Compare commits

...
Author SHA1 Message Date
Bailey Dixon 23c06d60b9 ci(android): prefer cloud verification lanes 2026-08-31 15:29:06 -04:00
Bailey Dixon 78203fd8a1 Merge pull request #510 from Codename-11/fix/android-generated-image-retention
fix(android): retain generated image results
2026-08-31 14:03:44 -04:00
Bailey Dixon 814afc56da fix(android): retain generated image results 2026-08-31 13:37:22 -04:00
Bailey Dixon 1f055cb91f Merge pull request #507 from Codename-11/fix/android-supervised-gateway-salvage
fix(android): harden supervised Gateway setup
2026-08-31 13:36:26 -04:00
Bailey Dixon 936b9bed8a Merge pull request #508 from Codename-11/feature/android-release-notes-expansion
feat(android): make What's New a complete release record
2026-08-31 13:31:19 -04:00
Bailey Dixon 245362d58e Merge remote-tracking branch 'origin/dev' into feature/android-release-notes-expansion 2026-08-31 13:21:40 -04:00
Bailey Dixon 95e78e0657 Merge pull request #509 from Codename-11/chore/android-build-lane
chore(android): serialize Windows build lanes
2026-08-31 13:14:56 -04:00
Bailey DixonandUpbeat7898 7b390fa99f fix(android): harden supervised gateway setup
Co-authored-by: Upbeat7898 <upbeat7898@noreply.git.meberthosting.de>
2026-08-31 12:47:41 -04:00
Bailey Dixon cd856da6a0 Merge remote-tracking branch 'origin/dev' into feature/android-release-notes-expansion
# Conflicts:
#	app/src/test/kotlin/com/hermesandroid/relay/screenshots/ChangelogHistoryScreenshotTest.kt
#	app/src/test/kotlin/com/hermesandroid/relay/screenshots/WhatsNewToastScreenshotTest.kt
2026-08-31 12:46:18 -04:00
Bailey Dixon 9a40aedb7d chore(android): serialize Windows build lanes 2026-08-31 12:46:03 -04:00
Bailey Dixon 30eb70daa3 Merge pull request #506 from Codename-11/fix/android-whats-new-tests
test(android): refresh v1.14 What's New assertions
2026-08-31 12:14:32 -04:00
Bailey Dixon 6be6cec201 test(android): refresh v1.14 What's New assertions 2026-08-31 12:03:24 -04:00
Bailey Dixon 4f5f3fac10 Merge remote-tracking branch 'origin/dev' into feature/android-release-notes-expansion
# Conflicts:
#	CHANGELOG.md
2026-08-31 11:43:28 -04:00
Bailey Dixon 7f7112caf2 feat(android): expand in-app release notes 2026-08-31 11:42:53 -04:00
Bailey Dixon 4c00e8edb7 Merge pull request #499 from Codename-11/dependabot/github_actions/dev/actions/setup-java-6
chore(deps): bump actions/setup-java from 5 to 6
2026-08-31 11:08:59 -04:00
Bailey Dixon 44f0acec94 Merge pull request #505 from Codename-11/fix/android-bot-chat-binding-lifecycle-refresh
fix(android): render Bot Chat history after binding
2026-08-31 11:08:15 -04:00
Bailey Dixonandlayerflex c8cd13e5bc fix(android): render bot chat history after binding
Preserve the route-owned ChatHandler as the rendered state source from first composition and cover fast/delayed history plus handler replacement and on-device lifecycle recovery.

Supersedes PR #453 while preserving contributor credit.

Co-authored-by: layerflex <254160994+layerflex@users.noreply.github.com>
2026-08-31 10:08:20 -04:00
Bailey Dixon ad4175bb6d test(android): remove obsolete clean chat instrumentation 2026-08-31 10:08:20 -04:00
dependabot[bot] 6b7cb706e0 chore(deps): bump coil from 3.5.0 to 3.6.0 (#502)
Bumps `coil` from 3.5.0 to 3.6.0.

Updates `io.coil-kt.coil3:coil-compose` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.5.0...3.6.0)

Updates `io.coil-kt.coil3:coil-gif` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.5.0...3.6.0)

Updates `io.coil-kt.coil3:coil-network-okhttp` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/coil-kt/coil/releases)
- [Changelog](https://github.com/coil-kt/coil/blob/main/CHANGELOG.md)
- [Commits](https://github.com/coil-kt/coil/compare/3.5.0...3.6.0)

---
updated-dependencies:
- dependency-name: io.coil-kt.coil3:coil-compose
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.coil-kt.coil3:coil-gif
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.coil-kt.coil3:coil-network-okhttp
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 12:00:18 +00:00
dependabot[bot] 6031427ffb chore(deps): bump haze from 1.7.2 to 1.7.3 (#504)
Bumps `haze` from 1.7.2 to 1.7.3.

Updates `dev.chrisbanes.haze:haze` from 1.7.2 to 1.7.3
- [Release notes](https://github.com/chrisbanes/haze/releases)
- [Changelog](https://github.com/chrisbanes/haze/blob/1.7.3/CHANGELOG.md)
- [Commits](https://github.com/chrisbanes/haze/compare/1.7.2...1.7.3)

Updates `dev.chrisbanes.haze:haze-materials` from 1.7.2 to 1.7.3
- [Release notes](https://github.com/chrisbanes/haze/releases)
- [Changelog](https://github.com/chrisbanes/haze/blob/1.7.3/CHANGELOG.md)
- [Commits](https://github.com/chrisbanes/haze/compare/1.7.2...1.7.3)

---
updated-dependencies:
- dependency-name: dev.chrisbanes.haze:haze
  dependency-version: 1.7.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: dev.chrisbanes.haze:haze-materials
  dependency-version: 1.7.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 11:59:10 +00:00
dependabot[bot] 53dd21400a chore(deps): bump org.jetbrains.compose from 1.11.1 to 1.12.0 (#503)
Bumps [org.jetbrains.compose](https://github.com/JetBrains/compose-multiplatform) from 1.11.1 to 1.12.0.
- [Release notes](https://github.com/JetBrains/compose-multiplatform/releases)
- [Changelog](https://github.com/JetBrains/compose-multiplatform/blob/master/CHANGELOG.md)
- [Commits](https://github.com/JetBrains/compose-multiplatform/compare/v1.11.1...v1.12.0)

---
updated-dependencies:
- dependency-name: org.jetbrains.compose
  dependency-version: 1.12.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 11:58:09 +00:00
dependabot[bot] 802a0b0844 chore(deps): bump androidx.navigation:navigation-compose (#501)
Bumps androidx.navigation:navigation-compose from 2.9.8 to 2.10.0.

---
updated-dependencies:
- dependency-name: androidx.navigation:navigation-compose
  dependency-version: 2.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 11:57:10 +00:00
dependabot[bot] 7658329ca7 chore(deps): bump markdown-renderer from 0.44.0 to 0.45.0 (#500)
Bumps `markdown-renderer` from 0.44.0 to 0.45.0.

Updates `com.mikepenz:multiplatform-markdown-renderer-m3` from 0.44.0 to 0.45.0
- [Release notes](https://github.com/mikepenz/multiplatform-markdown-renderer/releases)
- [Changelog](https://github.com/mikepenz/multiplatform-markdown-renderer/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/mikepenz/multiplatform-markdown-renderer/compare/v0.44.0...v0.45.0)

Updates `com.mikepenz:multiplatform-markdown-renderer-code` from 0.44.0 to 0.45.0
- [Release notes](https://github.com/mikepenz/multiplatform-markdown-renderer/releases)
- [Changelog](https://github.com/mikepenz/multiplatform-markdown-renderer/blob/develop/CHANGELOG.md)
- [Commits](https://github.com/mikepenz/multiplatform-markdown-renderer/compare/v0.44.0...v0.45.0)

---
updated-dependencies:
- dependency-name: com.mikepenz:multiplatform-markdown-renderer-m3
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: com.mikepenz:multiplatform-markdown-renderer-code
  dependency-version: 0.45.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 11:56:41 +00:00
dependabot[bot] 1622db0b23 chore(deps): bump the testing group with 2 updates (#498)
Bumps the testing group with 2 updates: [io.github.takahirom.roborazzi:roborazzi](https://github.com/takahirom/roborazzi) and [io.github.takahirom.roborazzi:roborazzi-compose](https://github.com/takahirom/roborazzi).


Updates `io.github.takahirom.roborazzi:roborazzi` from 1.72.0 to 1.73.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.72.0...1.73.0)

Updates `io.github.takahirom.roborazzi:roborazzi-compose` from 1.72.0 to 1.73.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.72.0...1.73.0)

