && choices != null,
// Current upstream owns expiry through clarify.expire and
// does not advertise its configurable deadline. Never
// invent a local deadline; consume future additive
// metadata only when it is present and positive.
timeoutSeconds = payload.int("timeout_seconds")?.coerceAtLeast(0) ?: 0,
)
}
"approval.request" -> GatewayAsk(
kind = GatewayAsk.Kind.APPROVAL,
@@ -556,9 +572,9 @@ class GatewayEventMapper(
}
}
// Upstream `_block()` timeouts per ask kind (server.py) — the blocked thread
// resolves to "" when these elapse. Approval has none (session-scoped).
private const val CLARIFY_TIMEOUT_SECONDS = 300
// Upstream clarify tool accepts at most four choices. Sudo/secret retain fixed
// `_block()` timeouts; clarify is configurable and expires authoritatively.
private const val MAX_CLARIFY_CHOICES = 4
private const val SUDO_TIMEOUT_SECONDS = 120
private const val SECRET_TIMEOUT_SECONDS = 300
@@ -578,6 +594,12 @@ private fun JsonObject?.approvalChoices(): List<String>? =
(this?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.lowercase() }
?.filter { it in setOf("once", "session", "always", "deny") }
// Scope-denial flags are authoritative. Current upstream protected-
// instruction requests set both flags false, but gateway event builders
// can still include the broader session choice in `choices`.
// Never offer a scope the request explicitly forbids.
?.filterNot { it == "session" && this.boolean("allow_session") == false }
?.filterNot { it == "always" && this.boolean("allow_permanent") == false }
?.distinct()
?.takeIf { it.isNotEmpty() }
@@ -218,13 +218,15 @@ data class GatewayAsk(
val text: String,
/** Server-advertised answers for clarify and approval requests. */
val choices: List<String>? = null,
/** Clarify-only: several advertised choices may be returned together. */
val multiSelect: Boolean = false,
/** Approval-only: the smart observer denied and the owner may override once. */
val smartDenied: Boolean = false,
/** Secret-only: the env var the value will be stored under. */
val envVar: String? = null,
/**
* Upstream blocking timeout (clarify/secret 300s, sudo 120s). 0 means no
* countdown — approvals are session-scoped and never expire on their own.
* Server-advertised blocking timeout. 0 means no client countdown; the
* authoritative `*.expire` event still retires the interaction.
*/
val timeoutSeconds: Int,
) {
@@ -270,6 +272,7 @@ data class GatewaySubagentEvent(
val toolName: String? = null,
val preview: String? = null,
val durationSeconds: Double? = null,
val subagentId: String? = null,
) {
enum class Phase { START, THINKING, TOOL, PROGRESS, COMPLETE }
}
@@ -503,6 +506,21 @@ internal fun isCurrentModelOptionsResponse(
): Boolean =
requestGeneration == currentGeneration && requestProfileKey == currentProfileKey
/**
* Selects the identity a model-options response may publish into chat UI state.
* Catalog-only requests populate picker choices without changing session identity.
*/
internal fun modelOptionsIdentityToPublish(
catalogOnly: Boolean,
hasLiveSession: Boolean,
sessionIdentity: GatewayModelIdentity?,
options: GatewayModelOptions,
): GatewayModelIdentity? = when {
catalogOnly -> null
hasLiveSession && sessionIdentity != null -> sessionIdentity
else -> GatewayModelIdentity(options.currentModel, options.currentProvider)
}
/**
* The explicit in-chat overrides to bind onto a gateway `session.create` as the
* new session's PER-SESSION overrides. Matches the upstream desktop client,
@@ -19,6 +19,7 @@ import com.hermesandroid.relay.network.upstream.models.SkillListResponse
import com.hermesandroid.relay.network.upstream.models.UsageInfo
import com.hermesandroid.relay.util.TurnLatencyTracer
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.withContext
import kotlinx.serialization.encodeToString
import kotlinx.serialization.Serializable
@@ -431,6 +432,7 @@ private class RetryingEventSource(
class HermesApiClient(
baseUrl: String,
private val apiKey: String,
httpClient: OkHttpClient? = null,
private val json: Json = Json {
ignoreUnknownKeys = true
isLenient = true
@@ -478,7 +480,7 @@ class HermesApiClient(
private val mainHandler = Handler(Looper.getMainLooper())
private val client: OkHttpClient = OkHttpClient.Builder()
private val client: OkHttpClient = httpClient ?: OkHttpClient.Builder()
.readTimeout(5, TimeUnit.MINUTES)
.connectTimeout(10, TimeUnit.SECONDS)
.build()
@@ -713,19 +715,34 @@ class HermesApiClient(
}
}
suspend fun getMessages(sessionId: String): List<MessageItem> = withContext(Dispatchers.IO) {
try {
val request = authRequest("$baseUrl/api/sessions/$sessionId/messages")
.get()
.build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) return@withContext emptyList()
val body = response.body?.string() ?: return@withContext emptyList()
val parsed = json.decodeFromString<MessageListResponse>(body)
parsed.data ?: parsed.items ?: parsed.messages ?: emptyList()
suspend fun getMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): List<MessageItem> = withContext(Dispatchers.IO) {
loadSessionMessages(mode) { page ->
runCatching {
val url = "$baseUrl/api/sessions/$sessionId/messages".toHttpUrlOrNull()
?.newBuilder()
?.addQueryParameter("limit", page.limit.toString())
?.addQueryParameter("offset", page.offset.toString())
?.addQueryParameter("order", page.order)
?.build()
?: error("invalid session messages URL")
val request = authRequest(url.toString()).get().build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) error("HTTP ${response.code}")
val body = response.body?.string() ?: error("empty response body")
val parsed = json.decodeFromString<MessageListResponse>(body)
SessionMessagePage(
messages = parsed.data ?: parsed.items ?: parsed.messages ?: emptyList(),
pagination = parsed.pagination,
payloadChars = body.length,
)
}
}
} catch (e: Exception) {
Log.w(TAG, "Failed to get messages: ${e.message}")
}.getOrElse { error ->
if (error is CancellationException) throw error
Log.w(TAG, "Failed to get messages: ${error.message}")
emptyList()
}
}
@@ -0,0 +1,78 @@
package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.MessagePagination
import kotlinx.coroutines.CancellationException
/** Explicit transcript read intent for Hermes' bounded messages endpoint. */
enum class SessionMessageLoadMode {
/** One bounded newest-first window, returned in chronological order. */
LATEST,
/** Every page, oldest first, subject to Android memory safety bounds. */
COMPLETE,
}
internal const val SESSION_MESSAGE_PAGE_SIZE = 500
private const val MAX_COMPLETE_TRANSCRIPT_MESSAGES = 50_000
private const val MAX_COMPLETE_TRANSCRIPT_PAYLOAD_CHARS = 32_000_000
internal data class SessionMessagePageRequest(
val limit: Int = SESSION_MESSAGE_PAGE_SIZE,
val offset: Int = 0,
val order: String,
)
internal data class SessionMessagePage(
val messages: List<MessageItem>,
val pagination: MessagePagination?,
val payloadChars: Int,
)
internal class SessionTranscriptTooLargeException(message: String) : IllegalStateException(message)
/** Shared API-server/dashboard pagination contract. Legacy unpaginated envelopes remain valid. */
internal suspend fun loadSessionMessages(
mode: SessionMessageLoadMode,
fetchPage: suspend (SessionMessagePageRequest) -> Result<SessionMessagePage>,
): Result<List<MessageItem>> {
return try {
val order = if (mode == SessionMessageLoadMode.LATEST) "latest" else "oldest"
val collected = ArrayList<MessageItem>()
var offset = 0
var payloadChars = 0L
while (true) {
val request = SessionMessagePageRequest(offset = offset, order = order)
val page = fetchPage(request).getOrThrow()
payloadChars += page.payloadChars
if (payloadChars > MAX_COMPLETE_TRANSCRIPT_PAYLOAD_CHARS) {
throw SessionTranscriptTooLargeException(
"Session transcript exceeds Android's 32 MB safe-load limit",
)
}
if (collected.size + page.messages.size > MAX_COMPLETE_TRANSCRIPT_MESSAGES) {
throw SessionTranscriptTooLargeException(
"Session transcript exceeds Android's 50,000-message safe-load limit",
)
}
collected += page.messages
if (mode == SessionMessageLoadMode.LATEST) break
// Older Hermes returned one unpaginated complete envelope. Never issue
// a speculative second request against that contract.
val pagination = page.pagination ?: break
val returned = pagination.returned ?: page.messages.size
if (page.messages.isEmpty() || returned < request.limit || page.messages.size < request.limit) break
val nextOffset = offset + page.messages.size
if (nextOffset <= offset) break
offset = nextOffset
}
Result.success(collected)
} catch (error: CancellationException) {
throw error
} catch (error: Throwable) {
Result.failure(error)
}
}
@@ -16,6 +16,7 @@ import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.jsonArray
import kotlinx.serialization.json.jsonPrimitive
import kotlinx.serialization.json.longOrNull
import java.time.Instant
/**
@@ -76,6 +77,26 @@ object FlexibleIdNonNullSerializer : KSerializer<String> {
}
}
/** Unknown-safe durable SQLite row id used by current Gateway history. */
@OptIn(ExperimentalSerializationApi::class)
object FlexibleLongSerializer : KSerializer<Long?> {
override val descriptor = PrimitiveSerialDescriptor("FlexibleLong", PrimitiveKind.LONG)
override fun deserialize(decoder: Decoder): Long? {
return try {
val jsonDecoder = decoder as? JsonDecoder
?: return decoder.decodeLong()
(jsonDecoder.decodeJsonElement() as? JsonPrimitive)?.longOrNull
} catch (_: Exception) {
null
}
}
override fun serialize(encoder: Encoder, value: Long?) {
if (value != null) encoder.encodeLong(value) else encoder.encodeNull()
}
}
/** Timestamp serializer for Hermes session metadata.
*
* Upstream currently returns epoch seconds for `started_at` / `last_active`;
@@ -142,6 +163,8 @@ data class SessionItem(
val preview: String? = null,
val model: String? = null,
val source: String? = null,
/** Owning profile on the cross-profile `/api/profiles/sessions` endpoint. */
val profile: String? = null,
@SerialName("started_at")
@Serializable(with = FlexibleTimestampSerializer::class)
val startedAt: Double? = null,
@@ -168,11 +191,39 @@ data class SessionItem(
/** Durable flags returned by current Dashboard and API-server session resources. */
val pinned: Boolean = false,
val archived: Boolean = false,
/** Optional workspace metadata added by newer Dashboard session lists. */
val cwd: String? = null,
@SerialName("git_branch") val gitBranch: String? = null,
@SerialName("git_repo_root") val gitRepoRoot: String? = null,
/** Best-effort association from the Dashboard's read-only transcript scan. */
val pullRequest: SessionPullRequest? = null,
) {
val resolvedLastActivity: Double?
get() = lastActive ?: lastActivity ?: lastActivityAt ?: updatedAt
}
@Serializable
data class SessionPullRequest(
val number: Int,
val url: String,
val branch: String? = null,
val state: String? = null,
val draft: Boolean = false,
val title: String? = null,
)
@Serializable
data class SessionPullRequestScanResponse(
@SerialName("pull_requests") val pullRequests: Map<String, SessionPullRequest> = emptyMap(),
val scanned: List<String> = emptyList(),
)
@Serializable
data class RepositoryPullRequestListResponse(
val ghReady: Boolean = false,
val prs: List<SessionPullRequest> = emptyList(),
)
@Serializable
data class CreateSessionRequest(
val title: String? = null,
@@ -244,7 +295,16 @@ data class MessageListResponse(
val items: List<MessageItem>? = null,
val messages: List<MessageItem>? = null, // alternate key
val data: List<MessageItem>? = null, // upstream /api/sessions/{id}/messages list envelope
val total: Int? = null
val total: Int? = null,
val pagination: MessagePagination? = null,
)
@Serializable
data class MessagePagination(
val limit: Int? = null,
val offset: Int? = null,
val order: String? = null,
val returned: Int? = null,
)
@Serializable
@@ -254,6 +314,9 @@ data class MessageItem(
@SerialName("session_id")
@Serializable(with = FlexibleIdSerializer::class)
val sessionId: String? = null,
@SerialName("row_id")
@Serializable(with = FlexibleLongSerializer::class)
val rowId: Long? = null,
val role: String,
val content: JsonElement? = null,
@SerialName("tool_calls") val toolCalls: JsonElement? = null,
@@ -9,6 +9,7 @@ import android.content.Context
import android.content.Intent
import android.content.pm.PackageManager
import android.os.Build
import android.net.Uri
import android.util.Log
import androidx.core.app.NotificationCompat
import androidx.core.app.NotificationManagerCompat
@@ -47,10 +48,13 @@ object ProactiveMessageNotifier {
/**
* Tap route — opens Chat, where the message lives as a Thread. Must match
* `Screen.Chat.route()` in RelayApp. Routed via the EXTRA_NAV_ROUTE deep-link
* path (MainActivity → NavRouteRequest → RelayApp collector). Opening the
* exact Thread by chat_id is a follow-up (see TODO).
* path (MainActivity → NavRouteRequest → RelayApp collector), carrying the
* `chat_id` so RelayApp opens the exact real or provisional Thread.
*/
private const val TAP_ROUTE = "chat"
private fun tapRoute(chatId: String?): String =
chatId?.takeIf { it.isNotBlank() }
?.let { "chat?proactiveChatId=${Uri.encode(it)}" }
?: "chat"
/**
* Post (or replace) a proactive-message notification.
@@ -80,7 +84,7 @@ object ProactiveMessageNotifier {
val tapIntent = Intent(context, MainActivity::class.java).apply {
flags = Intent.FLAG_ACTIVITY_NEW_TASK or Intent.FLAG_ACTIVITY_CLEAR_TOP
putExtra(MainActivity.EXTRA_NAV_ROUTE, TAP_ROUTE)
putExtra(MainActivity.EXTRA_NAV_ROUTE, tapRoute(chatId))
}
val pendingFlags = PendingIntent.FLAG_UPDATE_CURRENT or PendingIntent.FLAG_IMMUTABLE
// Distinct requestCode per slot so each notification gets its own
@@ -176,7 +176,7 @@ internal class HermesRuntimeBinder(
chat.setDisplayProfileProvider { connection.effectiveDisplayProfile.value }
chat.setDisplayAliasProvider { connection.profileDisplayAlias.value }
chat.setProfileSessionLister { connection.listProfileScopedSessions() }
chat.setProfileMessageLoader(connection::loadProfileScopedMessages)
chat.setProfileMessageLoaderWithMode(connection::loadProfileScopedMessages)
chat.setDashboardConfigLoader { connection.loadActiveDashboardConfig() }
chat.profileSessionDeleter = connection::deleteProfileScopedSession
chat.profileSessionRenamer = connection::renameProfileScopedSession
@@ -59,6 +59,7 @@ import androidx.compose.ui.draw.alpha
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.platform.LocalConfiguration
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.platform.LocalWindowInfo
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.unit.dp
@@ -96,13 +97,16 @@ import com.hermesandroid.relay.ui.components.avatar.LocalPetPlaybackSpeed
import com.hermesandroid.relay.ui.components.avatar.LocalPetStabilize
import com.hermesandroid.relay.ui.components.avatar.PetLoader
import com.hermesandroid.relay.ui.components.avatar.SphereAvatar
import com.hermesandroid.relay.ui.components.avatar.resolveBackgroundAvatar
import com.hermesandroid.relay.ui.components.FloatingPetCompanion
import com.hermesandroid.relay.ui.components.shouldCompactFloatingPet
import com.hermesandroid.relay.ui.components.pet.LocalPetCompanionCoordinator
import com.hermesandroid.relay.ui.components.pet.LocalPetSafeAreaRegistry
import com.hermesandroid.relay.ui.components.pet.PetCompanionCoordinator
import com.hermesandroid.relay.ui.components.pet.PetInteractionLayer
import com.hermesandroid.relay.ui.components.pet.PetSafeAreaRegistry
import com.hermesandroid.relay.ui.components.pet.petPerchSurface
import com.hermesandroid.relay.ui.components.pet.platformModalOwnsPetLayer
import com.hermesandroid.relay.ui.components.ConnectionSwitcherSheet
import com.hermesandroid.relay.ui.components.ChatTransportStatusBadge
import com.hermesandroid.relay.ui.components.ChatTransportTier
@@ -135,6 +139,7 @@ import com.hermesandroid.relay.ui.onboarding.OnboardingScreen
import com.hermesandroid.relay.ui.screens.AboutScreen
import com.hermesandroid.relay.ui.screens.AnalyticsScreen
import com.hermesandroid.relay.ui.screens.AppearanceSettingsScreen
import com.hermesandroid.relay.ui.screens.CustomPetGuideScreen
import com.hermesandroid.relay.ui.screens.PetdexBrowseScreen
import com.hermesandroid.relay.ui.screens.BridgeCoreScreen
import com.hermesandroid.relay.ui.screens.DiagnosticsScreen
@@ -331,17 +336,20 @@ sealed class Screen(
// NavHost, and the NavigationBarItem click must navigate via [route]()
// so no unresolved `{openAgentSheet}` leaks into the destination.
data object Chat : Screen(
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}",
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}" +
"&proactiveChatId={proactiveChatId}",
"Chat",
Icons.AutoMirrored.Filled.Chat,
) {
const val ARG_OPEN_AGENT_SHEET: String = "openAgentSheet"
const val ARG_SESSION_ID: String = "sessionId"
const val ARG_PROFILE: String = "profile"
const val ARG_PROACTIVE_CHAT_ID: String = "proactiveChatId"
fun route(
openAgentSheet: Boolean = false,
sessionId: String? = null,
profile: String? = null,
proactiveChatId: String? = null,
): String {
val params = buildList {
if (openAgentSheet) add("$ARG_OPEN_AGENT_SHEET=true")
@@ -351,6 +359,9 @@ sealed class Screen(
profile?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROFILE=${android.net.Uri.encode(it)}")
}
proactiveChatId?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROACTIVE_CHAT_ID=${android.net.Uri.encode(it)}")
}
}
return if (params.isEmpty()) "chat" else "chat?${params.joinToString("&")}"
}
@@ -465,6 +476,7 @@ sealed class Screen(
data object MediaSettings : Screen("settings/media", "Media", Icons.Filled.Settings)
data object AppearanceSettings : Screen("settings/appearance", "Appearance", Icons.Filled.Settings)
data object PetdexBrowse : Screen("settings/appearance/petdex", "Petdex", Icons.Filled.Settings)
data object CustomPetGuide : Screen("settings/appearance/custom-pet", "Create a pet", Icons.Filled.Settings)
data object Analytics : Screen("settings/analytics", "Analytics", Icons.Filled.Settings)
data object Diagnostics : Screen("settings/diagnostics", "Diagnostics", Icons.Filled.Settings)
data object DeveloperSettings : Screen("settings/developer", "Developer", Icons.Filled.Settings)
@@ -612,21 +624,11 @@ fun RelayApp() {
val standardVoiceAvailability by connectionViewModel.standardVoiceAvailability.collectAsState()
val relayVoiceReady by connectionViewModel.relayVoiceReady.collectAsState()
// Profile Inspector client. Shares the same lazy relay URL + bearer
// token providers as the voice client so any rotation/re-pair is
// automatically picked up on the next fetch. Process-stable via
// remember {} so the OkHttpClient isn't rebuilt on recomposition.
val profileInspectorClient = remember {
RelayProfileInspectorClient(
okHttpClient = okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build(),
relayUrlProvider = { connectionViewModel.effectiveRelayUrl.value },
sessionTokenProvider = {
(connectionViewModel.authState.value as? AuthState.Paired)?.token
},
)
val profileInspectorHttpClient = remember {
okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build()
}
// === PHASE3-status: sync granular phone-status settings to chat ===
val appContextEnabled by connectionViewModel.appContextEnabled.collectAsState()
@@ -698,16 +700,20 @@ fun RelayApp() {
val appThemeId by connectionViewModel.appTheme.collectAsState()
val fontScale by connectionViewModel.fontScale.collectAsState()
val appFontId by connectionViewModel.appFont.collectAsState()
val appearanceAccent by connectionViewModel.appearanceAccent.collectAsState()
val appearanceShape by connectionViewModel.appearanceShape.collectAsState()
// Resolve the active sphere skin (built-in / adaptive / user-loaded) and
// publish it + the full available set so every MorphingSphere picks it up
// via LocalSphereSkin without per-call-site threading. Adaptive skins read
// the brand lazily inside MorphingSphere, so this can sit outside the theme.
val sphereSkinId by connectionViewModel.sphereSkin.collectAsState()
val appearanceAssetsRefreshTick by connectionViewModel.avatarsRefreshTick.collectAsState()
val sphereContext = androidx.compose.ui.platform.LocalContext.current
val availableSphereSkins by produceState(
initialValue = SphereRegistry.builtIns,
key1 = sphereContext,
key2 = appearanceAssetsRefreshTick,
) {
value = SphereRegistry.builtIns +
withContext(Dispatchers.IO) { SphereSkinLoader.loadUserSkins(sphereContext) }
@@ -720,14 +726,14 @@ fun RelayApp() {
)
}
// Ambient visualization and pet companionship are independent. Existing
// LocalAgentAvatar call sites keep rendering the sphere; a selected pet is
// published separately for the floating companion surface.
// Central/background visualization and pet companionship are independent.
// LocalAgentAvatar owns the central surfaces; LocalFloatingPet owns roaming.
val floatingPetId by connectionViewModel.floatingPet.collectAsState()
val backgroundAvatarId by connectionViewModel.backgroundAvatar.collectAsState()
// Re-scans the pets/ dir whenever the tick bumps (in-app import/delete, or the
// Appearance screen opening), so newly added/removed pets appear everywhere
// without an app restart.
val avatarsRefreshTick by connectionViewModel.avatarsRefreshTick.collectAsState()
val avatarsRefreshTick = appearanceAssetsRefreshTick
val availablePets by produceState(
initialValue = emptyList<AgentAvatar>(),
key1 = sphereContext,
@@ -738,6 +744,10 @@ fun RelayApp() {
val activeFloatingPet = remember(floatingPetId, availablePets) {
availablePets.firstOrNull { it.id == floatingPetId }
}
var floatingPetMenuExpanded by remember(activeFloatingPet?.id) { mutableStateOf(false) }
val activeBackgroundAvatar = remember(backgroundAvatarId, availablePets) {
resolveBackgroundAvatar(backgroundAvatarId, availablePets)
}
val petSpeed by connectionViewModel.petSpeed.collectAsState()
val petStabilize by connectionViewModel.petStabilize.collectAsState()
val petRoamingEnabled by connectionViewModel.petRoamingEnabled.collectAsState()
@@ -818,7 +828,7 @@ fun RelayApp() {
CompositionLocalProvider(
LocalSphereSkin provides activeSphereSkin,
LocalAvailableSphereSkins provides availableSphereSkins,
LocalAgentAvatar provides SphereAvatar,
LocalAgentAvatar provides activeBackgroundAvatar,
// Compatibility list for the existing Appearance picker during the
// transition; new companion UI consumes LocalAvailablePets.
LocalAvailableAvatars provides listOf(SphereAvatar) + availablePets,
@@ -831,11 +841,23 @@ fun RelayApp() {
LocalPetSafeAreaRegistry provides petSafeAreaRegistry,
LocalAgentIconPath provides agentIconPath,
) {
// Dialogs and modal sheets use their own focused window. Treat that
// focus handoff as an app-wide interaction layer so a dock-only pet on
// any route cannot remain visible beneath modal chrome.
PetInteractionLayer(
owner = "platform-modal-window",
active = platformModalOwnsPetLayer(
windowFocused = LocalWindowInfo.current.isWindowFocused,
petMenuExpanded = floatingPetMenuExpanded,
),
)
HermesRelayTheme(
appThemeId = appThemeId,
themePreference = themePreference,
fontScale = fontScale,
appFontId = appFontId,
accentHex = appearanceAccent,
shapeId = appearanceShape,
) {
// Surface a crash report from a previous session, if any. Renders a
// platform Dialog (own window) so tree position is z-order-agnostic;
@@ -1051,6 +1073,22 @@ fun RelayApp() {
val gatewayCurrentModel by chatViewModel.gatewayCurrentModel.collectAsState()
val appReady by connectionViewModel.isReady.collectAsState()
val initialChatSettled by chatViewModel.initialChatSettled.collectAsState()
// Android sharesheet handoff: wait until the configured chat context is
// settled, then ask ChatViewModel to own the new draft and composer
// prefill. Navigation is presentation-only; no composable writes chat
// stores or sends the shared text.
LaunchedEffect(navController, onboardingCompleted, initialChatSettled) {
if (!onboardingCompleted || !initialChatSettled) return@LaunchedEffect
com.hermesandroid.relay.util.SharedTextRequest.pending.collect { request ->
request ?: return@collect
if (chatViewModel.openSharedTextDraft(request.text)) {
navController.navigate(Screen.Chat.route(openAgentSheet = false)) {
launchSingleTop = true
}
com.hermesandroid.relay.util.SharedTextRequest.consume(request.id)
}
}
}
// The SAME readiness signal ChatScreen renders its "Connect Standard
// Hermes" CTA from (chat client exists + reachable verdict). The gate
// must release on this — releasing on the resolver's earlier
@@ -1653,13 +1691,18 @@ fun RelayApp() {
nullable = true
defaultValue = null
},
navArgument(Screen.Chat.ARG_PROACTIVE_CHAT_ID) {
type = NavType.StringType
nullable = true
defaultValue = null
},
),
) { backStackEntry ->
// Responsive bubble width based on screen width. The "Blend"
// chat look favors wider bubbles: on compact phones the cap is
// raised so long turns fill most of the row (binding on the
// available width minus the assistant avatar gutter) instead
// of wrapping early in a narrow column.
