Compare commits

...
Author SHA1 Message Date
Bailey Dixon d8a6bf0ce6 Merge pull request #607 from AYin-Z/fix/tray-notice-capability
fix(desktop): grant tray capability to the notice and evidence windows
2026-09-23 18:20:13 -04:00
Bailey Dixon 9e96111813 fix(desktop): restore secondary tray window dismissal
Give notice and evidence only the Tauri hide permission, retain secondary windows on native close, and ignore stale screenshot responses.

Based on contributor report and PR #607 by AYin-Z. Refs #606.

(cherry picked from commit 0d7ea149cf3e0e7605607733499e7ac821ce4ff2)
2026-09-23 18:06:31 -04:00
Bailey Dixon 42efc01d58 Merge PR #607 tray capability fix into current dev 2026-09-23 18:06:06 -04:00
Bailey Dixon dc93d5eab2 Merge pull request #628 from Codename-11/fix/media-consumer-parity
fix: render proactive and desktop media with private cleanup
2026-09-23 18:02:47 -04:00
Bailey Dixon cafbadc583 docs: align media route reference with managed uploads 2026-09-23 17:49:19 -04:00
Bailey Dixon 607c26660c merge: integrate current dev into media consumer fixes 2026-09-23 17:48:41 -04:00
Bailey Dixon 3882b857e3 fix(relay): retire owned media and redact activity logs 2026-09-23 17:48:33 -04:00
Bailey Dixon 81c186c6ba fix(plugin): attach desktop screenshots as host images 2026-09-23 17:48:26 -04:00
Bailey Dixon 4ad0709fbe fix(android): render proactive Thread media markers 2026-09-23 17:48:25 -04:00
Bailey Dixon 0324c9f5dd Merge pull request #615 from ophirhan/feat/provider-usage-supergrok
feat(plugin): report SuperGrok subscription usage on the provider surface
2026-09-23 17:39:22 -04:00
Bailey Dixon f8c31f8b59 fix(plugin): distinguish SuperGrok credential failures and on-demand state 2026-09-23 17:16:12 -04:00
Bailey Dixon abb4bc0ced Merge PR #615 SuperGrok provider usage into current dev 2026-09-23 17:14:32 -04:00
Bailey Dixon 07b683fbb5 Merge pull request #627 from Codename-11/fix/android-screenshot-media-token
fix(plugin): resolve Android screenshot media tokens for host tools
2026-09-23 16:39:40 -04:00
Bailey Dixon 759ac490c9 fix(plugin): resolve Android screenshot media tokens for host tools 2026-09-23 16:37:50 -04:00
Bailey Dixon 150e375284 Merge pull request #626 from Codename-11/fix/android-chat-model-picker-cold-load
fix(android): load Chat models when picker first opens
2026-09-23 16:00:51 -04:00
Bailey Dixon 1f49f08dbe fix(android): load Chat models when picker first opens 2026-09-23 15:42:43 -04:00
Bailey Dixon e96aa435f2 Merge pull request #625 from Codename-11/integration/agp-941
chore(deps): update Android Gradle plugins to 9.4.1
2026-09-23 14:24:01 -04:00
Bailey Dixon 592affca40 Merge remote-tracking branch 'origin/pr-614-dependabot' into integration/agp-941
# Conflicts:
#	build.gradle.kts
2026-09-23 14:11:02 -04:00
Bailey Dixon 7e5123b22f Merge remote-tracking branch 'origin/pr-612-dependabot' into integration/agp-941 2026-09-23 14:10:28 -04:00
Bailey Dixon ad3786fb0b Merge pull request #624 from Codename-11/integration/secure-link-contract
feat: guide Secure Link setup and preserve paired routes
2026-09-23 13:57:11 -04:00
Bailey Dixon 8bd67e3363 fix: render Desktop recovery instructions as static children 2026-09-23 13:21:50 -04:00
Bailey Dixon 17cf12fff9 fix: retire Desktop setup results when the listener changes 2026-09-23 13:18:09 -04:00
Bailey Dixon b55e798c3b fix: allow bounded Secure Link preflight checks to finish 2026-09-23 13:12:33 -04:00
Bailey Dixon a128e910f1 feat: guide Secure Link setup across Relay surfaces 2026-09-23 13:10:25 -04:00
ophirhan a7cbf377a0 test(plugin): resolve temp paths in profile-home usage test
On macOS tempfile lives under /var which Path.resolve() maps to
/private/var; compare resolved paths so the assertion is stable.
2026-09-23 19:36:16 +03:00
ophirhan 9435d43b04 feat(android): show SuperGrok in default usage-provider visibility
Include supergrok in DEFAULT_VISIBLE_PROVIDERS and the Usage Limits
fallback list so the Settings summary surfaces Grok once the host
reports it, without a one-off toggle.
2026-09-23 19:36:16 +03:00
ophirhan 52170f76ea fix(plugin): keep the Grok window when a period reports no usage yet
For a billing period that has recorded no usage, xAI omits `creditUsagePercent` and `productUsage` from the credits snapshot instead of reporting zero. The adapter treated the resulting empty window list as an upstream failure, so a freshly rolled-over period surfaced as 'usage is temporarily unavailable' on the device.

Emit the period window with no percentage and an explicit detail line whenever the period bounds are known: the window, its label, and its reset time are real, only the figure is absent. A payload carrying neither a figure nor period bounds still reports unavailable, so a genuinely broken upstream contract is not masked.

Verified against a rolled-over weekly period that previously produced the error state; the surface now reports the window with its reset time.
2026-09-23 19:36:15 +03:00
ophirhan 9871b0cb7c feat(plugin): report Grok subscription usage in the provider surface
Hosts signed in with `xai-oauth` have a Grok subscription whose windows are
only served by xAI's CLI proxy, not the public API, so the provider-neutral
usage surface could not see them.

Add a `supergrok` adapter that reads the account identity and then the credits
billing snapshot over the pinned `cli-chat-proxy.grok.com` contract with the
host-side OAuth bearer: the current billing period, per-product usage, and
on-demand credit state map onto the existing window/detail shape. Hosts with
no `xai-oauth` credential report `not_configured`, upstream failures degrade to
`unavailable`, and the bearer never enters the response.
2026-09-23 19:36:15 +03:00
Bailey Dixon 14500096c6 fix: simplify Secure Link routes and fit pairing QR payloads 2026-09-23 11:17:12 -04:00
Bailey Dixon 1ea84630d2 chore: refresh Secure Link integration from dev 2026-09-23 10:03:24 -04:00
Bailey Dixon d98e0b113b Merge pull request #620 from ophirhan/fix/appearance-light-mode-cold-start
fix(android): lock night mode to Appearance on cold start
2026-09-23 09:57:42 -04:00
Bailey Dixon ea2110fa14 chore: refresh Secure Link integration from dev 2026-09-23 09:49:27 -04:00
Bailey Dixon 43357a387d fix: enforce the combined Secure Link transport contract 2026-09-23 09:48:56 -04:00
Bailey Dixon 336475e451 Merge remote-tracking branch 'origin/dev' into codex/fix-appearance-cold-start
# Conflicts:
#	CHANGELOG.md
2026-09-23 09:40:55 -04:00
Bailey Dixon 13492610a8 Merge pull request #622 from Codename-11/fix/android-gateway-onboarding
fix(android): clarify Gateway onboarding and HTTP consent
2026-09-23 09:39:06 -04:00
Bailey Dixon 4e75564d33 fix: integrate Android Secure Link transport 2026-09-23 09:29:34 -04:00
Bailey Dixon 50adab99fa fix: integrate Secure Link proxy contract 2026-09-23 09:29:16 -04:00
Bailey Dixon 284f19d62d Merge origin/dev into fix/android-gateway-onboarding 2026-09-23 09:29:13 -04:00
Bailey Dixon 1302da4846 Merge pull request #623 from Codename-11/fix/android-onnxruntime-compatibility
fix(android): restore Sherpa ONNX compatibility
2026-09-23 09:28:39 -04:00
Bailey Dixon dc8e076836 fix(android): hydrate appearance before first frame 2026-09-23 09:26:30 -04:00
Bailey Dixon ce5f9c7c98 fix(android): restore Sherpa ONNX compatibility 2026-09-23 09:16:33 -04:00
Bailey Dixon ad4e9d7b81 Merge origin/dev into fix/android-gateway-onboarding 2026-09-23 08:50:52 -04:00
Bailey Dixon 774ab90ad5 fix(android): clarify Gateway onboarding 2026-09-23 08:50:40 -04:00
ophirhan b296b56bce fix(android): remove forceDarkAllowed from base values theme
Companion to values-v29 override; clears lint NewApi on minSdk 26.
2026-09-22 22:39:31 +03:00
ophirhan a74ad0738f fix(android): gate forceDarkAllowed behind values-v29
Lint NewApi: android:forceDarkAllowed needs API 29; minSdk is 26.
Keep base Theme.HermesRelay in values/ and disable OEM force-dark only
on API 29+.
2026-09-22 22:39:02 +03:00
ophirhan 6bb186ee2b docs(android): changelog Appearance cold-start night mode lock 2026-09-22 22:14:32 +03:00
ophirhan db4a6f37c7 docs(android): changelog Secure Link pin path; scrub test fixture hosts
Use existing 192.168.1.x examples in presentation tests (no personal LAN).
2026-09-22 22:04:17 +03:00
ophirhan 0f19deae7f fix(android): pin Secure Link only in TrustManager, not CertificatePinner
OkHttp CertificatePinner can fail with an empty peer chain after the custom
TrustManager already accepted the paired SPKI (OEM stacks). That surfaces as
Certificate pinning failure / TLS failed — server may be http:// while the
Mac live pin still matches.
2026-09-22 22:00:52 +03:00
ophirhan fa2d17338d fix(android): Secure Link pin path for HTTP probes, routes UI, gateway WS
Carry pairing SPKI pin through Relay HTTP/voice probes, LAN endpoint
resolution, Secure Link route labels, and GatewayChatClient upgrades so
self-signed Secure Link stays healthy beyond the WSS path alone.
2026-09-22 22:00:45 +03:00
ophirhan bc2f2b0010 fix(android): lock night mode to Appearance on cold start
DayNight followed system/OEM force-dark while DataStore still said Light,
so the UI opened dark until the mode control was toggled. Apply
AppCompatDelegate from the saved preference before first frame and disable
force-dark on the activity theme.
2026-09-22 16:01:35 +03:00
ophirhan dcc8d54916 fix(plugin): make Secure Link proxy usable for Gateway chat and login
Preserve WebSocket query strings (auth tickets) when proxying dashboard
and Gateway sockets, disable nested permessage-deflate on the upstream
leg, scope dashboard login HTML/JSON and redirects under /dashboard
without double-prefixing, register bare /api and /dashboard routes, and
include version on /relay/health for route probes.
2026-09-22 14:40:45 +03:00
dependabot[bot] a1cc34e649 chore(deps): bump com.microsoft.onnxruntime:onnxruntime-android (#613)
Bumps [com.microsoft.onnxruntime:onnxruntime-android](https://github.com/microsoft/onnxruntime) from 1.27.0 to 1.30.0.
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](https://github.com/microsoft/onnxruntime/compare/v1.27.0...v1.30.0)

---
updated-dependencies:
- dependency-name: com.microsoft.onnxruntime:onnxruntime-android
  dependency-version: 1.30.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 11:57:05 +00:00
dependabot[bot] 47e27f6ac9 chore(deps): bump com.android.application from 9.4.0 to 9.4.1
Bumps com.android.application from 9.4.0 to 9.4.1.

---
updated-dependencies:
- dependency-name: com.android.application
  dependency-version: 9.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-21 11:56:56 +00:00
dependabot[bot] e7f882f8b5 chore(deps): bump coil from 3.6.2 to 3.6.3 (#611)
Bumps `coil` from 3.6.2 to 3.6.3.

Updates `io.coil-kt.coil3:coil-compose` from 3.6.2 to 3.6.3
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.2...3.6.3)

Updates `io.coil-kt.coil3:coil-gif` from 3.6.2 to 3.6.3
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.2...3.6.3)

Updates `io.coil-kt.coil3:coil-network-okhttp` from 3.6.2 to 3.6.3
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.2...3.6.3)

---
updated-dependencies:
- dependency-name: io.coil-kt.coil3:coil-compose
  dependency-version: 3.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.coil-kt.coil3:coil-gif
  dependency-version: 3.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.coil-kt.coil3:coil-network-okhttp
  dependency-version: 3.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-21 11:56:31 +00:00
dependabot[bot] 5e53d5cfd1 chore(deps): bump com.android.library from 9.4.0 to 9.4.1
Bumps com.android.library from 9.4.0 to 9.4.1.

---
updated-dependencies:
- dependency-name: com.android.library
  dependency-version: 9.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-21 11:56:23 +00:00
AYin-Z b21b9c225c fix(desktop): grant tray capability to the notice and evidence windows
The tray capability listed only main and grant while tauri.conf.json declares four windows: main, grant, notice and evidence. The notice and evidence windows are created with decorations:false and dismiss themselves through the core window API, so without the capability their close controls and auto-hide timers are rejected - silently, because the callers use void on the promise.

Closes #606.
2026-09-19 20:58:07 +08:00
Bailey Dixon 971a9a7e39 Merge pull request #605 from Codename-11/fix/android-gateway-foreground-start
fix(android): settle Gateway foreground starts before stopping
2026-09-18 20:46:18 -04:00
Bailey Dixon 635aaa44e7 fix(android): settle Gateway foreground starts before stopping 2026-09-18 17:09:41 -04:00
Bailey Dixon e088469dbf Merge pull request #602 from Codename-11/fix/545-standard-voice-completions
fix(android): speak unsolicited Gateway completions in Standard Voice
2026-09-18 16:23:21 -04:00
Bailey Dixon 2d202bdeac test(android): await Gateway recovery and catalog callbacks 2026-09-14 20:31:02 -04:00
Bailey Dixon 798441c1e1 fix(android): speak unsolicited Gateway completions in Standard Voice 2026-09-14 20:15:35 -04:00
Bailey Dixon b424678f44 Merge pull request #601 from Codename-11/release/android-1.17.0-plugin-1.11.3
docs: confirm Android 1.17.0 Play publication
2026-09-14 16:31:22 -04:00
Bailey Dixon d5210bcd5e docs: confirm Android 1.17.0 Play publication 2026-09-14 16:27:42 -04:00
Bailey Dixon 6458a854a8 chore: refresh release publication record 2026-09-14 16:27:40 -04:00
Bailey Dixon 65fe37a2ba Merge pull request #600 from Codename-11/release/android-1.17.0-plugin-1.11.3
docs: record Android 1.17.0 and Plugin 1.11.3 verification
2026-09-14 16:12:52 -04:00
Bailey Dixon 9ac10cf645 docs: record Android and Plugin release verification 2026-09-14 16:11:10 -04:00
Bailey Dixon bd904e26e4 chore: refresh release documentation against dev 2026-09-14 16:11:07 -04:00
dependabot[bot] ba5a2c82a5 chore(deps): bump kotlin from 2.4.10 to 2.4.20 (#597)
Bumps `kotlin` from 2.4.10 to 2.4.20.

Updates `org.jetbrains.kotlin.plugin.compose` from 2.4.10 to 2.4.20
- [Release notes](https://github.com/JetBrains/kotlin/releases)
- [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md)
- [Commits](https://github.com/JetBrains/kotlin/compare/v2.4.10...v2.4.20)

Updates `org.jetbrains.kotlin.plugin.serialization` from 2.4.10 to 2.4.20
- [Release notes](https://github.com/JetBrains/kotlin/releases)
- [Changelog](https://github.com/JetBrains/kotlin/blob/master/ChangeLog.md)
- [Commits](https://github.com/JetBrains/kotlin/compare/v2.4.10...v2.4.20)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlin.plugin.compose
  dependency-version: 2.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.jetbrains.kotlin.plugin.serialization
  dependency-version: 2.4.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 12:07:03 +00:00
dependabot[bot] 6119f3ba79 chore(deps): bump androidx.navigation:navigation-compose (#596)
Bumps androidx.navigation:navigation-compose from 2.10.0 to 2.10.1.

---
updated-dependencies:
- dependency-name: androidx.navigation:navigation-compose
  dependency-version: 2.10.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 12:02:29 +00:00
dependabot[bot] 2bcdca09e9 chore(deps): bump org.robolectric:robolectric from 4.16.1 to 4.17 (#599)
Bumps [org.robolectric:robolectric](https://github.com/robolectric/robolectric) from 4.16.1 to 4.17.
- [Release notes](https://github.com/robolectric/robolectric/releases)
- [Commits](https://github.com/robolectric/robolectric/compare/robolectric-4.16.1...robolectric-4.17)

---
updated-dependencies:
- dependency-name: org.robolectric:robolectric
  dependency-version: '4.17'
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 12:00:57 +00:00
dependabot[bot] e2e9cc72b7 chore(deps): bump media3 from 1.11.0 to 1.11.1 (#598)
Bumps `media3` from 1.11.0 to 1.11.1.

Updates `androidx.media3:media3-exoplayer` from 1.11.0 to 1.11.1
- [Release notes](https://github.com/androidx/media/releases)
- [Changelog](https://github.com/androidx/media/blob/release/RELEASENOTES.md)
- [Commits](https://github.com/androidx/media/compare/1.11.0...1.11.1)

Updates `androidx.media3:media3-ui-compose` from 1.11.0 to 1.11.1
- [Release notes](https://github.com/androidx/media/releases)
- [Changelog](https://github.com/androidx/media/blob/release/RELEASENOTES.md)
- [Commits](https://github.com/androidx/media/compare/1.11.0...1.11.1)

---
updated-dependencies:
- dependency-name: androidx.media3:media3-exoplayer
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: androidx.media3:media3-ui-compose
  dependency-version: 1.11.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 12:00:05 +00:00
dependabot[bot] ca555fd617 chore(deps): bump the testing group with 2 updates (#595)
Bumps the testing group with 2 updates: [io.github.takahirom.roborazzi:roborazzi](https://github.com/takahirom/roborazzi) and [io.github.takahirom.roborazzi:roborazzi-compose](https://github.com/takahirom/roborazzi).


Updates `io.github.takahirom.roborazzi:roborazzi` from 1.73.0 to 1.74.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.73.0...1.74.0)

Updates `io.github.takahirom.roborazzi:roborazzi-compose` from 1.73.0 to 1.74.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.73.0...1.74.0)

---
updated-dependencies:
- dependency-name: io.github.takahirom.roborazzi:roborazzi
  dependency-version: 1.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
- dependency-name: io.github.takahirom.roborazzi:roborazzi-compose
  dependency-version: 1.74.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 11:56:01 +00:00
dependabot[bot] 3b5e61e149 chore(deps): bump androidx.compose:compose-bom in the compose group (#594)
Bumps the compose group with 1 update: androidx.compose:compose-bom.


Updates `androidx.compose:compose-bom` from 2026.08.00 to 2026.09.00

---
updated-dependencies:
- dependency-name: androidx.compose:compose-bom
  dependency-version: 2026.09.00
  dependency-type: direct:production
  dependency-group: compose
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-14 11:55:18 +00:00
Bailey Dixon 1d25985aca Merge pull request #592 from Codename-11/release/android-1.17.0-play-notes
release(android): reconcile Chinese Play notes for 1.17.0
2026-09-13 21:38:29 -04:00
Bailey Dixon 500cc83de6 release(android): reconcile Chinese Play notes for 1.17.0 2026-09-13 21:26:31 -04:00
Bailey Dixon 7d3c761c6a Merge pull request #590 from Codename-11/release/android-1.17.0-plugin-1.11.3
release: prepare Android 1.17.0 and Plugin 1.11.3
2026-09-13 21:25:20 -04:00
Bailey Dixon 2e097035fb release(android): android-v1.17.0 and server-v1.11.3 2026-09-13 21:14:30 -04:00
Bailey Dixon 280c20dbca Merge pull request #585 from Codename-11/fix/android-batch-clarify
fix(android): support batch Clarify and simplify chat cards
2026-09-13 20:33:18 -04:00
Bailey Dixon 86a570e72d chore: refresh chat UI cleanup against dev 2026-09-13 20:13:40 -04:00
Bailey Dixon cbe811fb52 fix(android): simplify chat bubble surfaces and footers 2026-09-13 20:13:15 -04:00
Bailey Dixon ac2508c5ce Merge pull request #588 from Codename-11/fix/android-gateway-context-audit
fix(android): show Gateway context-sharing limitations
2026-09-13 16:04:24 -04:00
Bailey Dixon 2ad7de4cc9 fix(android): make injected context previews transport-aware 2026-09-13 13:36:50 -04:00
Bailey Dixon 5eb5d198f4 chore: refresh batch Clarify against current dev 2026-09-13 13:29:57 -04:00
Bailey Dixon 7a86b9cee7 Merge pull request #583 from nicolasestrem/fix/dashboard-ws-guard-compat
fix(dashboard): resolve relocated upstream WebSocket guards
2026-09-12 20:14:26 -04:00
Bailey Dixon 60f93994f5 chore: merge current dev into dashboard WebSocket guard fix 2026-09-12 20:12:06 -04:00
Bailey Dixon 52e0e38a81 chore: merge current dev into batch Clarify fix 2026-09-12 20:11:40 -04:00
Bailey Dixon 471595240b Merge pull request #584 from Codename-11/feature/play-voice-overlay
feat(android): add user-started Play voice overlay
2026-09-12 20:03:40 -04:00
Bailey Dixon 061512d330 fix(android): support upstream batch Clarify requests 2026-09-12 19:59:06 -04:00
Bailey Dixon 1c59f44ad7 fix(website): ignore release-only screenshot metadata drift 2026-09-12 19:53:48 -04:00
Bailey Dixon 269a2b5b36 fix(android): enforce revocation before voice handoff 2026-09-12 18:02:58 -04:00
Bailey Dixon a6879aac6f fix(android): fit overlay actions at large font sizes 2026-09-12 17:43:45 -04:00
Bailey Dixon a04930c946 feat(android): add user-started Play voice overlay 2026-09-12 17:43:01 -04:00
Bailey Dixon b71fea701f Merge pull request #581 from Codename-11/fix/android-profile-default-identity
fix(android): resolve profile identity and group server default
2026-09-12 16:54:23 -04:00
nicolasestrem af54cdddb3 fix(dashboard): resolve relocated upstream WebSocket guards
Preserve fail-closed admission and legacy compatibility. Add regression and real-upstream conformance tests plus transport documentation.
2026-09-12 18:21:33 +02:00
Bailey Dixon a717278e95 fix(android): guard unresolved profile assets and verify identity controls 2026-09-12 09:49:09 -04:00
Bailey Dixon 19d5237ebb chore: merge current dev into profile identity fix
# Conflicts:
#	CHANGELOG.md
2026-09-12 09:28:56 -04:00
Bailey Dixon 6fbb21f437 fix(android): resolve profile display identity and group server default 2026-09-12 09:28:33 -04:00
Bailey Dixon c7f54321ad Merge pull request #579 from Codename-11/release/android-1.16.1
release(android): android-v1.16.1
2026-09-12 09:26:59 -04:00
Bailey Dixon e6b9933d46 release(android): android-v1.16.1 2026-09-12 09:17:51 -04:00
Bailey Dixon c27ee439ef Merge pull request #578 from Codename-11/fix/android-gateway-directory-bootstrap
fix(android): release Gateway directory bootstrap
2026-09-12 08:55:33 -04:00
Bailey Dixon 68fce1b1da fix(android): release gateway directory bootstrap 2026-09-10 20:07:41 -04:00
Bailey Dixon 4547031bba Merge pull request #576 from Codename-11/docs/release-date-2026-09-10
docs(release): correct 1.16.0 and 1.11.2 dates
2026-09-10 09:52:19 -04:00
Bailey Dixon 41e9acf4c2 docs(release): correct 1.16.0 and 1.11.2 dates 2026-09-10 09:43:58 -04:00
Bailey Dixon a5f671c06c Merge pull request #575 from Codename-11/dev
release: Android 1.16.0 and Plugin 1.11.2
2026-09-10 09:33:47 -04:00
Bailey Dixon 5372fc1fef Merge pull request #574 from Codename-11/release/android-1.16.0
release(android): android-v1.16.0
2026-09-09 22:44:43 -04:00
Bailey Dixon 6c5ecbb028 release(android): android-v1.16.0 2026-09-09 22:32:25 -04:00
Bailey Dixon bd5a1c3335 Merge pull request #573 from Codename-11/release/plugin-1.11.2
release(server): server-v1.11.2
2026-09-09 22:25:27 -04:00
Bailey Dixon 2c740c9f04 release(server): server-v1.11.2 2026-09-09 22:23:26 -04:00
Bailey Dixon 3ec89680ed Merge pull request #572 from Codename-11/fix/android-endpoint-cache-race
fix(android): serialize endpoint probe invalidation
2026-09-09 22:04:10 -04:00
Bailey Dixon 42860d38cd chore: merge queued Android fixes for endpoint verification 2026-09-09 21:49:24 -04:00
Bailey Dixon ef4b3bdb6c Merge pull request #571 from Codename-11/fix/android-gateway-cold-start
fix(android): wake gateway on cold foreground
2026-09-09 21:48:53 -04:00
Bailey Dixon 44bbb16cd3 chore: merge current dev before gateway startup integration 2026-09-09 21:35:37 -04:00
Bailey Dixon 1f5b7e68fc Merge pull request #570 from Codename-11/fix/android-basic-auth-paste
fix(android): normalize pasted dashboard credentials
2026-09-09 21:35:00 -04:00
Bailey Dixon 4bb8d6fa7b chore: merge current dev for endpoint invalidation verification 2026-09-09 21:20:42 -04:00
Bailey Dixon 6395e73927 Merge remote-tracking branch 'origin/dev' into fix/android-basic-auth-paste
# Conflicts:
#	CHANGELOG.md
2026-09-09 21:20:33 -04:00
Bailey Dixon c956232b96 fix(android): serialize endpoint probe invalidation 2026-09-09 21:20:16 -04:00
Bailey Dixon 9814cdca55 chore: merge current dev for gateway startup verification 2026-09-09 21:17:51 -04:00
Bailey Dixon 0c337c9384 Merge pull request #569 from Codename-11/fix/plugin-availability-probe
fix(plugin): share relay availability checks
2026-09-09 21:06:46 -04:00
Bailey Dixon 273e3f5aff fix(android): wake gateway on cold foreground 2026-09-09 21:05:02 -04:00
Bailey DixonandJack Hunzicker 179080d6d9 fix(plugin): share relay availability checks
Co-authored-by: Jack Hunzicker <JackHunzicker@users.noreply.github.com>
2026-09-09 20:57:22 -04:00
Bailey Dixon ac1f42b7d5 Merge remote-tracking branch 'origin/dev' into fix/android-basic-auth-paste
# Conflicts:
#	CHANGELOG.md
2026-09-09 20:21:19 -04:00
Bailey Dixon 88591fca89 fix(android): normalize pasted dashboard credentials
Refs #541
2026-09-09 20:20:48 -04:00
Bailey Dixon 00c5f5daa2 Merge pull request #566 from trevornk/fix/connection-owned-dashboard-auth
fix(android): bind dashboard auth to connection-owned routes
2026-09-09 20:14:28 -04:00
Bailey Dixon 69b6c005cd chore: merge current dev for dashboard auth verification 2026-09-09 19:50:39 -04:00
Bailey Dixon c902215a15 Merge pull request #560 from JackHunzicker/contrib/git-state-callback-test-order
test(android): await git commit success callback
2026-09-09 19:37:25 -04:00
Bailey Dixon d39368bc51 Merge pull request #568 from Codename-11/fix/470-bot-mode-list-identity
fix(android): prevent duplicate Bot Mode keys across connections
2026-09-09 19:34:28 -04:00
Bailey Dixon 414dc08b9f Merge branch 'dev' into contrib/git-state-callback-test-order 2026-09-09 19:28:12 -04:00
Bailey Dixon 3b78a17bd7 chore: merge current dev for Bot Mode verification 2026-09-09 19:22:10 -04:00
Bailey Dixon a5efb9ec96 fix(android): scope Bot Mode item identity to connection and profile 2026-09-09 19:21:34 -04:00
Bailey Dixon e5228f2089 Merge pull request #567 from Codename-11/fix/android-detached-subagent-preview
fix(android): preserve chat activity and correct feedback ownership
2026-09-09 17:18:15 -04:00
Bailey Dixon c738a2c2c0 chore: merge current dev before activity integration 2026-09-09 17:05:38 -04:00
Bailey Dixon 8ed6b35e76 Merge pull request #555 from Codename-11/dependabot/gradle/dev/com.android.library-9.4.0
chore(deps): bump com.android.library from 9.3.2 to 9.4.0
2026-09-09 17:02:23 -04:00
Bailey Dixon c6d4a15226 Merge pull request #552 from Codename-11/dependabot/github_actions/dev/actions/cache-6
chore(deps): bump actions/cache from 5 to 6
2026-09-09 16:59:59 -04:00
Bailey Dixon 22c8f76c72 fix(android): preserve chat activity and correct feedback ownership 2026-09-09 16:57:40 -04:00
Bailey Dixon a0161f51ef Merge origin/dev into dependabot/gradle/dev/com.android.library-9.4.0 2026-09-09 16:52:49 -04:00
Bailey Dixon 7aa3b1c697 test(ci): align cache contract with v6 2026-09-09 16:49:59 -04:00
Bailey Dixon e7112dda9e Merge origin/dev into dependabot/github_actions/dev/actions/cache-6 2026-09-09 16:49:26 -04:00
trevornk c1413c494f fix(android): bind dashboard auth to connection-owned routes
Refs #565
2026-09-09 11:44:14 -05:00
Jack bb23e6ab48 test(android): await git commit success callback
Mutation success is published before detail refresh finishes and the callback runs. Await callback delivery explicitly instead of treating the state flow as a callback-completion barrier.

Signed-off-by: Jack <JLHunzicker@gmail.com>
2026-09-07 22:27:56 -05:00
dependabot[bot] 816638b46a chore(deps): bump com.android.library from 9.3.2 to 9.4.0
Bumps com.android.library from 9.3.2 to 9.4.0.

---
updated-dependencies:
- dependency-name: com.android.library
  dependency-version: 9.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-07 11:56:52 +00:00
dependabot[bot] df0fe59b0b chore(deps): bump coil from 3.6.0 to 3.6.2 (#554)
Bumps `coil` from 3.6.0 to 3.6.2.

Updates `io.coil-kt.coil3:coil-compose` from 3.6.0 to 3.6.2
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.0...3.6.2)

Updates `io.coil-kt.coil3:coil-gif` from 3.6.0 to 3.6.2
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.0...3.6.2)

Updates `io.coil-kt.coil3:coil-network-okhttp` from 3.6.0 to 3.6.2
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.6.0...3.6.2)

---
updated-dependencies:
- dependency-name: io.coil-kt.coil3:coil-compose
  dependency-version: 3.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.coil-kt.coil3:coil-gif
  dependency-version: 3.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.coil-kt.coil3:coil-network-okhttp
  dependency-version: 3.6.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-07 11:56:33 +00:00
dependabot[bot] df4d4c8f2a chore(deps): bump com.android.application from 9.3.2 to 9.4.0 (#553)
Bumps com.android.application from 9.3.2 to 9.4.0.

---
updated-dependencies:
- dependency-name: com.android.application
  dependency-version: 9.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-09-07 11:56:21 +00:00
dependabot[bot] 398ad253f1 chore(deps): bump actions/cache from 5 to 6
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](https://github.com/actions/cache/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-09-07 11:54:44 +00:00
Bailey Dixon ad4bbb2c86 Merge pull request #543 from nicolasestrem/fix/android-bridge-token-fallback-final
fix(plugin): resolve bridge token after host startup
2026-09-03 21:28:08 -04:00
Bailey Dixon 7c5894213d fix(plugin): harden bridge credential recovery 2026-09-03 20:53:19 -04:00
nicolasestrem 82c088aa89 test(plugin): remove trailing blank line 2026-09-03 22:40:30 +02:00
nicolasestrem ed599995d6 fix(plugin): resolve bridge token from disk and make android_setup callable
Every android_* tool returned `401 Client Error: Unauthorized` on a phone
that was paired, connected and healthy (`/bridge/status` reported
phone_connected: true, accessibility_granted: true).

Cause: `_bridge_token()` read ANDROID_BRIDGE_TOKEN from the process
environment only. The env is snapshotted when the host starts, so a token
written afterwards — by `android_setup`, by `hermes-pair`, or by hand —
stayed invisible and `_require_bearer_session` rejected every bridge
dispatch until a full restart.

Resolution order is now env -> ~/.hermes/.env -> most-recently-seen paired
session in ~/.hermes/hermes-relay-sessions.json, with the disk fallbacks
cached for 30s so we don't stat two files on every bridge call. The process
environment still wins when set, and HERMES_HOME is honoured.

The documented recovery path was itself broken: android_setup's schema
required `pairing_code` while the signature had been renamed to
`bridge_session_token`, and the dispatcher calls func(**call_args) — so the
schema-conformant call raised TypeError and the canonical one was rejected
by the validator. The tool could not be invoked at all. Both spellings are
now accepted (canonical wins), neither is schema-required, a missing token
returns a structured error, and the description no longer mislabels the
value as a "6-character pairing code" or claims the tool performs pairing.

Also pin TestSetup to a temporary home. It exercises the real
android_setup, which persists ANDROID_BRIDGE_* to ~/.hermes/.env — running
the suite on a real host overwrote the machine's live paired session token
with a fixture value.

Verified: 43 passed (test_android_tool.py + test_android_tool_device_selector.py),
and against the physical device with ANDROID_BRIDGE_TOKEN unset from the
environment — /ping and /current_app both 200 via the new disk fallback.
2026-09-03 22:40:30 +02:00
Bailey Dixon 75feb55adf Merge pull request #540 from Codename-11/dev
release: Android 1.15.1 and CLI+UI 0.4.0-beta.7
2026-09-02 22:02:09 -04:00
Bailey Dixon e20540d16f Merge pull request #539 from Codename-11/release/patch-2026-09-02
release: prepare Android 1.15.1 and CLI+UI 0.4.0-beta.7
2026-09-02 21:43:43 -04:00
Bailey Dixon c932adbc7b release(desktop): desktop-v0.4.0-beta.7 2026-09-02 21:34:28 -04:00
Bailey Dixon 23cec497ce release(android): android-v1.15.1 2026-09-02 21:34:28 -04:00
Bailey Dixon 1739dc36a2 Merge pull request #538 from Codename-11/fix/android-voice-error-dialog
fix(android): polish voice errors and steer/queue controls
2026-09-02 21:21:05 -04:00
Bailey Dixon c917a94fcb fix(android): polish voice errors and steer/queue controls 2026-09-02 21:09:32 -04:00
Bailey Dixon e1a72ee8af Merge pull request #537 from Codename-11/fix/android-session-refresh-oom
fix(android): harden chat sessions and media rendering
2026-09-02 13:49:02 -04:00
Bailey Dixon 94f9ba4305 fix(android): harden chat sessions and media rendering 2026-09-02 13:34:14 -04:00
Bailey Dixon 3186afdde8 Merge pull request #536 from Codename-11/fix/android-attachment-viewer-rotation-salvage
fix(android): preserve attachment previews across rotation
2026-09-02 06:59:34 -04:00
Bailey Dixon 0261a342cf merge: refresh attachment viewer salvage from dev
# Conflicts:
#	CHANGELOG.md
2026-09-01 22:16:20 -04:00
Bailey DixonandYuzhe Wang f4c212f800 fix(android): preserve attachment previews across rotation
Hoist full-screen media viewers above transcript rows so responsive portrait/landscape reflow cannot dismiss an active image, attachment, or gallery preview. Reset the host when its connection, session, or policy owner changes.

Render video through Media3's fitted Compose content frame, retain playback position and controls across player recreation, and respect the user's system rotation preference.

Add focused state-restoration and viewer-host coverage for attachments, images, galleries, and owner changes.

Co-authored-by: Yuzhe Wang <o_xkenshin@icloud.com>
2026-09-01 22:15:56 -04:00
Bailey Dixon 3bb294c6c3 Merge pull request #535 from Codename-11/fix/android-sherpa-r8-jni
fix(android): preserve sherpa JNI names through R8
2026-09-01 22:03:15 -04:00
Bailey Dixon dc73cc74b1 Merge remote-tracking branch 'origin/dev' into fix/android-sherpa-r8-jni 2026-09-01 21:52:27 -04:00
Bailey Dixon 607bc95b73 Merge chore/repository-organization-20260901 into integration/repository-organization-20260901 2026-09-01 21:47:50 -04:00
Bailey Dixon 3b4da0305e docs: organize project records 2026-09-01 21:37:16 -04:00
Bailey Dixon 3af0092b8f Merge remote-tracking branch 'origin/dev' into fix/android-sherpa-r8-jni
# Conflicts:
#	CHANGELOG.md
2026-09-01 21:14:38 -04:00
Bailey DixonandMattyB01 9cfa4c8b8c fix(android): preserve sherpa JNI names through R8
Co-authored-by: MattyB01 <141138642+MattyB01@users.noreply.github.com>
2026-09-01 21:14:15 -04:00
Bailey Dixon a7c860a2e3 Merge pull request #532 from Codename-11/fix/android-stream-dashboard-media
fix(android): stream dashboard media to disk
2026-09-01 21:02:39 -04:00
Bailey Dixon ed71b02b01 Merge remote-tracking branch 'origin/dev' into fix/android-stream-dashboard-media
# Conflicts:
#	CHANGELOG.md
2026-09-01 19:25:15 -04:00
Bailey Dixon a90dc85466 Merge pull request #533 from Codename-11/fix/android-gateway-owner-rejection
fix(android): wait for gateway session readiness
2026-09-01 19:08:41 -04:00
Bailey Dixon 67a60143cb fix(android): wait for gateway session readiness 2026-09-01 18:50:46 -04:00
Bailey Dixon c3276fa7e5 chore: quarantine Quest experiment 2026-09-01 18:17:22 -04:00
Bailey Dixon 99ac20de35 fix(android): stream dashboard media to disk 2026-09-01 13:06:15 -04:00
Bailey Dixon 0650102230 docs: organize localized readme entrypoints 2026-09-01 12:19:03 -04:00
Bailey Dixon 8d4f324717 feat(release): promote exact-tree artifacts and CI evidence (#530) 2026-09-01 11:00:43 -04:00
Bailey Dixon c9ee5348bf Merge origin/dev into feature/release-fast-path 2026-09-01 10:40:01 -04:00
Bailey Dixon ee2a7840a2 test(android): generalize release notice coverage 2026-09-01 10:39:40 -04:00
Bailey Dixon 52dd399565 Merge docs/refine-readme-connection-map-teknium into integration/readme-connection-map-refinement-20260901 2026-09-01 10:38:01 -04:00
Bailey Dixon 86a0421163 docs(release): record tray cache reuse 2026-09-01 10:37:54 -04:00
Bailey Dixon 0e191f946d fix(marketing): refine README connection graphic 2026-09-01 10:37:40 -04:00
Bailey Dixon 065912f2bf fix(release): keep coordinated approval stable-only 2026-09-01 10:37:30 -04:00
Bailey Dixon 075138433e fix(release): report promoted Android signing 2026-09-01 10:35:57 -04:00
Bailey Dixon 92e65bbfc2 Merge origin/dev into feature/release-fast-path
# Conflicts:
#	DEVLOG.md
2026-09-01 10:34:23 -04:00
Bailey Dixon 7ccd4ac4c9 docs(release): document exact-tree promotion 2026-09-01 10:33:49 -04:00
Bailey Dixon 5739e17750 test(ci): cover release fast paths 2026-09-01 10:33:49 -04:00
Bailey Dixon 037f4e91c8 ci(desktop): cache exact tray builds 2026-09-01 10:33:39 -04:00
Bailey Dixon 685c3c5a24 test(android): derive release presentation expectations 2026-09-01 10:33:30 -04:00
Bailey Dixon 6dc18abc4d ci(release): reuse exact-tree verification 2026-09-01 10:33:21 -04:00
Bailey Dixon ee43a87cec feat(release): promote verified Android artifacts 2026-09-01 10:33:09 -04:00
Bailey Dixon ce961b81d9 Merge pull request #529 from Codename-11/fix/desktop-unified-updater
fix(desktop): keep CLI and UI updates in sync
2026-09-01 10:32:16 -04:00
Bailey Dixon c7b392b26f test(desktop): honor injected updater platform 2026-09-01 10:14:52 -04:00
Bailey Dixon 0a04efbbcf chore: merge origin/dev into fix/desktop-unified-updater 2026-09-01 10:09:49 -04:00
Bailey Dixon 11977dad56 fix(release): validate extension tags before creation (#527) 2026-09-01 08:08:37 -04:00
Bailey Dixon c8fea9c061 Merge origin/dev into fix/release-tag-approval 2026-09-01 07:58:08 -04:00
Bailey Dixon b0a8909dc7 Merge pull request #522 from Codename-11/fix/android-tablet-chat-layout
fix(android): adapt Chat and Voice for tablets
2026-09-01 07:56:37 -04:00
Bailey Dixon 57c236e7da fix(release): validate extension tags before creation 2026-09-01 07:48:58 -04:00
Bailey Dixon 8156a821eb chore: refresh tablet layout branch from origin/dev
# Conflicts:
#	CHANGELOG.md
2026-09-01 07:38:43 -04:00
Bailey Dixon b015acb063 fix(desktop): keep CLI and UI updates in sync 2026-09-01 07:18:19 -04:00
Bailey Dixon f4b366389b release: Android 1.15.0, Plugin 1.11.1, CLI+UI 0.4.0-beta.6 (#525) 2026-08-31 23:45:58 -04:00
Bailey Dixon e6368dada8 release: Android 1.15.0, Plugin 1.11.1, CLI+UI 0.4.0-beta.6 (#524) 2026-08-31 23:23:05 -04:00
Bailey Dixon e55662e0e1 test(android): align release presentation coverage 2026-08-31 23:11:10 -04:00
Bailey Dixon 051844bc14 release(desktop): desktop-v0.4.0-beta.6 2026-08-31 22:30:34 -04:00
Bailey Dixon 1e5ce986be release(server): server-v1.11.1 2026-08-31 22:30:34 -04:00
Bailey Dixon 06b24631e3 release(android): android-v1.15.0 2026-08-31 22:30:34 -04:00
Bailey Dixon 2d2e54ba79 Merge pull request #523 from Codename-11/feature/upstream-first-media
feat(android): prefer upstream standard surfaces
2026-08-31 22:16:38 -04:00
Bailey Dixon ee59149b41 Merge origin/dev into feature/upstream-first-media
# Conflicts:
#	README.md
2026-08-31 21:41:37 -04:00
Bailey Dixon 23a6231b20 chore: restore localized docs metadata 2026-08-31 21:41:02 -04:00
Bailey Dixon a4fac4550a chore: complete localization refresh 2026-08-31 21:40:48 -04:00
Bailey Dixon 88ab48cfc0 chore: refresh localization metadata 2026-08-31 21:39:51 -04:00
Bailey Dixon 7c03f8554f Merge docs/readme-marketing-hero into integration/readme-marketing-visuals-20260831 2026-08-31 21:39:07 -04:00
Bailey Dixon 367e5d271c Merge origin/dev into feature/upstream-first-media
# Conflicts:
#	CHANGELOG.md
#	README.md
#	docs/localization-status.json
#	docs/upstream-surface-matrix.md
#	user-docs/features/connections.md
#	user-docs/features/index.md
#	user-docs/guide/index.md
#	user-docs/guide/remote-access.md
#	user-docs/reference/configuration.md
2026-08-31 21:39:05 -04:00
Bailey Dixon 47a395ab76 feat(marketing): refresh README and store visuals 2026-08-31 21:38:45 -04:00
Bailey Dixon e7cbed3c8f feat(android): prefer upstream standard surfaces 2026-08-31 21:36:18 -04:00
Bailey Dixon 2f7bd843bc docs: note Android tablet layout improvements 2026-08-31 21:32:50 -04:00
Bailey Dixon d1527d47e4 chore: refresh tablet layout branch from origin/dev 2026-08-31 21:00:44 -04:00
Bailey Dixon bc0853360a fix(android): adapt chat and voice for tablets 2026-08-31 21:00:07 -04:00
Bailey Dixon b72ab5aef2 Merge pull request #521 from Codename-11/fix/android-stale-stream-liveness
fix(android): settle owned streams from live idle state
2026-08-31 20:35:58 -04:00
Bailey Dixon 40fcb80a7d Merge origin/dev into fix/android-stale-stream-liveness
# Conflicts:
#	CHANGELOG.md
#	docs/spec.md
#	docs/upstream-surface-matrix.md
2026-08-31 20:12:08 -04:00
Bailey Dixon ff64548085 fix(android): settle owned streams from live idle state 2026-08-31 20:09:06 -04:00
Bailey Dixon 35362b8895 chore: refresh tablet layout branch from origin/dev 2026-08-31 20:06:05 -04:00
Bailey Dixon ff7ca89b90 fix(android): improve tablet chat layout 2026-08-31 20:06:05 -04:00
Bailey Dixon 042f02b852 Merge pull request #518 from Codename-11/fix/android-passive-session-activity
fix(android): show passive external session activity
2026-08-31 20:04:12 -04:00
Bailey Dixon 5fc85c1699 chore: refresh plugin-only dev tip before merge
# Conflicts:
#	CHANGELOG.md
2026-08-31 19:53:02 -04:00
Bailey Dixon c01c6cf457 Merge pull request #520 from Codename-11/fix/plugin-manifest-installer-compat
fix(plugin): restore native installer compatibility
2026-08-31 19:50:43 -04:00
Bailey Dixon 22780881e1 Merge remote-tracking branch 'origin/dev' into fix/plugin-manifest-installer-compat
# Conflicts:
#	CHANGELOG.md
2026-08-31 19:45:59 -04:00
Bailey Dixon 201e204290 fix(plugin): restore native installer compatibility 2026-08-31 19:45:38 -04:00
Bailey Dixon eb8434e508 chore: refresh chat transport base before passive session activity merge
# Conflicts:
#	CHANGELOG.md
#	docs/spec.md
2026-08-31 19:41:41 -04:00
Bailey Dixon 597b13e2db Merge pull request #515 from Codename-11/fix/android-chat-transport-affinity
fix(android): keep chat transport ownership stable
2026-08-31 19:35:59 -04:00
Bailey Dixon 946b333109 chore: refresh origin/dev before merging passive session activity
# Conflicts:
#	CHANGELOG.md
2026-08-31 19:32:34 -04:00
Bailey Dixon 8b3731b22f chore(android): refresh localization status 2026-08-31 19:20:43 -04:00
Bailey Dixon b76ba7a314 Merge remote-tracking branch 'origin/dev' into fix/android-chat-transport-affinity
# Conflicts:
#	CHANGELOG.md
2026-08-31 18:37:03 -04:00
Bailey Dixon 2c15bd4207 fix(android): clarify gateway connection status 2026-08-31 18:36:25 -04:00
Bailey Dixon 949add15b1 Merge pull request #512 from Codename-11/fix/android-compaction-watchdog
fix(android): preserve gateway turns during context compaction
2026-08-31 17:09:07 -04:00
Bailey Dixon 6a93d13ecb Merge origin/dev into fix/android-compaction-watchdog
# Conflicts:
#	CHANGELOG.md
2026-08-31 16:56:15 -04:00
Bailey Dixon cbc02bb407 Merge pull request #514 from Codename-11/fix/android-emulator-testing
test(android): add on-demand emulator coverage
2026-08-31 16:49:11 -04:00
Bailey Dixon 525f6b5fc0 Merge origin/dev into fix/android-compaction-watchdog 2026-08-31 16:41:54 -04:00
Bailey Dixon 58e8b1edb6 Merge remote-tracking branch 'origin/dev' into fix/android-chat-transport-affinity 2026-08-31 16:37:31 -04:00
Bailey Dixon d42fa91698 Merge remote-tracking branch 'origin/dev' into fix/android-chat-transport-affinity 2026-08-31 16:25:42 -04:00
Bailey Dixon a2be512c45 chore: refresh origin/dev before passive session activity handoff 2026-08-31 16:23:58 -04:00
Bailey Dixon 6a66710763 Merge origin/dev into fix/android-compaction-watchdog 2026-08-31 16:22:08 -04:00
Bailey Dixon 9690071e7d Merge remote-tracking branch 'origin/dev' into fix/android-chat-transport-affinity 2026-08-31 16:07:06 -04:00
Bailey Dixon 698b45cbb3 fix(android): avoid cold-start chat owner crash 2026-08-31 16:05:03 -04:00
Bailey Dixon afa875d89f chore: merge origin/dev into passive session activity fix 2026-08-31 16:02:37 -04:00
Bailey Dixon aff758fb99 fix(android): project passive session activity 2026-08-31 16:00:26 -04:00
Bailey Dixon 8625963846 Merge origin/dev into fix/android-compaction-watchdog 2026-08-31 16:00:20 -04:00
Bailey Dixon e0b726de85 Merge origin/dev into fix/android-compaction-watchdog 2026-08-31 15:51:12 -04:00
Bailey Dixon dbf71a87f4 Merge remote-tracking branch 'origin/dev' into fix/android-chat-transport-affinity 2026-08-31 14:22:36 -04:00
Bailey Dixon 95ed8e6edb fix(android): bind chat conversations to one transport 2026-08-31 14:22:26 -04:00
Bailey Dixon d26bf6c25b Merge origin/dev into fix/android-compaction-watchdog
# Conflicts:
#	DEVLOG.md
2026-08-31 14:10:59 -04:00
Bailey Dixon 181e10f2ad test(android): cover compaction watchdog leases 2026-08-31 14:09:57 -04:00
Bailey Dixon 857a1551f3 Merge origin/dev into fix/android-compaction-watchdog 2026-08-31 13:17:04 -04:00
JackandClaude Opus 5 00052d20d9 watchdog: arm longer leash on compacting status instead of killing silent compaction
Server-side context compaction summarizes the transcript with NO deltas
or tool events flowing until it finishes. Near the context ceiling that
silence routinely exceeds TURN_TIMEOUT_MS (180s), so the idle watchdog
fired session.interrupt on a healthy compression, rolled back its work,
and retriggered on the next prompt — an infinite 'Operation interrupted'
loop that makes near-full sessions permanently unresponsive from mobile.

Observed against a live gateway: four turns killed at exactly
prompt+~251s (visible tool work + 180.0s of silent compaction), server
compression telemetry aborted at 180469/180233/180219ms with
failure_class=explicit_interrupt.