---
updated-dependencies:
- dependency-name: io.github.takahirom.roborazzi:roborazzi
  dependency-version: 1.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
- dependency-name: io.github.takahirom.roborazzi:roborazzi-compose
  dependency-version: 1.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-31 11:56:30 +00:00
dependabot[bot] 41b724e072 chore(deps): bump actions/setup-java from 5 to 6
Bumps [actions/setup-java](https://github.com/actions/setup-java) from 5 to 6.
- [Release notes](https://github.com/actions/setup-java/releases)
- [Commits](https://github.com/actions/setup-java/compare/v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-java
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-08-31 11:56:27 +00:00
Bailey Dixon bca3cd0e48 fix(plugin): harden Git workspace path containment (#492) 2026-08-30 23:30:51 -04:00
Bailey Dixon bb2f1e6c0c fix(plugin): harden Git workspace path containment 2026-08-30 23:28:51 -04:00
Bailey Dixon ff23d54332 Merge pull request #491 from Codename-11/fix/release-desktop-ui-assets
chore(website): refresh desktop UI source fingerprint
2026-08-30 22:28:31 -04:00
Bailey Dixon a4a0575688 chore(website): refresh desktop UI source fingerprint 2026-08-30 22:26:55 -04:00
Bailey Dixon 0509ac8377 Merge pull request #489 from Codename-11/release/android-plugin-cli-2026-08-30
release: prepare Android 1.14.0, Plugin 1.11.0, and CLI+UI beta.6
2026-08-30 22:01:55 -04:00
Bailey Dixon 3fdc2260dd release: prepare Android 1.14.0, Plugin 1.11.0, and CLI+UI beta.6 2026-08-30 21:50:10 -04:00
Bailey Dixon 1800bee7b1 Merge pull request #488 from Codename-11/integration/android-live-fixes
feat: integrate Android live fixes and Dashboard routing
2026-08-30 21:41:19 -04:00
Bailey Dixon 4317b7c2b3 fix(dashboard): scope Relay auth probe health 2026-08-30 21:05:58 -04:00
Bailey Dixon 93fb30150e fix(android): keep relay ingress on authenticated route 2026-08-30 21:02:24 -04:00
Bailey Dixon faf4281486 fix(pairing): omit inactive Tailscale API routes 2026-08-30 20:15:42 -04:00
Bailey Dixon 11dcafc2fe fix(dashboard): render pairing QR at integer scale 2026-08-30 20:14:16 -04:00
Bailey Dixon a57b2b66a1 fix(dashboard): allow Tailscale listener migration cleanup 2026-08-30 20:01:19 -04:00
Bailey Dixon f4acd351f5 fix(dashboard): use dedicated Tailscale listener 2026-08-30 19:58:00 -04:00
Bailey Dixon 8ee772f5fb fix(pairing): prefer dedicated Tailscale listener 2026-08-30 19:56:05 -04:00
Bailey Dixon 6c27bc9cda fix(plugin): dedicate Tailscale dashboard port 2026-08-30 19:55:09 -04:00
Bailey Dixon 460d6cd198 fix(installer): dedicate Tailscale listener port 2026-08-30 19:54:51 -04:00
Bailey Dixon ce63030bcf fix(pairing): reject ambiguous dashboard ingress 2026-08-30 18:15:36 -04:00
Bailey Dixon bd9c077599 fix(android): bind pairing to dashboard ingress route 2026-08-30 18:12:06 -04:00
Bailey Dixon 92f99a4120 fix(pairing): bind relay to selected dashboard origin 2026-08-30 18:02:53 -04:00
Bailey Dixon 85ba13bd04 fix(pairing): prefer recommended Tailscale listener 2026-08-30 15:44:56 -04:00
Bailey Dixon 81347e9c28 fix(dashboard): require Tailscale listener 443 2026-08-30 15:44:29 -04:00
Bailey Dixon 8d260c0eeb fix(dashboard): distinguish Tailscale listener and target 2026-08-30 15:41:27 -04:00
Bailey Dixon ea982c60d4 fix(plugin): separate Tailscale listener from dashboard 2026-08-30 15:37:43 -04:00
Bailey Dixon 8f394e8b18 fix(installer): serve dashboard through Tailscale 443 2026-08-30 15:36:10 -04:00
Bailey Dixon 841e237905 fix(pairing): reject public plaintext routes 2026-08-30 15:11:56 -04:00
Bailey Dixon 6aad90144f fix(android): localize route security status 2026-08-30 15:06:29 -04:00
Bailey Dixon c5df87cd28 feat(dashboard): clarify one-port pairing routes 2026-08-30 15:03:18 -04:00
Bailey Dixon 01533337eb fix(pairing): route new invites through dashboard ingress 2026-08-30 15:02:55 -04:00
Bailey Dixon a4a0fb5741 fix(android): clarify route reachability and security 2026-08-30 15:02:10 -04:00
Bailey Dixon a2ed48ab20 fix(installer): default Tailscale to dashboard ingress 2026-08-30 14:59:07 -04:00
Bailey Dixon ef280979e9 fix(plugin): prefer dashboard Tailscale ingress 2026-08-30 14:58:58 -04:00
Bailey Dixon 0bb0a1e3e2 fix(pairing): make direct relay compatibility explicit 2026-08-30 14:53:11 -04:00
Bailey Dixon 6421d47c96 Merge dashboard plugin UI preview head 2026-08-30 13:58:01 -04:00
Bailey Dixon 523794995a feat(dashboard): redesign Hermes-Relay plugin UI 2026-08-30 13:52:29 -04:00
Bailey Dixon 1c9af237fb fix(android): preserve gateway integration invariants 2026-08-30 13:32:08 -04:00
Bailey Dixon ea7c7cd3e2 Merge dashboard route preview head
# Conflicts:
#	CHANGELOG.md
#	app/src/main/kotlin/com/hermesandroid/relay/ui/screens/ChatScreen.kt
#	app/src/main/kotlin/com/hermesandroid/relay/viewmodel/ChatViewModel.kt
#	app/src/main/kotlin/com/hermesandroid/relay/viewmodel/ConnectionViewModel.kt
#	app/src/main/kotlin/com/hermesandroid/relay/viewmodel/connection/ProfileController.kt
#	app/src/main/res/values-b+pt+BR/strings.xml
#	app/src/main/res/values-b+zh+Hans/strings.xml
#	app/src/main/res/values-de/strings.xml
#	app/src/main/res/values-es/strings.xml
#	app/src/main/res/values-ja/strings.xml
#	app/src/main/res/values-ru/strings.xml
#	app/src/test/kotlin/com/hermesandroid/relay/network/upstream/GatewayChatClientTest.kt
#	docs/decisions.md
#	docs/localization-status.json
2026-08-30 13:02:58 -04:00
Bailey Dixon 41fa23a7f9 feat(android): complete gateway connection integration 2026-08-30 12:51:24 -04:00
Bailey Dixon c6ad31972c test(android): preserve passive Clarify expiry coverage 2026-08-30 03:47:35 -04:00
Bailey Dixon 7091fd7a4a Merge PR #481: subagent preview
# Conflicts:
#	docs/localization-status.json
2026-08-30 03:47:25 -04:00
Bailey Dixon 9b903c87dc Merge PR #472: Clarify input
# Conflicts:
#	CHANGELOG.md
#	docs/localization-status.json
2026-08-30 03:46:24 -04:00
Bailey Dixon a05cc3c941 Merge PR #471: provisional Threads
# Conflicts:
#	CHANGELOG.md
2026-08-30 03:45:27 -04:00
Bailey Dixon 6dfa94b65e Merge PR #475: fresh profile drafts
# Conflicts:
#	CHANGELOG.md
2026-08-30 03:45:00 -04:00
Bailey Dixon cef0771980 Merge PR #476: passive session observation
# Conflicts:
#	CHANGELOG.md
2026-08-30 03:44:23 -04:00
Bailey Dixon b900148f7f Merge PR #480: Assistant launch recovery
# Conflicts:
#	CHANGELOG.md
2026-08-30 03:43:58 -04:00
Bailey Dixon 291fe2e88b Merge PR #478: Voice Focus controls 2026-08-30 03:43:10 -04:00
Bailey Dixon e629cb4947 Merge PR #477: continuous microphone handoff
# Conflicts:
#	CHANGELOG.md
2026-08-30 03:43:01 -04:00
Bailey Dixon 74100fb249 Merge PR #469: wake native runtime 2026-08-30 03:42:37 -04:00
Bailey Dixon 8aa27d6084 fix(android): restore accessible hold controls 2026-08-30 03:30:11 -04:00
Bailey Dixon a894da5fda fix(android): preserve recovered child profile 2026-08-30 00:18:04 -04:00
Bailey Dixon 17446f13d0 fix(android): restore voice focus interruption 2026-08-29 20:42:21 -04:00
Bailey Dixon 89f2f772e2 Merge fix/android-continuous-mic-handoff into fix/android-voice-focus-stop-overlay 2026-08-29 19:25:24 -04:00
Bailey Dixon 3ae19758e4 fix(android): fence stale barge-in capture 2026-08-29 19:23:01 -04:00
Bailey Dixon 734f8074d5 feat(android): animate gateway pair progress 2026-08-29 17:56:33 -04:00
Bailey Dixon 46502c1785 fix(android): unblock gateway sign in handoff 2026-08-29 17:40:44 -04:00
Bailey Dixon 70b9c4e4e3 fix(android): remove gateways from UI immediately 2026-08-29 17:28:22 -04:00
Bailey Dixon 5e10864795 fix(android): stabilize gateway setup completion 2026-08-29 17:15:19 -04:00
Bailey Dixon c8351e03c1 test(android): pin setup navigation hydration 2026-08-29 16:41:43 -04:00
Bailey Dixon 808dfd12a5 fix(android): keep setup navigation mounted 2026-08-29 16:35:18 -04:00
Bailey Dixon 9ce41e366a fix(android): retain onboarding gateway through sign in 2026-08-29 16:22:17 -04:00
Bailey Dixon 4884d077b3 fix(android): activate gateway draft before sign in 2026-08-29 16:12:24 -04:00
Bailey Dixon f47ca00998 fix(android): unify gateway setup and ingress sign in 2026-08-29 15:54:17 -04:00
Bailey Dixon e23ab3fbdf fix(android): clear stale QR state before scanning 2026-08-29 14:47:40 -04:00
Bailey Dixon b862a0a875 fix(android): keep pairing on gateway draft 2026-08-29 14:23:13 -04:00
Bailey Dixon 318a02db49 fix(pairing): preserve relay routes from QR 2026-08-29 13:58:29 -04:00
Bailey Dixon 80e636bc30 feat(android): preview delegated agent activity 2026-08-29 13:37:43 -04:00
Bailey Dixon 578c074797 fix(android): surface assistant capture recovery 2026-08-29 13:37:35 -04:00
Bailey Dixon 23fa69e8d1 fix(android): retain gateway draft through sign in 2026-08-29 10:51:55 -04:00
Bailey Dixon 10f62d798c fix(android): serialize continuous microphone handoff 2026-08-29 10:24:07 -04:00
Bailey Dixon d80b3db329 fix(android): keep passive gateway observation read-only 2026-08-28 23:40:13 -04:00
Bailey Dixon a1d8419dcd feat(android): refocus connections on gateways 2026-08-28 23:12:12 -04:00
Bailey Dixon 258e6f5390 fix(android): keep clarify custom answers reachable 2026-08-28 22:21:53 -04:00
Bailey Dixon 76ead50c60 fix(android): remove provisional threads safely 2026-08-28 22:08:47 -04:00
Bailey Dixon 0213dbf5db fix(android): align wake native runtime 2026-08-28 21:22:28 -04:00
Bailey Dixon 3bddb6fc70 fix(android): reconcile startup with live gateway 2026-08-27 23:27:59 -04:00
Bailey Dixon 729d9ea620 docs: streamline Android device review gates 2026-08-27 22:55:02 -04:00
Bailey Dixon 0ef67814cf fix(android): retain profile sessions through route stalls 2026-08-27 22:39:49 -04:00
Bailey Dixon ee3b31d8ea fix(android): refresh recents after profile switch 2026-08-27 21:28:52 -04:00
Bailey Dixon 6e95f6fe83 Merge remote-tracking branch 'origin/dev' into integration/dashboard-relay-connections
# Conflicts:
#	docs/localization-status.json
2026-08-27 21:01:06 -04:00
Bailey Dixon 08ef5cd08e fix(android): make session drawer loading authoritative 2026-08-27 20:59:52 -04:00
Bailey Dixon e483617c09 Merge remote-tracking branch 'origin/dev' into integration/dashboard-relay-connections 2026-08-27 20:09:27 -04:00
Bailey Dixon 95aca51bd5 fix(desktop): close relay ingress compatibility guard 2026-08-27 19:45:42 -04:00
Bailey Dixon eb94bc92f2 Merge branch 'feature/dashboard-relay-ingress' into integration/dashboard-relay-connections
# Conflicts:
#	app/src/main/kotlin/com/hermesandroid/relay/viewmodel/ConnectionViewModel.kt
#	app/src/test/kotlin/com/hermesandroid/relay/network/relay/ConnectionManagerRouteTest.kt
#	desktop/src/pairingQr.ts
#	desktop/tests/pairingQr.test.ts
#	plugin/dashboard/plugin_api.py
#	plugin/dashboard/test_plugin_api.py
2026-08-27 19:41:57 -04:00
Bailey Dixon 4c0b3038de Merge branch 'fix/android-self-hosted-oidc-399' into integration/dashboard-relay-connections
# Conflicts:
#	DEVLOG.md
2026-08-27 19:39:55 -04:00
Bailey Dixon 380a604ba5 fix(android): settle gateway and session loading promptly 2026-08-27 19:27:59 -04:00
Bailey Dixon 20d7bfe633 fix(android): recover masked dashboard token expiry 2026-08-27 18:41:37 -04:00
Bailey Dixon 68520549a1 fix(android): preserve dashboard sign-in during ticket outages 2026-08-27 18:25:59 -04:00
Bailey Dixon 711b2f945b fix(android): preserve async voice resume recovery 2026-08-26 23:03:48 -04:00
Bailey Dixon 526c5be5ae fix(android): preserve async voice resume recovery 2026-08-26 23:03:35 -04:00
Bailey Dixon 8e2f7d7084 fix(android): fence relay ingress admission 2026-08-26 22:33:44 -04:00
Bailey Dixon ee98432095 fix(android): fence relay ingress admission 2026-08-26 22:33:28 -04:00
Bailey Dixon b432e90dc0 fix(desktop): reject dashboard ingress dials 2026-08-26 22:31:20 -04:00
Bailey Dixon aab1555004 fix(android): authorize relay ingress reconnects 2026-08-26 22:24:44 -04:00
Bailey Dixon a5ec94f669 fix(android): authorize relay ingress reconnects 2026-08-26 22:23:46 -04:00
Bailey Dixon 7621b762e7 test(relay): exercise dashboard websocket ingress 2026-08-26 22:21:27 -04:00
Bailey Dixon 78b0f8c10c fix(desktop): skip dashboard relay ingress 2026-08-26 22:19:42 -04:00
Bailey Dixon bb47acd8f6 docs(relay): track websocket admission follow-up 2026-08-26 22:13:12 -04:00
Bailey Dixon 7d4a0b6096 feat(android): wire dashboard relay ingress 2026-08-26 22:07:09 -04:00
Bailey Dixon d3ff0ef3f7 test(android): cover prefixed relay ingress 2026-08-26 22:02:02 -04:00
Bailey Dixon 0c5d61dfc1 fix(android): recognize prefixed relay ingress 2026-08-26 22:00:38 -04:00
Bailey Dixon ab8a300e8d feat(android): wire dashboard relay ingress 2026-08-26 22:00:14 -04:00
Bailey Dixon 5fa2416cf3 fix(android): recognize prefixed relay ingress 2026-08-26 21:59:55 -04:00
Bailey Dixon f350fe0b82 docs(relay): document dashboard ingress 2026-08-26 21:55:51 -04:00
Bailey Dixon 7ce0825f69 chore(plugin): align manifest dependencies 2026-08-26 21:55:50 -04:00
Bailey Dixon 47b471acb4 feat(relay): add dashboard same-origin ingress 2026-08-26 21:54:56 -04:00
Bailey Dixon 3465b0b2a9 feat(relay): add dashboard same-origin ingress 2026-08-26 21:53:59 -04:00
Bailey Dixon 44d8fea138 Merge origin/dev into fix/android-self-hosted-oidc-399
# Conflicts:
#	DEVLOG.md
#	docs/localization-status.json
2026-08-26 21:38:01 -04:00
Bailey Dixon 3ff307ac6d fix(android): clarify connection ownership and auth 2026-08-26 21:36:20 -04:00
Bailey Dixon 26c8658eb7 Merge remote-tracking branch 'origin/dev' into fix/android-self-hosted-oidc-399 2026-08-26 19:51:20 -04:00
Bailey Dixon 6e2b2d6ca6 fix(android): harden dashboard auth and routing 2026-08-26 19:31:03 -04:00
Bailey Dixon d8fbcd6b16 Merge remote-tracking branch 'origin/dev' into fix/android-self-hosted-oidc-399 2026-08-26 19:13:12 -04:00
Bailey Dixon 0c6edb3fe5 Merge remote-tracking branch 'origin/dev' into fix/android-self-hosted-oidc-399 2026-08-26 18:25:40 -04:00
311 changed files with 33896 additions and 6088 deletions
-38
View File
@@ -1,38 +0,0 @@
## Summary
<!-- Brief description of what this PR does -->
## Changes
-
## Verification
<!-- List the checks you ran, or explain why a check is not applicable. -->
-
## Lineage / contributor credit
<!--
If this PR salvages or supersedes earlier work, link every source PR and name
the original contributor(s). Preserve original commit authors where practical;
otherwise use verified Co-authored-by trailers. Write "N/A" for original work.
-->
- Source PR(s): N/A
- Attribution preserved by: N/A
## Checklist
- [ ] Target branch is `dev`, unless this is a `dev` → `main` release PR or a focused production-tag hotfix PR to `main`
- [ ] Android changes: lint and focused unit tests ran, or rationale is listed above
- [ ] Translation changes: locale status/review references are accurate, `python scripts/check-android-locales.py` ran, and device/emulator review is documented, or N/A
- [ ] Server changes: focused `python -m unittest ...` checks ran, or rationale is listed above
- [ ] Desktop changes: `npm run build` or a narrower documented check ran, or rationale is listed above
- [ ] Docs/site changes: docs build or link check ran, or rationale is listed above
- [ ] UI changes were tested on emulator/device or desktop surface when applicable
- [ ] Commit messages follow [Conventional Commits](https://www.conventionalcommits.org/)
- [ ] CHANGELOG.md updated (if user-facing)
- [ ] Public writing hygiene checked: no secrets, private infrastructure, personal names, or AI/process narration
- [ ] Salvaged work links the source PR and preserves contributor authorship, or N/A
+5 -4
View File
@@ -5,9 +5,8 @@ not `AGENTS.md`) picks up the project's agent guidance.
**Read [AGENTS.md](../AGENTS.md) first — it is the single source of truth**
for agent guidance: the entry point, the non-negotiables, and the public-repo
writing hygiene. It links on to `CLAUDE.md` for the deep reference
(architecture, upstream Hermes API, repository layout, per-language code style,
the dev loop, and the Key Files map). Follow those; don't restate them here.
writing hygiene. `CLAUDE.md` imports that same canonical file. Follow
`AGENTS.md` and its linked project records; don't restate them here.
Quick non-negotiables (the full list and rationale are in `AGENTS.md`):
@@ -17,6 +16,8 @@ Quick non-negotiables (the full list and rationale are in `AGENTS.md`):
- **Conventional Commits**, `main`/`dev` branching — feature branches off
`dev`, `--no-ff` merges, tags cut from `main`.
- **Android:** Jetpack Compose (no XML), kotlinx.serialization (no Gson),
OkHttp (no Ktor), `wss://` only; run `./gradlew lint` before pushing Kotlin.
OkHttp (no Ktor), `wss://` only. Narrow local checks use the Android lane;
pushed exact SHAs prefer `Android On-Demand` for heavy verification; full
local pre-push remains an explicit fallback.
- **Public repo:** no personal names, no private infrastructure, no
AI/assistant self-narration in committed prose.
+7 -2
View File
@@ -16,8 +16,13 @@ function classifyCiPaths(paths) {
android: forceAll || under(['app/', 'relay-core/', 'relay-ui/', 'ui-preview/', 'quest/', 'gradle/']) || exact([
'build.gradle.kts', 'settings.gradle.kts', 'gradle.properties', 'gradlew', 'gradlew.bat',
'scripts/check-android-locales.py', 'scripts/android-locale-harness.py',
'scripts/check-android-collection-apis.py', 'scripts/check-android-release-notes.py',
'scripts/tests/check_android_release_notes_test.py', '.github/workflows/ci-android.yml',
'scripts/check-android-collection-apis.py', 'scripts/check-android-native-compat.py',
'scripts/check-android-release-notes.py',
'scripts/android-lane.ps1', 'scripts/android-prepush.py', 'scripts/dev.bat', 'scripts/dev.sh',
'scripts/tests/android_prepush_test.py',
'scripts/tests/check_android_native_compat_test.py',
'scripts/tests/check_android_release_notes_test.py',
'.github/workflows/android-on-demand.yml', '.github/workflows/ci-android.yml',
'.github/workflows/play-preflight-android.yml',
'.github/workflows/approve-release-android.yml',
'.github/workflows/release-android.yml',
@@ -16,6 +16,14 @@ assert.deepEqual(classifyCiPaths(['README.md']), none);
assert.deepEqual(classifyCiPaths(['desktop/src/cli.ts']), { ...none, desktop: true });
assert.deepEqual(classifyCiPaths(['relay-core/src/main/kotlin/Wire.kt']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/check-android-release-notes.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/check-android-native-compat.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/check_android_native_compat_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-lane.ps1']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-prepush.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/dev.bat']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/dev.sh']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/android_prepush_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/android-on-demand.yml']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['plugin/relay/server.py']), { ...none, plugin: true });
assert.deepEqual(classifyCiPaths(['plugin/dashboard/src/App.tsx']), { ...none, dashboard: true });
assert.deepEqual(classifyCiPaths(['user-docs/index.md']), { ...none, docs: true });
+227
View File
@@ -0,0 +1,227 @@
name: Android On-Demand
run-name: Android ${{ inputs.preset }} · ${{ inputs.head_sha }}
on:
workflow_dispatch:
inputs:
head_sha:
description: Exact pushed commit SHA to verify
required: true
type: string
preset:
description: Android verification lane
required: true
default: focused
type: choice
options:
- focused
- lint
- assemble-debug
- release-smoke
- all-final
permissions:
contents: read
concurrency:
group: android-on-demand-${{ inputs.head_sha }}-${{ inputs.preset }}
cancel-in-progress: false
jobs:
validate:
name: Validate exact SHA
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- name: Validate input shape
shell: bash
env:
REQUESTED_SHA: ${{ inputs.head_sha }}
run: |
if [[ ! "$REQUESTED_SHA" =~ ^[0-9a-f]{40}$ ]]; then
echo "head_sha must be a full lowercase 40-character commit SHA" >&2
exit 2
fi
- name: Checkout exact commit
uses: actions/checkout@v7
with:
ref: ${{ inputs.head_sha }}
fetch-depth: 1
- name: Confirm checkout identity
shell: bash
env:
REQUESTED_SHA: ${{ inputs.head_sha }}
run: test "$(git rev-parse HEAD)" = "$REQUESTED_SHA"
focused:
name: Focused Android checks
needs: validate
if: ${{ inputs.preset == 'focused' || inputs.preset == 'all-final' }}
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.head_sha }}
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
- uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: true
- name: Run repository checks and focused sideload tests
run: python3 scripts/android-prepush.py --skip-lint
- name: Run the same focused tests for Google Play
shell: bash
run: |
mapfile -t focused_tests < <(python3 -c \
"import runpy; print(*runpy.run_path('scripts/android-prepush.py')['FOCUSED_TESTS'], sep='\n')")
test_args=()
for test_name in "${focused_tests[@]}"; do
test_args+=(--tests "$test_name")
done
./gradlew :app:testGooglePlayDebugUnitTest "${test_args[@]}" --console=plain
- name: Upload failed test reports
uses: actions/upload-artifact@v7
if: failure()
with:
name: focused-test-reports-${{ inputs.head_sha }}
path: app/build/reports/tests/
if-no-files-found: ignore
retention-days: 7
lint:
name: Android lint
needs: validate
if: ${{ inputs.preset == 'lint' || inputs.preset == 'all-final' }}
runs-on: ubuntu-latest
timeout-minutes: 20
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.head_sha }}
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
- uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: true
- name: Validate Android repository inputs
run: |
python3 scripts/check-android-locales.py
python3 scripts/check-user-docs-locales.py
python3 scripts/check-android-collection-apis.py
python3 scripts/check-android-release-notes.py
python3 scripts/check-version-tracks.py
if [[ -f scripts/tests/android_prepush_test.py ]]; then
python3 -m unittest scripts.tests.android_prepush_test
fi
python3 -m unittest scripts.tests.check_android_release_notes_test
python3 -m unittest scripts.tests.check_android_native_compat_test
- name: Run Android lint
run: ./gradlew lint --console=plain
- name: Upload lint reports
uses: actions/upload-artifact@v7
if: always()
with:
name: lint-reports-${{ inputs.head_sha }}
path: app/build/reports/lint-results*
if-no-files-found: ignore
retention-days: 7
assemble-debug:
name: Assemble both debug flavors
needs: validate
if: ${{ inputs.preset == 'assemble-debug' || inputs.preset == 'all-final' }}
runs-on: ubuntu-latest
timeout-minutes: 25
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.head_sha }}
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
- uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: true
- name: Build debug APKs
run: ./gradlew assembleDebug --console=plain
- name: Verify packaged native compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/debug/*.apk \
app/build/outputs/apk/sideload/debug/*.apk
- name: Upload debug APKs
uses: actions/upload-artifact@v7
with:
name: debug-apks-${{ inputs.head_sha }}
path: app/build/outputs/apk/*/debug/*.apk
if-no-files-found: error
retention-days: 7
release-smoke:
name: Release build smoke
needs: validate
if: ${{ inputs.preset == 'release-smoke' || inputs.preset == 'all-final' }}
runs-on: ubuntu-latest
timeout-minutes: 35
steps:
- uses: actions/checkout@v7
with:
ref: ${{ inputs.head_sha }}
- uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
- uses: gradle/actions/setup-gradle@v6.3.0
with:
cache-read-only: true
- name: Build release bundles and APKs
run: ./gradlew bundleRelease assembleRelease --console=plain
- name: Scan release DEX for unsupported collection APIs
run: |
python3 scripts/check-android-collection-apis.py \
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
- name: Verify packaged native compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
- name: Upload release smoke artifacts
uses: actions/upload-artifact@v7
with:
name: release-smoke-${{ inputs.head_sha }}
path: |
app/build/outputs/apk/*/release/*.apk
app/build/outputs/bundle/**/*.aab
if-no-files-found: error
retention-days: 7
+28 -4
View File
@@ -30,12 +30,20 @@ on:
- "gradle.properties"
- "gradlew"
- "gradlew.bat"
- "scripts/android-lane.ps1"
- "scripts/android-prepush.py"
- "scripts/dev.bat"
- "scripts/dev.sh"
- "scripts/tests/android_prepush_test.py"
- "scripts/check-android-locales.py"
- "scripts/android-locale-harness.py"
- "scripts/check-android-collection-apis.py"
- "scripts/check-android-native-compat.py"
- "scripts/check-android-release-notes.py"
- "scripts/tests/check_android_native_compat_test.py"
- "scripts/tests/check_android_release_notes_test.py"
- ".github/workflows/ci-android.yml"
- ".github/workflows/android-on-demand.yml"
- ".github/workflows/play-preflight-android.yml"
- ".github/workflows/approve-release-android.yml"
- ".github/workflows/release-android.yml"
@@ -59,7 +67,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -78,8 +86,12 @@ jobs:
- name: Validate Android release notes
run: |
python3 scripts/check-android-release-notes.py
python3 -m unittest scripts.tests.android_prepush_test
python3 -m unittest scripts.tests.check_android_release_notes_test
- name: Test Android native compatibility checker
run: python3 -m unittest scripts.tests.check_android_native_compat_test
- name: Run Android lint
run: ./gradlew lint --console=plain
@@ -96,7 +108,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -109,6 +121,12 @@ jobs:
- name: Build debug APK
run: ./gradlew assembleDebug --console=plain
- name: Verify packaged ONNX Runtime compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/debug/*.apk \
app/build/outputs/apk/sideload/debug/*.apk
- name: Upload debug APK
uses: actions/upload-artifact@v7
if: ${{ github.ref == 'refs/heads/main' }}
@@ -140,7 +158,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -204,7 +222,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -225,3 +243,9 @@ jobs:
python3 scripts/check-android-collection-apis.py \
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
- name: Verify packaged ONNX Runtime compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
+1 -1
View File
@@ -70,7 +70,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
+1 -1
View File
@@ -68,7 +68,7 @@ jobs:
fi
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
+15 -2
View File
@@ -137,7 +137,7 @@ jobs:
ref: ${{ github.event_name == 'workflow_dispatch' && format('android-v{0}', inputs.version) || github.ref }}
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -176,7 +176,7 @@ jobs:
ref: ${{ github.event_name == 'workflow_dispatch' && format('android-v{0}', inputs.version) || github.ref }}
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
@@ -263,6 +263,19 @@ jobs:
python3 scripts/check-android-collection-apis.py \
--apk app/build/outputs/apk/sideload/candidate/*.apk
- name: Verify stable packaged ONNX Runtime compatibility
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
- name: Verify candidate packaged ONNX Runtime compatibility
if: ${{ needs.validate.outputs.prerelease == 'true' }}
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/sideload/candidate/*.apk
- name: List produced artifacts (debug aid)
run: |
echo "=== APK outputs ==="
+1 -1
View File
@@ -83,7 +83,7 @@ jobs:
run: test "$(git rev-parse HEAD)" = "$EXPECTED_SHA"
- name: Set up JDK 17
uses: actions/setup-java@v5
uses: actions/setup-java@v6
with:
distribution: temurin
java-version: 17
+17 -5
View File
@@ -7,12 +7,14 @@ coding agent (Claude Code, Codex, Cursor, etc.).
This file is the provider-neutral canonical agent context. Read it before
touching code, then `docs/spec.md` and `docs/decisions.md`. Provider adapters
such as **[CLAUDE.md](CLAUDE.md)** may add tool-specific guidance, but they do
not redefine the branch, release, or hotfix policy here and in `RELEASE.md`.
such as **[CLAUDE.md](CLAUDE.md)** import this file instead of duplicating
policy. They do not redefine the branch, release, hotfix, or verification
contract here and in `RELEASE.md`.
- Release process → **[RELEASE.md](RELEASE.md)**
- Contributor setup → **[CONTRIBUTING.md](CONTRIBUTING.md)**
- Gateway/session/reconnect testing → **[docs/gateway-contract-testing.md](docs/gateway-contract-testing.md)**
- Android local/cloud verification → **[docs/android-build-lane.md](docs/android-build-lane.md)**
- `android_*` toolset + MCP → **[docs/mcp-tooling.md](docs/mcp-tooling.md)**
- Follow-ups / deferred work / known gaps → **[TODO.md](TODO.md)** (the single home for "what's next" — never DEVLOG, never scattered code comments)
@@ -83,11 +85,21 @@ PR; never resolve those cases by choosing a side automatically.
Version bumps happen only on a release-prep branch targeting `dev`, and
production tags are cut only from `main`.
- **Android:** Jetpack Compose only (no XML), kotlinx.serialization (no Gson),
OkHttp (no Ktor), `wss://` only. Run `./gradlew lint` before pushing Kotlin.
OkHttp (no Ktor), `wss://` only. While editing, use only the narrow local
compile or focused test needed for feedback, through `scripts/android-lane.ps1`
on Windows. Once an exact commit is already pushed, prefer the `Android
On-Demand` workflow for lint, the focused shards, both-flavor assemblies, and
release smoke; isolated cloud jobs may run concurrently. Do not push solely
to obtain cloud compute without push authorization, and do not duplicate a
preset already running for the same SHA. Full local verification remains
available through `scripts/dev.bat prepush` (or `./scripts/dev.sh prepush`)
when explicitly wanted or when cloud execution is unavailable.
Physical-device checks and APK installation remain separately owned local
evidence.
- **Plugin (Python 3.11+):** aiohttp + asyncio (no threading), type hints
everywhere, structured `logging` (no `print`). **Desktop CLI (Node ≥21):**
zero runtime deps, strict TS + ES modules, ship compiled `dist/`. Full
per-language style and the dev loop live in CLAUDE.md → "Code Style".
zero runtime deps, strict TS + ES modules, ship compiled `dist/`. Contributor
commands and the development loop live in `CONTRIBUTING.md`.
## Review guidelines
+54 -3
View File
@@ -6,24 +6,75 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
### Changed
- **Android What's New now provides a readable, complete release record.** One overall title and summary lead into selected highlights, every remaining user-visible addition, improvement, and fix, and relevant compatibility boundaries. Toast counts and previews are derived from that same inventory, so View all no longer promises details the expanded dialog and history cannot show.
### Fixed
- **Android Bot Chats render loaded history immediately.** Route-owned chat screens observe their own handler state from first composition, including fast history loads that settle before another frame. (Supersedes #453.)
- **Supervised Gateway setup stays parent-owned.** Add Gateway is single-flight and checks live parent authority before allocating a draft, relock/back cancels the exact pending setup, and the locked Chat footer no longer attempts protected navigation.
- **Generated images stay visible and use their intended Chat animation.** Completed image media survives a marker-lagging history refresh, and both the built-in `image_generate` tool and profile tools ending in `_create_image` use the image-generation presentation.
## [Android 1.14.0] - 2026-08-30
### Added
- **Android presents Relay Git as a first-class native workspace.** A compact optional Chat rail opens repository status, line totals, filters, diffs, branches, staging, commits, and remotes; the full workspace remains available from Settings when Chat controls are hidden.
- **Hermes-Relay Plugin provides a bounded Git workspace API for authenticated Dashboard clients.** Configured repository roots, path validation, tracked line totals, scoped write grants, and explicit confirmation protect repository reads and mutations.
- **Android can preview delegated agent work without leaving the parent chat.** The current-chat activity sheet shows bounded lifecycle, progress, and tool previews for concurrent children, opens vanilla Hermes child history read-only when the Gateway exposes it, and stays explicit when reconnect gaps or older routes leave details unavailable. (#447)
- **Android presents Relay Git as a first-class native workspace.** A compact optional Chat rail opens repository status, line totals, filters, diffs, branches, staging, commits, and remotes; the full workspace remains available from Settings when Chat controls are hidden. An updated optional Hermes-Relay Plugin is required for Git operations.
