Compare commits

..
Author SHA1 Message Date
Bailey Dixon 3d11cfb5f2 Merge pull request #366 from Codename-11/dev
release(android): android-v1.9.1
2026-08-16 17:09:20 -04:00
Bailey Dixon 0f589d030f release(android): android-v1.9.1 2026-08-16 16:38:38 -04:00
Bailey Dixon af96579e06 merge: sync main into dev after desktop release 2026-08-16 16:20:04 -04:00
Bailey Dixon f0167ee00f fix(android): persist shared profile avatars 2026-08-16 15:29:43 -04:00
Bailey Dixon a5798e5e6c merge: integrate upstream animated profile pets 2026-08-16 15:04:18 -04:00
Bailey Dixon 479d788967 feat(android): sync upstream animated profile pets 2026-08-16 11:04:24 -04:00
Bailey Dixon 3f6723da6f merge: fix Nous callback authentication 2026-08-16 10:01:10 -04:00
Bailey Dixon c1cd376d8b fix(android): align Nous callback authentication 2026-08-16 10:01:02 -04:00
Bailey Dixon 87e2fb710d feat(android): add phone-only animated profile icons 2026-08-16 09:46:52 -04:00
Bailey Dixon 5a617f9482 merge: integrate Hermes profile contracts 2026-08-15 22:57:33 -04:00
Bailey Dixon 13152a4fab feat(android): adopt Hermes profile contracts 2026-08-15 22:56:30 -04:00
Bailey Dixon 7f31c88f46 merge: integrate high-value Android and Relay enhancements 2026-08-15 21:39:14 -04:00
Bailey Dixon 3e857b54a2 test(android): align hardened gateway contracts 2026-08-15 21:36:50 -04:00
Bailey Dixon 163e3341da fix(android): verify draft profile ownership 2026-08-15 21:36:49 -04:00
Bailey Dixon a5419df579 fix(android): guard draft model selection 2026-08-15 21:36:49 -04:00
Bailey Dixon e834c603d0 fix(android): clear rejected recovery events 2026-08-15 21:36:49 -04:00
Bailey Dixon a31d715569 feat(android): surface resource and model risk 2026-08-15 21:36:49 -04:00
Bailey Dixon c6b8d891ac fix(android): harden attachment delivery 2026-08-15 21:35:38 -04:00
Bailey Dixon 8996f34347 feat(android): add bounded cron and reset evidence 2026-08-15 21:35:38 -04:00
Bailey Dixon f5f1a4c7d4 fix(android): enforce profile ownership 2026-08-15 21:34:36 -04:00
Bailey Dixon 31eccc631e fix(android): fail closed on ambiguous rewinds 2026-08-15 21:34:35 -04:00
Bailey Dixon 64ba979816 Merge pull request #364 from Codename-11/feature/proactive-away-summary
feat(threads): surface messages received while away
2026-08-15 21:24:04 -04:00
Bailey Dixon 5be0979d74 chore(android): refresh localization catalog status 2026-08-15 21:13:05 -04:00
Bailey Dixon 80b1a3b6df Merge remote-tracking branch 'origin/dev' into feature/proactive-away-summary 2026-08-15 21:08:57 -04:00
Bailey Dixon 257a11ffa2 feat(threads): surface messages received while away 2026-08-15 21:08:50 -04:00
Bailey Dixon 62f3572e11 Merge pull request #363 from Codename-11/fix/android-media-download-state
fix(android): settle media download states
2026-08-15 21:03:40 -04:00
Bailey Dixon 621e526c7d fix(android): settle media download states 2026-08-15 20:52:40 -04:00
Bailey Dixon a5afec36d9 Merge pull request #234 from Codename-11/dependabot/github_actions/dev/actions/setup-python-7
chore(deps): bump actions/setup-python from 6 to 7
2026-08-15 20:11:58 -04:00
Bailey Dixon 29bf9a08ac Merge branch 'dev' into dependabot/github_actions/dev/actions/setup-python-7 2026-08-15 20:10:46 -04:00
Bailey Dixon 342e977594 Merge pull request #233 from Codename-11/dependabot/github_actions/dev/actions/setup-node-7
chore(deps): bump actions/setup-node from 4 to 7
2026-08-15 20:10:39 -04:00
Bailey Dixon 24e767e7ae Merge branch 'dev' into dependabot/github_actions/dev/actions/setup-node-7 2026-08-15 20:09:21 -04:00
Bailey Dixon fdf210ec2b Merge pull request #361 from Codename-11/dev
release(desktop): desktop-v0.4.0-beta.4
2026-08-15 13:49:30 -04:00
Bailey Dixon d05ab31296 release(desktop): desktop-v0.4.0-beta.4 2026-08-15 13:42:14 -04:00
Bailey Dixon 0e0cc16f47 Merge branch 'fix/desktop-daemon-stopped-loading' into dev 2026-08-15 13:32:25 -04:00
Bailey Dixon e90be03f2e fix(desktop): load UI while daemon is stopped 2026-08-15 13:32:11 -04:00
Bailey Dixon f1e4fdcc91 Merge pull request #360 from Codename-11/chore/backmerge-android-1.9.0
chore: back-merge Android 1.9.0 release
2026-08-14 21:52:34 -04:00
Bailey Dixon 5b8b3da350 chore: back-merge Android 1.9.0 release 2026-08-14 21:52:16 -04:00
Bailey Dixon 447ec356d7 Merge pull request #359 from Codename-11/dev
release(android): android-v1.9.0
2026-08-14 21:32:50 -04:00
Bailey Dixon ab359e5efb release(android): android-v1.9.0 2026-08-14 21:01:51 -04:00
Bailey Dixon 86b8161cb7 feat(android): refine sessions and messaging 2026-08-14 20:58:31 -04:00
Bailey Dixon e401fdb0c7 fix(android): persist landed message reactions 2026-08-14 17:04:54 -04:00
Bailey Dixon d4325d5aab fix(android): restore compact chat interactions 2026-08-14 16:57:19 -04:00
Bailey Dixon c734d75484 feat(android): add desktop-style session profiles 2026-08-14 16:57:18 -04:00
Bailey Dixon 0411804780 fix(android): accept compatible session flags 2026-08-14 16:57:18 -04:00
Bailey Dixon 8f89c2841d fix(android): keep dashboard teardown off main thread 2026-08-14 16:57:18 -04:00
Bailey Dixon 933c1842a0 Merge pull request #358 from Codename-11/chore/backmerge-desktop-beta3
chore: back-merge Desktop beta.3 release
2026-08-14 16:31:24 -04:00
Bailey Dixon dfe1b53327 chore: back-merge desktop beta.3 release 2026-08-14 16:30:37 -04:00
Bailey Dixon d36580a983 Merge pull request #356 from Codename-11/dev
release: Desktop beta.3 process-containment patch
2026-08-14 16:11:35 -04:00
Bailey Dixon 2d178ff884 Merge pull request #357 from Codename-11/release/desktop-0.4.0-beta.3
fix(desktop): close process containment race
2026-08-14 16:05:00 -04:00
Bailey Dixon d61955f82a fix(desktop): close process containment race 2026-08-14 15:58:57 -04:00
Bailey Dixon adec6ed2c0 Merge pull request #355 from Codename-11/release/desktop-0.4.0-beta.3
release(desktop): desktop-v0.4.0-beta.3
2026-08-14 15:44:24 -04:00
Bailey Dixon e9e44c8bb2 release(desktop): desktop-v0.4.0-beta.3 2026-08-14 15:36:53 -04:00
Bailey Dixon c6b0732a02 Merge pull request #354 from Codename-11/fix/desktop-tray-process-containment
fix(desktop): contain tray subprocess storms
2026-08-14 15:22:21 -04:00
Bailey Dixon d919115788 fix(desktop): contain tray subprocess storms 2026-08-14 15:15:12 -04:00
Bailey Dixon 49da085ae8 Merge pull request #353 from Codename-11/chore/backmerge-desktop-beta2-server-1.8.0
chore: backmerge Desktop beta.2 and Server 1.8.0 releases
2026-08-14 15:05:21 -04:00
Bailey Dixon 889b6f0858 chore: merge desktop beta.2 and server 1.8.0 release history into dev 2026-08-14 15:05:12 -04:00
Bailey Dixon 5100c524f6 Merge pull request #351 from Codename-11/dev
release: Desktop beta.2 and Server 1.8.0
2026-08-14 15:04:03 -04:00
Bailey Dixon c609ae867f Merge pull request #352 from Codename-11/chore/backmerge-desktop-beta1
chore: back-merge Desktop beta.1 release history
2026-08-14 14:49:23 -04:00
Bailey Dixon 107f8c7720 chore: merge desktop beta.1 release history into dev 2026-08-14 14:49:08 -04:00
Bailey Dixon 8963e4fafd Merge pull request #350 from Codename-11/release/server-1.8.0
release(server): server-v1.8.0
2026-08-14 14:46:57 -04:00
Bailey Dixon 5d9624e2ef release(server): server-v1.8.0 2026-08-14 14:35:01 -04:00
Bailey Dixon 4b063d3fd7 Merge pull request #349 from Codename-11/release/desktop-0.4.0-beta.2
release(desktop): desktop-v0.4.0-beta.2
2026-08-14 12:56:04 -04:00
Bailey Dixon 9b9d7b654c release(desktop): desktop-v0.4.0-beta.2 2026-08-14 12:45:56 -04:00
Bailey Dixon a26e17e72c Merge pull request #348 from Codename-11/fix/cua-windows-health-compat
feat(desktop): enhance activity and control diagnostics
2026-08-14 12:38:12 -04:00
Bailey Dixon a3a6a9bb13 fix(desktop): satisfy tray release lint 2026-08-14 12:36:46 -04:00
Bailey Dixon 169bd09559 merge: sync desktop activity work with dev
# Conflicts:
#	CHANGELOG.md
2026-08-14 11:32:56 -04:00
Bailey Dixon 45d631e7ac feat(desktop): enhance activity and control diagnostics 2026-08-14 11:30:36 -04:00
Bailey Dixon eb6a6c95d2 merge: integrate official desktop relay plugin 2026-08-14 07:58:10 -04:00
Bailey Dixon 3b102663c2 feat(plugin): add official desktop relay surface 2026-08-14 07:56:26 -04:00
Bailey Dixon 0e5fc4c606 Merge branch 'fix/android-proactive-thread-entry' into dev 2026-08-14 07:50:07 -04:00
Bailey Dixon c3189f2cbb fix(android): open proactive messages as threads 2026-08-14 07:49:39 -04:00
Bailey Dixon 0d6c3bd6b0 Merge pull request #346 from Codename-11/dev
release(desktop): desktop-v0.4.0-beta.1
2026-08-13 21:18:41 -04:00
Bailey Dixon 06d88ad40a Merge pull request #345 from Codename-11/release/desktop-0.4.0-beta.1
release(desktop): desktop-v0.4.0-beta.1
2026-08-13 21:11:57 -04:00
Bailey Dixon 8ae5b3fbc2 release(desktop): desktop-v0.4.0-beta.1 2026-08-13 21:04:07 -04:00
Bailey Dixon 39b7a8f108 Merge pull request #344 from Codename-11/fix/desktop-updater-cua-hardening
feat(desktop): adopt CUA as primary control backend
2026-08-13 20:57:50 -04:00
Bailey Dixon af6e167692 fix(desktop): normalize Windows installer paths 2026-08-13 20:51:17 -04:00
Bailey Dixon 274bd6ae98 fix(desktop): honor CUA health schema 2026-08-13 20:45:58 -04:00
Bailey Dixon 9fc55b379a fix(desktop): clarify CUA readiness fallback 2026-08-13 20:34:45 -04:00
Bailey Dixon 559a0ffdc8 feat(desktop): make CUA the primary control backend 2026-08-13 20:16:03 -04:00
Bailey Dixon 75bcd9180f feat(desktop): add optional CUA control engine 2026-08-13 19:33:11 -04:00
Bailey Dixon 9c995a443d fix(desktop): harden bundle updates 2026-08-13 19:06:25 -04:00
Bailey Dixon 7440ef2948 Merge pull request #343 from Codename-11/dev
release: server 1.7.0 and desktop 0.4.0-alpha.8
2026-08-13 17:14:58 -04:00
Bailey Dixon a88539bc59 fix(android): dequeue reach frames compatibly 2026-08-13 16:56:54 -04:00
Bailey Dixon b2ccfdc500 fix(security): carry secure link trust anchor 2026-08-13 16:49:44 -04:00
Bailey Dixon 481c62ac59 fix(desktop): bind pinned secure link probes 2026-08-13 16:42:37 -04:00
Bailey Dixon 5d415fbaf0 fix(android): use compatible reach buffer removal 2026-08-13 16:39:26 -04:00
Bailey Dixon 074b715055 fix(android): complete secure route translations 2026-08-13 16:37:32 -04:00
Bailey Dixon f63ee8721e release(desktop): desktop-v0.4.0-alpha.8 2026-08-13 16:21:51 -04:00
Bailey Dixon 777bc80bcc release(server): server-v1.7.0 2026-08-13 16:21:50 -04:00
Bailey Dixon 9539975bb5 merge: integrate native secure routes 2026-08-13 15:41:46 -04:00
Bailey Dixon 2863a1bc8f merge: reconcile native secure routes with dev 2026-08-13 15:31:53 -04:00
Bailey Dixon b0a7cf0494 feat: add self-hosted secure connection routes 2026-08-13 15:31:46 -04:00
Bailey Dixon 76b4084310 merge: integrate Android and Relay upstream work 2026-08-13 13:24:32 -04:00
Bailey Dixon 2ace70c4fc test: close integration verification gaps 2026-08-13 13:24:02 -04:00
Bailey Dixon 4f52f371ba fix(ops): fail closed on unsafe certification state 2026-08-13 11:16:27 -04:00
Bailey Dixon 064c89bda4 docs: record Android and Relay integration 2026-08-13 11:08:27 -04:00
Bailey Dixon 0cb1e3642f feat(android): add gateway-native profile editor 2026-08-13 11:03:10 -04:00
Bailey Dixon cf4bf87242 fix(android): honor upstream routing contracts 2026-08-13 11:00:39 -04:00
Bailey Dixon 9cbed21014 fix(android): preserve durable gateway rewinds 2026-08-13 10:58:55 -04:00
Bailey Dixon ce75c0fa01 docs: add controlled runtime safety preflight 2026-08-13 10:50:52 -04:00
Bailey Dixon bf2aece6e6 docs: reconcile upstream architecture evaluations 2026-08-13 10:50:14 -04:00
Bailey Dixon 198da78fc8 fix(android): honor upstream approval and compression outcomes 2026-08-13 10:50:14 -04:00
Bailey Dixon 986ce3b12b fix(plugin): isolate profile-owned registrations 2026-08-13 10:50:14 -04:00
Bailey Dixon b53f757830 fix(plugin): support strict phone targets 2026-08-13 10:50:14 -04:00
Bailey Dixon cdeccd69e4 feat: add secure relay route selection 2026-08-12 20:10:41 -04:00
Bailey Dixon bb72516bb5 Merge pull request #340 from Codename-11/chore/backmerge-server-1.6.4
chore: back-merge server-v1.6.4 hotfix
2026-08-12 18:43:50 -04:00
Bailey Dixon 3a51644342 chore: merge server-v1.6.4 release history into dev
# Conflicts:
#	docs/decisions.md
#	user-docs/desktop/tools.md
2026-08-12 18:43:39 -04:00
Bailey Dixon 51c0c7dee9 Merge pull request #338 from Codename-11/fix/server-multidevice-hotfix
fix(server): release targeted multi-desktop routing
2026-08-12 18:39:31 -04:00
Bailey Dixon 7ef2420c85 release(server): server-v1.6.4 2026-08-12 18:38:32 -04:00
Bailey Dixon 6a810c850b fix(server): route concurrent desktop clients explicitly 2026-08-12 18:38:02 -04:00
Bailey Dixon d383002583 Merge pull request #336 from Codename-11/release/server-1.6.4
release(server): server-v1.6.4
2026-08-12 18:35:31 -04:00
Bailey Dixon e3aae829e1 release(server): server-v1.6.4 2026-08-12 18:35:16 -04:00
Bailey Dixon 5207ed4193 Merge pull request #335 from Codename-11/fix/desktop-placement-device-identity
feat(desktop): support targeted multi-device control
2026-08-12 18:32:06 -04:00
Bailey Dixon b46bb00ea8 test(desktop): serialize cross-platform suite 2026-08-12 18:31:50 -04:00
Bailey Dixon b8dde409c5 merge: synchronize desktop management with dev
# Conflicts:
#	CHANGELOG.md
#	docs/decisions.md
2026-08-12 18:26:20 -04:00
Bailey Dixon ca7ded3939 test(server): prove concurrent desktop routing 2026-08-12 18:24:44 -04:00
Bailey Dixon db85a26c68 feat(desktop): add contextual approvals and UI pairing 2026-08-12 18:24:43 -04:00
Bailey Dixon aa2595629d feat(desktop): expand tray management controls 2026-08-12 17:55:56 -04:00
Bailey Dixon d79146dc90 feat(desktop): add ask every time access preset 2026-08-12 17:13:51 -04:00
Bailey Dixon eabc4dd328 refactor(desktop): clarify access navigation 2026-08-12 16:57:50 -04:00
Bailey Dixon e165bfeff3 feat(desktop): animate bidirectional relay traffic 2026-08-12 15:42:43 -04:00
Bailey Dixon 40bcd796d1 refactor(desktop): simplify host access presets 2026-08-12 13:29:29 -04:00
Bailey Dixon 57ae0c9456 feat(desktop): unify capabilities and activity drilldown 2026-08-12 13:06:34 -04:00
Bailey Dixon 9b31a16c89 fix(desktop): preserve Hermes shortcut icons 2026-08-12 11:44:17 -04:00
Bailey Dixon f97bbdd395 feat(desktop): add host-wide raw USB control 2026-08-12 11:38:09 -04:00
Bailey Dixon 722a294947 feat(desktop): adopt compact capability ledger 2026-08-12 11:13:50 -04:00
Bailey Dixon bbfb57b462 feat(desktop): harden targeted remote management 2026-08-12 10:37:12 -04:00
Bailey Dixon 6db12a0bec merge: complete upstream app and Relay workflows 2026-08-12 09:24:24 -04:00
Bailey Dixon f1de957848 fix(android): translate Manage workflows 2026-08-12 09:08:31 -04:00
Bailey Dixon cc01d9c8ad test(android): compile upstream workflow fixtures 2026-08-12 09:00:04 -04:00
Bailey Dixon d574182d84 fix(android): wire Manage workflow dialogs 2026-08-12 08:46:10 -04:00
Bailey Dixon a328763da3 fix(android): localize backup completion 2026-08-12 08:46:05 -04:00
Bailey Dixon f53db68e7d feat(android): complete upstream Manage workflows 2026-08-12 07:45:55 -04:00
Bailey Dixon eb9e570fc0 feat(android): show session repository and PR state 2026-08-12 07:41:35 -04:00
Bailey Dixon 260f119637 fix(voice): align upstream auth and transport 2026-08-12 07:39:42 -04:00
Bailey Dixon d0fa2ea39d fix(android): preserve clarify selection semantics 2026-08-12 07:37:28 -04:00
Bailey Dixon a1c74b1567 fix(plugin): enumerate phone home target 2026-08-12 07:34:19 -04:00
Bailey Dixon 7c45acd38d chore: merge server-v1.6.3 release history into dev 2026-08-11 22:03:36 -04:00
Bailey Dixon 4605b87c10 Merge pull request #333 from Codename-11/dev
release(server): server-v1.6.3
2026-08-11 22:00:43 -04:00
Bailey Dixon 6a91d6ee7e fix(android): complete upstream feature translations 2026-08-11 21:46:45 -04:00
Bailey Dixon 95a2813efe fix(server): validate translated media path components 2026-08-11 21:37:54 -04:00
Bailey Dixon 2ecf521c8c chore: merge main release history into dev 2026-08-11 21:35:40 -04:00
Bailey Dixon 7752c5c404 release(server): server-v1.6.3 2026-08-11 21:35:05 -04:00
Bailey Dixon e1d3764cd2 feat(android): browse sessions across profiles 2026-08-11 20:50:36 -04:00
Bailey Dixon e34171b5ad feat(android): add gateway message reactions 2026-08-11 20:48:09 -04:00
Bailey Dixon 8040cac39a feat(android): redirect running subagents 2026-08-11 20:45:33 -04:00
Bailey Dixon aab70520ca feat(android): open referenced Hermes sessions 2026-08-11 20:40:27 -04:00
Bailey Dixon 5a0cd8123c feat(android): expand Hermes management surfaces 2026-08-11 20:37:03 -04:00
Bailey Dixon 4370d9a925 feat(android): adopt richer gateway chat contracts 2026-08-11 20:30:38 -04:00
Bailey Dixon 726308d2ef fix: harden gateway recovery diagnostics 2026-08-11 20:26:05 -04:00
Bailey Dixon 1acc3a4c80 fix: align app and relay upstream contracts 2026-08-11 20:04:43 -04:00
Bailey Dixon 11ccbd6e5c Merge pull request #332 from Codename-11/dev
release(desktop): desktop-v0.4.0-alpha.7
2026-08-11 19:55:05 -04:00
Bailey Dixon d13af35357 chore: merge main release history into dev 2026-08-11 19:48:26 -04:00
Bailey Dixon e3752d43f3 release(desktop): desktop-v0.4.0-alpha.7 2026-08-11 19:48:24 -04:00
Bailey Dixon 97293b62c3 Merge pull request #331 from Codename-11/dev
release(desktop): desktop-v0.4.0-alpha.6
2026-08-11 19:33:13 -04:00
Bailey Dixon 454e770648 chore: merge main release history into dev 2026-08-11 19:26:15 -04:00
Bailey Dixon e18572e8e3 release(desktop): desktop-v0.4.0-alpha.6 2026-08-11 19:24:27 -04:00
Bailey Dixon 83f69725b9 Merge pull request #330 from Codename-11/dev
release: Desktop 0.4.0-alpha.5
2026-08-11 19:05:39 -04:00
Bailey Dixon 72aa7c3046 chore: merge main release history into dev 2026-08-11 18:59:06 -04:00
Bailey Dixon 3995c64493 release(desktop): desktop-v0.4.0-alpha.5 2026-08-11 18:59:04 -04:00
Bailey Dixon ce538ced3d Merge pull request #329 from Codename-11/dev
release: Desktop 0.4.0-alpha.4
2026-08-11 18:43:32 -04:00
Bailey Dixon 352bc5b439 chore: merge main release history into dev 2026-08-11 18:35:52 -04:00
Bailey Dixon 9ec163b27b release(desktop): desktop-v0.4.0-alpha.4 2026-08-11 18:35:32 -04:00
Bailey Dixon 7a3efa2c4d Merge pull request #328 from Codename-11/dev
release: Desktop 0.4.0-alpha.3 and Server 1.6.2
2026-08-11 18:19:36 -04:00
Bailey Dixon c28be7c92e style(desktop): format tray contract test 2026-08-11 18:03:02 -04:00
Bailey Dixon 8d1758ec8b fix(desktop): build tray assets before Rust checks 2026-08-11 18:01:17 -04:00
Bailey Dixon ce8b8702c3 test(desktop): make UI install coverage portable 2026-08-11 17:53:56 -04:00
Bailey Dixon ca0a9eb524 release(desktop): desktop-v0.4.0-alpha.3 2026-08-11 17:51:25 -04:00
Bailey Dixon b91d8c9a09 release(server): server-v1.6.2 2026-08-11 17:51:13 -04:00
Bailey Dixon bebd327816 Merge pull request #327 from Codename-11/feature/desktop-relay-management-release
feat: ship desktop management UI and paired-device identity
2026-08-11 17:49:18 -04:00
Bailey Dixon 8fa97e0b46 feat(desktop): add host management tray UI 2026-08-11 17:48:47 -04:00
Bailey Dixon 45dc82e573 feat(server): enrich paired device identity 2026-08-11 17:48:09 -04:00
dependabot[bot] 48b23f4d9e chore(deps): bump gradle-wrapper from 9.6.1 to 9.7.0 (#326)
Bumps [gradle-wrapper](https://github.com/gradle/gradle) from 9.6.1 to 9.7.0.
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](https://github.com/gradle/gradle/compare/v9.6.1...v9.7.0)

---
updated-dependencies:
- dependency-name: gradle-wrapper
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:56:21 +00:00
dependabot[bot] f708ef3353 chore(deps): bump androidx.media3:media3-exoplayer from 1.10.1 to 1.11.0 (#325)
Bumps [androidx.media3:media3-exoplayer](https://github.com/androidx/media) from 1.10.1 to 1.11.0.
- [Release notes](https://github.com/androidx/media/releases)
- [Changelog](https://github.com/androidx/media/blob/release/RELEASENOTES.md)
- [Commits](https://github.com/androidx/media/compare/1.10.1...1.11.0)

---
updated-dependencies:
- dependency-name: androidx.media3:media3-exoplayer
  dependency-version: 1.11.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:55:39 +00:00
dependabot[bot] 3224595a46 chore(deps): bump gradle/actions from 6.2.0 to 6.3.0 (#324)
Bumps [gradle/actions](https://github.com/gradle/actions) from 6.2.0 to 6.3.0.
- [Release notes](https://github.com/gradle/actions/releases)
- [Commits](https://github.com/gradle/actions/compare/v6.2.0...v6.3.0)

---
updated-dependencies:
- dependency-name: gradle/actions
  dependency-version: 6.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:55:08 +00:00
dependabot[bot] c0453f040d chore(deps): bump the testing group with 2 updates (#323)
Bumps the testing group with 2 updates: [io.github.takahirom.roborazzi:roborazzi](https://github.com/takahirom/roborazzi) and [io.github.takahirom.roborazzi:roborazzi-compose](https://github.com/takahirom/roborazzi).


Updates `io.github.takahirom.roborazzi:roborazzi` from 1.70.0 to 1.71.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.70.0...1.71.0)

Updates `io.github.takahirom.roborazzi:roborazzi-compose` from 1.70.0 to 1.71.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.70.0...1.71.0)

---
updated-dependencies:
- dependency-name: io.github.takahirom.roborazzi:roborazzi
  dependency-version: 1.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
- dependency-name: io.github.takahirom.roborazzi:roborazzi-compose
  dependency-version: 1.71.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-10 11:54:54 +00:00
Bailey Dixon 33a0ea3216 chore: merge main back after android-v1.8.1 2026-08-10 00:05:29 -04:00
Bailey Dixon cec05ceec2 Merge pull request #322 from Codename-11/dev
release(android): android-v1.8.1
2026-08-09 23:46:51 -04:00
Bailey Dixon 0e30699fff release(android): android-v1.8.1 2026-08-09 23:20:15 -04:00
Bailey Dixon d4041e4528 chore: merge main back after android-v1.8.0 2026-08-09 23:15:39 -04:00
Bailey Dixon c5ae402cd7 fix(android): align gateway and transcript contracts 2026-08-09 23:08:26 -04:00
dependabot[bot] de9211b7c5 chore(deps): bump actions/setup-node from 4 to 7
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-25 18:37:14 +00:00
dependabot[bot] 7ca5c61be5 chore(deps): bump actions/setup-python from 6 to 7
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 11:55:24 +00:00
371 changed files with 47747 additions and 3372 deletions
+4 -4
View File
@@ -63,7 +63,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -95,7 +95,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -139,7 +139,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
@@ -203,7 +203,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
+1 -1
View File
@@ -67,7 +67,7 @@ jobs:
fetch-depth: 1
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+1 -1
View File
@@ -39,7 +39,7 @@ jobs:
run: npm run build
- name: Setup Python
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+4 -2
View File
@@ -100,13 +100,15 @@ jobs:
with:
node-version: '22'
cache: npm
cache-dependency-path: desktop/package-lock.json
cache-dependency-path: |
desktop/package-lock.json
desktop/tray/package-lock.json
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Install deps
run: npm ci
run: npm ci && npm --prefix tray ci
- name: Check tray formatting
run: npm run tray:fmt
+2 -2
View File
@@ -44,7 +44,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
@@ -84,7 +84,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+1 -1
View File
@@ -30,7 +30,7 @@ jobs:
working-directory: website
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
with:
node-version: 22
cache: npm
+2 -2
View File
@@ -44,7 +44,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.12"
@@ -76,7 +76,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+1 -1
View File
@@ -74,7 +74,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+2 -2
View File
@@ -125,7 +125,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
@@ -163,7 +163,7 @@ jobs:
java-version: 17
- name: Setup Gradle
uses: gradle/actions/setup-gradle@v6.2.0
uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: false
+186 -8
View File
@@ -80,7 +80,7 @@ jobs:
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.x'
bun-version-file: 'desktop/.bun-version'
- name: Install deps
run: npm ci
@@ -153,6 +153,40 @@ jobs:
desktop/dist/bin/hermes-relay-darwin-arm64
retention-days: 7
smoke-windows-cli-release-asset:
name: Smoke exact Windows CLI release asset
runs-on: windows-latest
needs:
- validate-release
- build-cli-binaries
steps:
- uses: actions/download-artifact@v8
with:
name: cli-binaries
path: release-assets
- name: Repeated launch and process cleanup gate
shell: pwsh
env:
EXPECTED_DESKTOP_VERSION: ${{ needs.validate-release.outputs.version }}
run: |
$ErrorActionPreference = 'Stop'
$exe = (Resolve-Path 'release-assets/hermes-relay-win-x64.exe').Path
1..20 | ForEach-Object {
$output = & $exe --version
if ($LASTEXITCODE -ne 0) { throw "Windows CLI smoke failed with exit $LASTEXITCODE" }
if ($output -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "Unexpected Windows CLI version output: $output"
}
}
Start-Sleep -Milliseconds 500
$leftovers = Get-CimInstance Win32_Process | Where-Object {
$_.ExecutablePath -eq $exe
}
if ($leftovers) {
throw "Windows CLI smoke left $(@($leftovers).Count) process(es) behind"
}
build-windows-tray-installer:
name: Build Windows tray installer
runs-on: windows-latest
@@ -168,18 +202,20 @@ jobs:
with:
node-version: '22'
cache: npm
cache-dependency-path: desktop/package-lock.json
cache-dependency-path: |
desktop/package-lock.json
desktop/tray/package-lock.json
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.x'
bun-version-file: 'desktop/.bun-version'
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Install deps
run: npm ci
run: npm ci && npm --prefix tray ci
- name: Type-check
run: npm run type-check
@@ -213,12 +249,153 @@ jobs:
$proc = Start-Process -FilePath tray/target/release/hermes-relay-tray.exe -WindowStyle Hidden -PassThru
Start-Sleep -Seconds 5
if ($proc.HasExited) { throw "tray app exited early with code $($proc.ExitCode)" }
$proc.Refresh()
if ($proc.MainWindowHandle -ne 0) { throw 'menu-only systray created an application window' }
$traySize = (Get-Item tray/target/release/hermes-relay-tray.exe).Length
if ($traySize -gt 5242880) { throw "tray executable exceeds 5 MiB: $traySize bytes" }
if ($traySize -le 0) { throw 'tray executable is empty' }
Stop-Process -Id $proc.Id -Force
Write-Host "menu-only tray launch smoke OK pid=$($proc.Id) bytes=$traySize"
Write-Host "management tray launch smoke OK pid=$($proc.Id) bytes=$traySize"
- name: Smoke-test packaged installer lifecycle
shell: pwsh
env:
EXPECTED_DESKTOP_VERSION: ${{ needs.validate-release.outputs.version }}
run: |
$ErrorActionPreference = 'Stop'
function Normalize-UserPath([string]$Value) {
return (@($Value -split ';' | Where-Object { $_ }) -join ';')
}
function Get-RawUserPath {
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment')
if ($null -eq $environmentKey) { return '' }
try {
return [string]$environmentKey.GetValue(
'Path',
'',
[Microsoft.Win32.RegistryValueOptions]::DoNotExpandEnvironmentNames
)
} finally {
$environmentKey.Dispose()
}
}
$setup = (Resolve-Path 'dist/tray/hermes-relay-windows-x64-setup.exe').Path
$smokeRoot = Join-Path $env:RUNNER_TEMP 'hermes-installer-lifecycle-smoke'
$smokeProfile = Join-Path $smokeRoot 'profile'
$installDir = Join-Path $smokeRoot 'installed files'
$sessionDir = Join-Path $smokeProfile '.hermes'
$sessionSentinel = Join-Path $sessionDir 'remote-sessions.json'
$uninstaller = Join-Path $installDir 'uninstall-hermes-relay.exe'
$uninstallKey = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Uninstall\HermesRelay'
$productKey = 'HKCU:\Software\HermesRelay'
$startupKey = 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run'
$startMenuDir = Join-Path $env:APPDATA 'Microsoft\Windows\Start Menu\Programs\Hermes-Relay CLI'
$oldUserProfile = $env:USERPROFILE
$oldHomeEnv = $env:HOME
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
$hadUserPath = $environmentKey.GetValueNames() -contains 'Path'
$originalUserPath = Get-RawUserPath
$originalUserPathKind = if ($hadUserPath) { $environmentKey.GetValueKind('Path') } else { $null }
$userPathBefore = 'C:\Windows\System32'
$environmentKey.Dispose()
$startupBefore = (Get-ItemProperty -Path $startupKey -Name HermesRelayTray -ErrorAction SilentlyContinue).HermesRelayTray
if (Test-Path $uninstallKey) { throw 'installer smoke requires a clean HermesRelay uninstall registry key' }
if (Test-Path $productKey) { throw 'installer smoke requires a clean HermesRelay product registry key' }
if (Test-Path $smokeRoot) { Remove-Item -LiteralPath $smokeRoot -Recurse -Force }
New-Item -ItemType Directory -Force -Path $sessionDir | Out-Null
Set-Content -LiteralPath $sessionSentinel -Value '{"sentinel":"preserve-me"}' -Encoding UTF8
$env:USERPROFILE = $smokeProfile
$env:HOME = $smokeProfile
try {
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
$environmentKey.SetValue('Path', $userPathBefore, [Microsoft.Win32.RegistryValueKind]::String)
$environmentKey.Dispose()
$installProcess = Start-Process -FilePath $setup -ArgumentList @('/S', "/D=$installDir") -Wait -PassThru
if ($installProcess.ExitCode -ne 0) { throw "installer exited with code $($installProcess.ExitCode)" }
$expectedFiles = @(
'hermes-relay.exe',
'hermes-relay-tray.exe',
'hermes-relay-ui.cmd',
'hermes-relay-path.ps1',
'uninstall-hermes-relay.exe'
)
foreach ($name in $expectedFiles) {
$path = Join-Path $installDir $name
if (-not (Test-Path -LiteralPath $path -PathType Leaf)) {
throw "packaged installer did not create $path"
}
}
$cli = Join-Path $installDir 'hermes-relay.exe'
$versionOutput = (& $cli --version | Out-String).Trim()
if ($LASTEXITCODE -ne 0) { throw "installed CLI --version exited with code $LASTEXITCODE" }
if ($versionOutput -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "installed CLI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$versionOutput'"
}
$helpOutput = (& $cli --help | Out-String)
if ($LASTEXITCODE -ne 0 -or $helpOutput -notmatch 'Usage:') {
throw 'installed CLI --help smoke failed'
}
if (-not (Test-Path -LiteralPath $sessionSentinel -PathType Leaf)) {
throw 'installer removed profile session data'
}
$uninstallProcess = Start-Process -FilePath $uninstaller -ArgumentList '/S' -Wait -PassThru
if ($uninstallProcess.ExitCode -ne 0) { throw "uninstaller exited with code $($uninstallProcess.ExitCode)" }
$deadline = [DateTime]::UtcNow.AddSeconds(20)
while ((Test-Path -LiteralPath $uninstaller) -and [DateTime]::UtcNow -lt $deadline) {
Start-Sleep -Milliseconds 250
}
foreach ($name in $expectedFiles) {
$path = Join-Path $installDir $name
if (Test-Path -LiteralPath $path) { throw "uninstaller left owned artifact $path" }
}
if (Test-Path $uninstallKey) { throw 'uninstaller left the Installed Apps registry key' }
if (Test-Path $productKey) { throw 'uninstaller left the HermesRelay product registry key' }
if (Test-Path -LiteralPath $startMenuDir) { throw "uninstaller left Start-menu artifacts at $startMenuDir" }
if (-not (Test-Path -LiteralPath $sessionSentinel -PathType Leaf)) {
throw 'uninstaller removed preserved profile session data'
}
if ((Get-Content -LiteralPath $sessionSentinel -Raw) -notmatch 'preserve-me') {
throw 'installer lifecycle modified preserved profile session data'
}
# Compare the raw registry value so expandable entries such as
# %USERPROFILE% are not resolved against the isolated smoke profile.
$userPathAfter = Normalize-UserPath (Get-RawUserPath)
if ($userPathAfter -ne $userPathBefore) {
throw "uninstaller did not restore user PATH (before='$userPathBefore', after='$userPathAfter')"
}
$startupAfter = (Get-ItemProperty -Path $startupKey -Name HermesRelayTray -ErrorAction SilentlyContinue).HermesRelayTray
if ($startupAfter -ne $startupBefore) {
throw "installer lifecycle changed the pre-existing tray startup preference"
}
Write-Host "packaged installer lifecycle smoke OK version=$versionOutput install=$installDir"
} finally {
Get-Process -Name 'hermes-relay-tray' -ErrorAction SilentlyContinue |
Stop-Process -Force -ErrorAction SilentlyContinue
if (Test-Path -LiteralPath $uninstaller) {
Start-Process -FilePath $uninstaller -ArgumentList '/S' -Wait | Out-Null
}
$env:USERPROFILE = $oldUserProfile
$env:HOME = $oldHomeEnv
$environmentKey = [Microsoft.Win32.Registry]::CurrentUser.OpenSubKey('Environment', $true)
if ($hadUserPath) {
$environmentKey.SetValue('Path', $originalUserPath, $originalUserPathKind)
} else {
$environmentKey.DeleteValue('Path', $false)
}
$environmentKey.Dispose()
if (Test-Path -LiteralPath $smokeRoot) {
Remove-Item -LiteralPath $smokeRoot -Recurse -Force -ErrorAction SilentlyContinue
}
}
- name: Upload Windows tray release asset
uses: actions/upload-artifact@v4
@@ -232,6 +409,7 @@ jobs:
runs-on: ubuntu-latest
needs:
- build-cli-binaries
- smoke-windows-cli-release-asset
- build-windows-tray-installer
steps:
# Needed so CLI_RELEASE_NOTES.md is available to render into the release body
+2 -2
View File
@@ -53,7 +53,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
@@ -88,7 +88,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+202 -2
View File
@@ -6,11 +6,211 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
## [1.9.1] - 2026-08-16
### Added
- **Android adopts Hermes-owned profile creation, shared avatars, and animated pets.** Current Gateways provide the profile roster, explicit shared/copied/isolated authentication choices, partial create outcomes, validated avatar upload/fetch/clear, and profile-scoped pet selection that follows the agent across supported Hermes clients. Older hosts retain authenticated Dashboard creation plus Relay/local presentation fallbacks, and profile deletion remains Dashboard-only.
- **Android identifies proactive messages delivered after reconnect.** Relay marks messages flushed from its bounded offline queue, Thread bubbles label them as received “While away,” and Android shows one accessible localized summary for the completed batch.
- **Android can create finite recurring schedules from Manage.** The native editor uses the authenticated Hermes Gateway `cron.manage` contract, optionally stops after 1–999 runs, and rejects invalid counts rather than silently creating unlimited work.
- **Chat resets retain content-free local evidence.** New-chat and Thread transitions save a bounded app-private checkpoint for user-reviewed Diagnostics without prompts, message text, IDs, profile names, paths, URLs, media, tool payloads, secrets, or telemetry.
- **Android surfaces host resource risk before chat state is lost.** Current Hermes Dashboard memory and disk pressure signals render as a persistent, capability-gated warning; older hosts remain unchanged and no telemetry is added.
- **Android honors Hermes model-selection safeguards.** Every Gateway model transition, including fresh-chat and Server-default choices, now avoids raw session overrides; picks requiring cost or data-training consent show Hermes' exact warning and apply only after a confirmed second request.
### Changed
- **Profile identity sources are explicit in Agent Passport.** Server-owned static avatars and upstream pets follow the Hermes profile, while phone picks, Relay-host imports, phone-only animated icons, and Sphere skins remain separate local presentation choices.
- **Interactive Gateway asks remain resolver-bound.** Android continues to use upstream clarify, approval, sudo, and secret response RPCs; connector-only prompt/reaction operations are not copied into Relay cards as a second approval protocol.
### Fixed
- **Issue area labels require maintainer review.** The unreliable keyword-based auto-labeling workflow no longer assigns ownership from ambiguous issue text.
- **Shared avatar picks now persist from Android's filesystem picker.** The app accepts any image Android can decode, applies display orientation, and safely resizes or re-encodes it to the upstream PNG/JPEG/WebP and 2,000,000-byte contract. Successful writes update the local shared cache immediately, and upload failures remain visible beside the control.
- **Nous-hosted Android sign-in follows the official native broker contract.** The gateway now selects its native provider exactly as Hermes Desktop does, callback attempts retain the upstream five-minute window, and post-callback failures explain whether the one-time code, hosted gateway, network, response, or secure storage prevented session creation without exposing auth material.
- **Android edit-and-regenerate fails closed on incomplete durable history.** Mixed Gateway transcripts now require the selected message's durable row identity instead of attempting an ordinal-only rewind, while older Hermes histories with no row identities remain editable.
- **Android fails closed when a Gateway does not confirm the selected profile.** Named-profile session creation and recovery now require Hermes to echo the exact owning profile, preventing stale or older gateways from silently running the launch profile under another agent's identity. Profile inspection also keeps read-only Gateway data available when `profiles.configure` is unsupported while disabling further write attempts without discarding drafts.
- **Android attachment sends are bounded and fail closed.** Picked files are size-limited while streaming into the encoder, cold and queued Gateway sends upload only after the exact session is ready, and an unsupported or interrupted document upload no longer falls through to a text-only route while its file card implies delivery. Every attachment type retains the same compact collapse/expand affordance.
## [0.4.0-beta.4] - 2026-08-15
### Fixed
- **The Windows management UI remains available while the daemon is stopped.** Missing, stale, malformed, or temporarily unavailable daemon status now resolves to an explicit stopped state instead of trapping the tray on its loading screen, so configuration, diagnostics, host management, and daemon controls remain accessible.
## [1.9.0] - 2026-08-14
### Added
- **Android session browsing matches Hermes Desktop's recent organization model.** The primary session drawer can toggle between the active profile and all profiles, group by recency, project, status, or profile, order by supported session metrics, and narrow rows by status, project, profile, or pull-request state without collapsing duplicate IDs across profile stores. Named profiles receive stable identity-color badges with locally persisted color overrides.
- **Android can edit current Hermes profiles through the standard Gateway.** The Profile Inspector capability-gates `profiles.describe` and `profiles.configure`, keeps Relay-only memory editing and older-Hermes fallback intact, and reports partial section saves without discarding failed drafts.
- **Android sessions show their coding context when Hermes supplies it.** Session rows can display repository, Git branch, and the current state of the pull request created by that session while older hosts remain unchanged.
- Android Manage can now finish host-owned backup workflows, edit or remove learning nodes with explicit recovery guidance, configure and activate memory providers, and complete profile-scoped WhatsApp QR onboarding through the authenticated upstream Dashboard contracts.
### Fixed
- **Android network clients shut down safely during route changes.** Replacing an authenticated Dashboard client now moves OkHttp connection-pool eviction off the main thread, preventing a live TLS socket close from crashing the app with `NetworkOnMainThreadException`. (#334)
- **Android preserves authoritative Gateway outcomes.** Protected-file cards cannot offer forbidden persistent scopes, compression no-ops show the server result, bounded resume failures do not create context-free replacement sessions, and edit/regenerate retains durable row identities across consecutive rewinds.
- **Android routes and uploads against live upstream truth.** Multiplex API fallback trusts `served_profiles` instead of installed profiles, and generic documents carry the Gateway-issued `@file:` reference into ordinary and queued prompts.
- **Android clarify cards preserve upstream decision semantics.** Multi-select prompts keep independent selections and submit one exact list, while server expiry events—not an invented local deadline—retire unanswered cards.
- **Android keeps profile management and retained automation truthful.** Custom Endpoint list and mutation routes now follow the selected Hermes profile, while completed one-shot cron jobs show their retained outcome and expose only valid Runs/Delete actions.
- **Android and Relay recover more generated media reliably.** Android accepts upstream-valid wrapped, punctuated, adjacent, spaced, and Windows `MEDIA:` markers without consuming fenced examples, and Relay translates Docker-visible workspace, home, cache, and configured-mount paths before applying its existing credential, sandbox, and size checks.
- **Android keeps cross-profile sessions with their owning agent.** Opening a session from All Profiles hydrates, resumes, sends, and renders with that session's profile without changing the global profile selection; New Chat from that view starts with the default profile.
- **Android reactions and standard voice follow the active conversation.** Reactions resolve durable rows for both user and assistant messages, while Vanilla Hermes voice remains on the authenticated Gateway instead of requiring the optional API fallback.
- **Android session navigation behaves predictably.** The drawer closes on outside taps, uses an ungrouped recent-session list by default, retains project grouping as an explicit option, and exposes secondary actions in All Profiles mode.
## [0.4.0-beta.3] - 2026-08-14
### Fixed
- **Windows tray polling can no longer accumulate unbounded helper processes.** Grant discovery now uses lightweight local state, management refreshes are single-flight and visibility-aware, and child probes have hard timeouts, bounded output, tree cleanup, caching, and backoff. A dedicated bounded `tray.log` records sanitized operational failures without mixing them into daemon logs.
- **Concurrent Desktop lifecycle requests cannot start duplicate daemons.** Cross-process lifecycle and runtime ownership locks serialize startup and recovery while preserving stale-owner cleanup.
## [1.8.0] - 2026-08-14
### Added
- **Official Hermes Desktop can surface Relay through its supported runtime Plugin SDK.** The unified plugin package now includes an opt-in, profile-scoped Desktop pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management. Loading, startup, reconnects, profile changes, and updates never open it; only labeled sidebar, status-bar, or command-palette actions register and reveal the movable native pane.
## [0.4.0-beta.2] - 2026-08-14
### Added
- **Desktop Activity now keeps inspectable local evidence.** Commands, files, devices, connection lifecycle, and computer control share a truthful event stepper with dedicated failure details; screenshot events can retain bounded local PNG evidence and open it in a larger borderless viewer. Settings controls retention as Off, 1 day, 7 days, or 30 days and shows local file usage.
### Fixed
- **Tunnel state stays responsive through interruption and retry.** The CLI UI distinguishes connected, reconnecting, and stopped states, exposes retry attempt/timing and a Retry now action, records connection failures and recovery in Activity, and shows compact connection cards only while the main UI is hidden.
- **Windows CUA readiness no longer depends on the flaky whole-desktop health scan.** Hermes-Relay verifies the canonical runtime, manifest, required tools, daemon, and safe permission mode before starting structured sessions, while accessibility health remains an explicit CLI/UI diagnostic that can be rechecked without forcing the compatibility backend. This temporary workaround is scoped to the upstream fixed-timeout issue and keeps individual actions fail-closed.
## [0.4.0-beta.1] - 2026-08-14
### Added
- **CUA Driver is the preferred Windows structured-control engine.** New local settings prefer a verified CUA runtime for window-targeted background actions, fresh snapshot tokens, and optional per-session animated agent cursors without moving the physical pointer; Windows Input is the explicit compatibility backend and backend choice is fixed for each control session. Full-display observation remains on the read-only system capture path. CLI and UI can explicitly install, check, or update the canonical CUA package after verifying the upstream release manifest and installer checksum; nothing is bundled or updated automatically, driver telemetry stays off for Hermes sessions, and activity records contain only bounded, redacted control metadata.
### Fixed
- **Windows bundle updates fail closed when installed processes retain a binary lock.** Setup waits for the invoking CLI, quiesces the tray and its short-lived CLI children, checks every payload extraction before writing release metadata, preserves custom install directories, and returns a failure instead of reporting a mixed-version installation.
- **CUA readiness follows the published driver contract.** Hermes accepts the documented `ok` health state, distinguishes an installed-but-degraded runtime from a missing installation, and constructs trusted Windows installer paths consistently across verification environments.
## [1.7.0] - 2026-08-13
### Added
- **Hermes Secure Link provides self-hosted pinned TLS ingress.** Relay, API, and Dashboard namespaces share one operator-owned TLS endpoint while retaining their native authentication boundaries, QR-carried certificate continuity, explicit rotation, and fail-closed route validation.
- **Hermes Reach is available for explicit experimentation.** The optional self-hosted rendezvous broker carries opaque Secure Link TLS records over outbound-only connections with bounded multiplexing, hashed credentials, replay protection, persistence, revocation, and no access to Hermes payloads.
- **Remote-access management exposes supported reachability clearly.** Dashboard status and pairing metadata distinguish Tailscale reachability, Secure Link transport protection, direct routes, and experimental Reach without presenting the broker as a replacement for authentication.
### Changed
- **Tailscale is the recommended remote route.** Pairing, Dashboard, documentation, and public site guidance present Tailscale as the easiest supported remote-access path; Reach remains disabled by default, advanced, and lower priority than supported routes.
- **Relay voice custom transports follow upstream provider security options.** Relay-owned OpenAI/xAI realtime and TTS clients honor custom headers, custom CA bundles, standard CA environment precedence, and an explicitly warned development-only verification override.
- **Voice Lab xAI sign-in uses device authorization.** The standalone login shows a verification URL and user code and polls for approval without requiring a loopback callback.
### Fixed
- **Phone delivery remains compatible with strict Hermes targets.** Version-tolerant parser and validator hooks retain older-host registration and exactly-once standalone delivery.
- **Profile-owned Relay registrations stay isolated.** Current Hermes uses profile-scoped ownership and context-local profile homes while legacy hosts retain a guarded compatibility path.
- **Phone is discoverable before its first historical session.** The Relay phone adapter publishes its configured home destination through Hermes' standard channel directory.
## [0.4.0-alpha.8] - 2026-08-13
### Added
- **Windows management separates each Relay host from this PC.** Host detail owns identity, pairing, access, capabilities, authorized clients, re-pairing, and guarded removal; Settings owns local daemon lifecycle, startup, privilege, terminal, logs, diagnostics, updates, and Help & About.
- **Desktop access uses clear host-scoped presets and capabilities.** Restricted, Ask Every Time, Standard, Full Access, and Custom remain explicit across commands, files, screen/input, USB, microphone, and camera controls.
- **Activity drilldown preserves bounded execution evidence.** Overview shows the latest three events and detail views expose request, output, result, exit, duration, and truncation metadata without copying sensitive inputs.
- **Connection presentation shows the live Agent-to-PC path.** Host selection, bidirectional packet motion, transition feedback, route details, and connection testing stay compact, responsive, and reduced-motion aware.
### Changed
- **Connect and disconnect remain responsive during daemon work.** Lifecycle calls and snapshot collection run outside the UI thread, transition status polls quickly without overlapping probes, and progress remains visible until authoritative daemon state arrives.
- **Tailscale is recommended for remote access.** Secure Link and direct TLS routes remain supported, while Hermes Reach is visibly experimental and lower priority.
### Fixed
- **Connection tests classify legacy private routes correctly.** A saved generic role is inferred from its actual endpoint, so LAN and Tailscale routes no longer appear as Custom VPN; results include reachability, latency, security, endpoint, and route count.
- **Ask-mode approval cards show the requested action.** A bounded preview appears in the compact card with full context and an Open in UI action.
- **Mixed capability policies are labeled Custom.** Overview no longer claims a preset when individual capability controls differ.
- **Tray placement follows the notification-area monitor and DPI.** Responsive popup geometry stays anchored above the tray icon across compact and high-DPI desktops.
- **PowerShell success output is complete and self-describing.** Scalar, pipeline, JSON, native stdout/stderr, exit status, and truncation metadata survive the desktop RPC response.
## [1.6.4] - 2026-08-12
### Added
- **Desktop tools support explicit host targeting.** Every client-routed desktop tool accepts a stable device ID or unambiguous computer name, and `/desktop/health` enumerates connected targets and their advertised tools.
- **USB operations retain both routing scopes.** Raw USB and ADB tools use `device` to select the desktop PC, while ADB operations continue to use `serial` to select hardware attached to that PC.
### Fixed
- **Multiple desktop clients remain connected simultaneously.** The Relay no longer replaces the previous desktop when another heartbeat arrives; concurrent requests are bound to their selected WebSockets, responses from another PC are ignored, and an untargeted call fails closed when several desktops are online.
- **Pairing another desktop preserves existing credentials.** Legacy placeholder device identifiers are treated as absent instead of shared ownership, preventing an unrelated PC from revoking the first desktop's session.
## [1.6.3] - 2026-08-11
### Fixed
- **Relay diagnostics distinguish a prior clean stop from a crash.** Doctor and `/relay/info` expose only bounded clean, unclean, or unknown gateway-exit state with an optional suspected out-of-memory hint, without returning raw log evidence.
- **Relay reconnects spread out after shared gateway restarts.** Ordinary exponential reconnect delays use full jitter while explicit reconnects and server-directed retry timing retain their exact behavior.
## [0.4.0-alpha.7] - 2026-08-11
### Fixed
- **Installer lifecycle validation uses an isolated Windows PATH fixture.** Release smoke tests now verify add/remove cleanup against a fixed registry value and restore the runner's original value afterward, independently of the temporary profile used for session-preservation checks.
## [0.4.0-alpha.6] - 2026-08-11
### Fixed
- **Installer cleanup validation compares the unexpanded Windows PATH.** Release smoke tests now read the raw user registry value, ensuring `%USERPROFILE%` entries are verified without temporary-profile expansion changing their apparent value.
## [0.4.0-alpha.5] - 2026-08-11
### Fixed
- **Installer cleanup validation handles expandable Windows PATH entries.** Release smoke tests restore the original profile environment before comparing user PATH, avoiding false failures when unchanged `%USERPROFILE%` entries are expanded inside an isolated test profile.
## [0.4.0-alpha.4] - 2026-08-11
### Fixed
- **Windows release validation waits for installer processes.** The packaged install/uninstall lifecycle smoke now captures GUI-subsystem process exit codes reliably before validating installed files, preserved sessions, registry state, and cleanup.
## [0.4.0-alpha.3] - 2026-08-11
### Added
- **Windows tray provides focused remote-access management.** The compact host-aware popup covers connection state, per-host Ask/Trusted/Full Access, pending grant dialogs, authorized-client revocation, activity, daemon controls, and settings without adding chat, terminal, plugin, voice, or session surfaces.
- **Desktop access policy is isolated per Hermes host.** `hermes-relay hosts` lists and selects local pairings and stores fail-closed access modes independently for each canonical relay URL.
- **Windows CLI installations can add or open the management UI directly.** `hermes-relay ui install|open|status` and the installed UI shim provide a supported lifecycle for optional UI setup, discovery, and activation.
### Changed
- **Daemon connectivity no longer requires a tool grant.** Ask mode can keep an authenticated daemon connected with zero desktop tools attached; Trusted enables command/file tools with task-scoped screen/input grants, while Full Access removes those task prompts only for the selected host.
- **Windows bundle updates preserve the desktop lifecycle.** The CLI and tray coordinate one verified installer launch, restore the daemon and UI after setup, and permit same-version UI add or repair without silently downgrading a newer CLI.
### Fixed
- **Background daemon start reports real readiness.** Detached startup now waits for the spawned process to authenticate and connect, and returns actionable log evidence for configuration, authentication, early-exit, and timeout failures.
- **Local and release tray builds embed the packaged UI.** Development installs use Tauri's production protocol instead of attempting to load a missing localhost development server, and release CI exercises a silent install/uninstall lifecycle.
- **Windows-trusted certificates work in the desktop CLI.** The packaged Windows binary and newer Node runtimes add the Windows certificate store without dropping bundled or operator-supplied roots, while TLS verification and Relay certificate pinning remain enforced.
## [1.6.2] - 2026-08-11
### Fixed
- **Paired sessions use recognizable device identities.** Relay sessions preserve a client-provided hostname as the primary name, retain model and platform details, and enrich valid reconnects without requiring users to pair again.
- **Long-lived session expiry is readable.** The Dashboard presents paired-session lifetime in days or weeks with the exact local deadline available in the detail view instead of accumulating hundreds of hours.
## [Android 1.8.1] - 2026-08-09
### Fixed
- **Android preserves complete long-session transcripts.** API-server and profile-scoped Dashboard history reads now use explicit bounded pagination, retain compatibility with older unpaginated responses, and keep edit, retry, sharing, and recovery anchors stable beyond Hermes' latest-500 default window.
- **Android follows authoritative Gateway turn contracts.** Submit rejections retain the server's message without silently falling through to SSE, event envelopes reconcile consistently, and edit-and-regenerate requests send the required truncation confirmation.
## [Android 1.8.0] - 2026-08-09
### Added
@@ -517,7 +717,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Spoken-turn badges (chat).** Voice-mode replies now carry a "Voice" chip and realtime replies a "Realtime Agent" chip — both with a speaker glyph — so spoken turns are distinguishable from typed ones in the scrollback.
- **App themes.** A new theme picker in Settings → Appearance ships eight looks: the signature Hermes Relay brand (with full light/dark) plus ports of the Nous Hermes baselines — Hermes Teal, Nous Blue (light), Midnight, Ember, Mono, Cyberpunk, and Rosé. The whole app — brand chrome, accents, and chat background — follows the chosen theme. Light/Dark/Auto applies to themes that ship both modes; fixed-mode themes show their own complete look.
- **Hot-swappable agent sphere.** The orb is now a pluggable "skin": an Adaptive skin that recolors to match your theme, built-in Classic / Aurora / Solar / Mono looks, and support for **user-authored skins** loaded from a small JSON spec. Each skin declares which live signals it reacts to (voice, tool bursts, activity), shown as capability badges in the picker. See `docs/sphere-spec.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. A plugin-provided **Secure proxy** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. The optional plugin-provided **Hermes Secure Link** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Enhanced voice control (Gemini & xAI).** When the relay uses a Gemini or xAI voice provider, Voice Settings can now steer it: pick a Gemini voice and model and turn on expressive tone tags (with optional natural-language voice direction), or set an xAI voice with expressive speech tags. Expressive tags also apply to xAI on the streaming voice-output renderer. Standard (no-plugin) voice stays configured server-side.
- **Voice render-path visibility.** Voice Settings shows which path is rendering speech (streaming vs. basic), and Diagnostics records it each session, making voice issues easier to troubleshoot.
- **Agent pets — a living, swappable avatar.** The orb can be replaced with an animated "pet" that reacts to what the agent is doing: idle / thinking / writing / speaking / listening states, a distinct **working** pose during tool calls, one-shot **greet** / **celebrate** reactions, and a loop that quickens as output streams. Add or remove pets right in Settings → Appearance (no `adb` needed), with a live state preview, a playback-speed slider, and optional frame auto-stabilization; capability badges (Voice · Tools · Activity) show honestly what each pet actually reacts to. Pets are pure data — an AI authoring kit and a JSON schema let you generate one from sprite art. See `docs/pet-spec.md` and the custom-avatars guide.
+11 -25
View File
@@ -1,35 +1,21 @@
# Hermes-Relay-CLI v__VERSION__
# Hermes-Relay CLI v__VERSION__
**Release Date:** 2026-07-13
**Release Date:** 2026-08-15
This alpha makes the desktop direction explicit: Hermes-Relay is a real CLI/TUI with an optional Windows right-click systray—not a second desktop application. The old Tauri/WebView dashboard and its embedded windows are gone. The installed CLI remains the single source of behavior for pairing, TUI, daemon management, grants, audit, diagnostics, chat, voice, and tools.
This patch keeps the Windows management UI usable when the Relay daemon is stopped or its status cannot be read.
**Experimental phase.** Assets are unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the optional native systray is Windows-only.
**Beta phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the management UI is Windows-only.
## What's changed
### Added
- **Persistent desktop-use control.** `hermes-relay computer-use status|enable|disable|cancel` stores one local preference, reports daemon privilege and active/pending grants, and can end an active task-scoped grant without relying on a GUI.
- **Headless grant review.** `hermes-relay grants` lists pending local computer-use requests and supports interactive review plus explicit `approve`, `reject`, and JSON forms for scripts.
- **Typed Relay chat option.** `chat --relay-chat` sends `chat.send` over WSS and renders typed `stream.event` v1 assistant, tool, artifact, memory, skill, and error lifecycles while preserving the existing gateway path as the default.
- **Release-parity verification.** One version contract now keeps the npm package, compiled CLI, Rust tray, lockfile, and installer metadata aligned. The Windows verification target covers TypeScript, compiled-binary smoke tests, Rust formatting/lint/check/tests, and installer packaging.
### Changed
- **Menu-only Windows systray.** The optional tray is a small native Rust process with no application window, WebView, overlay, embedded terminal, chat view, voice view, or settings dashboard. Interactive actions open the installed CLI in a normal terminal.
- **State- and privilege-aware daemon control.** The menu reports PID-backed daemon state and User/Administrator privilege, disables invalid lifecycle actions, and requests UAC only when **Start/Restart daemon as Administrator…** is explicitly chosen. The tray itself remains unprivileged.
- **Visible desktop-use safety.** The tray shows enablement, active grant mode and expiry, warns when an Administrator control grant is active, raises a native alert for pending approvals, opens CLI grant review, and provides immediate cancellation and emergency stop.
- **Per-user Windows installation.** The default PowerShell installer downloads the checksum-verified NSIS package, installs the CLI and optional tray under `~/.hermes/bin`, adds Start-menu shortcuts and user PATH, and can start the tray at sign-in. CLI-only installation remains available with `HERMES_RELAY_INSTALL_SURFACE=cli`.
### Fixed
- **Installed-binary diagnostics.** `hermes-relay doctor` reports the physical Bun-compiled executable instead of a virtual embedded-module path, so PATH and install-directory checks describe the binary that actually launched.
- **Release guardrails.** CLI tag automation rejects version drift, tags not contained in `main`, oversized tray binaries, or a tray process that creates an application window.
- **Stopped daemons no longer block the management UI.** Missing, stale, malformed, or temporarily unavailable daemon status falls back to an explicit stopped state while hosts, settings, activity, CLI details, diagnostics, and daemon controls continue loading normally.
- **Starting the daemon restores live status without reopening the UI.** A valid running status continues through the same bounded, single-flight snapshot path introduced in beta.3.
## Install
**Windows CLI + optional systray (PowerShell):**
**Windows CLI + management tray (PowerShell):**
```powershell
irm https://raw.githubusercontent.com/Codename-11/hermes-relay/main/desktop/scripts/install.ps1 | iex
@@ -53,11 +39,11 @@ Pin this release with `HERMES_RELAY_VERSION=__TAG__`.
```text
hermes-relay --version
hermes-relay pair --remote ws://<host>:8767 --grant-tools
hermes-relay hosts list --json
hermes-relay daemon start
hermes-relay daemon status
hermes-relay daemon status --json
```
On Windows, open **Hermes Relay Systray** from the Start menu and right-click its notification-area icon. No separate desktop window is installed.
On Windows, click the Hermes-Relay CLI UI notification-area icon to open the management popup directly above it.
See the [CLI and systray guide](https://hermes-relay.dev/docs/desktop/) for installation, commands, desktop-use safety, and troubleshooting.
See the [CLI and tray guide](https://hermes-relay.dev/docs/desktop/) for installation, access modes, grants, and troubleshooting.
+16
View File
@@ -1,5 +1,21 @@
# Hermes-Relay — Dev Log
## 2026-08-14 — Android 1.9.0 session identity and conversation controls
Hermes-Relay Android 1.9.0 is published from the immutable
`android-v1.9.0` tag. Multi-profile session browsing now keeps the aggregate
drawer scope selected while transcript hydration, resume, sending, and header
identity follow the session's owning profile. New Chat from All Profiles uses
the default profile, and the session list starts ungrouped while retaining
project grouping and the other desktop-style views as explicit options.
Message reactions now resolve durable rows for both user and assistant
messages. Vanilla Hermes voice remains on the authenticated Gateway instead of
requiring the optional API fallback. Session rows can expose profile, project,
branch, and pull-request context without crowding the chat header, secondary
drawer actions remain available in All Profiles, and outside taps dismiss the
drawer.
## 2026-08-09 — Gateway activity recovery and chat speech
Successful Android Gateway turns now reconcile against their profile-owned,
+11 -5
View File
@@ -1,17 +1,22 @@
# Hermes-Relay-Server v__VERSION__
**Release Date:** August 8, 2026
**Release Date:** August 14, 2026
This patch makes the optional Dashboard plugin's Android setup handoff reliable for hosted Hermes connections.
This release adds an official, opt-in Relay pane for Hermes Desktop through the supported runtime Plugin SDK. It keeps Relay management profile-scoped and user-invoked without opening a pane during startup, reconnects, profile changes, or plugin updates.
Standard chat, session history, and Vanilla Hermes voice remain upstream-owned and do not require this plugin.
## What's changed
### Fixed
### Added
- **Canonical hosted-Hermes setup handoff.** The Dashboard plugin supplies the verified Dashboard address Android needs to continue through the official system-browser authentication flow.
- **Contained dialog focus behavior.** Mobile setup dialogs retain their own focus and keyboard handling without disrupting the surrounding Dashboard.
- **Official Hermes Desktop pane.** The unified plugin package registers a movable native pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management.
- **Explicit entry points.** Labeled sidebar, status-bar, and command-palette actions register and reveal the pane lazily; repeated opens reuse the same surface.
- **Profile-scoped state.** Cached Relay state follows the active Hermes profile and is disposed cleanly when the plugin unloads.
### Changed
- **Plugin loading stays passive.** Loading, startup, reconnects, profile changes, and updates never reveal the pane or perform pane-owned network work.
## Install / update
@@ -26,6 +31,7 @@ Standard chat, session history, and Vanilla Hermes voice remain upstream-owned a
## Verify
hermes relay doctor
# Agent/tool callers can use desktop_health to list desktop targets.
python scripts/check-plugin-version-sync.py --expect __VERSION__
---
+25 -2
View File
@@ -70,6 +70,21 @@ an HTTPS reverse proxy. The [full walkthrough](https://hermes-relay.dev/docs/gui
covers Windows, remote access, and dashboard authentication. You do not need to
enable the separate API server or invent an API key for the standard path.
For plugin-enabled setups, optional **Hermes Secure Link** presents Relay, API,
and Dashboard routes through one pairing-pinned TLS origin. It protects traffic
to the paired endpoint while each service keeps its own authentication; it does
not provide reachability or independently identify the physical host. You still
use LAN routing, Tailscale or another VPN, or an operator-managed public route
to reach the listener. Secure Link is off by default and requires a fresh QR
pairing after it is enabled. See the
[remote-access guide](https://hermes-relay.dev/docs/guide/remote-access/).
**Hermes Reach** is an experimental, advanced outbound-broker route. It remains
available for development and self-hosted evaluation, but it is disabled by
default, ordered after supported routes, and not recommended for normal remote
access. Use Tailscale for the easiest supported remote setup, or a public TLS
domain / Direct Secure Link when you want to own the complete network path.
### 3 · Connect and talk
Open the app, choose **Connect to Hermes**, and enter or discover the dashboard
@@ -186,7 +201,7 @@ tracked independently so community corrections remain easy to contribute.
## Hands on any machine — the Hermes-Relay CLI&nbsp;<sub>(alpha)</sub>
> **Alpha.** Self-contained CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64 — no Node required. Windows also has an optional native, menu-only systray. Assets are unsigned during the experimental phase, so SmartScreen / Gatekeeper warnings are expected.
> **Alpha.** Self-contained CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64 — no Node required. Windows also has an optional compact management tray. Assets are unsigned during the experimental phase, so SmartScreen / Gatekeeper warnings are expected.
The agent's brain stays on the host; the CLI lets it call tools **on your machine** over the same WSS relay — `read_file`, `write_file`, `terminal`, `search_files`, `screenshot`, `clipboard`, `open_in_editor`, and more — behind a one-time consent gate, interactive diff approval for patches, and a `--no-tools` kill-switch.
@@ -202,7 +217,15 @@ hermes-relay update # self-update via GitHub Releases
It pairs against the **same relay and credential store** as the Android app — pair once from either, both work. Tagged on the `desktop-v*` [release track](https://github.com/Codename-11/hermes-relay/releases?q=desktop), with historical releases still visible under `cli-v*`.
On Windows, the default installer adds the optional right-click-only systray: no dashboard or app window, just TUI launch, User/Administrator-aware daemon controls, pairing, local grant review, audit, diagnostics, logs, desktop-use status/cancellation, sign-in startup, and emergency stop.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. It is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
Structured Windows computer control prefers a compatible local CUA Driver
runtime for window-targeted background actions and virtual per-session agent
cursors. It remains behind Hermes host policy, grants, targeting, audit, and
emergency stop; Windows input is an explicit compatibility backend. CUA is not
bundled or updated automatically, but the local CLI/UI can explicitly install,
check, or update its verified canonical package. It is never exposed as a raw
remote tool surface. See the [desktop tools guide](https://hermes-relay.dev/docs/desktop/tools.html#computer-use-engines).
- **Docs:** [CLI guide](https://hermes-relay.dev/docs/desktop/) · [`desktop/README.md`](desktop/README.md)
- **AI-agent setup recipe:** `/hermes-relay-desktop-setup`
+9 -3
View File
@@ -119,19 +119,23 @@ artifacts.
### CLI / tray versioning
`desktop/package.json` is the Desktop/CLI release track's source of truth. Its version
must match the generated CLI and native Windows systray metadata. The systray is
a menu-only controller for the installed CLI; it has no application window,
WebView, embedded terminal, or separate desktop product surface. The public
must match the generated CLI and Windows tray metadata. The tray is a compact
management popup over the installed CLI and shared state; it has no chat,
embedded terminal, plugins, voice, or separate desktop product surface. The public
release remains one `Hermes-Relay-Desktop` track containing CLI binaries plus the
optional Windows installer.
| File | Purpose |
|---|---|
| `desktop/package.json` | canonical CLI version |
| `desktop/.bun-version` | exact Bun compiler/runtime for standalone binaries |
| `desktop/package-lock.json` | npm root/workspace package metadata |
| `desktop/src/version.ts` | compiled CLI runtime version |
| `desktop/tray/Cargo.toml` | native systray package version |
| `desktop/tray/Cargo.lock` | locked systray package version |
| `desktop/tray/tauri.conf.json` | tray application and bundle version |
| `desktop/tray/package.json` | tray UI package version |
| `desktop/tray/package-lock.json` | locked tray UI package version |
Prepare a new CLI version on `dev` without creating a tag or npm-generated
commit:
@@ -149,6 +153,8 @@ manually, run `npm run sync:version` before checking. `npm run verify` is the
single Windows release-parity gate: version sync, type-check, tests, TypeScript
build, compiled CLI smoke, and tray formatting, Clippy, check, and tests. CI runs
the portable portions on every desktop change and the Windows tray gates separately.