Fix: treat a status.update event with kind 'compacting' like the ask
events that already arm longer leashes (same watchdogTimeoutFor seam):
arm COMPACTING_TIMEOUT_MS (600s) instead of the 180s default. Any
regular event rearms TURN_TIMEOUT_MS as before. Pairs with the gateway
fix that emits periodic compacting heartbeats during compression
(NousResearch/hermes-agent#98371); a single compacting event at
compaction start already engages the longer leash on current gateways.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-31 13:14:35 -04:00
Bailey Dixon 2ec7b7aac9 release: Android 1.14.0 and Plugin 1.11.0 (#490) 2026-08-30 23:50:41 -04:00
568 changed files with 28513 additions and 5384 deletions
+9 -1
View File
@@ -4,6 +4,7 @@ function classifyCiPaths(paths) {
const forceAll = paths.some((path) => [
'.github/workflows/ci-required.yml',
'.github/workflows/release-backmerge.yml',
'.github/workflows/approve-release-train.yml',
'.github/scripts/classify-ci-paths.cjs',
'.github/scripts/classify-ci-paths.test.cjs',
'scripts/plan_release_backmerge.py',
@@ -13,15 +14,18 @@ function classifyCiPaths(paths) {
const under = (prefixes) => paths.some((path) => prefixes.some((prefix) => path.startsWith(prefix)));
return {
android: forceAll || under(['app/', 'relay-core/', 'relay-ui/', 'ui-preview/', 'quest/', 'gradle/']) || exact([
android: forceAll || under(['app/', 'gradle/']) || exact([
'build.gradle.kts', 'settings.gradle.kts', 'gradle.properties', 'gradlew', 'gradlew.bat',
'scripts/check-android-locales.py', 'scripts/android-locale-harness.py',
'scripts/check-android-capabilities.py', 'scripts/tests/check_android_capabilities_test.py',
'scripts/check-android-collection-apis.py', 'scripts/check-android-native-compat.py',
'scripts/check-android-release-notes.py',
'scripts/android_release_artifacts.py',
'scripts/android-lane.ps1', 'scripts/android-prepush.py', 'scripts/dev.bat', 'scripts/dev.sh',
'scripts/tests/android_prepush_test.py',
'scripts/tests/check_android_native_compat_test.py',
'scripts/tests/check_android_release_notes_test.py',
'scripts/tests/android_release_artifacts_test.py',
'.github/workflows/android-on-demand.yml', '.github/workflows/ci-android.yml',
'.github/workflows/play-preflight-android.yml',
'.github/workflows/approve-release-android.yml',
@@ -29,12 +33,16 @@ function classifyCiPaths(paths) {
]),
desktop: forceAll || under(['desktop/']) || exact([
'.github/workflows/ci-desktop.yml',
'.github/workflows/approve-release-extensions.yml',
'.github/workflows/release-cli.yml',
]),
plugin: forceAll || paths.some((path) => /^plugin\/[^/]+\.py$/.test(path)) ||
under(['plugin/relay/', 'plugin/tools/', 'plugin/tests/', 'relay_server/', 'hermes_relay_bootstrap/']) || exact([
'plugin/plugin.yaml', 'pyproject.toml', 'scripts/check-plugin-version-sync.py',
'scripts/check-server-version-sync.py', 'scripts/bump-plugin-version.sh',
'scripts/bump-server-version.sh', '.github/workflows/ci-plugin.yml',
'.github/workflows/approve-release-extensions.yml',
'.github/workflows/release-plugin.yml',
]),
dashboard: forceAll || under(['plugin/dashboard/']) || exact([
'.github/workflows/ci-dashboard.yml',
+83 -1
View File
@@ -1,6 +1,8 @@
'use strict';
const assert = require('node:assert/strict');
const { readFileSync } = require('node:fs');
const { join } = require('node:path');
const { classifyCiPaths } = require('./classify-ci-paths.cjs');
const none = {
@@ -14,9 +16,11 @@ const none = {
assert.deepEqual(classifyCiPaths(['README.md']), none);
assert.deepEqual(classifyCiPaths(['desktop/src/cli.ts']), { ...none, desktop: true });
assert.deepEqual(classifyCiPaths(['relay-core/src/main/kotlin/Wire.kt']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['experiments/quest/src/main/kotlin/Quest.kt']), none);
assert.deepEqual(classifyCiPaths(['scripts/check-android-release-notes.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/check-android-native-compat.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android_release_artifacts.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/android_release_artifacts_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/check_android_native_compat_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-lane.ps1']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-prepush.py']), { ...none, android: true });
@@ -24,6 +28,13 @@ assert.deepEqual(classifyCiPaths(['scripts/dev.bat']), { ...none, android: true
assert.deepEqual(classifyCiPaths(['scripts/dev.sh']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/android_prepush_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/android-on-demand.yml']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/approve-release-extensions.yml']), {
...none,
desktop: true,
plugin: true,
});
assert.deepEqual(classifyCiPaths(['.github/workflows/release-cli.yml']), { ...none, desktop: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/release-plugin.yml']), { ...none, plugin: true });
assert.deepEqual(classifyCiPaths(['plugin/relay/server.py']), { ...none, plugin: true });
assert.deepEqual(classifyCiPaths(['plugin/dashboard/src/App.tsx']), { ...none, dashboard: true });
assert.deepEqual(classifyCiPaths(['user-docs/index.md']), { ...none, docs: true });
@@ -47,5 +58,76 @@ assert.deepEqual(classifyCiPaths(['.github/workflows/release-backmerge.yml']), {
contract: true,
docs: true,
});
assert.deepEqual(classifyCiPaths(['.github/workflows/approve-release-train.yml']), {
android: true,
desktop: true,
plugin: true,
dashboard: true,
contract: true,
docs: true,
});
const repoRoot = join(__dirname, '..', '..');
const approvalWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-extensions.yml'),
'utf8',
);
const cliReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-cli.yml'),
'utf8',
);
const pluginReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-plugin.yml'),
'utf8',
);
const desktopCiWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'ci-desktop.yml'),
'utf8',
);
const androidPreflightWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'play-preflight-android.yml'),
'utf8',
);
const androidApprovalWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-android.yml'),
'utf8',
);
const androidReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-android.yml'),
'utf8',
);
const requiredChecksWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'ci-required.yml'),
'utf8',
);
const releaseTrainWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-train.yml'),
'utf8',
);
assert.match(approvalWorkflow, /permissions:\r?\n contents: read/);
assert.match(
approvalWorkflow,
/approve:[\s\S]*?permissions:\r?\n actions: write\r?\n contents: write/,
);
assert.match(
approvalWorkflow,
/ref: \$\{\{ contains\(inputs\.version, '-'\) && 'dev' \|\| 'main' \}\}/,
);
assert.match(cliReleaseWorkflow, /workflow_dispatch:[\s\S]*?Approved CLI\+UI version/);
assert.match(cliReleaseWorkflow, /name: Restore exact-source tray build cache[\s\S]*?actions\/cache@v6/);
assert.match(desktopCiWorkflow, /name: Restore exact-source tray build cache[\s\S]*?actions\/cache@v6/);
assert.match(pluginReleaseWorkflow, /workflow_dispatch:[\s\S]*?Approved Plugin version/);
assert.match(androidPreflightWorkflow, /Package immutable preflight artifacts/);
assert.match(androidApprovalWorkflow, /Android public approval accepts stable SemVer only/);
assert.match(androidReleaseWorkflow, /Download exact stable preflight artifacts/);
assert.match(androidReleaseWorkflow, /artifact-ids: \$\{\{ needs\.validate\.outputs\.preflight_artifact_id \}\}/);
assert.match(requiredChecksWorkflow, /name: Reuse exact-tree required checks/);
assert.match(requiredChecksWorkflow, /name: required-checks-\$\{\{ needs\.changes\.outputs\.tree \}\}/);
assert.match(releaseTrainWorkflow, /name: Hermes-Relay Coordinated Release Approval/);
assert.match(releaseTrainWorkflow, /Coordinated Android approval is stable-only/);
console.log('CI path classification tests passed.');
assert.deepEqual(classifyCiPaths(['scripts/check-android-capabilities.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/check_android_capabilities_test.py']), { ...none, android: true });
+6
View File
@@ -166,6 +166,9 @@ jobs:
- name: Build debug APKs
run: ./gradlew assembleDebug --console=plain
- name: Verify Play capability manifest
run: python3 scripts/check-android-capabilities.py --variant googlePlayDebug
- name: Verify packaged native compatibility
run: |
python3 scripts/check-android-native-compat.py \
@@ -203,6 +206,9 @@ jobs:
- name: Build release bundles and APKs
run: ./gradlew bundleRelease assembleRelease --console=plain
- name: Verify Play release capability manifest
run: python3 scripts/check-android-capabilities.py --variant googlePlayRelease
- name: Scan release DEX for unsupported collection APIs
run: |
python3 scripts/check-android-collection-apis.py \
+16 -4
View File
@@ -40,6 +40,10 @@ jobs:
echo "::error::Hermes-Relay Android Release Approval must run from main, not $GITHUB_REF"
exit 1
fi
if [[ ! "$REQUESTED_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "::error::Android public approval accepts stable SemVer only: $REQUESTED_VERSION"
exit 1
fi
TOML_VERSION=$(grep -oP 'appVersionName\s*=\s*"\K[^"]+' gradle/libs.versions.toml)
if [ "$REQUESTED_VERSION" != "$TOML_VERSION" ]; then
echo "::error::Requested version $REQUESTED_VERSION does not match appVersionName $TOML_VERSION"
@@ -56,13 +60,21 @@ jobs:
RELEASE_TREE: ${{ steps.metadata.outputs.tree }}
run: |
ARTIFACT_NAME="play-preflight-${VERSION}-${RELEASE_TREE}"
COUNT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | length')
if [ "$COUNT" -lt 1 ]; then
ARTIFACT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
RUN_ID=$(jq -r '.workflow_run.id // empty' <<<"$ARTIFACT")
if [ -z "$RUN_ID" ]; then
echo "::error::No successful Play preflight found for version $VERSION with tree $RELEASE_TREE"
exit 1
fi
echo "Verified Play preflight proof: $ARTIFACT_NAME"
RUN=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${RUN_ID}")
CONCLUSION=$(jq -r '.conclusion' <<<"$RUN")
WORKFLOW_PATH=$(jq -r '.path' <<<"$RUN")
if [ "$WORKFLOW_PATH" != ".github/workflows/play-preflight-android.yml" ] || [ "$CONCLUSION" != "success" ]; then
echo "::error::Preflight artifact came from ${WORKFLOW_PATH} with conclusion ${CONCLUSION}"
exit 1
fi
echo "Verified immutable Play preflight artifacts: $ARTIFACT_NAME (run $RUN_ID)"
- name: Ensure release tag does not already exist
env:
@@ -0,0 +1,158 @@
name: Hermes-Relay Plugin and CLI+UI Release Approval
on:
workflow_dispatch:
inputs:
surface:
description: "Release surface"
required: true
type: choice
options:
- plugin
- desktop
version:
description: "Approved version (for example 1.11.2 or 0.4.0-beta.7)"
required: true
type: string
permissions:
contents: read
concurrency:
group: approve-${{ inputs.surface }}-release
cancel-in-progress: false
jobs:
validate:
name: Validate release source and metadata
runs-on: ubuntu-latest
outputs:
source_branch: ${{ steps.metadata.outputs.source_branch }}
source_sha: ${{ steps.metadata.outputs.source_sha }}
tag: ${{ steps.metadata.outputs.tag }}
workflow: ${{ steps.metadata.outputs.workflow }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ contains(inputs.version, '-') && 'dev' || 'main' }}
- name: Validate approval request
id: metadata
env:
REQUESTED_SURFACE: ${{ inputs.surface }}
REQUESTED_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
if [[ ! "$REQUESTED_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::Version must be SemVer with an optional prerelease suffix: $REQUESTED_VERSION"
exit 1
fi
if [[ "$REQUESTED_VERSION" == *-* ]]; then
source_branch="dev"
else
source_branch="main"
fi
if [ "$GITHUB_REF" != "refs/heads/main" ]; then
echo "::error::Release approval must run from the trusted main workflow definition, not $GITHUB_REF"
exit 1
fi
git fetch origin "$source_branch" --no-tags
source_sha="$(git rev-parse HEAD)"
expected_sha="$(git rev-parse FETCH_HEAD)"
if [ "$source_sha" != "$expected_sha" ]; then
echo "::error::Checked out $source_sha, but origin/$source_branch is $expected_sha"
exit 1
fi
case "$REQUESTED_SURFACE" in
plugin)
tag="server-v${REQUESTED_VERSION}"
workflow="release-plugin.yml"
python3 scripts/check-plugin-version-sync.py --expect "$REQUESTED_VERSION"
if ! grep -Eq "^## \[Plugin ${REQUESTED_VERSION}\]" CHANGELOG.md; then
echo "::error::CHANGELOG.md has no Plugin release heading for $REQUESTED_VERSION"
exit 1
fi
;;
desktop)
tag="desktop-v${REQUESTED_VERSION}"
workflow="release-cli.yml"
node desktop/scripts/cli-version-sync.mjs --expect "$REQUESTED_VERSION"
if ! grep -Fq "## [$REQUESTED_VERSION]" CHANGELOG.md; then
echo "::error::CHANGELOG.md has no CLI+UI release heading for $REQUESTED_VERSION"
exit 1
fi
;;
*)
echo "::error::Unsupported release surface: $REQUESTED_SURFACE"
exit 1
;;
esac
echo "tag=$tag" >> "$GITHUB_OUTPUT"
echo "workflow=$workflow" >> "$GITHUB_OUTPUT"
echo "source_branch=$source_branch" >> "$GITHUB_OUTPUT"
echo "source_sha=$source_sha" >> "$GITHUB_OUTPUT"
approve:
name: Create release tag and start publication
needs: validate
permissions:
actions: write
contents: write
runs-on: ubuntu-latest
steps:
- name: Verify release source has not moved
env:
GH_TOKEN: ${{ github.token }}
SOURCE_BRANCH: ${{ needs.validate.outputs.source_branch }}
SOURCE_SHA: ${{ needs.validate.outputs.source_sha }}
run: |
current_sha=$(gh api "/repos/${GITHUB_REPOSITORY}/git/ref/heads/${SOURCE_BRANCH}" --jq .object.sha)
if [ "$current_sha" != "$SOURCE_SHA" ]; then
echo "::error::$SOURCE_BRANCH moved from $SOURCE_SHA to $current_sha; run approval again"
exit 1
fi
- name: Ensure release tag does not already exist
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.validate.outputs.tag }}
run: |
if gh api "/repos/${GITHUB_REPOSITORY}/git/ref/tags/${RELEASE_TAG}" >/dev/null 2>&1; then
echo "::error::Tag $RELEASE_TAG already exists"
exit 1
fi
- name: Create approved release tag
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.validate.outputs.tag }}
RELEASE_SHA: ${{ needs.validate.outputs.source_sha }}
run: |
gh api --method POST "/repos/${GITHUB_REPOSITORY}/git/refs" \
-f ref="refs/tags/${RELEASE_TAG}" \
-f sha="$RELEASE_SHA"
- name: Start the immutable tag release workflow
env:
GH_TOKEN: ${{ github.token }}
RELEASE_WORKFLOW: ${{ needs.validate.outputs.workflow }}
RELEASE_VERSION: ${{ inputs.version }}
run: |
# A tag created by GITHUB_TOKEN does not recursively start workflows.
# Dispatch the trusted definition from main; release jobs check out
# and validate the immutable tag created above.
gh workflow run "$RELEASE_WORKFLOW" \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f version="$RELEASE_VERSION"
- name: Approval summary
run: |
echo "## Release approved" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "Created \`${{ needs.validate.outputs.tag }}\` from \`${{ needs.validate.outputs.source_branch }}\` at \`${{ needs.validate.outputs.source_sha }}\`." >> "$GITHUB_STEP_SUMMARY"
echo "Dispatched \`${{ needs.validate.outputs.workflow }}\` to validate and publish that immutable tag." >> "$GITHUB_STEP_SUMMARY"
+120
View File
@@ -0,0 +1,120 @@
name: Hermes-Relay Coordinated Release Approval
on:
workflow_dispatch:
inputs:
android:
description: "Approve Hermes-Relay Android"
required: true
default: false
type: boolean
android_version:
description: "Android version when selected"
required: false
type: string
plugin:
description: "Approve Hermes-Relay Plugin"
required: true
default: false
type: boolean
plugin_version:
description: "Plugin version when selected"
required: false
type: string
desktop:
description: "Approve Hermes-Relay CLI+UI"
required: true
default: false
type: boolean
desktop_version:
description: "CLI+UI version when selected"
required: false
type: string
permissions:
actions: write
contents: read
concurrency:
group: approve-coordinated-release
cancel-in-progress: false
jobs:
validate:
name: Validate selected release surfaces
runs-on: ubuntu-latest
steps:
- name: Require versions for every selected surface
env:
ANDROID: ${{ inputs.android }}
ANDROID_VERSION: ${{ inputs.android_version }}
PLUGIN: ${{ inputs.plugin }}
PLUGIN_VERSION: ${{ inputs.plugin_version }}
DESKTOP: ${{ inputs.desktop }}
DESKTOP_VERSION: ${{ inputs.desktop_version }}
run: |
set -euo pipefail
if [ "$ANDROID" != "true" ] && [ "$PLUGIN" != "true" ] && [ "$DESKTOP" != "true" ]; then
echo "::error::Select at least one release surface"
exit 1
fi
for pair in \
"$ANDROID:$ANDROID_VERSION:Android" \
"$PLUGIN:$PLUGIN_VERSION:Plugin" \
"$DESKTOP:$DESKTOP_VERSION:CLI+UI"; do
IFS=: read -r selected version label <<<"$pair"
if [ "$selected" = "true" ] && [[ ! "$version" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::$label requires a valid SemVer version"
exit 1
fi
done
if [ "$ANDROID" = "true" ] && [[ "$ANDROID_VERSION" == *-* ]]; then
echo "::error::Coordinated Android approval is stable-only; use a dev candidate tag for prereleases"
exit 1
fi
android:
name: Approve Hermes-Relay Android
needs: validate
if: inputs.android
runs-on: ubuntu-latest
steps:
- name: Dispatch Android approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.android_version }}
run: gh workflow run approve-release-android.yml --repo "$GITHUB_REPOSITORY" --ref main -f version="$VERSION"
plugin:
name: Approve Hermes-Relay Plugin
needs: validate
if: inputs.plugin
runs-on: ubuntu-latest
steps:
- name: Dispatch Plugin approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.plugin_version }}
run: |
gh workflow run approve-release-extensions.yml \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f surface=plugin \
-f version="$VERSION"
desktop:
name: Approve Hermes-Relay CLI+UI
needs: validate
if: inputs.desktop
runs-on: ubuntu-latest
steps:
- name: Dispatch CLI+UI approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.desktop_version }}
run: |
gh workflow run approve-release-extensions.yml \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f surface=desktop \
-f version="$VERSION"
+20 -4
View File
@@ -20,10 +20,6 @@ on:
branches: [main, dev]
paths:
- "app/**"
- "relay-core/**"
- "relay-ui/**"
- "ui-preview/**"
- "quest/**"
- "gradle/**"
- "build.gradle.kts"
- "settings.gradle.kts"
@@ -38,6 +34,8 @@ on:
- "scripts/check-android-locales.py"
- "scripts/android-locale-harness.py"
- "scripts/check-android-collection-apis.py"
- "scripts/check-android-capabilities.py"
- "scripts/tests/check_android_capabilities_test.py"
- "scripts/check-android-native-compat.py"
- "scripts/check-android-release-notes.py"
- "scripts/tests/check_android_native_compat_test.py"
@@ -77,6 +75,11 @@ jobs:
with:
cache-read-only: ${{ github.ref != 'refs/heads/main' && github.ref != 'refs/heads/dev' }}
- name: Validate Play capability boundary
run: |
python3 scripts/check-android-capabilities.py
python3 -m unittest scripts.tests.check_android_capabilities_test
- name: Validate translation catalogs
run: python3 scripts/check-android-locales.py
@@ -121,6 +124,9 @@ jobs:
- name: Build debug APK
run: ./gradlew assembleDebug --console=plain
- name: Verify Play capability manifest
run: python3 scripts/check-android-capabilities.py --variant googlePlayDebug
- name: Verify packaged ONNX Runtime compatibility
run: |
python3 scripts/check-android-native-compat.py \
@@ -177,11 +183,21 @@ jobs:
./gradlew :app:testSideloadDebugUnitTest \
--tests com.hermesandroid.relay.network.ArchitectureBoundaryTest \
--tests com.hermesandroid.relay.network.relay.RelayUrlDeriverTest \
--tests com.hermesandroid.relay.network.shared.PluginProxyTransportTest \
--tests '*GatewayChatClientTest*retarget*' \
--tests '*RelayVoiceClientRoutingTest.proxyProviderOwnsBothVoiceSessionAndWebSocketRequests' \
--tests com.hermesandroid.relay.network.relay.RelayHttpClientDiagnosticsTest \
--tests com.hermesandroid.relay.ui.components.GatewayRoutesAccessPresentationTest \
--tests com.hermesandroid.relay.ui.components.EndpointsCardCompactLayoutTest \
--tests com.hermesandroid.relay.ui.screens.ConnectionDetailPresentationTest \
--tests com.hermesandroid.relay.viewmodel.ConnectionSwitchTest \
--tests com.hermesandroid.relay.util.ServerAddressTest \
--tests com.hermesandroid.relay.util.IssueReportAndDiagnosticsTest \
--tests com.hermesandroid.relay.data.AppLanguageTest \
--tests com.hermesandroid.relay.viewmodel.ChatStreamRecoveryTest \
--tests com.hermesandroid.relay.viewmodel.ChatViewModelGatewayInboundTurnTest \
--tests com.hermesandroid.relay.viewmodel.VoiceInboundCompletionTest \
--tests com.hermesandroid.relay.voice.VoiceViewModelBargeInTest \
--tests com.hermesandroid.relay.viewmodel.ChatViewModelRealtimeTurnTest \
--tests com.hermesandroid.relay.network.relay.RealtimeVoiceEventParsingTest \
--tests com.hermesandroid.relay.voice.VoiceCommandInterpreterTest \
+12
View File
@@ -107,6 +107,18 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Restore exact-source tray build cache
uses: actions/cache@v6
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
desktop/tray/target
key: ${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-${{ hashFiles('desktop/tray/Cargo.toml', 'desktop/tray/build.rs', 'desktop/tray/src/**/*.rs') }}
restore-keys: |
${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-
- name: Install deps
run: npm ci && npm --prefix tray ci
+10 -1
View File
@@ -101,7 +101,12 @@ jobs:
- name: Run focused Plugin tests
run: |
python -m pytest \
plugin/tests/test_manifest_compatibility.py \
plugin/tests/test_relay_security.py \
plugin/tests/test_secure_proxy.py \
plugin/tests/test_secure_proxy_contract.py \
plugin/tests/test_secure_link_setup.py \
plugin/tests/test_secure_proxy_security.py \
plugin/tests/test_voice_routes.py \
plugin/tests/test_session_grants.py \
plugin/tests/test_native_layout_imports.py \
@@ -110,4 +115,8 @@ jobs:
plugin/tests/test_git_state.py \
plugin/tests/test_git_state_write.py \
plugin/tests/test_git_state_extras.py \
plugin/tests/test_mobile_plugin_store.py
plugin/tests/test_mobile_plugin_store.py \
plugin/tests/test_android_tool.py \
plugin/tests/test_android_navigate.py \
plugin/tests/test_phone_platform.py \
plugin/tests/test_desktop_tool_availability.py
+138 -16
View File
@@ -34,6 +34,7 @@ on:
- all-final
permissions:
actions: read
contents: read
pull-requests: read
@@ -52,6 +53,8 @@ jobs:
dashboard: ${{ steps.filter.outputs.dashboard }}
contract: ${{ steps.filter.outputs.contract }}
docs: ${{ steps.filter.outputs.docs }}
release_pr: ${{ steps.release.outputs.release_pr }}
tree: ${{ steps.tree.outputs.tree }}
steps:
- name: Checkout pull request merge
if: github.event_name == 'pull_request'
@@ -69,6 +72,26 @@ jobs:
- name: Test path classifier
run: node .github/scripts/classify-ci-paths.test.cjs
- name: Record checked tree
id: tree
run: echo "tree=$(git rev-parse 'HEAD^{tree}')" >> "$GITHUB_OUTPUT"
- name: Detect canonical release promotion
id: release
env:
BASE_REF: ${{ github.base_ref }}
HEAD_REF: ${{ github.head_ref }}
HEAD_REPOSITORY: ${{ github.event.pull_request.head.repo.full_name }}
run: |
if [ "$GITHUB_EVENT_NAME" = "pull_request" ] && \
[ "$BASE_REF" = "main" ] && \
[ "$HEAD_REF" = "dev" ] && \
[ "$HEAD_REPOSITORY" = "$GITHUB_REPOSITORY" ]; then
echo "release_pr=true" >> "$GITHUB_OUTPUT"
else
echo "release_pr=false" >> "$GITHUB_OUTPUT"
fi
- name: Classify changed files
id: filter
uses: actions/github-script@v8
@@ -123,43 +146,117 @@ jobs:
core.notice(`Changed paths: ${paths.join(', ')}`);
core.notice(`Selected checks: ${Object.entries(outputs).filter(([, value]) => value).map(([key]) => key).join(', ') || 'none'}`);
android:
release-proof:
name: Reuse exact-tree required checks
needs: changes
if: needs.changes.outputs.android == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
if: needs.changes.outputs.release_pr == 'true'
runs-on: ubuntu-latest
outputs:
reuse: ${{ steps.proof.outputs.reuse }}
artifact_id: ${{ steps.proof.outputs.artifact_id }}
run_id: ${{ steps.proof.outputs.run_id }}
tree: ${{ steps.proof.outputs.tree }}
steps:
- name: Checkout simulated release merge
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Locate exact-tree proof
id: proof
env:
GH_TOKEN: ${{ github.token }}
DEV_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
merge_tree=$(git rev-parse 'HEAD^{tree}')
dev_tree=$(git rev-parse "${DEV_SHA}^{tree}")
echo "reuse=false" >> "$GITHUB_OUTPUT"
echo "tree=$dev_tree" >> "$GITHUB_OUTPUT"
if [ "$merge_tree" != "$dev_tree" ]; then
echo "Release merge changes the dev tree ($dev_tree -> $merge_tree); running full CI."
exit 0
fi
artifact_name="required-checks-${dev_tree}"
artifact=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${artifact_name}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
artifact_id=$(jq -r '.id // empty' <<<"$artifact")
run_id=$(jq -r '.workflow_run.id // empty' <<<"$artifact")
if [ -z "$artifact_id" ] || [ -z "$run_id" ]; then
echo "No reusable proof exists for tree $dev_tree; running full CI."
exit 0
fi
run=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${run_id}")
conclusion=$(jq -r '.conclusion' <<<"$run")
workflow_path=$(jq -r '.path' <<<"$run")
if [ "$workflow_path" != ".github/workflows/ci-required.yml" ] || [ "$conclusion" != "success" ]; then
echo "::error::Required-check proof came from ${workflow_path} with conclusion ${conclusion}"
exit 1
fi
echo "artifact_id=$artifact_id" >> "$GITHUB_OUTPUT"
echo "run_id=$run_id" >> "$GITHUB_OUTPUT"
echo "reuse=true" >> "$GITHUB_OUTPUT"
- name: Download exact-tree proof
if: steps.proof.outputs.reuse == 'true'
uses: actions/download-artifact@v8
with:
artifact-ids: ${{ steps.proof.outputs.artifact_id }}
github-token: ${{ github.token }}
repository: ${{ github.repository }}
run-id: ${{ steps.proof.outputs.run_id }}
path: required-check-proof
- name: Verify exact-tree proof
if: steps.proof.outputs.reuse == 'true'
env:
EXPECTED_TREE: ${{ steps.proof.outputs.tree }}
run: |
jq -e \
--arg repository "$GITHUB_REPOSITORY" \
--arg tree "$EXPECTED_TREE" \
'.schemaVersion == 1 and .repository == $repository and .tree == $tree' \
required-check-proof/required-checks.json
android:
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.android == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-android.yml
android_on_demand:
needs: changes
if: github.event_name == 'workflow_dispatch' && inputs.android_preset != 'auto'
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.release-proof.outputs.reuse != 'true' && github.event_name == 'workflow_dispatch' && inputs.android_preset != 'auto' }}
uses: ./.github/workflows/android-on-demand.yml
with:
head_sha: ${{ inputs.head_sha }}
preset: ${{ inputs.android_preset }}
desktop:
needs: changes
if: needs.changes.outputs.desktop == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.desktop == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-desktop.yml
plugin:
needs: changes
if: needs.changes.outputs.plugin == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.plugin == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-plugin.yml
dashboard:
needs: changes
if: needs.changes.outputs.dashboard == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.dashboard == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-dashboard.yml
contract:
needs: changes
if: needs.changes.outputs.contract == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.contract == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-contract.yml
docs:
name: Build public docs
needs: changes
if: needs.changes.outputs.docs == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.docs == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
runs-on: ubuntu-latest
defaults:
run:
@@ -181,10 +278,12 @@ jobs:
guard:
name: Required checks
if: always()
needs: [changes, android, android_on_demand, desktop, plugin, dashboard, contract, docs]
needs: [changes, release-proof, android, android_on_demand, desktop, plugin, dashboard, contract, docs]
runs-on: ubuntu-latest
env:
CHANGES_RESULT: ${{ needs.changes.result }}
RELEASE_PROOF_RESULT: ${{ needs.release-proof.result }}
REUSED_REQUIRED_CHECKS: ${{ needs.release-proof.outputs.reuse }}
ANDROID_RESULT: ${{ needs.android.result }}
ANDROID_ON_DEMAND_RESULT: ${{ needs.android_on_demand.result }}
DESKTOP_RESULT: ${{ needs.desktop.result }}
@@ -197,7 +296,7 @@ jobs:
shell: bash
run: |
failed=0
for check in CHANGES ANDROID ANDROID_ON_DEMAND DESKTOP PLUGIN DASHBOARD CONTRACT DOCS; do
for check in CHANGES RELEASE_PROOF ANDROID ANDROID_ON_DEMAND DESKTOP PLUGIN DASHBOARD CONTRACT DOCS; do
result_var="${check}_RESULT"
result="${!result_var}"
echo "$check: $result"
@@ -207,3 +306,26 @@ jobs:
esac
done
exit "$failed"
- name: Write exact-tree proof
if: ${{ needs.release-proof.outputs.reuse != 'true' }}
env:
CHECKED_TREE: ${{ needs.changes.outputs.tree }}
run: |
mkdir -p required-check-proof
jq -n \
--arg repository "$GITHUB_REPOSITORY" \
--arg tree "$CHECKED_TREE" \
--arg commit "$GITHUB_SHA" \
--arg run_id "$GITHUB_RUN_ID" \
'{schemaVersion: 1, repository: $repository, tree: $tree, commit: $commit, runId: $run_id}' \
> required-check-proof/required-checks.json
- name: Upload exact-tree proof
if: ${{ needs.release-proof.outputs.reuse != 'true' }}
uses: actions/upload-artifact@v7
with:
name: required-checks-${{ needs.changes.outputs.tree }}
path: required-check-proof/required-checks.json
if-no-files-found: error
retention-days: 30
+18
View File
@@ -8,6 +8,15 @@ on:
- "assets/screenshots/03_voice.png"
- "assets/screenshots/06_manage.png"
- "docs/media/screenshots.json"
- "docs/media/desktop-ui-screenshots.json"
- "assets/screenshots/desktop-ui/**"
- "desktop/tray/ui/**"
- "desktop/tray/scripts/*.mjs"
- "desktop/tray/package-lock.json"
- "desktop/tray/index.html"
- "desktop/tray/icons/icon-256.png"
- "desktop/src/endpoint.ts"
- "desktop/src/transportSecurity.ts"
- ".github/workflows/ci-website.yml"
push:
branches: [main, dev]
@@ -17,6 +26,15 @@ on:
- "assets/screenshots/03_voice.png"
- "assets/screenshots/06_manage.png"
- "docs/media/screenshots.json"
- "docs/media/desktop-ui-screenshots.json"
- "assets/screenshots/desktop-ui/**"
- "desktop/tray/ui/**"
- "desktop/tray/scripts/*.mjs"
- "desktop/tray/package-lock.json"
- "desktop/tray/index.html"
- "desktop/tray/icons/icon-256.png"
- "desktop/src/endpoint.ts"
- "desktop/src/transportSecurity.ts"
- ".github/workflows/ci-website.yml"
permissions:
+35 -20
View File
@@ -2,10 +2,11 @@
#
# Run manually from the final dev or untagged main tree before creating
# android-v*. The job
# builds the same signed release artifacts, scans final DEX, and uploads the
# Google Play bundle as a production DRAFT. A successful upload is the automated
# Play gate while no public GitHub Release or sideload APK exists. Console-only
# pre-review and pre-launch reports are informational and do not block release.
# builds the signed release artifacts once, scans the final packages, and uploads
# the Google Play bundle as a production DRAFT. The exact signed APK/AAB,
# mappings, manifest, and checksums remain private Actions artifacts until
# approval publishes those same bytes. Console-only pre-review and pre-launch
# reports are informational and do not block release.
name: Hermes-Relay Android Play Preflight
@@ -98,7 +99,15 @@ jobs:
HERMES_KEYSTORE_PASSWORD: ${{ secrets.HERMES_KEYSTORE_PASSWORD }}
HERMES_KEY_ALIAS: ${{ secrets.HERMES_KEY_ALIAS }}
HERMES_KEY_PASSWORD: ${{ secrets.HERMES_KEY_PASSWORD }}
run: ./gradlew bundleRelease assembleRelease --console=plain
run: |
./gradlew \
:app:bundleGooglePlayRelease \
:app:assembleGooglePlayRelease \
:app:assembleSideloadRelease \
--console=plain
- name: Verify Play capability manifest
run: python3 scripts/check-android-capabilities.py --variant googlePlayRelease
- name: Scan final release DEX
run: |
@@ -106,6 +115,12 @@ jobs:
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
- name: Verify packaged native compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
- name: Upload private production draft to Play
env:
PLAY_SERVICE_ACCOUNT_JSON: ${{ secrets.PLAY_SERVICE_ACCOUNT_JSON }}
@@ -121,27 +136,27 @@ jobs:
--resolution-strategy=ignore \
--release-name="Hermes-Relay Android v${{ steps.metadata.outputs.version }}"
- name: Record successful preflight for the exact commit
- name: Package immutable preflight artifacts
run: |
mkdir -p app/build/reports
cat > app/build/reports/play-preflight.json <<EOF
{
"version": "${{ steps.metadata.outputs.version }}",
"versionCode": "${{ steps.metadata.outputs.version_code }}",
"commit": "$GITHUB_SHA",
"tree": "${{ steps.metadata.outputs.tree }}",
"track": "production",
"status": "draft"
}
EOF
python3 scripts/android_release_artifacts.py package \
--version "${{ steps.metadata.outputs.version }}" \
--version-code "${{ steps.metadata.outputs.version_code }}" \
--commit "$GITHUB_SHA" \
--tree "${{ steps.metadata.outputs.tree }}" \
--sideload-apk app/build/outputs/apk/sideload/release/*.apk \
--google-play-aab app/build/outputs/bundle/googlePlayRelease/*.aab \
--sideload-mapping app/build/outputs/mapping/sideloadRelease/mapping.txt \
--google-play-mapping app/build/outputs/mapping/googlePlayRelease/mapping.txt \
--output app/build/preflight-artifacts
- name: Upload preflight proof
- name: Upload immutable preflight artifacts
uses: actions/upload-artifact@v7
with:
name: play-preflight-${{ steps.metadata.outputs.version }}-${{ steps.metadata.outputs.tree }}
path: app/build/reports/play-preflight.json
path: app/build/preflight-artifacts/*
if-no-files-found: error
retention-days: 30
compression-level: 0
- name: Preflight summary
run: |
@@ -152,4 +167,4 @@ jobs:
echo "- Release tree: \`${{ steps.metadata.outputs.tree }}\`" >> "$GITHUB_STEP_SUMMARY"
echo "- Play track/status: **Production draft**" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "The signed build, DEX scan, and Play draft upload passed. Ensure this exact release tree is on main, then run **Hermes-Relay Android Release Approval** from main. Console-only reports are informational and non-blocking." >> "$GITHUB_STEP_SUMMARY"
echo "The signed build, package scans, and Play draft upload passed. Approval will publish these exact private artifacts if the unchanged tree reaches main. Console-only reports are informational and non-blocking." >> "$GITHUB_STEP_SUMMARY"
+61 -57
View File
@@ -36,6 +36,9 @@ jobs:
version: ${{ steps.version.outputs.version }}
version_code: ${{ steps.version.outputs.version_code }}
prerelease: ${{ steps.version.outputs.prerelease }}
release_tree: ${{ steps.version.outputs.release_tree }}
preflight_artifact_id: ${{ steps.preflight.outputs.artifact_id }}
preflight_run_id: ${{ steps.preflight.outputs.run_id }}
steps:
- uses: actions/checkout@v7
with:
@@ -66,6 +69,7 @@ jobs:
echo "version=$REF_VERSION" >> "$GITHUB_OUTPUT"
echo "version_code=$VERSION_CODE" >> "$GITHUB_OUTPUT"
echo "prerelease=$PRERELEASE" >> "$GITHUB_OUTPUT"
echo "release_tree=$(git rev-parse 'HEAD^{tree}')" >> "$GITHUB_OUTPUT"
- name: Verify version sync
run: |
@@ -110,25 +114,38 @@ jobs:
fi
- name: Require successful Play preflight for this exact release tree
id: preflight
if: ${{ !contains(steps.version.outputs.version, '-') }}
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ steps.version.outputs.version }}
run: |
RELEASE_TREE=$(git rev-parse 'HEAD^{tree}')
RELEASE_TREE="${{ steps.version.outputs.release_tree }}"
ARTIFACT_NAME="play-preflight-${VERSION}-${RELEASE_TREE}"
COUNT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | length')
if [ "$COUNT" -lt 1 ]; then
ARTIFACT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
ARTIFACT_ID=$(jq -r '.id // empty' <<<"$ARTIFACT")
RUN_ID=$(jq -r '.workflow_run.id // empty' <<<"$ARTIFACT")
if [ -z "$ARTIFACT_ID" ] || [ -z "$RUN_ID" ]; then
echo "::error::No successful Play preflight found for version $VERSION with tree $RELEASE_TREE"
echo "Run Hermes-Relay Android Play Preflight from the final dev tree, merge that unchanged tree to main, then approve the release."
exit 1
fi
echo "Play preflight proof found: $ARTIFACT_NAME"
RUN=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${RUN_ID}")
CONCLUSION=$(jq -r '.conclusion' <<<"$RUN")
WORKFLOW_PATH=$(jq -r '.path' <<<"$RUN")
if [ "$WORKFLOW_PATH" != ".github/workflows/play-preflight-android.yml" ] || [ "$CONCLUSION" != "success" ]; then
echo "::error::Preflight artifact came from ${WORKFLOW_PATH} with conclusion ${CONCLUSION}"
exit 1
fi
echo "artifact_id=$ARTIFACT_ID" >> "$GITHUB_OUTPUT"
echo "run_id=$RUN_ID" >> "$GITHUB_OUTPUT"
echo "Play preflight artifacts verified: $ARTIFACT_NAME (run $RUN_ID, artifact $ARTIFACT_ID)"
ci:
name: CI Checks
name: CI Checks (prerelease only)
needs: validate
if: ${{ needs.validate.outputs.prerelease == 'true' }}
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
@@ -168,6 +185,7 @@ jobs:
release:
name: Build & Publish Release
needs: [validate, ci]
if: ${{ always() && needs.validate.result == 'success' && (needs.ci.result == 'success' || needs.ci.result == 'skipped') }}
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
@@ -186,31 +204,33 @@ jobs:
with:
cache-read-only: false
- name: Decode release keystore
- name: Download exact stable preflight artifacts
if: ${{ needs.validate.outputs.prerelease != 'true' }}
uses: actions/download-artifact@v8
with:
artifact-ids: ${{ needs.validate.outputs.preflight_artifact_id }}
github-token: ${{ github.token }}
repository: ${{ github.repository }}
run-id: ${{ needs.validate.outputs.preflight_run_id }}
path: app/build/preflight-artifacts
- name: Verify exact stable preflight artifacts
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/android_release_artifacts.py verify \
--version "${{ needs.validate.outputs.version }}" \
--version-code "${{ needs.validate.outputs.version_code }}" \
--tree "${{ needs.validate.outputs.release_tree }}" \
--directory app/build/preflight-artifacts
- name: Decode release keystore for candidate build
env:
HERMES_KEYSTORE_BASE64: ${{ secrets.HERMES_KEYSTORE_BASE64 }}
if: env.HERMES_KEYSTORE_BASE64 != ''
if: ${{ needs.validate.outputs.prerelease == 'true' && env.HERMES_KEYSTORE_BASE64 != '' }}
run: |
echo "$HERMES_KEYSTORE_BASE64" | base64 -d > "$RUNNER_TEMP/release.keystore"
echo "HERMES_KEYSTORE_PATH=$RUNNER_TEMP/release.keystore" >> "$GITHUB_ENV"
- name: Build stable release artifacts (APK + AAB)
if: ${{ needs.validate.outputs.prerelease != 'true' }}
env:
HERMES_KEYSTORE_PASSWORD: ${{ secrets.HERMES_KEYSTORE_PASSWORD }}
HERMES_KEY_ALIAS: ${{ secrets.HERMES_KEY_ALIAS }}
HERMES_KEY_PASSWORD: ${{ secrets.HERMES_KEY_PASSWORD }}
# `assembleRelease` and `bundleRelease` are flavor-wide task aliases
# (added by `flavorDimensions += "track"` in app/build.gradle.kts), so
# this one line builds ALL four artifacts at once. Filenames come from
# `archivesName` (set in app/build.gradle.kts) which injects the app
# version, so `<version>` below is `libs.versions.appVersionName`:
# app/build/outputs/apk/googlePlay/release/hermes-relay-<version>-googlePlay-release.apk
# app/build/outputs/apk/sideload/release/hermes-relay-<version>-sideload-release.apk
# app/build/outputs/bundle/googlePlayRelease/hermes-relay-<version>-googlePlay-release.aab
# app/build/outputs/bundle/sideloadRelease/hermes-relay-<version>-sideload-release.aab
run: ./gradlew bundleRelease assembleRelease
- name: Build side-by-side release candidate APK
if: ${{ needs.validate.outputs.prerelease == 'true' }}
env:
@@ -234,10 +254,10 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
uses: actions/upload-artifact@v7
with:
name: android-r8-mappings-${{ needs.validate.outputs.version }}-${{ github.sha }}
name: android-r8-mappings-${{ needs.validate.outputs.version }}-${{ needs.validate.outputs.release_tree }}
path: |
app/build/outputs/mapping/googlePlayRelease/mapping.txt
app/build/outputs/mapping/sideloadRelease/mapping.txt
app/build/preflight-artifacts/mapping-googlePlayRelease.txt
app/build/preflight-artifacts/mapping-sideloadRelease.txt
if-no-files-found: error
retention-days: 90
@@ -254,8 +274,7 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/check-android-collection-apis.py \
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
--apk app/build/preflight-artifacts/*-sideload-release.apk
- name: Scan candidate DEX for unsupported collection APIs
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -267,8 +286,7 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
app/build/preflight-artifacts/*-sideload-release.apk
- name: Verify candidate packaged ONNX Runtime compatibility
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -278,23 +296,10 @@ jobs:
- name: List produced artifacts (debug aid)
run: |
echo "=== APK outputs ==="
echo "=== Reused stable artifacts ==="
find app/build/preflight-artifacts -maxdepth 1 -type f -print 2>/dev/null || true
echo "=== Candidate APK outputs ==="
find app/build/outputs/apk -name '*.apk' -print 2>/dev/null || true
echo "=== AAB outputs ==="
find app/build/outputs/bundle -name '*.aab' -print 2>/dev/null || true
- name: Generate stable checksums
if: ${{ needs.validate.outputs.prerelease != 'true' }}
# Flavor dimension adds an extra path segment to the AGP output layout.
# APKs live under `apk/<flavor>/release/`, AABs under `bundle/<flavor>Release/`
# (note the concatenated camelCase — AGP path quirk, documented but
# different between APK and AAB). Checksums cover EXACTLY the files
# attached to the GitHub Release (see the 2-asset policy on the
# release step below) so SHA256SUMS.txt matches the assets 1:1.
run: |
cd app/build/outputs
sha256sum apk/sideload/release/*.apk bundle/googlePlayRelease/*.aab > SHA256SUMS.txt
cat SHA256SUMS.txt
- name: Generate candidate checksums
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -340,9 +345,9 @@ jobs:
# Deliberate 2-asset policy (#144): attach ONLY the installable
# sideload APK and Play AAB, plus checksums covering those files.
files: |
app/build/outputs/apk/sideload/release/*.apk
app/build/outputs/bundle/googlePlayRelease/*.aab
app/build/outputs/SHA256SUMS.txt
app/build/preflight-artifacts/*-sideload-release.apk
app/build/preflight-artifacts/*-googlePlay-release.aab
app/build/preflight-artifacts/SHA256SUMS.txt
- name: Create candidate GitHub prerelease
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -364,18 +369,17 @@ jobs:
run: |
echo "## Hermes-Relay Android v${{ needs.validate.outputs.version }}" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
if [ "$PRERELEASE" = "true" ] && [ -n "$HERMES_KEYSTORE_BASE64" ]; then
echo "✅ **Release-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
elif [ "$PRERELEASE" = "true" ]; then
echo "⚠️ **Debug-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
if [ "$PRERELEASE" != "true" ]; then
echo "✅ **Published the exact signed Play-preflight artifacts**" >> "$GITHUB_STEP_SUMMARY"
elif [ -n "$HERMES_KEYSTORE_BASE64" ]; then
echo "✅ **Signed with release keystore** — suitable for Play Store upload" >> "$GITHUB_STEP_SUMMARY"
echo "✅ **Release-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
else
echo "⚠️ **Debug-signed** (no \`HERMES_KEYSTORE_BASE64\` secret) — NOT suitable for Play Store. Add the secret in repo settings to enable release signing." >> "$GITHUB_STEP_SUMMARY"
echo "⚠️ **Debug-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
fi
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "### Artifacts" >> "$GITHUB_STEP_SUMMARY"
echo '```' >> "$GITHUB_STEP_SUMMARY"
find app/build/preflight-artifacts -maxdepth 1 -type f -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
find app/build/outputs/apk -name '*.apk' -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
find app/build/outputs/bundle -name '*.aab' -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
echo '```' >> "$GITHUB_STEP_SUMMARY"
+49 -15
View File
@@ -3,6 +3,12 @@ name: Hermes-Relay CLI+UI Release
on:
push:
tags: ['desktop-v*']
workflow_dispatch:
inputs:
version:
description: "Approved CLI+UI version"
required: true
type: string
permissions:
contents: write
@@ -20,6 +26,7 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js
uses: actions/setup-node@v7
@@ -34,10 +41,16 @@ jobs:
- name: Extract and validate tag version
id: version
shell: bash
env:
DISPATCHED_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
version="${GITHUB_REF_NAME#desktop-v}"
if [[ -z "$version" || "$version" == "$GITHUB_REF_NAME" ]]; then
if [ -n "$DISPATCHED_VERSION" ]; then
version="$DISPATCHED_VERSION"
else
version="${GITHUB_REF_NAME#desktop-v}"
fi
if [ -z "$version" ] || { [ -z "$DISPATCHED_VERSION" ] && [ "$version" = "$GITHUB_REF_NAME" ]; }; then
echo "Expected a desktop-v* tag, got $GITHUB_REF_NAME" >&2
exit 1
fi
@@ -51,11 +64,12 @@ jobs:
- name: Verify tag belongs to the correct integration branch
shell: bash
working-directory: .
env:
TAG_VERSION: ${{ steps.version.outputs.version }}
run: |
set -euo pipefail
version="${GITHUB_REF_NAME#desktop-v}"
tag_commit="$(git rev-parse "${GITHUB_REF_NAME}^{commit}")"
if [[ "$version" == *-* ]]; then
tag_commit="$(git rev-parse HEAD)"
if [[ "$TAG_VERSION" == *-* ]]; then
git fetch origin dev --no-tags
if ! git merge-base --is-ancestor "$tag_commit" origin/dev; then
echo "CLI+UI prereleases must be tagged from dev; $tag_commit is not in origin/dev" >&2
@@ -78,6 +92,8 @@ jobs:
working-directory: desktop
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js (for npm ci + tsc)
uses: actions/setup-node@v7
@@ -271,6 +287,8 @@ jobs:
working-directory: desktop
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js
uses: actions/setup-node@v7
@@ -289,6 +307,18 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Restore exact-source tray build cache
uses: actions/cache@v6
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
desktop/tray/target
key: ${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-${{ hashFiles('desktop/tray/Cargo.toml', 'desktop/tray/build.rs', 'desktop/tray/src/**/*.rs') }}
restore-keys: |
${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-
- name: Install deps
run: npm ci && npm --prefix tray ci
@@ -411,6 +441,11 @@ jobs:
if ($versionOutput -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "installed CLI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$versionOutput'"
}
$tray = Join-Path $installDir 'hermes-relay-tray.exe'
$trayVersion = (Get-Item -LiteralPath $tray).VersionInfo.ProductVersion
if ($trayVersion -ne $env:EXPECTED_DESKTOP_VERSION) {
throw "installed UI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$trayVersion'"
}
$helpOutput = (& $cli --help | Out-String)
if ($LASTEXITCODE -ne 0 -or $helpOutput -notmatch 'Usage:') {
throw 'installed CLI --help smoke failed'
@@ -451,7 +486,7 @@ jobs:
throw "installer lifecycle changed the pre-existing tray startup preference"
}
Write-Host "packaged installer lifecycle smoke OK version=$versionOutput install=$installDir"
Write-Host "packaged installer lifecycle smoke OK cli=$versionOutput ui=$trayVersion install=$installDir"
} finally {
Get-Process -Name 'hermes-relay-tray' -ErrorAction SilentlyContinue |
Stop-Process -Force -ErrorAction SilentlyContinue
@@ -483,6 +518,7 @@ jobs:
name: Publish GitHub Release
runs-on: ubuntu-latest
needs:
- validate-release
- build-cli-binaries
- smoke-windows-cli-release-asset
- smoke-macos-cli-release-asset
@@ -492,10 +528,8 @@ jobs:
# Needed so CLI_RELEASE_NOTES.md is available to render into the release body
# (the other publish-release steps only consume downloaded build artifacts).
- uses: actions/checkout@v7
- name: Extract CLI+UI version
id: version
run: echo "version=${GITHUB_REF_NAME#desktop-v}" >> "$GITHUB_OUTPUT"
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- uses: actions/download-artifact@v8
with:
@@ -515,8 +549,8 @@ jobs:
# (desktop-v0.3.0) so install/pin commands stay accurate without manual edits.
- name: Render release notes
env:
VERSION: ${{ steps.version.outputs.version }}
TAG: ${{ github.ref_name }}
VERSION: ${{ needs.validate-release.outputs.version }}
TAG: desktop-v${{ needs.validate-release.outputs.version }}
run: |
sed -e "s/__VERSION__/${VERSION}/g" -e "s/__TAG__/${TAG}/g" \
CLI_RELEASE_NOTES.md > cli_release_notes_rendered.md
@@ -525,10 +559,10 @@ jobs:
- name: Publish GitHub Release
uses: softprops/action-gh-release@v3
with:
name: Hermes-Relay CLI+UI v${{ steps.version.outputs.version }}
tag_name: ${{ github.ref_name }}
name: Hermes-Relay CLI+UI v${{ needs.validate-release.outputs.version }}
tag_name: desktop-v${{ needs.validate-release.outputs.version }}
draft: false
prerelease: ${{ contains(steps.version.outputs.version, 'alpha') || contains(steps.version.outputs.version, 'beta') || contains(steps.version.outputs.version, 'rc') }}
prerelease: ${{ contains(needs.validate-release.outputs.version, '-') }}
fail_on_unmatched_files: true
body_path: cli_release_notes_rendered.md
files: |
+26 -2
View File
@@ -4,6 +4,12 @@ on:
push:
tags:
- "server-v*"
workflow_dispatch:
inputs:
version:
description: "Approved Plugin version"
required: true
type: string
permissions:
contents: write
@@ -19,10 +25,19 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Extract version from tag
id: version
run: echo "version=${GITHUB_REF#refs/tags/server-v}" >> "$GITHUB_OUTPUT"
env:
DISPATCHED_VERSION: ${{ inputs.version }}
run: |
if [ -n "$DISPATCHED_VERSION" ]; then
version="$DISPATCHED_VERSION"
else
version="${GITHUB_REF#refs/tags/server-v}"
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
- name: Verify Plugin version sync and changelog
run: |
@@ -61,6 +76,8 @@ jobs:
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Set up Python 3.11
uses: actions/setup-python@v7
@@ -85,11 +102,16 @@ jobs:
- name: Run focused Plugin tests
run: |
python -m pytest \
plugin/tests/test_manifest_compatibility.py \
plugin/tests/test_relay_security.py \
plugin/tests/test_voice_routes.py \
plugin/tests/test_session_grants.py \
plugin/tests/test_proactive_channel.py \
plugin/tests/test_android_phone_status.py
plugin/tests/test_android_phone_status.py \
plugin/tests/test_android_tool.py \
plugin/tests/test_android_navigate.py \
plugin/tests/test_phone_platform.py \
plugin/tests/test_desktop_tool_availability.py
package:
name: Build and publish Plugin package
@@ -98,6 +120,8 @@ jobs:
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Set up Python 3.11
uses: actions/setup-python@v7
+1 -4
View File
@@ -24,10 +24,7 @@ Thumbs.db
local.properties
/build/
/app/build/
/relay-core/build/
/relay-ui/build/
/ui-preview/build/
/quest/build/
/experiments/quest/**/build/
/app/release/
*.apk
*.aab
+5 -3
View File
@@ -17,7 +17,7 @@ contract here and in `RELEASE.md`.
- Android local/cloud verification → **[docs/android-build-lane.md](docs/android-build-lane.md)**
- Android emulator lanes → **[docs/android-emulator-testing.md](docs/android-emulator-testing.md)** — suggest the smallest relevant API 36 lanes; never run the full matrix automatically
- `android_*` toolset + MCP → **[docs/mcp-tooling.md](docs/mcp-tooling.md)**
- Follow-ups / deferred work / known gaps → **[TODO.md](TODO.md)** (the single home for "what's next" — never DEVLOG, never scattered code comments)
- Follow-ups / deferred work / known gaps → **[docs/project/TODO.md](docs/project/TODO.md)** (the single home for "what's next" — never DEVLOG, never scattered code comments)
## Branch contract
@@ -65,8 +65,10 @@ PR; never resolve those cases by choosing a side automatically.
- **Vanilla Hermes path = upstream-only.** The standard (no-plugin) connection
uses the upstream Dashboard/Gateway for chat, authentication, Manage, sessions,
and Vanilla Hermes voice. The API server is an optional automatic fallback and
advanced headless-compatibility surface; Relay adds optional extensions. This
and Vanilla Hermes voice. The API server is an explicit API-only/headless
compatibility surface; Relay adds optional extensions. A Gateway-owned
conversation never changes transport because Gateway auth or reachability
changes. This
path must work against unmodified upstream hermes-agent. Server-side needs go
through upstream PRs or the optional relay plugin, never fork patches.
- **Verify endpoints against upstream** (`gateway/platforms/api_server.py` /
+114 -3
View File
@@ -6,18 +6,129 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
### Added
- Provider usage shows Grok subscription periods, product usage, and on-demand credit state for hosts signed in with `xai-oauth`. Android shows SuperGrok by default when no provider visibility choice is saved.
- Guided Secure Link setup in Dashboard and the Desktop Relay pane, with shared read-only host CLI checks, restart instructions, and signed pairing handoff.
### Fixed
- Desktop tray notices, screenshot evidence, and grant prompts stay reusable after dismissal; screenshot evidence keeps the most recently selected image. (#606)
- Proactive phone Thread messages render relay-token and host-path media as attachments while preserving multiline text; notification previews omit media markers. (#485)
- Desktop computer screenshots attach validated image bytes to the host tool result instead of returning base64 as plain text.
- Relay-owned media uploads are removed on token expiry, eviction, and shutdown; media activity logs omit tokens, file paths, and screenshot bytes.
- Plugin screenshot and navigation tools resolve Android's authenticated media token, attach the actual bounded image to host vision, and keep legacy inline screenshots readable. (#593)
- Android Chat can open the model picker before the first turn, loads Gateway models when opened, and distinguishes loading, unavailable, and empty catalogs.
- Secure Link configuration failures leave ordinary Relay available; route details and pairing previews resolve the advertised service namespaces.
- Dashboard pairing QR codes support larger certificate-bearing Secure Link invites.
- Secure Link preserves Gateway ticket authentication and Dashboard login paths, bounds rewritten responses, and serves compatible health information without additional loopback probes.
- Android Secure Link enforces the paired certificate pin for HTTP, Gateway, and voice traffic, retains the correct TLS policy during Gateway route changes, and displays the active HTTPS Dashboard route.
- Android cold start restores the saved Appearance palette and platform light/dark mode before the first app frame.
- Android Gateway onboarding verifies Dashboard access without overstating Chat or voice readiness, explains common authentication setup failures, and requires exact-address consent before using HTTP. Custom Dashboard ports are accepted and shown throughout setup and route editing. (#604)
- Android safely settles Gateway foreground-service starts before stopping local retention, preventing the startup/shutdown race reported in #603. Turning off always-on connectivity preserves active turns.
- Android Standard Voice speaks live background completions in its active conversation after the original reply finishes. Stop and conversation changes discard pending speech. (#545)
## [Android 1.17.0] - 2026-09-13
### Added
- Optional voice controls over other apps in Google Play, with contextual permission setup, a persistent Stop voice notification, and session shutdown on screen lock or permission loss. Phone control remains sideload-only.
### Fixed
- Android shows standalone response cards without an outer bubble, uses subtler assistant surfaces, and places delivery status beside message timestamps.
- Android answers upstream Clarify batches one question at a time, with independent choices, custom answers, and confirmed progress preserved across reconnects. (#474)
- Android context previews mark phone status and turn context as unavailable in Gateway chats instead of claiming they are sent. Settings clarify that automatic phone-status sharing applies to API-only chats. (#556)
- Android shows Hermes profile display names and groups the resolved server default under its agent identity, while preserving explicit profile selection and saved conversations.
## [Plugin 1.11.3] - 2026-09-13
### Fixed
- Relay Dashboard WebSockets work with current Hermes authentication helpers while preserving older-host compatibility, single-use tickets, Host/Origin/IP checks, and Relay session authentication.
## [Android 1.16.1] - 2026-09-12
### Fixed
- Android Dashboard-only connections start the profile-scoped session directory before Gateway readiness, so a cold launch no longer leaves both the directory and passive Gateway socket waiting on each other. (#495, #528)
## [Android 1.16.0] - 2026-09-10
### Fixed
- Android no longer crashes when a route probe finishes while a network change invalidates the endpoint cache.
- Android opens an authenticated Gateway chat on the first foreground launch instead of waiting for a background-and-resume cycle to leave the waking state. (#495, #528)
- Android Dashboard sign-in removes pasted line breaks from username and password fields, matching the browser login while preserving every other credential character. (#541)
- Android keeps saved Dashboard sign-ins bound to their connection when switching gateways, rather than letting a stale resolver route invalidate another connection's session.
- Bot Mode no longer crashes when different connections have bots with the same profile name. Both the conversation list and Active Now strip preserve each bot's connection, and opening progress appears only on the selected bot.
- Android feedback uses themed banners and action cards instead of platform toasts and default snackbars. Dashboard errors no longer misidentify missing resources as an outdated Relay. Developer settings includes local-only message previews.
- Missing chat attachments show their error and retry in the attachment card without repeated global popups. Global action messages occupy the top message area instead of covering the composer.
- Chat distinguishes session preparation from response streaming and retains initialization errors that arrive before the session acknowledgement. Long-press the agent header to open a live session-diagnostics drawer.
- Delegated-agent activity survives parent replies and leaves compact history entries for later read-only review. The activity strip appears only while work runs; historical process views cannot stop or dismiss live work. (#447)
## [Plugin 1.11.2] - 2026-09-10
### Fixed
- **Relay tool availability avoids repeated Windows loopback delays and preserves multi-PC capabilities.** Host-local Android, Desktop, and Phone paths use explicit IPv4 loopback, while Desktop checks share a bounded health snapshot that preserves per-client advertisements and fails closed when Hermes-Relay is unavailable. (#562, #563)
- **`android_*` tools resolve bridge credentials written after host startup.** Requests retry profile-scoped env and active bridge-session credentials after a stale token is rejected, and vision navigation now shares the same current Relay transport instead of the retired standalone default.
- **`android_setup` accepts both its canonical and legacy schema keys.** `bridge_session_token` and `pairing_code` are accepted, while a missing token returns a structured error.
- **Android tool setup tests use a temporary Hermes home.** Test runs no longer write bridge settings into a developer environment.
## [Android 1.15.1] - 2026-09-02
### Changed
- Chat and Bot Chat offer a compact Correct now / Queue next tray behind the composer. Chat settings sets the default; each message can override it. Stop pauses pending work until Resume, and editing or removing queued messages preserves the remaining order.
- Wider Chat and Voice layouts keep text and controls centered and readable, including landscape Voice Focus.
### Fixed
- Delivery and correction labels remain readable inside user-message bubbles.
- Voice errors use a scrollable dialog with separate Retry and Dismiss actions.
- Attachment previews stay open through rotation, and videos retain their original proportions. (#483)
- Release builds preserve the native configuration names required for wake-word startup. (#444)
- Standard Hermes attachments stream to disk while enforcing download size limits. (#531)
- Session refresh no longer sustains a request loop. History loads, chat rendering, image previews, and media exports keep memory use bounded.
- Image-generation progress remains visible between interim replies and media delivery.
- New Gateway chats wait for session readiness before the first prompt; ownership refusals preserve the retryable prompt and server error.
## [0.4.0-beta.7] - 2026-09-02
### Fixed
- Windows updates detect a colocated management UI, report both installed versions, and update the CLI and UI together through the verified bundle installer. CLI-only installations keep their standalone updater.
## [Android 1.15.0] - 2026-08-31
### Changed
- **Android prefers current upstream Hermes for standard media, Git, usage, and notices.** Authenticated Dashboard file delivery, current-session `/api/git/*`, Gateway `usage.bars`, and keyed agent notices work without the optional Hermes-Relay Plugin; Relay remains additive for older-host media compatibility, sensitivity metadata, repository discovery and guarded mutations, multi-provider usage, and true Relay tools.
- **Android Settings separates standard Hermes from Relay tools.** Media now sits with Chat and Voice under Hermes, while proactive Threads, Terminal, Notification Companion, Relay sessions, and Device Control remain clearly grouped behind the optional plugin.
- **Android Supervised Mode uses app-specific parent access.** Parents choose a six-digit PIN or password, receive a shareable six-word recovery phrase, and can remove the credential without losing their supervised profile, capability, appearance, visibility, session, or relock settings. Android device credentials and biometrics no longer grant parent access.
- **Android What's New now provides a readable, complete release record.** One overall title and summary lead into selected highlights, every remaining user-visible addition, improvement, and fix, and relevant compatibility boundaries. Toast counts and previews are derived from that same inventory, so View all no longer promises details the expanded dialog and history cannot show.
### Fixed
- **Standard Hermes attachments no longer demand Relay pairing.** Host-local images, audio, video, and files download through the authenticated Dashboard, stay loaded across history reconciliation, and fall back to one neutral compatibility card on older hosts instead of flashing `Relay URL not configured` or retrying indefinitely.
- **Removing optional Relay does not strand Standard voice or leak preferences across connections.** Runtime fallback keeps Dashboard voice usable, preserves configured choices through temporary outages, and normalizes only connection-scoped named-profile settings after explicit Relay removal.
- **Passively observed Desktop/TUI turns now show live activity in the Android session drawer.** A uniquely matched selected session projects Working or Waiting without Android resuming, activating, or interrupting the external runtime; ambiguous cross-profile matches remain neutral. (Related: #365)
- **Android Chat keeps one transport owner through sign-out and outages.** Dashboard/Gateway conversations now preserve their transcript, draft, profile, and session for sign-in or retry instead of silently sending the next turn to a reachable Direct API database. Legacy API-only connections and explicitly selected Direct API chats remain supported.
- **Android keeps completed chat text visible when Dashboard sign-in expires.** Generic and reason-coded history `401` responses settle the local turn, preserve its transcript, and surface the existing sign-in recovery without reading another profile's API history.
- **Android keeps long-running context compaction alive.** A client-visible compaction status extends and refreshes the Gateway turn watchdog instead of interrupting healthy compression after the ordinary idle window. (Supersedes #484.)
- **Android Bot Chats render loaded history immediately.** Route-owned chat screens observe their own handler state from first composition, including fast history loads that settle before another frame. (Supersedes #453.)
- **Android Chat settles an owned Gateway turn when its terminal frame is lost.** An exact idle `session.active_list` snapshot now completes the matching local stream, reconciles durable history, and drains its queued follow-up without interrupting or claiming Desktop/TUI work.