### Changed
- **Connections now explain and recover each Dashboard, Relay, and optional API route independently.** LAN, Tailscale, and public HTTPS can fail over without allowing an unauthenticated or different-origin Relay route to borrow Dashboard credentials. Protected same-origin Relay health challenges are recognized as authentication boundaries instead of outages. An updated optional Hermes-Relay Plugin is required for same-origin Relay ingress. (Related: #399)
- **Android What's New leads with one curated release highlight without interrupting startup.** A timed post-update toast can be swiped or closed, previews additional feature/fix counts when a release has meaningful secondary items, expands into the centered highlight view on request, and keeps the full technical history available. Each release can present one plain-language summary, up to three primary benefits, and up to two quieter improvements, while release checks keep the structured entry, fallback, Play copy, and public release records aligned.
### Fixed
- **Android wake-word detection now loads a compatible native ONNX Runtime.** Packaged sherpa and Java JNI consumers are checked against the shared runtime for every supported ABI before release. (#444)
- **Android Continuous voice waits for barge-in microphone teardown before listening again.** Multi-turn hands-free conversations no longer lose the microphone after a response finishes with barge-in enabled. (#464)
- **Opening Android no longer claims or interrupts a turn already running in Hermes Desktop/TUI.** Passive foreground and session browsing now use read-only Gateway status plus profile-scoped history; live-session resume remains reserved for explicit Android actions and exact Android-owned recovery. (Related: #365)
- **Android provisional Threads can be removed without touching server history.** The drawer now offers a local-only removal action, reconciles promoted phone sessions without duplicate rows, and keeps Thread routing isolated to the active saved connection. (#461)
- **Android Clarify cards make custom answers explicit and keyboard-friendly.** Choice prompts label their Other answer field, submit trimmed text from the keyboard, and do not restore an authoritatively expired prompt after session navigation. (#446)
- **The visible Android Sphere keeps its smooth procedural motion across startup and chat.** Backgrounded and motion-disabled surfaces remain still without reducing foreground animation to a stepped ambient pulse.
- **Android New Chat keeps the current profile and stays fresh across profile switches.** Starting from All Profiles no longer forces the literal default profile, choosing another profile from an empty draft no longer reopens that profile's previous session after route settlement or restart, and leaving a provisional phone Thread cannot route the next turn to its old chat under the new profile.
- **Android Voice Focus keeps Stop and immediate spoken steering available across every interaction mode.** Hold-to-talk now interrupts Thinking and Transcribing turns before capturing the replacement direction, remains operable through TalkBack, Switch Access, and keyboard controls, preserves pointer press-and-release behavior across floating controls, and Google Play no longer offers the sideload-only system overlay action.
- **Android Assistant sessions explain when no speech was captured instead of appearing stuck at Ready.** Retry feedback survives the separate system overlay process, recreated session UI requests the current turn state, and locked sessions keep transcript, response, and technical error text private. (Related: #424)
- **Android New Chat keeps the current profile and stays fresh across profile switches.** Starting from All Profiles no longer forces the literal default profile, choosing another profile from an empty draft no longer reopens that profile's previous session after route settlement or restart, and leaving a provisional phone Thread cannot route the next turn to its old chat under the new profile. (#436)
- **Android Dashboard connections and profile drawers no longer wait on unavailable optional routes.** Dashboard, API fallback, and Relay probes run independently; API/Relay never gate a normal Dashboard connection, Gateway auth/ticket failures are not blindly retried, and authenticated session history remains available without a live Gateway socket. Concurrent route probes are shared and generation-safe, healthy same-priority routes win immediately, superseded session reads cancel their HTTP calls, and optional PR decoration stays outside the session-list critical path.
### Removed
- **Android Chat no longer includes the hidden clean-focus presentation.** The long-press gesture, overlapping instructional pill, reduced composer, and alternate fading transcript were removed so Chat keeps one complete interaction model. Voice Focus remains available.
## [Plugin 1.11.0] - 2026-08-30
### Added
- **Hermes-Relay Plugin provides a bounded Git workspace API for authenticated Dashboard clients.** Configured repository roots, path validation, tracked line totals, scoped write grants, and explicit confirmation protect repository reads and mutations.
- **Relay extensions can use the authenticated Dashboard origin as one network ingress.** Fixed allowlisted HTTP and WebSocket paths proxy to the local Relay while Dashboard admission and Relay session authentication remain separate. (Related: #399)
### Changed
- **Hermes-Relay Dashboard management is organized around operator tasks.** Overview, Devices, Activity, Remote Access, Git, and Settings now have separate native Dashboard surfaces; pairing is QR-first, paired clients use responsive cards, and token-backed media is labeled as a bounded diagnostic instead of a health counter. (#486)
- **Dashboard, CLI, and TUI pairing advertise the same explicit route set.** Recommended Tailscale uses dedicated HTTPS `:10443` for local Dashboard `:9119`, public HTTPS and LAN stay visible fallbacks, and old `:443`/`:9119` plus direct `:8767` remain migration compatibility.
- **Pairing receipts explain transport protection before exposing an invite.** Per-surface probes distinguish application TLS, tailnet encryption, optional API fallback, and authenticated Relay ingress.
### Fixed
- **Public and roaming pairing no longer invent closed direct Relay or Dashboard ports.** Exact Dashboard origins own their same-origin Relay paths, ambiguous or plaintext public candidates fail closed, and inactive optional API routes are omitted.
- **Dense pairing QRs scan reliably.** Dashboard, CLI, and TUI render integer-sized modules with a full quiet zone.
- **Remote-access migration keeps existing listeners safe.** Recommended setup avoids taking over `:443`, explicit legacy cleanup remains available, and default disable actions remove only the listeners they own.
## [0.4.0-beta.6] - 2026-08-30
### Changed
- **Hermes-Relay CLI+UI preserves the complete multi-route pairing topology.** Dashboard, Relay, optional API, priorities, and transport protection remain attached to one saved host across LAN, Tailscale, and public routes. (Related: #399)
### Fixed
- **Desktop rejects Dashboard-ingress Relay dials until it can mint Dashboard WebSocket tickets.** The daemon and host selector choose a compatible direct Relay fallback instead of attempting an unauthenticated same-origin ingress.
- **API-less pairing remains valid.** Dashboard and direct Relay routes can pair without inventing an optional API server, while secure-first ranking keeps plain LAN as the final fallback.
## [Android 1.13.2] - 2026-08-25
### Added
+1 -525
View File
@@ -1,525 +1 @@
# Hermes-Relay — Claude Code Adapter
> Read [AGENTS.md](AGENTS.md) first. It is the provider-neutral canonical agent
> context. Branch, release, staging, and hotfix rules live in `AGENTS.md` and
> [RELEASE.md](RELEASE.md); this file only adds Claude-specific project and tool
> guidance. Then read `docs/spec.md` and `docs/decisions.md`.
## What This Is
A native Android app (Kotlin + Jetpack Compose) paired with an optional Python relay plugin/server (aiohttp) for the Hermes agent platform. Vanilla Hermes chat, Manage, and dashboard voice work against unmodified upstream Hermes. The Relay plugin adds phone control, terminal, remote desktop tooling, extra voice engines, and dashboard Relay management via the official Hermes web dashboard.
**Current state:** Reference latest released version for stable state and current dev branch for working state. The default no-plugin path supports chat, Manage, and voice on vanilla upstream Hermes. Chat auto-prefers the dashboard `/api/ws` gateway transport when Manage auth is ready, then falls back to API-server SSE routes. Vanilla Hermes voice uses dashboard `/api/audio/*` with the Manage session. Relay remains an additive power path for terminal, bridge/device control, notification companion, extra/provider-native voice, remote access, and desktop tooling. Two Android product flavors ship: `googlePlay` (conservative, no unattended Device Control surface) and `sideload` (full-capability).
## Architecture
```
Phone (WS) -> Hermes dashboard (:9119) [vanilla Hermes gateway chat, live thinking]
Phone (HTTP/SSE) -> Hermes API Server (:8642) [vanilla Hermes chat fallback, sessions, runs]
Phone (HTTP) -> Hermes dashboard (:9119) [vanilla Hermes Manage + voice]
Phone (WSS/HTTP) -> Relay plugin/server (:8767) [optional bridge, terminal, relay voice, remote tools]
```
The Vanilla Hermes path must stay upstream-only. API-server bearer auth and dashboard cookie auth are separate. Terminal and bridge require Relay pairing; Vanilla Hermes chat, Manage, and dashboard voice must not.
### Upstream Hermes API Reference
**IMPORTANT:** Always verify endpoints against the actual hermes-agent source (`gateway/platforms/api_server.py`). The upstream repo is the source of truth — not our docs, not our memory, not assumptions from other frontends.
**Vanilla Hermes endpoints (confirmed in hermes-agent source):**
| Endpoint | Purpose | Tool Call Format |
| --------------------------------------- | -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------ |
| `POST /v1/chat/completions` | OpenAI-compatible chat (stream=true for SSE) | Inline markdown text (``💻 terminal``) — no separate tool events |
| `POST /v1/runs` | Start an agent run | Returns `run_id` |
| `GET /v1/runs/{run_id}/events` | SSE stream of run lifecycle events | **Structured events**: `tool.started`, `tool.completed`, `message.delta`, `reasoning.available`, `run.completed`, `run.failed` |
| `POST /v1/responses` | OpenAI Responses API format | Structured `function_call` objects (non-streaming only) |
| `GET /v1/capabilities` | Machine-readable feature + endpoint discovery | Use before assuming optional surfaces exist |
| `GET /v1/models` | List available models | — |
| `GET /v1/skills` | Read-only skill list for the API-server agent | `{"object":"list","data":[...]}` |
| `GET /v1/toolsets` | Read-only API-server toolset inventory | `{"object":"list","platform":"api_server","data":[...]}` |
| `GET/POST/PATCH/DELETE /api/sessions/*` | Native session CRUD, messages, fork, sync chat, SSE chat | Upstream merged via NousResearch/hermes-agent PR #33134 |
| `GET /health` | Health check | — |
| `GET/POST/PATCH/DELETE /api/jobs/*` | Cron job management (api_server surface) | — |
**Compatibility endpoints (not all native upstream API-server routes):**
Upstream main now contains the focused session-control API (`#33134`) and read-only skills/toolsets (`#33016`). The original broad PR [#8556](https://github.com/NousResearch/hermes-agent/pull/8556) was closed as superseded. Keep these distinctions straight:
1. **Native upstream** — `/api/sessions`, `/api/sessions/{id}/messages`, `/api/sessions/{id}/chat`, `/api/sessions/{id}/chat/stream`, `/v1/capabilities`, `/v1/skills`, and `/v1/toolsets` exist in current `gateway/platforms/api_server.py`.
2. **Bootstrap compatibility** (`plugin/hermes_relay_bootstrap/`) — monkey-patches aiohttp on startup via `.pth` file, injecting only compatibility-only surfaces (session search, memory, legacy skill detail/toggle, config, available-models, slash middleware). Sessions CRUD/messages/fork and the legacy skills list are **retired** — native upstream owns them (#33134/#33016) and the bootstrap carries no fallback for old builds. Native routes still win per method/path for the remaining set. The repo-root `hermes_relay_bootstrap/` package is a legacy import shim.
3. **Legacy fork branches** — useful as lineage only. Do not cite `feat/session-api` / `#8556` as the current upstream contract.
| Endpoint | Purpose | Provided by |
| -------------------------------------- | -------------------------------------- | -------------------------------------------------------------------------------------- |
| `GET /api/sessions` (CRUD) | Session list/create/rename/delete/fork | Native upstream (#33134); bootstrap injection retired |
| `GET /api/sessions/{id}/messages` | Conversation history | Native upstream (#33134); bootstrap injection retired |
| `POST /api/sessions/{id}/chat` | Synchronous session chat | Native upstream (#33134) |
| `POST /api/sessions/{id}/chat/stream` | Session-based SSE chat | Native upstream (#33134); bootstrap does NOT inject |
| `GET /v1/skills`, `GET /v1/toolsets` | Read-only skill/toolset discovery | Native upstream (#33016) |
| `GET /api/sessions/search` | Full-text message search | Bootstrap/fork legacy; not in current upstream main |
| `GET /api/config`, `PATCH /api/config` | Personalities + model config | Bootstrap/fork legacy or dashboard web-server surface; not current API-server upstream |
| `GET /api/skills/{name}` | Legacy skill detail | Bootstrap compat; list (`GET /api/skills`) retired — use native `/v1/skills` |
| `PUT /api/skills/toggle` | Enable/disable installed skill | `hermes_cli/web_server.py` dashboard surface; bootstrap stub returns 501 |
| `GET/POST/PATCH/DELETE /api/memory` | Memory CRUD | Bootstrap/fork legacy; not current API-server upstream |
| `GET /api/available-models` | Provider model list | Bootstrap/fork legacy; not current API-server upstream |
The Android client probes per-endpoint capability via `HermesApiClient.probeCapabilities()` (returns `ServerCapabilities`). When `streamingEndpoint = "auto"`, `ConnectionViewModel.resolveStreamingEndpoint()` picks `sessions`, `completions`, or `runs` based on the capability snapshot.
**Dashboard web server (separate surface — standard Manage / Desktop remote gateway):**
hermes-agent ships a second web server at `hermes_cli/web_server.py` that hosts the React admin dashboard at `hermes_cli/web_dist/`. It has its **own** `/api/*` routes that **do not live on `api_server.py`** — notably: `GET/PUT /api/config` (full tree), `GET /api/config/schema`, `GET /api/config/defaults`, `GET/PUT /api/config/raw` (YAML text), `GET/PUT/DELETE /api/env` + `POST /api/env/reveal`, `PUT /api/skills/toggle`, `/api/cron/jobs/*` (different shape from `/api/jobs/*`), `/api/providers/oauth/*`, `/api/dashboard/themes`, `/api/dashboard/plugins`, `/api/model/info` + `/api/model/options` + `POST /api/model/set`, `/api/profiles/*` (CRUD, `POST /api/profiles/active`, per-profile soul/description/model), `/api/mcp/*`, `/api/logs`, `/api/analytics/usage`, and `**POST /api/audio/transcribe` + `POST /api/audio/speak`** (base64 data-url contract, built for hermes-desktop voice). The API server has **no audio routes** — its `/v1/capabilities` advertises `audio_api: false`; PR #8199 (`/v1/audio/*`) is the canonical future surface but is unmerged. Android's **Vanilla Hermes (no-plugin) voice** therefore rides this dashboard surface via `StandardHermesVoiceClient` with the per-connection dashboard cookie session (Manage sign-in unlocks voice); `AutoVoiceAudioClient` prefers Relay when paired and falls back to standard.
Current upstream supports two auth modes on this surface. Loopback dashboards still use the injected `window.__HERMES_SESSION_TOKEN__` path. Remote/non-loopback dashboards use the Desktop-style dashboard auth gate: `/api/status` advertises `auth_required` and providers, `/auth/password-login` handles password providers, `/auth/login?provider=...` handles Nous/OIDC redirects, `/api/auth/me` returns the verified session, and `/api/auth/ws-ticket` mints a short-lived ticket for `/api/ws` / `/api/pty`. This dashboard session is **not** an `API_SERVER_KEY`. Android uses it for Manage, Vanilla Hermes voice, and the gateway chat transport. `/api/ws` is backed by `tui_gateway/server.py` (what hermes-desktop + the Ink TUI speak) and is the only upstream surface with **live** `reasoning.delta`/`thinking.delta` streaming; the api_server SSE paths remain the SSE fallback. Relay-only capabilities remain behind Relay pairing. **Do not proxy dashboard auth or dashboard admin APIs over the relay.**
**Tool call rendering paths:**
1. **Runs API** — Emits `tool.started`/`tool.completed` as real SSE events → `ToolProgressCard` in real-time.
2. **Sessions API** — Native upstream emits structured SSE (`run.started`, `message.started`, `assistant.delta`, `tool.progress`, `tool.started/completed/failed`, `assistant.completed`, `run.completed`, `done`). `run.completed.messages` can reconcile authoritative per-turn transcript.
3. **Annotation parser** — Fallback for servers emitting inline markdown annotations (``💻 terminal``).
## Key Instructions
- **Vanilla Hermes path = upstream-only.** The default (no-plugin) connection path — gateway/API chat, Manage, and Vanilla Hermes voice via the dashboard surface — must work against **unmodified upstream hermes-agent**: no fork patches, no bespoke server config as a dependency. The app ships on Google Play to users whose servers we don't control. Features that need server-side changes go through upstream PRs (with graceful degradation until merged) or live behind the opt-in relay plugin.
- **Always verify upstream before assuming an endpoint exists.** Check `gateway/platforms/api_server.py` in hermes-agent. If an endpoint isn't there, document whether bootstrap injects it or it requires the fork.
- If we use a non-standard endpoint, ensure `probeCapabilities()` covers it and the auto-resolver degrades gracefully.
- **Bootstrap maintenance:** Retire `plugin/hermes_relay_bootstrap/` per surface. Done: sessions CRUD/messages/fork and the legacy skills list are retired from the bootstrap (native upstream #33134/#33016, no old-build fallback kept). Remaining: config, memory, legacy skill detail/toggle, available-models, session search, and slash middleware still need explicit replacement decisions before full removal.
## Repository Layout
```
hermes-android/
├── app/src/main/kotlin/com/hermesandroid/relay/
│ ├── ui/ # Screens, components, theme
│ ├── network/ # ConnectionManager, ChannelMultiplexer, handlers
│ ├── auth/ # AuthManager (pairing + tokens)
│ ├── viewmodel/ # ChatViewModel, ConnectionViewModel
│ ├── data/ # ChatMessage, ToolCall models, FeatureFlags
│ ├── audio/ # VoiceRecorder, VoicePlayer, VoiceSfxPlayer
│ ├── voice/ # VoiceViewModel, VoiceBridgeIntentHandler
│ ├── accessibility/ # HermesAccessibilityService, ScreenReader, ActionExecutor
│ ├── bridge/ # BridgeSafetyManager, BridgeForegroundService, BridgeStatusOverlay
│ └── notifications/ # HermesNotificationCompanion
├── relay-core/ ← [EXPERIMENTAL] Quest/XR shared core lib (com.axiomlabs.hermesrelay.core) — pairing, transport, terminal, voice, wire
├── relay-ui/ ← [EXPERIMENTAL] Quest/XR shared Compose UI lib — sphere, terminal WebView, QR scanner
├── quest/ ← [EXPERIMENTAL] Meta Spatial SDK Quest/XR app (gradle includeBuild; in development, not shipped)
├── ui-preview/ ← Desktop Compose Hot Reload harness for PC UI iteration (NOT shipped; shares MorphingSphereCore)
├── desktop/ ← Node thin-client CLI (`@hermes-relay/cli`)
│ ├── bin/hermes-relay.js # #!/usr/bin/env node shim → dist/cli.js
│ ├── src/
│ │ ├── cli.ts # argv parser + subcommand dispatcher (bare → shell)
│ │ ├── commands/ # chat, shell, pair, status, tools, devices
│ │ ├── banner.ts # contextual connect line (LAN / Tailscale / Plain / Secure)
│ │ ├── renderer.ts # GatewayEvent → plain-line stdout formatter (chat only)
│ │ ├── endpoint.ts # ADR 24 EndpointCandidate + role helpers
│ │ ├── pairingQr.ts # v3 QR decode + priority-raced reachability probe
│ │ ├── pairing.ts # readline 6-char prompt + payload validator
│ │ ├── credentials.ts # token → pair-qr → code → stored → prompt precedence
│ │ ├── certPin.ts # TOFU SPKI sha256 extract / pinKey / compare
│ │ ├── tools/ # desktop.command router + fs/terminal/search handlers + consent
│ │ ├── transport/ # RelayTransport (reconnect state machine + TLS probe TOFU)
│ │ └── lib/ # gracefulExit, rpc, circularBuffer (vendored)
│ └── scripts/ # install.sh + install.ps1 curl/iwr one-liners
├── website/ ← Astro product/marketing site (static Coolify/Nixpacks deployment)
├── plugin/ ← Hermes agent plugin
│ ├── android_tool.py # 18 android_* tool handlers
│ ├── pair.py # QR pairing implementation
│ ├── relay/ # Canonical WSS relay (server.py, auth.py, channels/, media.py, voice.py)
│ ├── tools/ # android_navigate.py, android_notifications.py
│ └── dashboard/ # hermes-agent dashboard plugin — manifest, React UI, FastAPI proxy
├── relay_server/ ← Thin compat shim → plugin.relay (legacy entrypoint)
├── hermes_relay_bootstrap/ ← Legacy import shim for older startup hooks
├── skills/devops/hermes-relay-pair/ ← /hermes-relay-pair slash command
├── scripts/ ← dev.bat, bridge-smoke.sh, bump-version.sh
└── docs/ ← spec, decisions, security, relay-server, mcp-tooling
```
## Project Conventions
### File Structure
- **Root-level:** README.md, CLAUDE.md, AGENTS.md, DEVLOG.md, TODO.md, .gitignore
- **docs/** — spec, decisions, security, and any other long-form documentation
- **DEVLOG.md** — update at end of each work session with what was done + verification (the factual record of *what happened*). It churns; do NOT park forward work here.
- **TODO.md** — the single home for follow-ups / deferred work / known gaps ("what's next"). Record them here — never buried in DEVLOG or scattered through code/doc comments where they get lost.
- **CLAUDE.md hygiene:** Key Files entries must stay one line — implementation detail belongs in the file or `docs/`. Run `/revise-claude-md` after feature-heavy sessions to trim drift.
### Public-repo writing hygiene
This is a **public, distributed repo** — every committed file (CHANGELOG, DEVLOG, README, docs, release notes) is public-facing. Write accordingly:
- **No personal names** in prose — attribute impersonally ("a user reported", "observed"). Author identity lives in git history + the signing cert, not the changelog.
- **No private infrastructure** — real server hostnames/IPs, internal deployment names, `~/SYSTEM.md` contents. (Generic example IPs like `192.168.1.100` in setup docs are fine.)
- **No AI/assistant process self-narration** — no "I should have…", no course-correction confessionals. State the technical conclusion, not the path to it.
- **No internal jargon / fork-branch plumbing** in user-facing notes — keep *what changed*, drop *where we staged it*.
- **CHANGELOG** uses Keep-a-Changelog grouping (Added / Changed / Fixed). Detail may accumulate during iteration, but at **release-prep the version block is condensed to crisp public bullets** (1–2 lines each) — deep "how we debugged it" stays in commits/DEVLOG. See [RELEASE.md](RELEASE.md) §2 "Scrub for public distribution".
- **DEVLOG.md** is a committed, factual engineering log — what changed, why, and verification — depersonalized and third-person, not a diary.
### Code Style — Android (Kotlin)
- **Jetpack Compose** — no XML layouts. Material 3 / Material You.
- **kotlinx.serialization** — not Gson. Type-safe, faster.
- **OkHttp** for WebSocket + SSE — `okhttp` for WSS relay, `okhttp-sse` for API streaming
- **Single-activity** — Compose Navigation for all routing
- **Namespace (Kotlin source tree):** `com.hermesandroid.relay` — stable, drives on-disk layout + class FQCNs
- **applicationId:** `com.axiomlabs.hermesrelay` (googlePlay), `com.axiomlabs.hermesrelay.sideload` (sideload)
- **Min SDK 26, Target SDK 35, Compile SDK 37** / **Kotlin 2.0+**, JVM toolchain 17
### Code Style — Desktop CLI (Node/TypeScript)
- **Node ≥21** — uses built-in global `WebSocket` (no `ws`/`undici` dep). Strict TS, ES modules, `NodeNext` resolution.
- **Zero runtime deps** — `@types/node` + `tsx`/`rimraf`/`typescript` are devDeps only. Ship compiled `dist/`, not tsx.
- **One binary, subcommands** — idiomatic for Node CLIs (codex, continue, vite pattern). Bare invocation is `chat`.
- **Vendor-for-now** — transport/gateway/types are copied verbatim from `hermes-agent-tui-smoke/ui-tui/src/` with a header note. Extract to a shared package when the TUI and CLI stabilize.
- **Dev loop:** `npx tsx src/cli.ts <args>` (no rebuild). `npm run build` + `npm link` before pushing to verify the bin shim. Never ship tsx in the published tarball — pre-build with `tsc` so Windows `npm install -g` can cmd-shim the JS directly.
### Code Style — Server (Python)
- **aiohttp** — async, matches existing Hermes relay patterns
- **Type hints everywhere** — Python 3.11+ syntax
- **asyncio** — no threading; **structured logging** — use `logging`, not print()
### Git
- **Conventional Commits:** `feat`, `fix`, `docs`, `refactor`, `test`, `chore`
- **Branch/release policy:** follow the branch-contract table in `AGENTS.md` and
the executable release and hotfix procedures in `RELEASE.md`. Do not maintain
a Claude-specific parallel policy here.
### Testing
- **Android:** JUnit + Compose testing for UI, MockK for mocks
- **Gateway/session/reconnect work:** follow the on-demand scenario,
current-upstream conformance, Android instrumentation, and physical-proof
routing in `docs/gateway-contract-testing.md`; do not infer device behavior
from fixture or source checks.
- **Python:** `python -m unittest plugin.tests.test_<name>` — avoid bare `pytest` (conftest imports `responses` which may not be installed in the venv)
- **CI and release gates:** follow the repository-wide requirements in
`AGENTS.md` and `RELEASE.md`; Claude-specific guidance does not redefine them.
## Key Files
| File | Why |
| ----------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `docs/spec.md` | Full specification — protocol, UI layouts, phases, dependencies |
| `docs/decisions.md` | Architecture decisions — framework choice, channel design, auth model |
| `docs/gateway-contract-testing.md` | On-demand reusable Gateway scenarios, upstream conformance, Android instrumentation, and ADB certification |
| `AGENTS.md` | Universal agent entry point — points here + the non-negotiables (standard-path, commits, writing hygiene) |
| `docs/mcp-tooling.md` | MCP server setup — android-tools-mcp + mobile-mcp; `android_*` tool usage patterns |
| **App — Core** | |
| `ui/RelayApp.kt` | Main scaffold (Scaffold + Compose nav); Chat is home — no mode strip, Manage/Bridge reached via Settings; `bottomBar` is a status pill, not a NavigationBar |
| `viewmodel/ChatViewModel.kt` | Chat orchestration — send, stream, cancel, slash commands |
| `viewmodel/ConnectionViewModel.kt` | Dual connection model (API + relay); `resolveStreamingEndpoint()`; derived `relayUiState` flow + `markPaired` hook stamp the active Connection |
| `viewmodel/RelayUiState.kt` | Shared sealed state for the relay row — 5 cases + `asBadgeState()` / `statusText()` extensions; 5s grace window before Stale |
| `network/HermesApiClient.kt` | Direct HTTP/SSE — `sendRunStream()`, `sendChatStream()`, `probeCapabilities()` |
| `network/GatewayChatClient.kt` | Gateway chat transport — JSON-RPC over dashboard `/api/ws` (tui_gateway); live `reasoning.delta`; fresh ws-ticket per connect; per-turn SSE fallback via `onPreflightFailure`; `prewarm()` (connect+resume off the send path); `setKeepAliveInBackground()` suppresses the 120s idle-close |
| `network/GatewayKeepAliveService.kt` | Opt-in `specialUse` foreground service (BOTH flavors; declared in main manifest; Play needs a Console FGS declaration) holding the process up so the gateway socket survives background/Doze; driven by ConnectionViewModel from the `KEY_GATEWAY_KEEP_ALIVE` toggle; stops on task-removal |
| `data/GatewayKeepAlivePrefs.kt` | Shared `KEY_GATEWAY_KEEP_ALIVE` pref key + `Context.setGatewayKeepAlive()` — used by ConnectionViewModel (StateFlow/setter) and the FGS Stop action |
| `network/GatewayEventMapper.kt` | Pure-JVM gateway event→callback mapping for one turn; unknown event types silently ignored; tui_gateway usage-key translation |
| `network/GatewayModels.kt` | `GatewayAvailability`, `ActiveTurnHandle`, `GatewayTurnCallbacks` (all members REQUIRED — forces dispatchOn main-thread wrap), `GatewayAsk`, `GatewaySubagentEvent`, `resolveStreamingEndpointPreference()` |
| `ui/components/ChatInputBar.kt` | Redesigned input bar — pill field, one trailing slot morphing Send/Voice/Stop/Steer/Queue, no slash button (long-press + opens palette) |
| `ui/components/SubagentLane.kt` | Per-taskIndex subagent progress lane — guide rail, compact tool rows, auto-collapse |
| `notifications/TurnCompleteNotifier.kt` | Turn-complete local notification when backgrounded — channel `chat_turn_complete`, cancel on resume, settings-gated |
| `network/ConnectionManager.kt` | WSS to relay with auto-reconnect; rebuilds OkHttpClient with fresh CertPinner on connect |
| `network/ChannelMultiplexer.kt` | Envelope routing by channel; `sendNotification()` for notification outbound |
| `network/handlers/ChatHandler.kt` | Chat message state, streaming events, tool annotation parser |
| `network/models/SessionModels.kt` | Session, message, SSE event data models |
| `data/FeatureFlags.kt` | Feature gating — DEV_MODE + DataStore overrides; `BuildFlavor` (googlePlay/sideload Tier flags) |
| **App — Auth** | |
| `auth/AuthManager.kt` | Wires SessionTokenStore + CertPinStore; parses auth.ok; `applyServerIssuedCodeAndReset()` |
| `auth/SessionTokenStore.kt` | Keystore (StrongBox) + EncryptedSharedPrefs fallback; lossless migration on upgrade |
| `auth/CertPinStore.kt` | TOFU cert pinning — SHA-256 SPKI per host:port in DataStore |
| `auth/PairedSession.kt` | PairedSession state + PairedDeviceInfo wire model |
| `data/Endpoint.kt` | `EndpointCandidate` / `ApiEndpoint` / `RelayEndpoint` — multi-endpoint pairing (ADR 24); `displayLabel()` for LAN/Tailscale/Public/Custom chips |
| `network/RelayHttpClient.kt` | OkHttp for /media, /sessions (list/revoke/extend), /health |
| **App — Bridge** | |
| `network/handlers/BridgeCommandHandler.kt` | Routes `bridge.command` → ActionExecutor; full path inventory + safety-rail integration |
| `viewmodel/BridgeViewModel.kt` | BridgeScreen VM — masterToggle, bridgeStatus, permissionStatus, activityLog |
| `bridge/BridgeSafetyManager.kt` | Connection-scoped capabilities + timed screen expiry + blocklist + destructive confirmation; unknown, denied, and expired commands fail closed |
| `bridge/BridgeCapabilities.kt` / `data/BridgeCapabilityPolicyRepository.kt` | Closed method/path registry + no-backup-bound per-Connection Always/Never/Timed policy; global safety vocabulary and timer duration remain in `BridgeSafetyPreferences.kt` |
| `ui/screens/BridgeScreen.kt` | Bridge cockpit — master → Agent access posture/setup → single Unattended Access control → capability-scoped Android readiness (expandable full matrix) → Advanced safety/full editor → activity log |
| `ui/components/BridgeAccessCards.kt` | Native access cockpit + first-use preset and screen-lease sheets (renewable idle limits or warned Until-off dedicated-device mode); preserves full permission/safety drilldowns while keeping selected policy/readiness above the fold |
| `ui/components/UnattendedAccessRow.kt` | Unattended toggle card (sideload); `enabled=masterEnabled`; inline `KeyguardDetectedAlert` |
| `ui/components/UnattendedGlobalBanner.kt` | 28dp amber strip at scaffold top when master+unattended on (sideload); tap → Bridge tab |
| `bridge/BridgeStatusOverlay.kt` | WindowManager overlay; `ConfirmationOverlayHost`; requires `SavedStateRegistryOwner` init order (CREATED→restore→RESUMED) |
| `accessibility/HermesAccessibilityService.kt` | AccessibilityService subclass; `@Volatile instance` singleton for BridgeCommandHandler |
| `accessibility/ScreenReader.kt` | UI tree → ScreenContent; `findNodeBoundsByText()`, `findFocusedInput()` |
| `accessibility/ActionExecutor.kt` | Gesture/text dispatch via GestureDescription + ACTION_SET_TEXT; pressKey maps vocab only |
| **App — Voice** | |
| `voice/VoiceViewModel.kt` | Voice turn state machine; TTS queue; `ignoreAssistantId`; `errorEvents: SharedFlow` |
| `audio/VoiceRecorder.kt` | MediaRecorder wrapper; perceptual amplitude curve; `.m4a` at 16kHz/64kbps |
| `audio/VoicePlayer.kt` | Media3 ExoPlayer (gapless TTS queue) + Visualizer; amplitude StateFlow; `awaitCompletion()` via coroutine; `audioSessionId` is a thread-safe `@Volatile` cache |