Release jobs read `desktop/.bun-version`; cross-built and Windows-built artifacts
must not silently embed different Bun runtime versions.
## Branching policy
+26 -34
View File
@@ -1,10 +1,10 @@
# Hermes-Relay-Android v1.8.0
# Hermes-Relay-Android v1.9.1
**Release Date:** August 9, 2026
**Release Date:** August 16, 2026
## Download
> Installing on your phone? Download `hermes-relay-1.8.0-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
> Installing on your phone? Download `hermes-relay-1.9.1-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
The `.aab` file is a Play Console upload bundle and cannot be installed by tapping it on a phone.
@@ -12,43 +12,35 @@ Verify the download against `SHA256SUMS.txt`. See the [sideload guide](https://h
## Summary
This release makes mobile conversations calmer and more capable: richer message
actions and attachments, concise reasoning and tool activity, immediate profile
switching, and deeper appearance customization without mixing session identity.
This patch aligns Agent Passport with current Hermes profile identity, makes
shared avatar changes reliable from the phone, and hardens several Gateway
operations around profile ownership, attachments, recovery, and model consent.
## Added
- Quote or edit a message, attach and reorder files with previews, search the
conversation, and jump between prompt turns without losing session context.
- Switch agents from the compact Profile Shelf while preserving each profile's
last session and the server-default identity.
- Share text from another Android app into a fresh reviewed Chat draft.
- Customize theme accents and shapes, import Sphere skins, and create or install
pets from one live-preview Appearance workflow.
## Changed
- Live reasoning opens inline and settles to a compact Thought disclosure.
Routine tool work groups into a concise activity surface, while approvals,
failures, generated media, edits, risks, and delegated work stay distinct.
- Agent Passport controls remain session-scoped: model and reasoning choices no
longer overwrite server defaults merely by inspecting or switching profiles.
- Create Hermes profiles with explicit shared, copied, or isolated
authentication choices and inspect partial setup outcomes.
- Select upstream animated pets that follow the active Hermes profile across
supported clients, while keeping phone-only animated icons separate.
- Create finite recurring schedules, review bounded reset evidence, and see
host resource or model-consent warnings before taking action.
## Fixed
- Configured voice can speak any completed assistant message without requiring
Voice Mode, and the same message menu exposes Stop during playback.
- Quotes remain readable inside bubbles, portrait images honor EXIF rotation,
and keyboard controls follow standard capitalization and Enter behavior.
- Persisted Gateway history recovers missing structured tool activity without
republishing healthy transcript state or duplicating cards.
- Floating pets avoid chat identity rows and controls while scrolling, remain
touchable for their menu, and Appearance stays clear of system status bars.
- Shared avatar images selected from Android now persist. The app accepts any
decodable image and safely converts it to Hermes' supported static format and
size contract when needed.
- Named-profile sessions, draft writes, rewinds, and recovery fail closed when
Hermes cannot confirm the owning profile or durable history.
- Attachment sends remain bounded and no longer fall through to text-only
delivery after an unsupported or interrupted upload.
- Nous hosted sign-in follows the official native callback and provider
contract with clearer, non-sensitive failure guidance.
## Install / Verify
- App version: **1.8.0** (versionCode **41**).
- Standard Chat, sessions, Manage, and Vanilla Hermes voice continue to work
against unmodified upstream Hermes.
- The optional Relay plugin is not required for standard Android chat or hosted
Dashboard authentication.
- App version: **1.9.1** (versionCode **44**).
- Standard Chat, sessions, Manage, profile identity, and Vanilla Hermes voice
continue to work against unmodified upstream Hermes.
- The optional Relay plugin is not required for standard Android chat, shared
profile avatars, upstream pets, or hosted Dashboard authentication.
+58 -5
View File
@@ -6,6 +6,40 @@ For shipped work, see `DEVLOG.md`. For architectural decisions, see `docs/decisi
---
## Certify the official Desktop Relay plugin
The unified `plugin/desktop/plugin.js` implementation is covered by source-level
SDK contract, packaging, explicit-open, no-auto-open, close, unload, and profile
cache-isolation tests. A physical official Hermes Desktop session is still
required before calling the UX live-certified:
- Test default and named local profiles, ordinary authenticated remote mode,
and SSH mode with differently named local/remote profile mapping.
- In two full app windows, prove enabling, registration, explicit open,
requests, close/reopen, hot reload, and disable/unload remain window-local.
- Prove startup, reconnect, profile change, layout restore/reset, update, and
background events never open or focus Relay.
- Drag and dock the pane across native zones, close it, reopen it from all three
labeled actions, and verify no private-hook fallback is needed.
- Exercise Relay running/unreachable, zero/one/multiple devices, pairing,
revocation, bridge activity, media, remote access, and renderer error logging
without exposing credentials, pairing payloads, filesystem paths, or tokens.
---
## Structured desktop hardware capabilities
Structured access and per-host USB policy now ship with typed, serial-bound ADB
list, shell, push, pull, install, and bounded logcat operations. Remaining work:
- Add microphone and camera only with backend readiness detection, bounded local
grants, active-use indicators, audit events, and immediate cancellation.
- Reconcile legacy `desktop_screenshot` with the task-granted computer screenshot
path so screen capture follows one policy.
- Extend capability policy beyond hardware only where a typed broker provides a
meaningfully stronger boundary than Structured mode already provides.
---
## Android Plugin Studio protocol follow-ups
The first live declarative Plugin lane is host-local: Relay tools create bounded
@@ -909,7 +943,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
- Live gateway must discover the plugin (`~/.hermes/plugins/hermes-relay` → `plugin/`) and `plugins.enabled` must include `hermes-relay` for the `phone` platform to register. Confirm `phone` appears in `hermes gateway status` with `PHONE_ENABLED=1`.
- End-to-end: with the app paired + "Let Hermes message me" on, run `send_message target=phone text=...` (and a cron `deliver=phone`) and confirm a notification on the device. Verify 503 (no phone) and the off-by-default gates.
- **Phase 2c reply round-trip — ✅ DONE (verified on-device 2026-06-29).** Confirmed: agent → phone notification → inline reply → drained through the relay's loopback `GET /phone/replies` (different process) → `handle_message` (`role_authorized=True`, no `PHONE_ALLOW_ALL_USERS`) → agent answer back in the *same* thread. Both fixes required (see DEVLOG / the Phase 2c bullet above).
- **FIX: cron `deliver=phone` / standalone send is broken.** Live testing: `hermes send --to phone` returns `{"error": "Unknown platform: phone"}`. The standalone (non-gateway) send path doesn't run a `kind=standalone` plugin's programmatic `ctx.register_platform`, so it never learns `phone` — only the running gateway (which loads `register()` at startup) does. The agent path (`send_message target=phone` in the gateway) works and was verified end-to-end on-device; the standalone/cron path needs the platform discoverable there too (declare it so the standalone loader picks it up, or route cron through the gateway). Until then `cron deliver=phone` won't work.
- **Cron `deliver=phone` live certification pending.** The plugin now registers its standalone sender and enumerates the canonical phone home through the upstream adapter channel-directory hook. Re-run the device scenario above on the deployed plugin to certify scheduled delivery, including the offline queue and opt-in gates.
- **FIX SHIPPED (2026-07-07) — installer + doctor guard against stale duplicate plugin copies; live-host verify pending.** Root cause of the 2026-06-29 round-trip failure: the gateway loader dedups discovered plugins by manifest `name`, so a second directory declaring `name: hermes-relay` (an old-installer backup copy, or a stray native install) could win the dedup and make the gateway load stale code — silently ignoring every later deploy. `plugin/doctor.py` now emits a `plugin-name-unique` warning when more than one directory under `~/.hermes/plugins/` declares the same plugin name (distinct real targets only — two links to the same target are deduped), and `install.sh` sweeps any such duplicate so only the canonical `hermes-relay` symlink survives. (Current `install.sh` already `rm -rf`s the old link rather than backing it up inside the plugins dir, so the original "back up outside the plugins dir" half is moot.) **Verify on the live host:** `hermes relay doctor` reports the `plugin-name-unique` check, and a reinstall leaves exactly one `hermes-relay` entry under `~/.hermes/plugins/`.
## Phone platform — usability roadmap (post device-verification, 2026-06-29)
@@ -920,9 +954,9 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
**Refinement (2026-06-29) — unified-session model: "Threads."** Going further on "unified surface": the agent conversation is **not a separate tab/segment** at all — it is a **source-tagged session inside the one Chat surface**, a **Thread** (`source=phone`). What makes a Thread special vs. a normal gateway chat are *session properties*, not a separate UI: (a) the agent can initiate, (b) relay `proactive` transport + relay-gated, (c) standing/named DM. **Scrollback = the gateway session store** (same read path Chat uses); **live receive = relay `proactive` push** (→ notification); **send = `proactive.reply`**. `ProactiveInboxStore` is demoted to a live-push cache + outbox (no parallel history). The Thread capability shows in the **best-path/capability UI** (relay tier, like terminal/bridge/voice) and as a clean **Threads** entry — thread-spool icon, NOT a phone glyph — pinned atop the session drawer when active; never a connection-wizard step. Degrades cleanly (no plugin → no `source=phone` sessions → Chat unchanged). **Supersedes the "separate Agent lane / 4th nav segment" sketch** and merges with the "source attribution in Chat" goal below. Keep the two "gateway" senses straight: *platform layer* (the Thread's `source`) ≠ *dashboard `/api/ws` transport* (how live bytes flow). Full re-cut: docs/decisions.md ADR 12.
- **Outbound buffering — ✅ relay-side DONE (2026-06-29).** `ProactiveChannel.push()` now queues agent→phone messages in a bounded deque (drop-oldest, 24 h TTL) when no phone is subscribed and returns `{queued: true}` (not 503); `_flush_outbound` delivers FIFO on the next subscribe (stale pruned). Inspect/cancel via `peek_outbound`/`cancel_outbound` + loopback `GET`/`DELETE /phone/outbound`. **UI surfacing of the queued state** (host-side, since the queue exists while the phone is OFFLINE): (a) ✅ **desktop CLI `relay queue` / `relay queue --clear` / `--cancel <id>` DONE (2026-06-29)** over the new endpoints (loopback-only — run on the relay host); a dashboard Relay-tab view is the optional GUI equivalent; (b) **remaining** — in the threaded agent surface, mark messages that arrived-while-away, and show the user's OWN pending replies (the Phase 3 reply queue) with a sending/Cancel affordance — that's where phone-side "queued + cancel" belongs.
- **Outbound buffering — ✅ relay-side + arrived-while-away receive UX DONE.** `ProactiveChannel.push()` queues agent→phone messages in a bounded deque (drop-oldest, 24 h TTL) when no phone is subscribed and returns `{queued: true}`. `_flush_outbound` delivers FIFO on the next subscribe (stale pruned), marks flushed messages, and sends one batch-complete count; Android labels those Thread bubbles “While away” and shows one accessible batch summary without changing unread behavior. Inspect/cancel remains available through `peek_outbound`/`cancel_outbound`, loopback `GET`/`DELETE /phone/outbound`, and desktop `relay queue`. **Remaining:** show the user's OWN pending replies (the Phase 3 reply queue) with an honest Queued/Cancel affordance; a dashboard queue view remains optional.
- **Threads surface (unified-session model — see ADR 12 + the Refinement above).** Build order, each shippable: **(1)** source tags in the session drawer (`source=phone` → clean **Threads** chip + thread-spool icon, NOT a phone glyph) — also delivers the "source attribution in Chat" goal; **(2)** open a Thread in Chat from its session-store history (reuse the existing message-history path); **(3)** route the live `proactive` push into the session view + notification + unread, demoting `ProactiveInboxStore` to cache/outbox; **(4)** reply from the Chat composer via `proactive.reply` + persist the user turn + local `Sending/Queued/Failed` status — **MVP**; **(5)** a **Threads capability row** in the best-path UI + a pinned **Threads** entry atop the drawer (thread-spool icon, shown only when relay-paired + opted-in) + retire `HermesInboxScreen`, re-point the notification deep-link + Settings "View messages"; **(6)** outbox/retry on reconnect; **(7)** relay `proactive.reply.ack` (honest Delivered) + `proactive.cancel`; **(8)** multi-thread `chat_id` (named/project Threads). **Verify gate before (1):** confirm the app's session-list/history path surfaces a `source=phone` session cleanly (upstream `session.list` returns all sources flat, so it should — but check whether the drawer currently filters it out). Honesty call: do NOT show "Delivered" until (7) lands (can't confirm it client-side before the ack).
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering** (an agent reply lands in the open Thread as an ASSISTANT bubble, suppressing the notification/inbox — `injectIntoThread`); **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`** (deleted; route + nav removed; notification tap + Settings "View messages" re-pointed to Chat; surface renamed "Hermes messages" → **"Threads"**); relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DEFERRED (reasons):** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **exact-Thread deep-link** from the notification (opens Chat today, not the specific thread — needs select-session-on-entry); **remove the now-orphaned `ProactiveInboxStore`** (viewer-less write-only log); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering**; **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`**; relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DONE (2026-08-14):** notification taps survive cold start and open the exact `chat_id`; agent-initiated outbound messages appear as connection-scoped provisional Threads backed by the bounded proactive store, then promote to the real `source=phone` session after the first reply. **DEFERRED:** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **User-created Threads (slice 8, Discord-style) — CODE-COMPLETE on `dev` (built + installed 2026-06-29; on-device behavior pending).** "+ New Thread" in the drawer's Threads view → name dialog → `ChatViewModel.startNewThread` mints a fresh `chat_id`; the first composer message opens it over `proactive.reply` (gateway auto-creates the `source=phone` session) → `switchToCreatedThread` polls + switches to the real session + applies the name. Existing-thread replies route by the `chat_id` parsed from the session id (`…:dm:<chat_id>`; opaque id → home fallback). **On-device verifies:** (1) a fresh-`chat_id` no-`reply_to` inbound creates a new `source=phone` session; (2) the phone session id carries the `…:dm:<chat_id>` form the client parses; (3) `renameSession` titles a phone session. **Remaining slice-8:** AGENT-initiated named Threads (the upstream `send_message` thread/chat_id param so the agent can open its own named Threads).
- **`chat_id` not exposed by `/api/sessions` (root cause of the 2026-06-29 on-device create-flow bugs — fixed client-side).** Confirmed on the host: a phone session's `id` is a timestamp (e.g. `20260629_204755_94f391d6`); the real `chat_id` lives in the `session_key` (`agent:main:phone:dm:<chat_id>`) and a `chat_id` column — but `/api/sessions` returns **neither `chat_id` nor `session_key`**, only `source` + the timestamp `id`. So the client could not map a session ↔ its `chat_id`, which broke create-thread switch/rename + reply routing + in-thread injection. **Client workaround shipped:** find a created thread by session-list **diff** (the new `source=phone` session), keep an in-memory `sessionId → chat_id` map (learned at creation + from incoming `phone.message`s) for reply routing, and inject by source (+ learned chat_id) rather than a parsed id. **Limitation:** for a thread the app didn't create *this* session (agent-created, another device, or after an app restart) `chat_id` is unknown until a message arrives while viewing it → its replies fall back to the home channel until then. **RESOLVED via the plugin (2026-06-29, per upstream-or-plugin policy):** the relay now exposes `GET /phone/threads` (`plugin/relay/session_store.py` reads the gateway store read-only → `[{session_id, chat_id, title}]`; `server.py` `handle_phone_threads`, bearer for the app / loopback for diag; 5 unit tests). The app (`RelayHttpClient.fetchPhoneThreads` → `ConnectionViewModel.phoneThreadChatIds` on every `auth.ok` → `ChatViewModel.seedThreadChatIds`, authoritative over the learned map) now routes replies correctly for **any** Thread — incl. ones it didn't create + after restart. Deployed + verified live. **Still-nice-to-have (lower priority): the upstream PR** to add `chat_id`/`session_key` to `/api/sessions` (the standard-path proper fix; the relay route then becomes redundant + the client prefers upstream when present).
- **Threads as named/project conversations (Discord-parity — folds into multi-thread #8).** A stable *named* `chat_id` per project = a persistent, agent-reachable project Thread (Discord named-thread parity for "persist a session for a project"). Enables: the agent **opening** a new named Thread for a background job/topic (a relay/gateway "open thread" affordance + a `send_message`-adjacent tool); cron/job updates landing in their own Thread; and replying to a Thread from any surface (desktop CLI / dashboard) since it is just a gateway session. Also evaluate per-Thread profile binding (a project Thread uses the "work" profile — ties to profile=contact).
@@ -942,7 +976,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
The gateway-platform model is the *correct + sufficient architecture* (the phone is a registered platform peer, so anything that routes to a platform — `send_message`, cron `deliver=`, channel directory, background jobs — can reach the phone). These are the concrete gaps between "architecturally a peer" and "I never open Discord":
- **Guaranteed background delivery (the biggest gap; no push today).** Delivery is **live-WSS-only** + a 24 h relay buffer; there is **no FCM/UnifiedPush** wake-up. If the app process is dead AND not holding a socket, a message waits for the next reconnect, and the relay buffer is ephemeral (lost on relay restart). Discord/Telegram feel instant because they wake the device via push even when the app is dead. Decide a **push transport**: **UnifiedPush/ntfy** (recommended — self-hostable, no Google dependency, upstream *already* ships an `ntfy` platform, on-brand for self-hosted) vs **FCM** (simplest UX but adds Play Services + a push relay; clashes with self-hosted ethos — at most the `googlePlay` flavor) vs **persistent foreground keep-alive service** holding the relay WSS (zero new infra, like `GatewayKeepAliveService`, but battery cost + Doze-fragile). Likely: UnifiedPush primary + foreground-keepalive fallback.
- **Cron / background-job delivery is BROKEN** (already tracked above): `deliver=phone` standalone path → `Unknown platform: phone`. This is load-bearing for "receiver of crons/background jobs" — fix is required, not optional, for the replacement goal.
- **Cron / background-job delivery needs live certification.** The standalone sender and channel-directory enumeration are implemented; certify `deliver=phone` against a deployed Relay and paired device, including reconnect delivery from the bounded offline queue.
- **Agent-initiated multi-thread creation remains.** The app already renders N
`source=phone` sessions, user-created Threads vary `chat_id`, and replies route
by `chat_id` + `reply_to`. The missing parity is letting the agent open/name a
@@ -951,7 +985,7 @@ The gateway-platform model is the *correct + sufficient architecture* (the phone
session store; the relay buffer is only the live/offline-delivery layer, not a
parallel history database.
- **Profile = contact mapping (new idea, fold in).** Multiple Hermes **profiles** (distinct agent personas/configs) could each be a distinct thread *source*/"contact" — DMing different agents. Maps cleanly onto the per-thread `chat_id` + source-attribution work; lets the app feel like a contact list of agents.
- **Per-thread notification controls + deep-link (Discord-parity affordances).** Per-thread notification channels, mute/DND/quiet-hours (Phase 3 partially), and a notification that **deep-links into the exact thread** (tap → land in that conversation) so dipping in/out while multitasking is frictionless.
- **Per-thread notification controls (Discord-parity affordances).** Exact-thread notification deep-linking is shipped. Remaining: per-thread notification channels and mute/DND/quiet-hours controls (Phase 3 partially).
- **Agent-initiated rich content.** Agent → phone thread with **images/cards** (relay media infra + `InboundAttachmentCard`/`HermesCardBubble` already exist on the chat side — reuse). Inbound (phone → agent) reply media stays deferred (text-first), but outbound rich content is low-cost parity.
- **In-thread "agent is working" indicator.** A typing/working state in the thread while the agent thinks/runs tools (Discord typing-dots parity) — the chat surface already has thinking indicators to reuse.
@@ -1217,6 +1251,25 @@ When the answer becomes clearer, this section becomes either an ADR in `docs/dec
## Smaller deferred items
- **Certify the preferred CUA Driver backend (ADR 56).** The canonical-runtime
probe, bounded adapter, server-owned control-session envelope, per-session
grant state, local engine/status controls, telemetry-off process environment,
and Hermes snapshot-token primitives now exist. Before graduating the engine,
finish end-to-end enforcement of app/display/folder scopes and sensitive
pixel/accessibility denial or redaction, harden the grant-bridge ACL and nonce
lifecycle, and complete live Windows certification proving the physical cursor and
foreground app stay unchanged, stale or cross-window tokens fail, two remote
control sessions receive isolated animated cursors, and foreground escalation
never happens implicitly. Exercise revoke on grant expiry, disconnect,
re-pair, policy downgrade, emergency stop, Windows-session change, and daemon
shutdown. The explicit local CUA install/update surface now verifies upstream
manifest identity and installer SHA-256; add Windows publisher verification
when upstream signs the installer. Keep raw CUA tools, configuration,
recording, replay, and JavaScript outside the remote agent surface.
Remove the temporary Windows readiness/health split once
[trycua/cua#3103](https://github.com/trycua/cua/issues/3103) ships in the
supported CUA range; restore a mandatory health gate only if the upstream
probe is bounded and cannot leave UI Automation falsely busy.
- **MediaProjection consent flow** — wired in MainActivity (2026-04-12), needs end-to-end test on a real device
- **WorkManager upgrade for auto-disable timer** — currently a coroutine `Job + delay()` in `AutoDisableWorker.kt`; documented at top of file. Upgrade when androidx.work joins the classpath
- **Wave 3 voice-bridge multi-turn confirmation** — currently a 5s TTS countdown with cancel; conversational confirmation is the follow-up
+4 -2
View File
@@ -319,11 +319,13 @@ dependencies {
// Coil 3 — async image loading for generated images in chat
implementation(libs.coil.compose)
implementation(libs.coil.gif)
implementation(libs.coil.network.okhttp)
implementation(libs.exifinterface)
// QR Code scanning (ML Kit + CameraX)
implementation(libs.mlkit.barcode)
implementation(libs.zxing.core)
implementation(libs.camera.core)
implementation(libs.camera.camera2)
implementation(libs.camera.lifecycle)
@@ -370,8 +372,8 @@ dependencies {
// [POC] Roborazzi host-side screenshot rendering (src/test, Robolectric).
// Renders real composables on the JVM at an exact canvas — no device, no
// status bar, no clipping. See StoreScreenshotTest.
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.70.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.70.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.71.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.71.0")
testImplementation(libs.compose.ui.test.junit4)
testImplementation(libs.compose.ui.test.manifest)
testImplementation("androidx.test.ext:junit:1.3.0")
@@ -1 +1 @@
Quote, edit, search, and attach files without losing chat context. Switch profiles from Chat while each agent keeps its own session. Thinking and routine tool activity are cleaner, message actions can speak or stop completed replies, Appearance adds live theme and companion previews, and floating pets avoid controls while scrolling.
Change shared avatars from your phone without oversized or native image formats disappearing. Select upstream animated pets that follow the Hermes profile across supported clients while keeping phone-only icons separate. Profile creation now exposes clear authentication choices, and attachment, recovery, rewind, model-consent, ownership, and hosted sign-in paths fail more safely.
+77
View File
@@ -1,5 +1,82 @@
{
"versions": [
{
"version": "1.9.1",
"title": "Profile identity that sticks",
"date": "2026-08-16",
"sections": [
{
"header": "Identity follows the right scope",
"bullets": [
"Change shared avatars from Android with automatic orientation, resizing, and safe conversion to the Hermes profile-asset contract.",
"Select upstream animated pets that follow the Hermes profile while phone-only animated icons, local avatar overrides, and Sphere skins stay local."
]
},
{
"header": "Profile setup stays explicit",
"bullets": [
"Create profiles with clear shared, copied, or isolated authentication choices and see partial setup outcomes.",
"Named-profile sessions and profile drafts fail closed when Hermes cannot confirm their owner."
]
},
{
"header": "Safer Gateway operations",
"bullets": [
"Attachments, rewinds, recovery, model-consent changes, and hosted sign-in now follow stricter upstream contracts.",
"Finite schedules, bounded reset evidence, and host resource warnings make consequential actions easier to review."
]
}
]
},
{
"version": "1.9.0",
"title": "Better sessions, reactions, and voice",
"date": "2026-08-14",
"sections": [
{
"header": "Sessions keep their identity",
"bullets": [
"Browse one profile or all profiles, customize sorting and filters, and optionally group sessions by project, recency, status, or profile.",
"Cross-profile sessions hydrate, resume, and send with their owning agent without changing the global profile selection; New Chat in All Profiles uses the default profile."
]
},
{
"header": "Conversation controls stay attached",
"bullets": [
"Reactions pin to durable rows on both user and assistant messages.",
"Vanilla Hermes voice stays on the authenticated Gateway instead of requiring the optional API fallback."
]
},
{
"header": "Context without clutter",
"bullets": [
"Session rows show profile, project, branch, and pull-request context when Hermes supplies it, while the default view remains ungrouped.",
"The session drawer restores secondary actions in All Profiles and closes when you tap outside it."
]
}
]
},
{
"version": "1.8.1",
"title": "Complete, reliable transcripts",
"date": "2026-08-09",
"sections": [
{
"header": "Keep long sessions complete",
"bullets": [
"Android pages explicitly through complete API-server and profile-scoped Dashboard history instead of silently stopping at Hermes' latest-500 default.",
"Sharing, retry, edit, and recovery retain stable transcript anchors while bounded safety limits keep unusually large reads controlled."
]
},
{
"header": "Follow Gateway truth",
"bullets": [
"Authoritative submit rejections preserve the server's message without an unintended SSE fallback.",
"Gateway event envelopes and edit-and-regenerate truncation confirmation now follow current upstream contracts."
]
}
]
},
{
"version": "1.8.0",
"title": "Conversations with more context",
+6 -6
View File
@@ -1,7 +1,7 @@
v1.8.0 - Conversations with more context
v1.9.1 - Profile identity that sticks
* Quote, edit, search, and attach files without losing the active chat context.
* Switch profiles quickly from Chat while each agent keeps its own session.
* Read quieter thinking and grouped tool activity, with important actions kept distinct.
* Speak or stop completed replies directly from message actions.
* Customize themes, Sphere skins, and pets from a live Appearance preview.
* Change shared avatars from your phone without oversized or native image formats disappearing.
* Select upstream animated pets that follow the Hermes profile across supported clients.
* Keep phone-only animated icons and local avatar overrides clearly separate.
* Create profiles with explicit authentication choices and safer ownership checks.
* Get stricter attachment, recovery, rewind, model-consent, and hosted sign-in behavior.
@@ -7,6 +7,8 @@ import android.os.Build
import coil3.ImageLoader
import coil3.PlatformContext
import coil3.SingletonImageLoader
import coil3.gif.AnimatedImageDecoder
import coil3.gif.GifDecoder
import coil3.network.okhttp.OkHttpNetworkFetcherFactory
import coil3.request.crossfade
import com.hermesandroid.relay.bridge.UnattendedAccessManager
@@ -38,7 +40,14 @@ class HermesRelayApp : Application(), SingletonImageLoader.Factory {
*/
override fun newImageLoader(context: PlatformContext): ImageLoader =
ImageLoader.Builder(context)
.components { add(OkHttpNetworkFetcherFactory()) }
.components {
add(OkHttpNetworkFetcherFactory())
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.P) {
add(AnimatedImageDecoder.Factory())
} else {
add(GifDecoder.Factory())
}
}
.crossfade(true)
.build()
@@ -1,11 +1,17 @@
package com.hermesandroid.relay.auth
import android.content.Context
import android.provider.Settings
import android.util.Log
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.BrokerEndpoint
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.replaceHermesReachCredential
import com.hermesandroid.relay.data.sameBrokerAuthority
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.data.isSafeProfileUiMeta
import com.hermesandroid.relay.network.relay.ChannelMultiplexer
import com.hermesandroid.relay.network.relay.models.Envelope
import kotlinx.coroutines.CoroutineScope
@@ -14,6 +20,7 @@ import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
@@ -280,6 +287,7 @@ class AuthManager(
?: return@mapNotNull null
val model = obj["model"]?.jsonPrimitive?.contentOrNull
?: "unknown"
val provider = obj["provider"]?.jsonPrimitive?.contentOrNull.orEmpty()
val description = obj["description"]?.jsonPrimitive?.contentOrNull
?: ""
val systemMessage = obj["system_message"]?.jsonPrimitive?.contentOrNull
@@ -299,9 +307,15 @@ class AuthManager(
?.jsonPrimitive?.intOrNull
val apiServerKeyPresent = obj["api_server_key_present"]
?.jsonPrimitive?.booleanOrNull ?: false
val isDefault = obj["is_default"]?.jsonPrimitive?.booleanOrNull ?: false
val hasAvatar = obj["has_avatar"]?.jsonPrimitive?.booleanOrNull ?: false
val uiMeta = (obj["ui_meta"] as? JsonObject)
?.takeIf(::isSafeProfileUiMeta)
?: JsonObject(emptyMap())
Profile(
name = name,
model = model,
provider = provider,
description = description,
systemMessage = systemMessage,
gatewayRunning = gatewayRunning,
@@ -312,6 +326,9 @@ class AuthManager(
apiServerHost = apiServerHost,
apiServerPort = apiServerPort,
apiServerKeyPresent = apiServerKeyPresent,
isDefault = isDefault,
hasAvatar = hasAvatar,
uiMeta = uiMeta,
)
}
}
@@ -557,6 +574,12 @@ class AuthManager(
* Either way, we leave the previously-persisted list untouched.
*/
private var pendingEndpoints: List<EndpointCandidate>? = null
private var activeEndpointProvider: () -> EndpointCandidate? = { null }
/** Bind auth.ok route credentials to the transport that actually carried them. */
fun setActiveEndpointProvider(provider: () -> EndpointCandidate?) {
activeEndpointProvider = provider
}
/**
* Server-advertised agent profiles from the `auth.ok` payload's
@@ -631,7 +654,7 @@ class AuthManager(
val now = System.currentTimeMillis() / 1000L
val defaults = PairedSession(
token = token,
deviceName = android.os.Build.MODEL,
deviceName = relayDeviceName(),
expiresAt = null,
grants = emptyMap(),
transportHint = null,
@@ -651,7 +674,7 @@ class AuthManager(
val transportHint = obj["transport_hint"]?.jsonPrimitive?.contentOrNull
val firstSeen = obj["first_seen"]?.jsonPrimitive?.longOrNull ?: now
val deviceName = obj["device_name"]?.jsonPrimitive?.contentOrNull
?: android.os.Build.MODEL
?: relayDeviceName()
PairedSession(
token = token,
@@ -750,6 +773,26 @@ class AuthManager(
})
}
private fun JsonObjectBuilder.putRelayDeviceIdentity() {
val model = android.os.Build.MODEL.orEmpty().ifBlank { "Android device" }
val deviceName = relayDeviceName()
put("device_name", deviceName)
put("device_hostname", deviceName)
put("device_model", model)
put("device_platform", "Android ${android.os.Build.VERSION.RELEASE}")
put("client_surface", "android")
put("device_form_factor", "phone")
}
private fun relayDeviceName(): String {
val configured = runCatching {
Settings.Global.getString(context.contentResolver, "device_name")
}.getOrNull()?.trim().orEmpty()
return configured.ifBlank {
android.os.Build.MODEL.orEmpty().ifBlank { "Android device" }
}
}
/**
* Send auth envelope when connection is established.
*
@@ -784,7 +827,7 @@ class AuthManager(
put("refresh_token", refreshToken)
}
put("device_id", deviceId)
put("device_name", android.os.Build.MODEL)
putRelayDeviceIdentity()
putRelayClientSupports()
}
}
@@ -800,7 +843,7 @@ class AuthManager(
buildJsonObject {
put("pairing_code", codeToSend)
put("device_id", deviceId)
put("device_name", android.os.Build.MODEL)
putRelayDeviceIdentity()
putRelayClientSupports()
pendingTtlSeconds?.let { put("ttl_seconds", it) }
pendingGrants?.let { grants ->
@@ -1021,6 +1064,7 @@ class AuthManager(
}
if (token != null) {
applyBrokerRouteCredential(payload)
val s = store()
s.putString(KEY_SESSION_TOKEN, token)
val refreshToken = payload["refresh_token"]
@@ -1066,7 +1110,7 @@ class AuthManager(
val paired = PairedSession(
token = token,
deviceName = android.os.Build.MODEL,
deviceName = relayDeviceName(),
expiresAt = expiresAt,
grants = grantsMap,
transportHint = transportHint,
@@ -1129,6 +1173,40 @@ class AuthManager(
}
}
private suspend fun applyBrokerRouteCredential(payload: JsonObject) {
val active = activeEndpointProvider()?.takeIf { it.hasHermesReach() } ?: return
val current = active.broker ?: return
// Fresh pairing is scoped by pendingEndpoints; reconnect rotation is
// accepted only by this connection-scoped AuthManager's live session.
if (pendingEndpoints == null && _authState.value !is AuthState.Paired) return
val credential = payload["route_credential"] as? JsonObject ?: return
if (credential["kind"]?.jsonPrimitive?.contentOrNull != "broker_route") return
val brokerUrl = credential["broker_url"]?.jsonPrimitive?.contentOrNull ?: return
val hostId = credential["host_id"]?.jsonPrimitive?.contentOrNull ?: return
if (!sameBrokerAuthority(brokerUrl, current.url) || hostId != current.hostId) {
Log.w(TAG, "Ignoring broker route credential that does not match the active paired route")
return
}
val replacement = BrokerEndpoint(
url = current.url,
protocolVersion = current.protocolVersion,
hostId = current.hostId,
credentialKind = "route",
token = credential["token"]?.jsonPrimitive?.contentOrNull ?: return,
expiresAt = credential["expires_at"]?.jsonPrimitive?.longOrNull,
)
val validated = active.copy(broker = replacement).takeIf { it.hasHermesReach() } ?: return
val deviceId = getDeviceId()
val source = pendingEndpoints
?: PairingPreferences.getDeviceEndpoints(context, deviceId).first()
val updated = replaceHermesReachCredential(source, current, validated)
if (updated == source) return
if (pendingEndpoints != null) pendingEndpoints = updated
else PairingPreferences.setDeviceEndpoints(context, deviceId, updated)
Log.i(TAG, "Accepted a durable Hermes Reach route credential for the active paired route")
}
private fun handleAuthFail(envelope: Envelope) {
try {
val rawReason = envelope.payload["reason"]?.jsonPrimitive?.contentOrNull
@@ -90,12 +90,28 @@ class CertPinStore(private val context: Context) {
if (pins.isEmpty()) return CertificatePinner.DEFAULT
val builder = CertificatePinner.Builder()
for ((hostPort, pin) in pins) {
val host = hostPort.substringBefore(':')
val host = hostPort.substringBeforeLast(':')
builder.add(host, pin)
}
return builder.build()
}
/**
* Build a pinner for one exact URL authority. CertificatePinner keys by
* hostname only, so adding every stored host:port entry to one client
* accidentally lets a pin learned on one port govern another port.
*/
fun buildPinnerSnapshotFor(url: String): CertificatePinner {
val hostPort = hostPortFromUrl(url) ?: return CertificatePinner.DEFAULT
val pin = getPinsBlocking()[hostPort] ?: return CertificatePinner.DEFAULT
val host = runCatching { URI(url.trim()).host }.getOrNull()
?.takeIf { it.isNotBlank() }
?: return CertificatePinner.DEFAULT
return CertificatePinner.Builder()
.add(host, pin)
.build()
}
/**
* Record a pin for a host. Called from the WebSocket listener's `onOpen`
* when we have a successful connection and can read the peer certs from
@@ -74,6 +74,14 @@ data class PairedDeviceInfo(
val deviceName: String = "",
@SerialName("device_id")
val deviceId: String = "",
@SerialName("device_model")
val deviceModel: String = "",
@SerialName("device_platform")
val devicePlatform: String = "",
@SerialName("client_surface")
val clientSurface: String = "",
@SerialName("device_form_factor")
val deviceFormFactor: String = "",
@SerialName("created_at")
val createdAt: Double? = null,
@SerialName("last_seen")
@@ -141,6 +141,18 @@ data class ChatMessage(
* through `copy`, while [id] remains the authoritative lookup/wire id.
*/
val uiKey: String = id,
/**
* Durable Gateway transcript row identity for rewind/edit-regenerate.
* This is server-owned and can change after a truncating rewrite; it is
* never used as a Compose key or synthesized client-side.
*/
val rowId: Long? = null,
/**
* Durable iOS-style tapbacks attached to this server message. Hermes keeps
* one reaction per author in the message's display metadata; the UI also
* updates this list optimistically while a reaction write is in flight.
*/
val reactions: List<MessageReaction> = emptyList(),
/**
* Mixture-of-Agents advisor responses surfaced during the live turn.
* Unavailable advisors retain only neutral state, never their raw failure
@@ -150,6 +162,29 @@ data class ChatMessage(
val moaReferences: List<MoaReference> = emptyList(),
)
data class MessageReaction(
val emoji: String,
val author: String,
/** Epoch seconds, matching the Gateway/Desktop contract. */
val at: Double,
)
/** Apply Hermes' one-reaction-per-author, re-tap-to-retract semantics. */
internal fun applyMessageReaction(
reactions: List<MessageReaction>,
emoji: String?,
author: String = "user",
at: Double = System.currentTimeMillis() / 1000.0,
): List<MessageReaction> {
val previous = reactions.firstOrNull { it.author == author }
val withoutAuthor = reactions.filterNot { it.author == author }
return if (emoji.isNullOrBlank() || previous?.emoji == emoji) {
withoutAuthor
} else {
withoutAuthor + MessageReaction(emoji = emoji, author = author, at = at)
}
}
data class MoaReference(
val index: Int,
val count: Int?,
@@ -366,6 +401,8 @@ data class ToolCall(
* header can render without a separate lane registry.
*/
val taskLabel: String? = null,
/** Live upstream child id used by subagent.steer while this lane runs. */
val subagentId: String? = null,
/** Deterministic non-low output risk reported by upstream for this call. */
val outputRisk: String? = null,
/** Human-readable deterministic findings; rendered as untrusted metadata. */
@@ -404,6 +441,11 @@ data class ChatSession(
val title: String?,
val model: String?,
val messageCount: Int = 0,
val inputTokens: Int = 0,
val outputTokens: Int = 0,
val actualCostUsd: Double? = null,
val estimatedCostUsd: Double? = null,
val isActive: Boolean = false,
val updatedAt: Long = 0L,
val startedAt: Long = 0L,
val lastActivityAt: Long = 0L,
@@ -419,7 +461,21 @@ data class ChatSession(
/** Durable upstream session metadata, scoped by the owning connection/profile DB. */
val pinned: Boolean = false,
val archived: Boolean = false,
/** Optional newer-upstream workspace context; absent on legacy/API-only hosts. */
val workingDirectory: String? = null,
val gitBranch: String? = null,
val gitRepoRoot: String? = null,
val pullRequestNumber: Int? = null,
val pullRequestUrl: String? = null,
val pullRequestState: String? = null,
val pullRequestDraft: Boolean = false,
) {
val totalTokens: Int
get() = inputTokens + outputTokens
val costUsd: Double
get() = actualCostUsd ?: estimatedCostUsd ?: 0.0
val activityTimestamp: Long
get() = firstPositive(lastActivityAt, updatedAt, startedAt)
@@ -129,6 +129,7 @@ data class ChatTurnAskCheckpoint(
val requestId: String? = null,
val text: String,
val choices: List<String>? = null,
val multiSelect: Boolean = false,
val smartDenied: Boolean = false,
val envVar: String? = null,
val timeoutSeconds: Int,
@@ -14,6 +14,9 @@ data class DashboardConnectionStatus(
val gatewayTicketAvailable: Boolean? = null,
val message: String? = null,
val gatewayMode: String? = null,
/** Profiles positively advertised by the live multiplex gateway. */
val servedProfiles: List<String> = emptyList(),
/** Installed profiles reported by the dashboard; never routing authority. */
val profiles: List<String> = emptyList(),
)
@@ -63,12 +63,8 @@ fun EndpointCandidate?.isEncryptedOverlayRoute(isTailscaleDetected: Boolean): Bo
val hint = security.orEmpty().lowercase()
return r == "tailscale" ||
(isTailscaleDetected && hint.contains("tailscale")) ||
r == "plugin_proxy" ||
r == "plugin-proxy" ||
hasSecureProxy() ||
hint.contains("wireguard") ||
hint.contains("https") ||
hint.contains("tls")
(!hasSecureProxy() && (hint.contains("https") || hint.contains("tls")))
}
/** Human label for the overlay mechanism encrypting a route. */
@@ -78,7 +74,6 @@ fun EndpointCandidate?.overlayMechanism(isTailscaleDetected: Boolean): String {
val hint = security.orEmpty().lowercase()
return when {
r == "tailscale" || (isTailscaleDetected && hint.contains("tailscale")) -> "Tailscale"
r == "plugin_proxy" || r == "plugin-proxy" || hasSecureProxy() -> "Proxy"
hint.contains("wireguard") -> "WireGuard"
hint.contains("https") || hint.contains("tls") -> "TLS"
else -> "Encrypted"
@@ -92,7 +87,10 @@ fun classifySurfaceSecurity(
activeEndpoint: EndpointCandidate?,
isTailscaleDetected: Boolean,
): SurfaceSecurity {
val secureLinkProtected = activeEndpoint.secureLinkProtects(label, url)
val (kind, mechanism) = when {
secureLinkProtected -> SurfaceSecurityKind.Tls to
if (activeEndpoint?.hasHermesReach() == true) "Hermes Reach" else "Hermes Secure Link"
isTlsUrl(url) -> SurfaceSecurityKind.Tls to "TLS"
activeEndpoint.isEncryptedOverlayRoute(isTailscaleDetected) ->
SurfaceSecurityKind.Overlay to activeEndpoint.overlayMechanism(isTailscaleDetected)
@@ -101,6 +99,33 @@ fun classifySurfaceSecurity(
return SurfaceSecurity(label = label, kind = kind, mechanism = mechanism, url = url)
}
private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): Boolean {
val candidate = this ?: return false
val routes = candidate.proxy?.takeIf { candidate.hasSecureProxy() }
?.let { proxy ->
val base = proxy.url.trim().trimEnd('/')
Triple(
"$base/dashboard",
"$base/api",
"wss://${base.substringAfter("://")}/relay/ws",
)
} ?: return false
val normalized = url.trim().trimEnd('/')
val service = when (label) {
"Chat & Manage" -> "dashboard"
"API / sessions" -> "api"
"Relay tools" -> "relay"
else -> return false
}
if (service !in candidate.secureLinkServices()) return false
val expected = when (service) {
"dashboard" -> routes.first
"api" -> routes.second
else -> routes.third
}
return normalized.equals(expected, ignoreCase = true)
}
/**
* Roll up the per-surface verdicts into one connection-level [ConnectionSecurity].
* Pure + side-effect free so it is unit-testable without Android.
@@ -45,8 +45,13 @@ data class EndpointCandidate(
val relay: RelayEndpoint? = null,
val dashboard: DashboardEndpoint? = null,
val proxy: ProxyEndpoint? = null,
/** Optional outbound rendezvous carrying the pinned [proxy] byte stream. */
val broker: BrokerEndpoint? = null,
val security: String? = null,
val recommended: Boolean = false,
val experimental: Boolean = false,
@SerialName("display_name")
val displayName: String? = null,
)
/**
@@ -110,6 +115,27 @@ data class ProxyEndpoint(
val transportHint: String? = null,
@SerialName("pin_sha256")
val pinSha256: String? = null,
/** Independently authenticated services carried by this pinned origin. */
val surfaces: List<String> = listOf("relay"),
)
/**
* Hermes Reach rendezvous metadata from an operator-reviewed pairing payload.
* The token authenticates only this broker route; Hermes service credentials
* remain inside the QR-pinned Secure Link TLS connection.
*/
@Serializable
data class BrokerEndpoint(
val url: String,
@SerialName("protocol_version")
val protocolVersion: Int = 1,
@SerialName("host_id")
val hostId: String,
@SerialName("credential_kind")
val credentialKind: String,
val token: String,
@SerialName("expires_at")
val expiresAt: Long? = null,
)
/**
@@ -123,7 +149,7 @@ data class ProxyEndpoint(
*/
fun EndpointCandidate.isKnownRole(): Boolean {
return when (role.lowercase()) {
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "https" -> true
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "outbound_broker", "https" -> true
else -> false
}
}
@@ -146,7 +172,8 @@ fun EndpointCandidate.displayLabel(): String {
"Public"
}
"https" -> "HTTPS"
"plugin_proxy", "plugin-proxy" -> "Plugin proxy"
"plugin_proxy", "plugin-proxy" -> "Hermes Secure Link"
"outbound_broker", "broker", "relay_broker" -> "Hermes Reach · Experimental"
else -> "Custom VPN ($role)"
}
}
@@ -177,7 +204,69 @@ fun EndpointCandidate.routeAuthority(): String? {
}
fun EndpointCandidate.hasSecureProxy(): Boolean =
proxy?.url?.startsWith("https://", ignoreCase = true) == true ||
proxy?.url?.startsWith("wss://", ignoreCase = true) == true ||
role.equals("plugin_proxy", ignoreCase = true) ||
role.equals("plugin-proxy", ignoreCase = true)
proxy?.isValidPinnedProxy() == true
/** Product-facing service inventory; wire identifiers remain unchanged. */
fun EndpointCandidate.secureLinkServices(): List<String> =
if (!hasSecureProxy()) emptyList() else proxy.orEmptySurfaces()
fun EndpointCandidate.secureLinkCoversAllServices(): Boolean =
secureLinkServices().containsAll(listOf("relay", "api", "dashboard"))
fun EndpointCandidate.presentationRouteUrl(): String? =
broker?.url?.takeIf { hasHermesReach() } ?: proxy?.url?.takeIf { hasSecureProxy() } ?: primaryRouteUrl()
fun EndpointCandidate.hasHermesReach(): Boolean =
role.lowercase() in setOf("outbound_broker", "broker", "relay_broker") &&
broker?.isValidHermesReach() == true && hasSecureProxy()
fun BrokerEndpoint.isValidHermesReach(): Boolean {
if (protocolVersion != 1 || !hostId.isCanonicalBase64Url(16) || !token.isCanonicalBase64Url(32)) return false
if (credentialKind !in setOf("bootstrap", "route")) return false
if (credentialKind == "bootstrap" && expiresAt?.let { it <= System.currentTimeMillis() / 1000L } == true) return false
val uri = runCatching { URI(url.trim()) }.getOrNull() ?: return false
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
return uri.rawPath.orEmpty().let { it.isEmpty() || it == "/" || it == "/v1/connect" }
}
private fun String.isCanonicalBase64Url(byteCount: Int): Boolean {
if (isBlank() || '=' in this) return false
val decoded = runCatching { java.util.Base64.getUrlDecoder().decode(this) }.getOrNull() ?: return false
return decoded.size == byteCount &&
java.util.Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == this
}
/** Exact host locator + broker authority replacement; never crosses devices. */
internal fun replaceHermesReachCredential(
source: List<EndpointCandidate>,
expected: BrokerEndpoint,
replacement: EndpointCandidate,
): List<EndpointCandidate> = source.map { candidate ->
if (candidate.broker?.hostId == expected.hostId &&
sameBrokerAuthority(candidate.broker.url, expected.url)
) replacement else candidate
}
internal fun sameBrokerAuthority(left: String, right: String): Boolean = runCatching {
val a = URI(left.trim())
val b = URI(right.trim())
fun port(uri: URI) = if (uri.port > 0) uri.port else 443
a.scheme.equals("wss", true) && b.scheme.equals("wss", true) &&
a.host.equals(b.host, true) && port(a) == port(b) &&
a.rawPath.orEmpty().trimEnd('/') == b.rawPath.orEmpty().trimEnd('/')
}.getOrDefault(false)
private fun ProxyEndpoint?.orEmptySurfaces(): List<String> = this?.surfaces.orEmpty()
.map { it.trim().lowercase() }
.filter { it in setOf("relay", "api", "dashboard") }
.distinct()
fun ProxyEndpoint.isValidPinnedProxy(): Boolean {
val uri = runCatching { URI(url.trim().trimEnd('/')) }.getOrNull() ?: return false
if (!uri.scheme.equals("https", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" }) return false
val pin = pinSha256?.trim()?.removePrefix("sha256/") ?: return false
return runCatching { java.util.Base64.getDecoder().decode(pin).size == 32 }.getOrDefault(false)
}
@@ -2,6 +2,8 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
/**
* A rich content card emitted inline in an assistant message via the
@@ -117,6 +119,8 @@ data class HermesCardInput(
val kind: String,
/** Quick-answer chips (clarify). Empty = no chip row. */
val choices: List<String> = emptyList(),
/** Choices toggle independently and require an explicit submit. */
val multiSelect: Boolean = false,
/** Render the inline free-text mini field under the chips. */
val allowFreeText: Boolean = false,
/** Password-style field: masked glyphs + reveal toggle (secret/sudo). */
@@ -124,7 +128,7 @@ data class HermesCardInput(
/** Submit is a 650ms hold-to-confirm press-fill instead of a tap (sudo). */
val holdToConfirm: Boolean = false,
/**
* Wall-clock expiry for timed asks (sudo 120s, clarify/secret 300s).
* Wall-clock expiry for asks with an advertised deadline.
* The renderer shows a countdown footer (Amber under 30s) and
* self-collapses to "Expired — not granted" past it. Null = no timeout
* (approval is session-scoped).
@@ -155,6 +159,10 @@ data class HermesCardInput(
}
}
/** Exact JSON-array wire value expected by upstream multi-select clarify. */
internal fun encodeClarifyMultiSelectAnswer(values: List<String>): String =
Json.encodeToString(values.map(String::trim).filter(String::isNotEmpty).distinct())
/**
* A label/value row inside a card. [value] is rendered as markdown so the
* agent can embed emphasis, inline code, or links.
@@ -34,6 +34,10 @@ data class ProactiveInboxEntry(
* field).
*/
val chatId: String? = null,
/** Owning saved connection. Null only for entries written by older builds. */
val connectionId: String? = null,
/** Relay proved this row came from its bounded offline queue. */
val arrivedWhileAway: Boolean = false,
)
private val Context.proactiveInboxStore: DataStore<Preferences> by
@@ -49,10 +53,10 @@ private const val MAX_ENTRIES = 100
* newest-first, deduped by id (so a re-delivered message doesn't double up), and
* capped at [MAX_ENTRIES]. Survives app restart.
*
* Demoted (2026-06-29): the agent conversation now lives as a Thread in Chat (the
* gateway session is the durable history), so the in-app inbox view is retired.
* This store is only fed for messages NOT shown in an open Thread; it currently
* has no viewer and is fully retireable — see TODO.
* Demoted (2026-06-29): once a phone gateway session exists, it is the durable
* history. Outbound agent messages arrive before that session exists, so this
* bounded store also backs the provisional Thread until the user's first reply
* promotes it to a real `source=phone` session.
*/
class ProactiveInboxRepository(private val context: Context) {
@@ -0,0 +1,125 @@
package com.hermesandroid.relay.data
import android.content.Context
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.ImageDecoder
import android.net.Uri
import android.os.Build
import java.io.ByteArrayOutputStream
import kotlin.math.roundToInt
internal fun profileAvatarMime(bytes: ByteArray): String? = when {
bytes.size >= 8 && bytes.copyOfRange(0, 8).contentEquals(
byteArrayOf(0x89.toByte(), 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a),
) -> "image/png"
bytes.size >= 3 && bytes[0] == 0xff.toByte() && bytes[1] == 0xd8.toByte() &&
bytes[2] == 0xff.toByte() -> "image/jpeg"
bytes.size >= 12 && bytes.copyOfRange(0, 4).contentEquals("RIFF".toByteArray()) &&
bytes.copyOfRange(8, 12).contentEquals("WEBP".toByteArray()) -> "image/webp"
else -> null
}
/**
* Convert any image Android can decode into the small static format accepted by
* upstream `profiles.set_asset`. ImageDecoder applies camera EXIF orientation
* and downsamples before allocating the bitmap on current Android releases.
*/
internal fun prepareProfileAvatar(
context: Context,
uri: Uri,
maxBytes: Int,
): ByteArray? {
val original = runCatching {
context.contentResolver.openInputStream(uri)?.use { input ->
val output = ByteArrayOutputStream(minOf(maxBytes + 1, 64 * 1024))
val buffer = ByteArray(16 * 1024)
while (output.size() <= maxBytes) {
val read = input.read(buffer)
if (read < 0) break
output.write(buffer, 0, read)
}
output.toByteArray()
}
}.getOrNull()
if (original != null && original.size <= maxBytes && profileAvatarMime(original) != null) {
return original
}
val bitmap = decodeProfileAvatar(context, uri) ?: return null
return try {
encodeProfileAvatar(bitmap, maxBytes)
} finally {
bitmap.recycle()
}
}
private fun decodeProfileAvatar(context: Context, uri: Uri): Bitmap? = runCatching {
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.P) {
ImageDecoder.decodeBitmap(ImageDecoder.createSource(context.contentResolver, uri)) { decoder, info, _ ->
decoder.allocator = ImageDecoder.ALLOCATOR_SOFTWARE
val width = info.size.width
val height = info.size.height
val longest = maxOf(width, height)
if (longest > PROFILE_AVATAR_MAX_DIMENSION) {
val scale = PROFILE_AVATAR_MAX_DIMENSION.toFloat() / longest
decoder.setTargetSize(
(width * scale).roundToInt().coerceAtLeast(1),
(height * scale).roundToInt().coerceAtLeast(1),
)
}
}
} else {
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
context.contentResolver.openInputStream(uri)?.use { BitmapFactory.decodeStream(it, null, bounds) }
var sample = 1
while (maxOf(bounds.outWidth, bounds.outHeight) / sample > PROFILE_AVATAR_MAX_DIMENSION) sample *= 2
context.contentResolver.openInputStream(uri)?.use {
BitmapFactory.decodeStream(it, null, BitmapFactory.Options().apply { inSampleSize = sample })
}
}
}.getOrNull()
internal fun encodeProfileAvatar(bitmap: Bitmap, maxBytes: Int): ByteArray? {
var working = bitmap.scaledToFit(PROFILE_AVATAR_MAX_DIMENSION)
var ownsWorking = working !== bitmap
try {
while (true) {
val format = if (working.hasAlpha()) Bitmap.CompressFormat.PNG else Bitmap.CompressFormat.JPEG
val qualities = if (format == Bitmap.CompressFormat.PNG) intArrayOf(100) else intArrayOf(92, 82, 72, 62)
for (quality in qualities) {
val encoded = ByteArrayOutputStream().use { output ->
if (!working.compress(format, quality, output)) null else output.toByteArray()
}
if (encoded != null && encoded.size <= maxBytes) return encoded
}
if (maxOf(working.width, working.height) <= PROFILE_AVATAR_MIN_DIMENSION) return null
val next = Bitmap.createScaledBitmap(
working,
(working.width * 0.75f).roundToInt().coerceAtLeast(1),
(working.height * 0.75f).roundToInt().coerceAtLeast(1),
true,
)
if (ownsWorking) working.recycle()
working = next
ownsWorking = true
}
} finally {
if (ownsWorking) working.recycle()
}
}
private fun Bitmap.scaledToFit(maxDimension: Int): Bitmap {
val longest = maxOf(width, height)
if (longest <= maxDimension) return this
val scale = maxDimension.toFloat() / longest
return Bitmap.createScaledBitmap(
this,
(width * scale).roundToInt().coerceAtLeast(1),
(height * scale).roundToInt().coerceAtLeast(1),
true,
)
}
private const val PROFILE_AVATAR_MAX_DIMENSION = 1024
private const val PROFILE_AVATAR_MIN_DIMENSION = 128
@@ -2,6 +2,35 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.contentOrNull
internal fun isSafeProfileUiMeta(meta: JsonObject): Boolean {
if (meta.toString().toByteArray(Charsets.UTF_8).size > 65_536) return false
fun containsEmbeddedAsset(value: String): Boolean {
val compact = value.trim()
return compact.startsWith("data:image/", ignoreCase = true) ||
compact.startsWith("iVBORw0KGgo") || // PNG
compact.startsWith("/9j/") || // JPEG
compact.startsWith("UklGR") || // RIFF/WebP
compact.startsWith("R0lGOD") || // GIF
compact.startsWith("UEsDB") // ZIP/pet archive
}
fun safe(element: JsonElement): Boolean = when (element) {
is JsonObject -> element.size <= 128 && element.all { (key, value) ->
key.length <= 128 && safe(value)
}
is JsonArray -> element.size <= 128 && element.all(::safe)
is JsonPrimitive -> {
val value = element.contentOrNull
value == null || (value.length <= 4_096 && !containsEmbeddedAsset(value))
}
}
return safe(meta)
}
/**
* An agent profile advertised by a Hermes server in its `auth.ok` payload.
@@ -56,6 +85,7 @@ import kotlinx.serialization.Serializable
data class Profile(
val name: String,
val model: String,
val provider: String = "",
val description: String = "",
@SerialName("system_message")
val systemMessage: String? = null,
@@ -75,6 +105,12 @@ data class Profile(
val apiServerPort: Int? = null,
@SerialName("api_server_key_present")
val apiServerKeyPresent: Boolean = false,
@SerialName("is_default")
val isDefault: Boolean = false,
@SerialName("has_avatar")
val hasAvatar: Boolean = false,
@SerialName("ui_meta")
val uiMeta: JsonObject = JsonObject(emptyMap()),
) {
val hasIsolatedApi: Boolean
get() = !apiServerUrl.isNullOrBlank()
@@ -4,13 +4,15 @@ import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.booleanPreferencesKey
import androidx.datastore.preferences.core.stringPreferencesKey
import androidx.datastore.preferences.preferencesDataStore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.map
/**
* Local-only per-profile agent icons — the visual twin of [ProfileDisplayAliasStore].
* Per-profile icon cache. Local fallback paths and Hermes-owned avatar cache
* paths use separate keys so syncing either side never silently overwrites the other.
*
* Stores a **file path** to an image that was copied into app storage (not a SAF
* content URI, so it survives without a persistable-permission grant). Like the
@@ -25,6 +27,8 @@ class ProfileIconStore(
companion object {
private const val PREFIX = "profile_icon__"
private const val SERVER_PREFIX = "profile_avatar_server__"
private const val LOCAL_OVERRIDE_PREFIX = "profile_icon_override__"
private fun keyName(connectionId: String, profileName: String?): String =
"$PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}"
@@ -34,6 +38,20 @@ class ProfileIconStore(
private fun connectionPrefix(connectionId: String): String =
"$PREFIX${connectionId}__"
private fun serverKeyFor(connectionId: String, profileName: String) =
stringPreferencesKey("$SERVER_PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}")
private fun serverConnectionPrefix(connectionId: String): String =
"$SERVER_PREFIX${connectionId}__"
private fun localOverrideKeyFor(connectionId: String, profileName: String?) =
booleanPreferencesKey(
"$LOCAL_OVERRIDE_PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}",
)
private fun localOverrideConnectionPrefix(connectionId: String): String =
"$LOCAL_OVERRIDE_PREFIX${connectionId}__"
}
suspend fun setIcon(connectionId: String, profileName: String?, path: String?) {
@@ -52,11 +70,39 @@ class ProfileIconStore(
return dataStore.data.map { prefs -> prefs[key] }
}
suspend fun setServerAvatar(connectionId: String, profileName: String, path: String?) {
dataStore.edit { prefs ->
val key = serverKeyFor(connectionId, profileName)
if (path.isNullOrBlank()) prefs.remove(key) else prefs[key] = path
}
}
fun serverAvatarFlow(connectionId: String, profileName: String): Flow<String?> {
val key = serverKeyFor(connectionId, profileName)
return dataStore.data.map { prefs -> prefs[key] }
}
suspend fun setLocalOverride(connectionId: String, profileName: String?, enabled: Boolean) {
dataStore.edit { prefs ->
val key = localOverrideKeyFor(connectionId, profileName)
if (enabled) prefs[key] = true else prefs.remove(key)
}
}
fun localOverrideFlow(connectionId: String, profileName: String?): Flow<Boolean> {
val key = localOverrideKeyFor(connectionId, profileName)
return dataStore.data.map { prefs -> prefs[key] ?: false }
}
suspend fun clearConnection(connectionId: String) {
val prefix = connectionPrefix(connectionId)
val prefixes = listOf(
connectionPrefix(connectionId),
serverConnectionPrefix(connectionId),
localOverrideConnectionPrefix(connectionId),
)
dataStore.edit { prefs ->
prefs.asMap().keys
.filter { it.name.startsWith(prefix) }
.filter { key -> prefixes.any(key.name::startsWith) }
.forEach { prefs.remove(it) }
}
}
@@ -66,5 +112,11 @@ class ProfileIconStore(
}
}
internal fun preferredProfileIcon(
server: String?,
local: String?,
useLocalOverride: Boolean,
): String? = if (useLocalOverride && !local.isNullOrBlank()) local else server ?: local
internal val Context.profileIconsDataStore: DataStore<Preferences>
by preferencesDataStore(name = "profile_icons")
@@ -136,3 +136,154 @@ data class ProfileMemoryUpdateResponse(
@SerialName("bytes_written")
val bytesWritten: Long,
)
/** Authoritative upstream `profiles.describe` snapshot. */
data class GatewayProfileDescription(
val name: String,
val description: String,
val soul: String,
val provider: String,
val model: String,
val skills: List<GatewayProfileSkill>,
val toolsets: List<GatewayProfileToolset>,
val toolsetsPinned: Boolean,
)
data class GatewayProfileSkill(val name: String, val enabled: Boolean)
data class GatewayProfileToolset(
val name: String,
val description: String,
val toolCount: Int,
val enabled: Boolean,
)
enum class GatewayProfileSection(val wireName: String) {
Description("description"),
Soul("soul"),
Model("model"),
Skills("skills"),
Toolsets("toolsets"),
McpServers("mcp_servers"),
UiMeta("ui_meta"),
}
/** Null leaves a section unchanged; empty lists retain upstream replace semantics. */
data class GatewayProfilePatch(
val description: String? = null,
val soul: String? = null,
val provider: String? = null,
val model: String? = null,
val disabledSkills: List<String>? = null,
val enabledToolsets: List<String>? = null,
val enabledMcpServers: List<String>? = null,
/** Small interoperable preferences only; binary assets belong in profiles.set_asset. */
val uiMeta: JsonObject? = null,
) {
val requestedSections: Set<GatewayProfileSection>
get() = buildSet {
if (description != null) add(GatewayProfileSection.Description)
if (soul != null) add(GatewayProfileSection.Soul)
if (provider != null && model != null) add(GatewayProfileSection.Model)
if (disabledSkills != null) add(GatewayProfileSection.Skills)
if (enabledToolsets != null) add(GatewayProfileSection.Toolsets)
if (enabledMcpServers != null) add(GatewayProfileSection.McpServers)
if (uiMeta != null) add(GatewayProfileSection.UiMeta)
}
}
enum class GatewayProfileAuthChoice {
/** Share the launch profile's refreshable OAuth/token store; copy static environment keys. */
Shared,
/** Copy the current credential snapshot into a separate profile-owned store. */
Copied,
/** Copy no credentials or provider defaults. */
Isolated,
}
data class GatewayProfileCreateRequest(
val name: String,
val description: String? = null,
val cloneFrom: String? = null,
val cloneAll: Boolean = false,
val noSkills: Boolean = false,
val soul: String? = null,
val model: String? = null,
val provider: String? = null,
val authChoice: GatewayProfileAuthChoice = GatewayProfileAuthChoice.Shared,
)
data class GatewayProfileCreateResult(
val name: String,
val soulWritten: Boolean,
val modelSet: Boolean,
val mirroredEnvironment: Boolean,
val mirroredAuth: String?,
val modelInherited: Boolean,
val voiceMirrored: Boolean,
) {
fun partialMessages(request: GatewayProfileCreateRequest): List<String> = buildList {
if (!request.soul.isNullOrBlank() && !soulWritten) add("SOUL was not saved")
if (!request.model.isNullOrBlank() && !modelSet) add("model was not saved")
if (request.authChoice == GatewayProfileAuthChoice.Shared && mirroredAuth != "shared") {
add("shared sign-in was not confirmed")
}
if (
request.authChoice == GatewayProfileAuthChoice.Copied &&
!mirroredEnvironment && mirroredAuth != "true"
) {
add("no credential source was copied")
}
}
}
data class GatewayProfileAsset(
val data: ByteArray,
val mime: String,
)
class GatewayProfileManagementUnsupportedException(
operation: String,
) : Exception("$operation is not supported by this gateway")
data class GatewayProfileConfigureResult(
val requested: Set<GatewayProfileSection>,
val applied: Set<GatewayProfileSection>,
) {
val failed: Set<GatewayProfileSection> get() = requested - applied
}
interface GatewayProfileEditorClient {
suspend fun describeProfile(profileName: String): Result<GatewayProfileDescription>
suspend fun configureProfile(
profileName: String,
patch: GatewayProfilePatch,
): Result<GatewayProfileConfigureResult>
}
class GatewayProfileEditorUnsupportedException : Exception(
"Profile editing is not supported by this gateway",
)
/** Relay fallback retained for older gateways and Relay-only memory files. */
interface LegacyProfileInspectorClient {
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse>
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse>
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse>
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse>
suspend fun updateSoul(profileName: String, content: String): Result<ProfileSoulUpdateResponse>
suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
): Result<ProfileMemoryUpdateResponse>
suspend fun updateSkillToggle(skillName: String, enabled: Boolean): Result<RelaySkillToggleResult>
suspend fun probeSkillToggleSupported(): Boolean
}
sealed interface RelaySkillToggleResult {
data object Ok : RelaySkillToggleResult
data object NotImplemented : RelaySkillToggleResult
}
@@ -9,6 +9,7 @@ import androidx.datastore.preferences.preferencesDataStore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.map
import kotlinx.serialization.builtins.ListSerializer
import kotlinx.serialization.builtins.MapSerializer
import kotlinx.serialization.builtins.serializer
import kotlinx.serialization.json.Json
@@ -16,6 +17,8 @@ import kotlinx.serialization.json.Json
data class ProfilePresentation(
val order: List<String> = emptyList(),
val hidden: Set<String> = emptySet(),
/** Local-only named-profile accent overrides, stored as normalized RGB hex. */
val colors: Map<String, String> = emptyMap(),
)
/**
@@ -63,14 +66,17 @@ class ProfilePresentationStore(
private val json = Json { ignoreUnknownKeys = true }
private val listSerializer = ListSerializer(String.serializer())
private val mapSerializer = MapSerializer(String.serializer(), String.serializer())
private fun orderKey(connectionId: String) = stringPreferencesKey("order_$connectionId")
private fun hiddenKey(connectionId: String) = stringPreferencesKey("hidden_$connectionId")
private fun colorsKey(connectionId: String) = stringPreferencesKey("colors_$connectionId")
fun presentationFlow(connectionId: String): Flow<ProfilePresentation> = dataStore.data.map { prefs ->
ProfilePresentation(
order = decode(prefs[orderKey(connectionId)]),
hidden = decode(prefs[hiddenKey(connectionId)]).toSet(),
colors = decodeMap(prefs[colorsKey(connectionId)]),
)
}
@@ -82,10 +88,18 @@ class ProfilePresentationStore(
dataStore.edit { it[hiddenKey(connectionId)] = json.encodeToString(listSerializer, hidden.sorted()) }
}
suspend fun setColors(connectionId: String, colors: Map<String, String>) {
dataStore.edit {
if (colors.isEmpty()) it.remove(colorsKey(connectionId))
else it[colorsKey(connectionId)] = json.encodeToString(mapSerializer, colors.toSortedMap())
}
}
suspend fun clear(connectionId: String) {
dataStore.edit {
it.remove(orderKey(connectionId))
it.remove(hiddenKey(connectionId))
it.remove(colorsKey(connectionId))
}
}
@@ -98,6 +112,12 @@ class ProfilePresentationStore(
} else {
runCatching { json.decodeFromString(listSerializer, raw) }.getOrDefault(emptyList())
}
private fun decodeMap(raw: String?): Map<String, String> = if (raw == null) {
emptyMap()
} else {
runCatching { json.decodeFromString(mapSerializer, raw) }.getOrDefault(emptyMap())
}
}
internal val Context.profilePresentationDataStore: DataStore<Preferences>
@@ -12,6 +12,7 @@ import com.hermesandroid.relay.auth.CertPinStore
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
import com.hermesandroid.relay.diagnostics.DiagnosticCategory
import com.hermesandroid.relay.diagnostics.DiagnosticSeverity
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
@@ -19,6 +20,7 @@ import com.hermesandroid.relay.diagnostics.NetworkDiagnosticGuidance
import com.hermesandroid.relay.network.relay.models.Envelope
import com.hermesandroid.relay.network.shared.EndpointResolver
import com.hermesandroid.relay.network.shared.EndpointSurface
import com.hermesandroid.relay.network.shared.fullJitterDelayMs
import com.hermesandroid.relay.network.shutdownOffMainThread
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
@@ -76,6 +78,9 @@ internal fun buildRelayRequestOrNull(url: String): Request? =
null
}
private fun EndpointCandidate.relayWebSocketUrl(): String? =
pluginProxyRoutesOrNull()?.relayWebSocketUrl ?: relay?.url
class ConnectionManager(
private val multiplexer: ChannelMultiplexer,
/**
@@ -139,6 +144,12 @@ class ConnectionManager(
* non-null — the manager falls back to the single-URL path.