// raised so long turns fill most of the row instead of
// wrapping early in a narrow column. Assistant identity
// stays in the group header and does not reduce this cap.
val configuration = LocalConfiguration.current
val screenWidthDp = configuration.screenWidthDp.dp
val maxBubbleWidth = when {
@@ -1683,6 +1726,35 @@ fun RelayApp() {
val requestedProfileRoute = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROFILE)
?.takeIf { it.isNotBlank() }
val requestedProactiveChatId = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROACTIVE_CHAT_ID)
?.takeIf { it.isNotBlank() }
val proactiveInboxEntries by connectionViewModel.inboxMessages.collectAsState()
val phoneThreadChatIds by connectionViewModel.phoneThreadChatIds.collectAsState()
LaunchedEffect(
requestedProactiveChatId,
proactiveInboxEntries,
phoneThreadChatIds,
) {
val chatId = requestedProactiveChatId ?: return@LaunchedEffect
val realSessionId = phoneThreadChatIds.entries
.firstOrNull { it.value == chatId }
?.key
if (realSessionId != null) {
chatViewModel.switchSession(realSessionId)
} else {
val entries = proactiveInboxEntries.filter {
(it.connectionId == null || it.connectionId == activeConnectionId) &&
(it.chatId ?: "phone") == chatId
}
if (entries.isEmpty()) return@LaunchedEffect
chatViewModel.openProactiveThread(chatId, entries)
}
backStackEntry.arguments?.putString(
Screen.Chat.ARG_PROACTIVE_CHAT_ID,
null,
)
}
LaunchedEffect(
requestedSessionId,
requestedProfileRoute,
@@ -2475,6 +2547,7 @@ fun RelayApp() {
connectionViewModel = connectionViewModel,
onBack = { navController.popBackStack() },
onBrowsePetdex = { navController.navigate(Screen.PetdexBrowse.route) },
onCreatePet = { navController.navigate(Screen.CustomPetGuide.route) },
)
}
composable(Screen.PetdexBrowse.route) {
@@ -2483,6 +2556,20 @@ fun RelayApp() {
onBack = { navController.popBackStack() },
)
}
composable(Screen.CustomPetGuide.route) {
CustomPetGuideScreen(
connectionViewModel = connectionViewModel,
onBack = { navController.popBackStack() },
onStartNewChat = { prompt ->
chatViewModel.createNewChat()
chatViewModel.stageComposerDraft(prompt)
navController.navigate(Screen.Chat.route(openAgentSheet = false)) {
popUpTo(Screen.Chat.route) { inclusive = false }
launchSingleTop = true
}
},
)
}
composable(Screen.Analytics.route) {
AnalyticsScreen(
connectionViewModel = connectionViewModel,
@@ -2562,7 +2649,8 @@ fun RelayApp() {
val sectionArg = backStackEntry.arguments
?.getString(Screen.ProfileInspector.ARG_SECTION)
?: Screen.ProfileInspector.SECTION_CONFIG
if (coldStartAuthState !is AuthState.Paired) {
val inspectorGatewayClient = connectionViewModel.activeGatewayChatClient()
if (coldStartAuthState !is AuthState.Paired && inspectorGatewayClient == null) {
PowerFeatureGateScreen(
title = stringResource(R.string.screen_profile_inspector_label),
summary = stringResource(R.string.power_gate_profile_inspector_summary),
@@ -2590,8 +2678,18 @@ fun RelayApp() {
// SavedStateHandle contains our
// `profileName` arg automatically.
val ssh = extras.createSavedStateHandle()
// Freeze both transports to the connection that
// owned this nav entry. A later connection/profile
// switch cannot redirect an open editor's writes.
val relayUrl = connectionViewModel.effectiveRelayUrl.value
val relayToken = (connectionViewModel.authState.value as? AuthState.Paired)?.token
return ProfileInspectorViewModel(
client = profileInspectorClient,
legacyClient = RelayProfileInspectorClient(
okHttpClient = profileInspectorHttpClient,
relayUrlProvider = { relayUrl },
sessionTokenProvider = { relayToken },
),
gatewayClient = inspectorGatewayClient,
savedStateHandle = ssh,
) as T
}
@@ -2670,6 +2768,7 @@ fun RelayApp() {
onOpenAppearance = {
navController.navigate(Screen.AppearanceSettings.route) { launchSingleTop = true }
},
onMenuExpandedChanged = { floatingPetMenuExpanded = it },
onExitTerrainDebug = {
petTerrainOverlayScope.launch {
FeatureFlags.setPetTerrainOverlayEnabled(sphereContext, false)
@@ -1739,7 +1739,10 @@ fun ActiveCardRoutesSection(
var routeEditorOriginal by remember(connection.id) {
mutableStateOf<EndpointCandidate?>(null)
}
val hasTailscaleRoute = endpoints.any { it.role.equals("tailscale", ignoreCase = true) }
val hasTailscaleRoute = hasConfiguredTailscaleRoute(
endpoints = endpoints,
primaryEndpointUrl = connection.primaryEndpointUrl,
)
val tailscalePreferred = preferredRole?.equals("tailscale", ignoreCase = true) == true
val routeNeedsAttention = activeEndpoint == null && liveState != RelayUiState.Connected
val showTailscaleUnavailableHint =
@@ -2171,6 +2174,12 @@ fun ActiveCardRoutesSection(
}
}
internal fun hasConfiguredTailscaleRoute(
endpoints: List<EndpointCandidate>,
primaryEndpointUrl: String,
): Boolean = endpoints.any { it.role.equals("tailscale", ignoreCase = true) } ||
Connection.inferRouteRole(primaryEndpointUrl) == "tailscale"
/**
* Numbered step row for the Manual pairing code fallback. Tightly
* coupled to its Card 3 layout — step badge sizing + content shape —
@@ -1,15 +1,20 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.Image
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.padding
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.res.painterResource
import androidx.compose.ui.text.TextStyle
import androidx.compose.ui.unit.dp
import coil3.compose.AsyncImage
import com.hermesandroid.relay.R
import java.io.File
/**
@@ -28,6 +33,15 @@ fun AgentAvatarFace(name: String, letterStyle: TextStyle, modifier: Modifier = M
contentScale = ContentScale.Crop,
modifier = modifier.fillMaxSize(),
)
} else if (name.equals("Hermes", ignoreCase = true)) {
Image(
painter = painterResource(R.drawable.splash_icon),
contentDescription = null,
contentScale = ContentScale.Fit,
modifier = modifier
.fillMaxSize()
.padding(2.dp),
)
} else {
Box(modifier = modifier.fillMaxSize(), contentAlignment = Alignment.Center) {
Text(
@@ -332,7 +332,7 @@ private fun decodeGalleryBitmap(bytes: ByteArray): android.graphics.Bitmap? {
sample *= 2
}
val options = BitmapFactory.Options().apply { inSampleSize = sample }
return BitmapFactory.decodeByteArray(bytes, 0, bytes.size, options)
return decodeOrientedBitmap(bytes, options)
}
private const val GALLERY_COLUMNS = 2
@@ -4,7 +4,6 @@ package com.hermesandroid.relay.ui.components
import android.content.Context
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.pdf.PdfRenderer
import android.media.audiofx.Visualizer
import android.net.Uri
@@ -697,7 +696,7 @@ private fun ImageBody(
val decoded = withContext(Dispatchers.IO) {
runCatching {
val bytes = attachmentBytes(context, attachment)
bytes?.let { BitmapFactory.decodeByteArray(it, 0, it.size)?.asImageBitmap() }
bytes?.let { decodeOrientedBitmap(it)?.asImageBitmap() }
}.getOrNull()
}
if (decoded != null) bitmap = decoded else failed = true
@@ -304,10 +304,8 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
BitmapFactory.decodeByteArray(decoded.bytes, 0, decoded.bytes.size, bounds)
val sample = inlineImageSampleSize(bounds.outWidth, bounds.outHeight)
?: return@withInlineImageDecodeLock DataUrlImagePhase.Rejected
val bitmap = BitmapFactory.decodeByteArray(
val bitmap = decodeOrientedBitmap(
decoded.bytes,
0,
decoded.bytes.size,
BitmapFactory.Options().apply {
inSampleSize = sample
inPreferredConfig = android.graphics.Bitmap.Config.ARGB_8888
@@ -482,7 +480,7 @@ private fun RelayServerImage(
is ServerImageResult.Success -> {
val bytes = result.bytes
val bmp = runCatching {
BitmapFactory.decodeByteArray(bytes, 0, bytes.size)
decodeOrientedBitmap(bytes)
}.getOrNull()?.asImageBitmap()
if (bmp != null) {
putInlineImage(image.src, bmp, result.sensitive)
@@ -29,6 +29,8 @@ import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.BasicTextField
import androidx.compose.foundation.text.KeyboardActions
import androidx.compose.foundation.text.KeyboardOptions
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.Send
import androidx.compose.material.icons.filled.Add
@@ -58,8 +60,18 @@ import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.focus.FocusRequester
import androidx.compose.ui.focus.focusProperties
import androidx.compose.ui.graphics.SolidColor
import androidx.compose.ui.input.key.onPreviewKeyEvent
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.input.ImeAction
import androidx.compose.ui.text.input.KeyboardCapitalization
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
@@ -84,6 +96,7 @@ enum class ChatInputTrailing { SEND, VOICE, STOP, STEER, QUEUE }
private val ChatComposerShape = RoundedCornerShape(18.dp)
private val ChatInputChipShape = RoundedCornerShape(12.dp)
internal const val CHAT_INPUT_FIELD_TEST_TAG = "chat-input-field"
data class ChatInputPickerOption(
val label: String,
@@ -174,7 +187,14 @@ fun ChatInputBar(
modifier: Modifier = Modifier,
surfaceModifier: Modifier = Modifier,
enabled: Boolean = true,
physicalEnterSends: Boolean = true,
) {
val canSubmit = enabled && trailing in setOf(
ChatInputTrailing.SEND,
ChatInputTrailing.STEER,
ChatInputTrailing.QUEUE,
)
// Keep the last caption around so the AnimatedVisibility exit doesn't
// flash an empty line while collapsing.
var lastCaption by remember { mutableStateOf<String?>(null) }
@@ -203,18 +223,57 @@ fun ChatInputBar(
}
Column(modifier = modifier.fillMaxWidth()) {
// Caption row — correct/queue hinting, single line, no buttons.
// Correction and queueing are materially different actions. Keep the
// explanation, but lead with a visible state pill so the distinction
// does not depend on the trailing icon or accent color alone.
AnimatedVisibility(visible = caption != null) {
Text(
text = caption ?: lastCaption.orEmpty(),
style = relayMetadataStyle(),
color = if (trailing == ChatInputTrailing.STEER) {
MaterialTheme.colorScheme.tertiary.copy(alpha = 0.9f)
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
modifier = Modifier.padding(horizontal = 20.dp, vertical = 2.dp),
)
val detail = caption ?: lastCaption.orEmpty()
val actionLabel = when (trailing) {
ChatInputTrailing.STEER -> stringResource(R.string.chat_input_steer_response)
ChatInputTrailing.QUEUE -> stringResource(R.string.chat_input_queue_message)
else -> null
}
Row(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 20.dp, vertical = 2.dp)
.semantics {
liveRegion = LiveRegionMode.Polite
contentDescription = listOfNotNull(actionLabel, detail)
.joinToString(separator = ". ")
},
horizontalArrangement = Arrangement.spacedBy(8.dp),
verticalAlignment = Alignment.CenterVertically,
) {
if (actionLabel != null) {
Text(
text = actionLabel,
style = MaterialTheme.typography.labelSmall,
color = if (trailing == ChatInputTrailing.STEER) {
MaterialTheme.colorScheme.onTertiaryContainer
} else {
MaterialTheme.colorScheme.onSecondaryContainer
},
modifier = Modifier
.clip(RoundedCornerShape(999.dp))
.background(
if (trailing == ChatInputTrailing.STEER) {
MaterialTheme.colorScheme.tertiaryContainer
} else {
MaterialTheme.colorScheme.secondaryContainer
},
)
.padding(horizontal = 8.dp, vertical = 3.dp),
)
}
Text(
text = detail,
style = relayMetadataStyle(),
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
// Voice hint pill — floats above the trailing button.
@@ -290,9 +349,44 @@ fun ChatInputBar(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 34.dp)
.padding(horizontal = 8.dp, vertical = 4.dp),
.padding(horizontal = 8.dp, vertical = 4.dp)
// Keep directional keys inside the editor. Compose's
// BasicTextField owns normal caret/selection movement;
// cancelling focus traversal prevents a boundary arrow
// from jumping to a neighboring composer control.
.focusProperties {
left = FocusRequester.Cancel
right = FocusRequester.Cancel
up = FocusRequester.Cancel
down = FocusRequester.Cancel
}
.onPreviewKeyEvent { event ->
val native = event.nativeKeyEvent
val isEnter = native.keyCode == android.view.KeyEvent.KEYCODE_ENTER ||
native.keyCode == android.view.KeyEvent.KEYCODE_NUMPAD_ENTER
val isSubmitShortcut = native.isCtrlPressed || native.isMetaPressed
if (native.action != android.view.KeyEvent.ACTION_DOWN || !isEnter) {
false
} else if (isSubmitShortcut || (physicalEnterSends && !native.isShiftPressed)) {
if (canSubmit) onSend()
true
} else {
// Shift+Enter always inserts a newline. When
// Enter is configured for newlines, the plain
// key also stays owned by BasicTextField.
false
}
}
.testTag(CHAT_INPUT_FIELD_TEST_TAG),
maxLines = 5,
enabled = enabled,
keyboardOptions = KeyboardOptions(
capitalization = KeyboardCapitalization.Sentences,
imeAction = ImeAction.Send,
),
keyboardActions = KeyboardActions(
onSend = { if (canSubmit) onSend() },
),
textStyle = MaterialTheme.typography.bodyLarge.copy(
color = MaterialTheme.colorScheme.onSurface,
),
@@ -314,7 +408,7 @@ fun ChatInputBar(
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 40.dp),
.heightIn(min = 48.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
@@ -324,7 +418,7 @@ fun ChatInputBar(
Box {
Box(
modifier = Modifier
.size(38.dp)
.size(48.dp)
.clip(CircleShape)
.combinedClickable(
onClick = { attachMenuExpanded = true },
@@ -0,0 +1,122 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.ColorScheme
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ChatQuoteReference
internal data class ChatQuoteReferenceColors(
val background: Color,
val author: Color,
val excerpt: Color,
val accent: Color,
)
internal fun chatQuoteReferenceColors(colorScheme: ColorScheme) = ChatQuoteReferenceColors(
background = colorScheme.surfaceContainerHigh,
author = colorScheme.onSurface,
excerpt = colorScheme.onSurfaceVariant,
accent = colorScheme.primary,
)
/** Attachment-like quote reference used in both the composer and sent bubbles. */
@Composable
fun ChatQuoteReferenceChip(
reference: ChatQuoteReference,
modifier: Modifier = Modifier,
onOpenOriginal: (() -> Unit)? = null,
onRemove: (() -> Unit)? = null,
) {
val openDescription = stringResource(R.string.chat_quote_open, reference.authorLabel)
val colors = chatQuoteReferenceColors(MaterialTheme.colorScheme)
Surface(
modifier = modifier.fillMaxWidth(),
shape = RoundedCornerShape(8.dp),
color = colors.background,
) {
Row(
modifier = Modifier
.then(
onOpenOriginal?.let { open ->
Modifier.clickable(
role = Role.Button,
onClickLabel = openDescription,
onClick = open,
)
} ?: Modifier,
)
.semantics { contentDescription = "$openDescription. ${reference.excerpt}" }
.padding(start = 7.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Box(
modifier = Modifier
.width(3.dp)
.height(32.dp)
.clip(RoundedCornerShape(99.dp))
.background(colors.accent),
)
Column(
modifier = Modifier
.weight(1f)
.padding(horizontal = 8.dp, vertical = 5.dp),
) {
Text(
text = "@${reference.authorLabel}",
style = MaterialTheme.typography.labelMedium,
fontWeight = FontWeight.Medium,
color = colors.author,
)
Text(
text = reference.excerpt,
style = MaterialTheme.typography.labelSmall,
color = colors.excerpt,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
}
if (onRemove != null) {
IconButton(
onClick = onRemove,
modifier = Modifier.size(48.dp),
) {
Icon(
imageVector = Icons.Filled.Close,
contentDescription = stringResource(R.string.chat_quote_remove),
tint = colors.excerpt,
modifier = Modifier.size(18.dp),
)
}
}
}
}
}
@@ -64,6 +64,10 @@ data class SlashCommand(
* instead of plain text.
*/
val source: String? = null,
/** Bounded server-recorded skill usage; zero for non-skill commands. */
val usageRank: Int = 0,
/** Sanitized server skill origin such as local or bundled. */
val origin: String? = null,
) {
companion object {
const val SOURCE_SERVER = "server"
@@ -684,7 +684,6 @@ fun RelayInfoSheet(
// the Profile section footer spells out the override.
private enum class AgentPassportPicker {
Profile,
Personality,
Model,
Reasoning,
@@ -762,6 +761,7 @@ fun AgentInfoSheet(
var selectedTab by remember { mutableStateOf(0) }
var activePicker by remember { mutableStateOf<AgentPassportPicker?>(null) }
var showProfileSwitcher by remember { mutableStateOf(false) }
var showIdentityEditor by remember { mutableStateOf(false) }
var showProfileManager by remember { mutableStateOf(false) }
@@ -771,6 +771,20 @@ fun AgentInfoSheet(
val currentSession = remember(sessions, currentSessionId) {
sessions.firstOrNull { it.sessionId == currentSessionId }
}
val sessionModelState = resolveSessionModelUiState(
hasSession = currentSessionId != null,
pendingModel = selectedModel,
pendingProvider = selectedProvider,
gatewayModel = gatewayModel,
gatewayProvider = gatewayProvider,
persistedSessionModel = currentSession?.model,
profileDefaultModel = resolvedProfile?.model,
serverDefaultModel = serverModel,
)
val sessionPickerProvider = sessionModelState.pickerProvider
?: sessionModelState.pickerModel?.let { model ->
modelProviders.singleOrNull { model in it.models }?.slug
}
val agentName = AgentDisplay.agentName(
profile = resolvedProfile,
selectedPersonality = selectedPersonality,
@@ -782,25 +796,22 @@ fun AgentInfoSheet(
AgentDisplay.profileDisplayName(it) ?: it.name
} ?: stringResource(R.string.conn_info_server_default)
val serverDefaultLabel = stringResource(R.string.conn_info_server_default)
val modelLabel = AgentDisplay.displayModelName(selectedModel ?: gatewayModel)
?: AgentDisplay.displayModelName(resolvedProfile?.model)
?: AgentDisplay.displayModelName(serverModel)
val modelLabel = AgentDisplay.displayModelName(sessionModelState.model)
?: serverDefaultLabel
val serverDefaultModelLabel = AgentDisplay.displayModelName(serverModel)
?: AgentDisplay.displayModelName(resolvedProfile?.model)
val providerLabel = modelProviders
.firstOrNull { it.slug.equals(gatewayProvider, ignoreCase = true) }
.firstOrNull { it.slug.equals(sessionModelState.provider, ignoreCase = true) }
?.name
?.takeIf { it.isNotBlank() }
?: gatewayProvider.takeIf { it.isNotBlank() }
val sessionModelLabel = AgentDisplay.displayModelName(currentSession?.model)
?: modelLabel
val sessionProviderLabel = currentSession?.model
?: sessionModelState.provider
val sessionModelLabel = modelLabel
val sessionProviderLabel = sessionModelState.model
?.takeIf { it.isNotBlank() }
?.let { sessionModel ->
modelProviders.firstOrNull { sessionModel in it.models }?.name
}
?: providerLabel.takeIf { currentSession?.model.isNullOrBlank() }
?: providerLabel
val connected = chatReady
val resolvedPresence = resolvedProfile?.let {
ProfilePresenceResolver.resolve(it, connected)
@@ -851,6 +862,8 @@ fun AgentInfoSheet(
agentProfiles,
selectedModel,
selectedProvider,
sessionModelState,
sessionPickerProvider,
modelLabel,
unavailableModelLabel,
modelNeedsSetupLabel,
@@ -871,7 +884,7 @@ fun AgentInfoSheet(
label = serverDefaultLabel,
value = null,
secondary = serverDefaultModelLabel,
selected = selectedModel == null,
selected = sessionModelState.inheritsProfileDefault,
),
)
modelProviders
@@ -891,8 +904,8 @@ fun AgentInfoSheet(
provider.warning ?: modelNeedsSetupLabel
else -> null
},
selected = selectedModel == model &&
selectedProvider.equals(provider.slug, ignoreCase = true),
selected = sessionModelState.pickerModel == model &&
sessionPickerProvider.equals(provider.slug, ignoreCase = true),
enabled = !unavailable,
),
)
@@ -908,7 +921,7 @@ fun AgentInfoSheet(
value = model.id,
group = "Routes",
secondary = model.routeDetail,
selected = selectedModel == model.id,
selected = sessionModelState.pickerModel == model.id,
),
)
}
@@ -916,10 +929,10 @@ fun AgentInfoSheet(
}
LaunchedEffect(Unit) {
chatViewModel.refreshModelOptions()
chatViewModel.refreshModelOptions(catalogOnly = true)
chatViewModel.refreshApprovalMode()
chatViewModel.refreshPersonalities()
chatViewModel.refreshModels()
chatViewModel.refreshModels(catalogOnly = true)
connectionViewModel.refreshDashboardProfiles()
}
@@ -945,10 +958,7 @@ fun AgentInfoSheet(
presence = resolvedPresence,
hasSoul = resolvedProfile?.hasSoul == true,
skillCount = resolvedProfile?.skillCount ?: 0,
transportLabel = transportFriendlyName(sessionTransport.type),
sessionLabel = currentSessionId?.take(8) ?: "—",
contextLabel = contextLabel,
onProfileClick = { activePicker = AgentPassportPicker.Profile },
onProfileClick = { showProfileSwitcher = true },
)
if (showIdentityEditor) {
@@ -982,7 +992,7 @@ fun AgentInfoSheet(
) {
Column {
Text(
text = stringResource(R.string.conn_info_active_configuration),
text = stringResource(R.string.conn_info_session_title),
modifier = Modifier.padding(
start = 18.dp,
top = 17.dp,
@@ -992,25 +1002,13 @@ fun AgentInfoSheet(
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
)
PassportConfigRow(
icon = Icons.Filled.Person,
title = stringResource(R.string.conn_info_personality_title),
value = AgentDisplay.personalityLabel(
selectedPersonality,
defaultPersonality,
),
expanded = false,
enabled = !isStreaming,
onClick = { activePicker = AgentPassportPicker.Personality },
)
PassportDivider()
PassportConfigRow(
icon = Icons.Filled.ViewInAr,
title = stringResource(R.string.conn_info_model_title),
value = selectedModel ?: if (modelLabel == serverDefaultLabel) {
serverDefaultLabel
} else {
value = if (sessionModelState.inheritsProfileDefault) {
stringResource(R.string.conn_info_server_default_model, modelLabel)
} else {
modelLabel
},
expanded = false,
enabled = !isStreaming,
@@ -1034,6 +1032,44 @@ fun AgentInfoSheet(
}
}
// Upstream personality changes persist to the active profile
// while also applying to the live session. Keep that control
// visibly separate from the session-only model/effort card so
// it cannot be mistaken for an ephemeral override.