| `network/RelayVoiceClient.kt` | OkHttp for `/voice/transcribe`, `/synthesize`, `/config` |
| `voice/VoiceBridgeIntentHandler.kt` | Interface routing voice utterances to bridge; impls per flavor via factory |
| `voice/VoiceIntentClassifier.kt` | Regex phone-control classifier (sideload only); false-negatives preferred over false-positives |
| `ui/components/VoiceModeOverlay.kt` | Full-screen voice UI — MorphingSphere + VoiceWaveform + mic button |
| `ui/components/MorphingSphere.kt` | Compose renderer for the agent sphere — delegates math to `MorphingSphereCore` |
| `ui/components/MorphingSphereCore.kt` | Platform-agnostic sphere algorithm (`kotlin.math` only) — single source of truth; mirrored byte-for-byte in `preview/web/sphere.js` |
| `preview/web/` | Zero-dep browser harness — live `index.html` preview + `parity-check.mjs`; paired with `MorphingSphereCoreParityTest` (JVM) for struct/full checksum diffing |
| `user-docs/.vitepress/theme/components/SphereMark.vue` | Docs-site sphere embed — imports `preview/web/sphere.js` directly; autonomous fbm drift + pointer-proximity gaze/state blend; `<ClientOnly>` + `IntersectionObserver` + `prefers-reduced-motion` aware |
| **App — Media + Notifications** | |
| `util/MediaCacheWriter.kt` | `cacheDir/hermes-media/` LRU writer; returns FileProvider URIs |
| `util/MediaSaver.kt` | Save/share/open for chat media — MediaStore scoped-storage save (Pictures/Download `Hermes-Relay`, no perms on API 29+; pre-Q → share sheet); FileProvider share staging; remote-byte fetch; magic-byte image-MIME sniff for correct extensions |
| `ui/components/ChatImageViewer.kt` | Full-screen image viewer — pinch-zoom/pan (`detectTransformGestures`), double-tap 1×/2.5×, Share/Save/Close; `ChatImageViewerSource` decouples Coil-model/bitmap display from a suspend `bytesProvider` so Save keeps original bytes |
| `ui/components/InboundAttachmentCard.kt` | Discord-style attachment card for images/video/audio/pdf/text/generic; image tap → ChatImageViewer, file card long-press → Open/Share/Save menu |
| `ui/components/ChatImageContent.kt` | Parses `![alt](src)` out of assistant content; remote http(s) → Coil (tap → ChatImageViewer), server-local/failed → inline "can't render" notice with the path |
| `data/HermesCard.kt` | `CARD:{json}` envelope (ADR 26) — type/accent/fields/actions; kotlinx.serialization |
| `ui/components/HermesCardBubble.kt` | Rich-card renderer — accent stripe + FlowRow actions + dispatch stamp collapse |
| `viewmodel/CardDispatchSyncBuilder.kt` | Twin of VoiceIntentSyncBuilder — synthesizes card dispatches as `hermes_card_action` OpenAI pairs for session memory |
| `notifications/HermesNotificationCompanion.kt` | NotificationListenerService; cold-start buffer (50); forwards via ChannelMultiplexer |
| `util/RelayErrorClassifier.kt` | `classifyError(Throwable, context) → HumanError`; used by Voice/Chat/Connection |
| `util/TurnLatencyTracer.kt` | One `TurnLatency` INFO line per chat turn — `warm/cold` + `connect/session/submit/ttfe/ttft/done@…ms`; gateway + 3 SSE paths use it for desktop-comparable latency diagnosis; durations only |
| **Relay — Server** | |
| `plugin/relay/server.py` | Canonical relay — WSS + HTTP routes; bridge, media, voice, session, pairing handlers. `handle_pairing_mint` mirrors `pair.py:762` — top-level = API server, `relay.{url,code}` nested |
| `plugin/relay/auth.py` | PairingManager, SessionManager, RateLimiter; `math.inf` for never-expire |
| `plugin/relay/channels/bridge.py` | Bridge handler — `handle_command()` mints request_id, awaits response, 30s timeout |
| `plugin/relay/channels/notifications.py` | Bounded deque (100) of notification metadata; in-memory only |
| `plugin/relay/media.py` | MediaRegistry — LRU token store; `strict_sandbox` off by default for `/media/by-path` |
| `plugin/relay/voice.py` | Voice endpoints — transcribe, synthesize, voice_config; lazy tool imports |
| `plugin/relay/qr_sign.py` | HMAC-SHA256 QR signing; secret at `~/.hermes/hermes-relay-qr-secret`; canonical form preserves `endpoints` array order + role strings verbatim (ADR 24) |
| `plugin/relay/tailscale.py` | First-class Tailscale helper (ADR 25) — `status()` / `enable(port)` / `disable(port)` / `canonical_upstream_present()`; safe-absent via shell-out to `tailscale` CLI |
| `plugin/relay/_env_bootstrap.py` | Loads `~/.hermes/.env` before relay imports; called from both entry points |
| **Plugin — Tools + Installer** | |
| `plugin/tools/android_tool.py` | 18 `android_*` tool handlers (14 baseline + send_sms, call, search_contacts, return_to_hermes); `android_screenshot` first consumer of `register_media()` |
| `plugin/tools/android_navigate.py` | Vision-driven navigation loop; up to 20 iterations; `llm_gap` error until vision client wired |
| `plugin/pair.py` | QR payload builder + CLI; `build_payload(sign=True)`; `--register-code` fallback |
| `plugin/doctor.py` | `hermes relay doctor`; checks standard upstream API/dashboard reachability, Relay loopback state, plugin layout, and compat hook state |
| `plugin/compat.py` | `hermes relay compat status/install/remove`; owns the optional `hermes_relay_bootstrap.pth` lifecycle |
| `plugin/hermes_relay_bootstrap/` | Plugin-owned runtime compatibility patch — compat-only surfaces (session search, memory, skill detail/toggle, config, available-models, slash middleware); sessions + skills-list injection retired (#33134/#33016) |
| `install.sh` | Canonical installer — 6 steps; idempotent; drops `hermes-relay-update` shim |
| `uninstall.sh` | Canonical uninstaller; reverses install.sh; never touches `.env` or `state.db` |
| `hermes_relay_bootstrap/` | Legacy import shim for old `.pth` files and editable installs |
| **Plugin — Dashboard** | |
| `plugin/dashboard/manifest.json` | Declares tab, entry bundle, and FastAPI module for hermes-agent discovery |
| `plugin/dashboard/plugin_api.py` | FastAPI router proxying 5 routes to relay over loopback; `/pairing` body = API-server overrides (host/port/tls/api_key), relay URL auto-derived |
| `plugin/dashboard/src/index.jsx` | React root registering `hermes-relay` plugin with 4-tab shell |
| `plugin/dashboard/dist/index.js` | Committed IIFE bundle loaded verbatim by dashboard |
| **Desktop CLI** | |
| `desktop/package.json` | `@hermes-relay/cli` package manifest — Node ≥21, one `hermes-relay` bin, pre-built dist |
| `desktop/bin/hermes-relay.js` | Tiny shim: `import('../dist/cli.js').then(m => m.main())` + error surfacing |
| `desktop/src/chatAttach.ts` | captureClipboardImage / captureScreenshot / readImageFile; ships base64 to server via `image.attach.bytes` RPC before next prompt.submit |
| `desktop/src/cli.ts` | argv parser + subcommand dispatcher — bare → `shell` (PTY), positional-only → `chat`; command-scoped `--help` falls through to each command |
| `desktop/src/lib/theme.ts` | Shared ANSI palette + `colorEnabled()` + `Theme` (semantic helpers, `statusDot`) — single visual language; `--no-color`/`NO_COLOR`/TTY aware |
| `desktop/src/lib/table.ts` | Zero-dep column-aligned table renderer (ANSI-width aware, last column flexes to terminal width) — used by devices/sessions/audit |
| `desktop/src/lib/spinner.ts` | Stderr braille spinner for slow ops (pair probe, gateway connect); no-op when piped/quiet/json |
| `desktop/src/lib/usage.ts` | `UsageSpec` + `renderUsage`/`printUsage`/`unknownSubcommand` — per-subcommand `--help` + self-documenting sub-verb fallback |
| `desktop/src/lib/hints.ts` | `suggestedFix(err, ctx)` → next-step command (re-pair on auth fail, etc.); `formatError` renders error + hint |
| `desktop/src/lib/logo.ts` | Slim box-drawing "Hermes Relay" wordmark; shown atop `--help`, first-run welcome, REPL header, and `hermes-relay logo`; theme/no-color aware |
| `desktop/src/lib/auditLog.ts` | Local desktop-tool audit JSONL (`~/.hermes/desktop-audit.jsonl`); router appends per dispatch; backs `audit` command (relay's ring is loopback-only) |
| `desktop/src/lib/daemonStatus.ts` | Daemon heartbeat file (`~/.hermes/daemon-status.json`) + `isPidAlive` liveness; backs `daemon --status` |
| `desktop/src/commands/audit.ts` | `hermes-relay audit` — tails the local audit log into a table (WHEN/TOOL/STATUS/DETAIL); `--limit`, `--json` |
| `desktop/src/commands/relay.ts` | `hermes-relay relay info/security/context/queue` — relay-server management surface; info/security/queue loopback-only, context works remote with bearer; `queue` lists/cancels the agent→phone outbound buffer (`--clear` / `--cancel <id>`) |
| `desktop/src/commands/chat.ts` | REPL + one-shot + piped-stdin; `runOneTurn` returns `{promise, cancel}` for safe SIGINT; auto-wires `DesktopToolRouter` when consented |
| `desktop/src/commands/shell.ts` | Pipes the `terminal` relay channel to raw-mode stdin/stdout; post-attach `exec hermes` 350ms after tmux settles; `Ctrl+A .` detach / `Ctrl+A k` kill / `Ctrl+A Ctrl+A` literal |
| `desktop/src/commands/pair.ts` | Either 6-char code + `--remote`, or full v3 QR via `--pair-qr` — probes + picks endpoint, records role; `--grant-tools` (TTY prompt) / `--auto-grant-tools` (silent) stamp `toolsConsented` so `daemon` works without a `shell` round-trip |
| `desktop/src/commands/tools.ts` | `tools.list` RPC → enabled/available toolsets; `--verbose` lists individual tools |
| `desktop/src/commands/status.ts` | Local read of `~/.hermes/remote-sessions.json`; renders `grants:` + `expires:` + `route:`; `--json` redacts tokens, `--reveal-tokens` opts in |
| `desktop/src/commands/devices.ts` | Server-side session management — `GET/DELETE/PATCH /sessions` via `fetch` over http(s)://host:port; `list` / `revoke <prefix>` / `extend <prefix> --ttl <s>` |
| `desktop/src/banner.ts` | `buildConnectBanner({url, meta, endpointRole})` → "Connected via LAN (plain) — server 0.6.0"; `humanExpiry()` for TTL formatting |
| `desktop/src/endpoint.ts` | `EndpointCandidate` / `EndpointRole` types + `displayLabel()` — mirrors Android `data/Endpoint.kt` |
| `desktop/src/pairingQr.ts` | `decodePairingPayload` (JSON or base64), `payloadToCandidates` (v3 verbatim / v1–v2 synthesized), `probeCandidatesByPriority` (`Promise.any` within tier, `AbortSignal.any`, 4s timeout, 60s cache) |
| `desktop/src/certPin.ts` | `extractSpkiSha256(der)` via `crypto.X509Certificate` + `publicKey.export({type:'spki'})`; `pinKey(url)`, `comparePins()`, `isSecureUrl()` |
| `desktop/src/tools/router.ts` | `DesktopToolRouter.attach(relay)` — `onChannel('desktop')` dispatch under 30s `AbortController`; heartbeat enriched with host/platform/version/uptime_ms + sticky `last_error` for `desktop_health` |
| `desktop/src/tools/handlerSet.ts` | Single source of truth for the desktop tool map — `DESKTOP_HANDLERS` + `DESKTOP_ADVERTISED_TOOLS`; consumed by `chat.ts` / `shell.ts` / `daemon.ts` so adding a tool is a one-file change |
| `desktop/src/tools/consent.ts` | `ensureToolsConsent(url)` — stored per-URL in `toolsConsented`; TTY prompt; non-TTY fails closed |
| `desktop/src/tools/handlers/fs.ts` | `readFileHandler` / `writeFileHandler` / `patchHandler` — strict unified-diff applier, no fuzz |
| `desktop/src/tools/handlers/terminal.ts` | `bash -lc` / `cmd /c`, SIGKILL on timeout or abort, returns `{stdout, stderr, exit_code, duration_ms}` |
| `desktop/src/tools/handlers/powershell.ts` | Spawns `pwsh`/`powershell` directly with `-Command -`, script piped via stdin — no cmd.exe quote-mangling; auto-picks pwsh &gt; powershell |
| `desktop/src/tools/handlers/process.ts` | `spawn_detached` (unref'd, returns pid+log_path), `list_processes` (tasklist /FO CSV — no /V to dodge window-title latency), `kill_process`, `find_pid_by_port` (netstat/lsof/ss) |
| `desktop/src/tools/handlers/jobs.ts` | Job API — `~/.hermes/desktop-jobs/<id>/{stdout.log, stderr.log, meta.json}` is source of truth across daemon restarts; `taskkill /T` on Windows so build trees die fully |
| `desktop/src/tools/handlers/transfer.ts` | `copy_directory` via `fs.cp`, `zip`/`unzip` via tar &gt; zip &gt; PowerShell probe, `checksum` streamed (sha256/sha1/md5) |
| `desktop/src/tools/handlers/search.ts` | ripgrep with pure-Node fallback, skips `.git`/`node_modules`/`dist`/`.next`/`.cache` |
| `desktop/src/renderer.ts` | Streams `message.delta` → stdout, tool events → decorated lines; NO_COLOR / --json / --quiet aware |
| `desktop/src/pairing.ts` | readline-based 6-char prompt (`A-Z0-9`); headless mirror of TUI's Ink prompt; `validatePairingPayloadString` discriminated-union wrapper |
| `desktop/src/credentials.ts` | Precedence: `--token` → `--pair-qr` (probe+pair) → `--code` → stored → prompt; returns `Credentials{sessionToken?, pairingCode?, resolvedEndpoint?}` |
| `desktop/src/transport/RelayTransport.ts` | Fork of ui-tui's transport + reconnect state machine (`idle/connecting/connected/reconnecting`, exp backoff 1→30s, 5min on 429, gate re-check post-sleep) + pre-WS TLS probe for TOFU |
| `desktop/src/remoteSessions.ts` | Same file path as TUI (`~/.hermes/remote-sessions.json`, 0600); schema widened with `grants`, `ttlExpiresAt`, `endpointRole`, `toolsConsented`; `saveSession` back-compat overload |
| `desktop/src/commands/daemon.ts` | Headless WSS + tool router for always-on access; JSON-line logs; fails closed on missing consent unless `--allow-tools` with explicit `--token` |
| `desktop/src/commands/doctor.ts` | Local-only diagnostic report — version / binary path / PATH / sessions / daemon detection; `--json` for support-paste; omits tokens entirely |
| `desktop/src/relayUrlPrompt.ts` | First-run URL fallback — `resolveFirstRunUrl()` auto-picks single stored session, numbered picker for multiple, welcome banner for zero; throws on non-interactive + ambiguous |
| `desktop/src/version.ts` | Build-time-generated constant (`npm run gen:version` before every build) — Bun compiled binaries can't read package.json via `__dirname` so version is embedded at build |
| `desktop/scripts/install.sh` / `install.ps1` | curl/iwr one-liner installers — download prebuilt Bun binary (no Node required), SHA256-verified, API-resolver for `latest` that includes prereleases, version-aware pre/post-install readback |
| `desktop/scripts/uninstall.sh` / `uninstall.ps1` | 3-tier removal — default (binary + PATH), `--purge` (also wipes `~/.hermes/remote-sessions.json`), `--service` (stub for future service installers); Windows iex-safe env-var fallback |
| `desktop/README.md` | User-facing install + usage reference |
| **Desktop CLI — dev iteration** | |
| `npm run smoke` (in `desktop/`) | Builds Windows binary + runs `--version` / `--help` / `doctor`, fails loud on zero-output. Local pre-flight before cutting any tag. |
| `npm run gen:version` | Regenerates `src/version.ts` from `package.json`. Runs automatically before every `build` / `build:bin:*`. |
| `release-cli.yml → Smoke-test Linux binary` step | CI-side equivalent: runs compiled Linux binary through the same 3-command check before uploading assets. Catches silent-exit-0 + segfault classes. |
| **Server — Desktop tool routing (Phase B)** | |
| `plugin/relay/channels/desktop.py` | Mirrors `bridge.py` — `desktop.command`/`desktop.response`/`desktop.status`, UUID-correlated futures, 30s timeout, single-client MVP, per-session advertised-tools set |
| `plugin/tools/desktop_tool.py` | 24 `desktop_*` tools (fs/shell/powershell/process/jobs/transfer/health) — registers with `tools.registry` under `desktop` toolset; per-tool `check_fn` pings `/desktop/_ping?tool=<name>`; `desktop_health` is `_RELAY_ONLY` and pings `/desktop/health` so it works even when the client is wedged |
| **Gradle modules — experimental Quest/XR (in development)** | |
| `relay-core/` | [EXPERIMENTAL] Android library (`com.axiomlabs.hermesrelay.core`) — shared pairing/transport/terminal/voice/wire for the Quest port; not yet wired into the shipped `:app` |
| `relay-ui/` | [EXPERIMENTAL] Android library (`com.axiomlabs.hermesrelay.ui`) — shared Compose UI (sphere, terminal WebView, QR scanner) for the Quest port; carries its own sphere copy |
| `quest/` | [EXPERIMENTAL] Meta Spatial SDK Quest/XR app — gradle `includeBuild("quest")`; needs further development, not shipped |
| **Tooling — dev iteration (not shipped)** | |
| `ui-preview/` | Desktop Compose Hot Reload harness — JVM Compose for Desktop; source-shares `MorphingSphereCore` from `:relay-ui`; `Main.kt` gallery; see `ui-preview/README.md` |
| `app/src/test/.../screenshots/StoreScreenshotTest.kt` | Roborazzi host-side store/docs screenshot renderer — deterministic, no device, exact 1080×2160; reuses real components+chrome with mock data; `capture(name, themeId){…}` renders any view; see `docs/screenshot-automation.md` §Deterministic rendering (JDK-21 + no-plugin gotchas) |
## What NOT to Do
- **Don't use XML layouts** — Compose only
- **Don't use Gson** — kotlinx.serialization
- **Don't use Ktor for networking** — OkHttp for WebSocket
- **Don't use plaintext WebSocket** — `wss://` only, even in development
- **Don't put documentation in root** — long-form docs go in `docs/`
- **Don't forget DEVLOG.md** — update it (record *what happened*)
- **Don't bury follow-ups** — deferred work / known gaps go in `TODO.md`, never in DEVLOG or one-off code/doc comments
- **Don't touch production / remote hosts** — automation and orchestrated agents must NEVER SSH into, deploy to, pull/restart/reconfigure, or push code to a live/remote Hermes host. Building, on-device testing, and server deployment are owner-driven (see Server Deployment). Stop at committing on your branch; surface "this needs a deploy/on-device check" rather than doing it.
## MCP Tooling
Two MCP servers are configured for AI-assisted development. See `docs/mcp-tooling.md` for full reference.
| Server | Layer | Requires |
| ------------------- | --------------------------------------------------------------- | ---------------------------------------- |
| `android-tools-mcp` | IDE/Build — Compose previews, Gradle, code search, Android docs | Android Studio running with project open |
| `mobile-mcp` | Device/Runtime — tap, swipe, screenshot, app management | ADB + connected device/emulator |
## Dev Workflow
```bash
scripts/dev.bat build # Build debug APK (DEV_MODE=true)
scripts/dev.bat release # Build signed release APK (DEV_MODE=false)
scripts/dev.bat bundle # Build release AAB for Google Play upload
scripts/dev.bat run # Build + install + launch + logcat
scripts/dev.bat test # Run unit tests
scripts/dev.bat version # Show current version from libs.versions.toml
scripts/dev.bat relay # Start relay server (dev mode, no SSL)
```
### Bridge smoke test (run on hermes-host, not local PC)
```bash
scripts/bridge-smoke.sh # full suite, destructive ON
scripts/bridge-smoke.sh --no-destructive # read-only paths only
scripts/bridge-smoke.sh --filter open_app # re-run a single test
scripts/bridge-smoke.sh --pair ABCDEF # register pairing code first
```
Curls every bridge HTTP route via `localhost:8767`. Catches the silent-drop regression class (Python relay registers a route but Kotlin dispatcher's `when (path)` has no matching branch). Run after every relay restart.
### Typical Dev Loop
1. **Edit locally** — Windows checkout. Both plugin (`plugin/`) and app (`app/`) live here.
2. **Python syntax check** — `python -m py_compile plugin/<file>.py`. Full tests run on the server.
3. **Kotlin changes** — do NOT run `gradle build`. Bailey builds via Android Studio's ▶ button. Never `adb install` from Claude.
4. **Before pushing Kotlin changes** — run `./gradlew lint` locally. It's the exact task CI runs and catches errors Android Studio's live inspections miss — e.g. `UnsafeOptInUsageError` with `kotlin.OptIn` vs `androidx.annotation.OptIn`, `FlowOperatorInvokedInComposition` (mapped flows inside Composables), Media3 `@UnstableApi` propagation. Android CI runs lint alongside build/test for faster feedback, but a local lint run still surfaces issues before the workflow spends runner time compiling and packaging.
5. **Commit + push** — follow `AGENTS.md` and `RELEASE.md`; normal work PRs to `dev`.
6. **Pull + restart on server** — see Server Deployment below.
7. **Test on phone** — Bailey builds from Studio, installs to Samsung device, pairs via `/hermes-relay-pair`.
### Server Deployment
Server is a Linux box running hermes-agent with hermes-relay editable-installed (`pip install -e`). Sensitive details (IP, user, secrets) in `~/SYSTEM.md` on the server — not in this repo.
| What | Where |
| ------------------ | ------------------------------------------------------------------ |
| hermes-agent repo | `~/.hermes/hermes-agent/` |
| hermes-relay clone | `~/.hermes/hermes-relay/` |
| Plugin symlink | `~/.hermes/plugins/hermes-relay` → `~/.hermes/hermes-relay/plugin` |
| Config | `~/.hermes/config.yaml` + `~/.hermes/.env` |
| Relay log | `journalctl --user -u hermes-relay -f` |
**Update:** `hermes-relay-update` (idempotent, re-fetches install.sh). Or manually: `git pull --ff-only && systemctl --user restart hermes-relay`.
**Compat hook:** `hermes relay compat status/install/remove` manages only the
optional `hermes_relay_bootstrap.pth` startup hook. New installs load the
plugin-owned bootstrap from `plugin/hermes_relay_bootstrap/`; the repo-root
package is only a legacy import shim. Vanilla Hermes chat, Manage, and dashboard voice
must not depend on this hook.
**Key conventions:**
- Phone pairing **survives** relay restart — `SessionManager` persists sessions to `~/.hermes/hermes-relay-sessions.json` (`server.py:88-90`, `persistence_path` from `RelayConfig.from_env`); a trusted-device refresh token recovers a lost/revoked/reset session without a new QR scan. (Only the in-memory *live-connection presence* clears on restart; the phone reconnects automatically.)
- Use `python -m unittest` not `pytest` — conftest imports `responses` which may not be installed
- `_env_bootstrap.py` loads `~/.hermes/.env` on every relay start — no stale API keys
### Where Python vs. Kotlin changes land
| Change type | Who restarts? | Command |
| ------------------------------------ | ------------------------ | -------------------------------------------------- |
| Plugin tool (`android_tool.py` etc.) | `hermes-gateway.service` | `systemctl --user restart hermes-gateway` |
| Relay code (`plugin/relay/*.py`) | `hermes-relay.service` | `systemctl --user restart hermes-relay` |
| Pair CLI / skill files | — | No restart — fresh process / scanned on invocation |
| Android app | Bailey (Studio) | Studio run button |
### Release Process
See [AGENTS.md](AGENTS.md) for the canonical branch contract and
[RELEASE.md](RELEASE.md) for version sources, release trains, surface tags,
hotfixes, secrets, publishing, and verification. Claude-specific automation
must not infer release authority from feature completion.
## Integration Points
| Surface | Endpoint | Notes |
| ------------------------------ | ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Chat (gateway) | Dashboard `POST /api/auth/ws-ticket` -&gt; WS `/api/ws` | Vanilla Hermes dashboard/tui_gateway path; live thinking/reasoning; requires dashboard auth |
| Chat streaming | `POST /v1/runs` → `GET /v1/runs/{id}/events` | Structured tool events; async run-control path |
| Chat (sessions) | `POST /api/sessions/{id}/chat/stream` | Native upstream session-persisted SSE; preferred when capability probe finds it |
| Chat (compat) | `POST /v1/chat/completions` (stream=true) | Inline tool annotations only |
| Session CRUD | `GET/POST/PATCH/DELETE /api/sessions` | Native upstream (#33134); bootstrap fallback retired |
| Manage | Dashboard `/api/status`, `/api/auth/me`, `/api/config`, `/api/profiles/*`, `/api/env`, `/api/model/*`, `/api/mcp/*` | Vanilla Hermes dashboard surface; do not proxy through Relay |
| Vanilla Hermes voice | Dashboard `POST /api/audio/transcribe`, `POST /api/audio/speak` | Vanilla Hermes no-plugin voice; uses dashboard session from Manage |
| Pairing (QR) | `POST /pairing/register` (loopback only) | Via `/hermes-relay-pair` or `hermes-pair` shim; accepts optional `endpoints` for multi-endpoint QRs |
| Pairing (multi-endpoint) | QR `endpoints` array (ADR 24) | `hermes: 3` schema; ordered `lan`/`tailscale`/`public`/... candidates; phone re-probes on network change |
| Pairing auth | WSS `auth.ok` payload | Includes `expires_at`, `grants`, `transport_hint` |
| Tailscale Serve (ADR 25) | `hermes-relay-tailscale enable|disable|status` CLI | Fronts loopback `:8767` with `tailscale serve --bg --https=<port>`; auto-retires on upstream PR #9295 |
| Inbound media (token) | `GET /media/{token}` | Bearer auth; 24h TTL |
| Inbound media (path) | `GET /media/by-path?path=<abs>` | Permissive by default; `RELAY_MEDIA_STRICT_SANDBOX=1` to restrict |
| Session management | `GET /sessions`, `DELETE /sessions/{prefix}`, `PATCH /sessions/{prefix}` | List/revoke/extend; RelayHttpClient |
| Voice transcribe | `POST /voice/transcribe` | multipart/form-data; bearer auth |
| Voice synthesize | `POST /voice/synthesize` | JSON → audio/mpeg; max 5000 chars |
| Voice config | `GET /voice/config` | Returns current tts/stt provider info |
| Plugin diagnostics | `hermes relay doctor --json` | Reports upstream route reachability, Relay loopback state, plugin layout, and legacy bootstrap state |
| Compat hook lifecycle | `hermes relay compat status/install/remove` | Optional legacy API compatibility hook; not required for the standard path |
| Notifications | `GET /notifications/recent?limit=N` | Loopback callers skip bearer |
| Relay health | `GET /health` on `:8767` | Used by `RelayHttpClient.probeHealth()` |
| Capabilities | `GET /v1/capabilities` plus targeted `HEAD` probes | Prefer capabilities when present; HEAD probes keep mixed-version fallback working |
| Desktop CLI (tui channel) | WSS `tui.attach` / `tui.rpc.request` / `tui.rpc.event` | Same channel + envelopes as the Ink TUI — the CLI just renders events as plain lines. Zero server changes. |
| Desktop CLI (terminal channel) | WSS `terminal.attach` / `terminal.input` / `terminal.output` / `terminal.resize` / `terminal.detached` | Existing channel (shared with Android). CLI `shell` subcommand attaches, injects `clear; exec hermes\n` 350ms after ack, pipes raw bytes. `Ctrl+A .` detaches (tmux preserved), `Ctrl+A k` kills. |
| Desktop CLI tool visibility | `tools.list` RPC on the shared tui channel | Returns `{toolsets: [{name, description, tool_count, enabled, tools:[]}]}`; surfaced by `hermes-relay tools` |
| Desktop CLI devices | HTTP `GET/DELETE/PATCH /sessions` on the relay's same port | Wrapped by `hermes-relay devices list |
| Desktop tool routing (Phase B) | WSS `desktop.command` (s→c) + `desktop.response` (c→s) + `desktop.status` (c→s heartbeat) | New channel. Hermes calls `desktop_read_file(path)` → Python handler POSTs to `/desktop/desktop_read_file` → relay forwards over `desktop.command` → Node client's `DesktopToolRouter` runs the handler locally → response bubbles back. Mirror of Android's `bridge.command` pattern. |
| Desktop tool check_fn | HTTP `GET /desktop/_ping?tool=<name>` | Returns 200 if a client is connected AND advertises this tool; 503 otherwise. Hermes uses this to fail the tool quickly when no desktop client is live, instead of waiting 30s for the dispatch timeout. |
| Desktop health | HTTP `GET /desktop/health` | Returns full status snapshot — connected/host/platform/version/pid/uptime/advertised_tools/last_error/recent_commands. Loopback-only. Backs the `desktop_health` agent tool, which intentionally does NOT round-trip through the client so it remains callable when other tools are wedged. |
## Upstream References
| Topic | Upstream File |
| -------------------------- | ----------------------------------------------------------------------------- |
| API endpoints | `gateway/platforms/api_server.py` — all registered HTTP routes |
| Platform adapter interface | `gateway/platforms/base.py` — `BasePlatformAdapter` abstract class |
| Adding a platform | `gateway/platforms/ADDING_A_PLATFORM.md` — 16-step checklist |
| Platform registration | `gateway/run.py` → `_create_adapter()`, `gateway/config.py` → `Platform` enum |
| Channel directory | `gateway/channel_directory.py` — how platforms/channels are enumerated |
| Send message routing | `tools/send_message_tool.py` → `platform_map` dict |
| SSE streaming (runs) | `gateway/platforms/api_server.py` → runs endpoint, `_on_tool_progress` |
## Related Projects
- [**hermes-agent**](https://github.com/NousResearch/hermes-agent) — the agent platform (gateway, WebAPI, plugin system)
- [**android-tools-mcp**](https://github.com/Codename-11/android-tools-mcp) — our fork of Android Studio MCP bridge (Compose previews, Gradle, docs)
- [**mobile-mcp**](https://github.com/mobile-next/mobile-mcp) — device control MCP server (ADB, tap/swipe, screenshots)
@AGENTS.md
+6 -22
View File
@@ -1,33 +1,22 @@
# Hermes-Relay CLI+UI v__VERSION__
**Release Date:** 2026-08-25
**Release Date:** 2026-08-30
This beta makes the Desktop connector resilient through Relay interruptions,
aligns Windows computer control with current CUA Driver releases, adds a native
Linux ARM64 build, and hardens installation and update discovery.
This beta preserves complete multi-route pairing while preventing Desktop from dialing Dashboard-ingress Relay routes before Dashboard WebSocket ticket support is available. (Related: #399)
**Beta phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64/arm64, and macOS x64/arm64; the management UI is Windows-only.
## What's changed
### Added
- **Linux ARM64 is a first-class release target.** The one-line installer,
updater, checksums, and release artifacts now cover both Linux x64 and arm64.
- **The public site shows the real Windows CLI UI.** Deterministic screenshots
cover connections, host access, activity, computer control, and updates.
### Changed
- **Public naming is aligned.** Releases use `Hermes-Relay CLI+UI` while the
beta keeps its existing `desktop-v*` tag and updater contract.
- **Saved hosts retain the full route topology.** Dashboard, Relay, optional API, route priority, transport protection, certificate pins, and the selected host survive LAN, Tailscale, and public-route changes without creating duplicate hosts.
- **API-less pairing is first-class.** Dashboard plus direct Relay can pair without inventing an optional API server, while secure-first ranking retains plain LAN as the final fallback.
### Fixed
- **The daemon reconnects instead of exiting after an interrupted Relay socket.** Relay restarts and repeated transient replacement failures stay on bounded automatic backoff, and terminal failures persist an accurate stopped reason for the UI.
- **Oversized desktop-tool output no longer closes the shared connection.** PowerShell output and every serialized desktop response stay inside the Relay WebSocket budget.
- **Current CUA Driver releases remain compatible by contract.** Driver 0.20 and newer are accepted when their manifest and required tools match Hermes, and Windows uses the manifest-declared direct standard-mode runtime instead of a stale machine-wide daemon.
- **Install and update discovery paginates the multi-surface release history.** Desktop releases remain discoverable after more Android and Server releases, Windows cooperative updates clean their released backup, and unsigned installers retain the normal SmartScreen warning.
- **Dashboard-ingress Relay routes fail closed on Desktop.** The daemon, host selector, and Relay transport reject ingress that requires a Dashboard WebSocket ticket and choose a compatible direct Relay fallback instead of attempting an unauthenticated dial.
- **Pairing accepts the current v3 candidate shape.** Optional API records, same-origin Dashboard/Relay routes, and legacy top-level payloads remain compatible without collapsing route ownership.
## Install
@@ -58,9 +47,4 @@ hermes-relay --version
hermes-relay hosts list --json
hermes-relay daemon start
hermes-relay daemon status --json
hermes-relay computer-use status --json
```
On Windows, click the Hermes-Relay CLI UI notification-area icon to open the management popup directly above it.
See the [CLI and tray guide](https://hermes-relay.dev/docs/desktop/) for installation, access modes, grants, and troubleshooting.
+23 -8
View File
@@ -61,6 +61,15 @@ configuration between invocations and do not add `--no-daemon` to normal dev
commands; a different heap or Java home starts a separate daemon and discards
the warm-process benefit.
On Windows, all repository dev helpers serialize Android build and device work
through one machine-wide lane shared by every Hermes-Relay worktree. Use
`scripts/android-lane.ps1` for ad hoc Gradle, connected-test, and APK-install
commands, and keep Android Studio idle while another owner holds the lane. For