*/
private val deviceIdProvider: (suspend () -> String?)? = null,
/** Random source for ordinary reconnect full-jitter; exact backoffs never use it. */
private val reconnectJitterUnit: () -> Double = { kotlin.random.Random.nextDouble() },
/** Exact-authority pinned client for a plugin-proxy WSS URL. */
private val proxyClientProvider: ((String) -> OkHttpClient?)? = null,
/** Test seam for observing lifecycle teardown without opening a socket. */
private val okHttpClientFactory: (() -> OkHttpClient)? = null,
) {
private val supervisorJob = SupervisorJob()
private val scope = CoroutineScope(supervisorJob + Dispatchers.IO)
@@ -148,7 +159,8 @@ class ConnectionManager(
encodeDefaults = true
}
private fun buildClient(): OkHttpClient {
private fun buildClient(url: String? = null): OkHttpClient {
okHttpClientFactory?.let { return it() }
val builder = OkHttpClient.Builder()
// OkHttp's 10s default connectTimeout is LAN-tuned; a Tailscale
// DERP-relayed cold-start handshake can exceed it, and a failed
@@ -162,7 +174,9 @@ class ConnectionManager(
// that wipes a pin would still be subject to the pre-wipe rules.
certPinStore?.let { store ->
try {
builder.certificatePinner(store.buildPinnerSnapshot())
builder.certificatePinner(
url?.let(store::buildPinnerSnapshotFor) ?: store.buildPinnerSnapshot(),
)
} catch (e: Exception) {
Log.w(TAG, "CertificatePinner build failed: ${e.message}")
builder.certificatePinner(CertificatePinner.DEFAULT)
@@ -221,10 +235,12 @@ class ConnectionManager(
// Endpoints card in Settings.
private val _activeEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeEndpoint: StateFlow<EndpointCandidate?> = _activeEndpoint.asStateFlow()
private val _activeApiEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeApiEndpoint: StateFlow<EndpointCandidate?> = _activeApiEndpoint.asStateFlow()
/** Relay-only winner, deliberately separate from the standard route. */
@Volatile
private var activeRelayEndpoint: EndpointCandidate? = null
private val _activeRelayEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeRelayEndpoint: StateFlow<EndpointCandidate?> = _activeRelayEndpoint.asStateFlow()
/**
* Manual role override. When non-null, the resolver's output is replaced
@@ -345,11 +361,14 @@ class ConnectionManager(
// behavior for freshly-upgraded installs and for v1/v2 QRs where
// the synthesized list just collapses to the same URL anyway.
scope.launch {
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val resolvedRelayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
val resolvedRelayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
val targetUrl = resolvedRelayUrl ?: url.takeIf { it.isNotBlank() }
activeRelayEndpoint = relayResolved
_activeRelayEndpoint.value = relayResolved
_activeApiEndpoint.value = apiResolved
if (resolved != null) {
_activeEndpoint.value = resolved
Log.i(TAG, "connect: standard resolver picked role=${resolved.role} " +
@@ -376,7 +395,7 @@ class ConnectionManager(
Log.i(
TAG,
"connect: relay resolver picked role=${relayRoute.role} " +
"url=${relayRoute.relay?.url}",
"url=${relayRoute.relayWebSocketUrl()}",
)
}
if (targetUrl != null) {
@@ -531,7 +550,8 @@ class ConnectionManager(
* for any reason we don't block the connect loop forever.
*/
suspend fun resolveBestEndpoint(): EndpointCandidate? =
resolveBestEndpointSafe(EndpointSurface.Standard)
resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
private suspend fun resolveBestEndpointSafe(
surface: EndpointSurface,
@@ -609,7 +629,9 @@ class ConnectionManager(
suspend fun probeAndReconnectNow(): EndpointCandidate? {
endpointResolver?.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
@@ -618,8 +640,9 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
if (relayResolved != null) activeRelayEndpoint = relayResolved
val targetUrl = relayResolved?.relay?.url ?: current ?: return resolved
_activeApiEndpoint.value = apiResolved
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val targetUrl = relayResolved?.relayWebSocketUrl() ?: current ?: return resolved
val normalizedTarget = normalizeRelayUrl(targetUrl)
// Reconnect when the winner changed, and also when the socket is
// stale/disconnected on the same winner. The latter makes the
@@ -656,7 +679,9 @@ class ConnectionManager(
*/
suspend fun refreshActiveEndpoint(clearProbeCache: Boolean = false): EndpointCandidate? {
if (clearProbeCache) endpointResolver?.clearCache()
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
// (slow resume, mid-handoff blip) — keep publishing the live
@@ -665,6 +690,7 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
return resolved
}
@@ -681,7 +707,7 @@ class ConnectionManager(
fun getManualRoleOverride(): String? = _manualRoleOverride.value
private fun markActiveRelayEndpointUnreachable(reason: String) {
val active = activeRelayEndpoint ?: return
val active = _activeRelayEndpoint.value ?: return
endpointResolver?.markUnreachable(active, EndpointSurface.Relay)
Log.i(TAG, "marked endpoint role=${active.role} unreachable ($reason)")
}
@@ -707,7 +733,9 @@ class ConnectionManager(
// manages its own cache (clear + markUnreachable) and passes false.
if (wipeCache) endpointResolver.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null) {
// Hysteresis for the AUTOMATIC (network-callback) path. A
// transient cold-route probe miss must NOT null the published
@@ -744,6 +772,7 @@ class ConnectionManager(
}
sustainedLossDeclared = false
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
if (current == null) return@launch
// After an explicit disconnect() the route still publishes above
// (HTTP surfaces keep roaming), but no socket action: without
@@ -753,8 +782,8 @@ class ConnectionManager(
// the swap path never re-checked it.)
if (!shouldReconnect) return@launch
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (relayResolved != null) activeRelayEndpoint = relayResolved
val relayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val relayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
?: return@launch
if (isRelayRateLimitBackoffActive(
rateLimitBackoffUntilMs,
@@ -899,7 +928,8 @@ class ConnectionManager(
// the ViewModel on the next connection load.
_manualRoleOverride.value = null
_activeEndpoint.value = null
activeRelayEndpoint = null
_activeApiEndpoint.value = null
_activeRelayEndpoint.value = null
reconnectState.reset()
}
@@ -979,7 +1009,18 @@ class ConnectionManager(
// Every new socket starts unauthenticated — the send-gate stays closed
// (auth frame excepted) until this socket's own auth.ok arrives.
authenticated = false
client = buildClient()
val isPluginProxyUrl = _activeRelayEndpoint.value?.pluginProxyRoutesOrNull()
?.relayWebSocketUrl
?.equals(url, ignoreCase = true) == true
client = if (isPluginProxyUrl) {
proxyClientProvider?.invoke(url) ?: run {
Log.e(TAG, "Pinned plugin proxy client unavailable — refusing generic TLS fallback")
_connectionState.value = ConnectionState.Disconnected
return
}
} else {
buildClient(url)
}
val request = buildRelayRequestOrNull(url)
if (request == null) {
@@ -1213,8 +1254,9 @@ class ConnectionManager(
SLOW_POLL_BACKOFF_MS
}
else -> {
val ms = (BASE_BACKOFF_MS * (1L shl minOf(reconnectAttempt - 1, 4)))
val capMs = (BASE_BACKOFF_MS * (1L shl minOf(reconnectAttempt - 1, 4)))
.coerceAtMost(MAX_BACKOFF_MS)
val ms = fullJitterDelayMs(capMs, reconnectJitterUnit())
DiagnosticsLog.record(
category = DiagnosticCategory.Relay,
severity = DiagnosticSeverity.Info,
@@ -1236,7 +1278,7 @@ class ConnectionManager(
// during the retry window).
if (shouldReconnect && reconnectGate()) {
val resolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val targetUrl = resolved?.relay?.url
val targetUrl = resolved?.relayWebSocketUrl()
if (resolved != null) {
// Mirror scheduleNetworkReResolve: clear the sustained-loss
// latch on a successful resolve so a later transient miss
@@ -1244,7 +1286,7 @@ class ConnectionManager(
// in onLost's grace job but can be cleared on EITHER success
// edge — network-callback or relay-timer.)
sustainedLossDeclared = false
activeRelayEndpoint = resolved
_activeRelayEndpoint.value = resolved
}
if (targetUrl != null && normalizeRelayUrl(targetUrl) != url) {
Log.i(TAG, "scheduleReconnect: switching $url → ${normalizeRelayUrl(targetUrl)}")
@@ -5,7 +5,9 @@ import android.util.Log
import com.hermesandroid.relay.network.relay.models.Envelope
import com.hermesandroid.relay.notifications.ProactiveMessageNotifier
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.booleanOrNull
import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.intOrNull
import kotlinx.serialization.json.jsonPrimitive
/**
@@ -50,7 +52,7 @@ class ProactiveMessageHandler(
/** Sink for the dedicated Hermes inbox (Phase 2a) — the always-present log. */
private val toInbox: ((ProactiveMessage) -> Unit)? = null,
/** Sink for injecting into the active chat session (Phase 2b). */
var toSession: ((ProactiveMessage) -> Unit)? = null,
var toSession: ((ProactiveMessage) -> Boolean)? = null,
/**
* Sink for the relay's per-reply ack (`proactive.reply.ack`) — lets the
* chat layer settle a Thread reply bubble from SENDING → DELIVERED. Wired
@@ -61,11 +63,13 @@ class ProactiveMessageHandler(
/**
* Show an inbound message inline in the Chat **Thread** it belongs to, when
* that Thread is currently open. Returns true if it was shown there — in
* which case the message is NOT also notified or added to the inbox (you're
* already looking at the conversation). The unified-Threads counterpart of
* which case the message is persisted but not also notified (you're already
* looking at the conversation). The unified-Threads counterpart of
* [toSession]; wired after construction.
*/
var injectIntoThread: ((ProactiveMessage) -> Boolean)? = null,
/** One callback per completed queued-message flush, never per message. */
var onBacklogDelivered: ((Int) -> Unit)? = null,
) {
fun onMessage(envelope: Envelope) {
@@ -80,6 +84,10 @@ class ProactiveMessageHandler(
}
// Subscribe ack — informational; nothing to do client-side.
"proactive.subscribed" -> Log.d(TAG, "proactive subscribe acked")
"proactive.backlog.complete" -> {
val count = envelope.payload["count"]?.jsonPrimitive?.intOrNull ?: 0
if (count > 0) onBacklogDelivered?.invoke(count)
}
// Per-reply ack — settle the matching Thread reply bubble (the
// `client_msg_id` is the id the app stamped on its own reply).
"proactive.reply.ack" -> {
@@ -94,24 +102,28 @@ class ProactiveMessageHandler(
/** Route a parsed message: into the open Thread if it belongs there, else
* the durable inbox log + the surface its hint selects. */
private fun dispatch(msg: ProactiveMessage) {
// Unified Threads: if this message belongs to the Thread currently open
// in Chat, render it inline there and STOP — no notification, no inbox
// entry (you're already looking at the conversation).
if (injectIntoThread?.invoke(msg) == true) return
// Otherwise the inbox is the durable log of agent-initiated messages and
// the surfacing hint selects the additional surface.
// Persist first even when the currently open Thread consumes the live
// message. Agent-initiated outbound sends do not create a gateway
// session until the phone replies, so this cache is the provisional
// Thread transcript during that gap.
toInbox?.invoke(msg)
// The surfacing hint selects the additional surface. Thread injection
// is best-effort presentation of the persisted row, not itself a reason
// to suppress an explicitly requested notification.
when (msg.surfacing?.lowercase()) {
"inbox" -> { /* inbox only — already recorded above */ }
"inbox" -> {
injectIntoThread?.invoke(msg)
}
"session" -> {
val sink = toSession
// Legacy explicit "inject into active session" path; if no sink
// (or no active chat) fall back to a notification so it isn't
// silently missed (the inbox copy already exists either way).
if (sink != null) sink.invoke(msg) else notify(msg)
val delivered = injectIntoThread?.invoke(msg) == true ||
toSession?.invoke(msg) == true
if (!delivered) notify(msg)
}
// null / "default" / "notification" / anything unrecognized.
else -> notify(msg)
else -> {
injectIntoThread?.invoke(msg)
notify(msg)
}
}
}
@@ -136,6 +148,7 @@ class ProactiveMessageHandler(
surfacing = payload["surfacing"]?.jsonPrimitive?.contentOrNull,
sentAt = payload["sent_at"]?.jsonPrimitive?.contentOrNull?.toLongOrNull(),
replyTo = payload["reply_to"]?.jsonPrimitive?.contentOrNull,
arrivedWhileAway = payload["queued_delivery"]?.jsonPrimitive?.booleanOrNull == true,
)
}
@@ -157,4 +170,6 @@ data class ProactiveMessage(
val sentAt: Long?,
/** Id of the message this one answers, if any (server threading hint). */
val replyTo: String? = null,
/** True only when Relay explicitly marked this as a reconnect queue flush. */
val arrivedWhileAway: Boolean = false,
)
@@ -7,6 +7,8 @@ import com.hermesandroid.relay.data.ProfileSkillsResponse
import com.hermesandroid.relay.data.ProfileSoulResponse
import com.hermesandroid.relay.data.ProfileSoulUpdateResponse
import com.hermesandroid.relay.data.ProfileMemoryUpdateResponse
import com.hermesandroid.relay.data.LegacyProfileInspectorClient
import com.hermesandroid.relay.data.RelaySkillToggleResult
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import kotlinx.serialization.SerializationException
@@ -48,7 +50,7 @@ class RelayProfileInspectorClient(
private val okHttpClient: OkHttpClient,
private val relayUrlProvider: () -> String?,
private val sessionTokenProvider: suspend () -> String?,
) {
) : LegacyProfileInspectorClient {
companion object {
private const val TAG = "RelayProfileInspector"
@@ -79,19 +81,19 @@ class RelayProfileInspectorClient(
/** Fetch `GET /api/profiles/{name}/config`. */
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
override suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
get(profileName, "config", ProfileConfigResponse.serializer())
/** Fetch `GET /api/profiles/{name}/skills`. */
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
override suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
get(profileName, "skills", ProfileSkillsResponse.serializer())
/** Fetch `GET /api/profiles/{name}/soul`. */
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
override suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
get(profileName, "soul", ProfileSoulResponse.serializer())
/** Fetch `GET /api/profiles/{name}/memory`. */
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
override suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
get(profileName, "memory", ProfileMemoryResponse.serializer())
/**
@@ -108,7 +110,7 @@ class RelayProfileInspectorClient(
* would be a protocol violation; we send empty-string for an empty
* SOUL.
*/
suspend fun updateSoul(
override suspend fun updateSoul(
profileName: String,
content: String,
): Result<ProfileSoulUpdateResponse> = withContext(Dispatchers.IO) {
@@ -137,7 +139,7 @@ class RelayProfileInspectorClient(
* Used for both creating a new memory entry (the relay writes the
* file if missing) and updating an existing entry.
*/
suspend fun updateMemoryEntry(
override suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
@@ -270,10 +272,10 @@ class RelayProfileInspectorClient(
* server" snackbar and ghost out the toggle. When the real
* implementation lands server-side, this method needs no change.
*/
suspend fun updateSkillToggle(
override suspend fun updateSkillToggle(
skillName: String,
enabled: Boolean,
): Result<SkillToggleResult> = withContext(Dispatchers.IO) {
): Result<RelaySkillToggleResult> = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) {
return@withContext Result.failure(
@@ -319,8 +321,8 @@ class RelayProfileInspectorClient(
try {
okHttpClient.newCall(request).execute().use { response ->
when (response.code) {
in 200..299 -> Result.success(SkillToggleResult.Ok)
501 -> Result.success(SkillToggleResult.NotImplemented)
in 200..299 -> Result.success(RelaySkillToggleResult.Ok)
501 -> Result.success(RelaySkillToggleResult.NotImplemented)
401, 403 -> Result.failure(
IOException("Unauthorized — re-pair with the relay")
)
@@ -348,7 +350,7 @@ class RelayProfileInspectorClient(
* "not implemented" and any 2xx as "supported". The relay serves
* OPTIONS via aiohttp's CORS handling by default.
*/
suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
override suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) return@withContext false
val sessionToken = sessionTokenProvider() ?: return@withContext false
@@ -402,11 +404,6 @@ class RelayProfileInspectorClient(
* answered 501 — not implemented yet" without inventing magic
* error strings.
*/
sealed class SkillToggleResult {
data object Ok : SkillToggleResult()
data object NotImplemented : SkillToggleResult()
}
/**
* Best-effort pull of a `detail` or `error` string out of a relay
* 400 body. Falls back to the first 120 chars of the payload when
@@ -55,6 +55,8 @@ data class RouteProbeOutcome(
*/
enum class EndpointSurface {
Standard,
Dashboard,
Api,
Relay,
}
@@ -109,6 +111,8 @@ class EndpointResolver(
* expected path for plain JVM tests.
*/
private val context: Context? = null,
/** Route-aware client for pinned plugin proxy probes. */
private val clientForCandidate: ((EndpointCandidate) -> OkHttpClient?)? = null,
) {
/**
@@ -196,8 +200,13 @@ class EndpointResolver(
val authority = when (surface) {
EndpointSurface.Standard ->
candidate.routeAuthority() ?: candidate.primaryRouteUrl().orEmpty().lowercase()
EndpointSurface.Dashboard ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl ?: candidate.dashboard?.url).orEmpty()
EndpointSurface.Api ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.apiBaseUrl ?: candidate.api?.url).orEmpty()
EndpointSurface.Relay ->
routeAuthority(candidate.relay?.url).orEmpty()
candidate.pluginProxyRoutesOrNull()?.authority
?: routeAuthority(candidate.relay?.url).orEmpty()
}
return "${surface.name.lowercase()}|${candidate.role}|$authority"
}
@@ -239,11 +248,16 @@ class EndpointResolver(
val eligible = candidates.filter { probeTarget(it, surface) != null }
if (eligible.isEmpty()) return null
// Strict priority: sort ascending so priority-0 lands first. Grouping
// preserves emitted order within a priority class (DNS SRV parity).
val groups = eligible.groupBy { it.priority }.toSortedMap()
// Supported routes always run before experimental routes. Priority is
// strict inside each stability tier, so Reach remains available as a
// last-resort fallback without displacing Tailscale or direct TLS.
val supported = eligible.filterNot { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val experimental = eligible.filter { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val groups = (supported.groupBy { it.priority }.toSortedMap().values +
experimental.groupBy { it.priority }.toSortedMap().values)
for ((priority, group) in groups) {
for (group in groups) {
val priority = group.first().priority
Log.d(TAG, "probing priority=$priority group (size=${group.size})")
val winner = raceGroup(group, surface)
if (winner != null) {
@@ -356,6 +370,8 @@ class EndpointResolver(
val startedAtMs = clock()
val operation = when (surface) {
EndpointSurface.Standard -> "Dashboard or API route health probe"
EndpointSurface.Dashboard -> "Dashboard route health probe"
EndpointSurface.Api -> "API route health probe"
EndpointSurface.Relay -> "Relay route health probe"
}
val target = probeTarget(candidate, surface)
@@ -375,7 +391,7 @@ class EndpointResolver(
recordOutcome(candidate, surface, reachable = false, detail = "Invalid route URL")
return false
}
val fastClient = httpClient.newBuilder()
val fastClient = (clientForCandidate?.invoke(candidate) ?: httpClient).newBuilder()
.connectTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.readTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.writeTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
@@ -480,6 +496,29 @@ class EndpointResolver(
candidate: EndpointCandidate,
surface: EndpointSurface,
): ProbeTarget? {
if (surface == EndpointSurface.Dashboard) {
candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl?.let { base ->
return ProbeTarget(base, "$base/api/status", "/dashboard/api/status")
}
candidate.dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }?.let { base ->
return ProbeTarget(base, "$base/api/status", "/api/status")
}
return null
}
if (surface == EndpointSurface.Api) {
candidate.pluginProxyRoutesOrNull()?.apiBaseUrl?.let { base ->
return ProbeTarget(base, "$base/health", "/api/health")
}
candidate.api?.url?.let { base -> return ProbeTarget(base, "$base/health", "/health") }
return null
}
if (surface == EndpointSurface.Relay) candidate.pluginProxyRoutesOrNull()?.let { proxy ->
return ProbeTarget(
baseUrl = proxy.relayHttpUrl,
requestUrl = "${proxy.relayHttpUrl}/health",
path = "/relay/health",
)
}
if (surface == EndpointSurface.Relay) {
return relayProbeTarget(candidate)
}
@@ -529,6 +568,11 @@ class EndpointResolver(
return null
}
internal fun probeRequestUrlForTest(
candidate: EndpointCandidate,
surface: EndpointSurface,
): String? = probeTarget(candidate, surface)?.requestUrl
/**
* Map a probe exception to a short, actionable string for the Routes
* card. The TLS case is the headline: a route saved with `https://`
@@ -546,6 +590,8 @@ class EndpointResolver(
private fun EndpointSurface.diagnosticTarget(): String = when (this) {
EndpointSurface.Standard -> "Dashboard or API server"
EndpointSurface.Dashboard -> "Dashboard"
EndpointSurface.Api -> "API server"
EndpointSurface.Relay -> "Relay"
}
@@ -0,0 +1,402 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.isValidHermesReach
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.Response
import okhttp3.WebSocket
import okhttp3.WebSocketListener
import okio.ByteString
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.InetAddress
import java.net.InetSocketAddress
import java.net.Socket
import java.net.SocketAddress
import java.net.SocketException
import java.net.URI
import java.security.SecureRandom
import java.util.Base64
import java.util.ArrayDeque
import java.util.concurrent.CountDownLatch
import java.util.concurrent.TimeUnit
import javax.net.SocketFactory
private const val REACH_PROTOCOL_VERSION = 1
private const val REACH_MAX_FRAME_BYTES = 1024 * 1024
internal const val REACH_MAX_QUEUED_FRAMES = 32
internal const val REACH_MAX_QUEUED_BYTES = 8 * 1024 * 1024
private const val REACH_MATCH_TIMEOUT_MS = 10_000L
/**
* Connection metadata for Hermes Reach's outer WSS rendezvous.
*
* This is deliberately transport-only. The inner HTTPS/WSS origin and its
* pairing-authenticated SPKI pin continue to be owned by [PluginProxyRoutes],
* so broker reachability can never weaken Secure Link trust.
*/
data class HermesReachRoute(
val brokerUrl: String,
val hostId: String,
val credentialKind: String,
val token: String,
) {
fun tunnelUrlOrNull(): String? {
if (hostId.isBlank() || token.isBlank()) return null
if (credentialKind !in setOf("bootstrap", "route")) return null
val uri = runCatching { URI(brokerUrl.trim()) }.getOrNull() ?: return null
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" && it != "/v1/connect" }) return null
val authority = buildString {
append(if (':' in uri.host) "[${uri.host}]" else uri.host)
if (uri.port > 0 && uri.port != 443) append(":${uri.port}")
}
return "wss://$authority/v1/connect"
}
}
fun EndpointCandidate.hermesReachRouteOrNull(): HermesReachRoute? {
val metadata = broker?.takeIf { it.isValidHermesReach() } ?: return null
if (pluginProxyRoutesOrNull() == null) return null
return HermesReachRoute(
brokerUrl = metadata.url,
hostId = metadata.hostId,
credentialKind = metadata.credentialKind,
token = metadata.token,
)
}
/** Build the pinned inner Secure Link client over an outer Hermes Reach WSS. */
fun buildHermesReachClient(
baseBuilder: OkHttpClient.Builder,
outerClient: OkHttpClient,
candidate: EndpointCandidate,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
): OkHttpClient? {
val secureLink = candidate.pluginProxyRoutesOrNull() ?: return null
val reach = candidate.hermesReachRouteOrNull() ?: return null
return buildPluginProxyClient(
baseBuilder = baseBuilder,
routes = secureLink,
sessionTokenProvider = sessionTokenProvider,
includeRelaySessionHeader = includeRelaySessionHeader,
rawSocketFactory = HermesReachSocketFactory(outerClient, reach),
)
}
@Serializable
private data class ReachRegistration(
val type: String = "register",
@SerialName("protocol_version") val protocolVersion: Int = REACH_PROTOCOL_VERSION,
val role: String = "client",
@SerialName("host_id") val hostId: String,
@SerialName("connection_id") val connectionId: String,
@SerialName("credential_kind") val credentialKind: String,
val token: String,
)
@Serializable
private data class ReachControl(
val type: String? = null,
@SerialName("protocol_version") val protocolVersion: Int? = null,
@SerialName("stream_id") val streamId: String? = null,
val code: String? = null,
)
internal object HermesReachHandshake {
private val json = Json {
ignoreUnknownKeys = false
encodeDefaults = true
}
fun registration(route: HermesReachRoute, connectionId: String): String = json.encodeToString(
ReachRegistration(
hostId = route.hostId,
connectionId = connectionId,
credentialKind = route.credentialKind,
token = route.token,
),
)
fun validateMatched(payload: String): String? {
val control = runCatching { json.decodeFromString<ReachControl>(payload) }
.getOrElse { return "Hermes Reach returned an invalid match response" }
if (control.type == "error") {
return "Hermes Reach rejected the route (${control.code ?: "unknown"})"
}
val streamIdValid = control.streamId?.let(::isCanonicalId) == true
if (control.type != "matched" ||
control.protocolVersion != REACH_PROTOCOL_VERSION ||
!streamIdValid
) {
return "Hermes Reach returned a mismatched route response"
}
return null
}
private fun isCanonicalId(value: String): Boolean {
if (value.isBlank() || '=' in value) return false
val decoded = runCatching { Base64.getUrlDecoder().decode(value) }.getOrNull() ?: return false
return decoded.size == 16 && Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == value
}
}
/**
* Raw socket factory that carries bytes through Hermes Reach. OkHttp layers
* the normal Secure Link TLS socket factory over the returned socket, so SNI,
* hostname verification, and the QR SPKI pin all apply to the inner endpoint.
*/
class HermesReachSocketFactory(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : SocketFactory() {
init {
require(route.tunnelUrlOrNull() != null) { "Invalid Hermes Reach route" }
}
override fun createSocket(): Socket = HermesReachSocket(outerClient, route)
override fun createSocket(host: String?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(host: String?, port: Int, localHost: InetAddress?, localPort: Int): Socket =
createSocket().apply {
if (localHost != null) bind(InetSocketAddress(localHost, localPort))
connect(InetSocketAddress(host, port))
}
override fun createSocket(host: InetAddress?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(
address: InetAddress?,
port: Int,
localAddress: InetAddress?,
localPort: Int,
): Socket = createSocket().apply {
if (localAddress != null) bind(InetSocketAddress(localAddress, localPort))
connect(InetSocketAddress(address, port))
}
}
private class HermesReachSocket(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : Socket() {
private val inbound = ReachInputStream()
private val matchLatch = CountDownLatch(1)
private val connectionId = randomConnectionId()
@Volatile private var matchError: IOException? = null
@Volatile private var webSocket: WebSocket? = null
@Volatile private var connected = false
@Volatile private var closed = false
@Volatile private var matched = false
@Volatile private var remote: InetSocketAddress? = null
private var readTimeoutMs: Int = 0
private val outbound = object : OutputStream() {
override fun write(value: Int) = write(byteArrayOf(value.toByte()))
override fun write(bytes: ByteArray, offset: Int, length: Int) {
if (length == 0) return
if (!matched || closed) throw SocketException("Hermes Reach tunnel is not open")
var cursor = offset
var remaining = length
while (remaining > 0) {
val count = minOf(remaining, REACH_MAX_FRAME_BYTES)
val accepted = webSocket?.send(ByteString.of(*bytes.copyOfRange(cursor, cursor + count))) == true
if (!accepted) throw SocketException("Hermes Reach could not queue tunnel bytes")
cursor += count
remaining -= count
}
}
}
override fun connect(endpoint: SocketAddress?) = connect(endpoint, REACH_MATCH_TIMEOUT_MS.toInt())
override fun connect(endpoint: SocketAddress?, timeout: Int) {
if (connected) throw SocketException("Socket is already connected")
if (closed) throw SocketException("Socket is closed")
remote = endpoint as? InetSocketAddress
?: throw SocketException("Hermes Reach requires an internet socket target")
val request = Request.Builder().url(requireNotNull(route.tunnelUrlOrNull())).build()
webSocket = outerClient.newWebSocket(request, listener)
val waitMs = minOf(
timeout.takeIf { it > 0 }?.toLong() ?: REACH_MATCH_TIMEOUT_MS,
REACH_MATCH_TIMEOUT_MS,
)
if (!matchLatch.await(waitMs, TimeUnit.MILLISECONDS)) {
closeWithError(IOException("Hermes Reach host match timed out"))
}
matchError?.let { throw it }
if (!matched) throw IOException("Hermes Reach closed before matching the host")
connected = true
}
private val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
val registration = HermesReachHandshake.registration(route, connectionId)
if (!webSocket.send(registration)) {
closeWithError(IOException("Hermes Reach registration could not be sent"))
}
}
override fun onMessage(webSocket: WebSocket, text: String) {
if (matched) {
closeWithError(IOException("Hermes Reach sent text after matching"))
return
}
HermesReachHandshake.validateMatched(text)?.let { message ->
closeWithError(IOException(message))
return
}
matched = true
matchLatch.countDown()
}
override fun onMessage(webSocket: WebSocket, bytes: ByteString) {
if (!matched) {
closeWithError(IOException("Hermes Reach sent bytes before matching"))
return
}
if (bytes.size > REACH_MAX_FRAME_BYTES) {
closeWithError(IOException("Hermes Reach frame exceeds 1 MiB"))
return
}
if (!inbound.offer(bytes.toByteArray())) {
closeWithError(IOException("Hermes Reach receive queue exceeded its safe limit"))
}
}
override fun onClosing(webSocket: WebSocket, code: Int, reason: String) {
webSocket.close(code, null)
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (!matched) matchError = IOException("Hermes Reach closed before matching the host")
closed = true
inbound.close(matchError)
matchLatch.countDown()
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
closeWithError(IOException("Hermes Reach connection failed", t))
}
}
private fun closeWithError(error: IOException) {
matchError = error
closed = true
webSocket?.cancel()
inbound.close(error)
matchLatch.countDown()
}
override fun getInputStream(): InputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
inbound.readTimeoutMs = readTimeoutMs
return inbound
}
override fun getOutputStream(): OutputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
return outbound
}
override fun close() {
if (closed) return
closed = true
webSocket?.close(1000, null)
inbound.close(null)
matchLatch.countDown()
}
override fun isConnected(): Boolean = connected
override fun isClosed(): Boolean = closed
override fun getRemoteSocketAddress(): SocketAddress? = remote
override fun getInetAddress(): InetAddress? = remote?.address
override fun getPort(): Int = remote?.port ?: 0
override fun setSoTimeout(timeout: Int) { readTimeoutMs = timeout }
override fun getSoTimeout(): Int = readTimeoutMs
override fun setTcpNoDelay(on: Boolean) = Unit
override fun getTcpNoDelay(): Boolean = true
override fun setKeepAlive(on: Boolean) = Unit
override fun getKeepAlive(): Boolean = true
override fun setReuseAddress(on: Boolean) = Unit
override fun getReuseAddress(): Boolean = false
}
internal class ReachInputStream : InputStream() {
private val chunks = ArrayDeque<ByteArray>()
private var offset = 0
private var queuedBytes = 0
private var terminalError: IOException? = null
private var closed = false
@Volatile var readTimeoutMs: Int = 0
@Synchronized
fun offer(bytes: ByteArray): Boolean {
if (closed) return false
if (chunks.size >= REACH_MAX_QUEUED_FRAMES || queuedBytes + bytes.size > REACH_MAX_QUEUED_BYTES) {
return false
}
chunks.addLast(bytes)
queuedBytes += bytes.size
(this as java.lang.Object).notifyAll()
return true
}
@Synchronized
fun close(error: IOException?) {
if (closed) return
closed = true
terminalError = error
(this as java.lang.Object).notifyAll()
}
override fun read(): Int {
val one = ByteArray(1)
return if (read(one, 0, 1) < 0) -1 else one[0].toInt() and 0xff
}
@Synchronized
override fun read(target: ByteArray, targetOffset: Int, length: Int): Int {
if (length == 0) return 0
val started = System.nanoTime()
while (chunks.isEmpty() && !closed) {
val waitMs = if (readTimeoutMs > 0) {
val elapsed = TimeUnit.NANOSECONDS.toMillis(System.nanoTime() - started)
(readTimeoutMs - elapsed).coerceAtLeast(0)
} else 0L
if (readTimeoutMs > 0 && waitMs == 0L) throw java.net.SocketTimeoutException("Hermes Reach read timed out")
(this as java.lang.Object).wait(if (readTimeoutMs > 0) waitMs else 0L)
}
if (chunks.isEmpty()) {
terminalError?.let { throw it }
return -1
}
val chunk = chunks.first()
val count = minOf(length, chunk.size - offset)
chunk.copyInto(target, targetOffset, offset, offset + count)
offset += count
queuedBytes -= count
if (offset == chunk.size) {
chunks.remove(chunk)
offset = 0
}
return count
}
}
private fun randomConnectionId(): String {
val bytes = ByteArray(16).also(SecureRandom()::nextBytes)
return Base64.getUrlEncoder().withoutPadding().encodeToString(bytes)
}
@@ -0,0 +1,145 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.ProxyEndpoint
import com.hermesandroid.relay.data.isValidPinnedProxy
import okhttp3.CertificatePinner
import okhttp3.Interceptor
import okhttp3.OkHttpClient
import java.net.URI
import java.security.KeyStore
import java.security.MessageDigest
import java.security.SecureRandom
import java.security.cert.CertificateException
import java.security.cert.X509Certificate
import javax.net.ssl.SSLContext
import javax.net.ssl.TrustManagerFactory
import javax.net.ssl.X509TrustManager
import javax.net.SocketFactory
/** Runtime endpoints exposed beneath one plugin-owned pinned-TLS origin. */
data class PluginProxyRoutes(
val authority: String,
val host: String,
val port: Int,
val relayHttpUrl: String,
val relayWebSocketUrl: String,
val apiBaseUrl: String?,
val dashboardBaseUrl: String?,
val pinSha256: String,
)
/**
* Resolve and validate the pairing-advertised proxy contract. Invalid or
* incomplete advertisements are never treated as secure routes.
*/
fun ProxyEndpoint.toPluginProxyRoutesOrNull(): PluginProxyRoutes? {
if (!isValidPinnedProxy()) return null
val base = url.trim().trimEnd('/')
val uri = runCatching { URI(base) }.getOrNull() ?: return null
if (!uri.scheme.equals("https", ignoreCase = true)) return null
val host = uri.host?.lowercase()?.takeIf { it.isNotBlank() } ?: return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
val rawPath = uri.rawPath.orEmpty()
if (rawPath.isNotEmpty() && rawPath != "/") return null
val port = if (uri.port > 0) uri.port else 443
val pin = pinSha256!!.trim()
val authority = "$host:$port"
val wsBase = "wss://${formatHost(host)}${if (port == 443) "" else ":$port"}$rawPath"
.trimEnd('/')
val surfaces = surfaces.map(String::lowercase).toSet()
return PluginProxyRoutes(
authority = authority,
host = host,
port = port,
relayHttpUrl = "$base/relay",
relayWebSocketUrl = "$wsBase/relay/ws",
apiBaseUrl = "$base/api".takeIf { "api" in surfaces },
dashboardBaseUrl = "$base/dashboard".takeIf { "dashboard" in surfaces },
pinSha256 = pin,
)
}
fun EndpointCandidate.pluginProxyRoutesOrNull(): PluginProxyRoutes? =
proxy?.toPluginProxyRoutesOrNull()
private fun formatHost(host: String): String = if (':' in host) "[$host]" else host
/**
* Build a client that trusts the system normally, plus exactly the
* pairing-advertised SPKI for this proxy. The authority guard keeps a pin
* scoped to host *and port*; OkHttp's CertificatePinner alone is host-only.
*/
fun buildPluginProxyClient(
baseBuilder: OkHttpClient.Builder,
routes: PluginProxyRoutes,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
rawSocketFactory: SocketFactory? = null,
): OkHttpClient {
val expectedHost = routes.host
val expectedPort = routes.port
val systemTrust = systemTrustManager()
val pinnedTrust = PinnedOrSystemTrustManager(systemTrust, routes.pinSha256)
val sslContext = SSLContext.getInstance("TLS").apply {
init(null, arrayOf(pinnedTrust), SecureRandom())
}
if (rawSocketFactory != null) baseBuilder.socketFactory(rawSocketFactory)
return baseBuilder
.sslSocketFactory(sslContext.socketFactory, pinnedTrust)
.certificatePinner(
CertificatePinner.Builder().add(expectedHost, routes.pinSha256).build(),
)
.addNetworkInterceptor(Interceptor { chain ->
val requestUrl = chain.request().url
if (!requestUrl.host.equals(expectedHost, ignoreCase = true) ||
requestUrl.port != expectedPort
) {
throw java.io.IOException("Pinned proxy redirect left its paired authority")
}
val token = sessionTokenProvider().takeIf { includeRelaySessionHeader }
?.takeIf { it.isNotBlank() }
val request = if (token != null) {
chain.request().newBuilder()
.header("X-Hermes-Relay-Session", token)
.build()
} else {
chain.request()
}
chain.proceed(request)
})
.build()
}
private fun systemTrustManager(): X509TrustManager {
val factory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm())
factory.init(null as KeyStore?)
return factory.trustManagers.filterIsInstance<X509TrustManager>().single()
}
private class PinnedOrSystemTrustManager(
private val system: X509TrustManager,
private val expectedPin: String,
) : X509TrustManager {
override fun checkClientTrusted(chain: Array<out X509Certificate>?, authType: String?) =
system.checkClientTrusted(chain, authType)
override fun checkServerTrusted(chain: Array<out X509Certificate>?, authType: String?) {
val certificates = chain?.takeIf { it.isNotEmpty() }
?: throw CertificateException("Proxy supplied no certificate chain")
val systemAccepted = runCatching { system.checkServerTrusted(chain, authType) }.isSuccess
if (systemAccepted) return
val leaf = certificates.first()
leaf.checkValidity()
val actual = "sha256/" + java.util.Base64.getEncoder().encodeToString(
MessageDigest.getInstance("SHA-256").digest(leaf.publicKey.encoded),
)
if (!MessageDigest.isEqual(actual.toByteArray(), expectedPin.toByteArray())) {
throw CertificateException("Plugin proxy certificate does not match the paired pin")
}
}
override fun getAcceptedIssuers(): Array<X509Certificate> = system.acceptedIssuers
}
@@ -0,0 +1,13 @@
package com.hermesandroid.relay.network.shared
import kotlin.random.Random
/** Full-jitter retry delay in the inclusive range 0..[capMs]. */
internal fun fullJitterDelayMs(
capMs: Long,
unit: Double = Random.nextDouble(),
): Long {
if (capMs <= 0L) return 0L
val boundedUnit = unit.coerceIn(0.0, Math.nextDown(1.0))
return (boundedUnit * (capMs + 1.0)).toLong().coerceAtMost(capMs)
}
@@ -90,12 +90,9 @@ class ChatHandler {
// Fallback form (no relay): `MEDIA:/absolute/path` — relay wasn't
// reachable when the tool fired, so we render an "unavailable"
// placeholder instead of attempting a fetch.
private val mediaRelayRegex = Regex("""MEDIA:hermes-relay://([A-Za-z0-9_-]+)""")
// `/.+?` (not `/\S+`) so absolute paths containing spaces — e.g.
// `MEDIA:/mnt/media/Coralee Adshade/undressher.jpg` — still match. The
// trailing `\s*$` trims any trailing whitespace; non-greedy keeps the
// capture to the path. OkHttp re-encodes the space for /media/by-path.
private val mediaBarePathRegex = Regex("""^\s*MEDIA:(/.+?)\s*$""")
private val mediaRelayPayloadRegex = Regex("""^hermes-relay://([A-Za-z0-9_-]+)$""")
private val mediaMarkerPrefixRegex = Regex("MEDIA:")
private val windowsAbsoluteMediaPathRegex = Regex("""^[A-Za-z]:[\\/].+""")
// Rich card marker — single line, full JSON object payload.
//
// Agents emit:
@@ -188,6 +185,7 @@ class ChatHandler {
* post-stream finalize reconciliation pass.
*/
private var mediaLineBuffer = StringBuilder()
private var mediaFenceDelimiter: String? = null
private val dispatchedMediaMarkers = mutableSetOf<String>()
/**
@@ -473,7 +471,12 @@ class ChatHandler {
* across the history reconcile; idempotent on the proactive [messageId] so a
* re-delivered push (e.g. an outbound-buffer flush) never double-posts.
*/
fun addAgentThreadMessage(text: String, messageId: String?, agentName: String?) {
fun addAgentThreadMessage(
text: String,
messageId: String?,
agentName: String?,
arrivedWhileAway: Boolean = false,
) {
val id = messageId?.let { "proactive-$it" } ?: "proactive-${java.util.UUID.randomUUID()}"
_messages.update { list ->
if (messageId != null && list.any { it.id == id }) return@update list
@@ -483,6 +486,7 @@ class ChatHandler {
content = text,
timestamp = System.currentTimeMillis(),
agentName = agentName,
badges = if (arrivedWhileAway) listOf("While away") else emptyList(),
clientOnly = true,
)
(list + msg).let { if (it.size > MAX_MESSAGES) it.drop(it.size - MAX_MESSAGES) else it }
@@ -526,6 +530,42 @@ class ChatHandler {
}
}
/**
* Whether [messageId] can be addressed without downgrading a durable
* transcript to an ordinal-only rewind. A wholly legacy transcript has no
* row ids and remains compatible with older Gateways. Once any visible
* user turn has a durable row id, the selected turn must have one too;
* otherwise the caller must refresh instead of guessing by position.
*/
fun hasSafeGatewayRewindAddress(messageId: String): Boolean {
val userTurns = _messages.value.filter { it.isGatewayRewindUser() }
val target = userTurns.firstOrNull { it.matchesIdentity(messageId) } ?: return false
return target.rowId != null || userTurns.none { it.rowId != null }
}
/**
* Rebind visible user turns after Gateway rewrites a truncated durable
* prefix. The response is positional in the same user-ordinal space used
* for edit/regenerate. Missing entries clear cached ids so a later rewind
* cannot accidentally send an archived pre-rewrite row id.
*/
fun rebindSurvivorUserRowIds(rowIds: List<Long?>) {
var ordinal = 0
_messages.update { messages ->
messages.map { message ->
if (!message.isGatewayRewindUser()) return@map message
val rebound = rowIds.getOrNull(ordinal)
ordinal += 1
if (message.rowId == rebound) message else message.copy(rowId = rebound)
}
}
}
private fun ChatMessage.isGatewayRewindUser(): Boolean =
role == MessageRole.USER &&
!id.startsWith("voice-intent-") &&
!id.startsWith("steer-")
fun replaceMessageContent(messageId: String, content: String) {
_messages.update { messages ->
messages.map { message ->
@@ -1176,12 +1216,14 @@ class ChatHandler {
// Drop any pending line buffers / dedupe state so a fresh session
// doesn't inherit leftovers from the previous one.
mediaLineBuffer.clear()
mediaFenceDelimiter = null
dispatchedMediaMarkers.clear()
annotationLineBuffer.clear()
activeAnnotationTools.clear()
cardLineBuffer.clear()
dispatchedCardMarkers.clear()
subagentLabels.clear()
subagentIds.clear()
}
/**
@@ -1497,6 +1539,8 @@ class ChatHandler {
// this as the same visible row across the post-turn reload.
prior.copy(
id = messageId,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1527,6 +1571,8 @@ class ChatHandler {
// nothing local to carry).
ChatMessage(
id = messageId,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1771,7 +1817,7 @@ class ChatHandler {
for (line in text.lines()) {
val t = line.trim()
if (t.isEmpty()) continue
if (mediaRelayRegex.containsMatchIn(t) || mediaBarePathRegex.containsMatchIn(t)) continue
if (parseMediaMarkerLine(t).isNotEmpty()) continue
if (PersistedImageReferenceParser.parse(t).paths.isNotEmpty()) continue
if (cardMarkerRegex.containsMatchIn(t)) continue
if (sb.isNotEmpty()) sb.append('\n')
@@ -1788,6 +1834,51 @@ class ChatHandler {
data class BarePath(val path: String) : MediaMarkerHit
}
/**
* Parse one marker-only line using upstream-compatible wrappers and
* boundaries. Prose and malformed examples remain ordinary text; a whole
* inline-code or emphasis wrapper is accepted, as are adjacent markers,
* sentence-final punctuation, POSIX paths, and Windows absolute paths.
*/
private fun parseMediaMarkerLine(line: String): List<MediaMarkerHit> {
val trimmed = line.trim()
if (trimmed.isEmpty() || trimmed.startsWith("```") || trimmed.startsWith("~~~")) {
return emptyList()
}
val starts = mediaMarkerPrefixRegex.findAll(trimmed).map { it.range.first }.toList()
if (starts.isEmpty()) return emptyList()
val prefix = trimmed.substring(0, starts.first())
if (prefix.any { !it.isWhitespace() && it !in "`*_~" }) return emptyList()
val hits = ArrayList<MediaMarkerHit>(starts.size)
for ((index, start) in starts.withIndex()) {
val payloadStart = start + "MEDIA:".length
val payloadEnd = starts.getOrNull(index + 1) ?: trimmed.length
val payload = trimmed.substring(payloadStart, payloadEnd)
.trim()
.trimEnd { it in "`*_~.,;:)}]" }
.trim()
if (payload.isEmpty()) return emptyList()
val relay = mediaRelayPayloadRegex.matchEntire(payload)
when {
relay != null -> hits += MediaMarkerHit.RelayToken(relay.groupValues[1])
payload.startsWith("/") || windowsAbsoluteMediaPathRegex.matches(payload) ->
hits += MediaMarkerHit.BarePath(payload)
else -> return emptyList()
}
}
return hits
}
private fun fenceDelimiter(line: String): String? {
val trimmed = line.trimStart()
return when {
trimmed.startsWith("```") -> "```"
trimmed.startsWith("~~~") -> "~~~"
else -> null
}
}
/**
* Scan loaded (non-streaming) message content line-by-line for media
* markers, append hits to [out], and return the content with matched
@@ -1800,24 +1891,20 @@ class ChatHandler {
out: MutableList<Pair<String, MediaMarkerHit>>,
): String {
var cleaned = content
var openFence: String? = null
for (rawLine in content.lines()) {
val trimmed = rawLine.trim()
if (trimmed.isEmpty()) continue
val relayMatch = mediaRelayRegex.find(trimmed)
if (relayMatch != null) {
out.add(messageId to MediaMarkerHit.RelayToken(relayMatch.groupValues[1]))
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
.replace("\n$rawLine", "")
.replace("$rawLine\n", "")
.replace(rawLine, "")
val delimiter = fenceDelimiter(rawLine)
if (delimiter != null) {
openFence = if (openFence == delimiter) null else if (openFence == null) delimiter else openFence
continue
}
if (openFence != null) continue
val bareMatch = mediaBarePathRegex.find(trimmed)
if (bareMatch != null) {
out.add(messageId to MediaMarkerHit.BarePath(bareMatch.groupValues[1]))
val hits = parseMediaMarkerLine(trimmed)
if (hits.isNotEmpty()) {
hits.forEach { out.add(messageId to it) }
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
.replace("\n$rawLine", "")
@@ -1984,6 +2071,11 @@ class ChatHandler {
title = resolvedTitle,
model = item.model,
messageCount = item.messageCount ?: 0,
inputTokens = item.inputTokens ?: 0,
outputTokens = item.outputTokens ?: 0,
actualCostUsd = item.actualCostUsd,
estimatedCostUsd = item.estimatedCostUsd,
isActive = item.isActive,
updatedAt = activityAtMs,
startedAt = startedAtMs,
lastActivityAt = lastActivityAtMs,
@@ -1995,6 +2087,13 @@ class ChatHandler {
hasModelConfig = item.hasModelConfig,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
)
}.sortedByDescending { it.activityTimestamp }
// Preserve the active session's optimistic row when the server list
@@ -2265,6 +2364,18 @@ class ChatHandler {
val trimmed = line.trim()
if (trimmed.isEmpty()) continue
fenceDelimiter(line)?.let { delimiter ->
mediaFenceDelimiter = if (mediaFenceDelimiter == delimiter) {
null
} else if (mediaFenceDelimiter == null) {
delimiter
} else {
mediaFenceDelimiter
}
continue
}
if (mediaFenceDelimiter != null) continue
if (tryDispatchMediaMarker(messageId, trimmed)) {
stripLineFromContent(messageId, trimmed)
}
@@ -2394,29 +2505,26 @@ class ChatHandler {
* Returns true when a marker was matched so the caller can strip the line.
*/
private fun tryDispatchMediaMarker(messageId: String, line: String): Boolean {
val relayMatch = mediaRelayRegex.find(line)
if (relayMatch != null) {
val token = relayMatch.groupValues[1]
val dedupeKey = "$messageId:relay:$token"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay): token=$token")
onMediaAttachmentRequested(messageId, token)
val hits = parseMediaMarkerLine(line)
for (hit in hits) {
when (hit) {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay): token=${hit.token}")
onMediaAttachmentRequested(messageId, hit.token)
}
}
is MediaMarkerHit.BarePath -> {
val dedupeKey = "$messageId:bare:${hit.path}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path): ${hit.path}")
onMediaBarePathRequested(messageId, hit.path)
}
}
}
return true
}
val bareMatch = mediaBarePathRegex.find(line)
if (bareMatch != null) {
val path = bareMatch.groupValues[1]
val dedupeKey = "$messageId:bare:$path"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path, unavailable): $path")
onMediaBarePathRequested(messageId, path)
}
return true
}
return false
return hits.isNotEmpty()
}
/**
@@ -2555,10 +2663,11 @@ class ChatHandler {
if (mediaLineBuffer.isNotEmpty()) {
val remaining = mediaLineBuffer.toString().trim()
mediaLineBuffer.clear()
if (remaining.isNotEmpty() && tryDispatchMediaMarker(messageId, remaining)) {
if (mediaFenceDelimiter == null && remaining.isNotEmpty() && tryDispatchMediaMarker(messageId, remaining)) {
stripLineFromContent(messageId, remaining)
}
}
mediaFenceDelimiter = null
// Post-stream reconciliation: re-scan the final content for markers
// that raced with stripLineFromContent during streaming.
@@ -2567,12 +2676,16 @@ class ChatHandler {
if (!msg.matchesIdentity(messageId) || msg.role != MessageRole.ASSISTANT) return@map msg
var cleaned = msg.content
var changed = false
var openFence: String? = null
for (rawLine in msg.content.lines()) {
val trimmed = rawLine.trim()
if (trimmed.isEmpty()) continue
if (mediaRelayRegex.containsMatchIn(trimmed) ||
mediaBarePathRegex.containsMatchIn(trimmed)
) {
val delimiter = fenceDelimiter(rawLine)
if (delimiter != null) {
openFence = if (openFence == delimiter) null else if (openFence == null) delimiter else openFence
continue
}
if (openFence == null && parseMediaMarkerLine(trimmed).isNotEmpty()) {
tryDispatchMediaMarker(messageId, trimmed)
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
@@ -2903,6 +3016,7 @@ class ChatHandler {
* [onStreamComplete] / [clearMessages].
*/
private val subagentLabels = mutableMapOf<Int, String>()
private val subagentIds = mutableMapOf<Int, String>()
/**
* Apply one gateway `subagent.*` lifecycle event to the streaming
@@ -2918,6 +3032,9 @@ class ChatHandler {
when (event.phase) {
GatewaySubagentEvent.Phase.START -> {
if (label != null) subagentLabels[event.taskIndex] = label
event.subagentId?.takeIf(String::isNotBlank)?.let {
subagentIds[event.taskIndex] = it
}
}
GatewaySubagentEvent.Phase.TOOL -> {
@@ -2932,6 +3049,8 @@ class ChatHandler {
isComplete = false,
taskIndex = event.taskIndex,
taskLabel = laneLabel,
subagentId = event.subagentId?.takeIf(String::isNotBlank)
?: subagentIds[event.taskIndex],
)
_messages.update { messages ->
val target = messages.findLast {
@@ -2971,6 +3090,7 @@ class ChatHandler {
// "interrupted" lanes never finished — not a success either.
val failed = event.status == "failed" || event.status == "interrupted"
val laneLabel = subagentLabels.remove(event.taskIndex) ?: label
val subagentId = subagentIds.remove(event.taskIndex) ?: event.subagentId
val summaryId = "subagent-${event.taskIndex}-${syntheticToolSeq++}"
_messages.update { messages ->
messages.map { msg ->
@@ -3003,6 +3123,7 @@ class ChatHandler {
completedAt = System.currentTimeMillis(),
taskIndex = event.taskIndex,
taskLabel = laneLabel,
subagentId = subagentId,
)
}
msg.copy(toolCalls = withSummary)
@@ -3260,6 +3381,7 @@ class ChatHandler {
}
}
subagentLabels.clear()
subagentIds.clear()
}
fun onStreamError(message: String) {
@@ -3289,6 +3411,7 @@ class ChatHandler {
}
}
subagentLabels.clear()
subagentIds.clear()
}
fun onThinkingDelta(messageId: String, delta: String) {
@@ -0,0 +1,50 @@
package com.hermesandroid.relay.network.upstream
/**
* User-reviewed input for upstream `cron.manage` creation.
*
* Repeat is intentionally bounded on the client. Upstream treats zero and
* negative values as an unlimited schedule, which is unsafe when the user
* explicitly chose a finite run count.
*/
data class CronCreationDraft(
val name: String,
val schedule: String,
val prompt: String,
val repeat: Int? = null,
val profile: String? = null,
) {
fun validated(): Result<CronCreationDraft> = runCatching {
val cleanName = name.trim()
val cleanSchedule = schedule.trim()
val cleanPrompt = prompt.trim()
require(cleanName.isNotEmpty()) { "Schedule name is required" }
require(cleanSchedule.isNotEmpty()) { "Schedule is required" }
require(cleanPrompt.isNotEmpty()) { "Task instructions are required" }
require(repeat == null || repeat in MIN_REPEAT..MAX_REPEAT) {
"Run count must be between $MIN_REPEAT and $MAX_REPEAT"
}
copy(
name = cleanName,
schedule = cleanSchedule,
prompt = cleanPrompt,
profile = profile?.trim()?.takeIf(String::isNotEmpty),
)
}
companion object {
const val MIN_REPEAT = 1
const val MAX_REPEAT = 999
}
}
/** Parse an optional finite-count field without ever coercing invalid input to unlimited. */
internal fun parseFiniteRepeat(value: String): Result<Int?> = runCatching {
val clean = value.trim()
if (clean.isEmpty()) return@runCatching null
val parsed = clean.toIntOrNull() ?: throw IllegalArgumentException("Run count must be a whole number")
require(parsed in CronCreationDraft.MIN_REPEAT..CronCreationDraft.MAX_REPEAT) {
"Run count must be between ${CronCreationDraft.MIN_REPEAT} and ${CronCreationDraft.MAX_REPEAT}"
}
parsed
}
@@ -7,9 +7,12 @@ import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.MessageListResponse
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.network.upstream.models.SessionListResponse
import com.hermesandroid.relay.network.upstream.models.SessionPullRequest
import com.hermesandroid.relay.network.upstream.models.SessionPullRequestScanResponse
import com.hermesandroid.relay.network.upstream.models.SessionPruneFilters
import com.hermesandroid.relay.network.upstream.models.SessionPrunePreview
import com.hermesandroid.relay.network.upstream.models.SessionPruneResult
import com.hermesandroid.relay.network.upstream.models.RepositoryPullRequestListResponse
import com.hermesandroid.relay.auth.SecureStoreCache
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.buildRawTokenStore
@@ -35,13 +38,18 @@ import okhttp3.CookieJar
import okhttp3.HttpUrl
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.MultipartBody
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody
import okhttp3.RequestBody.Companion.toRequestBody
import okhttp3.Response
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.URLEncoder
import java.util.concurrent.TimeUnit
import okio.BufferedSink
// Status/session/provider snapshots are @Serializable so the Manage tab's
// disk cache (DashboardManageDiskCache) can persist Loaded entries verbatim.
@@ -58,6 +66,29 @@ data class DashboardStatus(
@SerialName("gateway_mode") val gatewayMode: String? = null,
val gateways: List<DashboardGatewayTopology> = emptyList(),
val componentHealth: DashboardComponentHealthRollup = DashboardComponentHealthRollup(),
val memory: DashboardMemoryStatus? = null,
val disk: DashboardDiskStatus? = null,
)
@Serializable
data class DashboardMemoryStatus(
val pressure: String,
@SerialName("gateway_rss_mb") val gatewayRssMb: Int? = null,
@SerialName("system_total_mb") val systemTotalMb: Int? = null,
@SerialName("system_available_mb") val systemAvailableMb: Int? = null,
@SerialName("swap_used_mb") val swapUsedMb: Int? = null,
@SerialName("sampled_at") val sampledAt: String? = null,
@SerialName("last_boot_unclean") val lastBootUnclean: Boolean = false,
@SerialName("last_boot_suspected_oom") val lastBootSuspectedOom: Boolean = false,
@SerialName("boot_id") val bootId: String? = null,
)
@Serializable
data class DashboardDiskStatus(
val pressure: String,
@SerialName("total_mb") val totalMb: Int? = null,
@SerialName("free_mb") val freeMb: Int? = null,
@SerialName("used_percent") val usedPercent: Double? = null,
)
@Serializable
@@ -67,6 +98,23 @@ data class DashboardGatewayTopology(
@SerialName("served_profiles") val servedProfiles: List<String> = emptyList(),
)
/**
* Return only profiles the launch gateway positively reports as served.
*
* `/api/status.profiles` is the installed-profile inventory. Selective
* multiplex serving can exclude an installed profile, so that list must never
* authorize construction of a `/p/<profile>` API fallback route.
*/
internal fun DashboardStatus.multiplexServedProfiles(): List<String> {
if (!gatewayMode.equals("multiplex", ignoreCase = true)) return emptyList()
return gateways.firstOrNull { it.profile.equals("default", ignoreCase = true) }
?.servedProfiles
.orEmpty()
.map(String::trim)
.filter(String::isNotBlank)
.distinct()
}
@Serializable
data class DashboardComponentHealthRollup(
val supported: Boolean = false,
@@ -173,6 +221,71 @@ data class DashboardCustomEndpointValidation(
val models: List<String>,
)
internal class BoundedStreamRequestBody(
private val declaredLength: Long?,
private val limitBytes: Long,
private val openStream: () -> InputStream,
) : RequestBody() {
init {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit."
}
}
override fun contentType() = "application/zip".toMediaType()
override fun contentLength(): Long = declaredLength ?: -1L
override fun writeTo(sink: BufferedSink) {
openStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit.")
}
sink.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being read.")
}
}
}
}
internal fun copyBounded(
input: InputStream,
output: OutputStream,
declaredLength: Long?,
limitBytes: Long,
): Long {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit."
}
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit.")
}
output.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being downloaded.")
}
return written
}
/** One entry from `GET /api/audio/elevenlabs/voices` — non-secret voice metadata. */
data class ElevenLabsVoice(
val voiceId: String,
@@ -206,8 +319,14 @@ class DashboardApiClient(
isLenient = true
coerceInputValues = true
},
private val nowMillis: () -> Long = System::currentTimeMillis,
) {
private val baseUrl: String = baseUrl.trim().trimEnd('/')
private val sessionPrScanLock = Any()
private val sessionPrScannedAt = mutableMapOf<String, Long>()
private val sessionPrScanWasTerminal = mutableMapOf<String, Boolean>()
private val sessionPullRequests = mutableMapOf<String, SessionPullRequest>()
private var sessionPrScanSupported: Boolean? = null
/**
* Resolve a request URL without ever throwing. okhttp's
@@ -500,6 +619,7 @@ class DashboardApiClient(
name: String,
cloneFromDefault: Boolean = true,
description: String? = null,
mcpServers: List<String> = emptyList(),
): Result<JsonObject> =
postJsonObject(
path = "/api/profiles",
@@ -507,9 +627,167 @@ class DashboardApiClient(
put("name", name)
put("clone_from_default", cloneFromDefault)
if (!description.isNullOrBlank()) put("description", description)
if (mcpServers.isNotEmpty()) {
put("mcp_servers", JsonArray(mcpServers.map(::JsonPrimitive)))
}
},
)
/** Create a host-owned Hermes backup, distinct from Android settings export. */
suspend fun createServerBackup(): Result<JsonObject> =
postJsonObject("/api/ops/backup")
/** Download only archives created inside upstream's guarded dashboard backup directory. */
suspend fun downloadServerBackup(
archive: String,
openOutput: () -> OutputStream,
): Result<String> = download(
path = "/api/ops/backup/download?archive=${queryValue(archive)}",
operation = "Hermes backup",
openOutput = openOutput,
)
/** Import a server-local archive path after the user confirms the destructive restore. */
suspend fun importServerBackup(archive: String): Result<JsonObject> =
postJsonObject(
path = "/api/ops/import",
payload = buildJsonObject { put("archive", archive) },
)
/** Upload an Android-selected zip to upstream's guarded staging directory and start import. */
suspend fun uploadServerBackup(
filename: String,
contentLength: Long?,
openStream: () -> InputStream,
force: Boolean = false,
): Result<JsonObject> = withContext(Dispatchers.IO) {
val path = "/api/ops/import-upload"
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val body = MultipartBody.Builder()
.setType(MultipartBody.FORM)
.addFormDataPart("force", force.toString())
.addFormDataPart(
"file",
filename.ifBlank { "hermes-backup.zip" },
runCatching {
BoundedStreamRequestBody(contentLength, MAX_BACKUP_TRANSFER_BYTES, openStream)
}.getOrElse { return@withContext Result.failure(it) },
)
.build()
executeJson(Request.Builder().url(httpUrl).post(body).build(), path)
}
suspend fun getLearningNode(id: String, profile: String? = null): Result<JsonObject> =
getJsonObject("/api/learning/node?id=${queryValue(id)}${profileQuerySuffix(profile)}")
suspend fun updateLearningNode(
id: String,
content: String,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
put("content", content)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun deleteLearningNode(id: String, profile: String? = null): Result<JsonObject> =
deleteJsonObjectWithBody(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun selectMemoryProvider(provider: String): Result<JsonObject> =
putJsonObject(
path = "/api/memory/provider",
payload = buildJsonObject { put("provider", provider) },
)
/** Activate an already-configured provider inside the selected upstream profile. */
suspend fun activateMemoryProvider(provider: String, profile: String? = null): Result<JsonObject> =
updateMemoryProviderConfig(provider, JsonObject(emptyMap()), profile)
suspend fun getMemoryProviderConfig(
provider: String,
profile: String? = null,
): Result<JsonObject> = getJsonObject(
"/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
)
suspend fun updateMemoryProviderConfig(
provider: String,
values: JsonObject,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
payload = buildJsonObject { put("values", values) },
)
suspend fun setupMemoryProvider(provider: String): Result<JsonObject> =
postJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/setup",
// Dependency installation is host-global upstream. Do not submit
// profile-owned values through this unscoped route.
payload = buildJsonObject { put("values", JsonObject(emptyMap())) },
)
suspend fun startWhatsAppOnboarding(
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/start",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun getWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
getJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun applyWhatsAppOnboarding(
pairingId: String,
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}/apply",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun cancelWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
deleteJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun setMessagingPlatformEnabled(
platform: String,
enabled: Boolean,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/messaging/platforms/${pathSegment(platform)}${profileQuery(profile)}",
payload = buildJsonObject {
put("enabled", enabled)
put("env", JsonObject(emptyMap()))
put("clear_env", JsonArray(emptyList()))
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun testMessagingPlatform(platform: String, profile: String? = null): Result<JsonObject> =
postJsonObject(
"/api/messaging/platforms/${pathSegment(platform)}/test${profileQuery(profile)}",
)
suspend fun setProfileDescription(name: String, description: String): Result<JsonObject> =
putJsonObject(
path = "/api/profiles/${pathSegment(name)}/description",
@@ -605,15 +883,16 @@ class DashboardApiClient(
)
}
suspend fun getCustomEndpoints(): Result<DashboardCustomEndpoints> =
getJsonObject("/api/providers/custom-endpoints")
suspend fun getCustomEndpoints(profile: String? = null): Result<DashboardCustomEndpoints> =
getJsonObject("/api/providers/custom-endpoints${profileQuery(profile)}")
.mapCatching(::parseCustomEndpoints)
suspend fun saveCustomEndpoint(
draft: DashboardCustomEndpointDraft,
profile: String? = null,
): Result<DashboardCustomEndpoints> =
postJsonObject(
"/api/providers/custom-endpoints",
"/api/providers/custom-endpoints${profileQuery(profile)}",
customEndpointPayload(draft),
).mapCatching(::parseCustomEndpoints)
@@ -634,13 +913,19 @@ class DashboardApiClient(
suspend fun activateCustomEndpoint(
id: String,
profile: String? = null,
): Result<JsonObject> =
postJsonObject("/api/providers/custom-endpoints/${pathSegment(id)}/activate")
postJsonObject(
"/api/providers/custom-endpoints/${pathSegment(id)}/activate${profileQuery(profile)}",
)
suspend fun deleteCustomEndpoint(
id: String,
profile: String? = null,
): Result<DashboardCustomEndpoints> =
deleteJsonObject("/api/providers/custom-endpoints/${pathSegment(id)}")
deleteJsonObject(
"/api/providers/custom-endpoints/${pathSegment(id)}${profileQuery(profile)}",
)
.mapCatching(::parseCustomEndpoints)
suspend fun installMcpCatalogEntry(
@@ -749,9 +1034,157 @@ class DashboardApiClient(
pageSessions.forEach { sessions.putIfAbsent(it.id, it) }
if (pageSessions.size < page.limit) break
}
Result.success(sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)))
Result.success(
enrichSessionWorkState(
sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)),
fixedProfile = profile?.trim()?.takeIf { it.isNotBlank() }
?: DEFAULT_SESSION_PROFILE_SCOPE,
),
)
}
/**
* Read the bounded, authoritative session window across every profile.
* Every usable row must retain its owning profile; rows without one are
* skipped rather than risking a cross-profile transcript or mutation.
*/
suspend fun listAllProfileSessions(
limit: Int = SESSION_LIST_WINDOW_LIMIT,
): Result<List<SessionItem>> = withContext(Dispatchers.IO) {
val boundedLimit = limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)
val result = getJson(
"/api/profiles/sessions?limit=$boundedLimit&offset=0&order=recent" +
"&min_messages=1&archived=include&profile=all",
).mapCatching { root ->
val parsed = json.decodeFromJsonElement(SessionListResponse.serializer(), root)
(parsed.sessions ?: parsed.items ?: parsed.data ?: emptyList())
.filter { it.id.isNotBlank() && !it.profile.isNullOrBlank() }
.distinctBy { "${it.profile}:${it.id}" }
.take(boundedLimit)
}
if (result.isFailure) return@withContext result
Result.success(enrichSessionWorkState(result.getOrThrow(), fixedProfile = null))
}
/**
* Attach the PR a coding session created using the current upstream
* transcript-backed endpoint. Repository and branch already arrive on the
* list row. Missing/older endpoints are deliberately ignored, leaving the
* original rows intact. Active misses retry on a bounded cadence; terminal
* rows get one final scan and resolved associations remain cached.
*/
private suspend fun enrichSessionWorkState(
sessions: List<SessionItem>,
fixedProfile: String?,
): List<SessionItem> {
val candidates = sessions.filter {
it.id.isNotBlank() &&
(!it.gitRepoRoot.isNullOrBlank() || !it.gitBranch.isNullOrBlank() || !it.cwd.isNullOrBlank())
}
val duplicateIds = if (fixedProfile == null) {
candidates.groupingBy { it.id }.eachCount().filterValues { it > 1 }.keys
} else {
emptySet()
}
val now = nowMillis()
val pending = synchronized(sessionPrScanLock) {
candidates.filter { session ->
if (session.id in duplicateIds) return@filter false
val key = sessionWorkKey(session, fixedProfile)
val scannedAt = sessionPrScannedAt[key]
val resolved = sessionPullRequests[key] != null
!resolved && when {
scannedAt == null -> true
session.endedAt != null -> sessionPrScanWasTerminal[key] != true
else -> now - scannedAt >= ACTIVE_SESSION_PR_MISS_TTL_MILLIS
}
}
}
val pendingIds = pending.map { it.id }.distinct()
if (pendingIds.isNotEmpty()) {
val payload = buildJsonObject {
put("ids", JsonArray(pendingIds.map { JsonPrimitive(it) }))
}
val scan = postJsonObject("/api/profiles/sessions/pull-requests", payload)
.mapCatching { root ->
json.decodeFromJsonElement(SessionPullRequestScanResponse.serializer(), root)
}
synchronized(sessionPrScanLock) {
// A legacy 404 is a compatibility outcome, not a session-list failure.