- **Supervised Gateway setup stays parent-owned.** Add Gateway is single-flight and checks live parent authority before allocating a draft, relock/back cancels the exact pending setup, and the locked Chat footer no longer attempts protected navigation.
- **Generated images stay visible and use their intended Chat animation.** Completed image media survives a marker-lagging history refresh, and both the built-in `image_generate` tool and profile tools ending in `_create_image` use the image-generation presentation.
## [Plugin 1.11.1] - 2026-08-31
### Fixed
- **Hermes-Relay Plugin installs through the native Hermes command again.** The manifest remains fully described for current hosts while avoiding the installer/runtime schema mismatch in affected Hermes releases.
- **Relay prompt context advertises only real callable phone tools.** Phone-control and cross-platform delivery guidance now follows the exact selected session/profile tool catalog instead of implying unavailable `android_*` or `send_message` capabilities.
## [Android 1.14.0] - 2026-08-30
### Added
@@ -66,7 +177,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Dense pairing QRs scan reliably.** Dashboard, CLI, and TUI render integer-sized modules with a full quiet zone.
- **Remote-access migration keeps existing listeners safe.** Recommended setup avoids taking over `:443`, explicit legacy cleanup remains available, and default disable actions remove only the listeners they own.
## [0.4.0-beta.6] - 2026-08-30
## [0.4.0-beta.6] - 2026-08-31
### Changed
@@ -1254,7 +1365,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Voice-exit chime firing on every Add-connection tap.** `ConnectionSwitchCoordinator.switchConnection` fires the `voiceStopCallback` unconditionally at step 3 (correct for connection-to-connection switches while voice is active), but `beginAddConnection` also routes through `switchConnection` to bind the placeholder Connection's auth store before the pair wizard runs — and `VoiceViewModel.exitVoiceMode()` was playing `sfxPlayer.playExit()` regardless of whether voice mode was actually on. Logcat confirmed the chime on every Add-connection FAB tap. Fix adds an idempotence guard at the top of `exitVoiceMode()`: early-return when `_uiState.value.voiceMode` is already false. Teardown is still safe to skip because every inner statement is null-guarded + try/catch-wrapped and would be a no-op on an already-stopped voice session; the only meaningful line is the `playExit()` SFX, which is what we're silencing.
- **500 ms freeze on every Add-connection tap.** `ConnectionSwitchCoordinator.switchConnection` runs a `withTimeoutOrNull(AUTH_HYDRATE_TIMEOUT_MS = 500L)` block at step 10 to wait for the freshly-bound `AuthManager` to flip `AuthState` from `Loading` to `Paired`. The comment acknowledged Add-connection is the common path and the 500 ms was meant to be "imperceptible," but on-device it wasn't — the user perceived the delay (and the voice chime masking it) on every tap. The placeholder Connection created by `beginAddConnection` has `pairedAt == null` and an empty EncryptedSharedPreferences store, so `AuthState` will NEVER reach `Paired` — the 500 ms is pure stall. Fix short-circuits the hydrate wait when `target.pairedAt == null`: skip `withTimeoutOrNull` entirely for placeholders and log at DEBUG instead of the misleading "auth hydrate timeout" INFO. Real paired-to-paired switches still run the full hydrate wait because both sides have `pairedAt != null`.
- **KDoc nested-comment trap in `ConnectionViewModel.relayReady` doc block.** A literal `/voice/*` path pattern inside the `relayReady` KDoc opened a nested block comment (Kotlin supports nested `/* */`, Java does not) whose `*/` then closed only the nested level — leaving the outer `/**` open for the remaining ~2200 lines of the file. Symptom: `MainActivity.kt:67` "Unresolved reference 'isReady'" plus ~50 cascading "Cannot infer type" errors across `PairedDevicesScreen`, `SettingsScreen`, `TerminalScreen`. Real errors (`Missing '}`, `Unclosed comment`) were the last two lines of `./gradlew compileGooglePlayDebugKotlin` output, easy to miss. Fix was a two-character rewrite: path patterns now wrapped in backticks AND `/*` → `/...` so the glob-looking character isn't in a block-comment position. Lesson logged in `DEVLOG.md` 2026-04-21; worth a sweep of other KDoc blocks for shell/regex-looking patterns before the next large diff.
- **KDoc nested-comment trap in `ConnectionViewModel.relayReady` doc block.** A literal `/voice/*` path pattern inside the `relayReady` KDoc opened a nested block comment (Kotlin supports nested `/* */`, Java does not) whose `*/` then closed only the nested level — leaving the outer `/**` open for the remaining ~2200 lines of the file. Symptom: `MainActivity.kt:67` "Unresolved reference 'isReady'" plus ~50 cascading "Cannot infer type" errors across `PairedDevicesScreen`, `SettingsScreen`, `TerminalScreen`. Real errors (`Missing '}`, `Unclosed comment`) were the last two lines of `./gradlew compileGooglePlayDebugKotlin` output, easy to miss. Fix was a two-character rewrite: path patterns now wrapped in backticks AND `/*` → `/...` so the glob-looking character isn't in a block-comment position. Lesson logged in `docs/project/DEVLOG.md` 2026-04-21; worth a sweep of other KDoc blocks for shell/regex-looking patterns before the next large diff.
- **Orphan placeholder connections from abandoned Add-connection flows.** The `beginAddConnection` path pre-creates a placeholder Connection and switches to it before the pair wizard runs — so `applyPairingPayload` lands the token in the right auth store. Previously, cleanup of the placeholder was wired only to the explicit Cancel button and TopAppBar back arrow. System back (gesture back / predictive back) bypassed that branch, leaving the placeholder in the connection list forever. Two-part fix: (a) `PairScreen` now installs a `BackHandler` that routes system back through the same `onCancel` → `discardPlaceholderConnection` branch the explicit back arrow uses; (b) `ConnectionViewModel.init` sweeps for any existing orphans (tuple: `pairedAt == null && apiServerUrl.isBlank() && label == PLACEHOLDER_LABEL`) on cold start and removes them — the tuple cannot be produced by any real pairing, so the sweep is safe without a dry-run. If the active connection at startup points at an orphan, the sweep switches to the first surviving real connection before deleting. Fixes the "why does my chip say 'New connection…'" symptom on devices that were affected pre-fix.
- **Pair flow now auto-starts the camera on Add connection.** `ConnectionWizard` gains an `autoStart: String?` param (currently only `"scan"` is honored). The Add-connection FAB on `ConnectionsSettingsScreen` passes it so the wizard fires the camera permission launcher on first composition instead of forcing users through the Method chooser — one obvious next step, one-tap flow. Re-pair surfaces intentionally leave `autoStart` null so the full Scan / Enter code / Show code chooser stays available there. The deep-link arg is plumbed through `Screen.Pair`'s route (`pair?connectionId=...&autoStart=...`) and `PairScreen`'s new `autoStart` param; unrecognized values fall through to the default Method step so future builds can add more targets without breaking old ones.
@@ -2071,7 +2182,7 @@ picker.
- **`CLAUDE.md`** — updated Git section with the new branching policy,
added file-table entries for `hermes-relay-update`,
`register_code_command`, and the expanded `install.sh`
- **`TODO.md`** — captures open research questions around proper
- **`docs/project/TODO.md`** — captures open research questions around proper
Hermes plugin/skill/tool distribution
- **`user-docs` vitepress site** — new "For AI Agents" copy-paste
block on the home view, Feature Matrix component, two-track explainer,
+5 -9
View File
@@ -1,22 +1,18 @@
# Hermes-Relay CLI+UI v__VERSION__
**Release Date:** 2026-08-30
**Release Date:** 2026-09-02
This beta preserves complete multi-route pairing while preventing Desktop from dialing Dashboard-ingress Relay routes before Dashboard WebSocket ticket support is available. (Related: #399)
This beta fixes Windows updates so the installed CLI and management UI advance together. Explicit CLI-only installations keep their standalone update path.
**Beta phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64/arm64, and macOS x64/arm64; the management UI is Windows-only.
## What's changed
### Changed
- **Saved hosts retain the full route topology.** Dashboard, Relay, optional API, route priority, transport protection, certificate pins, and the selected host survive LAN, Tailscale, and public-route changes without creating duplicate hosts.
- **API-less pairing is first-class.** Dashboard plus direct Relay can pair without inventing an optional API server, while secure-first ranking retains plain LAN as the final fallback.
### Fixed
- **Dashboard-ingress Relay routes fail closed on Desktop.** The daemon, host selector, and Relay transport reject ingress that requires a Dashboard WebSocket ticket and choose a compatible direct Relay fallback instead of attempting an unauthenticated dial.
- **Pairing accepts the current v3 candidate shape.** Optional API records, same-origin Dashboard/Relay routes, and legacy top-level payloads remain compatible without collapsing route ownership.
- `hermes-relay update` detects an installed management UI beside the CLI and reports both installed versions.
- Bundle installations use the checksum-verified Windows installer to update and restart the affected CLI and UI together.
- Explicit CLI-only installations continue to use the standalone binary updater.
## Install
+15 -6
View File
@@ -82,6 +82,11 @@ Use the narrowest command that proves the change:
5. `scripts/dev.bat prepush` only when full local verification is explicitly
wanted or cloud execution is unavailable.
Android release preparation uses `python scripts/android-prepush.py
--release-prep` while version notes are changing. It keeps local feedback to
metadata and release-presentation tests; the exact pushed commit still goes
through required CI and Play preflight before publication.
`install-fast` is intentionally phone-specific. Use `install` for a universal
sideload debug APK or when the target ABI is not arm64. Release builds remain
universal and are unaffected unless `-Phermes.devAbi` is explicitly supplied.
@@ -254,16 +259,20 @@ translations may ship as `ai-translated`; do not claim fluent review unless a
review reference is recorded. Focused correction PRs from fluent contributors
are the canonical way to improve wording and can advance a locale to
`community-reviewed` or `verified` under `docs/translation-playbook.md`.
Translated READMEs use separate `README.<locale>.md` files; `README.md` remains
the canonical project description. User docs may be added incrementally under
`user-docs/<locale>/`, with links back to canonical English reference material.
Translated README entrypoints live under `docs/readme/` as
`README.<locale>.md`; root `README.md` remains the canonical project
description. Keep translated entrypoints concise: summarize onboarding and
core capabilities, link to localized user docs where available, and link back
to English for fast-moving architecture, security, and operator detail. User
docs may be added incrementally under `user-docs/<locale>/`, with links back to
canonical English reference material.
## Changelog & writing conventions
This is a **public repo** — `CHANGELOG.md`, `DEVLOG.md`, the README, and everything under `docs/` ship publicly. Keep them clean:
This is a **public repo** — `CHANGELOG.md`, `docs/project/DEVLOG.md`, the README, and everything under `docs/` ship publicly. Keep them clean:
- **`CHANGELOG.md`** follows [Keep a Changelog](https://keepachangelog.com/) (Added / Changed / Fixed). Append your change to the `## [Unreleased]` block in the PR. Entries can carry detail while they accumulate, but at release-prep the version block is **condensed to crisp public bullets** (1–2 lines each) — the deep "how we debugged it" narrative belongs in commit messages and `DEVLOG.md`, not the public changelog.
- **`DEVLOG.md`** is a factual engineering log — what changed, why, and how it was verified. Keep it depersonalized and third-person; it's a record, not a diary.
- **`CHANGELOG.md`** follows [Keep a Changelog](https://keepachangelog.com/) (Added / Changed / Fixed). Append your change to the `## [Unreleased]` block in the PR. Entries can carry detail while they accumulate, but at release-prep the version block is **condensed to crisp public bullets** (1–2 lines each) — the deep "how we debugged it" narrative belongs in commit messages and `docs/project/DEVLOG.md`, not the public changelog.
- **`docs/project/DEVLOG.md`** is a factual engineering log — what changed, why, and how it was verified. Keep it depersonalized and third-person; it's a record, not a diary.
- **No non-public wording anywhere committed:** no personal names (attribute impersonally — identity lives in git history), no real server hostnames/IPs or internal deployment names, no AI/assistant process self-narration, no fork/branch plumbing in user-facing notes. Generic example IPs in setup docs are fine.
Release notes (`RELEASE_NOTES.md`, `app/src/main/assets/whats_new.txt`, `docs/play-store-listing.md`) are theme-framed and user-facing; see [RELEASE.md](RELEASE.md) §2 "Scrub for public distribution" for the full checklist.
+4 -19
View File
@@ -1,29 +1,14 @@
# Hermes-Relay Plugin v__VERSION__
**Release Date:** August 30, 2026
**Release Date:** September 13, 2026
## Summary
This release lets one authenticated Hermes Dashboard origin carry Gateway plus optional Relay extensions, adds a bounded Git workspace, and reorganizes the Dashboard plugin around operator tasks. Standard chat, session history, profiles, Manage, and standard voice remain upstream-owned and do not require this plugin.
## Added
- **Dashboard same-origin Relay ingress.** Fixed allowlisted HTTP and WebSocket routes proxy to the local Relay while Dashboard admission and Relay session authentication remain independent. (Related: #399)
- **Bounded Git workspace.** Configured roots, path containment, line totals, diffs, branches, staging, commits, remotes, grants, and explicit confirmations protect repository operations.
## Changed
- **Task-oriented Dashboard UI.** Overview, Devices, Activity, Remote Access, Git, and Settings now have dedicated surfaces with QR-first pairing, responsive device cards, and honest media diagnostics. (#486)
- **One explicit route topology.** Dashboard, CLI, and TUI pairing advertise Dashboard, Relay, and optional API surfaces with stable priorities across Tailscale, public HTTPS, and LAN.
- **Dedicated Tailscale listener.** Recommended setup uses tailnet HTTPS `:10443` to local Dashboard `:9119`, avoiding ownership of a reverse proxy's `:443`. Existing `:443`, `:9119`, and direct `:8767` routes remain migration compatibility.
Dashboard WebSocket connections work again with current Hermes authentication helpers, while older Hermes hosts remain supported.
## Fixed
- Public and roaming invites no longer synthesize closed direct Relay `:8767` or wrong Dashboard `:9119` routes.
- Ambiguous, credential-bearing, or plaintext public candidates fail closed before an invite is exposed.
- Dense pairing QRs use integer-sized modules and a full quiet zone.
- Inactive optional API routes are omitted; protected Dashboard-ingress `401/403` responses display as authentication-required while direct Relay and API failures remain failures.
- Default Tailscale disable actions remove only owned listeners, and explicit migration cleanup accepts only the bounded supported ports.
- Resolve WebSocket guards from their current upstream module and retain the older-host fallback. Single-use tickets, Host/Origin/IP checks, and independent Hermes-Relay session authentication remain enforced. Missing or incomplete helper contracts deny admission.
## Install / update
@@ -35,7 +20,7 @@ This release lets one authenticated Hermes Dashboard origin carry Gateway plus o
# or, if already installed:
hermes-relay-update
Restart or reload the Hermes Dashboard and Relay after updating so the new manifest, routes, and committed Dashboard bundle are active.
Restart or reload the Hermes Dashboard and Relay after updating so the new manifest and prompt context are active.
## Verify
+32 -27
View File
@@ -1,5 +1,5 @@
<p align="center">
<img src="assets/play-store-feature-1024x500.png" alt="Hermes-Relay — your Hermes agent, in your pocket" width="800">
<img src="assets/readme-hero-v2.jpg" alt="Hermes-Relay — Your Hermes agent. Wherever you are. Android, Voice, Desktop." width="1000">
</p>
<p align="center">
@@ -21,7 +21,13 @@
</p>
<p align="center">
<strong>English</strong> · <a href="README.zh-CN.md">简体中文</a><br>
<strong>English</strong> ·
<a href="docs/readme/README.de.md">Deutsch</a> ·
<a href="docs/readme/README.es.md">Español</a> ·
<a href="docs/readme/README.ja.md">日本語</a> ·
<a href="docs/readme/README.pt-BR.md">Português (Brasil)</a> ·
<a href="docs/readme/README.ru.md">Русский</a> ·
<a href="docs/readme/README.zh-CN.md">简体中文</a><br>
<a href="https://hermes-relay.dev/docs/">Documentation</a> ·
<a href="https://github.com/Codename-11/hermes-relay/releases">Releases</a> ·
<a href="https://github.com/Codename-11/hermes-relay/discussions">Discussions</a> ·
@@ -38,10 +44,10 @@ Hermes-Relay puts your [Hermes agent](https://github.com/NousResearch/hermes-age
- **📱 Android app** — streaming chat, hands-free voice, native plugin pages, and the full Hermes dashboard (models, keys, skills, profiles), rebuilt native. Add a floating Petdex companion or optionally make Hermes your Android assistant; sideload builds can also let the agent read and act on your screen.
- **⌨️ Hermes-Relay CLI** *(beta)* — a single binary that gives the agent **hands on any machine you pair**: files, terminal, search, screenshots — consent-gated.
A vanilla [hermes-agent](https://github.com/NousResearch/hermes-agent) install is enough for the upstream standard path: chat, management, voice, Petdex, and ordinary installed-plugin pages. The Hermes-Relay plugin is optional for that base but encouraged for the complete current experience: Terminal/TUI, notifications, media, desktop tools, enhanced voice, Relay sessions, page drafts, and optional Device Control. Hermes-Relay prefers compatible upstream surfaces as they become available instead of keeping duplicate extension paths. **Connect Hermes first, then grant Hermes-Relay separately; the same one-time invite contract pairs Android or the Desktop CLI.**
A vanilla [hermes-agent](https://github.com/NousResearch/hermes-agent) install is enough for the upstream standard path: chat, management, voice, inbound files, Petdex, and ordinary installed-plugin pages. The Hermes-Relay plugin is optional for that base but encouraged for the complete current experience: Terminal/TUI, notifications, desktop tools, enhanced voice, Relay sessions, page drafts, optional Device Control, and media compatibility or metadata. Hermes-Relay prefers compatible upstream surfaces as they become available instead of keeping duplicate extension paths. **Connect Hermes first, then grant Hermes-Relay separately; the same one-time invite contract pairs Android or the Desktop CLI.**
<p align="center">
<img src="docs/diagrams/architecture-homepage.png" alt="How Hermes-Relay connects — upstream Hermes owns Chat, Manage, and standard Voice; the encouraged Relay extension fills current gaps for Terminal, notifications, media, enhanced voice, sessions, desktop tools, and optional Device Control." width="900">
<img src="assets/readme-connection-map-v2.png" alt="How Hermes-Relay connects — Dashboard and Gateway own the standard Android path for Chat, Manage, Voice, and inbound files; the optional Relay plugin separately adds Android enhancements plus CLI and UI tools; sideload adds Device Control." width="1000">
</p>
## Quick Start (Android)
@@ -50,7 +56,7 @@ Install → connect → talk, in about two minutes.
### 1 · Install the app
- **Google Play** *(easiest — auto-updates)* — [**install from Google Play**](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay). Chat, voice, sessions, and Manage work with standard Hermes; pairing the Hermes-Relay plugin adds Terminal/TUI, media, notifications, and Relay sessions.
- **Google Play** *(easiest — auto-updates)* — [**install from Google Play**](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay). Chat, voice, sessions, Manage, and inbound files work with standard Hermes; pairing the Hermes-Relay plugin adds Terminal/TUI, notifications, Relay sessions, and media enhancements.
- **APK** *(full phone-control feature set)* — download the file ending in **`-sideload-release.apk`** from the newest `android-v*` release on [GitHub Releases](https://github.com/Codename-11/hermes-relay/releases) and open it (allow your browser to install unknown apps the first time). Integrity verification, signing fingerprint, and per-build details are in the [Sideload guide](https://hermes-relay.dev/docs/guide/getting-started.html#sideload-apk).
Sideload builds check GitHub for updates and show a one-tap banner when you're behind; Play builds update through the Store. See [Release tracks](https://hermes-relay.dev/docs/guide/release-tracks) for the capability matrix.
@@ -58,7 +64,7 @@ Sideload builds check GitHub for updates and show a one-tap banner when you're b
### 2 · Have the Hermes Dashboard running
The normal Android connection uses the upstream Hermes Dashboard/Gateway for
chat, sign-in, sessions, Manage, and voice. Installing Hermes and choosing a
chat, sign-in, sessions, Manage, voice, and inbound files. Installing Hermes and choosing a
provider is vanilla Hermes setup:
```bash
@@ -77,16 +83,15 @@ the [remote-access guide](https://hermes-relay.dev/docs/guide/remote-access/).
### 3 · Connect and talk
For a plugin-enabled host, open the Web Dashboard's **Relay** page, click
**Connect mobile app**, and scan that tokenless QR from Android **Connect → Scan
Hermes setup QR**. It contains only the Dashboard address and configures the
upstream Chat, sessions, Manage, sign-in, and standard voice connection.
Without the Dashboard plugin, use **Find Hermes on LAN** or enter the Dashboard
address manually (conventionally `http://<host>:9119`). Sign in through the
Use **Find Hermes on LAN** or enter the Dashboard address manually
(conventionally `http://<host>:9119`). Sign in through the
Dashboard's configured provider when prompted. The app probes the available
upstream capabilities and finishes with a connection summary.
If the Relay Dashboard page is already installed, **Connect mobile app** offers
the same standard connection as a tokenless QR. It contains only the Dashboard
address and does not install, enable, or pair Relay.
The separate API server can be discovered automatically or added later under
**Advanced** as a chat fallback or for a headless compatibility setup. Its API
key is requested only when that optional endpoint is configured. Existing
@@ -99,7 +104,7 @@ The wizard probes everything and finishes with a capability card:
| **Chat** | Dashboard/Gateway ready — you can talk |
| **Manage** | Models, keys, skills, and profiles are available from the phone |
| **Voice** | Speech ready via your server (or one Manage sign-in away) |
| **API fallback** | Optional API route available/unavailable |
| **Direct API** | Optional API-only compatibility route available/unavailable |
| **Relay** | Recommended extensions paired/unpaired; never blocks the upstream path |
One dashboard sign-in unlocks Chat, Manage, sessions, and standard voice. That's
@@ -109,9 +114,9 @@ the whole Vanilla Hermes setup.
### 4 · Recommended: pair Relay for the complete experience
Install Relay for Terminal/TUI, notifications, media handoff, desktop tools,
enhanced voice, Relay sessions, approval-gated page drafts, and optional Device
Control:
Install Relay for Terminal/TUI, notifications, desktop tools, enhanced voice,
Relay sessions, approval-gated page drafts, optional Device Control, and media
compatibility or sensitivity metadata:
```bash
hermes plugins install Codename-11/hermes-relay/plugin --enable
@@ -140,7 +145,7 @@ manual fallbacks when QR or clipboard transfer is unavailable.
[Desktop CLI pairing](https://hermes-relay.dev/docs/desktop/pairing) ·
[server, TLS, legacy install, and uninstall reference](https://hermes-relay.dev/docs/reference/relay-server)
**Requirements:** Android 8.0+ (SDK 26) · current upstream [hermes-agent](https://github.com/NousResearch/hermes-agent) with the Dashboard/Gateway enabled · Python 3.11+ when installing the Hermes-Relay plugin. The API fallback is optional; the Hermes-Relay plugin is encouraged for the complete experience.
**Requirements:** Android 8.0+ (SDK 26) · current upstream [hermes-agent](https://github.com/NousResearch/hermes-agent) with the Dashboard/Gateway enabled · Python 3.11+ when installing the Hermes-Relay plugin. Direct API is optional; the Hermes-Relay plugin is encouraged for the complete experience.
## Screenshots
@@ -161,7 +166,7 @@ manual fallbacks when QR or clipboard transfer is unavailable.
<p align="center">
<img src="assets/screenshots/supplemental/15_git_workspace.png" alt="Native Git workspace showing repository changes, an inline diff, and staging controls" width="260"><br>
<sub><b>Native Git workspace</b> — optional Hermes-Relay plugin</sub>
<sub><b>Native Git workspace</b> — upstream session context with optional Relay discovery and operations</sub>
</p>
### Simplified Chinese
@@ -215,7 +220,7 @@ hermes-relay update # self-update via GitHub Releases
It pairs against the **same relay and credential store** as the Android app — pair once from either, both work. Tagged on the `desktop-v*` [release track](https://github.com/Codename-11/hermes-relay/releases?q=desktop), with historical releases still visible under `cli-v*`.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. It is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. `hermes-relay update` detects this bundle and updates the CLI and UI together; explicit CLI-only installations stay headless and continue using the standalone binary updater. The UI is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
<table>
<tr>
@@ -239,17 +244,17 @@ remote tool surface. See the [desktop tools guide](https://hermes-relay.dev/docs
## How It Works
```
Phone (HTTP/WSS) --> Hermes Dashboard (:9119) [chat gateway, manage, vanilla voice]
Phone (HTTP/SSE) --> Hermes API Server (:8642) [chat fallback, sessions, runs]
Phone (WSS/HTTP) --> Relay (:8767) [terminal, bridge, media, relay voice, sessions]
Phone (HTTP/WSS) --> Hermes Dashboard (:9119) [chat gateway, manage, vanilla voice, inbound files]
Phone (HTTP/SSE) --> Hermes API Server (:8642) [Direct API chat, sessions, runs]
Phone (WSS/HTTP) --> Relay (:8767) [terminal, bridge, media enhancements, relay voice, sessions]
CLI (WSS) --> Relay (:8767) [machine tools, tui, terminal]
```
Chat prefers the Hermes dashboard gateway when Manage auth is ready, then falls
back to the upstream API server SSE path with the API key. Manage and Vanilla Hermes
Standard connections keep Chat on the Hermes Dashboard/Gateway. Explicit API-only
connections use the upstream Direct API SSE path with an API key. Manage and Vanilla Hermes
voice ride the Hermes dashboard with its own one-time sign-in, so a vanilla
install needs no plugin for either. The optional relay on `:8767` adds the power
surfaces: terminal, bridge phone control, media handoff, machine tools, and
install needs no plugin for those surfaces or ordinary inbound files. The optional relay on `:8767` adds
terminal, bridge phone control, media compatibility/metadata, machine tools, and
relay-side voice, which is preferred automatically when paired. One QR can
configure API, dashboard, and relay routes without merging their auth models.
-109
View File
@@ -1,109 +0,0 @@
<p align="center">
<img src="assets/play-store-feature-1024x500.png" alt="Hermes-Relay — 随身携带您的 Hermes 代理" width="800">
</p>
<p align="center">
<strong>运行在您的电脑上,连接到您的设备。</strong><br>
Hermes-Relay 是 <a href="https://github.com/NousResearch/hermes-agent">Hermes Agent</a> 的原生 Android 客户端,提供流式聊天、免手动语音和代理管理;另有单文件 CLI,让代理在已配对的电脑上安全使用终端、文件和截图工具。
</p>
<p align="center">
<strong>简体中文</strong> · <a href="README.md">English</a><br>
<a href="https://hermes-relay.dev/docs/zh-CN/">中文文档</a> ·
<a href="https://github.com/Codename-11/hermes-relay/releases">版本下载</a> ·
<a href="https://github.com/Codename-11/hermes-relay/discussions">社区讨论</a> ·
<a href="CHANGELOG.md">更新日志</a>
</p>
> 英文 [README.md](README.md) 是最新、完整的项目说明。本页维护中文安装入口和核心功能摘要;协议、架构和维护者文档以英文版本为准。
## 功能简介
- **Android 应用**:流式聊天、会话历史、文件附件、Hermes 管理、语音模式、原生插件页面、Petdex 悬浮宠物、多连接和配置文件;也可将 Hermes 设为 Android 助手。
- **无需插件的标准路径**:聊天、管理和标准语音可直接连接未修改的上游 Hermes Agent。
- **可选 Relay 插件**:增加终端、手机控制、媒体传输、通知助手、Relay 语音、电脑工具,以及需确认的代理创建插件页面草稿。
- **安全连接**:二维码配对、Android Keystore、证书固定、按通道授权和可配置会话有效期。
- **远程使用**:可配置 Tailscale 或 HTTPS 地址,在家庭局域网和远程路由之间自动切换。
- **两种 Android 发行渠道**:Google Play 版本适合日常使用;sideload 版本包含完整手机控制能力。
## 快速开始
### 1. 安装 Android 应用
- [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay):自动更新,包含聊天、语音、管理、终端、媒体和通知功能。
- [GitHub Releases](https://github.com/Codename-11/hermes-relay/releases):下载最新 `android-v*` 版本中以 `-sideload-release.apk` 结尾的文件,获得完整手机控制功能。
### 2. 启动 Hermes API 服务
手机需要能够访问 Hermes API 服务,并使用 API 密钥进行身份验证:
```bash
hermes setup --portal
mkdir -p ~/.hermes
API_SERVER_KEY="$(openssl rand -hex 32)"
cat >> ~/.hermes/.env <<EOF
API_SERVER_ENABLED=true
API_SERVER_HOST=0.0.0.0
API_SERVER_PORT=8642
API_SERVER_KEY=$API_SERVER_KEY
EOF
chmod 600 ~/.hermes/.env
echo "Android API URL: http://<电脑IP>:8642 key: $API_SERVER_KEY"
hermes gateway
```
`0.0.0.0` 会让同一网络中的设备访问 API。请保留强密钥;离开可信局域网时,应使用 Tailscale 或 HTTPS 反向代理,不要直接把端口暴露到互联网。
### 3. 在手机上连接
打开应用后,可以:
- 扫描局域网中的 Hermes;
- 手动输入 `http://<主机>:8642` 和 API 密钥;
- 扫描包含 API、Dashboard 和可选 Relay 地址的设置二维码。
如需在手机上管理模型、密钥、技能和配置文件,请运行 Hermes Dashboard,并在应用的 **管理** 页面登录一次。同一登录会话也会启用标准语音。
### 4. 可选:安装 Relay
仅在需要终端、手机控制、媒体路由、Relay 会话、实时语音、电脑工具或代理创建插件页面草稿时安装:
```bash
hermes plugins install Codename-11/hermes-relay/plugin --enable
hermes relay doctor
hermes relay start --no-ssl
hermes pair
```
已安装的 Hermes 插件可通过已认证的 Dashboard 向 Android 提供由应用安全渲染的原生页面,无需在手机上运行插件代码。Relay 1.5.0 另支持需用户确认的代理创建页面草稿。
完整说明请阅读[中文快速开始](https://hermes-relay.dev/docs/zh-CN/guide/quick-start);远程访问、协议和高级配置暂时链接到英文参考文档。
安装问题、早期想法、一般交流和作品分享请使用 [GitHub Discussions](https://github.com/Codename-11/hermes-relay/discussions)。可复现的错误和明确、可执行的功能请求请提交到 [Issues](https://github.com/Codename-11/hermes-relay/issues/new)。
## 中文界面
<table>
<tr>
<td align="center" width="33%"><img src="assets/screenshots/Zh01.jpg" alt="中文设置界面" width="100%"><br><sub><b>设置</b></sub></td>
<td align="center" width="33%"><img src="assets/screenshots/Zh02.jpg" alt="中文管理界面" width="100%"><br><sub><b>管理</b></sub></td>
<td align="center" width="33%"><img src="assets/screenshots/Zh03.jpg" alt="中文导航界面" width="100%"><br><sub><b>导航</b></sub></td>
</tr>
</table>
## 参与翻译
Android 英文资源是规范来源。新增语言必须保持资源名称、类型和格式参数一致,并通过:
```bash
python scripts/check-android-locales.py
./gradlew lint
```
翻译规范、目录命名、复数和占位符规则见 [docs/localization.md](docs/localization.md)。
## 许可证
[MIT](LICENSE) — Copyright (c) 2026 [Axiom-Labs](https://codename-11.dev)
+87 -45
View File
@@ -628,6 +628,21 @@ and the release notes and learn only what the software does.
### 3. Build and verify locally
During release-note/version iteration, use the narrow release-prep lane:
```powershell
python scripts/android-prepush.py --release-prep
```
It runs release metadata checks plus the rendered Changelog/What's New tests in
the serialized Android lane. Once the exact commit is pushed, current-head CI
and Play preflight own lint, focused shards, both-flavor assemblies, signing,
and final package scans. Do not repeat the complete local release build unless
cloud execution is unavailable or explicit local artifact/device proof is
needed.
For that explicit full local proof:
```bat
scripts\dev.bat bundle
keytool -printcert -jarfile app\build\outputs\bundle\googlePlayRelease\hermes-relay-*-googlePlay-release.aab
@@ -661,14 +676,17 @@ The preflight workflow:
3. builds and release-signs the same APK/AAB variants used by the public release;
4. scans the final minified APK DEX for unsupported collection calls;
5. uploads the Google Play AAB as a private **Production draft**; and
6. records a 30-day preflight proof keyed to the version and Git tree hash.
6. retains the exact signed sideload APK, Play AAB, R8 mappings, manifest, and
checksums as one immutable 30-day artifact keyed to version and Git tree.
No sideload APK or GitHub Release is published by preflight. A successful signed
build, final DEX scan, and Production-draft upload is the automated Play release
gate. Play Console pre-review and pre-launch reports are informational and
non-blocking because their detailed results are not exposed through the release
automation API. If the release source changes after preflight, rerun it—the
approval workflow matches the complete Git tree, not just the version number.
build, final package scans, and Production-draft upload is the automated Play
release gate. The private artifact is immutable and hash-verified again before
publication; the stable release workflow does not rebuild those bytes. Play
Console pre-review and pre-launch reports are informational and non-blocking
because their detailed results are not exposed through the release automation
API. If the release source changes after preflight, rerun it—the approval
workflow matches the complete Git tree, not just the version number.
GitHub exposes manual workflows only after their workflow file exists on the
default branch. For the first release that introduces this process, merge the
@@ -709,12 +727,13 @@ from `main`; every release job explicitly checks out and verifies the immutable
an existing tag or changing its artifact tree. Manual stable tags are still
guarded by the same preflight proof in the tag workflow.
The tag-triggered `.github/workflows/release-android.yml` rebuilds and scans the
artifacts, changes the existing Play Production draft to `completed` (submitting
it for review), and only after Play accepts that operation creates the public
GitHub Release with the sideload APK. A missing preflight, changed release tree,
missing Play credential, or Play submission failure prevents public GitHub
publication.
The tag-triggered `.github/workflows/release-android.yml` downloads the exact
private preflight artifact by ID, verifies its source workflow, manifest, tree,
version, sizes, and hashes, reruns the package scanners, then changes the
existing Play Production draft to `completed` (submitting it for review). Only
after Play accepts that operation does it publish those same APK/AAB bytes on
GitHub. A missing preflight, changed release tree, artifact mismatch, missing
Play credential, or Play submission failure prevents public publication.
Plugin/Python version files are intentionally not part of an Android app
release unless the plugin package itself is also being released.
@@ -743,14 +762,19 @@ git commit -m "release(server): server-v0.6.2"
git push origin dev
# Open the release PR (dev -> main) and merge with --no-ff.
# After merge, tag from the new main tip:
git checkout main
git pull --ff-only origin main
git tag server-v0.6.2
git push origin server-v0.6.2
# Then run "Hermes-Relay Plugin and CLI+UI Release Approval" from main,
# select plugin, and enter 0.6.2. The workflow selects and validates main
# before it creates server-v0.6.2 and starts the immutable-tag release workflow.
```
Pushing `server-v*` triggers `.github/workflows/release-plugin.yml`, which
For a Plugin prerelease, keep the release-prepared commit on `dev` and run the
same trusted approval workflow from `main`; the version suffix makes it select
and validate the exact `origin/dev` tip before creating the tag. Stable versions
select `origin/main` instead.
Direct `server-v*` tag pushes remain a recovery path and are guarded by the same
branch-containment and metadata checks.
The approval workflow dispatches `.github/workflows/release-plugin.yml`, which
validates all plugin-owned version metadata with
`scripts/check-plugin-version-sync.py`. Run
`python scripts/check-version-tracks.py` locally before tagging when a change
@@ -781,20 +805,25 @@ git add desktop/package.json desktop/package-lock.json desktop/src/version.ts `
git commit -m "release(desktop): desktop-v0.4.0-alpha.2"
git push origin dev
# Open the release PR (dev -> main) and merge with --no-ff.
# After merge, tag from main:
git switch main
git pull --ff-only origin main
cd desktop
npm run check:version-sync -- --expect 0.4.0-alpha.2
cd ..
git tag desktop-v0.4.0-alpha.2
git push origin desktop-v0.4.0-alpha.2
# This is a prerelease: run "Hermes-Relay Plugin and CLI+UI Release Approval"
# from main, select desktop, and enter 0.4.0-alpha.2. The workflow validates dev
# before it creates the tag and starts the immutable-tag release workflow.
```
The tag workflow rejects version drift and tags whose commit is not in
`origin/main`, reruns CLI tests, builds all four standalone binaries, tests and
packages the Windows tray, generates checksums, and publishes the GitHub Release.
For a stable CLI+UI version, first merge the release PR from `dev` to `main`,
then run the approval workflow from `main`. The version determines the source:
prereleases select the exact `origin/dev` tip and stable releases select the
exact `origin/main` tip before creating any tag. Direct `desktop-v*` tag pushes
remain a recovery path.
The release workflow rejects version drift and requires prerelease tags to be
contained in `origin/dev` and stable tags to be contained in `origin/main`. It
reruns CLI tests, builds all four standalone binaries, tests and packages the
Windows tray, generates checksums, and publishes the GitHub Release.
Trusted desktop CI and the release installer job share a Cargo/target cache
keyed by the lockfile and exact tray sources. A `main` push for the release tree
warms the exact cache before the immutable tag build; a miss safely performs the
ordinary Rust/Tauri build.
### 6. Play review and publishing behavior
@@ -895,7 +924,7 @@ gradlew promoteReleaseArtifact --from-track=internal --promote-track=production
(This step was only needed as a retrofit for v0.1.0 — v0.1.1+ inherit
the Download section automatically from `RELEASE_NOTES.md`.)
- Confirm Play Console shows the new versionCode on the target track.
- Update `DEVLOG.md` with a short entry for the release.
- Update `docs/project/DEVLOG.md` with a short entry for the release.
## CI Behavior
@@ -903,28 +932,40 @@ Android, Plugin, dashboard, and desktop now have separate CI/release lanes.
This keeps a dashboard CSS fix from running the full server suite, and keeps
plugin changes from forcing an Android app `versionCode` bump.
Every successful `Required checks` run records a short-lived proof keyed to the
checked Git tree. For the canonical `dev` → `main` release PR, CI first proves
the simulated merge tree is identical to the `dev` tree. If an unexpired proof
from a successful Required-checks run exists, the PR verifies and reuses it;
otherwise it automatically falls back to the normal path-aware matrix. Content
changes can never reuse an older proof because they change the tree hash.
On every push of a tag matching `android-v*`, `.github/workflows/release-android.yml`:
1. Verifies a stable tag resolves to a commit contained in `main`, or a
prerelease tag resolves to a commit contained in `dev`, and that the tag matches `appVersionName` in
`gradle/libs.versions.toml` (mismatches fail the workflow).
2. Runs the Android debug build and the stable sideload pairing/connection
regression slice with explicit timeouts.
3. Decodes `HERMES_KEYSTORE_BASE64` into `$RUNNER_TEMP/release.keystore`
and exports `HERMES_KEYSTORE_PATH` (skipped if the secret is unset).
4. For stable releases, builds all four flavored release artifacts
(`./gradlew bundleRelease assembleRelease`); only the sideload APK and
googlePlay AAB are attached. For prereleases, builds only the side-by-side
`sideloadCandidate` APK.
5. Generates `SHA256SUMS.txt` covering the two attached files.
6. For stable releases only, promotes the exact preflighted Production draft to
2. For stable releases, verifies and downloads the exact immutable Play
preflight artifact; prereleases run the focused CI slice and build the
side-by-side `sideloadCandidate` APK.
3. Revalidates stable artifact hashes, DEX collection compatibility, packaged
native compatibility, and retained R8 mappings without recompiling.
4. Generates candidate checksums when applicable; stable checksums come from
the verified preflight artifact and cover the two public files.
5. For stable releases only, promotes the exact preflighted Production draft to
`completed`; prereleases never upload to Play.
7. Creates a GitHub Release named `Hermes-Relay Android v<version>` with `RELEASE_NOTES.md` as
6. Creates a GitHub Release named `Hermes-Relay Android v<version>` with `RELEASE_NOTES.md` as
the body. Attaches the APK, AAB, and `SHA256SUMS.txt`. Tags any version
containing a dash (e.g. `android-v0.2.0-beta.1`) as a prerelease automatically.
8. Prints a `$GITHUB_STEP_SUMMARY` with the release and Play result.
7. Prints a `$GITHUB_STEP_SUMMARY` with the release and Play result.
On every push of a tag matching `server-v*`,
For an approved multi-surface train, run **Hermes-Relay Coordinated Release
Approval** from `main`, select the affected surfaces, and enter their prepared
versions. It dispatches Android, Plugin, and CLI+UI approval jobs concurrently;
each surface keeps its independent source, validation, tag, artifact, and
publication workflow.
On every direct push of a tag matching `server-v*`, or after an approved
dispatch from `.github/workflows/approve-release-extensions.yml`,
`.github/workflows/release-plugin.yml`:
1. Verifies a stable tag commit is contained in `main`, or a prerelease tag is
@@ -937,7 +978,8 @@ On every push of a tag matching `server-v*`,
5. Creates a GitHub Release named `Hermes-Relay Plugin v<version>` with the wheel,
sdist, and checksum file attached.
On every push of a tag matching `desktop-v*`,
On every direct push of a tag matching `desktop-v*`, or after an approved
dispatch from `.github/workflows/approve-release-extensions.yml`,
`.github/workflows/release-cli.yml` builds and publishes the CLI binaries and
Windows tray installer. Its GitHub Release body comes from `CLI_RELEASE_NOTES.md`
(rewritten per release — the CLI counterpart of `RELEASE_NOTES.md`); the workflow
+16 -21
View File
@@ -1,10 +1,10 @@
# Hermes-Relay Android v1.14.0
# Hermes-Relay Android v1.17.0
**Release Date:** August 30, 2026
**Release Date:** September 13, 2026
## Download
> Installing on your phone? Download `hermes-relay-1.14.0-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
> Installing on your phone? Download `hermes-relay-1.17.0-sideload-release.apk` and tap it for the full feature set, or install from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
The `.aab` file is a Play Console upload bundle and cannot be installed by tapping it on a phone.
@@ -12,33 +12,28 @@ Verify the download against `SHA256SUMS.txt`. See the [sideload guide](https://h
## Summary
This release makes saved Hermes connections reliable across LAN, Tailscale, and public HTTPS while keeping Dashboard authentication bound to its exact trusted origin. It also adds delegated-agent previews and an optional native Git workspace, and improves Voice, Assistant, Threads, profile drafts, and Clarify interactions.
Google Play gains optional voice controls over other apps. This release also makes Clarify batches, profile identity, and chat context easier to follow while preserving confirmed answers and saved conversations.
## Added
- **Delegated-agent previews.** Follow bounded lifecycle, progress, tool previews, and available read-only child history without leaving the parent chat. Partial history and reconnect gaps remain explicit. (#447)
- **Native Git workspace.** Review repository state, diffs, branches, staging, commits, and remotes from Chat or Settings. Git operations require Hermes-Relay Plugin v1.11.0 and retain confirmation and grant boundaries.
- Start Voice Overlay from Voice Focus after granting microphone, notification, and display-over-other-apps access. Permission grants require a separate Start action. Stop voice from the overlay or persistent notification; screen lock, task removal, and permission loss end the session.
## Changed
- **Route-aware connections.** Dashboard, Relay, and optional API health are evaluated independently across LAN, Tailscale, and public HTTPS. Same-origin Relay ingress stays on the Dashboard origin that owns authentication, while direct compatibility routes keep separate credentials. (Related: #399)
- **Voice Focus controls.** Stop and immediate spoken steering remain accessible while Hermes is Thinking, Transcribing, or Speaking, including TalkBack, Switch Access, keyboard, and sideload overlay surfaces.
- Standalone response cards use one surface, assistant bubbles are subtler, and timestamps share a row with delivery status.
## Fixed
- Wake-word detection packages one compatible ONNX Runtime for sherpa and Java JNI on every supported ABI. (#444)
- Continuous voice waits for barge-in microphone teardown before listening again. (#464)
- Fresh chats retain their selected profile without reopening a previous session or carrying a proactive Thread route across profiles. (#436)
- Provisional Threads can be removed locally and reconcile with promoted sessions without deleting server history. (#461)
- Clarify cards expose a reachable Other answer, keyboard Send, and authoritative expiry behavior. (#446)
- Passive Android browsing no longer claims or interrupts a turn owned by another client. (Related: #365)
- Assistant sessions show retryable no-speech feedback, recover their active state after recreation, and redact conversation details behind the keyguard. (Related: #424)
- Protected Relay ingress `401/403` responses are recognized as authentication boundaries rather than outages; malformed, different-origin, and direct unauthorized routes still fail closed.
- Answer upstream Clarify batches one question at a time, with independent choices, custom answers, and confirmed progress across reconnects. (#474)
- Context previews show that Gateway chats cannot send phone status or general turn context. Automatic phone-status sharing remains supported for API-only chats. (#556)
- Profiles display their Hermes names and group the resolved server default under its agent identity, preserving explicit selection and saved conversations.
## Install / Verify
- App version: **1.14.0** (versionCode **52**).
- Standard Chat, sessions, profiles, Manage, and standard voice continue to work against unmodified upstream Hermes without the optional Relay plugin.
- Install Hermes-Relay Plugin v1.11.0 for same-origin Relay extensions, Git workspace actions, Bridge, media, proactive features, and enhanced voice.
- Granular Device Control and the system Voice Focus overlay remain sideload-only; the Google Play build does not declare their restricted permissions.
- Existing connections, drafts, sessions, profile ownership, and legacy direct Relay routes remain data-preserving compatibility paths.
- App version: **1.17.0** (versionCode **57**).
- Standard Chat, sessions, profiles, Manage, voice, and ordinary media use current upstream Hermes. Speech-to-text still requires a configured provider on the host.
- Hermes-Relay Plugin **1.11.3** is the optional release for Hermes-Relay tools and current Dashboard WebSocket compatibility.
- Explicit Direct API/API-only connections remain supported and are not used as silent failover for Dashboard-owned chats.
- Voice Overlay is available in Google Play and sideload builds. Device Control remains sideload-only.
- Gateway phone-status delivery and automatic Android identification remain unavailable pending upstream support.
- Physical Android 14-16 and OEM voice-overlay testing was not performed for this release. Code, rendered UI, existing emulator evidence, CI, and signed-package preflight provide the recorded verification.
+6 -5
View File
@@ -100,9 +100,9 @@ android {
}
// ─── Bridge release tracks ─────────────────────────────────────────────────
// Google Play ships Bridge Core only: pairing, chat, voice, terminal/TUI,
// Google Play ships Bridge Core and user-started voice-only overlay: pairing, chat, voice, terminal/TUI,
// media, notification companion, relay sessions, and status. It does not
// declare AccessibilityService, overlay, MediaProjection, wake-lock device
// declare AccessibilityService, MediaProjection, wake-lock device
// control, SMS/call/contact/location, or unattended-control permissions.
//
// googlePlay — canonical Play Store install. Bridge Core only.
@@ -367,8 +367,9 @@ dependencies {
implementation(libs.okhttp)
implementation(libs.okhttp.sse)
// Media3 ExoPlayer — gapless TTS queue playback (replaces MediaPlayer in VoicePlayer)
// Media3 ExoPlayer + lifecycle-aware Compose video surface.
implementation(libs.media3.exoplayer)
implementation(libs.media3.ui.compose)
// android-vad Silero — on-device VAD for barge-in (B2)
// Bundled ONNX Silero model (~2.2 MB); pulled from JitPack.
@@ -457,8 +458,8 @@ dependencies {
// [POC] Roborazzi host-side screenshot rendering (src/test, Robolectric).
// Renders real composables on the JVM at an exact canvas — no device, no
// status bar, no clipping. See StoreScreenshotTest.
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.73.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.73.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.74.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.74.0")
testImplementation(libs.compose.ui.test.junit4)
testImplementation(libs.compose.ui.test.manifest)
testImplementation("androidx.test.ext:junit:1.3.0")
+3
View File
@@ -55,6 +55,9 @@
-keep class androidx.camera.** { *; }
-dontwarn androidx.camera.**
# sherpa-onnx JNI resolves Kotlin configuration classes and fields by name.
-keep class com.k2fsa.sherpa.onnx.** { *; }
# ── General ──────────────────────────────────────────────────────────
-keepattributes SourceFile,LineNumberTable
-renamesourcefileattribute SourceFile
@@ -0,0 +1,100 @@
package com.hermesandroid.relay.network.shared
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.hermesandroid.relay.data.ApiEndpoint
import com.hermesandroid.relay.data.EndpointCandidate
import kotlinx.coroutines.CoroutineStart
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.async
import kotlinx.coroutines.runBlocking
import kotlinx.coroutines.withTimeout
import okhttp3.OkHttpClient
import okhttp3.Protocol
import okhttp3.Response
import okhttp3.ResponseBody.Companion.toResponseBody
import org.junit.Assert.assertEquals
import org.junit.Assert.assertTrue
import org.junit.Test
import org.junit.runner.RunWith
import java.io.InterruptedIOException
import java.util.concurrent.CountDownLatch
import java.util.concurrent.TimeUnit
import java.util.concurrent.atomic.AtomicInteger
@RunWith(AndroidJUnit4::class)
class EndpointResolverConcurrencyInstrumentedTest {
@Test
fun probeCompletionRacingInvalidation_staysCrashFreeOnAndroidCollections() = runBlocking {
repeat(25) { iteration ->
val candidateCount = 8
val requestsStarted = CountDownLatch(candidateCount)
val releaseRequests = CountDownLatch(1)
val raceGate = CountDownLatch(1)
val requestSequence = AtomicInteger(0)
val client = OkHttpClient.Builder()
.addInterceptor { chain ->
if (requestSequence.incrementAndGet() <= candidateCount) {
requestsStarted.countDown()
releaseRequests.await(5, TimeUnit.SECONDS)
throw InterruptedIOException("instrumented invalidation race")
}
Response.Builder()
.request(chain.request())
.protocol(Protocol.HTTP_1_1)
.code(200)
.message("OK")
.body("{}".toResponseBody())
.build()
}
.build()
val resolver = EndpointResolver(client)
val candidates = (1..candidateCount).map { index ->
EndpointCandidate(
role = "instrumented-$iteration-$index",
priority = 0,
api = ApiEndpoint(host = "127.0.0.1", port = 1, tls = false),
)
}
try {
val staleResolve = async(start = CoroutineStart.UNDISPATCHED) {
resolver.resolve(candidates, EndpointSurface.Api)
}
assertTrue(requestsStarted.await(5, TimeUnit.SECONDS))
val invalidation = async(Dispatchers.Default) {
raceGate.await(5, TimeUnit.SECONDS)
resolver.clearCache()
}
val completions = async(Dispatchers.Default) {
raceGate.await(5, TimeUnit.SECONDS)
releaseRequests.countDown()
}
raceGate.countDown()
withTimeout(2_000L) {
invalidation.await()
completions.await()
staleResolve.await()
}
assertTrue(resolver.cacheSnapshot().isEmpty())
resolver.clearCache()
val freshWinner = withTimeout(2_000L) {
resolver.resolve(listOf(candidates.first()), EndpointSurface.Api)
}
assertEquals(candidates.first(), freshWinner)
assertTrue(
resolver.probeOutcomes.value.getValue(
EndpointResolver.cacheKey(candidates.first(), EndpointSurface.Api),
).reachable,
)
} finally {
raceGate.countDown()
releaseRequests.countDown()
client.dispatcher.executorService.shutdown()
}
}
}
}
@@ -0,0 +1,111 @@
package com.hermesandroid.relay.network.upstream
import android.app.ActivityManager
import android.app.NotificationManager
import android.content.Context
import android.os.Build
import android.os.SystemClock
import androidx.activity.ComponentActivity
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.test.platform.app.InstrumentationRegistry
import com.hermesandroid.relay.data.KEY_GATEWAY_KEEP_ALIVE
import com.hermesandroid.relay.data.relayDataStore
import com.hermesandroid.relay.data.setGatewayKeepAlive
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.runBlocking
import org.junit.After
import org.junit.Assert.assertTrue
import org.junit.Before
import org.junit.Rule
import org.junit.Test
import java.util.concurrent.CountDownLatch
import java.util.concurrent.TimeUnit
/** Real ActivityManager/notification lifecycle; no Gateway or personal data. */
class GatewayKeepAliveServiceInstrumentedTest {
@get:Rule val activity = createAndroidComposeRule<ComponentActivity>()
private val instrumentation = InstrumentationRegistry.getInstrumentation()
private val context get() = instrumentation.targetContext
@Before fun setup() {
if (Build.VERSION.SDK_INT >= 33) {
instrumentation.uiAutomation.executeShellCommand(
"pm grant ${context.packageName} android.permission.POST_NOTIFICATIONS",
).close()
}
runBlocking { context.setGatewayKeepAlive(false) }
}
@After fun cleanup() {
instrumentation.runOnMainSync {
GatewayKeepAliveService.stop(context)
ActiveTurnKeepAliveRegistry.releaseAll()
}
await("service shutdown") { serviceState() == null }
runBlocking { context.setGatewayKeepAlive(false) }
}
@Test fun immediateStopsAndOverlappingStartsSurviveThePlatformWatchdog() {
// All changes happen before Android can dispatch onCreate/onStartCommand.
instrumentation.runOnMainSync {
repeat(25) {
GatewayKeepAliveService.update(context, true, ActiveTurnKeepAliveRegistry.Snapshot())
GatewayKeepAliveService.stop(context)
}
GatewayKeepAliveService.update(context, false, ActiveTurnKeepAliveRegistry.Snapshot(2, 1))
}
await("foreground promotion") { serviceState()?.foreground == true }
instrumentation.runOnMainSync { GatewayKeepAliveService.stop(context) }
await("settled shutdown") { serviceState() == null }
// Observation window, not a startup workaround: an asynchronous system
// foreground-start crash fails the instrumentation process during it.
CountDownLatch(1).await(12, TimeUnit.SECONDS)
assertTrue(serviceState() == null)
}
@Test fun notificationDisablesAlwaysOnWhileANewerTurnStaysProtected() {
runBlocking { context.setGatewayKeepAlive(true) }
instrumentation.runOnMainSync {
GatewayKeepAliveService.update(context, true, ActiveTurnKeepAliveRegistry.Snapshot())
}
val manager = context.getSystemService(NotificationManager::class.java)
await("persistent notification") {
manager.activeNotifications.any { it.id == GatewayKeepAliveService.NOTIFICATION_ID }
}
val action = manager.activeNotifications.single {
it.id == GatewayKeepAliveService.NOTIFICATION_ID
}.notification.actions.single().actionIntent
instrumentation.runOnMainSync {
ActiveTurnKeepAliveRegistry.acquire("fixture::profile-a::session")
GatewayKeepAliveService.update(context, true, ActiveTurnKeepAliveRegistry.snapshot.value)
}
action.send()
await("persisted notification action") {
runBlocking { context.relayDataStore.data.first()[KEY_GATEWAY_KEEP_ALIVE] == false }
}
instrumentation.runOnMainSync {
GatewayKeepAliveService.update(context, false, ActiveTurnKeepAliveRegistry.snapshot.value)
}
assertTrue(serviceState()?.foreground == true)
assertTrue(ActiveTurnKeepAliveRegistry.snapshot.value.required)
await("active-turn notification without always-on action") {
manager.activeNotifications.singleOrNull {
it.id == GatewayKeepAliveService.NOTIFICATION_ID
}?.notification?.let { it.actions.isNullOrEmpty() } == true
}
}
@Suppress("DEPRECATION")
private fun serviceState(): ActivityManager.RunningServiceInfo? =
context.getSystemService(ActivityManager::class.java).getRunningServices(100)
.singleOrNull { it.service.className == GatewayKeepAliveService::class.java.name }
private fun await(description: String, condition: () -> Boolean) {
val deadline = SystemClock.uptimeMillis() + 10_000
while (!condition() && SystemClock.uptimeMillis() < deadline) {
instrumentation.waitForIdleSync()
SystemClock.sleep(20)
}
assertTrue(description, condition())
}
}
@@ -3,230 +3,97 @@ package com.hermesandroid.relay.ui.onboarding
import android.app.Application
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.assertIsEnabled
import androidx.compose.ui.test.assertIsNotEnabled
import androidx.compose.ui.test.junit4.createComposeRule
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.compose.ui.test.performScrollTo
import androidx.compose.ui.test.performTextReplacement
import androidx.test.core.app.ApplicationProvider
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import org.junit.Rule
import org.junit.Test
/**
* Instrumented tests for the Standard-first onboarding pager.
*/
/** Standard setup stays separate from Direct API and optional Relay grants. */
class OnboardingFlowTest {
@get:Rule val compose = createComposeRule()
@get:Rule
val composeTestRule = createComposeRule()
private fun setOnboardingContent() {
val app = ApplicationProvider.getApplicationContext<Application>()
val connectionViewModel = ConnectionViewModel(app)
composeTestRule.setContent {
HermesRelayTheme {
OnboardingScreen(
connectionViewModel = connectionViewModel,
onComplete = {},
)
}
}
private fun start() {
val model = ConnectionViewModel(ApplicationProvider.getApplicationContext<Application>())
compose.setContent { HermesRelayTheme { OnboardingScreen(model, onComplete = {}) } }
}
@Test
fun firstPage_showsHermesForAndroidTitle() {
setOnboardingContent()
composeTestRule
.onNodeWithText("Hermes-Relay for Android")
.assertIsDisplayed()
private fun connectPage() {
compose.onNodeWithText("Get started").performClick()
repeat(3) { compose.onNodeWithText("Next").performClick(); compose.waitForIdle() }
}
@Test
fun firstPage_showsStandardFirstDescription() {
setOnboardingContent()
composeTestRule
.onNodeWithText("Chat with Hermes and manage your dashboard from your phone.")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Standard")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Advanced")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Setup Guide")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Hermes Docs")
.assertIsDisplayed()
@Test fun welcomeOffersStartAndDemo() {
start()
compose.onNodeWithText("Hermes,\nin your pocket").assertIsDisplayed()
compose.onNodeWithText("Get started").assertIsDisplayed().assertIsEnabled()
compose.onNodeWithText("Try the demo").assertIsDisplayed().assertIsEnabled()
compose.onNodeWithText("Back").assertDoesNotExist()
}
@Test
fun nextButton_navigatesForward_toChatPage() {
setOnboardingContent()
composeTestRule.onNodeWithText("Next").performClick()
composeTestRule.waitForIdle()
composeTestRule
.onNodeWithText("Chat")
.assertIsDisplayed()
@Test fun introNavigationAndSkipRemainAvailable() {
start()
compose.onNodeWithText("Get started").performClick()
compose.onNodeWithText("Chat").assertIsDisplayed()
compose.onNodeWithText("Back").performClick()
compose.onNodeWithText("Get started").assertIsDisplayed()
compose.onNodeWithText("Get started").performClick()
compose.onNodeWithText("Skip").performClick()
compose.onNodeWithText("Skip setup?").assertIsDisplayed()
compose.onNodeWithText("Go back").performClick()
compose.onNodeWithText("Chat").assertIsDisplayed()
}
@Test
fun canNavigateForward_throughStandardAndPowerPages() {
setOnboardingContent()
composeTestRule.onNodeWithText("Hermes-Relay for Android").assertIsDisplayed()
composeTestRule.onNodeWithText("Next").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Chat").assertIsDisplayed()
composeTestRule.onNodeWithText("Next").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Manage").assertIsDisplayed()
composeTestRule.onNodeWithText("Next").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Power tools").assertIsDisplayed()
composeTestRule.onNodeWithText("Connect").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Add gateway").assertIsDisplayed()
@Test fun standardMethodsDoNotAskForApiCredentials() {
start(); connectPage()
compose.onNodeWithText("Hermes nearby").assertIsDisplayed()
compose.onNodeWithText("Remote gateway").assertIsDisplayed().performClick()
compose.onNodeWithText("Hermes address").assertIsDisplayed()
compose.onNodeWithText("API key").assertDoesNotExist()
compose.onNodeWithText("Find Hermes").performScrollTo().assertIsDisplayed()
}
@Test
fun backButton_hiddenOnFirstPage() {
setOnboardingContent()
composeTestRule
.onNodeWithText("Back")
.assertDoesNotExist()
@Test fun publicHttpConsentResetsWhenAddressChanges() {
start(); connectPage()
compose.onNodeWithText("Remote gateway").performClick()
compose.onNodeWithText("Hermes address").performTextReplacement("http://11.0.0.1:9119")
compose.onNodeWithText("Find Hermes").performScrollTo().assertIsNotEnabled()
compose.onNodeWithText("I accept the risk and allow HTTP for this address").performScrollTo().performClick()
compose.onNodeWithText("Find Hermes").performScrollTo().assertIsEnabled()
compose.onNodeWithText("Hermes address").performScrollTo().performTextReplacement("http://11.0.0.1:9120")
compose.onNodeWithText("Find Hermes").performScrollTo().assertIsNotEnabled()
}
@Test
fun backButton_navigatesBackward() {
setOnboardingContent()
composeTestRule.onNodeWithText("Next").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Chat").assertIsDisplayed()
composeTestRule.onNodeWithText("Back").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Hermes-Relay for Android").assertIsDisplayed()
@Test fun advancedKeepsApiAndRelaySeparate() {
start(); connectPage()
compose.onNodeWithText("Advanced").performScrollTo().performClick()
compose.onNodeWithText("API-only connection").assertIsDisplayed()
compose.onNodeWithText("Pair Relay by code").performScrollTo().assertIsDisplayed()
}
@Test
fun addGatewayPage_leadsWithStandardGatewayMethods() {
setOnboardingContent()
navigateToPage(4)
composeTestRule
.onNodeWithText("Hermes nearby")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Remote gateway")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Scan Hermes setup QR")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Recommended")
.assertDoesNotExist()
@Test fun setupSkipIsScrollReachable() {
start(); connectPage()
compose.onNodeWithText("Skip for now — set up later in Settings").performScrollTo().assertIsDisplayed().performClick()
compose.onNodeWithText("Skip setup?").assertIsDisplayed()
}
@Test
fun manualSetup_showsHermesAddressWithoutApiCredentials() {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Remote gateway").performClick()
composeTestRule.waitForIdle()
composeTestRule
.onNodeWithText("Hermes address")
.assertIsDisplayed()
@Test fun hostedGatewayKeepsItsSeparateAddressEntry() {
start(); connectPage()
compose.onNodeWithText("Nous-hosted Hermes").performClick()