Surface(
shape = RoundedCornerShape(22.dp),
color = MaterialTheme.colorScheme.surfaceContainer,
border = androidx.compose.foundation.BorderStroke(
1.dp,
MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.55f),
),
) {
Column {
Text(
text = stringResource(R.string.conn_info_profile),
modifier = Modifier.padding(
start = 18.dp,
top = 17.dp,
end = 18.dp,
bottom = 4.dp,
),
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
)
PassportConfigRow(
icon = Icons.Filled.Person,
title = stringResource(R.string.conn_info_personality_title),
value = AgentDisplay.personalityLabel(
selectedPersonality,
defaultPersonality,
),
expanded = false,
enabled = !isStreaming,
onClick = { activePicker = AgentPassportPicker.Personality },
)
}
}
AgentPassportSafetyCard(
approvalMode = approvalMode,
approvalCapability = approvalCapability,
@@ -1155,49 +1191,6 @@ fun AgentInfoSheet(
}
when (activePicker) {
AgentPassportPicker.Profile -> {
val selectedProfileKey = AgentDisplay.profileSessionKey(selectedProfile?.name)
val visibleProfileKeys = ProfilePresentationPolicy.visibleKeys(
profiles = agentProfiles,
presentation = profilePresentation,
selectedKey = selectedProfileKey,
)
val options = visibleProfileKeys.mapNotNull { profileKey ->
if (profileKey == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY) {
ChatInputPickerOption(
label = serverDefaultLabel,
value = null,
secondary = AgentDisplay.profileDisplayName(resolvedProfile),
selected = selectedProfile == null,
enabled = !isProfileLocked && profileSwitchEnabled,
)
} else {
agentProfiles.firstOrNull { it.name == profileKey }?.let { profile ->
ChatInputPickerOption(
label = AgentDisplay.profileDisplayName(profile)
?: profile.name.replaceFirstChar { it.uppercase() },
value = profile.name,
secondary = profile.model.takeIf { it.isNotBlank() },
selected = selectedProfile?.name == profile.name,
enabled = !isProfileLocked && profileSwitchEnabled,
)
}
}
}
OptionPickerSheet(
title = stringResource(R.string.conn_info_profile),
options = options,
onSelect = { option ->
val profile = option.value?.let { name ->
agentProfiles.firstOrNull { it.name == name }
}
connectionViewModel.selectProfile(profile)
chatViewModel.activateGatewayProfile(profile)
activePicker = null
},
onDismiss = { activePicker = null },
)
}
AgentPassportPicker.Personality -> OptionPickerSheet(
title = stringResource(R.string.conn_info_personality_title),
options = buildList {
@@ -1228,7 +1221,9 @@ fun AgentInfoSheet(
AgentPassportPicker.Model -> ModelPickerSheet(
options = passportModelOptions,
refreshing = modelOptionsRefreshing,
onRefresh = { chatViewModel.refreshModelOptions(refresh = true) },
onRefresh = {
chatViewModel.refreshModelOptions(refresh = true, catalogOnly = true)
},
onSelect = { option ->
activePicker = null
if (option.provider == null && apiModelOptions.any { it.id == option.value }) {
@@ -1274,6 +1269,31 @@ fun AgentInfoSheet(
null -> Unit
}
if (showProfileSwitcher) {
ProfileSwitcherSheet(
connectionViewModel = connectionViewModel,
profiles = agentProfiles,
selectedProfile = selectedProfile,
resolvedProfile = resolvedProfile,
presentation = profilePresentation,
isProfileLocked = isProfileLocked,
switchEnabled = profileSwitchEnabled,
onSelect = { profile ->
if (AgentDisplay.profileSessionKey(profile?.name) !=
AgentDisplay.profileSessionKey(selectedProfile?.name)
) {
connectionViewModel.selectProfile(profile)
chatViewModel.activateGatewayProfile(profile)
}
},
onManageDisplay = {
showProfileSwitcher = false
showProfileManager = true
},
onDismiss = { showProfileSwitcher = false },
)
}
if (showProfileManager) {
ProfileDisplayManagerDialog(
profiles = agentProfiles,
@@ -1303,11 +1323,11 @@ internal fun AgentPassportSheetHost(
ModalBottomSheet(
onDismissRequest = onDismiss,
sheetState = sheetState,
// Use Material's gesture owner instead of custom pointer input. The
// verticalScroll child consumes downward movement until its top
// boundary, then hands the remainder to the sheet; Material also
// follows the platform animator scale for reduced-motion users.
sheetGesturesEnabled = true,
// A full-height sheet and its long verticalScroll child otherwise
// compete for the same drag at the content boundaries. On some devices
// that repeatedly settles/re-expands the sheet and produces a visible
// vibration at the bottom. Close and system Back remain explicit.
sheetGesturesEnabled = false,
) {
Column(
modifier = Modifier
@@ -1441,9 +1461,6 @@ private fun AgentPassportHeader(
presence: ProfilePresence?,
hasSoul: Boolean,
skillCount: Int,
transportLabel: String,
sessionLabel: String,
contextLabel: String,
onProfileClick: () -> Unit,
) {
val brand = LocalBrand.current
@@ -1461,18 +1478,9 @@ private fun AgentPassportHeader(
}
}
val identityMetadata = listOfNotNull(
providerLabel,
stringResource(R.string.conn_info_soul).takeIf { hasSoul },
stringResource(R.string.conn_info_skills_count, skillCount).takeIf { skillCount > 0 },
).joinToString(" · ")
val connectionValue = listOf(
transportLabel,
if (connected) {
stringResource(R.string.conn_info_connected)
} else {
stringResource(R.string.conn_info_disconnected)
},
).joinToString(" · ")
Surface(
shape = RoundedCornerShape(24.dp),
color = MaterialTheme.colorScheme.surfaceContainer,
@@ -1565,7 +1573,7 @@ private fun AgentPassportHeader(
) {
Column(modifier = Modifier.padding(horizontal = 14.dp, vertical = 10.dp)) {
Text(
text = stringResource(R.string.conn_info_active_profile).uppercase(),
text = stringResource(R.string.profile_shelf_switch_agent).uppercase(),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
@@ -1607,40 +1615,17 @@ private fun AgentPassportHeader(
}
}
HorizontalDivider(color = MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.5f))
Row(modifier = Modifier.fillMaxWidth()) {
PassportTechnicalField(
label = stringResource(R.string.conn_info_model_title),
value = modelLabel,
modifier = Modifier.weight(1f),
)
PassportTechnicalDivider(height = 44.dp)
PassportTechnicalField(
label = stringResource(R.string.conn_info_connection),
value = connectionValue,
valueColor = if (connected) brand.green else MaterialTheme.colorScheme.error,
modifier = Modifier.weight(1f),
)
}
HorizontalDivider(color = MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.5f))
Row(modifier = Modifier.fillMaxWidth()) {
PassportTechnicalField(
label = stringResource(R.string.conn_info_session_title),
value = sessionLabel,
modifier = Modifier.weight(1f),
)
PassportTechnicalDivider(height = 42.dp)
PassportTechnicalField(
label = stringResource(R.string.conn_info_context),
value = contextLabel,
modifier = Modifier.weight(1f),
)
PassportTechnicalDivider(height = 42.dp)
PassportTechnicalField(
label = stringResource(R.string.conn_info_transport),
value = transportLabel,
modifier = Modifier.weight(1f),
)
}
PassportTechnicalField(
label = stringResource(R.string.voice_test_label_provider),
value = providerLabel ?: "—",
modifier = Modifier.fillMaxWidth(),
)
PassportTechnicalField(
label = stringResource(R.string.conn_info_model_title),
value = modelLabel,
modifier = Modifier.fillMaxWidth(),
maxLines = 2,
)
}
}
}
@@ -1651,6 +1636,7 @@ private fun PassportTechnicalField(
value: String,
modifier: Modifier = Modifier,
valueColor: Color = MaterialTheme.colorScheme.onSurface,
maxLines: Int = 1,
) {
Column(
modifier = modifier.padding(horizontal = 8.dp),
@@ -1666,22 +1652,12 @@ private fun PassportTechnicalField(
text = value,
style = MaterialTheme.typography.labelLarge,
color = valueColor,
maxLines = 1,
maxLines = maxLines,
overflow = TextOverflow.Ellipsis,
)
}
}
@Composable
private fun PassportTechnicalDivider(height: Dp) {
Box(
modifier = Modifier
.height(height)
.widthIn(min = 1.dp, max = 1.dp)
.background(MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.5f)),
)
}
@Composable
private fun AgentPassportTabs(
selected: Int,
@@ -2290,7 +2266,7 @@ private fun LegacyAgentInfoSheet(
// Pull the gateway's curated provider/model list (model.options) when the
// sheet opens — the real switchable models, grouped by provider.
LaunchedEffect(Unit) { chatViewModel.refreshModelOptions() }
LaunchedEffect(Unit) { chatViewModel.refreshModelOptions(catalogOnly = true) }
LaunchedEffect(Unit) { chatViewModel.refreshApprovalMode() }
// Re-pull server-supplied personalities (list + default + active) on open so
// a server-side change shows without an app reload.
@@ -2298,7 +2274,7 @@ private fun LegacyAgentInfoSheet(
// Re-pull the SSE-fallback model list + skill catalog on open so server-side
// changes surface without an app reload (gateway model groups are covered by
// refreshModelOptions above; skills feed the command palette).
LaunchedEffect(Unit) { chatViewModel.refreshModels() }
LaunchedEffect(Unit) { chatViewModel.refreshModels(catalogOnly = true) }
LaunchedEffect(Unit) { chatViewModel.refreshSkills() }
// Pull the host's agent profiles from the dashboard so they appear in the
// Profile picker even on a dashboard-only (non-relay) connection.
@@ -2503,7 +2479,7 @@ private fun LegacyAgentInfoSheet(
// "default" so "Server default" vs "default" would be
// otherwise indistinguishable.
val serverDefaultProfile = agentProfiles
.firstOrNull { AgentDisplay.isServerDefaultAlias(it.name) }
.firstOrNull { it.name.equals("default", ignoreCase = true) }
val selectedKey = AgentDisplay.profileSessionKey(selectedProfile?.name)
val visibleProfileKeys = ProfilePresentationPolicy
.visibleKeys(agentProfiles, profilePresentation, selectedKey)
@@ -2526,8 +2502,7 @@ private fun LegacyAgentInfoSheet(
val lockedDisplayName = when {
lockedProfileName == null ->
stringResource(R.string.conn_info_server_default)
AgentDisplay.isServerDefaultAlias(lockedProfileName) ||
lockedProfileName == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY ->
lockedProfileName == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY ->
stringResource(R.string.conn_info_server_default)
else ->
agentProfiles
@@ -3615,7 +3590,7 @@ private fun LegacyAgentInfoSheet(
// --- AgentInfoSheet helpers ----------------------------------------------
@Composable
private fun ProfileDisplayManagerDialog(
internal fun ProfileDisplayManagerDialog(
profiles: List<Profile>,
presentation: ProfilePresentation,
selectedProfileName: String?,
@@ -105,6 +105,11 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.ConnectionValidation
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.presentationRouteUrl
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.network.shared.HermesLanDiscovery
import com.hermesandroid.relay.network.shared.HermesLanDiscoveryResult
@@ -3174,7 +3179,7 @@ private fun ConfirmStep(
// app auto-falls back to the secure one, so a blanket "Insecure (dev)"
// badge from endpoint[0] alone would lie to the user.
val anySecure = endpoints.any { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}
@@ -3195,7 +3200,7 @@ private fun ConfirmStep(
// Mixed case ("Tailscale is encrypted..." vs "Public is encrypted...").
val firstSecureLabel = endpoints
.firstOrNull { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}?.displayLabel()
@@ -3208,6 +3213,7 @@ private fun ConfirmStep(
val distinctRoles = endpoints.map { it.role }.distinct()
var preferRole by remember(payload) { mutableStateOf<String?>(null) }
var preferMenuOpen by remember { mutableStateOf(false) }
val secureLink = endpoints.firstOrNull { it.hasSecureProxy() }
Column(
verticalArrangement = Arrangement.spacedBy(14.dp),
@@ -3318,6 +3324,15 @@ private fun ConfirmStep(
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
secureLink?.let { route ->
SecureLinkPairingSummary(
services = route.secureLinkServices(),
complete = route.secureLinkCoversAllServices(),
hasFallback = endpoints.size > 1,
usesReach = route.hasHermesReach(),
)
HorizontalDivider()
}
endpoints.forEachIndexed { index, candidate ->
if (index > 0) HorizontalDivider()
EndpointPreviewRow(
@@ -3720,7 +3735,7 @@ private fun EndpointPreviewRow(
) {
// Per-row security derived from the same three signals as the overall
// securityState computation — scheme, tls flag, transportHint.
val isSecure = candidate.relay?.url?.startsWith("wss://") == true ||
val isSecure = candidate.hasSecureProxy() || candidate.relay?.url?.startsWith("wss://") == true ||
candidate.api?.tls == true ||
candidate.relay?.transportHint.equals("wss", ignoreCase = true) ||
candidate.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
@@ -3756,7 +3771,7 @@ private fun EndpointPreviewRow(
}
}
Text(
text = candidate.primaryRouteUrl().orEmpty() +
text = candidate.presentationRouteUrl().orEmpty() +
(candidate.relay?.transportHint?.let { " \u00b7 $it" } ?: ""),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
@@ -3772,6 +3787,75 @@ private fun EndpointPreviewRow(
}
}
@Composable
private fun SecureLinkPairingSummary(
services: List<String>,
complete: Boolean,
hasFallback: Boolean,
usesReach: Boolean,
) {
val relayLabel = stringResource(R.string.secure_link_service_relay)
val apiLabel = stringResource(R.string.secure_link_service_api)
val dashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val serviceText = services.map { service ->
when (service) {
"relay" -> relayLabel
"api" -> apiLabel
"dashboard" -> dashboardLabel
else -> service
}
}.joinToString(" · ")
Surface(
color = MaterialTheme.colorScheme.primary.copy(alpha = 0.08f),
shape = RoundedCornerShape(12.dp),
) {
Column(
modifier = Modifier.fillMaxWidth().padding(12.dp),
verticalArrangement = Arrangement.spacedBy(4.dp),
) {
Text(
stringResource(if (usesReach) R.string.hermes_reach_title else R.string.secure_link_title),
style = MaterialTheme.typography.titleSmall,
)
if (usesReach) {
Text(
stringResource(R.string.hermes_reach_summary),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
stringResource(R.string.secure_link_pinned_tls),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.primary,
)
Text(
if (serviceText.isBlank()) stringResource(R.string.secure_link_no_services)
else stringResource(R.string.secure_link_protects, serviceText),
style = MaterialTheme.typography.bodySmall,
)
if (!complete) {
Text(
stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
if (hasFallback) stringResource(R.string.secure_link_fallback_ready)
else stringResource(R.string.secure_link_no_fallback),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
/**
* Compact pill used by [EndpointPreviewRow] — matches the "Preferred" soft
* chip style so the row reads as a row of related chips rather than a mix
@@ -57,6 +57,9 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.SurfaceSecurityKind
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.isEncryptedOverlayRoute
import com.hermesandroid.relay.data.isKnownRole
import com.hermesandroid.relay.data.isTlsUrl
@@ -323,6 +326,9 @@ private fun EndpointRow(
val apiLabel = stringResource(R.string.active_section_api_server)
val relayLabel = stringResource(R.string.active_section_relay)
val surfaceSummary = listOfNotNull(
candidate.proxy?.takeIf { candidate.hasSecureProxy() }?.let {
stringResource(R.string.secure_link_pinned_tls_short)
},
dashboardSurfaceUrl?.let { "$dashboardLabel ${displayPort(it)}" },
candidate.api?.url?.let { "$apiLabel ${displayPort(it)}" },
candidate.relay?.url?.let { "$relayLabel ${displayPort(it)}" },
@@ -357,6 +363,36 @@ private fun EndpointRow(
)
}
}
if (candidate.hasSecureProxy()) {
val secureRelayLabel = stringResource(R.string.secure_link_service_relay)
val secureApiLabel = stringResource(R.string.secure_link_service_api)
val secureDashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val services = candidate.secureLinkServices().map { service ->
when (service) {
"relay" -> secureRelayLabel
"api" -> secureApiLabel
"dashboard" -> secureDashboardLabel
else -> service
}
}.joinToString(" · ")
Text(
text = stringResource(R.string.secure_link_protects, services),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
if (!candidate.secureLinkCoversAllServices()) {
Text(
text = stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
text = stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
// 3-dot overflow menu — actions per-row so the card stays flat
@@ -680,6 +716,7 @@ private fun roleIcon(role: String): ImageVector = when (role.lowercase()) {
* be classified independently before it's the active route.
*/
private fun EndpointCandidate.routeSecurityKind(): SurfaceSecurityKind = when {
hasSecureProxy() -> SurfaceSecurityKind.Tls
isTlsUrl(primaryRouteUrl().orEmpty()) -> SurfaceSecurityKind.Tls
isEncryptedOverlayRoute(isTailscaleDetected = false) -> SurfaceSecurityKind.Overlay
else -> SurfaceSecurityKind.Plain
@@ -19,6 +19,7 @@ import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.CompositionLocalProvider
import androidx.compose.runtime.DisposableEffect
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.key
@@ -319,6 +320,31 @@ internal fun shouldDockFloatingPet(
roamingAllowed: Boolean,
): Boolean = !roamingEnabled || !roamingAllowed
/**
* Chat gives a deliberately paused companion one stable home: the live
* composer rail. Other routes retain the user's saved free-form edge home, and
* active roaming keeps its richer settled-chat habitat hierarchy.
*/
internal fun floatingPetHomePoint(
route: String?,
roamingEnabled: Boolean,
roamingAllowed: Boolean,
manualHomePoint: PetPoint,
roamingHomePoint: PetPoint?,
pausedChatDockPoint: PetPoint?,
): PetPoint = when {
route == "chat" && roamingAllowed && !roamingEnabled && pausedChatDockPoint != null -> {
pausedChatDockPoint
}
roamingEnabled && roamingAllowed -> roamingHomePoint ?: manualHomePoint
else -> manualHomePoint
}
internal fun floatingPetAllowsVerticalMoveActions(
route: String?,
roamingEnabled: Boolean,
): Boolean = route != "chat" || roamingEnabled
internal fun petRailSupportingPoint(
rails: Iterable<PetRoamingRail>,
point: PetPoint,
@@ -465,10 +491,19 @@ fun FloatingPetCompanion(
onResetPlacement: () -> Unit,
onHide: () -> Unit,
onOpenAppearance: () -> Unit,
onMenuExpandedChanged: (Boolean) -> Unit = {},
onExitTerrainDebug: () -> Unit = {},
modifier: Modifier = Modifier,
) {
var menuExpanded by remember(pet.id) { mutableStateOf(false) }
val latestOnMenuExpandedChanged by rememberUpdatedState(onMenuExpandedChanged)
fun setMenuExpanded(expanded: Boolean) {
menuExpanded = expanded
onMenuExpandedChanged(expanded)
}
DisposableEffect(pet.id) {
onDispose { latestOnMenuExpandedChanged(false) }
}
var dragging by remember(pet.id) { mutableStateOf(false) }
var draggedPoint by remember(pet.id) { mutableStateOf<PetPoint?>(null) }
var pendingDrop by remember(pet.id) { mutableStateOf<PendingPetDrop?>(null) }
@@ -834,30 +869,47 @@ fun FloatingPetCompanion(
val requested = placement.sanitized().resolve(safeBounds, petLayoutDirection)
projectIntoSafeBounds(requested, safeBounds, registeredObstacles) ?: requested
}
val homeRail = remember(roamingRails, manualHomePoint, settledHabitat) {
val composerHomeRail = remember(composerRails, manualHomePoint) {
val distanceToHome: (PetRoamingRail) -> Float = { rail ->
rail.bounds.clamp(manualHomePoint).distanceSquaredTo(manualHomePoint)
}
composerRails.minByOrNull(distanceToHome)
}
val homeRail = remember(roamingRails, manualHomePoint, settledHabitat, composerHomeRail) {
val distanceToHome: (PetRoamingRail) -> Float = { rail ->
rail.bounds.clamp(manualHomePoint).distanceSquaredTo(manualHomePoint)
}
settledHabitat?.rail
?: roamingRails.filter { it.perchKey == CHAT_PET_WALK_REGION }.minByOrNull(distanceToHome)
?: composerHomeRail
?: roamingRails.minByOrNull(distanceToHome)
}
fun pointAtPlacementEdge(rail: PetSafeBounds): PetPoint {
val xAtEdge = if (
(placement.edge == PetLogicalEdge.Start) == (petLayoutDirection == PetLayoutDirection.Ltr)
) rail.left else rail.right
return PetPoint(xAtEdge, rail.top)
}
val roamingHomePoint = remember(placement.edge, homeRail, petLayoutDirection) {
homeRail?.bounds?.let { rail ->
homeRail?.bounds?.let(::pointAtPlacementEdge)
}
val pausedChatDockPoint = remember(placement.edge, composerHomeRail, petLayoutDirection) {
composerHomeRail?.bounds?.let { rail ->
val xAtEdge = if (
(placement.edge == PetLogicalEdge.Start) == (petLayoutDirection == PetLayoutDirection.Ltr)
) rail.left else rail.right
PetPoint(xAtEdge, rail.top)
}
}
// Enabling roaming explicitly docks onto the screen-owned safe rail. A
// manual drag or vertical accessibility action pauses roaming first, so the
// persisted free-form placement remains visible and authoritative.
val homePoint = if (roamingEnabled && roamingAllowed) {
roamingHomePoint ?: manualHomePoint
} else {
manualHomePoint
}
// Active roaming uses screen-owned terrain. Paused Chat deliberately uses
// the composer rail; other routes retain the persisted free-form edge home.
val homePoint = floatingPetHomePoint(
route = route,
roamingEnabled = roamingEnabled,
roamingAllowed = roamingAllowed,
manualHomePoint = manualHomePoint,
roamingHomePoint = roamingHomePoint,
pausedChatDockPoint = pausedChatDockPoint,
)
val heldProgress by animateFloatAsState(
targetValue = if (dragging) 1f else 0f,
@@ -1606,7 +1658,7 @@ fun FloatingPetCompanion(
// Chat roaming owns a measured composer rail. Publishing before that rail
// exists lets initialization race route registration and can strand the
// pet on transient fallback geometry until direct manipulation.
val initialTerrainReady = route != "chat" || !roamingEnabled || !roamingAllowed ||
val initialTerrainReady = route != "chat" || !roamingAllowed ||
composerRails.isNotEmpty()
LaunchedEffect(
pet.id,
@@ -2350,31 +2402,43 @@ fun FloatingPetCompanion(
enabled = floatingPetAcceptsPointerInput(positioned, surfaceScrolling),
) {
tapReactionNonce += 1
menuExpanded = true
setMenuExpanded(true)
}
.semantics(mergeDescendants = true) {
role = Role.Button
contentDescription = companionDescription
stateDescription = stateLabel
customActions = listOf(
CustomAccessibilityAction(moveStartLabel) {
customActions = buildList {
add(CustomAccessibilityAction(moveStartLabel) {
onPlacementChanged(placement.copy(edge = PetLogicalEdge.Start)); true
},
CustomAccessibilityAction(moveEndLabel) {
})
add(CustomAccessibilityAction(moveEndLabel) {
onPlacementChanged(placement.copy(edge = PetLogicalEdge.End)); true
},
CustomAccessibilityAction(moveUpLabel) {
if (roamingEnabled) onRoamingEnabledChanged(false)
onPlacementChanged(placement.copy(verticalFraction = placement.verticalFraction - 0.15f)); true
},
CustomAccessibilityAction(moveDownLabel) {
if (roamingEnabled) onRoamingEnabledChanged(false)
onPlacementChanged(placement.copy(verticalFraction = placement.verticalFraction + 0.15f)); true
},
CustomAccessibilityAction(resetLabel) { onResetPlacement(); true },
CustomAccessibilityAction(appearanceLabel) { onOpenAppearance(); true },
CustomAccessibilityAction(hideLabel) { onHide(); true },
)
})
// A paused Chat pet has no meaningful vertical free-form
// coordinate: it is deliberately attached to the composer.
// Do not expose TalkBack actions that would appear to do
// nothing; start/end still choose the dock corner.
if (floatingPetAllowsVerticalMoveActions(route, roamingEnabled)) {
add(CustomAccessibilityAction(moveUpLabel) {
if (roamingEnabled) onRoamingEnabledChanged(false)
onPlacementChanged(
placement.copy(verticalFraction = placement.verticalFraction - 0.15f),
)
true
})
add(CustomAccessibilityAction(moveDownLabel) {
if (roamingEnabled) onRoamingEnabledChanged(false)
onPlacementChanged(
placement.copy(verticalFraction = placement.verticalFraction + 0.15f),
)
true
})
}
add(CustomAccessibilityAction(resetLabel) { onResetPlacement(); true })
add(CustomAccessibilityAction(appearanceLabel) { onOpenAppearance(); true })
add(CustomAccessibilityAction(hideLabel) { onHide(); true })
}
},
contentAlignment = Alignment.Center,
) {
@@ -2419,7 +2483,7 @@ fun FloatingPetCompanion(
DropdownMenu(
expanded = menuExpanded,
onDismissRequest = { menuExpanded = false },
onDismissRequest = { setMenuExpanded(false) },
) {
DropdownMenuItem(
text = { Text("${pet.label} · $stateLabel", color = MaterialTheme.colorScheme.onSurfaceVariant) },
@@ -2436,28 +2500,28 @@ fun FloatingPetCompanion(
)
},
onClick = {
menuExpanded = false
setMenuExpanded(false)
onRoamingEnabledChanged(!roamingEnabled)
},
)
DropdownMenuItem(
text = { Text(resetLabel) },
onClick = {
menuExpanded = false
setMenuExpanded(false)
onResetPlacement()
},
)
DropdownMenuItem(
text = { Text(appearanceLabel) },
onClick = {
menuExpanded = false
setMenuExpanded(false)
onOpenAppearance()
},
)
DropdownMenuItem(
text = { Text(hideLabel) },
onClick = {
menuExpanded = false
setMenuExpanded(false)
onHide()
},
)
@@ -45,6 +45,8 @@ import androidx.compose.material3.Button
import androidx.compose.material3.ButtonDefaults
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.FilterChip
import androidx.compose.material3.FilterChipDefaults
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
@@ -81,6 +83,7 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.HermesCardDispatch
import com.hermesandroid.relay.data.HermesCardField
import com.hermesandroid.relay.data.HermesCardInput
import com.hermesandroid.relay.data.encodeClarifyMultiSelectAnswer
import com.hermesandroid.relay.ui.theme.RelayRefresh
import com.hermesandroid.relay.ui.theme.relayMetadataStyle
import kotlinx.coroutines.coroutineScope
@@ -389,7 +392,8 @@ private fun ChoseRow(
/**
* The interactive answer surface for ask cards, composed from the
* [HermesCardInput] flags rather than the card type:
* - [HermesCardInput.choices] → AssistChip row, one tap dispatches.