// Avoid hammering an unsupported host on every drawer refresh.
if (scan.isSuccess || sessionPrScanSupported == null) {
sessionPrScanSupported = scan.isSuccess
}
pending.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
sessionPrScannedAt[key] = now
sessionPrScanWasTerminal[key] = session.endedAt != null
scan.getOrNull()?.pullRequests?.get(session.id)?.takeIf {
it.number > 0 && it.url.isNotBlank()
}?.let { pullRequest ->
sessionPullRequests[key] = pullRequest
}
}
}
}
refreshPullRequestStates(candidates, fixedProfile)
val pullRequests = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
return sessions.map { session ->
session.copy(pullRequest = pullRequests[sessionWorkKey(session, fixedProfile)])
}
}
/** Refresh current PR lifecycle state using upstream's repo-scoped GitHub view. */
private suspend fun refreshPullRequestStates(
sessions: List<SessionItem>,
fixedProfile: String?,
) {
if (synchronized(sessionPrScanLock) { sessionPrScanSupported } != true) return
val known = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
sessions.groupBy { (it.gitRepoRoot ?: it.cwd).orEmpty().trim() }
.filterKeys { it.isNotBlank() }
.forEach { (path, repositorySessions) ->
val branches = repositorySessions.mapNotNull { it.gitBranch?.trim() }
.filter { it.isNotBlank() }
.distinct()
val numbers = repositorySessions.mapNotNull {
known[sessionWorkKey(it, fixedProfile)]?.number
}
.filter { it > 0 }
.distinct()
if (branches.isEmpty() && numbers.isEmpty()) return@forEach
val payload = buildJsonObject {
put("path", path)
put("branches", JsonArray(branches.map { JsonPrimitive(it) }))
put("numbers", JsonArray(numbers.map { JsonPrimitive(it) }))
}
val response = postJsonObject("/api/git/review/pr-list", payload)
.mapCatching { root ->
json.decodeFromJsonElement(RepositoryPullRequestListResponse.serializer(), root)
}
.getOrNull()
?: return@forEach
if (!response.ghReady) return@forEach
synchronized(sessionPrScanLock) {
repositorySessions.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
val recovered = sessionPullRequests[key]
val current = response.prs.firstOrNull { pr ->
recovered != null && pr.number == recovered.number
} ?: response.prs.firstOrNull { pr ->
!session.gitBranch.isNullOrBlank() && pr.branch == session.gitBranch
}
if (current != null && current.number > 0 && current.url.isNotBlank()) {
sessionPullRequests[key] = current
}
}
}
}
}
private fun sessionWorkKey(session: SessionItem, fixedProfile: String?): String =
"${fixedProfile ?: session.profile.orEmpty()}\u0000${session.id}"
/**
* A session's message history, scoped to its owning profile via the dashboard
* `GET /api/sessions/{id}/messages?profile=`. Required twin of [listSessions]:
@@ -763,12 +1196,24 @@ class DashboardApiClient(
suspend fun getSessionMessages(
sessionId: String,
profile: String? = null,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>> = withContext(Dispatchers.IO) {
val name = profile?.trim().orEmpty()
val query = if (name.isNotBlank()) "?profile=${pathSegment(name)}" else ""
getJson("/api/sessions/${pathSegment(sessionId)}/messages$query").mapCatching { root ->
val parsed = json.decodeFromJsonElement(MessageListResponse.serializer(), root)
parsed.messages ?: parsed.data ?: parsed.items ?: emptyList()
loadSessionMessages(mode) { page ->
val query = buildList {
add("limit=${page.limit}")
add("offset=${page.offset}")
add("order=${page.order}")
if (name.isNotBlank()) add("profile=${pathSegment(name)}")
}.joinToString(prefix = "?", separator = "&")
getJson("/api/sessions/${pathSegment(sessionId)}/messages$query").mapCatching { root ->
val parsed = json.decodeFromJsonElement(MessageListResponse.serializer(), root)
SessionMessagePage(
messages = parsed.messages ?: parsed.data ?: parsed.items ?: emptyList(),
pagination = parsed.pagination,
payloadChars = root.toString().length,
)
}
}
}
@@ -1062,8 +1507,44 @@ class DashboardApiClient(
}
}
private suspend fun download(
path: String,
operation: String,
openOutput: () -> OutputStream,
): Result<String> =
withContext(Dispatchers.IO) {
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val request = Request.Builder().url(httpUrl).get().build()
try {
okHttpClient.newCall(request).execute().use { response ->
if (!response.isSuccessful) return@withContext Result.failure(apiFailure(response, operation))
val disposition = response.header("Content-Disposition").orEmpty()
val filename = Regex("filename=\\\"?([^\\\";]+)").find(disposition)?.groupValues?.get(1)
?: "hermes-backup.zip"
val body = response.body
val declaredLength = body.contentLength().takeIf { it >= 0 }
if (declaredLength != null && declaredLength > MAX_BACKUP_TRANSFER_BYTES) {
throw IOException("Backup archive exceeds the ${MAX_BACKUP_TRANSFER_BYTES / (1024 * 1024)} MB download limit.")
}
openOutput().use { output ->
body.byteStream().use { input ->
copyBounded(input, output, declaredLength, MAX_BACKUP_TRANSFER_BYTES)
}
}
Result.success(filename)
}
} catch (e: Exception) {
Result.failure(e)
}
}
companion object {
private val JSON_MEDIA = "application/json; charset=utf-8".toMediaType()
private const val DEFAULT_SESSION_PROFILE_SCOPE = "__dashboard_default__"
internal const val ACTIVE_SESSION_PR_MISS_TTL_MILLIS = 60_000L
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
internal const val MAX_BACKUP_TRANSFER_BYTES = 100L * 1024L * 1024L
fun pathSegment(value: String): String =
URLEncoder.encode(value, "UTF-8").replace("+", "%20")
@@ -1121,6 +1602,11 @@ class DashboardApiClient(
return if (trimmed.isBlank()) "" else "?profile=${pathSegment(trimmed)}"
}
private fun profileQuerySuffix(profile: String?): String {
val trimmed = profile?.trim().orEmpty()
return if (trimmed.isBlank()) "" else "&profile=${queryValue(trimmed)}"
}
private fun profileLimitQuery(profile: String?, limit: Int): String {
val params = buildList {
val trimmed = profile?.trim().orEmpty()
@@ -1248,6 +1734,35 @@ class DashboardApiClient(
gatewayMode = root.stringField("gateway_mode"),
gateways = gateways,
componentHealth = parseComponentHealth(root),
memory = parseMemoryStatus(root["memory"] as? JsonObject),
disk = parseDiskStatus(root["disk"] as? JsonObject),
)
}
private fun parseMemoryStatus(obj: JsonObject?): DashboardMemoryStatus? {
obj ?: return null
val pressure = obj.stringField("pressure")?.lowercase() ?: return null
return DashboardMemoryStatus(
pressure = pressure,
gatewayRssMb = obj.intField("gateway_rss_mb"),
systemTotalMb = obj.intField("system_total_mb"),
systemAvailableMb = obj.intField("system_available_mb"),
swapUsedMb = obj.intField("swap_used_mb"),
sampledAt = obj.stringField("sampled_at"),
lastBootUnclean = obj.booleanField("last_boot_unclean") ?: false,
lastBootSuspectedOom = obj.booleanField("last_boot_suspected_oom") ?: false,
bootId = obj.stringField("boot_id"),
)
}
private fun parseDiskStatus(obj: JsonObject?): DashboardDiskStatus? {
obj ?: return null
val pressure = obj.stringField("pressure")?.lowercase() ?: return null
return DashboardDiskStatus(
pressure = pressure,
totalMb = obj.intField("total_mb"),
freeMb = obj.intField("free_mb"),
usedPercent = (obj["used_percent"] as? JsonPrimitive)?.contentOrNull?.toDoubleOrNull(),
)
}
File diff suppressed because it is too large Load Diff
@@ -207,7 +207,11 @@ class GatewayEventMapper(
}
else -> syntheticToolId(name)
}
val argsPreview = payload.string("args_text")
val argsPreview = payload?.get("args")
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
?: payload.string("args_text")
?.takeIf { it.isNotBlank() }
?: payload.string("context")?.takeIf { it.isNotBlank() }
callbacks.onToolCallStart(toolId, name, argsPreview)
@@ -294,6 +298,7 @@ class GatewayEventMapper(
// text; thinking/progress carry text only.
preview = payload.string("tool_preview") ?: payload.string("text"),
durationSeconds = payload.double("duration_seconds"),
subagentId = payload.string("subagent_id"),
),
)
}
@@ -439,15 +444,26 @@ class GatewayEventMapper(
}
fun interactionRequest(type: String, payload: JsonObject?): GatewayAsk? = when (type) {
"clarify.request" -> GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull }
?.takeIf { it.isNotEmpty() },
timeoutSeconds = CLARIFY_TIMEOUT_SECONDS,
)
"clarify.request" -> {
val choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.trim() }
?.filter { it.isNotEmpty() }
?.distinct()
?.take(MAX_CLARIFY_CHOICES)
?.takeIf { it.isNotEmpty() }
GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = choices,
multiSelect = payload.boolean("multi_select") == true && choices != null,
// Current upstream owns expiry through clarify.expire and
// does not advertise its configurable deadline. Never
// invent a local deadline; consume future additive
// metadata only when it is present and positive.
timeoutSeconds = payload.int("timeout_seconds")?.coerceAtLeast(0) ?: 0,
)
}
"approval.request" -> GatewayAsk(
kind = GatewayAsk.Kind.APPROVAL,
@@ -556,9 +572,9 @@ class GatewayEventMapper(
}
}
// Upstream `_block()` timeouts per ask kind (server.py) — the blocked thread
// resolves to "" when these elapse. Approval has none (session-scoped).
private const val CLARIFY_TIMEOUT_SECONDS = 300
// Upstream clarify tool accepts at most four choices. Sudo/secret retain fixed
// `_block()` timeouts; clarify is configurable and expires authoritatively.
private const val MAX_CLARIFY_CHOICES = 4
private const val SUDO_TIMEOUT_SECONDS = 120
private const val SECRET_TIMEOUT_SECONDS = 300
@@ -578,6 +594,12 @@ private fun JsonObject?.approvalChoices(): List<String>? =
(this?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.lowercase() }
?.filter { it in setOf("once", "session", "always", "deny") }
// Scope-denial flags are authoritative. Current upstream protected-
// instruction requests set both flags false, but gateway event builders
// can still include the broader session choice in `choices`.
// Never offer a scope the request explicitly forbids.
?.filterNot { it == "session" && this.boolean("allow_session") == false }
?.filterNot { it == "always" && this.boolean("allow_permanent") == false }
?.distinct()
?.takeIf { it.isNotEmpty() }
@@ -218,13 +218,15 @@ data class GatewayAsk(
val text: String,
/** Server-advertised answers for clarify and approval requests. */
val choices: List<String>? = null,
/** Clarify-only: several advertised choices may be returned together. */
val multiSelect: Boolean = false,
/** Approval-only: the smart observer denied and the owner may override once. */
val smartDenied: Boolean = false,
/** Secret-only: the env var the value will be stored under. */
val envVar: String? = null,
/**
* Upstream blocking timeout (clarify/secret 300s, sudo 120s). 0 means no
* countdown — approvals are session-scoped and never expire on their own.
* Server-advertised blocking timeout. 0 means no client countdown; the
* authoritative `*.expire` event still retires the interaction.
*/
val timeoutSeconds: Int,
) {
@@ -270,6 +272,7 @@ data class GatewaySubagentEvent(
val toolName: String? = null,
val preview: String? = null,
val durationSeconds: Double? = null,
val subagentId: String? = null,
) {
enum class Phase { START, THINKING, TOOL, PROGRESS, COMPLETE }
}
@@ -19,6 +19,7 @@ import com.hermesandroid.relay.network.upstream.models.SkillListResponse
import com.hermesandroid.relay.network.upstream.models.UsageInfo
import com.hermesandroid.relay.util.TurnLatencyTracer
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.withContext
import kotlinx.serialization.encodeToString
import kotlinx.serialization.Serializable
@@ -431,10 +432,12 @@ private class RetryingEventSource(
class HermesApiClient(
baseUrl: String,
private val apiKey: String,
httpClient: OkHttpClient? = null,
private val json: Json = Json {
ignoreUnknownKeys = true
isLenient = true
}
},
okHttpClient: OkHttpClient? = null,
) {
@Volatile
private var lastCapabilities: ServerCapabilities? = null
@@ -478,7 +481,7 @@ class HermesApiClient(
private val mainHandler = Handler(Looper.getMainLooper())
private val client: OkHttpClient = OkHttpClient.Builder()
private val client: OkHttpClient = httpClient ?: okHttpClient ?: OkHttpClient.Builder()
.readTimeout(5, TimeUnit.MINUTES)
.connectTimeout(10, TimeUnit.SECONDS)
.build()
@@ -713,19 +716,34 @@ class HermesApiClient(
}
}
suspend fun getMessages(sessionId: String): List<MessageItem> = withContext(Dispatchers.IO) {
try {
val request = authRequest("$baseUrl/api/sessions/$sessionId/messages")
.get()
.build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) return@withContext emptyList()
val body = response.body?.string() ?: return@withContext emptyList()
val parsed = json.decodeFromString<MessageListResponse>(body)
parsed.data ?: parsed.items ?: parsed.messages ?: emptyList()
suspend fun getMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): List<MessageItem> = withContext(Dispatchers.IO) {
loadSessionMessages(mode) { page ->
runCatching {
val url = "$baseUrl/api/sessions/$sessionId/messages".toHttpUrlOrNull()
?.newBuilder()
?.addQueryParameter("limit", page.limit.toString())
?.addQueryParameter("offset", page.offset.toString())
?.addQueryParameter("order", page.order)
?.build()
?: error("invalid session messages URL")
val request = authRequest(url.toString()).get().build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) error("HTTP ${response.code}")
val body = response.body?.string() ?: error("empty response body")
val parsed = json.decodeFromString<MessageListResponse>(body)
SessionMessagePage(
messages = parsed.data ?: parsed.items ?: parsed.messages ?: emptyList(),
pagination = parsed.pagination,
payloadChars = body.length,
)
}
}
} catch (e: Exception) {
Log.w(TAG, "Failed to get messages: ${e.message}")
}.getOrElse { error ->
if (error is CancellationException) throw error
Log.w(TAG, "Failed to get messages: ${error.message}")
emptyList()
}
}
@@ -140,7 +140,16 @@ class NativeDashboardAuthClient(
.addQueryParameter("code_challenge_method", "S256")
.addQueryParameter("redirect_uri", redirectUri)
.addQueryParameter("state", state)
.apply { provider?.takeIf(String::isNotBlank)?.let { addQueryParameter("provider", it) } }
// Match the official Desktop client for Nous-hosted gateways: the
// gateway selects its single native-eligible provider. The provider
// name advertised to UI clients is presentation/configuration data,
// not a stable native-broker identifier. Other providers retain the
// explicit selector for direct client use and tests.
.apply {
provider
?.takeIf { it.isNotBlank() && !it.equals("nous", ignoreCase = true) }
?.let { addQueryParameter("provider", it) }
}
.build()
.toString()
val generation = NativeTokenRefreshCoordinator.beginAuthorization(
@@ -22,7 +22,7 @@ private const val CALLBACK_PATH = "/callback"
private const val MAX_REQUEST_LINE_BYTES = 8 * 1024
private const val MAX_HEADER_BYTES = 16 * 1024
private const val ACCEPT_POLL_MILLIS = 500
internal const val DEFAULT_NATIVE_SIGN_IN_TIMEOUT_MILLIS = 2 * 60 * 1000L
internal const val DEFAULT_NATIVE_SIGN_IN_TIMEOUT_MILLIS = 5 * 60 * 1000L
internal val NATIVE_SIGN_IN_RETURN_URI = "${BuildConfig.APPLICATION_ID}://return"
private enum class CallbackPage(
@@ -46,6 +46,48 @@ private enum class CallbackPage(
message = "No session details were saved from this attempt.",
guidance = "Return to Hermes Relay and start sign-in again.",
),
AuthorizationRejected(
modifier = "failure",
eyebrow = "Provider sign-in",
title = "Sign-in was not completed",
message = "The provider returned without an approved authorization for Hermes.",
guidance = "Return to Hermes Relay and start again if you still want to sign in.",
),
CodeRejected(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hermes rejected the sign-in code",
message = "Google sign-in finished, but hosted Hermes could not exchange its one-time callback code for a session.",
guidance = "Return to Hermes Relay and start a fresh sign-in attempt.",
),
GatewayUnavailable(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hosted Hermes could not finish sign-in",
message = "The callback reached Hermes Relay, but the hosted Hermes sign-in service was unavailable.",
guidance = "Return to Hermes Relay, wait a moment, and try again.",
),
TransportFailure(
modifier = "failure",
eyebrow = "Secure sign-in connection",
title = "Could not reach hosted Hermes",
message = "Google sign-in finished, but the secure connection back to hosted Hermes was interrupted.",
guidance = "Return to Hermes Relay and retry on a stable connection.",
),
ResponseUnsupported(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hermes returned an unsupported session",
message = "The hosted gateway answered, but its sign-in response was not compatible with this app.",
guidance = "Return to Hermes Relay and check for app and hosted Hermes updates.",
),
SessionStorageFailure(
modifier = "failure",
eyebrow = "Secure session storage",
title = "The session could not be saved",
message = "Google sign-in finished, but Android could not securely save the Hermes session on this device.",
guidance = "Return to Hermes Relay and try again. If it repeats, check the app's diagnostics.",
),
Rejected(
modifier = "rejected",
eyebrow = "Protected callback",
@@ -194,14 +236,14 @@ class NativeDashboardSignInCoordinator(
writeResponse(
socket,
status = "400 Bad Request",
page = CallbackPage.Failure,
page = CallbackPage.AuthorizationRejected,
)
throw error
} catch (error: Exception) {
writeResponse(
socket,
status = "400 Bad Request",
page = CallbackPage.Failure,
page = callbackFailurePage(error),
)
throw error
}
@@ -296,6 +338,20 @@ class NativeDashboardSignInCoordinator(
}
}
private fun callbackFailurePage(error: Throwable): CallbackPage {
val stage = nativeDashboardSignInFailureStage(error)
return when {
stage == "token_http_400" -> CallbackPage.CodeRejected
stage == "callback_error" -> CallbackPage.AuthorizationRejected
stage == "token_http_429" || stage.startsWith("token_http_5") ->
CallbackPage.GatewayUnavailable
stage == "token_shape" -> CallbackPage.ResponseUnsupported
stage == "token_store" -> CallbackPage.SessionStorageFailure
stage.startsWith("token_transport") -> CallbackPage.TransportFailure
else -> CallbackPage.Failure
}
}
private fun callbackPageHtml(page: CallbackPage): String = """
<!doctype html>
<html lang="en">
@@ -0,0 +1,78 @@
package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.MessagePagination
import kotlinx.coroutines.CancellationException
/** Explicit transcript read intent for Hermes' bounded messages endpoint. */
enum class SessionMessageLoadMode {
/** One bounded newest-first window, returned in chronological order. */
LATEST,
/** Every page, oldest first, subject to Android memory safety bounds. */
COMPLETE,
}
internal const val SESSION_MESSAGE_PAGE_SIZE = 500
private const val MAX_COMPLETE_TRANSCRIPT_MESSAGES = 50_000
private const val MAX_COMPLETE_TRANSCRIPT_PAYLOAD_CHARS = 32_000_000
internal data class SessionMessagePageRequest(
val limit: Int = SESSION_MESSAGE_PAGE_SIZE,
val offset: Int = 0,
val order: String,
)
internal data class SessionMessagePage(
val messages: List<MessageItem>,
val pagination: MessagePagination?,
val payloadChars: Int,
)
internal class SessionTranscriptTooLargeException(message: String) : IllegalStateException(message)
/** Shared API-server/dashboard pagination contract. Legacy unpaginated envelopes remain valid. */
internal suspend fun loadSessionMessages(
mode: SessionMessageLoadMode,
fetchPage: suspend (SessionMessagePageRequest) -> Result<SessionMessagePage>,
): Result<List<MessageItem>> {
return try {
val order = if (mode == SessionMessageLoadMode.LATEST) "latest" else "oldest"
val collected = ArrayList<MessageItem>()
var offset = 0
var payloadChars = 0L
while (true) {
val request = SessionMessagePageRequest(offset = offset, order = order)
val page = fetchPage(request).getOrThrow()
payloadChars += page.payloadChars
if (payloadChars > MAX_COMPLETE_TRANSCRIPT_PAYLOAD_CHARS) {
throw SessionTranscriptTooLargeException(
"Session transcript exceeds Android's 32 MB safe-load limit",
)
}
if (collected.size + page.messages.size > MAX_COMPLETE_TRANSCRIPT_MESSAGES) {
throw SessionTranscriptTooLargeException(
"Session transcript exceeds Android's 50,000-message safe-load limit",
)
}
collected += page.messages
if (mode == SessionMessageLoadMode.LATEST) break
// Older Hermes returned one unpaginated complete envelope. Never issue
// a speculative second request against that contract.
val pagination = page.pagination ?: break
val returned = pagination.returned ?: page.messages.size
if (page.messages.isEmpty() || returned < request.limit || page.messages.size < request.limit) break
val nextOffset = offset + page.messages.size
if (nextOffset <= offset) break
offset = nextOffset
}
Result.success(collected)
} catch (error: CancellationException) {
throw error
} catch (error: Throwable) {
Result.failure(error)
}
}
@@ -1,21 +1,27 @@
package com.hermesandroid.relay.network.upstream.models
import com.hermesandroid.relay.data.MessageReaction
import kotlinx.serialization.ExperimentalSerializationApi
import kotlinx.serialization.KSerializer
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.SerializationException
import kotlinx.serialization.descriptors.PrimitiveKind
import kotlinx.serialization.descriptors.PrimitiveSerialDescriptor
import kotlinx.serialization.encoding.Decoder
import kotlinx.serialization.encoding.Encoder
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonDecoder
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonEncoder
import kotlinx.serialization.json.JsonNull
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.doubleOrNull
import kotlinx.serialization.json.jsonArray
import kotlinx.serialization.json.jsonPrimitive
import kotlinx.serialization.json.longOrNull
import java.time.Instant
/**
@@ -76,6 +82,56 @@ object FlexibleIdNonNullSerializer : KSerializer<String> {
}
}
/** Unknown-safe durable SQLite row id used by current Gateway history. */
@OptIn(ExperimentalSerializationApi::class)
object FlexibleLongSerializer : KSerializer<Long?> {
override val descriptor = PrimitiveSerialDescriptor("FlexibleLong", PrimitiveKind.LONG)
override fun deserialize(decoder: Decoder): Long? {
return try {
val jsonDecoder = decoder as? JsonDecoder
?: return decoder.decodeLong()
(jsonDecoder.decodeJsonElement() as? JsonPrimitive)?.longOrNull
} catch (_: Exception) {
null
}
}
override fun serialize(encoder: Encoder, value: Long?) {
if (value != null) encoder.encodeLong(value) else encoder.encodeNull()
}
}
/**
* Dashboard versions may expose SQLite JSON columns either as an object or as
* their raw JSON string. Normalize both shapes so persisted presentation data
* (notably message reactions) survives a history reload on every supported
* upstream version.
*/
object FlexibleJsonObjectSerializer : KSerializer<JsonObject?> {
override val descriptor = JsonObject.serializer().descriptor
override fun deserialize(decoder: Decoder): JsonObject? {
return try {
val jsonDecoder = decoder as? JsonDecoder ?: return null
when (val element = jsonDecoder.decodeJsonElement()) {
is JsonObject -> element
is JsonPrimitive -> element.content.takeIf { it.isNotBlank() }
?.let { Json.parseToJsonElement(it) as? JsonObject }
else -> null
}
} catch (_: Exception) {
null
}
}
override fun serialize(encoder: Encoder, value: JsonObject?) {
val jsonEncoder = encoder as? JsonEncoder
?: throw SerializationException("FlexibleJsonObjectSerializer requires JSON")
jsonEncoder.encodeJsonElement(value ?: JsonNull)
}
}
/** Timestamp serializer for Hermes session metadata.
*
* Upstream currently returns epoch seconds for `started_at` / `last_active`;
@@ -113,6 +169,32 @@ object FlexibleTimestampSerializer : KSerializer<Double?> {
}
}
/**
* Boolean serializer for session flags backed by SQLite integer columns.
*
* Older Dashboard responses can expose those columns as `0` / `1` instead of
* JSON booleans. Accept the equivalent primitive forms without making arbitrary
* numbers or strings truthy, and always serialize back to a real JSON boolean.
*/
object FlexibleBooleanSerializer : KSerializer<Boolean> {
override val descriptor = PrimitiveSerialDescriptor("FlexibleBoolean", PrimitiveKind.BOOLEAN)
override fun deserialize(decoder: Decoder): Boolean {
val jsonDecoder = decoder as? JsonDecoder ?: return decoder.decodeBoolean()
val element = jsonDecoder.decodeJsonElement()
val value = (element as? JsonPrimitive)?.content?.trim()?.lowercase()
return when (value) {
"true", "1" -> true
"false", "0" -> false
else -> throw SerializationException("Expected a boolean-compatible value, got $element")
}
}
override fun serialize(encoder: Encoder, value: Boolean) {
encoder.encodeBoolean(value)
}
}
// --- Session CRUD responses ---
@Serializable
@@ -142,6 +224,8 @@ data class SessionItem(
val preview: String? = null,
val model: String? = null,
val source: String? = null,
/** Owning profile on the cross-profile `/api/profiles/sessions` endpoint. */
val profile: String? = null,
@SerialName("started_at")
@Serializable(with = FlexibleTimestampSerializer::class)
val startedAt: Double? = null,
@@ -164,15 +248,50 @@ data class SessionItem(
@SerialName("tool_call_count") val toolCallCount: Int? = null,
@SerialName("input_tokens") val inputTokens: Int? = null,
@SerialName("output_tokens") val outputTokens: Int? = null,
@SerialName("has_model_config") val hasModelConfig: Boolean = false,
@SerialName("actual_cost_usd") val actualCostUsd: Double? = null,
@SerialName("estimated_cost_usd") val estimatedCostUsd: Double? = null,
@SerialName("is_active") val isActive: Boolean = false,
@SerialName("has_model_config")
@Serializable(with = FlexibleBooleanSerializer::class)
val hasModelConfig: Boolean = false,
/** Durable flags returned by current Dashboard and API-server session resources. */
@Serializable(with = FlexibleBooleanSerializer::class)
val pinned: Boolean = false,
@Serializable(with = FlexibleBooleanSerializer::class)
val archived: Boolean = false,
/** Optional workspace metadata added by newer Dashboard session lists. */
val cwd: String? = null,
@SerialName("git_branch") val gitBranch: String? = null,
@SerialName("git_repo_root") val gitRepoRoot: String? = null,
/** Best-effort association from the Dashboard's read-only transcript scan. */
val pullRequest: SessionPullRequest? = null,
) {
val resolvedLastActivity: Double?
get() = lastActive ?: lastActivity ?: lastActivityAt ?: updatedAt
}
@Serializable
data class SessionPullRequest(
val number: Int,
val url: String,
val branch: String? = null,
val state: String? = null,
val draft: Boolean = false,
val title: String? = null,
)
@Serializable
data class SessionPullRequestScanResponse(
@SerialName("pull_requests") val pullRequests: Map<String, SessionPullRequest> = emptyMap(),
val scanned: List<String> = emptyList(),
)
@Serializable
data class RepositoryPullRequestListResponse(
val ghReady: Boolean = false,
val prs: List<SessionPullRequest> = emptyList(),
)
@Serializable
data class CreateSessionRequest(
val title: String? = null,
@@ -244,7 +363,16 @@ data class MessageListResponse(
val items: List<MessageItem>? = null,
val messages: List<MessageItem>? = null, // alternate key
val data: List<MessageItem>? = null, // upstream /api/sessions/{id}/messages list envelope
val total: Int? = null
val total: Int? = null,
val pagination: MessagePagination? = null,
)
@Serializable
data class MessagePagination(
val limit: Int? = null,
val offset: Int? = null,
val order: String? = null,
val returned: Int? = null,
)
@Serializable
@@ -254,6 +382,9 @@ data class MessageItem(
@SerialName("session_id")
@Serializable(with = FlexibleIdSerializer::class)
val sessionId: String? = null,
@SerialName("row_id")
@Serializable(with = FlexibleLongSerializer::class)
val rowId: Long? = null,
val role: String,
val content: JsonElement? = null,
@SerialName("tool_calls") val toolCalls: JsonElement? = null,
@@ -264,7 +395,9 @@ data class MessageItem(
val timestamp: Double? = null,
@SerialName("finish_reason") val finishReason: String? = null,
@SerialName("display_kind") val displayKind: String? = null,
@SerialName("display_metadata") val displayMetadata: JsonObject? = null,
@SerialName("display_metadata")
@Serializable(with = FlexibleJsonObjectSerializer::class)
val displayMetadata: JsonObject? = null,
// Reasoning persisted with the assistant message (upstream serializes
// both names; reasoning is the canonical one). Restored into
// ChatMessage.thinkingContent so the Thought-process block survives a
@@ -272,11 +405,24 @@ data class MessageItem(
val reasoning: String? = null,
@SerialName("reasoning_content") val reasoningContent: String? = null,
) {
/**
* Dashboard history uses the SQLite row id as numeric `id`; Gateway
* history exposes the same value explicitly as `row_id`. Match Desktop by
* accepting either representation so persisted rows remain directly
* reactable after reload.
*/
val resolvedRowId: Long?
get() = rowId ?: id?.toLongOrNull()
/** Reasoning text under whichever field name the server used. */
val resolvedReasoning: String?
get() = reasoning?.takeIf { it.isNotBlank() }
?: reasoningContent?.takeIf { it.isNotBlank() }
/** Persisted tapbacks stored by Hermes in display_metadata.reactions. */
val reactions: List<MessageReaction>
get() = parseMessageReactions(displayMetadata?.get("reactions"))
/** Extract content as plain text string. Handles both string and array-of-parts formats. */
val contentText: String?
get() = when (content) {
@@ -304,6 +450,21 @@ data class MessageItem(
}
}
fun parseMessageReactions(element: JsonElement?): List<MessageReaction> =
(element as? JsonArray).orEmpty().mapNotNull { raw ->
val reaction = raw as? JsonObject ?: return@mapNotNull null
val emoji = (reaction["emoji"] as? JsonPrimitive)?.content?.takeIf { it.isNotBlank() }
?: return@mapNotNull null
val author = (reaction["author"] as? JsonPrimitive)?.content
?.takeIf { it == "user" || it == "agent" }
?: return@mapNotNull null
MessageReaction(
emoji = emoji,
author = author,
at = (reaction["at"] as? JsonPrimitive)?.doubleOrNull ?: 0.0,
)
}
// --- SSE streaming events from /api/sessions/{id}/chat/stream ---
//
// Hermes WebAPI event types (from server source):
@@ -9,6 +9,7 @@ import android.content.Context
import android.content.Intent
import android.content.pm.PackageManager
import android.os.Build
import android.net.Uri
import android.util.Log
import androidx.core.app.NotificationCompat
import androidx.core.app.NotificationManagerCompat
@@ -47,10 +48,13 @@ object ProactiveMessageNotifier {
/**
* Tap route — opens Chat, where the message lives as a Thread. Must match
* `Screen.Chat.route()` in RelayApp. Routed via the EXTRA_NAV_ROUTE deep-link
* path (MainActivity → NavRouteRequest → RelayApp collector). Opening the
* exact Thread by chat_id is a follow-up (see TODO).
* path (MainActivity → NavRouteRequest → RelayApp collector), carrying the
* `chat_id` so RelayApp opens the exact real or provisional Thread.
*/
private const val TAP_ROUTE = "chat"
private fun tapRoute(chatId: String?): String =
chatId?.takeIf { it.isNotBlank() }
?.let { "chat?proactiveChatId=${Uri.encode(it)}" }
?: "chat"
/**
* Post (or replace) a proactive-message notification.
@@ -80,7 +84,7 @@ object ProactiveMessageNotifier {
val tapIntent = Intent(context, MainActivity::class.java).apply {
flags = Intent.FLAG_ACTIVITY_NEW_TASK or Intent.FLAG_ACTIVITY_CLEAR_TOP
putExtra(MainActivity.EXTRA_NAV_ROUTE, TAP_ROUTE)
putExtra(MainActivity.EXTRA_NAV_ROUTE, tapRoute(chatId))
}
val pendingFlags = PendingIntent.FLAG_UPDATE_CURRENT or PendingIntent.FLAG_IMMUTABLE
// Distinct requestCode per slot so each notification gets its own
@@ -90,6 +90,29 @@ object ReliabilityCenter {
writer.execute { runCatching { target.append(report) } }
}
/** Persist a bounded, content-free checkpoint before a user-requested chat reset. */
fun recordSessionCheckpoint(context: Context, evidence: SessionResetEvidence) {
initialize(context)
val report = ReliabilityReport(
reportId = ReliabilityReport.newId("checkpoint"),
appSessionId = appSessionId,
timeIso = Instant.now().toString(),
kind = ReliabilityKind.SessionCheckpoint,
owner = ReliabilityOwner.Android,
severity = ReliabilitySeverity.Info,
summary = "Chat context reset",
recovery = "The prior context remains on Hermes when it had a stored session.",
reportRecommended = false,
technicalDetail = evidence.technicalDetail(),
routeRole = evidence.transport,
environment = environment(),
)
// A pre-reset checkpoint is useful only if it lands before state is
// replaced. The store is tiny and atomically rewritten, so persist it
// synchronously instead of queueing behind later failures.
runCatching { store?.append(report) }
}
fun reports(context: Context): List<ReliabilityReport> {
initialize(context)
return store?.readAll().orEmpty()
@@ -15,6 +15,7 @@ const val RELIABILITY_SCHEMA_VERSION = 1
enum class ReliabilityKind {
FatalCrash,
AnrSignal,
SessionCheckpoint,
RecoverableProductError,
Connectivity,
Authentication,
@@ -0,0 +1,33 @@
package com.hermesandroid.relay.reliability
/**
* Content-free evidence captured immediately before Android replaces a chat
* context. Deliberately excludes prompts, message text, IDs, profile names,
* URLs, paths, attachments, and tool arguments/results.
*/
data class SessionResetEvidence(
val reason: String,
val transport: String,
val messageCount: Int,
val toolCount: Int,
val queuedCount: Int,
val pendingAttachmentCount: Int,
val hadStoredSession: Boolean,
val turnActive: Boolean,
val askPending: Boolean,
) {
fun technicalDetail(): String = buildString {
appendLine("reason=${reason.safeToken()}")
appendLine("transport=${transport.safeToken()}")
appendLine("messages=${messageCount.coerceAtLeast(0)}")
appendLine("tools=${toolCount.coerceAtLeast(0)}")
appendLine("queued=${queuedCount.coerceAtLeast(0)}")
appendLine("pending_attachments=${pendingAttachmentCount.coerceAtLeast(0)}")
appendLine("had_stored_session=$hadStoredSession")
appendLine("turn_active=$turnActive")
append("ask_pending=$askPending")
}
private fun String.safeToken(): String =
lowercase().replace(Regex("[^a-z0-9_.-]"), "_").take(40).ifBlank { "unknown" }
}
@@ -176,7 +176,9 @@ internal class HermesRuntimeBinder(
chat.setDisplayProfileProvider { connection.effectiveDisplayProfile.value }
chat.setDisplayAliasProvider { connection.profileDisplayAlias.value }
chat.setProfileSessionLister { connection.listProfileScopedSessions() }
chat.setProfileMessageLoader(connection::loadProfileScopedMessages)
chat.setProfileMessageLoaderWithMode { profileName, sessionId, mode ->
connection.loadProfileScopedMessages(profileName, sessionId, mode)
}
chat.setDashboardConfigLoader { connection.loadActiveDashboardConfig() }
chat.profileSessionDeleter = connection::deleteProfileScopedSession
chat.profileSessionRenamer = connection::renameProfileScopedSession
@@ -96,6 +96,7 @@ import com.hermesandroid.relay.ui.components.avatar.LocalFloatingPet
import com.hermesandroid.relay.ui.components.avatar.LocalPetPlaybackSpeed
import com.hermesandroid.relay.ui.components.avatar.LocalPetStabilize
import com.hermesandroid.relay.ui.components.avatar.PetLoader
import com.hermesandroid.relay.ui.components.avatar.toAvatar
import com.hermesandroid.relay.ui.components.avatar.SphereAvatar
import com.hermesandroid.relay.ui.components.avatar.resolveBackgroundAvatar
import com.hermesandroid.relay.ui.components.FloatingPetCompanion
@@ -116,6 +117,7 @@ import com.hermesandroid.relay.ui.components.PowerFeatureGateStatus
import com.hermesandroid.relay.ui.components.RelayStatusStrip
import com.hermesandroid.relay.ui.components.UnattendedGlobalBanner
import com.hermesandroid.relay.ui.components.UpdateAvailableBanner
import com.hermesandroid.relay.ui.components.HostResourcePressureBanner
import com.hermesandroid.relay.ui.components.rememberUpdateAvailability
import com.hermesandroid.relay.ui.components.resolveChatTransportStatus
import com.hermesandroid.relay.ui.components.WhatsNewDialog
@@ -336,17 +338,20 @@ sealed class Screen(
// NavHost, and the NavigationBarItem click must navigate via [route]()
// so no unresolved `{openAgentSheet}` leaks into the destination.
data object Chat : Screen(
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}",
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}" +
"&proactiveChatId={proactiveChatId}",
"Chat",
Icons.AutoMirrored.Filled.Chat,
) {
const val ARG_OPEN_AGENT_SHEET: String = "openAgentSheet"
const val ARG_SESSION_ID: String = "sessionId"
const val ARG_PROFILE: String = "profile"
const val ARG_PROACTIVE_CHAT_ID: String = "proactiveChatId"
fun route(
openAgentSheet: Boolean = false,
sessionId: String? = null,
profile: String? = null,
proactiveChatId: String? = null,
): String {
val params = buildList {
if (openAgentSheet) add("$ARG_OPEN_AGENT_SHEET=true")
@@ -356,6 +361,9 @@ sealed class Screen(
profile?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROFILE=${android.net.Uri.encode(it)}")
}
proactiveChatId?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROACTIVE_CHAT_ID=${android.net.Uri.encode(it)}")
}
}
return if (params.isEmpty()) "chat" else "chat?${params.joinToString("&")}"
}
@@ -618,21 +626,11 @@ fun RelayApp() {
val standardVoiceAvailability by connectionViewModel.standardVoiceAvailability.collectAsState()
val relayVoiceReady by connectionViewModel.relayVoiceReady.collectAsState()
// Profile Inspector client. Shares the same lazy relay URL + bearer
// token providers as the voice client so any rotation/re-pair is
// automatically picked up on the next fetch. Process-stable via
// remember {} so the OkHttpClient isn't rebuilt on recomposition.
val profileInspectorClient = remember {
RelayProfileInspectorClient(
okHttpClient = okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build(),
relayUrlProvider = { connectionViewModel.effectiveRelayUrl.value },
sessionTokenProvider = {
(connectionViewModel.authState.value as? AuthState.Paired)?.token
},
)
val profileInspectorHttpClient = remember {
okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build()
}
// === PHASE3-status: sync granular phone-status settings to chat ===
val appContextEnabled by connectionViewModel.appContextEnabled.collectAsState()
@@ -745,8 +743,12 @@ fun RelayApp() {
) {
value = withContext(Dispatchers.IO) { PetLoader.loadPets(sphereContext) }
}
val activeFloatingPet = remember(floatingPetId, availablePets) {
availablePets.firstOrNull { it.id == floatingPetId }
val hermesPetState by connectionViewModel.hermesPetState.collectAsState()
val upstreamProfilePet = remember(hermesPetState.active) {
hermesPetState.active?.toAvatar()
}
val activeFloatingPet = remember(floatingPetId, availablePets, upstreamProfilePet) {
availablePets.firstOrNull { it.id == floatingPetId } ?: upstreamProfilePet
}
var floatingPetMenuExpanded by remember(activeFloatingPet?.id) { mutableStateOf(false) }
val activeBackgroundAvatar = remember(backgroundAvatarId, availablePets) {
@@ -891,6 +893,7 @@ fun RelayApp() {
// ChatViewModel isn't available where ConnectionViewModel builds the
// handler, so the session sink is set here at the app root where both
// ViewModels are in scope.
val proactiveSummaryResources = LocalContext.current.resources
LaunchedEffect(connectionViewModel, chatViewModel) {
connectionViewModel.proactiveMessageHandler.toSession = { msg ->
val text = buildString {
@@ -899,6 +902,15 @@ fun RelayApp() {
}
chatViewModel.injectProactiveMessage(text)
}
connectionViewModel.proactiveMessageHandler.onBacklogDelivered = { count ->
UiMessageBus.info(
proactiveSummaryResources.getQuantityString(
R.plurals.proactive_messages_arrived_while_away,
count,
count,
),
)
}
// Agent Thread reply path: a send from the chat composer while a
// source=phone Thread is open routes over the relay proactive
// channel (continues the gateway phone session) instead of a normal
@@ -910,7 +922,8 @@ fun RelayApp() {
chatViewModel.onProactiveReplyAck(clientMsgId, status)
}
// Unified Threads: render an inbound agent message inline in the open
// Thread (suppressing the notification/inbox) when it belongs there.
// Thread when it belongs there. Surfacing semantics still decide
// independently whether a system notification is also required.
connectionViewModel.proactiveMessageHandler.injectIntoThread = { msg ->
chatViewModel.injectThreadMessage(msg)
}
@@ -1387,6 +1400,22 @@ fun RelayApp() {
// user always knows the chat is sample data with no live server, and
// can exit into the real Connect flow with one tap.
val showDemoBanner = isDemoMode && !voiceUiState.voiceMode
val hostResourcePressure by connectionViewModel.hostResourcePressure.collectAsState()
val showHostResourcePressure = hostResourcePressure.needsAttention &&
!isDemoMode && !voiceUiState.voiceMode && !showStartupSphere
val hostResourcePressureText = buildList {
if (hostResourcePressure.lastBootSuspectedOom) {
add(stringResource(R.string.host_resource_recent_oom))
}
when (hostResourcePressure.memoryPressure) {
"critical" -> add(stringResource(R.string.host_resource_memory_critical))
"elevated" -> add(stringResource(R.string.host_resource_memory_elevated))
}
when (hostResourcePressure.diskPressure) {
"critical" -> add(stringResource(R.string.host_resource_disk_critical))
"elevated" -> add(stringResource(R.string.host_resource_disk_elevated))
}
}.distinct().joinToString(" ")
// Transient info/status banner (UiMessageBus) — thin, takes its own
// space, auto-dismisses. Folded into the inset accounting below so a
// child TopAppBar doesn't double-pad when this banner owns the top edge.
@@ -1493,6 +1522,18 @@ fun RelayApp() {
DemoModeBanner(onConnect = exitDemoToConnect)
}
AnimatedVisibility(
visible = showHostResourcePressure,
enter = fadeIn(tween(200)),
exit = fadeOut(tween(200)),
) {
HostResourcePressureBanner(
text = hostResourcePressureText,
critical = hostResourcePressure.critical,
includeStatusBarPadding = !showUnattendedBanner && !showDemoBanner,
)
}
// Connection status intentionally has NO top-of-screen surface (no
// banner, no strip, no float). Chat/agent status rides the chat header
// subtitle; the relay socket rides the bottom RelayStatusStrip cue. See
@@ -1503,7 +1544,7 @@ fun RelayApp() {
// that banner already padded the top — avoid double padding).
MessageBannerHost(
includeStatusBarPadding =
!showUnattendedBanner && !showDemoBanner,
!showUnattendedBanner && !showDemoBanner && !showHostResourcePressure,
)
// The update banner AND the connection-status indicator now render as
@@ -1543,7 +1584,7 @@ fun RelayApp() {
// The connection-status toast is now a floating overlay and
// doesn't occupy space above the Scaffold, so it no longer
// participates in the top-inset accounting.
if (showUnattendedBanner || showDemoBanner || connectionChipVisible ||
if (showUnattendedBanner || showDemoBanner || showHostResourcePressure || connectionChipVisible ||
showMessageBanner
) {
Modifier.consumeWindowInsets(WindowInsets.statusBars)
@@ -1695,6 +1736,11 @@ fun RelayApp() {
nullable = true
defaultValue = null
},
navArgument(Screen.Chat.ARG_PROACTIVE_CHAT_ID) {
type = NavType.StringType
nullable = true
defaultValue = null
},
),
) { backStackEntry ->
// Responsive bubble width based on screen width. The "Blend"
@@ -1725,6 +1771,35 @@ fun RelayApp() {
val requestedProfileRoute = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROFILE)
?.takeIf { it.isNotBlank() }
val requestedProactiveChatId = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROACTIVE_CHAT_ID)
?.takeIf { it.isNotBlank() }
val proactiveInboxEntries by connectionViewModel.inboxMessages.collectAsState()
val phoneThreadChatIds by connectionViewModel.phoneThreadChatIds.collectAsState()
LaunchedEffect(
requestedProactiveChatId,
proactiveInboxEntries,
phoneThreadChatIds,
) {
val chatId = requestedProactiveChatId ?: return@LaunchedEffect
val realSessionId = phoneThreadChatIds.entries
.firstOrNull { it.value == chatId }
?.key
if (realSessionId != null) {
chatViewModel.switchSession(realSessionId)
} else {
val entries = proactiveInboxEntries.filter {
(it.connectionId == null || it.connectionId == activeConnectionId) &&
(it.chatId ?: "phone") == chatId
}
if (entries.isEmpty()) return@LaunchedEffect
chatViewModel.openProactiveThread(chatId, entries)
}
backStackEntry.arguments?.putString(
Screen.Chat.ARG_PROACTIVE_CHAT_ID,
null,
)
}
LaunchedEffect(
requestedSessionId,
requestedProfileRoute,
@@ -2619,7 +2694,8 @@ fun RelayApp() {
val sectionArg = backStackEntry.arguments
?.getString(Screen.ProfileInspector.ARG_SECTION)
?: Screen.ProfileInspector.SECTION_CONFIG
if (coldStartAuthState !is AuthState.Paired) {
val inspectorGatewayClient = connectionViewModel.activeGatewayChatClient()
if (coldStartAuthState !is AuthState.Paired && inspectorGatewayClient == null) {
PowerFeatureGateScreen(
title = stringResource(R.string.screen_profile_inspector_label),
summary = stringResource(R.string.power_gate_profile_inspector_summary),
@@ -2647,8 +2723,18 @@ fun RelayApp() {
// SavedStateHandle contains our
// `profileName` arg automatically.
val ssh = extras.createSavedStateHandle()
// Freeze both transports to the connection that
// owned this nav entry. A later connection/profile
// switch cannot redirect an open editor's writes.
val relayUrl = connectionViewModel.effectiveRelayUrl.value
val relayToken = (connectionViewModel.authState.value as? AuthState.Paired)?.token
return ProfileInspectorViewModel(
client = profileInspectorClient,
legacyClient = RelayProfileInspectorClient(
okHttpClient = profileInspectorHttpClient,
relayUrlProvider = { relayUrl },
sessionTokenProvider = { relayToken },
),
gatewayClient = inspectorGatewayClient,
savedStateHandle = ssh,
) as T
}
@@ -1739,7 +1739,10 @@ fun ActiveCardRoutesSection(
var routeEditorOriginal by remember(connection.id) {
mutableStateOf<EndpointCandidate?>(null)
}
val hasTailscaleRoute = endpoints.any { it.role.equals("tailscale", ignoreCase = true) }
val hasTailscaleRoute = hasConfiguredTailscaleRoute(
endpoints = endpoints,
primaryEndpointUrl = connection.primaryEndpointUrl,
)
val tailscalePreferred = preferredRole?.equals("tailscale", ignoreCase = true) == true
val routeNeedsAttention = activeEndpoint == null && liveState != RelayUiState.Connected
val showTailscaleUnavailableHint =
@@ -2171,6 +2174,12 @@ fun ActiveCardRoutesSection(
}
}
internal fun hasConfiguredTailscaleRoute(
endpoints: List<EndpointCandidate>,
primaryEndpointUrl: String,
): Boolean = endpoints.any { it.role.equals("tailscale", ignoreCase = true) } ||
Connection.inferRouteRole(primaryEndpointUrl) == "tailscale"
/**
* Numbered step row for the Manual pairing code fallback. Tightly
* coupled to its Card 3 layout — step badge sizing + content shape —
@@ -3,105 +3,422 @@ package com.hermesandroid.relay.ui.components
import android.net.Uri
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.compose.foundation.BorderStroke
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.ColumnScope
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.lazy.LazyColumn
import androidx.compose.foundation.lazy.items
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedButton
import androidx.compose.material3.Surface
import androidx.compose.material3.Switch
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.unit.dp
import coil3.compose.AsyncImage
import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.R
import com.hermesandroid.relay.ui.components.SphereState
import com.hermesandroid.relay.ui.components.avatar.AvatarRenderState
import com.hermesandroid.relay.ui.components.avatar.PetAvatar
import com.hermesandroid.relay.ui.components.avatar.toAvatar
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import java.io.File
/**
* Per-profile agent-icon picker — the visual twin of the local-name (alias) row.
* The chosen image is copied into app storage and shown beside the agent's name
* in chat. Client-side only: never sent to Hermes. Keyed per `(connection,
* profile)` by [ConnectionViewModel.setProfileIcon] / `ProfileIconStore`.
*/
/** Shared Hermes identity and a separately-scoped phone presentation override. */
@Composable
fun AgentIconRow(connectionViewModel: ConnectionViewModel) {
val iconPath by connectionViewModel.profileIcon.collectAsState()
val localIconPath by connectionViewModel.localProfileIcon.collectAsState()
val serverAvatarPath by connectionViewModel.serverProfileAvatar.collectAsState()
val useLocalOverride by connectionViewModel.useLocalProfileIconOverride.collectAsState()
val hostImportState by connectionViewModel.hostProfileIconImportState.collectAsState()
val launcher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument()
) { uri: Uri? -> uri?.let { connectionViewModel.setProfileIcon(it) } }
val sharedState by connectionViewModel.sharedProfileAvatarState.collectAsState()
val hermesPetState by connectionViewModel.hermesPetState.collectAsState()
val hermesPetAvatar = remember(hermesPetState.active) { hermesPetState.active?.toAvatar() }
var confirmSharedRemoval by remember { mutableStateOf(false) }
var showHermesPetPicker by remember { mutableStateOf(false) }
Column(verticalArrangement = Arrangement.spacedBy(6.dp)) {
LaunchedEffect(Unit) { connectionViewModel.refreshHermesPet() }
val sharedLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument(),
) { uri: Uri? -> uri?.let(connectionViewModel::setSharedProfileAvatar) }
val localLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument(),
) { uri: Uri? -> uri?.let(connectionViewModel::setProfileIcon) }
Column(verticalArrangement = Arrangement.spacedBy(10.dp)) {
Text(
text = stringResource(R.string.agent_icon_title),
style = MaterialTheme.typography.labelLarge,
color = MaterialTheme.colorScheme.onSurface,
)
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Box(
modifier = Modifier
.size(44.dp)
.clip(CircleShape)
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
val path = iconPath
if (!path.isNullOrBlank()) {
AsyncImage(
model = File(path),
contentDescription = stringResource(R.string.agent_icon_title),
contentScale = ContentScale.Crop,
modifier = Modifier.fillMaxSize(),
HermesPetPreview(hermesPetAvatar)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_hermes_pet_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = when {
hermesPetState.supported == false -> stringResource(R.string.agent_icon_hermes_pet_unsupported)
hermesPetState.active != null -> stringResource(
R.string.agent_icon_hermes_pet_active,
hermesPetState.active?.displayName.orEmpty(),
)
else -> stringResource(R.string.agent_icon_hermes_pet_empty)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (hermesPetState.loading) {
CircularProgressIndicator(modifier = Modifier.size(24.dp), strokeWidth = 2.dp)
} else if (hermesPetState.supported != false) {
Switch(
checked = hermesPetState.active != null,
onCheckedChange = { enabled ->
if (enabled) {
showHermesPetPicker = true
connectionViewModel.loadHermesPetGallery()
} else {
connectionViewModel.disableHermesPet()
}
},
)
}
}
OutlinedButton(onClick = { launcher.launch(arrayOf("image/*")) }) {
Text(if (iconPath.isNullOrBlank()) stringResource(R.string.agent_icon_set) else stringResource(R.string.agent_icon_change))
}
if (!iconPath.isNullOrBlank()) {
TextButton(onClick = { connectionViewModel.clearProfileIcon() }) {
Text(stringResource(R.string.agent_icon_clear))
if (hermesPetState.supported != false) {
OutlinedButton(
onClick = {
showHermesPetPicker = true
connectionViewModel.loadHermesPetGallery()
},
enabled = !hermesPetState.loading,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.agent_icon_hermes_pet_browse))
}
}
}
OutlinedButton(
onClick = { connectionViewModel.importProfileIconFromHost() },
enabled = !hostImportState.loading,
) {
Text(
if (hostImportState.loading) {
stringResource(R.string.agent_icon_importing_host)
} else {
stringResource(R.string.agent_icon_import_host)
}
)
}
hostImportState.error?.let { error ->
Text(
text = error,
text = stringResource(R.string.agent_icon_hermes_pet_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
text = stringResource(R.string.agent_icon_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
AvatarPreview(serverAvatarPath)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_shared_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = if (serverAvatarPath.isNullOrBlank()) {
stringResource(R.string.agent_icon_shared_empty)
} else {
stringResource(R.string.agent_icon_shared_active)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
Row(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
OutlinedButton(
onClick = {
sharedLauncher.launch(arrayOf("image/*"))
},
enabled = !sharedState.loading,
) {
Text(stringResource(R.string.agent_icon_change_shared))
}
if (!serverAvatarPath.isNullOrBlank()) {
TextButton(
onClick = { confirmSharedRemoval = true },
enabled = !sharedState.loading,
) {
Text(
text = stringResource(R.string.agent_icon_remove_shared),
color = MaterialTheme.colorScheme.error,
)
}
}
}
sharedState.error?.let { AvatarError(it) }
}
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
AvatarPreview(localIconPath)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_phone_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = stringResource(R.string.agent_icon_phone_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Switch(
checked = useLocalOverride,
onCheckedChange = connectionViewModel::setUseLocalProfileIconOverride,
)
}
OutlinedButton(
onClick = { localLauncher.launch(arrayOf("image/*")) },
modifier = Modifier.fillMaxWidth(),
enabled = useLocalOverride,
) {
Text(
if (localIconPath.isNullOrBlank()) {
stringResource(R.string.agent_icon_choose_phone)
} else {
stringResource(R.string.agent_icon_change_phone)
},
)
}
OutlinedButton(
onClick = connectionViewModel::importProfileIconFromHost,
modifier = Modifier.fillMaxWidth(),
enabled = useLocalOverride && !hostImportState.loading,
) {
Text(
if (hostImportState.loading) {
stringResource(R.string.agent_icon_importing_host)
} else {
stringResource(R.string.agent_icon_import_host)
},
)
}
if (!localIconPath.isNullOrBlank()) {
TextButton(
onClick = connectionViewModel::clearProfileIcon,
enabled = useLocalOverride,
) {
Text(stringResource(R.string.agent_icon_remove_phone))
}
}
Text(
text = stringResource(R.string.agent_icon_animation_note),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
hostImportState.error?.let { AvatarError(it) }
hermesPetState.error?.let { AvatarError(it) }
}
if (confirmSharedRemoval) {
AlertDialog(
onDismissRequest = { confirmSharedRemoval = false },
title = { Text(stringResource(R.string.agent_icon_remove_shared_title)) },
text = { Text(stringResource(R.string.agent_icon_remove_shared_message)) },
confirmButton = {
TextButton(
onClick = {
confirmSharedRemoval = false
connectionViewModel.clearSharedProfileAvatar()
},
) {
Text(
text = stringResource(R.string.agent_icon_remove_shared),
color = MaterialTheme.colorScheme.error,
)
}
},
dismissButton = {
TextButton(onClick = { confirmSharedRemoval = false }) {
Text(stringResource(R.string.common_cancel))
}
},
)
}
if (showHermesPetPicker) {
AlertDialog(
onDismissRequest = { showHermesPetPicker = false },
title = { Text(stringResource(R.string.agent_icon_hermes_pet_picker_title)) },
text = {
if (hermesPetState.galleryLoading && hermesPetState.gallery.isEmpty()) {
Box(
modifier = Modifier.fillMaxWidth().padding(24.dp),
contentAlignment = Alignment.Center,
) { CircularProgressIndicator() }
} else {
LazyColumn(modifier = Modifier.fillMaxWidth().heightIn(max = 420.dp)) {
if (hermesPetState.gallery.isEmpty()) {
item {
Text(
text = stringResource(R.string.agent_icon_hermes_pet_empty),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.padding(12.dp),
)
}
}
items(hermesPetState.gallery, key = { it.slug }) { pet ->
LaunchedEffect(pet.slug, pet.spritesheetUrl) {
connectionViewModel.loadHermesPetThumbnail(pet)
}
TextButton(
onClick = {
showHermesPetPicker = false
connectionViewModel.selectHermesPet(pet.slug)
},
modifier = Modifier.fillMaxWidth(),
) {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
PetGalleryPreview(hermesPetState.thumbnails[pet.slug])
Column(modifier = Modifier.weight(1f)) {
Text(pet.displayName, style = MaterialTheme.typography.titleSmall)
Text(
text = when {
pet.slug == hermesPetState.active?.slug -> stringResource(R.string.agent_icon_hermes_pet_selected)
pet.installed -> stringResource(R.string.agent_icon_hermes_pet_installed)
else -> stringResource(R.string.agent_icon_hermes_pet_adopt)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
}
}
}
},
confirmButton = {},
dismissButton = {
TextButton(onClick = { showHermesPetPicker = false }) {
Text(stringResource(R.string.common_cancel))
}
},
)
}
}
@Composable
private fun AvatarSourceCard(content: @Composable ColumnScope.() -> Unit) {
Surface(
shape = RoundedCornerShape(16.dp),
color = MaterialTheme.colorScheme.surfaceContainerLow,
border = BorderStroke(1.dp, MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.6f)),
) {
Column(
modifier = Modifier.padding(12.dp),
verticalArrangement = Arrangement.spacedBy(8.dp),
content = content,
)
}
}
@Composable
private fun AvatarPreview(path: String?) {
Box(
modifier = Modifier
.size(48.dp)
.clip(CircleShape)
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
) {
if (!path.isNullOrBlank()) {
AsyncImage(
model = File(path),
contentDescription = null,
contentScale = ContentScale.Crop,
modifier = Modifier.fillMaxSize(),
)
}
}
}
@Composable
private fun HermesPetPreview(pet: PetAvatar?) {
Box(
modifier = Modifier.size(56.dp),
contentAlignment = Alignment.Center,
) {
pet?.Render(
state = AvatarRenderState(state = SphereState.Idle),
modifier = Modifier.fillMaxSize(),
)
}
}
@Composable
private fun PetGalleryPreview(dataUri: String?) {
Box(
modifier = Modifier
.size(48.dp)
.clip(RoundedCornerShape(12.dp))
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
) {
if (dataUri != null) {
AsyncImage(
model = dataUri,
contentDescription = null,
contentScale = ContentScale.Fit,
modifier = Modifier.fillMaxSize().padding(3.dp),
)
}
}
}
@Composable
private fun AvatarError(message: String) {
Text(
text = message,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
)
}
@@ -94,7 +94,7 @@ import kotlinx.coroutines.delay
*/
enum class ChatInputTrailing { SEND, VOICE, STOP, STEER, QUEUE }
private val ChatComposerShape = RoundedCornerShape(18.dp)
private val ChatComposerShape = RoundedCornerShape(26.dp)
private val ChatInputChipShape = RoundedCornerShape(12.dp)
internal const val CHAT_INPUT_FIELD_TEST_TAG = "chat-input-field"
@@ -315,7 +315,7 @@ fun ChatInputBar(
border = BorderStroke(1.dp, MaterialTheme.colorScheme.outlineVariant),
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 8.dp, vertical = 6.dp)
.padding(horizontal = 8.dp, vertical = 3.dp)
.then(surfaceModifier),
) {
Column {
@@ -341,15 +341,15 @@ fun ChatInputBar(
}
Column(
modifier = Modifier.padding(horizontal = 8.dp, vertical = 6.dp),
modifier = Modifier.padding(horizontal = 6.dp, vertical = 3.dp),
) {
BasicTextField(
value = value,
onValueChange = { if (it.length <= charLimit) onValueChange(it) },
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 34.dp)
.padding(horizontal = 8.dp, vertical = 4.dp)
.heightIn(min = 30.dp)
.padding(horizontal = 10.dp, vertical = 2.dp)
// Keep directional keys inside the editor. Compose's
// BasicTextField owns normal caret/selection movement;
// cancelling focus traversal prevents a boundary arrow
@@ -408,7 +408,7 @@ fun ChatInputBar(
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 48.dp),
.heightIn(min = 44.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
@@ -64,6 +64,10 @@ data class SlashCommand(
* instead of plain text.
*/
val source: String? = null,
/** Bounded server-recorded skill usage; zero for non-skill commands. */
val usageRank: Int = 0,
/** Sanitized server skill origin such as local or bundled. */
val origin: String? = null,
) {
companion object {
const val SOURCE_SERVER = "server"
@@ -105,6 +105,11 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.ConnectionValidation
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.presentationRouteUrl
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.network.shared.HermesLanDiscovery
import com.hermesandroid.relay.network.shared.HermesLanDiscoveryResult
@@ -3174,7 +3179,7 @@ private fun ConfirmStep(
// app auto-falls back to the secure one, so a blanket "Insecure (dev)"
// badge from endpoint[0] alone would lie to the user.
val anySecure = endpoints.any { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}
@@ -3195,7 +3200,7 @@ private fun ConfirmStep(
// Mixed case ("Tailscale is encrypted..." vs "Public is encrypted...").
val firstSecureLabel = endpoints
.firstOrNull { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}?.displayLabel()
@@ -3208,6 +3213,7 @@ private fun ConfirmStep(
val distinctRoles = endpoints.map { it.role }.distinct()
var preferRole by remember(payload) { mutableStateOf<String?>(null) }
var preferMenuOpen by remember { mutableStateOf(false) }
val secureLink = endpoints.firstOrNull { it.hasSecureProxy() }
Column(
verticalArrangement = Arrangement.spacedBy(14.dp),
@@ -3318,6 +3324,15 @@ private fun ConfirmStep(
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
secureLink?.let { route ->
SecureLinkPairingSummary(
services = route.secureLinkServices(),
complete = route.secureLinkCoversAllServices(),
hasFallback = endpoints.size > 1,
usesReach = route.hasHermesReach(),
)
HorizontalDivider()
}
endpoints.forEachIndexed { index, candidate ->
if (index > 0) HorizontalDivider()
EndpointPreviewRow(
@@ -3720,7 +3735,7 @@ private fun EndpointPreviewRow(
) {
// Per-row security derived from the same three signals as the overall
// securityState computation — scheme, tls flag, transportHint.
val isSecure = candidate.relay?.url?.startsWith("wss://") == true ||
val isSecure = candidate.hasSecureProxy() || candidate.relay?.url?.startsWith("wss://") == true ||
candidate.api?.tls == true ||
candidate.relay?.transportHint.equals("wss", ignoreCase = true) ||
candidate.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
@@ -3756,7 +3771,7 @@ private fun EndpointPreviewRow(
}
}
Text(
text = candidate.primaryRouteUrl().orEmpty() +
text = candidate.presentationRouteUrl().orEmpty() +
(candidate.relay?.transportHint?.let { " \u00b7 $it" } ?: ""),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
@@ -3772,6 +3787,75 @@ private fun EndpointPreviewRow(
}
}
@Composable
private fun SecureLinkPairingSummary(
services: List<String>,
complete: Boolean,
hasFallback: Boolean,
usesReach: Boolean,
) {
val relayLabel = stringResource(R.string.secure_link_service_relay)
val apiLabel = stringResource(R.string.secure_link_service_api)
val dashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val serviceText = services.map { service ->
when (service) {
"relay" -> relayLabel
"api" -> apiLabel
"dashboard" -> dashboardLabel
else -> service
}
}.joinToString(" · ")
Surface(
color = MaterialTheme.colorScheme.primary.copy(alpha = 0.08f),
shape = RoundedCornerShape(12.dp),
) {
Column(
modifier = Modifier.fillMaxWidth().padding(12.dp),
verticalArrangement = Arrangement.spacedBy(4.dp),
) {
Text(
stringResource(if (usesReach) R.string.hermes_reach_title else R.string.secure_link_title),
style = MaterialTheme.typography.titleSmall,
)
if (usesReach) {
Text(
stringResource(R.string.hermes_reach_summary),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
stringResource(R.string.secure_link_pinned_tls),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.primary,
)
Text(
if (serviceText.isBlank()) stringResource(R.string.secure_link_no_services)
else stringResource(R.string.secure_link_protects, serviceText),
style = MaterialTheme.typography.bodySmall,
)
if (!complete) {
Text(
stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
if (hasFallback) stringResource(R.string.secure_link_fallback_ready)
else stringResource(R.string.secure_link_no_fallback),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
/**
* Compact pill used by [EndpointPreviewRow] — matches the "Preferred" soft
* chip style so the row reads as a row of related chips rather than a mix
@@ -57,6 +57,9 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.SurfaceSecurityKind
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.isEncryptedOverlayRoute
import com.hermesandroid.relay.data.isKnownRole
import com.hermesandroid.relay.data.isTlsUrl
@@ -323,6 +326,9 @@ private fun EndpointRow(
val apiLabel = stringResource(R.string.active_section_api_server)
val relayLabel = stringResource(R.string.active_section_relay)
val surfaceSummary = listOfNotNull(
candidate.proxy?.takeIf { candidate.hasSecureProxy() }?.let {
stringResource(R.string.secure_link_pinned_tls_short)
},
dashboardSurfaceUrl?.let { "$dashboardLabel ${displayPort(it)}" },
candidate.api?.url?.let { "$apiLabel ${displayPort(it)}" },
candidate.relay?.url?.let { "$relayLabel ${displayPort(it)}" },
@@ -357,6 +363,36 @@ private fun EndpointRow(
)
}
}
if (candidate.hasSecureProxy()) {
val secureRelayLabel = stringResource(R.string.secure_link_service_relay)
val secureApiLabel = stringResource(R.string.secure_link_service_api)
val secureDashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val services = candidate.secureLinkServices().map { service ->
when (service) {
"relay" -> secureRelayLabel
"api" -> secureApiLabel
"dashboard" -> secureDashboardLabel
else -> service
}
}.joinToString(" · ")
Text(
text = stringResource(R.string.secure_link_protects, services),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
if (!candidate.secureLinkCoversAllServices()) {
Text(
text = stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
text = stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
// 3-dot overflow menu — actions per-row so the card stays flat
@@ -680,6 +716,7 @@ private fun roleIcon(role: String): ImageVector = when (role.lowercase()) {
* be classified independently before it's the active route.
*/
private fun EndpointCandidate.routeSecurityKind(): SurfaceSecurityKind = when {
hasSecureProxy() -> SurfaceSecurityKind.Tls
isTlsUrl(primaryRouteUrl().orEmpty()) -> SurfaceSecurityKind.Tls
isEncryptedOverlayRoute(isTailscaleDetected = false) -> SurfaceSecurityKind.Overlay
else -> SurfaceSecurityKind.Plain
@@ -45,6 +45,8 @@ import androidx.compose.material3.Button
import androidx.compose.material3.ButtonDefaults
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.FilterChip
import androidx.compose.material3.FilterChipDefaults
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
@@ -81,6 +83,7 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.HermesCardDispatch
import com.hermesandroid.relay.data.HermesCardField
import com.hermesandroid.relay.data.HermesCardInput
import com.hermesandroid.relay.data.encodeClarifyMultiSelectAnswer
import com.hermesandroid.relay.ui.theme.RelayRefresh
import com.hermesandroid.relay.ui.theme.relayMetadataStyle
import kotlinx.coroutines.coroutineScope
@@ -389,7 +392,8 @@ private fun ChoseRow(
/**
* The interactive answer surface for ask cards, composed from the
* [HermesCardInput] flags rather than the card type:
* - [HermesCardInput.choices] → AssistChip row, one tap dispatches.
* - [HermesCardInput.choices] → one-tap AssistChips, or independently
* selected FilterChips plus explicit submit for multi-select clarifies.
* - [HermesCardInput.allowFreeText] → [InlineAnswerField] mini pill +
* 18dp send affordance.
* - [HermesCardInput.masked] → password-style OutlinedTextField with a
@@ -411,6 +415,8 @@ private fun CardInputSlot(
// never be written into the saved-instance-state Bundle.
var answerText by remember { mutableStateOf("") }
var reveal by remember { mutableStateOf(false) }
var selectedChoices by remember(input.choices) { mutableStateOf(emptyList<String>()) }
val isMultiSelect = input.multiSelect && input.choices.isNotEmpty()
val showFreeText = !input.masked && (
input.allowFreeText ||
@@ -428,16 +434,45 @@ private fun CardInputSlot(
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
input.choices.forEach { choice ->
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
if (isMultiSelect) {
val selected = choice in selectedChoices
FilterChip(
selected = selected,
onClick = {
selectedChoices = if (selected) {
selectedChoices - choice
} else {
selectedChoices + choice
}
},
label = { Text(choice, style = MaterialTheme.typography.labelMedium) },
leadingIcon = if (selected) {
{
Icon(
Icons.Filled.Check,
contentDescription = null,
modifier = Modifier.size(16.dp),
)
}
} else {
null
},
colors = FilterChipDefaults.filterChipColors(
selectedContainerColor = MaterialTheme.colorScheme.secondaryContainer,
),
)
} else {
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
}
}
}
}
@@ -482,21 +517,38 @@ private fun CardInputSlot(
onValueChange = { answerText = it },
modifier = Modifier.weight(1f),
)
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
if (!isMultiSelect) {
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
}
}
}
}
if (isMultiSelect) {
val answers = selectedChoices +
listOfNotNull(answerText.trim().takeIf(String::isNotEmpty))
Spacer(Modifier.height(10.dp))
Button(
onClick = { onSubmit(encodeClarifyMultiSelectAnswer(answers)) },
enabled = answers.isNotEmpty(),
) {
Text(
stringResource(R.string.card_submit),
style = MaterialTheme.typography.labelMedium,
)
}
}
// Submit affordance for masked / hold-to-confirm inputs
when {
input.holdToConfirm -> {
@@ -0,0 +1,81 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.WindowInsets
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.statusBars
import androidx.compose.foundation.layout.windowInsetsPadding
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.outlined.WarningAmber
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
/** Persistent, server-authored resource-pressure warning for the active Hermes host. */
@Composable
fun HostResourcePressureBanner(
text: String,
critical: Boolean,
includeStatusBarPadding: Boolean,
modifier: Modifier = Modifier,
) {
val background = if (critical) {
MaterialTheme.colorScheme.errorContainer
} else {
MaterialTheme.colorScheme.tertiaryContainer
}
val foreground = if (critical) {
MaterialTheme.colorScheme.onErrorContainer
} else {
MaterialTheme.colorScheme.onTertiaryContainer
}
Column(
modifier = modifier
.fillMaxWidth()
.background(background)
.then(
if (includeStatusBarPadding) {
Modifier.windowInsetsPadding(WindowInsets.statusBars)
} else {
Modifier
},
),
) {
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 32.dp)
.padding(horizontal = 12.dp, vertical = 6.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Icon(
imageVector = Icons.Outlined.WarningAmber,
contentDescription = null,
tint = foreground,
modifier = Modifier.size(17.dp),
)
Text(
text = text,
color = foreground,
style = MaterialTheme.typography.labelMedium,
fontWeight = FontWeight.Medium,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.weight(1f),
)
}
}
}
@@ -42,6 +42,9 @@ import androidx.compose.runtime.setValue
import androidx.compose.runtime.snapshots.SnapshotStateList
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.res.stringResource
@@ -252,6 +255,7 @@ private fun MessageRow(
Row(
modifier = Modifier
.fillMaxWidth()
.semantics { liveRegion = LiveRegionMode.Polite }
.heightIn(min = ROW_MIN_HEIGHT_DP.dp)
.padding(horizontal = 10.dp, vertical = 7.dp),
horizontalArrangement = Arrangement.spacedBy(9.dp),
@@ -27,6 +27,7 @@ import androidx.compose.foundation.layout.fillMaxHeight
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.offset
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.widthIn
@@ -43,9 +44,11 @@ import androidx.compose.material.icons.filled.FormatQuote
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.material3.DropdownMenu
import androidx.compose.material3.DropdownMenuItem
import androidx.compose.runtime.Composable
@@ -89,6 +92,7 @@ import java.text.SimpleDateFormat
import java.util.Date
internal const val CHAT_PET_IDENTITY_OBSTACLE_PREFIX = "chat-message-identity:"
private val MESSAGE_REACTIONS = listOf("❤️", "👍", "👎", "😂", "‼️", "❓")
@OptIn(ExperimentalFoundationApi::class)
@Composable
@@ -113,6 +117,10 @@ fun MessageBubble(
onQuoteMessage: ((ChatMessage) -> Unit)? = null,
/** Navigate a rendered quote chip to its original message id. */
onNavigateToMessage: ((String) -> Unit)? = null,
/** Open an upstream @session:<profile>/<id> reference in app. */
onSessionReference: ((SessionReference) -> Unit)? = null,
/** React to the newest message for this role; null removes the reaction. */
onReact: ((String?) -> Unit)? = null,
/**
* Reads a completed assistant response through the active voice renderer.