an exact commit that is already pushed, prefer the `Android On-Demand` workflow
for heavy verification so concurrent worktrees use isolated GitHub-hosted
runners. See [Android build execution](docs/android-build-lane.md) for cloud
presets, the optional full local gate, status, and recovery modes.
Use the narrowest command that proves the change:
1. `scripts/dev.bat compile` for a Kotlin compile check.
@@ -68,7 +77,10 @@ Use the narrowest command that proves the change:
3. `scripts/dev.bat install-fast` when the result must run on the connected
arm64 phone. This passes `-Phermes.devAbi=arm64-v8a`, avoiding the x86,
x86_64, and armeabi-v7a native libraries in the local APK.
4. `scripts/dev.bat prepush` before pushing Android work.
4. `Android On-Demand` after an exact commit is pushed for lint, broad checks,
assemblies, or release smoke.
5. `scripts/dev.bat prepush` only when full local verification is explicitly
wanted or cloud execution is unavailable.
`install-fast` is intentionally phone-specific. Use `install` for a universal
sideload debug APK or when the target ABI is not arm64. Release builds remain
@@ -258,12 +270,15 @@ Release notes (`RELEASE_NOTES.md`, `app/src/main/assets/whats_new.txt`, `docs/pl
## Testing
- **Android pre-push gate:** `scripts\dev.bat prepush` on Windows or
`./scripts/dev.sh prepush` on macOS/Linux. This runs the Android repository
checks, Google Play debug lint, and the same focused unit-test shard used by
CI in one cached Gradle invocation. Run it before pushing Android PR updates
to catch common hosted failures without waiting for another full Actions
cycle; hosted CI remains the exhaustive all-variant gate.
- **Android cloud verification (preferred for pushed work):** dispatch
`.github/workflows/android-on-demand.yml` against the exact pushed SHA with
`focused`, `lint`, `assemble-debug`, `release-smoke`, or `all-final`. Check for
an existing run before dispatching the same SHA/preset again. The four
`all-final` compute jobs use isolated runners and may execute concurrently.
- **Full local Android gate (optional):** `scripts\dev.bat prepush` on Windows
or `./scripts/dev.sh prepush` on macOS/Linux. This retains the repository
checks, full Android lint, and both focused flavor shards for an explicit local
run or cloud outage. On Windows it acquires the machine-wide lane.
- **Focused Android unit test:** `scripts/dev.bat test-one "<fully-qualified-class-or-pattern>"`
- **Android unit tests:** `scripts/dev.bat test` (runs the sideload debug JUnit + MockK + Compose suite)
- **Gateway contract lab:** [`docs/gateway-contract-testing.md`](docs/gateway-contract-testing.md)
@@ -272,7 +287,7 @@ Release notes (`RELEASE_NOTES.md`, `app/src/main/assets/whats_new.txt`, `docs/pl
device lane is scheduled automatically.
- **Python tests:** `python -m unittest plugin.tests.test_<name>` from the repo root with the hermes-agent venv active. `pytest` works too but the pre-existing `conftest.py` imports a module that isn't always installed — `unittest` avoids that entirely.
CI is split into path-filtered workflows: `.github/workflows/ci-android.yml` (lint + build + test on app/Gradle changes), `.github/workflows/ci-server.yml` (syntax check + focused server tests on plugin/Python changes), and `.github/workflows/ci-desktop.yml` (desktop type/build/smoke checks). They run on pushes to `main` and `dev` and on PRs targeting either when their paths are touched.
CI is split into path-filtered workflows: `.github/workflows/ci-android.yml` (lint + build + test on app/Gradle changes), `.github/workflows/ci-server.yml` (syntax check + focused server tests on plugin/Python changes), and `.github/workflows/ci-desktop.yml` (desktop type/build/smoke checks). They run on pushes to `main` and `dev` and on PRs targeting either when their paths are touched. `android-on-demand.yml` is the trusted manual compute lane for an exact pushed commit; it does not replace required PR checks.
Superseded Android runs on `dev` and PR refs are canceled automatically; `main`
runs are never canceled because each release-branch commit must complete its
independent validation.
+72
View File
@@ -1,5 +1,27 @@
# Hermes-Relay — Dev Log
## 2026-08-31 — Complete, readable Android release notes
Android release metadata now keeps one overall title and summary plus a complete
typed inventory of user-visible additions, improvements, and fixes. Stable
change ids prevent duplicate records, selected highlights lead the expanded
view, and compatibility boundaries remain visible without turning the compact
notice into technical release documentation. Toast counts and previews are
derived from the same non-highlighted changes the dialog and history render, so
View all reaches every counted item. Older bundled changelog entries retain
their existing rendering path.
The Android 1.14.0 record was migrated to the complete schema and reconciled
against its released Android changelog: four highlights, two additional
improvements, ten fixes, and three compatibility notes. The dialog, full
history, large-text toast, seven Android resource catalogs, legacy text
fallback, Play note, listing copy, release-prep instructions, and validation
tests were updated together.
Structured release-note tests, focused Kotlin tests, Android locale and
collection-API gates, rendered 360×640 dark-theme screenshots including 135%
text, sideload APK assembly, Android lint, and diff checks passed.
## 2026-08-27 — Fixed issue ownership and bounded PR intake
The automated issue first-response lane now assigns only `Codename-11` when the
@@ -30,6 +52,56 @@ turn every surface into a mandatory test lane, does not replace CI or maintainer
review, and keeps normal work targeting `dev` while preserving the documented
release/hotfix exceptions.
## 2026-08-26 — Android OIDC origin continuity and route latency
Dashboard authentication now follows upstream `/api/status.auth_flows`:
interactive redirect and password providers use native PKCE when advertised,
with exact-host cookies retained only for older gateways or client-local native
failure. A different provider-declared callback is fenced by installation
identity and explicit review before becoming the authenticated Dashboard/Gateway
origin. Public origins require HTTPS; reviewed literal LAN, Tailscale, and
loopback HTTP retains upstream compatibility. Cookies are never copied between
hosts, API and Relay ownership remain separate, unsafe callbacks are rejected,
and third-party cookies are enabled only for the short-lived compatibility
WebView.
The saved authenticated origin is now modeled as connection-level
Dashboard/Gateway state rather than as a synthetic network candidate. The
Routes screen presents a dedicated Dashboard & Gateway card with edit and
re-check actions, keeps LAN, Tailscale, API, and Relay under Network routes, and
does not expose internal role keys or describe arbitrary routes as VPNs. Changing
the Dashboard origin clears origin-bound cookies and bearer state before the new
address is verified. The compact footer shows the active surface and transport
without allowing long model or profile names to displace the route label.
For self-hosted OIDC, authorization and callback use one exact Dashboard
address. Split DNS remains the preferred public-HTTPS/local-performance shape,
but a second public URL is not a universal onboarding field. Android does not
treat the identity origin as ownership of optional API or Relay paths.
Optional API discovery no longer blocks a healthy Dashboard/Gateway route.
Concurrent probes are shared, negative results are cached for a bounded window,
same-priority routes race by completion, and connection generations prevent a
late old route from overwriting a new one. Invalidated probes cannot publish a
stale unreachable result or diagnostic. Dashboard session and message reads
now cancel with their coroutine, one bounded budget covers the complete session
list, WebSocket-ticket minting is bounded, and optional pull-request decoration
falls off the critical path while preserving exact profile-scoped rows.
Gateway ticket/auth failures receive one bounded classified attempt rather than
two serialized waits. A pre-ready WebSocket close settles immediately, while
optional API and Relay work remains background capability discovery.
Focused auth, Dashboard, resolver, route, and native-sign-in coverage passed
135 tests on the final `origin/dev` merge, followed by Android lint and sideload
assembly. The matching Android 16 sideload was installed in place with app data
preserved. Cold-route evidence showed Dashboard selection completing in hundreds
of milliseconds, unavailable API fallback work continuing in the background,
and unauthenticated ticket failures returning immediately instead of stalling.
An upstream-compatible live-writer certification separately kept five full
profile-roster RPCs below one second while concurrent ticket mints stayed in
single-digit milliseconds. Final interactive provider consent/callback remains
a human gate because the test device was locked after deployment.
## 2026-08-26 — Bounded public issue triage contract
New GitHub issues may receive one clearly identified Hermes-Relay automated
+14 -9
View File
@@ -1,26 +1,29 @@
# Hermes-Relay Plugin v__VERSION__
**Release Date:** August 25, 2026
**Release Date:** August 30, 2026
## Summary
This release adds a provider-neutral account-usage surface for Android and Dashboard clients. Relay resolves Codex credential pools, structured Nous balances, and OpenCode Go windows on the Hermes host without returning provider credentials.
Standard chat, session history, and Vanilla Hermes voice remain upstream-owned and do not require this plugin.
This release lets one authenticated Hermes Dashboard origin carry Gateway plus optional Relay extensions, adds a bounded Git workspace, and reorganizes the Dashboard plugin around operator tasks. Standard chat, session history, profiles, Manage, and standard voice remain upstream-owned and do not require this plugin.
## Added
- **Provider-neutral usage snapshots.** Authenticated Dashboard clients can resolve the exact active Codex pool entry, Nous balances, and OpenCode Go account windows through one normalized schema.
- **Bounded paired-client fallback.** Operators may explicitly enable the Relay usage route for paired standalone clients while credentials remain host-side.
- **Dashboard same-origin Relay ingress.** Fixed allowlisted HTTP and WebSocket routes proxy to the local Relay while Dashboard admission and Relay session authentication remain independent. (Related: #399)
- **Bounded Git workspace.** Configured roots, path containment, line totals, diffs, branches, staging, commits, remotes, grants, and explicit confirmations protect repository operations.
## Changed
- **Usage capabilities are explicit.** Responses identify Relay-enhanced credential pools, structured balances, and provider adapters instead of implying unsupported upstream data.
- **Public product naming is aligned.** Releases use `Hermes-Relay Plugin` while retaining the `server-v*` tag and installation contract.
- **Task-oriented Dashboard UI.** Overview, Devices, Activity, Remote Access, Git, and Settings now have dedicated surfaces with QR-first pairing, responsive device cards, and honest media diagnostics. (#486)
- **One explicit route topology.** Dashboard, CLI, and TUI pairing advertise Dashboard, Relay, and optional API surfaces with stable priorities across Tailscale, public HTTPS, and LAN.
- **Dedicated Tailscale listener.** Recommended setup uses tailnet HTTPS `:10443` to local Dashboard `:9119`, avoiding ownership of a reverse proxy's `:443`. Existing `:443`, `:9119`, and direct `:8767` routes remain migration compatibility.
## Fixed
- **Custom Hermes homes resolve correctly.** Relay profile discovery and session persistence follow `HERMES_HOME` by default while preserving the explicit `RELAY_HERMES_CONFIG` override.
- Public and roaming invites no longer synthesize closed direct Relay `:8767` or wrong Dashboard `:9119` routes.
- Ambiguous, credential-bearing, or plaintext public candidates fail closed before an invite is exposed.
- Dense pairing QRs use integer-sized modules and a full quiet zone.
- Inactive optional API routes are omitted; protected Dashboard-ingress `401/403` responses display as authentication-required while direct Relay and API failures remain failures.
- Default Tailscale disable actions remove only owned listeners, and explicit migration cleanup accepts only the bounded supported ports.
## Install / update
@@ -32,6 +35,8 @@ Standard chat, session history, and Vanilla Hermes voice remain upstream-owned a
# or, if already installed:
hermes-relay-update
Restart or reload the Hermes Dashboard and Relay after updating so the new manifest, routes, and committed Dashboard bundle are active.
## Verify
hermes relay doctor
+3 -3
View File
@@ -105,7 +105,7 @@ The wizard probes everything and finishes with a capability card:
One dashboard sign-in unlocks Chat, Manage, sessions, and standard voice. That's
the whole Vanilla Hermes setup.
> **Going places?** Add the Dashboard's Tailscale address — for example `http://100.x.y.z:9119` or a separately published `https://host.ts.net` URL — under **Settings → Connections → Routes**. Android tests it as a Dashboard route; no API server or API key is required. The app uses LAN at home and switches routes automatically when you leave. See [Remote access](https://hermes-relay.dev/docs/guide/remote-access).
> **Going places?** Add the Dashboard's Tailscale address — for example `http://100.x.y.z:9119` or a separately published `https://host.ts.net` URL — under **Settings → Gateways → Routes**. Android tests it as a Dashboard route; no API server or API key is required. The app uses LAN at home and switches routes automatically when you leave. See [Remote access](https://hermes-relay.dev/docs/guide/remote-access).
### 4 · Recommended: pair Relay for the complete experience
@@ -124,7 +124,7 @@ Use `--no-ssl` only on a trusted LAN or VPN. Use the
exposing any Hermes surface beyond that network.
Refresh or restart the Dashboard/Gateway, open **Relay → Pair new device**, and
scan the one-time QR from Android **Settings → Connections → Pair Hermes Relay**.
scan the one-time QR from Android **Settings → Gateways → Access → Pair Relay**.
Leave mode on **Auto** for the recommended route discovery. The same dialog
shows a copyable invite for Desktop CLI clients:
@@ -154,7 +154,7 @@ manual fallbacks when QR or clipboard transfer is unavailable.
<tr>
<td align="center" width="25%"><img src="assets/screenshots/05_themes.png" alt="App themes" width="100%"><br><sub><b>App themes</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/06_manage.png" alt="Manage your agent" width="100%"><br><sub><b>Manage your agent</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/07_connections.png" alt="Connections and routes" width="100%"><br><sub><b>Connections &amp; routes</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/07_connections.png" alt="Gateways and routes" width="100%"><br><sub><b>Gateways &amp; routes</b></sub></td>
<td align="center" width="25%"><img src="assets/screenshots/08_appearance.png" alt="Agent avatar &amp; skins" width="100%"><br><sub><b>Avatars &amp; skins</b></sub></td>
</tr>
</table>
+30 -27
View File
@@ -531,13 +531,14 @@ the new app version and a higher `appVersionCode`.
`retrace <mapping.txt> <obfuscated-trace.txt>`. Play reports can additionally
use the mapping bundled into the uploaded AAB through Play Console.
- `app/src/main/assets/changelog.json` — curated source for the in-app
**What's New** dialog and Android release history. Prepend the newest entry
with one explicit `highlight` (`title`, plain-language `summary`, and 1–3
user-benefit bullets), up to two quieter `improvements`, Android-only
`playNotes`, a `toastDigest` with counts and 0–2 short previews for noteworthy
items beyond the hero, and the existing technical `sections` used by older clients.
Do not derive the highlight mechanically from `CHANGELOG.md`; choosing the
release's main reason to care is an editorial release-prep decision.
**What's New** dialog and Android release history. Prepend one schema-3 entry
with a single descriptive release `title`, a plain-language `summary`, and a
complete `changes` inventory. Every user-visible change has a stable `id`, a
`kind` (`added`, `improved`, or `fixed`), a short title, a useful explanation,
and an optional `highlight: true`; select 1–4 highlights. Add `compatibility`
bullets only when users need an availability, migration, flavor, or Plugin
boundary, plus Android-only `playNotes`. The app derives toast counts and
previews from the same inventory and renders every change exactly once.
- `app/src/main/assets/whats_new.txt` — legacy in-app fallback generated from
the newest structured entry. Do not edit it independently.
- `app/src/googlePlay/play/release-notes/en-US/default.txt` — the Play
@@ -551,8 +552,8 @@ the new app version and a higher `appVersionCode`.
block and the Gradle Play Publisher note are generated from `playNotes`.
After editing the newest structured entry, run
`python scripts/check-android-release-notes.py --write`, then run it again
without `--write` to validate the 1–3 / 0–2 editorial limits, current Android
version, GitHub-release/changelog headings, derived files, and Play's
without `--write` to validate complete unique change records, 1–4 highlights,
the current Android version, GitHub-release/changelog headings, derived files, and Play's
**500-character** limit. Frame Play copy around the release's themes, not a
feature dump. Compare its **Foreground service
permissions** section with the merged `googlePlayRelease` manifest and
@@ -570,28 +571,30 @@ authoring contract; do not maintain a separate prompt file.
boundary that users must understand. Do not generate from commit titles or
a mixed-surface changelog block alone.
2. Before editing release files, show a temporary coverage ledger in the task
output. Map every selected source change to exactly one placement:
`hero`, `secondary`, or `full-only`. Include the change kind (`feature`,
`change`, or `fix`) and a short reason. The ledger is review evidence, not a
committed public artifact; no selected source item may disappear silently.
3. Choose exactly one `hero`: the strongest user-facing reason to care about
the release. Its summary is one plain-language outcome, and its 1–3 bullets
are distinct user benefits rather than implementation steps or filler.
4. Use `secondary` for other important user-visible features and fixes. The
`toastDigest` counts only these items, excluding the hero. Preview the
strongest 1–2 secondary items in short phrases. If there are no legitimate
secondary items, set both counts to `0` and `preview` to `[]`; the app hides
the footer. Never invent an item to satisfy the layout.
5. Use `full-only` for technically relevant details that belong in
`RELEASE_NOTES.md` or `CHANGELOG.md` but would make the collapsed update card
noisy. Preserve user-relevant trust and compatibility limits; omit branches,
worktrees, CI mechanics, debugging history, and private/operator context.
output. Map every selected Android source change to one stable change id and
one kind (`added`, `improved`, or `fixed`), and mark whether it is a
highlight. The ledger is review evidence, not a committed public artifact;
no selected user-visible change may disappear silently or be counted twice.
3. Write one release title that describes the release as a whole. Do not let a
narrow feature name, internal project label, or poetic codename replace the
title users see in the toast and history. Follow it with a one- or two-sentence
summary that gives the release's overall outcome without becoming a feature dump.
4. Select 1–4 highlights from the complete change inventory. A highlight is a
strong reason to care, not a second copy of the change: the app presents it
once in the highlight section and derives the remaining counts and previews
from non-highlighted changes.
5. Include every meaningful user-visible addition, improvement, and fix in
`changes`, using plain titles and enough explanation for someone to recognize
the affected behavior. Internal refactors, tests, CI mechanics, branch work,
and debugging history stay in `RELEASE_NOTES.md`, `CHANGELOG.md`, or engineering
records unless they materially change reliability, security, or compatibility.
6. Write each surface for its audience:
- `RELEASE_NOTES.md`: concise Summary plus Added/Changed/Fixed; keep the
deterministic Download and Install/Verify scaffolding intact.
- `CHANGELOG.md`: complete, crisp public history for the released surface.
- `changelog.json`: curated hero, optional improvements, digest, Play copy,
and compatibility `sections` for older clients.
- `changelog.json`: overall title/summary, complete typed changes, selected
highlights, compatibility boundaries, and Play copy. Counts and previews
are derived; never author a parallel digest.
- `playNotes`: Android-only themes within the rendered 500-character limit.
7. Before presenting the draft, check that wording begins with user outcomes,
avoids unexplained implementation terminology, uses exact public product
+24 -11
View File
@@ -1,10 +1,10 @@
# Hermes-Relay Android v1.13.2
# Hermes-Relay Android v1.14.0
**Release Date:** August 25, 2026
**Release Date:** August 30, 2026
## Download
> Installing on your phone? Download `hermes-relay-1.13.2-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
> Installing on your phone? Download `hermes-relay-1.14.0-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
The `.aab` file is a Play Console upload bundle and cannot be installed by tapping it on a phone.
@@ -12,20 +12,33 @@ Verify the download against `SHA256SUMS.txt`. See the [sideload guide](https://h
## Summary
This release adds a parent-configured Supervised Mode and improves its return from full settings. It also keeps session rows neutral until live activity is confirmed.
This release makes saved Hermes connections reliable across LAN, Tailscale, and public HTTPS while keeping Dashboard authentication bound to its exact trusted origin. It also adds delegated-agent previews and an optional native Git workspace, and improves Voice, Assistant, Threads, profile drafts, and Clarify interactions.
## Added
- Use a profile-pinned Supervised Mode with parent-controlled attachments, Standard voice, generated media, history, actions, and technical details. Device authentication protects full settings; this remains a client-side restricted view rather than a server-enforced account boundary.
- **Delegated-agent previews.** Follow bounded lifecycle, progress, tool previews, and available read-only child history without leaving the parent chat. Partial history and reconnect gaps remain explicit. (#447)
- **Native Git workspace.** Review repository state, diffs, branches, staging, commits, and remotes from Chat or Settings. Git operations require Hermes-Relay Plugin v1.11.0 and retain confirmation and grant boundaries.
## Changed
- **Route-aware connections.** Dashboard, Relay, and optional API health are evaluated independently across LAN, Tailscale, and public HTTPS. Same-origin Relay ingress stays on the Dashboard origin that owns authentication, while direct compatibility routes keep separate credentials. (Related: #399)
- **Voice Focus controls.** Stop and immediate spoken steering remain accessible while Hermes is Thinking, Transcribing, or Speaking, including TalkBack, Switch Access, keyboard, and sideload overlay surfaces.
## Fixed
- Keep session rows neutral while optional live activity is unavailable or still loading, and reserve full-row activity borders for actual Starting or Working turns.
- Keep Supervised Chat rendered when parent access relocks after visiting full settings.
- Wake-word detection packages one compatible ONNX Runtime for sherpa and Java JNI on every supported ABI. (#444)
- Continuous voice waits for barge-in microphone teardown before listening again. (#464)
- Fresh chats retain their selected profile without reopening a previous session or carrying a proactive Thread route across profiles. (#436)
- Provisional Threads can be removed locally and reconcile with promoted sessions without deleting server history. (#461)
- Clarify cards expose a reachable Other answer, keyboard Send, and authoritative expiry behavior. (#446)
- Passive Android browsing no longer claims or interrupts a turn owned by another client. (Related: #365)
- Assistant sessions show retryable no-speech feedback, recover their active state after recreation, and redact conversation details behind the keyguard. (Related: #424)
- Protected Relay ingress `401/403` responses are recognized as authentication boundaries rather than outages; malformed, different-origin, and direct unauthorized routes still fail closed.
## Install / Verify
- App version: **1.13.2** (versionCode **51**).
- Standard Chat, sessions, Manage, sharing, profile switching, and Vanilla Hermes voice continue to work against unmodified upstream Hermes.
- Granular Device Control remains sideload-only; the Google Play build continues to ship Hermes Bridge Core without AccessibilityService Device Control.
- The optional Relay plugin remains unnecessary for standard Android chat, sessions, Manage, and Vanilla Hermes voice.
- App version: **1.14.0** (versionCode **52**).
- Standard Chat, sessions, profiles, Manage, and standard voice continue to work against unmodified upstream Hermes without the optional Relay plugin.
- Install Hermes-Relay Plugin v1.11.0 for same-origin Relay extensions, Git workspace actions, Bridge, media, proactive features, and enhanced voice.
- Granular Device Control and the system Voice Focus overlay remain sideload-only; the Google Play build does not declare their restricted permissions.
- Existing connections, drafts, sessions, profile ownership, and legacy direct Relay routes remain data-preserving compatibility paths.
+36 -11
View File
@@ -6,6 +6,20 @@ For shipped work, see `DEVLOG.md`. For architectural decisions, see `docs/decisi
---
## Upstream a public Dashboard plugin WebSocket admission seam
The same-origin Relay ingress follows current upstream's bundled Dashboard
plugin pattern but must feature-detect private
`hermes_cli.web_server._ws_request_is_allowed` and `_ws_auth_ok` helpers.
Propose one public helper that combines Host/Origin policy, single-use ticket
authentication, and runtime plugin-enabled gating for `APIRouter` WebSockets.
After it is available in the supported Hermes baseline, replace the private
imports and remove the Relay plugin's local runtime-disable polling. Until
then, missing helpers fail closed and direct Relay remains an advanced
compatibility route.
---
## Certify Android session activity across lifecycle and profile boundaries
The contract fixture now covers every upstream live status, complete-snapshot
@@ -26,6 +40,9 @@ model device-certified:
renders as Working.
- Run a background process that outlives its parent turn and verify Background
work remains separate from the conversation's Idle state.
- On a physical phone, open and repeatedly foreground Android while the same
session is working in official Desktop/TUI; verify Android sends no live
attach/interrupt RPC, the producer completes, and final history appears.
- Pursue an upstream `session.active_list` profile field/filter or an aggregate
activity route with explicit profile ownership so multi-profile clients do
not need to resolve process-wide rows from durable keys.
@@ -1148,16 +1165,19 @@ The gateway-platform model is the *correct + sufficient architecture* (the phone
### Session drawer audit follow-ups
- **Persist and server-back Pin/Archive behavior.** The drawer currently keeps
both sets in composable memory. They reset when the drawer/app is recreated,
and Archive does not call the existing upstream profile-scoped archive API or
load archived rows. Either wire Archive end to end and persist Pin locally,
or remove the misleading actions until those contracts are complete.
- **Paginate large session stores.** Android requests only the 200 most-recent
rows and filters/searches them locally. Older sessions are therefore
undiscoverable on long-lived profiles even though upstream list APIs support
`offset`. Add incremental paging (and server search where capability-backed)
without regressing profile scoping or compression-tip projection.
- **Certify first-open latency against a large profile store.** Verify a cold
launch, immediate drawer open, repeated close/open, and profile switches on a
real high-row-count Dashboard. The first bounded page must not wait on
Gateway socket readiness; cached rows must remain visible; a timeout must end
without another long automatic read; and the final failure must be retryable
**Unavailable**, never "No sessions." Capture both client timing and the
server's session-list request duration before calling the path fixed.
- **Certify progressive paging on large stores.** Android loads 50 visible-source
recents first and appends 50-row `offset` pages near the end of the drawer.
Exercise repeated near-end triggers, a profile/route switch during page load,
hidden-source preference changes, terminal short pages, and server search
without regressing ownership, cached rows, pin/archive state, or compression
tips.
The client-side mitigations shipped (see DEVLOG 2026-06-27): the `updateSessions` clobber guard, the post-turn title reconcile (gateway), and the subtle "not auto-named here" drawer note on SSE. These two are the larger follow-ups:
@@ -1300,7 +1320,12 @@ and whether the agent is waiting on the user.
permissions; exercise compact, expanded, collapsed, and full-Voice handoff
states, background tap-through, rotation and insets, cancel/back, microphone
denial, network failure, process kill/recreation, and wake→voice→wake
resumption. Measure idle battery drain because third-party assistants do not
resumption. For background and keyguard capture, record `AudioRecord`, AppOps,
and foreground-service state: the user-installed app owns capture outside the
separate session process, so confirm whether the selected Assistant role is
sufficient on each target OS or whether activation needs an explicit,
activation-scoped microphone foreground-service lease. Measure idle battery
drain because third-party assistants do not
receive Google's dedicated low-power hotword hardware.
- **Audio quality guardrails** — normalize output volume across realtime and
+2 -2
View File
@@ -399,8 +399,8 @@ dependencies {
// [POC] Roborazzi host-side screenshot rendering (src/test, Robolectric).
// Renders real composables on the JVM at an exact canvas — no device, no
// status bar, no clipping. See StoreScreenshotTest.
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.72.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.72.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.73.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.73.0")
testImplementation(libs.compose.ui.test.junit4)
testImplementation(libs.compose.ui.test.manifest)
testImplementation("androidx.test.ext:junit:1.3.0")
@@ -7,7 +7,6 @@ import androidx.compose.runtime.CompositionLocalProvider
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.test.junit4.createComposeRule
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onNodeWithText
import androidx.test.platform.app.InstrumentationRegistry
@@ -28,50 +27,6 @@ class AmbientVisualizationVisibilityTest {
@get:Rule
val composeTestRule = createComposeRule()
@Test
fun cleanMode_backgroundOff_hidesSphereAndKeepsComposer() {
composeTestRule.setContent {
AmbientTestProviders(enabled = false) {
CleanChatMode(
messages = emptyList(),
isStreaming = false,
sphereState = SphereState.Idle,
streamingIntensity = 0f,
toolCallBurst = 0f,
animationEnabled = true,
enabled = true,
onSend = {},
onExit = {},
)
}
}
composeTestRule.onNodeWithTag(AMBIENT_RENDERER_TAG).assertDoesNotExist()
composeTestRule.onNodeWithContentDescription(targetString(R.string.agent_text_send_cd))
.assertExists()
}
@Test
fun cleanMode_backgroundOn_rendersSphere() {
composeTestRule.setContent {
AmbientTestProviders(enabled = true) {
CleanChatMode(
messages = emptyList(),
isStreaming = false,
sphereState = SphereState.Idle,
streamingIntensity = 0f,
toolCallBurst = 0f,
animationEnabled = false,
enabled = true,
onSend = {},
onExit = {},
)
}
}
composeTestRule.onNodeWithTag(AMBIENT_RENDERER_TAG).assertExists()
}
@Test
fun voiceMode_backgroundOff_hidesSphereAndKeepsVoiceUi() {
composeTestRule.setContent {
@@ -95,7 +95,7 @@ class OnboardingFlowTest {
composeTestRule.onNodeWithText("Connect").performClick()
composeTestRule.waitForIdle()