* - [HermesCardInput.choices] → one-tap AssistChips, or independently
* selected FilterChips plus explicit submit for multi-select clarifies.
* - [HermesCardInput.allowFreeText] → [InlineAnswerField] mini pill +
* 18dp send affordance.
* - [HermesCardInput.masked] → password-style OutlinedTextField with a
@@ -411,6 +415,8 @@ private fun CardInputSlot(
// never be written into the saved-instance-state Bundle.
var answerText by remember { mutableStateOf("") }
var reveal by remember { mutableStateOf(false) }
var selectedChoices by remember(input.choices) { mutableStateOf(emptyList<String>()) }
val isMultiSelect = input.multiSelect && input.choices.isNotEmpty()
val showFreeText = !input.masked && (
input.allowFreeText ||
@@ -428,16 +434,45 @@ private fun CardInputSlot(
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
input.choices.forEach { choice ->
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
if (isMultiSelect) {
val selected = choice in selectedChoices
FilterChip(
selected = selected,
onClick = {
selectedChoices = if (selected) {
selectedChoices - choice
} else {
selectedChoices + choice
}
},
label = { Text(choice, style = MaterialTheme.typography.labelMedium) },
leadingIcon = if (selected) {
{
Icon(
Icons.Filled.Check,
contentDescription = null,
modifier = Modifier.size(16.dp),
)
}
} else {
null
},
colors = FilterChipDefaults.filterChipColors(
selectedContainerColor = MaterialTheme.colorScheme.secondaryContainer,
),
)
} else {
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
}
}
}
}
@@ -482,21 +517,38 @@ private fun CardInputSlot(
onValueChange = { answerText = it },
modifier = Modifier.weight(1f),
)
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
if (!isMultiSelect) {
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
}
}
}
}
if (isMultiSelect) {
val answers = selectedChoices +
listOfNotNull(answerText.trim().takeIf(String::isNotEmpty))
Spacer(Modifier.height(10.dp))
Button(
onClick = { onSubmit(encodeClarifyMultiSelectAnswer(answers)) },
enabled = answers.isNotEmpty(),
) {
Text(
stringResource(R.string.card_submit),
style = MaterialTheme.typography.labelMedium,
)
}
}
// Submit affordance for masked / hold-to-confirm inputs
when {
input.holdToConfirm -> {
@@ -2,7 +2,6 @@ package com.hermesandroid.relay.ui.components
import android.content.Context
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.pdf.PdfRenderer
import android.media.MediaMetadataRetriever
import android.net.Uri
@@ -290,7 +289,7 @@ private fun ImageRender(
android.util.Base64.decode(attachment.content, android.util.Base64.DEFAULT)
else -> null
}
bytes?.let { BitmapFactory.decodeByteArray(it, 0, it.size)?.asImageBitmap() }
bytes?.let { decodeOrientedBitmap(it)?.asImageBitmap() }
}.getOrNull()
}
if (decoded != null) bitmap = decoded else decodeFailed = true
@@ -1,6 +1,11 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.animateContentSize
import androidx.compose.animation.expandVertically
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.animation.shrinkVertically
import androidx.compose.animation.core.LinearOutSlowInEasing
import androidx.compose.animation.core.RepeatMode
import androidx.compose.animation.core.animateFloat
@@ -32,15 +37,20 @@ import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.foundation.text.selection.DisableSelection
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.VolumeUp
import androidx.compose.material.icons.filled.ContentCopy
import androidx.compose.material.icons.filled.Edit
import androidx.compose.material.icons.filled.FormatQuote
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.material3.DropdownMenu
import androidx.compose.material3.DropdownMenuItem
import androidx.compose.runtime.Composable
import androidx.compose.runtime.CompositionLocalProvider
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.key
@@ -71,13 +81,16 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.MediaSettingsRepository
import com.hermesandroid.relay.data.MessageDeliveryStatus
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.parseChatQuotedPrompt
import com.hermesandroid.relay.ui.components.pet.petObstacleSurface
import com.hermesandroid.relay.ui.components.pet.petPerchSurface
import com.hermesandroid.relay.ui.components.pet.petVisitTargetSurface
import com.hermesandroid.relay.ui.theme.leftEdgeGlow
import kotlinx.coroutines.delay
import java.text.SimpleDateFormat
import java.util.Date
internal const val CHAT_PET_IDENTITY_OBSTACLE_PREFIX = "chat-message-identity:"
@OptIn(ExperimentalFoundationApi::class)
@Composable
fun MessageBubble(
@@ -96,16 +109,23 @@ fun MessageBubble(
retainStreamingLayout: Boolean = false,
onCopyMessage: (String) -> Unit = {},
/**
* Quote this message into the input field. Null hides the Quote entry in
* the long-press menu, so legacy call sites keep the copy-only behavior.
* Select this message as a structured composer quote. Null hides Quote.
*/
onQuoteMessage: ((String) -> Unit)? = null,
onQuoteMessage: ((ChatMessage) -> Unit)? = null,
/** Navigate a rendered quote chip to its original message id. */
onNavigateToMessage: ((String) -> Unit)? = null,
/** Open an upstream @session:<profile>/<id> reference in app. */
onSessionReference: ((SessionReference) -> Unit)? = null,
/** React to the newest message for this role; null removes the reaction. */
onReact: ((String?) -> Unit)? = null,
/**
* Reads a completed assistant response through the active voice renderer.
* Null hides the entry; the owning screen uses that to limit the action to
* idle Conversation voice sessions.
*/
onSpeakMessage: ((String) -> Unit)? = null,
/** Stops a message-context narration currently owned by the voice pipeline. */
onStopSpeaking: (() -> Unit)? = null,
/**
* Invoked when the user taps a FAILED inbound attachment card.
* `attachmentIndex` is the position in [ChatMessage.attachments] so the
@@ -151,9 +171,11 @@ fun MessageBubble(
imageGenerationRotationIndex: Int = 0,
petVisitTargetKey: String? = null,
petPerchKey: String? = null,
animationEnabled: Boolean = true,
) {
val isUser = message.role == MessageRole.USER
val isSystem = message.role == MessageRole.SYSTEM
val sessionReferences = remember(message.content) { parseSessionReferences(message.content) }
// Phone/voice-origin action bubble marker.
//
@@ -204,18 +226,19 @@ fun MessageBubble(
val alignment = if (isUser) Alignment.End else Alignment.Start
val locale = LocalLocale.current.platformLocale
val timeFormat = remember(locale) { SimpleDateFormat("h:mm a", locale) }
val a11yDescription = "${message.role.name.lowercase()} message: ${message.content.take(100)}"
val quoteEnvelope = remember(message.content) { parseChatQuotedPrompt(message.content) }
val visibleMessageContent = quoteEnvelope?.body ?: message.content
val isDarkTheme = LocalBrand.current.isDark
// Pull generated/inline image links (`![alt](src)`) out of assistant
// content so they render as real images (remote URLs via Coil) or a
// graceful inline notice — not the blank element the markdown renderer
// emits for an image link. User/system bubbles keep their raw content.
val (markdownBody, inlineImages) = remember(message.content, isUser, isSystem) {
val (markdownBody, inlineImages) = remember(visibleMessageContent, isUser, isSystem) {
if (isUser || isSystem) {
message.content to emptyList()
visibleMessageContent to emptyList()
} else {
extractChatInlineImages(message.content)
extractChatInlineImages(visibleMessageContent)
}
}
val showImageGeneration = shouldShowImageGenerationPlaceholder(
@@ -223,6 +246,26 @@ fun MessageBubble(
isStreaming = message.isStreaming,
hasMediaResult = message.attachments.isNotEmpty() || inlineImages.isNotEmpty(),
)
val streamingStatusLabel = if (
!isUser &&
!isSystem &&
message.isStreaming &&
message.content.isBlank() &&
!showImageGeneration
) {
if (recoveringAnswer) {
stringResource(R.string.msg_bubble_reconnecting)
} else {
stringResource(R.string.msg_bubble_still_working)
}
} else {
null
}
val a11yDescription = buildString {
append(message.role.name.lowercase())
append(" message: ")
append(streamingStatusLabel ?: visibleMessageContent.take(100))
}
val hasImageGenerationCall = remember(message.toolCalls) {
message.toolCalls.any {
it.name.trim().lowercase() == "image_generate"
@@ -251,52 +294,36 @@ fun MessageBubble(
val blurMode by blurRepo.blurMode.collectAsState(initial = BlurMode.FLAGGED)
CompositionLocalProvider(LocalMediaBlurMode provides blurMode) {
// The active profile image is sender identity, distinct from both the
// floating pet companion and the ambient Sphere. Reserve one stable gutter
// for an assistant run and render the identity only on its first message.
Row(
Column(
modifier = modifier.fillMaxWidth(),
verticalAlignment = Alignment.Top,
horizontalAlignment = alignment,
) {
if (!isUser && !isSystem) {
Box(
modifier = Modifier.width(40.dp),
contentAlignment = Alignment.TopCenter,
) {
if (shouldShowMessageGroupAvatar(
isUser = isUser,
isSystem = isSystem,
isFirstInGroup = isFirstInGroup,
agentName = message.agentName,
)
// Keep sender identity in the first-message label rather than a
// persistent leading column. Long responses and every follow-up in the
// group therefore retain the full bubble-width allowance.
if (!isUser && !isSystem && isFirstInGroup && !message.agentName.isNullOrBlank()) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
modifier = Modifier
.padding(bottom = 3.dp, start = 4.dp)
.petObstacleSurface(
key = "$CHAT_PET_IDENTITY_OBSTACLE_PREFIX${message.uiKey}",
routes = setOf("chat"),
),
) {
Surface(
// Decorative: the adjacent visible agent name already owns
// the identity announcement, avoiding duplicate TalkBack copy.
modifier = Modifier.size(32.dp),
modifier = Modifier.size(24.dp),
shape = CircleShape,
color = MaterialTheme.colorScheme.primary,
) {
AgentAvatarFace(
name = message.agentName.orEmpty(),
letterStyle = MaterialTheme.typography.labelMedium,
letterStyle = MaterialTheme.typography.labelSmall,
)
}
}
}
}
Column(
modifier = Modifier.weight(1f),
horizontalAlignment = alignment
) {
// Agent name label sits beside the first group identity avatar. Pet
// companions never enter this row.
if (!isUser && !isSystem && isFirstInGroup && !message.agentName.isNullOrBlank()) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
modifier = Modifier.padding(bottom = 2.dp, start = 4.dp),
) {
Text(
text = localizeAgentName(message.agentName),
style = MaterialTheme.typography.labelSmall,
@@ -331,7 +358,7 @@ fun MessageBubble(
}
// Thinking block (above the bubble, only for assistant messages)
if (!isUser && showThinking && message.thinkingContent.isNotEmpty()) {
if (!isUser && showThinking && message.thinkingContent.isNotBlank()) {
ThinkingBlock(
thinkingContent = message.thinkingContent,
isStreaming = message.isThinkingStreaming,
@@ -380,12 +407,22 @@ fun MessageBubble(
// carries only thinking and/or tool calls (both rendered OUTSIDE
// this Surface — the ThinkingBlock above, the tool pills as separate
// rows) would otherwise paint a bare timestamp-only chip between the
// Thought-process block and the tool pill. Keep the bubble while
// streaming (StreamingDots is the live "working" indicator) and
// whenever there are cards/attachments to render inside it.
// Thought-process block and the tool pill. The first-token working state
// is rendered directly in the conversation
// lane below, without an opaque bubble. Cards and attachments still own
// a normal bubble even when response prose has not arrived yet.
streamingStatusLabel?.let { streamingStatus ->
StandaloneStreamingStatus(
status = streamingStatus,
accessibilityDescription = a11yDescription,
textColor = textColor,
modifier = Modifier.padding(start = 12.dp, top = 4.dp, bottom = 6.dp),
)
}
val showBubble = isUser || isSystem ||
message.content.isNotBlank() ||
message.isStreaming ||
visibleMessageContent.isNotBlank() ||
quoteEnvelope != null ||
showImageGeneration ||
message.cards.isNotEmpty() ||
message.attachments.isNotEmpty() ||
@@ -400,19 +437,25 @@ fun MessageBubble(
modifier = Modifier
.padding(top = 8.dp, bottom = 8.dp, end = 6.dp)
.width(3.dp)
.height(if (message.content.isBlank()) 14.dp else 24.dp)
.height(if (visibleMessageContent.isBlank()) 14.dp else 24.dp)
.clip(CircleShape)
.background(MaterialTheme.colorScheme.tertiary.copy(alpha = 0.85f))
)
}
// Long-press opens a compact action menu when a quote handler is
// wired; with copy as the only action it stays a direct copy so the
// one-action case doesn't pay a menu tap.
Column(horizontalAlignment = alignment) {
// A normal tap reveals the compact action strip. Long-press preserves
// the existing overflow menu (or direct-copy shortcut when Copy is the
// only available action).
var showMessageActions by remember { mutableStateOf(false) }
var showInlineActions by remember(message.uiKey) { mutableStateOf(false) }
val haptic = LocalHapticFeedback.current
val accessibleMotion = rememberAccessibleMotionState()
val animateInlineActions = animationEnabled && accessibleMotion.osAnimations &&
!accessibleMotion.touchExploration
val showEditAction = onEditMessage != null && isUser
val showSpeakAction = shouldShowSpeakResponseAction(message, onSpeakMessage != null)
if (onQuoteMessage != null || showEditAction || showSpeakAction) {
val showStopSpeakingAction = shouldShowStopSpeakingAction(message, onStopSpeaking != null)
if (onQuoteMessage != null || onReact != null || showEditAction || showSpeakAction || showStopSpeakingAction) {
DropdownMenu(
expanded = showMessageActions,
onDismissRequest = { showMessageActions = false },
@@ -421,7 +464,7 @@ fun MessageBubble(
text = { Text(stringResource(R.string.msg_bubble_copy)) },
onClick = {
showMessageActions = false
onCopyMessage(message.content)
onCopyMessage(visibleMessageContent)
},
)
if (onQuoteMessage != null) {
@@ -429,7 +472,7 @@ fun MessageBubble(
text = { Text(stringResource(R.string.msg_bubble_quote)) },
onClick = {
showMessageActions = false
onQuoteMessage(message.content)
onQuoteMessage(message.copy(content = visibleMessageContent))
},
)
}
@@ -444,7 +487,22 @@ fun MessageBubble(
},
onClick = {
showMessageActions = false
onSpeakMessage?.invoke(message.content)
onSpeakMessage?.invoke(visibleMessageContent)
},
)
}
if (showStopSpeakingAction) {
DropdownMenuItem(
text = { Text(stringResource(R.string.msg_bubble_stop_speaking)) },
leadingIcon = {
Icon(
imageVector = Icons.Filled.Stop,
contentDescription = null,
)
},
onClick = {
showMessageActions = false
onStopSpeaking?.invoke()
},
)
}
@@ -493,16 +551,19 @@ fun MessageBubble(
} else Modifier
)
.combinedClickable(
onClick = {},
onClick = { showInlineActions = !showInlineActions },
onLongClick = {
// Buzz the instant the long-press registers — opening the
// action menu is the discoverability moment, so it gets the
// same tactile confirm every chat app fires.
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
if (onQuoteMessage != null || showEditAction || showSpeakAction) {
if (
onQuoteMessage != null || showEditAction || showSpeakAction ||
showStopSpeakingAction
) {
showMessageActions = true
} else {
onCopyMessage(message.content)
onCopyMessage(visibleMessageContent)
}
}
)
@@ -528,12 +589,23 @@ fun MessageBubble(
}
)
) {
Column(modifier = Modifier.padding(horizontal = 14.dp, vertical = 9.dp)) {
Column(
modifier = Modifier.padding(horizontal = 14.dp, vertical = 9.dp),
) {
quoteEnvelope?.let { envelope ->
ChatQuoteReferenceChip(
reference = envelope.reference,
onOpenOriginal = onNavigateToMessage?.let { navigate ->
{ navigate(envelope.reference.messageId) }
},
modifier = Modifier.padding(bottom = 7.dp),
)
}
val messageTextContent: @Composable () -> Unit = {
if (isUser || isSystem) {
// Plain text for user and system messages
Text(
text = message.content,
text = visibleMessageContent,
style = MaterialTheme.typography.bodyMedium.copy(
fontSize = 15.sp,
lineHeight = 21.sp,
@@ -559,7 +631,7 @@ fun MessageBubble(
// a live Text node becomes a Markdown tree, or settled
// Markdown content changes its node topology, so a handle
// cannot keep pointing at a removed selectable.
if (showSpeakAction) {
if (showSpeakAction || showStopSpeakingAction) {
DisableSelection { messageTextContent() }
} else {
key(
@@ -573,6 +645,35 @@ fun MessageBubble(
SelectionContainer { messageTextContent() }
}
}
if (onReact != null) {
listOf("👍", "❤️", "😂").forEach { emoji ->
DropdownMenuItem(
text = { Text("React $emoji") },
onClick = {
showMessageActions = false
onReact(emoji)
},
)
}
DropdownMenuItem(
text = { Text("Remove reaction") },
onClick = {
showMessageActions = false
onReact(null)
},
)
}
if (onSessionReference != null && sessionReferences.isNotEmpty()) {
sessionReferences.forEach { reference ->
TextButton(
onClick = { onSessionReference(reference) },
modifier = Modifier.padding(top = 2.dp),
) {
Text("Open ${reference.label}")
}
}
}
// Inline generated images (assistant only) — rendered OUTSIDE
// the SelectionContainer (they're not selectable text). Remote
@@ -687,64 +788,6 @@ fun MessageBubble(
}
}
// Streaming indicator — only while awaiting the first token. Once
// text starts flowing, the growing reply is itself the progress
// signal, so the pulsing dots stop (Messenger/Telegram drop the
// typing bubble the moment content appears) instead of throbbing
// under the text for the whole turn.
if (
message.isStreaming &&
message.content.isBlank() &&
!showImageGeneration
) {
// After a few seconds with no content yet, escalate the bare
// dots to a labeled "Still working…" so a slow first token
// never reads as a hang on the SSE / sessions paths.
val awaitingFirstToken = message.content.isBlank()
var showStillWorking by remember(message.id) { mutableStateOf(false) }
LaunchedEffect(message.id, awaitingFirstToken) {
showStillWorking = false
if (awaitingFirstToken) {
delay(4_000)
showStillWorking = true
}
}
val thinkingIndicator = LocalThinkingIndicator.current
Row(verticalAlignment = Alignment.CenterVertically) {
when (thinkingIndicator.style) {
ThinkingIndicatorStyle.Matrix -> DotMatrixIndicator(
// Auto follows the bubble text color; accents
// come from the brand palette. The grid modulates
// its own alpha (idle dots ≈0.18, lit dots 1.0).
color = thinkingIndicator.color.toColor(autoColor = textColor),
pattern = thinkingIndicator.pattern,
animated = thinkingIndicator.animated,
modifier = Modifier.padding(top = 4.dp),
)
ThinkingIndicatorStyle.Dots -> StreamingDots(
color = textColor.copy(alpha = 0.6f),
modifier = Modifier.padding(top = 4.dp),
)
}
// During dropped-stream answer recovery the label shows
// immediately (the 4s escalation is for a slow first
// token; a recovery is already known to be slow).
if ((showStillWorking || recoveringAnswer) && awaitingFirstToken) {
Spacer(modifier = Modifier.width(8.dp))
Text(
text = if (recoveringAnswer) {
stringResource(R.string.msg_bubble_reconnecting)
} else {
stringResource(R.string.msg_bubble_still_working)
},
style = MaterialTheme.typography.labelSmall,
color = textColor.copy(alpha = 0.6f),
modifier = Modifier.padding(top = 4.dp),
)
}
}
}
// Timestamp — only on the LAST bubble of a same-author run so a
// burst of fragments doesn't stack three near-touching time labels.
// Grouping breaks on a >5min gap (ChatScreen), so every pause still
@@ -771,23 +814,17 @@ fun MessageBubble(
// message routed over the relay proactive channel). Null on every
// ordinary chat message, which render nothing here.
message.deliveryStatus?.takeIf { isUser }?.let { status ->
val label = stringResource(
when (status) {
MessageDeliveryStatus.SENDING -> R.string.msg_bubble_sending
MessageDeliveryStatus.DELIVERED -> R.string.msg_bubble_delivered
MessageDeliveryStatus.FAILED -> R.string.msg_bubble_not_sent
}
)
val alpha = when (status) {
MessageDeliveryStatus.SENDING -> 0.5f
MessageDeliveryStatus.DELIVERED -> 0.5f
MessageDeliveryStatus.FAILED -> 0.7f
}
Spacer(modifier = Modifier.height(2.dp))
Text(
text = label,
style = MaterialTheme.typography.labelSmall,
color = textColor.copy(alpha = alpha),
MessageDeliveryIndicator(
status = status,
text = MessageDeliveryIndicatorText(
sending = stringResource(R.string.msg_bubble_sending),
queued = stringResource(R.string.msg_bubble_queued),
steered = stringResource(R.string.msg_bubble_steered),
delivered = stringResource(R.string.msg_bubble_delivered),
failed = stringResource(R.string.msg_bubble_not_sent),
tapToRetry = stringResource(R.string.chat_retry),
),
)
}
@@ -801,13 +838,127 @@ fun MessageBubble(
}
}
}
val inlineActions: @Composable () -> Unit = {
MessageInlineActions(
showQuote = onQuoteMessage != null,
showSpeak = showSpeakAction,
showStopSpeaking = showStopSpeakingAction,
showEdit = showEditAction,
onCopy = {
showInlineActions = false
onCopyMessage(visibleMessageContent)
},
onQuote = {
showInlineActions = false
onQuoteMessage?.invoke(message.copy(content = visibleMessageContent))
},
onSpeak = {
showInlineActions = false
onSpeakMessage?.invoke(visibleMessageContent)
},
onStopSpeaking = {
showInlineActions = false
onStopSpeaking?.invoke()
},
onEdit = {
showInlineActions = false
onEditMessage?.invoke(message)
},
)
}
if (animateInlineActions) {
AnimatedVisibility(
visible = showInlineActions,
enter = fadeIn(tween(120)) + expandVertically(
animationSpec = tween(180, easing = LinearOutSlowInEasing),
expandFrom = Alignment.Top,
),
exit = fadeOut(tween(90)) + shrinkVertically(
animationSpec = tween(140),
shrinkTowards = Alignment.Top,
),
) {
inlineActions()
}
} else if (showInlineActions) {
inlineActions()
}
} // end Column (bubble + revealed actions)
} // end Row (bubble + optional leading accent bar)
} // end if (showBubble)
} // end content Column
} // end Row (avatar gutter + content)
} // end CompositionLocalProvider(LocalMediaBlurMode)
}
@Composable
private fun MessageInlineActions(
showQuote: Boolean,
showSpeak: Boolean,
showStopSpeaking: Boolean,
showEdit: Boolean,
onCopy: () -> Unit,
onQuote: () -> Unit,
onSpeak: () -> Unit,
onStopSpeaking: () -> Unit,
onEdit: () -> Unit,
) {
Surface(
shape = RoundedCornerShape(12.dp),
color = MaterialTheme.colorScheme.surfaceContainerHigh,
tonalElevation = 2.dp,
modifier = Modifier.padding(top = 2.dp),
) {
Row(
verticalAlignment = Alignment.CenterVertically,
modifier = Modifier.padding(horizontal = 2.dp),
) {
IconButton(onClick = onCopy, modifier = Modifier.size(48.dp)) {
Icon(
imageVector = Icons.Filled.ContentCopy,
contentDescription = stringResource(R.string.msg_bubble_copy),
modifier = Modifier.size(18.dp),
)
}
if (showQuote) {
IconButton(onClick = onQuote, modifier = Modifier.size(48.dp)) {
Icon(
imageVector = Icons.Filled.FormatQuote,
contentDescription = stringResource(R.string.msg_bubble_quote),
modifier = Modifier.size(18.dp),
)
}
}
if (showSpeak) {
IconButton(onClick = onSpeak, modifier = Modifier.size(48.dp)) {
Icon(
imageVector = Icons.AutoMirrored.Filled.VolumeUp,
contentDescription = stringResource(R.string.msg_bubble_speak_response),
modifier = Modifier.size(18.dp),
)
}
}
if (showStopSpeaking) {
IconButton(onClick = onStopSpeaking, modifier = Modifier.size(48.dp)) {
Icon(
imageVector = Icons.Filled.Stop,
contentDescription = stringResource(R.string.msg_bubble_stop_speaking),
modifier = Modifier.size(18.dp),
)
}
}
if (showEdit) {
IconButton(onClick = onEdit, modifier = Modifier.size(48.dp)) {
Icon(
imageVector = Icons.Filled.Edit,
contentDescription = stringResource(R.string.msg_bubble_edit),
modifier = Modifier.size(18.dp),
)
}
}
}
}
}
internal data class MessageSelectionTopologyKey(
val renderer: String,
val markdownBody: String?,
@@ -881,6 +1032,15 @@ internal fun shouldShowSpeakResponseAction(
!message.isStreaming &&
message.content.isNotBlank()
internal fun shouldShowStopSpeakingAction(
message: ChatMessage,
handlerAvailable: Boolean,
): Boolean =
handlerAvailable &&
message.role == MessageRole.ASSISTANT &&
!message.isStreaming &&
message.content.isNotBlank()
internal fun shouldShowMessageGroupAvatar(
isUser: Boolean,
isSystem: Boolean,
@@ -918,6 +1078,42 @@ private fun MessagePathBadge(text: String, leadingIcon: ImageVector? = null) {
}
}
/** First-token progress rendered in the conversation lane, not inside a message bubble. */
@Composable
private fun StandaloneStreamingStatus(
status: String,
accessibilityDescription: String,
textColor: Color,
modifier: Modifier = Modifier,
) {
val thinkingIndicator = LocalThinkingIndicator.current
Column(
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(5.dp),
modifier = modifier.clearAndSetSemantics {
contentDescription = accessibilityDescription
},
) {
when (thinkingIndicator.style) {
ThinkingIndicatorStyle.Matrix -> DotMatrixIndicator(
color = thinkingIndicator.color.toColor(autoColor = textColor),
pattern = thinkingIndicator.pattern,
animated = thinkingIndicator.animated,
)
ThinkingIndicatorStyle.Dots -> StreamingDots(
color = textColor.copy(alpha = 0.6f),
)
}
Text(
text = status,
style = MaterialTheme.typography.labelSmall,
color = textColor.copy(alpha = 0.68f),
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
}
}
/**
* Three dots that animate opacity in sequence to indicate streaming is in progress.