* Null hides the entry; the owning screen uses that to limit the action to
@@ -170,6 +178,7 @@ fun MessageBubble(
) {
val isUser = message.role == MessageRole.USER
val isSystem = message.role == MessageRole.SYSTEM
val sessionReferences = remember(message.content) { parseSessionReferences(message.content) }
// Phone/voice-origin action bubble marker.
//
@@ -449,11 +458,51 @@ fun MessageBubble(
val showEditAction = onEditMessage != null && isUser
val showSpeakAction = shouldShowSpeakResponseAction(message, onSpeakMessage != null)
val showStopSpeakingAction = shouldShowStopSpeakingAction(message, onStopSpeaking != null)
if (onQuoteMessage != null || showEditAction || showSpeakAction || showStopSpeakingAction) {
val selectedUserReaction = message.reactions.firstOrNull { it.author == "user" }?.emoji
if (onQuoteMessage != null || onReact != null || showEditAction || showSpeakAction || showStopSpeakingAction) {
DropdownMenu(
expanded = showMessageActions,
onDismissRequest = { showMessageActions = false },
shape = RoundedCornerShape(24.dp),
containerColor = MaterialTheme.colorScheme.surfaceContainerHigh,
tonalElevation = 3.dp,
shadowElevation = 8.dp,
) {
if (onReact != null) {
Row(
horizontalArrangement = Arrangement.SpaceEvenly,
verticalAlignment = Alignment.CenterVertically,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 4.dp, vertical = 6.dp),
) {
MESSAGE_REACTIONS.forEach { emoji ->
IconButton(
onClick = {
showMessageActions = false
onReact(emoji)
},
modifier = Modifier.background(
color = if (selectedUserReaction == emoji) {
MaterialTheme.colorScheme.secondaryContainer
} else {
Color.Transparent
},
shape = CircleShape,
),
) {
Text(
text = emoji,
fontSize = 24.sp,
modifier = Modifier.semantics {
contentDescription = "React with $emoji"
},
)
}
}
}
HorizontalDivider()
}
DropdownMenuItem(
text = { Text(stringResource(R.string.msg_bubble_copy)) },
onClick = {
@@ -509,8 +558,22 @@ fun MessageBubble(
},
)
}
if (onReact != null && selectedUserReaction != null) {
DropdownMenuItem(
text = { Text("Remove reaction") },
onClick = {
showMessageActions = false
onReact(null)
},
)
}
}
}
Box(
modifier = Modifier.padding(
bottom = if (message.reactions.isNotEmpty()) 8.dp else 0.dp,
),
) {
Surface(
shape = bubbleShape,
color = backgroundColor,
@@ -552,7 +615,7 @@ fun MessageBubble(
// same tactile confirm every chat app fires.
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
if (
onQuoteMessage != null || showEditAction || showSpeakAction ||
onQuoteMessage != null || onReact != null || showEditAction || showSpeakAction ||
showStopSpeakingAction
) {
showMessageActions = true
@@ -639,6 +702,16 @@ fun MessageBubble(
SelectionContainer { messageTextContent() }
}
}
if (onSessionReference != null && sessionReferences.isNotEmpty()) {
sessionReferences.forEach { reference ->
TextButton(
onClick = { onSessionReference(reference) },
modifier = Modifier.padding(top = 2.dp),
) {
Text("Open ${reference.label}")
}
}
}
// Inline generated images (assistant only) — rendered OUTSIDE
// the SelectionContainer (they're not selectable text). Remote
@@ -803,6 +876,19 @@ fun MessageBubble(
}
}
}
if (message.reactions.isNotEmpty()) {
MessageReactionBadge(
reactions = message.reactions.map { it.emoji },
onOpen = onReact?.let { { showMessageActions = true } },
modifier = Modifier
.align(if (isUser) Alignment.BottomEnd else Alignment.BottomStart)
.offset(
x = if (isUser) (-10).dp else 10.dp,
y = 9.dp,
),
)
}
}
val inlineActions: @Composable () -> Unit = {
MessageInlineActions(
showQuote = onQuoteMessage != null,
@@ -855,6 +941,41 @@ fun MessageBubble(
} // end CompositionLocalProvider(LocalMediaBlurMode)
}
@OptIn(ExperimentalFoundationApi::class)
@Composable
private fun MessageReactionBadge(
reactions: List<String>,
onOpen: (() -> Unit)?,
modifier: Modifier = Modifier,
) {
val description = "Reactions: ${reactions.joinToString(" ")}"
Surface(
shape = RoundedCornerShape(12.dp),
color = MaterialTheme.colorScheme.surfaceContainerHighest,
tonalElevation = 2.dp,
shadowElevation = 2.dp,
modifier = modifier
.then(
if (onOpen != null) {
Modifier.combinedClickable(onClick = onOpen, onLongClick = onOpen)
} else {
Modifier
},
)
.semantics { contentDescription = description },
) {
Row(
horizontalArrangement = Arrangement.spacedBy(2.dp),
verticalAlignment = Alignment.CenterVertically,
modifier = Modifier.padding(horizontal = 7.dp, vertical = 3.dp),
) {
reactions.forEach { emoji ->
Text(text = emoji, fontSize = 14.sp, lineHeight = 16.sp)
}
}
}
}
@Composable
private fun MessageInlineActions(
showQuote: Boolean,
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,167 @@
package com.hermesandroid.relay.ui.components
import com.hermesandroid.relay.data.ChatSession
import com.hermesandroid.relay.data.SessionActivityState
import java.util.Locale
internal enum class SessionDrawerGrouping {
None,
Updated,
Project,
Status,
Profile,
}
internal enum class SessionDrawerOrdering {
Updated,
Created,
Title,
Status,
Tokens,
Cost,
}
internal enum class SessionDrawerStatus {
NeedsInput,
Working,
Idle,
}
internal enum class SessionDrawerPrState {
Open,
Draft,
Merged,
Closed,
None,
}
internal data class SessionDrawerViewOptions(
val grouping: SessionDrawerGrouping = SessionDrawerGrouping.None,
val ordering: SessionDrawerOrdering = SessionDrawerOrdering.Updated,
val statuses: Set<SessionDrawerStatus> = emptySet(),
val profiles: Set<String> = emptySet(),
val projects: Set<String> = emptySet(),
val pullRequests: Set<SessionDrawerPrState> = emptySet(),
val showProfile: Boolean = false,
val showUpdated: Boolean = true,
val showTokens: Boolean = false,
val showCost: Boolean = false,
)
internal data class SessionDrawerGroup(
val key: String,
val label: String?,
val rows: List<ProfileSessionRow>,
)
internal fun sessionRowKey(row: ProfileSessionRow): String =
"${row.profile.lowercase(Locale.ROOT)}:${row.session.sessionId}"
internal fun sessionProjectLabel(session: ChatSession): String {
val raw = (session.gitRepoRoot ?: session.workingDirectory)
?.trim()
?.trimEnd('/', '\\')
.orEmpty()
if (raw.isBlank()) return "No project"
return raw.substringAfterLast('/').substringAfterLast('\\').ifBlank { raw }
}
internal fun sessionDrawerStatus(
row: ProfileSessionRow,
activityStates: Map<String, SessionActivityState>,
): SessionDrawerStatus = when (
activityStates[sessionRowKey(row)] ?: activityStates[row.session.sessionId]
) {
SessionActivityState.NeedsInput -> SessionDrawerStatus.NeedsInput
SessionActivityState.Working -> SessionDrawerStatus.Working
null -> if (row.session.isActive) SessionDrawerStatus.Working else SessionDrawerStatus.Idle
}
internal fun sessionDrawerPrState(session: ChatSession): SessionDrawerPrState = when {
session.pullRequestNumber == null -> SessionDrawerPrState.None
session.pullRequestDraft -> SessionDrawerPrState.Draft
session.pullRequestState.equals("merged", ignoreCase = true) -> SessionDrawerPrState.Merged
session.pullRequestState.equals("closed", ignoreCase = true) -> SessionDrawerPrState.Closed
else -> SessionDrawerPrState.Open
}
internal fun filterAndSortSessionRows(
rows: List<ProfileSessionRow>,
options: SessionDrawerViewOptions,
activityStates: Map<String, SessionActivityState> = emptyMap(),
): List<ProfileSessionRow> {
val filtered = rows.asSequence()
.filter { options.statuses.isEmpty() || sessionDrawerStatus(it, activityStates) in options.statuses }
.filter { options.profiles.isEmpty() || it.profile in options.profiles }
.filter { options.projects.isEmpty() || sessionProjectLabel(it.session) in options.projects }
.filter { options.pullRequests.isEmpty() || sessionDrawerPrState(it.session) in options.pullRequests }
.toList()
val statusRank = mapOf(
SessionDrawerStatus.NeedsInput to 0,
SessionDrawerStatus.Working to 1,
SessionDrawerStatus.Idle to 2,
)
val comparator = when (options.ordering) {
SessionDrawerOrdering.Updated -> compareByDescending<ProfileSessionRow> { it.session.activityTimestamp }
SessionDrawerOrdering.Created -> compareByDescending { it.session.startTimestamp }
SessionDrawerOrdering.Title -> compareBy { it.session.title.orEmpty().lowercase(Locale.ROOT) }
SessionDrawerOrdering.Status -> compareBy { statusRank.getValue(sessionDrawerStatus(it, activityStates)) }
SessionDrawerOrdering.Tokens -> compareByDescending { it.session.totalTokens }
SessionDrawerOrdering.Cost -> compareByDescending { it.session.costUsd }
}
return filtered.sortedWith(
compareByDescending<ProfileSessionRow> { it.session.pinned }
.then(comparator)
.thenBy { it.session.title.orEmpty().lowercase(Locale.ROOT) },
)
}
internal fun groupSessionRows(
rows: List<ProfileSessionRow>,
grouping: SessionDrawerGrouping,
activityStates: Map<String, SessionActivityState> = emptyMap(),
nowMillis: Long = System.currentTimeMillis(),
): List<SessionDrawerGroup> {
if (rows.isEmpty()) return emptyList()
val grouped = rows.groupBy { row ->
when (grouping) {
SessionDrawerGrouping.None -> null
SessionDrawerGrouping.Updated -> updatedBucket(row.session.activityTimestamp, nowMillis)
SessionDrawerGrouping.Project -> sessionProjectLabel(row.session)
SessionDrawerGrouping.Status -> sessionDrawerStatus(row, activityStates).displayLabel
SessionDrawerGrouping.Profile -> row.profile
}
}
val groups = grouped.map { (label, groupRows) ->
SessionDrawerGroup(key = "${grouping.name}:$label", label = label, rows = groupRows)
}
return if (grouping == SessionDrawerGrouping.Project) {
groups.sortedWith(
compareBy<SessionDrawerGroup> { it.label != "No project" }
.thenByDescending { group -> group.rows.maxOfOrNull { it.session.activityTimestamp } ?: 0L }
.thenBy { it.label.orEmpty().lowercase(Locale.ROOT) },
)
} else {
groups
}
}
private val SessionDrawerStatus.displayLabel: String
get() = when (this) {
SessionDrawerStatus.NeedsInput -> "Needs input"
SessionDrawerStatus.Working -> "Working"
SessionDrawerStatus.Idle -> "Idle"
}
private fun updatedBucket(timestamp: Long, nowMillis: Long): String {
if (timestamp <= 0L) return "Older"
val age = (nowMillis - timestamp).coerceAtLeast(0L)
return when {
age < DAY_MILLIS -> "Today"
age < 2 * DAY_MILLIS -> "Yesterday"
age < 7 * DAY_MILLIS -> "Last 7 days"
else -> "Older"
}
}
private const val DAY_MILLIS = 24L * 60L * 60L * 1_000L
@@ -0,0 +1,41 @@
package com.hermesandroid.relay.ui.components
data class SessionReference(val profile: String, val sessionId: String) {
val label: String
get() = "$profile · ${sessionId.takeLast(10)}"
}
private val SESSION_REFERENCE = Regex("@session:([A-Za-z0-9_.-]{1,64})/([A-Za-z0-9_.:-]{1,160})")
/** Find session references outside fenced and inline code. */
internal fun parseSessionReferences(markdown: String): List<SessionReference> {
val visible = buildString(markdown.length) {
var fenced = false
markdown.lineSequence().forEach { line ->
if (line.trimStart().startsWith("```")) {
fenced = !fenced
appendLine()
} else if (fenced) {
appendLine()
} else {
var inline = false
line.forEach { char ->
if (char == '`') inline = !inline
append(if (inline || char == '`') ' ' else char)
}
appendLine()
}
}
}
return SESSION_REFERENCE.findAll(visible)
.map {
SessionReference(
it.groupValues[1],
it.groupValues[2].trimEnd('.', ',', ';', '!', '?', ')', ']', '}'),
)
}
.filter { it.sessionId.isNotBlank() }
.distinct()
.take(16)
.toList()
}
@@ -25,8 +25,11 @@ import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material3.Icon
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedTextField
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
@@ -73,11 +76,13 @@ fun SubagentLane(
taskIndex: Int,
calls: List<ToolCall>,
modifier: Modifier = Modifier,
onSteer: ((subagentId: String, instruction: String) -> Unit)? = null,
) {
val anyRunning = calls.any { !it.isComplete }
val allComplete = calls.isNotEmpty() && calls.all { it.isComplete }
val anyFailed = calls.any { it.isComplete && it.success == false }
val runningCount = calls.count { !it.isComplete }
val steerableId = calls.firstNotNullOfOrNull { it.subagentId?.takeIf(String::isNotBlank) }
val laneLabel = calls.firstNotNullOfOrNull { call ->
call.taskLabel?.takeIf { it.isNotBlank() }
@@ -106,6 +111,8 @@ fun SubagentLane(
val failureLabel = stringResource(R.string.cd_subagent_failed)
var expanded by remember { mutableStateOf(!allComplete) }
var showSteerDialog by remember { mutableStateOf(false) }
var steerText by remember { mutableStateOf("") }
// Auto-collapse when the last child completes — same pattern as
// ToolProgressCard's LaunchedEffect(toolCall.isComplete).
@@ -162,6 +169,12 @@ fun SubagentLane(
modifier = Modifier.weight(1f),
)
if (anyRunning && steerableId != null && onSteer != null) {
TextButton(onClick = { showSteerDialog = true }) {
Text("Redirect")
}
}
Text(
text = statusMeta,
style = relayMetadataStyle(),
@@ -202,4 +215,33 @@ fun SubagentLane(
}
}
}
if (showSteerDialog && steerableId != null && onSteer != null) {
AlertDialog(
onDismissRequest = { showSteerDialog = false },
title = { Text("Redirect subagent") },
text = {
OutlinedTextField(
value = steerText,
onValueChange = { steerText = it },
label = { Text("New instruction") },
modifier = Modifier.fillMaxWidth(),
)
},
confirmButton = {
TextButton(
onClick = {
val instruction = steerText.trim()
showSteerDialog = false
steerText = ""
onSteer(steerableId, instruction)
},
enabled = steerText.isNotBlank(),
) { Text("Redirect") }
},
dismissButton = {
TextButton(onClick = { showSteerDialog = false }) { Text("Cancel") }
},
)
}
}
@@ -0,0 +1,34 @@
package com.hermesandroid.relay.ui.components.avatar
import com.hermesandroid.relay.viewmodel.connection.ProfileController
import java.io.File
/** Adapt upstream `pet.info` geometry to the existing bounded sprite renderer. */
fun ProfileController.HermesPetPresentation.toAvatar(): PetAvatar? {
val sheet = File(spritesheetPath)
if (!sheet.isFile || frameWidth <= 0 || frameHeight <= 0 || framesPerState <= 0) return null
val fps = (framesPerState * 1000f / loopMs.coerceAtLeast(1)).coerceIn(1f, 60f)
val clips = stateRows.mapIndexedNotNull { row, name ->
val normalized = name.trim().takeIf { it.isNotEmpty() } ?: return@mapIndexedNotNull null
val count = (framesByRow[normalized] ?: framesByState[normalized] ?: framesPerState)
.coerceIn(1, framesPerState)
normalized to PetClipSpec(
sheet = sheet.name,
frameWidth = frameWidth,
frameHeight = frameHeight,
frameCount = count,
startFrame = row * framesPerState,
fps = fps,
)
}.toMap()
if (clips["idle"] == null) return null
return runCatching {
PetSpec(
id = "hermes:$slug",
label = displayName,
description = "Profile-scoped Hermes animated pet",
reactive = PetReactiveSpec(voice = false, tools = true, intensity = true),
states = clips,
).toAvatar(sheet.parentFile ?: return null)
}.getOrNull()
}
@@ -56,6 +56,7 @@ import androidx.compose.material.icons.filled.Share
import androidx.compose.material.icons.filled.Tune
import androidx.compose.material3.AssistChip
import androidx.compose.material3.AssistChipDefaults
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.Badge
import androidx.compose.material3.BadgedBox
import androidx.compose.material3.Button
@@ -152,7 +153,6 @@ import android.content.ClipData
import android.content.Intent
import android.net.Uri
import android.provider.Settings
import android.util.Base64
import android.widget.Toast
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.PickVisualMediaRequest
@@ -164,6 +164,8 @@ import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.ChatMessage
import com.hermesandroid.relay.data.ChatComposerDraft
import com.hermesandroid.relay.data.ChatComposerDraftContext
import com.hermesandroid.relay.util.AttachmentTooLargeException
import com.hermesandroid.relay.util.readBase64Bounded
import com.hermesandroid.relay.data.ChatComposerDraftKey
import com.hermesandroid.relay.data.ChatQuoteReference
import com.hermesandroid.relay.data.buildChatQuotedPrompt
@@ -173,6 +175,7 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.PhysicalKeyboardEnterBehavior
import com.hermesandroid.relay.data.ProfilePresentationPolicy
import com.hermesandroid.relay.data.ProactiveInboxEntry
import com.hermesandroid.relay.data.SessionActivityState
import com.hermesandroid.relay.data.VoicePresentationMode
import com.hermesandroid.relay.data.hermesProcessNotificationOrNull
@@ -231,6 +234,8 @@ import com.hermesandroid.relay.ui.components.ThinkingIndicatorStyle
import com.hermesandroid.relay.ui.components.ThinkingMatrixColor
import com.hermesandroid.relay.ui.components.ThinkingMatrixPattern
import com.hermesandroid.relay.ui.components.SessionDrawerContent
import com.hermesandroid.relay.ui.components.ProfileSessionRow
import com.hermesandroid.relay.ui.components.ProvisionalThreadRow
import com.hermesandroid.relay.ui.components.ProfileDisplayManagerDialog
import com.hermesandroid.relay.ui.components.ProfileShelf
import com.hermesandroid.relay.ui.components.ProfileSwitcherSheet
@@ -297,14 +302,12 @@ internal fun resolveSessionActivityStates(
internal fun resolveChatHeaderSubtitle(
isStreaming: Boolean,
statusText: String,
projectName: String?,
personalityName: String?,
modelName: String?,
): String = if (isStreaming) {
statusText
} else {
listOfNotNull(
projectName?.takeIf { it.isNotBlank() },
personalityName?.takeIf { it.isNotBlank() },
modelName?.takeIf { it.isNotBlank() },
).joinToString(" \u00B7 ").ifBlank { statusText }
@@ -743,6 +746,13 @@ fun ChatScreen(
val messages by chatViewModel.messages.collectAsState()
val messageReactionsSupported by chatViewModel.messageReactionsSupported.collectAsState()
val newestReactableMessageKeys = remember(messages) {
setOfNotNull(
messages.lastOrNull { it.role == MessageRole.USER }?.uiKey,
messages.lastOrNull { it.role == MessageRole.ASSISTANT }?.uiKey,
)
}
val isStreaming by chatViewModel.isStreaming.collectAsState()
// Keep the screen on for the two "actively engaged, hands-off-keyboard"
// cases: voice mode is a call-like continuous session (mirrors Assistant/
@@ -813,18 +823,39 @@ fun ChatScreen(
// has been made (the /api/config fallback is more useful than the bare
// connection label).
val agentProfiles by connectionViewModel.agentProfiles.collectAsState()
var allProfileSessions by remember { mutableStateOf<List<ProfileSessionRow>>(emptyList()) }
var allProfileSessionsLoading by remember { mutableStateOf(false) }
val openedSessionProfileName by chatViewModel.openedSessionProfileName.collectAsState()
val conversationProfile = openedSessionProfileName?.let { owner ->
agentProfiles.firstOrNull { it.name.equals(owner, ignoreCase = true) }
?: allProfileSessions.firstOrNull {
it.profile.equals(owner, ignoreCase = true) &&
it.session.sessionId == currentSessionId
}?.session?.let { session ->
com.hermesandroid.relay.data.Profile(
name = owner,
model = session.model.orEmpty(),
description = owner,
)
}
?: com.hermesandroid.relay.data.Profile(
name = owner,
model = "",
description = owner,
)
} ?: effectiveProfile
val profileDisplayAlias by connectionViewModel.profileDisplayAlias.collectAsState()
val activeConnection by connectionViewModel.activeConnection.collectAsState()
val serverModelName by chatViewModel.serverModelName.collectAsState()
val apiModelOptions by chatViewModel.apiModelOptions.collectAsState()
val modelProviders by chatViewModel.modelProviders.collectAsState()
val modelOptionsRefreshing by chatViewModel.modelOptionsRefreshing.collectAsState()
val modelSelectionConfirmation by chatViewModel.modelSelectionConfirmation.collectAsState()
val reasoningCapabilityRevision by chatViewModel.reasoningCapabilityRevision.collectAsState()
val selectedModelOverride by chatViewModel.selectedModelOverride.collectAsState()
val selectedProviderOverride by chatViewModel.selectedProviderOverride.collectAsState()
val gatewayCurrentModel by chatViewModel.gatewayCurrentModel.collectAsState()
val gatewayCurrentProvider by chatViewModel.gatewayCurrentProvider.collectAsState()
val gatewayProjectName by chatViewModel.gatewayProjectName.collectAsState()
val selectedReasoningEffort by chatViewModel.selectedReasoningEffort.collectAsState()
val currentSession = remember(sessions, currentSessionId) {
sessions.firstOrNull { it.sessionId == currentSessionId }
@@ -836,8 +867,8 @@ fun ChatScreen(
gatewayModel = gatewayCurrentModel,
gatewayProvider = gatewayCurrentProvider,
persistedSessionModel = currentSession?.model,
profileDefaultModel = effectiveProfile?.model,
serverDefaultModel = serverModelName,
profileDefaultModel = conversationProfile?.model,
serverDefaultModel = serverModelName.takeIf { openedSessionProfileName == null },
)
val sessionPickerProvider = sessionModelState.pickerProvider
?: sessionModelState.pickerModel?.let { model ->
@@ -1985,7 +2016,7 @@ fun ChatScreen(
// four keys, which missed updates in some cases (most notably a
// profile switch while the ConnectionInfoSheet was open, where the
// ambient sheet scope appeared to swallow the key comparison).
val agentDisplayName by remember(
val globalSelectedAgentDisplayName by remember(
effectiveProfile,
selectedPersonality,
defaultPersonality,
@@ -1993,13 +2024,31 @@ fun ChatScreen(
activeConnection?.label,
) {
derivedStateOf {
val profile = effectiveProfile
AgentDisplay.agentName(
profile = effectiveProfile,
selectedPersonality = selectedPersonality,
defaultPersonality = defaultPersonality,
connectionLabel = activeConnection?.label,
localDisplayAlias = profileDisplayAlias,
)
}
}
val agentDisplayName by remember(
conversationProfile,
selectedPersonality,
defaultPersonality,
profileDisplayAlias,
openedSessionProfileName,
activeConnection?.label,
) {
derivedStateOf {
val profile = conversationProfile
AgentDisplay.agentName(
profile = profile,
selectedPersonality = selectedPersonality,
defaultPersonality = defaultPersonality,
connectionLabel = activeConnection?.label,
localDisplayAlias = profileDisplayAlias,
localDisplayAlias = profileDisplayAlias.takeIf { openedSessionProfileName == null },
)
}
}
@@ -2028,13 +2077,13 @@ fun ChatScreen(
ModalNavigationDrawer(
drawerState = drawerState,
// Disable the drawer's edge-swipe while voice mode is up so the
// overlay reads as a true modal — the swipe gesture lives on the
// drawer itself, so the overlay's pointer scrim alone can't block it.
gesturesEnabled = !voiceUiState.voiceMode,
// Material routes scrim taps through the drawer's gesture handler.
// Keep it enabled so tapping outside always dismisses the drawer; the
// voice overlay already owns input while voice mode is visible.
gesturesEnabled = true,
drawerContent = {
val drawerTitle = if (effectiveProfile != null) {
stringResource(R.string.chat_profile_sessions, agentDisplayName)
stringResource(R.string.chat_profile_sessions, globalSelectedAgentDisplayName)
} else {
stringResource(R.string.chat_server_default_sessions)
}
@@ -2056,12 +2105,29 @@ fun ChatScreen(
val threadsCapabilityActive = threadsProactiveEnabled &&
threadsAuthState is com.hermesandroid.relay.auth.AuthState.Paired
val hiddenSources by connectionViewModel.hiddenSources.collectAsState()
val proactiveInboxEntries by connectionViewModel.inboxMessages.collectAsState()
val phoneThreadChatIds by connectionViewModel.phoneThreadChatIds.collectAsState()
val provisionalThreadEntries = buildProvisionalThreadRows(
entries = proactiveInboxEntries,
activeConnectionId = activeConnection?.id,
realThreadChatIds = phoneThreadChatIds.values,
)
val provisionalThreads = provisionalThreadEntries.map { (chatId, entries) ->
val latest = entries.maxBy { it.receivedAt }
ProvisionalThreadRow(
chatId = chatId,
title = latest.title.ifBlank { "Hermes" },
messageCount = entries.size,
lastActivityAt = latest.receivedAt,
)
}
SessionDrawerContent(
sessions = sessions,
currentSessionId = currentSessionId,
scopeTitle = drawerTitle,
scopeSubtitle = drawerSubtitle,
activeProfileName = effectiveProfile?.name ?: "default",
isLoading = isLoadingSessions,
isOpen = drawerState.isOpen,
activityStates = sessionActivityStates,
@@ -2073,6 +2139,24 @@ fun ChatScreen(
chatViewModel.createNewChat()
scope.launch { drawerState.close() }
},
onNewDefaultChat = {
val defaultProfile = agentProfiles.firstOrNull {
it.name.equals("default", ignoreCase = true)
} ?: com.hermesandroid.relay.data.Profile(
name = "default",
model = "",
description = "Default",
)
chatViewModel.createProfileChat(
profileName = "default",
profile = defaultProfile,
contextKey = AgentDisplay.profileContextKey(
connectionId = activeConnection?.id,
profileName = "default",
),
)
scope.launch { drawerState.close() }
},
onSelectSession = { sessionId ->
chatViewModel.switchSession(sessionId)
scope.launch { drawerState.close() }
@@ -2102,10 +2186,152 @@ fun ChatScreen(
chatViewModel.startNewThread(name)
scope.launch { drawerState.close() }
},
provisionalThreads = provisionalThreads,
onSelectProvisionalThread = { chatId ->
chatViewModel.openProactiveThread(
chatId,
provisionalThreadEntries[chatId].orEmpty(),
)
scope.launch { drawerState.close() }
},
hiddenSources = hiddenSources,
onToggleSourceHidden = { source, hidden ->
connectionViewModel.setSourceHidden(source, hidden)
},
allProfilesSupported = !activeConnection?.resolvedDashboardUrl.isNullOrBlank(),
allProfileSessions = allProfileSessions,
allProfileSessionsLoading = allProfileSessionsLoading,
profileColors = profilePresentation.colors,
onProfileColorChange = connectionViewModel::setProfileColor,
onRefreshAllProfiles = {
if (!allProfileSessionsLoading) scope.launch {
allProfileSessionsLoading = true
val result = connectionViewModel.listAllProfileSessions()
result?.fold(
onSuccess = { items ->
allProfileSessions = items.mapNotNull { item ->
val owner = item.profile?.takeIf { it.isNotBlank() }
?: return@mapNotNull null
ProfileSessionRow(
profile = owner,
session = com.hermesandroid.relay.data.ChatSession(
sessionId = item.id,
title = item.title ?: item.preview,
model = item.model,
messageCount = item.messageCount ?: 0,
inputTokens = item.inputTokens ?: 0,
outputTokens = item.outputTokens ?: 0,
actualCostUsd = item.actualCostUsd,
estimatedCostUsd = item.estimatedCostUsd,
isActive = item.isActive,
startedAt = ((item.startedAt ?: 0.0) * 1000).toLong(),
lastActivityAt = ((item.resolvedLastActivity ?: 0.0) * 1000).toLong(),
source = item.source,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
),
)
}
},
onFailure = { error ->
snackbarHostState.showSnackbar(
"Couldn't load all profiles: ${error.message ?: "unsupported"}",
)
},
)
allProfileSessionsLoading = false
}
},
onSelectProfileSession = { profileName, sessionId ->
val target = agentProfiles.firstOrNull {
it.name.equals(profileName, ignoreCase = true)
}
if (target != null || profileName.equals("default", ignoreCase = true)) {
val ownerProfile = target ?: allProfileSessions.firstOrNull {
it.profile.equals(profileName, ignoreCase = true) &&
it.session.sessionId == sessionId
}?.session?.let { session ->
com.hermesandroid.relay.data.Profile(
name = profileName,
model = session.model.orEmpty(),
description = profileName,
)
} ?: com.hermesandroid.relay.data.Profile(
name = profileName,
model = "",
description = profileName,
)
chatViewModel.openProfileSession(
profileName = profileName,
profile = ownerProfile,
contextKey = AgentDisplay.profileContextKey(
connectionId = activeConnection?.id,
profileName = profileName,
),
sessionId = sessionId,
)
scope.launch { drawerState.close() }
} else {
scope.launch {
snackbarHostState.showSnackbar("Profile $profileName is not available.")
}
}
},
onDeleteProfileSession = { profileName, sessionId ->
scope.launch {
if (connectionViewModel.deleteSession(profileName, sessionId)) {
allProfileSessions = allProfileSessions.filterNot {
it.profile == profileName && it.session.sessionId == sessionId
}
}
}
},
onRenameProfileSession = { profileName, sessionId, title ->
scope.launch {
if (connectionViewModel.renameSession(profileName, sessionId, title)) {
allProfileSessions = allProfileSessions.map { row ->
if (row.profile == profileName && row.session.sessionId == sessionId) {
row.copy(session = row.session.copy(title = title))
} else {
row
}
}
}
}
},
onSetProfileSessionPinned = { profileName, sessionId, pinned ->
scope.launch {
if (connectionViewModel.setSessionPinned(profileName, sessionId, pinned)) {
allProfileSessions = allProfileSessions.map { row ->
if (row.profile == profileName && row.session.sessionId == sessionId) {
row.copy(session = row.session.copy(pinned = pinned))
} else {
row
}
}
}
}
},
onSetProfileSessionArchived = { profileName, sessionId, archived ->
scope.launch {
if (connectionViewModel.setSessionArchived(profileName, sessionId, archived)) {
allProfileSessions = allProfileSessions.map { row ->
if (row.profile == profileName && row.session.sessionId == sessionId) {
row.copy(session = row.session.copy(archived = archived))
} else {
row
}
}
}
}
},
)
}
) {
@@ -2211,7 +2437,6 @@ fun ChatScreen(
resolveChatHeaderSubtitle(
isStreaming = isStreaming,
statusText = statusText,
projectName = gatewayProjectName,
personalityName = nonDefaultPersonality,
modelName = modelName,
)
@@ -2518,7 +2743,7 @@ fun ChatScreen(
selectedProfile = selectedProfile,
resolvedProfile = effectiveProfile,
presentation = profilePresentation,
activeDisplayName = agentDisplayName,
activeDisplayName = globalSelectedAgentDisplayName,
isProfileLocked = isProfileLocked,
lockedProfileName = lockedProfileName,
switchEnabled = profileSwitchEnabled,
@@ -3023,6 +3248,36 @@ fun ChatScreen(
},
onCardAction = handleCardAction,
onCardInput = handleCardInput,
onSessionReference = { reference ->
val target = agentProfiles.firstOrNull {
it.name.equals(reference.profile, ignoreCase = true)
}
if (target != null) {
connectionViewModel.selectProfile(target)
chatViewModel.activateGatewayProfile(target)
chatViewModel.switchSession(reference.sessionId)
} else {
scope.launch {
snackbarHostState.showSnackbar(
message = "Profile ${reference.profile} is not available.",
duration = SnackbarDuration.Short,
)
}
}
},
onReact = if (
isGatewayTransport &&
messageReactionsSupported &&
!message.isStreaming &&
(
message.rowId != null ||
message.uiKey in newestReactableMessageKeys
)
) {
{ emoji -> chatViewModel.reactToMessage(message, emoji) }
} else {
null
},
onEditMessage = if (
isGatewayTransport &&
!isStreaming &&
@@ -3156,6 +3411,7 @@ fun ChatScreen(
SubagentLane(
taskIndex = taskIndex,
calls = laneGroups.getValue(taskIndex),
onSteer = chatViewModel::steerSubagent,
)
}
}
@@ -3875,6 +4131,23 @@ fun ChatScreen(
onDismiss = { showModelSheet = false },
)
}
modelSelectionConfirmation?.let { confirmation ->
AlertDialog(
onDismissRequest = chatViewModel::dismissModelSelectionConfirmation,
title = { Text(stringResource(R.string.chat_model_confirmation_title)) },
text = { Text(confirmation.message) },
confirmButton = {
TextButton(onClick = chatViewModel::confirmModelSelection) {
Text(stringResource(R.string.cw_continue))
}
},
dismissButton = {
TextButton(onClick = chatViewModel::dismissModelSelectionConfirmation) {
Text(stringResource(R.string.common_cancel))
}
},
)
}
if (showEffortSheet) {
OptionPickerSheet(
title = stringResource(R.string.chat_select_reasoning_effort),
@@ -4134,6 +4407,15 @@ fun ChatScreen(
}
}
internal fun buildProvisionalThreadRows(
entries: List<ProactiveInboxEntry>,
activeConnectionId: String?,
realThreadChatIds: Collection<String>,
): Map<String, List<ProactiveInboxEntry>> = entries
.filter { it.connectionId == null || it.connectionId == activeConnectionId }
.groupBy { it.chatId ?: "phone" }
.filterKeys { it !in realThreadChatIds }
// --- Helper functions ---
@Composable
@@ -4571,32 +4853,29 @@ private suspend fun ingestAttachmentFromUri(
) {
try {
val resolver = context.contentResolver
val maxSize = maxAttachmentMb.toLong() * 1024L * 1024L
val source = withContext(Dispatchers.IO) {
val mimeType = mimeOverride ?: resolver.getType(uri) ?: "application/octet-stream"
val fileName = resolveDisplayName(resolver, uri)
val bytes = resolver.openInputStream(uri)?.use { it.readBytes() } ?: return@withContext null
RawAttachmentSource(mimeType, fileName, bytes)
val payload = resolver.openInputStream(uri)?.use { input ->
readBase64Bounded(input, maxSize)
} ?: return@withContext null
RawAttachmentSource(mimeType, fileName, payload.base64, payload.sizeBytes)
} ?: return
val maxSize = maxAttachmentMb * 1024 * 1024
if (source.bytes.size > maxSize) {
Toast.makeText(
context,
context.getString(R.string.chat_file_too_large, maxAttachmentMb),
Toast.LENGTH_SHORT,
).show()
return
}
val base64 = withContext(Dispatchers.Default) {
Base64.encodeToString(source.bytes, Base64.NO_WRAP)
}
onAttachment(
Attachment(
contentType = source.mimeType,
content = base64,
content = source.base64,
fileName = source.fileName,
fileSize = source.bytes.size.toLong(),
fileSize = source.sizeBytes,
)
)
} catch (_: AttachmentTooLargeException) {
Toast.makeText(
context,
context.getString(R.string.chat_file_too_large, maxAttachmentMb),
Toast.LENGTH_SHORT,
).show()
} catch (e: Exception) {
Toast.makeText(context, context.getString(R.string.chat_failed_read_file), Toast.LENGTH_SHORT).show()
}
@@ -4605,7 +4884,8 @@ private suspend fun ingestAttachmentFromUri(
private data class RawAttachmentSource(
val mimeType: String,
val fileName: String,
val bytes: ByteArray,
val base64: String,
val sizeBytes: Long,
)
/**
@@ -54,6 +54,14 @@ internal enum class DashboardActionKind {
ValidateCustomEndpoint,
ActivateCustomEndpoint,
DeleteCustomEndpoint,
EditLearningNode,
DeleteLearningNode,
ConfigureMemoryProvider,
ActivateMemoryProvider,
SetupWhatsApp,
EnableChannel,
DisableChannel,
TestChannel,
// Input-backed kinds — intercepted before runAction and routed to a
// text-input or model-picker dialog instead of firing immediately.
File diff suppressed because it is too large Load Diff
@@ -264,14 +264,37 @@ fun DashboardSignInScreen(
operation = "dashboard_native_pkce",
)
Log.w(NATIVE_DASHBOARD_AUTH_LOG_TAG, failureDetail)
actionMessage = nativeDashboardSignInActionMessage(
failureStage = failureStage,
errorMessage = error.message,
fallbackMessage = resources.getString(R.string.dashboard_signin_failed),
transportRetryMessage = resources.getString(
actionMessage = when (nativeDashboardSignInMessageKind(failureStage)) {
NativeDashboardSignInMessageKind.CallbackRejected -> resources.getString(
R.string.dashboard_native_signin_callback_rejected,
)
NativeDashboardSignInMessageKind.CodeRejected -> resources.getString(
R.string.dashboard_native_signin_code_rejected,
)
NativeDashboardSignInMessageKind.GatewayRejected -> resources.getString(
R.string.dashboard_native_signin_gateway_rejected,
)
NativeDashboardSignInMessageKind.RateLimited -> resources.getString(
R.string.dashboard_native_signin_rate_limited,
)
NativeDashboardSignInMessageKind.GatewayUnavailable -> resources.getString(
R.string.dashboard_native_signin_gateway_unavailable,
)
NativeDashboardSignInMessageKind.ResponseUnsupported -> resources.getString(
R.string.dashboard_native_signin_response_unsupported,
)
NativeDashboardSignInMessageKind.AttemptInactive -> resources.getString(
R.string.dashboard_native_signin_attempt_inactive,
)
NativeDashboardSignInMessageKind.SecureStorage -> resources.getString(
R.string.dashboard_native_signin_storage_failed,
)
NativeDashboardSignInMessageKind.Transport -> resources.getString(
R.string.dashboard_native_signin_transport_retry,
),
)
)
NativeDashboardSignInMessageKind.Generic -> error.message
?: resources.getString(R.string.dashboard_signin_failed)
}
actionIsError = true
} finally {
actionInFlight = false
@@ -362,17 +385,34 @@ fun DashboardSignInScreen(
}
}
internal fun nativeDashboardSignInActionMessage(
failureStage: String,
errorMessage: String?,
fallbackMessage: String,
transportRetryMessage: String,
): String = if (failureStage.startsWith("token_transport")) {
transportRetryMessage
} else {
errorMessage ?: fallbackMessage
internal enum class NativeDashboardSignInMessageKind {
CallbackRejected,
CodeRejected,
GatewayRejected,
RateLimited,
GatewayUnavailable,
ResponseUnsupported,
AttemptInactive,
SecureStorage,
Transport,
Generic,
}
internal fun nativeDashboardSignInMessageKind(failureStage: String): NativeDashboardSignInMessageKind =
when {
failureStage == "callback_error" -> NativeDashboardSignInMessageKind.CallbackRejected
failureStage == "token_http_400" -> NativeDashboardSignInMessageKind.CodeRejected
failureStage == "token_http_401" || failureStage == "token_http_403" ->
NativeDashboardSignInMessageKind.GatewayRejected
failureStage == "token_http_429" -> NativeDashboardSignInMessageKind.RateLimited
failureStage.startsWith("token_http_5") -> NativeDashboardSignInMessageKind.GatewayUnavailable
failureStage == "token_shape" -> NativeDashboardSignInMessageKind.ResponseUnsupported
failureStage == "inactive_generation" -> NativeDashboardSignInMessageKind.AttemptInactive
failureStage == "token_store" -> NativeDashboardSignInMessageKind.SecureStorage
failureStage.startsWith("token_transport") -> NativeDashboardSignInMessageKind.Transport
else -> NativeDashboardSignInMessageKind.Generic
}
@Composable
private fun DashboardAuthenticationComplete(onContinue: () -> Unit) {
Column(
@@ -64,6 +64,8 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.auth.PairedDeviceInfo
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.routeAuthority
import com.hermesandroid.relay.ui.components.SessionTtlPickerDialog
import com.hermesandroid.relay.ui.components.TransportSecurityBadge
@@ -572,6 +574,18 @@ private fun DeviceCard(
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold
)
val deviceDetail = listOf(device.deviceModel, device.devicePlatform)
.map { it.trim() }
.filter { it.isNotBlank() }
.distinct()
.joinToString(" · ")
if (deviceDetail.isNotBlank()) {
Text(
text = deviceDetail,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (device.deviceId.isNotBlank()) {
Text(
text = device.deviceId,
@@ -927,6 +941,17 @@ private fun EndpointsSubList(
fontFamily = FontFamily.Monospace,
modifier = Modifier.weight(1f),
)
if (candidate.hasSecureProxy()) {
Text(
text = if (candidate.secureLinkCoversAllServices()) {
stringResource(R.string.secure_link_pinned_tls_short)
} else {
stringResource(R.string.secure_link_partial_short)
},
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
}
if (isActive) {
Text(
text = stringResource(R.string.paired_devices_active),
@@ -77,10 +77,12 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ProfileConfigResponse
import com.hermesandroid.relay.data.ProfileMemoryEntry
import com.hermesandroid.relay.data.ProfileSkillEntry
import com.hermesandroid.relay.data.GatewayProfileToolset
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.viewmodel.InspectorSection
import com.hermesandroid.relay.viewmodel.LoadState
import com.hermesandroid.relay.viewmodel.ProfileInspectorViewModel
import com.hermesandroid.relay.viewmodel.ProfileInspectorSource
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonNull
@@ -123,6 +125,9 @@ fun ProfileInspectorScreen(
val soulState by viewModel.soulState.collectAsState()
val memoryState by viewModel.memoryState.collectAsState()
val skillsState by viewModel.skillsState.collectAsState()
val source by viewModel.source.collectAsState()
val gatewayDescription by viewModel.gatewayDescription.collectAsState()
val gatewayWritable by viewModel.gatewayWritable.collectAsState()
// Lazy first-load on screen entry. Keyed on the profile name so a
// re-entry for a different profile (unlikely but possible via deep
@@ -244,6 +249,18 @@ fun ProfileInspectorScreen(
InspectorSection.Config -> ConfigPane(
state = configState,
onRetry = { viewModel.refreshSection(InspectorSection.Config) },
gatewayEditable = source == ProfileInspectorSource.Gateway && gatewayWritable,
editing = viewModel.configEditing.collectAsState().value,
descriptionDraft = viewModel.configDescriptionDraft.collectAsState().value,
providerDraft = viewModel.configProviderDraft.collectAsState().value,
modelDraft = viewModel.configModelDraft.collectAsState().value,
saving = viewModel.configSaving.collectAsState().value,
onBeginEdit = viewModel::beginConfigEdit,
onDescriptionChange = viewModel::updateConfigDescriptionDraft,
onProviderChange = viewModel::updateConfigProviderDraft,
onModelChange = viewModel::updateConfigModelDraft,
onSave = viewModel::saveConfigEdit,
onCancel = viewModel::cancelConfigEdit,
)
InspectorSection.Soul -> SoulPane(
state = soulState,
@@ -257,6 +274,7 @@ fun ProfileInspectorScreen(
onDraftChange = { viewModel.updateSoulDraft(it) },
onSave = { viewModel.saveSoulEdit() },
onCancelEdit = { viewModel.cancelSoulEdit() },
editable = source != ProfileInspectorSource.Gateway || gatewayWritable,
)
InspectorSection.Memory -> MemoryPane(
state = memoryState,
@@ -282,6 +300,13 @@ fun ProfileInspectorScreen(
onToggleSkill = { name, enabled ->
viewModel.toggleSkill(name, enabled)
},
gatewayNative = source == ProfileInspectorSource.Gateway && gatewayWritable,
skillDrafts = viewModel.skillDrafts.collectAsState().value,
toolsets = gatewayDescription?.toolsets.orEmpty(),
toolsetDrafts = viewModel.toolsetDrafts.collectAsState().value,
saving = viewModel.skillsSaving.collectAsState().value,
onToggleToolset = viewModel::toggleToolset,
onSaveDrafts = viewModel::saveSkillEdits,
)
}
}
@@ -291,6 +316,14 @@ fun ProfileInspectorScreen(
private data class InspectorTab(val label: String, val section: InspectorSection)
internal fun profileConfigSaveEnabled(provider: String, model: String, saving: Boolean): Boolean =
provider.isNotBlank() && model.isNotBlank() && !saving
internal fun gatewayDraftSaveVisible(
skillDrafts: Map<String, Boolean>,
toolsetDrafts: Map<String, Boolean>,
): Boolean = skillDrafts.isNotEmpty() || toolsetDrafts.isNotEmpty()
// ---------------------------------------------------------------
// Config pane — JSON tree with collapsible nested objects.
// ---------------------------------------------------------------
@@ -299,6 +332,18 @@ private data class InspectorTab(val label: String, val section: InspectorSection
private fun ConfigPane(
state: LoadState<ProfileConfigResponse>,
onRetry: () -> Unit,
gatewayEditable: Boolean,
editing: Boolean,
descriptionDraft: String,
providerDraft: String,
modelDraft: String,
saving: Boolean,
onBeginEdit: () -> Unit,
onDescriptionChange: (String) -> Unit,
onProviderChange: (String) -> Unit,
onModelChange: (String) -> Unit,
onSave: () -> Unit,
onCancel: () -> Unit,
) {
PaneShell(state = state, onRetry = onRetry) { response ->
var showRawConfig by remember(response.profile, response.config) {
@@ -318,6 +363,21 @@ private fun ConfigPane(
.padding(horizontal = 16.dp, vertical = 12.dp),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
if (gatewayEditable) {
GatewayConfigEditor(
editing = editing,
description = descriptionDraft,
provider = providerDraft,
model = modelDraft,
saving = saving,
onBeginEdit = onBeginEdit,
onDescriptionChange = onDescriptionChange,
onProviderChange = onProviderChange,
onModelChange = onModelChange,
onSave = onSave,
onCancel = onCancel,
)
}
ConfigSummaryCard(response)
OutlinedButton(
@@ -363,6 +423,75 @@ private fun ConfigPane(
}
}
@Composable
private fun GatewayConfigEditor(
editing: Boolean,
description: String,
provider: String,
model: String,
saving: Boolean,
onBeginEdit: () -> Unit,
onDescriptionChange: (String) -> Unit,
onProviderChange: (String) -> Unit,
onModelChange: (String) -> Unit,
onSave: () -> Unit,
onCancel: () -> Unit,
) {
Card(
modifier = Modifier.fillMaxWidth(),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.primaryContainer),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Row(verticalAlignment = Alignment.CenterVertically) {
Column(modifier = Modifier.weight(1f)) {
Text(stringResource(R.string.profile_inspector_gateway_settings), fontWeight = FontWeight.SemiBold)
Text(
stringResource(R.string.profile_inspector_gateway_settings_hint),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (!editing) {
IconButton(onClick = onBeginEdit) {
Icon(Icons.Filled.Edit, stringResource(R.string.profile_inspector_edit_config))
}
}
}
if (editing) {
OutlinedTextField(
value = description,
onValueChange = onDescriptionChange,
modifier = Modifier.fillMaxWidth(),
label = { Text(stringResource(R.string.profile_inspector_description)) },
)
OutlinedTextField(
value = provider,
onValueChange = onProviderChange,
modifier = Modifier.fillMaxWidth(),
singleLine = true,
label = { Text(stringResource(R.string.profile_inspector_provider)) },
)
OutlinedTextField(
value = model,
onValueChange = onModelChange,
modifier = Modifier.fillMaxWidth(),
singleLine = true,
label = { Text(stringResource(R.string.profile_inspector_model)) },
)
EditorBottomBar(
saving = saving,
canSave = profileConfigSaveEnabled(provider, model, saving),
onSave = onSave,
onCancel = onCancel,
)
}
}
}
}
@Composable
private fun ConfigSummaryCard(response: ProfileConfigResponse) {
val topLevelCount = response.config.size
@@ -708,6 +837,7 @@ private fun SoulPane(
onDraftChange: (String) -> Unit,
onSave: () -> Unit,
onCancelEdit: () -> Unit,
editable: Boolean,
) {
PaneShell(state = state, onRetry = onRetry) { response ->
Column(
@@ -759,11 +889,13 @@ private fun SoulPane(
},
)
}
IconButton(onClick = onBeginEdit) {
Icon(
imageVector = Icons.Filled.Edit,
contentDescription = stringResource(R.string.profile_inspector_edit_soul),
)
if (editable) {
IconButton(onClick = onBeginEdit) {
Icon(
imageVector = Icons.Filled.Edit,
contentDescription = stringResource(R.string.profile_inspector_edit_soul),
)
}
}
} else {
IconButton(
@@ -783,14 +915,14 @@ private fun SoulPane(
MonospaceEditor(
content = draft,
onContentChange = onDraftChange,
enabled = !saving,
enabled = editable && !saving,
modifier = Modifier
.fillMaxWidth()
.weight(1f),
)
EditorBottomBar(
saving = saving,
canSave = true,
canSave = editable,
onSave = onSave,
onCancel = onCancelEdit,
)
@@ -1334,9 +1466,16 @@ private fun SkillsPane(
onRetry: () -> Unit,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
gatewayNative: Boolean,
skillDrafts: Map<String, Boolean>,
toolsets: List<GatewayProfileToolset>,
toolsetDrafts: Map<String, Boolean>,
saving: Boolean,
onToggleToolset: (String, Boolean) -> Unit,
onSaveDrafts: () -> Unit,
) {
PaneShell(state = state, onRetry = onRetry) { response ->
if (response.skills.isEmpty()) {
if (response.skills.isEmpty() && !gatewayNative) {
Column(
modifier = Modifier
.fillMaxSize()
@@ -1391,6 +1530,30 @@ private fun SkillsPane(
visibleCount = visibleSkills.size,
)
}
if (gatewayNative && toolsets.isNotEmpty()) {
item(key = "__toolsets__") {
GatewayToolsetsCard(
toolsets = toolsets,
drafts = toolsetDrafts,
onToggle = onToggleToolset,
)
}
}
if (gatewayNative && gatewayDraftSaveVisible(skillDrafts, toolsetDrafts)) {
item(key = "__save_gateway_drafts__") {
Button(
onClick = onSaveDrafts,
enabled = !saving,
modifier = Modifier.fillMaxWidth(),
) {
if (saving) {
CircularProgressIndicator(modifier = Modifier.size(18.dp), strokeWidth = 2.dp)
Spacer(Modifier.width(8.dp))
}
Text(stringResource(if (saving) R.string.profile_inspector_saving else R.string.profile_inspector_save_changes))
}
}
}
if (visibleSkills.isEmpty()) {
item(key = "__skills_empty_filter__") {
Card(
@@ -1430,6 +1593,8 @@ private fun SkillsPane(
},
toggleSupported = toggleSupported,
onToggleSkill = onToggleSkill,
gatewayNative = gatewayNative,
skillDrafts = skillDrafts,
)
}
if (toggleSupported == false) {
@@ -1562,6 +1727,8 @@ private fun SkillCategorySection(
onToggleExpanded: () -> Unit,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
gatewayNative: Boolean,
skillDrafts: Map<String, Boolean>,
) {
val categoryStateDescription = stringResource(
if (expanded) {
@@ -1622,6 +1789,7 @@ private fun SkillCategorySection(
skill = skill,
toggleSupported = toggleSupported,
onToggleSkill = onToggleSkill,
controlledEnabled = if (gatewayNative) skillDrafts[skill.name] ?: skill.enabled else null,
)
if (index != skills.lastIndex) {
HorizontalDivider(
@@ -1640,6 +1808,7 @@ private fun SkillRow(
skill: ProfileSkillEntry,
toggleSupported: Boolean?,
onToggleSkill: (String, Boolean) -> Unit,
controlledEnabled: Boolean?,
) {
// Optimistic local toggle state. The VM's emitted events revert us
// on failure; on success the next `/skills` refetch will overwrite
@@ -1652,6 +1821,7 @@ private fun SkillRow(
// null (probe hasn't completed) → leave tappable but the PUT will
// ask authoritatively.
val switchEnabled = toggleSupported != false
val displayedEnabled = controlledEnabled ?: localEnabled
Row(
modifier = Modifier
@@ -1666,7 +1836,7 @@ private fun SkillRow(
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
if (!localEnabled) {
if (!displayedEnabled) {
Spacer(modifier = Modifier.width(8.dp))
Text(
text = stringResource(R.string.profile_inspector_disabled),
@@ -1684,7 +1854,7 @@ private fun SkillRow(
}
}
val toggleDescription = stringResource(
if (localEnabled) {
if (displayedEnabled) {
R.string.profile_inspector_disable_skill
} else {
R.string.profile_inspector_enable_skill
@@ -1692,7 +1862,7 @@ private fun SkillRow(
skill.name,
)
androidx.compose.material3.Switch(
checked = localEnabled,
checked = displayedEnabled,
enabled = switchEnabled,
modifier = Modifier.semantics {
contentDescription = toggleDescription
@@ -1705,7 +1875,7 @@ private fun SkillRow(
// the next recomposition sees — when the VM updates
// the flag to false post-call, we reset the switch to
// the prior state on the next pass.
localEnabled = new
if (controlledEnabled == null) localEnabled = new
onToggleSkill(skill.name, new)
},
)
@@ -1720,6 +1890,44 @@ private fun SkillRow(
}
}
@Composable
private fun GatewayToolsetsCard(
toolsets: List<GatewayProfileToolset>,
drafts: Map<String, Boolean>,
onToggle: (String, Boolean) -> Unit,
) {
Card(modifier = Modifier.fillMaxWidth()) {
Column(modifier = Modifier.padding(12.dp), verticalArrangement = Arrangement.spacedBy(4.dp)) {
Text(stringResource(R.string.profile_inspector_toolsets), fontWeight = FontWeight.SemiBold)
Text(
stringResource(R.string.profile_inspector_toolsets_hint),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
toolsets.forEach { toolset ->
val enabled = drafts[toolset.name] ?: toolset.enabled
Row(
modifier = Modifier.fillMaxWidth().padding(vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Column(modifier = Modifier.weight(1f)) {
Text(toolset.name, style = MaterialTheme.typography.bodyMedium)
Text(
stringResource(R.string.profile_inspector_tool_count, toolset.toolCount),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
androidx.compose.material3.Switch(
checked = enabled,
onCheckedChange = { onToggle(toolset.name, it) },
)
}
}
}
}
}
// ---------------------------------------------------------------
// Shared UI bits
// ---------------------------------------------------------------
@@ -0,0 +1,51 @@
package com.hermesandroid.relay.ui.theme
import androidx.compose.ui.graphics.Color
import java.util.Locale
import kotlin.math.abs
import kotlin.math.roundToInt
private const val PROFILE_SATURATION = 0.68f
private const val PROFILE_LIGHTNESS = 0.58f
/** The same evenly-spaced 12-hue picker model used by Hermes Desktop. */
val ProfileAccentSwatches: List<String> = (0 until 12).map { index ->
hslColor(index * 30f, PROFILE_SATURATION, PROFILE_LIGHTNESS).toRgbHex()
}
/** Desktop-compatible deterministic profile identity color; default remains neutral. */
fun resolveProfileAccent(name: String?, overrides: Map<String, String>): Color? {
val key = name?.trim().orEmpty()
if (key.isBlank() || key.equals("default", ignoreCase = true)) return null
return accentColor(overrides[key]) ?: deterministicProfileAccent(key)
}
internal fun deterministicProfileAccent(name: String): Color {
var hash = 0u
name.forEach { character -> hash = hash * 31u + character.code.toUInt() }
return hslColor((hash % 360u).toFloat(), PROFILE_SATURATION, PROFILE_LIGHTNESS)
}
private fun hslColor(hue: Float, saturation: Float, lightness: Float): Color {
val chroma = (1f - abs(2f * lightness - 1f)) * saturation
val section = (hue / 60f) % 6f
val x = chroma * (1f - abs(section % 2f - 1f))
val (red, green, blue) = when {
section < 1f -> Triple(chroma, x, 0f)
section < 2f -> Triple(x, chroma, 0f)
section < 3f -> Triple(0f, chroma, x)
section < 4f -> Triple(0f, x, chroma)
section < 5f -> Triple(x, 0f, chroma)
else -> Triple(chroma, 0f, x)
}
val match = lightness - chroma / 2f
return Color(red + match, green + match, blue + match)
}
private fun Color.toRgbHex(): String = String.format(
Locale.ROOT,
"#%02X%02X%02X",
(red * 255f).roundToInt(),
(green * 255f).roundToInt(),
(blue * 255f).roundToInt(),
)
@@ -0,0 +1,46 @@
package com.hermesandroid.relay.util
import java.io.ByteArrayOutputStream
import java.io.InputStream
import java.util.Base64
internal data class BoundedBase64Payload(
val base64: String,
val sizeBytes: Long,
)
internal class AttachmentTooLargeException(
val limitBytes: Long,
) : Exception("attachment exceeds the $limitBytes byte limit")
/**
* Base64-encode [input] while enforcing [limitBytes] before an oversized body
* is buffered. The picker previously called `readBytes()` and checked the cap
* afterwards, allowing a content provider to exhaust the app heap first.
*/
internal fun readBase64Bounded(
input: InputStream,
limitBytes: Long,
): BoundedBase64Payload {
require(limitBytes >= 0L) { "limitBytes must be non-negative" }
val initialCapacity = minOf(limitBytes, 64L * 1024L).toInt()
val encoded = ByteArrayOutputStream(initialCapacity)
var count = 0L
Base64.getEncoder().wrap(encoded).use { base64Out ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
while (true) {
val remaining = limitBytes - count
val requested = minOf(buffer.size.toLong(), remaining + 1L).toInt()
val read = input.read(buffer, 0, requested)
if (read < 0) break
if (read == 0) continue
if (read.toLong() > remaining) throw AttachmentTooLargeException(limitBytes)
base64Out.write(buffer, 0, read)
count += read
}
}
return BoundedBase64Payload(
base64 = encoded.toString(Charsets.US_ASCII.name()),
sizeBytes = count,
)
}
@@ -1,8 +1,8 @@
package com.hermesandroid.relay.util
import kotlinx.coroutines.flow.MutableSharedFlow
import kotlinx.coroutines.flow.SharedFlow
import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.channels.Channel
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.receiveAsFlow
/**
* Cross-layer one-shot navigation requests.
@@ -18,23 +18,21 @@ import kotlinx.coroutines.flow.asSharedFlow
* `BridgeSafetySettingsScreen` instead of dropping the user on `MainActivity`'s
* home screen.
*
* Buffer: `extraBufferCapacity = 4` so back-to-back tryEmit calls during
* `onCreate → setContent` don't drop on the floor before `RelayApp`'s
* collector subscribes. Replay 0 — late subscribers shouldn't replay stale
* navigation intents from prior process lifetimes.
* A buffered [Channel] is intentional here: notification taps are consumed in
* `MainActivity.onCreate` before Compose installs RelayApp's collector. A
* replay-0 SharedFlow drops those cold-start requests when no subscriber exists.
* The channel retains up to four one-shot routes and hands each to the single
* app-root collector exactly once.
*/
object NavRouteRequest {
private val _requests = MutableSharedFlow<String>(
replay = 0,
extraBufferCapacity = 4,
)
private val channel = Channel<String>(capacity = 4)
val requests: SharedFlow<String> = _requests.asSharedFlow()
val requests: Flow<String> = channel.receiveAsFlow()
/** Fire-and-forget emit. Safe to call from any thread, including the main thread. */
fun tryRequest(route: String): Boolean = _requests.tryEmit(route)
fun tryRequest(route: String): Boolean = channel.trySend(route).isSuccess
suspend fun request(route: String) {
_requests.emit(route)
channel.send(route)
}
}
File diff suppressed because it is too large Load Diff
@@ -33,6 +33,7 @@ import com.hermesandroid.relay.data.DemoMode
import com.hermesandroid.relay.data.DashboardEndpoint
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.MediaSettingsRepository
import com.hermesandroid.relay.data.PairingPreferences
@@ -76,18 +77,25 @@ import com.hermesandroid.relay.network.relay.ConnectionState
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.DashboardChatDisplaySettings
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.SessionMessageLoadMode
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.network.upstream.mirrorDashboardSessionCookies
import com.hermesandroid.relay.network.upstream.DashboardAuthSession
import com.hermesandroid.relay.network.upstream.DashboardCookieStore
import com.hermesandroid.relay.network.upstream.DashboardStatus
import com.hermesandroid.relay.network.upstream.multiplexServedProfiles
import com.hermesandroid.relay.network.upstream.NativeDashboardAuthClient
import com.hermesandroid.relay.network.upstream.ToolsetInfo
import com.hermesandroid.relay.network.shared.EndpointResolver
import com.hermesandroid.relay.network.shared.buildPluginProxyClient
import com.hermesandroid.relay.network.shared.buildHermesReachClient
import com.hermesandroid.relay.network.shared.hermesReachRouteOrNull
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
import com.hermesandroid.relay.network.upstream.GatewayAvailability
import com.hermesandroid.relay.network.upstream.ActiveTurnKeepAliveRegistry
import com.hermesandroid.relay.data.KEY_GATEWAY_KEEP_ALIVE
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.GatewayPetGalleryItem
import com.hermesandroid.relay.network.upstream.GatewayKeepAliveService
import com.hermesandroid.relay.network.upstream.HermesApiClient
import com.hermesandroid.relay.network.shared.RouteProbeOutcome
@@ -149,6 +157,31 @@ internal data class RelayUiInputs(
val configured: Boolean,
)
data class HostResourcePressureStatus(
val memoryPressure: String? = null,
val memoryAvailableMb: Int? = null,
val diskPressure: String? = null,
val diskFreeMb: Int? = null,
val lastBootSuspectedOom: Boolean = false,
) {
val needsAttention: Boolean
get() = memoryPressure in setOf("elevated", "critical") ||
diskPressure in setOf("elevated", "critical") ||
lastBootSuspectedOom
val critical: Boolean
get() = memoryPressure == "critical" || diskPressure == "critical" || lastBootSuspectedOom
}
internal fun DashboardStatus.hostResourcePressure(): HostResourcePressureStatus =
HostResourcePressureStatus(
memoryPressure = memory?.pressure,
memoryAvailableMb = memory?.systemAvailableMb,
diskPressure = disk?.pressure,
diskFreeMb = disk?.freeMb,
lastBootSuspectedOom = memory?.lastBootSuspectedOom == true,
)
internal fun RelayUiInputs.requiresReconnectGrace(): Boolean =
configured &&
url.isNotBlank() &&
@@ -237,6 +270,7 @@ internal fun resolveEffectiveDashboardUrl(
endpoint: EndpointCandidate?,
): String {
if (connection == null) return ""
endpoint?.pluginProxyRoutesOrNull()?.dashboardBaseUrl?.let { return it }
endpoint?.dashboard?.url
?.takeIf { it.isNotBlank() }
?.let { return it }
@@ -259,6 +293,7 @@ internal fun resolveEffectiveApiServerUrl(
endpoint: EndpointCandidate?,
): String {
if (savedUrl.isBlank()) return ""
endpoint?.pluginProxyRoutesOrNull()?.apiBaseUrl?.let { return it }
return endpoint?.api?.url?.takeIf { it.isNotBlank() } ?: savedUrl
}
@@ -607,6 +642,25 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
private val endpointResolver = EndpointResolver(
httpClient = endpointProbeClient,
clientForCandidate = { candidate ->
candidate.pluginProxyRoutesOrNull()?.let { proxy ->
val tokenProvider = { (authManager.authState.value as? AuthState.Paired)?.token }
if (candidate.hermesReachRouteOrNull() != null) {
buildHermesReachClient(
baseBuilder = endpointProbeClient.newBuilder(),
outerClient = endpointProbeClient,
candidate = candidate,
sessionTokenProvider = tokenProvider,
)
} else {
buildPluginProxyClient(
baseBuilder = endpointProbeClient.newBuilder(),
routes = proxy,
sessionTokenProvider = tokenProvider,
)
}
}
},
context = application,
)
@@ -617,6 +671,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
context = application,
endpointResolver = endpointResolver,
endpointCandidatesProvider = { activeRouteCandidatesSnapshot() },
proxyClientProvider = { url -> pluginProxyClientForUrl(url) },
// Pull the active device id through AuthManager — it's the same id
// PairingPreferences keys the endpoint list on. Nullable wrapper
// because AuthManager.getOrCreateDeviceId() is suspending.
@@ -712,6 +767,9 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
tokenStoreKeyProvider = { cid ->
connectionStore.connections.value.firstOrNull { it.id == cid }?.tokenStoreKey
},
pinnedClientProvider = { url, base ->
pluginProxyClientForUrl(url, base, includeRelaySessionHeader = false)
},
)
// Agent-profiles collaborator — owns the merged profile list, the
@@ -733,6 +791,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
},
rebuildChatApiClient = { rebuildChatApiClient() },
relayHttpClient = relayHttpClient,
gatewayClientProvider = { upstreamTransport.activeGatewayChatClient() },
)
// --- Relay connection state ---
@@ -783,7 +842,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
*/
val relayRowState: StateFlow<RelayRowState> = combine(
_relayUiState,
connectionManager.activeEndpoint,
connectionManager.activeRelayEndpoint,
) { phase, endpoint ->
RelayRowState(phase = phase, activeEndpointRole = endpoint?.role)
}.stateIn(
@@ -861,11 +920,55 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
private fun effectiveApiServerUrlSnapshot(): String =
resolveEffectiveApiServerUrl(
savedUrl = _apiServerUrl.value,
endpoint = connectionManager.activeEndpoint.value,
endpoint = connectionManager.activeApiEndpoint.value,
)
private fun effectiveRelayUrlSnapshot(): String =
connectionManager.activeEndpoint.value?.relay?.url ?: autoRelayUrlSnapshot()
connectionManager.activeEndpoint.value?.relay?.url
?: autoRelayUrlSnapshot()
private fun effectiveRelayWebSocketUrlSnapshot(): String =
connectionManager.activeRelayEndpoint.value?.pluginProxyRoutesOrNull()?.relayWebSocketUrl
?: connectionManager.activeRelayEndpoint.value?.relay?.url
?: autoRelayUrlSnapshot()
private fun pluginProxyClientForUrl(
url: String,
baseClient: OkHttpClient? = null,
includeRelaySessionHeader: Boolean = true,
): OkHttpClient? {
val requestAuthority = runCatching {
val parsed = java.net.URI(url)
val port = if (parsed.port > 0) parsed.port else 443
"${parsed.host?.lowercase()}:$port"
}.getOrNull() ?: return null
val candidate = activeConnection.value?.routeCandidates.orEmpty()
.firstOrNull { it.pluginProxyRoutesOrNull()?.authority == requestAuthority }
?: return null
val routes = candidate.pluginProxyRoutesOrNull() ?: return null
val configuredBuilder = (baseClient?.newBuilder() ?: OkHttpClient.Builder())
.connectTimeout(20, TimeUnit.SECONDS)
.readTimeout(0, TimeUnit.MILLISECONDS)
.pingInterval(30, TimeUnit.SECONDS)
val sessionTokenProvider = {
(authManager.authState.value as? AuthState.Paired)?.token
}
if (candidate.hermesReachRouteOrNull() != null) {
return buildHermesReachClient(
baseBuilder = configuredBuilder,
outerClient = endpointProbeClient,
candidate = candidate,
sessionTokenProvider = sessionTokenProvider,
includeRelaySessionHeader = includeRelaySessionHeader,
)
}
return buildPluginProxyClient(
baseBuilder = configuredBuilder,
routes = routes,
sessionTokenProvider = sessionTokenProvider,
includeRelaySessionHeader = includeRelaySessionHeader,
)
}
private fun autoRelayUrlSnapshot(): String {
val savedRelay = _relayUrl.value
@@ -995,6 +1098,10 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
val standardVoiceAvailability: StateFlow<StandardVoiceAvailability> =
_standardVoiceAvailability.asStateFlow()
private val _hostResourcePressure = MutableStateFlow(HostResourcePressureStatus())
val hostResourcePressure: StateFlow<HostResourcePressureStatus> =
_hostResourcePressure.asStateFlow()
private val _standardAudioApiReachable = MutableStateFlow(false)
val standardAudioApiReachable: StateFlow<Boolean> = _standardAudioApiReachable.asStateFlow()
@@ -1126,7 +1233,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
*/
val effectiveApiServerUrl: StateFlow<String> = combine(
_apiServerUrl,
connectionManager.activeEndpoint,
connectionManager.activeApiEndpoint,
) { savedUrl, endpoint ->
resolveEffectiveApiServerUrl(savedUrl, endpoint)
}.stateIn(viewModelScope, SharingStarted.Eagerly, "")
@@ -1492,8 +1599,32 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
suspend fun listProfileScopedSessions(limit: Int = 200): Result<List<SessionItem>>? =
profileController.listProfileScopedSessions(limit)
suspend fun loadProfileScopedMessages(sessionId: String): Result<List<MessageItem>>? =
profileController.loadProfileScopedMessages(sessionId)
suspend fun listAllProfileSessions(limit: Int = 200): Result<List<SessionItem>>? =
profileController.listAllProfileSessions(limit)
suspend fun deleteSession(profileName: String, sessionId: String): Boolean =
profileController.deleteSession(profileName, sessionId)
suspend fun renameSession(profileName: String, sessionId: String, title: String): Boolean =
profileController.renameSession(profileName, sessionId, title)
suspend fun setSessionPinned(profileName: String, sessionId: String, pinned: Boolean): Boolean =
profileController.setSessionPinned(profileName, sessionId, pinned)
suspend fun setSessionArchived(profileName: String, sessionId: String, archived: Boolean): Boolean =
profileController.setSessionArchived(profileName, sessionId, archived)
suspend fun loadProfileScopedMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>>? = profileController.loadProfileScopedMessages(sessionId, mode)
suspend fun loadProfileScopedMessages(
profileName: String?,
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>>? =
profileController.loadProfileScopedMessages(profileName, sessionId, mode)
/**
* Delete a session scoped to the ACTIVE PROFILE via the dashboard
@@ -1543,6 +1674,9 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
fun setProfileHidden(profileName: String?, hidden: Boolean) =
profileController.setProfileHidden(profileName, hidden)
fun setProfileColor(profileName: String, colorHex: String?) =
profileController.setProfileColor(profileName, colorHex)
fun resetProfilePresentation() = profileController.resetProfilePresentation()
/**
@@ -1559,6 +1693,14 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
/** The active profile's local agent-icon path (client-side, never sent to Hermes). */
val profileIcon: StateFlow<String?> get() = profileController.profileIcon
val localProfileIcon: StateFlow<String?> get() = profileController.localProfileIcon
val serverProfileAvatar: StateFlow<String?> get() = profileController.serverProfileAvatar
val useLocalProfileIconOverride: StateFlow<Boolean>
get() = profileController.useLocalProfileIconOverride
val sharedProfileAvatarState: StateFlow<ProfileController.SharedAvatarState>
get() = profileController.sharedAvatarState
val hermesPetState: StateFlow<ProfileController.HermesPetState>
get() = profileController.hermesPetState
/** A local icon path for a specific profile identity on the active connection. */
fun profileIconFlow(profileName: String?) = profileController.profileIconFlow(profileName)
@@ -1568,10 +1710,32 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
fun setProfileIcon(uri: Uri) = profileController.setProfileIcon(uri)
fun setSharedProfileAvatar(uri: Uri) = profileController.setSharedProfileAvatar(uri)
fun setUseLocalProfileIconOverride(enabled: Boolean) =
profileController.setUseLocalProfileIconOverride(enabled)
fun importProfileIconFromHost() = profileController.importProfileIconFromHost()
fun clearProfileIcon() = profileController.clearProfileIcon()
fun uploadLocalProfileIconToHermes() = profileController.uploadLocalProfileIconToHermes()
fun clearSharedProfileAvatar() = profileController.clearSharedProfileAvatar()
fun refreshHermesPet() = profileController.refreshHermesPet()
fun loadHermesPetGallery() = profileController.loadHermesPetGallery()
fun selectHermesPet(slug: String) = profileController.selectHermesPet(slug)
fun loadHermesPetThumbnail(pet: GatewayPetGalleryItem) =
profileController.loadHermesPetThumbnail(pet)
fun disableHermesPet() = profileController.disableHermesPet()
fun refreshGatewayProfiles() = profileController.refreshGatewayProfiles()
fun selectProfile(profile: Profile?) = profileController.selectProfile(profile)
// --- Profile lock (per-connection pin to one profile) ------------------
@@ -1851,6 +2015,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
}
init {
authManager.setActiveEndpointProvider { connectionManager.activeRelayEndpoint.value }
// Materialize the independent central and floating preferences. Legacy
// users retain the prior visual in both roles until they choose otherwise.
viewModelScope.launch {
@@ -2280,6 +2445,8 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
text = msg.text,
receivedAt = msg.sentAt ?: System.currentTimeMillis(),
chatId = msg.chatId,
connectionId = connectionStore.activeConnectionId.value,
arrivedWhileAway = msg.arrivedWhileAway,
),
)
}
@@ -2455,6 +2622,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
}
private fun installAuthManager(am: AuthManager) {
am.setActiveEndpointProvider { connectionManager.activeRelayEndpoint.value }
authManager = am
// Push into the flow so the flatMapLatest chains on authState /
// pairingCode / currentPairedSession repoint to the new manager.