compose.onNodeWithText("Connect to Nous-hosted Hermes").assertIsDisplayed()
compose.onNodeWithText("Find Hermes").performScrollTo().assertIsNotEnabled()
}
@Test
fun manualSetup_findButton_isShown() {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Remote gateway").performClick()
composeTestRule.waitForIdle()
composeTestRule
.onNodeWithText("Find Hermes")
.assertIsDisplayed()
}
@Test
fun cloudSetup_requestsTheHostedDashboardAddress() {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Nous-hosted Hermes").performClick()
composeTestRule.waitForIdle()
composeTestRule
.onNodeWithText("Connect to Nous-hosted Hermes")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Use the complete HTTPS address shown for your hosted agent.")
.assertIsDisplayed()
}
@Test
fun addGatewayPage_keepsPairingOptional() {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Advanced").performClick()
composeTestRule.waitForIdle()
composeTestRule
.onNodeWithText("Pair Relay by code")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Power-user path for Terminal, Bridge, Relay sessions, and grants")
.assertIsDisplayed()
}
@Test
fun powerPage_linksToPermissionReview() {
setOnboardingContent()
navigateToPage(3)
composeTestRule
.onNodeWithText("Review permissions")
.assertIsDisplayed()
.assertIsEnabled()
}
@Test
fun skipButton_visibleOnIntroPages_andWizardSkipOnAddGatewayPage() {
setOnboardingContent()
repeat(4) {
composeTestRule.onNodeWithText("Skip").assertIsDisplayed()
composeTestRule.onNodeWithText(if (it == 3) "Connect" else "Next").performClick()
composeTestRule.waitForIdle()
}
composeTestRule
.onNodeWithText("Skip for now — set up later in Settings")
.assertIsDisplayed()
}
private fun navigateToPage(pageIndex: Int) {
repeat(pageIndex) {
composeTestRule.onNodeWithText(if (it == 3) "Connect" else "Next").performClick()
composeTestRule.waitForIdle()
}
@Test fun optionalPowerPermissionsRemainReachable() {
start()
compose.onNodeWithText("Get started").performClick()
repeat(2) { compose.onNodeWithText("Next").performClick(); compose.waitForIdle() }
compose.onNodeWithText("Review permissions").performScrollTo().assertIsDisplayed().assertIsEnabled()
}
}
@@ -0,0 +1,65 @@
package com.hermesandroid.relay.ui.screens
import androidx.activity.ComponentActivity
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.material3.Text
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.compose.ui.test.longClick
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.compose.ui.test.performTouchInput
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.network.upstream.GatewayConnectionState
import com.hermesandroid.relay.ui.components.ChatDebugDrawer
import com.hermesandroid.relay.ui.components.ChatDebugOverlay
import com.hermesandroid.relay.ui.components.chatDebugHeaderGesture
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import org.junit.Assert.assertEquals
import org.junit.Rule
import org.junit.Test
class ChatDebugDrawerInstrumentedTest {
@get:Rule val compose = createAndroidComposeRule<ComponentActivity>()
@Test
fun longPressOpensDiagnosticsBelowHeaderAndCloseRestoresChat() {
compose.setContent {
var open by remember { mutableStateOf(false) }
HermesRelayTheme(appThemeId = "hermes-relay", themePreference = "dark") {
Box(Modifier.fillMaxSize()) {
Text("Hermes", Modifier.fillMaxWidth().height(64.dp).testTag("header")
.chatDebugHeaderGesture(true, onClick = {}, onHold = { open = true }))
ChatDebugOverlay(open, 64.dp, onClose = { open = false }) {
ChatDebugDrawer(
profile = "Server Default", model = "Example", sessionId = "session",
gateway = true, signedIn = true, signInRequired = false,
socketState = GatewayConnectionState.Ready, preparing = false,
streaming = false, loadingHistory = false, directoryUnavailable = false,
failure = null, onClose = { open = false }, onConnections = {},
)
}
}
}
}
val header = compose.onNodeWithTag("header")
val before = header.fetchSemanticsNode().boundsInRoot
header.performTouchInput { longClick() }
compose.onNodeWithText("Session diagnostics").assertIsDisplayed()
assertEquals(before, header.fetchSemanticsNode().boundsInRoot)
compose.onNodeWithContentDescription("Close session diagnostics").performClick()
compose.onNodeWithText("Session diagnostics").assertDoesNotExist()
header.assertIsDisplayed()
}
}
@@ -0,0 +1,141 @@
package com.hermesandroid.relay.ui.theme
import android.app.UiModeManager
import android.content.Context
import android.os.SystemClock
import androidx.appcompat.app.AppCompatDelegate
import androidx.datastore.preferences.core.edit
import androidx.test.core.app.ActivityScenario
import androidx.test.core.app.ApplicationProvider
import androidx.test.ext.junit.runners.AndroidJUnit4
import androidx.test.platform.app.InstrumentationRegistry
import com.hermesandroid.relay.HermesRelayApp
import com.hermesandroid.relay.MainActivity
import com.hermesandroid.relay.data.AppearancePreferences
import com.hermesandroid.relay.data.CustomThemePreset
import com.hermesandroid.relay.data.relayDataStore
import com.hermesandroid.relay.runtime.HermesRuntimeInitializationState
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.runBlocking
import kotlinx.coroutines.withTimeout
import org.junit.Assert.assertEquals
import org.junit.Assert.assertFalse
import org.junit.Assert.assertTrue
import org.junit.Assert.fail
import org.junit.Assume.assumeTrue
import org.junit.Test
import org.junit.runner.RunWith
/** Real Activity/DataStore/Compose ownership, with the device set to dark mode. */
@RunWith(AndroidJUnit4::class)
class AppearanceColdStartInstrumentedTest {
@Test
fun savedAppearanceOwnsColdStartAndLaterModeChanges() {
val instrumentation = InstrumentationRegistry.getInstrumentation()
val app = ApplicationProvider.getApplicationContext<HermesRelayApp>()
val previousPreferences = runBlocking { app.relayDataStore.data.first() }
val originalNightMode =
(app.getSystemService(Context.UI_MODE_SERVICE) as UiModeManager).nightMode
assumeTrue(
originalNightMode == UiModeManager.MODE_NIGHT_AUTO ||
originalNightMode == UiModeManager.MODE_NIGHT_NO ||
originalNightMode == UiModeManager.MODE_NIGHT_YES,
)
val custom = CustomThemePreset(
id = "day",
name = "Day",
mode = CustomThemePreset.MODE_LIGHT,
backgroundHex = "#F5F5F5",
surfaceHex = "#FFFFFF",
accentHex = "#0E18D6",
textHex = "#111111",
)
instrumentation.uiAutomation.executeShellCommand("cmd uimode night yes").close()
try {
runBlocking {
app.relayDataStore.edit { preferences ->
preferences[AppearancePreferences.themeKey] = "light"
preferences[AppearancePreferences.appThemeKey] = AppThemes.DEFAULT_ID
}
}
instrumentation.runOnMainSync {
AppCompatDelegate.setDefaultNightMode(AppCompatDelegate.MODE_NIGHT_FOLLOW_SYSTEM)
}
ActivityScenario.launch(MainActivity::class.java).use {
runBlocking {
withTimeout(30_000) {
app.runtime.connectionViewModel.isReady.first { it }
app.runtime.initializationState.first {
it == HermesRuntimeInitializationState.Ready
}
}
}
awaitTheme(isDark = false, nightMode = AppCompatDelegate.MODE_NIGHT_NO)
runBlocking {
app.relayDataStore.edit {
it[AppearancePreferences.themeKey] = "dark"
}
}
awaitTheme(isDark = true, nightMode = AppCompatDelegate.MODE_NIGHT_YES)
runBlocking {
app.relayDataStore.edit {
it[AppearancePreferences.themeKey] = "auto"
}
}
awaitTheme(isDark = true, nightMode = AppCompatDelegate.MODE_NIGHT_FOLLOW_SYSTEM)
runBlocking {
app.relayDataStore.edit {
it[AppearancePreferences.customThemesKey] =
AppearancePreferences.encodeCustomThemes(listOf(custom))
it[AppearancePreferences.appThemeKey] = custom.appThemeId
}
}
awaitTheme(isDark = false, nightMode = AppCompatDelegate.MODE_NIGHT_NO)
}
} finally {
runBlocking {
app.relayDataStore.edit { preferences ->
previousPreferences[AppearancePreferences.themeKey]?.let {
preferences[AppearancePreferences.themeKey] = it
} ?: preferences.remove(AppearancePreferences.themeKey)
previousPreferences[AppearancePreferences.appThemeKey]?.let {
preferences[AppearancePreferences.appThemeKey] = it
} ?: preferences.remove(AppearancePreferences.appThemeKey)
previousPreferences[AppearancePreferences.customThemesKey]?.let {
preferences[AppearancePreferences.customThemesKey] = it
} ?: preferences.remove(AppearancePreferences.customThemesKey)
}
}
val restoreMode = when (originalNightMode) {
UiModeManager.MODE_NIGHT_YES -> "yes"
UiModeManager.MODE_NIGHT_NO -> "no"
else -> "auto"
}
instrumentation.uiAutomation.executeShellCommand("cmd uimode night $restoreMode").close()
}
}
private fun awaitTheme(isDark: Boolean, nightMode: Int) {
val instrumentation = InstrumentationRegistry.getInstrumentation()
val deadline = SystemClock.uptimeMillis() + 15_000
while (SystemClock.uptimeMillis() < deadline) {
instrumentation.waitForIdleSync()
if (RelayRefresh.activePalette.isDark == isDark &&
AppCompatDelegate.getDefaultNightMode() == nightMode
) {
assertEquals(nightMode, AppCompatDelegate.getDefaultNightMode())
if (isDark) assertTrue(RelayRefresh.activePalette.isDark)
else assertFalse(RelayRefresh.activePalette.isDark)
return
}
SystemClock.sleep(25)
}
fail(
"Appearance did not settle: paletteDark=${RelayRefresh.activePalette.isDark}, " +
"nightMode=${AppCompatDelegate.getDefaultNightMode()}",
)
}
}
@@ -0,0 +1,183 @@
package com.hermesandroid.relay.viewmodel
import android.os.Handler
import android.os.Looper
import androidx.activity.ComponentActivity
import androidx.compose.foundation.layout.Column
import androidx.compose.material3.MaterialTheme
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.lifecycle.Lifecycle
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.hermesandroid.relay.data.AgentDisplay
import com.hermesandroid.relay.data.ChatActivityPhase
import com.hermesandroid.relay.data.InMemoryChatActivityStore
import com.hermesandroid.relay.data.projectChatActivityReceipts
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.HermesApiClient
import com.hermesandroid.relay.ui.components.ChatActivityReceipt
import com.hermesandroid.relay.ui.components.GatewayBackgroundProcessSheet
import com.hermesandroid.relay.ui.components.GatewayBackgroundProcessStrip
import com.hermesandroid.relay.ui.components.SubagentPreviewVisibility
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.cancel
import kotlinx.coroutines.runBlocking
import kotlinx.serialization.json.buildJsonObject
import kotlinx.serialization.json.put
import okhttp3.OkHttpClient
import okhttp3.WebSocket
import org.junit.After
import org.junit.Assert.assertTrue
import org.junit.Before
import org.junit.Rule
import org.junit.Test
/** Real Gateway callbacks drive production activity surfaces through Android lifecycle changes. */
class ChatActivityReceiptInstrumentedTest {
@get:Rule val compose = createAndroidComposeRule<ComponentActivity>()
private lateinit var fixture: AndroidGatewayContractFixture
private lateinit var gatewayScope: CoroutineScope
private lateinit var gateway: GatewayChatClient
private lateinit var handler: ChatHandler
private lateinit var viewModel: ChatViewModel
private lateinit var socket: WebSocket
private val owner = AgentDisplay.profileContextKey("fixture-connection", "research")
@Before
fun setUp() {
fixture = AndroidGatewayContractFixture().also { it.profileName = "research" }
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val http = OkHttpClient()
gateway = GatewayChatClient(
initialDashboardClient = DashboardApiClient(fixture.server.url("/").toString().trimEnd('/'), okHttpClient = http),
okHttpClient = http,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
handler = ChatHandler().also { it.setSessionId(STORED_SESSION_ID) }
viewModel = ChatViewModel().also {
it.initialize(HermesApiClient(fixture.server.url("/").toString(), "fixture-key"), handler)
it.streamingEndpoint = "gateway"
it.setSessionProfileNameProvider { "research" }
it.setProfileMessageLoader { Result.success(emptyList()) }
it.setChatActivityStore(InMemoryChatActivityStore())
it.switchProfileContext(owner, STORED_SESSION_ID)
it.updateGatewayClient(gateway)
it.setChatVisible(true)
}
compose.setContent {
val messages by viewModel.messages.collectAsStateWithLifecycle()
val records by viewModel.activityRecords.collectAsStateWithLifecycle()
val children by viewModel.subagentActivities.collectAsStateWithLifecycle()
val retained by viewModel.retainedActivityPreview.collectAsStateWithLifecycle()
val childPreview by viewModel.subagentChildPreview.collectAsStateWithLifecycle()
val session by viewModel.currentSessionId.collectAsStateWithLifecycle()
var sheetOpen by remember { mutableStateOf(false) }
MaterialTheme {
Column {
GatewayBackgroundProcessStrip(
processes = emptyList(), subagentActivities = children,
subagentPreviewVisibility = SubagentPreviewVisibility(), loading = false,
onClick = { viewModel.openCurrentActivityPreview(); sheetOpen = true },
modifier = Modifier.testTag("active-activity"),
)
projectChatActivityReceipts(messages, records, owner, session).forEach { message ->
message.activityRecord?.let { record ->
ChatActivityReceipt(
record = record,
onClick = { sheetOpen = viewModel.openRetainedActivity(record) },
modifier = Modifier.testTag("activity-receipt"),
)
}
}
}
if (sheetOpen) {
GatewayBackgroundProcessSheet(
processes = retained?.processes.orEmpty(),
subagentActivities = retained?.record?.previewActivities() ?: children,
subagentChildPreview = childPreview,
subagentPreviewVisibility = SubagentPreviewVisibility(),
loading = false, stoppingProcessIds = emptySet(),
onRefresh = viewModel::refreshBackgroundProcesses,
onStop = viewModel::stopBackgroundProcess,
onDismissProcess = viewModel::dismissBackgroundProcess,
onOpenSubagentChild = viewModel::openSubagentChildPreview,
onDismiss = { viewModel.closeActivityPreview(); sheetOpen = false },
readOnlyHistory = retained != null,
historyNotice = "Recorded activity. Available child history is read-only.",
)
}
}
}
assertTrue(runBlocking { gateway.prewarmAwait(STORED_SESSION_ID) })
socket = fixture.awaitServerSocket()
fixture.awaitRpc("session.resume")
}
@After
fun tearDown() {
viewModel.updateGatewayClient(null)
gateway.shutdown()
gatewayScope.cancel()
fixture.shutdown()
}
@Test
fun detachedCompletionLeavesReopenableReceiptAcrossActivityResume() {
viewModel.sendMessage("Delegate a background task")
fixture.awaitRpc("prompt.submit")
socket.send(fixture.event("message.start", null, LIVE_SESSION_ID))
socket.send(fixture.event("subagent.start", buildJsonObject {
put("subagent_id", "receipt-child")
put("delegation_id", "receipt-delegation")
put("task_count", 1)
put("goal", "Inspect activity lifecycle")
}, LIVE_SESSION_ID))
compose.waitUntil(5_000) { viewModel.subagentActivities.value.size == 1 }
compose.onNodeWithTag("active-activity").assertIsDisplayed()
socket.send(fixture.event("message.complete", buildJsonObject { put("text", "Launched") }, LIVE_SESSION_ID))
compose.waitUntil(5_000) { !handler.isStreaming.value }
compose.onNodeWithTag("active-activity").assertIsDisplayed()
socket.send(fixture.event("subagent.complete", buildJsonObject {
put("subagent_id", "receipt-child")
put("delegation_id", "receipt-delegation")
put("status", "completed")
}, LIVE_SESSION_ID))
compose.waitUntil(5_000) { viewModel.activityRecords.value.singleOrNull()?.phase == ChatActivityPhase.COMPLETE }
compose.onNodeWithTag("active-activity").assertDoesNotExist()
compose.onNodeWithTag("activity-receipt").assertIsDisplayed().performClick()
compose.onNodeWithText("Chat activity").assertIsDisplayed()
compose.onNodeWithText("Recorded activity. Available child history is read-only.").assertIsDisplayed()
compose.onNodeWithText("Stop").assertDoesNotExist()
compose.onNodeWithContentDescription("Close activity preview").performClick()
compose.onNodeWithTag("activity-receipt").assertIsDisplayed()
compose.activityRule.scenario.moveToState(Lifecycle.State.STARTED)
compose.activityRule.scenario.moveToState(Lifecycle.State.RESUMED)
compose.onNodeWithTag("active-activity").assertDoesNotExist()
compose.onNodeWithTag("activity-receipt").assertIsDisplayed().performClick()
compose.onNodeWithText("Chat activity").assertIsDisplayed()
}
private companion object {
const val STORED_SESSION_ID = "20260821_120000_fixture"
const val LIVE_SESSION_ID = "fixture-live-1"
}
}
@@ -0,0 +1,116 @@
package com.hermesandroid.relay.viewmodel
import android.os.Handler
import android.os.Looper
import androidx.activity.ComponentActivity
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.lazy.LazyColumn
import androidx.compose.material3.MaterialTheme
import androidx.compose.runtime.getValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.compose.ui.test.performImeAction
import androidx.compose.ui.test.performTextInput
import androidx.lifecycle.Lifecycle
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.HermesApiClient
import com.hermesandroid.relay.ui.components.MessageBubble
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.cancel
import kotlinx.coroutines.runBlocking
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import okhttp3.OkHttpClient
import okhttp3.WebSocket
import org.junit.After
import org.junit.Assert.assertEquals
import org.junit.Assert.assertTrue
import org.junit.Before
import org.junit.Rule
import org.junit.Test
/** Production socket, ViewModel, transcript, Compose and IME actions on a virtual device. */
class ClarifyBatchInstrumentedTest {
@get:Rule val compose = createAndroidComposeRule<ComponentActivity>()
private lateinit var fixture: AndroidGatewayContractFixture
private lateinit var scope: CoroutineScope
private lateinit var gateway: GatewayChatClient
private lateinit var viewModel: ChatViewModel
private lateinit var handler: ChatHandler
private lateinit var socket: WebSocket
@Before fun setUp() {
fixture = AndroidGatewayContractFixture()
scope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val http = OkHttpClient()
gateway = GatewayChatClient(
initialDashboardClient = DashboardApiClient(fixture.server.url("/").toString().trimEnd('/'), http),
okHttpClient = http, scope = scope,
callbackDispatcher = { Handler(Looper.getMainLooper()).post(it) },
)
handler = ChatHandler().also { it.setSessionId("20260821_120000_fixture") }
viewModel = ChatViewModel().also {
it.initialize(HermesApiClient(fixture.server.url("/").toString(), "fixture-key"), handler)
it.streamingEndpoint = "gateway"
it.setProfileMessageLoader { Result.success(emptyList()) }
it.updateGatewayClient(gateway)
}
compose.setContent {
val messages by handler.messages.collectAsStateWithLifecycle()
MaterialTheme {
LazyColumn(Modifier.fillMaxSize()) {
items(messages.size, key = { messages[it].id }) { index ->
MessageBubble(messages[index], showTimestamps = false,
onCardInput = viewModel::answerAsk, animationEnabled = false)
}
}
}
}
assertTrue(runBlocking { gateway.prewarmAwait("20260821_120000_fixture") })
socket = fixture.awaitServerSocket()
}
@After fun tearDown() {
viewModel.updateGatewayClient(null)
gateway.shutdown()
scope.cancel()
fixture.shutdown()
}
@Test fun confirmedProgressSurvivesLifecycleAndCustomAnswerUsesIme() {
compose.runOnIdle { viewModel.sendMessage("Ask two questions") }
fixture.awaitRpc("prompt.submit")
socket.send(fixture.event("clarify.request", Json.parseToJsonElement("""
{"request_id":"batch-device","questions":[
{"qid":"route/a","question":"Which route?","choices":["Canary","Immediate"]},
{"qid":"notes:b","question":"Anything else?","choices":null}
]}
""") as JsonObject, "fixture-live-1"))
compose.waitUntil(10_000) { viewModel.pendingAsk.value != null }
compose.onNodeWithText("Canary").performClick()
compose.waitUntil(10_000) { viewModel.pendingAsk.value?.ask?.answers?.get("route/a") == "Canary" }
assertEquals(JsonPrimitive("route/a"), fixture.awaitRpc("clarify.respond")["question_id"])
compose.activityRule.scenario.moveToState(Lifecycle.State.STARTED)
compose.activityRule.scenario.moveToState(Lifecycle.State.RESUMED)
compose.onNodeWithText("Question 2 of 2").assertIsDisplayed()
compose.onNodeWithContentDescription("Type an answer…").apply {
performClick()
performTextInput(" Keep rollback ready ")
performImeAction()
}
compose.waitUntil(10_000) { viewModel.pendingAsk.value == null }
compose.onNodeWithText("All questions answered").assertIsDisplayed()
assertEquals(2, fixture.rpcCount("clarify.respond"))
assertEquals(1, fixture.rpcCount("prompt.submit"))
}
}
@@ -15,6 +15,10 @@ import androidx.compose.ui.test.assertTextEquals
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.compose.ui.test.onAllNodesWithText
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onAllNodesWithContentDescription
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.test.platform.app.InstrumentationRegistry
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.hermesandroid.relay.data.MessageRole
@@ -58,9 +62,17 @@ class GatewayExternalFixtureInstrumentedTest {
private var gatewayScope: CoroutineScope? = null
private var gatewayClient: GatewayChatClient? = null
private var viewModel: ChatViewModel? = null
private var voiceViewModel: VoiceViewModel? = null
private var voicePlayer: com.hermesandroid.relay.audio.VoicePlayer? = null
private var voiceSfx: com.hermesandroid.relay.audio.VoiceSfxPlayer? = null
@After
fun tearDown() {
compose.runOnUiThread {
voiceViewModel?.exitVoiceMode()
voicePlayer?.release()
voiceSfx?.release()
}
viewModel?.updateGatewayClient(null)
gatewayClient?.shutdown()
gatewayScope?.cancel()
@@ -171,6 +183,155 @@ class GatewayExternalFixtureInstrumentedTest {
}
}
@Test
fun queuedStopResume_preservesWorkAcrossLifecycleAndUsesExplicitResume() {
val base = InstrumentationRegistry.getArguments().getString(ARG_FIXTURE_BASE_URL)?.trimEnd('/')
assumeTrue("Pass a queued_stop_resume fixture URL", !base.isNullOrBlank())
requireNotNull(base)
val http = OkHttpClient.Builder().callTimeout(10, TimeUnit.SECONDS).build()
assertEquals("queued_stop_resume", readFixtureJson(http, "$base/__fixture__/state")["scenario"]?.jsonString())
val dashboard = DashboardApiClient(base, http)
val scope = CoroutineScope(SupervisorJob() + Dispatchers.IO).also { gatewayScope = it }
val gateway = GatewayChatClient(
initialDashboardClient = dashboard, okHttpClient = http, scope = scope,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
reconnectJitterUnit = { 0.0 },
).also { gatewayClient = it }
val handler = ChatHandler().also { it.setSessionId(STORED_SESSION_ID) }
val vm = ChatViewModel().also {
it.initialize(null, handler)
it.streamingEndpoint = "gateway"
it.setProfileMessageLoaderWithMode { profile, session, mode -> dashboard.getSessionMessages(session, profile, mode) }
it.updateGatewayClient(gateway)
it.switchProfileContext(com.hermesandroid.relay.data.AgentDisplay.profileContextKey("fixture-queue", null), STORED_SESSION_ID)
}.also { viewModel = it }
compose.setContent {
val queue by vm.queuedMessages.collectAsStateWithLifecycle()
val paused by vm.queuePaused.collectAsStateWithLifecycle()
com.hermesandroid.relay.ui.theme.HermesRelayTheme(themePreference = "dark") {
androidx.compose.material3.Surface {
Column {
com.hermesandroid.relay.ui.components.ChatBusyActionSelector(
com.hermesandroid.relay.data.BusyMessageAction.QueueNext, {}, onStop = vm::cancelStream,
)
com.hermesandroid.relay.ui.components.ChatMessageQueue(
queue, paused, vm::resumeQueue, vm::clearQueue, {}, vm::removeQueuedAt, canEdit = true,
)
}
}
}
}
assertTrue(runBlocking { gateway.prewarmAwait(STORED_SESSION_ID) })
compose.runOnIdle { vm.sendMessage("Original work") }
compose.waitUntil(10_000) { handler.isStreaming.value && vm.steerableTurn.value }
compose.runOnIdle {
vm.sendMessage("Remove this follow-up", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
vm.sendMessage("Keep this follow-up", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
}
compose.onAllNodesWithContentDescription("Remove queued message")[0].performClick()
compose.onNodeWithContentDescription("Stop streaming").performClick()
compose.onNodeWithText("Queue paused").assertIsDisplayed()
assertEquals(listOf("Keep this follow-up"), vm.queuedMessages.value)
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.CREATED)
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.RESUMED)
compose.onNodeWithText("Keep this follow-up").assertIsDisplayed()
compose.onNodeWithText("Resume").performClick()
try {
compose.waitUntil(15_000) {
vm.queuedMessages.value.isEmpty() && !handler.isStreaming.value &&
handler.messages.value.any { it.content == "Resumed follow-up." }
}
} catch (error: androidx.compose.ui.test.ComposeTimeoutException) {
throw AssertionError(
"Synthetic queue fixture did not settle: queued=${vm.queuedMessages.value.size}, " +
"paused=${vm.queuePaused.value}, streaming=${handler.isStreaming.value}, " +
"messages=${handler.messages.value.map { it.role to it.content }}, " +
"error=${handler.error.value}",
error,
)
}
val evidence = readFixtureJson(http, "$base/__fixture__/evidence")["entries"] as JsonArray
assertEquals(2, evidence.rpcCount("prompt.submit"))
assertEquals(1, evidence.rpcCount("session.interrupt"))
assertEquals(0, evidence.rpcCount("session.redirect"))
assertEquals("gateway", vm.streamingEndpoint)
}
@Test
fun unsolicitedVoiceCompletions_surviveActivityPauseWithoutHistorySpeech() {
val base = InstrumentationRegistry.getArguments().getString(ARG_FIXTURE_BASE_URL)
?.trim()?.trimEnd('/')
assumeTrue("Pass the unsolicited_voice_completions fixture URL", !base.isNullOrBlank())
requireNotNull(base)
val http = OkHttpClient.Builder().callTimeout(10, TimeUnit.SECONDS).build()
assertEquals("unsolicited_voice_completions", readFixtureJson(http, "$base/__fixture__/state")["scenario"]?.jsonString())
val dashboard = DashboardApiClient(base, http)
val scope = CoroutineScope(SupervisorJob() + Dispatchers.IO).also { gatewayScope = it }
val gateway = GatewayChatClient(
initialDashboardClient = dashboard, okHttpClient = http,
callbackDispatcher = { Handler(Looper.getMainLooper()).post(it) }, scope = scope,
).also { gatewayClient = it }
val handler = ChatHandler().also { it.setSessionId(STORED_SESSION_ID) }
val spoken = java.util.concurrent.CopyOnWriteArrayList<String>()
lateinit var vm: ChatViewModel
compose.runOnUiThread {
val app = compose.activity.application
vm = ChatViewModel().also {
it.initialize(null, handler)
it.streamingEndpoint = "gateway"
it.setProfileMessageLoaderWithMode { profile, id, mode ->
dashboard.getSessionMessages(id, profile, mode)
}
it.updateGatewayClient(gateway)
viewModel = it
}
val audio = object : com.hermesandroid.relay.network.shared.VoiceAudioClient {
override val route = com.hermesandroid.relay.data.VoiceAudioRoute.Standard
override suspend fun transcribe(audioFile: java.io.File) = Result.success("")
override suspend fun synthesize(text: String): Result<java.io.File> {
spoken.add(text)
// A short silent WAV exercises the production play/drain path without a provider.
val pcm = ByteArray(3200)
val header = java.nio.ByteBuffer.allocate(44).order(java.nio.ByteOrder.LITTLE_ENDIAN)
.put("RIFF".toByteArray()).putInt(36 + pcm.size).put("WAVEfmt ".toByteArray())
.putInt(16).putShort(1).putShort(1).putInt(16000).putInt(32000)
.putShort(2).putShort(16).put("data".toByteArray()).putInt(pcm.size).array()
val file = java.io.File.createTempFile("fixture-voice", ".wav", app.cacheDir)
file.writeBytes(header + pcm)
return Result.success(file)
}
}
val player = com.hermesandroid.relay.audio.VoicePlayer(app).also { voicePlayer = it }
val sfx = com.hermesandroid.relay.audio.VoiceSfxPlayer(app).also { voiceSfx = it }
voiceViewModel = VoiceViewModel(app).also {
it.initialize(
voiceClient = com.hermesandroid.relay.network.relay.RelayVoiceClient(app, http, { null }, { null }),
voiceAudioClient = audio, chatViewModel = vm,
recorder = com.hermesandroid.relay.audio.VoiceRecorder(app, scope),
player = player, sfxPlayer = sfx,
)
it.enterVoiceMode()
}
}
compose.setContent {
val messages by vm.messages.collectAsStateWithLifecycle()
Text(messages.joinToString("\n") { it.content }, Modifier.testTag("voice-fixture-history"))
}
assertTrue(runBlocking { gateway.prewarmAwait(STORED_SESSION_ID) })
compose.runOnUiThread { vm.sendMessage("Start background work.") }
compose.waitUntil(10_000) { handler.messages.value.any { it.content == "Work started." } }
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.STARTED)
compose.waitUntil(15_000) { spoken.size == 3 }
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.RESUMED)
compose.runOnUiThread { voiceViewModel?.onAppResumed() }
compose.waitForIdle()
assertEquals(listOf("Process finished.", "Watch matched.", "Delegated work finished."), spoken.toList())
assertEquals(1, readFixtureJson(http, "$base/__fixture__/evidence")["entries"].let { it as JsonArray }.rpcCount("prompt.submit"))
assertTrue(handler.messages.value.any { it.content == "Delegated work finished." })
assertEquals("gateway", vm.streamingEndpoint)
}
private fun JsonArray.rpcCount(method: String): Int = count { element ->
val entry = element as? JsonObject ?: return@count false
entry["kind"]?.jsonString() == "rpc" && entry["method"]?.jsonString() == method
@@ -5,11 +5,12 @@ import android.os.Looper
import androidx.activity.ComponentActivity
import androidx.compose.foundation.layout.Column
import androidx.compose.material3.Button
import androidx.compose.runtime.getValue
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.Modifier
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.assertTextEquals
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
@@ -17,23 +18,30 @@ import androidx.compose.ui.test.onAllNodesWithTag
import androidx.compose.ui.test.onNodeWithTag
import androidx.lifecycle.Lifecycle
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.AgentDisplay
import com.hermesandroid.relay.data.ChatTurnAssistantCheckpoint
import com.hermesandroid.relay.data.ChatTurnCheckpoint
import com.hermesandroid.relay.data.ChatTurnCheckpointStore
import com.hermesandroid.relay.data.ChatTurnUserCheckpoint
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayAvailability
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.GatewayConnectionState
import com.hermesandroid.relay.network.upstream.HermesApiClient
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.ui.components.GatewayBackgroundProcessStrip
import com.hermesandroid.relay.ui.components.SubagentPreviewVisibility
import com.hermesandroid.relay.ui.screens.shouldOwnVisibleGateway
import kotlinx.coroutines.CompletableDeferred
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.cancel
import kotlinx.coroutines.runBlocking
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.runBlocking
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
@@ -83,6 +91,8 @@ class GatewayForegroundRecoveryInstrumentedTest {
@Volatile
private var persistedHistory: List<MessageItem> = emptyList()
private val historySignInRequired = MutableStateFlow(false)
private val coldStartAdmissionEnabled = MutableStateFlow(false)
private val coldStartGatewayAvailability = MutableStateFlow(GatewayAvailability.Unknown)
@Before
fun setUp() {
@@ -115,9 +125,31 @@ class GatewayForegroundRecoveryInstrumentedTest {
compose.setContent {
val messages by viewModel.messages.collectAsStateWithLifecycle()
val streaming by viewModel.isStreaming.collectAsStateWithLifecycle()
val children by viewModel.subagentActivities.collectAsStateWithLifecycle()
val signInRequired by historySignInRequired.collectAsStateWithLifecycle()
val admissionEnabled by coldStartAdmissionEnabled.collectAsStateWithLifecycle()
val admissionAvailability by coldStartGatewayAvailability.collectAsStateWithLifecycle()
LaunchedEffect(admissionEnabled, admissionAvailability) {
if (admissionEnabled) {
viewModel.setChatVisible(
shouldOwnVisibleGateway(
appForeground = true,
isGatewayTransport = true,
gatewayAvailability = admissionAvailability,
),
)
}
}
MaterialTheme {
Column(Modifier.testTag("contract-transcript")) {
GatewayBackgroundProcessStrip(
processes = emptyList(),
subagentActivities = children,
subagentPreviewVisibility = SubagentPreviewVisibility(),
loading = false,
onClick = {},
modifier = Modifier.testTag("child-activity"),
)
Text(
text = if (streaming) "STREAMING" else "IDLE",
modifier = Modifier.testTag("stream-state"),
@@ -145,6 +177,122 @@ class GatewayForegroundRecoveryInstrumentedTest {
fixture.awaitRpc("session.resume")
}
@Test
fun authenticatedUnknownColdLaunch_opensObservationSocketWithoutLifecycleBounce() {
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val controlMethods = setOf(
"session.resume",
"session.activate",
"prompt.submit",
"session.interrupt",
)
val baseline = controlMethods.associateWith(fixture::rpcCount)
val ticketMintsBefore = fixture.requestsTo("/api/auth/ws-ticket")
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val okHttp = OkHttpClient()
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = fixture.server.url("/").toString().trimEnd('/'),
okHttpClient = okHttp,
),
okHttpClient = okHttp,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
viewModel.setChatTurnCheckpointStore(null)
viewModel.updateGatewayClient(gatewayClient)
coldStartGatewayAvailability.value = GatewayAvailability.Unknown
coldStartAdmissionEnabled.value = true
compose.waitUntil(5_000) {
gatewayClient.connectionState.value == GatewayConnectionState.Ready
}
serverSocket = fixture.awaitServerSocket()
assertEquals(ticketMintsBefore + 1, fixture.requestsTo("/api/auth/ws-ticket"))
controlMethods.forEach { method ->
assertEquals(
"cold observation sent $method",
baseline.getValue(method),
fixture.rpcCount(method),
)
}
}
@Test
fun dashboardOnlyColdLaunch_waitsForExactDirectoryThenOpensObservationSocket() {
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val directoryStarted = CompletableDeferred<Unit>()
val directoryResult = CompletableDeferred<Result<List<SessionItem>>>()
viewModel.setProfileSessionLister { profile ->
assertEquals(PROFILE_NAME, profile)
directoryStarted.complete(Unit)
directoryResult.await()
}
handler.setSessionId(null)
viewModel.switchProfileContext(
AgentDisplay.profileContextKey("fixture-connection", PROFILE_NAME),
STORED_SESSION_ID,
)
val controlMethods = setOf(
"session.resume",
"session.activate",
"prompt.submit",
"session.interrupt",
)
val baseline = controlMethods.associateWith(fixture::rpcCount)
val ticketMintsBefore = fixture.requestsTo("/api/auth/ws-ticket")
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val okHttp = OkHttpClient()
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = fixture.server.url("/").toString().trimEnd('/'),
okHttpClient = okHttp,
),
okHttpClient = okHttp,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
viewModel.setChatTurnCheckpointStore(null)
viewModel.updateGatewayClient(gatewayClient)
viewModel.setChatVisible(true)
// This is the production binder's Dashboard/profile hydration edge.
// The socket must stay passive and closed until the exact-owner REST
// directory publishes, then open without a lifecycle bounce.
viewModel.refreshSessions()
compose.waitUntil(5_000) { directoryStarted.isCompleted }
assertEquals(ticketMintsBefore, fixture.requestsTo("/api/auth/ws-ticket"))
directoryResult.complete(
Result.success(listOf(SessionItem(id = STORED_SESSION_ID, title = "Fixture session"))),
)
compose.waitUntil(5_000) {
gatewayClient.connectionState.value == GatewayConnectionState.Ready
}
serverSocket = fixture.awaitServerSocket()
assertEquals(ticketMintsBefore + 1, fixture.requestsTo("/api/auth/ws-ticket"))
controlMethods.forEach { method ->
assertEquals(
"directory-gated cold observation sent $method",
baseline.getValue(method),
fixture.rpcCount(method),
)
}
}
@After
fun tearDown() {
viewModel.updateGatewayClient(null)
@@ -153,6 +301,37 @@ class GatewayForegroundRecoveryInstrumentedTest {
fixture.shutdown()
}
@Test
fun detachedChildActivity_survivesParentTerminalAndActivityResume() {
viewModel.sendMessage("Delegate a background task")
fixture.awaitRpc("prompt.submit")
serverSocket.send(fixture.event("message.start", null, LIVE_SESSION_ID))
serverSocket.send(fixture.event("subagent.start", buildJsonObject {
put("subagent_id", "detached-child")
put("goal", "Inspect")
}, LIVE_SESSION_ID))
compose.waitUntil(5_000) { viewModel.subagentActivities.value.size == 1 }
compose.onNodeWithTag("child-activity").assertIsDisplayed()
serverSocket.send(fixture.event("message.complete", buildJsonObject { put("text", "Launched") }, LIVE_SESSION_ID))
compose.waitUntil(5_000) { !handler.isStreaming.value }
compose.activityRule.scenario.moveToState(Lifecycle.State.STARTED)
serverSocket.send(fixture.event("subagent.progress", buildJsonObject {
put("subagent_id", "detached-child")
put("text", "Still working")
}, LIVE_SESSION_ID))
compose.activityRule.scenario.moveToState(Lifecycle.State.RESUMED)
compose.waitUntil(5_000) { viewModel.subagentActivities.value.single().events.last().text == "Still working" }
compose.onNodeWithTag("child-activity").assertIsDisplayed()
assertFalse(viewModel.subagentActivities.value.single().isTerminal)
compose.onNodeWithTag("stream-state").assertTextEquals("IDLE")
serverSocket.send(fixture.event("subagent.complete", buildJsonObject {
put("subagent_id", "detached-child")
put("status", "completed")
}, LIVE_SESSION_ID))
compose.waitUntil(5_000) { viewModel.subagentActivities.value.single().isTerminal }
compose.onNodeWithTag("child-activity").assertDoesNotExist()
}
@Test
fun terminalGapActivate_recoversForegroundTurnWithoutNavigationOrCrossSessionLeak() {
viewModel.sendMessage("Run a long foreground task")
@@ -258,6 +437,46 @@ class GatewayForegroundRecoveryInstrumentedTest {
assertEquals(0, fixture.requestsTo("/v1/chat/completions"))
}
@Test
fun terminalGapActiveList_settlesExactOwnedTurnAndRendersAuthoritativeHistory() {
viewModel.sendMessage("Run an Android-owned task")
fixture.awaitRpc("prompt.submit")
serverSocket.send(fixture.event("message.start", null, LIVE_SESSION_ID))
serverSocket.send(
fixture.event(
"message.delta",
buildJsonObject { put("text", PARTIAL_ANSWER) },
LIVE_SESSION_ID,
),
)
compose.waitUntil(5_000) { handler.isStreaming.value }
compose.onNodeWithTag("stream-state").assertTextEquals("STREAMING")
persistedHistory = listOf(
MessageItem(
id = PERSISTED_ANSWER_ID,
sessionId = STORED_SESSION_ID,
role = "assistant",
content = JsonPrimitive(AUTHORITATIVE_ANSWER),
),
)
fixture.activeSessionStatus = "idle"
runBlocking { gatewayClient.listActiveSessions() }
compose.waitUntil(5_000) {
!handler.isStreaming.value &&
!gatewayClient.hasActiveTurn() &&
handler.messages.value.singleOrNull()?.id == PERSISTED_ANSWER_ID
}
compose.onNodeWithTag("stream-state").assertTextEquals("IDLE")
compose.onNodeWithTag("message-$PERSISTED_ANSWER_ID")
.assertTextEquals("${MessageRole.ASSISTANT.name}:$AUTHORITATIVE_ANSWER")
assertEquals(1, fixture.rpcCount("prompt.submit"))
assertEquals(0, fixture.rpcCount("session.interrupt"))
assertEquals(0, fixture.rpcCount("session.activate"))
assertEquals(0, fixture.requestsTo("/v1/chat/completions"))
}
@Test
fun desktopOwnedTurn_remainsReadOnlyAcrossAndroidForegroundLifecycle() {
viewModel.setChatVisible(false)
+4 -1
View File
@@ -8,7 +8,7 @@
Google Play ships Hermes Bridge Core only. It intentionally does not merge
any Device Control services or permissions.
This file is intentionally kept as an empty overlay so future flavor-specific
This overlay owns the voice-only special access so future flavor-specific
permissions / activities have an obvious home. Mirror structural additions
in `app/src/sideload/AndroidManifest.xml` unless the change is intentionally
track-specific.
@@ -22,6 +22,9 @@
android:name="android.permission.WAKE_LOCK"
tools:node="remove" />
<!-- User-started voice controls only; does not enable Device Control. -->
<uses-permission android:name="android.permission.SYSTEM_ALERT_WINDOW" />
<application />
</manifest>
@@ -23,7 +23,7 @@ GOOGLE PLAY AND SIDELOAD
The Google Play build includes Chat, voice, sessions, Manage, profiles, notifications, media, and Terminal/TUI when the Hermes-Relay plugin is paired.
Google Play does not include Android Device Control. It cannot read the phone screen, tap, type, swipe, take device screenshots, send SMS, place calls, or access contacts or location.
Google Play does not include Android Device Control. It cannot tap, type, swipe, send SMS, place calls, or access contacts or location. Optional Voice Overlay provides user-started voice controls over other apps, with microphone notification and Stop voice. Selecting Hermes as Android Digital Assistant can provide bounded screen text and a screenshot for an explicit unlocked assistant invocation; this context goes to your configured server and AI provider.
Device Control is available only in the signed Sideload build on this project's GitHub Releases. It requires the Sideload app, a paired Hermes-Relay plugin, explicit Android accessibility permission, and the app's safety controls.
@@ -32,9 +32,6 @@ FEATURES
- Streaming Chat with reasoning, markdown, tool progress, attachments, mid-turn steering, edit-and-resend, and searchable commands.
- Manage models and provider keys, edit profiles, and browse, install, or update skills through the Hermes Dashboard.
- Hands-free voice through your server's speech providers. Hermes-Relay pairing adds per-profile voices and an experimental realtime engine.
- Create, switch, search, rename, pin, archive, and continue sessions.
- Connect multiple Hermes servers and switch in one tap; add LAN, Tailscale, or public routes.
- Pair the Hermes-Relay plugin for Terminal/TUI, notifications, media, enhanced voice, Relay sessions, and per-feature grants.
- Inspect connection readiness, routes, response timing, token usage, and stream health without exposing credentials.
SECURITY AND PRIVACY
Binary file not shown.

Before

Width:  |  Height:  |  Size: 44 KiB

After

Width:  |  Height:  |  Size: 509 KiB

@@ -1,3 +1,3 @@
v1.14.0 - Connections, delegated work, Git, and voice
v1.17.0 - Voice over other apps and clearer conversations
Connections now recover independently across LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication. Preview delegated agents, use the optional native Git workspace, and get safer Continuous voice, Voice Focus, Assistant, Threads, profile drafts, and Clarify controls. Wake-word detection also packages a compatible native runtime.
Use optional voice controls over other apps, with clear permission setup and an immediate Stop action. Answer Clarify batches one question at a time, with progress preserved across reconnects. Enjoy cleaner chat cards, recognizable profile names, and context previews that show what your connection supports. Phone control remains sideload-only.
@@ -1 +1,3 @@
新增监督模式:家长可配置并固定到指定配置文件,设置受设备身份验证保护。家长可限制附件、标准语音、生成媒体、历史记录、操作和技术详情。实时活动不可用时会话行保持中性显示,从家长设置返回时监督聊天也不再空白。
v1.17.0 - 跨应用语音与更清晰的对话
可选的语音悬浮控件让你在使用其他应用时继续语音会话,提供清晰的权限说明和随时停止操作。逐题回答 Clarify 批量问题,重连后保留已确认的进度。聊天卡片更简洁,配置文件显示名称更易辨认,上下文预览准确说明当前连接支持发送哪些信息。设备控制仍仅限侧载版本。
+292
View File
@@ -1,6 +1,298 @@
{
"schema": 3,
"versions": [
{
"version": "1.17.0",
"title": "Voice over other apps and clearer conversations",
"date": "2026-09-13",
"summary": "Google Play gains optional voice controls over other apps. Clarify questions, profile names, and chat context are easier to follow without losing confirmed answers or saved conversations.",
"changes": [
{"id": "play-voice-overlay", "kind": "added", "title": "Keep voice controls over other apps", "summary": "Start Voice Overlay from Voice Focus after granting microphone, notification, and display-over-other-apps access. Stop voice from its controls or persistent notification; screen lock and permission loss end the session.", "highlight": true},
{"id": "clarify-batches", "kind": "fixed", "title": "Answer Clarify questions one at a time", "summary": "Multi-question requests support separate choices and custom answers. Confirmed progress survives reconnects, and failed sends keep the current answer available.", "highlight": true},
{"id": "chat-card-surfaces", "kind": "improved", "title": "Read cleaner chat cards", "summary": "Standalone response cards lose the extra outer bubble, assistant messages use quieter surfaces, and delivery status sits beside the timestamp."},
{"id": "transport-context-preview", "kind": "fixed", "title": "See which context your chat can send", "summary": "Gateway previews mark phone status and turn context as unavailable. Automatic phone-status sharing is labeled for API-only chats, where it remains supported."},
{"id": "profile-display-names", "kind": "fixed", "title": "Recognize profiles by their display names", "summary": "Profiles use their Hermes display names, and the resolved server default appears under its agent identity. Explicit profile choices and saved conversations are preserved.", "highlight": true}
],
"compatibility": [
"Voice Overlay is now available in Google Play and sideload builds. Device Control remains sideload-only.",
"Standard Chat and voice use upstream Hermes without requiring Hermes-Relay Plugin. Gateway phone-status delivery and automatic Android identification remain unavailable."
],
"playNotes": "Use optional voice controls over other apps, with clear permission setup and an immediate Stop action. Answer Clarify batches one question at a time, with progress preserved across reconnects. Enjoy cleaner chat cards, recognizable profile names, and context previews that show what your connection supports. Phone control remains sideload-only.",
"sections": []
},
{
"version": "1.16.1",
"title": "Dashboard-only cold starts recover",
"date": "2026-09-12",
"summary": "Dashboard-only connections can now prepare the selected profile and open Gateway chat without waiting for a background, resume, or network-route change.",
"changes": [
{
"id": "gateway-directory-bootstrap",
"kind": "fixed",
"title": "Open Gateway chat from a Dashboard-only cold start",
"summary": "The selected profile's session directory starts before Gateway readiness, so it cannot wait on the same passive socket that depends on its result.",
"highlight": true
}
],
"compatibility": [
"Standard Dashboard and Gateway chat continue to use current upstream Hermes without requiring the optional Hermes-Relay Plugin.",
"Hermes-Relay Plugin 1.11.2 remains the matching optional release for Relay tools."
],
"playNotes": "Dashboard-only connections now prepare the selected profile before Gateway readiness, fixing a remaining cold-start path that could stay on waking or waiting for Gateway until the app resumed or its network route changed.",
"sections": []
},
{
"version": "1.16.0",
"title": "Safer startup, connections, and activity",
"date": "2026-09-10",
"summary": "Gateway chat opens reliably from a cold launch, saved sign-ins stay with the correct connection, and network changes no longer race the route cache. Bot Mode and delegated-work feedback also remain stable across multiple gateways and later review.",
"changes": [
{
"id": "gateway-cold-start",
"kind": "fixed",
"title": "Open Gateway chat on the first launch",
"summary": "An authenticated Gateway wakes and opens from a cold foreground start instead of waiting for the app to background and resume.",
"highlight": true
},
{
"id": "connection-owned-signin",
"kind": "fixed",
"title": "Keep saved sign-ins with their connection",
"summary": "Switching gateways cannot reuse an outgoing resolver route to invalidate another connection's saved Dashboard session.",
"highlight": true
},
{
"id": "network-change-invalidation",
"kind": "fixed",
"title": "Recover safely when the network changes",
"summary": "Route-probe completion and endpoint-cache invalidation are serialized so Wi-Fi, mobile-data, VPN, or Tailscale changes do not trigger the reported crash.",
"highlight": true
},
{
"id": "bot-mode-connection-identity",
"kind": "fixed",
"title": "Open same-named bots from multiple gateways",
"summary": "Bot Mode and Active Now keep connection and profile identity together, avoiding duplicate list keys and opening progress on the selected bot."
},
{
"id": "delegated-activity-receipts",
"kind": "improved",
"title": "Review delegated work after it finishes",
"summary": "Compact, bounded activity receipts survive parent replies and remain available read-only, while the live strip appears only during active work.",
"highlight": true
},
{
"id": "chat-feedback-surfaces",
"kind": "improved",
"title": "Keep feedback with the surface that owns it",
"summary": "Themed banners and action cards replace platform popups, global actions stay clear of the composer, and local Developer previews make feedback states inspectable."
},
{
"id": "attachment-error-recovery",
"kind": "fixed",
"title": "Retry missing attachments in place",
"summary": "A missing attachment keeps its error and Retry action in the attachment card without producing repeated global messages."
},
{
"id": "session-preparation-diagnostics",
"kind": "improved",
"title": "See session preparation and initialization failures",
"summary": "Chat distinguishes session preparation from response streaming, retains early initialization errors, and opens session diagnostics from the agent header."
},
{
"id": "pasted-dashboard-credentials",
"kind": "fixed",
"title": "Paste Dashboard credentials without hidden line breaks",
"summary": "Username and password fields remove pasted carriage returns and line feeds while preserving every other credential character."
}
],
"compatibility": [
"Standard Chat, sessions, profiles, Manage, voice, Bot Mode, and delegated activity continue to use current upstream Hermes without requiring the optional Hermes-Relay Plugin.",
"Hermes-Relay Plugin 1.11.2 is the matching optional release for Relay tools. Existing erased or revoked Dashboard credentials still require a legitimate sign-in.",
"Granular Device Control and the system Voice Focus overlay remain sideload-only."
],
"playNotes": "Gateway chat now opens reliably on a cold launch. Saved Dashboard sign-ins stay bound to the correct connection, pasted credentials ignore accidental line breaks, and network changes no longer race the route cache. Bot Mode supports duplicate profile names across gateways, while delegated work, session setup, attachment errors, and feedback remain visible and easier to review.",
"sections": []
},
{
"version": "1.15.1",
"title": "Steadier chat, media, and voice",
"date": "2026-09-02",
"summary": "Chats use less memory, attachment previews stay in place, and voice failures are easier to recover from. Follow-up controls make it clear whether a message changes the current response or waits for the next turn.",
"changes": [
{
"id": "follow-up-controls",
"kind": "improved",
"title": "Choose when follow-up messages are sent",
"summary": "A slim tray behind the composer offers Correct now or Queue next. Chat settings sets the default, and a composer choice applies to one message. Stop pauses pending work until Resume; editing or removing an item keeps the remaining queue usable.",
"highlight": true
},
{
"id": "tablet-layouts",
"kind": "improved",
"title": "Make better use of wider screens",
"summary": "Chat and Voice keep text and controls on readable centered layouts. Landscape Voice Focus separates identity controls from conversation activity."
},
{
"id": "delivery-labels",
"kind": "fixed",
"title": "Read message delivery status clearly",
"summary": "Correction and delivery labels use contrasting text instead of disappearing into the message bubble."
},
{
"id": "voice-error-dialog",
"kind": "fixed",
"title": "Read and dismiss voice errors",
"summary": "Voice errors open in a contained dialog with scrollable details and separate Retry and Dismiss actions, without overlapping chat controls."
},
{
"id": "attachment-previews",
"kind": "fixed",
"title": "Keep attachment previews open through rotation",
"summary": "Image, video, audio, PDF, text, and file previews stay open as the screen rotates. Videos retain their original proportions.",
"highlight": true
},
{
"id": "wake-word-startup",
"kind": "fixed",
"title": "Fix wake-word startup in release builds",
"summary": "Release optimization now preserves the native speech configuration names needed to initialize wake-word detection."
},
{
"id": "attachment-downloads",
"kind": "fixed",
"title": "Download attachments with less memory",
"summary": "Standard Hermes attachments stream into the on-disk cache while download size limits remain enforced."
},
{
"id": "chat-memory-safety",
"kind": "fixed",
"title": "Keep large chats and media manageable",
"summary": "Automatic session refresh no longer loops. Routine history loads, chat rendering, image previews, and media exports use bounded memory instead of allocating entire large responses.",
"highlight": true
},
{
"id": "image-progress",
"kind": "fixed",
"title": "Keep image-generation progress visible",
"summary": "The working indicator stays visible between interim replies and the generated image, including gateways that omit tool activity events."
},
{
"id": "first-message-readiness",
"kind": "fixed",
"title": "Wait for new chats to be ready",
"summary": "The first message waits for the Gateway session to initialize. Ownership refusals keep the prompt retryable and show the server's error."
}
],
"compatibility": [
"Standard Chat, sessions, media, and voice continue to use upstream Hermes. Voice transcription still requires a configured speech-to-text provider on the Hermes host.",
"Paused text queues can be restored. Attachment bytes are not stored in preferences; an attachment queue that cannot be restored must be reviewed and sent again."
],
"playNotes": "More reliable chats and media: fewer memory-heavy refreshes, smoother large histories, and attachment previews that survive rotation. Choose whether follow-ups correct the current response or wait in a queue. Voice errors are easier to read, image-generation progress stays visible, and wake-word startup and first-message readiness are fixed.",
"sections": []
},
{
"version": "1.15.0",
"title": "Standard Hermes first, with clearer Relay boundaries",
"date": "2026-08-31",
"summary": "Chat, voice, attachments, inbound files, current-session Git, usage, and Hermes notices now prefer current upstream Dashboard and Gateway support. Relay stays optional for compatibility and the tools it uniquely provides.",
"changes": [
{
"id": "upstream-standard-surfaces",
"kind": "improved",
"title": "Use standard Hermes without Relay prompts",
"summary": "Chat attachments, inbound files, current-session Git, Nous usage, and Hermes notices use upstream routes first.",
"highlight": true
},
{
"id": "stable-inbound-media",
"kind": "fixed",
"title": "Keep returned files loaded",
"summary": "Images, audio, video, and documents download through the Dashboard and no longer flash Relay errors or return to Loading.",
"highlight": true
},
{
"id": "supervised-parent-access",
"kind": "improved",
"title": "Use app-specific parent access",
"summary": "A parent PIN or password plus recovery phrase protects Supervised Mode without trusting the phone unlock credential.",
"highlight": true
},
{
"id": "settings-relay-boundaries",
"kind": "improved",
"title": "See which features need Relay",
"summary": "Media sits with standard Hermes settings while Threads, Terminal, notifications, enhanced voice, and device tools stay under Relay tools."
},
{
"id": "complete-release-history",
"kind": "improved",
"title": "Read the complete release record",
"summary": "What's New shows one release summary, selected highlights, every remaining change, and relevant compatibility notes."
},
{
"id": "relay-removal-voice",
"kind": "fixed",
"title": "Keep Standard voice after removing Relay",
"summary": "Dashboard voice remains ready, temporary outages preserve choices, and shared default-profile settings stay isolated."
},
{
"id": "passive-external-activity",
"kind": "fixed",
"title": "Observe another client's activity safely",
"summary": "A uniquely matched Desktop or TUI turn can show Working or Waiting without Android taking control."
},
{
"id": "chat-transport-ownership",
"kind": "fixed",
"title": "Keep each chat on its chosen transport",
"summary": "Dashboard chats preserve their transcript, draft, profile, and session through sign-out or outages instead of silently changing databases."
},
{
"id": "history-auth-recovery",
"kind": "fixed",
"title": "Preserve completed replies at sign-in expiry",
"summary": "A Dashboard history authentication failure keeps completed text visible and opens the existing sign-in recovery path."
},
{
"id": "compaction-watchdog",
"kind": "fixed",
"title": "Let long context compaction finish",
"summary": "Visible compaction activity refreshes the turn watchdog instead of being interrupted as idle."
},
{
"id": "bot-chat-binding",
"kind": "fixed",
"title": "Render Bot Chat history immediately",
"summary": "Route-owned Bot Chats observe their bound history from first composition."
},
{
"id": "missing-terminal-recovery",
"kind": "fixed",
"title": "Settle turns after a lost terminal frame",
"summary": "An exact idle live-session snapshot reconciles the Android-owned turn and drains its queued follow-up."
},
{
"id": "supervised-gateway-setup",
"kind": "fixed",
"title": "Keep Gateway setup parent-owned",
"summary": "Relock and back navigation cancel the exact pending setup without bypassing parent authority."
},
{
"id": "generated-image-retention",
"kind": "fixed",
"title": "Keep completed generated images visible",
"summary": "Generated media survives marker persistence lag and retains its intended Chat animation."
}
],
"compatibility": [
"Current upstream Hermes provides standard Chat, sessions, Manage, voice, attachments, inbound files, current-session Git reads, usage, and notices without the optional Hermes-Relay Plugin.",
"Hermes-Relay Plugin 1.11.1 remains required for Terminal, proactive Threads and offline delivery, Notification Companion, Relay sessions, enhanced voice, Secure Link, and phone or device control.",
"Granular Device Control and the system Voice Focus overlay remain sideload-only."
],
"playNotes": "Standard Chat, Voice, attachments, returned files, current-session Git, usage, and Hermes notices now prefer upstream Dashboard and Gateway support without requiring Relay. Returned media stays loaded, voice survives Relay removal, and Settings clearly separates standard Hermes from Relay tools. Supervised Mode also gains app-specific parent access and recovery.",
"sections": []
},
{
"version": "1.14.0",
"title": "Connections, delegated work, Git, and voice",
+9 -21
View File
@@ -1,31 +1,19 @@
v1.14.0 - Connections, delegated work, Git, and voice
v1.17.0 - Voice over other apps and clearer conversations
Summary
* Connections now recover cleanly across networks. You can also follow delegated agents, work with Git repositories, and rely on steadier voice, sessions, Threads, profiles, Assistant, and Clarify controls.
* Google Play gains optional voice controls over other apps. Clarify questions, profile names, and chat context are easier to follow without losing confirmed answers or saved conversations.
Highlights
* Connections recover independently — Move between LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication.
* Follow delegated-agent activity — See lifecycle, progress, tool previews, and available read-only child history from the parent chat.
* Work with repositories from Android — Review status, diffs, branches, staging, commits, and remotes from Chat or Settings.
* Steer voice at any time — Stop or redirect Hermes while it is Thinking, Transcribing, or Speaking, including with accessibility controls.
* Keep voice controls over other apps — Start Voice Overlay from Voice Focus after granting microphone, notification, and display-over-other-apps access. Stop voice from its controls or persistent notification; screen lock and permission loss end the session.
* Answer Clarify questions one at a time — Multi-question requests support separate choices and custom answers. Confirmed progress survives reconnects, and failed sends keep the current answer available.
* Recognize profiles by their display names — Profiles use their Hermes display names, and the resolved server default appears under its agent identity. Explicit profile choices and saved conversations are preserved.
Improved
* Release notes stay out of your way — A dismissible post-update notice keeps startup usable and leaves the complete history available from Settings.
* Chat uses one consistent presentation — The overlapping clean-focus mode was removed while the separate Voice Focus experience remains available.
* Read cleaner chat cards — Standalone response cards lose the extra outer bubble, assistant messages use quieter surfaces, and delivery status sits beside the timestamp.
Fixed
* Wake-word detection starts reliably — Compatible native voice components are now packaged for every supported phone architecture.
* The visible Sphere keeps moving smoothly — Foreground animation no longer falls back to a stepped ambient pulse.
* Continuous voice keeps the microphone — The next listening turn waits for barge-in recording to release cleanly.
* New chats keep the selected profile — Fresh drafts no longer reopen an older session or carry a Thread route into another profile.
* Provisional Threads can be removed safely — Local removal and later session promotion no longer risk duplicate rows or server history.
* Clarify keeps custom answers reachable — Other answers, keyboard Send, and expired prompts now behave consistently.
* Browsing no longer interrupts another client — Passive Android observation does not claim a turn owned by Desktop, TUI, or another client.
* Assistant sessions recover more clearly — No-speech feedback, recreated session state, and keyguard privacy now remain intact.
* Protected Relay routes report the right problem — Authentication challenges are no longer presented as outages, while unsafe routes still fail closed.
* Connections and sessions become ready sooner — Unavailable optional API and Relay routes no longer delay a healthy Dashboard or authenticated session history.
* See which context your chat can send — Gateway previews mark phone status and turn context as unavailable. Automatic phone-status sharing is labeled for API-only chats, where it remains supported.
Compatibility
* Standard Chat, sessions, profiles, Manage, and standard voice continue to work without the optional Hermes-Relay Plugin.
* The Git workspace and same-origin Relay extensions require Hermes-Relay Plugin 1.11.0.
* Granular Device Control and the system Voice Focus overlay remain available only in the sideload build.
* Voice Overlay is now available in Google Play and sideload builds. Device Control remains sideload-only.
* Standard Chat and voice use upstream Hermes without requiring Hermes-Relay Plugin. Gateway phone-status delivery and automatic Android identification remain unavailable.
@@ -13,10 +13,15 @@ import coil3.network.okhttp.OkHttpNetworkFetcherFactory
import coil3.request.crossfade
import com.hermesandroid.relay.bridge.UnattendedAccessManager
import com.hermesandroid.relay.data.AppAnalytics
import com.hermesandroid.relay.data.relayDataStore
import com.hermesandroid.relay.power.WakeLockManager
import com.hermesandroid.relay.runtime.HermesProcessRuntime
import com.hermesandroid.relay.ui.theme.AppearanceNightMode
import com.hermesandroid.relay.util.AppForegroundTracker
import com.hermesandroid.relay.util.CrashReporter
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.runBlocking
import kotlinx.coroutines.withTimeoutOrNull
class HermesRelayApp : Application(), SingletonImageLoader.Factory {
@@ -57,6 +62,10 @@ class HermesRelayApp : Application(), SingletonImageLoader.Factory {
// Install the crash handler FIRST so any failure in the rest of app
// init (or anywhere later) is captured and surfaced on next launch.
CrashReporter.install(this)
// Apply saved Light/Dark/Auto before the first Activity frame so DayNight
// does not briefly follow the system when Appearance is explicitly Light.
// Bounded + best-effort: HermesRelayTheme SideEffect is the durable path.
applyPersistedAppearanceNightMode()
AppAnalytics.initialize(this)
// A8 — wire the bridge-gesture wake-lock wrapper so
// ActionExecutor.tap/tapText/typeText/swipe/scroll can hold
@@ -76,6 +85,19 @@ class HermesRelayApp : Application(), SingletonImageLoader.Factory {
AppForegroundTracker.initialize()
}
private fun applyPersistedAppearanceNightMode() {
try {
runBlocking {
val preferences = withTimeoutOrNull(400L) {
relayDataStore.data.first()
} ?: return@runBlocking
AppearanceNightMode.applyFromPreferences(preferences)
}
} catch (_: Throwable) {
// Non-fatal — theme root reapplies once DataStore is ready.