*/
@@ -0,0 +1,167 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.Send
import androidx.compose.material.icons.filled.Bolt
import androidx.compose.material.icons.filled.CheckCircle
import androidx.compose.material.icons.filled.ErrorOutline
import androidx.compose.material.icons.filled.Schedule
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.material3.minimumInteractiveComponentSize
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.data.MessageDeliveryStatus
import com.hermesandroid.relay.ui.theme.relayMetadataStyle
/**
* Localized copy for [MessageDeliveryIndicator]. Keeping copy at the call site
* lets MessageBubble use Android string resources without coupling this small
* presentation component to a particular resource catalog.
*/
data class MessageDeliveryIndicatorText(
val sending: String,
val queued: String,
val steered: String,
val delivered: String,
val failed: String,
val tapToRetry: String,
)
/**
* Compact, accessible lifecycle feedback for a user-authored chat message.
*
* Every state has both a distinct icon and a visible text label, so meaning is
* never carried by color alone. A failed state becomes a button only when
* [onRetry] is supplied; its entire 48dp row is then the retry target.
*/
@Composable
fun MessageDeliveryIndicator(
status: MessageDeliveryStatus,
text: MessageDeliveryIndicatorText,
modifier: Modifier = Modifier,
failureMessage: String? = null,
onRetry: (() -> Unit)? = null,
) {
val retryAction = onRetry.takeIf { status == MessageDeliveryStatus.FAILED }
val retryable = retryAction != null
val line = messageDeliveryStatusLine(
status = status,
text = text,
failureMessage = failureMessage,
retryable = retryable,
)
val presentation = messageDeliveryPresentation(status)
val tint = when (presentation.colorRole) {
DeliveryColorRole.NEUTRAL -> MaterialTheme.colorScheme.onSurfaceVariant
DeliveryColorRole.ACCENT -> MaterialTheme.colorScheme.primary
DeliveryColorRole.QUEUED -> MaterialTheme.colorScheme.tertiary
DeliveryColorRole.ERROR -> MaterialTheme.colorScheme.error
}
Row(
modifier = modifier
.then(
if (retryable) {
Modifier
.minimumInteractiveComponentSize()
.clickable(
role = Role.Button,
onClickLabel = text.tapToRetry,
onClick = retryAction,
)
} else {
Modifier
},
)
.semantics(mergeDescendants = true) {
contentDescription = line
liveRegion = LiveRegionMode.Polite
}
.padding(horizontal = 2.dp, vertical = 2.dp),
horizontalArrangement = Arrangement.spacedBy(4.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(
imageVector = presentation.icon,
contentDescription = null,
tint = tint,
modifier = Modifier.size(14.dp),
)
Text(
text = line,
style = relayMetadataStyle(),
color = tint,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
}
}
internal fun messageDeliveryStatusLine(
status: MessageDeliveryStatus,
text: MessageDeliveryIndicatorText,
failureMessage: String? = null,
retryable: Boolean = false,
): String {
val label = when (status) {
MessageDeliveryStatus.SENDING -> text.sending
MessageDeliveryStatus.QUEUED -> text.queued
MessageDeliveryStatus.STEERED -> text.steered
MessageDeliveryStatus.DELIVERED -> text.delivered
MessageDeliveryStatus.FAILED -> text.failed
}
if (status != MessageDeliveryStatus.FAILED) return label
return buildList {
add(label)
failureMessage?.trim()?.takeIf(String::isNotEmpty)?.let(::add)
if (retryable) add(text.tapToRetry)
}.joinToString(" · ")
}
private data class DeliveryPresentation(
val icon: ImageVector,
val colorRole: DeliveryColorRole,
)
private enum class DeliveryColorRole { NEUTRAL, ACCENT, QUEUED, ERROR }
private fun messageDeliveryPresentation(status: MessageDeliveryStatus): DeliveryPresentation =
when (status) {
MessageDeliveryStatus.SENDING -> DeliveryPresentation(
icon = Icons.AutoMirrored.Filled.Send,
colorRole = DeliveryColorRole.NEUTRAL,
)
MessageDeliveryStatus.QUEUED -> DeliveryPresentation(
icon = Icons.Filled.Schedule,
colorRole = DeliveryColorRole.QUEUED,
)
MessageDeliveryStatus.STEERED -> DeliveryPresentation(
icon = Icons.Filled.Bolt,
colorRole = DeliveryColorRole.ACCENT,
)
MessageDeliveryStatus.DELIVERED -> DeliveryPresentation(
icon = Icons.Filled.CheckCircle,
colorRole = DeliveryColorRole.ACCENT,
)
MessageDeliveryStatus.FAILED -> DeliveryPresentation(
icon = Icons.Filled.ErrorOutline,
colorRole = DeliveryColorRole.ERROR,
)
}
@@ -0,0 +1,64 @@
package com.hermesandroid.relay.ui.components
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.Matrix
import androidx.exifinterface.media.ExifInterface
import java.io.ByteArrayInputStream
internal data class ImageOrientationTransform(
val rotationDegrees: Float = 0f,
val flipHorizontal: Boolean = false,
)
internal fun imageOrientationTransform(orientation: Int): ImageOrientationTransform = when (orientation) {
ExifInterface.ORIENTATION_FLIP_HORIZONTAL -> ImageOrientationTransform(flipHorizontal = true)
ExifInterface.ORIENTATION_ROTATE_180 -> ImageOrientationTransform(rotationDegrees = 180f)
ExifInterface.ORIENTATION_FLIP_VERTICAL ->
ImageOrientationTransform(rotationDegrees = 180f, flipHorizontal = true)
ExifInterface.ORIENTATION_TRANSPOSE ->
ImageOrientationTransform(rotationDegrees = 90f, flipHorizontal = true)
ExifInterface.ORIENTATION_ROTATE_90 -> ImageOrientationTransform(rotationDegrees = 90f)
ExifInterface.ORIENTATION_TRANSVERSE ->
ImageOrientationTransform(rotationDegrees = -90f, flipHorizontal = true)
ExifInterface.ORIENTATION_ROTATE_270 -> ImageOrientationTransform(rotationDegrees = -90f)
else -> ImageOrientationTransform()
}
/**
* Decode image bytes for display and apply their EXIF orientation. BitmapFactory
* returns the stored pixel layout and otherwise leaves portrait phone photos
* sideways when the camera encoded rotation as metadata.
*/
internal fun decodeOrientedBitmap(
bytes: ByteArray,
options: BitmapFactory.Options? = null,
): Bitmap? {
if (bytes.isEmpty()) return null
val decoded = if (options == null) {
BitmapFactory.decodeByteArray(bytes, 0, bytes.size)
} else {
BitmapFactory.decodeByteArray(bytes, 0, bytes.size, options)
} ?: return null
val orientation = runCatching {
ByteArrayInputStream(bytes).use { stream ->
ExifInterface(stream).getAttributeInt(
ExifInterface.TAG_ORIENTATION,
ExifInterface.ORIENTATION_NORMAL,
)
}
}.getOrDefault(ExifInterface.ORIENTATION_NORMAL)
val transform = imageOrientationTransform(orientation)
if (transform.rotationDegrees == 0f && !transform.flipHorizontal) return decoded
val matrix = Matrix().apply {
if (transform.rotationDegrees != 0f) postRotate(transform.rotationDegrees)
if (transform.flipHorizontal) postScale(-1f, 1f)
}
return runCatching {
Bitmap.createBitmap(decoded, 0, 0, decoded.width, decoded.height, matrix, true)
}.getOrNull()?.also { oriented ->
if (oriented !== decoded) decoded.recycle()
} ?: decoded
}
@@ -0,0 +1,325 @@
package com.hermesandroid.relay.ui.components
import android.graphics.BitmapFactory
import android.util.Base64
import androidx.compose.foundation.Image
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.horizontalScroll
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.ArrowBack
import androidx.compose.material.icons.automirrored.filled.ArrowForward
import androidx.compose.material.icons.filled.AttachFile
import androidx.compose.material.icons.filled.BrokenImage
import androidx.compose.material.icons.filled.Close
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.ImageBitmap
import androidx.compose.ui.graphics.asImageBitmap
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.AttachmentRenderMode
import com.hermesandroid.relay.data.AttachmentState
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
/**
* Pending files shown immediately above the chat composer.
*
* The owner keeps attachment state and handles the four stable integration
* callbacks. [onMove] receives the current and requested indices, allowing a
* ViewModel or session-owned draft store to perform one atomic reorder.
*/
@Composable
fun PendingAttachmentComposer(
attachments: List<Attachment>,
onPreview: (attachment: Attachment, index: Int) -> Unit,
onRemove: (index: Int) -> Unit,
onMove: (fromIndex: Int, toIndex: Int) -> Unit,
modifier: Modifier = Modifier,
imageDecoder: suspend (Attachment) -> ImageBitmap? = ::decodePendingAttachmentImage,
) {
if (attachments.isEmpty()) return
val attachmentLabel = stringResource(R.string.attachment_title)
Row(
modifier = modifier
.fillMaxWidth()
.horizontalScroll(rememberScrollState())
.semantics {
contentDescription = "${attachments.size} $attachmentLabel"
}
.testTag("pending-attachment-composer"),
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
attachments.forEachIndexed { index, attachment ->
PendingAttachmentItem(
attachment = attachment,
index = index,
count = attachments.size,
onPreview = { onPreview(attachment, index) },
onRemove = { onRemove(index) },
onMoveLeft = { onMove(index, index - 1) },
onMoveRight = { onMove(index, index + 1) },
imageDecoder = imageDecoder,
)
}
}
}
@Composable
private fun PendingAttachmentItem(
attachment: Attachment,
index: Int,
count: Int,
onPreview: () -> Unit,
onRemove: () -> Unit,
onMoveLeft: () -> Unit,
onMoveRight: () -> Unit,
imageDecoder: suspend (Attachment) -> ImageBitmap?,
) {
var previewState by remember(attachment.content, attachment.cachedUri, attachment.state) {
mutableStateOf(initialPreviewState(attachment))
}
LaunchedEffect(attachment.content, attachment.cachedUri, attachment.state) {
if (attachment.isImage && attachment.state == AttachmentState.LOADED) {
previewState = PendingPreviewState.Loading
previewState = imageDecoder(attachment)?.let(PendingPreviewState::Ready)
?: PendingPreviewState.Failed
}
}
val name = attachment.fileName?.takeIf(String::isNotBlank)
?: stringResource(R.string.attachment_title)
val type = attachmentTypeLabel(attachment.renderMode)
val size = attachment.fileSize?.let { formatAttachmentSize(it) }
val status = when (previewState) {
PendingPreviewState.Loading -> stringResource(R.string.pending_attachment_status_loading)
is PendingPreviewState.Ready -> stringResource(R.string.pending_attachment_status_ready)
PendingPreviewState.Failed -> attachment.errorMessage?.takeIf(String::isNotBlank)
?: stringResource(R.string.pending_attachment_status_failed)
}
val summary = listOfNotNull(name, type, size, status).joinToString(", ")
val previewEnabled = previewState is PendingPreviewState.Ready
Surface(
modifier = Modifier
.width(216.dp)
.semantics { contentDescription = summary }
.clip(RoundedCornerShape(14.dp))
.clickable(
enabled = previewEnabled,
onClickLabel = stringResource(R.string.pending_attachment_preview_named, name),
role = Role.Button,
onClick = onPreview,
)
.testTag("pending-attachment-$index"),
shape = RoundedCornerShape(14.dp),
color = MaterialTheme.colorScheme.surfaceVariant,
) {
Column(modifier = Modifier.padding(8.dp)) {
Row(verticalAlignment = Alignment.CenterVertically) {
PendingAttachmentThumbnail(previewState)
Spacer(Modifier.width(8.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
text = name,
style = MaterialTheme.typography.labelLarge,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
Text(
text = listOfNotNull(type, size).joinToString(" · "),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
Text(
text = status,
style = MaterialTheme.typography.labelSmall,
color = if (previewState == PendingPreviewState.Failed) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
)
}
}
Spacer(Modifier.height(4.dp))
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.End,
) {
IconButton(
onClick = onMoveLeft,
enabled = index > 0,
modifier = Modifier
.size(48.dp)
.testTag("pending-attachment-move-left-$index"),
) {
Icon(
Icons.AutoMirrored.Filled.ArrowBack,
contentDescription = stringResource(R.string.pending_attachment_move_left, name),
)
}
IconButton(
onClick = onMoveRight,
enabled = index < count - 1,
modifier = Modifier
.size(48.dp)
.testTag("pending-attachment-move-right-$index"),
) {
Icon(
Icons.AutoMirrored.Filled.ArrowForward,
contentDescription = stringResource(R.string.pending_attachment_move_right, name),
)
}
IconButton(
onClick = onRemove,
modifier = Modifier
.size(48.dp)
.testTag("pending-attachment-remove-$index"),
) {
Icon(
Icons.Filled.Close,
contentDescription = stringResource(R.string.pending_attachment_remove, name),
)
}
}
}
}
}
@Composable
private fun PendingAttachmentThumbnail(state: PendingPreviewState) {
Box(
modifier = Modifier
.size(64.dp)
.clip(RoundedCornerShape(10.dp))
.background(MaterialTheme.colorScheme.surface),
contentAlignment = Alignment.Center,
) {
when (state) {
PendingPreviewState.Loading -> CircularProgressIndicator(
modifier = Modifier.size(24.dp),
strokeWidth = 2.dp,
)
is PendingPreviewState.Ready -> if (state.bitmap != null) {
Image(
bitmap = state.bitmap,
contentDescription = null,
contentScale = ContentScale.Crop,
modifier = Modifier.size(64.dp),
)
} else {
Icon(Icons.Filled.AttachFile, contentDescription = null)
}
PendingPreviewState.Failed -> Icon(
Icons.Filled.BrokenImage,
contentDescription = null,
tint = MaterialTheme.colorScheme.error,
)
}
}
}
@Composable
private fun attachmentTypeLabel(mode: AttachmentRenderMode): String = stringResource(
when (mode) {
AttachmentRenderMode.IMAGE -> R.string.attachment_type_image
AttachmentRenderMode.VIDEO -> R.string.attachment_type_video
AttachmentRenderMode.AUDIO -> R.string.attachment_type_audio
AttachmentRenderMode.PDF -> R.string.attachment_type_pdf
AttachmentRenderMode.TEXT -> R.string.attachment_type_text
AttachmentRenderMode.GENERIC -> R.string.attachment_type_file
},
)
private fun initialPreviewState(attachment: Attachment): PendingPreviewState = when {
attachment.state == AttachmentState.FAILED -> PendingPreviewState.Failed
attachment.state == AttachmentState.LOADING -> PendingPreviewState.Loading
attachment.isImage -> PendingPreviewState.Loading
else -> PendingPreviewState.Ready(bitmap = null)
}
@Composable
internal fun formatAttachmentSize(bytes: Long): String {
val safeBytes = bytes.coerceAtLeast(0)
return when {
safeBytes >= 1024L * 1024L * 1024L -> stringResource(
R.string.media_bytes_gb,
safeBytes / (1024.0 * 1024.0 * 1024.0),
)
safeBytes >= 1024L * 1024L -> stringResource(
R.string.media_bytes_mb,
safeBytes / (1024.0 * 1024.0),
)
safeBytes >= 1024L -> stringResource(R.string.media_bytes_kb, safeBytes / 1024.0)
else -> stringResource(R.string.media_bytes_b, safeBytes)
}
}
private suspend fun decodePendingAttachmentImage(attachment: Attachment): ImageBitmap? =
withContext(Dispatchers.IO) {
runCatching {
val bytes = Base64.decode(attachment.content, Base64.DEFAULT)
if (bytes.isEmpty()) return@runCatching null
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
BitmapFactory.decodeByteArray(bytes, 0, bytes.size, bounds)
if (bounds.outWidth <= 0 || bounds.outHeight <= 0) return@runCatching null
var sample = 1
while (
bounds.outWidth / sample > PENDING_ATTACHMENT_THUMBNAIL_TARGET_PX ||
bounds.outHeight / sample > PENDING_ATTACHMENT_THUMBNAIL_TARGET_PX
) {
sample *= 2
}
decodeOrientedBitmap(
bytes,
BitmapFactory.Options().apply { inSampleSize = sample },
)?.asImageBitmap()
}.getOrNull()
}
private sealed interface PendingPreviewState {
data object Loading : PendingPreviewState
data class Ready(val bitmap: ImageBitmap?) : PendingPreviewState
data object Failed : PendingPreviewState
}
private const val PENDING_ATTACHMENT_THUMBNAIL_TARGET_PX = 256
@@ -0,0 +1,527 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.BorderStroke
import androidx.compose.foundation.ExperimentalFoundationApi
import androidx.compose.foundation.combinedClickable
import androidx.compose.foundation.horizontalScroll
import androidx.compose.foundation.verticalScroll
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.selection.selectable
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.KeyboardArrowRight
import androidx.compose.material.icons.filled.Check
import androidx.compose.material.icons.filled.Home
import androidx.compose.material.icons.filled.Lock
import androidx.compose.material.icons.filled.MoreHoriz
import androidx.compose.material.icons.filled.Person
import androidx.compose.material.icons.filled.Tune
import androidx.compose.material.icons.filled.Visibility
import androidx.compose.material.icons.filled.VisibilityOff
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.ExperimentalMaterial3Api
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.ListItem
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.ModalBottomSheet
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.disabled
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import coil3.compose.AsyncImage
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.AgentDisplay
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.data.ProfilePresentation
import com.hermesandroid.relay.data.ProfilePresentationPolicy
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import java.io.File
data class ProfileChoice(
val key: String,
val profile: Profile?,
) {
val isServerDefault: Boolean get() = key == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY
}
object ProfileShelfPolicy {
fun choices(
profiles: List<Profile>,
presentation: ProfilePresentation,
selectedProfileName: String?,
): List<ProfileChoice> {
val selectedKey = AgentDisplay.profileSessionKey(selectedProfileName)
return ProfilePresentationPolicy
.visibleKeys(profiles, presentation, selectedKey)
.mapNotNull { key ->
if (key == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY) {
ProfileChoice(key, null)
} else {
profiles.firstOrNull { it.name == key }?.let { ProfileChoice(key, it) }
}
}
}
fun canSwitch(isStreaming: Boolean, streamingEndpoint: String): Boolean =
!isStreaming || streamingEndpoint == "gateway"
fun isSelected(choice: ProfileChoice, selectedProfileName: String?): Boolean =
choice.key == AgentDisplay.profileSessionKey(selectedProfileName)
/** Local presentation assets follow the selected choice key, not the sticky profile it resolves to. */
fun iconProfileName(choice: ProfileChoice): String? = choice.profile?.name
}
@OptIn(ExperimentalFoundationApi::class)
@Composable
fun ProfileShelf(
connectionViewModel: ConnectionViewModel,
profiles: List<Profile>,
selectedProfile: Profile?,
resolvedProfile: Profile?,
presentation: ProfilePresentation,
activeDisplayName: String,
isProfileLocked: Boolean,
lockedProfileName: String?,
switchEnabled: Boolean,
onSelect: (Profile?) -> Unit,
onOpenPassport: () -> Unit,
onOpenSwitcher: () -> Unit,
onInspect: (String) -> Unit,
onLock: (Profile?) -> Unit,
onUnlock: () -> Unit,
onHide: (String?) -> Unit,
modifier: Modifier = Modifier,
) {
val choices = remember(profiles, presentation, selectedProfile?.name) {
ProfileShelfPolicy.choices(profiles, presentation, selectedProfile?.name)
}
if (choices.size <= 1) return
var actionChoice by remember { mutableStateOf<ProfileChoice?>(null) }
val lockedKey = lockedProfileName ?: AgentDisplay.SERVER_DEFAULT_PROFILE_KEY
Surface(
modifier = modifier.fillMaxWidth(),
color = MaterialTheme.colorScheme.surface,
tonalElevation = 0.dp,
) {
Column {
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 55.dp)
.padding(start = 8.dp, end = 4.dp, top = 3.dp, bottom = 3.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Row(
modifier = Modifier
.weight(1f)
.horizontalScroll(rememberScrollState()),
horizontalArrangement = Arrangement.spacedBy(6.dp),
verticalAlignment = Alignment.CenterVertically,
) {
choices.forEach { choice ->
val selected = ProfileShelfPolicy.isSelected(choice, selectedProfile?.name)
val label = if (selected) {
activeDisplayName
} else {
profileChoiceLabel(choice, resolvedProfile)
}
if (selected) {
val openPassportDescription = stringResource(R.string.profile_shelf_open_passport)
Box(
modifier = Modifier
.heightIn(min = 48.dp)
.widthIn(max = 190.dp)
.combinedClickable(
role = Role.Button,
onClick = onOpenPassport,
onLongClick = { actionChoice = choice },
)
.semantics {
contentDescription = "$label. $openPassportDescription"
},
contentAlignment = Alignment.Center,
) {
Surface(
shape = RoundedCornerShape(22.dp),
color = MaterialTheme.colorScheme.surfaceContainerLow,
border = BorderStroke(
1.dp,
MaterialTheme.colorScheme.primary.copy(alpha = 0.72f),
),
) {
Row(
modifier = Modifier.padding(horizontal = 7.dp, vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(7.dp),
) {
ProfileChoiceAvatar(
connectionViewModel,
choice,
resolvedProfile,
label,
36,
)
Text(
text = label,
modifier = Modifier.weight(1f, fill = false),
style = MaterialTheme.typography.labelLarge,
fontWeight = FontWeight.SemiBold,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
Icon(
Icons.AutoMirrored.Filled.KeyboardArrowRight,
contentDescription = null,
modifier = Modifier.size(18.dp),
tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
} else {
val enabled = switchEnabled && !isProfileLocked
val switchToDescription = stringResource(R.string.profile_shelf_switch_to)
Box(
modifier = Modifier
.size(48.dp)
.clip(CircleShape)
.combinedClickable(
enabled = true,
role = Role.Button,
onClick = { if (enabled) onSelect(choice.profile) },
onLongClick = { actionChoice = choice },
)
.semantics {
if (!enabled) disabled()
contentDescription = if (enabled) {
"$label. $switchToDescription"
} else {
label
}
},
contentAlignment = Alignment.Center,
) {
ProfileChoiceAvatar(
connectionViewModel,
choice,
resolvedProfile,
label,
36,
)
}
}
}
}
IconButton(
onClick = onOpenSwitcher,
modifier = Modifier.size(48.dp),
) {
Surface(
modifier = Modifier.size(40.dp),
shape = CircleShape,
color = MaterialTheme.colorScheme.surfaceContainerLow,
border = BorderStroke(
1.dp,
MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.42f),
),
) {
Box(contentAlignment = Alignment.Center) {
Icon(
Icons.Filled.MoreHoriz,
contentDescription = stringResource(R.string.profile_shelf_all_profiles),
modifier = Modifier.size(20.dp),
)
}
}
}
}
HorizontalDivider(color = MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.32f))
}
}
actionChoice?.let { choice ->
val selected = ProfileShelfPolicy.isSelected(choice, selectedProfile?.name)
val target = choice.profile ?: resolvedProfile
val label = profileChoiceLabel(choice, resolvedProfile)
ProfileShelfActionsDialog(
label = label,
canSwitch = switchEnabled && !isProfileLocked,
selected = selected,
canInspect = target != null,
lockedToChoice = isProfileLocked && lockedKey == choice.key,