@@ -4152,6 +4320,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
.collectLatest {
_standardVoiceAvailability.value = StandardVoiceAvailability.Unknown
_standardAudioApiReachable.value = false
_hostResourcePressure.value = HostResourcePressureStatus()
_serverChatDisplaySettings.value = null
updateGatewayAvailability(GatewayAvailability.Unknown)
probeStandardVoice()
@@ -4451,6 +4620,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
if (connectionId == null || dashboardUrl.isNullOrBlank()) {
_standardVoiceAvailability.value = StandardVoiceAvailability.Unknown
_standardAudioApiReachable.value = false
_hostResourcePressure.value = HostResourcePressureStatus()
_serverChatDisplaySettings.value = null
updateGatewayAvailability(GatewayAvailability.Unknown)
return
@@ -4469,11 +4639,13 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
updateDashboardTopology(connectionId, null)
_standardVoiceAvailability.value = StandardVoiceAvailability.Unreachable
_standardAudioApiReachable.value = false
_hostResourcePressure.value = HostResourcePressureStatus()
_serverChatDisplaySettings.value = null
updateGatewayAvailability(GatewayAvailability.Unreachable)
recordDashboardStatusIfChanged(connectionId, status = null, session = null)
return
}
_hostResourcePressure.value = status.hostResourcePressure()
updateDashboardTopology(connectionId, status)
val session = if (status.authRequired) client.currentSession().getOrNull() else null
val authed = !status.authRequired || session?.authenticated == true
@@ -4511,6 +4683,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
android.util.Log.w("ConnectionVM", "probeStandardVoice failed: ${e.message}")
_standardVoiceAvailability.value = StandardVoiceAvailability.Unreachable
_standardAudioApiReachable.value = false
_hostResourcePressure.value = HostResourcePressureStatus()
_serverChatDisplaySettings.value = null
updateGatewayAvailability(GatewayAvailability.Unreachable)
} finally {
@@ -4553,14 +4726,14 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
?.dashboardLastStatus
val liveTopology = topologyConnectionId == activeConnectionId
val mode = if (liveTopology) topologyGatewayMode else persisted?.gatewayMode
val profiles = if (liveTopology) topologyProfiles else persisted?.profiles.orEmpty()
val profiles = if (liveTopology) topologyProfiles else persisted?.servedProfiles.orEmpty()
return mode.equals("multiplex", ignoreCase = true) && profile.name in profiles
}
/** Keep chat routing synchronized with the latest public dashboard topology. */
private suspend fun updateDashboardTopology(connectionId: String, status: DashboardStatus?) {
val nextMode = status?.gatewayMode
val nextProfiles = status?.profiles.orEmpty()
val nextProfiles = status?.multiplexServedProfiles().orEmpty()
val changed = topologyConnectionId != connectionId ||
topologyGatewayMode != nextMode ||
topologyProfiles != nextProfiles
@@ -4605,6 +4778,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
previous.authRequired == status?.authRequired &&
previous.authenticated == session?.authenticated &&
previous.gatewayMode == status?.gatewayMode &&
previous.servedProfiles == status?.multiplexServedProfiles().orEmpty() &&
previous.profiles == status?.profiles.orEmpty()
if (!materiallySame) {
recordDashboardStatus(status = status, session = session, reachable = reachable)
@@ -5171,6 +5345,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
gatewayTicketAvailable = gatewayTicketAvailable,
message = message,
gatewayMode = status?.gatewayMode,
servedProfiles = status?.multiplexServedProfiles().orEmpty(),
profiles = status?.profiles.orEmpty(),
),
)
@@ -5205,6 +5380,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
gatewayTicketAvailable = false,
message = "Dashboard session cleared",
gatewayMode = active?.dashboardLastStatus?.gatewayMode,
servedProfiles = active?.dashboardLastStatus?.servedProfiles.orEmpty(),
profiles = active?.dashboardLastStatus?.profiles.orEmpty(),
),
)
@@ -5611,7 +5787,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
profileApiUrl = selectedProfile?.apiServerUrl,
selectedProfileName = selectedProfile?.name,
gatewayMode = if (liveTopology) topologyGatewayMode else topology?.gatewayMode,
servedProfiles = if (liveTopology) topologyProfiles else topology?.profiles.orEmpty(),
servedProfiles = if (liveTopology) topologyProfiles else topology?.servedProfiles.orEmpty(),
)
}
@@ -5736,7 +5912,13 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
// a coherent in-flight pose instead of flashing the previous
// result through.
_apiServerHealth.value = HealthStatus.Probing
val client = HermesApiClient(baseUrl = url, apiKey = key)
val client = HermesApiClient(
baseUrl = url,
apiKey = key,
httpClient = pluginProxyClientForUrl(
url, includeRelaySessionHeader = false
),
)
_apiClient.value = client
shutdownClientOffMain(oldClient)
val ok = client.checkHealth()
@@ -5768,7 +5950,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
?.dashboardLastStatus
val liveTopology = topologyConnectionId == activeConnectionId
val gatewayMode = if (liveTopology) topologyGatewayMode else topology?.gatewayMode
val servedProfiles = if (liveTopology) topologyProfiles else topology?.profiles.orEmpty()
val servedProfiles = if (liveTopology) topologyProfiles else topology?.servedProfiles.orEmpty()
val usesMultiplexProfileKey = ProfileApiUrlResolver.usesMultiplexProfileKey(
profileApiUrl = selectedProfile?.apiServerUrl,
selectedProfileName = selectedProfile?.name,
@@ -5815,7 +5997,13 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
return
}
val nextProfileClient = HermesApiClient(baseUrl = profileApiUrl, apiKey = key)
val nextProfileClient = HermesApiClient(
baseUrl = profileApiUrl,
apiKey = key,
httpClient = pluginProxyClientForUrl(
profileApiUrl, includeRelaySessionHeader = false
),
)
profileChatApiClient = nextProfileClient
profileChatApiClientUrl = profileApiUrl
profileChatApiClientKey = key
@@ -5864,7 +6052,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
}
fun connectRelay() {
connectRelayInternal(effectiveRelayUrlSnapshot())
connectRelayInternal(effectiveRelayWebSocketUrlSnapshot())
}
/**
@@ -6267,6 +6455,7 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
* is unavailable.
*/
suspend fun lookupEndpointPin(candidate: com.hermesandroid.relay.data.EndpointCandidate): String? {
candidate.proxy?.pinSha256?.takeIf { candidate.hasSecureProxy() }?.let { return it }
val hostPort = candidate.routeAuthority() ?: return null
val pins = PairingPreferences.getTofuPins(getApplication())
return pins[hostPort]
@@ -3,11 +3,21 @@ package com.hermesandroid.relay.viewmodel
import androidx.lifecycle.SavedStateHandle
import androidx.lifecycle.ViewModel
import androidx.lifecycle.viewModelScope
import com.hermesandroid.relay.data.GatewayProfileConfigureResult
import com.hermesandroid.relay.data.GatewayProfileDescription
import com.hermesandroid.relay.data.GatewayProfileEditorClient
import com.hermesandroid.relay.data.GatewayProfileEditorUnsupportedException
import com.hermesandroid.relay.data.GatewayProfilePatch
import com.hermesandroid.relay.data.GatewayProfileSection
import com.hermesandroid.relay.data.LegacyProfileInspectorClient
import com.hermesandroid.relay.data.ProfileConfigResponse
import com.hermesandroid.relay.data.ProfileMemoryResponse
import com.hermesandroid.relay.data.ProfileSkillEntry
import com.hermesandroid.relay.data.ProfileSkillsResponse
import com.hermesandroid.relay.data.ProfileSoulResponse
import com.hermesandroid.relay.network.relay.RelayProfileInspectorClient
import com.hermesandroid.relay.data.RelaySkillToggleResult
import kotlinx.coroutines.async
import kotlinx.coroutines.coroutineScope
import kotlinx.coroutines.flow.MutableSharedFlow
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.SharedFlow
@@ -15,24 +25,12 @@ import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.launch
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.buildJsonObject
import kotlinx.serialization.json.put
/**
* One of the four sections the inspector screen can display — used by
* [ProfileInspectorViewModel.refreshSection] to target a single pane
* without reloading the whole screen.
*/
enum class InspectorSection { Config, Soul, Memory, Skills }
/**
* Generic load state for each of the four inspector sections. Kept
* separate per section so a slow `/memory` fetch doesn't block the
* already-arrived `/config` tab from rendering.
*
* `Idle` is the pre-first-fetch state (useful for "don't render anything
* yet"); `Loading` is during an active fetch; `Loaded` carries the
* successfully-parsed payload; `Error` carries a human-readable message
* for inline display with a retry button.
*/
sealed class LoadState<out T> {
data object Idle : LoadState<Nothing>()
data object Loading : LoadState<Nothing>()
@@ -40,168 +38,153 @@ sealed class LoadState<out T> {
data class Error(val message: String) : LoadState<Nothing>()
}
enum class ProfileInspectorSource { Unknown, Gateway, Relay }
/**
* ViewModel for the Profile Inspector screen. Owns four load states
* (one per section) plus a one-shot `loadAll()` and per-section
* `refreshSection()` for pull-to-refresh. Lazy: no fetch is kicked off
* until the screen first calls [loadAll].
*
* The inspected profile name comes in via [SavedStateHandle] so it
* survives process death — Android nav graph arg → SavedStateHandle is
* the standard path. If the arg is missing (unexpected), [profileName]
* falls back to an empty string and every fetch short-circuits to an
* error state.
* Owns one immutable profile-name namespace. Gateway-native describe/configure
* is preferred when the active connection exposes it; Relay reads remain the
* compatibility fallback and the sole owner of memory-file editing.
*/
class ProfileInspectorViewModel(
private val client: RelayProfileInspectorClient,
private val legacyClient: LegacyProfileInspectorClient,
private val gatewayClient: GatewayProfileEditorClient?,
savedStateHandle: SavedStateHandle,
) : ViewModel() {
/**
* Key the screen pass on. Read from [SavedStateHandle] so a
* process-death restore brings the same profile back — Android
* nav args are automatically mirrored into savedStateHandle when
* the screen is registered via `composable(route, arguments=...)`.
*/
val profileName: String =
savedStateHandle.get<String>(ARG_PROFILE_NAME).orEmpty()
val profileName: String = savedStateHandle.get<String>(ARG_PROFILE_NAME).orEmpty()
private val _configState =
MutableStateFlow<LoadState<ProfileConfigResponse>>(LoadState.Idle)
val configState: StateFlow<LoadState<ProfileConfigResponse>> =
_configState.asStateFlow()
private val _source = MutableStateFlow(ProfileInspectorSource.Unknown)
val source: StateFlow<ProfileInspectorSource> = _source.asStateFlow()
private val _soulState =
MutableStateFlow<LoadState<ProfileSoulResponse>>(LoadState.Idle)
val soulState: StateFlow<LoadState<ProfileSoulResponse>> =
_soulState.asStateFlow()
private val _gatewayDescription = MutableStateFlow<GatewayProfileDescription?>(null)
val gatewayDescription: StateFlow<GatewayProfileDescription?> = _gatewayDescription.asStateFlow()
private val _gatewayWritable = MutableStateFlow(false)
val gatewayWritable: StateFlow<Boolean> = _gatewayWritable.asStateFlow()
private var gatewayConfigureUnsupported = false
private val _memoryState =
MutableStateFlow<LoadState<ProfileMemoryResponse>>(LoadState.Idle)
val memoryState: StateFlow<LoadState<ProfileMemoryResponse>> =
_memoryState.asStateFlow()
private val _configState = MutableStateFlow<LoadState<ProfileConfigResponse>>(LoadState.Idle)
val configState: StateFlow<LoadState<ProfileConfigResponse>> = _configState.asStateFlow()
private val _soulState = MutableStateFlow<LoadState<ProfileSoulResponse>>(LoadState.Idle)
val soulState: StateFlow<LoadState<ProfileSoulResponse>> = _soulState.asStateFlow()
private val _memoryState = MutableStateFlow<LoadState<ProfileMemoryResponse>>(LoadState.Idle)
val memoryState: StateFlow<LoadState<ProfileMemoryResponse>> = _memoryState.asStateFlow()
private val _skillsState = MutableStateFlow<LoadState<ProfileSkillsResponse>>(LoadState.Idle)
val skillsState: StateFlow<LoadState<ProfileSkillsResponse>> = _skillsState.asStateFlow()
private val _skillsState =
MutableStateFlow<LoadState<ProfileSkillsResponse>>(LoadState.Idle)
val skillsState: StateFlow<LoadState<ProfileSkillsResponse>> =
_skillsState.asStateFlow()
// -----------------------------------------------------------------
// UI view-state flags — session-scoped (no DataStore). All of these
// are kept on the VM rather than inside the Composable so they
// survive process-death restore via SavedStateHandle plumbing and
// — more importantly — recomposition-bound state hoists cleanly
// into a single source of truth per pane.
// -----------------------------------------------------------------
/**
* SOUL pane render mode. Defaults to rendered markdown — raw source
* is an explicit opt-in toggle in the top-right of the pane. Kept
* session-scoped because "Bailey wants raw this time" is a transient
* preference, not something worth persisting across app restarts.
*/
private val _soulRawView = MutableStateFlow(false)
val soulRawView: StateFlow<Boolean> = _soulRawView.asStateFlow()
fun toggleSoulRawView() {
_soulRawView.value = !_soulRawView.value
}
// -----------------------------------------------------------------
// Edit-mode state for SOUL + memory panes.
//
// Both panes share the same edit-mode pattern:
// 1. User taps the pencil icon → enters edit mode.
// 2. A monospace BasicTextField lets them type; state is kept in
// [soulDraft] / [memoryDraft]. The currently-saving flag is
// [soulSaving] / [memorySaving] so the Save button disables
// and a progress indicator renders.
// 3. On Save we PUT and, on success, reload the pane (fresh
// content from disk) and emit an [EditEvent.Saved] so the
// screen shows a snackbar. On failure we stay in edit mode so
// the user can retry.
//
// Per-memory-entry edit uses the same triple of flows keyed by
// filename. A separate key-based design (rather than "one memory
// entry at a time") keeps the door open to tabbed edits later
// without rewiring the state model.
// -----------------------------------------------------------------
/** User-facing snackbar events emitted by the edit pipeline. */
sealed class EditEvent {
data class Saved(val message: String) : EditEvent()
data class Error(val message: String) : EditEvent()
}
private val _editEvents = MutableSharedFlow<EditEvent>(
extraBufferCapacity = 8,
)
private val _editEvents = MutableSharedFlow<EditEvent>(extraBufferCapacity = 8)
val editEvents: SharedFlow<EditEvent> = _editEvents.asSharedFlow()
// --- SOUL edit state ---------------------------------------------
private val _soulRawView = MutableStateFlow(false)
val soulRawView: StateFlow<Boolean> = _soulRawView.asStateFlow()
fun toggleSoulRawView() { _soulRawView.value = !_soulRawView.value }
private val _configEditing = MutableStateFlow(false)
val configEditing: StateFlow<Boolean> = _configEditing.asStateFlow()
private val _configDescriptionDraft = MutableStateFlow("")
val configDescriptionDraft: StateFlow<String> = _configDescriptionDraft.asStateFlow()
private val _configProviderDraft = MutableStateFlow("")
val configProviderDraft: StateFlow<String> = _configProviderDraft.asStateFlow()
private val _configModelDraft = MutableStateFlow("")
val configModelDraft: StateFlow<String> = _configModelDraft.asStateFlow()
private val _configSaving = MutableStateFlow(false)
val configSaving: StateFlow<Boolean> = _configSaving.asStateFlow()
fun beginConfigEdit() {
val description = _gatewayDescription.value ?: return
_configDescriptionDraft.value = description.description
_configProviderDraft.value = description.provider
_configModelDraft.value = description.model
_configEditing.value = true
}
fun updateConfigDescriptionDraft(value: String) { _configDescriptionDraft.value = value }
fun updateConfigProviderDraft(value: String) { _configProviderDraft.value = value }
fun updateConfigModelDraft(value: String) { _configModelDraft.value = value }
fun cancelConfigEdit() { _configEditing.value = false }
fun saveConfigEdit() {
val baseline = _gatewayDescription.value ?: return
if (_configSaving.value) return
val descriptionChanged = _configDescriptionDraft.value != baseline.description
val modelChanged = _configProviderDraft.value != baseline.provider ||
_configModelDraft.value != baseline.model
if (modelChanged && (_configProviderDraft.value.isBlank() || _configModelDraft.value.isBlank())) {
_editEvents.tryEmit(EditEvent.Error("Provider and model are both required"))
return
}
val patch = GatewayProfilePatch(
description = _configDescriptionDraft.value.takeIf { descriptionChanged },
provider = _configProviderDraft.value.takeIf { modelChanged },
model = _configModelDraft.value.takeIf { modelChanged },
)
if (patch.requestedSections.isEmpty()) {
_configEditing.value = false
return
}
_configSaving.value = true
saveGatewayPatch(patch) { result, refreshed ->
if (GatewayProfileSection.Description in result.applied) {
_configDescriptionDraft.value = refreshed.description
}
if (GatewayProfileSection.Model in result.applied) {
_configProviderDraft.value = refreshed.provider
_configModelDraft.value = refreshed.model
}
_configEditing.value = result.failed.isNotEmpty()
_configSaving.value = false
}
}
private val _soulEditing = MutableStateFlow(false)
val soulEditing: StateFlow<Boolean> = _soulEditing.asStateFlow()
private val _soulDraft = MutableStateFlow("")
val soulDraft: StateFlow<String> = _soulDraft.asStateFlow()
private val _soulSaving = MutableStateFlow(false)
val soulSaving: StateFlow<Boolean> = _soulSaving.asStateFlow()
fun beginSoulEdit() {
val current = (soulState.value as? LoadState.Loaded)?.value?.content ?: ""
_soulDraft.value = current
_soulDraft.value = (soulState.value as? LoadState.Loaded)?.value?.content.orEmpty()
_soulEditing.value = true
}
fun updateSoulDraft(content: String) {
_soulDraft.value = content
}
fun cancelSoulEdit() {
_soulEditing.value = false
_soulDraft.value = ""
}
fun updateSoulDraft(content: String) { _soulDraft.value = content }
fun cancelSoulEdit() { _soulEditing.value = false }
fun saveSoulEdit() {
if (profileName.isBlank() || _soulSaving.value) return
val content = _soulDraft.value
_soulSaving.value = true
if (_source.value == ProfileInspectorSource.Gateway) {
saveGatewayPatch(GatewayProfilePatch(soul = _soulDraft.value)) { result, refreshed ->
if (GatewayProfileSection.Soul in result.applied) {
_soulDraft.value = refreshed.soul
_soulEditing.value = false
}
_soulSaving.value = false
}
return
}
viewModelScope.launch {
val result = client.updateSoul(profileName, content)
val result = legacyClient.updateSoul(profileName, _soulDraft.value)
_soulSaving.value = false
result.fold(
onSuccess = {
_soulEditing.value = false
_soulDraft.value = ""
_editEvents.tryEmit(EditEvent.Saved("SOUL saved"))
// Re-fetch the pane so the user sees freshly-loaded
// content (byte counts, truncation flags etc.).
refreshSection(InspectorSection.Soul)
},
onFailure = { err ->
_editEvents.tryEmit(
EditEvent.Error(err.message ?: "Save failed")
)
refreshLegacySection(InspectorSection.Soul)
},
onFailure = { _editEvents.tryEmit(EditEvent.Error(it.message ?: "Save failed")) },
)
}
}
// --- Memory edit state (keyed by filename) ------------------------
/**
* Filename of the memory entry currently being edited, or `null`
* when no memory entry is in edit mode. A single active edit at a
* time — matches the card-expansion model already in the pane.
*/
private val _memoryEditingFilename = MutableStateFlow<String?>(null)
val memoryEditingFilename: StateFlow<String?> = _memoryEditingFilename.asStateFlow()
private val _memoryDraft = MutableStateFlow("")
val memoryDraft: StateFlow<String> = _memoryDraft.asStateFlow()
private val _memorySaving = MutableStateFlow(false)
val memorySaving: StateFlow<Boolean> = _memorySaving.asStateFlow()
@@ -209,206 +192,297 @@ class ProfileInspectorViewModel(
_memoryEditingFilename.value = filename
_memoryDraft.value = initialContent
}
fun updateMemoryDraft(content: String) {
_memoryDraft.value = content
}
fun cancelMemoryEdit() {
_memoryEditingFilename.value = null
_memoryDraft.value = ""
}
fun updateMemoryDraft(content: String) { _memoryDraft.value = content }
fun cancelMemoryEdit() { _memoryEditingFilename.value = null }
fun saveMemoryEdit() {
val filename = _memoryEditingFilename.value ?: return
if (profileName.isBlank() || _memorySaving.value) return
val content = _memoryDraft.value
// Client-side filename sanity so we don't round-trip an obvious
// bad name and eat a 400. Server validates authoritatively.
val err = validateMemoryFilename(filename)
if (err != null) {
_editEvents.tryEmit(EditEvent.Error(err))
validateMemoryFilename(filename)?.let {
_editEvents.tryEmit(EditEvent.Error(it))
return
}
_memorySaving.value = true
viewModelScope.launch {
val result = client.updateMemoryEntry(profileName, filename, content)
val result = legacyClient.updateMemoryEntry(profileName, filename, _memoryDraft.value)
_memorySaving.value = false
result.fold(
onSuccess = {
_memoryEditingFilename.value = null
_memoryDraft.value = ""
_editEvents.tryEmit(EditEvent.Saved("Memory entry saved"))
refreshSection(InspectorSection.Memory)
},
onFailure = { e ->
_editEvents.tryEmit(
EditEvent.Error(e.message ?: "Save failed")
)
refreshLegacySection(InspectorSection.Memory)
},
onFailure = { _editEvents.tryEmit(EditEvent.Error(it.message ?: "Save failed")) },
)
}
}
// -----------------------------------------------------------------
// Skill toggle — server stubs this out as HTTP 501 today. We expose
// the probe result so the Skills pane can disable the Switch until
// the relay implements the endpoint, and we emit the 501 response
// as an EditEvent.Error on optimistic tap so the UI can revert
// the Switch visual state.
// -----------------------------------------------------------------
/**
* Capability flag. `null` = probe hasn't run yet (Switch renders
* enabled-but-pending); `true` = server claimed support on the
* capability probe; `false` = 501 / 404 / 405 — definitively not
* supported, Switch renders ghosted.
*/
private val _skillToggleSupported = MutableStateFlow<Boolean?>(null)
val skillToggleSupported: StateFlow<Boolean?> = _skillToggleSupported.asStateFlow()
private val _skillDrafts = MutableStateFlow<Map<String, Boolean>>(emptyMap())
val skillDrafts: StateFlow<Map<String, Boolean>> = _skillDrafts.asStateFlow()
private val _toolsetDrafts = MutableStateFlow<Map<String, Boolean>>(emptyMap())
val toolsetDrafts: StateFlow<Map<String, Boolean>> = _toolsetDrafts.asStateFlow()
private val _skillsSaving = MutableStateFlow(false)
val skillsSaving: StateFlow<Boolean> = _skillsSaving.asStateFlow()
/**
* One-shot capability probe. Fires at screen-open time from the
* Composable; idempotent — extra calls during the screen's lifetime
* reprobe but leave a positive result in place on failure.
*/
fun probeSkillToggleSupport() {
if (_source.value == ProfileInspectorSource.Gateway) {
_skillToggleSupported.value = true
return
}
viewModelScope.launch {
val supported = client.probeSkillToggleSupported()
_skillToggleSupported.value = supported
val supported = legacyClient.probeSkillToggleSupported()
if (_source.value != ProfileInspectorSource.Gateway) {
_skillToggleSupported.value = supported
}
}
}
/**
* Optimistic toggle — UI flips the switch immediately, then we PUT.
* On a 501 we emit an error event so the screen can revert the
* local visual state and cache "not supported" so subsequent taps
* are short-circuited.
*/
fun toggleSkill(skillName: String, enabled: Boolean) {
if (_source.value == ProfileInspectorSource.Gateway) {
val baseline = _gatewayDescription.value?.skills?.firstOrNull { it.name == skillName }
?.enabled ?: return
_skillDrafts.value = _skillDrafts.value.toMutableMap().apply {
if (enabled == baseline) remove(skillName) else put(skillName, enabled)
}
return
}
viewModelScope.launch {
val result = client.updateSkillToggle(skillName, enabled)
result.fold(
onSuccess = { outcome ->
when (outcome) {
is RelayProfileInspectorClient.SkillToggleResult.Ok ->
_editEvents.tryEmit(
EditEvent.Saved(
if (enabled) "Enabled $skillName" else "Disabled $skillName"
)
)
is RelayProfileInspectorClient.SkillToggleResult.NotImplemented -> {
legacyClient.updateSkillToggle(skillName, enabled).fold(
onSuccess = {
when (it) {
RelaySkillToggleResult.Ok -> {
_editEvents.tryEmit(EditEvent.Saved(if (enabled) "Enabled $skillName" else "Disabled $skillName"))
refreshLegacySection(InspectorSection.Skills)
}
RelaySkillToggleResult.NotImplemented -> {
_skillToggleSupported.value = false
_editEvents.tryEmit(
EditEvent.Error("Skill toggle not yet supported on this server")
)
_editEvents.tryEmit(EditEvent.Error("Skill toggle not yet supported on this server"))
}
}
},
onFailure = { err ->
_editEvents.tryEmit(
EditEvent.Error(err.message ?: "Skill toggle failed")
)
},
onFailure = { _editEvents.tryEmit(EditEvent.Error(it.message ?: "Skill toggle failed")) },
)
}
}
/**
* Local filename sanity for new/updated memory entries. Mirrors
* the rules the server worker enforces:
* - Must end in `.md`.
* - No path-traversal components (`..`).
* - No slashes/backslashes.
* - No leading `.` (dotfiles).
*
* Returns the error string to show, or null when the name passes.
* Running this client-side saves a server round-trip for the
* common typo cases and produces a tighter error ("filename must
* end in .md") than the server's generic 400.
*/
fun toggleToolset(toolsetName: String, enabled: Boolean) {
val baseline = _gatewayDescription.value?.toolsets?.firstOrNull { it.name == toolsetName }
?.enabled ?: return
_toolsetDrafts.value = _toolsetDrafts.value.toMutableMap().apply {
if (enabled == baseline) remove(toolsetName) else put(toolsetName, enabled)
}
}
fun saveSkillEdits() {
val description = _gatewayDescription.value ?: return
if (_source.value != ProfileInspectorSource.Gateway || _skillsSaving.value) return
val skillDrafts = _skillDrafts.value
val toolsetDrafts = _toolsetDrafts.value
val disabledSkills = if (skillDrafts.isNotEmpty()) {
description.skills.filter { !(skillDrafts[it.name] ?: it.enabled) }.map { it.name }
} else null
val enabledToolsets = if (toolsetDrafts.isNotEmpty()) {
description.toolsets.filter { toolsetDrafts[it.name] ?: it.enabled }.map { it.name }
.takeUnless { it.size == description.toolsets.size } ?: emptyList()
} else null
val patch = GatewayProfilePatch(
disabledSkills = disabledSkills,
enabledToolsets = enabledToolsets,
)
if (patch.requestedSections.isEmpty()) return
_skillsSaving.value = true
saveGatewayPatch(patch) { result, _ ->
if (GatewayProfileSection.Skills in result.applied) _skillDrafts.value = emptyMap()
if (GatewayProfileSection.Toolsets in result.applied) _toolsetDrafts.value = emptyMap()
_skillsSaving.value = false
}
}
fun validateMemoryFilename(name: String): String? {
val trimmed = name.trim()
if (trimmed.isEmpty()) return "Filename required"
if (!trimmed.endsWith(".md", ignoreCase = false)) {
return "Filename must end in .md"
}
if (!trimmed.endsWith(".md")) return "Filename must end in .md"
if (trimmed.startsWith(".")) return "Filename cannot start with '.'"
if (trimmed.contains("/") || trimmed.contains("\\")) {
return "Filename cannot contain slashes"
}
if (trimmed.contains("/") || trimmed.contains("\\")) return "Filename cannot contain slashes"
if (trimmed.contains("..")) return "Filename cannot contain '..'"
return null
}
/**
* Kick off all four fetches in parallel. Safe to call more than once
* — re-invoking replaces the load state from scratch (reverts any
* previous Error to Loading and re-tries).
*/
fun loadAll() {
if (profileName.isBlank()) {
val msg = "No profile name supplied"
_configState.value = LoadState.Error(msg)
_soulState.value = LoadState.Error(msg)
_memoryState.value = LoadState.Error(msg)
_skillsState.value = LoadState.Error(msg)
val error = LoadState.Error("No profile name supplied")
_configState.value = error
_soulState.value = error
_memoryState.value = error
_skillsState.value = error
return
}
refreshSection(InspectorSection.Config)
refreshSection(InspectorSection.Soul)
refreshSection(InspectorSection.Memory)
refreshSection(InspectorSection.Skills)
refreshEditorSections()
refreshLegacySection(InspectorSection.Memory)
}
/**
* Refresh a single section (pull-to-refresh on one pane). Transitions
* state to [LoadState.Loading] immediately so the UI can show a
* progress indicator; then fires the coroutine and updates the state
* with either [LoadState.Loaded] or [LoadState.Error].
*/
fun refreshSection(section: InspectorSection) {
if (profileName.isBlank()) return
if (section == InspectorSection.Memory) refreshLegacySection(section) else refreshEditorSections()
}
private fun refreshEditorSections() {
_configState.value = LoadState.Loading
_soulState.value = LoadState.Loading
_skillsState.value = LoadState.Loading
viewModelScope.launch {
val gatewayResult = gatewayClient?.describeProfile(profileName)
val gatewayDescription = gatewayResult?.getOrNull()
if (gatewayDescription != null) {
_source.value = ProfileInspectorSource.Gateway
applyGatewayDescription(gatewayDescription)
return@launch
}
loadLegacyEditorSections(gatewayResult?.exceptionOrNull())
}
}
private suspend fun loadLegacyEditorSections(gatewayError: Throwable?) = coroutineScope {
val config = async { legacyClient.fetchConfig(profileName) }
val soul = async { legacyClient.fetchSoul(profileName) }
val skills = async { legacyClient.fetchSkills(profileName) }
val configResult = config.await()
val soulResult = soul.await()
val skillsResult = skills.await()
if (configResult.isSuccess || soulResult.isSuccess || skillsResult.isSuccess) {
_source.value = ProfileInspectorSource.Relay
_gatewayDescription.value = null
_gatewayWritable.value = false
}
val fallbackMessage = gatewayError
?.takeUnless { it is GatewayProfileEditorUnsupportedException }
?.message
_configState.value = configResult.toLoadState(fallbackMessage)
_soulState.value = soulResult.toLoadState(fallbackMessage)
_skillsState.value = skillsResult.toLoadState(fallbackMessage)
}
private fun refreshLegacySection(section: InspectorSection) {
when (section) {
InspectorSection.Config -> {
_configState.value = LoadState.Loading
viewModelScope.launch {
val result = client.fetchConfig(profileName)
_configState.value = result.toLoadState()
}
}
InspectorSection.Soul -> {
_soulState.value = LoadState.Loading
viewModelScope.launch {
val result = client.fetchSoul(profileName)
_soulState.value = result.toLoadState()
}
}
InspectorSection.Config, InspectorSection.Soul, InspectorSection.Skills -> refreshEditorSections()
InspectorSection.Memory -> {
_memoryState.value = LoadState.Loading
viewModelScope.launch {
val result = client.fetchMemory(profileName)
_memoryState.value = result.toLoadState()
}
}
InspectorSection.Skills -> {
_skillsState.value = LoadState.Loading
viewModelScope.launch {
val result = client.fetchSkills(profileName)
_skillsState.value = result.toLoadState()
_memoryState.value = legacyClient.fetchMemory(profileName).toLoadState()
}
}
}
}
private fun <T> Result<T>.toLoadState(): LoadState<T> = fold(
private fun applyGatewayDescription(description: GatewayProfileDescription) {
if (description.name != profileName) return
_gatewayDescription.value = description
_gatewayWritable.value = !gatewayConfigureUnsupported
_skillToggleSupported.value = !gatewayConfigureUnsupported
_configState.value = LoadState.Loaded(description.toConfigResponse())
_soulState.value = LoadState.Loaded(description.toSoulResponse())
_skillsState.value = LoadState.Loaded(description.toSkillsResponse())
}
private fun saveGatewayPatch(
patch: GatewayProfilePatch,
afterAuthoritativeRefresh: (GatewayProfileConfigureResult, GatewayProfileDescription) -> Unit,
) {
val client = gatewayClient
if (client == null) {
_editEvents.tryEmit(EditEvent.Error("Gateway profile editor unavailable"))
return
}
viewModelScope.launch {
val configured = client.configureProfile(profileName, patch)
if (configured.isFailure) {
if (configured.exceptionOrNull() is GatewayProfileEditorUnsupportedException) {
gatewayConfigureUnsupported = true
_gatewayWritable.value = false
_skillToggleSupported.value = false
}
clearSavingFlags()
_editEvents.tryEmit(EditEvent.Error(configured.exceptionOrNull()?.message ?: "Save failed"))
return@launch
}
val result = configured.getOrThrow()
val refreshed = client.describeProfile(profileName)
if (refreshed.isFailure) {
clearSavingFlags()
_editEvents.tryEmit(EditEvent.Error(saveSummary(result) + "; authoritative refresh failed"))
return@launch
}
val description = refreshed.getOrThrow()
applyGatewayDescription(description)
afterAuthoritativeRefresh(result, description)
val summary = saveSummary(result)
if (result.applied.isEmpty()) _editEvents.tryEmit(EditEvent.Error(summary))
else _editEvents.tryEmit(EditEvent.Saved(summary))
}
}
private fun clearSavingFlags() {
_configSaving.value = false
_soulSaving.value = false
_skillsSaving.value = false
}
private fun saveSummary(result: GatewayProfileConfigureResult): String {
val applied = result.applied.joinToString { it.wireName }.ifBlank { "none" }
val failed = result.failed.joinToString { it.wireName }.ifBlank { "none" }
return "Applied: $applied; failed: $failed"
}
private fun GatewayProfileDescription.toConfigResponse(): ProfileConfigResponse =
ProfileConfigResponse(
profile = name,
path = "profiles.describe",
readonly = false,
config = buildJsonObject {
put("description", description)
put("model", buildJsonObject {
put("provider", provider)
put("default", model)
})
put("tools", buildJsonObject {
put("toolsets_pinned", toolsetsPinned)
put("enabled_toolsets", JsonArray(toolsets.filter { it.enabled }.map { kotlinx.serialization.json.JsonPrimitive(it.name) }))
})
},
)
private fun GatewayProfileDescription.toSoulResponse(): ProfileSoulResponse =
ProfileSoulResponse(
profile = name,
path = "profiles.describe",
content = soul,
exists = soul.isNotEmpty(),
sizeBytes = soul.toByteArray(Charsets.UTF_8).size.toLong(),
)
private fun GatewayProfileDescription.toSkillsResponse(): ProfileSkillsResponse =
ProfileSkillsResponse(
profile = name,
skills = skills.map {
ProfileSkillEntry(
name = it.name,
category = "Gateway",
description = "",
path = "",
enabled = it.enabled,
)
},
total = skills.size,
)
private fun <T> Result<T>.toLoadState(fallbackMessage: String? = null): LoadState<T> = fold(
onSuccess = { LoadState.Loaded(it) },
onFailure = { LoadState.Error(it.message ?: "Unknown error") },
onFailure = { LoadState.Error(it.message ?: fallbackMessage ?: "Unknown error") },
)
companion object {
/** Nav-arg key for the profile-name path segment. Matches the
* declaration in `Screen.ProfileInspector`. */
const val ARG_PROFILE_NAME: String = "profileName"
}
}
@@ -4,9 +4,13 @@ import android.content.Context
import android.net.Uri
import com.hermesandroid.relay.auth.AuthManager
import com.hermesandroid.relay.data.AgentDisplay
import com.hermesandroid.relay.data.GatewayProfileManagementUnsupportedException
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.data.ProfileDisplayAliasStore
import com.hermesandroid.relay.data.ProfileIconStore
import com.hermesandroid.relay.data.prepareProfileAvatar
import com.hermesandroid.relay.data.profileAvatarMime
import com.hermesandroid.relay.data.preferredProfileIcon
import com.hermesandroid.relay.data.ProfileLockStore
import com.hermesandroid.relay.data.ProfilePresentation
import com.hermesandroid.relay.data.ProfilePresentationPolicy
@@ -17,7 +21,12 @@ import com.hermesandroid.relay.data.SessionTransport
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.DashboardProfileScope
import com.hermesandroid.relay.network.upstream.GatewayAvailability
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.GatewayPetGalleryItem
import com.hermesandroid.relay.network.upstream.GatewayPetInfo
import com.hermesandroid.relay.network.upstream.GatewayRpcException
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.SessionMessageLoadMode
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.network.relay.RelayHttpClient
import kotlinx.coroutines.CoroutineScope
@@ -38,7 +47,46 @@ import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
import kotlinx.coroutines.withContext
import java.io.ByteArrayOutputStream
import java.io.File
import java.security.MessageDigest
import java.util.concurrent.ConcurrentHashMap
import java.util.concurrent.atomic.AtomicLong
internal fun isCurrentProfileAvatarRefresh(
requestConnectionId: String,
activeConnectionId: String?,
requestGeneration: Long,
currentGeneration: Long,
): Boolean = requestConnectionId == activeConnectionId && requestGeneration == currentGeneration
internal fun mergeGatewayProfileRoster(
gateway: List<Profile>,
fallback: List<Profile>,
): List<Profile> = gateway.map { authoritative ->
val extension = fallback.firstOrNull { it.name == authoritative.name }
?: return@map authoritative
authoritative.copy(
systemMessage = extension.systemMessage,
gatewayRunning = extension.gatewayRunning,
hasSoul = extension.hasSoul,
apiServerEnabled = extension.apiServerEnabled,
apiServerUrl = extension.apiServerUrl,
apiServerHost = extension.apiServerHost,
apiServerPort = extension.apiServerPort,
apiServerKeyPresent = extension.apiServerKeyPresent,
)
}
internal fun selectProfileRoster(
gatewayAuthoritative: Boolean,
gateway: List<Profile>,
fallback: List<Profile>,
): List<Profile> = if (gatewayAuthoritative) {
mergeGatewayProfileRoster(gateway, fallback)
} else {
fallback
}
/**
* Owns the **agent-profiles cluster** of
@@ -92,6 +140,8 @@ class ProfileController(
private val rebuildChatApiClient: suspend () -> Unit,
/** Optional Relay client used only for importing an icon from the host. */
private val relayHttpClient: RelayHttpClient? = null,
/** Current per-connection Gateway client; profile management stays upstream-owned. */
private val gatewayClientProvider: () -> GatewayChatClient? = { null },
) {
// Server-advertised named agent configs, flattened to a StateFlow the
@@ -100,15 +150,24 @@ class ProfileController(
// underlying AuthManager instance is replaced and the public flow needs to
// repoint at the new manager's backing state.
private val _dashboardProfiles = MutableStateFlow<List<Profile>>(emptyList())
private val _gatewayProfiles = MutableStateFlow<List<Profile>>(emptyList())
private val _gatewayRosterAuthoritative = MutableStateFlow(false)
private val avatarRefreshGeneration = AtomicLong(0L)
private val petRefreshGeneration = AtomicLong(0L)
private val petGalleryGeneration = AtomicLong(0L)
private val petThumbnailRequests = ConcurrentHashMap.newKeySet<String>()
val agentProfiles: StateFlow<List<Profile>> = combine(
authManagerFlow.flatMapLatest { it.agentProfiles },
_dashboardProfiles,
) { relay, dashboard ->
// Prefer the relay's list when it has entries (richer runtime metadata);
// fall back to the dashboard list so a dashboard-only connection still
// sees its server profiles in the chat picker.
relay.ifEmpty { dashboard }
_gatewayProfiles,
_gatewayRosterAuthoritative,
) { relay, dashboard, gateway, gatewayAuthoritative ->
// Current Gateway rows are authoritative for shared profile metadata and
// avatar presence. Relay-only runtime/API routing fields are joined by
// exact name so adopting the roster never drops an isolated profile route.
val fallback = relay.ifEmpty { dashboard }
selectProfileRoster(gatewayAuthoritative, gateway, fallback)
}.stateIn(scope, SharingStarted.Eagerly, authManagerFlow.value.agentProfiles.value)
private val _selectedProfile = MutableStateFlow<Profile?>(null)
@@ -256,8 +315,8 @@ class ProfileController(
val profileIconStore: ProfileIconStore = ProfileIconStore(context)
/** The active profile's local agent-icon path (twin of [profileDisplayAlias]). */
val profileIcon: StateFlow<String?> = combine(
/** The active profile's device-local fallback icon. */
val localProfileIcon: StateFlow<String?> = combine(
activeConnectionId,
selectedProfile,
) { connectionId, profile ->
@@ -270,11 +329,63 @@ class ProfileController(
}
}.stateIn(scope, SharingStarted.Eagerly, null)
private val activeServerAvatarIdentity: Flow<Pair<String?, String?>> = combine(
activeConnectionId,
selectedProfile,
serverDefaultProfileScope,
_gatewayProfiles,
) { connectionId, selected, serverDefault, gatewayProfiles ->
connectionId to (
selected?.name ?: serverDefault?.active
?: gatewayProfiles.firstOrNull(Profile::isDefault)?.name
)
}
/** Cached bytes fetched from Hermes; always preferred over the local fallback. */
val serverProfileAvatar: StateFlow<String?> = activeServerAvatarIdentity
.flatMapLatest { (connectionId, profileName) ->
if (connectionId == null || profileName.isNullOrBlank()) flowOf(null)
else profileIconStore.serverAvatarFlow(connectionId, profileName)
}.stateIn(scope, SharingStarted.Eagerly, null)
/** Whether this phone should prefer its local image over Hermes' shared avatar. */
val useLocalProfileIconOverride: StateFlow<Boolean> = combine(
activeConnectionId,
selectedProfile,
) { connectionId, profile ->
connectionId to AgentDisplay.profileRequestName(profile?.name)
}.flatMapLatest { (connectionId, profileName) ->
if (connectionId == null) flowOf(false)
else profileIconStore.localOverrideFlow(connectionId, profileName)
}.stateIn(scope, SharingStarted.Eagerly, false)
val profileIcon: StateFlow<String?> = combine(
serverProfileAvatar,
localProfileIcon,
useLocalProfileIconOverride,
) { server, local, localOverride -> preferredProfileIcon(server, local, localOverride) }
.stateIn(scope, SharingStarted.Eagerly, null)
/** Local icon for any profile identity on the active connection. */
fun profileIconFlow(profileName: String?): Flow<String?> = activeConnectionId
.flatMapLatest { connectionId ->
if (connectionId == null) flowOf(null)
else profileIconStore.iconFlow(connectionId, profileName)
fun profileIconFlow(profileName: String?): Flow<String?> = combine(
activeConnectionId,
serverDefaultProfileScope,
_gatewayProfiles,
) { connectionId, serverDefault, gatewayProfiles ->
connectionId to (
profileName ?: serverDefault?.active
?: gatewayProfiles.firstOrNull(Profile::isDefault)?.name
)
}
.flatMapLatest { (connectionId, serverProfileName) ->
if (connectionId == null) return@flatMapLatest flowOf(null)
val local = profileIconStore.iconFlow(connectionId, profileName)
val localOverride = profileIconStore.localOverrideFlow(connectionId, profileName)
if (serverProfileName.isNullOrBlank()) local else combine(
profileIconStore.serverAvatarFlow(connectionId, serverProfileName),
local,
localOverride,
) { server, fallback, override -> preferredProfileIcon(server, fallback, override) }
}
data class HostIconImportState(
@@ -286,6 +397,44 @@ class ProfileController(
val hostIconImportState: StateFlow<HostIconImportState> =
_hostIconImportState.asStateFlow()
data class SharedAvatarState(
val loading: Boolean = false,
val error: String? = null,
)
private val _sharedAvatarState = MutableStateFlow(SharedAvatarState())
val sharedAvatarState: StateFlow<SharedAvatarState> = _sharedAvatarState.asStateFlow()
data class HermesPetPresentation(
val connectionId: String,
val profileName: String?,
val slug: String,
val displayName: String,
val spritesheetPath: String,
val spritesheetRevision: String,
val frameWidth: Int,
val frameHeight: Int,
val framesPerState: Int,
val framesByState: Map<String, Int>,
val framesByRow: Map<String, Int>,
val loopMs: Int,
val scale: Float,
val stateRows: List<String>,
)
data class HermesPetState(
val supported: Boolean? = null,
val loading: Boolean = false,
val galleryLoading: Boolean = false,
val active: HermesPetPresentation? = null,
val gallery: List<GatewayPetGalleryItem> = emptyList(),
val thumbnails: Map<String, String> = emptyMap(),
val error: String? = null,
)
private val _hermesPetState = MutableStateFlow(HermesPetState())
val hermesPetState: StateFlow<HermesPetState> = _hermesPetState.asStateFlow()
/**
* Load the host's agent profiles from the dashboard `/api/profiles` into
* [agentProfiles] (merged in the combine above). Lets the chat agent sheet
@@ -301,6 +450,8 @@ class ProfileController(
return
}
scope.launch {
refreshGatewayProfiles(connectionId)
refreshHermesPet(connectionId)
val client = dashboardClientFactory(connectionId, dashboardUrl)
val defaultScope = client.getActiveProfileScope().getOrNull()
if (activeConnectionId.value != connectionId) return@launch
@@ -323,6 +474,258 @@ class ProfileController(
}
}
fun refreshGatewayProfiles() {
val connectionId = activeConnectionId.value ?: return
scope.launch {
refreshGatewayProfiles(connectionId)
refreshHermesPet(connectionId)
}
}
private suspend fun refreshGatewayProfiles(connectionId: String) {
val gateway = gatewayClientProvider() ?: return
val generation = avatarRefreshGeneration.incrementAndGet()
gateway.listProfiles().onSuccess { profiles ->
if (!isCurrentProfileAvatarRefresh(connectionId, activeConnectionId.value, generation, avatarRefreshGeneration.get())) return@onSuccess
_gatewayProfiles.value = profiles
_gatewayRosterAuthoritative.value = true
profiles.forEach { profile ->
if (!profile.hasAvatar) {
clearServerAvatarCache(connectionId, profile.name, generation)
} else {
gateway.getProfileAvatar(profile.name).onSuccess { asset ->
if (!isCurrentProfileAvatarRefresh(connectionId, activeConnectionId.value, generation, avatarRefreshGeneration.get())) {
return@onSuccess
}
if (asset == null) {
clearServerAvatarCache(connectionId, profile.name, generation)
} else {
val path = copyServerAvatarBytes(connectionId, profile.name, asset.data, asset.mime)
if (path != null && avatarRefreshGeneration.get() == generation) {
profileIconStore.setServerAvatar(connectionId, profile.name, path)
}
}
}
}
}
}.onFailure { failure ->
if (
failure is GatewayProfileManagementUnsupportedException &&
isCurrentProfileAvatarRefresh(
connectionId,
activeConnectionId.value,
generation,
avatarRefreshGeneration.get(),
)
) {
_gatewayProfiles.value = emptyList()
_gatewayRosterAuthoritative.value = false
}
}
}
private suspend fun clearServerAvatarCache(connectionId: String, profileName: String, generation: Long) {
if (avatarRefreshGeneration.get() != generation) return
profileIconStore.serverAvatarFlow(connectionId, profileName).first()?.let { runCatching { File(it).delete() } }
profileIconStore.setServerAvatar(connectionId, profileName, null)
}
/** Refresh the active profile's upstream sprite contract without re-sending an unchanged sheet. */
fun refreshHermesPet() {
val connectionId = activeConnectionId.value ?: return
scope.launch { refreshHermesPet(connectionId) }
}
private suspend fun refreshHermesPet(connectionId: String) {
val gateway = gatewayClientProvider() ?: run {
_hermesPetState.value = HermesPetState(supported = null)
return
}
val profileName = resolveSessionProfileName()
val generation = petRefreshGeneration.incrementAndGet()
val previous = _hermesPetState.value.active?.takeIf {
it.connectionId == connectionId && it.profileName == profileName
}
_hermesPetState.value = _hermesPetState.value.copy(loading = true, error = null)
gateway.petInfo(profile = profileName, knownRevision = previous?.spritesheetRevision).fold(
onSuccess = { info ->
if (!isCurrentPetRefresh(connectionId, generation)) return@fold
if (!info.enabled) {
_hermesPetState.value = HermesPetState(supported = true)
return@fold
}
val presentation = cacheHermesPet(connectionId, profileName, info, previous)
_hermesPetState.value = if (presentation == null) {
HermesPetState(
supported = true,
error = "Hermes returned an animated pet that this phone could not cache",
)
} else {
_hermesPetState.value.copy(
supported = true,
loading = false,
active = presentation,
error = null,
)
}
},
onFailure = { failure ->
if (!isCurrentPetRefresh(connectionId, generation)) return@fold
_hermesPetState.value = if ((failure as? GatewayRpcException)?.code == -32601) {
HermesPetState(supported = false)
} else {
_hermesPetState.value.copy(
loading = false,
error = failure.message ?: "Could not load the Hermes animated pet",
)
}
},
)
}
/** Load the profile-scoped upstream gallery only when the user opens the picker. */
fun loadHermesPetGallery() {
val connectionId = activeConnectionId.value ?: return
val gateway = gatewayClientProvider() ?: return
val profileName = resolveSessionProfileName()
val generation = petGalleryGeneration.incrementAndGet()
scope.launch {
_hermesPetState.value = _hermesPetState.value.copy(galleryLoading = true, error = null)
gateway.petGallery(profile = profileName).fold(
onSuccess = { gallery ->
if (!isCurrentPetGallery(connectionId, profileName, generation)) return@fold
_hermesPetState.value = _hermesPetState.value.copy(
supported = true,
galleryLoading = false,
gallery = gallery.pets,
error = null,
)
},
onFailure = { failure ->
if (!isCurrentPetGallery(connectionId, profileName, generation)) return@fold
_hermesPetState.value = _hermesPetState.value.copy(
galleryLoading = false,
error = failure.message ?: "Could not load the Hermes pet gallery",
)
},
)
}
}
fun selectHermesPet(slug: String) = mutateHermesPet { gateway, profile ->
gateway.selectPet(slug, profile)
}
/** Lazily fetch one upstream-cropped idle frame for a visible gallery row. */
fun loadHermesPetThumbnail(pet: GatewayPetGalleryItem) {
if (_hermesPetState.value.thumbnails.containsKey(pet.slug)) return
val connectionId = activeConnectionId.value ?: return
val gateway = gatewayClientProvider() ?: return
val profileName = resolveSessionProfileName()
val requestKey = "$connectionId\u0000${AgentDisplay.profileSessionKey(profileName)}\u0000${pet.slug}"
if (!petThumbnailRequests.add(requestKey)) return
scope.launch {
try {
gateway.petThumbnail(
slug = pet.slug,
spritesheetUrl = pet.spritesheetUrl,
profile = profileName,
).onSuccess { dataUri ->
if (
dataUri != null && activeConnectionId.value == connectionId &&
resolveSessionProfileName() == profileName
) {
_hermesPetState.value = _hermesPetState.value.copy(
thumbnails = _hermesPetState.value.thumbnails + (pet.slug to dataUri),
)
}
}
} finally {
petThumbnailRequests.remove(requestKey)
}
}
}
fun disableHermesPet() = mutateHermesPet { gateway, profile ->
gateway.disablePet(profile)
}
private fun mutateHermesPet(
mutation: suspend (GatewayChatClient, String?) -> Result<Unit>,
) {
val connectionId = activeConnectionId.value ?: return
val gateway = gatewayClientProvider() ?: return
val profileName = resolveSessionProfileName()
scope.launch {
_hermesPetState.value = _hermesPetState.value.copy(loading = true, error = null)
mutation(gateway, profileName).fold(
onSuccess = { refreshHermesPet(connectionId) },
onFailure = { failure ->
_hermesPetState.value = _hermesPetState.value.copy(
loading = false,
error = failure.message ?: "Could not update the Hermes animated pet",
)
},
)
}
}
private fun isCurrentPetRefresh(connectionId: String, generation: Long): Boolean =
activeConnectionId.value == connectionId && petRefreshGeneration.get() == generation
private fun isCurrentPetGallery(connectionId: String, profileName: String?, generation: Long): Boolean =
activeConnectionId.value == connectionId &&
resolveSessionProfileName() == profileName &&
petGalleryGeneration.get() == generation
private suspend fun cacheHermesPet(
connectionId: String,
profileName: String?,
info: GatewayPetInfo,
previous: HermesPetPresentation?,
): HermesPetPresentation? = withContext(Dispatchers.IO) {
val slug = info.slug ?: return@withContext null
val revision = info.spritesheetRevision ?: return@withContext null
val path = if (info.spritesheetUnchanged && previous?.spritesheetRevision == revision) {
previous.spritesheetPath.takeIf { File(it).isFile }
} else {
val bytes = info.spritesheet ?: return@withContext null
val dir = File(context.filesDir, "hermes-profile-pets").apply { mkdirs() }
val key = MessageDigest.getInstance("SHA-256")
.digest("$connectionId\u0000${AgentDisplay.profileSessionKey(profileName)}".toByteArray())
.take(12)
.joinToString("") { "%02x".format(it) }
val extension = if (info.mime == "image/webp") "webp" else "png"
val target = File(dir, "$key.$extension")
val pending = File(dir, "$key.$extension.tmp")
runCatching {
pending.writeBytes(bytes)
if (!pending.renameTo(target)) {
target.writeBytes(bytes)
pending.delete()
}
target.absolutePath
}.getOrNull()
} ?: return@withContext null
HermesPetPresentation(
connectionId = connectionId,
profileName = profileName,
slug = slug,
displayName = info.displayName ?: slug,
spritesheetPath = path,
spritesheetRevision = revision,
frameWidth = info.frameWidth,
frameHeight = info.frameHeight,
framesPerState = info.framesPerState,
framesByState = info.framesByState,
framesByRow = info.framesByRow,
loopMs = info.loopMs,
scale = info.scale,
stateRows = info.stateRows,
)
}
/** Effective profile namespace for Gateway and profile-scoped session I/O. */
fun resolveSessionProfileName(selectedProfileName: String? = _selectedProfile.value?.name): String? =
AgentDisplay.effectiveSessionProfileName(
@@ -343,17 +746,67 @@ class ProfileController(
.listSessions(profile = profileName, limit = limit, archived = "include")
}
suspend fun listAllProfileSessions(limit: Int = 200): Result<List<SessionItem>>? {
val connectionId = activeConnectionId.value ?: return null
val dashboardUrl = activeDashboardUrlProvider() ?: return null
return dashboardClientFactory(connectionId, dashboardUrl).listAllProfileSessions(limit)
}
suspend fun deleteSession(profileName: String, sessionId: String): Boolean {
val connectionId = activeConnectionId.value ?: return false
val dashboardUrl = activeDashboardUrlProvider() ?: return false
return dashboardClientFactory(connectionId, dashboardUrl)
.deleteSession(sessionId, profileName)
.isSuccess
}
suspend fun renameSession(profileName: String, sessionId: String, title: String): Boolean {
val connectionId = activeConnectionId.value ?: return false
val dashboardUrl = activeDashboardUrlProvider() ?: return false
return dashboardClientFactory(connectionId, dashboardUrl)
.renameSession(sessionId, title, profileName)
.isSuccess
}
suspend fun setSessionPinned(profileName: String, sessionId: String, pinned: Boolean): Boolean {
val connectionId = activeConnectionId.value ?: return false
val dashboardUrl = activeDashboardUrlProvider() ?: return false
return dashboardClientFactory(connectionId, dashboardUrl)
.setSessionPinned(sessionId, pinned, profileName)
.isSuccess
}
suspend fun setSessionArchived(profileName: String, sessionId: String, archived: Boolean): Boolean {
val connectionId = activeConnectionId.value ?: return false
val dashboardUrl = activeDashboardUrlProvider() ?: return false
return dashboardClientFactory(connectionId, dashboardUrl)
.setSessionArchived(sessionId, archived, profileName)
.isSuccess
}
/**
* A session's transcript, scoped to the active profile via the dashboard
* `/api/sessions/{id}/messages?profile=`. Returns `null` off the dashboard
* surface so the caller falls back to the api_server transcript.
*/
suspend fun loadProfileScopedMessages(sessionId: String): Result<List<MessageItem>>? {
suspend fun loadProfileScopedMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>>? = loadProfileScopedMessages(
profileName = resolveSessionProfileName(),
sessionId = sessionId,
mode = mode,
)
suspend fun loadProfileScopedMessages(
profileName: String?,
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
): Result<List<MessageItem>>? {
val connectionId = activeConnectionId.value ?: return null
val dashboardUrl = activeDashboardUrlProvider() ?: return null
val profileName = resolveSessionProfileName()
return dashboardClientFactory(connectionId, dashboardUrl)
.getSessionMessages(sessionId, profileName)
.getSessionMessages(sessionId, profileName, mode)
}
suspend fun deleteProfileScopedSession(sessionId: String): Boolean {
@@ -421,6 +874,7 @@ class ProfileController(
scope.launch {
val path = copyIcon(connectionId, profileName, uri) ?: return@launch
profileIconStore.setIcon(connectionId, profileName, path)
profileIconStore.setLocalOverride(connectionId, profileName, true)
}
}
@@ -446,6 +900,7 @@ class ProfileController(
)
} else {
profileIconStore.setIcon(connectionId, profileName, path)
profileIconStore.setLocalOverride(connectionId, profileName, true)
_hostIconImportState.value = HostIconImportState()
}
},
@@ -469,23 +924,120 @@ class ProfileController(
}
}
fun setUseLocalProfileIconOverride(enabled: Boolean) {
val connectionId = activeConnectionId.value ?: return
val profileName = AgentDisplay.profileRequestName(_selectedProfile.value?.name)
scope.launch { profileIconStore.setLocalOverride(connectionId, profileName, enabled) }
}
/** Upload a selected static image directly to Hermes without changing this phone's override. */
fun setSharedProfileAvatar(uri: Uri) {
val connectionId = activeConnectionId.value ?: return
val profileName = resolveSharedAssetProfileName()
val gateway = gatewayClientProvider()
if (profileName.isNullOrBlank() || gateway == null) {
_sharedAvatarState.value = SharedAvatarState(error = "Shared avatars require a current Hermes Gateway")
return
}
scope.launch {
_sharedAvatarState.value = SharedAvatarState(loading = true)
val bytes = withContext(Dispatchers.IO) {
prepareProfileAvatar(context, uri, GatewayChatClient.PROFILE_AVATAR_MAX_BYTES)
}
if (bytes == null) {
_sharedAvatarState.value = SharedAvatarState(error = "That image could not be prepared for Hermes")
return@launch
}
gateway.setProfileAvatar(profileName, bytes).fold(
onSuccess = {
cacheAcknowledgedSharedAvatar(connectionId, profileName, bytes)
_sharedAvatarState.value = SharedAvatarState()
},
onFailure = { failure ->
_sharedAvatarState.value = SharedAvatarState(
error = failure.message ?: "Shared avatar upload failed",
)
},
)
}
}
/** Explicit migration: upload the current device-local fallback to Hermes. */
fun uploadLocalProfileIconToHermes() {
val connectionId = activeConnectionId.value ?: return
val profileName = resolveSharedAssetProfileName()
if (profileName.isNullOrBlank()) {
_sharedAvatarState.value = SharedAvatarState(error = "Hermes profile identity is not available")
return
}
val gateway = gatewayClientProvider()
if (gateway == null) {
_sharedAvatarState.value = SharedAvatarState(error = "Shared avatars require a current Hermes Gateway")
return
}
scope.launch {
_sharedAvatarState.value = SharedAvatarState(loading = true)
val path = profileIconStore.iconFlow(
connectionId,
AgentDisplay.profileRequestName(_selectedProfile.value?.name),
).first()
val file = path?.let(::File)
val bytes = when {
file == null || !file.isFile -> null
file.length() > GatewayChatClient.PROFILE_AVATAR_MAX_BYTES -> null
else -> withContext(Dispatchers.IO) { runCatching { file.readBytes() }.getOrNull() }
}
if (bytes == null) {
_sharedAvatarState.value = SharedAvatarState(error = "Choose a local PNG, JPEG, or WebP under 2 MB first")
return@launch
}
gateway.setProfileAvatar(profileName, bytes).fold(
onSuccess = {
cacheAcknowledgedSharedAvatar(connectionId, profileName, bytes)
_sharedAvatarState.value = SharedAvatarState()
},
onFailure = { failure ->
_sharedAvatarState.value = SharedAvatarState(
error = failure.message ?: "Shared avatar upload failed",
)
},
)
}
}
/** Clear only Hermes' shared asset; the device-local fallback remains untouched. */
fun clearSharedProfileAvatar() {
val connectionId = activeConnectionId.value ?: return
val profileName = resolveSharedAssetProfileName()
val gateway = gatewayClientProvider()
if (profileName.isNullOrBlank() || gateway == null) {
_sharedAvatarState.value = SharedAvatarState(error = "Shared avatars require a current Hermes Gateway")
return
}
scope.launch {
_sharedAvatarState.value = SharedAvatarState(loading = true)
gateway.clearProfileAvatar(profileName).fold(
onSuccess = {
val generation = avatarRefreshGeneration.incrementAndGet()
clearServerAvatarCache(connectionId, profileName, generation)
_gatewayProfiles.value = _gatewayProfiles.value.map { profile ->
if (profile.name == profileName) profile.copy(hasAvatar = false) else profile
}
_sharedAvatarState.value = SharedAvatarState()
},
onFailure = { failure ->
_sharedAvatarState.value = SharedAvatarState(
error = failure.message ?: "Shared avatar clear failed",
)
},
)
}
}
/** Copy [uri]'s image bytes into app-internal storage; returns the path or null. */
private suspend fun copyIcon(connectionId: String, profileName: String?, uri: Uri): String? =
withContext(Dispatchers.IO) {
try {
val dir = File(context.filesDir, "profile-icons").apply { mkdirs() }
val key = AgentDisplay.profileSessionKey(profileName)
val safe = "${connectionId}_$key"
.map { if (it.isLetterOrDigit() || it == '-' || it == '_') it else '_' }
.joinToString("")
val out = File(dir, "$safe.png")
context.contentResolver.openInputStream(uri)?.use { input ->
out.outputStream().use { input.copyTo(it) }
} ?: return@withContext null
out.absolutePath
} catch (t: Throwable) {
null
}
readBoundedUri(uri, LOCAL_PROFILE_ICON_MAX_BYTES)?.let { bytes ->
copyIconBytes(connectionId, profileName, bytes)
}
private suspend fun copyIconBytes(
@@ -494,17 +1046,131 @@ class ProfileController(
bytes: ByteArray,
): String? = withContext(Dispatchers.IO) {
try {
val extension = localImageExtension(bytes) ?: return@withContext null
val dir = File(context.filesDir, "profile-icons").apply { mkdirs() }
val key = AgentDisplay.profileSessionKey(profileName)
val safe = "${connectionId}_$key"
.map { if (it.isLetterOrDigit() || it == '-' || it == '_') it else '_' }
.joinToString("")
File(dir, "$safe.png").also { it.writeBytes(bytes) }.absolutePath
val target = File(dir, "$safe.$extension")
target.writeBytes(bytes)
LOCAL_PROFILE_ICON_EXTENSIONS
.filterNot(extension::equals)
.forEach { stale -> runCatching { File(dir, "$safe.$stale").delete() } }
target.absolutePath
} catch (_: Throwable) {
null
}
}
private suspend fun readBoundedUri(uri: Uri, maxBytes: Int): ByteArray? =
withContext(Dispatchers.IO) {
runCatching {
context.contentResolver.openInputStream(uri)?.use { input ->
val output = ByteArrayOutputStream(minOf(maxBytes, 64 * 1024))
val buffer = ByteArray(16 * 1024)
var total = 0
while (true) {
val read = input.read(buffer)
if (read < 0) break
total += read
if (total > maxBytes) return@use null
output.write(buffer, 0, read)
}
output.toByteArray()
}
}.getOrNull()
}
private fun localImageExtension(bytes: ByteArray): String? = when {
bytes.size >= 8 && bytes.copyOfRange(0, 8).contentEquals(
byteArrayOf(0x89.toByte(), 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a),
) -> "png"
bytes.size >= 3 && bytes[0] == 0xff.toByte() && bytes[1] == 0xd8.toByte() &&
bytes[2] == 0xff.toByte() -> "jpg"
bytes.size >= 6 && (
bytes.copyOfRange(0, 6).contentEquals("GIF87a".toByteArray()) ||
bytes.copyOfRange(0, 6).contentEquals("GIF89a".toByteArray())
) -> "gif"
bytes.size >= 12 && bytes.copyOfRange(0, 4).contentEquals("RIFF".toByteArray()) &&
bytes.copyOfRange(8, 12).contentEquals("WEBP".toByteArray()) -> "webp"
else -> null
}
private suspend fun copyServerAvatarBytes(
connectionId: String,
profileName: String,
bytes: ByteArray,
mime: String,
): String? = withContext(Dispatchers.IO) {
try {
val extension = when (mime) {
"image/png" -> "png"
"image/jpeg" -> "jpg"
"image/webp" -> "webp"
else -> return@withContext null
}
val dir = File(context.filesDir, "profile-avatars-server").apply { mkdirs() }
val safe = MessageDigest.getInstance("SHA-256")
.digest("$connectionId\u0000${AgentDisplay.profileSessionKey(profileName)}".toByteArray())
.joinToString("") { (it.toInt() and 0xff).toString(16).padStart(2, '0') }
val target = File(dir, "$safe.$extension")
val temp = File(dir, "$safe.$extension.tmp")
temp.writeBytes(bytes)
try {
java.nio.file.Files.move(
temp.toPath(),
target.toPath(),
java.nio.file.StandardCopyOption.ATOMIC_MOVE,
java.nio.file.StandardCopyOption.REPLACE_EXISTING,
)
} catch (_: java.nio.file.AtomicMoveNotSupportedException) {
java.nio.file.Files.move(
temp.toPath(),
target.toPath(),
java.nio.file.StandardCopyOption.REPLACE_EXISTING,
)
}
listOf("png", "jpg", "webp")
.filterNot(extension::equals)
.forEach { stale -> runCatching { File(dir, "$safe.$stale").delete() } }
target.absolutePath
} catch (_: Throwable) {
null
}
}
private suspend fun cacheAcknowledgedSharedAvatar(
connectionId: String,
profileName: String,
bytes: ByteArray,
) {
if (activeConnectionId.value != connectionId) return
val mime = profileAvatarMime(bytes) ?: return
val generation = avatarRefreshGeneration.incrementAndGet()
val path = copyServerAvatarBytes(connectionId, profileName, bytes, mime) ?: return
if (!isCurrentProfileAvatarRefresh(
connectionId,
activeConnectionId.value,
generation,
avatarRefreshGeneration.get(),
)
) return
profileIconStore.setServerAvatar(connectionId, profileName, path)
_gatewayProfiles.value = _gatewayProfiles.value.map { profile ->
if (profile.name == profileName) profile.copy(hasAvatar = true) else profile
}
}
private fun resolveSharedAssetProfileName(): String? =
resolveSessionProfileName()
?: _gatewayProfiles.value.firstOrNull(Profile::isDefault)?.name
private companion object {
const val LOCAL_PROFILE_ICON_MAX_BYTES = 8_000_000
val LOCAL_PROFILE_ICON_EXTENSIONS = listOf("png", "jpg", "gif", "webp")
}
/**
* The stored lock-token for a (possibly null) profile. Server default —
* A null selection maps to [AgentDisplay.SERVER_DEFAULT_PROFILE_KEY]; a
@@ -573,6 +1239,24 @@ class ProfileController(
}
}
/** Persist or clear a local cosmetic accent for a named profile. */
fun setProfileColor(profileName: String, colorHex: String?) {
val connectionId = activeConnectionId.value ?: return
val key = profileName.trim()
if (key.isBlank() || key.equals("default", ignoreCase = true)) return
scope.launch {
profilePresentationWriteMutex.withLock {
val updated = profilePresentationStore
.presentationFlow(connectionId)
.first()
.colors
.toMutableMap()
.apply { if (colorHex == null) remove(key) else put(key, colorHex) }
profilePresentationStore.setColors(connectionId, updated)
}
}
}
fun resetProfilePresentation() {
val connectionId = activeConnectionId.value ?: return
scope.launch {
@@ -590,6 +1274,11 @@ class ProfileController(
* [selectProfile] is the gated public entry point.