composeTestRule.onNodeWithText("Connect to Hermes").assertIsDisplayed()
composeTestRule.onNodeWithText("Add gateway").assertIsDisplayed()
}
@Test
@@ -121,16 +121,22 @@ class OnboardingFlowTest {
}
@Test
fun connectPage_recommendsGeneralSetupQr() {
fun addGatewayPage_leadsWithStandardGatewayMethods() {
setOnboardingContent()
navigateToPage(4)
composeTestRule
.onNodeWithText("Hermes nearby")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Remote gateway")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Scan Hermes setup QR")
.assertIsDisplayed()
composeTestRule
.onNodeWithText("Recommended")
.assertIsDisplayed()
.assertDoesNotExist()
}
@Test
@@ -138,7 +144,7 @@ class OnboardingFlowTest {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Server or VPS").performClick()
composeTestRule.onNodeWithText("Remote gateway").performClick()
composeTestRule.waitForIdle()
composeTestRule
@@ -151,7 +157,7 @@ class OnboardingFlowTest {
setOnboardingContent()
navigateToPage(4)
composeTestRule.onNodeWithText("Server or VPS").performClick()
composeTestRule.onNodeWithText("Remote gateway").performClick()
composeTestRule.waitForIdle()
composeTestRule
@@ -176,7 +182,7 @@ class OnboardingFlowTest {
}
@Test
fun connectPage_keepsPairingOptional() {
fun addGatewayPage_keepsPairingOptional() {
setOnboardingContent()
navigateToPage(4)
@@ -203,7 +209,7 @@ class OnboardingFlowTest {
}
@Test
fun skipButton_visibleOnIntroPages_andWizardSkipOnConnectPage() {
fun skipButton_visibleOnIntroPages_andWizardSkipOnAddGatewayPage() {
setOnboardingContent()
repeat(4) {
@@ -0,0 +1,160 @@
package com.hermesandroid.relay.ui.screens
import android.os.Handler
import android.os.Looper
import android.view.accessibility.AccessibilityNodeInfo
import androidx.activity.compose.setContent
import androidx.compose.material3.MaterialTheme
import androidx.lifecycle.Lifecycle
import androidx.test.core.app.ActivityScenario
import androidx.test.platform.app.InstrumentationRegistry
import com.hermesandroid.relay.data.BotGatewayRoute
import com.hermesandroid.relay.data.BotGatewayRouteKey
import com.hermesandroid.relay.data.BotRosterEntry
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.viewmodel.AndroidGatewayContractFixture
import com.hermesandroid.relay.viewmodel.ChatViewModel
import java.util.concurrent.TimeUnit
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.cancel
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.serialization.json.JsonPrimitive
import okhttp3.OkHttpClient
import org.junit.After
import org.junit.Assert.assertEquals
import org.junit.Assert.assertTrue
import org.junit.Before
import org.junit.Test
/** On-device proof for the route-owned first-composition collection boundary. */
class BotChatScreenBindingInstrumentedTest {
private lateinit var fixture: AndroidGatewayContractFixture
private lateinit var gatewayScope: CoroutineScope
private lateinit var dashboardClient: DashboardApiClient
private lateinit var gatewayClient: GatewayChatClient
private lateinit var viewModel: ChatViewModel
private lateinit var handler: ChatHandler
private var activityScenario: ActivityScenario<BotChatBindingTestActivity>? = null
@Before
fun setUp() {
fixture = AndroidGatewayContractFixture()
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
dashboardClient = DashboardApiClient(
baseUrl = fixture.server.url("/").toString().trimEnd('/'),
okHttpClient = OkHttpClient(),
)
gatewayClient = GatewayChatClient(
initialDashboardClient = dashboardClient,
okHttpClient = OkHttpClient(),
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
viewModel = ChatViewModel()
handler = ChatHandler()
}
@After
fun tearDown() {
activityScenario?.close()
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
dashboardClient.shutdown()
fixture.shutdown()
}
@Test
fun fastInitialHistoryRendersBeforeNavigationAndSurvivesLifecycleResume() {
val route = BotGatewayRoute(
key = BotGatewayRouteKey("fixture-gateway", PROFILE_NAME),
connectionLabel = "Fixture gateway",
)
val bot = BotRosterEntry(
profile = Profile(
name = PROFILE_NAME,
model = "fixture-model",
description = "Fixture profile",
),
displayName = "Research",
route = route,
)
val scenario = ActivityScenario.launch(BotChatBindingTestActivity::class.java)
.also { activityScenario = it }
scenario.onActivity { activity ->
activity.setContent {
MaterialTheme {
BotChatScreen(
route = route,
bot = bot,
sessionId = STORED_SESSION_ID,
gatewayClient = gatewayClient,
dashboardClient = dashboardClient,
chatViewModel = viewModel,
onBack = {},
handlerFactory = { handler },
historyLoader = { _, _, _ ->
Result.success(
listOf(
MessageItem(
id = HISTORY_ID,
sessionId = STORED_SESSION_ID,
role = "assistant",
content = JsonPrimitive(HISTORY_TEXT),
timestamp = 1.0,
finishReason = "stop",
),
),
)
},
profileIconFlow = { _, _ -> MutableStateFlow(null) },
)
}
}
}
waitUntil { handler.messages.value.singleOrNull()?.content == HISTORY_TEXT }
waitUntil { renderedTextExists(HISTORY_TEXT) }
scenario.moveToState(Lifecycle.State.STARTED)
scenario.moveToState(Lifecycle.State.RESUMED)
waitUntil { renderedTextExists(HISTORY_TEXT) }
assertEquals(0, fixture.rpcCount("prompt.submit"))
}
private fun renderedTextExists(expected: String): Boolean {
val instrumentation = InstrumentationRegistry.getInstrumentation()
instrumentation.waitForIdleSync()
val root = instrumentation.uiAutomation.rootInActiveWindow ?: return false
return root.containsText(expected)
}
private fun AccessibilityNodeInfo.containsText(expected: String): Boolean {
if (text?.toString() == expected || contentDescription?.toString() == expected) return true
return (0 until childCount).any { index -> getChild(index)?.containsText(expected) == true }
}
private fun waitUntil(condition: () -> Boolean) {
val deadline = System.nanoTime() + TimeUnit.SECONDS.toNanos(5)
while (System.nanoTime() < deadline) {
if (condition()) return
Thread.sleep(25)
}
assertTrue("Condition was not satisfied within 5 seconds", condition())
}
private companion object {
const val PROFILE_NAME = "research"
const val STORED_SESSION_ID = "20260829_120000_bot_chat"
const val HISTORY_ID = "persisted-bot-history"
const val HISTORY_TEXT = "Durable Bot Chat history is ready."
}
}
@@ -239,6 +239,60 @@ class GatewayForegroundRecoveryInstrumentedTest {
assertEquals(0, fixture.requestsTo("/v1/chat/completions"))
}
@Test
fun desktopOwnedTurn_remainsReadOnlyAcrossAndroidForegroundLifecycle() {
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val controlMethods = setOf(
"session.resume",
"session.activate",
"session.interrupt",
"prompt.submit",
)
val baseline = controlMethods.associateWith(fixture::rpcCount)
val baselineActiveList = fixture.rpcCount("session.active_list")
fixture.activeSessionStatus = "working"
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val okHttp = OkHttpClient()
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = fixture.server.url("/").toString().trimEnd('/'),
okHttpClient = okHttp,
),
okHttpClient = okHttp,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
viewModel.setChatTurnCheckpointStore(null)
viewModel.updateGatewayClient(gatewayClient)
viewModel.setChatVisible(true)
compose.activityRule.scenario.moveToState(Lifecycle.State.STARTED)
compose.activityRule.scenario.moveToState(Lifecycle.State.RESUMED)
viewModel.setChatVisible(false)
viewModel.setChatVisible(true)
fixture.awaitRpcCount("session.active_list", baselineActiveList + 1)
controlMethods.forEach { method ->
assertEquals(
"passive lifecycle sent $method",
baseline.getValue(method),
fixture.rpcCount(method),
)
}
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
assertEquals(
"observer teardown interrupted the Desktop turn",
baseline.getValue("session.interrupt"),
fixture.rpcCount("session.interrupt"),
)
}
private companion object {
const val STORED_SESSION_ID = "20260821_120000_fixture"
const val LIVE_SESSION_ID = "fixture-live-1"
@@ -263,6 +317,9 @@ internal class AndroidGatewayContractFixture {
@Volatile
var recoveryRunning = false
@Volatile
var activeSessionStatus: String? = null
private val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
sockets.add(webSocket)
@@ -282,6 +339,18 @@ internal class AndroidGatewayContractFixture {
"session.activate" -> sessionSnapshot(
(params["session_id"] as? JsonPrimitive)?.contentOrNull ?: "fixture-live-1",
)
"session.active_list" -> buildJsonObject {
put("sessions", kotlinx.serialization.json.buildJsonArray {
activeSessionStatus?.let { status ->
add(buildJsonObject {
put("id", LIVE_SESSION_ID)
put("session_key", STORED_SESSION_ID)
put("status", status)
put("last_active", 1.0)
})
}
})
}
"prompt.submit", "session.interrupt" -> buildJsonObject { put("ok", true) }
else -> JsonObject(emptyMap())
}
@@ -345,6 +414,15 @@ internal class AndroidGatewayContractFixture {
error("Gateway RPC $method not observed; saw ${rpcLog.map { it.first }}")
}
fun awaitRpcCount(method: String, count: Int) {
val deadline = System.nanoTime() + TimeUnit.SECONDS.toNanos(5)
while (System.nanoTime() < deadline) {
if (rpcCount(method) >= count) return
Thread.sleep(20)
}
error("Gateway RPC $method count $count not observed; saw ${rpcLog.map { it.first }}")
}
fun requestsTo(path: String): Int = requestPaths.count { it.startsWith(path) }
fun rpcCount(method: String): Int = rpcLog.count { it.first == method }
@@ -353,4 +431,9 @@ internal class AndroidGatewayContractFixture {
allSockets.forEach { socket -> runCatching { socket.close(1001, "teardown") } }
runCatching { server.shutdown() }
}
private companion object {
const val STORED_SESSION_ID = "20260821_120000_fixture"
const val LIVE_SESSION_ID = "fixture-live-1"
}
}
+4
View File
@@ -1,6 +1,10 @@
<?xml version="1.0" encoding="utf-8"?>
<manifest xmlns:android="http://schemas.android.com/apk/res/android">
<application>
<activity
android:name="com.hermesandroid.relay.ui.screens.BotChatBindingTestActivity"
android:exported="false"
android:screenOrientation="portrait" />
<activity
android:name="com.hermesandroid.relay.ui.screens.VoiceSettingsDesignQaActivity"
android:exported="true"
@@ -0,0 +1,6 @@
package com.hermesandroid.relay.ui.screens
import androidx.activity.ComponentActivity
/** Empty debug-only host populated by the Bot Chat lifecycle instrumentation. */
class BotChatBindingTestActivity : ComponentActivity()
@@ -1,3 +1,3 @@
v1.13.2 - Supervised Mode and clearer activity
v1.14.0 - Connections, delegated work, Git, and voice
Supervised Mode creates a simpler, profile-focused chat with device-protected parent settings and control over attachments, Standard voice, generated media, history, actions, and technical details. Activity indicators now appear only while Hermes is genuinely working, and returning from parent settings keeps Supervised Chat open.
Connections now recover independently across LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication. Preview delegated agents, use the optional native Git workspace, and get safer Continuous voice, Voice Focus, Assistant, Threads, profile drafts, and Clarify controls. Wake-word detection also packages a compatible native runtime.
+116 -1
View File
@@ -1,6 +1,121 @@
{
"schema": 2,
"schema": 3,
"versions": [
{
"version": "1.14.0",
"title": "Connections, delegated work, Git, and voice",
"date": "2026-08-30",
"summary": "Connections now recover cleanly across networks. You can also follow delegated agents, work with Git repositories, and rely on steadier voice, sessions, Threads, profiles, Assistant, and Clarify controls.",
"changes": [
{
"id": "route-aware-connections",
"kind": "improved",
"title": "Connections recover independently",
"summary": "Move between LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication.",
"highlight": true
},
{
"id": "delegated-agent-previews",
"kind": "added",
"title": "Follow delegated-agent activity",
"summary": "See lifecycle, progress, tool previews, and available read-only child history from the parent chat.",
"highlight": true
},
{
"id": "native-git-workspace",
"kind": "added",
"title": "Work with repositories from Android",
"summary": "Review status, diffs, branches, staging, commits, and remotes from Chat or Settings.",
"highlight": true
},
{
"id": "voice-focus-controls",
"kind": "improved",
"title": "Steer voice at any time",
"summary": "Stop or redirect Hermes while it is Thinking, Transcribing, or Speaking, including with accessibility controls.",
"highlight": true
},
{
"id": "non-blocking-release-notice",
"kind": "improved",
"title": "Release notes stay out of your way",
"summary": "A dismissible post-update notice keeps startup usable and leaves the complete history available from Settings."
},
{
"id": "single-chat-presentation",
"kind": "improved",
"title": "Chat uses one consistent presentation",
"summary": "The overlapping clean-focus mode was removed while the separate Voice Focus experience remains available."
},
{
"id": "wake-word-runtime",
"kind": "fixed",
"title": "Wake-word detection starts reliably",
"summary": "Compatible native voice components are now packaged for every supported phone architecture."
},
{
"id": "sphere-motion",
"kind": "fixed",
"title": "The visible Sphere keeps moving smoothly",
"summary": "Foreground animation no longer falls back to a stepped ambient pulse."
},
{
"id": "continuous-microphone-handoff",
"kind": "fixed",
"title": "Continuous voice keeps the microphone",
"summary": "The next listening turn waits for barge-in recording to release cleanly."
},
{
"id": "fresh-profile-drafts",
"kind": "fixed",
"title": "New chats keep the selected profile",
"summary": "Fresh drafts no longer reopen an older session or carry a Thread route into another profile."
},
{
"id": "provisional-thread-removal",
"kind": "fixed",
"title": "Provisional Threads can be removed safely",
"summary": "Local removal and later session promotion no longer risk duplicate rows or server history."
},
{
"id": "clarify-custom-answers",
"kind": "fixed",
"title": "Clarify keeps custom answers reachable",
"summary": "Other answers, keyboard Send, and expired prompts now behave consistently."
},
{
"id": "passive-session-observation",
"kind": "fixed",
"title": "Browsing no longer interrupts another client",
"summary": "Passive Android observation does not claim a turn owned by Desktop, TUI, or another client."
},
{
"id": "assistant-recovery-privacy",
"kind": "fixed",
"title": "Assistant sessions recover more clearly",
"summary": "No-speech feedback, recreated session state, and keyguard privacy now remain intact."
},
{
"id": "relay-auth-boundaries",
"kind": "fixed",
"title": "Protected Relay routes report the right problem",
"summary": "Authentication challenges are no longer presented as outages, while unsafe routes still fail closed."
},
{
"id": "connection-session-readiness",
"kind": "fixed",
"title": "Connections and sessions become ready sooner",
"summary": "Unavailable optional API and Relay routes no longer delay a healthy Dashboard or authenticated session history."
}
],
"compatibility": [
"Standard Chat, sessions, profiles, Manage, and standard voice continue to work without the optional Hermes-Relay Plugin.",
"The Git workspace and same-origin Relay extensions require Hermes-Relay Plugin 1.11.0.",
"Granular Device Control and the system Voice Focus overlay remain available only in the sideload build."
],
"playNotes": "Connections now recover independently across LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication. Preview delegated agents, use the optional native Git workspace, and get safer Continuous voice, Voice Focus, Assistant, Threads, profile drafts, and Clarify controls. Wake-word detection also packages a compatible native runtime.",
"sections": []
},
{
"version": "1.13.2",
"title": "Supervised Mode and clearer activity",
+29 -7
View File
@@ -1,9 +1,31 @@
v1.13.2 - Supervised Mode and clearer activity
v1.14.0 - Connections, delegated work, Git, and voice
Supervised Mode
* Protect parent settings with your phone's device authentication.
* Choose access to attachments, Standard voice, generated media, history, actions, and technical details.
* Keep Supervised Chat open when returning from parent settings.
Summary
* Connections now recover cleanly across networks. You can also follow delegated agents, work with Git repositories, and rely on steadier voice, sessions, Threads, profiles, Assistant, and Clarify controls.
Also improved
* Activity indicators now appear only while Hermes is genuinely working.
Highlights
* Connections recover independently — Move between LAN, Tailscale, and public HTTPS without mixing Dashboard and Relay authentication.
* Follow delegated-agent activity — See lifecycle, progress, tool previews, and available read-only child history from the parent chat.
* Work with repositories from Android — Review status, diffs, branches, staging, commits, and remotes from Chat or Settings.
* Steer voice at any time — Stop or redirect Hermes while it is Thinking, Transcribing, or Speaking, including with accessibility controls.
Improved
* Release notes stay out of your way — A dismissible post-update notice keeps startup usable and leaves the complete history available from Settings.
* Chat uses one consistent presentation — The overlapping clean-focus mode was removed while the separate Voice Focus experience remains available.
Fixed
* Wake-word detection starts reliably — Compatible native voice components are now packaged for every supported phone architecture.
* The visible Sphere keeps moving smoothly — Foreground animation no longer falls back to a stepped ambient pulse.
* Continuous voice keeps the microphone — The next listening turn waits for barge-in recording to release cleanly.
* New chats keep the selected profile — Fresh drafts no longer reopen an older session or carry a Thread route into another profile.
* Provisional Threads can be removed safely — Local removal and later session promotion no longer risk duplicate rows or server history.
* Clarify keeps custom answers reachable — Other answers, keyboard Send, and expired prompts now behave consistently.
* Browsing no longer interrupts another client — Passive Android observation does not claim a turn owned by Desktop, TUI, or another client.
* Assistant sessions recover more clearly — No-speech feedback, recreated session state, and keyguard privacy now remain intact.
* Protected Relay routes report the right problem — Authentication challenges are no longer presented as outages, while unsafe routes still fail closed.
* Connections and sessions become ready sooner — Unavailable optional API and Relay routes no longer delay a healthy Dashboard or authenticated session history.
Compatibility
* Standard Chat, sessions, profiles, Manage, and standard voice continue to work without the optional Hermes-Relay Plugin.
* The Git workspace and same-origin Relay extensions require Hermes-Relay Plugin 1.11.0.
* Granular Device Control and the system Voice Focus overlay remain available only in the sideload build.
@@ -39,14 +39,38 @@ enum class AssistantSessionPhase {
Closed,
}
enum class AssistantSessionNotice {
NoSpeech,
}
data class AssistantSessionSnapshot(
val phase: AssistantSessionPhase = AssistantSessionPhase.Launching,
val transcript: String? = null,
val response: String = "",
val notice: AssistantSessionNotice? = null,
val error: String? = null,
val screenContextSupported: Boolean = false,
)
internal fun assistantSnapshotForPresentation(
snapshot: AssistantSessionSnapshot,
locked: Boolean,
): AssistantSessionSnapshot = if (locked) {
snapshot.copy(
transcript = null,
response = "",
error = null,
screenContextSupported = false,
)
} else {
snapshot
}
internal fun assistantSnapshotMatchesActivation(
expectedActivationId: String?,
receivedActivationId: String?,
): Boolean = expectedActivationId != null && expectedActivationId == receivedActivationId
object AssistantRole {
fun status(context: Context): AssistantRoleStatus {
val component = ComponentName(context, HermesVoiceInteractionService::class.java)
@@ -209,6 +233,7 @@ object AssistantSessionProtocol {
onFailure = { failure ->
publish(
application,
activation.id,
AssistantSessionSnapshot(
phase = AssistantSessionPhase.Error,
error = failure.message ?: "Hermes voice could not start",
@@ -219,13 +244,19 @@ object AssistantSessionProtocol {
return true
}
fun publish(context: Context, snapshot: AssistantSessionSnapshot) {
fun publish(
context: Context,
activationId: String,
snapshot: AssistantSessionSnapshot,
) {
context.sendBroadcast(
Intent(context, AssistantSessionStateReceiver::class.java).apply {
action = ACTION_STATUS
putExtra(EXTRA_ACTIVATION_ID, activationId)
putExtra(EXTRA_PHASE, snapshot.phase.name)
putExtra(EXTRA_TRANSCRIPT, snapshot.transcript)
putExtra(EXTRA_RESPONSE, snapshot.response)
putExtra(EXTRA_NOTICE, snapshot.notice?.name)
putExtra(EXTRA_ERROR, snapshot.error)
putExtra(EXTRA_SCREEN_CONTEXT_SUPPORTED, snapshot.screenContextSupported)
}
@@ -238,10 +269,6 @@ object AssistantSessionProtocol {
}
}
fun publish(context: Context, state: VoiceUiState) {
publish(context, snapshotFromVoiceState(state))
}
internal fun snapshotFromVoiceState(state: VoiceUiState): AssistantSessionSnapshot {
val phase = when {
!state.voiceMode -> AssistantSessionPhase.Closed
@@ -256,7 +283,10 @@ object AssistantSessionProtocol {
phase = phase,
transcript = state.transcribedText?.take(MAX_SESSION_TEXT_CHARS),
response = state.responseText.take(MAX_SESSION_TEXT_CHARS),
error = state.error?.take(MAX_SESSION_ERROR_CHARS),
notice = state.assistantNotice,
error = state.error
?.takeIf { phase == AssistantSessionPhase.Error }
?.take(MAX_SESSION_ERROR_CHARS),
)
}
@@ -350,6 +380,9 @@ object AssistantSessionProtocol {
phase = phase,
transcript = intent.getStringExtra(EXTRA_TRANSCRIPT),
response = intent.getStringExtra(EXTRA_RESPONSE).orEmpty(),
notice = intent.getStringExtra(EXTRA_NOTICE)?.let { raw ->
runCatching { AssistantSessionNotice.valueOf(raw) }.getOrNull()
},
error = intent.getStringExtra(EXTRA_ERROR),
screenContextSupported = intent.getBooleanExtra(
EXTRA_SCREEN_CONTEXT_SUPPORTED,
@@ -360,24 +393,33 @@ object AssistantSessionProtocol {
private const val MAX_SESSION_TEXT_CHARS = 4_000
private const val MAX_SESSION_ERROR_CHARS = 1_000
private const val EXTRA_NOTICE = "notice"
}
object AssistantSessionState {
private val _snapshot = MutableStateFlow(AssistantSessionSnapshot())
val snapshot: StateFlow<AssistantSessionSnapshot> = _snapshot.asStateFlow()
@Volatile private var activationId: String? = null
internal fun update(snapshot: AssistantSessionSnapshot) {
internal fun update(receivedActivationId: String?, snapshot: AssistantSessionSnapshot) {
if (!assistantSnapshotMatchesActivation(activationId, receivedActivationId)) return
_snapshot.value = snapshot
}
internal fun reset() {
internal fun reset(activationId: String) {
this.activationId = activationId
_snapshot.value = AssistantSessionSnapshot()
}
}
class AssistantSessionStateReceiver : BroadcastReceiver() {
override fun onReceive(context: Context, intent: Intent) {
AssistantSessionState.update(AssistantSessionProtocol.readSnapshot(intent))
AssistantSessionState.update(
receivedActivationId = intent.getStringExtra(
AssistantSessionProtocol.EXTRA_ACTIVATION_ID
),
snapshot = AssistantSessionProtocol.readSnapshot(intent),
)
}
}
@@ -423,6 +465,7 @@ class AssistantSessionLifecycleReceiver : BroadcastReceiver() {
onFailure = { failure ->
AssistantSessionProtocol.publish(
application,
id,
AssistantSessionSnapshot(
phase = AssistantSessionPhase.Error,
error = failure.message ?: "Hermes voice could not start",
@@ -430,6 +473,7 @@ class AssistantSessionLifecycleReceiver : BroadcastReceiver() {
)
},
)
application.runtime.republishAssistantSnapshot(id)
return
}
if (AssistantSessionProtocol.isStartAction(intent.action)) {
@@ -3,6 +3,11 @@ package com.hermesandroid.relay.assistant
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.drawable.ColorDrawable
import android.app.KeyguardManager
import android.content.BroadcastReceiver
import android.content.Context
import android.content.Intent
import android.content.IntentFilter
import android.os.Bundle
import android.service.voice.VoiceInteractionSession
import android.service.voice.VoiceInteractionSessionService
@@ -67,6 +72,7 @@ import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import androidx.core.content.ContextCompat
import androidx.lifecycle.Lifecycle
import androidx.lifecycle.LifecycleOwner
import androidx.lifecycle.LifecycleRegistry
@@ -108,6 +114,11 @@ internal fun shouldCancelVoiceWhenSessionUiEnds(
presentation: AssistantSessionPresentation,
): Boolean = presentation == AssistantSessionPresentation.Overlay
internal fun assistantPresentationLocked(
currentKeyguardLocked: Boolean?,
fallbackLocked: Boolean,
): Boolean = currentKeyguardLocked ?: fallbackLocked
private class HermesVoiceInteractionSession(
private val service: HermesVoiceInteractionSessionService,
) : VoiceInteractionSession(service) {
@@ -118,12 +129,19 @@ private class HermesVoiceInteractionSession(
private var surfaceExpanded by mutableStateOf(false)
private var activationId: String? = null
private var manualMic = false
private var keyguardLocked by mutableStateOf(false)
private var expectScreenContext: Boolean? = null
private var pendingSemantic = AssistantSemanticContext()
private var pendingScreenshot: ByteArray? = null
private var screenContextUi by mutableStateOf(AssistantScreenContextUi())
private val contextStore = assistantContextStore(service)
private var heartbeatJob: Job? = null
private var keyguardReceiverRegistered = false
private val keyguardReceiver = object : BroadcastReceiver() {
override fun onReceive(context: Context?, intent: Intent?) {
refreshKeyguardState()
}
}
init {
scope.launch {
@@ -139,6 +157,17 @@ private class HermesVoiceInteractionSession(
override fun onCreate() {
super.onCreate()
ContextCompat.registerReceiver(
service,
keyguardReceiver,
IntentFilter().apply {
addAction(Intent.ACTION_SCREEN_OFF)
addAction(Intent.ACTION_SCREEN_ON)
addAction(Intent.ACTION_USER_PRESENT)
},
ContextCompat.RECEIVER_NOT_EXPORTED,
)
keyguardReceiverRegistered = true
window.window?.apply {
setBackgroundDrawable(ColorDrawable(android.graphics.Color.TRANSPARENT))
clearFlags(WindowManager.LayoutParams.FLAG_DIM_BEHIND)
@@ -155,6 +184,7 @@ private class HermesVoiceInteractionSession(
PersistedHermesRelayTheme {
AssistantSessionSurface(
expanded = surfaceExpanded,
locked = keyguardLocked,
screenContext = screenContextUi,
onExpandedChange = { surfaceExpanded = it },
onCancel = { finishSession(cancelVoice = true) },
@@ -183,11 +213,22 @@ private class HermesVoiceInteractionSession(
override fun onShow(args: Bundle?, showFlags: Int) {
super.onShow(args, showFlags)
if (args?.getBoolean(HermesVoiceInteractionService.EXTRA_FROM_KEYGUARD, false) == true) {
refreshKeyguardState(
fallbackLocked = args?.getBoolean(
HermesVoiceInteractionService.EXTRA_FROM_KEYGUARD,
false,
) == true,
)
if (keyguardLocked) {
window.window?.addFlags(
WindowManager.LayoutParams.FLAG_SHOW_WHEN_LOCKED or
WindowManager.LayoutParams.FLAG_TURN_SCREEN_ON
)
} else {
window.window?.clearFlags(
WindowManager.LayoutParams.FLAG_SHOW_WHEN_LOCKED or
WindowManager.LayoutParams.FLAG_TURN_SCREEN_ON
)
}
setUiEnabled(true)
val startsNewLifecycle = presentation == AssistantSessionPresentation.Inactive
@@ -195,10 +236,10 @@ private class HermesVoiceInteractionSession(
if (!startsNewLifecycle) return
surfaceExpanded = false
AssistantSessionState.reset()
screenContextUi = AssistantScreenContextUi()
activationId = args?.getString(AssistantSessionProtocol.EXTRA_ACTIVATION_ID)
?: UUID.randomUUID().toString()
AssistantSessionState.reset(activationId!!)
manualMic = args?.getBoolean(AssistantSessionProtocol.EXTRA_MANUAL_MIC, false) ?: false
expectScreenContext = args?.getBoolean(
AssistantSessionProtocol.EXTRA_EXPECT_SCREEN_CONTEXT,
@@ -300,6 +341,10 @@ private class HermesVoiceInteractionSession(
pendingSemantic = AssistantSemanticContext()
pendingScreenshot = null
screenContextUi = AssistantScreenContextUi()
if (keyguardReceiverRegistered) {
runCatching { service.unregisterReceiver(keyguardReceiver) }
keyguardReceiverRegistered = false
}
viewOwner.stop()
scope.cancel()
super.onDestroy()
@@ -319,6 +364,7 @@ private class HermesVoiceInteractionSession(
)
}.onFailure {
AssistantSessionState.update(
activationId,
AssistantSessionSnapshot(
phase = AssistantSessionPhase.Error,
error = it.message ?: "Hermes could not open the voice session.",
@@ -337,6 +383,7 @@ private class HermesVoiceInteractionSession(
setUiEnabled(false)
}.onFailure {
AssistantSessionState.update(
activationId,
AssistantSessionSnapshot(
phase = AssistantSessionPhase.Error,
error = it.message ?: "Hermes could not open full voice.",
@@ -377,6 +424,14 @@ private class HermesVoiceInteractionSession(
}
}
private fun refreshKeyguardState(fallbackLocked: Boolean = keyguardLocked) {
keyguardLocked = assistantPresentationLocked(
currentKeyguardLocked = service.getSystemService(KeyguardManager::class.java)
?.isKeyguardLocked,
fallbackLocked = fallbackLocked,
)
}
@RequiresApi(android.os.Build.VERSION_CODES.Q)
private fun stageAssistState(state: AssistState) {
stageAssistData(state.assistStructure, state.assistContent)
@@ -463,6 +518,7 @@ private class AssistantSessionViewOwner :
@Composable
private fun AssistantSessionSurface(
expanded: Boolean,
locked: Boolean,
screenContext: AssistantScreenContextUi,
onExpandedChange: (Boolean) -> Unit,
onCancel: () -> Unit,
@@ -471,7 +527,8 @@ private fun AssistantSessionSurface(
onOpenFullVoice: () -> Unit,
onSurfaceBoundsChanged: (android.graphics.Rect) -> Unit,
) {
val snapshot by AssistantSessionState.snapshot.collectAsState()
val rawSnapshot by AssistantSessionState.snapshot.collectAsState()
val snapshot = assistantSnapshotForPresentation(rawSnapshot, locked)
val status = assistantStatus(snapshot.phase)
val transmittedScreenContext = if (snapshot.screenContextSupported) {
screenContext
@@ -650,6 +707,13 @@ private fun ExpandedAssistantSurface(
color = MaterialTheme.colorScheme.onSurface,
)
}
snapshot.notice?.let { notice ->
Text(
text = assistantNoticeText(notice),
color = MaterialTheme.colorScheme.onSurfaceVariant,
style = MaterialTheme.typography.bodyMedium,
)
}
snapshot.error?.let { error ->
Text(
text = error,
@@ -896,5 +960,11 @@ private fun assistantStatus(phase: AssistantSessionPhase): String = when (phase)
private fun compactAssistantText(snapshot: AssistantSessionSnapshot): String =
snapshot.transcript?.takeIf { it.isNotBlank() }
?: snapshot.response.takeIf { it.isNotBlank() }
?: snapshot.notice?.let { assistantNoticeText(it) }
?: snapshot.error?.takeIf { it.isNotBlank() }
?: assistantStatus(snapshot.phase)
@Composable
private fun assistantNoticeText(notice: AssistantSessionNotice): String = when (notice) {
AssistantSessionNotice.NoSpeech -> stringResource(R.string.voice_no_speech_try_again)
}
@@ -994,7 +994,7 @@ class AuthManager(
val serverSource = if (serverIssuedCode != null) "QR" else "local-fallback"
Log.i(
TAG,
"authenticate: sending pairing_code=$codeToSend source=$serverSource " +
"authenticate: sending pairing credential source=$serverSource " +
"ttl=$pendingTtlSeconds grants=${pendingGrants?.keys}"
)
buildJsonObject {
@@ -1063,7 +1063,8 @@ class AuthManager(
_currentPairedSession.value = null
Log.i(
TAG,
"applyServerIssuedCodeAndReset: code=$normalized relayUrl=$relayUrl " +
"applyServerIssuedCodeAndReset: credential=present " +
"relayConfigured=${!relayUrl.isNullOrBlank()} " +
"prevState=${prevState::class.simpleName} → Unpaired"
)
scope.launch {
@@ -10,6 +10,16 @@ package com.hermesandroid.relay.data
*/
object AgentDisplay {
const val SERVER_DEFAULT_PROFILE_KEY: String = "__server_default__"
private const val PROFILE_CONTEXT_SEPARATOR = "::"
data class ProfileContextIdentity(
val connectionId: String,
val profileKey: String,
) {
/** Null means the upstream request must inherit Server Default. */
val requestProfileName: String?
get() = profileRequestName(profileKey)
}
private val GENERIC_MODEL_ALIASES = setOf(
"hermes-agent",
"hermes_agent",
@@ -163,7 +173,25 @@ object AgentDisplay {
profileRequestName(profileName) ?: SERVER_DEFAULT_PROFILE_KEY
fun profileContextKey(connectionId: String?, profileName: String?): String =
"${connectionId.orEmpty()}::${profileSessionKey(profileName)}"
"${connectionId.orEmpty()}$PROFILE_CONTEXT_SEPARATOR${profileSessionKey(profileName)}"
/**
* Parse the canonical profile/context identity used by persisted chat state.
*
* Legacy or malformed opaque keys deliberately return null: recovery may
* still use the exact key for ownership, but must not invent an upstream
* profile override from it. The first separator is authoritative so legal
* profile names containing `::` remain round-trippable.
*/
fun parseProfileContextKey(contextKey: String?): ProfileContextIdentity? {
val raw = contextKey?.trim().orEmpty()