onInspect = {
actionChoice = null
target?.name?.let(onInspect)
},
onPassport = {
actionChoice = null
if (!selected && switchEnabled && !isProfileLocked) onSelect(choice.profile)
onOpenPassport()
},
onToggleLock = {
actionChoice = null
if (isProfileLocked && lockedKey == choice.key) onUnlock() else onLock(choice.profile)
},
onHide = {
actionChoice = null
onHide(choice.profile?.name)
},
onDismiss = { actionChoice = null },
)
}
}
@OptIn(ExperimentalMaterial3Api::class, ExperimentalFoundationApi::class)
@Composable
fun ProfileSwitcherSheet(
connectionViewModel: ConnectionViewModel,
profiles: List<Profile>,
selectedProfile: Profile?,
resolvedProfile: Profile?,
presentation: ProfilePresentation,
isProfileLocked: Boolean,
switchEnabled: Boolean,
onSelect: (Profile?) -> Unit,
onManageDisplay: () -> Unit,
onDismiss: () -> Unit,
) {
val choices = remember(profiles, presentation, selectedProfile?.name) {
ProfileShelfPolicy.choices(profiles, presentation, selectedProfile?.name)
}
ModalBottomSheet(onDismissRequest = onDismiss) {
Column(
modifier = Modifier
.fillMaxWidth()
.heightIn(max = 560.dp)
.verticalScroll(rememberScrollState())
.padding(bottom = 24.dp),
) {
Text(
text = stringResource(R.string.profile_shelf_switch_agent),
modifier = Modifier.padding(horizontal = 24.dp, vertical = 12.dp),
style = MaterialTheme.typography.headlineSmall,
fontWeight = FontWeight.SemiBold,
)
if (isProfileLocked) {
Text(
text = stringResource(R.string.profile_shelf_locked_hint),
modifier = Modifier.padding(horizontal = 24.dp, vertical = 4.dp),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
choices.forEach { choice ->
val selected = ProfileShelfPolicy.isSelected(choice, selectedProfile?.name)
val label = profileChoiceLabel(choice, resolvedProfile)
val model = choice.profile?.model?.takeIf { it.isNotBlank() }
ListItem(
modifier = Modifier.selectable(
selected = selected,
enabled = selected || (switchEnabled && !isProfileLocked),
role = Role.RadioButton,
onClick = {
if (!selected) onSelect(choice.profile)
onDismiss()
},
),
headlineContent = {
Text(label, maxLines = 1, overflow = TextOverflow.Ellipsis)
},
supportingContent = if (model != null) {
{ Text(model, maxLines = 1, overflow = TextOverflow.Ellipsis) }
} else {
null
},
leadingContent = {
ProfileChoiceAvatar(connectionViewModel, choice, resolvedProfile, label, 42)
},
trailingContent = if (selected) {
{ Icon(Icons.Filled.Check, contentDescription = null) }
} else {
null
},
)
}
HorizontalDivider(modifier = Modifier.padding(top = 8.dp))
TextButton(
onClick = onManageDisplay,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 12.dp, vertical = 4.dp),
) {
Icon(Icons.Filled.Tune, contentDescription = null)
Spacer(Modifier.size(8.dp))
Text(stringResource(R.string.conn_info_manage_profiles))
}
}
}
}
@Composable
private fun ProfileChoiceAvatar(
connectionViewModel: ConnectionViewModel,
choice: ProfileChoice,
resolvedProfile: Profile?,
label: String,
size: Int,
) {
val iconProfileName = ProfileShelfPolicy.iconProfileName(choice)
val iconPath by connectionViewModel.profileIconFlow(iconProfileName).collectAsState(initial = null)
Box(modifier = Modifier.size(size.dp)) {
Surface(
modifier = Modifier.fillMaxSize(),
shape = CircleShape,
color = MaterialTheme.colorScheme.primary,
border = BorderStroke(
1.dp,
MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.55f),
),
) {
when {
!iconPath.isNullOrBlank() -> AsyncImage(
model = File(iconPath.orEmpty()),
contentDescription = null,
contentScale = ContentScale.Crop,
modifier = Modifier.fillMaxSize(),
)
resolvedProfile == null && choice.isServerDefault -> Box(contentAlignment = Alignment.Center) {
Icon(
Icons.Filled.Home,
contentDescription = null,
modifier = Modifier.size((size * 0.48f).dp),
tint = MaterialTheme.colorScheme.onPrimary,
)
}
else -> Box(contentAlignment = Alignment.Center) {
Text(
text = label.trim().firstOrNull()?.uppercase() ?: "H",
color = MaterialTheme.colorScheme.onPrimary,
style = MaterialTheme.typography.labelLarge,
fontWeight = FontWeight.Bold,
)
}
}
}
if (choice.isServerDefault && resolvedProfile != null) {
Surface(
modifier = Modifier
.align(Alignment.BottomStart)
.size((size * 0.38f).dp),
shape = CircleShape,
color = MaterialTheme.colorScheme.surfaceContainerHighest,
border = BorderStroke(1.dp, MaterialTheme.colorScheme.surface),
) {
Box(contentAlignment = Alignment.Center) {
Icon(
Icons.Filled.Home,
contentDescription = null,
modifier = Modifier.size((size * 0.22f).dp),
tint = MaterialTheme.colorScheme.onSurface,
)
}
}
}
}
}
@Composable
private fun ProfileShelfActionsDialog(
label: String,
canSwitch: Boolean,
selected: Boolean,
canInspect: Boolean,
lockedToChoice: Boolean,
onInspect: () -> Unit,
onPassport: () -> Unit,
onToggleLock: () -> Unit,
onHide: () -> Unit,
onDismiss: () -> Unit,
) {
AlertDialog(
onDismissRequest = onDismiss,
title = { Text(label, maxLines = 1, overflow = TextOverflow.Ellipsis) },
text = {
Column {
ProfileActionRow(Icons.Filled.Visibility, stringResource(R.string.profile_shelf_inspect), canInspect, onInspect)
ProfileActionRow(
Icons.Filled.Person,
stringResource(R.string.conn_info_agent_passport),
selected || canSwitch,
onPassport,
)
ProfileActionRow(
Icons.Filled.Lock,
stringResource(if (lockedToChoice) R.string.settings_unlock else R.string.settings_profile_lock),
true,
onToggleLock,
)
ProfileActionRow(
Icons.Filled.VisibilityOff,
stringResource(R.string.profile_shelf_hide),
!selected,
onHide,
)
}
},
confirmButton = { TextButton(onClick = onDismiss) { Text(stringResource(R.string.chat_dismiss)) } },
)
}
@Composable
private fun ProfileActionRow(
icon: androidx.compose.ui.graphics.vector.ImageVector,
label: String,
enabled: Boolean,
onClick: () -> Unit,
) {
TextButton(onClick = onClick, enabled = enabled, modifier = Modifier.fillMaxWidth()) {
Icon(icon, contentDescription = null)
Spacer(Modifier.size(12.dp))
Text(label, modifier = Modifier.weight(1f))
}
}
@Composable
private fun profileChoiceLabel(choice: ProfileChoice, resolvedProfile: Profile?): String =
if (choice.isServerDefault) {
stringResource(R.string.conn_info_server_default)
} else {
choice.profile?.let(AgentDisplay::profileDisplayName)
?: choice.profile?.name?.replaceFirstChar { it.uppercase() }
?: resolvedProfile?.let(AgentDisplay::profileDisplayName)
?: stringResource(R.string.chat_agent_default)
}
@@ -99,6 +99,39 @@ internal enum class SessionDrawerFilter {
internal const val SESSION_DRAWER_LIST_TAG = "session-drawer-list"
internal const val UNPINNED_STAR_ALPHA = 0.45f
data class ProfileSessionRow(
val profile: String,
val session: ChatSession,
)
data class ProvisionalThreadRow(
val chatId: String,
val title: String,
val messageCount: Int,
val lastActivityAt: Long,
)
private const val PROVISIONAL_THREAD_PREFIX = "proactive:"
internal fun sessionWorkLabels(session: ChatSession): List<String> = buildList {
val repo = (session.gitRepoRoot ?: session.workingDirectory)
?.trimEnd('/', '\\')
?.substringAfterLast('/')
?.substringAfterLast('\\')
?.takeIf { it.isNotBlank() }
repo?.let(::add)
session.gitBranch?.trim()?.takeIf { it.isNotBlank() }?.let(::add)
session.pullRequestNumber?.takeIf { it > 0 }?.let { number ->
val status = when {
session.pullRequestDraft -> "Draft"
!session.pullRequestState.isNullOrBlank() ->
session.pullRequestState.lowercase().replaceFirstChar { it.uppercaseChar() }
else -> null
}
add(listOfNotNull("PR #$number", status).joinToString(" · "))
}
}
internal fun sessionPinIcon(pinned: Boolean) =
if (pinned) Icons.Filled.Star else Icons.Outlined.StarBorder
@@ -145,10 +178,16 @@ fun SessionDrawerContent(
* filter view. The first message the user types opens the conversation.
*/
onNewThread: ((String) -> Unit)? = null,
provisionalThreads: List<ProvisionalThreadRow> = emptyList(),
onSelectProvisionalThread: ((String) -> Unit)? = null,
/** Gateway sources currently hidden from the drawer (default: cron+webhook). */
hiddenSources: Set<String> = emptySet(),
/** Toggle a source's visibility (persisted). Null hides the source filter. */
onToggleSourceHidden: ((String, Boolean) -> Unit)? = null,
allProfileSessions: List<ProfileSessionRow> = emptyList(),
allProfileSessionsLoading: Boolean = false,
onRefreshAllProfiles: (() -> Unit)? = null,
onSelectProfileSession: ((String, String) -> Unit)? = null,
) {
var renameDialogSession by remember { mutableStateOf<ChatSession?>(null) }
var newThreadDialog by remember { mutableStateOf(false) }
@@ -157,12 +196,26 @@ fun SessionDrawerContent(
var query by remember { mutableStateOf("") }
var searchExpanded by remember { mutableStateOf(false) }
var filter by remember { mutableStateOf(SessionDrawerFilter.All) }
var allProfilesOpen by remember { mutableStateOf(false) }
val listState = rememberLazyListState()
val trimmedQuery = query.trim()
// Threads affordance shows when the capability is active OR there's already at least one
// agent Thread (source=phone) in the list. If the filter is on Threads but they've
// vanished, fall back to All so the drawer never gets stuck on an empty hidden filter.
val showThreads = threadsCapabilityActive || sessions.any { isThreadSource(it.source) }
val provisionalSessions = provisionalThreads.map { thread ->
ChatSession(
sessionId = "$PROVISIONAL_THREAD_PREFIX${thread.chatId}",
title = thread.title,
model = null,
messageCount = thread.messageCount,
updatedAt = thread.lastActivityAt,
startedAt = thread.lastActivityAt,
lastActivityAt = thread.lastActivityAt,
source = "phone",
)
}
val allSessions = sessions + provisionalSessions
val showThreads = threadsCapabilityActive || allSessions.any { isThreadSource(it.source) }
val activeFilter = resolveSessionDrawerFilter(filter, showThreads, archiveSupported)
// External gateway sources present (discord/telegram/cron/…) for the source
// filter dropdown. Own chats (tui/api_server) + phone Threads aren't listed.
@@ -171,7 +224,7 @@ fun SessionDrawerContent(
.distinct()
.filter { sourceBadge(it) != null }
.sorted()
val visibleSessions = sessions
val visibleSessions = allSessions
.asSequence()
.filter { session ->
when (activeFilter) {
@@ -196,7 +249,8 @@ fun SessionDrawerContent(
needle.isBlank() ||
session.sessionId.contains(needle, ignoreCase = true) ||
session.title.orEmpty().contains(needle, ignoreCase = true) ||
session.model.orEmpty().contains(needle, ignoreCase = true)
session.model.orEmpty().contains(needle, ignoreCase = true) ||
sessionWorkLabels(session).any { it.contains(needle, ignoreCase = true) }
}
.sortedWith(
compareByDescending<ChatSession> { it.pinned }
@@ -355,6 +409,16 @@ fun SessionDrawerContent(
overflow = TextOverflow.Ellipsis,
)
}
if (onRefreshAllProfiles != null && onSelectProfileSession != null) {
TextButton(
onClick = {
allProfilesOpen = true
onRefreshAllProfiles()
},
) {
Text(stringResource(R.string.drawer_all_profiles))
}
}
Spacer(modifier = Modifier.height(8.dp))
@@ -489,7 +553,7 @@ fun SessionDrawerContent(
horizontalAlignment = Alignment.CenterHorizontally
) {
Text(
text = if (sessions.isEmpty()) stringResource(R.string.drawer_no_sessions) else stringResource(R.string.drawer_no_matching_sessions),
text = if (allSessions.isEmpty()) stringResource(R.string.drawer_no_sessions) else stringResource(R.string.drawer_no_matching_sessions),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant
)
@@ -513,7 +577,16 @@ fun SessionDrawerContent(
pinned = session.pinned,
archived = session.archived,
archiveSupported = archiveSupported,
onClick = { onSelectSession(session.sessionId) },
onClick = {
if (session.sessionId.startsWith(PROVISIONAL_THREAD_PREFIX)) {
onSelectProvisionalThread?.invoke(
session.sessionId.removePrefix(PROVISIONAL_THREAD_PREFIX),
)
} else {
onSelectSession(session.sessionId)
}
},
actionsEnabled = !session.sessionId.startsWith(PROVISIONAL_THREAD_PREFIX),
onTogglePinned = {
onSetSessionPinned(session.sessionId, !session.pinned)
},
@@ -620,6 +693,82 @@ fun SessionDrawerContent(
}
)
}
if (allProfilesOpen) {
var allQuery by remember { mutableStateOf("") }
val needle = allQuery.trim()
val rows = allProfileSessions.filter { row ->
needle.isBlank() ||
row.profile.contains(needle, ignoreCase = true) ||
row.session.title.orEmpty().contains(needle, ignoreCase = true) ||
row.session.sessionId.contains(needle, ignoreCase = true) ||
sessionWorkLabels(row.session).any { it.contains(needle, ignoreCase = true) }
}
AlertDialog(
onDismissRequest = { allProfilesOpen = false },
title = { Text(stringResource(R.string.drawer_all_profiles)) },
text = {
Column(modifier = Modifier.fillMaxWidth()) {
OutlinedTextField(
value = allQuery,
onValueChange = { allQuery = it },
modifier = Modifier.fillMaxWidth(),
singleLine = true,
leadingIcon = { Icon(Icons.Filled.Search, contentDescription = null) },
placeholder = { Text(stringResource(R.string.drawer_search_placeholder)) },
)
Spacer(modifier = Modifier.height(8.dp))
when {
allProfileSessionsLoading && allProfileSessions.isEmpty() ->
CircularProgressIndicator(modifier = Modifier.align(Alignment.CenterHorizontally))
rows.isEmpty() -> Text(
stringResource(R.string.drawer_no_profile_sessions),
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
else -> LazyColumn(modifier = Modifier.height(420.dp)) {
items(rows, key = { "${it.profile}:${it.session.sessionId}" }) { row ->
Column(
modifier = Modifier
.fillMaxWidth()
.clickable {
allProfilesOpen = false
onSelectProfileSession?.invoke(row.profile, row.session.sessionId)
}
.padding(vertical = 10.dp, horizontal = 4.dp),
) {
Text(
row.session.title?.takeIf { it.isNotBlank() }
?: stringResource(R.string.drawer_untitled),
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
Text(
row.profile,
style = relayMetadataStyle(),
color = RelayRefresh.Relay,
)
sessionWorkLabels(row.session).takeIf { it.isNotEmpty() }?.let { labels ->
Text(
labels.joinToString(" • "),
style = relayMetadataStyle(),
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
}
}
}
}
},
confirmButton = {
TextButton(onClick = { allProfilesOpen = false }) {
Text(stringResource(R.string.drawer_close))
}
},
)
}
}
@Composable
@@ -632,6 +781,7 @@ private fun SessionItem(
archived: Boolean,
archiveSupported: Boolean,
onClick: () -> Unit,
actionsEnabled: Boolean = true,
onTogglePinned: () -> Unit,
onToggleArchived: () -> Unit,
onRename: () -> Unit,
@@ -685,6 +835,28 @@ private fun SessionItem(
MaterialTheme.colorScheme.onSurface
}
)
val workLabels = sessionWorkLabels(session)
if (workLabels.isNotEmpty()) {
Row(
horizontalArrangement = Arrangement.spacedBy(5.dp),
modifier = Modifier
.padding(top = 4.dp)
.horizontalScroll(rememberScrollState()),
) {
workLabels.forEach { label ->
Text(
text = label,
style = relayMetadataStyle(),
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
modifier = Modifier
.clip(RoundedCornerShape(6.dp))
.background(MaterialTheme.colorScheme.surfaceVariant)
.padding(horizontal = 6.dp, vertical = 1.dp),
)
}
}
}
Row(
horizontalArrangement = Arrangement.spacedBy(8.dp),
verticalAlignment = Alignment.CenterVertically,
@@ -750,7 +922,7 @@ private fun SessionItem(
}
}
Box {
if (actionsEnabled) Box {
IconButton(
onClick = { menuOpen = true },
modifier = Modifier.size(36.dp),
@@ -0,0 +1,52 @@
package com.hermesandroid.relay.ui.components
/**
* Model identity shown by chat-scoped controls.
*
* A running/resumed session owns its runtime model. Profile and server values
* are defaults only, and may seed a fresh draft, but must never repaint an
* existing session merely because a picker or Agent Passport was opened.
*/
internal data class SessionModelUiState(
val model: String?,
val provider: String?,
val pickerModel: String?,
val pickerProvider: String?,
val inheritsProfileDefault: Boolean,
)
internal fun resolveSessionModelUiState(
hasSession: Boolean,
pendingModel: String?,
pendingProvider: String?,
gatewayModel: String?,
gatewayProvider: String?,
persistedSessionModel: String?,
profileDefaultModel: String?,
serverDefaultModel: String?,
): SessionModelUiState {
fun String?.present(): String? = this?.trim()?.takeIf(String::isNotEmpty)
val pending = pendingModel.present()
val gateway = gatewayModel.present()
val persisted = persistedSessionModel.present()
val profileDefault = profileDefaultModel.present()
val serverDefault = serverDefaultModel.present()
val effectiveModel = if (hasSession) {
pending ?: gateway ?: persisted ?: profileDefault ?: serverDefault
} else {
pending ?: profileDefault ?: gateway ?: serverDefault
}
val effectiveProvider = pendingProvider.present()
?: gatewayProvider.present()
return SessionModelUiState(
model = effectiveModel,
provider = effectiveProvider,
// A live session highlights what it is actually running. On a fresh
// draft, null remains the explicit "inherit profile default" state.
pickerModel = if (hasSession) effectiveModel else pending,
pickerProvider = if (hasSession) effectiveProvider else pendingProvider.present(),
inheritsProfileDefault = !hasSession && pending == null,
)
}
@@ -0,0 +1,41 @@
package com.hermesandroid.relay.ui.components
data class SessionReference(val profile: String, val sessionId: String) {
val label: String
get() = "$profile · ${sessionId.takeLast(10)}"
}
private val SESSION_REFERENCE = Regex("@session:([A-Za-z0-9_.-]{1,64})/([A-Za-z0-9_.:-]{1,160})")
/** Find session references outside fenced and inline code. */
internal fun parseSessionReferences(markdown: String): List<SessionReference> {
val visible = buildString(markdown.length) {
var fenced = false
markdown.lineSequence().forEach { line ->
if (line.trimStart().startsWith("```")) {
fenced = !fenced
appendLine()
} else if (fenced) {
appendLine()
} else {
var inline = false
line.forEach { char ->
if (char == '`') inline = !inline
append(if (inline || char == '`') ' ' else char)
}
appendLine()
}
}
}
return SESSION_REFERENCE.findAll(visible)
.map {
SessionReference(
it.groupValues[1],
it.groupValues[2].trimEnd('.', ',', ';', '!', '?', ')', ']', '}'),
)
}
.filter { it.sessionId.isNotBlank() }
.distinct()
.take(16)
.toList()
}
@@ -0,0 +1,96 @@
package com.hermesandroid.relay.ui.components
import android.content.Context
import android.net.Uri
import android.util.Log
import kotlinx.serialization.json.Json
import java.io.File
import java.io.InputStream
sealed interface SphereSkinImportResult {
data class Success(val id: String, val label: String) : SphereSkinImportResult
data class Failure(val reason: String) : SphereSkinImportResult
}
/** Imports one declarative sphere-skin JSON file into app-scoped local storage. */
object SphereSkinImporter {
private const val TAG = "SphereSkinImporter"
private const val MAX_BYTES = 256L * 1024L
private val json = Json {
ignoreUnknownKeys = true
isLenient = true
}
fun importUri(context: Context, uri: Uri): SphereSkinImportResult {
val input = try {
context.contentResolver.openInputStream(uri)
} catch (t: Throwable) {
Log.w(TAG, "openInputStream failed: ${t.message}")
null
} ?: return SphereSkinImportResult.Failure("Couldn't open that file.")
return input.use { importStream(it, SphereSkinLoader.userDir(context)) }
}
/** Pure import core used by tests: bounds, parses, validates, then swaps with rollback. */
internal fun importStream(input: InputStream, skinsDir: File): SphereSkinImportResult {
return try {
val bytes = readBounded(input)
?: return SphereSkinImportResult.Failure("That sphere file is too large.")
val spec = try {
json.decodeFromString(SphereSpec.serializer(), bytes.decodeToString())
} catch (_: Throwable) {
return SphereSkinImportResult.Failure("That sphere file isn't valid JSON.")
}
val resolved = spec.copy(id = spec.id.ifBlank { "custom-sphere" })
val skin = try {
resolved.toSkin()
} catch (t: Throwable) {
return SphereSkinImportResult.Failure(t.message ?: "That isn't a valid sphere skin.")
}
skinsDir.mkdirs()
val target = File(skinsDir, "${safeFileName(skin.id)}.json")
val staging = File(skinsDir, ".${target.name}.tmp")
val backup = File(skinsDir, ".${target.name}.bak")
staging.writeBytes(bytes)
if (backup.exists() && !target.exists()) backup.renameTo(target)
if (backup.exists() && target.exists()) backup.delete()
if (target.exists() && !target.renameTo(backup)) {
staging.delete()
return SphereSkinImportResult.Failure("Couldn't replace the existing sphere skin.")
}
if (!staging.renameTo(target)) {
staging.delete()
if (backup.exists()) backup.renameTo(target)
return SphereSkinImportResult.Failure("Couldn't save that sphere skin.")
}
backup.delete()
SphereSkinImportResult.Success(skin.id, skin.label)
} catch (t: Throwable) {
Log.w(TAG, "import failed: ${t.message}")
SphereSkinImportResult.Failure("Couldn't import that sphere skin.")
}
}
private fun readBounded(input: InputStream): ByteArray? {
val buffer = ByteArray(8 * 1024)
val output = java.io.ByteArrayOutputStream()
var total = 0L
while (true) {
val count = input.read(buffer)
if (count < 0) break
total += count
if (total > MAX_BYTES) return null
output.write(buffer, 0, count)
}
return output.toByteArray()
}
private fun safeFileName(id: String): String = id.trim()
.map { if (it.isLetterOrDigit() || it == '-' || it == '_' || it == '.') it else '-' }
.joinToString("")
.trim('.', '-')
.ifBlank { "custom-sphere" }
}
@@ -25,8 +25,11 @@ import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material3.Icon
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedTextField
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
@@ -73,11 +76,13 @@ fun SubagentLane(
taskIndex: Int,
calls: List<ToolCall>,
modifier: Modifier = Modifier,
onSteer: ((subagentId: String, instruction: String) -> Unit)? = null,
) {
val anyRunning = calls.any { !it.isComplete }
val allComplete = calls.isNotEmpty() && calls.all { it.isComplete }
val anyFailed = calls.any { it.isComplete && it.success == false }
val runningCount = calls.count { !it.isComplete }
val steerableId = calls.firstNotNullOfOrNull { it.subagentId?.takeIf(String::isNotBlank) }
val laneLabel = calls.firstNotNullOfOrNull { call ->
call.taskLabel?.takeIf { it.isNotBlank() }
@@ -106,6 +111,8 @@ fun SubagentLane(
val failureLabel = stringResource(R.string.cd_subagent_failed)
var expanded by remember { mutableStateOf(!allComplete) }
var showSteerDialog by remember { mutableStateOf(false) }
var steerText by remember { mutableStateOf("") }
// Auto-collapse when the last child completes — same pattern as
// ToolProgressCard's LaunchedEffect(toolCall.isComplete).