}
}
private fun isMainApplicationProcess(): Boolean {
val processName = if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.P) {
getProcessName()
@@ -34,9 +34,7 @@ object AgentDisplay {
profiles: List<Profile>,
): Profile? = selectedProfile
// Display can use the root default profile's metadata without making it a
// request/session override. Verbose SOUL summaries are filtered by
// profileDisplayName below, so this is safe for headers/cards.
// Display resolution never changes selection or persistence identity.
fun effectiveDisplayProfile(
selectedProfile: Profile?,
profiles: List<Profile>,
@@ -44,36 +42,22 @@ object AgentDisplay {
): Profile? {
selectedProfile?.let { return it }
val resolvedServerDefault = profileRequestName(serverDefaultProfileName)
return resolvedServerDefault
?.let { activeName ->
profiles.firstOrNull { it.name.equals(activeName, ignoreCase = true) }
}
?: profiles.firstOrNull { it.name.equals("default", ignoreCase = true) }
// An absent roster row is not authority to substitute the root profile.
// Retain the confirmed name while its display metadata is loading.
return resolvedServerDefault?.let { activeName ->
profiles.firstOrNull { it.name == activeName }
?: Profile(name = activeName, model = "")
}
}
// The NAME goes in the name slot. Non-default profiles use their profile
// name first. The synthetic default profile uses its description only when
// that description looks like a concise human agent name ("Victor"), not a
// verbose SOUL summary.
// Match upstream Desktop: presentation-only display_name, then exact request name.
fun profileDisplayName(profile: Profile?): String? {
if (profile == null) return null
if (profile.name.equals("default", ignoreCase = true)) {
return defaultProfileDisplayName(profile)
}
return when {
profile.name.isNotBlank() -> titleCase(profile.name.trim())
profile.description.isNotBlank() -> profile.description.trim()
else -> null
}
return profile.displayName.trim().takeIf(String::isNotEmpty)
?: profile.name.trim().takeIf(String::isNotEmpty)
}
fun defaultProfileDisplayName(profile: Profile?): String? =
profile
?.description
?.trim()
?.takeIf { it.looksLikeConciseAgentName() }
?.let(::titleCase)
@Suppress("UNUSED_PARAMETER") // connectionLabel retained for source compatibility.
fun agentName(
profile: Profile?,
selectedPersonality: String,
@@ -86,7 +70,7 @@ object AgentDisplay {
// "none"/"neutral" are the upstream "cleared overlay" aliases — treat
// them like "default" for identity: fall through to the server default
// (or the base connection identity) rather than rendering the literal
// identity rather than rendering the literal
// word as an agent name.
val personalityName = if (
isClearedPersonality(selectedPersonality) &&
@@ -102,7 +86,6 @@ object AgentDisplay {
return when {
personalityName.isNotBlank() && personalityName != "default" ->
titleCase(personalityName.trim())
!connectionLabel.isNullOrBlank() -> connectionLabel.trim()
else -> "Hermes"
}
}
@@ -199,16 +182,6 @@ object AgentDisplay {
?.replace(Regex("\\s+"), " ")
?.takeIf { it.isNotEmpty() }
private fun String.looksLikeConciseAgentName(): Boolean {
if (isBlank() || length > 40 || contains('\n') || contains('\r')) {
return false
}
if (any { it == '.' || it == ':' || it == ';' }) {
return false
}
return trim().split(Regex("\\s+")).size <= 4
}
private fun titleCase(value: String): String =
value.replaceFirstChar { it.uppercase() }
}
@@ -1,6 +1,7 @@
package com.hermesandroid.relay.data
import android.content.Context
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.floatPreferencesKey
import androidx.datastore.preferences.core.stringPreferencesKey
import com.hermesandroid.relay.ui.theme.AppFont
@@ -35,23 +36,25 @@ internal object AppearancePreferences {
private val serializer = ListSerializer(CustomThemePreset.serializer())
fun state(context: Context): Flow<PersistedAppearance> = context.applicationContext.relayDataStore.data
.map { preferences ->
val customThemes = decodeCustomThemes(preferences[customThemesKey])
val requestedThemeId = preferences[appThemeKey]
val customTheme = CustomThemePreset.idFromAppTheme(requestedThemeId)
?.let { id -> customThemes.firstOrNull { it.id == id } }
PersistedAppearance(
themePreference = preferences[themeKey]
?.takeIf { it == "auto" || it == "light" || it == "dark" }
?: "auto",
appThemeId = customTheme?.appThemeId ?: AppThemes.byId(requestedThemeId).id,
accentHex = normalizeAccentHex(preferences[accentKey]),
shapeId = AppearanceShape.fromId(preferences[shapeKey]).id,
appFontId = AppFont.byId(preferences[appFontKey]).id,
fontScale = (preferences[fontScaleKey] ?: 1.0f).coerceIn(0.85f, 1.3f),
customTheme = customTheme,
)
}
.map(::decode)
fun decode(preferences: Preferences): PersistedAppearance {
val customThemes = decodeCustomThemes(preferences[customThemesKey])
val requestedThemeId = preferences[appThemeKey]
val customTheme = CustomThemePreset.idFromAppTheme(requestedThemeId)
?.let { id -> customThemes.firstOrNull { it.id == id } }
return PersistedAppearance(
themePreference = preferences[themeKey]
?.takeIf { it == "auto" || it == "light" || it == "dark" }
?: "auto",
appThemeId = customTheme?.appThemeId ?: AppThemes.byId(requestedThemeId).id,
accentHex = normalizeAccentHex(preferences[accentKey]),
shapeId = AppearanceShape.fromId(preferences[shapeKey]).id,
appFontId = AppFont.byId(preferences[appFontKey]).id,
fontScale = (preferences[fontScaleKey] ?: 1.0f).coerceIn(0.85f, 1.3f),
customTheme = customTheme,
)
}
fun shape(context: Context): Flow<String> = state(context).map { it.shapeId }
@@ -0,0 +1,102 @@
package com.hermesandroid.relay.data
/** Presentation only: canonical rows retain their wire identity, role and content. */
internal fun projectChatActivityReceipts(
messages: List<ChatMessage>,
records: List<ChatActivityRecord>,
scopeKey: String?,
sessionId: String?,
): List<ChatMessage> {
val originals = messages.filterNot {
it.clientOnly && it.id.startsWith("activity:") && it.activityRecord != null
}
if (scopeKey.isNullOrBlank() || sessionId.isNullOrBlank()) {
return originals.map { it.copy(activityRecord = null) }
}
val owned = records.filter { it.scopeKey == scopeKey && it.sessionId == sessionId }
.sortedByDescending { it.updatedAt }
.distinctBy { it.id }
val represented = mutableSetOf<String>()
val canonical = originals.map { message ->
val process = message.hermesProcessNotificationOrNull()
val delegation = message.activitySourceId?.takeIf { it.startsWith("delegation:") }
?.removePrefix("delegation:")?.takeIf { it.isNotBlank() }
val kind = when {
message.activitySourceId != null -> ChatActivityKind.SUBAGENTS
process != null -> ChatActivityKind.PROCESS
else -> return@map message.copy(activityRecord = null)
}
val sourceId = delegation ?: process?.processId
val processTerminal = process?.let { notice ->
PROCESS_TERMINAL_HEADLINE.matchEntire(notice.headline)?.let { match ->
match.groupValues[2].toIntOrNull()?.let { code ->
val phase = when {
match.groupValues[1].startsWith("terminated by ") -> ChatActivityPhase.CANCELLED
code == 0 -> ChatActivityPhase.COMPLETE
else -> ChatActivityPhase.FAILED
}
phase to code
}
}
}
// A process id can be reused after a registry restart. A canonical row has
// no start-generation field, so multiple generations must remain unmatched.
val matching = if (sourceId == null) emptyList() else owned.filter {
it.kind == kind && it.sourceId == sourceId
}
val record = matching.singleOrNull()?.also { represented += it.id }
?: ChatActivityRecord(
id = "canonical:${message.id}",
scopeKey = scopeKey,
sessionId = sessionId,
kind = kind,
sourceId = sourceId ?: "unavailable:${message.id}",
title = process?.headline ?: message.content,
phase = when {
kind == ChatActivityKind.PROCESS -> processTerminal?.first ?: ChatActivityPhase.UNKNOWN
(message.activityFailedCount ?: 0) > 0 ->
if (message.activityFailedCount == message.activityTaskCount) {
ChatActivityPhase.FAILED
} else ChatActivityPhase.UNKNOWN
(message.activityTaskCount ?: 0) > 0 -> ChatActivityPhase.COMPLETE
else -> ChatActivityPhase.UNKNOWN
},
createdAt = message.timestamp,
updatedAt = message.timestamp,
taskCount = message.activityTaskCount?.coerceAtLeast(0) ?: 0,
processId = process?.processId,
exitCode = processTerminal?.second,
)
// Aggregate completion metadata never rewrites captured child phases.
message.copy(activityRecord = record)
}
val pending = owned.filter { it.phase != ChatActivityPhase.RUNNING && it.id !in represented }
.sortedWith(compareBy<ChatActivityRecord> { it.updatedAt }.thenBy { it.id })
.map { record ->
ChatMessage(
id = "activity:${record.id}",
role = MessageRole.SYSTEM,
content = record.title,
timestamp = record.updatedAt,
clientOnly = true,
activityRecord = record,
)
}
// Stable merge: history order is authoritative even if server timestamps
// regress. Only insert local receipts; never sort canonical messages.
var next = 0
return buildList {
canonical.forEach { message ->
while (next < pending.size && pending[next].timestamp < message.timestamp) {
add(pending[next++])
}
add(message)
}
while (next < pending.size) add(pending[next++])
}
}
/** Upstream completion envelope only; never search arbitrary command/output text. */
private val PROCESS_TERMINAL_HEADLINE = Regex(
"""Background process \S+ (completed normally|exited|terminated by [^\r\n]+|marked lost because the process backend disappeared|failed to start) \(exit code (-?\d+)(?:, SIGTERM)?\)\.""",
)
@@ -0,0 +1,222 @@
package com.hermesandroid.relay.data
import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import java.io.IOException
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.jsonPrimitive
import kotlinx.serialization.json.intOrNull
@Serializable
enum class ChatActivityKind { SUBAGENTS, PROCESS }
@Serializable
enum class ChatActivityPhase { RUNNING, COMPLETE, FAILED, CANCELLED, UNKNOWN }
@Serializable
data class ChatActivityChild(
val id: String,
val childSessionId: String? = null,
val goal: String = "",
val phase: ChatActivityPhase = ChatActivityPhase.UNKNOWN,
val summary: String? = null,
)
/** Local presentation metadata and exact references, never transcripts or process output. */
@Serializable
data class ChatActivityRecord(
val id: String,
val scopeKey: String,
val sessionId: String,
val kind: ChatActivityKind,
val sourceId: String,
val title: String,
val phase: ChatActivityPhase,
val createdAt: Long,
val updatedAt: Long,
val children: List<ChatActivityChild> = emptyList(),
val taskCount: Int = 0,
val processId: String? = null,
val processStartedAt: String? = null,
val exitCode: Int? = null,
)
interface ChatActivityStore {
/** Recovery is not live evidence: RUNNING becomes UNKNOWN, including child phases. */
suspend fun read(scopeKey: String, sessionId: String): List<ChatActivityRecord>
suspend fun upsert(record: ChatActivityRecord)
suspend fun removeRecord(scopeKey: String, sessionId: String, id: String)
suspend fun removeSession(scopeKey: String, sessionId: String)
}
/**
* Bounded app-private history references in the shared settings DataStore.
* Retains 30 days, 128 records overall, 32 per exact owner/session, and 32 children
* per record. Titles are 160 characters; goals/summaries 512. Identity fields are
* rejected above 512 characters (scope 2048), never truncated into another owner.
* The complete encoded envelope is capped at 1 MiB, evicting oldest records first.
* Five minutes of future skew allows monotonic local revisions within one clock tick.
* All read/modify/write operations occur inside DataStore's serialized edit.
*/
class DataStoreChatActivityStore(
private val dataStore: DataStore<Preferences>,
private val now: () -> Long = System::currentTimeMillis,
) : ChatActivityStore {
constructor(context: Context) : this(context.applicationContext.relayDataStore)
override suspend fun read(scopeKey: String, sessionId: String): List<ChatActivityRecord> {
val raw = try {
dataStore.data.first()[CHAT_ACTIVITY_KEY]
} catch (_: IOException) {
return emptyList()
}
return boundChatActivities(decodeChatActivities(raw), now())
.filter { it.scopeKey == scopeKey && it.sessionId == sessionId }
.map(ChatActivityRecord::recovered)
}
override suspend fun upsert(record: ChatActivityRecord) {
dataStore.edit { preferences ->
val records = mergeChatActivity(decodeChatActivities(preferences[CHAT_ACTIVITY_KEY]), record, now())
preferences[CHAT_ACTIVITY_KEY] = encodeChatActivities(records)
}
}
override suspend fun removeSession(scopeKey: String, sessionId: String) {
dataStore.edit { preferences ->
val remaining = boundChatActivities(decodeChatActivities(preferences[CHAT_ACTIVITY_KEY]), now())
.filterNot { it.scopeKey == scopeKey && it.sessionId == sessionId }
if (remaining.isEmpty()) preferences.remove(CHAT_ACTIVITY_KEY)
else preferences[CHAT_ACTIVITY_KEY] = encodeChatActivities(remaining)
}
}
override suspend fun removeRecord(scopeKey: String, sessionId: String, id: String) {
dataStore.edit { preferences ->
val remaining = boundChatActivities(decodeChatActivities(preferences[CHAT_ACTIVITY_KEY]), now())
.filterNot { it.scopeKey == scopeKey && it.sessionId == sessionId && it.id == id }
if (remaining.isEmpty()) preferences.remove(CHAT_ACTIVITY_KEY)
else preferences[CHAT_ACTIVITY_KEY] = encodeChatActivities(remaining)
}
}
}
/** Test/ephemeral implementation with the same bounds and recovery semantics. */
class InMemoryChatActivityStore(
private val now: () -> Long = System::currentTimeMillis,
) : ChatActivityStore {
private val mutex = Mutex()
private var records = emptyList<ChatActivityRecord>()
override suspend fun read(scopeKey: String, sessionId: String): List<ChatActivityRecord> = mutex.withLock {
records = boundChatActivities(records, now())
records.filter { it.scopeKey == scopeKey && it.sessionId == sessionId }
.map(ChatActivityRecord::recovered)
}
override suspend fun upsert(record: ChatActivityRecord) = mutex.withLock {
records = mergeChatActivity(records, record, now())
}
override suspend fun removeSession(scopeKey: String, sessionId: String) = mutex.withLock {
records = boundChatActivities(records, now())
.filterNot { it.scopeKey == scopeKey && it.sessionId == sessionId }
}
override suspend fun removeRecord(scopeKey: String, sessionId: String, id: String) = mutex.withLock {
records = boundChatActivities(records, now())
.filterNot { it.scopeKey == scopeKey && it.sessionId == sessionId && it.id == id }
}
}
internal const val CHAT_ACTIVITY_MAX_AGE_MS = 30L * 24L * 60L * 60L * 1_000L
private const val MAX_RECORDS = 128
private const val MAX_SESSION_RECORDS = 32
private const val MAX_PAYLOAD_BYTES = 1_048_576
private val CHAT_ACTIVITY_KEY = stringPreferencesKey("chat_activity_records_v1")
private val activityJson = Json { ignoreUnknownKeys = true; encodeDefaults = true }
@Serializable
private data class ChatActivityEnvelope(val version: Int = 1, val records: List<ChatActivityRecord>)
private fun encodeChatActivities(records: List<ChatActivityRecord>): String =
activityJson.encodeToString(ChatActivityEnvelope(records = records))
internal fun decodeChatActivities(raw: String?): List<ChatActivityRecord> {
if (raw == null || raw.length > MAX_PAYLOAD_BYTES || raw.toByteArray().size > MAX_PAYLOAD_BYTES) {
return emptyList()
}
val envelope = runCatching { activityJson.parseToJsonElement(raw) as? JsonObject }.getOrNull()
?: return emptyList()
val version = runCatching { envelope["version"]?.jsonPrimitive?.intOrNull }.getOrNull()
if (version != 1) return emptyList()
val rows = envelope["records"] as? JsonArray ?: return emptyList()
// One corrupt or newer row must not hide independently valid records.
return rows.mapNotNull { row ->
runCatching { activityJson.decodeFromJsonElement(ChatActivityRecord.serializer(), row) }.getOrNull()
}
}
private fun ChatActivityRecord.identity() = Triple(scopeKey, sessionId, id)
private fun mergeChatActivity(
existing: List<ChatActivityRecord>,
record: ChatActivityRecord,
now: Long,
): List<ChatActivityRecord> {
// Sorting first also rejects a late write for an older generation of the same record.
return boundChatActivities(listOf(record) + existing, now)
}
internal fun boundChatActivities(records: List<ChatActivityRecord>, now: Long): List<ChatActivityRecord> {
val counts = mutableMapOf<Pair<String, String>, Int>()
val bounded = records.mapNotNull { it.bounded(now) }
.sortedByDescending(ChatActivityRecord::updatedAt)
.distinctBy { it.identity() }
.filter {
val owner = it.scopeKey to it.sessionId
val count = counts.getOrDefault(owner, 0)
counts[owner] = count + 1
count < MAX_SESSION_RECORDS
}.take(MAX_RECORDS).toMutableList()
while (bounded.isNotEmpty() && encodeChatActivities(bounded).toByteArray().size > MAX_PAYLOAD_BYTES) {
bounded.removeAt(bounded.lastIndex)
}
return bounded
}
private fun validIdentity(value: String, max: Int = 512) = value.isNotBlank() && value.length <= max
private fun ChatActivityRecord.bounded(now: Long): ChatActivityRecord? {
if (!validIdentity(scopeKey, 2048) || !validIdentity(sessionId) || !validIdentity(id) ||
!validIdentity(sourceId) || (processId != null && !validIdentity(processId)) ||
(processStartedAt != null && !validIdentity(processStartedAt)) ||
createdAt < 0 || updatedAt < createdAt || updatedAt > now + 300_000L ||
now - updatedAt > CHAT_ACTIVITY_MAX_AGE_MS
) return null
return copy(
title = title.take(160),
taskCount = taskCount.coerceIn(0, 10_000),
children = children.asSequence().filter {
validIdentity(it.id) && (it.childSessionId == null || validIdentity(it.childSessionId))
}.distinctBy(ChatActivityChild::id).take(32)
.map { it.copy(goal = it.goal.take(512), summary = it.summary?.take(512)) }.toList(),
)
}
private fun ChatActivityRecord.recovered() = copy(
phase = if (phase == ChatActivityPhase.RUNNING) ChatActivityPhase.UNKNOWN else phase,
children = children.map {
if (it.phase == ChatActivityPhase.RUNNING) it.copy(phase = ChatActivityPhase.UNKNOWN) else it
},
)
@@ -22,6 +22,26 @@ enum class PhysicalKeyboardEnterBehavior(val storedValue: String) {
}
}
/** Default intent for a message submitted while an agent is responding. */
enum class BusyMessageAction(val storedValue: String) {
CorrectNow("correct_now"),
QueueNext("queue_next");
companion object {
fun fromStoredValue(value: String?): BusyMessageAction =
entries.firstOrNull { it.storedValue == value } ?: CorrectNow
}
}
fun canCorrectBusyMessage(
steerable: Boolean,
hasAttachments: Boolean,
hasPendingInput: Boolean,
status: String?,
text: String,
): Boolean = steerable && !hasAttachments && !hasPendingInput &&
status?.contains("compact", ignoreCase = true) != true && !text.trimStart().startsWith("/")
/** Device-level chat input preferences shared by every Hermes profile. */
class ChatInputPreferencesRepository(
private val dataStore: DataStore<Preferences>,
@@ -29,6 +49,7 @@ class ChatInputPreferencesRepository(
constructor(context: Context) : this(context.relayDataStore)
companion object {
internal val KEY_BUSY_MESSAGE_ACTION = stringPreferencesKey("busy_message_action")
internal val KEY_PHYSICAL_KEYBOARD_ENTER =
stringPreferencesKey("physical_keyboard_enter_behavior")
internal val KEY_CONVERT_LARGE_PASTES =
@@ -45,6 +66,14 @@ class ChatInputPreferencesRepository(
}
.distinctUntilChanged()
val busyMessageAction: Flow<BusyMessageAction> = dataStore.data
.map { BusyMessageAction.fromStoredValue(it[KEY_BUSY_MESSAGE_ACTION]) }
.distinctUntilChanged()
suspend fun setBusyMessageAction(action: BusyMessageAction) {
dataStore.edit { it[KEY_BUSY_MESSAGE_ACTION] = action.storedValue }
}
val convertLargePastesToAttachments: Flow<Boolean> = dataStore.data
.map { preferences -> preferences[KEY_CONVERT_LARGE_PASTES] ?: true }
.distinctUntilChanged()
@@ -170,6 +170,12 @@ data class ChatMessage(
* but server history never owns these presentation blocks.
*/
val moaReferences: List<MoaReference> = emptyList(),
/** Exact upstream identity on a persisted activity-completion marker. */
val activitySourceId: String? = null,
val activityTaskCount: Int? = null,
val activityFailedCount: Int? = null,
/** Read-only UI projection; never sent as model history or voice input. */
val activityRecord: ChatActivityRecord? = null,
)
data class MessageReaction(
@@ -5,6 +5,7 @@ import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import com.hermesandroid.relay.network.upstream.GatewayClarifyQuestion
import kotlinx.coroutines.flow.first
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
@@ -35,6 +36,9 @@ data class ChatTurnCheckpoint(
val baselineAssistantCount: Int,
val pendingAsk: ChatTurnAskCheckpoint? = null,
val queuedMessages: List<ChatQueuedMessageCheckpoint> = emptyList(),
val queuePaused: Boolean = false,
/** Only pending local work remains; never reattach the completed/stopped turn. */
val queueOnly: Boolean = false,
val startedAt: Long,
val updatedAt: Long,
) {
@@ -132,6 +136,9 @@ data class ChatTurnAskCheckpoint(
val text: String,
val choices: List<String>? = null,
val multiSelect: Boolean = false,
val questions: List<GatewayClarifyQuestion> = emptyList(),
val answers: Map<String, String> = emptyMap(),
val ownerId: String? = null,
val smartDenied: Boolean = false,
val envVar: String? = null,
val timeoutSeconds: Int,
@@ -29,3 +29,26 @@ val Connection.capabilities: ConnectionCapabilities
apiServerConfigured = apiServerUrl.isNotBlank(),
relayConfigured = relayUrl.isNotBlank(),
)
/**
* Stable owner for an Auto chat before a conversation is opened.
*
* A legacy API-only record has no persisted Dashboard route; the conventional
* same-host `:9119` derivation remains useful for an explicit upgrade, but it
* must not silently turn that compatibility record into a Gateway-owned chat.
* Once a Dashboard route (or authenticated Dashboard origin) is persisted,
* standard Chat belongs to Gateway even while that route is signed out or
* temporarily unreachable.
*/
val Connection.automaticChatTransport: SessionTransport
get() {
val dashboardPersisted = !dashboardUrl.isNullOrBlank() ||
!authenticatedDashboardOrigin.isNullOrBlank()
// An empty first-setup placeholder is standard Gateway intent, not an
// API-only conversation. Only an actual API endpoint selects legacy SSE.
return if (dashboardPersisted || apiServerUrl.isBlank()) SessionTransport.GATEWAY else SessionTransport.SSE
}
fun Connection.chatTransportForPreference(preference: String): SessionTransport =
if (preference == "auto") automaticChatTransport
else SessionTransport.forEndpoint(preference)
@@ -67,6 +67,8 @@ data class Connection(
* "derive from [apiServerUrl] using the conventional same-host :9119".
*/
val dashboardUrl: String? = null,
/** User-accepted cleartext origins. This does not assert or monitor VPN protection. */
val dashboardHttpConsentOrigins: Set<String> = emptySet(),
/**
* Credential-free origin that most recently completed Dashboard
* authentication for this connection. Public origins require HTTPS;
@@ -116,7 +118,7 @@ data class Connection(
*/
val resolvedDashboardUrl: String
get() = authenticatedDashboardOrigin
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
?.let { normalizeCredentialFreeAuthenticatedDashboardOrigin(it, dashboardHttpConsentOrigins) }
?: configuredDashboardUrl
/** Stable display/host identity that does not depend on the API surface. */
@@ -628,7 +630,10 @@ internal fun normalizeCredentialFreeHttpsOrigin(raw: String): String? {
* HTTPS; cleartext is accepted only for literal loopback, RFC1918/link-local,
* or Tailscale CGNAT addresses.
*/
internal fun normalizeCredentialFreeAuthenticatedDashboardOrigin(raw: String): String? {
internal fun normalizeCredentialFreeAuthenticatedDashboardOrigin(
raw: String,
httpConsentOrigins: Set<String> = emptySet(),
): String? {
normalizeCredentialFreeHttpsOrigin(raw)?.let { return it }
val parsed = runCatching { URI(raw.trim()) }.getOrNull() ?: return null
if (!parsed.scheme.equals("http", ignoreCase = true)) return null
@@ -651,6 +656,6 @@ internal fun normalizeCredentialFreeAuthenticatedDashboardOrigin(raw: String): S
else -> false
}
}
if (!trustedHost) return null
if (!trustedHost && !dashboardHttpConsentMatches(raw, httpConsentOrigins)) return null
return parsed.normalize().toASCIIString().trimEnd('/').takeIf { it.isNotBlank() }
}
@@ -124,7 +124,7 @@ private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): B
val normalized = url.trim().trimEnd('/')
val service = when (label) {
"Chat & Manage", "Dashboard & Gateway" -> "dashboard"
"API / sessions", "API fallback" -> "api"
"API / sessions", "API fallback", "Direct API" -> "api"
"Relay tools" -> "relay"
else -> return false
}
@@ -170,7 +170,7 @@ fun computeConnectionSecurity(
apiUrl.trim().takeIf { it.isNotBlank() }?.let {
add(
classifySurfaceSecurity(
label = "API fallback",
label = "Direct API",
url = it,
activeEndpoint = apiEndpoint,
isTailscaleDetected = isTailscaleDetected,
@@ -581,7 +581,7 @@ internal fun Connection.withDashboardDefaults(): Connection {
it.role.equals(LEGACY_AUTHENTICATED_DASHBOARD_ROUTE_ROLE, ignoreCase = true)
}
val migratedAuthenticatedOrigin = authenticatedDashboardOrigin
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
?.let { normalizeCredentialFreeAuthenticatedDashboardOrigin(it, dashboardHttpConsentOrigins) }
?: legacyAuthenticatedRoute?.dashboard?.url
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
val routesWithoutLegacyAuthentication = routeCandidates.filterNot {
@@ -0,0 +1,31 @@
package com.hermesandroid.relay.data
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
/** An explicit HTTP exception is scoped to a connection and exact origin, never a VPN claim. */
fun dashboardHttpOrigin(address: String): String? {
val url = address.trim().toHttpUrlOrNull() ?: return null
if (url.scheme != "http" || url.username.isNotEmpty() || url.password.isNotEmpty() ||
url.query != null || url.fragment != null
) return null
return url.newBuilder().encodedPath("/").build().toString().trimEnd('/')
}
fun dashboardHttpConsentRequired(address: String): Boolean =
dashboardHttpOrigin(address) != null && Connection.inferRouteRole(address) == "public"
fun dashboardHttpConsentMatches(address: String, approvedOrigins: Set<String>): Boolean =
dashboardHttpOrigin(address)?.let { it in approvedOrigins } == true
/** Editing an origin retires its old exception; another address requires its own confirmation. */
fun updatedDashboardHttpConsents(
previous: Set<String>,
oldAddress: String?,
newAddress: String,
confirmedOrigin: String?,
): Set<String> {
val oldOrigin = oldAddress?.let(::dashboardHttpOrigin)
val newOrigin = dashboardHttpOrigin(newAddress)
val retained = if (oldOrigin != newOrigin) previous - setOfNotNull(oldOrigin) else previous
return if (newOrigin != null && confirmedOrigin == newOrigin) retained + newOrigin else retained
}
@@ -197,15 +197,34 @@ fun EndpointCandidate.isDashboardOnlyRoute(): Boolean =
/** Dashboard-first URL identity for routing, diagnostics, and UI labels. */
fun EndpointCandidate.primaryRouteUrl(): String? =
dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
?: proxyDashboardBaseUrlOrNull()
?: api?.url
?: relay?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
?: proxy?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
/** Dashboard/Gateway identity only; Relay and broker transports are extensions. */
/**
* Dashboard/Gateway identity only; Relay and broker transports are extensions.
*
* Hermes Secure Link stores the dashboard surface under [ProxyEndpoint.surfaces]
* (`…/dashboard`), not [DashboardEndpoint.url]. Without that hop, Routes/Access
* fall back to the saved plain `:9119` URL while Overview already rides the
* live Secure Link origin.
*/
fun EndpointCandidate.gatewayRouteUrl(): String? =
dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
?: proxyDashboardBaseUrlOrNull()
?: api?.url?.let(Connection::deriveDefaultDashboardUrl)
/** Secure Link dashboard base when the proxy advertises a dashboard surface. */
internal fun EndpointCandidate.proxyDashboardBaseUrlOrNull(): String? {
val proxy = proxy ?: return null
if (!proxy.isValidPinnedProxy()) return null
val surfaces = proxy.surfaces.map { it.trim().lowercase() }.toSet()
if ("dashboard" !in surfaces) return null
val base = proxy.url.trim().trimEnd('/').takeIf { it.isNotBlank() } ?: return null
return "$base/dashboard"
}
/** Stable host/port identity without assuming that an API surface exists. */
fun EndpointCandidate.routeAuthority(): String? {
val rawUrl = primaryRouteUrl() ?: return null
@@ -96,7 +96,8 @@ object FeatureFlags {
* flavor ships AccessibilityService-backed Device Control. The `googlePlay`
* flavor is Bridge Core: relay pairing, chat, voice, terminal, notification
* companion, media, and session-grant surfaces without screen reading, taps,
* typing, screenshots, overlays, or unattended control.
* typing, MediaProjection screenshots, or unattended control. Voice-only overlay
* presentation is a separate capability shared by both flavors.
*
* Device Control tier definitions (see `Phase 3 — Bridge Channel.md`):
* 1. baseline — sideload only (app open, tap, navigate within app)
@@ -126,6 +127,9 @@ object BuildFlavor {
*/
val isSideload: Boolean get() = current == SIDELOAD
/** Voice presentation does not grant Device Control. Unknown distributions fail closed. */
val voiceSystemOverlay: Boolean get() = current == GOOGLE_PLAY || current == SIDELOAD
val bridgeTier1: Boolean get() = current == SIDELOAD // baseline device control
val bridgeTier2: Boolean get() = current == SIDELOAD // screen context
val bridgeTier3: Boolean get() = current == SIDELOAD // voice-first
@@ -1,7 +1,13 @@
package com.hermesandroid.relay.data
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.DashboardHttpException
import com.hermesandroid.relay.plugins.runtime.ScopedPluginApiClient
import java.io.IOException
import java.net.URLEncoder
import java.util.Locale
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.buildJsonArray
@@ -9,113 +15,178 @@ import kotlinx.serialization.json.buildJsonObject
import kotlinx.serialization.json.decodeFromJsonElement
import kotlinx.serialization.json.put
// Read + write client for the Hermes-Relay Git State endpoints.
// All requests are confined to the ``hermes-relay`` plugin namespace and the
// ``git/*`` sub-path via ScopedPluginApiClient, which rejects traversal and
// encodes query values.
private fun pathsArray(paths: List<String>) = buildJsonArray { paths.forEach { add(JsonPrimitive(it)) } }
/**
* Uses official Dashboard `/api/git/…` reads for the active session repository.
* Relay remains the discovery source and owns stronger write/preview extensions.
* Operational upstream failures are never hidden by a Relay retry; only a 404
* can fall back to a matching Relay-discovered repository.
*/
class GitStateApiClient(
dashboard: DashboardApiClient,
private val dashboard: DashboardApiClient,
) {
private val scoped = ScopedPluginApiClient("hermes-relay", dashboard)
private val json = Json { ignoreUnknownKeys = true }
private val reposById = linkedMapOf<String, GitRepo>()
private val relayRepoIdsByRoot = linkedMapOf<String, String>()
suspend fun repos(): Result<List<GitRepo>> = scoped
.get("git/repos")
.mapCatching { element ->
json.decodeFromJsonElement<ReposResponse>(element).repos
suspend fun repos(
sessionRepoPath: String? = null,
includeRelayDiscovery: Boolean = true,
): Result<List<GitRepo>> {
reposById.clear()
relayRepoIdsByRoot.clear()
val path = sessionRepoPath?.trim().orEmpty()
if (path.isBlank()) {
return if (includeRelayDiscovery) relayRepos().onSuccess(::rememberRepos)
else Result.success(emptyList())
}
suspend fun status(repo: String): Result<GitStatus> = scoped
.get("git/status", mapOf("repo" to repo))
.mapCatching { element -> json.decodeFromJsonElement<GitStatus>(element) }
suspend fun branches(repo: String): Result<List<GitBranch>> = scoped
.get("git/branches", mapOf("repo" to repo))
.mapCatching { element ->
json.decodeFromJsonElement<BranchesResponse>(element).branches
val upstream = upstreamStatus(path)
if (upstream.isFailure) {
val error = upstream.exceptionOrNull()!!
if (!error.isUnsupportedGitRoute()) return Result.failure(error)
return if (includeRelayDiscovery) relayRepos().onSuccess(::rememberRepos)
else Result.failure(error)
}
val status = upstream.getOrNull()
if (status == null) {
return if (includeRelayDiscovery) relayRepos().onSuccess(::rememberRepos)
else Result.success(emptyList())
}
suspend fun diff(repo: String, path: String, kind: String): Result<GitDiff> = scoped
.get("git/diff", mapOf("repo" to repo, "path" to path, "kind" to kind))
.mapCatching { element -> json.decodeFromJsonElement<GitDiff>(element) }
val standardRepo = GitRepo(
id = UPSTREAM_SESSION_REPO_ID,
name = path.replace('\\', '/').trimEnd('/').substringAfterLast('/').ifBlank { path },
root = path,
currentBranch = status.branch,
dirty = status.changed > 0,
route = GitRepositoryRoute.UPSTREAM,
)
suspend fun file(repo: String, path: String): Result<GitFile> = scoped
.get("git/file", mapOf("repo" to repo, "path" to path))
.mapCatching { element -> json.decodeFromJsonElement<GitFile>(element) }
// Plugin discovery is an enhancement. Once upstream answered, plugin
// absence or breakage cannot take the standard session repository down.
val relay = if (includeRelayDiscovery) relayRepos().getOrDefault(emptyList()) else emptyList()
val merged = buildList {
add(standardRepo)
addAll(relay.filterNot { sameRoot(it.root, standardRepo.root) })
}
rememberRepos(merged)
rememberRelayRepos(relay)
return Result.success(merged)
}
// ── Write operations ───────────────────────────────────────────────────
// Every write requires the plugin.api.write grant, which the app enforces
// (see GitStateViewModel: a POST is never sent without the grant). The
// server additionally enforces per-use confirmation strings for destructive
// ops (discard/push/dirty-checkout) — the caller passes the echoed token.
suspend fun status(repo: String): Result<GitStatus> {
val target = reposById[repo]
if (target?.route != GitRepositoryRoute.UPSTREAM) return relayStatus(repo)
return fallbackOnUnsupported(target, upstreamStatusWithFiles(target.root), ::relayStatus)
}
suspend fun branches(repo: String): Result<List<GitBranch>> {
val target = reposById[repo]
if (target?.route != GitRepositoryRoute.UPSTREAM) return relayBranches(repo)
return fallbackOnUnsupported(target, upstreamBranches(target.root), ::relayBranches)
}
suspend fun diff(repo: String, path: String, kind: String): Result<GitDiff> {
val target = reposById[repo]
if (target?.route != GitRepositoryRoute.UPSTREAM) return relayDiff(repo, path, kind)
val upstream = dashboard.getJsonElement(
upstreamPath(
"/api/git/review/diff",
mapOf(
"path" to target.root,
"file" to path,
"scope" to "uncommitted",
"staged" to (kind == "staged").toString(),
),
),
).mapCatching { element ->
GitDiff(
path = path,
kind = kind,
diff = json.decodeFromJsonElement<UpstreamDiffResponse>(element).diff,
)
}
return fallbackOnUnsupported(target, upstream) { relay -> relayDiff(relay, path, kind) }
}
/** Clean tracked-file preview is a Relay enhancement; file-diff is not equivalent. */
suspend fun file(repo: String, path: String): Result<GitFile> {
val relay = relayRepoId(repo)
?: return Result.failure(IOException("Tracked-file preview requires the Relay plugin"))
return relayFile(relay, path)
}
// Writes intentionally stay on Relay. The upstream Desktop mutation shape
// does not carry plugin.api.write or the server-enforced confirmation echoes
// used by this mobile surface, so it is not an equivalent safety contract.
suspend fun stage(repo: String, paths: List<String>): Result<GitMutationResult> =
scoped.post("git/stage", buildJsonObject {
put("repo", repo)
relayWrite(repo) { relay -> scoped.post("git/stage", buildJsonObject {
put("repo", relay)
put("paths", pathsArray(paths))
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun unstage(repo: String, paths: List<String>): Result<GitMutationResult> =
scoped.post("git/unstage", buildJsonObject {
put("repo", repo)
relayWrite(repo) { relay -> scoped.post("git/unstage", buildJsonObject {
put("repo", relay)
put("paths", pathsArray(paths))
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun discard(
repo: String,
paths: List<String>,
confirmation: String,
deleteUntracked: Boolean = false,
): Result<GitMutationResult> = scoped.post("git/discard", buildJsonObject {
put("repo", repo)
): Result<GitMutationResult> = relayWrite(repo) { relay -> scoped.post("git/discard", buildJsonObject {
put("repo", relay)
put("paths", pathsArray(paths))
put("confirmation", confirmation)
put("delete_untracked", deleteUntracked)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun commit(repo: String, message: String): Result<GitMutationResult> =
scoped.post("git/commit", buildJsonObject {
put("repo", repo)
relayWrite(repo) { relay -> scoped.post("git/commit", buildJsonObject {
put("repo", relay)
put("message", message)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun commitSelected(
repo: String,
message: String,
paths: List<String>,
): Result<GitMutationResult> = scoped.post("git/commit_selected", buildJsonObject {
put("repo", repo)
): Result<GitMutationResult> = relayWrite(repo) { relay -> scoped.post("git/commit_selected", buildJsonObject {
put("repo", relay)
put("message", message)
put("paths", pathsArray(paths))
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun fetch(repo: String, remote: String = "origin"): Result<GitMutationResult> =
scoped.post("git/fetch", buildJsonObject {
put("repo", repo)
relayWrite(repo) { relay -> scoped.post("git/fetch", buildJsonObject {
put("repo", relay)
put("remote", remote)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun pull(repo: String, remote: String = "origin", branch: String = ""): Result<GitMutationResult> =
scoped.post("git/pull", buildJsonObject {
put("repo", repo)
relayWrite(repo) { relay -> scoped.post("git/pull", buildJsonObject {
put("repo", relay)
put("remote", remote)
put("branch", branch)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun push(
repo: String,
confirmation: String,
remote: String = "origin",
branch: String = "",
): Result<GitMutationResult> = scoped.post("git/push", buildJsonObject {
put("repo", repo)
): Result<GitMutationResult> = relayWrite(repo) { relay -> scoped.post("git/push", buildJsonObject {
put("repo", relay)
put("remote", remote)
put("branch", branch)
put("confirmation", confirmation)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
suspend fun checkout(
repo: String,
@@ -123,41 +194,217 @@ class GitStateApiClient(
confirmation: String? = null,
newBranch: String = "",
track: Boolean = false,
): Result<GitMutationResult> = scoped.post("git/checkout", buildJsonObject {
put("repo", repo)
): Result<GitMutationResult> = relayWrite(repo) { relay -> scoped.post("git/checkout", buildJsonObject {
put("repo", relay)
put("ref", ref)
if (confirmation != null) put("confirmation", confirmation)
if (newBranch.isNotEmpty()) put("new_branch", newBranch)
put("track", track)
}).mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
}).decodeMutation() }
// ── Phase 3 extras ─────────────────────────────────────────────────────
suspend fun commitMessage(repo: String): Result<GitCommitMessage> = relayWrite(repo) { relay ->
scoped.post("git/commit_message", buildJsonObject { put("repo", relay) })
.mapCatching { json.decodeFromJsonElement<GitCommitMessage>(it) }
}
/** Generate a commit-message suggestion from the staged diff. */
suspend fun commitMessage(repo: String): Result<GitCommitMessage> =
scoped.post("git/commit_message", buildJsonObject {
put("repo", repo)
}).mapCatching { json.decodeFromJsonElement<GitCommitMessage>(it) }
suspend fun commitMessageSelected(repo: String, paths: List<String>): Result<GitCommitMessage> =
relayWrite(repo) { relay -> scoped.post("git/commit_message_selected", buildJsonObject {
put("repo", relay)
put("paths", pathsArray(paths))
}).mapCatching { json.decodeFromJsonElement<GitCommitMessage>(it) } }
/** Generate a commit-message suggestion from the given paths' staged diff. */
suspend fun commitMessageSelected(
repo: String,
paths: List<String>,
): Result<GitCommitMessage> = scoped.post("git/commit_message_selected", buildJsonObject {
put("repo", repo)
put("paths", pathsArray(paths))
}).mapCatching { json.decodeFromJsonElement<GitCommitMessage>(it) }
/** Checkout that auto-stashes a dirty tree first. */
suspend fun stashCheckout(
repo: String,
ref: String,
newBranch: String = "",
track: Boolean = false,
): Result<GitStashCheckoutResult> = scoped.post("git/stash_checkout", buildJsonObject {
put("repo", repo)
): Result<GitStashCheckoutResult> = relayWrite(repo) { relay -> scoped.post("git/stash_checkout", buildJsonObject {
put("repo", relay)
put("ref", ref)
if (newBranch.isNotEmpty()) put("new_branch", newBranch)
put("track", track)
}).mapCatching { json.decodeFromJsonElement<GitStashCheckoutResult>(it) }
}).mapCatching { json.decodeFromJsonElement<GitStashCheckoutResult>(it) } }
private suspend fun relayRepos(): Result<List<GitRepo>> = scoped.get("git/repos").mapCatching {
json.decodeFromJsonElement<ReposResponse>(it).repos
}
private suspend fun relayStatus(repo: String): Result<GitStatus> = scoped
.get("git/status", mapOf("repo" to repo))
.mapCatching { json.decodeFromJsonElement<GitStatus>(it) }
private suspend fun relayBranches(repo: String): Result<List<GitBranch>> = scoped
.get("git/branches", mapOf("repo" to repo))
.mapCatching { json.decodeFromJsonElement<BranchesResponse>(it).branches }
private suspend fun relayDiff(repo: String, path: String, kind: String): Result<GitDiff> = scoped
.get("git/diff", mapOf("repo" to repo, "path" to path, "kind" to kind))
.mapCatching { json.decodeFromJsonElement<GitDiff>(it) }
private suspend fun relayFile(repo: String, path: String): Result<GitFile> = scoped
.get("git/file", mapOf("repo" to repo, "path" to path))
.mapCatching { json.decodeFromJsonElement<GitFile>(it) }
private suspend fun upstreamStatus(path: String): Result<UpstreamStatus?> = dashboard
.getJsonElement(upstreamPath("/api/git/status", mapOf("path" to path)))
.mapCatching { json.decodeFromJsonElement<UpstreamStatus?>(it) }
private suspend fun upstreamStatusWithFiles(path: String): Result<GitStatus> {
val status = upstreamStatus(path).mapCatching {
it ?: throw IOException("The active session path is not a Git repository")
}.getOrElse { return Result.failure(it) }
val review = dashboard.getJsonElement(
upstreamPath("/api/git/review/list", mapOf("path" to path, "scope" to "uncommitted")),
).mapCatching { json.decodeFromJsonElement<UpstreamReviewList>(it) }
.getOrElse { return Result.failure(it) }
val statusByPath = status.files.associateBy { it.path }
val staged = mutableListOf<GitStatusEntry>()
val modified = mutableListOf<GitStatusEntry>()
val untracked = mutableListOf<GitStatusEntry>()
review.files.forEach { file ->
val entry = GitStatusEntry(file.path, file.added, file.removed)
val fileStatus = statusByPath[file.path]
if (fileStatus?.untracked == true) {
untracked += entry
} else {
if (file.staged || fileStatus?.staged == true) staged += entry
if (fileStatus?.unstaged == true || (!file.staged && fileStatus == null)) {
modified += entry
}
}
}
return Result.success(
GitStatus(
counts = GitStatusCounts(
staged = status.staged,
modified = status.unstaged,
untracked = status.untracked,
changes = status.changed,
additions = status.added,
deletions = status.removed,
),
staged = staged,
modified = modified,
untracked = untracked,
),
)
}
private suspend fun upstreamBranches(path: String): Result<List<GitBranch>> = dashboard
.getJsonElement(upstreamPath("/api/git/branches", mapOf("path" to path)))
.mapCatching { element ->
json.decodeFromJsonElement<UpstreamBranches>(element).branches.map {
GitBranch(name = it.name, isCurrent = it.checkedOut)
}
}
private suspend fun <T> fallbackOnUnsupported(
target: GitRepo,
upstream: Result<T>,
relayCall: suspend (String) -> Result<T>,
): Result<T> {
if (upstream.isSuccess) return upstream
val error = upstream.exceptionOrNull()!!
if (!error.isUnsupportedGitRoute()) return Result.failure(error)
val relay = relayRepoIdsByRoot[normalizedRoot(target.root)] ?: return Result.failure(error)
return relayCall(relay)
}
private suspend fun <T> relayWrite(repo: String, block: suspend (String) -> Result<T>): Result<T> {
val relay = relayRepoId(repo)
?: return Result.failure(IOException("This Git action requires the Relay plugin enhancement"))
return block(relay)
}
private fun relayRepoId(repo: String): String? {
val target = reposById[repo] ?: return repo.takeUnless { it == UPSTREAM_SESSION_REPO_ID }
return if (target.route == GitRepositoryRoute.RELAY) target.id
else relayRepoIdsByRoot[normalizedRoot(target.root)]
}
private fun rememberRepos(repos: List<GitRepo>) {
repos.forEach { reposById[it.id] = it }
rememberRelayRepos(repos.filter { it.route == GitRepositoryRoute.RELAY })
}
private fun rememberRelayRepos(repos: List<GitRepo>) {
repos.forEach { relayRepoIdsByRoot[normalizedRoot(it.root)] = it.id }
}
private fun upstreamPath(path: String, query: Map<String, String>): String = buildString {
append(path)
if (query.isNotEmpty()) {
append('?')
append(query.entries.joinToString("&") { (key, value) -> "${encode(key)}=${encode(value)}" })
}
}
private fun encode(value: String): String =
URLEncoder.encode(value, Charsets.UTF_8.name()).replace("+", "%20")
private fun normalizedRoot(path: String): String {
val normalized = path.trim().replace('\\', '/').trimEnd('/')
return if (WINDOWS_ROOT.containsMatchIn(normalized) || normalized.startsWith("//")) {
normalized.lowercase(Locale.ROOT)
} else {
normalized
}
}
private fun sameRoot(first: String, second: String): Boolean =
normalizedRoot(first) == normalizedRoot(second)
private fun Result<kotlinx.serialization.json.JsonObject>.decodeMutation(): Result<GitMutationResult> =
mapCatching { json.decodeFromJsonElement<GitMutationResult>(it) }
private fun Throwable.isUnsupportedGitRoute(): Boolean =
this is DashboardHttpException && statusCode == 404
private companion object {
const val UPSTREAM_SESSION_REPO_ID = "__upstream_session__"
val WINDOWS_ROOT = Regex("^[A-Za-z]:/")
}
}
@Serializable
private data class UpstreamStatus(
val branch: String? = null,
val staged: Int = 0,
val unstaged: Int = 0,
val untracked: Int = 0,
val changed: Int = 0,
val added: Int = 0,
val removed: Int = 0,
val files: List<UpstreamStatusFile> = emptyList(),
)
@Serializable
private data class UpstreamStatusFile(
val path: String,
val staged: Boolean = false,
val unstaged: Boolean = false,
val untracked: Boolean = false,
)
@Serializable
private data class UpstreamReviewList(val files: List<UpstreamReviewFile> = emptyList())
@Serializable
private data class UpstreamReviewFile(
val path: String,
val added: Int = 0,
val removed: Int = 0,
val staged: Boolean = false,
)
@Serializable
private data class UpstreamBranches(val branches: List<UpstreamBranch> = emptyList())
@Serializable
private data class UpstreamBranch(
val name: String,
@SerialName("checkedOut") val checkedOut: Boolean = false,
)
@Serializable
private data class UpstreamDiffResponse(val diff: String = "")
@@ -3,7 +3,7 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
/** A repository discovered by the plugin's /git/repos endpoint. */
/** A current-session upstream repository or a Relay-discovered repository. */
@Serializable
data class GitRepo(
val id: String,
@@ -11,9 +11,19 @@ data class GitRepo(
val root: String,
@SerialName("current_branch") val currentBranch: String? = null,
val dirty: Boolean = false,
val route: GitRepositoryRoute = GitRepositoryRoute.RELAY,
)
/** Working-tree status from /git/status. */
@Serializable
enum class GitRepositoryRoute {
@SerialName("relay")
RELAY,
@SerialName("upstream")
UPSTREAM,
}
/** Normalized working-tree status from upstream or Relay Git routes. */
@Serializable
data class GitStatus(
val counts: GitStatusCounts = GitStatusCounts(),
@@ -71,6 +71,8 @@ data class HermesCard(
* actions.
*/
val input: HermesCardInput? = null,
/** Local Gateway batch; never an ordinary chat-message answer protocol. */
val clarifyBatch: HermesCardClarifyBatch? = null,
) {
object BuiltInTypes {
const val SKILL_RESULT = "skill_result"
@@ -96,6 +98,25 @@ data class HermesCard(
}
}
@Serializable
data class HermesCardClarifyBatch(
val questions: List<HermesCardClarifyQuestion>,
val expiresAtMillis: Long? = null,
)
@Serializable
data class HermesCardClarifyQuestion(
val key: String,
val question: String,
val input: HermesCardInput,
val answer: String? = null,
val submitting: Boolean = false,
)
/** Local callback identity. The RPC always uses the original qid, never this UI key. */
fun clarifyQuestionCardKey(cardKey: String, qid: String): String =
Json.encodeToString(listOf(cardKey, qid))
/**
* Interactive input slot on a [HermesCard]. The flags compose rather than
* branch — a sudo ask can be `masked + holdToConfirm` (password field whose
@@ -111,6 +111,8 @@ data class Profile(
val hasAvatar: Boolean = false,
@SerialName("ui_meta")
val uiMeta: JsonObject = JsonObject(emptyMap()),
@SerialName("display_name")
val displayName: String = "",
) {
val hasIsolatedApi: Boolean
get() = !apiServerUrl.isNullOrBlank()
@@ -27,7 +27,7 @@ data class ProviderUsagePreferences(
val visibleProviders: Set<String> = DEFAULT_VISIBLE_PROVIDERS,
) {
companion object {
val DEFAULT_VISIBLE_PROVIDERS = setOf("openai-codex", "nous", "opencode-go")
val DEFAULT_VISIBLE_PROVIDERS = setOf("openai-codex", "nous", "opencode-go", "supergrok")
}
}
@@ -344,6 +344,46 @@ class VoicePreferencesRepository(private val dataStore: DataStore<Preferences>)
dataStore.edit { it[key] = route.storageValue }
}
/**
* Clear Relay-only selections after Relay has been explicitly removed from
* the active connection. A temporarily unreachable configured Relay must
* not call this: preserving the selection lets the richer route resume
* when connectivity returns.
*
* [expectedScope] fences profile/connection changes that can race the
* DataStore edit. Values are re-read inside the transaction instead of
* trusting an earlier settings snapshot, so a newer user choice wins.
* The legacy default-profile keys are global (their storage names predate
* connection scoping), so they are never rewritten here: runtime fallback
* handles an unpaired default profile without changing another
* connection's selection.
*/
suspend fun reconcileRelayRemoval(expectedScope: VoiceProfileScope): Boolean {
if (_scope.value != expectedScope || expectedScope.profileName == null) return false
var changed = false
dataStore.edit { prefs ->
if (_scope.value != expectedScope) return@edit
val engine = VoiceEngineMode.fromStorage(
resolveString(prefs, KEY_ENGINE_MODE, expectedScope, DEFAULT_ENGINE_MODE),
)
val route = VoiceAudioRoute.fromStorage(
resolveString(prefs, KEY_AUDIO_ROUTE, expectedScope, DEFAULT_AUDIO_ROUTE),
)
if (engine == VoiceEngineMode.RealtimeAgent) {
prefs[stringPreferencesKey(scopedName(KEY_ENGINE_MODE, expectedScope))] =
VoiceEngineMode.HermesVoiceOutput.storageValue
changed = true
}
if (route == VoiceAudioRoute.Relay) {
prefs[stringPreferencesKey(scopedName(KEY_AUDIO_ROUTE, expectedScope))] =
VoiceAudioRoute.Auto.storageValue
changed = true
}
}
return changed
}
/** "" clears the override (relay falls back to the server's saved voice). */
suspend fun setEnhancedVoice(voice: String) {
val key = stringPreferencesKey(scopedName(KEY_ENH_VOICE, _scope.value))
@@ -348,7 +348,7 @@ class BridgeCommandHandler(
* the multiplexer. The two paths are fully independent.
*
* Caught by Bailey's on-device test 2026-04-14 — see the v0.4.1
* "voice intent local dispatch loop" entry in ROADMAP.md.
* "voice intent local dispatch loop" entry in docs/project/ROADMAP.md.
*/
suspend fun handleLocalCommand(envelope: Envelope): LocalDispatchResult {
if (envelope.type != "bridge.command") {
@@ -131,7 +131,7 @@ class ProactiveMessageHandler(
ProactiveMessageNotifier.notify(
context = context,
title = msg.title,
text = msg.text,
text = mediaFreeProactivePreview(msg.text),
messageId = msg.messageId,
chatId = msg.chatId,
)
@@ -156,6 +156,30 @@ class ProactiveMessageHandler(
}
}
/** Notification text is a preview; the Thread owns attachment rendering. */
internal fun mediaFreeProactivePreview(text: String): String {
var fence: String? = null
val lines = mutableListOf<String>()
for (line in text.lines()) {
val trimmed = line.trim()
val delimiter = when {
trimmed.startsWith("```") -> "```"
trimmed.startsWith("~~~") -> "~~~"
else -> null
}
if (delimiter != null) {
fence = if (fence == delimiter) null else if (fence == null) delimiter else fence
}
val markerOnly = fence == null && (
trimmed.startsWith("MEDIA:hermes-relay://") ||
trimmed.startsWith("MEDIA:/") ||
Regex("^MEDIA:[A-Za-z]:\\\\").containsMatchIn(trimmed)
)
if (!markerOnly && trimmed.isNotEmpty()) lines += trimmed
}
return lines.joinToString(" ").ifBlank { "Attachment" }
}
/**
* A parsed agent-initiated message. `surfacing` is the optional route hint
* (null = app default); Phase 2 keys inbox/session delivery off it.
@@ -28,6 +28,7 @@ import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody
import java.io.IOException
import java.io.ByteArrayOutputStream
internal const val RELAY_SESSION_HEADER: String = "X-Hermes-Relay-Session"
@@ -74,20 +75,30 @@ class RelayHttpClient(
private val context: Context? = null,
/** Dashboard-authenticated client for same-origin plugin ingress calls. */
private val dashboardHttpClientProvider: ((String) -> OkHttpClient?)? = null,
/**
* Pinned-TLS client for Hermes Secure Link (`plugin_proxy`) relay URLs.
* Without this, HTTPS probes against the self-signed Secure Link cert fail
* with "Trust anchor for certification path not found" while the WSS path
* (which already uses buildPluginProxyClient) stays healthy — the UI then
* reports dashboard/relay surfaces offline despite an Active connection.
*/
private val pluginProxyHttpClientProvider: ((String) -> OkHttpClient?)? = null,
) {
private fun relayHttpBaseOrNull(url: String): String? =
RelayEndpointContract.parseOrNull(url)?.httpBaseUrl
private fun callClient(relayUrl: String): OkHttpClient =
if (isDashboardRelayIngressUrl(relayUrl)) {
dashboardHttpClientProvider?.invoke(relayUrl) ?: okHttpClient
} else {
okHttpClient
when {
isDashboardRelayIngressUrl(relayUrl) ->
dashboardHttpClientProvider?.invoke(relayUrl) ?: okHttpClient
else ->
pluginProxyHttpClientProvider?.invoke(relayUrl) ?: okHttpClient
}
companion object {
private const val TAG = "RelayHttpClient"
private const val DEFAULT_MEDIA_DOWNLOAD_LIMIT_BYTES = 100L * 1024L * 1024L
const val MAX_MODEL_CAPABILITY_ROWS = 64
private const val MAX_MODEL_CAPABILITY_PROVIDER_CHARS = 128
private const val MAX_MODEL_CAPABILITY_MODEL_CHARS = 512
@@ -257,7 +268,10 @@ class RelayHttpClient(
* underlying exception with a human-readable message suitable for
* surfacing in the attachment's `errorMessage` field.
*/
suspend fun fetchMedia(token: String): Result<FetchedMedia> = withContext(Dispatchers.IO) {
suspend fun fetchMedia(
token: String,
maxBytes: Long = DEFAULT_MEDIA_DOWNLOAD_LIMIT_BYTES,
): Result<FetchedMedia> = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) {
return@withContext Result.failure(
@@ -318,15 +332,15 @@ class RelayHttpClient(
if (body == null) {
return@withContext Result.failure(IOException("Empty response body"))
}
val bytes = body.bytes()
val bytes = body.readBytesBounded(maxBytes)
Result.success(FetchedMedia(contentType, bytes, fileName, sensitive))
}
} catch (e: IOException) {
Log.w(TAG, "fetchMedia failed: ${e.message}")
Result.failure(e)
Log.w(TAG, "fetchMedia failed")
Result.failure(if (e is RelayMediaLimitException) e else IOException("Relay media request failed"))
} catch (e: Exception) {
Log.w(TAG, "fetchMedia unexpected error: ${e.message}")
Result.failure(e)
Log.w(TAG, "fetchMedia unexpected error")
Result.failure(IOException("Relay media request failed"))
}
}
@@ -352,6 +366,7 @@ class RelayHttpClient(
suspend fun fetchMediaByPath(
path: String,
contentTypeHint: String? = null,
maxBytes: Long = DEFAULT_MEDIA_DOWNLOAD_LIMIT_BYTES,
): Result<FetchedMedia> = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) {
@@ -401,7 +416,7 @@ class RelayHttpClient(
val reason = when (response.code) {
401 -> "Unauthorized — re-pair with the relay"
403 -> "Path not allowed by relay sandbox"
404 -> "File not found on relay: $path"
404 -> "File not found on relay"
400 -> "Bad request — missing path"
in 500..599 -> "Relay error (HTTP ${response.code})"
else -> "HTTP ${response.code}: ${response.message.ifBlank { "request failed" }}"
@@ -427,15 +442,19 @@ class RelayHttpClient(
if (body == null) {
return@withContext Result.failure(IOException("Empty response body"))
}
val bytes = body.bytes()
val bytes = body.readBytesBounded(maxBytes)
Result.success(FetchedMedia(contentType, bytes, fileName, sensitive))
}
} catch (e: IOException) {
Log.w(TAG, "fetchMediaByPath failed for $path: ${e.message}")
Result.failure(IOException("Relay unreachable: ${e.message ?: "IO error"}"))
Log.w(TAG, "fetchMediaByPath failed")
if (e is RelayMediaLimitException) {
Result.failure(e)
} else {
Result.failure(IOException("Relay media request failed"))
}
} catch (e: Exception) {
Log.w(TAG, "fetchMediaByPath unexpected error for $path: ${e.message}")
Result.failure(e)
Log.w(TAG, "fetchMediaByPath unexpected error")
Result.failure(IOException("Relay media request failed"))
}
}
@@ -1350,7 +1369,16 @@ class RelayHttpClient(
IOException("Relay reports status=${status ?: "missing"} (expected 'ok')")
)
}
val version = (parsed["version"] as? kotlinx.serialization.json.JsonPrimitive)?.content
val surface = (parsed["surface"] as? kotlinx.serialization.json.JsonPrimitive)?.content
val versionRaw = (parsed["version"] as? kotlinx.serialization.json.JsonPrimitive)?.content
// Secure Link /relay/health historically returned status=ok without
// version (surface=hermes_secure_proxy). Treat that as healthy so
// route probes don't spam "Missing version field".
val version = when {
!versionRaw.isNullOrBlank() -> versionRaw
surface.equals("hermes_secure_proxy", ignoreCase = true) -> "secure-link"
else -> null
}
if (version.isNullOrBlank()) {
DiagnosticsLog.record(
category = DiagnosticCategory.Relay,
@@ -1456,6 +1484,33 @@ class RelayHttpClient(
return match?.groupValues?.get(1)?.trim()?.ifBlank { null }
}
private fun okhttp3.ResponseBody.readBytesBounded(maxBytes: Long): ByteArray {
if (maxBytes <= 0L) throw RelayMediaLimitException()
val declared = contentLength().takeIf { it >= 0L }
if (declared != null && declared > maxBytes) throw RelayMediaLimitException()
val output = ByteArrayOutputStream(
declared?.coerceAtMost(Int.MAX_VALUE.toLong())?.toInt() ?: DEFAULT_BUFFER_SIZE,
)
byteStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var total = 0L
while (true) {
val count = input.read(buffer)
if (count < 0) break
total += count
if (total > maxBytes) throw RelayMediaLimitException()
output.write(buffer, 0, count)
}
if (declared != null && total != declared) {
throw IOException("Media file changed while it was being downloaded")
}
}
return output.toByteArray()
}
private class RelayMediaLimitException :
IOException("File exceeds the configured download limit")
/**
* Parse the relay's `X-Media-Sensitive` response header into a bool.
*
@@ -1468,7 +1523,7 @@ class RelayHttpClient(
return value == "1" || value == "true"
}
/** Provider-neutral compatibility fetch for gateways without `account.usage`. */
/** Provider-neutral enhancement for pools and providers upstream does not expose. */
suspend fun fetchProviderUsage(
profile: String? = null,
sessionId: String? = null,
@@ -103,6 +103,8 @@ class RelayVoiceClient(
private val voiceOutputFirstAudioTimeoutMs: Long = VOICE_OUTPUT_FIRST_AUDIO_TIMEOUT_MS,
/** Dashboard-authenticated transport for same-origin plugin ingress. */
private val dashboardHttpClientProvider: ((String) -> OkHttpClient?)? = null,
/** Pinned-TLS client for Hermes Secure Link relay URLs (self-signed leaf). */
private val pluginProxyHttpClientProvider: ((String) -> OkHttpClient?)? = null,
/** Fresh Dashboard ticket request for every ingress voice socket dial. */
private val dashboardIngressWebSocketRequestProvider:
(suspend (String) -> Request?)? = null,
@@ -114,11 +116,7 @@ class RelayVoiceClient(
private val okHttpClient: OkHttpClient
get() {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
return if (isDashboardRelayIngressUrl(relayUrl)) {
dashboardHttpClientProvider?.invoke(relayUrl) ?: directOkHttpClient
} else {
directOkHttpClient
}
return resolveClient(relayUrl)
}
companion object {
@@ -163,13 +161,16 @@ class RelayVoiceClient(
}
}
private fun callClient(url: String): OkHttpClient =
if (isDashboardRelayIngressUrl(url)) {
dashboardHttpClientProvider?.invoke(url) ?: directOkHttpClient
} else {
directOkHttpClient
private fun resolveClient(url: String): OkHttpClient =
when {
isDashboardRelayIngressUrl(url) ->
dashboardHttpClientProvider?.invoke(url) ?: directOkHttpClient
else ->
pluginProxyHttpClientProvider?.invoke(url) ?: directOkHttpClient
}
private fun callClient(url: String): OkHttpClient = resolveClient(url)
private fun sessionClient(): OkHttpClient =
okHttpClient.newBuilder()
.callTimeout(SESSION_CALL_TIMEOUT_SECONDS, TimeUnit.SECONDS)
@@ -124,8 +124,15 @@ class EndpointResolver(
* expected path for plain JVM tests.
*/
private val context: Context? = null,
/** Route-aware client for pinned plugin proxy probes. */
private val clientForCandidate: ((EndpointCandidate) -> OkHttpClient?)? = null,
/**
* Route-aware client for pinned plugin proxy probes.
* Second arg is the concrete probe request URL when known — callers must
* pin only when *this* request targets the Secure Link authority. Using a
* pin client for every surface on a LAN candidate that merely *stores* a
* Secure Link relay URL breaks plain :9119/:8642 probes (authority guard
* throws IOException → "Unreachable - IOException").
*/
private val clientForCandidate: ((EndpointCandidate, probeRequestUrl: String?) -> OkHttpClient?)? = null,
) {
/**
@@ -149,7 +156,10 @@ class EndpointResolver(
)
private val probeCache = ConcurrentHashMap<String, CacheEntry>()
private val inFlightProbes = ConcurrentHashMap<String, Deferred<Boolean>>()
// Every access is owned by [probeStateLock]. This must not be a
// concurrently-mutated collection: clearCache() takes a stable snapshot
// while completion callbacks remove finished probes.
private val inFlightProbes = mutableMapOf<String, Deferred<Boolean>>()
private val probeScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
private val probeStateLock = Any()
private var probeGeneration = 0L
@@ -486,7 +496,13 @@ class EndpointResolver(
probe(candidate, surface, generation)
}.also { deferred ->
inFlightProbes[key] = deferred
deferred.invokeOnCompletion { inFlightProbes.remove(key, deferred) }
deferred.invokeOnCompletion {
synchronized(probeStateLock) {
// Identity-aware removal prevents an invalidated
// probe from removing its fresh replacement.
inFlightProbes.remove(key, deferred)
}
}
deferred.start()
}
}
@@ -547,7 +563,9 @@ class EndpointResolver(
)
}
}
val fastClient = (clientForCandidate?.invoke(candidate) ?: httpClient).newBuilder()
val fastClient = (
clientForCandidate?.invoke(candidate, target.requestUrl) ?: httpClient
).newBuilder()
.connectTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.readTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.writeTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
@@ -3,7 +3,6 @@ package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.ProxyEndpoint
import com.hermesandroid.relay.data.isValidPinnedProxy
import okhttp3.CertificatePinner
import okhttp3.Interceptor
import okhttp3.OkHttpClient
import java.net.URI
@@ -66,9 +65,10 @@ fun EndpointCandidate.pluginProxyRoutesOrNull(): PluginProxyRoutes? =
private fun formatHost(host: String): String = if (':' in host) "[$host]" else host
/**
* Build a client that trusts the system normally, plus exactly the
* pairing-advertised SPKI for this proxy. The authority guard keeps a pin
* scoped to host *and port*; OkHttp's CertificatePinner alone is host-only.
* Require the paired leaf SPKI for both system-trusted and self-signed chains.
* Validate it in the trust manager, before OkHttp's chain cleaning, so a
* self-signed paired leaf does not depend on a platform-supplied cleaned chain.
* The authority guard applies to HTTP calls and WebSocket upgrades alike.
*/
fun buildPluginProxyClient(
baseBuilder: OkHttpClient.Builder,
@@ -88,12 +88,12 @@ fun buildPluginProxyClient(
if (rawSocketFactory != null) baseBuilder.socketFactory(rawSocketFactory)