*/
private fun applyProfileSelection(normalizedProfile: Profile?) {
_sharedAvatarState.value = SharedAvatarState()
_hostIconImportState.value = HostIconImportState()
petRefreshGeneration.incrementAndGet()
petGalleryGeneration.incrementAndGet()
_hermesPetState.value = HermesPetState()
_selectedProfile.value = normalizedProfile
setLastSessionId(null)
val connectionId = activeConnectionId.value ?: return
@@ -598,6 +1287,7 @@ class ProfileController(
scope.launch {
profileSelectionStore.setSelectedProfile(connectionId, normalizedProfile?.name)
rebuildChatApiClient()
refreshHermesPet(connectionId)
}
refreshLastSessionForProfile(connectionId, normalizedProfile?.name)
}
@@ -771,6 +1461,12 @@ class ProfileController(
// pending persisted name can't resolve against the previous connection's
// profiles before the new connection's list arrives.
_dashboardProfiles.value = emptyList()
_gatewayProfiles.value = emptyList()
_gatewayRosterAuthoritative.value = false
avatarRefreshGeneration.incrementAndGet()
petRefreshGeneration.incrementAndGet()
petGalleryGeneration.incrementAndGet()
_hermesPetState.value = HermesPetState()
}
/** Clear just the in-memory selection + pending state (resetAppData). */
@@ -780,6 +1476,9 @@ class ProfileController(
_pendingSelectedProfileName.value = null
_serverDefaultProfileScope.value = null
_serverDefaultProfileSettled.value = false
petRefreshGeneration.incrementAndGet()
petGalleryGeneration.incrementAndGet()
_hermesPetState.value = HermesPetState()
}
fun clearSelectedProfile() {
@@ -16,6 +16,7 @@ import com.hermesandroid.relay.network.upstream.isNativeDashboardTransportEligib
import com.hermesandroid.relay.network.upstream.ServerCapabilities
import com.hermesandroid.relay.network.upstream.resolveStreamingEndpointPreference
import com.hermesandroid.relay.network.upstream.trustedDashboardBearerAuthOrNull
import com.hermesandroid.relay.network.shutdownOffMainThread
import java.util.concurrent.ConcurrentHashMap
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
@@ -77,6 +78,13 @@ class UpstreamTransportController(
* `hermes_dashboard_<id>` file (original behavior).
*/
private val tokenStoreKeyProvider: (String) -> String? = { null },
/** Applies pairing-bound TLS to a standard authenticated client when needed. */
private val pinnedClientProvider: (String, okhttp3.OkHttpClient) -> okhttp3.OkHttpClient? =
{ _, _ -> null },
private val dashboardHttpClientFactory:
(DashboardCookieStore, DashboardBearerAuth?) -> okhttp3.OkHttpClient = { cookieStore, bearerAuth ->
DashboardApiClient.defaultClient(cookieStore, bearerAuth)
},
) {
// --- Per-connection dashboard cookie stores ----------------------------
@@ -147,30 +155,34 @@ class UpstreamTransportController(
* factory the dashboard-surface callers (profile lists, session/message
* scoping, the gateway client, standard-API setup probe) route through.
*/
fun dashboardClientFor(connectionId: String, dashboardUrl: String): DashboardApiClient =
DashboardApiClient(
baseUrl = dashboardUrl,
okHttpClient = DashboardApiClient.defaultClient(
cookieStore = dashboardCookieStoreFor(connectionId),
bearerAuth = bearerAuthForTrustedDashboard(connectionId, dashboardUrl),
),
fun dashboardClientFor(connectionId: String, dashboardUrl: String): DashboardApiClient {
val base = dashboardHttpClientFactory(
dashboardCookieStoreFor(connectionId),
bearerAuthForTrustedDashboard(connectionId, dashboardUrl),
)
return DashboardApiClient(
baseUrl = dashboardUrl,
okHttpClient = pinnedClientProvider(dashboardUrl, base) ?: base,
)
}
/**
* Build a [DashboardApiClient] for the active connection against
* [dashboardUrl], falling back to an in-memory cookie store when there is
* no active connection (the standard-voice probe path).
*/
fun dashboardClientForActive(dashboardUrl: String): DashboardApiClient =
DashboardApiClient(
baseUrl = dashboardUrl,
okHttpClient = DashboardApiClient.defaultClient(
cookieStore = activeDashboardCookieStore() ?: InMemoryDashboardCookieStore(),
bearerAuth = activeConnectionIdProvider()?.let {
bearerAuthForTrustedDashboard(it, dashboardUrl)
},
),
fun dashboardClientForActive(dashboardUrl: String): DashboardApiClient {
val base = dashboardHttpClientFactory(
activeDashboardCookieStore() ?: InMemoryDashboardCookieStore(),
activeConnectionIdProvider()?.let {
bearerAuthForTrustedDashboard(it, dashboardUrl)
},
)
return DashboardApiClient(
baseUrl = dashboardUrl,
okHttpClient = pinnedClientProvider(dashboardUrl, base) ?: base,
)
}
/**
* Native PKCE client for the active connection's exact trusted dashboard
@@ -190,9 +202,16 @@ class UpstreamTransportController(
) {
return null
}
val base = okhttp3.OkHttpClient.Builder()
.retryOnConnectionFailure(false)
.connectTimeout(10, java.util.concurrent.TimeUnit.SECONDS)
.readTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.writeTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build()
return NativeDashboardAuthClient(
baseUrl = dashboardUrl,
tokenStore = dashboardTokenStoreFor(connectionId),
client = pinnedClientProvider(dashboardUrl, base) ?: base,
)
}
@@ -205,12 +224,14 @@ class UpstreamTransportController(
disposeDashboardHttpClient(client)
dashboardHttpClientCache = null
}
return DashboardApiClient.defaultClient(
cookieStore = activeDashboardCookieStore() ?: InMemoryDashboardCookieStore(),
bearerAuth = activeConnectionIdProvider()?.let { activeId ->
val base = dashboardHttpClientFactory(
activeDashboardCookieStore() ?: InMemoryDashboardCookieStore(),
activeConnectionIdProvider()?.let { activeId ->
bearerAuthForTrustedDashboard(activeId, dashboardUrl)
},
).also { dashboardHttpClientCache = Triple(connectionId, dashboardUrl, it) }
)
return (pinnedClientProvider(dashboardUrl, base) ?: base)
.also { dashboardHttpClientCache = Triple(connectionId, dashboardUrl, it) }
}
@Synchronized
@@ -234,10 +255,12 @@ class UpstreamTransportController(
}
private fun disposeDashboardHttpClient(client: okhttp3.OkHttpClient) {
client.dispatcher.cancelAll()
client.connectionPool.evictAll()
runCatching { client.cache?.close() }
client.dispatcher.executorService.shutdown()
shutdownOffMainThread("DashboardHttpClient-shutdown") {
client.dispatcher.cancelAll()
client.connectionPool.evictAll()
runCatching { client.cache?.close() }
client.dispatcher.executorService.shutdown()
}
}
// --- Gateway availability ----------------------------------------------
+182 -1
View File
@@ -1722,6 +1722,17 @@
<!-- Section action buttons -->
<string name="dashboard_section_action_change_main_model">Alterar modelo principal</string>
<string name="dashboard_section_action_new_profile">Novo perfil</string>
<string name="dashboard_section_action_new_schedule">Novo agendamento</string>
<string name="dashboard_cron_create_title">Criar agendamento</string>
<string name="dashboard_cron_name">Nome</string>
<string name="dashboard_cron_schedule">Agendamento</string>
<string name="dashboard_cron_schedule_hint">Exemplos: every 2h, 0 9 * * 1-5 ou 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">Instruções da tarefa</string>
<string name="dashboard_cron_repeat">Parar após esta quantidade de execuções (opcional)</string>
<string name="dashboard_cron_repeat_help">Deixe em branco para manter o comportamento normal. Agendamentos finitos aceitam de 1 a 999 execuções.</string>
<string name="dashboard_cron_gateway_required">A criação de agendamentos requer uma conexão atual com o Hermes Gateway.</string>
<string name="dashboard_cron_created">Agendamento “%1$s” criado</string>
<string name="dashboard_cron_create_failed">Não foi possível criar o agendamento</string>
<string name="dashboard_section_action_browse_hub">Explorar a central</string>
<string name="dashboard_section_action_update_installed">Atualizar instaladas</string>
<!-- Action labels (rendered via kind → string) -->
@@ -1863,6 +1874,16 @@
<string name="dashboard_skills_update_failed">Falha ao iniciar a atualização de habilidades</string>
<!-- Profile create -->
<string name="dashboard_profile_created">Perfil %1$s criado</string>
<string name="dashboard_profile_created_partial">O perfil %1$s foi criado, mas %2$s. Revise antes de usar.</string>
<string name="dashboard_profile_created_legacy">O perfil %1$s foi criado pela rota antiga do Painel. Revise as credenciais antes de usar.</string>
<string name="dashboard_profile_no_skills">Não adicionar as habilidades incluídas</string>
<string name="dashboard_profile_auth_title">Autenticação</string>
<string name="dashboard_profile_auth_shared">Compartilhar login (recomendado) — um conjunto de tokens renováveis</string>
<string name="dashboard_profile_auth_copied">Copiar credenciais atuais — instantâneo separado que pode ficar desatualizado</string>
<string name="dashboard_profile_auth_isolated">Isolado — não copiar credenciais nem padrões do provedor</string>
<string name="dashboard_profile_auth_help">O Hermes aplica esta escolha no servidor. Senhas e tokens nunca são retornados ao Android.</string>
<string name="dashboard_profile_allow_legacy">Se a criação pelo Gateway não estiver disponível, permitir a rota antiga do Painel. O comportamento das credenciais depende do host e deve ser revisado.</string>
<string name="dashboard_profile_mcp_partial">A seleção de servidores MCP não foi aplicada</string>
<string name="dashboard_profile_create_failed">Falha ao criar o perfil</string>
<!-- Stats for nerds -->
<string name="stats_overview">Visão geral</string>
@@ -2466,7 +2487,35 @@
<plurals name="tool_run_using_tools"><item quantity="one">Usando %d ferramenta</item><item quantity="many">Usando %d ferramentas</item><item quantity="other">Usando %d ferramentas</item></plurals>
<plurals name="tool_run_used_tools"><item quantity="one">Usou %d ferramenta</item><item quantity="many">Usou %d ferramentas</item><item quantity="other">Usou %d ferramentas</item></plurals>
<!-- AgentIconRow -->
<string name="agent_icon_title">Ícone do agente</string>
<string name="agent_icon_title">Visual do agente</string>
<string name="agent_icon_hermes_pet_title">Mascote animado do Hermes</string>
<string name="agent_icon_hermes_pet_description">Vinculado ao perfil e compartilhado com as interfaces upstream do Hermes. Reage à atividade do agente e aparece como companheiro no celular.</string>
<string name="agent_icon_hermes_pet_active">Ativo: %1$s</string>
<string name="agent_icon_hermes_pet_empty">Nenhum mascote upstream selecionado</string>
<string name="agent_icon_hermes_pet_unsupported">Atualize o Hermes para gerenciar mascotes animados aqui</string>
<string name="agent_icon_hermes_pet_browse">Explorar mascotes do Hermes</string>
<string name="agent_icon_hermes_pet_picker_title">Escolha um mascote do Hermes</string>
<string name="agent_icon_hermes_pet_selected">Selecionado</string>
<string name="agent_icon_hermes_pet_installed">Instalado</string>
<string name="agent_icon_hermes_pet_adopt">Adotar do Petdex</string>
<string name="agent_icon_shared_title">Compartilhado no Hermes</string>
<string name="agent_icon_shared_active">Avatar compartilhado</string>
<string name="agent_icon_shared_empty">Nenhum avatar compartilhado</string>
<string name="agent_icon_change_shared">Alterar avatar compartilhado</string>
<string name="agent_icon_remove_shared">Remover</string>
<string name="agent_icon_remove_shared_title">Remover avatar compartilhado?</string>
<string name="agent_icon_remove_shared_message">Isso remove o avatar do Hermes e de outros clientes. A imagem deste celular não será afetada.</string>
<string name="agent_icon_phone_title">Somente neste celular</string>
<string name="agent_icon_phone_description">Substitua o avatar compartilhado somente neste celular sem alterar o Hermes.</string>
<string name="agent_icon_choose_phone">Escolher imagem do celular</string>
<string name="agent_icon_change_phone">Alterar imagem do celular</string>
<string name="agent_icon_remove_phone">Remover imagem do celular</string>
<string name="agent_icon_animation_note">Substituições animadas em GIF e WebP são reproduzidas somente neste celular. Use o mascote animado do Hermes acima para uma animação upstream vinculada ao perfil.</string>
<string name="agent_icon_set_local">Escolher imagem reserva do dispositivo</string>
<string name="agent_icon_change_local">Alterar imagem reserva do dispositivo</string>
<string name="agent_icon_clear_local">Limpar imagem reserva do dispositivo</string>
<string name="agent_icon_upload_shared">Enviar ícone do dispositivo ao Hermes</string>
<string name="agent_icon_clear_shared">Limpar avatar compartilhado do Hermes</string>
<string name="agent_icon_set">Escolher arquivo</string>
<string name="agent_icon_change">Escolher arquivo</string>
<string name="agent_icon_clear">Limpar</string>
@@ -3304,6 +3353,14 @@
<string name="dashboard_native_signin_requires_https">O login seguro pelo navegador exige um endereço HTTPS do painel.</string>
<string name="dashboard_native_signin_unavailable">O login seguro pelo navegador não está disponível para esta conexão. Atualize a conexão e tente novamente.</string>
<string name="dashboard_native_signin_transport_retry">A conexão segura foi interrompida. Toque no botão de login para tentar novamente.</string>
<string name="dashboard_native_signin_callback_rejected">O provedor não aprovou este login. Se você cancelou, nenhuma ação é necessária; caso contrário, inicie uma nova tentativa.</string>
<string name="dashboard_native_signin_code_rejected">O login com o Google terminou, mas o Hermes hospedado rejeitou o código de retorno de uso único antes de criar uma sessão. Inicie uma nova tentativa.</string>
<string name="dashboard_native_signin_gateway_rejected">O Hermes hospedado recusou a troca da sessão. Verifique se o agente hospedado está atualizado e inicie o login novamente.</string>
<string name="dashboard_native_signin_rate_limited">O Hermes hospedado recebeu tentativas de login demais. Aguarde um momento e tente novamente.</string>
<string name="dashboard_native_signin_gateway_unavailable">O login com o Google terminou, mas o serviço de login do Hermes hospedado está indisponível. Aguarde um momento e tente novamente.</string>
<string name="dashboard_native_signin_response_unsupported">O Hermes hospedado retornou uma resposta de login que este app não pode usar. Verifique se há atualizações do Hermes Relay e do agente hospedado.</string>
<string name="dashboard_native_signin_attempt_inactive">Esta tentativa de login foi cancelada ou substituída. Feche a aba antiga e comece novamente.</string>
<string name="dashboard_native_signin_storage_failed">O login com o Google terminou, mas o Android não conseguiu salvar a sessão do Hermes com segurança. Tente novamente; se o problema se repetir, abra Diagnósticos para ver a etapa da falha.</string>
<string name="conn_info_yolo_mode_desc_ephemeral">Ignore as solicitações de aprovação somente neste chat. A opção é redefinida quando a sessão muda.</string>
<string name="conn_info_yolo_mode_profile_off">As aprovações do perfil estão desativadas, então este chat já ignora as solicitações. Escolha Manual ou Inteligente antes de usar a exceção por chat.</string>
<string name="conn_info_approval_mode_title">Modo de aprovação do perfil</string>
@@ -3825,4 +3882,128 @@
<string name="pet_creator_step_review">Revisar e importar</string>
<string name="pet_creator_review_desc">Inspecione primeiro a imagem ou o ZIP retornado. A importação copia os arquivos validados para o armazenamento do app; ela não os publica.</string>
<string name="pet_creator_import">Importar pet concluído</string>
<string name="dashboard_tab_memory">Memória</string>
<string name="dashboard_tab_learning">Aprendizado</string>
<string name="dashboard_tab_channels">Canais</string>
<string name="dashboard_tab_operations">Operações</string>
<string name="dashboard_tab_memory_lower">memória</string>
<string name="dashboard_tab_learning_lower">aprendizado</string>
<string name="dashboard_tab_channels_lower">canais</string>
<string name="dashboard_tab_operations_lower">operações</string>
<string name="dashboard_section_action_server_backup">Criar backup do servidor</string>
<string name="dashboard_section_action_download_backup">Salvar backup mais recente</string>
<string name="dashboard_section_action_import_backup">Importar backup</string>
<string name="dashboard_backup_create_first">Crie um backup nesta sessão antes de baixá-lo.</string>
<string name="dashboard_backup_download_failed">Não foi possível baixar o backup.</string>
<string name="dashboard_backup_saved">Backup salvo como %1$s.</string>
<string name="dashboard_import_title">Importar backup do servidor?</string>
<string name="dashboard_import_warning">Isso envia o ZIP selecionado ao Hermes e inicia a importação autenticada no servidor. A configuração e os dados podem ser substituídos. Primeiro, crie e salve um backup atual.</string>
<string name="dashboard_import_confirm">Importar</string>
<string name="dashboard_import_started">Importação do servidor iniciada. Acompanhe a conclusão em Operações antes de reiniciar o Hermes.</string>
<string name="dashboard_import_failed">Não foi possível iniciar a importação do servidor.</string>
<string name="dashboard_profile_mcp_servers_optional">Servidores MCP (opcional)</string>
<string name="dashboard_profile_mcp_servers_help">Nomes de servidor separados por vírgulas ou linhas. As credenciais permanecem no servidor.</string>
<string name="dashboard_tile_memory_title">Memória</string>
<string name="dashboard_tile_memory_sub">Status do provedor e configuração de memória do servidor</string>
<string name="dashboard_tile_learning_title">Grafo de aprendizado</string>
<string name="dashboard_tile_learning_sub">Inspecione os nós aprendidos do perfil ativo</string>
<string name="dashboard_tile_channels_title">Canais</string>
<string name="dashboard_tile_channels_sub">Status das plataformas de mensagens, incluindo WhatsApp</string>
<string name="dashboard_tile_operations_title">Operações do servidor</string>
<string name="dashboard_tile_operations_sub">Integridade do host e backup geral do servidor</string>
<string name="dashboard_action_configure">Configurar</string>
<string name="dashboard_action_setup">Configurar</string>
<string name="dashboard_action_setup_whatsapp">Configurar o WhatsApp</string>
<string name="dashboard_learning_edit_title">Editar %1$s</string>
<string name="dashboard_learning_edit_warning">As edições substituem todo o conteúdo do nó. As habilidades excluídas do grafo são arquivadas pelo Hermes e podem ser restauradas; a exclusão de nós de memória é permanente, então exporte um backup primeiro.</string>
<string name="dashboard_learning_saved">Nó de aprendizado salvo.</string>
<string name="dashboard_learning_save_failed">Não foi possível salvar o nó de aprendizado.</string>
<string name="dashboard_learning_delete_warning">O Hermes arquiva as habilidades aprendidas para que possam ser restauradas pelo servidor. A exclusão de nós de memória é permanente. Se este conteúdo puder ser necessário depois, salve primeiro um backup do servidor.</string>
<string name="dashboard_memory_config_title">Configurar %1$s</string>
<string name="dashboard_memory_config_help">Os valores permanecem no perfil do Hermes selecionado. Os campos secretos são aceitos pelo servidor e nunca retornados após o salvamento. Os campos obrigatórios são marcados com *.</string>
<string name="dashboard_memory_values_json">Valores do provedor (JSON)</string>
<string name="dashboard_memory_run_setup">Executar configuração</string>
<string name="dashboard_memory_invalid_json">Os valores do provedor devem formar um objeto JSON.</string>
<string name="dashboard_memory_setup_started">A instalação do provedor em todo o host foi iniciada. Atualize após a conclusão e salve os valores deste perfil.</string>
<string name="dashboard_memory_saved">Provedor de memória configurado e ativado.</string>
<string name="dashboard_memory_save_failed">Não foi possível salvar a configuração do provedor de memória.</string>
<string name="dashboard_whatsapp_title">Configurar o WhatsApp</string>
<string name="dashboard_whatsapp_help">O Hermes inicia uma sessão de pareamento de dez minutos limitada ao perfil. Escolha o modo bot para uma conta dedicada ou conversa própria para enviar mensagens à sua conta vinculada.</string>
<string name="dashboard_whatsapp_bot">Conta de bot</string>
<string name="dashboard_whatsapp_self_chat">Conversa própria</string>
<string name="dashboard_whatsapp_allowed_users">Números de telefone permitidos (opcional)</string>
<string name="dashboard_whatsapp_start">Iniciar pareamento</string>
<string name="dashboard_whatsapp_scan">Escaneie este código na tela Dispositivos conectados do WhatsApp. Mantenha esta caixa de diálogo aberta enquanto o Hermes confirma a conta.</string>
<string name="dashboard_whatsapp_qr">Código QR de dispositivo conectado do WhatsApp</string>
<string name="dashboard_whatsapp_apply">Ativar o WhatsApp</string>
<string name="dashboard_whatsapp_start_failed">Não foi possível iniciar o pareamento do WhatsApp.</string>
<string name="dashboard_whatsapp_apply_failed">Não foi possível salvar a configuração do WhatsApp.</string>
<string name="dashboard_whatsapp_saved">WhatsApp ativado; o Hermes iniciou a reinicialização do gateway.</string>
<string name="drawer_all_profiles">Todos os perfis</string>
<string name="drawer_no_profile_sessions">Nenhuma sessão de perfil correspondente.</string>
<string name="drawer_customize_sessions">Personalizar sessões</string>
<string name="drawer_group_by">Agrupar por</string>
<string name="drawer_order_by">Ordenar por</string>
<string name="drawer_show_metadata">Mostrar nas linhas</string>
<string name="drawer_show_details">Mostrar detalhes</string>
<string name="drawer_filters">Filtros</string>
<string name="drawer_project_home">Início</string>
<string name="drawer_expand_project">Expandir %1$s</string>
<string name="drawer_collapse_project">Recolher %1$s</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d sessão</item>
<item quantity="other">%1$d sessões</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d perfil</item>
<item quantity="other">%1$d perfis</item>
</plurals>
<string name="drawer_filter_status">Status</string>
<string name="drawer_filter_profile">Perfil</string>
<string name="drawer_filter_project">Projeto</string>
<string name="drawer_filter_pull_request">Pull request</string>
<string name="drawer_option_updated">Atualizado</string>
<string name="drawer_option_profile">Perfil</string>
<string name="drawer_option_tokens">Tokens</string>
<string name="drawer_option_cost">Custo</string>
<string name="drawer_reset_filters">Redefinir</string>
<string name="drawer_profile_colors">Cores dos perfis</string>
<string name="drawer_profile_color_auto">Automática</string>
<string name="drawer_profile_color_set">Definir a cor do perfil %1$s como %2$s</string>
<string name="drawer_close">Fechar</string>
<string name="profile_inspector_gateway_settings">Configurações do perfil do Gateway</string>
<string name="profile_inspector_gateway_settings_hint">Salvo diretamente pelo Hermes para este perfil selecionado.</string>
<string name="profile_inspector_edit_config">Editar configurações do perfil</string>
<string name="profile_inspector_description">Descrição</string>
<string name="profile_inspector_provider">Provedor</string>
<string name="profile_inspector_model">Modelo</string>
<string name="profile_inspector_save_changes">Salvar alterações</string>
<string name="profile_inspector_toolsets">Conjuntos de ferramentas</string>
<string name="profile_inspector_toolsets_hint">Escolha quais grupos de ferramentas do Hermes este perfil pode usar.</string>
<string name="profile_inspector_tool_count">%1$d ferramentas</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · Experimental</string>
<string name="hermes_reach_summary">Rota de broker experimental para redes onde o acesso direto e o Tailscale não estão disponíveis. Ela ainda não é recomendada para a configuração normal; o TLS do Secure Link continua protegido de ponta a ponta.</string>
<string name="secure_link_pinned_tls">TLS fixado · identidade verificada por este pareamento</string>
<string name="secure_link_pinned_tls_short">Secure Link · TLS fixado</string>
<string name="secure_link_protects">Serviços protegidos: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">Painel</string>
<string name="secure_link_no_services">Nenhum serviço protegido foi anunciado. O Secure Link não será usado.</string>
<string name="secure_link_partial_warning">Proteção parcial: os serviços não listados aqui usam sua própria rota e segurança configuradas.</string>
<string name="secure_link_partial_short">Secure Link · parcial</string>
<string name="secure_link_fallback_ready">Se o Secure Link não estiver disponível, o Hermes poderá tentar as rotas alternativas aprovadas abaixo.</string>
<string name="secure_link_no_fallback">Nenhuma rota alternativa está incluída. Os serviços protegidos permanecerão offline se o Secure Link não estiver disponível.</string>
<string name="secure_link_auth_note">A proteção do transporte não ignora a autenticação. O pareamento do Relay, as credenciais da API e o login no Painel continuam sendo exigidos por serviço.</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="one">%1$d mensagem chegou enquanto você estava ausente</item>
<item quantity="other">%1$d mensagens chegaram enquanto você estava ausente</item>
</plurals>
<string name="chat_model_confirmation_title">Confirmar seleção do modelo</string>
<string name="host_resource_recent_oom">O Hermes reiniciou recentemente, provavelmente por falta de memória.</string>
<string name="host_resource_memory_critical">A memória do servidor está criticamente baixa; chats ativos podem parar.</string>
<string name="host_resource_memory_elevated">A memória do servidor está baixa.</string>
<string name="host_resource_disk_critical">O armazenamento do servidor está criticamente baixo; mensagens e configurações podem não ser salvas.</string>
<string name="host_resource_disk_elevated">O armazenamento do servidor está baixo.</string>
</resources>
+179 -1
View File
@@ -1796,6 +1796,17 @@
<!-- Section action buttons -->
<string name="dashboard_section_action_change_main_model">更改主模型</string>
<string name="dashboard_section_action_new_profile">新建配置文件</string>
<string name="dashboard_section_action_new_schedule">新建计划</string>
<string name="dashboard_cron_create_title">创建计划</string>
<string name="dashboard_cron_name">名称</string>
<string name="dashboard_cron_schedule">计划</string>
<string name="dashboard_cron_schedule_hint">示例:every 2h、0 9 * * 1-5 或 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">任务说明</string>
<string name="dashboard_cron_repeat">运行指定次数后停止(可选)</string>
<string name="dashboard_cron_repeat_help">留空以保留计划的正常行为。有限计划可设置 1–999 次运行。</string>
<string name="dashboard_cron_gateway_required">创建计划需要当前 Hermes Gateway 连接。</string>
<string name="dashboard_cron_created">已创建计划“%1$s”</string>
<string name="dashboard_cron_create_failed">无法创建计划</string>
<string name="dashboard_section_action_browse_hub">浏览中心</string>
<string name="dashboard_section_action_update_installed">更新已安装</string>
@@ -1950,6 +1961,16 @@
<!-- Profile create -->
<string name="dashboard_profile_created">已创建配置文件 %1$s</string>
<string name="dashboard_profile_created_partial">配置文件 %1$s 已创建,但%2$s。使用前请检查。</string>
<string name="dashboard_profile_created_legacy">配置文件 %1$s 已通过旧版控制面板路由创建。使用前请检查其凭据。</string>
<string name="dashboard_profile_no_skills">不添加内置技能</string>
<string name="dashboard_profile_auth_title">身份验证</string>
<string name="dashboard_profile_auth_shared">共享登录(推荐)— 共用一个可刷新的令牌池</string>
<string name="dashboard_profile_auth_copied">复制当前凭据 — 独立快照可能会过期</string>
<string name="dashboard_profile_auth_isolated">隔离 — 不复制凭据或提供商默认值</string>
<string name="dashboard_profile_auth_help">Hermes 在服务器上应用此选择。密码和令牌绝不会返回到 Android。</string>
<string name="dashboard_profile_allow_legacy">如果无法通过 Gateway 创建,则允许使用旧版控制面板路由。凭据行为取决于该主机,必须进行检查。</string>
<string name="dashboard_profile_mcp_partial">未应用 MCP 服务器选择</string>
<string name="dashboard_profile_create_failed">创建配置文件失败</string>
<!-- Stats for nerds -->
@@ -2576,7 +2597,35 @@
<plurals name="tool_run_used_tools"><item quantity="other">已使用 %d 个工具</item></plurals>
<!-- AgentIconRow -->
<string name="agent_icon_title">代理图标</string>
<string name="agent_icon_title">代理外观</string>
<string name="agent_icon_hermes_pet_title">Hermes 动画宠物</string>
<string name="agent_icon_hermes_pet_description">按配置文件保存,并与上游 Hermes 界面共享。它会响应代理活动,并作为手机伴侣显示。</string>
<string name="agent_icon_hermes_pet_active">已启用:%1$s</string>
<string name="agent_icon_hermes_pet_empty">未选择上游宠物</string>
<string name="agent_icon_hermes_pet_unsupported">请更新 Hermes 以在此管理动画宠物</string>
<string name="agent_icon_hermes_pet_browse">浏览 Hermes 宠物</string>
<string name="agent_icon_hermes_pet_picker_title">选择 Hermes 宠物</string>
<string name="agent_icon_hermes_pet_selected">已选择</string>
<string name="agent_icon_hermes_pet_installed">已安装</string>
<string name="agent_icon_hermes_pet_adopt">从 Petdex 领养</string>
<string name="agent_icon_shared_title">在 Hermes 中共享</string>
<string name="agent_icon_shared_active">共享头像</string>
<string name="agent_icon_shared_empty">无共享头像</string>
<string name="agent_icon_change_shared">更改共享头像</string>
<string name="agent_icon_remove_shared">移除</string>
<string name="agent_icon_remove_shared_title">移除共享头像?</string>
<string name="agent_icon_remove_shared_message">这会从 Hermes 和其他客户端移除头像,但不会影响本手机上的图像。</string>
<string name="agent_icon_phone_title">仅限本手机</string>
<string name="agent_icon_phone_description">仅在本手机上覆盖共享头像,不更改 Hermes。</string>
<string name="agent_icon_choose_phone">选择手机图像</string>
<string name="agent_icon_change_phone">更改手机图像</string>
<string name="agent_icon_remove_phone">移除手机图像</string>
<string name="agent_icon_animation_note">GIF 和 WebP 动画替代仅在本手机上播放。如需按配置文件管理的上游动画,请使用上方的 Hermes 动画宠物。</string>
<string name="agent_icon_set_local">选择设备备用图像</string>
<string name="agent_icon_change_local">更改设备备用图像</string>
<string name="agent_icon_clear_local">清除设备备用图像</string>
<string name="agent_icon_upload_shared">将设备图标上传到 Hermes</string>
<string name="agent_icon_clear_shared">清除共享的 Hermes 头像</string>
<string name="agent_icon_set">选择文件</string>
<string name="agent_icon_change">选择文件</string>
<string name="agent_icon_clear">清除</string>
@@ -3397,6 +3446,14 @@
<string name="dashboard_native_signin_requires_https">安全浏览器登录需要 HTTPS 控制面板地址。</string>
<string name="dashboard_native_signin_unavailable">此连接无法使用安全浏览器登录。请刷新连接后重试。</string>
<string name="dashboard_native_signin_transport_retry">安全连接已中断。请点按登录按钮重试。</string>
<string name="dashboard_native_signin_callback_rejected">提供商未批准本次登录。如果是你取消的,则无需操作;否则请重新开始登录。</string>
<string name="dashboard_native_signin_code_rejected">Google 登录已完成,但托管的 Hermes 在创建会话前拒绝了一次性回调代码。请重新开始登录。</string>
<string name="dashboard_native_signin_gateway_rejected">托管的 Hermes 拒绝了会话交换。请确认托管代理已更新,然后重新开始登录。</string>
<string name="dashboard_native_signin_rate_limited">托管的 Hermes 收到了过多登录尝试。请稍等片刻后重试。</string>
<string name="dashboard_native_signin_gateway_unavailable">Google 登录已完成,但托管的 Hermes 登录服务不可用。请稍等片刻后重试。</string>
<string name="dashboard_native_signin_response_unsupported">托管的 Hermes 返回了此应用无法使用的登录响应。请检查 Hermes Relay 和托管代理的更新。</string>
<string name="dashboard_native_signin_attempt_inactive">本次登录尝试已取消或被替换。请关闭旧浏览器标签页并重新开始。</string>
<string name="dashboard_native_signin_storage_failed">Google 登录已完成,但 Android 无法安全保存 Hermes 会话。请重试;如果问题重复出现,请打开“诊断”查看失败阶段。</string>
<string name="conn_info_yolo_mode_desc_ephemeral">仅在此聊天中跳过批准提示。会在会话更改时重置。</string>
<string name="conn_info_yolo_mode_profile_off">配置文件批准已关闭,因此此聊天已经会跳过提示。使用单聊天例外前,请选择手动或智能。</string>
<string name="conn_info_approval_mode_title">配置文件批准模式</string>
@@ -3913,4 +3970,125 @@
<string name="pet_creator_step_review">检查并导入</string>
<string name="pet_creator_review_desc">请先检查返回的图片或 ZIP。导入会将经过验证的文件复制到应用专属存储空间,不会发布它们。</string>
<string name="pet_creator_import">导入完成的宠物</string>
<string name="dashboard_tab_memory">记忆</string>
<string name="dashboard_tab_learning">学习</string>
<string name="dashboard_tab_channels">频道</string>
<string name="dashboard_tab_operations">运维</string>
<string name="dashboard_tab_memory_lower">记忆</string>
<string name="dashboard_tab_learning_lower">学习</string>
<string name="dashboard_tab_channels_lower">频道</string>
<string name="dashboard_tab_operations_lower">运维</string>
<string name="dashboard_section_action_server_backup">创建服务器备份</string>
<string name="dashboard_profile_mcp_servers_optional">MCP 服务器(可选)</string>
<string name="dashboard_profile_mcp_servers_help">用逗号或换行分隔服务器名称。凭据仍由服务器保管。</string>
<string name="dashboard_tile_memory_title">记忆</string>
<string name="dashboard_tile_memory_sub">提供商状态和服务器端记忆配置</string>
<string name="dashboard_tile_learning_title">学习图谱</string>
<string name="dashboard_tile_learning_sub">查看当前配置文件的已学习节点</string>
<string name="dashboard_tile_channels_title">频道</string>
<string name="dashboard_tile_channels_sub">消息平台状态,包括 WhatsApp</string>
<string name="dashboard_tile_operations_title">服务器运维</string>
<string name="dashboard_tile_operations_sub">主机健康状况和服务器整体备份</string>
<string name="dashboard_section_action_download_backup">保存最新备份</string>
<string name="dashboard_section_action_import_backup">导入备份</string>
<string name="dashboard_backup_create_first">请先在本次会话中创建备份,再下载。</string>
<string name="dashboard_backup_download_failed">无法下载备份。</string>
<string name="dashboard_backup_saved">备份已保存为 %1$s。</string>
<string name="dashboard_import_title">导入服务器备份?</string>
<string name="dashboard_import_warning">这会将所选 ZIP 上传到 Hermes,并启动经过身份验证的服务器导入。导入可能替换配置和数据。请先创建并保存当前备份。</string>
<string name="dashboard_import_confirm">导入</string>
<string name="dashboard_import_started">服务器导入已启动。请在“运维”中等待完成,然后再重启 Hermes。</string>
<string name="dashboard_import_failed">无法启动服务器导入。</string>
<string name="dashboard_action_configure">配置</string>
<string name="dashboard_action_setup">设置</string>
<string name="dashboard_action_setup_whatsapp">设置 WhatsApp</string>
<string name="dashboard_learning_edit_title">编辑 %1$s</string>
<string name="dashboard_learning_edit_warning">编辑会替换节点的全部内容。Hermes 会归档从图谱中删除的技能,以便从归档中恢复;删除记忆节点则无法撤销,因此请先导出备份。</string>
<string name="dashboard_learning_saved">学习节点已保存。</string>
<string name="dashboard_learning_save_failed">无法保存学习节点。</string>
<string name="dashboard_learning_delete_warning">Hermes 会归档已学习技能,以便从服务器归档中恢复。删除记忆节点则无法撤销。如果以后可能需要这些内容,请先保存服务器备份。</string>
<string name="dashboard_memory_config_title">配置 %1$s</string>
<string name="dashboard_memory_config_help">值会保留在所选 Hermes 配置文件中。服务器接受机密字段,但保存后绝不会返回这些字段。必填字段以 * 标记。</string>
<string name="dashboard_memory_values_json">提供商值 (JSON)</string>
<string name="dashboard_memory_run_setup">运行设置</string>
<string name="dashboard_memory_invalid_json">提供商值必须是 JSON 对象。</string>
<string name="dashboard_memory_setup_started">全主机范围的提供商安装已启动。完成后请刷新,然后保存此配置文件的值。</string>
<string name="dashboard_memory_saved">记忆提供商已配置并启用。</string>
<string name="dashboard_memory_save_failed">无法保存记忆提供商配置。</string>
<string name="dashboard_whatsapp_title">设置 WhatsApp</string>
<string name="dashboard_whatsapp_help">Hermes 会启动一个时长十分钟、仅限当前配置文件的配对会话。专用账号请选择机器人模式;要向自己已关联的账号发消息,请选择自聊。</string>
<string name="dashboard_whatsapp_bot">机器人账号</string>
<string name="dashboard_whatsapp_self_chat">自聊</string>
<string name="dashboard_whatsapp_allowed_users">允许的电话号码(可选)</string>
<string name="dashboard_whatsapp_start">开始配对</string>
<string name="dashboard_whatsapp_scan">请在 WhatsApp 的“关联设备”页面扫描此代码。Hermes 确认账号期间,请保持此对话框打开。</string>
<string name="dashboard_whatsapp_qr">WhatsApp 关联设备二维码</string>
<string name="dashboard_whatsapp_apply">启用 WhatsApp</string>
<string name="dashboard_whatsapp_start_failed">无法开始 WhatsApp 配对。</string>
<string name="dashboard_whatsapp_apply_failed">无法保存 WhatsApp 配置。</string>
<string name="dashboard_whatsapp_saved">WhatsApp 已启用;Hermes 已开始重启网关。</string>
<string name="drawer_all_profiles">所有配置文件</string>
<string name="drawer_no_profile_sessions">没有匹配的配置文件会话。</string>
<string name="drawer_customize_sessions">自定义会话</string>
<string name="drawer_group_by">分组方式</string>
<string name="drawer_order_by">排序方式</string>
<string name="drawer_show_metadata">在行中显示</string>
<string name="drawer_show_details">显示详细信息</string>
<string name="drawer_filters">筛选器</string>
<string name="drawer_project_home">主页</string>
<string name="drawer_expand_project">展开%1$s</string>
<string name="drawer_collapse_project">折叠%1$s</string>
<plurals name="drawer_project_session_count">
<item quantity="other">%1$d 个会话</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="other">%1$d 个配置文件</item>
</plurals>
<string name="drawer_filter_status">状态</string>
<string name="drawer_filter_profile">配置文件</string>
<string name="drawer_filter_project">项目</string>
<string name="drawer_filter_pull_request">拉取请求</string>
<string name="drawer_option_updated">更新时间</string>
<string name="drawer_option_profile">配置文件</string>
<string name="drawer_option_tokens">令牌</string>
<string name="drawer_option_cost">费用</string>
<string name="drawer_reset_filters">重置</string>
<string name="drawer_profile_colors">配置文件颜色</string>
<string name="drawer_profile_color_auto">自动</string>
<string name="drawer_profile_color_set">将 %1$s 配置文件颜色设为 %2$s</string>
<string name="drawer_close">关闭</string>
<string name="profile_inspector_gateway_settings">Gateway 配置文件设置</string>
<string name="profile_inspector_gateway_settings_hint">通过 Hermes 直接保存到当前所选配置文件。</string>
<string name="profile_inspector_edit_config">编辑配置文件设置</string>
<string name="profile_inspector_description">说明</string>
<string name="profile_inspector_provider">提供商</string>
<string name="profile_inspector_model">模型</string>
<string name="profile_inspector_save_changes">保存更改</string>
<string name="profile_inspector_toolsets">工具集</string>
<string name="profile_inspector_toolsets_hint">选择此配置文件可以使用的 Hermes 工具组。</string>
<string name="profile_inspector_tool_count">%1$d 个工具</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · 实验性</string>
<string name="hermes_reach_summary">用于无法直接访问且无法使用 Tailscale 的网络的实验性代理路由。目前不建议用于常规设置;Secure Link TLS 仍保持端到端保护。</string>
<string name="secure_link_pinned_tls">固定 TLS · 已通过此次配对验证身份</string>
<string name="secure_link_pinned_tls_short">Secure Link · 固定 TLS</string>
<string name="secure_link_protects">受保护的服务:%1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">控制面板</string>
<string name="secure_link_no_services">未公布任何受保护的服务。不会使用 Secure Link。</string>
<string name="secure_link_partial_warning">部分保护:未在此列出的服务将使用各自配置的路由和安全设置。</string>
<string name="secure_link_partial_short">Secure Link · 部分</string>
<string name="secure_link_fallback_ready">如果 Secure Link 不可用,Hermes 可以尝试下面已批准的备用路由。</string>
<string name="secure_link_no_fallback">未包含备用路由。如果 Secure Link 不可用,受保护的服务将保持离线。</string>
<string name="secure_link_auth_note">传输保护不会绕过身份验证。Relay 配对、API 凭据和控制面板登录仍会按服务分别强制执行。</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="other">离开期间收到了 %1$d 条消息</item>
</plurals>
<string name="chat_model_confirmation_title">确认模型选择</string>
<string name="host_resource_recent_oom">Hermes 最近可能因内存不足而重启。</string>
<string name="host_resource_memory_critical">主机内存严重不足,进行中的聊天可能会停止。</string>
<string name="host_resource_memory_elevated">主机内存不足。</string>
<string name="host_resource_disk_critical">主机存储空间严重不足,消息和设置可能无法保存。</string>
<string name="host_resource_disk_elevated">主机存储空间不足。</string>
</resources>
+182 -1
View File
@@ -1799,6 +1799,17 @@
<!-- Section action buttons -->
<string name="dashboard_section_action_change_main_model">Hauptmodell ändern</string>
<string name="dashboard_section_action_new_profile">Neues Profil</string>
<string name="dashboard_section_action_new_schedule">Neuer Zeitplan</string>
<string name="dashboard_cron_create_title">Zeitplan erstellen</string>
<string name="dashboard_cron_name">Name</string>
<string name="dashboard_cron_schedule">Zeitplan</string>
<string name="dashboard_cron_schedule_hint">Beispiele: every 2h, 0 9 * * 1-5 oder 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">Aufgabenanweisungen</string>
<string name="dashboard_cron_repeat">Nach dieser Anzahl von Ausführungen stoppen (optional)</string>
<string name="dashboard_cron_repeat_help">Leer lassen, um das normale Verhalten des Zeitplans beizubehalten. Endliche Zeitpläne akzeptieren 1–999 Ausführungen.</string>
<string name="dashboard_cron_gateway_required">Zum Erstellen eines Zeitplans ist eine aktuelle Hermes-Gateway-Verbindung erforderlich.</string>
<string name="dashboard_cron_created">Zeitplan „%1$s“ erstellt</string>
<string name="dashboard_cron_create_failed">Zeitplan konnte nicht erstellt werden</string>
<string name="dashboard_section_action_browse_hub">Sammlung durchsuchen</string>
<string name="dashboard_section_action_update_installed">Installierte aktualisieren</string>
@@ -1953,6 +1964,16 @@
<!-- Profile create -->
<string name="dashboard_profile_created">Profil %1$s erstellt</string>
<string name="dashboard_profile_created_partial">Profil %1$s wurde erstellt, aber %2$s. Vor der Verwendung prüfen.</string>
<string name="dashboard_profile_created_legacy">Profil %1$s wurde über die ältere Dashboard-Route erstellt. Zugangsdaten vor der Verwendung prüfen.</string>
<string name="dashboard_profile_no_skills">Gebündelte Skills nicht hinzufügen</string>
<string name="dashboard_profile_auth_title">Authentifizierung</string>
<string name="dashboard_profile_auth_shared">Anmeldung teilen (empfohlen) — ein aktualisierbarer Token-Pool</string>
<string name="dashboard_profile_auth_copied">Aktuelle Zugangsdaten kopieren — separater Snapshot, der veralten kann</string>
<string name="dashboard_profile_auth_isolated">Isoliert — keine Zugangsdaten oder Anbieterstandards kopieren</string>
<string name="dashboard_profile_auth_help">Hermes wendet diese Auswahl auf dem Server an. Passwörter und Token werden nie an Android zurückgegeben.</string>
<string name="dashboard_profile_allow_legacy">Wenn die Gateway-Erstellung nicht verfügbar ist, die ältere Dashboard-Route zulassen. Das Verhalten der Zugangsdaten hängt vom Host ab und muss geprüft werden.</string>
<string name="dashboard_profile_mcp_partial">Die MCP-Serverauswahl wurde nicht angewendet</string>
<string name="dashboard_profile_create_failed">Profil konnte nicht erstellt werden</string>
<!-- Stats for nerds -->
@@ -2579,7 +2600,35 @@
<plurals name="tool_run_used_tools"><item quantity="one">%d Werkzeug verwendet</item><item quantity="other">%d Werkzeuge verwendet</item></plurals>
<!-- AgentIconRow -->
<string name="agent_icon_title">Agentensymbol</string>
<string name="agent_icon_title">Agentendarstellung</string>
<string name="agent_icon_hermes_pet_title">Animiertes Hermes-Haustier</string>
<string name="agent_icon_hermes_pet_description">Profilbezogen und mit Upstream-Hermes-Oberflächen geteilt. Es reagiert auf Agentenaktivität und erscheint als Begleiter auf dem Smartphone.</string>
<string name="agent_icon_hermes_pet_active">Aktiv: %1$s</string>
<string name="agent_icon_hermes_pet_empty">Kein Upstream-Haustier ausgewählt</string>
<string name="agent_icon_hermes_pet_unsupported">Hermes aktualisieren, um animierte Haustiere hier zu verwalten</string>
<string name="agent_icon_hermes_pet_browse">Hermes-Haustiere durchsuchen</string>
<string name="agent_icon_hermes_pet_picker_title">Hermes-Haustier auswählen</string>
<string name="agent_icon_hermes_pet_selected">Ausgewählt</string>
<string name="agent_icon_hermes_pet_installed">Installiert</string>
<string name="agent_icon_hermes_pet_adopt">Aus Petdex übernehmen</string>
<string name="agent_icon_shared_title">In Hermes geteilt</string>
<string name="agent_icon_shared_active">Geteilter Avatar</string>
<string name="agent_icon_shared_empty">Kein geteilter Avatar</string>
<string name="agent_icon_change_shared">Geteilten Avatar ändern</string>
<string name="agent_icon_remove_shared">Entfernen</string>
<string name="agent_icon_remove_shared_title">Geteilten Avatar entfernen?</string>
<string name="agent_icon_remove_shared_message">Dadurch wird der Avatar aus Hermes und anderen Clients entfernt. Das Bild auf diesem Smartphone bleibt erhalten.</string>
<string name="agent_icon_phone_title">Nur dieses Smartphone</string>
<string name="agent_icon_phone_description">Den geteilten Avatar nur auf diesem Smartphone überschreiben, ohne Hermes zu ändern.</string>
<string name="agent_icon_choose_phone">Smartphone-Bild auswählen</string>
<string name="agent_icon_change_phone">Smartphone-Bild ändern</string>
<string name="agent_icon_remove_phone">Smartphone-Bild entfernen</string>
<string name="agent_icon_animation_note">Animierte GIF- und WebP-Überschreibungen werden nur auf diesem Smartphone abgespielt. Für eine profilbezogene Upstream-Animation oben ein animiertes Hermes-Haustier verwenden.</string>
<string name="agent_icon_set_local">Geräte-Ersatzbild auswählen</string>
<string name="agent_icon_change_local">Geräte-Ersatzbild ändern</string>
<string name="agent_icon_clear_local">Geräte-Ersatzbild löschen</string>
<string name="agent_icon_upload_shared">Gerätesymbol zu Hermes hochladen</string>
<string name="agent_icon_clear_shared">Geteilten Hermes-Avatar löschen</string>
<string name="agent_icon_set">Datei auswählen</string>
<string name="agent_icon_change">Datei auswählen</string>
<string name="agent_icon_clear">Löschen</string>
@@ -3464,6 +3513,14 @@
<string name="dashboard_native_signin_requires_https">Die sichere Browser-Anmeldung erfordert eine HTTPS-Dashboard-Adresse.</string>
<string name="dashboard_native_signin_unavailable">Die sichere Browser-Anmeldung ist für diese Verbindung nicht verfügbar. Aktualisiere die Verbindung und versuche es erneut.</string>
<string name="dashboard_native_signin_transport_retry">Die sichere Verbindung wurde unterbrochen. Tippe auf die Anmeldeschaltfläche, um es erneut zu versuchen.</string>
<string name="dashboard_native_signin_callback_rejected">Der Anbieter hat diese Anmeldung nicht genehmigt. Wenn du abgebrochen hast, ist keine Aktion nötig; andernfalls starte einen neuen Anmeldeversuch.</string>
<string name="dashboard_native_signin_code_rejected">Die Google-Anmeldung wurde abgeschlossen, aber das gehostete Hermes hat den einmaligen Rückrufcode abgelehnt, bevor eine Sitzung erstellt werden konnte. Starte einen neuen Anmeldeversuch.</string>
<string name="dashboard_native_signin_gateway_rejected">Das gehostete Hermes hat den Sitzungsaustausch abgelehnt. Prüfe, ob der gehostete Agent aktuell ist, und starte die Anmeldung erneut.</string>
<string name="dashboard_native_signin_rate_limited">Das gehostete Hermes hat zu viele Anmeldeversuche erhalten. Warte einen Moment und versuche es erneut.</string>
<string name="dashboard_native_signin_gateway_unavailable">Die Google-Anmeldung wurde abgeschlossen, aber der Anmeldedienst des gehosteten Hermes ist nicht verfügbar. Warte einen Moment und versuche es erneut.</string>
<string name="dashboard_native_signin_response_unsupported">Das gehostete Hermes hat eine Anmeldeantwort zurückgegeben, die diese App nicht verwenden kann. Suche nach Updates für Hermes Relay und den gehosteten Agent.</string>
<string name="dashboard_native_signin_attempt_inactive">Dieser Anmeldeversuch wurde abgebrochen oder ersetzt. Schließe den alten Browser-Tab und starte erneut.</string>
<string name="dashboard_native_signin_storage_failed">Die Google-Anmeldung wurde abgeschlossen, aber Android konnte die Hermes-Sitzung nicht sicher speichern. Versuche es erneut. Falls der Fehler wiederholt auftritt, öffne die Diagnose für die Fehlerstufe.</string>
<string name="conn_info_yolo_mode_desc_ephemeral">Umgehe Bestätigungsabfragen nur für diesen Chat. Wird beim Sitzungswechsel zurückgesetzt.</string>
<string name="conn_info_yolo_mode_profile_off">Profilbestätigungen sind deaktiviert, daher umgeht dieser Chat bereits Abfragen. Wähle Manuell oder Smart, bevor du die chatbezogene Ausnahme verwendest.</string>
<string name="conn_info_approval_mode_title">Profil-Bestätigungsmodus</string>
@@ -3985,4 +4042,128 @@
<string name="pet_creator_step_review">Prüfen und importieren</string>
<string name="pet_creator_review_desc">Prüfen Sie zuerst das zurückgegebene Bild oder ZIP. Beim Import werden die validierten Dateien in den App-Speicher kopiert; sie werden nicht veröffentlicht.</string>
<string name="pet_creator_import">Fertiges Pet importieren</string>
<string name="dashboard_tab_memory">Speicher</string>
<string name="dashboard_tab_learning">Lernen</string>
<string name="dashboard_tab_channels">Kanäle</string>
<string name="dashboard_tab_operations">Betrieb</string>
<string name="dashboard_tab_memory_lower">Speicher</string>
<string name="dashboard_tab_learning_lower">Lernen</string>
<string name="dashboard_tab_channels_lower">Kanäle</string>
<string name="dashboard_tab_operations_lower">Betrieb</string>
<string name="dashboard_section_action_server_backup">Server-Sicherung erstellen</string>
<string name="dashboard_profile_mcp_servers_optional">MCP-Server (optional)</string>
<string name="dashboard_profile_mcp_servers_help">Komma- oder zeilengetrennte Servernamen. Anmeldedaten verbleiben auf dem Server.</string>
<string name="dashboard_tile_memory_title">Speicher</string>
<string name="dashboard_tile_memory_sub">Anbieterstatus und servereigene Speicherkonfiguration</string>
<string name="dashboard_tile_learning_title">Lerngraph</string>
<string name="dashboard_tile_learning_sub">Gelernte Knoten des aktiven Profils prüfen</string>
<string name="dashboard_tile_channels_title">Kanäle</string>
<string name="dashboard_tile_channels_sub">Status der Nachrichtenplattformen einschließlich WhatsApp</string>
<string name="dashboard_tile_operations_title">Serverbetrieb</string>
<string name="dashboard_tile_operations_sub">Hostzustand und serverweite Sicherung</string>
<string name="dashboard_section_action_download_backup">Neueste Sicherung speichern</string>
<string name="dashboard_section_action_import_backup">Sicherung importieren</string>
<string name="dashboard_backup_create_first">Erstellen Sie in dieser Sitzung eine Sicherung, bevor Sie sie herunterladen.</string>
<string name="dashboard_backup_download_failed">Die Sicherung konnte nicht heruntergeladen werden.</string>
<string name="dashboard_backup_saved">Sicherung als %1$s gespeichert.</string>
<string name="dashboard_import_title">Server-Sicherung importieren?</string>
<string name="dashboard_import_warning">Dies lädt die ausgewählte ZIP-Datei zu Hermes hoch und startet den authentifizierten Serverimport. Dabei können Konfiguration und Daten ersetzt werden. Erstellen und speichern Sie zuerst eine aktuelle Sicherung.</string>
<string name="dashboard_import_confirm">Importieren</string>
<string name="dashboard_import_started">Serverimport gestartet. Warten Sie unter „Betrieb“ auf den Abschluss, bevor Sie Hermes neu starten.</string>
<string name="dashboard_import_failed">Der Serverimport konnte nicht gestartet werden.</string>
<string name="dashboard_action_configure">Konfigurieren</string>
<string name="dashboard_action_setup">Einrichten</string>
<string name="dashboard_action_setup_whatsapp">WhatsApp einrichten</string>
<string name="dashboard_learning_edit_title">%1$s bearbeiten</string>
<string name="dashboard_learning_edit_warning">Beim Bearbeiten wird der gesamte Inhalt des Knotens ersetzt. Aus dem Graphen gelöschte Skills werden von Hermes archiviert und können aus dem Archiv wiederhergestellt werden. Das Löschen von Speicherknoten ist endgültig; exportieren Sie daher zuerst eine Sicherung.</string>
<string name="dashboard_learning_saved">Lernknoten gespeichert.</string>
<string name="dashboard_learning_save_failed">Der Lernknoten konnte nicht gespeichert werden.</string>
<string name="dashboard_learning_delete_warning">Hermes archiviert erlernte Skills, sodass sie aus dem Serverarchiv wiederhergestellt werden können. Das Löschen von Speicherknoten ist endgültig. Speichern Sie zuerst eine Server-Sicherung, falls dieser Inhalt später noch benötigt wird.</string>
<string name="dashboard_memory_config_title">%1$s konfigurieren</string>
<string name="dashboard_memory_config_help">Die Werte verbleiben im ausgewählten Hermes-Profil. Vertrauliche Felder werden vom Server akzeptiert und nach dem Speichern nie zurückgegeben. Pflichtfelder sind mit * markiert.</string>
<string name="dashboard_memory_values_json">Anbieterwerte (JSON)</string>
<string name="dashboard_memory_run_setup">Einrichtung starten</string>
<string name="dashboard_memory_invalid_json">Die Anbieterwerte müssen ein JSON-Objekt sein.</string>
<string name="dashboard_memory_setup_started">Die hostweite Anbieterinstallation wurde gestartet. Aktualisieren Sie nach Abschluss die Ansicht und speichern Sie dann die Werte dieses Profils.</string>
<string name="dashboard_memory_saved">Speicheranbieter konfiguriert und aktiviert.</string>
<string name="dashboard_memory_save_failed">Die Konfiguration des Speicheranbieters konnte nicht gespeichert werden.</string>
<string name="dashboard_whatsapp_title">WhatsApp einrichten</string>
<string name="dashboard_whatsapp_help">Hermes startet eine zehnminütige, profilbezogene Kopplungssitzung. Wählen Sie den Bot-Modus für ein eigenes Konto oder den Selbstchat, um Nachrichten an Ihr eigenes verknüpftes Konto zu senden.</string>
<string name="dashboard_whatsapp_bot">Bot-Konto</string>
<string name="dashboard_whatsapp_self_chat">Selbstchat</string>
<string name="dashboard_whatsapp_allowed_users">Zulässige Telefonnummern (optional)</string>
<string name="dashboard_whatsapp_start">Kopplung starten</string>
<string name="dashboard_whatsapp_scan">Scannen Sie diesen Code unter „Verknüpfte Geräte“ in WhatsApp. Lassen Sie diesen Dialog geöffnet, während Hermes das Konto bestätigt.</string>
<string name="dashboard_whatsapp_qr">QR-Code für ein verknüpftes WhatsApp-Gerät</string>
<string name="dashboard_whatsapp_apply">WhatsApp aktivieren</string>
<string name="dashboard_whatsapp_start_failed">Die WhatsApp-Kopplung konnte nicht gestartet werden.</string>
<string name="dashboard_whatsapp_apply_failed">Die WhatsApp-Konfiguration konnte nicht gespeichert werden.</string>
<string name="dashboard_whatsapp_saved">WhatsApp aktiviert; Hermes hat einen Gateway-Neustart gestartet.</string>
<string name="drawer_all_profiles">Alle Profile</string>
<string name="drawer_no_profile_sessions">Keine passenden Profilsitzungen.</string>
<string name="drawer_customize_sessions">Sitzungen anpassen</string>
<string name="drawer_group_by">Gruppieren nach</string>
<string name="drawer_order_by">Sortieren nach</string>
<string name="drawer_show_metadata">In Zeilen anzeigen</string>
<string name="drawer_show_details">Details anzeigen</string>
<string name="drawer_filters">Filter</string>
<string name="drawer_project_home">Startseite</string>
<string name="drawer_expand_project">%1$s erweitern</string>
<string name="drawer_collapse_project">%1$s reduzieren</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d Sitzung</item>
<item quantity="other">%1$d Sitzungen</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d Profil</item>
<item quantity="other">%1$d Profile</item>
</plurals>
<string name="drawer_filter_status">Status</string>
<string name="drawer_filter_profile">Profil</string>
<string name="drawer_filter_project">Projekt</string>
<string name="drawer_filter_pull_request">Pull Request</string>
<string name="drawer_option_updated">Aktualisiert</string>
<string name="drawer_option_profile">Profil</string>
<string name="drawer_option_tokens">Tokens</string>
<string name="drawer_option_cost">Kosten</string>
<string name="drawer_reset_filters">Zurücksetzen</string>
<string name="drawer_profile_colors">Profilfarben</string>
<string name="drawer_profile_color_auto">Automatisch</string>
<string name="drawer_profile_color_set">Profilfarbe von %1$s auf %2$s setzen</string>
<string name="drawer_close">Schließen</string>
<string name="profile_inspector_gateway_settings">Gateway-Profileinstellungen</string>
<string name="profile_inspector_gateway_settings_hint">Wird für dieses ausgewählte Profil direkt über Hermes gespeichert.</string>
<string name="profile_inspector_edit_config">Profileinstellungen bearbeiten</string>
<string name="profile_inspector_description">Beschreibung</string>
<string name="profile_inspector_provider">Anbieter</string>
<string name="profile_inspector_model">Modell</string>
<string name="profile_inspector_save_changes">Änderungen speichern</string>
<string name="profile_inspector_toolsets">Toolsets</string>
<string name="profile_inspector_toolsets_hint">Wähle aus, welche Hermes-Werkzeuggruppen dieses Profil verwenden darf.</string>
<string name="profile_inspector_tool_count">%1$d Werkzeuge</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · Experimentell</string>
<string name="hermes_reach_summary">Experimentelle Broker-Route für Netzwerke, in denen direkter Zugriff und Tailscale nicht verfügbar sind. Für die normale Einrichtung wird sie noch nicht empfohlen; Secure-Link-TLS bleibt Ende-zu-Ende geschützt.</string>
<string name="secure_link_pinned_tls">Angeheftetes TLS · Identität aus dieser Kopplung bestätigt</string>
<string name="secure_link_pinned_tls_short">Secure Link · angeheftetes TLS</string>
<string name="secure_link_protects">Geschützte Dienste: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">Dashboard</string>
<string name="secure_link_no_services">Es wurden keine geschützten Dienste angekündigt. Secure Link wird nicht verwendet.</string>
<string name="secure_link_partial_warning">Teilweiser Schutz: Nicht aufgeführte Dienste verwenden ihre eigene konfigurierte Route und Sicherheit.</string>
<string name="secure_link_partial_short">Secure Link · teilweise</string>
<string name="secure_link_fallback_ready">Wenn Secure Link nicht verfügbar ist, kann Hermes die genehmigten Ausweichrouten unten versuchen.</string>
<string name="secure_link_no_fallback">Keine Ausweichroute enthalten. Geschützte Dienste bleiben offline, wenn Secure Link nicht verfügbar ist.</string>
<string name="secure_link_auth_note">Transportschutz umgeht keine Authentifizierung. Relay-Kopplung, API-Zugangsdaten und Dashboard-Anmeldung werden weiterhin pro Dienst erzwungen.</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="one">%1$d Nachricht ist eingegangen, während du weg warst</item>
<item quantity="other">%1$d Nachrichten sind eingegangen, während du weg warst</item>
</plurals>
<string name="chat_model_confirmation_title">Modellauswahl bestätigen</string>
<string name="host_resource_recent_oom">Hermes wurde kürzlich wahrscheinlich wegen Speichermangels neu gestartet.</string>
<string name="host_resource_memory_critical">Der Arbeitsspeicher des Hosts ist äußerst knapp; aktive Chats können beendet werden.</string>
<string name="host_resource_memory_elevated">Der Arbeitsspeicher des Hosts wird knapp.</string>
<string name="host_resource_disk_critical">Der Speicherplatz des Hosts ist äußerst knapp; Nachrichten und Einstellungen können möglicherweise nicht gespeichert werden.</string>
<string name="host_resource_disk_elevated">Der Speicherplatz des Hosts wird knapp.</string>
</resources>
+182 -1
View File
@@ -1646,6 +1646,17 @@
<string name="dashboard_empty_section">No se devolvió ningún %1$s</string>
<string name="dashboard_section_action_change_main_model">Cambiar modelo principal</string>
<string name="dashboard_section_action_new_profile">Nuevo perfil</string>
<string name="dashboard_section_action_new_schedule">Nueva programación</string>
<string name="dashboard_cron_create_title">Crear programación</string>
<string name="dashboard_cron_name">Nombre</string>
<string name="dashboard_cron_schedule">Programación</string>
<string name="dashboard_cron_schedule_hint">Ejemplos: every 2h, 0 9 * * 1-5 o 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">Instrucciones de la tarea</string>
<string name="dashboard_cron_repeat">Detener después de esta cantidad de ejecuciones (opcional)</string>
<string name="dashboard_cron_repeat_help">Déjalo en blanco para conservar el comportamiento normal. Las programaciones finitas aceptan entre 1 y 999 ejecuciones.</string>
<string name="dashboard_cron_gateway_required">La creación de programaciones requiere una conexión actual con Hermes Gateway.</string>
<string name="dashboard_cron_created">Programación «%1$s» creada</string>
<string name="dashboard_cron_create_failed">No se pudo crear la programación</string>
<string name="dashboard_section_action_browse_hub">Centro de exploración</string>
<string name="dashboard_section_action_update_installed">Actualización instalada</string>
<string name="dashboard_action_set">Colocar</string>
@@ -1774,6 +1785,16 @@
<string name="dashboard_skills_update_started">La actualización de habilidades comenzó en el servidor: actualice las habilidades en un minuto</string>
<string name="dashboard_skills_update_failed">La actualización de habilidades no pudo iniciarse</string>
<string name="dashboard_profile_created">Perfil %1$s creado</string>
<string name="dashboard_profile_created_partial">Se creó el perfil %1$s, pero %2$s. Revísalo antes de usarlo.</string>
<string name="dashboard_profile_created_legacy">El perfil %1$s se creó mediante la ruta antigua del panel. Revisa sus credenciales antes de usarlo.</string>
<string name="dashboard_profile_no_skills">No añadir las habilidades incluidas</string>
<string name="dashboard_profile_auth_title">Autenticación</string>
<string name="dashboard_profile_auth_shared">Compartir inicio de sesión (recomendado) — un grupo de tokens renovables</string>
<string name="dashboard_profile_auth_copied">Copiar credenciales actuales — instantánea separada que puede quedar desactualizada</string>
<string name="dashboard_profile_auth_isolated">Aislado — no copiar credenciales ni valores predeterminados del proveedor</string>
<string name="dashboard_profile_auth_help">Hermes aplica esta opción en el servidor. Las contraseñas y los tokens nunca se devuelven a Android.</string>
<string name="dashboard_profile_allow_legacy">Si la creación mediante Gateway no está disponible, permitir la ruta antigua del panel. El comportamiento de las credenciales depende del host y debe revisarse.</string>
<string name="dashboard_profile_mcp_partial">No se aplicó la selección de servidores MCP</string>
<string name="dashboard_profile_create_failed">Error al crear el perfil</string>
<string name="stats_overview">Descripción general</string>
<string name="stats_reset">Reiniciar</string>
@@ -2350,7 +2371,35 @@
<plurals name="tool_run_used_device"><item quantity="one">Se ejecutó %d acción del dispositivo</item><item quantity="other">Se ejecutaron %d acciones del dispositivo</item></plurals>
<plurals name="tool_run_using_tools"><item quantity="one">Usando %d herramienta</item><item quantity="other">Usando %d herramientas</item></plurals>
<plurals name="tool_run_used_tools"><item quantity="one">Se usó %d herramienta</item><item quantity="other">Se usaron %d herramientas</item></plurals>
<string name="agent_icon_title">Icono de agente</string>
<string name="agent_icon_title">Aspecto del agente</string>
<string name="agent_icon_hermes_pet_title">Mascota animada de Hermes</string>
<string name="agent_icon_hermes_pet_description">Se guarda por perfil y se comparte con las superficies upstream de Hermes. Reacciona a la actividad del agente y aparece como acompañante en el teléfono.</string>
<string name="agent_icon_hermes_pet_active">Activa: %1$s</string>
<string name="agent_icon_hermes_pet_empty">No hay mascota upstream seleccionada</string>
<string name="agent_icon_hermes_pet_unsupported">Actualiza Hermes para gestionar aquí mascotas animadas</string>
<string name="agent_icon_hermes_pet_browse">Explorar mascotas de Hermes</string>
<string name="agent_icon_hermes_pet_picker_title">Elige una mascota de Hermes</string>
<string name="agent_icon_hermes_pet_selected">Seleccionada</string>
<string name="agent_icon_hermes_pet_installed">Instalada</string>
<string name="agent_icon_hermes_pet_adopt">Adoptar desde Petdex</string>
<string name="agent_icon_shared_title">Compartido en Hermes</string>
<string name="agent_icon_shared_active">Avatar compartido</string>
<string name="agent_icon_shared_empty">Sin avatar compartido</string>
<string name="agent_icon_change_shared">Cambiar avatar compartido</string>
<string name="agent_icon_remove_shared">Quitar</string>
<string name="agent_icon_remove_shared_title">¿Quitar el avatar compartido?</string>
<string name="agent_icon_remove_shared_message">Esto quita el avatar de Hermes y de otros clientes. La imagen del teléfono no se modifica.</string>
<string name="agent_icon_phone_title">Solo este teléfono</string>
<string name="agent_icon_phone_description">Reemplaza el avatar compartido solo en este teléfono sin cambiar Hermes.</string>
<string name="agent_icon_choose_phone">Elegir imagen del teléfono</string>
<string name="agent_icon_change_phone">Cambiar imagen del teléfono</string>
<string name="agent_icon_remove_phone">Quitar imagen del teléfono</string>
<string name="agent_icon_animation_note">Las sustituciones GIF y WebP animadas se reproducen solo en este teléfono. Usa arriba una mascota animada de Hermes para una animación upstream por perfil.</string>
<string name="agent_icon_set_local">Elegir imagen alternativa del dispositivo</string>
<string name="agent_icon_change_local">Cambiar imagen alternativa del dispositivo</string>
<string name="agent_icon_clear_local">Borrar imagen alternativa del dispositivo</string>
<string name="agent_icon_upload_shared">Subir icono del dispositivo a Hermes</string>
<string name="agent_icon_clear_shared">Borrar avatar compartido de Hermes</string>
<string name="agent_icon_set">Elegir archivo</string>
<string name="agent_icon_change">Elegir archivo</string>
<string name="agent_icon_clear">Claro</string>
@@ -3149,6 +3198,14 @@
<string name="dashboard_native_signin_requires_https">El inicio de sesión seguro en el navegador requiere una dirección HTTPS del panel.</string>
<string name="dashboard_native_signin_unavailable">El inicio de sesión seguro en el navegador no está disponible para esta conexión. Actualiza la conexión e inténtalo de nuevo.</string>
<string name="dashboard_native_signin_transport_retry">Se interrumpió la conexión segura. Toca el botón de inicio de sesión para volver a intentarlo.</string>
<string name="dashboard_native_signin_callback_rejected">El proveedor no aprobó este inicio de sesión. Si lo cancelaste, no tienes que hacer nada; de lo contrario, inicia un intento nuevo.</string>
<string name="dashboard_native_signin_code_rejected">El inicio de sesión con Google terminó, pero Hermes alojado rechazó el código de devolución de un solo uso antes de crear una sesión. Inicia un intento nuevo.</string>
<string name="dashboard_native_signin_gateway_rejected">Hermes alojado rechazó el intercambio de sesión. Comprueba que el agente alojado esté actualizado y vuelve a iniciar sesión.</string>
<string name="dashboard_native_signin_rate_limited">Hermes alojado recibió demasiados intentos de inicio de sesión. Espera un momento y vuelve a intentarlo.</string>
<string name="dashboard_native_signin_gateway_unavailable">El inicio de sesión con Google terminó, pero el servicio de acceso de Hermes alojado no está disponible. Espera un momento y vuelve a intentarlo.</string>
<string name="dashboard_native_signin_response_unsupported">Hermes alojado devolvió una respuesta de inicio de sesión que esta aplicación no puede usar. Busca actualizaciones de Hermes Relay y del agente alojado.</string>
<string name="dashboard_native_signin_attempt_inactive">Este intento de inicio de sesión se canceló o fue reemplazado. Cierra la pestaña anterior y empieza de nuevo.</string>