@@ -162,6 +169,12 @@ fun SubagentLane(
modifier = Modifier.weight(1f),
)
if (anyRunning && steerableId != null && onSteer != null) {
TextButton(onClick = { showSteerDialog = true }) {
Text("Redirect")
}
}
Text(
text = statusMeta,
style = relayMetadataStyle(),
@@ -202,4 +215,33 @@ fun SubagentLane(
}
}
}
if (showSteerDialog && steerableId != null && onSteer != null) {
AlertDialog(
onDismissRequest = { showSteerDialog = false },
title = { Text("Redirect subagent") },
text = {
OutlinedTextField(
value = steerText,
onValueChange = { steerText = it },
label = { Text("New instruction") },
modifier = Modifier.fillMaxWidth(),
)
},
confirmButton = {
TextButton(
onClick = {
val instruction = steerText.trim()
showSteerDialog = false
steerText = ""
onSteer(steerableId, instruction)
},
enabled = steerText.isNotBlank(),
) { Text("Redirect") }
},
dismissButton = {
TextButton(onClick = { showSteerDialog = false }) { Text("Cancel") }
},
)
}
}
@@ -15,12 +15,11 @@ import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material.icons.filled.Psychology
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
@@ -29,6 +28,9 @@ import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.LocalLocale
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.stateDescription
import androidx.compose.ui.semantics.semantics
import com.hermesandroid.relay.R
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.style.TextOverflow
@@ -49,7 +51,12 @@ fun ThinkingBlock(
/** Stable key when this interactive block participates in Chat pet terrain. */
petObstacleKey: String? = null,
) {
if (thinkingContent.isBlank()) return
var expanded by remember { mutableStateOf(isStreaming) }
var userToggled by remember { mutableStateOf(false) }
LaunchedEffect(isStreaming) {
if (!userToggled) expanded = isStreaming
}
val locale = LocalLocale.current.platformLocale
val timeLabel = timestamp?.let {
remember(it, locale) {
@@ -57,8 +64,13 @@ fun ThinkingBlock(
.format(java.util.Date(it))
}
}
val expansionState = if (expanded) {
stringResource(R.string.tool_progress_state_expanded)
} else {
stringResource(R.string.tool_progress_state_collapsed)
}
Card(
Column(
modifier = modifier
.then(
if (petObstacleKey != null) {
@@ -71,18 +83,20 @@ fun ThinkingBlock(
},
)
.fillMaxWidth(),
colors = CardDefaults.cardColors(
containerColor = MaterialTheme.colorScheme.surfaceVariant.copy(alpha = 0.5f)
)
) {
Column(modifier = Modifier.padding(8.dp)) {
// Header row
Row(
modifier = Modifier
.fillMaxWidth()
.clickable { expanded = !expanded },
verticalAlignment = Alignment.CenterVertically
) {
Row(
modifier = Modifier
.fillMaxWidth()
.clickable(role = Role.Button) {
userToggled = true
expanded = !expanded
}
.semantics {
stateDescription = expansionState
}
.padding(horizontal = 4.dp, vertical = 3.dp),
verticalAlignment = Alignment.CenterVertically
) {
Icon(
imageVector = Icons.Filled.Psychology,
contentDescription = accessibilityLabel,
@@ -91,9 +105,13 @@ fun ThinkingBlock(
)
Spacer(modifier = Modifier.width(6.dp))
Text(
text = headerText ?: if (isStreaming) stringResource(R.string.thinking_thinking) else stringResource(R.string.thinking_title),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.tertiary
text = headerText ?: if (isStreaming) {
stringResource(R.string.thinking_thinking)
} else {
stringResource(R.string.thinking_settled)
},
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant
)
Spacer(modifier = Modifier.weight(1f))
if (!isStreaming && timeLabel != null) {
@@ -110,25 +128,23 @@ fun ThinkingBlock(
modifier = Modifier.size(16.dp),
tint = MaterialTheme.colorScheme.onSurfaceVariant
)
}
}
// Collapsible content
AnimatedVisibility(
visible = expanded,
enter = expandVertically(),
exit = shrinkVertically()
) {
Text(
text = thinkingContent,
style = MaterialTheme.typography.bodySmall.copy(
fontFamily = FontFamily.Default,
color = MaterialTheme.colorScheme.onSurfaceVariant
),
modifier = Modifier.padding(top = 4.dp),
maxLines = if (isStreaming) Int.MAX_VALUE else 50,
overflow = TextOverflow.Ellipsis
)
}
AnimatedVisibility(
visible = expanded,
enter = expandVertically(),
exit = shrinkVertically()
) {
Text(
text = thinkingContent,
style = MaterialTheme.typography.bodySmall.copy(
fontFamily = FontFamily.Default,
color = MaterialTheme.colorScheme.onSurfaceVariant
),
modifier = Modifier.padding(start = 26.dp, top = 2.dp, end = 4.dp, bottom = 4.dp),
maxLines = if (isStreaming) Int.MAX_VALUE else 50,
overflow = TextOverflow.Ellipsis
)
}
}
}
@@ -0,0 +1,284 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.animation.AnimatedContent
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.expandVertically
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.animation.shrinkVertically
import androidx.compose.animation.slideInVertically
import androidx.compose.animation.slideOutVertically
import androidx.compose.animation.togetherWith
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material.icons.filled.MoreHoriz
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.key
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.LocalResources
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.stateDescription
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ToolCall
import com.hermesandroid.relay.ui.components.pet.petObstacleSurface
private val TOOL_ACTIVITY_PET_ROUTES = setOf("chat")
private val FILE_EDIT_TOOLS = setOf("edit_file", "write_file", "apply_patch", "patch")
private val ATTENTION_TOOLS = setOf(
"clarify",
"delegate_task",
"image_generate",
"approval",
"request_user_input",
"ask_user",
"sudo",
"secret",
)
internal sealed interface ToolTranscriptItem {
data class ActivityRun(val calls: List<ToolCall>) : ToolTranscriptItem
data class Standalone(val call: ToolCall) : ToolTranscriptItem
}
/** Off suppresses diagnostics, never an attention or deliverable surface. */
internal fun ToolTranscriptItem.isVisibleForToolDisplay(toolDisplay: String): Boolean =
this is ToolTranscriptItem.Standalone || toolDisplay != "off"
/**
* Preserve source order while folding only routine activity. Calls that are
* actionable, security-relevant, failed, or deliver a file/media result split
* the run and retain their own surface.
*/
internal fun groupTranscriptTools(calls: List<ToolCall>): List<ToolTranscriptItem> {
val result = mutableListOf<ToolTranscriptItem>()
val run = mutableListOf<ToolCall>()
fun flushRun() {
if (run.isNotEmpty()) {
result += ToolTranscriptItem.ActivityRun(run.toList())
run.clear()
}
}
calls.forEach { call ->
if (call.requiresStandaloneToolSurface()) {
flushRun()
result += ToolTranscriptItem.Standalone(call)
} else {
run += call
}
}
flushRun()
return result
}
internal fun ToolCall.requiresStandaloneToolSurface(): Boolean {
val normalized = name.trim().lowercase()
return success == false ||
!error.isNullOrBlank() ||
outputRisk != null ||
normalized in FILE_EDIT_TOOLS ||
normalized in ATTENTION_TOOLS
}
internal data class ToolActivityCounts(
val reads: Int = 0,
val searches: Int = 0,
val commands: Int = 0,
val browserActions: Int = 0,
val deviceActions: Int = 0,
val other: Int = 0,
)
internal fun countToolActivity(calls: List<ToolCall>): ToolActivityCounts {
var counts = ToolActivityCounts()
calls.forEach { call ->
val name = call.name.trim().lowercase()
counts = when {
name.contains("search") || name.contains("grep") || name.contains("find") ->
counts.copy(searches = counts.searches + 1)
name.contains("terminal") || name.contains("shell") || name.contains("exec") ||
name.contains("command") || name.contains("bash") || name.contains("powershell") ->
counts.copy(commands = counts.commands + 1)
name.contains("browser") || name.contains("chrome") || name.contains("playwright") ||
name.startsWith("web_") -> counts.copy(browserActions = counts.browserActions + 1)
name.contains("android") || name.contains("adb") || name.contains("device") ||
name.contains("tap") || name.contains("swipe") ->
counts.copy(deviceActions = counts.deviceActions + 1)
name.contains("read") || name.contains("list") || name.contains("glob") ||
name.contains("open") || name.contains("inspect") -> counts.copy(reads = counts.reads + 1)
else -> counts.copy(other = counts.other + 1)
}
}
return counts
}
@Composable
fun ToolActivityRun(
calls: List<ToolCall>,
live: Boolean,
detailed: Boolean,
modifier: Modifier = Modifier,
messageTimestamp: Long? = null,
petObstacleKey: String? = null,
onExpandedChange: (Boolean) -> Unit = {},
) {
if (calls.isEmpty()) return
var expanded by rememberSaveable(calls.first().uiKey) { mutableStateOf(false) }
val summary = toolActivitySummary(countToolActivity(calls), live)
val stateLabel = if (expanded) {
stringResource(R.string.tool_progress_cd_collapse)
} else {
stringResource(R.string.tool_progress_cd_expand)
}
val expansionState = if (expanded) {
stringResource(R.string.tool_progress_state_expanded)
} else {
stringResource(R.string.tool_progress_state_collapsed)
}
Column(
modifier = modifier
.then(
if (petObstacleKey != null) {
Modifier.petObstacleSurface(petObstacleKey, TOOL_ACTIVITY_PET_ROUTES)
} else {
Modifier
},
)
.fillMaxWidth(),
) {
Row(
modifier = Modifier
.fillMaxWidth()
.clickable(role = Role.Button) {
expanded = !expanded
onExpandedChange(expanded)
}
.semantics {
contentDescription = summary
stateDescription = expansionState
}
.padding(horizontal = 4.dp, vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(
imageVector = Icons.Filled.MoreHoriz,
contentDescription = null,
modifier = Modifier.size(16.dp),
tint = if (live) MaterialTheme.colorScheme.tertiary
else MaterialTheme.colorScheme.onSurfaceVariant,
)
Spacer(modifier = Modifier.width(6.dp))
Text(
text = summary,
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.weight(1f),
)
Icon(
imageVector = if (expanded) Icons.Filled.ExpandLess else Icons.Filled.ExpandMore,
contentDescription = stateLabel,
modifier = Modifier.size(16.dp),
tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (live && !expanded) {
val latest = calls.last()
AnimatedContent(
targetState = latest.uiKey,
transitionSpec = {
(slideInVertically { it / 2 } + fadeIn()) togetherWith
(slideOutVertically { -it / 2 } + fadeOut())
},
label = "toolActivityTicker",
) { latestKey ->
val visible = calls.lastOrNull { it.uiKey == latestKey } ?: latest
Text(
text = toolActivityTickerLabel(visible),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant.copy(alpha = 0.78f),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.padding(start = 26.dp, end = 4.dp, bottom = 4.dp),
)
}
}
AnimatedVisibility(
visible = expanded,
enter = expandVertically(),
exit = shrinkVertically(),
) {
Column(modifier = Modifier.padding(start = 22.dp, top = 2.dp)) {
calls.forEach { call ->
key(call.uiKey) {
if (detailed) {
ToolProgressCard(
toolCall = call,
messageTimestamp = messageTimestamp,
onExpandedChange = onExpandedChange,
)
} else {
CompactToolCall(toolCall = call)
}
Spacer(modifier = Modifier.height(4.dp))
}
}
}
}
}
}
@Composable
private fun toolActivitySummary(counts: ToolActivityCounts, live: Boolean): String {
val resources = LocalResources.current
val clauses = buildList {
fun addClause(count: Int, liveRes: Int, settledRes: Int) {
if (count > 0) add(resources.getQuantityString(if (live) liveRes else settledRes, count, count))
}
addClause(counts.reads, R.plurals.tool_run_reading, R.plurals.tool_run_read)
addClause(counts.searches, R.plurals.tool_run_searching, R.plurals.tool_run_searched)
addClause(counts.commands, R.plurals.tool_run_running_commands, R.plurals.tool_run_ran_commands)
addClause(counts.browserActions, R.plurals.tool_run_browsing, R.plurals.tool_run_browsed)
addClause(counts.deviceActions, R.plurals.tool_run_using_device, R.plurals.tool_run_used_device)
addClause(counts.other, R.plurals.tool_run_using_tools, R.plurals.tool_run_used_tools)
}
return clauses.joinToString(" · ")
}
@Composable
private fun toolActivityTickerLabel(call: ToolCall): String {
val name = localizeToolName(call.name).ifBlank { stringResource(R.string.tool_preparing) }
return when {
call.isGenerating && !call.isComplete -> stringResource(R.string.tool_run_preparing, name)
!call.isComplete -> stringResource(R.string.tool_run_running, name)
else -> stringResource(R.string.tool_run_finished, name)
}
}
@@ -0,0 +1,368 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.background
import androidx.compose.foundation.border
import androidx.compose.foundation.horizontalScroll
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.BasicTextField
import androidx.compose.foundation.text.KeyboardActions
import androidx.compose.foundation.text.KeyboardOptions
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.KeyboardArrowDown
import androidx.compose.material.icons.filled.KeyboardArrowUp
import androidx.compose.material.icons.filled.Search
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.Immutable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableIntStateOf
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.focus.FocusRequester
import androidx.compose.ui.focus.focusRequester
import androidx.compose.ui.graphics.SolidColor
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.input.ImeAction
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.data.ChatMessage
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.ui.theme.LocalBrand
@Immutable
data class TranscriptMatch(
val messageUiKey: String,
val messageIndex: Int,
val start: Int,
val endExclusive: Int,
)
@Immutable
data class TranscriptTurnMarker(
val messageUiKey: String,
val messageIndex: Int,
val turnNumber: Int,
val label: String,
val matchCount: Int,
val containsActiveMatch: Boolean,
)
@Immutable
data class TranscriptNavigationModel(
val matches: List<TranscriptMatch>,
val turns: List<TranscriptTurnMarker>,
)
/**
* User-facing copy is injectable so the component remains reusable and its
* eventual ChatScreen integration can supply localized resources without
* coupling the pure navigation model to Android resources.
*/
@Immutable
data class TranscriptNavigatorStrings(
val searchPlaceholder: String = "Search conversation",
val previousMatch: String = "Previous match",
val nextMatch: String = "Next match",
val closeSearch: String = "Close search",
val noResults: String = "No results",
val resultCount: (current: Int, total: Int) -> String = { current, total -> "$current of $total" },
val resultCountDescription: (current: Int, total: Int) -> String = { current, total ->
if (total == 0) "No search results" else "Search result $current of $total"
},
val turnDescription: (turn: Int, label: String, matches: Int) -> String = { turn, label, matches ->
val suffix = if (matches == 1) ", 1 match" else if (matches > 1) ", $matches matches" else ""
"Jump to turn $turn: $label$suffix"
},
)
object TranscriptNavigatorTestTags {
const val Query = "transcript-search-query"
const val ResultCount = "transcript-search-result-count"
const val Previous = "transcript-search-previous"
const val Next = "transcript-search-next"
const val Close = "transcript-search-close"
const val TurnPrefix = "transcript-turn-"
}
/**
* Compact, self-contained find bar plus prompt rail for an active transcript.
* All jump callbacks use [ChatMessage.uiKey], the same stable identity used by
* Chat's LazyColumn, so a history reconciliation cannot invalidate a target.
*/
@Composable
fun TranscriptSearchNavigator(
messages: List<ChatMessage>,
onJumpToMessage: (messageUiKey: String) -> Unit,
onClose: () -> Unit,
modifier: Modifier = Modifier,
initialQuery: String = "",
strings: TranscriptNavigatorStrings = TranscriptNavigatorStrings(),
) {
val brand = LocalBrand.current
var query by rememberSaveable { mutableStateOf(initialQuery) }
var activeMatchIndex by rememberSaveable { mutableIntStateOf(0) }
val model = remember(messages, query, activeMatchIndex) {
buildTranscriptNavigationModel(messages, query, activeMatchIndex)
}
val normalizedActiveIndex = activeMatchIndex.coerceIn(0, (model.matches.size - 1).coerceAtLeast(0))
val focusRequester = remember { FocusRequester() }
LaunchedEffect(Unit) {
runCatching { focusRequester.requestFocus() }
}
fun selectMatch(index: Int) {
if (model.matches.isEmpty()) return
val normalized = Math.floorMod(index, model.matches.size)
activeMatchIndex = normalized
onJumpToMessage(model.matches[normalized].messageUiKey)
}
Column(
modifier = modifier
.fillMaxWidth()
.background(brand.navy)
.border(1.dp, brand.line, RoundedCornerShape(14.dp))
.padding(horizontal = 8.dp, vertical = 6.dp),
verticalArrangement = Arrangement.spacedBy(2.dp),
) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(2.dp),
) {
Row(
modifier = Modifier
.weight(1f)
.clip(RoundedCornerShape(10.dp))
.background(brand.surfaceLow)
.border(1.dp, brand.line, RoundedCornerShape(10.dp))
.padding(horizontal = 10.dp, vertical = 8.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Icon(
imageVector = Icons.Filled.Search,
contentDescription = null,
tint = brand.muted,
modifier = Modifier.size(18.dp),
)
BasicTextField(
value = query,
onValueChange = {
query = it
activeMatchIndex = 0
},
modifier = Modifier
.weight(1f)
.focusRequester(focusRequester)
.testTag(TranscriptNavigatorTestTags.Query),
singleLine = true,
textStyle = MaterialTheme.typography.bodyMedium.copy(color = brand.ink),
cursorBrush = SolidColor(brand.relay),
keyboardOptions = KeyboardOptions(imeAction = ImeAction.Search),
keyboardActions = KeyboardActions(onSearch = { selectMatch(normalizedActiveIndex) }),
decorationBox = { inner ->
Box {
if (query.isEmpty()) {
Text(
text = strings.searchPlaceholder,
color = brand.dim,
style = MaterialTheme.typography.bodyMedium,
)
}
inner()
}
},
)
}
val current = if (model.matches.isEmpty()) 0 else normalizedActiveIndex + 1
Text(
text = if (model.matches.isEmpty() && query.isNotBlank()) {
strings.noResults
} else {
strings.resultCount(current, model.matches.size)
},
color = brand.muted,
style = MaterialTheme.typography.labelSmall,
maxLines = 1,
modifier = Modifier
.testTag(TranscriptNavigatorTestTags.ResultCount)
.semantics {
contentDescription = strings.resultCountDescription(current, model.matches.size)
},
)
IconButton(
onClick = { selectMatch(normalizedActiveIndex - 1) },
enabled = model.matches.isNotEmpty(),
modifier = Modifier.testTag(TranscriptNavigatorTestTags.Previous),
) {
Icon(Icons.Filled.KeyboardArrowUp, strings.previousMatch, tint = brand.ink)
}
IconButton(
onClick = { selectMatch(normalizedActiveIndex + 1) },
enabled = model.matches.isNotEmpty(),
modifier = Modifier.testTag(TranscriptNavigatorTestTags.Next),
) {
Icon(Icons.Filled.KeyboardArrowDown, strings.nextMatch, tint = brand.ink)
}
IconButton(
onClick = onClose,
modifier = Modifier.testTag(TranscriptNavigatorTestTags.Close),
) {
Icon(Icons.Filled.Close, strings.closeSearch, tint = brand.ink)
}
}
TranscriptTurnRail(
turns = model.turns,
onJumpToMessage = onJumpToMessage,
strings = strings,
)
}
}
@Composable
fun TranscriptTurnRail(
turns: List<TranscriptTurnMarker>,
onJumpToMessage: (messageUiKey: String) -> Unit,
modifier: Modifier = Modifier,
strings: TranscriptNavigatorStrings = TranscriptNavigatorStrings(),
) {
if (turns.isEmpty()) return
val brand = LocalBrand.current
Row(
modifier = modifier
.fillMaxWidth()
.horizontalScroll(rememberScrollState()),
verticalAlignment = Alignment.CenterVertically,
) {
turns.forEach { turn ->
IconButton(
onClick = { onJumpToMessage(turn.messageUiKey) },
modifier = Modifier
.testTag("${TranscriptNavigatorTestTags.TurnPrefix}${turn.messageUiKey}")
.semantics {
contentDescription = strings.turnDescription(
turn.turnNumber,
turn.label,
turn.matchCount,
)
},
) {
Box(
modifier = Modifier
.size(if (turn.containsActiveMatch) 12.dp else 8.dp)
.clip(RoundedCornerShape(50))
.background(
when {
turn.containsActiveMatch -> brand.relay
turn.matchCount > 0 -> brand.purple
else -> brand.dim
},
),
)
}
}
}
}
internal fun buildTranscriptNavigationModel(
messages: List<ChatMessage>,
query: String,
activeMatchIndex: Int = 0,
): TranscriptNavigationModel {
val needle = query.trim()
val matches = if (needle.isEmpty()) {
emptyList()
} else {
buildList {
messages.forEachIndexed { messageIndex, message ->
val text = message.searchableRenderedText()
var start = 0
while (start <= text.length - needle.length) {
val found = text.indexOf(needle, startIndex = start, ignoreCase = true)
if (found < 0) break
add(TranscriptMatch(message.uiKey, messageIndex, found, found + needle.length))
start = found + needle.length.coerceAtLeast(1)
}
}
}
}
val activeMatch = matches.getOrNull(activeMatchIndex.coerceIn(0, (matches.size - 1).coerceAtLeast(0)))
val userIndexes = messages.indices.filter { messages[it].role == MessageRole.USER }
val turns = userIndexes.mapIndexed { ordinal, messageIndex ->
val endExclusive = userIndexes.getOrNull(ordinal + 1) ?: messages.size
val turnMatches = matches.count { it.messageIndex in messageIndex until endExclusive }
val prompt = messages[messageIndex]
TranscriptTurnMarker(
messageUiKey = prompt.uiKey,
messageIndex = messageIndex,
turnNumber = ordinal + 1,
label = prompt.content.compactTranscriptLabel("Prompt ${ordinal + 1}"),
matchCount = turnMatches,
containsActiveMatch = activeMatch?.messageIndex?.let { it in messageIndex until endExclusive } == true,
)
}
return TranscriptNavigationModel(matches = matches, turns = turns)
}
internal fun ChatMessage.searchableRenderedText(): String = buildList {
add(content)
add(thinkingContent)
moaReferences.forEach {
add(it.label)
add(it.text)
}
toolCalls.forEach {
add(it.name)
add(it.taskLabel.orEmpty())
add(it.args.orEmpty())
add(it.result.orEmpty())
add(it.error.orEmpty())
}
attachments.forEach {
add(it.fileName.orEmpty())
add(it.errorMessage.orEmpty())
}
cards.forEach { card ->
add(card.title.orEmpty())
add(card.subtitle.orEmpty())
add(card.body.orEmpty())
card.fields.forEach {
add(it.label)
add(it.value)
}
card.actions.forEach { add(it.label) }
add(card.footer.orEmpty())
}
}.filter(String::isNotBlank).joinToString("\n")
private fun String.compactTranscriptLabel(fallback: String): String {
val compact = trim().replace(Regex("\\s+"), " ")
return when {
compact.isEmpty() -> fallback
compact.length <= 64 -> compact
else -> compact.take(61).trimEnd() + "…"
}
}
@@ -104,8 +104,8 @@ interface AgentAvatar {
}
/**
* Legacy ambient-visualization seam. The app now provides [SphereAvatar] here;
* floating companions are published through [LocalFloatingPet].
* Central/ambient visualization seam. The app provides the independently saved
* Sphere or pet-format background here; floating companions use [LocalFloatingPet].
*/
val LocalAgentAvatar = staticCompositionLocalOf<AgentAvatar> { SphereAvatar }
@@ -117,14 +117,20 @@ val LocalAvailableAvatars = staticCompositionLocalOf<List<AgentAvatar>> { listOf
/**
* The optional floating pet companion. Unlike [LocalAgentAvatar], this does not
* replace the ambient sphere or the active profile's identity image. `null`
* means the user has not selected a companion.
* replace the independently selected central/background visualization or the
* active profile's identity image. `null` means no companion is selected.
*/
val LocalFloatingPet = staticCompositionLocalOf<AgentAvatar?> { null }
/** User-installed pets available to the companion picker (sphere excluded). */
val LocalAvailablePets = staticCompositionLocalOf<List<AgentAvatar>> { emptyList() }
/** Resolve a central visualization without ever coupling it to floating state. */
internal fun resolveBackgroundAvatar(
selectedId: String,
availablePets: List<AgentAvatar>,
): AgentAvatar = availablePets.firstOrNull { it.id == selectedId } ?: SphereAvatar
/** Ambient sphere/background visibility, independent of the motion setting. */
val LocalBackgroundVisualizationEnabled = staticCompositionLocalOf { true }
@@ -12,6 +12,8 @@ import androidx.compose.ui.geometry.Rect
import androidx.compose.ui.layout.boundsInRoot
import androidx.compose.ui.layout.onGloballyPositioned
import androidx.compose.runtime.DisposableEffect
import androidx.compose.runtime.Composable
import androidx.compose.runtime.SideEffect
import com.hermesandroid.relay.ui.components.SphereState
import com.hermesandroid.relay.ui.components.avatar.AvatarRenderState
@@ -100,6 +102,7 @@ class PetCompanionCoordinator {
private var renderState by mutableStateOf(AvatarRenderState(SphereState.Idle))
private var visitRequestState by mutableStateOf(PetVisitRequestState())
private val surfaces = mutableStateMapOf<String, PetCompanionSurface>()
private val interactionLayers = mutableStateMapOf<String, Boolean>()
val pendingVisitRequest: PetVisitRequest?
get() = visitRequestState.pending
@@ -141,20 +144,49 @@ class PetCompanionCoordinator {
surfaces.remove(owner)
}
/** App-wide UI ownership gate for drawers and other same-window overlays. */
fun publishInteractionLayer(owner: String, active: Boolean) {
require(owner.isNotBlank()) { "Pet interaction-layer owner must not be blank." }
if (active) interactionLayers[owner] = true else interactionLayers.remove(owner)
}
fun clearInteractionLayer(owner: String) {
interactionLayers.remove(owner)
}
fun activityFor(owner: String?): PetCompanionActivity {
val surface = owner?.let(surfaces::get)
return PetCompanionActivity(
renderState = renderState,
scrolling = surface?.scrolling == true,
hidden = surface?.hidden == true,
hidden = surface?.hidden == true || interactionLayers.values.any { it },
)
}
}
private data class PetCompanionSurface(val scrolling: Boolean, val hidden: Boolean)
/** A pet-owned popup may take window focus without becoming a competing modal. */
internal fun platformModalOwnsPetLayer(
windowFocused: Boolean,
petMenuExpanded: Boolean,
): Boolean = !windowFocused && !petMenuExpanded
val LocalPetCompanionCoordinator = staticCompositionLocalOf { PetCompanionCoordinator() }
/**
* Declares that a same-window interaction layer currently owns input. Platform
* dialogs and modal sheets are covered separately by root window-focus state.