return baseBuilder
.sslSocketFactory(sslContext.socketFactory, pinnedTrust)
.certificatePinner(
CertificatePinner.Builder().add(expectedHost, routes.pinSha256).build(),
)
.addNetworkInterceptor(Interceptor { chain ->
.followRedirects(false)
.followSslRedirects(false)
.addInterceptor(Interceptor { chain ->
val requestUrl = chain.request().url
if (!requestUrl.host.equals(expectedHost, ignoreCase = true) ||
if (!requestUrl.isHttps ||
!requestUrl.host.equals(expectedHost, ignoreCase = true) ||
requestUrl.port != expectedPort
) {
throw java.io.IOException("Pinned proxy redirect left its paired authority")
@@ -122,7 +122,7 @@ private fun systemTrustManager(): X509TrustManager {
return factory.trustManagers.filterIsInstance<X509TrustManager>().single()
}
private class PinnedOrSystemTrustManager(
internal class PinnedOrSystemTrustManager(
private val system: X509TrustManager,
private val expectedPin: String,
) : X509TrustManager {
@@ -133,10 +133,8 @@ private class PinnedOrSystemTrustManager(
val certificates = chain?.takeIf { it.isNotEmpty() }
?: throw CertificateException("Proxy supplied no certificate chain")
val systemAccepted = runCatching { system.checkServerTrusted(chain, authType) }.isSuccess
if (systemAccepted) return
val leaf = certificates.first()
leaf.checkValidity()
if (!systemAccepted) leaf.checkValidity()
val actual = "sha256/" + java.util.Base64.getEncoder().encodeToString(
MessageDigest.getInstance("SHA-256").digest(leaf.publicKey.encoded),
)
@@ -479,12 +479,15 @@ class ChatHandler {
arrivedWhileAway: Boolean = false,
) {
val id = messageId?.let { "proactive-$it" } ?: "proactive-${java.util.UUID.randomUUID()}"
val mediaHits = mutableListOf<Pair<String, MediaMarkerHit>>()
val cleanedText = extractMediaMarkersFromContent(id, text, mediaHits)
val visibleText = if (mediaHits.isEmpty()) text else cleanedText
_messages.update { list ->
if (messageId != null && list.any { it.id == id }) return@update list
val msg = ChatMessage(
id = id,
role = MessageRole.ASSISTANT,
content = text,
content = visibleText,
timestamp = System.currentTimeMillis(),
agentName = agentName,
badges = if (arrivedWhileAway) listOf("While away") else emptyList(),
@@ -492,6 +495,8 @@ class ChatHandler {
)
(list + msg).let { if (it.size > MAX_MESSAGES) it.drop(it.size - MAX_MESSAGES) else it }
}
// The row must exist before the ViewModel attaches a loading card.
mediaHits.forEach { (_, hit) -> dispatchMediaHit(id, hit) }
}
/**
@@ -518,6 +523,16 @@ class ChatHandler {
}
}
/** Refresh only an existing local ask, preserving its dispatches and transcript position. */
fun updateAskCardMessage(messageId: String, card: HermesCard) {
_messages.update { list ->
list.map { message ->
if (message.clientOnly && message.matchesIdentity(messageId)) message.copy(cards = listOf(card))
else message
}
}
}
/**
* Edit-and-regenerate local truncation: drop [messageId] and everything
* after it. The gateway performs the authoritative truncation via
@@ -1451,6 +1466,12 @@ class ChatHandler {
val loaded = renderedItems.mapNotNull { item ->
val displayKind = item.displayKind?.trim()?.lowercase()
if (displayKind == "hidden") return@mapNotNull null
val activitySourceId = if (displayKind == "async_delegation_complete") {
item.displayMetadata.stringField("delegation_id")?.let { "delegation:$it" }
?: "unavailable:${item.id}"
} else null
val activityTaskCount = if (activitySourceId != null) item.displayMetadata.intField("task_count") else null
val activityFailedCount = if (activitySourceId != null) item.displayMetadata.intField("failed_count") else null
val role = when {
displayKind == "model_switch" ||
displayKind == "async_delegation_complete" ||
@@ -1540,19 +1561,28 @@ class ChatHandler {
val prior = priorById[messageId]
// Outbound attachments: prefer an id-match (covers any future
// user-message id reconciliation), else fall back to the
// content-keyed queue. Inbound attachments normally come back via
// marker re-dispatch. One narrow exception retains a completed
// image_generate result when the immediate post-turn history read
// still lacks its MEDIA marker; otherwise the rendered image
// disappears during the persistence-lag window.
// content-keyed queue. Exact inbound marker attachments are also
// carried by id: a history refresh must not replace a successfully
// loaded image/file with a fresh LOADING placeholder. A process
// restart has no prior attachment, so the marker still dispatches
// normally and rehydrates it. One additional narrow exception
// retains a completed image_generate result when the immediate
// post-turn history read still lacks its MEDIA marker.
val carriedAttachments = run {
val persistedImagePaths = persistedImages.paths.toHashSet()
val persistedMediaKeys = messageMediaHits.mapTo(HashSet()) { (_, hit) ->
when (hit) {
is MediaMarkerHit.RelayToken -> hit.token
is MediaMarkerHit.BarePath -> hit.path
}
}
val priorGeneratedImage = prior?.toolCalls.orEmpty().any { tool ->
isImageGenerationToolName(tool.name) &&
tool.isComplete && tool.success != false
}
val byId = prior?.attachments.orEmpty().filter { attachment ->
attachment.relayToken == null ||
attachment.relayToken in persistedMediaKeys ||
(role == MessageRole.USER && attachment.relayToken in persistedImagePaths) ||
(
role == MessageRole.ASSISTANT &&
@@ -1602,6 +1632,9 @@ class ChatHandler {
// this as the same visible row across the post-turn reload.
prior.copy(
id = messageId,
activitySourceId = activitySourceId,
activityTaskCount = activityTaskCount,
activityFailedCount = activityFailedCount,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
@@ -1634,6 +1667,9 @@ class ChatHandler {
// nothing local to carry).
ChatMessage(
id = messageId,
activitySourceId = activitySourceId,
activityTaskCount = activityTaskCount,
activityFailedCount = activityFailedCount,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
@@ -1704,22 +1740,7 @@ class ChatHandler {
// Now that the reloaded messages are in state, fire callbacks so the
// ViewModel can insert LOADING/FAILED attachments via mutateMessage.
for ((messageId, hit) in pendingMediaHits) {
when (hit) {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker accepted from reloaded Relay history")
onMediaAttachmentRequested(messageId, hit.token)
}
}
is MediaMarkerHit.BarePath -> {
val dedupeKey = "$messageId:bare:${hit.path}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path, reload): ${hit.path}")
onMediaBarePathRequested(messageId, hit.path)
}
}
}
dispatchMediaHit(messageId, hit)
}
for ((messageId, path) in pendingPersistedUserImages) {
onPersistedUserImageRequested(messageId, path)
@@ -1953,29 +1974,33 @@ class ChatHandler {
content: String,
out: MutableList<Pair<String, MediaMarkerHit>>,
): String {
var cleaned = content
val visibleLines = mutableListOf<String>()
var openFence: String? = null
for (rawLine in content.lines()) {
val trimmed = rawLine.trim()
if (trimmed.isEmpty()) continue
if (trimmed.isEmpty()) {
visibleLines += rawLine
continue
}
val delimiter = fenceDelimiter(rawLine)
if (delimiter != null) {
openFence = if (openFence == delimiter) null else if (openFence == null) delimiter else openFence
visibleLines += rawLine
continue
}
if (openFence != null) {
visibleLines += rawLine
continue
}
if (openFence != null) continue
val hits = parseMediaMarkerLine(trimmed)
if (hits.isNotEmpty()) {
hits.forEach { out.add(messageId to it) }
cleaned = cleaned
.replace("\n$rawLine\n", "\n")
.replace("\n$rawLine", "")
.replace("$rawLine\n", "")
.replace(rawLine, "")
} else {
visibleLines += rawLine
}
}
return cleaned.trim()
return visibleLines.joinToString("\n").trim()
}
/**
@@ -2582,27 +2607,28 @@ class ChatHandler {
*/
private fun tryDispatchMediaMarker(messageId: String, line: String): Boolean {
val hits = parseMediaMarkerLine(line)
for (hit in hits) {
when (hit) {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker accepted from Relay stream")
onMediaAttachmentRequested(messageId, hit.token)
}
}
is MediaMarkerHit.BarePath -> {
val dedupeKey = "$messageId:bare:${hit.path}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (bare-path): ${hit.path}")
onMediaBarePathRequested(messageId, hit.path)
}
}
}
}
hits.forEach { dispatchMediaHit(messageId, it) }
return hits.isNotEmpty()
}
private fun dispatchMediaHit(messageId: String, hit: MediaMarkerHit) {
val (key, reference) = when (hit) {
is MediaMarkerHit.RelayToken -> "$messageId:relay:${hit.token}" to hit.token
is MediaMarkerHit.BarePath -> "$messageId:bare:${hit.path}" to hit.path
}
if (!dispatchedMediaMarkers.add(key)) return
val alreadyHydrated = _messages.value
.firstOrNull { it.matchesIdentity(messageId) }
?.attachments
?.any { it.relayToken == reference } == true
if (alreadyHydrated) return
Log.d(TAG, "Media marker accepted")
when (hit) {
is MediaMarkerHit.RelayToken -> onMediaAttachmentRequested(messageId, hit.token)
is MediaMarkerHit.BarePath -> onMediaBarePathRequested(messageId, hit.path)
}
}
/**
* Remove a matched annotation line from the message's displayed content.
* This prevents the raw annotation text (e.g., `💻 terminal`) from showing
@@ -29,6 +29,7 @@ import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonNull
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.booleanOrNull
import kotlinx.serialization.json.buildJsonObject
@@ -49,6 +50,7 @@ import okhttp3.Request
import okhttp3.RequestBody
import okhttp3.RequestBody.Companion.toRequestBody
import okhttp3.Response
import java.io.ByteArrayOutputStream
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
@@ -293,6 +295,34 @@ internal fun copyBounded(
return written
}
internal fun copyMediaBounded(
input: InputStream,
output: OutputStream,
declaredLength: Long?,
limitBytes: Long,
): Long {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
if (declaredLength != null && declaredLength > limitBytes) {
throw IOException("File exceeds the configured download limit")
}
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("File exceeds the configured download limit")
}
output.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Media file changed while it was being downloaded")
}
return written
}
/** One entry from `GET /api/audio/elevenlabs/voices` — non-secret voice metadata. */
data class ElevenLabsVoice(
val voiceId: String,
@@ -310,6 +340,19 @@ data class ElevenLabsVoices(
val voices: List<ElevenLabsVoice>,
)
/**
* Metadata for a file streamed from upstream's authenticated managed-files surface.
*
* The Dashboard applies its own managed-root, sensitive-file, and maximum-size
* policy before the file leaves the Hermes host. Android applies the user's
* stricter inbound-media cap while reading the response as a second boundary.
*/
data class DashboardFetchedFile(
val sizeBytes: Long,
val contentType: String,
val fileName: String?,
)
/**
* Native client for the Hermes dashboard/admin server (:9119).
*
@@ -320,7 +363,7 @@ data class ElevenLabsVoices(
*/
class DashboardApiClient(
baseUrl: String,
private val okHttpClient: OkHttpClient = defaultClient(),
internal val okHttpClient: OkHttpClient = defaultClient(),
private val ownsHttpClient: Boolean = true,
private val json: Json = Json {
ignoreUnknownKeys = true
@@ -381,6 +424,58 @@ class DashboardApiClient(
executeJsonElement(request, normalized)
}
/**
* Download a server-local artifact through current upstream Hermes.
*
* This is the same authenticated `/api/files/download` route official
* Desktop uses for remote gateway files. The caller supplies its display
* cap so a malicious or stale Content-Length cannot cause an unbounded
* allocation. The supplied output is normally Android's on-disk media cache;
* local playback supplies seeking, so `/api/files/stream` is unnecessary
* on this path.
*/
suspend fun downloadManagedFile(
serverPath: String,
maxBytes: Long,
output: OutputStream,
): Result<DashboardFetchedFile> = withContext(Dispatchers.IO) {
if (serverPath.isBlank()) {
return@withContext Result.failure(IOException("Media path is empty"))
}
if (maxBytes <= 0L) {
return@withContext Result.failure(IOException("Media download limit is invalid"))
}
val httpUrl = resolveUrl("/api/files/download")
?.newBuilder()
?.addQueryParameter("path", serverPath)
?.build()
?: return@withContext Result.failure(invalidUrlException())
val request = Request.Builder().url(httpUrl).get().build()
executeCancellable(request, "Dashboard media download") { response ->
val body = response.body
val declaredLength = body.contentLength().takeIf { it >= 0L }
if (declaredLength != null && declaredLength > maxBytes) {
throw IOException("File exceeds the configured download limit")
}
val readTotal = body.byteStream().use { input ->
copyMediaBounded(input, output, declaredLength, maxBytes)
}
DashboardFetchedFile(
sizeBytes = readTotal,
contentType = response.header("Content-Type")
?.substringBefore(';')
?.trim()
?.takeIf(String::isNotEmpty)
?: "application/octet-stream",
fileName = response.header("Content-Disposition")
?.let(::contentDispositionFileName)
?: serverPath.substringAfterLast('/').substringAfterLast('\\')
.takeIf(String::isNotBlank),
)
}
}
suspend fun postJsonObject(
path: String,
payload: JsonObject = JsonObject(emptyMap()),
@@ -1262,7 +1357,7 @@ class DashboardApiClient(
suspend fun getSessionMessages(
sessionId: String,
profile: String? = null,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>> = withContext(Dispatchers.IO) {
val name = profile?.trim().orEmpty()
loadSessionMessages(mode) { page ->
@@ -1412,7 +1507,7 @@ class DashboardApiClient(
val patched = buildJsonObject {
obj.forEach { (k, v) -> put(k, v) }
if (obj["name"] == null && !nameOverride.isNullOrBlank()) put("name", nameOverride)
if (obj["model"] == null) put("model", "")
if (obj["model"] == null || obj["model"] == JsonNull) put("model", "")
}
json.decodeFromJsonElement(Profile.serializer(), patched)
}.getOrNull()
@@ -1431,10 +1526,14 @@ class DashboardApiClient(
password: String,
next: String = "/",
): Result<DashboardLoginResponse> = withContext(Dispatchers.IO) {
// Match the Dashboard's single-line HTML username/password controls:
// remove only forbidden line breaks and preserve every other code point.
val normalizedUsername = username.replace("\r", "").replace("\n", "")
val normalizedPassword = password.replace("\r", "").replace("\n", "")
val payload = buildJsonObject {
put("provider", provider)
put("username", username)
put("password", password)
put("username", normalizedUsername)
put("password", normalizedPassword)
put("next", next)
}
val httpUrl = resolveUrl("/auth/password-login")
@@ -1666,6 +1765,7 @@ class DashboardApiClient(
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
internal const val MAX_BACKUP_TRANSFER_BYTES = 100L * 1024L * 1024L
internal const val MAX_JSON_RESPONSE_BYTES = 8L * 1024L * 1024L
fun pathSegment(value: String): String =
URLEncoder.encode(value, "UTF-8").replace("+", "%20")
@@ -2057,9 +2157,10 @@ fun sameDashboardBase(candidate: String, trusted: String): Boolean {
fun trustedDashboardBearerAuthOrNull(
candidate: String,
trusted: String,
httpConsentOrigins: Set<String> = emptySet(),
tokenStoreProvider: () -> NativeDashboardTokenStore,
): DashboardBearerAuth? =
if (isNativeDashboardTransportEligible(candidate) &&
if (isNativeDashboardTransportEligible(candidate, httpConsentOrigins) &&
sameDashboardBase(candidate, trusted)
) {
DashboardBearerAuth(candidate, tokenStoreProvider())
@@ -2394,17 +2495,61 @@ data class StoredDashboardCookie(
}
private fun Response.readJsonObject(json: Json): JsonObject {
val raw = body.string()
val raw = body.readUtf8Bounded(DashboardApiClient.MAX_JSON_RESPONSE_BYTES)
if (raw.isBlank()) return JsonObject(emptyMap())
return json.parseToJsonElement(raw).jsonObject
}
private fun Response.readJsonElement(json: Json): JsonElement {
val raw = body.string()
val raw = body.readUtf8Bounded(DashboardApiClient.MAX_JSON_RESPONSE_BYTES)
if (raw.isBlank()) return JsonObject(emptyMap())
return json.parseToJsonElement(raw)
}
internal fun okhttp3.ResponseBody.readUtf8Bounded(maxBytes: Long): String {
require(maxBytes in 1..Int.MAX_VALUE.toLong()) { "Invalid response byte limit" }
val declaredLength = contentLength()
if (declaredLength > maxBytes) {
throw IOException("Dashboard response exceeds Android's bounded JSON limit")
}
val initialSize = when {
declaredLength in 1..maxBytes -> declaredLength.toInt()
else -> minOf(maxBytes, DEFAULT_BUFFER_SIZE.toLong()).toInt()
}
val output = ByteArrayOutputStream(initialSize)
byteStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var total = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
total += read
if (total > maxBytes) {
throw IOException("Dashboard response exceeds Android's bounded JSON limit")
}
output.write(buffer, 0, read)
}
}
return output.toString(Charsets.UTF_8.name())
}
private fun contentDispositionFileName(header: String): String? {
val encoded = Regex("""filename\*=UTF-8''([^;]+)""", RegexOption.IGNORE_CASE)
.find(header)
?.groupValues
?.getOrNull(1)
?.let { runCatching { java.net.URLDecoder.decode(it, "UTF-8") }.getOrNull() }
val plain = Regex("""filename=\"([^\"]+)\"|filename=([^;]+)""", RegexOption.IGNORE_CASE)
.find(header)
?.let { it.groupValues[1].ifBlank { it.groupValues[2] } }
?.trim()
?.trim('"')
return (encoded ?: plain)
?.substringAfterLast('/')
?.substringAfterLast('\\')
?.takeIf(String::isNotBlank)
}
internal class DashboardHttpException(
val statusCode: Int,
message: String,
@@ -2448,8 +2593,39 @@ internal fun Throwable.isDashboardSignInRequiredFailure(): Boolean {
return false
}
/** True only when the managed-file route itself is absent on this Hermes build. */
internal fun Throwable.isDashboardManagedFilesUnsupported(): Boolean {
var current: Throwable? = this
val seen = java.util.Collections.newSetFromMap(
java.util.IdentityHashMap<Throwable, Boolean>(),
)
while (current != null && seen.add(current)) {
if (current is DashboardHttpException) {
if (current.statusCode in setOf(405, 501)) return true
if (current.statusCode == 404) {
val detail = current.message.orEmpty()
// FastAPI's missing-route response is the generic "Not Found".
// A real managed-file miss says "File not found" and must not
// silently escape to Relay's broader path policy.
val isManagedFileMiss = detail.contains("File not found", ignoreCase = true) ||
detail.contains("Path not found", ignoreCase = true)
val isGenericRouteMiss = detail.trim().endsWith(": not found", ignoreCase = true) ||
detail.contains("\"detail\":\"Not Found\"", ignoreCase = true) ||
detail.contains("\"detail\": \"Not Found\"", ignoreCase = true)
if (!isManagedFileMiss && isGenericRouteMiss) return true
}
}
current = current.cause
}
return false
}
private fun apiFailure(response: Response, operation: String): IOException {
val bodyDetail = runCatching { response.body.string() }.getOrDefault("")
val bodyDetail = try {
response.body.readUtf8Bounded(4L * 1024L)
} catch (_: Exception) {
""
}
val detail = bodyDetail.take(240).ifBlank { response.message }
return DashboardHttpException(
statusCode = response.code,
@@ -0,0 +1,38 @@
package com.hermesandroid.relay.network.upstream
import java.io.IOException
data class DashboardSetupVerification(
val status: DashboardStatus,
val session: DashboardAuthSession,
val ticketAvailable: Boolean,
) {
val authenticated: Boolean get() = session.authenticated && ticketAvailable
}
/** Public status is discovery, not proof that a phone can use protected Dashboard routes. */
suspend fun DashboardApiClient.verifySetup(): DashboardSetupVerification {
val status = getStatus().getOrThrow()
var session = currentSession().getOrThrow()
val ticketAvailable = if (session.authenticated) {
val ticket = requestWsTicket()
val failure = ticket.exceptionOrNull()
if (failure?.isDashboardSignInRequiredFailure() == true) {
session = session.copy(authenticated = false)
false
} else {
ticket.getOrThrow()
true
}
} else false
if (!status.authRequired && !session.authenticated) {
throw DashboardLocalAuthenticationRequiredException()
}
return DashboardSetupVerification(status, session, ticketAvailable)
}
class DashboardLocalAuthenticationRequiredException : IOException(
"Hermes is reachable, but protected requests are not authorized. If the Dashboard is forwarded " +
"from loopback, check its bind address, authentication provider, and dashboard.public_url " +
"on the host. A 401 alone does not identify the cause.",
)
@@ -119,6 +119,10 @@ class GatewayChatClient(
private val promptSubmitTimeoutMs: Long = PROMPT_SUBMIT_REQUEST_TIMEOUT_MS,
/** Test seam — idle-progress watchdog base. Production keeps [TURN_TIMEOUT_MS]. */
private val turnIdleTimeoutMs: Long = TURN_TIMEOUT_MS,
/** Test seam — lazy session.create/resume readiness barrier. */
private val sessionReadyTimeoutMs: Long = SESSION_READY_TIMEOUT_MS,
/** Test seam — compaction idle lease. Production keeps [COMPACTING_TIMEOUT_MS]. */
private val compactingTimeoutMs: Long = COMPACTING_TIMEOUT_MS,
/** Random source for ordinary reconnect full-jitter. */
private val reconnectJitterUnit: () -> Double = { kotlin.random.Random.nextDouble() },
) : GatewayProfileEditorClient {
@@ -159,6 +163,19 @@ class GatewayChatClient(
private const val ASK_SUDO_TIMEOUT_MS = 150_000L
private const val ASK_UNBOUNDED_TIMEOUT_MS = 600_000L
/**
* Server-side context compaction summarizes the transcript through a
* (possibly slow) model with NO deltas or tool events flowing until it
* finishes — near the context ceiling that silence routinely exceeds
* [TURN_TIMEOUT_MS], so the idle watchdog would `session.interrupt` a
* healthy compression, roll back its work, and retrigger on the next
* prompt forever. A `status.update` event with kind `compacting`
* (emitted at compaction start, and periodically by newer gateways)
* arms this longer leash instead; any regular event rearms
* [TURN_TIMEOUT_MS].
*/
private const val COMPACTING_TIMEOUT_MS = 600_000L
private const val RPC_TIMEOUT_MS = 15_000L
const val PROFILE_AVATAR_MAX_BYTES = 2_000_000
@@ -176,6 +193,7 @@ class GatewayChatClient(
* would have been abandoned server-side anyway.
*/
private const val PROMPT_SUBMIT_REQUEST_TIMEOUT_MS = 1_800_000L
private const val SESSION_READY_TIMEOUT_MS = 300_000L
private const val CONNECT_TIMEOUT_MS = 20_000L
/**
@@ -259,11 +277,11 @@ class GatewayChatClient(
private val json = Json { ignoreUnknownKeys = true }
private val client: OkHttpClient = (okHttpClient ?: OkHttpClient())
private fun socketClient(base: OkHttpClient): OkHttpClient = base
.newBuilder()
// The 10s default connectTimeout is LAN-tuned; a remote dashboard
// reached over Tailscale (DERP cold start) can take longer to complete
// the WS upgrade. A failed connect drops chat to the SSE fallback and a
// the WS upgrade. A failed connect leaves Android on its Gateway owner and a
// 5s cooldown, so give the first remote handshake room.
.connectTimeout(20, TimeUnit.SECONDS)
.pingInterval(30, TimeUnit.SECONDS)
@@ -276,8 +294,19 @@ class GatewayChatClient(
* being torn down — the in-flight turn's session is server-side and the
* same shared gateway sits behind both routes.
*/
private data class RouteTransport(
val dashboard: DashboardApiClient,
val socket: OkHttpClient,
)
@Volatile
private var dashboardClient: DashboardApiClient = initialDashboardClient
private var routeTransport = RouteTransport(
initialDashboardClient,
socketClient(okHttpClient ?: initialDashboardClient.okHttpClient),
)
private val dashboardClient: DashboardApiClient
get() = routeTransport.dashboard
private val _connectionState = MutableStateFlow(GatewayConnectionState.Idle)
val connectionState: StateFlow<GatewayConnectionState> = _connectionState.asStateFlow()
@@ -384,12 +413,24 @@ class GatewayChatClient(
private val _serverProject = MutableStateFlow<GatewaySessionProject?>(null)
val serverProject: StateFlow<GatewaySessionProject?> = _serverProject.asStateFlow()
/**
* Exact model-callable tool names from upstream `session.info.tools` for
* the selected live session/profile. Null means the gateway has not
* supplied a catalog; an empty set means it authoritatively supplied none.
*/
private val _serverTools = MutableStateFlow<Set<String>?>(null)
val serverTools: StateFlow<Set<String>?> = _serverTools.asStateFlow()
/** Serializes connect / session-establish so concurrent sends share one socket. */
private val connectMutex = Mutex()
@Volatile
private var webSocket: WebSocket? = null
/** Profile explicitly routed by the Dashboard `/api/ws?profile=` handshake. */
@Volatile
private var connectedSocketProfile: String? = null
/** Completed when the server's `gateway.ready` event arrives for the current socket. */
@Volatile
private var readySignal: CompletableDeferred<Unit>? = null
@@ -398,6 +439,12 @@ class GatewayChatClient(
/** Invalidates an older async prewarm when a newer session selection wins. */
private val prewarmRequestGeneration = AtomicLong(0)
private val pendingRpcs = ConcurrentHashMap<Long, CompletableDeferred<JsonObject>>()
private val lazyLiveSessions = ConcurrentHashMap.newKeySet<String>()
private val readyLiveSessions = ConcurrentHashMap.newKeySet<String>()
private val sessionReadyWaiters = ConcurrentHashMap<String, CompletableDeferred<Unit>>()
private val sessionReadyFailures = ConcurrentHashMap<String, String>()
private val _preparingSessionId = MutableStateFlow<String?>(null)
val preparingSessionId: StateFlow<String?> = _preparingSessionId.asStateFlow()
/** Monotonic client-local fence for lazy child watch open/close races. */
private val childWatchGeneration = AtomicLong(0)
@@ -548,6 +595,28 @@ class GatewayChatClient(
val terminalRequired: Boolean,
)
/**
* One exact turn settled from authoritative session state may still receive
* the terminal frame that was already in flight. Consume only that terminal
* so it cannot be reported as a second unmatched completion. A subsequent
* message.start clears the drain because it establishes the next turn on
* the same live runtime.
*/
@Volatile
private var settledTurnDrain: SettledTurnDrain? = null
private data class SettledTurnDrain(
val storedSessionId: String,
val liveSessionId: String,
)
private data class ActiveTurnLivenessProbe(
val turn: GatewayTurn,
val storedSessionId: String,
val liveSessionId: String,
val progressGeneration: Long,
)
/**
* Creates UI callbacks when the server starts a turn that has no matching
* [sendTurn] call (for example a background-process completion). The
@@ -578,6 +647,13 @@ class GatewayChatClient(
@Volatile
private var processEventListener: ((GatewayProcessEvent) -> Unit)? = null
@Volatile
private var subagentEventListener: ((String, String?, GatewaySubagentEvent) -> Unit)? = null
fun setSubagentEventListener(listener: ((String, String?, GatewaySubagentEvent) -> Unit)?) {
subagentEventListener = listener
}
/** Process-wide durable-session invalidation/liveness edge. */
@Volatile
private var sessionDirectoryInvalidationListener: (() -> Unit)? = null
@@ -677,6 +753,7 @@ class GatewayChatClient(
): ActiveTurnHandle {
val turn = GatewayTurn(
callbacks = dispatchOn(callbacks),
androidOwned = true,
onTransportAccepted = onTransportAccepted,
)
// Warm = the connection-establish phases are skipped this turn (socket
@@ -724,6 +801,10 @@ class GatewayChatClient(
cleanupStagedAttachments(stagedImagePaths)
return@launch
}
// A newly accepted Android send is a distinct generation on
// this runtime. Its terminal must never be consumed by the
// prior turn's optional late-terminal drain.
settledTurnDrain = null
activeTurn = turn
turn.armWatchdog()
// Generic `file.attach` uploads are staged artifacts, not
@@ -758,7 +839,7 @@ class GatewayChatClient(
// Once this turn's own events are flowing (or it already
// finished), the prompt provably reached the server — a
// slow, lost, or socket-severed ack must NOT preflight-fail
// into the SSE fallback, which would resubmit the same
// into a second transport, which would resubmit the same
// prompt as a duplicate turn. Recovery belongs to the
// stream: the watchdog and mid-turn rejoin own it.
if (turn.started || turn.ended || turn.transportRecoveryStarted) {
@@ -782,7 +863,7 @@ class GatewayChatClient(
// through the normal failed-turn callback instead.
cleanupStagedAttachments(stagedImagePaths)
turn.tracer.done("submit-rejected")
turn.callbacks.onError(
turn.callbacks.onSubmitRejected(
submitError?.message ?: "Hermes rejected the new session",
)
return@launch
@@ -849,7 +930,11 @@ class GatewayChatClient(
liveSessionId = null
storedSessionId = null
liveSessionProfile = null
failSessionReadyWaiters("gateway session cleared")
lazyLiveSessions.clear()
readyLiveSessions.clear()
cancelledTurnDrain = null
_serverTools.value = null
}
/**
@@ -927,7 +1012,7 @@ class GatewayChatClient(
fun retarget(newDashboardClient: DashboardApiClient) {
if (dashboardClient === newDashboardClient) return
Log.i(TAG, "Gateway retargeting to a new route (turn active=${hasActiveTurn()})")
dashboardClient = newDashboardClient
routeTransport = RouteTransport(newDashboardClient, socketClient(newDashboardClient.okHttpClient))
if (hasActiveTurn()) {
retargetedThisTurn = activeTurn?.ended == false
webSocket?.cancel()
@@ -1363,6 +1448,7 @@ class GatewayChatClient(
callbacks = dispatchOn(callbacks),
dedupeAdjacentMessageStarts = true,
deferEvents = true,
androidOwned = true,
).also { turn ->
turn.markRecoveredStarted()
activeTurn = turn
@@ -1486,6 +1572,7 @@ class GatewayChatClient(
boundTurn = GatewayTurn(
callbacks = dispatchOn(callbacks),
dedupeAdjacentMessageStarts = true,
androidOwned = true,
).also { turn ->
turn.markRecoveredStarted()
activeTurn = turn
@@ -1497,7 +1584,10 @@ class GatewayChatClient(
.orEmpty()
.also { recoveryEvents = null }
}
buffered.forEach { event -> boundTurn?.onEvent(event.type, event.payload) }
buffered.forEach { event ->
dispatchSubagentEvent(event.type, event.payload, event.sessionId)
boundTurn.onEvent(event.type, event.payload)
}
queued?.let { queuedTurn ->
queuedTurnProvider?.invoke(queuedTurn)?.let { registration ->
boundTurn.installQueuedSuccessor(registration)
@@ -1507,6 +1597,7 @@ class GatewayChatClient(
claimedBackground?.pendingAsk?.let { ask ->
boundTurn.restoreInteraction(ask)
}
boundTurn.restorePendingClarify(response)
boundTurn.armWatchdog()
} else if (queued != null) {
synchronized(recoveryEventLock) { recoveryEvents = null }
@@ -1519,6 +1610,7 @@ class GatewayChatClient(
val queuedTurn = GatewayTurn(
callbacks = dispatchOn(registration.callbacks),
dedupeAdjacentMessageStarts = true,
androidOwned = true,
)
// recoverTurn is resumed on its caller's coroutine context;
// ChatViewModel calls it from Main, so this admission runs
@@ -1666,17 +1758,39 @@ class GatewayChatClient(
)
/** Answer a [GatewayAsk.Kind.CLARIFY] ask. */
suspend fun respondClarify(requestId: String, answer: String): Result<GatewayAskResponse> {
suspend fun respondClarify(
requestId: String,
answer: String,
questionId: String? = null,
): Result<GatewayAskResponse> {
val respondingTurn = activeTurn
if (questionId != null) {
val ask = respondingTurn?.pendingInteraction
// A lost acknowledgement is ambiguous until activation replays server progress.
// Never overwrite an accepted answer while reconnect is still reconciling it.
if (rejoinInProgress || ask?.kind != GatewayAsk.Kind.CLARIFY || ask.requestId != requestId ||
ask.questions.none { it.qid == questionId } || ask.ownershipToken.retired.get() ||
questionId in ask.ownershipToken.answers.get()
) return Result.failure(GatewayRpcException("Clarification is not ready for this question"))
}
val generation = respondingTurn?.interactionGeneration
val ownershipToken = respondingTurn?.pendingInteraction?.ownershipToken
return rpc(
"clarify.respond",
buildJsonObject {
put("request_id", requestId)
put("answer", answer)
questionId?.let { put("question_id", it) }
},
).map {
it.gatewayAskResponse().also {
respondingTurn?.acknowledgeInteraction(GatewayAskExpiry(GatewayAsk.Kind.CLARIFY, requestId))
if (generation != null) {
respondingTurn.acknowledgeClarify(requestId, questionId, answer, it == GatewayAskResponse.EXPIRED, generation)
}
val currentTurn = activeTurn
if (ownershipToken != null && currentTurn !== respondingTurn) {
currentTurn?.acknowledgeClarifyOwner(requestId, questionId, answer, it == GatewayAskResponse.EXPIRED, ownershipToken)
}
}
}
}
@@ -1765,18 +1879,17 @@ class GatewayChatClient(
}
/**
* Provider-neutral account limits owned by upstream Hermes. Current hosts
* may not expose this additive method yet; callers should treat JSON-RPC
* method-not-found as capability absence and use the optional Relay
* compatibility surface when paired.
* Official upstream Nous usage bars. Current hosts may not expose this
* additive method yet; callers should treat JSON-RPC method-not-found as
* capability absence and use the optional Relay enhancement when paired.
*/
suspend fun providerUsage(): Result<JsonObject> {
suspend fun usageBars(): Result<JsonObject> {
try {
connectMutex.withLock { ensureConnected() }
} catch (e: Exception) {
return Result.failure(e)
}
return rpc("account.usage", JsonObject(emptyMap()))
return rpc("usage.bars", JsonObject(emptyMap()))
}
/**
@@ -1834,6 +1947,7 @@ class GatewayChatClient(
model = row.stringField("model").orEmpty(),
provider = row.stringField("provider").orEmpty(),
description = row.stringField("description").orEmpty(),
displayName = row.stringField("display_name").orEmpty(),
skillCount = (row["skill_count"] as? JsonPrimitive)?.intOrNull ?: 0,
isDefault = (row["is_default"] as? JsonPrimitive)?.booleanOrNull ?: false,
hasAvatar = (row["has_avatar"] as? JsonPrimitive)?.booleanOrNull ?: false,
@@ -2414,6 +2528,7 @@ class GatewayChatClient(
} catch (error: Exception) {
return GatewayActiveSessionsResult.TransientFailure(error)
}
val livenessProbe = captureActiveTurnLivenessProbe()
val result = rpc(
"session.active_list",
buildJsonObject {
@@ -2433,12 +2548,58 @@ class GatewayChatClient(
val payload = result.getOrThrow()
val rows = payload["sessions"] as? JsonArray
?: throw GatewayRpcException("session.active_list returned no sessions array")
GatewayActiveSessionsResult.Success(rows.map(::parseGatewayActiveSession))
val sessions = rows.map(::parseGatewayActiveSession)
reconcileActiveTurnFromSnapshot(livenessProbe, sessions)
GatewayActiveSessionsResult.Success(sessions)
} catch (parseError: Exception) {
GatewayActiveSessionsResult.TransientFailure(parseError)
}
}
/**
* Capture only a locally submitted/recovered turn. Merely observing an
* exact session through the shared Gateway socket never grants Android
* authority to settle Desktop/TUI work.
*/
private fun captureActiveTurnLivenessProbe(): ActiveTurnLivenessProbe? {
val turn = activeTurn ?: return null
val generation = turn.captureLivenessGeneration() ?: return null
val storedId = storedSessionId ?: return null
val liveId = liveSessionId ?: return null
return ActiveTurnLivenessProbe(turn, storedId, liveId, generation)
}
/**
* `session.active_list` is process-wide, but a row naming both identifiers
* already owned by this client is authoritative for that exact runtime.
* Fence the delayed snapshot by turn identity and progress generation so an
* old idle result cannot settle a newer turn or race newer live events.
*/
private fun reconcileActiveTurnFromSnapshot(
probe: ActiveTurnLivenessProbe?,
sessions: List<GatewayActiveSession>,
) {
probe ?: return
if (activeTurn !== probe.turn ||
storedSessionId != probe.storedSessionId ||
liveSessionId != probe.liveSessionId
) return
val exact = sessions.singleOrNull { row ->
row.runtimeSessionId == probe.liveSessionId &&
row.storedSessionId == probe.storedSessionId
} ?: return
if (exact.status != GatewayActiveSessionStatus.Idle) return
if (probe.turn.settleFromAuthoritativeSessionState(
running = false,
source = "session.active_list",
expectedProgressGeneration = probe.progressGeneration,
)
) {
if (activeTurn === probe.turn) activeTurn = null
if (!AppForegroundTracker.isForeground.value) scheduleBackgroundClose()
}
}
/** Stop one process owned by the current live gateway session. */
suspend fun killProcess(processId: String): Result<Unit> {
if (processId.isBlank()) {
@@ -2831,11 +2992,13 @@ class GatewayChatClient(
activeTurn = null
backgroundTurns.clear()
cancelledTurnDrain = null
settledTurnDrain = null
unsolicitedTurnProvider = null
coldPrewarmSessionReadyListener = null
unmatchedTurnCompleteListener = null
backgroundInteractionListener = null
processEventListener = null
subagentEventListener = null
sessionDirectoryInvalidationListener = null
closeSocket("client shutdown")
backgroundCloseJob?.cancel()
@@ -2928,12 +3091,14 @@ class GatewayChatClient(
}
private suspend fun connectOnce() {
// Ticket, URL and TLS/auth policy must belong to one route snapshot.
val transport = routeTransport
val connectStart = System.nanoTime()
_processCapability.value = GatewayProcessCapability.Unknown
_activeSessionCapability.value = GatewayActiveSessionCapability.Unknown
_approvalModeCapability.value = GatewayApprovalModeCapability.Unknown
_connectionState.value = GatewayConnectionState.MintingTicket
val ticket = dashboardClient.requestWsTicket().getOrElse { e ->
val ticket = transport.dashboard.requestWsTicket().getOrElse { e ->
val statusCode = (e as? DashboardHttpException)?.statusCode
val authFailure = statusCode in setOf(401, 403)
val rateLimited = statusCode == 429
@@ -2956,9 +3121,17 @@ class GatewayChatClient(
)
}
val ticketMs = (System.nanoTime() - connectStart) / 1_000_000
val url = dashboardClient.gatewayWebSocketUrl(
if (transport !== routeTransport) {
throw GatewayConnectAttemptException(
"Gateway route changed while minting a ticket",
GatewayConnectFailureStage.Ticket,
retryable = true,
)
}
val socketProfile = currentSessionProfile()
val url = transport.dashboard.gatewayWebSocketUrl(
ticket = ticket.ticket,
profile = currentSessionProfile(),
profile = socketProfile,
)
?: throw GatewayConnectAttemptException(
"could not build /api/ws URL",
@@ -2969,7 +3142,7 @@ class GatewayChatClient(
_connectionState.value = GatewayConnectionState.Connecting
val ready = CompletableDeferred<Unit>()
readySignal = ready
val socket = client.newWebSocket(
val socket = transport.socket.newWebSocket(
Request.Builder().url(url).build(),
createListener(ready),
)
@@ -2992,6 +3165,7 @@ class GatewayChatClient(
if (readyFailure != null) {
socket.cancel()
webSocket = null
connectedSocketProfile = null
throw (readyFailure as? GatewayConnectAttemptException
?: GatewayConnectAttemptException(
"gateway connection failed: ${readyFailure.message}",
@@ -3004,6 +3178,7 @@ class GatewayChatClient(
val wsMs = (System.nanoTime() - connectStart) / 1_000_000 - ticketMs
Log.i(TAG, "Gateway connected (/api/ws ready) — ticket=${ticketMs}ms ws=${wsMs}ms")
hasEverReachedReady = true
connectedSocketProfile = socketProfile
coldStartFailureEpisodes = 0
_reconnectDisposition.value = GatewayReconnectDisposition.None
_connectionState.value = GatewayConnectionState.Ready
@@ -3134,6 +3309,18 @@ class GatewayChatClient(
)
}
}
if (info.containsKey("tools")) {
val groups = info["tools"] as? JsonObject
_serverTools.value = groups
?.values
?.asSequence()
?.mapNotNull { it as? JsonArray }
?.flatMap { it.asSequence() }
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull }
?.filter { it.isNotBlank() }
?.toSet()
?: emptySet()
}
// Context usage: require used > 0 — a COLD resume resets counters and
// reports 0 until the first turn rebuilds the prompt; painting 0 would
// mislead on a session that actually has history.
@@ -3149,6 +3336,7 @@ class GatewayChatClient(
/** Apply a session create/resume result without leaking metadata from the prior session. */
private fun applySessionResultInfo(result: JsonObject) {
_serverProject.value = null
_serverTools.value = null
(result["info"] as? JsonObject)?.let { applySessionInfo(it) }
}
@@ -3165,7 +3353,8 @@ class GatewayChatClient(
?.stringField("profile_name")
?.trim()
?.takeIf { it.isNotEmpty() }
if (actual != expected) {
val socketConfirmed = actual == null && connectedSocketProfile == expected
if (actual != expected && !socketConfirmed) {
val detail = actual?.let { "Hermes returned profile '$it'" }
?: "Hermes did not confirm profile ownership"
throw GatewayPreflightException(
@@ -3267,6 +3456,7 @@ class GatewayChatClient(
val requestedProfile = currentSessionProfile()
if (requestedStoredId != null && requestedStoredId != storedSessionId) {
cancelledTurnDrain = null
settledTurnDrain = null
}
if (
liveSessionId != null &&
@@ -3274,6 +3464,7 @@ class GatewayChatClient(
requestedStoredId != null &&
liveSessionProfile == requestedProfile
) {
awaitSessionReadyIfRequired(liveSessionId!!)
return
}
@@ -3303,6 +3494,7 @@ class GatewayChatClient(
liveSessionProfile = requestedProfile
updateCancelledDrainLiveSession(requestedStoredId, live)
applySessionResultInfo(result)
awaitSessionReadyIfRequired(live, result)
return
}
throw GatewayAuthoritativeResumeException(
@@ -3336,7 +3528,54 @@ class GatewayChatClient(
storedSessionId = stored
liveSessionProfile = requestedProfile
if (cancelledTurnDrain?.storedSessionId != stored) cancelledTurnDrain = null
if (settledTurnDrain?.storedSessionId != stored) settledTurnDrain = null
turn.callbacks.onSessionId(stored)
awaitSessionReadyIfRequired(live, created)
}
/**
* Wait for current upstream's authoritative deferred-build edge instead of
* racing a lazy session into compute-host turn isolation. Without this
* barrier, the parent runtime can claim the durable lease before the child
* rechecks it, causing the child to reject itself as a second live owner.
*/
private suspend fun awaitSessionReadyIfRequired(
liveId: String,
sessionResult: JsonObject? = null,
) {
sessionReadyFailures[liveId]?.let { throw GatewayPreflightException(it) }
val lazy = (sessionResult?.get("info") as? JsonObject)?.booleanField("lazy") == true
if (lazy) lazyLiveSessions += liveId
if (liveId !in lazyLiveSessions) return
if (readyLiveSessions.remove(liveId)) {
lazyLiveSessions.remove(liveId)
return
}
val waiter = sessionReadyWaiters.computeIfAbsent(liveId) { CompletableDeferred() }
if (readyLiveSessions.remove(liveId)) waiter.complete(Unit)
sessionReadyFailures[liveId]?.let { waiter.completeExceptionally(GatewayRpcException(it)) }
val preparingStoredId = storedSessionId
_preparingSessionId.value = preparingStoredId
try {
withTimeout(sessionReadyTimeoutMs) { waiter.await() }
lazyLiveSessions.remove(liveId)
} catch (error: Exception) {
throw GatewayPreflightException(
error.message ?: "Hermes session initialization timed out",
)
} finally {
if (_preparingSessionId.value == preparingStoredId) _preparingSessionId.value = null
sessionReadyWaiters.remove(liveId, waiter)
}
}
private fun failSessionReadyWaiters(message: String) {
_preparingSessionId.value = null
sessionReadyFailures.clear()
sessionReadyWaiters.values.forEach {
it.completeExceptionally(GatewayRpcException(message))
}
sessionReadyWaiters.clear()
}
private fun createListener(ready: CompletableDeferred<Unit>) = object : WebSocketListener() {
@@ -3515,6 +3754,40 @@ class GatewayChatClient(
return
}
// Lazy create/resume returns before its AIAgent exists. The deferred
// build publishes exact-session session.info when it is ready. Record
// that edge before live-session routing so a fast build cannot race
// the RPC response and strand the first submit.
if (type == "session.info" && !eventSessionId.isNullOrBlank() &&
payload?.booleanField("lazy") != true
) {
sessionReadyFailures.remove(eventSessionId)
readyLiveSessions += eventSessionId
sessionReadyWaiters.remove(eventSessionId)?.complete(Unit)
}
// Deferred agent construction can fail after lazy session.create/
// resume returns but before prompt.submit. Fail the readiness barrier
// immediately so the optimistic prompt remains retryable/Not sent
// instead of waiting for the five-minute readiness timeout.
if (type == "error" && !eventSessionId.isNullOrBlank() &&
(eventSessionId in lazyLiveSessions || sessionReadyWaiters.containsKey(eventSessionId) ||
payload?.stringField("message")?.startsWith("agent init failed:") == true)
) {
val message = payload?.stringField("message")
?: "Hermes session initialization failed"
// A fast deferred build can fail before the lazy RPC acknowledgement.
// Retain the exact runtime failure so the subsequent readiness wait
// cannot lose that edge and hang until its deadline.
if (sessionReadyFailures.size >= 64) sessionReadyFailures.keys.firstOrNull()?.let(sessionReadyFailures::remove)
sessionReadyFailures[eventSessionId] = message.take(2_000)
lazyLiveSessions.remove(eventSessionId)
readyLiveSessions.remove(eventSessionId)
sessionReadyWaiters.remove(eventSessionId)
?.completeExceptionally(GatewayRpcException(message))
return
}
// Upstream emits session.reclaimed process-wide, so it is identified
// by payload rather than params.session_id. Retire only an exact live
// runtime we own; preserve the durable id so the next send resumes it.
@@ -3624,7 +3897,10 @@ class GatewayChatClient(
val interactionRequest = GatewayEventMapper.interactionRequest(type, payload)
if (interactionRequest != null) {
val previous = backgroundTurn.pendingAsk
backgroundTurn.pendingAsk = interactionRequest
backgroundTurn.pendingAsk = if (previous?.kind == interactionRequest.kind &&
previous.requestId == interactionRequest.requestId && interactionRequest.questions.isNotEmpty()
) interactionRequest.withAnswers(previous.answers + interactionRequest.answers, previous)
else interactionRequest
if (previous?.kind != interactionRequest.kind ||
previous.requestId != interactionRequest.requestId
) {
@@ -3651,6 +3927,7 @@ class GatewayChatClient(
// be replayed or buffered. Only an authoritative expiry retires a
// detached ask; an explicit response is retired by its foreground VM.
if (explicitlyExpired) {
pendingAsk.ownershipToken.retired.set(true)
backgroundTurn.pendingAsk = null
callbackDispatcher {
backgroundInteractionListener?.invoke(
@@ -3713,6 +3990,8 @@ class GatewayChatClient(
}
dispatchProcessEvent(type, payload, eventSessionId)
if (consumeCancelledTurnEvent(type, eventSessionId)) return
if (consumeSettledTurnTerminal(type, eventSessionId)) return
dispatchSubagentEvent(type, payload, eventSessionId)
var turn = activeTurn
if (turn == null && type == "message.start") {
// Unsolicited turns are accepted only with an explicit exact live-
@@ -3766,6 +4045,9 @@ class GatewayChatClient(
}
return
}
if (type == "session.info" && eventSessionId != null && eventSessionId == liveSessionId) {
payload?.let(turn::restorePendingClarify)
}
turn.onEvent(type, payload)
if (turn.ended) {
if (activeTurn === turn) activeTurn = null
@@ -3774,10 +4056,25 @@ class GatewayChatClient(
}
/**
* Deliver session-scoped process events before the active-turn gate. The
* gateway socket is process-wide, so an exact non-blank live id match is
* required; missing/foreign ids must never leak another window's process.
* Detached child updates belong to the session even between parent turns.
* Recheck socket, session, profile and listener ownership on UI dispatch.
*/
private fun dispatchSubagentEvent(type: String, payload: JsonObject?, eventSessionId: String?) {
val liveId = liveSessionId ?: return
val storedId = storedSessionId ?: return
if (eventSessionId.isNullOrBlank() || eventSessionId != liveId) return
val event = GatewayEventMapper.parseSubagentEvent(type, payload) ?: return
val profile = liveSessionProfile
val socket = webSocket
val listener = subagentEventListener ?: return
callbackDispatcher {
if (webSocket === socket && liveSessionId == liveId && storedSessionId == storedId &&
liveSessionProfile == profile && subagentEventListener === listener
) listener(storedId, profile, event)
}
}
/** Process updates likewise require an exact live-session match before turn admission. */
private fun dispatchProcessEvent(type: String, payload: JsonObject?, eventSessionId: String?) {
val liveId = liveSessionId ?: return
if (eventSessionId.isNullOrBlank() || eventSessionId != liveId) return
@@ -3828,6 +4125,7 @@ class GatewayChatClient(
// id on the shared gateway stream) keeps matching after reconnect.
val preservedLiveId = liveSessionId
webSocket = null
connectedSocketProfile = null
readySignal = null
liveSessionId = null
attachMethodForSocket = null
@@ -3841,6 +4139,9 @@ class GatewayChatClient(
it.completeExceptionally(GatewayRpcException("gateway connection lost"))
}
pendingRpcs.clear()
failSessionReadyWaiters("gateway connection lost")
lazyLiveSessions.clear()
readyLiveSessions.clear()
failChildWatches("Child watch disconnected from the gateway")
val turn = activeTurn
if (turn == null) {
@@ -3953,6 +4254,7 @@ class GatewayChatClient(
activated.isSuccess -> {
activated.getOrNull()?.let { result ->
applySessionResultInfo(result)
turn.restorePendingClarify(result)
turn.settleFromAuthoritativeSessionState(
running = result.booleanField("running"),
source = "session.activate",
@@ -4016,8 +4318,12 @@ class GatewayChatClient(
private fun closeSocket(reason: String) {
webSocket?.close(1000, reason)
webSocket = null
connectedSocketProfile = null
readySignal = null
liveSessionId = null
failSessionReadyWaiters("gateway socket closed")
lazyLiveSessions.clear()
readyLiveSessions.clear()
attachMethodForSocket = null
commandsCatalogCache = null
_processCapability.value = GatewayProcessCapability.Unknown
@@ -4226,10 +4532,12 @@ class GatewayChatClient(
// ------------------------------------------------------------------
/** Per-event idle-watchdog duration — asks block server-side with no events, so they arm longer. */
private fun watchdogTimeoutFor(eventType: String): Long = when (eventType) {
"clarify.request", "secret.request" -> ASK_CLARIFY_SECRET_TIMEOUT_MS
"sudo.request" -> ASK_SUDO_TIMEOUT_MS
"approval.request" -> ASK_UNBOUNDED_TIMEOUT_MS
private fun watchdogTimeoutFor(eventType: String, payload: JsonObject? = null): Long = when {
eventType == "clarify.request" || eventType == "secret.request" -> ASK_CLARIFY_SECRET_TIMEOUT_MS
eventType == "sudo.request" -> ASK_SUDO_TIMEOUT_MS
eventType == "approval.request" -> ASK_UNBOUNDED_TIMEOUT_MS
eventType == "status.update" &&
payload?.stringField("kind") == "compacting" -> compactingTimeoutMs
else -> turnIdleTimeoutMs
}
@@ -4237,6 +4545,7 @@ class GatewayChatClient(
val callbacks: GatewayTurnCallbacks,
dedupeAdjacentMessageStarts: Boolean = false,
deferEvents: Boolean = false,
private val androidOwned: Boolean = false,
private val onTransportAccepted: () -> Unit = { },
) : ActiveTurnHandle {
private val mapper = GatewayEventMapper(callbacks, dedupeAdjacentMessageStarts)
@@ -4248,6 +4557,19 @@ class GatewayChatClient(
fun acknowledgeInteraction(expiry: GatewayAskExpiry) {
mapper.acknowledgeInteraction(expiry)
}
val interactionGeneration: Long get() = mapper.interactionGeneration
fun acknowledgeClarify(requestId: String, questionId: String?, answer: String, expired: Boolean, generation: Long) {
mapper.acknowledgeClarify(requestId, questionId, answer, expired, generation)
}
fun acknowledgeClarifyOwner(requestId: String, questionId: String?, answer: String, expired: Boolean, owner: GatewayAskOwnership) {
mapper.acknowledgeClarifyOwner(requestId, questionId, answer, expired, owner)
}
fun restorePendingClarify(snapshot: JsonObject) {
val payload = snapshot["pending_clarify"] as? JsonObject
?: (snapshot["info"] as? JsonObject)?.get("pending_clarify") as? JsonObject
?: return
GatewayEventMapper.interactionRequest("clarify.request", payload)?.let(mapper::restoreInteraction)
}
private val deferredEventLock = Any()
private val deferredEvents = mutableListOf<Pair<String, JsonObject?>>()
private var eventsDeferred = deferEvents
@@ -4263,6 +4585,7 @@ class GatewayChatClient(
private val rejoinAttempts = java.util.concurrent.atomic.AtomicInteger(0)
private val transportAccepted = AtomicBoolean(false)
private val progressGeneration = java.util.concurrent.atomic.AtomicLong(0L)
fun markTransportAccepted() {
if (transportAccepted.compareAndSet(false, true)) {
@@ -4339,6 +4662,7 @@ class GatewayChatClient(
if (settledWithoutTerminalFrame) return
if (type != "session.info") {
started = true
progressGeneration.incrementAndGet()
markTransportAccepted()
}
tracer.mark("ttfe")
@@ -4348,7 +4672,7 @@ class GatewayChatClient(
// Reset on every event — long tool runs keep the turn alive.
// Ask requests block with no further events, so they arm with
// their own (longer) duration via watchdogTimeoutFor.
armWatchdog(watchdogTimeoutFor(type))
armWatchdog(watchdogTimeoutFor(type, payload))
// Queue this immediately before the terminal callbacks. Both are
// marshalled through the same dispatcher, preserving callback order
// even when the WebSocket reader and reconnect coroutine differ.
@@ -4368,10 +4692,20 @@ class GatewayChatClient(
* exact turn has proved it went live. A pre-start `running=false`
* heartbeat can race `prompt.submit` and is not a completion boundary.
*/
fun settleFromAuthoritativeSessionState(running: Boolean?, source: String): Boolean {
fun captureLivenessGeneration(): Long? =
if (androidOwned && started && !ended) progressGeneration.get() else null
fun settleFromAuthoritativeSessionState(
running: Boolean?,
source: String,
expectedProgressGeneration: Long? = null,
): Boolean {
if (running != false || !started) return false
val settled = synchronized(deferredEventLock) {
if (ended) {
if (ended ||
(expectedProgressGeneration != null &&
progressGeneration.get() != expectedProgressGeneration)
) {
false
} else {
settledWithoutTerminalFrame = true
@@ -4382,6 +4716,7 @@ class GatewayChatClient(
if (!settled) return false
disarmWatchdog()
armSettledTurnDrain()
Log.i(TAG, "Gateway turn settled from $source after missing terminal frame")
callbacks.onReconcileRequired()
callbacks.onComplete()
@@ -4402,6 +4737,7 @@ class GatewayChatClient(
callbacks = dispatchOn(registration.callbacks),
dedupeAdjacentMessageStarts = true,
deferEvents = true,
androidOwned = true,
)
}
}
@@ -4529,6 +4865,26 @@ class GatewayChatClient(
)
}
private fun armSettledTurnDrain() {
val storedId = storedSessionId ?: return
val liveId = liveSessionId ?: return
settledTurnDrain = SettledTurnDrain(storedId, liveId)
}
/** Consume one late terminal from a turn already settled by session state. */
private fun consumeSettledTurnTerminal(type: String, eventSessionId: String?): Boolean {
val drain = settledTurnDrain ?: return false
if (eventSessionId != drain.liveSessionId) return false
if (type == "message.start") {
if (settledTurnDrain === drain) settledTurnDrain = null
return false
}
if (type != "message.complete" && type != "error") return false
if (settledTurnDrain === drain) settledTurnDrain = null
Log.d(TAG, "Ignored late terminal for gateway turn settled from session state")
return true
}
private fun updateCancelledDrainLiveSession(storedId: String, liveId: String) {
val drain = cancelledTurnDrain ?: return
if (drain.storedSessionId == storedId) {
@@ -4655,6 +5011,11 @@ class GatewayChatClient(
dispatchIfCurrent(stillCurrent) { callbacks.onStatusUpdate(kind, text) }
},
onStatusClear = { kind -> dispatchIfCurrent(stillCurrent) { callbacks.onStatusClear(kind) } },
onNoticeShow = { notice -> dispatchIfCurrent(stillCurrent) { callbacks.onNoticeShow(notice) } },
onNoticeClear = { key -> dispatchIfCurrent(stillCurrent) { callbacks.onNoticeClear(key) } },
onSubmitRejected = { message ->
dispatchIfCurrent(stillCurrent) { callbacks.onSubmitRejected(message) }
},
)
private fun dispatchIfCurrent(stillCurrent: () -> Boolean, callback: () -> Unit) {
@@ -4707,7 +5068,7 @@ data class GatewayAttachment(
val sizeBytes: Long? = null,
)
/** Connect/auth/submit failed before the turn started — safe to fall back to SSE. */
/** Connect/auth/submit failed before the turn started; the caller retains transport ownership. */
internal class GatewayPreflightException(message: String) : Exception(message)
/** Attachment bytes were not safely bound to a Gateway turn; never silently fall through to SSE. */
@@ -4972,6 +5333,7 @@ private fun parseBotRosterEntry(row: JsonObject): BotRosterEntry? {
model = row.stringField("model").orEmpty(),
provider = row.stringField("provider").orEmpty(),
description = row.stringField("description")?.take(512).orEmpty(),
displayName = row.stringField("display_name").orEmpty(),
skillCount = (row["skill_count"] as? JsonPrimitive)?.intOrNull ?: 0,
isDefault = (row["is_default"] as? JsonPrimitive)?.booleanOrNull ?: false,
hasAvatar = (row["has_avatar"] as? JsonPrimitive)?.booleanOrNull ?: false,
@@ -7,6 +7,7 @@ import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.doubleOrNull
import kotlinx.serialization.json.intOrNull
import kotlinx.serialization.json.longOrNull
import kotlinx.serialization.json.booleanOrNull
/**
@@ -31,19 +32,66 @@ class GatewayEventMapper(
var turnEnded: Boolean = false
private set
@get:Synchronized
internal val currentInteraction: GatewayAsk?
get() = pendingInteraction
@Volatile internal var interactionGeneration: Long = 0
private set
internal fun restoreInteraction(ask: GatewayAsk) {
val duplicate = pendingInteraction?.sameRequestAs(ask) == true
pendingInteraction = ask
if (!duplicate) callbacks.onInteractionRequest(ask)
@Synchronized internal fun restoreInteraction(ask: GatewayAsk) {
val previous = pendingInteraction
val duplicate = previous?.sameRequestAs(ask) == true
if (!duplicate) interactionGeneration++
val merged = if (duplicate && ask.questions.isNotEmpty()) {
ask.withAnswers(previous.answers + ask.answers, previous)
} else if (ask.questions.isNotEmpty()) ask.withAnswers(emptyMap()) else ask
if (merged.ownershipToken.retired.get() && !merged.clarifyComplete) {
if (duplicate) pendingInteraction = null
callbacks.onInteractionExpired(GatewayAskExpiry(merged.kind, merged.requestId))
if (pendingInteraction == null) drainDeferredTerminalEvent()
return
}
pendingInteraction = merged
if (!duplicate || previous != merged) callbacks.onInteractionRequest(merged)
if (merged.clarifyComplete) {
pendingInteraction = null
drainDeferredTerminalEvent()
}
}
@Synchronized internal fun acknowledgeClarify(
requestId: String,
questionId: String?,
answer: String,
expired: Boolean,
generation: Long = interactionGeneration,
) {
if (generation != interactionGeneration) return
val pending = pendingInteraction ?: return
if (pending.kind != GatewayAsk.Kind.CLARIFY || pending.requestId != requestId) return
if (!expired && questionId != null && pending.questions.none { it.qid == questionId }) return
if (!expired && questionId != null && pending.questions.any { it.qid == questionId }) {
val updated = pending.withAnswers(pending.answers + (questionId to answer))
if (updated.questions.any { it.qid !in updated.answers }) {
pendingInteraction = updated
return
}
}
acknowledgeInteraction(GatewayAskExpiry(GatewayAsk.Kind.CLARIFY, requestId))
}
@Synchronized internal fun acknowledgeClarifyOwner(
requestId: String, questionId: String?, answer: String, expired: Boolean, owner: GatewayAskOwnership,
) {
if (pendingInteraction?.ownershipToken !== owner) return
acknowledgeClarify(requestId, questionId, answer, expired)
}
/** Retire only the ask whose explicit respond RPC reached server truth. */
internal fun acknowledgeInteraction(expiry: GatewayAskExpiry) {
@Synchronized internal fun acknowledgeInteraction(expiry: GatewayAskExpiry) {
val pending = pendingInteraction ?: return
if (pending.matches(expiry)) {
pending.ownershipToken.retired.set(true)
pendingInteraction = null
drainDeferredTerminalEvent()
}
@@ -76,7 +124,7 @@ class GatewayEventMapper(
*/
private val generatingIdsByName = mutableMapOf<String, ArrayDeque<String>>()
fun onEvent(type: String, payload: JsonObject?) {
@Synchronized fun onEvent(type: String, payload: JsonObject?) {
if (turnEnded) return
interactionRequest(type, payload)?.let { ask ->
@@ -87,6 +135,7 @@ class GatewayEventMapper(
interactionExpiry(type, payload)?.let { expiry ->
val pending = pendingInteraction
if (pending != null && pending.matches(expiry)) {
pending.ownershipToken.retired.set(true)
pendingInteraction = null
}
callbacks.onInteractionExpired(expiry)
@@ -195,7 +244,8 @@ class GatewayEventMapper(
"tool.start" -> {
clearActivityStatuses()
val name = payload.string("name") ?: "unknown"
val identity = payload.effectiveToolIdentity()
val name = identity.name
// A pending generating placeholder for this name is adopted
// (consumed FIFO) whether or not the server sent a real id.
val adopted = generatingIdsByName[name]?.removeFirstOrNull()
@@ -207,7 +257,7 @@ class GatewayEventMapper(
}
else -> syntheticToolId(name)
}
val argsPreview = payload?.get("args")
val argsPreview = identity.argsPreview ?: payload?.get("args")
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
@@ -219,7 +269,7 @@ class GatewayEventMapper(
"tool.complete" -> {
clearActivityStatuses()
val name = payload.string("name") ?: "unknown"
val name = payload.effectiveToolIdentity().name
val toolId = payload.string("tool_id")
?: openSyntheticIdsByName[name]?.removeFirstOrNull()
?: return
@@ -278,41 +328,19 @@ class GatewayEventMapper(
"error" -> {
turnEnded = true
callbacks.onError(payload.string("message") ?: "Gateway error")
val message = payload.string("message") ?: "Gateway error"
if (isSessionOwnershipRejection(message)) {
callbacks.onSubmitRejected(message)
} else {
callbacks.onError(message)
}
}
"subagent.spawn_requested", "subagent.start", "subagent.thinking", "subagent.tool",
"subagent.progress", "subagent.complete",
-> {
clearActivityStatuses()
val phase = when (type) {
"subagent.spawn_requested" -> GatewaySubagentEvent.Phase.SPAWN_REQUESTED
"subagent.start" -> GatewaySubagentEvent.Phase.START
"subagent.thinking" -> GatewaySubagentEvent.Phase.THINKING
"subagent.tool" -> GatewaySubagentEvent.Phase.TOOL
"subagent.progress" -> GatewaySubagentEvent.Phase.PROGRESS
else -> GatewaySubagentEvent.Phase.COMPLETE
}
callbacks.onSubagentEvent(
GatewaySubagentEvent(
phase = phase,
taskIndex = payload.int("task_index") ?: 0,
taskCount = payload.int("task_count") ?: 1,
goal = payload.string("goal") ?: "",
status = payload.string("status"),
summary = payload.string("summary"),
toolName = payload.string("tool_name"),
// subagent.tool sets tool_preview AND mirrors it into
// text; thinking/progress carry text only.
preview = payload.string("tool_preview") ?: payload.string("text"),
durationSeconds = payload.double("duration_seconds"),
subagentId = payload.string("subagent_id"),
childSessionId = payload.string("child_session_id"),
parentId = payload.string("parent_id"),
depth = payload.int("depth"),
model = payload.string("model"),
),
)
parseSubagentEvent(type, payload)?.let(callbacks.onSubagentEvent)
}
"tool.output_risk" -> {
@@ -397,8 +425,26 @@ class GatewayEventMapper(
}
}
// Known-but-unrendered (notification.show, …) and unknown types
// alike: ignore.
"notification.show" -> {
val text = payload.string("text")?.trim().orEmpty()
if (text.isNotEmpty()) {
callbacks.onNoticeShow(
GatewayAgentNotice(
text = text,
level = payload.string("level"),
kind = payload.string("kind"),
ttlMs = payload.long("ttl_ms"),
key = payload.string("key"),
id = payload.string("id"),
),
)
}
}
"notification.clear" ->
payload.string("key")?.trim()?.takeIf(String::isNotEmpty)?.let(callbacks.onNoticeClear)
// Unknown event types remain forward-compatible no-ops.
else -> Unit
}
previousEventType = type
@@ -442,6 +488,42 @@ class GatewayEventMapper(
}
companion object {
/** Shared by turn transcripts and the session-owned activity stream. */
fun parseSubagentEvent(type: String, payload: JsonObject?): GatewaySubagentEvent? {
if (type !in setOf(
"subagent.spawn_requested", "subagent.start", "subagent.thinking",
"subagent.tool", "subagent.progress", "subagent.complete",
)) return null
val phase = when (type) {
"subagent.spawn_requested" -> GatewaySubagentEvent.Phase.SPAWN_REQUESTED
"subagent.start" -> GatewaySubagentEvent.Phase.START
"subagent.thinking" -> GatewaySubagentEvent.Phase.THINKING
"subagent.tool" -> GatewaySubagentEvent.Phase.TOOL
"subagent.progress" -> GatewaySubagentEvent.Phase.PROGRESS
else -> GatewaySubagentEvent.Phase.COMPLETE
}
return GatewaySubagentEvent(
phase = phase,
taskIndex = payload.int("task_index") ?: 0,
taskCount = payload.int("task_count") ?: 1,
goal = payload.string("goal") ?: "",
status = payload.string("status"),
summary = payload.string("summary"),
toolName = payload.string("tool_name"),
// subagent.tool sets tool_preview AND mirrors it into
// text; thinking/progress carry text only.
preview = payload.string("tool_preview") ?: payload.string("text"),
durationSeconds = payload.double("duration_seconds"),
subagentId = payload.string("subagent_id"),