<string name="dashboard_native_signin_storage_failed">El inicio de sesión con Google terminó, pero Android no pudo guardar de forma segura la sesión de Hermes. Vuelve a intentarlo; si se repite, abre Diagnósticos para ver la fase del error.</string>
<string name="conn_info_yolo_mode_desc_ephemeral">Omite las solicitudes de aprobación solo para este chat. Se restablece al cambiar de sesión.</string>
<string name="conn_info_yolo_mode_profile_off">Las aprobaciones del perfil están desactivadas, por lo que este chat ya omite las solicitudes. Elige Manual o Inteligente antes de usar la excepción por chat.</string>
<string name="conn_info_approval_mode_title">Modo de aprobación del perfil</string>
@@ -3670,4 +3727,128 @@
<string name="pet_creator_step_review">Revisar e importar</string>
<string name="pet_creator_review_desc">Inspecciona primero la imagen o el ZIP recibido. Al importar se copian los archivos validados al almacenamiento de la aplicación; no se publican.</string>
<string name="pet_creator_import">Importar mascota terminada</string>
<string name="dashboard_tab_memory">Memoria</string>
<string name="dashboard_tab_learning">Aprendizaje</string>
<string name="dashboard_tab_channels">Canales</string>
<string name="dashboard_tab_operations">Operaciones</string>
<string name="dashboard_tab_memory_lower">memoria</string>
<string name="dashboard_tab_learning_lower">aprendizaje</string>
<string name="dashboard_tab_channels_lower">canales</string>
<string name="dashboard_tab_operations_lower">operaciones</string>
<string name="dashboard_section_action_server_backup">Crear copia del servidor</string>
<string name="dashboard_profile_mcp_servers_optional">Servidores MCP (opcional)</string>
<string name="dashboard_profile_mcp_servers_help">Nombres de servidor separados por comas o líneas. Las credenciales permanecen en el servidor.</string>
<string name="dashboard_tile_memory_title">Memoria</string>
<string name="dashboard_tile_memory_sub">Estado del proveedor y configuración de memoria del servidor</string>
<string name="dashboard_tile_learning_title">Grafo de aprendizaje</string>
<string name="dashboard_tile_learning_sub">Inspecciona los nodos aprendidos del perfil activo</string>
<string name="dashboard_tile_channels_title">Canales</string>
<string name="dashboard_tile_channels_sub">Estado de plataformas de mensajería, incluido WhatsApp</string>
<string name="dashboard_tile_operations_title">Operaciones del servidor</string>
<string name="dashboard_tile_operations_sub">Estado del host y copia de seguridad del servidor</string>
<string name="dashboard_section_action_download_backup">Guardar la copia más reciente</string>
<string name="dashboard_section_action_import_backup">Importar copia de seguridad</string>
<string name="dashboard_backup_create_first">Crea una copia de seguridad en esta sesión antes de descargarla.</string>
<string name="dashboard_backup_download_failed">No se pudo descargar la copia de seguridad.</string>
<string name="dashboard_backup_saved">Copia de seguridad guardada como %1$s.</string>
<string name="dashboard_import_title">¿Importar copia de seguridad del servidor?</string>
<string name="dashboard_import_warning">Esto sube el ZIP seleccionado a Hermes e inicia la importación autenticada del servidor. Puede reemplazar la configuración y los datos. Crea y guarda primero una copia de seguridad actual.</string>
<string name="dashboard_import_confirm">Importar</string>
<string name="dashboard_import_started">Se inició la importación del servidor. Espera a que termine en Operaciones antes de reiniciar Hermes.</string>
<string name="dashboard_import_failed">No se pudo iniciar la importación del servidor.</string>
<string name="dashboard_action_configure">Configurar</string>
<string name="dashboard_action_setup">Configurar</string>
<string name="dashboard_action_setup_whatsapp">Configurar WhatsApp</string>
<string name="dashboard_learning_edit_title">Editar %1$s</string>
<string name="dashboard_learning_edit_warning">Al editar se reemplaza todo el contenido del nodo. Hermes archiva las habilidades eliminadas del grafo y se pueden restaurar desde el archivo; eliminar un nodo de memoria es permanente, así que exporta primero una copia de seguridad.</string>
<string name="dashboard_learning_saved">Nodo de aprendizaje guardado.</string>
<string name="dashboard_learning_save_failed">No se pudo guardar el nodo de aprendizaje.</string>
<string name="dashboard_learning_delete_warning">Hermes archiva las habilidades aprendidas para poder restaurarlas desde el archivo del servidor. Eliminar un nodo de memoria es permanente. Guarda primero una copia de seguridad del servidor si podrías necesitar este contenido más adelante.</string>
<string name="dashboard_memory_config_title">Configurar %1$s</string>
<string name="dashboard_memory_config_help">Los valores permanecen en el perfil de Hermes seleccionado. El servidor acepta los campos secretos y nunca los devuelve después de guardarlos. Los campos obligatorios están marcados con *.</string>
<string name="dashboard_memory_values_json">Valores del proveedor (JSON)</string>
<string name="dashboard_memory_run_setup">Ejecutar configuración</string>
<string name="dashboard_memory_invalid_json">Los valores del proveedor deben ser un objeto JSON.</string>
<string name="dashboard_memory_setup_started">Se inició la instalación del proveedor en todo el host. Actualiza la vista cuando termine y guarda los valores de este perfil.</string>
<string name="dashboard_memory_saved">Proveedor de memoria configurado y activado.</string>
<string name="dashboard_memory_save_failed">No se pudo guardar la configuración del proveedor de memoria.</string>
<string name="dashboard_whatsapp_title">Configurar WhatsApp</string>
<string name="dashboard_whatsapp_help">Hermes inicia una sesión de vinculación de diez minutos para este perfil. Elige el modo bot para una cuenta exclusiva o el chat contigo mismo para enviar mensajes a tu propia cuenta vinculada.</string>
<string name="dashboard_whatsapp_bot">Cuenta de bot</string>
<string name="dashboard_whatsapp_self_chat">Chat contigo mismo</string>
<string name="dashboard_whatsapp_allowed_users">Números de teléfono permitidos (opcional)</string>
<string name="dashboard_whatsapp_start">Iniciar vinculación</string>
<string name="dashboard_whatsapp_scan">Escanea este código desde la pantalla Dispositivos vinculados de WhatsApp. Mantén abierto este cuadro mientras Hermes confirma la cuenta.</string>
<string name="dashboard_whatsapp_qr">Código QR de dispositivo vinculado de WhatsApp</string>
<string name="dashboard_whatsapp_apply">Activar WhatsApp</string>
<string name="dashboard_whatsapp_start_failed">No se pudo iniciar la vinculación de WhatsApp.</string>
<string name="dashboard_whatsapp_apply_failed">No se pudo guardar la configuración de WhatsApp.</string>
<string name="dashboard_whatsapp_saved">WhatsApp activado; Hermes inició un reinicio del gateway.</string>
<string name="drawer_all_profiles">Todos los perfiles</string>
<string name="drawer_no_profile_sessions">No hay sesiones de perfil coincidentes.</string>
<string name="drawer_customize_sessions">Personalizar sesiones</string>
<string name="drawer_group_by">Agrupar por</string>
<string name="drawer_order_by">Ordenar por</string>
<string name="drawer_show_metadata">Mostrar en las filas</string>
<string name="drawer_show_details">Mostrar detalles</string>
<string name="drawer_filters">Filtros</string>
<string name="drawer_project_home">Inicio</string>
<string name="drawer_expand_project">Expandir %1$s</string>
<string name="drawer_collapse_project">Contraer %1$s</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d sesión</item>
<item quantity="other">%1$d sesiones</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d perfil</item>
<item quantity="other">%1$d perfiles</item>
</plurals>
<string name="drawer_filter_status">Estado</string>
<string name="drawer_filter_profile">Perfil</string>
<string name="drawer_filter_project">Proyecto</string>
<string name="drawer_filter_pull_request">Solicitud de incorporación</string>
<string name="drawer_option_updated">Actualizado</string>
<string name="drawer_option_profile">Perfil</string>
<string name="drawer_option_tokens">Tokens</string>
<string name="drawer_option_cost">Coste</string>
<string name="drawer_reset_filters">Restablecer</string>
<string name="drawer_profile_colors">Colores de perfil</string>
<string name="drawer_profile_color_auto">Automático</string>
<string name="drawer_profile_color_set">Establecer el color del perfil %1$s en %2$s</string>
<string name="drawer_close">Cerrar</string>
<string name="profile_inspector_gateway_settings">Ajustes del perfil de Gateway</string>
<string name="profile_inspector_gateway_settings_hint">Se guarda directamente mediante Hermes para este perfil seleccionado.</string>
<string name="profile_inspector_edit_config">Editar ajustes del perfil</string>
<string name="profile_inspector_description">Descripción</string>
<string name="profile_inspector_provider">Proveedor</string>
<string name="profile_inspector_model">Modelo</string>
<string name="profile_inspector_save_changes">Guardar cambios</string>
<string name="profile_inspector_toolsets">Conjuntos de herramientas</string>
<string name="profile_inspector_toolsets_hint">Elige qué grupos de herramientas de Hermes puede usar este perfil.</string>
<string name="profile_inspector_tool_count">%1$d herramientas</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · Experimental</string>
<string name="hermes_reach_summary">Ruta de intermediario experimental para redes donde no están disponibles el acceso directo ni Tailscale. Aún no se recomienda para la configuración normal; el TLS de Secure Link sigue protegido de extremo a extremo.</string>
<string name="secure_link_pinned_tls">TLS fijado · identidad verificada desde este emparejamiento</string>
<string name="secure_link_pinned_tls_short">Secure Link · TLS fijado</string>
<string name="secure_link_protects">Servicios protegidos: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">Panel</string>
<string name="secure_link_no_services">No se anunciaron servicios protegidos. Secure Link no se utilizará.</string>
<string name="secure_link_partial_warning">Protección parcial: los servicios no incluidos aquí usan su propia ruta y seguridad configuradas.</string>
<string name="secure_link_partial_short">Secure Link · parcial</string>
<string name="secure_link_fallback_ready">Si Secure Link no está disponible, Hermes puede probar las rutas alternativas aprobadas que aparecen abajo.</string>
<string name="secure_link_no_fallback">No se incluye ninguna ruta alternativa. Los servicios protegidos permanecerán sin conexión si Secure Link no está disponible.</string>
<string name="secure_link_auth_note">La protección del transporte no omite la autenticación. El emparejamiento de Relay, las credenciales de API y el inicio de sesión del Panel se siguen aplicando por servicio.</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="one">Ha llegado %1$d mensaje mientras no estabas</item>
<item quantity="other">Han llegado %1$d mensajes mientras no estabas</item>
</plurals>
<string name="chat_model_confirmation_title">Confirmar selección de modelo</string>
<string name="host_resource_recent_oom">Hermes se reinició recientemente, probablemente por falta de memoria.</string>
<string name="host_resource_memory_critical">La memoria del servidor está casi agotada; los chats activos podrían detenerse.</string>
<string name="host_resource_memory_elevated">La memoria del servidor se está agotando.</string>
<string name="host_resource_disk_critical">El almacenamiento del servidor está casi agotado; puede que los mensajes y ajustes no se guarden.</string>
<string name="host_resource_disk_elevated">El almacenamiento del servidor se está agotando.</string>
</resources>
+181 -1
View File
@@ -1812,6 +1812,17 @@
<!-- Section action buttons -->
<string name="dashboard_section_action_change_main_model">メイン機種変更</string>
<string name="dashboard_section_action_new_profile">新しいプロフィール</string>
<string name="dashboard_section_action_new_schedule">新しいスケジュール</string>
<string name="dashboard_cron_create_title">スケジュールを作成</string>
<string name="dashboard_cron_name">名前</string>
<string name="dashboard_cron_schedule">スケジュール</string>
<string name="dashboard_cron_schedule_hint">例: every 2h、0 9 * * 1-5、2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">タスクの指示</string>
<string name="dashboard_cron_repeat">この実行回数の後に停止(任意)</string>
<string name="dashboard_cron_repeat_help">通常の動作を維持する場合は空欄にします。有限スケジュールには1~999回を指定できます。</string>
<string name="dashboard_cron_gateway_required">スケジュールの作成には、現在のHermes Gateway接続が必要です。</string>
<string name="dashboard_cron_created">スケジュール「%1$s」を作成しました</string>
<string name="dashboard_cron_create_failed">スケジュールを作成できませんでした</string>
<string name="dashboard_section_action_browse_hub">ハブを参照する</string>
<string name="dashboard_section_action_update_installed">アップデートがインストールされました</string>
@@ -1966,6 +1977,16 @@
<!-- Profile create -->
<string name="dashboard_profile_created">プロファイル %1$s が作成されました</string>
<string name="dashboard_profile_created_partial">プロファイル %1$s は作成されましたが、%2$s。使用前に確認してください。</string>
<string name="dashboard_profile_created_legacy">プロファイル %1$s は旧 Dashboard ルートで作成されました。使用前に認証情報を確認してください。</string>
<string name="dashboard_profile_no_skills">同梱スキルを追加しない</string>
<string name="dashboard_profile_auth_title">認証</string>
<string name="dashboard_profile_auth_shared">サインインを共有(推奨)— 更新可能なトークンプールを共有</string>
<string name="dashboard_profile_auth_copied">現在の認証情報をコピー — 別スナップショットのため古くなる場合があります</string>
<string name="dashboard_profile_auth_isolated">分離 — 認証情報やプロバイダー既定値をコピーしない</string>
<string name="dashboard_profile_auth_help">Hermes がサーバー上でこの選択を適用します。パスワードやトークンが Android に返されることはありません。</string>
<string name="dashboard_profile_allow_legacy">Gateway で作成できない場合、旧 Dashboard ルートを許可します。認証情報の動作はホストによって異なるため確認が必要です。</string>
<string name="dashboard_profile_mcp_partial">MCP サーバーの選択は適用されませんでした</string>
<string name="dashboard_profile_create_failed">プロファイルの作成に失敗しました</string>
<!-- Stats for nerds -->
@@ -2590,7 +2611,35 @@
<plurals name="tool_run_used_tools"><item quantity="other">%d 個のツールを使用</item></plurals>
<!-- AgentIconRow -->
<string name="agent_icon_title">エージェントアイコン</string>
<string name="agent_icon_title">エージェントの外観</string>
<string name="agent_icon_hermes_pet_title">Hermes アニメーションペット</string>
<string name="agent_icon_hermes_pet_description">プロファイル単位で upstream Hermes の各画面と共有されます。エージェントの活動に反応し、スマートフォンのコンパニオンとして表示されます。</string>
<string name="agent_icon_hermes_pet_active">有効: %1$s</string>
<string name="agent_icon_hermes_pet_empty">upstream ペットが選択されていません</string>
<string name="agent_icon_hermes_pet_unsupported">ここでアニメーションペットを管理するには Hermes を更新してください</string>
<string name="agent_icon_hermes_pet_browse">Hermes ペットを探す</string>
<string name="agent_icon_hermes_pet_picker_title">Hermes ペットを選択</string>
<string name="agent_icon_hermes_pet_selected">選択中</string>
<string name="agent_icon_hermes_pet_installed">インストール済み</string>
<string name="agent_icon_hermes_pet_adopt">Petdex から迎える</string>
<string name="agent_icon_shared_title">Hermes 全体で共有</string>
<string name="agent_icon_shared_active">共有アバター</string>
<string name="agent_icon_shared_empty">共有アバターなし</string>
<string name="agent_icon_change_shared">共有アバターを変更</string>
<string name="agent_icon_remove_shared">削除</string>
<string name="agent_icon_remove_shared_title">共有アバターを削除しますか?</string>
<string name="agent_icon_remove_shared_message">Hermes と他のクライアントからアバターを削除します。この端末の画像には影響しません。</string>
<string name="agent_icon_phone_title">この端末のみ</string>
<string name="agent_icon_phone_description">Hermes を変更せず、この端末だけ共有アバターを上書きします。</string>
<string name="agent_icon_choose_phone">端末の画像を選択</string>
<string name="agent_icon_change_phone">端末の画像を変更</string>
<string name="agent_icon_remove_phone">端末の画像を削除</string>
<string name="agent_icon_animation_note">アニメーション GIF と WebP の上書きはこの端末でのみ再生されます。プロファイル単位の upstream アニメーションには、上の Hermes アニメーションペットを使用してください。</string>
<string name="agent_icon_set_local">端末の予備画像を選択</string>
<string name="agent_icon_change_local">端末の予備画像を変更</string>
<string name="agent_icon_clear_local">端末の予備画像を消去</string>
<string name="agent_icon_upload_shared">端末アイコンを Hermes にアップロード</string>
<string name="agent_icon_clear_shared">共有 Hermes アバターを消去</string>
<string name="agent_icon_set">ファイルを選択</string>
<string name="agent_icon_change">ファイルを選択</string>
<string name="agent_icon_clear">クリア</string>
@@ -3463,6 +3512,14 @@
<string name="dashboard_native_signin_requires_https">安全なブラウザサインインには、HTTPSのダッシュボードアドレスが必要です。</string>
<string name="dashboard_native_signin_unavailable">この接続では安全なブラウザサインインを利用できません。接続を更新して、もう一度お試しください。</string>
<string name="dashboard_native_signin_transport_retry">安全な接続が中断されました。サインインボタンをタップして、もう一度お試しください。</string>
<string name="dashboard_native_signin_callback_rejected">プロバイダーがこのサインインを承認しませんでした。キャンセルした場合は操作不要です。それ以外の場合は、新しいサインインを開始してください。</string>
<string name="dashboard_native_signin_code_rejected">Google サインインは完了しましたが、ホストされた Hermes がセッション作成前に一回限りのコールバックコードを拒否しました。新しいサインインを開始してください。</string>
<string name="dashboard_native_signin_gateway_rejected">ホストされた Hermes がセッション交換を拒否しました。ホスト側エージェントが最新であることを確認し、サインインをやり直してください。</string>
<string name="dashboard_native_signin_rate_limited">ホストされた Hermes が短時間に多すぎるサインイン試行を受け取りました。しばらく待ってから再試行してください。</string>
<string name="dashboard_native_signin_gateway_unavailable">Google サインインは完了しましたが、ホストされた Hermes のサインインサービスを利用できません。しばらく待ってから再試行してください。</string>
<string name="dashboard_native_signin_response_unsupported">ホストされた Hermes から、このアプリでは使用できないサインイン応答が返されました。Hermes Relay とホスト側エージェントの更新を確認してください。</string>
<string name="dashboard_native_signin_attempt_inactive">このサインイン試行はキャンセルされたか置き換えられました。古いブラウザタブを閉じて、やり直してください。</string>
<string name="dashboard_native_signin_storage_failed">Google サインインは完了しましたが、Android が Hermes セッションを安全に保存できませんでした。再試行し、繰り返す場合は診断で失敗段階を確認してください。</string>
<string name="conn_info_yolo_mode_desc_ephemeral">このチャットでのみ承認確認を省略します。セッションが変わるとリセットされます。</string>
<string name="conn_info_yolo_mode_profile_off">プロフィールの承認がオフのため、このチャットではすでに確認を省略しています。チャット単位の例外を使う前に、手動またはスマートを選択してください。</string>
<string name="conn_info_approval_mode_title">プロフィール承認モード</string>
@@ -3984,4 +4041,127 @@
<string name="pet_creator_step_review">確認してインポート</string>
<string name="pet_creator_review_desc">返された画像またはZIPを最初に確認してください。インポートすると検証済みファイルがアプリ専用ストレージにコピーされますが、公開はされません。</string>
<string name="pet_creator_import">完成したペットをインポート</string>
<string name="dashboard_tab_memory">メモリ</string>
<string name="dashboard_tab_learning">学習</string>
<string name="dashboard_tab_channels">チャンネル</string>
<string name="dashboard_tab_operations">運用</string>
<string name="dashboard_tab_memory_lower">メモリ</string>
<string name="dashboard_tab_learning_lower">学習</string>
<string name="dashboard_tab_channels_lower">チャンネル</string>
<string name="dashboard_tab_operations_lower">運用</string>
<string name="dashboard_section_action_server_backup">サーバーバックアップを作成</string>
<string name="dashboard_section_action_download_backup">最新のバックアップを保存</string>
<string name="dashboard_section_action_import_backup">バックアップをインポート</string>
<string name="dashboard_backup_create_first">ダウンロードする前に、このセッションでバックアップを作成してください。</string>
<string name="dashboard_backup_download_failed">バックアップをダウンロードできませんでした。</string>
<string name="dashboard_backup_saved">バックアップを %1$s として保存しました。</string>
<string name="dashboard_import_title">サーバーバックアップをインポートしますか?</string>
<string name="dashboard_import_warning">選択した ZIP を Hermes にアップロードし、認証済みのサーバーインポートを開始します。設定やデータが置き換わる可能性があります。先に現在のバックアップを作成して保存してください。</string>
<string name="dashboard_import_confirm">インポート</string>
<string name="dashboard_import_started">サーバーのインポートを開始しました。Hermes を再起動する前に、運用画面で完了を確認してください。</string>
<string name="dashboard_import_failed">サーバーのインポートを開始できませんでした。</string>
<string name="dashboard_profile_mcp_servers_optional">MCP サーバー(任意)</string>
<string name="dashboard_profile_mcp_servers_help">サーバー名をカンマまたは改行で区切ります。認証情報はサーバー側に保持されます。</string>
<string name="dashboard_tile_memory_title">メモリ</string>
<string name="dashboard_tile_memory_sub">プロバイダーの状態とサーバー側のメモリ設定</string>
<string name="dashboard_tile_learning_title">学習グラフ</string>
<string name="dashboard_tile_learning_sub">アクティブなプロファイルの学習済みノードを確認</string>
<string name="dashboard_tile_channels_title">チャンネル</string>
<string name="dashboard_tile_channels_sub">WhatsApp を含むメッセージプラットフォームの状態</string>
<string name="dashboard_tile_operations_title">サーバー運用</string>
<string name="dashboard_tile_operations_sub">ホストの状態とサーバー全体のバックアップ</string>
<string name="dashboard_action_configure">設定</string>
<string name="dashboard_action_setup">セットアップ</string>
<string name="dashboard_action_setup_whatsapp">WhatsApp を設定</string>
<string name="dashboard_learning_edit_title">%1$sを編集</string>
<string name="dashboard_learning_edit_warning">編集するとノードの内容全体が置き換わります。グラフから削除したスキルは Hermes によってアーカイブされ、復元できます。メモリノードの削除は元に戻せないため、先にバックアップをエクスポートしてください。</string>
<string name="dashboard_learning_saved">学習ノードを保存しました。</string>
<string name="dashboard_learning_save_failed">学習ノードを保存できませんでした。</string>
<string name="dashboard_learning_delete_warning">Hermes は学習済みスキルをアーカイブするため、サーバーのアーカイブから復元できます。メモリノードの削除は元に戻せません。この内容が後で必要になる可能性がある場合は、先にサーバーバックアップを保存してください。</string>
<string name="dashboard_memory_config_title">%1$sを設定</string>
<string name="dashboard_memory_config_help">値は選択した Hermes プロファイルに保持されます。シークレット項目はサーバーに保存されますが、保存後に返されることはありません。必須項目には * が付いています。</string>
<string name="dashboard_memory_values_json">プロバイダーの値(JSON)</string>
<string name="dashboard_memory_run_setup">セットアップを実行</string>
<string name="dashboard_memory_invalid_json">プロバイダーの値は JSON オブジェクトである必要があります。</string>
<string name="dashboard_memory_setup_started">ホスト全体へのプロバイダーのインストールを開始しました。完了後に更新し、このプロファイルの値を保存してください。</string>
<string name="dashboard_memory_saved">メモリプロバイダーを設定して有効にしました。</string>
<string name="dashboard_memory_save_failed">メモリプロバイダーの設定を保存できませんでした。</string>
<string name="dashboard_whatsapp_title">WhatsApp を設定</string>
<string name="dashboard_whatsapp_help">Hermes はプロファイル単位のペアリングセッションを10分間開始します。専用アカウントにはボットモード、自分のリンク済みアカウントへのメッセージにはセルフチャットを選択してください。</string>
<string name="dashboard_whatsapp_bot">ボットアカウント</string>
<string name="dashboard_whatsapp_self_chat">セルフチャット</string>
<string name="dashboard_whatsapp_allowed_users">許可する電話番号(任意)</string>
<string name="dashboard_whatsapp_start">ペアリングを開始</string>
<string name="dashboard_whatsapp_scan">WhatsApp の「リンク済みデバイス」画面でこのコードをスキャンしてください。Hermes がアカウントを確認するまで、このダイアログを開いたままにしてください。</string>
<string name="dashboard_whatsapp_qr">WhatsApp リンク済みデバイスの QR コード</string>
<string name="dashboard_whatsapp_apply">WhatsApp を有効化</string>
<string name="dashboard_whatsapp_start_failed">WhatsApp のペアリングを開始できませんでした。</string>
<string name="dashboard_whatsapp_apply_failed">WhatsApp の設定を保存できませんでした。</string>
<string name="dashboard_whatsapp_saved">WhatsApp を有効にしました。Hermes がゲートウェイの再起動を開始しました。</string>
<string name="drawer_all_profiles">すべてのプロファイル</string>
<string name="drawer_no_profile_sessions">一致するプロファイルセッションはありません。</string>
<string name="drawer_customize_sessions">セッションをカスタマイズ</string>
<string name="drawer_group_by">グループ化</string>
<string name="drawer_order_by">並び順</string>
<string name="drawer_show_metadata">行に表示</string>
<string name="drawer_show_details">詳細を表示</string>
<string name="drawer_filters">フィルター</string>
<string name="drawer_project_home">ホーム</string>
<string name="drawer_expand_project">%1$sを展開</string>
<string name="drawer_collapse_project">%1$sを折りたたむ</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d件のセッション</item>
<item quantity="other">%1$d件のセッション</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d件のプロファイル</item>
<item quantity="other">%1$d件のプロファイル</item>
</plurals>
<string name="drawer_filter_status">ステータス</string>
<string name="drawer_filter_profile">プロフィール</string>
<string name="drawer_filter_project">プロジェクト</string>
<string name="drawer_filter_pull_request">プルリクエスト</string>
<string name="drawer_option_updated">更新日時</string>
<string name="drawer_option_profile">プロフィール</string>
<string name="drawer_option_tokens">トークン</string>
<string name="drawer_option_cost">コスト</string>
<string name="drawer_reset_filters">リセット</string>
<string name="drawer_profile_colors">プロフィールの色</string>
<string name="drawer_profile_color_auto">自動</string>
<string name="drawer_profile_color_set">%1$s のプロフィール色を %2$s に設定</string>
<string name="drawer_close">閉じる</string>
<string name="profile_inspector_gateway_settings">Gateway プロファイル設定</string>
<string name="profile_inspector_gateway_settings_hint">選択中のプロファイルに Hermes 経由で直接保存します。</string>
<string name="profile_inspector_edit_config">プロファイル設定を編集</string>
<string name="profile_inspector_description">説明</string>
<string name="profile_inspector_provider">プロバイダー</string>
<string name="profile_inspector_model">モデル</string>
<string name="profile_inspector_save_changes">変更を保存</string>
<string name="profile_inspector_toolsets">ツールセット</string>
<string name="profile_inspector_toolsets_hint">このプロファイルで使用できる Hermes のツールグループを選択します。</string>
<string name="profile_inspector_tool_count">%1$d 個のツール</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · 試験機能</string>
<string name="hermes_reach_summary">直接アクセスと Tailscale を利用できないネットワーク向けの試験的なブローカールートです。通常の設定にはまだ推奨されません。Secure Link TLS は引き続きエンドツーエンドで保護されます。</string>
<string name="secure_link_pinned_tls">ピン留め TLS · このペアリングから ID を確認済み</string>
<string name="secure_link_pinned_tls_short">Secure Link · ピン留め TLS</string>
<string name="secure_link_protects">保護されるサービス: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">ダッシュボード</string>
<string name="secure_link_no_services">保護対象のサービスが通知されていません。Secure Link は使用されません。</string>
<string name="secure_link_partial_warning">一部のみ保護: ここにないサービスは、それぞれ設定されたルートとセキュリティを使用します。</string>
<string name="secure_link_partial_short">Secure Link · 一部</string>
<string name="secure_link_fallback_ready">Secure Link を利用できない場合、Hermes は以下の承認済み代替ルートを試行できます。</string>
<string name="secure_link_no_fallback">代替ルートは含まれていません。Secure Link を利用できない場合、保護対象サービスはオフラインのままです。</string>
<string name="secure_link_auth_note">トランスポート保護によって認証が省略されることはありません。Relay のペアリング、API 資格情報、ダッシュボードへのログインはサービスごとに引き続き適用されます。</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="other">離れている間に%1$d件のメッセージが届きました</item>
</plurals>
<string name="chat_model_confirmation_title">モデル選択を確認</string>
<string name="host_resource_recent_oom">Hermes は最近、メモリ不足が原因と思われる再起動を行いました。</string>
<string name="host_resource_memory_critical">ホストのメモリが極端に不足しています。進行中のチャットが停止する可能性があります。</string>
<string name="host_resource_memory_elevated">ホストのメモリが不足しています。</string>
<string name="host_resource_disk_critical">ホストのストレージが極端に不足しています。メッセージや設定を保存できない可能性があります。</string>
<string name="host_resource_disk_elevated">ホストのストレージが不足しています。</string>
</resources>
+188 -1
View File
@@ -1822,6 +1822,14 @@
<string name="dashboard_native_signin_requires_https">Безопасный вход в браузере требует HTTPS-адреса панели управления.</string>
<string name="dashboard_native_signin_unavailable">Безопасный вход в браузере недоступен для этого подключения. Обновите подключение и попробуйте снова.</string>
<string name="dashboard_native_signin_transport_retry">Защищённое соединение было прервано. Нажмите кнопку входа, чтобы повторить попытку.</string>
<string name="dashboard_native_signin_callback_rejected">Провайдер не подтвердил этот вход. Если вы отменили его, ничего делать не нужно; иначе начните новую попытку входа.</string>
<string name="dashboard_native_signin_code_rejected">Вход через Google завершён, но размещённый Hermes отклонил одноразовый код обратного вызова до создания сеанса. Начните новую попытку входа.</string>
<string name="dashboard_native_signin_gateway_rejected">Размещённый Hermes отклонил обмен сеанса. Убедитесь, что размещённый агент обновлён, и начните вход заново.</string>
<string name="dashboard_native_signin_rate_limited">Размещённый Hermes получил слишком много попыток входа. Подождите немного и повторите попытку.</string>
<string name="dashboard_native_signin_gateway_unavailable">Вход через Google завершён, но служба входа размещённого Hermes недоступна. Подождите немного и повторите попытку.</string>
<string name="dashboard_native_signin_response_unsupported">Размещённый Hermes вернул ответ входа, который это приложение не может использовать. Проверьте обновления Hermes Relay и размещённого агента.</string>
<string name="dashboard_native_signin_attempt_inactive">Эта попытка входа была отменена или заменена. Закройте старую вкладку и начните заново.</string>
<string name="dashboard_native_signin_storage_failed">Вход через Google завершён, но Android не смог безопасно сохранить сеанс Hermes. Повторите попытку; если ошибка повторится, откройте диагностику, чтобы увидеть этап сбоя.</string>
<string name="dashboard_close_signin">Закрыть вход</string>
<string name="dashboard_error_title">Панель управления недоступна</string>
<string name="dashboard_error_target">Не удалось загрузить из %1$s</string>
@@ -1831,6 +1839,17 @@
<string name="dashboard_empty_section">Не возвращено %1$s</string>
<string name="dashboard_section_action_change_main_model">Изменить основную модель</string>
<string name="dashboard_section_action_new_profile">Новый профиль</string>
<string name="dashboard_section_action_new_schedule">Новое расписание</string>
<string name="dashboard_cron_create_title">Создать расписание</string>
<string name="dashboard_cron_name">Название</string>
<string name="dashboard_cron_schedule">Расписание</string>
<string name="dashboard_cron_schedule_hint">Примеры: every 2h, 0 9 * * 1-5 или 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">Инструкции задачи</string>
<string name="dashboard_cron_repeat">Остановить после указанного числа запусков (необязательно)</string>
<string name="dashboard_cron_repeat_help">Оставьте пустым для обычного поведения расписания. Для конечных расписаний можно указать от 1 до 999 запусков.</string>
<string name="dashboard_cron_gateway_required">Для создания расписания требуется текущее подключение к Hermes Gateway.</string>
<string name="dashboard_cron_created">Расписание «%1$s» создано</string>
<string name="dashboard_cron_create_failed">Не удалось создать расписание</string>
<string name="dashboard_section_action_browse_hub">Просмотр центра</string>
<string name="dashboard_section_action_update_installed">Обновить установленное</string>
<string name="dashboard_action_set">Установить</string>
@@ -1955,6 +1974,16 @@
<string name="dashboard_skills_update_started">Обновление навыка начато на сервере — обновите Навыки через минуту</string>
<string name="dashboard_skills_update_failed">Обновление навыка не удалось</string>
<string name="dashboard_profile_created">Профиль %1$s создан</string>
<string name="dashboard_profile_created_partial">Профиль %1$s создан, но %2$s. Проверьте его перед использованием.</string>
<string name="dashboard_profile_created_legacy">Профиль %1$s создан через старый маршрут панели. Проверьте его учётные данные перед использованием.</string>
<string name="dashboard_profile_no_skills">Не добавлять встроенные навыки</string>
<string name="dashboard_profile_auth_title">Аутентификация</string>
<string name="dashboard_profile_auth_shared">Общий вход (рекомендуется) — единый пул обновляемых токенов</string>
<string name="dashboard_profile_auth_copied">Копировать текущие учётные данные — отдельный снимок может устареть</string>
<string name="dashboard_profile_auth_isolated">Изолированный — не копировать учётные данные и настройки провайдера</string>
<string name="dashboard_profile_auth_help">Hermes применяет этот выбор на сервере. Пароли и токены никогда не возвращаются в Android.</string>
<string name="dashboard_profile_allow_legacy">Если создание через Gateway недоступно, разрешить старый маршрут панели. Поведение учётных данных зависит от хоста и требует проверки.</string>
<string name="dashboard_profile_mcp_partial">Выбор серверов MCP не был применён</string>
<string name="dashboard_profile_create_failed">Создание профиля не удалось</string>
<string name="stats_overview">Обзор</string>
<string name="stats_reset">Сброс</string>
@@ -2553,7 +2582,35 @@
<plurals name="tool_run_used_device"><item quantity="one">Выполнено %d действие устройства</item><item quantity="few">Выполнено %d действия устройства</item><item quantity="many">Выполнено %d действий устройства</item><item quantity="other">Выполнено %d действий устройства</item></plurals>
<plurals name="tool_run_using_tools"><item quantity="one">Используется %d инструмент</item><item quantity="few">Используется %d инструмента</item><item quantity="many">Используется %d инструментов</item><item quantity="other">Используется %d инструментов</item></plurals>
<plurals name="tool_run_used_tools"><item quantity="one">Использован %d инструмент</item><item quantity="few">Использовано %d инструмента</item><item quantity="many">Использовано %d инструментов</item><item quantity="other">Использовано %d инструментов</item></plurals>
<string name="agent_icon_title">Иконка агента</string>
<string name="agent_icon_title">Внешний вид агента</string>
<string name="agent_icon_hermes_pet_title">Анимированный питомец Hermes</string>
<string name="agent_icon_hermes_pet_description">Привязан к профилю и доступен в upstream-интерфейсах Hermes. Реагирует на действия агента и отображается как спутник на телефоне.</string>
<string name="agent_icon_hermes_pet_active">Активен: %1$s</string>
<string name="agent_icon_hermes_pet_empty">Upstream-питомец не выбран</string>
<string name="agent_icon_hermes_pet_unsupported">Обновите Hermes, чтобы управлять анимированными питомцами здесь</string>
<string name="agent_icon_hermes_pet_browse">Выбрать питомца Hermes</string>
<string name="agent_icon_hermes_pet_picker_title">Выберите питомца Hermes</string>
<string name="agent_icon_hermes_pet_selected">Выбран</string>
<string name="agent_icon_hermes_pet_installed">Установлен</string>
<string name="agent_icon_hermes_pet_adopt">Добавить из Petdex</string>
<string name="agent_icon_shared_title">Общий в Hermes</string>
<string name="agent_icon_shared_active">Общий аватар</string>
<string name="agent_icon_shared_empty">Нет общего аватара</string>
<string name="agent_icon_change_shared">Изменить общий аватар</string>
<string name="agent_icon_remove_shared">Удалить</string>
<string name="agent_icon_remove_shared_title">Удалить общий аватар?</string>
<string name="agent_icon_remove_shared_message">Аватар будет удалён из Hermes и других клиентов. Изображение на телефоне не изменится.</string>
<string name="agent_icon_phone_title">Только на этом телефоне</string>
<string name="agent_icon_phone_description">Заменить общий аватар только на этом телефоне, не изменяя Hermes.</string>
<string name="agent_icon_choose_phone">Выбрать изображение на телефоне</string>
<string name="agent_icon_change_phone">Изменить изображение на телефоне</string>
<string name="agent_icon_remove_phone">Удалить изображение с телефона</string>
<string name="agent_icon_animation_note">Анимированные GIF- и WebP-переопределения работают только на этом телефоне. Для профильной upstream-анимации используйте анимированного питомца Hermes выше.</string>
<string name="agent_icon_set_local">Выбрать резервное изображение на устройстве</string>
<string name="agent_icon_change_local">Изменить резервное изображение на устройстве</string>
<string name="agent_icon_clear_local">Удалить резервное изображение с устройства</string>
<string name="agent_icon_upload_shared">Загрузить значок устройства в Hermes</string>
<string name="agent_icon_clear_shared">Удалить общий аватар Hermes</string>
<string name="agent_icon_set">Выбрать файл</string>
<string name="agent_icon_change">Выбрать файл</string>
<string name="agent_icon_clear">Очистить</string>
@@ -3706,4 +3763,134 @@
<string name="pet_creator_step_review">Проверить и импортировать</string>
<string name="pet_creator_review_desc">Сначала проверьте полученное изображение или ZIP. При импорте проверенные файлы копируются в хранилище приложения и не публикуются.</string>
<string name="pet_creator_import">Импортировать готового питомца</string>
<string name="dashboard_tab_memory">Память</string>
<string name="dashboard_tab_learning">Обучение</string>
<string name="dashboard_tab_channels">Каналы</string>
<string name="dashboard_tab_operations">Операции</string>
<string name="dashboard_tab_memory_lower">память</string>
<string name="dashboard_tab_learning_lower">обучение</string>
<string name="dashboard_tab_channels_lower">каналы</string>
<string name="dashboard_tab_operations_lower">операции</string>
<string name="dashboard_section_action_server_backup">Создать резервную копию сервера</string>
<string name="dashboard_profile_mcp_servers_optional">Серверы MCP (необязательно)</string>
<string name="dashboard_profile_mcp_servers_help">Имена серверов через запятую или с новой строки. Учётные данные остаются на сервере.</string>
<string name="dashboard_tile_memory_title">Память</string>
<string name="dashboard_tile_memory_sub">Состояние провайдера и серверная настройка памяти</string>
<string name="dashboard_tile_learning_title">Граф обучения</string>
<string name="dashboard_tile_learning_sub">Просмотр изученных узлов активного профиля</string>
<string name="dashboard_tile_channels_title">Каналы</string>
<string name="dashboard_tile_channels_sub">Состояние платформ сообщений, включая WhatsApp</string>
<string name="dashboard_tile_operations_title">Операции сервера</string>
<string name="dashboard_tile_operations_sub">Состояние хоста и резервная копия всего сервера</string>
<string name="dashboard_section_action_download_backup">Сохранить последнюю резервную копию</string>
<string name="dashboard_section_action_import_backup">Импортировать резервную копию</string>
<string name="dashboard_backup_create_first">Перед скачиванием создайте резервную копию в этом сеансе.</string>
<string name="dashboard_backup_download_failed">Не удалось скачать резервную копию.</string>
<string name="dashboard_backup_saved">Резервная копия сохранена как %1$s.</string>
<string name="dashboard_import_title">Импортировать резервную копию сервера?</string>
<string name="dashboard_import_warning">Выбранный ZIP-файл будет загружен в Hermes, после чего начнётся аутентифицированный импорт на сервере. Он может заменить конфигурацию и данные. Сначала создайте и сохраните актуальную резервную копию.</string>
<string name="dashboard_import_confirm">Импортировать</string>
<string name="dashboard_import_started">Импорт на сервере запущен. Перед перезапуском Hermes дождитесь его завершения в разделе «Операции».</string>
<string name="dashboard_import_failed">Не удалось запустить импорт на сервере.</string>
<string name="dashboard_action_configure">Настроить</string>
<string name="dashboard_action_setup">Настройка</string>
<string name="dashboard_action_setup_whatsapp">Настроить WhatsApp</string>
<string name="dashboard_learning_edit_title">Изменить %1$s</string>
<string name="dashboard_learning_edit_warning">Изменения заменят всё содержимое узла. Hermes архивирует навыки, удалённые из графа, чтобы их можно было восстановить из архива; удаление узла памяти необратимо, поэтому сначала экспортируйте резервную копию.</string>
<string name="dashboard_learning_saved">Изученный узел сохранён.</string>
<string name="dashboard_learning_save_failed">Не удалось сохранить изученный узел.</string>
<string name="dashboard_learning_delete_warning">Hermes архивирует изученные навыки, чтобы их можно было восстановить из архива сервера. Удаление узла памяти необратимо. Если содержимое может понадобиться позже, сначала сохраните резервную копию сервера.</string>
<string name="dashboard_memory_config_title">Настроить %1$s</string>
<string name="dashboard_memory_config_help">Значения сохраняются в выбранном профиле Hermes. Секретные поля принимаются сервером и не возвращаются после сохранения. Обязательные поля отмечены символом *.</string>
<string name="dashboard_memory_values_json">Значения провайдера (JSON)</string>
<string name="dashboard_memory_run_setup">Запустить настройку</string>
<string name="dashboard_memory_invalid_json">Значения провайдера должны быть объектом JSON.</string>
<string name="dashboard_memory_setup_started">Установка провайдера на всём хосте запущена. После её завершения обновите данные, затем сохраните значения этого профиля.</string>
<string name="dashboard_memory_saved">Провайдер памяти настроен и активирован.</string>
<string name="dashboard_memory_save_failed">Не удалось сохранить конфигурацию провайдера памяти.</string>
<string name="dashboard_whatsapp_title">Настроить WhatsApp</string>
<string name="dashboard_whatsapp_help">Hermes запускает десятиминутный сеанс привязки для выбранного профиля. Выберите режим бота для отдельной учётной записи или чат с собой, чтобы писать в собственную привязанную учётную запись.</string>
<string name="dashboard_whatsapp_bot">Учётная запись бота</string>
<string name="dashboard_whatsapp_self_chat">Чат с собой</string>
<string name="dashboard_whatsapp_allowed_users">Разрешённые номера телефонов (необязательно)</string>
<string name="dashboard_whatsapp_start">Начать привязку</string>
<string name="dashboard_whatsapp_scan">Отсканируйте этот код на экране «Связанные устройства» в WhatsApp. Не закрывайте это окно, пока Hermes подтверждает учётную запись.</string>
<string name="dashboard_whatsapp_qr">QR-код связанного устройства WhatsApp</string>
<string name="dashboard_whatsapp_apply">Включить WhatsApp</string>
<string name="dashboard_whatsapp_start_failed">Не удалось начать привязку WhatsApp.</string>
<string name="dashboard_whatsapp_apply_failed">Не удалось сохранить конфигурацию WhatsApp.</string>
<string name="dashboard_whatsapp_saved">WhatsApp включён; Hermes начал перезапуск шлюза.</string>
<string name="drawer_all_profiles">Все профили</string>
<string name="drawer_no_profile_sessions">Нет подходящих сеансов профиля.</string>
<string name="drawer_customize_sessions">Настроить сеансы</string>
<string name="drawer_group_by">Группировать по</string>
<string name="drawer_order_by">Сортировать по</string>
<string name="drawer_show_metadata">Показывать в строках</string>
<string name="drawer_show_details">Показывать подробности</string>
<string name="drawer_filters">Фильтры</string>
<string name="drawer_project_home">Главная</string>
<string name="drawer_expand_project">Развернуть %1$s</string>
<string name="drawer_collapse_project">Свернуть %1$s</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d сеанс</item>
<item quantity="few">%1$d сеанса</item>
<item quantity="many">%1$d сеансов</item>
<item quantity="other">%1$d сеанса</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d профиль</item>
<item quantity="few">%1$d профиля</item>
<item quantity="many">%1$d профилей</item>
<item quantity="other">%1$d профиля</item>
</plurals>
<string name="drawer_filter_status">Статус</string>
<string name="drawer_filter_profile">Профиль</string>
<string name="drawer_filter_project">Проект</string>
<string name="drawer_filter_pull_request">Запрос на слияние</string>
<string name="drawer_option_updated">Обновлено</string>
<string name="drawer_option_profile">Профиль</string>
<string name="drawer_option_tokens">Токены</string>
<string name="drawer_option_cost">Стоимость</string>
<string name="drawer_reset_filters">Сбросить</string>
<string name="drawer_profile_colors">Цвета профилей</string>
<string name="drawer_profile_color_auto">Автоматически</string>
<string name="drawer_profile_color_set">Установить цвет профиля %1$s: %2$s</string>
<string name="drawer_close">Закрыть</string>
<string name="profile_inspector_gateway_settings">Настройки профиля Gateway</string>
<string name="profile_inspector_gateway_settings_hint">Сохраняются напрямую через Hermes для выбранного профиля.</string>
<string name="profile_inspector_edit_config">Изменить настройки профиля</string>
<string name="profile_inspector_description">Описание</string>
<string name="profile_inspector_provider">Провайдер</string>
<string name="profile_inspector_model">Модель</string>
<string name="profile_inspector_save_changes">Сохранить изменения</string>
<string name="profile_inspector_toolsets">Наборы инструментов</string>
<string name="profile_inspector_toolsets_hint">Выберите группы инструментов Hermes, доступные этому профилю.</string>
<string name="profile_inspector_tool_count">Инструментов: %1$d</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · Экспериментально</string>
<string name="hermes_reach_summary">Экспериментальный маршрут через брокер для сетей, где недоступны прямое подключение и Tailscale. Он пока не рекомендуется для обычной настройки; TLS Secure Link остаётся защищённым из конца в конец.</string>
<string name="secure_link_pinned_tls">Закреплённый TLS · подлинность подтверждена этим сопряжением</string>
<string name="secure_link_pinned_tls_short">Secure Link · закреплённый TLS</string>
<string name="secure_link_protects">Защищённые сервисы: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">Панель</string>
<string name="secure_link_no_services">Защищённые сервисы не объявлены. Secure Link использоваться не будет.</string>
<string name="secure_link_partial_warning">Частичная защита: не указанные здесь сервисы используют собственные настроенные маршруты и параметры безопасности.</string>
<string name="secure_link_partial_short">Secure Link · частично</string>
<string name="secure_link_fallback_ready">Если Secure Link недоступен, Hermes может попробовать одобренные резервные маршруты ниже.</string>
<string name="secure_link_no_fallback">Резервный маршрут не указан. Защищённые сервисы останутся офлайн, если Secure Link недоступен.</string>
<string name="secure_link_auth_note">Защита транспорта не отменяет аутентификацию. Сопряжение Relay, учётные данные API и вход в Панель по-прежнему проверяются отдельно для каждого сервиса.</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="one">Пока вас не было, пришло %1$d сообщение</item>
<item quantity="few">Пока вас не было, пришло %1$d сообщения</item>
<item quantity="many">Пока вас не было, пришло %1$d сообщений</item>
<item quantity="other">Пока вас не было, пришло %1$d сообщения</item>
</plurals>
<string name="chat_model_confirmation_title">Подтвердите выбор модели</string>
<string name="host_resource_recent_oom">Hermes недавно перезапустился, вероятно, из-за нехватки памяти.</string>
<string name="host_resource_memory_critical">Память хоста почти исчерпана; активные чаты могут остановиться.</string>
<string name="host_resource_memory_elevated">Память хоста заканчивается.</string>
<string name="host_resource_disk_critical">Хранилище хоста почти заполнено; сообщения и настройки могут не сохраниться.</string>
<string name="host_resource_disk_elevated">Хранилище хоста заканчивается.</string>
</resources>
+182 -1
View File
@@ -455,6 +455,21 @@
<string name="cw_step_connect">3. Then come back and tap Connect</string>
<string name="cw_routes_count">Routes (%1$d)</string>
<string name="cw_routes_desc">Your phone tries these routes in order and uses the first one it can reach. It switches automatically as you change networks.</string>
<string name="secure_link_title">Hermes Secure Link</string>
<string name="hermes_reach_title">Hermes Reach · Experimental</string>
<string name="hermes_reach_summary">Experimental broker route for networks where direct access and Tailscale are unavailable. It is not recommended for normal setup yet; Secure Link TLS remains end to end.</string>
<string name="secure_link_pinned_tls">Pinned TLS · identity verified from this pairing</string>
<string name="secure_link_pinned_tls_short">Secure Link · pinned TLS</string>
<string name="secure_link_protects">Protected services: %1$s</string>
<string name="secure_link_service_relay">Relay</string>
<string name="secure_link_service_api">API</string>
<string name="secure_link_service_dashboard">Dashboard</string>
<string name="secure_link_no_services">No protected services were advertised. Secure Link will not be used.</string>
<string name="secure_link_partial_warning">Partial protection: services not listed here use their own configured route and security.</string>
<string name="secure_link_partial_short">Secure Link · partial</string>
<string name="secure_link_fallback_ready">If Secure Link is unavailable, Hermes can try the approved fallback routes below.</string>
<string name="secure_link_no_fallback">No fallback route is included. Protected services will remain offline if Secure Link is unavailable.</string>
<string name="secure_link_auth_note">Transport protection does not bypass authentication. Relay pairing, API credentials, and Dashboard sign-in are still enforced per service.</string>
<string name="cw_prefer_label">Prefer:</string>
<string name="cw_natural_order">Natural order</string>
<string name="cw_keep_pairing_for">Keep this pairing for…</string>
@@ -1479,6 +1494,10 @@
<string name="proactive_about">About</string>
<string name="proactive_about_desc">When on, your phone tells the relay it\'s open to agent-initiated messages. The agent delivers them over the same paired connection the relay already uses — no new permissions beyond notifications.</string>
<string name="proactive_about_server_note">Your server must also enable the phone platform (set PHONE_ENABLED on the server). Until both sides are on and the phone is paired, nothing is pushed.</string>
<plurals name="proactive_messages_arrived_while_away">
<item quantity="one">%1$d message arrived while you were away</item>
<item quantity="other">%1$d messages arrived while you were away</item>
</plurals>
<!-- ProfileInspectorScreen -->
<string name="profile_inspector_back">Back</string>
@@ -1862,6 +1881,10 @@
<string name="dashboard_tab_models">Models</string>
<string name="dashboard_tab_keys">Keys</string>
<string name="dashboard_tab_config">Config</string>
<string name="dashboard_tab_memory">Memory</string>
<string name="dashboard_tab_learning">Learning</string>
<string name="dashboard_tab_channels">Channels</string>
<string name="dashboard_tab_operations">Operations</string>
<!-- Lowercase tab labels for compact UI surfaces (KPI strip) -->
<string name="dashboard_tab_skills_lower">skills</string>
<string name="dashboard_tab_cron_lower">cron</string>
@@ -1872,6 +1895,10 @@
<string name="dashboard_tab_models_lower">models</string>
<string name="dashboard_tab_keys_lower">keys</string>
<string name="dashboard_tab_config_lower">config</string>
<string name="dashboard_tab_memory_lower">memory</string>
<string name="dashboard_tab_learning_lower">learning</string>
<string name="dashboard_tab_channels_lower">channels</string>
<string name="dashboard_tab_operations_lower">operations</string>
<!-- Tile titles + subtitles -->
<string name="dashboard_tile_profiles_title">Profiles</string>
@@ -1951,6 +1978,14 @@
<string name="dashboard_native_signin_requires_https">Secure browser sign-in requires an HTTPS dashboard address.</string>
<string name="dashboard_native_signin_unavailable">Secure browser sign-in is unavailable for this connection. Refresh the connection and try again.</string>
<string name="dashboard_native_signin_transport_retry">The secure connection was interrupted. Tap the sign-in button to try again.</string>
<string name="dashboard_native_signin_callback_rejected">The provider did not approve this sign-in. If you cancelled, no action is needed; otherwise start a fresh sign-in attempt.</string>
<string name="dashboard_native_signin_code_rejected">Google sign-in finished, but hosted Hermes rejected the one-time callback code before it could create a session. Start a fresh sign-in attempt.</string>
<string name="dashboard_native_signin_gateway_rejected">Hosted Hermes refused the session exchange. Check that the hosted agent is current, then start sign-in again.</string>
<string name="dashboard_native_signin_rate_limited">Hosted Hermes received too many sign-in attempts. Wait a moment, then try again.</string>
<string name="dashboard_native_signin_gateway_unavailable">Google sign-in finished, but the hosted Hermes sign-in service is unavailable. Wait a moment, then try again.</string>
<string name="dashboard_native_signin_response_unsupported">Hosted Hermes returned a sign-in response this app could not use. Check for Hermes Relay and hosted agent updates.</string>
<string name="dashboard_native_signin_attempt_inactive">This sign-in attempt was cancelled or replaced. Close the old browser tab and start again.</string>
<string name="dashboard_native_signin_storage_failed">Google sign-in finished, but Android could not securely save the Hermes session. Try again; if it repeats, open Diagnostics for the failure stage.</string>
<string name="dashboard_close_signin">Close sign-in</string>
<!-- Error body -->
@@ -1966,8 +2001,40 @@
<!-- Section action buttons -->
<string name="dashboard_section_action_change_main_model">Change main model</string>
<string name="dashboard_section_action_new_profile">New profile</string>
<string name="dashboard_section_action_new_schedule">New schedule</string>
<string name="dashboard_cron_create_title">Create schedule</string>
<string name="dashboard_cron_name">Name</string>
<string name="dashboard_cron_schedule">Schedule</string>
<string name="dashboard_cron_schedule_hint">Examples: every 2h, 0 9 * * 1-5, or 2026-08-20 09:00</string>
<string name="dashboard_cron_prompt">Task instructions</string>
<string name="dashboard_cron_repeat">Stop after this many runs (optional)</string>
<string name="dashboard_cron_repeat_help">Leave blank to keep the schedule’s normal behavior. Finite schedules accept 1–999 runs.</string>
<string name="dashboard_cron_gateway_required">Schedule creation requires a current Hermes Gateway connection.</string>
<string name="dashboard_cron_created">Created schedule “%1$s”</string>
<string name="dashboard_cron_create_failed">Couldn’t create schedule</string>
<string name="dashboard_section_action_browse_hub">Browse hub</string>
<string name="dashboard_section_action_update_installed">Update installed</string>
<string name="dashboard_section_action_server_backup">Create server backup</string>
<string name="dashboard_section_action_download_backup">Save latest backup</string>
<string name="dashboard_section_action_import_backup">Import backup</string>
<string name="dashboard_backup_create_first">Create a backup in this session before downloading it.</string>
<string name="dashboard_backup_download_failed">Backup could not be downloaded.</string>
<string name="dashboard_backup_saved">Backup saved as %1$s.</string>
<string name="dashboard_import_title">Import server backup?</string>
<string name="dashboard_import_warning">This uploads the selected zip to Hermes and starts its authenticated server import. It can replace configuration and data. Create and save a current backup first.</string>
<string name="dashboard_import_confirm">Import</string>
<string name="dashboard_import_started">Server import started. Watch Operations for completion before restarting Hermes.</string>
<string name="dashboard_import_failed">Server import could not be started.</string>
<string name="dashboard_profile_mcp_servers_optional">MCP servers (optional)</string>
<string name="dashboard_profile_mcp_servers_help">Comma or line-separated server names. Credentials remain server-owned.</string>
<string name="dashboard_tile_memory_title">Memory</string>
<string name="dashboard_tile_memory_sub">Provider status and host-owned memory configuration</string>
<string name="dashboard_tile_learning_title">Learning graph</string>
<string name="dashboard_tile_learning_sub">Inspect learned nodes for the active profile</string>
<string name="dashboard_tile_channels_title">Channels</string>
<string name="dashboard_tile_channels_sub">Messaging platform status, including WhatsApp</string>
<string name="dashboard_tile_operations_title">Server operations</string>
<string name="dashboard_tile_operations_sub">Host health and server-wide backup</string>
<!-- Action labels (rendered via kind → string) -->
<string name="dashboard_action_set">Set</string>
@@ -1991,6 +2058,34 @@
<string name="dashboard_action_use">Use</string>
<string name="dashboard_action_describe">Describe</string>
<string name="dashboard_action_model">Model</string>
<string name="dashboard_action_configure">Configure</string>
<string name="dashboard_action_setup">Setup</string>
<string name="dashboard_action_setup_whatsapp">Set up WhatsApp</string>
<string name="dashboard_learning_edit_title">Edit %1$s</string>
<string name="dashboard_learning_edit_warning">Edits replace the node’s complete content. Skills deleted from the graph are archived by Hermes and can be restored from the archive; memory-node deletion is permanent, so export a backup first.</string>
<string name="dashboard_learning_saved">Learning node saved.</string>
<string name="dashboard_learning_save_failed">Learning node could not be saved.</string>
<string name="dashboard_learning_delete_warning">Hermes archives learned skills so they can be restored from the server archive. Memory-node deletion is permanent. Save a server backup first if this content may be needed later.</string>
<string name="dashboard_memory_config_title">Configure %1$s</string>
<string name="dashboard_memory_config_help">Values stay on the selected Hermes profile. Secret fields are accepted by the server and are never returned after saving. Required fields are marked with *.</string>
<string name="dashboard_memory_values_json">Provider values (JSON)</string>
<string name="dashboard_memory_run_setup">Run setup</string>
<string name="dashboard_memory_invalid_json">Provider values must be a JSON object.</string>
<string name="dashboard_memory_setup_started">Host-wide provider installation started. Refresh after it completes, then save this profile’s values.</string>
<string name="dashboard_memory_saved">Memory provider configured and activated.</string>
<string name="dashboard_memory_save_failed">Memory provider configuration could not be saved.</string>
<string name="dashboard_whatsapp_title">Set up WhatsApp</string>
<string name="dashboard_whatsapp_help">Hermes starts a ten-minute, profile-scoped pairing session. Choose bot mode for a dedicated account or self-chat to message your own linked account.</string>
<string name="dashboard_whatsapp_bot">Bot account</string>
<string name="dashboard_whatsapp_self_chat">Self-chat</string>
<string name="dashboard_whatsapp_allowed_users">Allowed phone numbers (optional)</string>
<string name="dashboard_whatsapp_start">Start pairing</string>
<string name="dashboard_whatsapp_scan">Scan this code from WhatsApp’s Linked devices screen. Keep this dialog open while Hermes confirms the account.</string>
<string name="dashboard_whatsapp_qr">WhatsApp linked-device QR code</string>
<string name="dashboard_whatsapp_apply">Enable WhatsApp</string>
<string name="dashboard_whatsapp_start_failed">WhatsApp pairing could not be started.</string>
<string name="dashboard_whatsapp_apply_failed">WhatsApp configuration could not be saved.</string>
<string name="dashboard_whatsapp_saved">WhatsApp enabled; Hermes started a gateway restart.</string>
<string name="dashboard_mcp_oauth_title">Authenticate %1$s</string>
<string name="dashboard_mcp_oauth_body">Hermes will open the provider in your browser. Return here after approving access; credentials stay on the Hermes server.</string>
<string name="dashboard_mcp_oauth_approved">MCP authentication approved</string>
@@ -2116,6 +2211,16 @@
<!-- Profile create -->
<string name="dashboard_profile_created">Profile %1$s created</string>
<string name="dashboard_profile_created_partial">Profile %1$s created, but %2$s. Review it before use.</string>
<string name="dashboard_profile_created_legacy">Profile %1$s created through the older Dashboard route. Review its credentials before use.</string>
<string name="dashboard_profile_no_skills">Do not seed bundled skills</string>
<string name="dashboard_profile_auth_title">Authentication</string>
<string name="dashboard_profile_auth_shared">Share sign-in (recommended) — one refreshable token pool</string>
<string name="dashboard_profile_auth_copied">Copy current credentials — separate snapshot that can drift</string>
<string name="dashboard_profile_auth_isolated">Isolated — copy no credentials or provider defaults</string>
<string name="dashboard_profile_auth_help">Hermes applies this choice on the server. Passwords and tokens are never returned to Android.</string>
<string name="dashboard_profile_allow_legacy">If Gateway create is unavailable, allow the older Dashboard route. Credential behavior depends on that host and must be reviewed.</string>
<string name="dashboard_profile_mcp_partial">MCP server selection was not applied</string>
<string name="dashboard_profile_create_failed">Profile create failed</string>
<!-- Stats for nerds -->
@@ -2763,7 +2868,35 @@
<plurals name="tool_run_used_tools"><item quantity="one">Used %d tool</item><item quantity="other">Used %d tools</item></plurals>
<!-- AgentIconRow -->
<string name="agent_icon_title">Agent icon</string>
<string name="agent_icon_title">Agent visuals</string>
<string name="agent_icon_hermes_pet_title">Hermes animated pet</string>
<string name="agent_icon_hermes_pet_description">Profile-scoped and shared with upstream Hermes surfaces. It reacts to agent activity and appears as the phone companion.</string>
<string name="agent_icon_hermes_pet_active">Active: %1$s</string>
<string name="agent_icon_hermes_pet_empty">No upstream pet selected</string>
<string name="agent_icon_hermes_pet_unsupported">Update Hermes to manage animated pets here</string>
<string name="agent_icon_hermes_pet_browse">Browse Hermes pets</string>
<string name="agent_icon_hermes_pet_picker_title">Choose a Hermes pet</string>
<string name="agent_icon_hermes_pet_selected">Selected</string>
<string name="agent_icon_hermes_pet_installed">Installed</string>
<string name="agent_icon_hermes_pet_adopt">Adopt from Petdex</string>
<string name="agent_icon_shared_title">Shared across Hermes</string>
<string name="agent_icon_shared_active">Shared avatar</string>
<string name="agent_icon_shared_empty">No shared avatar</string>
<string name="agent_icon_change_shared">Change shared avatar</string>
<string name="agent_icon_remove_shared">Remove</string>
<string name="agent_icon_remove_shared_title">Remove shared avatar?</string>
<string name="agent_icon_remove_shared_message">This removes the avatar from Hermes and other clients. Your phone image is not affected.</string>
<string name="agent_icon_phone_title">This phone only</string>
<string name="agent_icon_phone_description">Override the shared avatar on this phone without changing Hermes.</string>
<string name="agent_icon_choose_phone">Choose phone image</string>
<string name="agent_icon_change_phone">Change phone image</string>
<string name="agent_icon_remove_phone">Remove phone image</string>
<string name="agent_icon_animation_note">Animated GIF and WebP overrides play only on this phone. Use Hermes animated pets above for an upstream-managed, profile-scoped animation.</string>
<string name="agent_icon_set_local">Choose device fallback</string>
<string name="agent_icon_change_local">Change device fallback</string>
<string name="agent_icon_clear_local">Clear device fallback</string>
<string name="agent_icon_upload_shared">Upload device icon to Hermes</string>
<string name="agent_icon_clear_shared">Clear shared Hermes avatar</string>
<string name="agent_icon_set">Choose file</string>
<string name="agent_icon_change">Choose file</string>
<string name="agent_icon_clear">Clear</string>
@@ -3991,4 +4124,52 @@
<string name="support_bundle_copied">Support information copied</string>
<string name="support_bundle_no_share">Support information copied — no app found to share to</string>
<string name="support_bundle_share_title">Share Hermes-Relay support information</string>
<string name="drawer_all_profiles">All Profiles</string>
<string name="drawer_no_profile_sessions">No matching profile sessions.</string>
<string name="drawer_customize_sessions">Customize sessions</string>
<string name="drawer_group_by">Group by</string>
<string name="drawer_order_by">Order by</string>
<string name="drawer_show_metadata">Show on rows</string>
<string name="drawer_show_details">Show details</string>
<string name="drawer_filters">Filters</string>
<string name="drawer_project_home">Home</string>
<string name="drawer_expand_project">Expand %1$s</string>
<string name="drawer_collapse_project">Collapse %1$s</string>
<plurals name="drawer_project_session_count">
<item quantity="one">%1$d session</item>
<item quantity="other">%1$d sessions</item>
</plurals>
<plurals name="drawer_profile_count">
<item quantity="one">%1$d profile</item>
<item quantity="other">%1$d profiles</item>
</plurals>
<string name="drawer_filter_status">Status</string>
<string name="drawer_filter_profile">Profile</string>
<string name="drawer_filter_project">Project</string>
<string name="drawer_filter_pull_request">Pull request</string>
<string name="drawer_option_updated">Updated</string>
<string name="drawer_option_profile">Profile</string>
<string name="drawer_option_tokens">Tokens</string>
<string name="drawer_option_cost">Cost</string>
<string name="drawer_reset_filters">Reset</string>
<string name="drawer_profile_colors">Profile colors</string>
<string name="drawer_profile_color_auto">Auto</string>
<string name="drawer_profile_color_set">Set %1$s profile color to %2$s</string>
<string name="drawer_close">Close</string>
<string name="profile_inspector_gateway_settings">Gateway profile settings</string>
<string name="profile_inspector_gateway_settings_hint">Saved directly through upstream Hermes for this selected profile.</string>
<string name="profile_inspector_edit_config">Edit profile settings</string>
<string name="profile_inspector_description">Description</string>
<string name="profile_inspector_provider">Provider</string>
<string name="profile_inspector_model">Model</string>
<string name="profile_inspector_save_changes">Save changes</string>
<string name="profile_inspector_toolsets">Toolsets</string>
<string name="profile_inspector_toolsets_hint">Choose which upstream tool groups this profile can use.</string>
<string name="profile_inspector_tool_count">%1$d tools</string>
<string name="chat_model_confirmation_title">Confirm model selection</string>
<string name="host_resource_recent_oom">Hermes recently restarted after likely running out of memory.</string>
<string name="host_resource_memory_critical">Host memory is critically low; active chats may stop.</string>
<string name="host_resource_memory_elevated">Host memory is running low.</string>
<string name="host_resource_disk_critical">Host storage is critically low; messages and settings may fail to save.</string>
<string name="host_resource_disk_elevated">Host storage is running low.</string>
</resources>
@@ -336,4 +336,23 @@ class AuthManagerProfilesParseTest {
assertFalse(parsed[0].apiServerKeyPresent)
assertFalse(parsed[0].hasIsolatedApi)
}
@Test
fun parsesBoundedSharedProfileMetadata() {
val parsed = AuthManager.parseAgentProfiles(buildJsonArray {
add(buildJsonObject {
put("name", "operator")
put("model", "gpt")
put("provider", "openai")
put("is_default", true)
put("has_avatar", true)
put("ui_meta", buildJsonObject { put("accent", "#ff5500") })
})
}).single()
assertEquals("openai", parsed.provider)
assertTrue(parsed.isDefault)
assertTrue(parsed.hasAvatar)
assertEquals("#ff5500", (parsed.uiMeta["accent"] as JsonPrimitive).content)
}
}

Some files were not shown because too many files have changed in this diff Show More