*/
@Composable
fun PetInteractionLayer(owner: String, active: Boolean) {
val coordinator = LocalPetCompanionCoordinator.current
SideEffect { coordinator.publishInteractionLayer(owner, active) }
DisposableEffect(coordinator, owner) {
onDispose { coordinator.clearInteractionLayer(owner) }
}
}
/**
* Explicit UI surfaces measured by their owners. Their top edges become
* walkable perches, matching Hermes Desktop's live-DOM ledge model without
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -60,6 +60,7 @@ import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.PhysicalKeyboardEnterBehavior
import com.hermesandroid.relay.network.upstream.GatewayAvailability
import com.hermesandroid.relay.network.upstream.ServerCapabilities
import com.hermesandroid.relay.ui.components.ChatTransportStatus
@@ -443,6 +444,48 @@ fun ChatSettingsScreen(
HorizontalDivider()
val physicalKeyboardEnterBehavior by
connectionViewModel.physicalKeyboardEnterBehavior.collectAsState()
Column(verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(
text = stringResource(R.string.chat_settings_physical_keyboard_enter),
style = MaterialTheme.typography.bodyMedium,
)
Text(
text = stringResource(R.string.chat_settings_physical_keyboard_enter_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
val enterBehaviors = PhysicalKeyboardEnterBehavior.entries
SingleChoiceSegmentedButtonRow(modifier = Modifier.fillMaxWidth()) {
enterBehaviors.forEachIndexed { index, behavior ->
SegmentedButton(
shape = SegmentedButtonDefaults.itemShape(
index = index,
count = enterBehaviors.size,
),
onClick = {
connectionViewModel.setPhysicalKeyboardEnterBehavior(behavior)
},
selected = behavior == physicalKeyboardEnterBehavior,
) {
Text(
text = stringResource(
if (behavior == PhysicalKeyboardEnterBehavior.SendMessage) {
R.string.chat_input_send_message
} else {
R.string.chat_settings_insert_newline
},
),
style = MaterialTheme.typography.labelMedium,
)
}
}
}
}
HorizontalDivider()
// Background chat-alert toggle. First enable on
// API 33+ runs the POST_NOTIFICATIONS request (the
// BridgeScreen master-toggle precedent); if the user
@@ -0,0 +1,249 @@
package com.hermesandroid.relay.ui.screens
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.ColumnScope
import androidx.compose.foundation.layout.FlowRow
import androidx.compose.foundation.layout.ExperimentalLayoutApi
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.ArrowBack
import androidx.compose.material.icons.filled.Add
import androidx.compose.material.icons.filled.AutoAwesome
import androidx.compose.material.icons.filled.ContentCopy
import androidx.compose.material3.Button
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.ExperimentalMaterial3Api
import androidx.compose.material3.FilterChip
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedButton
import androidx.compose.material3.OutlinedTextField
import androidx.compose.material3.Scaffold
import androidx.compose.material3.SnackbarHost
import androidx.compose.material3.SnackbarHostState
import androidx.compose.material3.Text
import androidx.compose.material3.TopAppBar
import androidx.compose.material3.TopAppBarDefaults
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.LocalClipboardManager
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.AnnotatedString
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import kotlinx.coroutines.launch
internal enum class CustomPetKind { STATIC, ANIMATED }
internal fun buildCustomPetPrompt(
name: String,
description: String,
kind: CustomPetKind,
): String {
val safeName = name.trim().ifBlank { "My Hermes companion" }
val safeDescription = description.trim().ifBlank {
"a friendly companion that remains recognizable at small mobile sizes"
}
val output = if (kind == CustomPetKind.STATIC) {
"Create one transparent PNG or WebP image. Keep the subject centered with generous edge padding."
} else {
"Create a validated Hermes pet pack ZIP using pet.json plus transparent sprite sheets. " +
"Include idle, walk-left/right, thinking or working, writing, speaking, listening, greet, done, and error where practical. " +
"Frames must show real motion while keeping the character, scale, baseline, and anchor consistent. " +
"At minimum, pet.json must use schemaVersion 1, a stable id and label, and an idle state. " +
"A frame-list state is shaped like {\"frames\":[\"idle-01.png\"],\"fps\":8}; a sheet state is shaped like " +
"{\"sheet\":\"idle.png\",\"frameWidth\":256,\"frameHeight\":256,\"frameCount\":16,\"fps\":8}. " +
"All referenced files must remain inside the pack folder."
}
return """
Help me create a custom floating pet for the Hermes Relay Android app.
Pet name: $safeName
Character direction: $safeDescription
Format: ${if (kind == CustomPetKind.STATIC) "single static image" else "animated pet pack"}
$output
Follow the current Hermes Relay pet contract above. If the repository docs/pet-spec.md or user-docs/features/custom-avatars.md are available, use them as the final authority. Use image-generation tools only if they are available in this chat. Do not upload my reference image, generated art, or pet pack anywhere except through tools I explicitly approve. Work locally where possible.
Before returning anything, validate the manifest and every referenced file, reject path traversal, verify decoded image dimensions and safe margins, and check that animated frames differ visibly without drifting. Then show me a concise review summary and attach the final PNG/WebP or ZIP for me to inspect. Do not install, publish, or share it automatically. I will review it and import it from Appearance > Floating pet.
If you need a visual reference, ask me to attach it in this chat before generating the pet.
""".trimIndent()
}
@OptIn(ExperimentalMaterial3Api::class, ExperimentalLayoutApi::class)
@Composable
fun CustomPetGuideScreen(
connectionViewModel: ConnectionViewModel,
onBack: () -> Unit,
onStartNewChat: (String) -> Unit,
) {
var name by remember { mutableStateOf("") }
var description by remember { mutableStateOf("") }
var kind by remember { mutableStateOf(CustomPetKind.ANIMATED) }
val prompt = remember(name, description, kind) { buildCustomPetPrompt(name, description, kind) }
val clipboard = LocalClipboardManager.current
val copiedMessage = stringResource(R.string.pet_creator_copied)
val snackbarHostState = remember { SnackbarHostState() }
val scope = rememberCoroutineScope()
val importLauncher = rememberLauncherForActivityResult(ActivityResultContracts.OpenDocument()) { uri ->
uri?.let(connectionViewModel::importPet)
}
LaunchedEffect(connectionViewModel) {
connectionViewModel.avatarEvents.collect { snackbarHostState.showSnackbar(it) }
}
Scaffold(
topBar = {
TopAppBar(
title = { Text(stringResource(R.string.pet_creator_title)) },
navigationIcon = {
IconButton(onClick = onBack) {
Icon(Icons.AutoMirrored.Filled.ArrowBack, stringResource(R.string.appearance_back))
}
},
colors = TopAppBarDefaults.topAppBarColors(containerColor = MaterialTheme.colorScheme.surface),
)
},
snackbarHost = { SnackbarHost(snackbarHostState) },
) { innerPadding ->
Column(
modifier = Modifier
.fillMaxSize()
.padding(innerPadding)
.verticalScroll(rememberScrollState())
.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(16.dp),
) {
Text(
text = stringResource(R.string.pet_creator_intro),
style = MaterialTheme.typography.bodyLarge,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
GuideCard(step = "1", title = stringResource(R.string.pet_creator_step_idea)) {
OutlinedTextField(
value = name,
onValueChange = { name = it },
modifier = Modifier.fillMaxWidth(),
label = { Text(stringResource(R.string.pet_creator_name)) },
singleLine = true,
)
OutlinedTextField(
value = description,
onValueChange = { description = it },
modifier = Modifier.fillMaxWidth(),
label = { Text(stringResource(R.string.pet_creator_description)) },
supportingText = { Text(stringResource(R.string.pet_creator_description_hint)) },
minLines = 3,
)
FlowRow(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
FilterChip(
selected = kind == CustomPetKind.ANIMATED,
onClick = { kind = CustomPetKind.ANIMATED },
label = { Text(stringResource(R.string.pet_creator_animated)) },
)
FilterChip(
selected = kind == CustomPetKind.STATIC,
onClick = { kind = CustomPetKind.STATIC },
label = { Text(stringResource(R.string.pet_creator_static)) },
)
}
}
GuideCard(step = "2", title = stringResource(R.string.pet_creator_step_create)) {
Text(
text = stringResource(R.string.pet_creator_review_copy),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Card(
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surface),
shape = RoundedCornerShape(12.dp),
) {
Text(
text = prompt,
modifier = Modifier.padding(14.dp),
style = MaterialTheme.typography.bodySmall,
)
}
Row(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
OutlinedButton(
onClick = {
clipboard.setText(AnnotatedString(prompt))
scope.launch { snackbarHostState.showSnackbar(copiedMessage) }
},
modifier = Modifier.weight(1f),
) {
Icon(Icons.Filled.ContentCopy, null)
Text(stringResource(R.string.pet_creator_copy), modifier = Modifier.padding(start = 6.dp))
}
Button(
onClick = { onStartNewChat(prompt) },
modifier = Modifier.weight(1f),
) {
Icon(Icons.Filled.AutoAwesome, null)
Text(stringResource(R.string.pet_creator_new_chat), modifier = Modifier.padding(start = 6.dp))
}
}
}
GuideCard(step = "3", title = stringResource(R.string.pet_creator_step_review)) {
Text(
text = stringResource(R.string.pet_creator_review_desc),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
OutlinedButton(
onClick = {
importLauncher.launch(arrayOf("application/zip", "image/*", "application/octet-stream", "*/*"))
},
modifier = Modifier.fillMaxWidth(),
) {
Icon(Icons.Filled.Add, null)
Text(stringResource(R.string.pet_creator_import), modifier = Modifier.padding(start = 6.dp))
}
}
}
}
}
@Composable
private fun GuideCard(step: String, title: String, content: @Composable ColumnScope.() -> Unit) {
Card(
modifier = Modifier.fillMaxWidth(),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant),
shape = RoundedCornerShape(16.dp),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
text = "$step · $title",
style = MaterialTheme.typography.titleMedium,
color = MaterialTheme.colorScheme.primary,
)
content()
}
}
}
@@ -54,6 +54,14 @@ internal enum class DashboardActionKind {
ValidateCustomEndpoint,
ActivateCustomEndpoint,
DeleteCustomEndpoint,
EditLearningNode,
DeleteLearningNode,
ConfigureMemoryProvider,
ActivateMemoryProvider,
SetupWhatsApp,
EnableChannel,
DisableChannel,
TestChannel,
// Input-backed kinds — intercepted before runAction and routed to a
// text-input or model-picker dialog instead of firing immediately.
File diff suppressed because it is too large Load Diff
@@ -64,6 +64,8 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.auth.PairedDeviceInfo
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.routeAuthority
import com.hermesandroid.relay.ui.components.SessionTtlPickerDialog
import com.hermesandroid.relay.ui.components.TransportSecurityBadge
@@ -572,6 +574,18 @@ private fun DeviceCard(
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold
)
val deviceDetail = listOf(device.deviceModel, device.devicePlatform)
.map { it.trim() }
.filter { it.isNotBlank() }
.distinct()
.joinToString(" · ")
if (deviceDetail.isNotBlank()) {
Text(
text = deviceDetail,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (device.deviceId.isNotBlank()) {
Text(
text = device.deviceId,
@@ -927,6 +941,17 @@ private fun EndpointsSubList(
fontFamily = FontFamily.Monospace,
modifier = Modifier.weight(1f),
)
if (candidate.hasSecureProxy()) {
Text(
text = if (candidate.secureLinkCoversAllServices()) {
stringResource(R.string.secure_link_pinned_tls_short)
} else {
stringResource(R.string.secure_link_partial_short)
},
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
}
if (isActive) {
Text(
text = stringResource(R.string.paired_devices_active),
@@ -77,10 +77,12 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ProfileConfigResponse
import com.hermesandroid.relay.data.ProfileMemoryEntry
import com.hermesandroid.relay.data.ProfileSkillEntry
import com.hermesandroid.relay.data.GatewayProfileToolset
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.viewmodel.InspectorSection
import com.hermesandroid.relay.viewmodel.LoadState
import com.hermesandroid.relay.viewmodel.ProfileInspectorViewModel
import com.hermesandroid.relay.viewmodel.ProfileInspectorSource
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonNull
@@ -123,6 +125,8 @@ fun ProfileInspectorScreen(
val soulState by viewModel.soulState.collectAsState()
val memoryState by viewModel.memoryState.collectAsState()
val skillsState by viewModel.skillsState.collectAsState()
val source by viewModel.source.collectAsState()
val gatewayDescription by viewModel.gatewayDescription.collectAsState()
// Lazy first-load on screen entry. Keyed on the profile name so a
// re-entry for a different profile (unlikely but possible via deep
@@ -244,6 +248,18 @@ fun ProfileInspectorScreen(
InspectorSection.Config -> ConfigPane(
state = configState,
onRetry = { viewModel.refreshSection(InspectorSection.Config) },
gatewayEditable = source == ProfileInspectorSource.Gateway,
editing = viewModel.configEditing.collectAsState().value,
descriptionDraft = viewModel.configDescriptionDraft.collectAsState().value,
providerDraft = viewModel.configProviderDraft.collectAsState().value,
modelDraft = viewModel.configModelDraft.collectAsState().value,
saving = viewModel.configSaving.collectAsState().value,
onBeginEdit = viewModel::beginConfigEdit,
onDescriptionChange = viewModel::updateConfigDescriptionDraft,
onProviderChange = viewModel::updateConfigProviderDraft,
onModelChange = viewModel::updateConfigModelDraft,
onSave = viewModel::saveConfigEdit,
onCancel = viewModel::cancelConfigEdit,
)
InspectorSection.Soul -> SoulPane(
state = soulState,
@@ -282,6 +298,13 @@ fun ProfileInspectorScreen(
onToggleSkill = { name, enabled ->
viewModel.toggleSkill(name, enabled)
},
gatewayNative = source == ProfileInspectorSource.Gateway,
skillDrafts = viewModel.skillDrafts.collectAsState().value,
toolsets = gatewayDescription?.toolsets.orEmpty(),
toolsetDrafts = viewModel.toolsetDrafts.collectAsState().value,
saving = viewModel.skillsSaving.collectAsState().value,
onToggleToolset = viewModel::toggleToolset,
onSaveDrafts = viewModel::saveSkillEdits,
)
}
}
@@ -291,6 +314,14 @@ fun ProfileInspectorScreen(
private data class InspectorTab(val label: String, val section: InspectorSection)
internal fun profileConfigSaveEnabled(provider: String, model: String, saving: Boolean): Boolean =
provider.isNotBlank() && model.isNotBlank() && !saving
internal fun gatewayDraftSaveVisible(
skillDrafts: Map<String, Boolean>,
toolsetDrafts: Map<String, Boolean>,
): Boolean = skillDrafts.isNotEmpty() || toolsetDrafts.isNotEmpty()
// ---------------------------------------------------------------
// Config pane — JSON tree with collapsible nested objects.
// ---------------------------------------------------------------
@@ -299,6 +330,18 @@ private data class InspectorTab(val label: String, val section: InspectorSection
private fun ConfigPane(
state: LoadState<ProfileConfigResponse>,
onRetry: () -> Unit,
gatewayEditable: Boolean,
editing: Boolean,
descriptionDraft: String,
providerDraft: String,
modelDraft: String,
saving: Boolean,
onBeginEdit: () -> Unit,
onDescriptionChange: (String) -> Unit,
onProviderChange: (String) -> Unit,
onModelChange: (String) -> Unit,
onSave: () -> Unit,
onCancel: () -> Unit,
) {
PaneShell(state = state, onRetry = onRetry) { response ->
var showRawConfig by remember(response.profile, response.config) {
@@ -318,6 +361,21 @@ private fun ConfigPane(
.padding(horizontal = 16.dp, vertical = 12.dp),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
if (gatewayEditable) {
GatewayConfigEditor(
editing = editing,
description = descriptionDraft,
provider = providerDraft,
model = modelDraft,
saving = saving,
onBeginEdit = onBeginEdit,
onDescriptionChange = onDescriptionChange,
onProviderChange = onProviderChange,
onModelChange = onModelChange,
onSave = onSave,
onCancel = onCancel,
)
}
ConfigSummaryCard(response)
OutlinedButton(
@@ -363,6 +421,75 @@ private fun ConfigPane(
}
}
@Composable
private fun GatewayConfigEditor(
editing: Boolean,
description: String,
provider: String,
model: String,
saving: Boolean,
onBeginEdit: () -> Unit,
onDescriptionChange: (String) -> Unit,
onProviderChange: (String) -> Unit,
onModelChange: (String) -> Unit,
onSave: () -> Unit,
onCancel: () -> Unit,
) {
Card(
modifier = Modifier.fillMaxWidth(),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.primaryContainer),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Row(verticalAlignment = Alignment.CenterVertically) {
Column(modifier = Modifier.weight(1f)) {
Text(stringResource(R.string.profile_inspector_gateway_settings), fontWeight = FontWeight.SemiBold)
Text(
stringResource(R.string.profile_inspector_gateway_settings_hint),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (!editing) {
IconButton(onClick = onBeginEdit) {
Icon(Icons.Filled.Edit, stringResource(R.string.profile_inspector_edit_config))
}
}
}
if (editing) {
OutlinedTextField(
value = description,
onValueChange = onDescriptionChange,
modifier = Modifier.fillMaxWidth(),
label = { Text(stringResource(R.string.profile_inspector_description)) },
)
OutlinedTextField(
value = provider,
onValueChange = onProviderChange,
modifier = Modifier.fillMaxWidth(),
singleLine = true,
label = { Text(stringResource(R.string.profile_inspector_provider)) },
)
OutlinedTextField(
value = model,
onValueChange = onModelChange,
modifier = Modifier.fillMaxWidth(),
singleLine = true,
label = { Text(stringResource(R.string.profile_inspector_model)) },
)
EditorBottomBar(
saving = saving,
canSave = profileConfigSaveEnabled(provider, model, saving),
onSave = onSave,
onCancel = onCancel,
)
}
}
}
}
@Composable
private fun ConfigSummaryCard(response: ProfileConfigResponse) {
val topLevelCount = response.config.size
@@ -1334,9 +1461,16 @@ private fun SkillsPane(
onRetry: () -> Unit,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
gatewayNative: Boolean,
skillDrafts: Map<String, Boolean>,
toolsets: List<GatewayProfileToolset>,
toolsetDrafts: Map<String, Boolean>,
saving: Boolean,
onToggleToolset: (String, Boolean) -> Unit,
onSaveDrafts: () -> Unit,
) {
PaneShell(state = state, onRetry = onRetry) { response ->
if (response.skills.isEmpty()) {
if (response.skills.isEmpty() && !gatewayNative) {
Column(
modifier = Modifier
.fillMaxSize()
@@ -1391,6 +1525,30 @@ private fun SkillsPane(
visibleCount = visibleSkills.size,
)
}
if (gatewayNative && toolsets.isNotEmpty()) {
item(key = "__toolsets__") {
GatewayToolsetsCard(
toolsets = toolsets,
drafts = toolsetDrafts,
onToggle = onToggleToolset,
)
}
}
if (gatewayNative && gatewayDraftSaveVisible(skillDrafts, toolsetDrafts)) {
item(key = "__save_gateway_drafts__") {
Button(
onClick = onSaveDrafts,
enabled = !saving,
modifier = Modifier.fillMaxWidth(),
) {
if (saving) {
CircularProgressIndicator(modifier = Modifier.size(18.dp), strokeWidth = 2.dp)
Spacer(Modifier.width(8.dp))
}
Text(stringResource(if (saving) R.string.profile_inspector_saving else R.string.profile_inspector_save_changes))
}
}
}
if (visibleSkills.isEmpty()) {
item(key = "__skills_empty_filter__") {
Card(
@@ -1430,6 +1588,8 @@ private fun SkillsPane(
},
toggleSupported = toggleSupported,
onToggleSkill = onToggleSkill,
gatewayNative = gatewayNative,
skillDrafts = skillDrafts,
)
}
if (toggleSupported == false) {
@@ -1562,6 +1722,8 @@ private fun SkillCategorySection(
onToggleExpanded: () -> Unit,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
gatewayNative: Boolean,
skillDrafts: Map<String, Boolean>,
) {
val categoryStateDescription = stringResource(
if (expanded) {
@@ -1622,6 +1784,7 @@ private fun SkillCategorySection(
skill = skill,
toggleSupported = toggleSupported,
onToggleSkill = onToggleSkill,
controlledEnabled = if (gatewayNative) skillDrafts[skill.name] ?: skill.enabled else null,
)
if (index != skills.lastIndex) {
HorizontalDivider(
@@ -1640,6 +1803,7 @@ private fun SkillRow(
skill: ProfileSkillEntry,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
controlledEnabled: Boolean?,
) {
// Optimistic local toggle state. The VM's emitted events revert us
// on failure; on success the next `/skills` refetch will overwrite
@@ -1652,6 +1816,7 @@ private fun SkillRow(
// null (probe hasn't completed) → leave tappable but the PUT will
// ask authoritatively.
val switchEnabled = toggleSupported != false
val displayedEnabled = controlledEnabled ?: localEnabled
Row(
modifier = Modifier
@@ -1666,7 +1831,7 @@ private fun SkillRow(
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
if (!localEnabled) {
if (!displayedEnabled) {
Spacer(modifier = Modifier.width(8.dp))
Text(
text = stringResource(R.string.profile_inspector_disabled),
@@ -1684,7 +1849,7 @@ private fun SkillRow(
}
}
val toggleDescription = stringResource(
if (localEnabled) {
if (displayedEnabled) {
R.string.profile_inspector_disable_skill
} else {
R.string.profile_inspector_enable_skill
@@ -1692,7 +1857,7 @@ private fun SkillRow(
skill.name,
)
androidx.compose.material3.Switch(
checked = localEnabled,
checked = displayedEnabled,
enabled = switchEnabled,
modifier = Modifier.semantics {
contentDescription = toggleDescription
@@ -1705,7 +1870,7 @@ private fun SkillRow(
// the next recomposition sees — when the VM updates
// the flag to false post-call, we reset the switch to
// the prior state on the next pass.
localEnabled = new
if (controlledEnabled == null) localEnabled = new
onToggleSkill(skill.name, new)
},
)
@@ -1720,6 +1885,44 @@ private fun SkillRow(
}
}
@Composable
private fun GatewayToolsetsCard(
toolsets: List<GatewayProfileToolset>,
drafts: Map<String, Boolean>,
onToggle: (String, Boolean) -> Unit,
) {
Card(modifier = Modifier.fillMaxWidth()) {
Column(modifier = Modifier.padding(12.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) {
Text(stringResource(R.string.profile_inspector_toolsets), fontWeight = FontWeight.SemiBold)
Text(
stringResource(R.string.profile_inspector_toolsets_hint),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
toolsets.forEach { toolset ->
val enabled = drafts[toolset.name] ?: toolset.enabled
Row(
modifier = Modifier.fillMaxWidth().padding(vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Column(modifier = Modifier.weight(1f)) {
Text(toolset.name, style = MaterialTheme.typography.bodyMedium)
Text(
stringResource(R.string.profile_inspector_tool_count, toolset.toolCount),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
androidx.compose.material3.Switch(
checked = enabled,
onCheckedChange = { onToggle(toolset.name, it) },
)
}
}
}
}
}
// ---------------------------------------------------------------
// Shared UI bits
// ---------------------------------------------------------------
@@ -424,7 +424,6 @@ fun SettingsScreen(
val lockedDisplayName: String? = when {
!isProfileLocked -> null
lockedProfileName == null ||
AgentDisplay.isServerDefaultAlias(lockedProfileName) ||
lockedProfileName == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY ->
serverDefaultLabel
else ->
@@ -1055,13 +1054,12 @@ private fun ProfileLockDialog(
onUnlock: () -> Unit,
onDismiss: () -> Unit,
) {
// Selectable rows: a synthetic "Server default" sentinel + the advertised
// profiles, minus the synthetic "default" alias (folded into Server default).
val selectableProfiles = profiles.filterNot { AgentDisplay.isServerDefaultAlias(it.name) }
// Selectable rows: a synthetic "Server default" sentinel + every advertised
// profile, including a profile literally named `default`.
val selectableProfiles = profiles
// Is the stored lock target Server default (sentinel / "default" alias / null)?
// Is the stored lock target Server default (sentinel / null)?
val lockedIsServerDefault = lockedProfileName == null ||
AgentDisplay.isServerDefaultAlias(lockedProfileName) ||
lockedProfileName == AgentDisplay.SERVER_DEFAULT_PROFILE_KEY
val lockedProfile = if (lockedIsServerDefault) {
null

Some files were not shown because too many files have changed in this diff Show More