val separator = raw.indexOf(PROFILE_CONTEXT_SEPARATOR)
if (separator <= 0 || separator + PROFILE_CONTEXT_SEPARATOR.length >= raw.length) return null
val connectionId = raw.substring(0, separator).trim()
val profileKey = raw.substring(separator + PROFILE_CONTEXT_SEPARATOR.length).trim()
if (connectionId.isEmpty() || profileKey.isEmpty()) return null
return ProfileContextIdentity(connectionId, profileKey)
}
fun localDisplayAlias(value: String?): String? =
value
@@ -10,6 +10,16 @@ package com.hermesandroid.relay.data
*/
enum class AttachmentState { LOADING, LOADED, FAILED }
/**
* Gateway tool events do not yet expose an output kind before completion.
* Recognize the upstream built-in plus the profile-tool naming convention used
* for image generators without guessing from generic prompt arguments.
*/
internal fun isImageGenerationToolName(name: String): Boolean {
val normalized = name.trim().lowercase()
return normalized == "image_generate" || normalized.endsWith("_create_image")
}
/**
* How the UI should render a loaded attachment. Derived from the MIME type.
* - [IMAGE] inline image (decode bytes / load URI).
@@ -23,6 +23,8 @@ import kotlinx.serialization.json.Json
data class ChatTurnCheckpoint(
val schemaVersion: Int = CURRENT_SCHEMA,
val contextKey: String,
/** Explicit persisted profile identity; null only for legacy checkpoints. */
val profileKey: String? = null,
val sessionId: String,
val liveSessionId: String? = null,
val transport: String,
@@ -1,6 +1,8 @@
package com.hermesandroid.relay.data
import kotlinx.serialization.Serializable
import java.net.Inet6Address
import java.net.InetAddress
import java.net.URI
@Serializable
@@ -65,6 +67,14 @@ data class Connection(
* "derive from [apiServerUrl] using the conventional same-host :9119".
*/
val dashboardUrl: String? = null,
/**
* Credential-free origin that most recently completed Dashboard
* authentication for this connection. Public origins require HTTPS;
* loopback/private-overlay HTTP retains upstream's trusted-network mode.
* Dashboard/Gateway consumers prefer this origin, while [routeCandidates]
* continue to own only network route selection for API and Relay.
*/
val authenticatedDashboardOrigin: String? = null,
val dashboardAuthRequired: Boolean? = null,
val dashboardAuthProviders: List<String> = emptyList(),
val dashboardLastStatus: DashboardConnectionStatus? = null,
@@ -77,6 +87,11 @@ data class Connection(
val routeCandidates: List<EndpointCandidate> = emptyList(),
/** Optional user preference such as "lan" or "tailscale"; null means Auto. */
val preferredRouteRole: String? = null,
/**
* Explicit per-installation consent for Relay Git repository discovery.
* Missing legacy values remain off; route/profile changes do not broaden it.
*/
val gitRepoScanningEnabled: Boolean = false,
/** Epoch milliseconds. Pass `System.currentTimeMillis()`; do not pass seconds. */
val pairedAt: Long? = null,
/** Last time the user explicitly selected this connection. */
@@ -86,21 +101,27 @@ data class Connection(
/** Epoch milliseconds. The auth.ok `expires_at` field is seconds — multiply by 1000 at the call site. */
val expiresAt: Long? = null,
) {
/**
* Effective Dashboard/Gateway endpoint. Legacy records did not persist a
* dashboard URL, so they retain the conventional same-host `:9119`
* derivation from the API server. Dashboard-only records persist an
* explicit URL and may leave [apiServerUrl] and [relayUrl] blank.
*/
val resolvedDashboardUrl: String
/** Saved Dashboard/Gateway route before any authenticated-origin override. */
val configuredDashboardUrl: String
get() = dashboardUrl
?.trim()
?.takeIf { it.isNotBlank() }
?: deriveDefaultDashboardUrl(apiServerUrl).orEmpty()
/**
* Effective Dashboard/Gateway endpoint. A verified authenticated origin
* wins without rewriting the saved network route. Legacy records retain
* the conventional same-host `:9119` derivation through
* [configuredDashboardUrl].
*/
val resolvedDashboardUrl: String
get() = authenticatedDashboardOrigin
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
?: configuredDashboardUrl
/** Stable display/host identity that does not depend on the API surface. */
val primaryEndpointUrl: String
get() = resolvedDashboardUrl.takeIf { it.isNotBlank() }
get() = configuredDashboardUrl.takeIf { it.isNotBlank() }
?: apiServerUrl.trim().takeIf { it.isNotBlank() }
?: relayUrl.trim()
@@ -506,6 +527,12 @@ data class Connection(
)
}
/**
* Normalize a hand-typed Dashboard/Gateway address. Bare private,
* LAN, and Tailscale hosts use upstream's `http://…:9119` default;
* bare public hosts use `https://` on the standard HTTPS port.
* Explicit schemes and ports are preserved for precise validation.
*/
fun normalizeDashboardUrlInput(
raw: String,
defaultPort: Int = DEFAULT_DASHBOARD_PORT,
@@ -513,7 +540,10 @@ data class Connection(
val trimmed = raw.trim().trimEnd('/')
if (trimmed.isEmpty()) return trimmed
if (SCHEME_REGEX.containsMatchIn(trimmed)) return trimmed
val withScheme = "http://$trimmed"
val provisionalHttpUrl = "http://$trimmed"
val publicAddress = inferRouteRole(provisionalHttpUrl) == "public"
val withScheme = if (publicAddress) "https://$trimmed" else provisionalHttpUrl
if (publicAddress) return withScheme
val uri = runCatching { URI(withScheme) }.getOrNull()
val canAppendPort = uri != null &&
!uri.host.isNullOrBlank() &&
@@ -528,16 +558,41 @@ data class Connection(
.getOrNull()
?.lowercase()
?: return "custom"
val normalizedHost = host.removePrefix("[").removeSuffix("]")
if (normalizedHost.contains(':')) {
val address = runCatching { InetAddress.getByName(normalizedHost) }
.getOrNull() as? Inet6Address
?: return "public"
return when {
isTailscaleIpv6(address) -> "tailscale"
address.isAnyLocalAddress ||
address.isLoopbackAddress ||
address.isLinkLocalAddress ||
isUniqueLocalIpv6(address) -> "lan"
else -> "public"
}
}
return when {
host.endsWith(".ts.net") || isTailscaleIpv4(host) -> "tailscale"
host == "localhost" ||
host == "127.0.0.1" ||
host == "::1" ||
isPrivateLanIpv4(host) -> "lan"
normalizedHost.endsWith(".ts.net") || isTailscaleIpv4(normalizedHost) -> "tailscale"
normalizedHost == "localhost" ||
normalizedHost == "127.0.0.1" ||
normalizedHost.endsWith(".local") ||
normalizedHost.endsWith(".lan") ||
!normalizedHost.contains('.') ||
isPrivateLanIpv4(normalizedHost) -> "lan"
else -> "public"
}
}
private fun isTailscaleIpv6(address: Inet6Address): Boolean {
val bytes = address.address
val prefix = intArrayOf(0xfd, 0x7a, 0x11, 0x5c, 0xa1, 0xe0)
return prefix.indices.all { index -> bytes[index].toInt() and 0xff == prefix[index] }
}
private fun isUniqueLocalIpv6(address: Inet6Address): Boolean =
address.address.first().toInt() and 0xfe == 0xfc
private fun isTailscaleIpv4(host: String): Boolean {
val parts = host.split('.').mapNotNull { it.toIntOrNull() }
if (parts.size != 4) return false
@@ -557,3 +612,45 @@ data class Connection(
}
}
}
/** Normalize an absolute, credential-free HTTPS origin for authenticated Dashboard use. */
internal fun normalizeCredentialFreeHttpsOrigin(raw: String): String? {
val parsed = runCatching { URI(raw.trim()) }.getOrNull() ?: return null
if (!parsed.scheme.equals("https", ignoreCase = true)) return null
if (parsed.host.isNullOrBlank() || parsed.userInfo != null) return null
if (parsed.query != null || parsed.fragment != null) return null
if (parsed.port > 65_535) return null
return parsed.normalize().toASCIIString().trimEnd('/').takeIf { it.isNotBlank() }
}
/**
* Normalize a reviewed Dashboard credential owner. Public origins require
* HTTPS; cleartext is accepted only for literal loopback, RFC1918/link-local,
* or Tailscale CGNAT addresses.
*/
internal fun normalizeCredentialFreeAuthenticatedDashboardOrigin(raw: String): String? {
normalizeCredentialFreeHttpsOrigin(raw)?.let { return it }
val parsed = runCatching { URI(raw.trim()) }.getOrNull() ?: return null
if (!parsed.scheme.equals("http", ignoreCase = true)) return null
val host = parsed.host
?.lowercase()
?.removePrefix("[")
?.removeSuffix("]")
?.takeIf { it.isNotBlank() }
?: return null
if (parsed.userInfo != null || parsed.query != null || parsed.fragment != null) return null
if (parsed.port > 65_535) return null
val trustedHost = host == "localhost" || host == "127.0.0.1" || host == "::1" ||
host.split('.').mapNotNull(String::toIntOrNull).let { octets ->
octets.size == 4 && octets.all { it in 0..255 } && when {
octets[0] == 10 -> true
octets[0] == 172 && octets[1] in 16..31 -> true
octets[0] == 192 && octets[1] == 168 -> true
octets[0] == 169 && octets[1] == 254 -> true
octets[0] == 100 && octets[1] in 64..127 -> true
else -> false
}
}
if (!trustedHost) return null
return parsed.normalize().toASCIIString().trimEnd('/').takeIf { it.isNotBlank() }
}
@@ -18,6 +18,9 @@ package com.hermesandroid.relay.data
*/
enum class SurfaceSecurityKind { Tls, Overlay, Plain }
/** Whether a configured surface currently contributes traffic to the connection. */
enum class SurfaceUseState { InUse, Available, Unavailable }
/** Connection-level rollup across the surfaces actually in use. */
enum class ConnectionSecurityLevel { Tls, Overlay, Mixed, Plain, Unknown }
@@ -28,6 +31,7 @@ data class SurfaceSecurity(
/** Human mechanism: "TLS", "Tailscale", "WireGuard", "Proxy", "Plain". */
val mechanism: String,
val url: String,
val useState: SurfaceUseState = SurfaceUseState.InUse,
)
data class ConnectionSecurity(
@@ -86,6 +90,7 @@ fun classifySurfaceSecurity(
url: String,
activeEndpoint: EndpointCandidate?,
isTailscaleDetected: Boolean,
useState: SurfaceUseState = SurfaceUseState.InUse,
): SurfaceSecurity {
val secureLinkProtected = activeEndpoint.secureLinkProtects(label, url)
val (kind, mechanism) = when {
@@ -96,7 +101,13 @@ fun classifySurfaceSecurity(
SurfaceSecurityKind.Overlay to activeEndpoint.overlayMechanism(isTailscaleDetected)
else -> SurfaceSecurityKind.Plain to "Plain"
}
return SurfaceSecurity(label = label, kind = kind, mechanism = mechanism, url = url)
return SurfaceSecurity(
label = label,
kind = kind,
mechanism = mechanism,
url = url,
useState = useState,
)
}
private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): Boolean {
@@ -112,8 +123,8 @@ private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): B
} ?: return false
val normalized = url.trim().trimEnd('/')
val service = when (label) {
"Chat & Manage" -> "dashboard"
"API / sessions" -> "api"
"Chat & Manage", "Dashboard & Gateway" -> "dashboard"
"API / sessions", "API fallback" -> "api"
"Relay tools" -> "relay"
else -> return false
}
@@ -137,23 +148,67 @@ fun computeConnectionSecurity(
relayConfigured: Boolean,
activeEndpoint: EndpointCandidate?,
isTailscaleDetected: Boolean,
dashboardInUse: Boolean = true,
apiInUse: Boolean = true,
apiAvailable: Boolean = apiInUse,
relayInUse: Boolean = relayConfigured,
apiEndpoint: EndpointCandidate? = activeEndpoint,
relayEndpoint: EndpointCandidate? = activeEndpoint,
): ConnectionSecurity {
val surfaces = buildList {
dashboardUrl.trim().takeIf { it.isNotBlank() }?.let {
add(classifySurfaceSecurity("Chat & Manage", it, activeEndpoint, isTailscaleDetected))
add(
classifySurfaceSecurity(
label = "Dashboard & Gateway",
url = it,
activeEndpoint = activeEndpoint,
isTailscaleDetected = isTailscaleDetected,
useState = if (dashboardInUse) SurfaceUseState.InUse else SurfaceUseState.Unavailable,
)
)
}
apiUrl.trim().takeIf { it.isNotBlank() }?.let {
add(classifySurfaceSecurity("API / sessions", it, activeEndpoint, isTailscaleDetected))
add(
classifySurfaceSecurity(
label = "API fallback",
url = it,
activeEndpoint = apiEndpoint,
isTailscaleDetected = isTailscaleDetected,
useState = when {
apiInUse -> SurfaceUseState.InUse
apiAvailable -> SurfaceUseState.Available
else -> SurfaceUseState.Unavailable
},
)
)
}
if (relayConfigured) {
relayUrl.trim().takeIf { it.isNotBlank() }?.let {
add(classifySurfaceSecurity("Relay tools", it, activeEndpoint, isTailscaleDetected))
add(
classifySurfaceSecurity(
label = "Relay tools",
url = it,
activeEndpoint = relayEndpoint,
isTailscaleDetected = isTailscaleDetected,
useState = if (relayInUse) SurfaceUseState.InUse else SurfaceUseState.Unavailable,
)
)
}
}
}
if (surfaces.isEmpty()) return ConnectionSecurity.UNKNOWN
val kinds = surfaces.map { it.kind }.toSet()
// Configured-but-unavailable fallbacks remain visible in the breakdown,
// but do not make the active transport look insecure.
val activeSurfaces = surfaces.filter { it.useState == SurfaceUseState.InUse }
if (activeSurfaces.isEmpty()) {
return ConnectionSecurity(
level = ConnectionSecurityLevel.Unknown,
mechanism = "",
surfaces = surfaces,
)
}
val kinds = activeSurfaces.map { it.kind }.toSet()
val hasPlain = SurfaceSecurityKind.Plain in kinds
val hasSecure = kinds.any { it != SurfaceSecurityKind.Plain }
@@ -167,7 +222,7 @@ fun computeConnectionSecurity(
val mechanism = when (level) {
ConnectionSecurityLevel.Tls -> "TLS"
ConnectionSecurityLevel.Overlay ->
surfaces.firstOrNull { it.kind == SurfaceSecurityKind.Overlay }?.mechanism ?: "Encrypted"
activeSurfaces.firstOrNull { it.kind == SurfaceSecurityKind.Overlay }?.mechanism ?: "Encrypted"
ConnectionSecurityLevel.Mixed -> "Mixed"
ConnectionSecurityLevel.Plain -> when (activeEndpoint?.role?.lowercase()) {
"lan" -> "LAN"
@@ -149,15 +149,15 @@ class ConnectionStore private constructor(
// between the two names — `{"id": ..., "label": ..., ...}` —
// so no per-record migration is needed.
if (newJson == null && oldJson != null) {
val restored = decodeConnections(oldJson)
dataStore.edit { p ->
p[KEY_CONNECTIONS] = oldJson
p[KEY_CONNECTIONS] = encodeConnections(restored)
p.remove(KEY_LEGACY_PROFILES)
if (activeNew == null && activeOld != null) {
p[KEY_ACTIVE_CONNECTION_ID] = activeOld
p.remove(KEY_LEGACY_ACTIVE_PROFILE_ID)
}
}
val restored = decodeConnections(oldJson)
val validStartupId = startupId?.takeIf { id -> restored.any { it.id == id } }
_connections.value = restored
_startupConnectionId.value = validStartupId
@@ -168,6 +168,12 @@ class ConnectionStore private constructor(
)
} else {
val restored = decodeConnections(newJson)
if (newJson != null) {
val normalizedJson = encodeConnections(restored)
if (normalizedJson != newJson) {
dataStore.edit { p -> p[KEY_CONNECTIONS] = normalizedJson }
}
}
val validStartupId = startupId?.takeIf { id -> restored.any { it.id == id } }
_connections.value = restored
_startupConnectionId.value = validStartupId
@@ -571,7 +577,17 @@ class ConnectionStore private constructor(
internal fun Connection.withDashboardDefaults(): Connection {
val derivedDashboardUrl = Connection.deriveDefaultDashboardUrl(apiServerUrl)
val effectiveDashboardUrl = dashboardUrl?.takeIf { it.isNotBlank() } ?: derivedDashboardUrl
val storedOrDefaultRoutes = routeCandidates.ifEmpty {
val legacyAuthenticatedRoute = routeCandidates.firstOrNull {
it.role.equals(LEGACY_AUTHENTICATED_DASHBOARD_ROUTE_ROLE, ignoreCase = true)
}
val migratedAuthenticatedOrigin = authenticatedDashboardOrigin
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
?: legacyAuthenticatedRoute?.dashboard?.url
?.let(::normalizeCredentialFreeAuthenticatedDashboardOrigin)
val routesWithoutLegacyAuthentication = routeCandidates.filterNot {
it.role.equals(LEGACY_AUTHENTICATED_DASHBOARD_ROUTE_ROLE, ignoreCase = true)
}
val storedOrDefaultRoutes = routesWithoutLegacyAuthentication.ifEmpty {
Connection.buildRouteCandidates(
apiServerUrl = apiServerUrl,
relayUrl = relayUrl,
@@ -582,16 +598,18 @@ internal fun Connection.withDashboardDefaults(): Connection {
dashboardUrl = effectiveDashboardUrl,
candidates = storedOrDefaultRoutes,
)
val normalizedPreferredRouteRole = preferredRouteRole?.takeIf { preferred ->
normalizedRoutes.any { it.role.equals(preferred, ignoreCase = true) }
}
val normalizedPreferredRouteRole = preferredRouteRole
?.takeUnless { it.equals(LEGACY_AUTHENTICATED_DASHBOARD_ROUTE_ROLE, ignoreCase = true) }
?.takeIf { preferred -> normalizedRoutes.any { it.role.equals(preferred, ignoreCase = true) } }
return if (
dashboardUrl != effectiveDashboardUrl ||
authenticatedDashboardOrigin != migratedAuthenticatedOrigin ||
normalizedRoutes != routeCandidates ||
normalizedPreferredRouteRole != preferredRouteRole
) {
copy(
dashboardUrl = effectiveDashboardUrl,
authenticatedDashboardOrigin = migratedAuthenticatedOrigin,
routeCandidates = normalizedRoutes,
preferredRouteRole = normalizedPreferredRouteRole,
)
@@ -599,3 +617,5 @@ internal fun Connection.withDashboardDefaults(): Connection {
this
}
}
internal const val LEGACY_AUTHENTICATED_DASHBOARD_ROUTE_ROLE = "authenticated_dashboard"
@@ -25,7 +25,7 @@ import java.net.URI
*
* **Semantics (locked by ADR 24):**
* - [role] is an open string. Known values `lan` / `tailscale` / `public`
* get styled labels; anything else renders generically (`Custom VPN (<role>)`).
* get styled labels; anything else renders generically (`Custom route (<role>)`).
* No enum, no normalization — the raw role string must round-trip exactly
* so HMAC canonicalization holds.
* - [priority] is strict, `0 = highest`. Reachability never promotes a lower
@@ -145,18 +145,19 @@ data class BrokerEndpoint(
*
* Unknown roles (`"wireguard"`, `"zerotier"`, `"netbird-eu"`, operator-defined
* labels) return false so the UI can fall back to [displayLabel]'s generic
* "Custom VPN" treatment.
* "Custom route" treatment.
*/
fun EndpointCandidate.isKnownRole(): Boolean {
return when (role.lowercase()) {
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "outbound_broker", "https" -> true
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "outbound_broker", "https",
"dashboard", "authenticated_dashboard" -> true
else -> false
}
}
/**
* Human-readable label for the UI. Known roles get fixed-case styled labels;
* unknown roles render as `"Custom VPN (<role>)"` with the raw role preserved
* unknown roles render as `"Custom route (<role>)"` with the raw role preserved
* so an operator can see exactly what they labeled it.
*
* The raw [role] on the [EndpointCandidate] is NOT modified — it stays in its
@@ -172,12 +173,27 @@ fun EndpointCandidate.displayLabel(): String {
"Public"
}
"https" -> "HTTPS"
"dashboard", "authenticated_dashboard" -> if (
primaryRouteUrl()?.startsWith("https://", ignoreCase = true) == true
) {
"HTTPS Dashboard"
} else {
"Dashboard"
}
"plugin_proxy", "plugin-proxy" -> "Hermes Secure Link"
"outbound_broker", "broker", "relay_broker" -> "Hermes Reach · Experimental"
else -> "Custom VPN ($role)"
else -> displayName?.trim()?.takeIf { it.isNotBlank() } ?: "Custom route ($role)"
}
}
/**
* True for a route created only to keep Dashboard/Gateway authentication on
* its canonical origin. It is a service address, not another selectable
* whole-connection or VPN route.
*/
fun EndpointCandidate.isDashboardOnlyRoute(): Boolean =
api == null && relay == null && proxy == null && broker == null && dashboard != null
/** Dashboard-first URL identity for routing, diagnostics, and UI labels. */
fun EndpointCandidate.primaryRouteUrl(): String? =
dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
@@ -185,6 +201,11 @@ fun EndpointCandidate.primaryRouteUrl(): String? =
?: relay?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
?: proxy?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
/** Dashboard/Gateway identity only; Relay and broker transports are extensions. */
fun EndpointCandidate.gatewayRouteUrl(): String? =
dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }
?: api?.url?.let(Connection::deriveDefaultDashboardUrl)
/** Stable host/port identity without assuming that an API surface exists. */
fun EndpointCandidate.routeAuthority(): String? {
val rawUrl = primaryRouteUrl() ?: return null
@@ -38,6 +38,8 @@ data class ProactiveInboxEntry(
val connectionId: String? = null,
/** Relay proved this row came from its bounded offline queue. */
val arrivedWhileAway: Boolean = false,
/** Exact Android notification slot, when recorded by the receiving build. */
val notificationId: Int? = null,
)
private val Context.proactiveInboxStore: DataStore<Preferences> by
@@ -58,15 +60,19 @@ private const val MAX_ENTRIES = 100
* bounded store also backs the provisional Thread until the user's first reply
* promotes it to a real `source=phone` session.
*/
class ProactiveInboxRepository(private val context: Context) {
class ProactiveInboxRepository internal constructor(
private val store: DataStore<Preferences>,
) {
constructor(context: Context) : this(context.proactiveInboxStore)
private val json = Json { ignoreUnknownKeys = true }
val entries: Flow<List<ProactiveInboxEntry>> =
context.proactiveInboxStore.data.map { prefs -> decode(prefs[INBOX_JSON]) }
store.data.map { prefs -> decode(prefs[INBOX_JSON]) }
suspend fun add(entry: ProactiveInboxEntry) {
context.proactiveInboxStore.edit { prefs ->
store.edit { prefs ->
val current = decode(prefs[INBOX_JSON]).toMutableList()
current.removeAll { it.id == entry.id }
current.add(0, entry)
@@ -76,7 +82,40 @@ class ProactiveInboxRepository(private val context: Context) {
}
suspend fun clear() {
context.proactiveInboxStore.edit { it.remove(INBOX_JSON) }
store.edit { it.remove(INBOX_JSON) }
}
/**
* Remove one provisional Thread owned by one saved connection.
*
* This only edits the bounded local inbox. A promoted Thread is server
* history and is deliberately outside this repository, so this operation
* can never delete it. Legacy entries without a connection owner are
* removed with the active row because they are rendered in that row; rows
* explicitly owned by another connection remain isolated.
*/
suspend fun removeThread(
chatId: String,
connectionId: String,
): List<ProactiveInboxEntry> {
val normalizedChatId = chatId.ifBlank { "phone" }
var removed = emptyList<ProactiveInboxEntry>()
store.edit { prefs ->
val current = decode(prefs[INBOX_JSON])
removed = current.filter {
(it.connectionId == null || it.connectionId == connectionId) &&
(it.chatId ?: "phone") == normalizedChatId
}
if (removed.isNotEmpty()) {
val retained = current.filterNot { it in removed }
if (retained.isEmpty()) {
prefs.remove(INBOX_JSON)
} else {
prefs[INBOX_JSON] = json.encodeToString(retained)
}
}
}
return removed
}
private fun decode(raw: String?): List<ProactiveInboxEntry> {
@@ -11,6 +11,29 @@ data class RelayEndpoints(
val healthUrl: String,
)
/** Dashboard plugin namespace used when Relay rides the Dashboard origin. */
const val DASHBOARD_RELAY_INGRESS_PATH: String =
"/api/plugins/hermes-relay/transport"
/**
* True when [raw] points at the Dashboard-mounted Relay transport rather than
* a directly exposed Relay listener. The distinction is authentication
* relevant: the outer Dashboard request keeps its cookie/bearer credential,
* while Relay's independently scoped session travels in
* `X-Hermes-Relay-Session`.
*/
fun isDashboardRelayIngressUrl(raw: String?): Boolean {
val endpoints = RelayEndpointContract.parseOrNull(raw) ?: return false
val path = runCatching { URI(endpoints.httpBaseUrl).rawPath.orEmpty() }
.getOrDefault("")
.trimEnd('/')
val marker = path.indexOf(DASHBOARD_RELAY_INGRESS_PATH)
if (marker < 0) return false
val markerEndsAt = marker + DASHBOARD_RELAY_INGRESS_PATH.length
val suffixBoundary = markerEndsAt == path.length || path[markerEndsAt] == '/'
return suffixBoundary
}
/**
* Parses the accepted Relay URL forms and derives every route from one base.
*
@@ -5,6 +5,7 @@ import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import com.hermesandroid.relay.reliability.ReliabilityCenter
import com.hermesandroid.relay.reliability.ReliabilityRedactor
import java.time.Instant
enum class DiagnosticCategory(val label: String) {
Api("API"),
@@ -83,6 +84,8 @@ data class StatusCheck(
object DiagnosticsLog {
private const val MAX_ENTRIES = 200
private const val MAX_TEXT_LENGTH = 180
const val SUPPORT_ENTRY_LIMIT = 80
private const val MAX_SUPPORT_TEXT_LENGTH = 32_000
/** Cap for the full stacktrace kept on an error entry — a few KB is plenty. */
private const val MAX_TRACE_LENGTH = 8000
@@ -204,6 +207,46 @@ object DiagnosticsLog {
}
}
/**
* Exact, bounded diagnostics section used by the review-before-sharing
* support export. Entries were already sanitized at record time; the final
* redaction pass protects legacy entries and keeps this safe to compose with
* persistent reliability reports.
*/
fun supportText(entries: List<DiagnosticLogEntry>): String {
val selected = entries.takeLast(SUPPORT_ENTRY_LIMIT)
if (selected.isEmpty()) return ""
return ReliabilityRedactor.redact(
buildString {
appendLine("Recent in-app diagnostics")
appendLine("Diagnostics: ${selected.size}")
selected.forEachIndexed { index, entry ->
appendLine()
appendLine("===== Diagnostic ${index + 1} =====")
appendLine("Time: ${Instant.ofEpochMilli(entry.timestampMs)}")
appendLine("Category: ${entry.category.label}")
appendLine("Severity: ${entry.severity.name}")
appendLine("Title: ${entry.title}")
entry.operation?.let { appendLine("Operation: $it") }
entry.endpointRole?.let { appendLine("Route: $it") }
entry.configuredUrl?.let { appendLine("Configured URL: $it") }
entry.requestUrl?.let { appendLine("Request: $it") }
if (entry.configuredUrl == null && entry.requestUrl == null) {
entry.url?.let { appendLine("URL: $it") }
}
entry.elapsedMs?.let { appendLine("Elapsed: ${it}ms") }
entry.detail?.let { appendLine("Detail: $it") }
entry.suggestion?.let { appendLine("Next: $it") }
entry.stacktrace?.let {
appendLine("Technical detail (redacted)")
appendLine(it)
}
}
},
MAX_SUPPORT_TEXT_LENGTH,
)
}
fun sanitizeUrl(value: String?): String? {
val trimmed = value?.trim()?.takeIf { it.isNotBlank() } ?: return null
val noQuery = trimmed.substringBefore('?').substringBefore('#')
@@ -11,6 +11,7 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.auth.CertPinStore
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.RelayEndpointContract
import com.hermesandroid.relay.data.isDashboardRelayIngressUrl
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
@@ -43,6 +44,7 @@ import okhttp3.Response
import okhttp3.WebSocket
import okhttp3.WebSocketListener
import java.util.concurrent.TimeUnit
import java.util.concurrent.atomic.AtomicLong
enum class ConnectionState {
Disconnected,
@@ -138,6 +140,12 @@ class ConnectionManager(
* back to the legacy per-device PairingPreferences source below.
*/
private val endpointCandidatesProvider: (suspend () -> List<EndpointCandidate>)? = null,
/**
* Dynamic ownership fence for Relay-only resolution. Production uses it
* to keep Dashboard ingress on the exact origin that owns Dashboard auth,
* while direct Relay and proxy routes remain independently eligible.
*/
private val relayCandidateEligibility: (EndpointCandidate) -> Boolean = { true },
/**
* Suspending supplier for the active device id. Used to key into
* [PairingPreferences.getDeviceEndpoints] during resolution. `null`
@@ -151,6 +159,14 @@ class ConnectionManager(
private val proxyClientProvider: ((String) -> OkHttpClient?)? = null,
/** Test seam for observing lifecycle teardown without opening a socket. */
private val okHttpClientFactory: (() -> OkHttpClient)? = null,
/**
* Builds a Dashboard-authorized WebSocket request for plugin ingress.
* Implementations mint a fresh single-use Dashboard WS ticket on every
* invocation. Direct Relay listeners never call this provider.
*/
private val dashboardRelayRequestProvider: (suspend (String) -> Request?)? = null,
/** Deterministic race seam immediately before an ingress failure may poison route state. */
private val beforeIngressFailureCommit: suspend () -> Unit = {},
) {
private val supervisorJob = SupervisorJob()
private val scope = CoroutineScope(supervisorJob + Dispatchers.IO)
@@ -191,6 +207,9 @@ class ConnectionManager(
@Volatile
private var webSocket: WebSocket? = null
private val socketGeneration = AtomicLong(0L)
@Volatile
private var activeSocketGeneration: Long = 0L
@Volatile
private var serverUrl: String? = null
@@ -273,6 +292,11 @@ class ConnectionManager(
@Volatile
private var networkResolveJob: kotlinx.coroutines.Job? = null
/** Optional API discovery is never part of Dashboard/Gateway readiness. */
@Volatile
private var apiResolveJob: Job? = null
private var apiResolveRevision: Long = 0L
/** Deferred reaction to a network loss — cancelled if a network returns within the grace. */
private var networkLossJob: kotlinx.coroutines.Job? = null
@@ -363,13 +387,12 @@ class ConnectionManager(
// the synthesized list just collapses to the same URL anyway.
scope.launch {
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
?: resolveLegacyStandardFallbackSafe()
scheduleApiResolution()
val relayResolved = resolveBestRelayEndpointSafe()
val resolvedRelayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
val targetUrl = resolvedRelayUrl ?: url.takeIf { it.isNotBlank() }
_activeRelayEndpoint.value = relayResolved
_activeApiEndpoint.value = apiResolved
if (resolved != null) {
_activeEndpoint.value = resolved
Log.i(TAG, "connect: standard resolver picked role=${resolved.role} " +
@@ -407,6 +430,18 @@ class ConnectionManager(
}
}
/**
* Open the exact QR-advertised socket for a fresh pair. Relay health probes
* require an established Relay session, so running the normal resolver
* before `auth.ok` is circular and can consume the entire pairing window.
* Post-pair reconnects continue to use [connect] and full route resolution.
*/
fun connectPairing(url: String) {
ensureNetworkCallbackRegistered()
_activeRelayEndpoint.value = null
connectToUrlOnMainPath(url, replaceReason = "Fresh Relay pairing")
}
/**
* Replace an ordinary scheduled reconnect with an immediate attempt.
*
@@ -577,10 +612,17 @@ class ConnectionManager(
*/
suspend fun resolveBestEndpoint(): EndpointCandidate? =
resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
?: resolveLegacyStandardFallbackSafe()
private suspend fun resolveLegacyStandardFallbackSafe(): EndpointCandidate? =
resolveBestEndpointSafe(EndpointSurface.Standard) { candidate ->
candidate.dashboard?.url.isNullOrBlank() &&
candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl == null
}
private suspend fun resolveBestEndpointSafe(
surface: EndpointSurface,
candidateFilter: (EndpointCandidate) -> Boolean = { true },
): EndpointCandidate? {
val resolver = endpointResolver ?: return null
val ctx = context ?: return null
@@ -609,13 +651,14 @@ class ConnectionManager(
} ?: emptyList()
}
if (endpoints.isEmpty()) return null
val eligibleEndpoints = endpoints.filter(candidateFilter)
if (eligibleEndpoints.isEmpty()) return null
// Manual override: if the user pinned a role in the Endpoints card,
// try that one first; fall through to the strict-priority algorithm
// if it isn't reachable.
_manualRoleOverride.value?.let { preferredRole ->
val preferred = endpoints.firstOrNull {
val preferred = eligibleEndpoints.firstOrNull {
it.role.equals(preferredRole, ignoreCase = true)
}
if (preferred != null) {
@@ -627,7 +670,54 @@ class ConnectionManager(
}
}
return resolver.resolve(endpoints, surface)
return resolver.resolve(eligibleEndpoints, surface)
}
/** Every Relay selection path must apply the same live ownership fence. */
private suspend fun resolveBestRelayEndpointSafe(): EndpointCandidate? =
resolveBestEndpointSafe(
surface = EndpointSurface.Relay,
candidateFilter = relayCandidateEligibility,
)
/**
* Discover the optional API fallback without holding up the standard
* Dashboard/Gateway route. A single manager-level job coalesces lifecycle
* callers; [EndpointResolver] additionally shares an in-flight request per
* route/surface. The negative cache keeps ordinary profile changes cheap,
* while network callbacks and explicit probes still invalidate it.
*/
private fun scheduleApiResolution() {
synchronized(this) {
apiResolveRevision += 1L
if (apiResolveJob?.isActive != true) {
startApiResolutionLocked(apiResolveRevision)
}
}
}
/** Caller must hold this manager's monitor. */
private fun startApiResolutionLocked(revision: Long) {
apiResolveJob = scope.launch {
try {
val resolved = resolveBestEndpointSafe(EndpointSurface.Api)
synchronized(this@ConnectionManager) {
// A route/connection refresh may have arrived while this
// optional probe was waiting. Never publish its stale
// winner over the newer connection's API ownership.
if (revision == apiResolveRevision) {
_activeApiEndpoint.value = resolved
}
}
} finally {
synchronized(this@ConnectionManager) {
apiResolveJob = null
if (revision != apiResolveRevision && supervisorJob.isActive) {
startApiResolutionLocked(apiResolveRevision)
}
}
}
}
}
/**
@@ -656,9 +746,9 @@ class ConnectionManager(
endpointResolver?.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
?: resolveLegacyStandardFallbackSafe()
scheduleApiResolution()
val relayResolved = resolveBestRelayEndpointSafe()
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
// — keep the live route published rather than downgrading every
@@ -666,7 +756,6 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val targetUrl = relayResolved?.relayWebSocketUrl() ?: current ?: return resolved