childSessionId = payload.string("child_session_id"),
parentId = payload.string("parent_id"),
depth = payload.int("depth"),
model = payload.string("model"),
delegationId = payload.string("delegation_id"),
)
}
const val PROVIDER_WAIT_STATUS_KIND = "provider_wait"
const val COMPACTION_STATUS_KIND = "compacting"
const val ERROR_STATUS_KIND = "error"
@@ -450,32 +532,26 @@ class GatewayEventMapper(
private const val MAX_MOA_REFERENCE_CHARS = 16_000
private val OUTPUT_RISK_LEVELS = setOf("low", "medium", "high", "critical")
private val TERMINAL_EVENTS = setOf("message.complete", "error")
/**
* Isolated-turn paths can acknowledge `prompt.submit` and then emit
* the ownership refusal as a plain terminal `error` event. That event
* has no JSON-RPC code or structured reason, so match both stable
* clauses from upstream's canonical message.
*/
internal fun isSessionOwnershipRejection(message: String): Boolean {
val normalized = message.lowercase()
return "already has a live owner (" in normalized &&
"only one surface at a time may run a session" in normalized
}
internal fun isFailedMoaReference(text: String): Boolean {
val normalized = text.trimStart().lowercase()
return normalized.startsWith("[failed:") || normalized.startsWith("[skipped:")
}
fun interactionRequest(type: String, payload: JsonObject?): GatewayAsk? = when (type) {
"clarify.request" -> {
val choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.trim() }
?.filter { it.isNotEmpty() }
?.distinct()
?.take(MAX_CLARIFY_CHOICES)
?.takeIf { it.isNotEmpty() }
GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = choices,
multiSelect = payload.boolean("multi_select") == true && choices != null,
// Current upstream owns expiry through clarify.expire and
// does not advertise its configurable deadline. Never
// invent a local deadline; consume future additive
// metadata only when it is present and positive.
timeoutSeconds = payload.int("timeout_seconds")?.coerceAtLeast(0) ?: 0,
)
}
"clarify.request" -> clarifyRequest(payload)
"approval.request" -> GatewayAsk(
kind = GatewayAsk.Kind.APPROVAL,
@@ -508,6 +584,41 @@ class GatewayEventMapper(
else -> null
}
private fun clarifyRequest(payload: JsonObject?): GatewayAsk? {
val rawQuestions = payload?.get("questions")
if (rawQuestions != null && rawQuestions !is JsonArray) return null
val questions = rawQuestions?.map { value ->
val row = value as? JsonObject ?: return null
val qid = (row["qid"] as? JsonPrimitive)?.takeIf { it.isString }
?.contentOrNull?.takeIf(String::isNotBlank) ?: return null
val text = row.string("question")?.takeIf(String::isNotBlank) ?: return null
val choices = (row["choices"] as? JsonArray)?.mapNotNull {
(it as? JsonPrimitive)?.takeIf { option -> option.isString }
?.contentOrNull?.takeIf(String::isNotBlank)
}.orEmpty().take(MAX_CLARIFY_CHOICES)
GatewayClarifyQuestion(qid, text, choices, row.boolean("multi_select") == true && choices.isNotEmpty())
}.orEmpty()
if (questions.size > MAX_CLARIFY_QUESTIONS || questions.map { it.qid }.distinct().size != questions.size) return null
val choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.trim() }
?.filter(String::isNotEmpty)?.distinct()?.take(MAX_CLARIFY_CHOICES)
?.takeIf { it.isNotEmpty() }
return GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = choices,
multiSelect = payload.boolean("multi_select") == true && choices != null,
// Upstream owns its configurable deadline; only consume advertised metadata.
timeoutSeconds = payload.int("timeout_seconds")?.coerceAtLeast(0) ?: 0,
questions = questions,
answers = (payload?.get("answers") as? JsonObject)?.mapNotNull { (qid, value) ->
(value as? JsonPrimitive)?.takeIf { it.isString }?.contentOrNull
?.takeIf { questions.any { q -> q.qid == qid } }?.let { qid to it }
}?.toMap().orEmpty(),
)
}
fun interactionExpiry(type: String, payload: JsonObject?): GatewayAskExpiry? = when (type) {
"clarify.expire" -> GatewayAskExpiry(
kind = GatewayAsk.Kind.CLARIFY,
@@ -587,15 +698,47 @@ class GatewayEventMapper(
// Upstream clarify tool accepts at most four choices. Sudo/secret retain fixed
// `_block()` timeouts; clarify is configurable and expires authoritatively.
private const val MAX_CLARIFY_CHOICES = 4
private const val MAX_CLARIFY_QUESTIONS = 5
private const val SUDO_TIMEOUT_SECONDS = 120
private const val SECRET_TIMEOUT_SECONDS = 300
private data class GatewayToolIdentity(
val name: String,
val argsPreview: String?,
)
/**
* Older Tool Search gateways can expose the model-visible `tool_call` bridge
* instead of the effective tool identity that current upstream callbacks use.
* Unwrap only the bridge's explicit structured `{name, arguments}` envelope;
* never infer a tool from prompt text or result content.
*/
private fun JsonObject?.effectiveToolIdentity(): GatewayToolIdentity {
val outerName = string("name") ?: "unknown"
val outerArgs = this?.get("args") as? JsonObject
if (outerName != "tool_call" || outerArgs == null) {
return GatewayToolIdentity(outerName, null)
}
val effectiveName = outerArgs.string("name")
?.trim()
?.takeIf { it.isNotEmpty() }
?: return GatewayToolIdentity(outerName, null)
val effectiveArgs = outerArgs["arguments"]
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
return GatewayToolIdentity(effectiveName, effectiveArgs)
}
private fun JsonObject?.string(key: String): String? =
(this?.get(key) as? JsonPrimitive)?.contentOrNull
private fun JsonObject?.int(key: String): Int? =
(this?.get(key) as? JsonPrimitive)?.intOrNull
private fun JsonObject?.long(key: String): Long? =
(this?.get(key) as? JsonPrimitive)?.longOrNull
private fun JsonObject?.double(key: String): Double? =
(this?.get(key) as? JsonPrimitive)?.doubleOrNull
@@ -9,18 +9,23 @@ import android.content.Context
import android.content.Intent
import android.content.pm.ServiceInfo
import android.content.res.Configuration
import android.net.Uri
import android.os.Build
import android.os.IBinder
import android.os.Looper
import android.util.Log
import androidx.annotation.MainThread
import androidx.core.app.NotificationCompat
import androidx.datastore.preferences.core.edit
import com.hermesandroid.relay.MainActivity
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.setGatewayKeepAlive
import com.hermesandroid.relay.data.KEY_GATEWAY_KEEP_ALIVE
import com.hermesandroid.relay.data.relayDataStore
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.cancel
import kotlinx.coroutines.launch
import java.util.UUID
/**
* Foreground service that holds the app process up so work the user already
@@ -48,16 +53,16 @@ import kotlinx.coroutines.launch
*
* The service's only job is to hold the process in the foreground. The socket
* stays open because [GatewayChatClient.setKeepAliveInBackground] stops its
* idle-close timer while retention is required. On task removal (user swipes the app
* away) the ViewModel + socket die with the process, so the service stops
* itself rather than leave a notification that lies about being connected.
* idle-close timer while retention is required. Task removal releases local
* foreground protection; it does not terminate server-owned work or assume
* that removing a task kills the application process.
*
* # Android 15 watchdog
* # Foreground-start obligation (Android 8+)
*
* On target SDK 35 any intent to a service that declares a foregroundServiceType
* must call `startForeground` within 5s — so [onStartCommand] always does that
* first, before branching on the action. Shutdown goes through [stop]
* (`stopService`) to bypass [onStartCommand] entirely.
* An accepted startForegroundService must promote promptly, even if demand
* disappears before delivery. Never stopService a pending start: Android 12
* also treats teardown before promotion as a foreground-start failure.
* Main-thread demand is coalesced until onStartCommand acknowledges the start.
*/
class GatewayKeepAliveService : Service() {
companion object {
@@ -67,47 +72,76 @@ class GatewayKeepAliveService : Service() {
const val NOTIFICATION_ID = 4713
const val ACTION_STOP = "com.hermesandroid.relay.gateway.KEEPALIVE_STOP"
private const val ACTION_REFRESH = "com.hermesandroid.relay.gateway.KEEPALIVE_REFRESH"
private const val EXTRA_PERSISTENT = "persistent"
private const val EXTRA_ACTIVE_TURNS = "active_turns"
private const val EXTRA_WAITING_SESSIONS = "waiting_sessions"
@Volatile private var runningInstance: GatewayKeepAliveService? = null
private const val EXTRA_START_TOKEN = "start_token"
private var runningInstance: GatewayKeepAliveService? = null
private var pendingStart: String? = null
private var desiredPersistent = false
private var desiredTurns = ActiveTurnKeepAliveRegistry.Snapshot()
private var wasForeground = false
private var taskRemoved = false
@Volatile private var persistentToken: String? = null
// Preference writes must survive service teardown, but never process death.
private val preferenceScope = CoroutineScope(SupervisorJob() + Dispatchers.Main.immediate)
@MainThread
fun update(
context: Context,
persistent: Boolean,
activeTurns: ActiveTurnKeepAliveRegistry.Snapshot,
appForeground: Boolean = true,
) {
if (!persistent && !activeTurns.required) {
stop(context)
return
checkMainThread()
if (appForeground && !wasForeground) taskRemoved = false
wasForeground = appForeground
if (persistent != desiredPersistent) {
persistentToken = if (persistent) UUID.randomUUID().toString() else null
}
runningInstance?.let { service ->
service.applyState(persistent, activeTurns)
service.startForegroundNotification()
desiredPersistent = persistent
desiredTurns = activeTurns
// Keep the accepted start alive until Android delivers its command.
if (pendingStart != null) return
runningInstance?.let {
it.reconcile()
return
}
if (taskRemoved || !appForeground || (!persistent && !activeTurns.required)) return
val token = UUID.randomUUID().toString()
pendingStart = token
val intent = Intent(context.applicationContext, GatewayKeepAliveService::class.java)
.setAction(ACTION_REFRESH)
.putExtra(EXTRA_PERSISTENT, persistent)
.putExtra(EXTRA_ACTIVE_TURNS, activeTurns.activeTurnCount)
.putExtra(EXTRA_WAITING_SESSIONS, activeTurns.waitingSessionCount)
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.O) {
context.applicationContext.startForegroundService(intent)
} else {
context.applicationContext.startService(intent)
.putExtra(EXTRA_START_TOKEN, token)
try {
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.O) {
context.applicationContext.startForegroundService(intent)
} else {
context.applicationContext.startService(intent)
}
} catch (e: Exception) {
pendingStart = null
Log.w(TAG, "Foreground service launch rejected; retaining server-owned work", e)
}
}
@MainThread
fun stop(context: Context) {
// stopService() bypasses onStartCommand, so a "please shut down"
// never trips the Android 15 foreground-start watchdog.
context.applicationContext.stopService(
Intent(context.applicationContext, GatewayKeepAliveService::class.java),
)
update(context, false, ActiveTurnKeepAliveRegistry.Snapshot(), wasForeground)
}
private fun checkMainThread() {
check(Looper.myLooper() == Looper.getMainLooper())
}
internal fun resetForTest() {
runningInstance = null
pendingStart = null
desiredPersistent = false
desiredTurns = ActiveTurnKeepAliveRegistry.Snapshot()
persistentToken = null
wasForeground = false
taskRemoved = false
}
}
private val scope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
private var persistent = false
private var activeTurns = 0
private var waitingSessions = 0
@@ -116,45 +150,63 @@ class GatewayKeepAliveService : Service() {
override fun onCreate() {
super.onCreate()
runningInstance = this
// No datastore, socket, coroutine or other owner work ahead of promotion.
// A cold stale notification action has no accepted foreground start.
if (pendingStart != null) {
applyState(desiredPersistent, desiredTurns)
startForegroundNotification()
}
}
override fun onStartCommand(intent: Intent?, flags: Int, startId: Int): Int {
val token = intent?.getStringExtra(EXTRA_START_TOKEN)
if (intent?.action == ACTION_REFRESH) {
persistent = intent.getBooleanExtra(EXTRA_PERSISTENT, false)
activeTurns = intent.getIntExtra(EXTRA_ACTIVE_TURNS, 0).coerceAtLeast(0)
waitingSessions = intent.getIntExtra(EXTRA_WAITING_SESSIONS, 0)
.coerceIn(0, activeTurns)
}
startForegroundNotification()
if (intent?.action == ACTION_STOP) {
Log.i(TAG, "ACTION_STOP → user disabled continuous background connection")
scope.launch { runCatching { applicationContext.setGatewayKeepAlive(false) } }
persistent = false
if (activeTurns == 0) {
stopForeground(STOP_FOREGROUND_REMOVE)
stopSelf()
} else {
startForegroundNotification()
applyState(desiredPersistent, desiredTurns)
// Also promote reused service instances before acknowledging the start.
// A delivered start still owes promotion if process-local demand
// was lost or its token is stale. Never replay its old demand.
if (startForegroundNotification()) {
if (token == pendingStart) pendingStart = null
if (pendingStart == null) {
runningInstance = this
reconcile()
}
}
return START_NOT_STICKY
} else if (intent?.action == ACTION_STOP &&
intent.data?.lastPathSegment == persistentToken && persistentToken != null
) {
val actionToken = persistentToken
val context = applicationContext
preferenceScope.launch {
try {
context.relayDataStore.edit { preferences ->
// Recheck inside the serialized edit; an old action must
// not undo a subsequent disable/re-enable cycle.
if (persistentToken == actionToken) preferences[KEY_GATEWAY_KEEP_ALIVE] = false
}
} catch (e: Exception) {
Log.w(TAG, "Could not disable persistent connection", e)
}
}
// The preference collector reconciles current active-turn demand
// after persistence. Never stop from the notification's old snapshot.
}
if (runningInstance !== this && pendingStart == null) stopSelfResult(startId)
return START_NOT_STICKY
}
override fun onTaskRemoved(rootIntent: Intent?) {
super.onTaskRemoved(rootIntent)
// The socket lives in the ViewModel, which dies when the task is
// removed — keeping the notification would be a lie. Stop cleanly.
Log.i(TAG, "onTaskRemoved → app swiped away; stopping keep-alive")
ActiveTurnKeepAliveRegistry.releaseAll()
stopForeground(STOP_FOREGROUND_REMOVE)
stopSelf()
taskRemoved = true
// Leases belong to chat owners. Keep them intact so a surviving
// process can protect unfinished turns again when the user returns.
// A queued new start still owes Android promotion before retirement.
if (pendingStart == null) retire()
}
override fun onDestroy() {
if (runningInstance === this) runningInstance = null
scope.cancel()
super.onDestroy()
}
@@ -164,7 +216,23 @@ class GatewayKeepAliveService : Service() {
// this foreground service (and its Gateway socket) alive. Re-post the
// existing notification so its localized title/body follow the new
// application resources without restarting either owner.
startForegroundNotification()
if (runningInstance === this) reconcile()
}
private fun reconcile() {
if (taskRemoved || (!desiredPersistent && !desiredTurns.required)) {
retire()
} else {
applyState(desiredPersistent, desiredTurns)
startForegroundNotification()
}
}
private fun retire() {
if (runningInstance === this) runningInstance = null
// Let Android remove the foreground notification with service teardown.
// Do not demote an instance while another start may be queued for it.
stopSelf()
}
private fun applyState(
@@ -181,10 +249,10 @@ class GatewayKeepAliveService : Service() {
// satisfied. Suppress retained defensively — lint's ForegroundServiceType
// check is finicky about correlating the runtime type arg with the manifest.
@SuppressLint("ForegroundServiceType")
private fun startForegroundNotification() {
ensureChannel()
val notification = buildNotification()
private fun startForegroundNotification(): Boolean {
try {
ensureChannel()
val notification = buildNotification()
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.UPSIDE_DOWN_CAKE) {
startForeground(
NOTIFICATION_ID,
@@ -194,9 +262,12 @@ class GatewayKeepAliveService : Service() {
} else {
startForeground(NOTIFICATION_ID, notification)
}
} catch (t: Throwable) {
Log.w(TAG, "startForeground failed — stopping keep-alive", t)
stopSelf()
return true
} catch (e: Exception) {
Log.w(TAG, "Foreground notification failed; retaining server-owned work", e)
pendingStart = null
retire()
return false
}
}
@@ -208,6 +279,7 @@ class GatewayKeepAliveService : Service() {
val tapPending = PendingIntent.getActivity(this, 0, tapIntent, pendingFlags)
val stopIntent = Intent(this, GatewayKeepAliveService::class.java).setAction(ACTION_STOP)
.setData(Uri.parse("hermes-relay://keep-alive/$persistentToken"))
val stopPending = PendingIntent.getService(this, 1, stopIntent, pendingFlags)
val (title, body) = when {
@@ -2,11 +2,14 @@ package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.UsageInfo
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.booleanOrNull
import kotlinx.serialization.json.contentOrNull
import java.util.concurrent.atomic.AtomicBoolean
import java.util.concurrent.atomic.AtomicReference
/**
* Shared types for the Gateway chat transport — upstream hermes-agent's
@@ -91,26 +94,19 @@ enum class GatewayApprovalModeCapability {
* is unit-testable without an AndroidViewModel. ConnectionViewModel
* delegates here with its live state.
*
* Manual picks pass through untouched (ChatViewModel handles per-turn
* fallback when a "gateway" pick can't serve a send); "auto" prefers the
* gateway while the dashboard probe is unresolved or ready. A capability-
* preferred SSE fallback is selected only after a definitive unavailable,
* unsupported, or sign-in-required verdict.
* Manual picks pass through untouched. "auto" follows the saved connection's
* stable owner: Dashboard/Gateway for a standard connection, or the
* capability-preferred SSE surface for a true API-only compatibility record.
* Live reachability and sign-in state never change the owner of an open chat.
*/
fun resolveStreamingEndpointPreference(
preference: String,
gateway: GatewayAvailability,
capabilities: ServerCapabilities,
gatewayOwned: Boolean = true,
): String = when (preference) {
"sessions", "completions", "runs", "gateway" -> preference
else -> if (
gateway == GatewayAvailability.Ready ||
gateway == GatewayAvailability.Unknown
) {
"gateway"
} else {
capabilities.preferredChatEndpoint()
}
else -> if (gatewayOwned) "gateway" else capabilities.preferredChatEndpoint()
}
/**
@@ -237,10 +233,35 @@ data class GatewayAsk(
* authoritative `*.expire` event still retires the interaction.
*/
val timeoutSeconds: Int,
val questions: List<GatewayClarifyQuestion> = emptyList(),
val answers: Map<String, String> = emptyMap(),
) {
enum class Kind { CLARIFY, APPROVAL, SUDO, SECRET }
val clarifyComplete: Boolean get() = questions.isNotEmpty() && questions.all { it.qid in answers }
/** In-memory request incarnation shared when a live ask moves between turn mappers. */
internal var ownershipToken = GatewayAskOwnership(answers)
private set
internal fun withAnswers(answers: Map<String, String>, owner: GatewayAsk = this): GatewayAsk =
copy(answers = owner.ownershipToken.answers.updateAndGet { it + answers })
.also { it.ownershipToken = owner.ownershipToken }
}
/** A detached/reclaimed mapper shares confirmed progress with an RPC still owned by its predecessor. */
internal class GatewayAskOwnership(answers: Map<String, String>) {
val answers = AtomicReference(answers.toMap())
val retired = AtomicBoolean(false)
}
@Serializable
data class GatewayClarifyQuestion(
val qid: String,
val question: String,
val choices: List<String> = emptyList(),
val multiSelect: Boolean = false,
)
/**
* Server-side expiry of one blocking gateway interaction. Sudo/secret asks
* correlate by [requestId]; approvals remain session-scoped and therefore
@@ -263,6 +284,16 @@ data class GatewayToolOutputRisk(
val redacted: Boolean,
)
/** Official upstream `notification.show` AgentNotice payload. */
data class GatewayAgentNotice(
val text: String,
val level: String? = null,
val kind: String? = null,
val ttlMs: Long? = null,
val key: String? = null,
val id: String? = null,
)
/**
* One `subagent.*` lifecycle event, emitted on the PARENT session. Lifecycle
* per task: SPAWN_REQUESTED → START → (THINKING | TOOL | PROGRESS)* →
@@ -290,6 +321,8 @@ data class GatewaySubagentEvent(
val depth: Int? = null,
/** Effective child model, when the emitter exposes it. */
val model: String? = null,
/** Exact delegation group id shared with persisted async completion metadata. */
val delegationId: String? = null,
) {
enum class Phase { SPAWN_REQUESTED, START, THINKING, TOOL, PROGRESS, COMPLETE }
}
@@ -734,6 +767,16 @@ class GatewayTurnCallbacks(
val onStatusUpdate: (kind: String?, text: String) -> Unit = { _, _ -> },
/** Clear a transient status only when [kind] still owns the visible status slot. */
val onStatusClear: (kind: String) -> Unit = { _ -> },
/** Official upstream account/agent notice; distinct from Relay proactive messages. */
val onNoticeShow: (GatewayAgentNotice) -> Unit = { _ -> },
/** Exact-key dismissal for an upstream notice. */
val onNoticeClear: (key: String) -> Unit = { _ -> },
/**
* The Gateway authoritatively refused `prompt.submit` before a model turn
* began. The composed user row remains local and retryable; callers must
* not treat this as a dropped stream or reconcile it from history.
*/
val onSubmitRejected: (String) -> Unit = onError,
)
/**
@@ -726,10 +726,10 @@ class HermesApiClient(
suspend fun getMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): List<MessageItem> = withContext(Dispatchers.IO) {
loadSessionMessages(mode) { page ->
runCatching {
try {
val url = "$baseUrl/api/sessions/$sessionId/messages".toHttpUrlOrNull()
?.newBuilder()
?.addQueryParameter("limit", page.limit.toString())
@@ -740,14 +740,20 @@ class HermesApiClient(
val request = authRequest(url.toString()).get().build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) error("HTTP ${response.code}")
val body = response.body?.string() ?: error("empty response body")
val body = response.body.readUtf8Bounded(
DashboardApiClient.MAX_JSON_RESPONSE_BYTES,
)
val parsed = json.decodeFromString<MessageListResponse>(body)
SessionMessagePage(
messages = parsed.data ?: parsed.items ?: parsed.messages ?: emptyList(),
pagination = parsed.pagination,
payloadChars = body.length,
)
}
}.let { Result.success(it) }
} catch (error: CancellationException) {
throw error
} catch (error: Exception) {
Result.failure(error)
}
}.getOrElse { error ->
if (error is CancellationException) throw error
@@ -111,6 +111,8 @@ class NativeDashboardAuthClient(
private val tokenStore: NativeDashboardTokenStore,
private val client: OkHttpClient = OkHttpClient.Builder()
.dns(RetryingNativeAuthDns())
.followRedirects(false)
.followSslRedirects(false)
.retryOnConnectionFailure(false)
.connectTimeout(10, TimeUnit.SECONDS)
.readTimeout(15, TimeUnit.SECONDS)
@@ -390,15 +392,28 @@ internal class NativeDashboardCallbackException(
val retryable: Boolean = true,
) : IOException(message)
internal fun isNativeDashboardTransportEligible(baseUrl: String): Boolean {
internal fun isNativeDashboardTransportEligible(
baseUrl: String,
httpConsentOrigins: Set<String> = emptySet(),
): Boolean {
val url = baseUrl.trim().trimEnd('/').toHttpUrlOrNull() ?: return false
return url.scheme == "https" ||
(
url.scheme == "http" &&
(url.host == "127.0.0.1" || isPrivateNetworkLiteral(url.host))
(url.host == "127.0.0.1" || isPrivateNetworkLiteral(url.host) ||
com.hermesandroid.relay.data.dashboardHttpConsentMatches(baseUrl, httpConsentOrigins))
)
}
/** A cleartext exception never authorizes following a request onto another origin. */
internal fun dashboardClientWithHttpConsent(
client: OkHttpClient,
baseUrl: String,
httpConsentOrigins: Set<String>,
): OkHttpClient = if (com.hermesandroid.relay.data.dashboardHttpConsentMatches(baseUrl, httpConsentOrigins)) {
client.newBuilder().followRedirects(false).followSslRedirects(false).build()
} else client
/**
* Hermes already permits explicitly configured HTTP dashboard sessions on
* local routes. The brokered flow is no less protected than that cookie flow,
@@ -72,7 +72,7 @@ internal suspend fun loadSessionMessages(
Result.success(collected)
} catch (error: CancellationException) {
throw error
} catch (error: Throwable) {
} catch (error: Exception) {
Result.failure(error)
}
}
@@ -195,7 +195,7 @@ class StandardHermesVoiceClient(
.let { Result.success<VoiceSpeechStream?>(it) }
} catch (cancelled: CancellationException) {
throw cancelled
} catch (error: Throwable) {
} catch (error: Exception) {
Result.failure(error)
}
}
@@ -222,7 +222,9 @@ class StandardHermesVoiceClient(
if (!response.isSuccessful) {
return Result.failure(apiFailure(response, operation))
}
val body = response.body.string()
val body = response.body.readUtf8Bounded(
DashboardApiClient.MAX_JSON_RESPONSE_BYTES,
)
if (body.isBlank()) {
return Result.failure(IOException("$operation returned an empty response"))
}
@@ -245,7 +247,11 @@ class StandardHermesVoiceClient(
}
private fun apiFailure(response: Response, operation: String): IOException {
val body = runCatching { response.body.string() }.getOrDefault("")
val body = try {
response.body.readUtf8Bounded(4L * 1024L)
} catch (_: Exception) {
""
}
val detail = body.takeIf { it.isNotBlank() } ?: response.message
val message = when (response.code) {
400 -> "$operation rejected that input - ${detail.ifBlank { "bad request" }}"
@@ -3,10 +3,12 @@ package com.hermesandroid.relay.network.usage
import com.hermesandroid.relay.network.relay.RelayHttpClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.decodeFromJsonElement
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.booleanOrNull
import kotlinx.serialization.json.doubleOrNull
/** Relay-enhanced usage with an upstream fallback for hosts without Relay support. */
/** Upstream usage enriched by the optional Relay provider/pool surface. */
class ProviderUsageRepository(
private val gatewayClientProvider: () -> GatewayChatClient?,
private val dashboardClientProvider: () -> DashboardApiClient? = { null },
@@ -14,33 +16,142 @@ class ProviderUsageRepository(
private val profileProvider: () -> String? = { null },
private val sessionProvider: () -> String? = { null },
) {
private val json = Json {
ignoreUnknownKeys = true
coerceInputValues = true
explicitNulls = false
}
suspend fun fetch(): Result<ProviderUsageResponse?> {
val profile = profileProvider()
val session = sessionProvider()
val upstream: Result<ProviderUsageResponse?> = gatewayClientProvider()
?.usageBars()
?.mapCatching(::providerUsageFromUpstreamBars)
?: Result.success(null)
val dashboard = dashboardClientProvider()
var enhancement: Result<ProviderUsageResponse?>? = null
if (dashboard != null) {
val enhanced = dashboard.getProviderUsage(profile, session)
if (enhanced.isSuccess && enhanced.getOrNull() != null) return enhanced
enhancement = dashboard.getProviderUsage(profile, session)
}
val relay = relayHttpClient.fetchProviderUsage(
profile = profile,
sessionId = session,
if (enhancement?.getOrNull() == null) {
enhancement = relayHttpClient.fetchProviderUsage(
profile = profile,
sessionId = session,
)
}
val merged = mergeProviderUsage(
upstream = upstream.getOrNull(),
enhancement = enhancement?.getOrNull(),
)
if (relay.isSuccess && relay.getOrNull() != null) return relay
if (merged != null) return Result.success(merged)
val gateway = gatewayClientProvider()
if (gateway != null) {
val upstream = gateway.providerUsage()
.mapCatching { json.decodeFromJsonElement<ProviderUsageResponse>(it) }
if (upstream.isSuccess) return upstream
return when {
upstream.isFailure && enhancement?.isFailure == true ->
Result.failure(enhancement?.exceptionOrNull()!!)
enhancement?.isFailure == true -> Result.failure(enhancement?.exceptionOrNull()!!)
else -> Result.success(null)
}
return relay
}
}
internal fun providerUsageFromUpstreamBars(root: JsonObject): ProviderUsageResponse? {
if (root.boolean("available") != true) return null
val renewsAt = root.string("renews_at")
val windows = listOfNotNull(
root.usageWindow("plan", "Plan", renewsAt),
root.usageWindow("topup", "Top-up", null),
)
val details = listOfNotNull(
root.string("subscription_remaining_display")?.let { "Subscription remaining: $it" },
root.string("topup_remaining_display")?.let { "Top-up remaining: $it" },
root.string("total_spendable_display")?.let { "Total spendable: $it" },
)
return ProviderUsageResponse(
providers = listOf(
ProviderUsageProvider(
id = "nous",
displayName = "Nous",
status = ProviderUsageProvider.STATUS_AVAILABLE,
source = "upstream:usage.bars",
plan = root.string("plan_name"),
windows = windows,
details = details,
renewsAt = renewsAt,
),
),
)
}
internal fun mergeProviderUsage(
upstream: ProviderUsageResponse?,
enhancement: ProviderUsageResponse?,
): ProviderUsageResponse? {
if (upstream == null) return enhancement
if (enhancement == null) return upstream
val providers = linkedMapOf<String, ProviderUsageProvider>()
upstream.providers.forEach { providers[it.id] = it }
enhancement.providers.forEach { enhanced ->
val standard = providers[enhanced.id]
providers[enhanced.id] = when {
standard == null -> enhanced
standard.available -> standard.copy(
// Official usage.bars stays authoritative for every field it
// supplies. Relay enriches the row with pool/balance metadata
// and fills only gaps that upstream left absent.
fetchedAt = standard.fetchedAt ?: enhanced.fetchedAt,
plan = standard.plan ?: enhanced.plan,
windows = standard.windows.ifEmpty { enhanced.windows },
details = (standard.details + enhanced.details).distinct(),
balances = enhanced.balances,
renewsAt = standard.renewsAt ?: enhanced.renewsAt,
actionUrl = standard.actionUrl ?: enhanced.actionUrl,
credentials = enhanced.credentials,
activeCredentialId = enhanced.activeCredentialId,
activeCredentialState = enhanced.activeCredentialState,
activeObservedAt = enhanced.activeObservedAt,
message = standard.message ?: enhanced.message,
)
enhanced.available -> enhanced
else -> enhanced
}
}
return ProviderUsageResponse(
schemaVersion = maxOf(upstream.schemaVersion, enhancement.schemaVersion),
fetchedAt = enhancement.fetchedAt ?: upstream.fetchedAt,
capabilities = upstream.capabilities + enhancement.capabilities,
providers = providers.values.toList(),
)
}
private fun JsonObject.usageWindow(
id: String,
label: String,
resetAt: String?,
): ProviderUsageWindow? {
val bar = this["${id}_bar"] as? JsonObject ?: return null
val remaining = bar.string("remaining_display")
val total = bar.string("total_display")
val detail = when {
remaining != null && total != null -> "$remaining remaining of $total"
remaining != null -> "$remaining remaining"
total != null -> "$total total"
else -> null
}
return ProviderUsageWindow(
id = id,
label = label,
usedPercent = bar.double("pct_used"),
resetAt = resetAt,
detail = detail,
)
}
private fun JsonObject.string(key: String): String? =
(this[key] as? JsonPrimitive)?.content?.trim()?.takeIf(String::isNotEmpty)
private fun JsonObject.boolean(key: String): Boolean? =
(this[key] as? JsonPrimitive)?.booleanOrNull
private fun JsonObject.double(key: String): Double? =
(this[key] as? JsonPrimitive)?.doubleOrNull
@@ -21,6 +21,7 @@ import com.hermesandroid.relay.data.EnhancedVoiceOverrides
import com.hermesandroid.relay.data.VoiceAudioRoute
import com.hermesandroid.relay.data.VoiceEngineMode
import com.hermesandroid.relay.data.VoicePreferencesRepository
import com.hermesandroid.relay.data.VoiceProfileScope
import com.hermesandroid.relay.data.VoiceSettings
import com.hermesandroid.relay.network.relay.RelayVoiceAudioClientAdapter
import com.hermesandroid.relay.network.relay.RelayVoiceClient
@@ -105,6 +106,9 @@ internal class HermesRuntimeBinder(
},
apiBearerTokenProvider = connection::getApiKey,
dashboardHttpClientProvider = connection::dashboardHttpClientForRelayIngress,
pluginProxyHttpClientProvider = { url ->
connection.pluginProxyClientForUrl(url, includeRelaySessionHeader = false)
},
dashboardIngressWebSocketRequestProvider = connection::dashboardRelayRequestForIngress,
)
val standardVoiceClient = StandardHermesVoiceClient(
@@ -170,6 +174,9 @@ internal class HermesRuntimeBinder(
relayHttpClient = connection.relayHttpClient,
mediaSettingsRepo = connection.mediaSettingsRepo,
mediaCacheWriter = connection.mediaCacheWriter,
dashboardMediaClientProvider = {
connection.activeDashboardUrl()?.let(connection::dashboardClientForActive)
},
)
chat.setSelectedProfileProvider { connection.selectedProfile.value }
chat.setIsolatedProfileApiProvider { connection.selectedProfileUsesIsolatedApiRoute() }
@@ -262,6 +269,11 @@ internal class HermesRuntimeBinder(
jobs += runtime.coroutineScope.launch {
chat.isStreaming.collect(connection::setChatStreaming)
}
jobs += runtime.coroutineScope.launch {
chat.conversationBinding.collect { binding ->
connection.setActiveConversationTransport(binding.transport)
}
}
jobs += runtime.coroutineScope.launch {
combine(
connection.activeConnectionId,
@@ -282,13 +294,44 @@ internal class HermesRuntimeBinder(
}
}
}
jobs += runtime.coroutineScope.launch {
combine(
connection.connectionsHydrated,
connection.activeConnectionId,
connection.relayConfigured,
voiceSettingsHydrated,
voicePreferencesRepository.activeScope,
) { connectionsReady, connectionId, relayConfigured, settingsReady, scope ->
VoiceRelayReconciliationInputs(
connectionsReady = connectionsReady,
connectionId = connectionId,
relayConfigured = relayConfigured,
settingsReady = settingsReady,
scope = scope,
)
}.collectLatest { inputs ->
if (
inputs.connectionsReady &&
inputs.settingsReady &&
inputs.connectionId != null &&
!inputs.relayConfigured &&
// Default-profile storage is a legacy global layer shared
// across connections. Keep its fallback runtime-only.
inputs.scope.profileName != null &&
inputs.scope.connectionId == inputs.connectionId
) {
voicePreferencesRepository.reconcileRelayRemoval(inputs.scope)
}
}
}
jobs += runtime.coroutineScope.launch {
combine(
connection.streamingEndpoint,
connection.serverCapabilities,
connection.gatewayAvailability,
connection.effectiveDashboardUrl,
) { preference, _, gateway, dashboardUrl ->
connection.activeConnection,
) { preference, _, gateway, dashboardUrl, _ ->
Triple(preference, gateway, dashboardUrl)
}.collectLatest { (preference, _, dashboardUrl) ->
if (
@@ -312,14 +355,18 @@ internal class HermesRuntimeBinder(
connection.activeConnectionId,
connection.effectiveSessionProfileName,
connection.lastSessionId,
connection.activeEndpoint,
) { ready, connectionId, profileName, sessionId, activeEndpoint ->
// The session directory belongs to the standard Dashboard
// route. connection.activeEndpoint is the optional Relay
// socket's selected candidate and stays null on a valid
// Dashboard-only LAN connection.
connection.effectiveDashboardUrl,
) { ready, connectionId, profileName, sessionId, dashboardUrl ->
ProfileContextInputs(
ready,
connectionId,
profileName,
sessionId,
dashboardRouteResolved = activeEndpoint != null,
dashboardUrl = dashboardUrl,
)
}
combine(
@@ -335,7 +382,7 @@ internal class HermesRuntimeBinder(
)
}.collectLatest { inputs ->
profileContextReady.value = false
if (!shouldRefreshSessionDirectory(inputs.chatReady, inputs.dashboardRouteResolved)) {
if (!shouldRefreshSessionDirectory(inputs.chatReady, inputs.dashboardUrl)) {
return@collectLatest
}
if (!inputs.profileSelectionSettled) {
@@ -398,13 +445,22 @@ internal class HermesRuntimeBinder(
connection.chatReady,
connection.standardVoiceAvailability,
connection.relayVoiceReady,
connection.profileSelectionSettled,
) { settings, chatReady, standard, relayReady, profileSettled ->
connection.relayConfigured,
) { settings, chatReady, standard, relayReady, relayConfigured ->
VoiceReadinessInputs(
settings = settings,
chatReady = chatReady,
standardAvailability = standard,
relayReady = relayReady,
relayConfigured = relayConfigured,
)
}.combine(connection.profileSelectionSettled) { inputs, profileSettled ->
resolveVoiceActivationReadiness(
settings,
chatReady,
standard,
relayReady,
inputs.settings,
inputs.chatReady,
inputs.standardAvailability,
inputs.relayReady,
inputs.relayConfigured,
profileSettled,
)
}
@@ -552,12 +608,28 @@ internal class HermesRuntimeBinder(
val connectionId: String?,
val profileName: String?,
val sessionId: String?,
val dashboardRouteResolved: Boolean,
val dashboardUrl: String,
val profileSelectionSettled: Boolean = false,
val profileLocked: Boolean = false,
val hiddenSources: Set<String> = emptySet(),
)
private data class VoiceRelayReconciliationInputs(
val connectionsReady: Boolean,
val connectionId: String?,
val relayConfigured: Boolean,
val settingsReady: Boolean,
val scope: VoiceProfileScope,
)
private data class VoiceReadinessInputs(
val settings: VoiceSettings,
val chatReady: Boolean,
val standardAvailability: StandardVoiceAvailability,
val relayReady: Boolean,
val relayConfigured: Boolean,
)
private companion object {
const val PROFILE_SETTLE_BACKSTOP_MS = 2_500L
const val PROFILE_CONTEXT_COALESCE_MS = 160L
@@ -568,12 +640,13 @@ internal class HermesRuntimeBinder(
/**
* Session browsing is Dashboard HTTP state, not Gateway-socket state. API-only
* connections still use chat readiness; Dashboard connections can refresh once
* the resolver has selected a live route, after the profile-settle fence.
* their persisted/resolved Dashboard origin publishes, after the profile-settle
* fence. The optional Relay endpoint is deliberately not part of this decision.
*/
internal fun shouldRefreshSessionDirectory(
chatReady: Boolean,
dashboardRouteResolved: Boolean,
): Boolean = chatReady || dashboardRouteResolved
dashboardUrl: String,
): Boolean = chatReady || dashboardUrl.isNotBlank()
internal fun assistantCanTransmitScreenContext(engineMode: VoiceEngineMode): Boolean =
engineMode == VoiceEngineMode.HermesVoiceOutput
@@ -596,12 +669,14 @@ internal fun resolveVoiceActivationReadiness(
chatReady: Boolean,
standardAvailability: StandardVoiceAvailability,
relayReady: Boolean,
relayConfigured: Boolean,
profileSettled: Boolean,
): HermesVoiceActivationReadiness {
if (!profileSettled) {
return HermesVoiceActivationReadiness.Waiting("Loading the selected Hermes profile")
}
return when (VoiceEngineMode.fromStorage(settings.engineMode)) {
val effectiveSettings = voiceSettingsForRelayConfiguration(settings, relayConfigured)
return when (VoiceEngineMode.fromStorage(effectiveSettings.engineMode)) {
VoiceEngineMode.RealtimeAgent -> {
if (relayReady) {
HermesVoiceActivationReadiness.Ready(HermesVoiceActivationRoute.Realtime)
@@ -613,7 +688,7 @@ internal fun resolveVoiceActivationReadiness(
if (!chatReady) {
return HermesVoiceActivationReadiness.Waiting("Waiting for Hermes chat")
}
when (VoiceAudioRoute.fromStorage(settings.audioRoute)) {
when (VoiceAudioRoute.fromStorage(effectiveSettings.audioRoute)) {
VoiceAudioRoute.Relay -> if (relayReady) {
HermesVoiceActivationReadiness.Ready(
HermesVoiceActivationRoute.RelayAudio
@@ -637,6 +712,24 @@ internal fun resolveVoiceActivationReadiness(
}
}
/**
* Relay absence is a topology decision, unlike a transient route outage. Only
* the former may fall back from Relay-only persisted selections.
*/
internal fun voiceSettingsForRelayConfiguration(
settings: VoiceSettings,
relayConfigured: Boolean,
): VoiceSettings {
if (relayConfigured) return settings
return settings.copy(
engineMode = VoiceEngineMode.HermesVoiceOutput.storageValue,
audioRoute = when (VoiceAudioRoute.fromStorage(settings.audioRoute)) {
VoiceAudioRoute.Relay -> VoiceAudioRoute.Auto.storageValue
else -> settings.audioRoute
},
)
}
private fun standardVoiceReadiness(
availability: StandardVoiceAvailability,
): HermesVoiceActivationReadiness = when (availability) {
@@ -0,0 +1,40 @@
package com.hermesandroid.relay.ui
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
/** Width policy shared by Chat's content and persistent status surfaces. */
internal data class ChatResponsiveLayout(
val introMaxWidth: Dp?,
val avatarSize: Dp?,
val chromeMaxWidth: Dp?,
val transcriptMaxWidth: Dp?,
val focusVoiceMaxWidth: Dp?,
)
internal fun chatResponsiveLayout(screenWidthDp: Int): ChatResponsiveLayout = when {
screenWidthDp >= 840 -> ChatResponsiveLayout(
introMaxWidth = 720.dp,
avatarSize = 360.dp,
chromeMaxWidth = 960.dp,
transcriptMaxWidth = 960.dp,
focusVoiceMaxWidth = 1120.dp,
)
screenWidthDp >= 600 -> ChatResponsiveLayout(
introMaxWidth = 600.dp,
avatarSize = 300.dp,
chromeMaxWidth = 760.dp,
transcriptMaxWidth = 760.dp,
focusVoiceMaxWidth = 760.dp,
)
else -> ChatResponsiveLayout(
introMaxWidth = null,
avatarSize = null,
chromeMaxWidth = null,
transcriptMaxWidth = null,
focusVoiceMaxWidth = null,
)
}
internal fun useSplitVoiceLayout(screenWidthDp: Int, screenHeightDp: Int): Boolean =
screenWidthDp >= 840 && screenWidthDp > screenHeightDp
@@ -36,7 +36,7 @@ import androidx.compose.material.icons.filled.Settings
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Scaffold
import androidx.compose.material3.SnackbarDuration
import androidx.compose.material3.SnackbarHost
import com.hermesandroid.relay.ui.components.ThemedMessageHost
import androidx.compose.material3.SnackbarHostState
import androidx.compose.material3.SnackbarResult
import androidx.compose.material3.Surface
@@ -117,6 +117,7 @@ import com.hermesandroid.relay.ui.components.pet.PetSafeAreaRegistry
import com.hermesandroid.relay.ui.components.pet.petPerchSurface
import com.hermesandroid.relay.ui.components.pet.platformModalOwnsPetLayer
import com.hermesandroid.relay.ui.components.ConnectionSwitcherSheet
import com.hermesandroid.relay.ui.components.ChatMediaViewerHost
import com.hermesandroid.relay.ui.components.ChatTransportStatusBadge
import com.hermesandroid.relay.ui.components.ChatTransportTier
import com.hermesandroid.relay.ui.components.ConnectionSecurityGlyph
@@ -136,6 +137,8 @@ import com.hermesandroid.relay.data.BridgeSafetyPreferencesRepository
import com.hermesandroid.relay.data.BuildFlavor
import com.hermesandroid.relay.data.CandidateBuild
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.SessionTransport
import com.hermesandroid.relay.data.chatTransportForPreference
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.FeatureFlags
import com.hermesandroid.relay.data.SupervisedModePolicy
@@ -227,11 +230,7 @@ val LocalSnackbarHost = staticCompositionLocalOf<SnackbarHostState> {
// Short-lived snackbar by default; retryable errors get Long so users have
// time to tap the action before it auto-dismisses.
suspend fun SnackbarHostState.showHumanError(err: HumanError): SnackbarResult {
return showSnackbar(
message = err.body,
actionLabel = err.actionLabel,
duration = if (err.retryable) SnackbarDuration.Long else SnackbarDuration.Short,
)
return showSnackbar(com.hermesandroid.relay.ui.components.HumanErrorVisuals(err))
}
/** Startup chrome should wait for either standard chat surface, not Relay. */
@@ -283,6 +282,8 @@ internal fun resolveAppChatRuntimeStatus(
connection: Connection?,
gatewayAvailability: GatewayAvailability,
apiHealth: ConnectionViewModel.HealthStatus,
streamingEndpoint: String = "auto",
conversationOwner: SessionTransport? = null,
): ChatRuntimeStatus {
val capabilities = connection?.capabilities
val gateway = when {
@@ -298,7 +299,11 @@ internal fun resolveAppChatRuntimeStatus(
apiHealth == ConnectionViewModel.HealthStatus.Probing -> ChatTransportReadiness.Connecting
else -> ChatTransportReadiness.Unavailable
}
return resolveChatRuntimeStatus(gateway = gateway, apiSse = api)
val owner = when (conversationOwner ?: connection?.chatTransportForPreference(streamingEndpoint)) {
SessionTransport.SSE -> ChatTransportPath.ApiSse
else -> ChatTransportPath.Gateway
}
return resolveChatRuntimeStatus(gateway = gateway, apiSse = api, owner = owner)
}
internal fun shouldSettleStartupUnreachable(
@@ -360,7 +365,7 @@ internal fun resolveFooterRouteCandidate(
*
* Endpoint roles are operator and wire metadata, so an internal role such as
* `authenticated_dashboard` must never leak into this constrained surface.
* Gateway labels describe how the Dashboard is reached; API fallback keeps
* Gateway labels describe how the Dashboard is reached; Direct API keeps
* the route's ordinary transport label.
*/
internal fun resolveFooterRouteLabel(
@@ -1007,6 +1012,17 @@ fun RelayApp() {
chatSessions.firstOrNull { it.sessionId == currentChatSessionId }
}
LaunchedEffect(
gitOwnerKey,
activeChatSession?.gitRepoRoot,
activeChatSession?.workingDirectory,
) {
gitStateViewModel.setSessionWorkspace(
repoRoot = activeChatSession?.gitRepoRoot,
workingDirectory = activeChatSession?.workingDirectory,
)
}
// Bind Git to the active coding session when upstream supplies its exact
// workspace metadata. CWD fallback only matches a path-segment descendant;
// an ambiguous multi-repo catalog stays unselected until the user chooses.
@@ -1023,7 +1039,7 @@ fun RelayApp() {
}
}
val gitWorkspaceAvailable = gitRepoScanningEnabled &&
val gitWorkspaceAvailable =
(gitReposState as? GitStateUiState.Ready)?.repos?.isNotEmpty() == true
val gitWorkspaceSummary = remember(
gitReposState,
@@ -1079,14 +1095,16 @@ fun RelayApp() {
}
}
// Observe theme preference
val themePreference by connectionViewModel.theme.collectAsState()
val appThemeId by connectionViewModel.appTheme.collectAsState()
val fontScale by connectionViewModel.fontScale.collectAsState()
val appFontId by connectionViewModel.appFont.collectAsState()
val appearanceAccent by connectionViewModel.appearanceAccent.collectAsState()
val appearanceShape by connectionViewModel.appearanceShape.collectAsState()
val activeCustomTheme by connectionViewModel.activeCustomTheme.collectAsState()
// The same decoded emission that releases splash readiness owns the first
// real frame; individual settings flows can hydrate independently later.
val appearance by connectionViewModel.appearance.collectAsState()
val themePreference = appearance.themePreference
val appThemeId = appearance.appThemeId
val fontScale = appearance.fontScale
val appFontId = appearance.appFontId
val appearanceAccent = appearance.accentHex
val appearanceShape = appearance.shapeId
val activeCustomTheme = appearance.customTheme
val navController = rememberNavController()
val navBackStackEntry by navController.currentBackStackEntryAsState()
val currentRoute = navBackStackEntry?.destination?.route
@@ -1593,6 +1611,7 @@ fun RelayApp() {
// evidence alone left a window where the reveal showed the CTA for
// the few hundred ms until the client-based health verdict landed.
val chatReady by connectionViewModel.chatReady.collectAsState()
val conversationOwner by connectionViewModel.activeConversationTransport.collectAsState()
var startupGateMinElapsed by remember { mutableStateOf(false) }
var startupGateTimedOut by remember { mutableStateOf(false) }
var startupGateReleased by remember { mutableStateOf(false) }
@@ -1619,6 +1638,8 @@ fun RelayApp() {
connection = activeConnection,
gatewayAvailability = gatewayAvailability,
apiHealth = apiHealth,
streamingEndpoint = streamingEndpoint,
conversationOwner = conversationOwner,
)
// A Dashboard/Gateway-only connection is a complete standard Hermes
// connection. Startup readiness follows the same transport-neutral
@@ -1929,6 +1950,8 @@ fun RelayApp() {
// child TopAppBar doesn't double-pad when this banner owns the top edge.
val activeMessageCount by UiMessageBus.activeCount.collectAsState()
val showMessageBanner = activeMessageCount > 0
val modalMessageHostActive by UiMessageBus.modalHostActive.collectAsState()
val showActionMessage = snackbarHostState.currentSnackbarData != null && !modalMessageHostActive
// Update availability (unified): googlePlay = Play In-App Update FLEXIBLE,
// sideload = GitHub releases. The handle filters dismissed versions +
// throttles checks internally, exposing a surfaceable status for the
@@ -1943,7 +1966,7 @@ fun RelayApp() {
// (WhatsApp-style; see ChatScreen). That's the "can I talk to the
// agent?" signal.
// • Relay socket (bridge/terminal/relay-voice) → the bottom
// RelayStatusStrip's "Reconnecting…" cue only. It never blocks chat,
// RelayStatusStrip is reserved for the active chat owner's status.
// so it stays ambient. (`connectionReconnecting` below.)
// A routine in-progress reconnect surfaces only in the bottom strip.
// Computed off the raw status (not the dismiss-gated `toast`) because the
@@ -2054,6 +2077,14 @@ fun RelayApp() {
includeStatusBarPadding =
!showUnattendedBanner && !showDemoBanner && !showHostResourcePressure,
)
// Action feedback owns layout space at the top, never the composer's
// touch area. Modal windows keep their own scoped host.
ThemedMessageHost(
snackbarHostState,
modifier = if (showActionMessage && !showMessageBanner &&
!showUnattendedBanner && !showDemoBanner && !showHostResourcePressure
) Modifier.windowInsetsPadding(WindowInsets.statusBars) else Modifier,
)
// The update banner AND the connection-status indicator now render as
// floating overlay TOASTS in the Box below (see the top-overlay Column
@@ -2094,7 +2125,7 @@ fun RelayApp() {
// participates in the top-inset accounting.
if (showUnattendedBanner || showDemoBanner || showHostResourcePressure ||
connectionChipVisible ||
showMessageBanner
showMessageBanner || showActionMessage
) {
Modifier.consumeWindowInsets(WindowInsets.statusBars)
} else {
@@ -2102,7 +2133,6 @@ fun RelayApp() {
}
),
contentWindowInsets = WindowInsets(0),
snackbarHost = { SnackbarHost(snackbarHostState) },
bottomBar = {
if (
!suppressGlobalChrome &&
@@ -2125,7 +2155,9 @@ fun RelayApp() {
?: stringResource(R.string.status_no_route),
)
val transportStatus = resolveChatTransportStatus(
streamingEndpoint = streamingEndpoint,
streamingEndpoint = connectionViewModel.resolveActiveStreamingEndpoint(
streamingEndpoint,
),
gatewayAvailability = gatewayAvailability,
serverCapabilities = serverCapabilities,
)
@@ -2176,6 +2208,9 @@ fun RelayApp() {
// Routine in-progress reconnect surfaces here (amber cue)
// instead of a take-space banner or a floating toast.
reconnecting = connectionReconnecting,
maxContentWidth = chatResponsiveLayout(
LocalConfiguration.current.screenWidthDp,
).chromeMaxWidth,
modifier = Modifier.petPerchSurface(
key = APP_STATUS_PET_WALK_REGION,
routes = APP_STATUS_PET_ROUTES,
@@ -2184,7 +2219,10 @@ fun RelayApp() {
}
}
) { innerPadding ->
CompositionLocalProvider(LocalSnackbarHost provides snackbarHostState) {
CompositionLocalProvider(
LocalSnackbarHost provides snackbarHostState,
com.hermesandroid.relay.ui.components.LocalMessageActionHost provides snackbarHostState,
) {
Column(
modifier = Modifier
.fillMaxSize()
@@ -2448,103 +2486,110 @@ fun RelayApp() {
val screenChatLabel = stringResource(R.string.screen_chat_label)
ChatScreen(
chatViewModel = chatViewModel,
connectionViewModel = connectionViewModel,
voiceViewModel = voiceViewModel,
voiceClient = voiceClient,
maxBubbleWidth = maxBubbleWidth,
voicePresentationMode = voicePresentationMode,
onVoicePresentationModeChange = { mode ->
connectionSwitchScope.launch {
voicePreferences.setPresentationMode(mode)
}
},
openAgentSheetOnEntry = openAgentSheetArg,
onAgentSheetArgConsumed = {
backStackEntry.arguments?.putBoolean(
Screen.Chat.ARG_OPEN_AGENT_SHEET, false,
)
},
// AgentInfoSheet footer jumps straight into the full
// Connections CRUD screen — saves a detour through
// Settings → Gateways.
onNavigateToConnections = {
navController.navigate(Screen.ConnectionsSettings.route)
},
onNavigateToConnect = {
navController.navigate(Screen.Pair.route()) {
launchSingleTop = true
}
},
onRepairConnection = {
navController.navigate(
Screen.Pair.route(
connectionId = activeConnectionId,
autoStart = "relay",
),
) {
launchSingleTop = true
}
},
// Empty-chat "needs connection" card also offers the offline
// demo, so a skipped / never-connected first run can explore
// without leaving Chat. Safe here — this state only shows when
// nothing is configured, so there's no placeholder in flight.
onTryDemo = enterDemo,
onNavigateToDashboardSignIn = {
navController.navigate(Screen.DashboardSignIn.route()) {
launchSingleTop = true
}
},
onNavigateToBridge = {
rememberBridgeReturn(
route = Screen.Chat.route(openAgentSheet = false),
label = screenChatLabel,
)
navController.navigate(Screen.Bridge.route) {
popUpTo(navController.graph.findStartDestination().id) {
saveState = true
ChatMediaViewerHost(
activeConnectionId,
effectiveSessionProfileName,
currentChatSessionId,
chatSupervisedPolicy,
) {
ChatScreen(
chatViewModel = chatViewModel,
connectionViewModel = connectionViewModel,
voiceViewModel = voiceViewModel,
voiceClient = voiceClient,
maxBubbleWidth = maxBubbleWidth,
voicePresentationMode = voicePresentationMode,
onVoicePresentationModeChange = { mode ->
connectionSwitchScope.launch {
voicePreferences.setPresentationMode(mode)
}
launchSingleTop = true
restoreState = true
}
},
onNavigateToTerminal = {
navController.navigate(Screen.Terminal.route) {
launchSingleTop = true
}
},
onNavigateToSettings = {
navController.navigate(Screen.Settings.route) {
launchSingleTop = true
}
},
onNavigateToAppearanceSettings = {
navController.navigate(Screen.AppearanceSettings.route) {
launchSingleTop = true
}
},
onNavigateToVoiceSettings = {
navController.navigate(Screen.VoiceSettings.route) {
launchSingleTop = true
}
},
onNavigateToProfileInspector = { profileName ->
navController.navigate(Screen.ProfileInspector.route(profileName)) {
launchSingleTop = true
}
},
supervisedPolicy = chatSupervisedPolicy,
onNavigateToBotMode = {
navController.navigate(Screen.BotMode.route) { launchSingleTop = true }
},
gitWorkspaceAvailable = gitWorkspaceAvailable,
gitWorkspaceSummary = gitWorkspaceSummary,
onNavigateToGitWorkspace = {
navController.navigate(Screen.GitState.route) { launchSingleTop = true }
},
)
},
openAgentSheetOnEntry = openAgentSheetArg,
onAgentSheetArgConsumed = {
backStackEntry.arguments?.putBoolean(
Screen.Chat.ARG_OPEN_AGENT_SHEET, false,
)
},
// AgentInfoSheet footer jumps straight into the full
// Connections CRUD screen — saves a detour through
// Settings → Gateways.
onNavigateToConnections = {
navController.navigate(Screen.ConnectionsSettings.route)
},
onNavigateToConnect = {
navController.navigate(Screen.Pair.route()) {
launchSingleTop = true
}
},
onRepairConnection = {
navController.navigate(
Screen.Pair.route(
connectionId = activeConnectionId,
autoStart = "relay",
),
) {
launchSingleTop = true
}
},
// Empty-chat "needs connection" card also offers the offline
// demo, so a skipped / never-connected first run can explore
// without leaving Chat. Safe here — this state only shows when
// nothing is configured, so there's no placeholder in flight.
onTryDemo = enterDemo,
onNavigateToDashboardSignIn = {
navController.navigate(Screen.DashboardSignIn.route()) {
launchSingleTop = true
}
},
onNavigateToBridge = {
rememberBridgeReturn(
route = Screen.Chat.route(openAgentSheet = false),
label = screenChatLabel,
)
navController.navigate(Screen.Bridge.route) {
popUpTo(navController.graph.findStartDestination().id) {
saveState = true
}
launchSingleTop = true
restoreState = true
}
},
onNavigateToTerminal = {
navController.navigate(Screen.Terminal.route) {
launchSingleTop = true
}
},
onNavigateToSettings = {
navController.navigate(Screen.Settings.route) {
launchSingleTop = true
}
},
onNavigateToAppearanceSettings = {
navController.navigate(Screen.AppearanceSettings.route) {
launchSingleTop = true
}
},
onNavigateToVoiceSettings = {
navController.navigate(Screen.VoiceSettings.route) {
launchSingleTop = true
}
},
onNavigateToProfileInspector = { profileName ->
navController.navigate(Screen.ProfileInspector.route(profileName)) {
launchSingleTop = true
}
},
supervisedPolicy = chatSupervisedPolicy,
onNavigateToBotMode = {
navController.navigate(Screen.BotMode.route) { launchSingleTop = true }
},
gitWorkspaceAvailable = gitWorkspaceAvailable,
gitWorkspaceSummary = gitWorkspaceSummary,
onNavigateToGitWorkspace = {
navController.navigate(Screen.GitState.route) { launchSingleTop = true }
},
)
}
}
composable(Screen.BotMode.route) {
BotModeScreen(
@@ -8,26 +8,50 @@ import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.flow.asStateFlow
import java.util.concurrent.atomic.AtomicLong
/** Visual tone of a transient banner message. Errors are NOT modelled here —
* they stay on the snackbar (see [LocalSnackbarHost]); this bus is info-only. */
enum class UiMessageSeverity { Info, Success, Status }
/** Visual tone of a transient banner message. */
enum class UiMessageSeverity { Info, Success, Status, Warning, Error }
data class UiMessage(
val id: Long,
val text: String,
val severity: UiMessageSeverity,
val ttlMillis: Long,
/** Stable upstream key for replace-in-place and exact dismissal. */
val key: String? = null,
)
sealed interface UiMessageEvent {
data class Show(val message: UiMessage) : UiMessageEvent
data class Clear(val key: String) : UiMessageEvent
data object ClearAll : UiMessageEvent
}
internal fun reduceUiMessages(
current: List<UiMessage>,
event: UiMessageEvent,
maxRetained: Int,
): List<UiMessage> = when (event) {
UiMessageEvent.ClearAll -> emptyList()
is UiMessageEvent.Clear -> current.filterNot { it.key == event.key }
is UiMessageEvent.Show -> {
val incoming = event.message
val withoutDuplicate = current.filterNot { existing ->
if (incoming.key != null) existing.key == incoming.key else existing.text == incoming.text
}
(withoutDuplicate + incoming).takeLast(maxRetained)
}
}
/**
* App-wide bus for transient, non-error status/confirmation messages that
* App-wide bus for transient status, confirmation, and error messages that
* surface in the top [com.hermesandroid.relay.ui.components.MessageBannerHost]
* — a thin banner that takes its own space (content slides down, no overlay),
* shows the newest line collapsed, expands to a few recent lines, auto-dismisses
* and coalesces duplicates.
*
* Deliberately info-only: errors and persistent/actionable messages keep going
* to the snackbar so they demand acknowledgement. Migrate frequent
* Messages requiring Retry or Undo use ThemedMessageHost and retain their
* action-result contract. Upstream keyed AgentNotices own their sticky/clear lifecycle.
* Migrate frequent
* `snackbarHostState.showSnackbar("…")` confirmations/status to [info] /
* [success] / [status] here.
*
@@ -39,8 +63,25 @@ object UiMessageBus {
const val STATUS_TTL_MS = 6_000L
private val counter = AtomicLong(0L)
private val _events = MutableSharedFlow<UiMessage>(extraBufferCapacity = 24)
val events: SharedFlow<UiMessage> = _events.asSharedFlow()
private val hosts = linkedMapOf<Long, Boolean>()
private val _activeHost = MutableStateFlow<Long?>(null)
internal val activeHost = _activeHost.asStateFlow()
private val _modalHostActive = MutableStateFlow(false)
internal val modalHostActive = _modalHostActive.asStateFlow()
internal fun registerHost(primary: Boolean): Long = synchronized(hosts) {
counter.incrementAndGet().also {
hosts[it] = primary
_activeHost.value = hosts.keys.lastOrNull()
_modalHostActive.value = hosts.values.any { primaryHost -> !primaryHost }
}
}
internal fun unregisterHost(id: Long) { synchronized(hosts) {
hosts.remove(id)
_activeHost.value = hosts.keys.lastOrNull()
_modalHostActive.value = hosts.values.any { !it }
} }
private val _events = MutableSharedFlow<UiMessageEvent>(extraBufferCapacity = 24)
val events: SharedFlow<UiMessageEvent> = _events.asSharedFlow()
// Number of messages currently shown by the host. Lifted here so the app
// scaffold can fold banner visibility into its status-bar inset accounting
@@ -52,12 +93,33 @@ object UiMessageBus {
text: String,
severity: UiMessageSeverity = UiMessageSeverity.Info,
ttlMillis: Long = DEFAULT_TTL_MS,
key: String? = null,
) {
val trimmed = text.trim()
if (trimmed.isEmpty()) return
_events.tryEmit(UiMessage(counter.incrementAndGet(), trimmed, severity, ttlMillis))
_events.tryEmit(
UiMessageEvent.Show(
UiMessage(
id = counter.incrementAndGet(),
text = trimmed,
severity = severity,
ttlMillis = ttlMillis.coerceAtLeast(0L),
key = key?.trim()?.takeIf(String::isNotEmpty),
),
),
)
}
/** Dismiss only the keyed message owned by the matching upstream notice. */
fun clear(key: String) {
key.trim().takeIf(String::isNotEmpty)?.let { _events.tryEmit(UiMessageEvent.Clear(it)) }
}
fun clearAll() { _events.tryEmit(UiMessageEvent.ClearAll) }
fun warning(text: String, ttlMillis: Long = STATUS_TTL_MS) = post(text, UiMessageSeverity.Warning, ttlMillis)
fun error(text: String, ttlMillis: Long = 10_000L) = post(text, UiMessageSeverity.Error, ttlMillis)
/** Neutral confirmation/info (e.g. "Pairing code copied"). */
fun info(text: String, ttlMillis: Long = DEFAULT_TTL_MS) =
post(text, UiMessageSeverity.Info, ttlMillis)
@@ -1,6 +1,6 @@
package com.hermesandroid.relay.ui.components
import android.widget.Toast
import com.hermesandroid.relay.ui.UiMessageBus
import androidx.compose.foundation.BorderStroke
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
@@ -209,7 +209,7 @@ fun ActiveCardRelayStatusSection(
val relayUiState by connectionViewModel.relayUiState.collectAsState()
val relayRowState by connectionViewModel.relayRowState.collectAsState()
// Pre-resolve strings for Toast (non-composable context)
// Pre-resolve strings for action callbacks (non-composable context).
val reconnectingRelayToast = stringResource(R.string.active_section_reconnecting_relay)
val relayStatusText = when (relayRowState.phase) {
RelayUiState.NotConfigured -> stringResource(R.string.relay_state_optional)
@@ -250,11 +250,7 @@ fun ActiveCardRelayStatusSection(
onClick = {
if (relayUiState == RelayUiState.Stale) {
connectionViewModel.reconnectIfStale()
Toast.makeText(
context,
reconnectingRelayToast,
Toast.LENGTH_SHORT,
).show()
UiMessageBus.status(reconnectingRelayToast)
} else {
onOpenRelayInfo()
}
@@ -613,7 +609,7 @@ private fun CapabilityRow(
/**
* Advanced compatibility and override content:
* - optional direct API fallback URL/key
* - optional Direct API URL/key
* - explicit direct Relay endpoint override/test
* - allow-insecure-connections development toggle
*
@@ -817,7 +813,7 @@ private fun ManualUrlSubsection(
}
val autoRelayUrl = RelayUrlDeriver.deriveFromApiUrl(apiUrlInput)
// Pre-resolve strings for Toast (non-composable context)
// Pre-resolve strings for action callbacks (non-composable context).
val apiHermesVoiceReachableToast = stringResource(R.string.active_section_api_hermes_voice_reachable)
val apiRelayVoiceReachableToast = stringResource(R.string.active_section_api_relay_voice_reachable)
val apiReachableVoiceReviewToast = stringResource(R.string.active_section_api_reachable_voice_review)
@@ -926,21 +922,21 @@ private fun ManualUrlSubsection(
relayOverrideVisible = true
result.relayUrl?.let { relayUrlInput = it }
}
Toast.makeText(
context,
when {
result.apiReachable && result.voiceConfigReachable ->
if (result.voiceRoute == "standard") {
apiHermesVoiceReachableToast
} else {
apiRelayVoiceReachableToast
}
result.apiReachable ->
apiReachableVoiceReviewToast
else -> cannotReachApiToast
},
Toast.LENGTH_SHORT,
).show()
val feedback = when {
result.apiReachable && result.voiceConfigReachable ->
if (result.voiceRoute == "standard") {
apiHermesVoiceReachableToast
} else {
apiRelayVoiceReachableToast
}
result.apiReachable -> apiReachableVoiceReviewToast
else -> cannotReachApiToast
}
when {
result.apiReachable && result.voiceConfigReachable -> UiMessageBus.success(feedback)
result.apiReachable -> UiMessageBus.warning(feedback)
else -> UiMessageBus.error(feedback)
}
}
},
enabled = apiUrlInput.isNotBlank() && !isTestingApi && inputApiKeyError == null,
@@ -1202,12 +1198,18 @@ fun ActiveCardSecurityPosture(
val authState by connectionViewModel.authState.collectAsState()
val currentPairedSession by connectionViewModel.currentPairedSession.collectAsState()
val pairedDevices by connectionViewModel.pairedDevices.collectAsState()
// Live dashboard path (Secure Link / preferred route), not only the saved
// plain :9119 configuredDashboardUrl that pairing still stores alongside.
val effectiveDashboardUrl by connectionViewModel.effectiveDashboardUrl.collectAsState()
val dashboardDisplayUrl = effectiveDashboardUrl.trim().trimEnd('/').ifBlank {
activeConnection?.resolvedDashboardUrl.orEmpty()
}
val dashboardStatus = activeConnection?.dashboardLastStatus
val dashboardSignInRequired = dashboardStatus?.authRequired == true &&
dashboardStatus.authenticated != true
val dashboardValue = when {
activeConnection?.resolvedDashboardUrl.isNullOrBlank() ->
dashboardDisplayUrl.isBlank() ->
stringResource(R.string.active_section_not_configured)
dashboardStatus == null -> stringResource(R.string.active_section_not_checked)
!dashboardStatus.reachable -> stringResource(R.string.active_section_unreachable)
@@ -1259,7 +1261,7 @@ fun ActiveCardSecurityPosture(
style = MaterialTheme.typography.bodyMedium,
)
Text(
text = activeConnection?.resolvedDashboardUrl.orEmpty().ifBlank {
text = dashboardDisplayUrl.ifBlank {
stringResource(R.string.active_section_not_configured)
},
style = MaterialTheme.typography.bodySmall,
@@ -2035,11 +2037,12 @@ fun ActiveCardRoutesSection(
original = routeEditorOriginal,
relayEnabled = connection.relayUrl.isNotBlank() ||
endpoints.any { it.relay != null },
onSave = { role, dashboardUrl, onResult ->
onSave = { role, dashboardUrl, httpConsentOrigin, onResult ->
connectionViewModel.saveExtraRoute(
role = role,
dashboardUrl = dashboardUrl,
original = routeEditorOriginal,
httpConsentOrigin = httpConsentOrigin,
onResult = onResult,
)
},
@@ -31,6 +31,7 @@ import androidx.compose.runtime.mutableStateMapOf
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
@@ -128,10 +129,11 @@ fun AttachmentGallery(
val exportAllowed = LocalImageExportAllowed.current
val scope = rememberCoroutineScope()
val blurMode = LocalMediaBlurMode.current
val viewerController = LocalChatMediaViewerController.current
val revealed = remember { mutableStateMapOf<String, Boolean>() }
var viewerStartIndex by remember { mutableStateOf<Int?>(null) }
var viewerStartIndex by rememberSaveable { mutableStateOf<Int?>(null) }
viewerStartIndex?.let { startIndex ->
viewerStartIndex?.takeIf { viewerController == null }?.let { startIndex ->
AttachmentGalleryViewer(
attachments = attachments,
initialIndex = startIndex.coerceIn(attachments.indices),
@@ -184,7 +186,21 @@ fun AttachmentGallery(
.testTag("attachment-gallery-tile-$galleryIndex")
.clip(RoundedCornerShape(GALLERY_CORNER))
.combinedClickable(
onClick = { viewerStartIndex = galleryIndex },
onClick = {
if (viewerController != null) {
viewerController.openGallery(
attachments = attachments,
initialIndex = galleryIndex,
initiallyRevealedKeys = revealed
.filterValues { it }
.keys,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerStartIndex = galleryIndex
}
},
onLongClick = { menuExpanded = true },
),
)
@@ -9,8 +9,7 @@ import android.media.audiofx.Visualizer
import android.net.Uri
import android.os.Build
import android.os.ParcelFileDescriptor
import android.view.SurfaceView
import android.widget.Toast
import com.hermesandroid.relay.ui.UiMessageBus
import androidx.annotation.OptIn
import androidx.compose.foundation.Image
import androidx.compose.foundation.background
@@ -63,10 +62,12 @@ import androidx.compose.runtime.Composable
import androidx.compose.runtime.DisposableEffect
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableLongStateOf
import androidx.compose.runtime.mutableStateMapOf
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import androidx.compose.ui.Alignment
@@ -86,13 +87,13 @@ import androidx.compose.ui.platform.testTag
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.IntSize
import androidx.compose.ui.viewinterop.AndroidView
import androidx.compose.ui.window.Dialog
import androidx.compose.ui.window.DialogProperties
import androidx.media3.common.MediaItem
import androidx.media3.common.Player
import androidx.media3.common.util.UnstableApi
import androidx.media3.exoplayer.ExoPlayer
import androidx.media3.ui.compose.ContentFrame
import coil3.compose.AsyncImage
import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.AttachmentRenderMode
@@ -290,7 +291,7 @@ fun Modifier.zoomable(maxScale: Float = 6f): Modifier {
* Dispatches on [Attachment.renderMode]:
* - IMAGE → zoomable image (Coil from the cached URI, or a decoded bitmap),
* honoring the sensitive blur gate.
* - VIDEO → ExoPlayer on a hand-wired [SurfaceView] with transport controls.
* - VIDEO → ExoPlayer through Media3's lifecycle-aware Compose content frame.
* - AUDIO → ExoPlayer mini-player with scrubber + a Visualizer amplitude meter.
* - PDF → [PdfRenderer] paginated pages in a LazyColumn.
* - TEXT → in-app monospace text viewer.
@@ -311,109 +312,112 @@ fun AttachmentViewer(
onDismissRequest = onDismiss,
properties = DialogProperties(usePlatformDefaultWidth = false),
) {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current ||
attachment.renderMode != AttachmentRenderMode.IMAGE
AllowDeviceRotation()
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
MessageOverlayScope {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current ||
attachment.renderMode != AttachmentRenderMode.IMAGE
AllowDeviceRotation()
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
var revealed by remember(attachment.cachedUri, attachment.relayToken) {
mutableStateOf(initiallyRevealed)
}
val blurred = !revealed &&
attachment.renderMode == AttachmentRenderMode.IMAGE &&
shouldBlurImage(blurMode, attachment.sensitive)
val title = attachment.fileName
?: attachment.contentType.substringBefore(';').ifBlank { stringResource(R.string.attachment_title) }
// --- One shared Share / Save / Open-externally action set ----------
fun runWithBytes(action: suspend (ByteArray) -> Unit) {
scope.launch {
busy = true
val bytes = attachmentBytes(context, attachment)
if (bytes == null) {
busy = false
viewerToast(context, context.getString(R.string.inbound_attach_share_failed))
return@launch
}
action(bytes)
busy = false
val blurMode = LocalMediaBlurMode.current
var revealed by remember(attachment.cachedUri, attachment.relayToken) {
mutableStateOf(initiallyRevealed)
}
}
val blurred = !revealed &&
attachment.renderMode == AttachmentRenderMode.IMAGE &&
shouldBlurImage(blurMode, attachment.sensitive)
val onShare = {
runWithBytes { bytes ->
val uri = MediaSaver.stageForShare(context, bytes, attachment.fileName, attachment.contentType)
MediaSaver.share(context, uri, attachment.contentType)
}
}
val onSave = {
runWithBytes { bytes ->
val result = if (attachment.renderMode == AttachmentRenderMode.IMAGE) {
MediaSaver.saveImage(context, bytes, attachment.fileName, attachment.contentType)
} else {
MediaSaver.saveFile(context, bytes, attachment.fileName, attachment.contentType)
}
when (result) {
is MediaSaver.SaveResult.Saved ->
viewerToast(context, context.getString(R.string.inbound_attach_saved, result.location))
MediaSaver.SaveResult.UseShareInstead -> {
val uri = MediaSaver.stageForShare(context, bytes, attachment.fileName, attachment.contentType)
MediaSaver.share(context, uri, attachment.contentType)
val title = attachment.fileName
?: attachment.contentType.substringBefore(';').ifBlank { stringResource(R.string.attachment_title) }
// --- One shared Share / Save / Open-externally action set ----------
fun runWithBytes(action: suspend (ByteArray) -> Unit) {
scope.launch {
busy = true
val bytes = attachmentBytes(context, attachment)
if (bytes == null) {
busy = false
UiMessageBus.error(context.getString(R.string.inbound_attach_share_failed))
return@launch
}
is MediaSaver.SaveResult.Failed ->
viewerToast(context, context.getString(R.string.inbound_attach_save_failed, result.message))
action(bytes)
busy = false
}
}
}
val onOpenExternal = {
val cached = attachment.cachedUri
if (!cached.isNullOrBlank()) {
MediaSaver.open(context, Uri.parse(cached), attachment.contentType)
} else {
val onShare = {
runWithBytes { bytes ->
val uri = MediaSaver.stageForShare(context, bytes, attachment.fileName, attachment.contentType)
MediaSaver.open(context, uri, attachment.contentType)
MediaSaver.share(context, uri, attachment.contentType)
}
}
}
Box(
modifier = modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.96f)),
) {
// Body fills; toolbar floats on top. PDF/TEXT add their own top
// inset so the first line clears the toolbar.
Box(modifier = Modifier.fillMaxSize(), contentAlignment = Alignment.Center) {
when (attachment.renderMode) {
AttachmentRenderMode.IMAGE -> ImageBody(
attachment = attachment,
blurred = blurred,
onReveal = { revealed = true },
)
AttachmentRenderMode.VIDEO -> VideoBody(attachment)
AttachmentRenderMode.AUDIO -> AudioBody(attachment)
AttachmentRenderMode.PDF -> PdfBody(attachment)
AttachmentRenderMode.TEXT -> TextBody(attachment)
AttachmentRenderMode.GENERIC -> GenericBody(attachment, onOpenExternal)
val onSave = {
runWithBytes { bytes ->
val result = if (attachment.renderMode == AttachmentRenderMode.IMAGE) {
MediaSaver.saveImage(context, bytes, attachment.fileName, attachment.contentType)
} else {
MediaSaver.saveFile(context, bytes, attachment.fileName, attachment.contentType)
}
when (result) {
is MediaSaver.SaveResult.Saved ->
UiMessageBus.success(context.getString(R.string.inbound_attach_saved, result.location))
MediaSaver.SaveResult.UseShareInstead -> {
val uri = MediaSaver.stageForShare(context, bytes, attachment.fileName, attachment.contentType)
MediaSaver.share(context, uri, attachment.contentType)
}
is MediaSaver.SaveResult.Failed ->
UiMessageBus.error(context.getString(R.string.inbound_attach_save_failed, result.message))
}
}
}
val onOpenExternal = {
val cached = attachment.cachedUri
if (!cached.isNullOrBlank()) {
MediaSaver.open(context, Uri.parse(cached), attachment.contentType)
} else {
runWithBytes { bytes ->
val uri = MediaSaver.stageForShare(context, bytes, attachment.fileName, attachment.contentType)
MediaSaver.open(context, uri, attachment.contentType)
}
}
}
MediaViewerToolbar(
title = title,
busy = busy,
actionsEnabled = !blurred,
exportAllowed = exportAllowed,
onShare = onShare,
onSave = onSave,
onOpenExternal = onOpenExternal,
onClose = onDismiss,
modifier = Modifier.align(Alignment.TopCenter),
)
Box(
modifier = modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.96f))
.testTag("attachment-viewer"),
) {
// Body fills; toolbar floats on top. PDF/TEXT add their own top
// inset so the first line clears the toolbar.
Box(modifier = Modifier.fillMaxSize(), contentAlignment = Alignment.Center) {
when (attachment.renderMode) {
AttachmentRenderMode.IMAGE -> ImageBody(
attachment = attachment,
blurred = blurred,
onReveal = { revealed = true },
)
AttachmentRenderMode.VIDEO -> VideoBody(attachment)
AttachmentRenderMode.AUDIO -> AudioBody(attachment)
AttachmentRenderMode.PDF -> PdfBody(attachment)
AttachmentRenderMode.TEXT -> TextBody(attachment)
AttachmentRenderMode.GENERIC -> GenericBody(attachment, onOpenExternal)
}
}
MediaViewerToolbar(
title = title,
busy = busy,
actionsEnabled = !blurred,
exportAllowed = exportAllowed,
onShare = onShare,
onSave = onSave,
onOpenExternal = onOpenExternal,
onClose = onDismiss,
modifier = Modifier.align(Alignment.TopCenter),
)
}
}
}
}
@@ -450,164 +454,165 @@ internal fun AttachmentGalleryViewer(
onDismissRequest = onDismiss,
properties = DialogProperties(usePlatformDefaultWidth = false),
) {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current
AllowDeviceRotation()
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
val revealed = remember { mutableStateMapOf<String, Boolean>() }
LaunchedEffect(initiallyRevealedKeys) {
initiallyRevealedKeys.forEach { revealed[it] = true }
}
val pagerState = rememberPagerState(
initialPage = initialIndex.coerceIn(attachments.indices),
pageCount = { attachments.size },
)
val currentIndex = pagerState.currentPage.coerceIn(attachments.indices)
val attachment = attachments[currentIndex]
val currentKey = galleryAttachmentKey(attachment, currentIndex)
val blurMode = LocalMediaBlurMode.current
val currentBlurred = revealed[currentKey] != true &&
shouldBlurImage(blurMode, attachment.sensitive)
val title = attachment.fileName
?: attachment.contentType.substringBefore(';').ifBlank { "Image" }
val toolbarTitle = "$title · ${currentIndex + 1} of ${attachments.size}"
// Capture the currently visible attachment in each click lambda. A
// swipe while IO is running must not redirect Save/Share to a new page.
fun runWithBytes(action: suspend (Attachment, ByteArray) -> Unit) {
if (currentBlurred || busy) return
val target = attachment
scope.launch {
busy = true
try {
val bytes = attachmentBytes(context, target)
if (bytes == null) {
viewerToast(context, "Couldn't read this image")
return@launch
}
action(target, bytes)
} catch (error: Exception) {
viewerToast(
context,
error.message?.takeIf { it.isNotBlank() }
?: "Couldn't complete that image action",
)
} finally {
busy = false
}
MessageOverlayScope {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current
AllowDeviceRotation()
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
val revealed = remember { mutableStateMapOf<String, Boolean>() }
LaunchedEffect(initiallyRevealedKeys) {
initiallyRevealedKeys.forEach { revealed[it] = true }
}
}
val pagerState = rememberPagerState(
initialPage = initialIndex.coerceIn(attachments.indices),
pageCount = { attachments.size },
)
val onShare = {
runWithBytes { target, bytes ->
val uri = MediaSaver.stageForShare(
context,
bytes,
target.fileName,
target.contentType,
)
MediaSaver.share(context, uri, target.contentType)
}
}
val onSave = {
runWithBytes { target, bytes ->
when (val result = MediaSaver.saveImage(
context,
bytes,
target.fileName,
target.contentType,
)) {
is MediaSaver.SaveResult.Saved ->
viewerToast(context, "Saved to ${result.location}")
MediaSaver.SaveResult.UseShareInstead -> {
val uri = MediaSaver.stageForShare(
context,
bytes,
target.fileName,
target.contentType,
val currentIndex = pagerState.currentPage.coerceIn(attachments.indices)
val attachment = attachments[currentIndex]
val currentKey = galleryAttachmentKey(attachment, currentIndex)
val blurMode = LocalMediaBlurMode.current
val currentBlurred = revealed[currentKey] != true &&
shouldBlurImage(blurMode, attachment.sensitive)
val title = attachment.fileName
?: attachment.contentType.substringBefore(';').ifBlank { "Image" }
val toolbarTitle = "$title · ${currentIndex + 1} of ${attachments.size}"
// Capture the currently visible attachment in each click lambda. A
// swipe while IO is running must not redirect Save/Share to a new page.
fun runWithBytes(action: suspend (Attachment, ByteArray) -> Unit) {
if (currentBlurred || busy) return
val target = attachment
scope.launch {
busy = true
try {
val bytes = attachmentBytes(context, target)
if (bytes == null) {
UiMessageBus.error("Couldn't read this image")
return@launch
}
action(target, bytes)
} catch (error: Exception) {
UiMessageBus.error(
error.message?.takeIf { it.isNotBlank() }
?: "Couldn't complete that image action",
)
MediaSaver.share(context, uri, target.contentType)
} finally {
busy = false
}
is MediaSaver.SaveResult.Failed ->
viewerToast(context, "Save failed: ${result.message}")
}
}
}
val onOpenExternal: () -> Unit = openExternal@{
if (currentBlurred || busy) return@openExternal
val target = attachment
val cached = target.cachedUri
if (!cached.isNullOrBlank()) {
runCatching {
MediaSaver.open(context, Uri.parse(cached), target.contentType)
}.onFailure {
viewerToast(context, "Couldn't open this image")
}
} else {
runWithBytes { item, bytes ->
val onShare = {
runWithBytes { target, bytes ->
val uri = MediaSaver.stageForShare(
context,
bytes,
item.fileName,
item.contentType,
target.fileName,
target.contentType,
)
MediaSaver.open(context, uri, item.contentType)
MediaSaver.share(context, uri, target.contentType)
}
}
}
Box(
modifier = modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.96f)),
) {
HorizontalPager(
state = pagerState,
beyondViewportPageCount = 0,
pageSpacing = 12.dp,
modifier = Modifier
.fillMaxSize()
.testTag("attachment-gallery-pager"),
) { page ->
val pageAttachment = attachments[page]
val pageKey = galleryAttachmentKey(pageAttachment, page)
val blurred = revealed[pageKey] != true && shouldBlurImage(
blurMode,
pageAttachment.sensitive,
)
ImageBody(
attachment = pageAttachment,
blurred = blurred,
onReveal = { revealed[pageKey] = true },
)
val onSave = {
runWithBytes { target, bytes ->
when (val result = MediaSaver.saveImage(
context,
bytes,
target.fileName,
target.contentType,
)) {
is MediaSaver.SaveResult.Saved ->
UiMessageBus.success("Saved to ${result.location}")
MediaSaver.SaveResult.UseShareInstead -> {
val uri = MediaSaver.stageForShare(
context,
bytes,
target.fileName,
target.contentType,
)
MediaSaver.share(context, uri, target.contentType)
}
is MediaSaver.SaveResult.Failed ->
UiMessageBus.error("Save failed: ${result.message}")
}
}
}
val onOpenExternal: () -> Unit = openExternal@{
if (currentBlurred || busy) return@openExternal
val target = attachment
val cached = target.cachedUri
if (!cached.isNullOrBlank()) {
runCatching {
MediaSaver.open(context, Uri.parse(cached), target.contentType)
}.onFailure {
UiMessageBus.error("Couldn't open this image")
}
} else {
runWithBytes { item, bytes ->
val uri = MediaSaver.stageForShare(
context,
bytes,
item.fileName,
item.contentType,
)
MediaSaver.open(context, uri, item.contentType)
}
}
}
MediaViewerToolbar(
title = toolbarTitle,
busy = busy,
actionsEnabled = !currentBlurred,
exportAllowed = exportAllowed,
onShare = onShare,
onSave = onSave,
onOpenExternal = onOpenExternal,
onClose = onDismiss,
modifier = Modifier.align(Alignment.TopCenter),
)
Box(
modifier = modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.96f)),
) {
HorizontalPager(
state = pagerState,
beyondViewportPageCount = 0,
pageSpacing = 12.dp,
modifier = Modifier
.fillMaxSize()
.testTag("attachment-gallery-pager"),
) { page ->
val pageAttachment = attachments[page]
val pageKey = galleryAttachmentKey(pageAttachment, page)
val blurred = revealed[pageKey] != true && shouldBlurImage(
blurMode,
pageAttachment.sensitive,
)
ImageBody(
attachment = pageAttachment,
blurred = blurred,
onReveal = { revealed[pageKey] = true },
)
}
Text(
text = "${currentIndex + 1} / ${attachments.size}",
style = MaterialTheme.typography.labelMedium,
color = Color.White,
modifier = Modifier
.align(Alignment.BottomCenter)
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(bottom = 12.dp)
.clip(RoundedCornerShape(50))
.background(Color.Black.copy(alpha = 0.55f))
.padding(horizontal = 12.dp, vertical = 6.dp),
)
MediaViewerToolbar(
title = toolbarTitle,
busy = busy,
actionsEnabled = !currentBlurred,
exportAllowed = exportAllowed,
onShare = onShare,
onSave = onSave,
onOpenExternal = onOpenExternal,
onClose = onDismiss,
modifier = Modifier.align(Alignment.TopCenter),
)
Text(
text = "${currentIndex + 1} / ${attachments.size}",
style = MaterialTheme.typography.labelMedium,
color = Color.White,
modifier = Modifier
.align(Alignment.BottomCenter)
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(bottom = 12.dp)
.clip(RoundedCornerShape(50))
.background(Color.Black.copy(alpha = 0.55f))
.padding(horizontal = 12.dp, vertical = 6.dp),
)
}
}
}
}
@@ -737,17 +742,27 @@ private fun VideoBody(attachment: Attachment) {
return
}
var savedPosition by rememberSaveable(uri.toString()) { mutableLongStateOf(0L) }
var wantsToPlay by rememberSaveable(uri.toString()) { mutableStateOf(true) }
var muted by rememberSaveable(uri.toString()) { mutableStateOf(false) }
val player = remember(uri) {
ExoPlayer.Builder(context).build().apply {
setMediaItem(MediaItem.fromUri(uri))
if (savedPosition > 0L) seekTo(savedPosition)
playWhenReady = wantsToPlay
volume = if (muted) 0f else 1f
prepare()
playWhenReady = true
}
}
DisposableEffect(player) { onDispose { player.release() } }
DisposableEffect(player) {
onDispose {
savedPosition = player.currentPosition.coerceAtLeast(0L)
wantsToPlay = player.playWhenReady
player.release()
}
}
var isPlaying by remember { mutableStateOf(true) }
var muted by remember { mutableStateOf(false) }
var isPlaying by remember { mutableStateOf(player.isPlaying) }
var position by remember { mutableStateOf(0L) }
var duration by remember { mutableStateOf(0L) }
@@ -761,24 +776,30 @@ private fun VideoBody(attachment: Attachment) {
LaunchedEffect(player) {
while (true) {
position = player.currentPosition.coerceAtLeast(0L)
savedPosition = position
duration = player.duration.takeIf { it > 0L } ?: 0L
delay(250)
}
}
Column(modifier = Modifier.fillMaxSize(), verticalArrangement = Arrangement.Center) {
AndroidView(
factory = { ctx ->
SurfaceView(ctx).also { player.setVideoSurfaceView(it) }
},
modifier = Modifier.fillMaxWidth().weight(1f, fill = false).aspectRatio(16f / 9f),
)
Box(
modifier = Modifier.fillMaxWidth().weight(1f),
contentAlignment = Alignment.Center,
) {
ContentFrame(
player = player,
modifier = Modifier.fillMaxSize().testTag("attachment-video-content"),
contentScale = ContentScale.Fit,
)
}
PlaybackControls(
isPlaying = isPlaying,
position = position,
duration = duration,
onPlayPause = {
if (player.isPlaying) player.pause() else player.play()
wantsToPlay = !player.playWhenReady
player.playWhenReady = wantsToPlay
},
onSeek = { player.seekTo(it) },
trailing = {
@@ -1173,10 +1194,6 @@ private fun rememberPlayableUri(attachment: Attachment): Uri? {
return uri
}
private fun viewerToast(context: Context, message: String) {
Toast.makeText(context, message, Toast.LENGTH_SHORT).show()
}
private const val MAX_TEXT_BYTES = 2 * 1024 * 1024
// --- Non-composable IO helpers ---------------------------------------------
@@ -0,0 +1,118 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.AccountTree
import androidx.compose.material.icons.filled.ChevronRight
import androidx.compose.material.icons.filled.Terminal
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.semantics.stateDescription
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ChatActivityKind
import com.hermesandroid.relay.data.ChatActivityPhase
import com.hermesandroid.relay.data.ChatActivityRecord
/** Stable transcript entry into the same read-only preview used by active work. */
@Composable
internal fun ChatActivityReceipt(
record: ChatActivityRecord,
onClick: () -> Unit,
modifier: Modifier = Modifier,
) {
val subagents = record.kind == ChatActivityKind.SUBAGENTS
val title = stringResource(
if (subagents) R.string.chat_activity_receipt_subagents else R.string.chat_activity_receipt_process,
)
val action = stringResource(
if (subagents) R.string.chat_activity_receipt_view_activity else R.string.chat_activity_receipt_view_output,
)
val status = if (subagents && record.children.isNotEmpty()) {
val groups = record.children.groupingBy { it.phase }.eachCount().toMutableMap()
val missing = (record.taskCount - record.children.size).coerceAtLeast(0)
if (missing > 0) groups[ChatActivityPhase.UNKNOWN] = (groups[ChatActivityPhase.UNKNOWN] ?: 0) + missing
val labels = groups.map { (phase, count) ->
stringResource(R.string.chat_activity_receipt_count_phase, count, activityPhaseLabel(phase))
}
labels.joinToString(" · ")
} else if (subagents && record.taskCount > 0) {
stringResource(R.string.chat_activity_receipt_count_phase, record.taskCount, activityPhaseLabel(record.phase))
} else {
activityPhaseLabel(record.phase)
}
Surface(
modifier = modifier
.fillMaxWidth()
.heightIn(min = 48.dp)
.semantics(mergeDescendants = true) { stateDescription = status }
.clickable(role = Role.Button, onClickLabel = action, onClick = onClick),
shape = MaterialTheme.shapes.medium,
color = MaterialTheme.colorScheme.surfaceVariant.copy(alpha = 0.58f),
) {
Row(
modifier = Modifier.padding(horizontal = 12.dp, vertical = 10.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(
imageVector = if (subagents) Icons.Filled.AccountTree else Icons.Filled.Terminal,
contentDescription = null,
tint = if (record.phase == ChatActivityPhase.FAILED) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
modifier = Modifier.size(16.dp),
)
Spacer(Modifier.width(8.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
text = "$title · $status",
style = MaterialTheme.typography.labelMedium,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
Text(
text = action,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Spacer(Modifier.width(8.dp))
Icon(
imageVector = Icons.Filled.ChevronRight,
contentDescription = null,
tint = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
}
}
}
@Composable
private fun activityPhaseLabel(phase: ChatActivityPhase): String = stringResource(
when (phase) {
ChatActivityPhase.RUNNING -> R.string.bg_processes_running
ChatActivityPhase.COMPLETE -> R.string.agent_activity_status_completed
ChatActivityPhase.FAILED -> R.string.agent_activity_status_failed
ChatActivityPhase.CANCELLED -> R.string.task_status_cancelled
ChatActivityPhase.UNKNOWN -> R.string.agent_activity_status_unavailable
},
)
@@ -0,0 +1,215 @@
package com.hermesandroid.relay.ui.components
import androidx.activity.compose.BackHandler
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.core.tween
import androidx.compose.animation.expandVertically
import androidx.compose.animation.shrinkVertically
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.animation.slideInVertically
import androidx.compose.animation.slideOutVertically
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.selection.selectable
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.Check
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.setValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.res.pluralStringResource
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.zIndex
import com.hermesandroid.relay.ui.theme.appearanceTopRoundedCornerShape
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.BusyMessageAction
private val COMPOSER_TRAY_UNDERLAP = 12.dp
/** A separate rear surface tucked beneath the composer's foreground edge. */
@Composable
fun ChatComposerLayers(
action: BusyMessageAction?,
onActionChange: (BusyMessageAction) -> Unit,
correctionAvailable: Boolean,
onStop: (() -> Unit)?,
modifier: Modifier = Modifier,
content: @Composable () -> Unit,
) {
Column(
modifier = modifier.fillMaxWidth(),
verticalArrangement = Arrangement.spacedBy(-COMPOSER_TRAY_UNDERLAP),
) {
if (action != null) {
ChatBusyActionSelector(
action, onActionChange,
correctionAvailable = correctionAvailable,
onStop = onStop,
bottomUnderlap = COMPOSER_TRAY_UNDERLAP,
modifier = Modifier.fillMaxWidth().padding(horizontal = 20.dp).zIndex(0f),
)
}
Box(Modifier.fillMaxWidth().zIndex(1f).testTag("chatComposerForeground")) { content() }
}
}
/** Compact current intent; optional plain-text choices slide out from behind it. */
@Composable
fun ChatBusyActionSelector(
action: BusyMessageAction,
onActionChange: (BusyMessageAction) -> Unit,
modifier: Modifier = Modifier,
correctionAvailable: Boolean = true,
onStop: (() -> Unit)? = null,
bottomUnderlap: Dp = 0.dp,
) {
var expanded by remember { mutableStateOf(false) }
BackHandler(enabled = expanded) { expanded = false }
Surface(
modifier = modifier.testTag("chatBusyActionTray"),
color = MaterialTheme.colorScheme.surfaceContainerLow.copy(alpha = 0.82f),
shape = appearanceTopRoundedCornerShape(12.dp),
tonalElevation = 0.dp,
) {
Column(Modifier.padding(bottom = bottomUnderlap)) {
AnimatedVisibility(
visible = expanded,
enter = expandVertically(tween(220), expandFrom = Alignment.Bottom) +
slideInVertically(tween(220)) { it } + fadeIn(tween(160)),
exit = shrinkVertically(tween(180), shrinkTowards = Alignment.Bottom) +
slideOutVertically(tween(180)) { it } + fadeOut(tween(120)),
) {
Row(
Modifier.fillMaxWidth().testTag("chatBusyActionDrawer").padding(horizontal = 8.dp),
verticalAlignment = Alignment.CenterVertically,
) {
BusyMessageAction.entries.forEach { option ->
val available = option == BusyMessageAction.QueueNext || correctionAvailable
Row(
Modifier.weight(1f).heightIn(min = 48.dp)
.testTag("chatBusyAction-${option.storedValue}")
.selectable(selected = option == action, enabled = available, role = Role.RadioButton) {
onActionChange(option)
expanded = false
}.padding(horizontal = 8.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
) {
if (option == action) {
Icon(Icons.Default.Check, null, Modifier.size(14.dp),
tint = MaterialTheme.colorScheme.onSurface)
} else Spacer(Modifier.size(14.dp))
Text(
stringResource(if (option == BusyMessageAction.CorrectNow) R.string.chat_correct_now else R.string.chat_queue_next),
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurface.copy(alpha = if (available) 1f else 0.38f),
)
}
}
}
}
Row(
Modifier.fillMaxWidth().padding(horizontal = 12.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Row(
Modifier.weight(1f).heightIn(min = 40.dp)
.testTag("chatBusyActionTrigger")
.clickable(role = Role.Button) { expanded = !expanded },
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
Text(
stringResource(if (action == BusyMessageAction.CorrectNow) R.string.chat_correct_now else R.string.chat_queue_next),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Icon(
if (expanded) Icons.Default.ExpandMore else Icons.Default.ExpandLess,
null, Modifier.size(14.dp), tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (onStop != null) {
IconButton(onClick = onStop) {
Icon(Icons.Default.Stop, stringResource(R.string.chat_input_stop_streaming), Modifier.size(18.dp))
}
}
}
}
}
}
@Composable
fun ChatMessageQueue(
messages: List<String>,
paused: Boolean,
onResume: () -> Unit,
onClear: () -> Unit,
onEdit: (Int) -> Unit,
onRemove: (Int) -> Unit,
canEdit: Boolean,
modifier: Modifier = Modifier,
) {
if (messages.isEmpty()) return
Column(modifier) {
Row(Modifier.fillMaxWidth(), verticalAlignment = Alignment.CenterVertically) {
Text(
if (paused) stringResource(R.string.chat_queue_paused)
else pluralStringResource(R.plurals.chat_queue_count, messages.size, messages.size),
style = MaterialTheme.typography.labelMedium,
modifier = Modifier.weight(1f),
)
if (paused) TextButton(onClick = onResume) { Text(stringResource(R.string.chat_queue_resume)) }
TextButton(onClick = onClear) { Text(stringResource(R.string.chat_clear)) }
}
Column(
Modifier.heightIn(max = 144.dp).verticalScroll(rememberScrollState()),
verticalArrangement = Arrangement.spacedBy(2.dp),
) {
messages.forEachIndexed { index, text ->
Row(Modifier.fillMaxWidth(), verticalAlignment = Alignment.CenterVertically) {
Text(
text = text,
maxLines = 2,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
style = MaterialTheme.typography.bodySmall,
modifier = Modifier.weight(1f)
.clickable(enabled = canEdit, role = Role.Button) { onEdit(index) }
.padding(vertical = 12.dp),
)
IconButton(onClick = { onRemove(index) }) {
Icon(Icons.Default.Close, stringResource(R.string.chat_queue_remove))
}
}
}
}
}
}
@@ -0,0 +1,197 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.BoxScope
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.combinedClickable
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.animation.slideInVertically
import androidx.compose.animation.slideOutVertically
import androidx.activity.compose.BackHandler
import androidx.compose.ui.draw.clipToBounds
import androidx.compose.ui.unit.Dp
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.paneTitle
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
import com.hermesandroid.relay.network.upstream.GatewayConnectionState
import com.hermesandroid.relay.viewmodel.ConnectionStepState
@Composable
internal fun Modifier.chatDebugHeaderGesture(enabled: Boolean, onClick: () -> Unit, onHold: () -> Unit): Modifier =
combinedClickable(enabled = enabled, onClick = onClick, onLongClick = onHold,
onLongClickLabel = stringResource(R.string.chat_debug_open))
@Composable
internal fun BoxScope.ChatDebugOverlay(
visible: Boolean,
headerHeight: Dp,
onClose: () -> Unit,
content: @Composable () -> Unit,
) {
BackHandler(enabled = visible, onBack = onClose)
if (visible) {
Box(Modifier.fillMaxSize().padding(top = headerHeight)
.background(MaterialTheme.colorScheme.scrim.copy(alpha = 0.28f))
.clickable(onClick = onClose))
}
AnimatedVisibility(
visible = visible,
enter = slideInVertically { -it } + fadeIn(),
exit = slideOutVertically { -it } + fadeOut(),
modifier = Modifier.align(Alignment.TopCenter).padding(top = headerHeight).fillMaxWidth().clipToBounds(),
) { content() }
}
/** Read-only snapshot of the visible conversation; opening it sends no RPCs. */
@Composable
internal fun ChatDebugDrawer(
profile: String,
model: String,
sessionId: String?,
gateway: Boolean,
signedIn: Boolean,
signInRequired: Boolean,
socketState: GatewayConnectionState,
preparing: Boolean,
streaming: Boolean,
loadingHistory: Boolean,
directoryUnavailable: Boolean,
failure: String?,
onClose: () -> Unit,
onConnections: () -> Unit,
modifier: Modifier = Modifier,
) {
val title = stringResource(R.string.chat_debug_title)
val safeFailure = DiagnosticsLog.redactReportText(failure)?.take(600)
val ready = socketState == GatewayConnectionState.Ready
val steps = buildList {
if (gateway) {
add(ConnectionSetupTimelineStep(
stringResource(R.string.chat_debug_sign_in),
stringResource(when {
signInRequired -> R.string.chat_debug_sign_in_needed
signedIn -> R.string.chat_debug_authenticated
else -> R.string.chat_debug_auth_unknown
}),
when {
signInRequired -> ConnectionStepState.Failed
signedIn -> ConnectionStepState.Done
else -> ConnectionStepState.Pending
},
))
add(ConnectionSetupTimelineStep(
stringResource(R.string.chat_debug_gateway),
stringResource(when (socketState) {
GatewayConnectionState.Ready -> R.string.chat_debug_socket_ready
GatewayConnectionState.MintingTicket -> R.string.chat_debug_ticket
GatewayConnectionState.Connecting -> R.string.chat_debug_socket_connecting
GatewayConnectionState.AwaitingReady -> R.string.chat_debug_socket_waiting
GatewayConnectionState.Idle -> R.string.chat_debug_socket_idle
}),
when {
ready -> ConnectionStepState.Done
signInRequired -> ConnectionStepState.Failed
socketState != GatewayConnectionState.Idle -> ConnectionStepState.Active
else -> ConnectionStepState.Pending
},
))
}
add(ConnectionSetupTimelineStep(
stringResource(R.string.chat_debug_session),
stringResource(when {
preparing -> R.string.chat_debug_preparing_detail
loadingHistory -> R.string.chat_debug_history_loading
directoryUnavailable -> R.string.chat_debug_history_failed
sessionId != null -> R.string.chat_debug_session_selected
else -> R.string.chat_debug_session_new
}),
when {
preparing || loadingHistory -> ConnectionStepState.Active
directoryUnavailable -> ConnectionStepState.Failed
sessionId != null -> ConnectionStepState.Done
else -> ConnectionStepState.Pending
},
))
add(ConnectionSetupTimelineStep(
stringResource(R.string.chat_debug_response),
stringResource(when {
safeFailure != null -> R.string.chat_debug_response_failed
preparing -> R.string.chat_debug_response_waiting
streaming -> R.string.chat_debug_response_active
else -> R.string.chat_debug_response_idle
}),
when {
safeFailure != null -> ConnectionStepState.Failed
preparing -> ConnectionStepState.Pending
streaming -> ConnectionStepState.Active
else -> ConnectionStepState.Pending
},
))
}
Surface(
modifier = modifier.fillMaxWidth().semantics { paneTitle = title },
shape = RoundedCornerShape(bottomStart = 24.dp, bottomEnd = 24.dp),
color = MaterialTheme.colorScheme.surface,
shadowElevation = 8.dp,
) {
Column(Modifier.heightIn(max = 560.dp).verticalScroll(rememberScrollState()).padding(20.dp),
verticalArrangement = Arrangement.spacedBy(16.dp)) {
Row(verticalAlignment = Alignment.CenterVertically) {
Column(Modifier.weight(1f)) {
Text(title, style = MaterialTheme.typography.titleLarge)
Text(listOf(if (gateway) "Gateway" else "Direct API", profile, model)
.filter(String::isNotBlank).joinToString(" · "), style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant)
}
IconButton(onClick = onClose) {
Icon(Icons.Filled.Close, stringResource(R.string.chat_debug_close))
}
}
ConnectionSetupTimeline(steps)
if (safeFailure != null) {
Surface(color = MaterialTheme.colorScheme.errorContainer, shape = RoundedCornerShape(12.dp)) {
Column(Modifier.padding(12.dp), verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(safeFailure, style = MaterialTheme.typography.bodySmall)
if (safeFailure.contains("agent init failed", ignoreCase = true)) {
Text(stringResource(R.string.chat_debug_init_recovery), style = MaterialTheme.typography.bodySmall)
}
}
}
}
HorizontalDivider()
Text(stringResource(R.string.chat_debug_session_id, sessionId ?: "—"),
style = MaterialTheme.typography.labelSmall, fontFamily = FontFamily.Monospace,
color = MaterialTheme.colorScheme.onSurfaceVariant)
TextButton(onClick = onConnections) { Text(stringResource(R.string.chat_debug_connections)) }
}
}
}
@@ -53,7 +53,13 @@ fun ChatFailurePanel(
Spacer(Modifier.width(10.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.chat_failure_title),
text = stringResource(
if (isInferenceUnavailableFailure(failure.rawError)) {
R.string.chat_failure_inference_unavailable
} else {
R.string.chat_failure_title
},
),
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
@@ -148,3 +154,10 @@ internal fun failureIdentity(route: String, model: String?, provider: String?):
provider?.trim()?.takeIf { it.isNotEmpty() },
model?.trim()?.takeIf { it.isNotEmpty() },
).distinct().joinToString(" · ")
internal fun isInferenceUnavailableFailure(rawError: String): Boolean {
val message = rawError.lowercase()
return "agent init failed" in message ||
"no codex credentials stored" in message ||
"runtime resolution still failed" in message
}
@@ -2,6 +2,7 @@ package com.hermesandroid.relay.ui.components
import android.content.Intent
import android.graphics.BitmapFactory
import android.net.Uri
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
@@ -29,6 +30,7 @@ import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import androidx.compose.ui.Alignment
@@ -97,9 +99,9 @@ private fun isSensitiveAltText(alt: String): Boolean {
/**
* Resolves a server-local image path — an absolute path the agent put in a
* markdown image `![alt](/abs/path)` — to raw bytes, via the relay's
* `/media/by-path` route when a relay session is paired. Returns null when no
* relay is available or the fetch fails, so the renderer falls back to the
* markdown image `![alt](/abs/path)` — to an on-disk cache URI, via the relay's
* authenticated Dashboard route (or Relay compatibility route). Returns a
* failure when no route is available or the fetch fails, so the renderer falls back to the
* "this image is on the server" notice. Provided by ChatScreen from
* [com.hermesandroid.relay.viewmodel.ChatViewModel.resolveServerImage]; the
* default is null, which preserves the standard (no-plugin) behavior where a
@@ -113,12 +115,12 @@ private fun isSensitiveAltText(alt: String): Boolean {
* `RelayServerImage` on app open with a server-local image in history).
*/
sealed interface ServerImageResult {
class Success(val bytes: ByteArray, val sensitive: Boolean = false) : ServerImageResult
class Success(val cachedUri: String, val sensitive: Boolean = false) : ServerImageResult
class Failure(val reason: String) : ServerImageResult
}
fun interface RelayServerImageResolver {
/** Fetch the server-local file's bytes over the relay, or a
/** Fetch the server-local file into the media cache, or a
* [ServerImageResult.Failure] whose reason explains why (unpaired /
* sandboxed / missing / decode) so the UI can surface it instead of a
* generic placeholder. */
@@ -293,8 +295,10 @@ private sealed interface DataUrlImagePhase {
@Composable
private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
var phase by remember(image.src) { mutableStateOf<DataUrlImagePhase>(DataUrlImagePhase.Loading) }
var viewerOpen by remember(image.src) { mutableStateOf(false) }
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
LaunchedEffect(image.src) {
phase = withInlineImageDecodeLock {
@@ -329,17 +333,17 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
reason = "Unsupported or oversized inline image.",
)
is DataUrlImagePhase.Loaded -> {
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Bitmap(
bitmap = current.bitmap,
displayName = image.alt.ifBlank { "image" },
mime = current.mime,
// Decode the already-retained data URL only when the user
// requests Save/Share; don't retain a second byte array.
bytesProvider = { decodeInlineImageDataUrlOffMain(image.src)?.bytes },
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Bitmap(
bitmap = current.bitmap,
displayName = image.alt.ifBlank { "image" },
mime = current.mime,
// Decode the already-retained data URL only when the
// user requests Save/Share; don't keep a second 5 MiB
// byte array beside every thumbnail.
bytesProvider = { decodeInlineImageDataUrlOffMain(image.src)?.bytes },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = image.sensitive,
initiallyRevealed = revealed,
@@ -358,7 +362,19 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = image.sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
)
}
}
@@ -368,18 +384,21 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
@Composable
private fun RemoteChatImage(image: ChatInlineImage, maxWidth: Dp) {
var viewerOpen by remember { mutableStateOf(false) }
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
val blurred = !revealed && shouldBlurImage(blurMode, image.sensitive)
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Coil(
model = image.src,
displayName = image.alt.ifBlank { "image" },
mime = "image/*",
bytesProvider = { MediaSaver.fetchRemoteBytes(image.src).first },
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Coil(
model = image.src,
displayName = image.alt.ifBlank { "image" },
mime = "image/*",
bytesProvider = { MediaSaver.fetchRemoteBytes(image.src).first },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = image.sensitive,
initiallyRevealed = revealed,
@@ -395,7 +414,19 @@ private fun RemoteChatImage(image: ChatInlineImage, maxWidth: Dp) {
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = image.sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
) {
val state by painter.state.collectAsState()
when (state) {
@@ -461,6 +492,7 @@ private fun RelayServerImage(
maxWidth: Dp,
resolver: RelayServerImageResolver,
) {
val context = LocalContext.current
var phase by remember(image.src) {
mutableStateOf<RelayImagePhase>(
cachedInlineImage(image.src)
@@ -473,20 +505,22 @@ private fun RelayServerImage(
phase = withContext(Dispatchers.IO) {
val result = try {
resolver.fetch(image.src)
} catch (t: Throwable) {
ServerImageResult.Failure(t.message ?: "relay fetch failed")
} catch (error: Exception) {
ServerImageResult.Failure(error.message ?: "relay fetch failed")
}
when (result) {
is ServerImageResult.Success -> {
val bytes = result.bytes
val bmp = runCatching {
decodeOrientedBitmap(bytes)
}.getOrNull()?.asImageBitmap()
val cachedUri = Uri.parse(result.cachedUri)
val bmp = try {
decodeBoundedOrientedBitmap(context, cachedUri)
} catch (_: Exception) {
null
}?.asImageBitmap()
if (bmp != null) {
putInlineImage(image.src, bmp, result.sensitive)
RelayImagePhase.Loaded(bmp, result.sensitive)
} else {
RelayImagePhase.Failed("fetched ${bytes.size} B but couldn't decode the image")
RelayImagePhase.Failed("fetched file could not be decoded as an image")
}
}
is ServerImageResult.Failure -> RelayImagePhase.Failed(result.reason)
@@ -527,23 +561,32 @@ private fun RelayServerImageContent(
maxWidth: Dp,
resolver: RelayServerImageResolver,
) {
var viewerOpen by remember { mutableStateOf(false) }
val context = LocalContext.current
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
val sensitive = image.sensitive || fetchedSensitive
val blurred = !revealed && shouldBlurImage(blurMode, sensitive)
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Bitmap(
bitmap = bitmap,
displayName = image.alt.ifBlank {
image.src.substringAfterLast('/').ifBlank { "image" }
},
mime = "image/*",
// Save/Share re-fetch the original bytes on demand so we don't hold
// them in memory next to the decoded bitmap.
bytesProvider = {
(resolver.fetch(image.src) as? ServerImageResult.Success)?.let { fetched ->
context.contentResolver.openInputStream(Uri.parse(fetched.cachedUri))
?.use { it.readBytes() }
}
},
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Bitmap(
bitmap = bitmap,
displayName = image.alt.ifBlank {
image.src.substringAfterLast('/').ifBlank { "image" }
},
mime = "image/*",
// Save/Share re-fetch the original bytes on demand so we don't
// hold them in memory next to the decoded bitmap.
bytesProvider = { (resolver.fetch(image.src) as? ServerImageResult.Success)?.bytes },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = sensitive,
initiallyRevealed = revealed,
@@ -559,7 +602,19 @@ private fun RelayServerImageContent(
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
)
}
}
@@ -2,7 +2,7 @@
package com.hermesandroid.relay.ui.components
import android.widget.Toast
import com.hermesandroid.relay.ui.UiMessageBus
import androidx.compose.foundation.Image
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Arrangement
@@ -107,135 +107,141 @@ fun ChatImageViewer(
onDismissRequest = onDismiss,
properties = DialogProperties(usePlatformDefaultWidth = false),
) {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current
AllowDeviceRotation()
val scope = rememberCoroutineScope()
MessageOverlayScope {
val context = LocalContext.current
val exportAllowed = LocalImageExportAllowed.current
AllowDeviceRotation()
val scope = rememberCoroutineScope()
var busy by remember { mutableStateOf(false) }
var busy by remember { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
var revealed by remember(source) { mutableStateOf(initiallyRevealed) }
val blurred = !revealed && shouldBlurImage(blurMode, sensitive)
val blurMode = LocalMediaBlurMode.current
var revealed by remember(source) { mutableStateOf(initiallyRevealed) }
val blurred = !revealed && shouldBlurImage(blurMode, sensitive)
val gestureModifier = Modifier.fillMaxSize().zoomable()
val gestureModifier = Modifier.fillMaxSize().zoomable()
Box(
modifier = Modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.94f)),
contentAlignment = Alignment.Center,
) {
BlurredMedia(
blurred = blurred,
onReveal = { revealed = true },
modifier = Modifier.fillMaxSize(),
) {
when (source) {
is ChatImageViewerSource.Coil -> AsyncImage(
model = source.model,
contentDescription = source.displayName,
contentScale = ContentScale.Fit,
modifier = gestureModifier,
)
is ChatImageViewerSource.Bitmap -> Image(
bitmap = source.bitmap,
contentDescription = source.displayName,
contentScale = ContentScale.Fit,
modifier = gestureModifier,
)
}
}
if (busy) {
CircularProgressIndicator(color = Color.White)
}
// Control bar — top-right, inset past the status bar / notch.
Row(
Box(
modifier = Modifier
.align(Alignment.TopEnd)
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(8.dp),
horizontalArrangement = Arrangement.spacedBy(4.dp),
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.94f)),
contentAlignment = Alignment.Center,
) {
val tint = IconButtonDefaults.iconButtonColors(contentColor = Color.White)
val cdClose = stringResource(R.string.cd_close_viewer)
val errorMsg = context.getString(R.string.image_viewer_error)
if (exportAllowed) {
val cdShare = stringResource(R.string.cd_share)
val cdSave = stringResource(R.string.cd_save)
IconButton(
onClick = {
scope.launch {
busy = true
val bytes = runCatching { source.bytesProvider() }.getOrNull()
busy = false
if (bytes == null) {
toast(context, errorMsg)
return@launch
}
val uri = MediaSaver.stageForShare(
context,
bytes,
source.displayName,
source.mime,
)
MediaSaver.share(context, uri, source.mime)
}
},
colors = tint,
) {
Icon(Icons.Filled.Share, contentDescription = cdShare)
}
val savedFmt = context.getString(R.string.image_viewer_saved)
val failedFmt = context.getString(R.string.image_viewer_failed)
IconButton(
onClick = {
scope.launch {
busy = true
val bytes = runCatching { source.bytesProvider() }.getOrNull()
if (bytes == null) {
busy = false
toast(context, errorMsg)
return@launch
}
when (val result = MediaSaver.saveImage(context, bytes, source.displayName, source.mime)) {
is MediaSaver.SaveResult.Saved -> {
busy = false
toast(context, savedFmt.format(result.location))
}
MediaSaver.SaveResult.UseShareInstead -> {
busy = false
val uri = MediaSaver.stageForShare(
context,
bytes,
source.displayName,
source.mime,
)
MediaSaver.share(context, uri, source.mime)
}
is MediaSaver.SaveResult.Failed -> {
busy = false
toast(context, failedFmt.format(result.message))
}
}
}
},
colors = tint,
) {
Icon(Icons.Filled.Download, contentDescription = cdSave)
BlurredMedia(
blurred = blurred,
onReveal = { revealed = true },
modifier = Modifier.fillMaxSize(),
) {
when (source) {
is ChatImageViewerSource.Coil -> AsyncImage(
model = source.model,
contentDescription = source.displayName,
contentScale = ContentScale.Fit,
modifier = gestureModifier,
)
is ChatImageViewerSource.Bitmap -> Image(
bitmap = source.bitmap,
contentDescription = source.displayName,
contentScale = ContentScale.Fit,
modifier = gestureModifier,
)
}
}
IconButton(onClick = onDismiss, colors = tint) {
Icon(Icons.Filled.Close, contentDescription = cdClose)
if (busy) {
CircularProgressIndicator(color = Color.White)
}
// Control bar — top-right, inset past the status bar / notch.
Row(
modifier = Modifier
.align(Alignment.TopEnd)
.windowInsetsPadding(WindowInsets.safeDrawing)
.padding(8.dp),
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
val tint = IconButtonDefaults.iconButtonColors(contentColor = Color.White)
val cdClose = stringResource(R.string.cd_close_viewer)
val errorMsg = context.getString(R.string.image_viewer_error)
if (exportAllowed) {
val cdShare = stringResource(R.string.cd_share)
val cdSave = stringResource(R.string.cd_save)
IconButton(
onClick = {
scope.launch {
busy = true
val bytes = try {
source.bytesProvider()
} catch (_: Exception) {
null
}
busy = false
if (bytes == null) {
UiMessageBus.error(errorMsg)
return@launch
}
val uri = MediaSaver.stageForShare(
context,
bytes,
source.displayName,
source.mime,
)
MediaSaver.share(context, uri, source.mime)
}
},
colors = tint,
) {
Icon(Icons.Filled.Share, contentDescription = cdShare)
}
val savedFmt = context.getString(R.string.image_viewer_saved)
val failedFmt = context.getString(R.string.image_viewer_failed)
IconButton(
onClick = {
scope.launch {
busy = true
val bytes = try {
source.bytesProvider()
} catch (_: Exception) {
null
}
if (bytes == null) {
busy = false
UiMessageBus.error(errorMsg)
return@launch
}
when (val result = MediaSaver.saveImage(context, bytes, source.displayName, source.mime)) {
is MediaSaver.SaveResult.Saved -> {
busy = false
UiMessageBus.success(savedFmt.format(result.location))
}
MediaSaver.SaveResult.UseShareInstead -> {
busy = false
val uri = MediaSaver.stageForShare(
context,
bytes,
source.displayName,
source.mime,
)
MediaSaver.share(context, uri, source.mime)
}
is MediaSaver.SaveResult.Failed -> {
busy = false
UiMessageBus.error(failedFmt.format(result.message))
}
}
}
},
colors = tint,
) {
Icon(Icons.Filled.Download, contentDescription = cdSave)
}
}
IconButton(onClick = onDismiss, colors = tint) {
Icon(Icons.Filled.Close, contentDescription = cdClose)
}
}
}
}
}
}
private fun toast(context: android.content.Context, message: String) {
Toast.makeText(context, message, Toast.LENGTH_SHORT).show()
}
@@ -1,5 +1,6 @@
package com.hermesandroid.relay.ui.components
import com.hermesandroid.relay.data.BusyMessageAction
import androidx.compose.animation.AnimatedContent
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.core.tween
@@ -191,6 +192,9 @@ fun ChatInputBar(
physicalEnterSends: Boolean = true,
largePasteThreshold: Int? = null,
onLargePaste: (String) -> Unit = {},
busyAction: BusyMessageAction? = null,
correctionAvailable: Boolean = true,
onBusyActionChange: (BusyMessageAction) -> Unit = {},
) {
val canSubmit = enabled && submitEnabled && trailing in setOf(
ChatInputTrailing.SEND,
@@ -236,7 +240,7 @@ fun ChatInputBar(
// Correction and queueing are materially different actions. Keep the
// explanation, but lead with a visible state pill so the distinction
// does not depend on the trailing icon or accent color alone.
AnimatedVisibility(visible = caption != null) {
AnimatedVisibility(visible = caption != null && busyAction == null) {
val detail = caption ?: lastCaption.orEmpty()
val actionLabel = when (trailing) {
ChatInputTrailing.STEER -> stringResource(R.string.chat_input_steer_response)
@@ -319,6 +323,12 @@ fun ChatInputBar(
)
}
ChatComposerLayers(
action = busyAction,
onActionChange = onBusyActionChange,
correctionAvailable = correctionAvailable,
onStop = onStop.takeUnless { trailing == ChatInputTrailing.STOP },
) {
Surface(
shape = appearanceComposerShape(),
color = MaterialTheme.colorScheme.surfaceContainerHigh,
@@ -646,6 +656,7 @@ fun ChatInputBar(
}
}
}
}
internal data class LargeTextInsertion(
val insertedText: String,
@@ -0,0 +1,146 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.runtime.Composable
import androidx.compose.runtime.CompositionLocalProvider
import androidx.compose.runtime.Stable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.BlurMode
private sealed interface ChatMediaViewerRequest {
val blurMode: BlurMode
val exportAllowed: Boolean
data class SingleAttachment(
val attachment: Attachment,
val initiallyRevealed: Boolean,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
data class AttachmentGallery(
val attachments: List<Attachment>,
val initialIndex: Int,
val initiallyRevealedKeys: Set<String>,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
data class InlineImage(
val source: ChatImageViewerSource,
val sensitive: Boolean,
val initiallyRevealed: Boolean,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
}
@Stable
internal class ChatMediaViewerController {
private var activeRequest by mutableStateOf<ChatMediaViewerRequest?>(null)
internal fun openAttachment(
attachment: Attachment,
initiallyRevealed: Boolean,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.SingleAttachment(
attachment = attachment,
initiallyRevealed = initiallyRevealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun openGallery(
attachments: List<Attachment>,
initialIndex: Int,
initiallyRevealedKeys: Set<String>,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.AttachmentGallery(
attachments = attachments,
initialIndex = initialIndex,
initiallyRevealedKeys = initiallyRevealedKeys,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun openImage(
source: ChatImageViewerSource,
sensitive: Boolean,
initiallyRevealed: Boolean,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.InlineImage(
source = source,
sensitive = sensitive,
initiallyRevealed = initiallyRevealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun dismiss() {
activeRequest = null
}
@Composable
internal fun RenderActiveViewer() {
val request = activeRequest ?: return
CompositionLocalProvider(
LocalMediaBlurMode provides request.blurMode,
LocalImageExportAllowed provides request.exportAllowed,
) {
when (request) {
is ChatMediaViewerRequest.SingleAttachment -> AttachmentViewer(
attachment = request.attachment,
onDismiss = ::dismiss,
initiallyRevealed = request.initiallyRevealed,
)
is ChatMediaViewerRequest.AttachmentGallery -> AttachmentGalleryViewer(
attachments = request.attachments,
initialIndex = request.initialIndex,
onDismiss = ::dismiss,
initiallyRevealedKeys = request.initiallyRevealedKeys,
)
is ChatMediaViewerRequest.InlineImage -> ChatImageViewer(
source = request.source,
onDismiss = ::dismiss,
sensitive = request.sensitive,
initiallyRevealed = request.initiallyRevealed,
)
}
}
}
}
internal val LocalChatMediaViewerController =
staticCompositionLocalOf<ChatMediaViewerController?> { null }
/**
* Owns the active full-screen preview above transcript rows so responsive
* portrait/landscape reflow cannot dispose the viewer with its source bubble.
*/
@Composable
internal fun ChatMediaViewerHost(
vararg ownerKeys: Any?,
content: @Composable () -> Unit,
) {
// A preview never follows a connection/session/policy owner change. Aside
// from avoiding stale media, this makes export permission fail closed when
// supervised policy changes while a viewer is open.
val controller = remember(*ownerKeys) { ChatMediaViewerController() }
CompositionLocalProvider(LocalChatMediaViewerController provides controller) {
content()
controller.RenderActiveViewer()
}
}
@@ -1,6 +1,6 @@
package com.hermesandroid.relay.ui.components
import android.widget.Toast
import com.hermesandroid.relay.ui.UiMessageBus
import androidx.compose.foundation.ExperimentalFoundationApi
import androidx.compose.foundation.combinedClickable
import androidx.compose.foundation.layout.padding
@@ -12,7 +12,6 @@ import androidx.compose.runtime.Composable
import androidx.compose.runtime.remember
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.network.upstream.GatewayAvailability
@@ -21,9 +20,9 @@ import com.hermesandroid.relay.ui.theme.RelayRefresh
enum class ChatTransportTier(val endpointId: String, val label: String) {
Gateway("gateway", "⚡ Gateway"),
Sessions("sessions", "📡 Sessions"),
Completions("completions", "Completions"),
Runs("runs", "Runs"),
Sessions("sessions", "Direct API"),
Completions("completions", "Direct API"),
Runs("runs", "Direct API"),
Offline("offline", "offline"),
}
@@ -67,18 +66,6 @@ fun resolveChatTransportStatus(
detail = "No reachable Hermes chat transport is available.",
)
fun sseFallback(gatewayReason: String): ChatTransportStatus {
if (!serverCapabilities.healthy) return offline(gatewayReason)
val tier = preferredAvailableSseTier(serverCapabilities)
?: return offline(gatewayReason)
return ChatTransportStatus(
tier = tier,
tone = ChatTransportTone.Fallback,
reason = "$gatewayReason → ${tier.plainName()}",
detail = "${tier.detailText()} Using this as the fallback while Gateway is unavailable.",
)
}
fun manualSse(tier: ChatTransportTier, supported: Boolean): ChatTransportStatus {
if (!serverCapabilities.healthy) return offline()
return if (supported) {
@@ -94,23 +81,17 @@ fun resolveChatTransportStatus(
}
return when (preference) {
"auto" -> when {
"auto", "gateway" -> when {
gatewayReady -> ChatTransportStatus(
tier = ChatTransportTier.Gateway,
tone = ChatTransportTone.Active,
reason = "auto → Gateway (best)",
reason = "Gateway connected",
detail = ChatTransportTier.Gateway.detailText(),
)
else -> sseFallback(gatewayFallbackReason(gatewayAvailability))
}
"gateway" -> when {
gatewayReady -> ChatTransportStatus(
tier = ChatTransportTier.Gateway,
tone = ChatTransportTone.Active,
reason = "Gateway selected",
detail = ChatTransportTier.Gateway.detailText(),
else -> unavailable(
ChatTransportTier.Gateway,
gatewayFallbackReason(gatewayAvailability),
)
else -> sseFallback(gatewayFallbackReason(gatewayAvailability))
}
"sessions" -> manualSse(ChatTransportTier.Sessions, serverCapabilities.sessionsChatStream)
"completions" -> manualSse(ChatTransportTier.Completions, serverCapabilities.portable)
@@ -119,42 +100,34 @@ fun resolveChatTransportStatus(
}
}
private fun preferredAvailableSseTier(capabilities: ServerCapabilities): ChatTransportTier? =
when {
capabilities.sessionsChatStream -> ChatTransportTier.Sessions
capabilities.portable -> ChatTransportTier.Completions
capabilities.runs -> ChatTransportTier.Runs
else -> null
}
private fun gatewayFallbackReason(availability: GatewayAvailability): String =
when (availability) {
GatewayAvailability.SignInRequired -> "gateway sign-in required"
GatewayAvailability.Unreachable -> "gateway unavailable"
GatewayAvailability.Unsupported -> "gateway unsupported"
GatewayAvailability.Unknown -> "checking gateway"
GatewayAvailability.Ready -> "gateway ready"
GatewayAvailability.SignInRequired -> "Gateway sign-in required"
GatewayAvailability.Unreachable -> "Gateway unavailable"
GatewayAvailability.Unsupported -> "Gateway unsupported"
GatewayAvailability.Unknown -> "Checking Gateway"
GatewayAvailability.Ready -> "Gateway ready"
}
private fun ChatTransportTier.plainName(): String =
when (this) {
ChatTransportTier.Gateway -> "Gateway"
ChatTransportTier.Sessions -> "Sessions"
ChatTransportTier.Completions -> "Completions"
ChatTransportTier.Runs -> "Runs"
ChatTransportTier.Sessions -> "Direct API"
ChatTransportTier.Completions -> "Direct API"
ChatTransportTier.Runs -> "Direct API"
ChatTransportTier.Offline -> "offline"
}
private fun ChatTransportTier.detailText(): String =
when (this) {
ChatTransportTier.Gateway ->
"Gateway uses the dashboard WebSocket /api/ws for live thinking and rich tool events."
"Hermes Chat uses the signed-in Dashboard connection."
ChatTransportTier.Sessions ->
"Sessions uses /api/sessions/{id}/chat/stream with server-side session history."
"Direct API compatibility chat with server-side session history."
ChatTransportTier.Completions ->
"Completions uses OpenAI-compatible SSE at /v1/chat/completions."
"Direct API compatibility chat."
ChatTransportTier.Runs ->
"Runs uses /v1/runs plus streamed run events."
"Direct API compatibility chat with streamed run events."
ChatTransportTier.Offline ->
"No chat transport is reachable."
}
@@ -166,18 +139,13 @@ fun ChatTransportStatusBadge(
modifier: Modifier = Modifier,
onClick: (() -> Unit)? = null,
) {
val context = LocalContext.current
val textColor = status.textColor()
val background = status.backgroundColor()
Surface(
modifier = modifier.combinedClickable(
onClick = { onClick?.invoke() },
onLongClick = {
Toast.makeText(
context,
"${status.reason}: ${status.detail}",
Toast.LENGTH_LONG,
).show()
UiMessageBus.info("${status.reason}: ${status.detail}")
},
),
shape = RoundedCornerShape(999.dp),
@@ -0,0 +1,103 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.material3.LinearProgressIndicator
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.key
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.LocalFocusManager
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.heading
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.HermesCardClarifyBatch
import kotlinx.serialization.json.Json
/** One mobile question surface; confirmed qids advance without resubmitting earlier answers. */
@Composable
internal fun ClarifyBatchContent(
batch: HermesCardClarifyBatch,
expired: Boolean,
onInputSubmit: (String, String) -> Unit,
) {
val answered = batch.questions.filter { it.answer != null }
val activeIndex = batch.questions.indexOfFirst { it.answer == null }
val active = batch.questions.getOrNull(activeIndex)
var showAnswers by rememberSaveable { mutableStateOf(false) }
val focusManager = LocalFocusManager.current
LaunchedEffect(active?.key, expired) { focusManager.clearFocus() }
Column(Modifier.fillMaxWidth(), verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(
text = when {
expired -> stringResource(R.string.clarify_batch_expired)
active == null -> stringResource(R.string.clarify_batch_complete)
else -> stringResource(R.string.clarify_batch_progress, activeIndex + 1, batch.questions.size)
},
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.semantics { liveRegion = LiveRegionMode.Polite },
)
if (batch.questions.size > 1) {
LinearProgressIndicator(
progress = { answered.size.toFloat() / batch.questions.size },
modifier = Modifier.fillMaxWidth(),
)
}
if (active != null && !expired) {
key(active.key) {
Text(
active.question,
style = MaterialTheme.typography.bodyLarge,
color = MaterialTheme.colorScheme.onSurface,
modifier = Modifier.semantics { heading() },
)
CardInputSlot(
input = active.input,
onSubmit = { if (!active.submitting) onInputSubmit(active.key, it) },
enabled = !active.submitting,
stackedChoices = true,
)
if (active.submitting) {
Text(stringResource(R.string.clarify_batch_sending), style = MaterialTheme.typography.labelMedium)
}
}
}
if (answered.isNotEmpty()) {
if (active == null || expired) {
Text(stringResource(R.string.clarify_batch_answered, answered.size), style = MaterialTheme.typography.labelLarge)
} else {
TextButton(onClick = { showAnswers = !showAnswers }) {
Text(stringResource(R.string.clarify_batch_answered, answered.size))
}
}
if (showAnswers || active == null || expired) {
answered.forEach { question ->
Text(question.question, style = MaterialTheme.typography.labelLarge)
val answer = if (question.input.multiSelect) {
runCatching { Json.decodeFromString<List<String>>(question.answer.orEmpty()).joinToString(", ") }
.getOrDefault(question.answer.orEmpty())
} else question.answer.orEmpty()
Text(answer, style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant)
Spacer(Modifier.height(4.dp))
}
}
}
}
}
@@ -73,7 +73,7 @@ private const val SWIPE_DISMISS_THRESHOLD_PX = 80f
* progress" moment (pairing, long upload, a bridge action sequence). When first
* reused, decouple it from [ConnectionStatusSnapshot] and rename to a generic
* `StatusToast`. It also anchors [UpdateAvailableBanner]'s visual language + the
* shared [ConnectionStepRow]/[StepGlyph] helpers. See TODO.md.
* shared [ConnectionStepRow]/[StepGlyph] helpers. See docs/project/TODO.md.
*
* Rendered as a top-aligned overlay inside a `Box` — it slides down OVER the UI
* without shifting layout. Pair it with `AnimatedVisibility(enter =

Some files were not shown because too many files have changed in this diff Show More