val normalizedTarget = normalizeRelayUrl(targetUrl)
@@ -706,8 +795,8 @@ class ConnectionManager(
suspend fun refreshActiveEndpoint(clearProbeCache: Boolean = false): EndpointCandidate? {
if (clearProbeCache) endpointResolver?.clearCache()
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
?: resolveLegacyStandardFallbackSafe()
scheduleApiResolution()
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
// (slow resume, mid-handoff blip) — keep publishing the live
@@ -716,7 +805,6 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
return resolved
}
@@ -738,6 +826,46 @@ class ConnectionManager(
Log.i(TAG, "marked endpoint role=${active.role} unreachable ($reason)")
}
/** Admission is stronger evidence than `/transport/health`: reject this ingress and retain direct fallback. */
private suspend fun fallbackFromBrokenDashboardIngress(
url: String,
reason: String,
failingSocket: WebSocket? = null,
failingGeneration: Long? = null,
): Boolean {
if (!isDashboardRelayIngressUrl(url)) return false
if (failingGeneration != null) {
beforeIngressFailureCommit()
if (activeSocketGeneration != failingGeneration || webSocket !== failingSocket) {
Log.i(TAG, "Ignoring stale Dashboard ingress failure ($reason)")
return false
}
}
val failed = _activeRelayEndpoint.value ?: return false
val failedUrl = failed.relayWebSocketUrl()?.let(::normalizeRelayUrl)
if (failedUrl != normalizeRelayUrl(url)) return false
endpointResolver?.markUnreachable(failed, EndpointSurface.Relay) ?: return false
val replacement = resolveBestRelayEndpointSafe() ?: return false
val replacementUrl = replacement.relayWebSocketUrl()?.takeIf(String::isNotBlank) ?: return false
if (normalizeRelayUrl(replacementUrl) == normalizeRelayUrl(url)) return false
_activeRelayEndpoint.value = replacement
Log.i(TAG, "Dashboard Relay ingress rejected; switching to ${replacement.role} ($reason)")
DiagnosticsLog.record(
category = DiagnosticCategory.Relay,
severity = DiagnosticSeverity.Warning,
title = "Relay ingress unavailable",
detail = "Dashboard admission failed; using retained direct Relay route.",
operation = "Select Relay transport after admission failure",
endpointRole = failed.role,
requestUrl = url,
)
connectToUrlOnMainPath(
replacementUrl,
replaceReason = "Dashboard Relay ingress admission failed",
)
return true
}
/**
* Debounced network-change re-resolution, shared by both NetworkCallback
* events. Re-runs the resolver and publishes the winner to
@@ -760,8 +888,8 @@ class ConnectionManager(
if (wipeCache) endpointResolver.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
?: resolveLegacyStandardFallbackSafe()
scheduleApiResolution()
if (resolved == null) {
// Hysteresis for the AUTOMATIC (network-callback) path. A
// transient cold-route probe miss must NOT null the published
@@ -798,7 +926,6 @@ class ConnectionManager(
}
sustainedLossDeclared = false
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
if (current == null) return@launch
// After an explicit disconnect() the route still publishes above
// (HTTP surfaces keep roaming), but no socket action: without
@@ -807,7 +934,7 @@ class ConnectionManager(
// (connectToUrlOnMainPath force-sets shouldReconnect = true, so
// the swap path never re-checked it.)
if (!shouldReconnect) return@launch
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val relayResolved = resolveBestRelayEndpointSafe()
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val relayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
?: return@launch
@@ -974,7 +1101,8 @@ class ConnectionManager(
webSocket?.send(text)
}
private fun isActiveSocket(socket: WebSocket): Boolean = webSocket === socket
private fun isActiveSocket(socket: WebSocket, generation: Long): Boolean =
webSocket === socket && activeSocketGeneration == generation
private fun doConnect(
url: String,
@@ -1010,7 +1138,7 @@ class ConnectionManager(
scope.launch { doConnectInternal(url, previousSocketToClose, replaceReason) }
}
private fun doConnectInternal(
private suspend fun doConnectInternal(
url: String,
previousSocketToClose: WebSocket? = null,
replaceReason: String = "Relay socket replaced",
@@ -1035,22 +1163,49 @@ class ConnectionManager(
buildClient(url)
}
val request = buildRelayRequestOrNull(url)
val request = if (isDashboardRelayIngressUrl(url)) {
dashboardRelayRequestProvider?.invoke(url)
} else {
buildRelayRequestOrNull(url)
}
if (request == null) {
// A malformed relay URL (an invalid/empty host from a corrupt or
// hand-edited pairing payload) can't be built into a request. This
// runs on a background coroutine, so letting OkHttp's url() throw
// would crash the app — the #131 "Invalid URL host" class, relay-
// socket half. Route it through the same path onFailure uses.
Log.e(TAG, "doConnect: malformed relay URL '$url' — not connecting")
Log.e(
TAG,
if (isDashboardRelayIngressUrl(url)) {
"doConnect: Dashboard Relay ticket/request unavailable for '$url'"
} else {
"doConnect: malformed relay URL '$url' — not connecting"
},
)
DiagnosticsLog.record(
category = DiagnosticCategory.Relay,
severity = DiagnosticSeverity.Error,
title = "Invalid relay URL",
detail = "The relay address could not be parsed; re-pair to refresh it.",
operation = "Build Relay WebSocket request",
title = if (isDashboardRelayIngressUrl(url)) {
"Dashboard Relay authorization unavailable"
} else {
"Invalid relay URL"
},
detail = if (isDashboardRelayIngressUrl(url)) {
"Dashboard authorization could not prepare the Relay WebSocket request."
} else {
"The relay address could not be parsed; re-pair to refresh it."
},
operation = if (isDashboardRelayIngressUrl(url)) {
"Mint Dashboard Relay WebSocket ticket"
} else {
"Build Relay WebSocket request"
},
configuredUrl = url,
suggestion = "Edit or re-pair the Relay route to replace the invalid address.",
suggestion = if (isDashboardRelayIngressUrl(url)) {
"Sign in to the matching Dashboard route, then recheck Relay routes."
} else {
"Edit or re-pair the Relay route to replace the invalid address."
},
)
authenticated = false
_connectionState.value = ConnectionState.Disconnected
@@ -1058,14 +1213,18 @@ class ConnectionManager(
runCatching { stale.close(1000, replaceReason) }
stale.cancel()
}
scheduleReconnect()
if (!fallbackFromBrokenDashboardIngress(url, "request provider or ticket unavailable")) {
scheduleReconnect()
}
return
}
Log.i(TAG, "doConnect: opening WSS to $url")
val generation = socketGeneration.incrementAndGet()
activeSocketGeneration = generation
val newSocket = client.newWebSocket(request, object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
if (!isActiveSocket(webSocket)) {
if (!isActiveSocket(webSocket, generation)) {
Log.i(TAG, "onOpen: stale WSS handshake ignored ($url)")
runCatching { webSocket.close(1000, "Stale relay socket") }
webSocket.cancel()
@@ -1108,7 +1267,7 @@ class ConnectionManager(
}
override fun onMessage(webSocket: WebSocket, text: String) {
if (!isActiveSocket(webSocket)) {
if (!isActiveSocket(webSocket, generation)) {
Log.i(TAG, "onMessage: stale WSS envelope ignored ($url)")
return
}
@@ -1135,7 +1294,7 @@ class ConnectionManager(
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (!isActiveSocket(webSocket)) {
if (!isActiveSocket(webSocket, generation)) {
Log.i(TAG, "onClosed: stale WSS close ignored ($url code=$code reason=$reason)")
return
}
@@ -1149,13 +1308,28 @@ class ConnectionManager(
requestUrl = url,
suggestion = if (code == 1000) null else "Check the Relay server logs for the matching close code and reason.",
)
val admitted = authenticated
authenticated = false
_connectionState.value = ConnectionState.Disconnected
scheduleReconnect()
if (isDashboardRelayIngressUrl(url) && !admitted && code != 1000) {
scope.launch {
if (!fallbackFromBrokenDashboardIngress(
url,
"pre-auth close $code",
webSocket,
generation,
) && activeSocketGeneration == generation
) {
scheduleReconnect()
}
}
} else {
scheduleReconnect()
}
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
if (!isActiveSocket(webSocket)) {
if (!isActiveSocket(webSocket, generation)) {
Log.i(TAG, "onFailure: stale WSS failure ignored ($url ${t.javaClass.simpleName}: ${t.message})")
return
}
@@ -1177,6 +1351,22 @@ class ConnectionManager(
} ?: NetworkDiagnosticGuidance.forThrowable(t, "Relay"),
)
lastUpgradeResponseCode = code
if (isDashboardRelayIngressUrl(url) && response != null) {
authenticated = false
_connectionState.value = ConnectionState.Disconnected
scope.launch {
if (!fallbackFromBrokenDashboardIngress(
url,
"HTTP admission ${response.code}",
webSocket,
generation,
) && activeSocketGeneration == generation
) {
scheduleReconnect()
}
}
return
}
if (response == null) {
// Transport-level failure (no HTTP upgrade response): on a
// remote (Tailscale) link the first handshake can fail cold.
@@ -1290,7 +1480,7 @@ class ConnectionManager(
// expires, auth state may have changed (e.g., user hit Revoke
// during the retry window).
if (shouldReconnect && reconnectGate()) {
val resolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val resolved = resolveBestRelayEndpointSafe()
val targetUrl = resolved?.relayWebSocketUrl()
if (resolved != null) {
// Mirror scheduleNetworkReResolve: clear the sustained-loss
@@ -102,22 +102,18 @@ class ProactiveMessageHandler(
/** Route a parsed message: into the open Thread if it belongs there, else
* the durable inbox log + the surface its hint selects. */
private fun dispatch(msg: ProactiveMessage) {
// Persist first even when the currently open Thread consumes the live
// message. Agent-initiated outbound sends do not create a gateway
// session until the phone replies, so this cache is the provisional
// Thread transcript during that gap.
toInbox?.invoke(msg)
// The surfacing hint selects the additional surface. Thread injection
// is best-effort presentation of the persisted row, not itself a reason
// to suppress an explicitly requested notification.
when (msg.surfacing?.lowercase()) {
val notificationId = when (msg.surfacing?.lowercase()) {
"inbox" -> {
injectIntoThread?.invoke(msg)
null
}
"session" -> {
val delivered = injectIntoThread?.invoke(msg) == true ||
toSession?.invoke(msg) == true
if (!delivered) notify(msg)
if (delivered) null else notify(msg)
}
// null / "default" / "notification" / anything unrecognized.
else -> {
@@ -125,9 +121,13 @@ class ProactiveMessageHandler(
notify(msg)
}
}
// Every message remains in the bounded local cache. Persist the exact
// posted notification slot as part of that row so a later local Thread
// removal can cancel only its own notification.
toInbox?.invoke(msg.copy(notificationId = notificationId))
}
private fun notify(msg: ProactiveMessage) {
private fun notify(msg: ProactiveMessage): Int? =
ProactiveMessageNotifier.notify(
context = context,
title = msg.title,
@@ -135,7 +135,6 @@ class ProactiveMessageHandler(
messageId = msg.messageId,
chatId = msg.chatId,
)
}
private fun parse(payload: JsonObject): ProactiveMessage? {
val text = payload["text"]?.jsonPrimitive?.contentOrNull
@@ -172,4 +171,6 @@ data class ProactiveMessage(
val replyTo: String? = null,
/** True only when Relay explicitly marked this as a reconnect queue flush. */
val arrivedWhileAway: Boolean = false,
/** Exact Android notification slot when this delivery posted one. */
val notificationId: Int? = null,
)
@@ -5,6 +5,7 @@ import android.util.Log
import com.hermesandroid.relay.R
import com.hermesandroid.relay.auth.PairedDeviceInfo
import com.hermesandroid.relay.data.RelayEndpointContract
import com.hermesandroid.relay.data.isDashboardRelayIngressUrl
import com.hermesandroid.relay.diagnostics.DiagnosticCategory
import com.hermesandroid.relay.diagnostics.DiagnosticSeverity
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
@@ -28,6 +29,18 @@ import okhttp3.Request
import okhttp3.RequestBody.Companion.toRequestBody
import java.io.IOException
internal const val RELAY_SESSION_HEADER: String = "X-Hermes-Relay-Session"
/** Keep Dashboard outer auth and Relay capability auth in separate headers. */
internal fun Request.Builder.relaySessionCredential(
token: String,
dashboardIngress: Boolean,
): Request.Builder = if (dashboardIngress) {
header(RELAY_SESSION_HEADER, token)
} else {
header("Authorization", "Bearer $token")
}
/**
* HTTP client for the Hermes relay media endpoint.
*
@@ -59,11 +72,20 @@ class RelayHttpClient(
/** Application context for localized string resources. Nullable for
* backwards-compat with call sites that don't need localization. */
private val context: Context? = null,
/** Dashboard-authenticated client for same-origin plugin ingress calls. */
private val dashboardHttpClientProvider: ((String) -> OkHttpClient?)? = null,
) {
private fun relayHttpBaseOrNull(url: String): String? =
RelayEndpointContract.parseOrNull(url)?.httpBaseUrl
private fun callClient(relayUrl: String): OkHttpClient =
if (isDashboardRelayIngressUrl(relayUrl)) {
dashboardHttpClientProvider?.invoke(relayUrl) ?: okHttpClient
} else {
okHttpClient
}
companion object {
private const val TAG = "RelayHttpClient"
const val MAX_MODEL_CAPABILITY_ROWS = 64
@@ -199,10 +221,10 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
val activityClient = okHttpClient.newBuilder()
val activityClient = callClient(relayUrl).newBuilder()
.callTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
.build()
@@ -261,12 +283,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "*/*")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val reason = when (response.code) {
401, 403 -> "Unauthorized — re-pair with the relay"
@@ -369,12 +391,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "*/*")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val reason = when (response.code) {
401 -> "Unauthorized — re-pair with the relay"
@@ -456,12 +478,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "image/*")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val errorCode = runCatching {
sessionsJson.parseToJsonElement(response.body.string())
@@ -554,11 +576,11 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
val auditClient = okHttpClient.newBuilder()
val auditClient = callClient(relayUrl).newBuilder()
.callTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
.build()
@@ -640,10 +662,10 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
val client = okHttpClient.newBuilder()
val client = callClient(relayUrl).newBuilder()
.callTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
.build()
try {
@@ -753,10 +775,10 @@ class RelayHttpClient(
return@withContext Result.failure(IOException("Invalid relay URL: ${e.message}"))
}
val request = Request.Builder().url(url).get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json").build()
try {
okHttpClient.newBuilder().callTimeout(4, java.util.concurrent.TimeUnit.SECONDS).build()
callClient(relayUrl).newBuilder().callTimeout(4, java.util.concurrent.TimeUnit.SECONDS).build()
.newCall(request).execute().use { response ->
if (response.code == 404) return@withContext Result.success(null)
if (!response.isSuccessful) return@withContext Result.failure(IOException("HTTP ${response.code}"))
@@ -807,11 +829,11 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.post(sessionsJson.encodeToString(payload).toRequestBody("application/json".toMediaType()))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newBuilder().callTimeout(4, java.util.concurrent.TimeUnit.SECONDS).build()
callClient(relayUrl).newBuilder().callTimeout(4, java.util.concurrent.TimeUnit.SECONDS).build()
.newCall(request).execute().use { response ->
if (response.code == 404) return@withContext Result.success(null)
if (!response.isSuccessful) return@withContext Result.failure(IOException("HTTP ${response.code}"))
@@ -857,12 +879,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
// Slightly longer than the other reads — a cache-miss on the relay does a
// GitHub round-trip in an executor before responding.
val client = okHttpClient.newBuilder()
val client = callClient(relayUrl).newBuilder()
.callTimeout(8, java.util.concurrent.TimeUnit.SECONDS)
.build()
try {
@@ -941,12 +963,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (response.code == 404) {
// Server hasn't shipped the endpoint yet — degrade to
// empty list so the UI can render "No paired devices"
@@ -1028,12 +1050,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.delete()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (response.code == 404) {
// Already gone — treat as success so the UI can just
// drop the row on the next refresh.
@@ -1145,12 +1167,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.patch(bodyJson.toRequestBody("application/json".toMediaType()))
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val reason = when (response.code) {
400 -> "Invalid extend request (check TTL/grants)"
@@ -1242,7 +1264,7 @@ class RelayHttpClient(
// Fast-timeout client — we don't want Save & Test to hang the UI
// for 10 seconds on a dead URL.
val fastClient = okHttpClient.newBuilder()
val fastClient = callClient(relayUrl).newBuilder()
.connectTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
.readTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
.writeTimeout(3, java.util.concurrent.TimeUnit.SECONDS)
@@ -1484,12 +1506,12 @@ class RelayHttpClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (response.code == 404) {
// Older or operator-disabled hosts simply do not expose
// account usage. This is capability absence, not an error.
@@ -10,6 +10,7 @@ import com.hermesandroid.relay.data.ProfileMemoryUpdateResponse
import com.hermesandroid.relay.data.LegacyProfileInspectorClient
import com.hermesandroid.relay.data.RelaySkillToggleResult
import com.hermesandroid.relay.data.RelayEndpointContract
import com.hermesandroid.relay.data.isDashboardRelayIngressUrl
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import kotlinx.serialization.SerializationException
@@ -51,11 +52,19 @@ class RelayProfileInspectorClient(
private val okHttpClient: OkHttpClient,
private val relayUrlProvider: () -> String?,
private val sessionTokenProvider: suspend () -> String?,
private val dashboardHttpClientProvider: ((String) -> OkHttpClient?)? = null,
) : LegacyProfileInspectorClient {
private fun relayHttpBaseOrNull(url: String): String? =
RelayEndpointContract.parseOrNull(url)?.httpBaseUrl
private fun callClient(relayUrl: String): OkHttpClient =
if (isDashboardRelayIngressUrl(relayUrl)) {
dashboardHttpClientProvider?.invoke(relayUrl) ?: okHttpClient
} else {
okHttpClient
}
companion object {
private const val TAG = "RelayProfileInspector"
@@ -211,12 +220,12 @@ class RelayProfileInspectorClient(
val request = Request.Builder()
.url(url)
.put(body.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val reason = when (response.code) {
400 -> {
@@ -314,12 +323,12 @@ class RelayProfileInspectorClient(
val request = Request.Builder()
.url(url)
.put(bodyJson.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
when (response.code) {
in 200..299 -> Result.success(RelaySkillToggleResult.Ok)
501 -> Result.success(RelaySkillToggleResult.NotImplemented)
@@ -374,11 +383,11 @@ class RelayProfileInspectorClient(
val request = Request.Builder()
.url(url)
.method("OPTIONS", null)
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
when (response.code) {
501 -> false
404, 405 -> false
@@ -464,12 +473,12 @@ class RelayProfileInspectorClient(
val request = Request.Builder()
.url(url)
.get()
.header("Authorization", "Bearer $sessionToken")
.relaySessionCredential(sessionToken, isDashboardRelayIngressUrl(relayUrl))
.header("Accept", "application/json")
.build()
try {
okHttpClient.newCall(request).execute().use { response ->
callClient(relayUrl).newCall(request).execute().use { response ->
if (!response.isSuccessful) {
val reason = when (response.code) {
401, 403 -> "Unauthorized — re-pair with the relay"
@@ -7,6 +7,7 @@ import com.hermesandroid.relay.data.EnhancedVoiceOverrides
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.RealtimeConversationContextMessage
import com.hermesandroid.relay.data.RelayEndpointContract
import com.hermesandroid.relay.data.isDashboardRelayIngressUrl
import kotlinx.coroutines.CompletableDeferred
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
@@ -89,7 +90,7 @@ import java.util.concurrent.atomic.AtomicReference
*/
class RelayVoiceClient(
private val context: Context,
private val okHttpClient: OkHttpClient,
okHttpClient: OkHttpClient,
private val relayUrlProvider: () -> String?,
private val sessionTokenProvider: suspend () -> String?,
private val profileNameProvider: () -> String? = { null },
@@ -100,8 +101,26 @@ class RelayVoiceClient(
private val realtimeResumeRetryIntervalMs: Long = REALTIME_RESUME_RETRY_INTERVAL_MS,
private val realtimeResumeRetryWindowMs: Long = REALTIME_RESUME_RETRY_WINDOW_MS,
private val voiceOutputFirstAudioTimeoutMs: Long = VOICE_OUTPUT_FIRST_AUDIO_TIMEOUT_MS,
/** Dashboard-authenticated transport for same-origin plugin ingress. */
private val dashboardHttpClientProvider: ((String) -> OkHttpClient?)? = null,
/** Fresh Dashboard ticket request for every ingress voice socket dial. */
private val dashboardIngressWebSocketRequestProvider:
(suspend (String) -> Request?)? = null,
) {
private val directOkHttpClient: OkHttpClient = okHttpClient
/** Resolve lazily so a Dashboard route/client handoff is observed. */
private val okHttpClient: OkHttpClient
get() {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
return if (isDashboardRelayIngressUrl(relayUrl)) {
dashboardHttpClientProvider?.invoke(relayUrl) ?: directOkHttpClient
} else {
directOkHttpClient
}
}
companion object {
private const val TAG = "RelayVoiceClient"
private val json = Json { ignoreUnknownKeys = true; isLenient = true }
@@ -144,13 +163,36 @@ class RelayVoiceClient(
}
}
private fun callClient(url: String): OkHttpClient =
if (isDashboardRelayIngressUrl(url)) {
dashboardHttpClientProvider?.invoke(url) ?: directOkHttpClient
} else {
directOkHttpClient
}
private fun sessionClient(): OkHttpClient =
okHttpClient.newBuilder()
.callTimeout(SESSION_CALL_TIMEOUT_SECONDS, TimeUnit.SECONDS)
.build()
private fun openWebSocket(request: Request, listener: WebSocketListener): WebSocket =
webSocketFactory?.invoke(request, listener) ?: okHttpClient.newWebSocket(request, listener)
webSocketFactory?.invoke(request, listener)
?: callClient(request.url.toString()).newWebSocket(request, listener)
private suspend fun voiceWebSocketRequest(url: String, relayToken: String): Request {
val dashboardIngress = isDashboardRelayIngressUrl(url)
val outerRequest = if (dashboardIngress) {
val provider = dashboardIngressWebSocketRequestProvider
?: throw IOException("Dashboard Relay voice authorization is unavailable")
provider(url)
?: throw IOException("Dashboard Relay voice ticket could not be minted")
} else {
Request.Builder().url(url).build()
}
return outerRequest.newBuilder()
.relaySessionCredential(relayToken, dashboardIngress)
.build()
}
private fun requestRouteProbeOnce(
surface: String,
@@ -196,7 +238,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/transcribe"))
.post(body)
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -278,7 +320,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url("$httpBase/voice/synthesize")
.post(bodyJson.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "audio/mpeg")
.build()
@@ -333,7 +375,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/config"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -375,7 +417,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/realtime/config"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -414,7 +456,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/realtime/providers/${pathSegment(provider)}/options"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -462,7 +504,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/realtime/providers/${pathSegment(provider)}/validate"))
.post(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -515,7 +557,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/realtime/config"))
.patch(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -618,7 +660,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/realtime-agent/config"))
.patch(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
try {
@@ -650,7 +692,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/output/config"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -689,7 +731,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/output/providers/${pathSegment(provider)}/options"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -741,7 +783,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/output/providers/${pathSegment(provider)}/validate"))
.post(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -812,7 +854,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase/voice/output/config"))
.patch(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
@@ -845,6 +887,7 @@ class RelayVoiceClient(
onHandoff: (VoiceHandoffEvent) -> Unit = {},
onEvent: (RealtimeVoiceEvent) -> Unit,
): Result<VoiceOutputSummary> = withContext(Dispatchers.IO) {
val owningScope = this
val httpBase = resolveHttpBase()
?: return@withContext Result.failure(IllegalStateException("Relay URL not configured"))
val token = resolveBearerToken()
@@ -869,6 +912,7 @@ class RelayVoiceClient(
val completed = AtomicBoolean(false)
val resumeAttempted = AtomicBoolean(false)
val routeProbeRequested = AtomicBoolean(false)
val resumeDialPending = AtomicBoolean(false)
val currentSocket = AtomicReference<WebSocket?>()
val firstAudioSeen = AtomicBoolean(false)
val socketGeneration = AtomicLong(0L)
@@ -907,14 +951,14 @@ class RelayVoiceClient(
}
}
fun openSocket(resume: Boolean, overrideWsBase: String? = null): WebSocket {
suspend fun openSocket(resume: Boolean, overrideWsBase: String? = null): WebSocket {
val generation = socketGeneration.incrementAndGet()
val currentWsBase = overrideWsBase ?: resolveWebSocketBase()
?: throw IOException("Relay URL not configured")
val request = Request.Builder()
.url("$currentWsBase${session.websocketPath}")
.header("Authorization", "Bearer $token")
.build()
val request = voiceWebSocketRequest(
"$currentWsBase${session.websocketPath}",
token,
)
Log.i(
TAG,
"Voice output websocket opening resume=$resume url=${request.url}",
@@ -1044,23 +1088,28 @@ class RelayVoiceClient(
return
}
if (session.resumeSupported && !session.resumeToken.isNullOrBlank() && resumeAttempted.compareAndSet(false, true)) {
try {
Log.i(TAG, "Voice output websocket failed; attempting resume: ${t.message}")
requestRouteProbeOnce("Voice output", t.message, routeProbeRequested)
onHandoff(
VoiceHandoffEvent(
label = context.getString(R.string.voice_diag_connection_changed),
detail = t.message,
route = routeLabel(webSocket.request().url.toString()),
active = true,
)
Log.i(TAG, "Voice output websocket failed; scheduling resume: ${t.message}")
requestRouteProbeOnce("Voice output", t.message, routeProbeRequested)
onHandoff(
VoiceHandoffEvent(
label = context.getString(R.string.voice_diag_connection_changed),
detail = t.message,
route = routeLabel(webSocket.request().url.toString()),
active = true,
)
openSocket(resume = true)
return
} catch (e: Exception) {
completeFailure("Voice output resume failed: ${e.message ?: "network error"}", e)
return
)
if (resumeDialPending.compareAndSet(false, true)) {
owningScope.launch {
try {
openSocket(resume = true)
} catch (e: Exception) {
completeFailure("Voice output resume failed: ${e.message ?: "network error"}", e)
} finally {
resumeDialPending.set(false)
}
}
}
return
}
completeFailure("Voice output websocket failed: ${t.message}", t)
}
@@ -1090,23 +1139,28 @@ class RelayVoiceClient(
return
}
if (session.resumeSupported && !session.resumeToken.isNullOrBlank() && resumeAttempted.compareAndSet(false, true)) {
try {
Log.i(TAG, "Voice output websocket closed code=$code; attempting resume")
requestRouteProbeOnce("Voice output", "Closed $code $reason", routeProbeRequested)
onHandoff(
VoiceHandoffEvent(
label = context.getString(R.string.voice_diag_connection_changed),
detail = "Closed $code $reason",
route = routeLabel(webSocket.request().url.toString()),
active = true,
)
Log.i(TAG, "Voice output websocket closed code=$code; scheduling resume")
requestRouteProbeOnce("Voice output", "Closed $code $reason", routeProbeRequested)
onHandoff(
VoiceHandoffEvent(
label = context.getString(R.string.voice_diag_connection_changed),
detail = "Closed $code $reason",
route = routeLabel(webSocket.request().url.toString()),
active = true,
)
openSocket(resume = true)
return
} catch (e: Exception) {
completeFailure("Voice output resume failed: ${e.message ?: "network error"}", e)
return
)
if (resumeDialPending.compareAndSet(false, true)) {
owningScope.launch {
try {
openSocket(resume = true)
} catch (e: Exception) {
completeFailure("Voice output resume failed: ${e.message ?: "network error"}", e)
} finally {
resumeDialPending.set(false)
}
}
}
return
}
completeFailure("Voice output websocket closed before completion: $code $reason")
}
@@ -1178,10 +1232,7 @@ class RelayVoiceClient(
var audioChunks = 0
var audioBytes = 0
val request = Request.Builder()
.url("$wsBase${session.websocketPath}")
.header("Authorization", "Bearer $token")
.build()
val request = voiceWebSocketRequest("$wsBase${session.websocketPath}", token)
val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
@@ -1306,6 +1357,7 @@ class RelayVoiceClient(
prewarm: Boolean = false,
onEvent: (RealtimeVoiceEvent, RealtimeAgentSessionControl) -> Unit,
): Result<RealtimeVoiceSummary> = withContext(Dispatchers.IO) {
val owningScope = this
val persistent = turnInputs != null
val httpBase = resolveHttpBase()
?: return@withContext Result.failure(IllegalStateException("Relay URL not configured"))
@@ -1649,7 +1701,7 @@ class RelayVoiceClient(
}
}
fun openSocket(
suspend fun openSocket(
resume: Boolean,
overrideWsBase: String? = null,
expectedResumeEpisode: Long? = null,
@@ -1673,10 +1725,10 @@ class RelayVoiceClient(
val (currentWsBase, request) = try {
val base = overrideWsBase ?: resolveWebSocketBase()
?: throw IOException("Relay URL not configured")
val socketRequest = Request.Builder()
.url("$base${session.websocketPath}")
.header("Authorization", "Bearer $token")
.build()
val socketRequest = voiceWebSocketRequest(
"$base${session.websocketPath}",
token,
)
Log.i(
TAG,
"Realtime agent websocket opening resume=$resume url=${socketRequest.url}",
@@ -1765,12 +1817,20 @@ class RelayVoiceClient(
// A synchronous failure callback can replace this
// socket while setup sends are still unwinding. A
// stale attempt must not terminate the newer route.
if (currentSocket.get() !== webSocket || completed.get()) return
if (
terminalCallbackSeen.get() ||
currentSocket.get() !== webSocket ||
completed.get()
) return
completeFailure("Realtime agent websocket rejected session setup")
webSocket.close(1011, "session setup failed")
return
}
if (currentSocket.get() !== webSocket || completed.get()) return
if (
terminalCallbackSeen.get() ||
currentSocket.get() !== webSocket ||
completed.get()
) return
if (resume) {
Log.i(TAG, "Realtime agent resume sent; awaiting relay confirmation")
} else {
@@ -1984,16 +2044,17 @@ class RelayVoiceClient(
)
)
if (!claim.openImmediately) return
try {
openSocket(
resume = true,
expectedResumeEpisode = claim.waiting.episode,
)
return
} catch (e: Exception) {
completeFailure("Realtime agent resume failed: ${e.message ?: "network error"}", e)
return
owningScope.launch {
try {
openSocket(
resume = true,
expectedResumeEpisode = claim.waiting.episode,
)
} catch (e: Exception) {
completeFailure("Realtime agent resume failed: ${e.message ?: "network error"}", e)
}
}
return
}
val transitionRevision = claimTerminalSocket(
webSocket,
@@ -2097,16 +2158,17 @@ class RelayVoiceClient(
)
)
if (!claim.openImmediately) return
try {
openSocket(
resume = true,
expectedResumeEpisode = claim.waiting.episode,
)
return
} catch (e: Exception) {
completeFailure("Realtime agent resume failed: ${e.message ?: "network error"}", e)
return
owningScope.launch {
try {
openSocket(
resume = true,
expectedResumeEpisode = claim.waiting.episode,
)
} catch (e: Exception) {
completeFailure("Realtime agent resume failed: ${e.message ?: "network error"}", e)
}
}
return
}
val transitionRevision = claimTerminalSocket(
webSocket,
@@ -2294,9 +2356,7 @@ class RelayVoiceClient(
null
}
val socket = openSocket(resume = false)
?: currentSocket.get()
?: throw IOException("Realtime agent websocket handshake was already pending")
val initialSocket = openSocket(resume = false) ?: currentSocket.get()
val routeWatcherResumeEpisode = AtomicLong(0L)
val routeWatcher = startRouteResumeWatcher(
surface = "Realtime agent",
@@ -2378,7 +2438,7 @@ class RelayVoiceClient(
awaitRealtimeAgentCompletion()
} catch (e: Exception) {
currentSocket.get()?.close(1001, "timeout")
socket.close(1001, "timeout")
initialSocket?.close(1001, "timeout")
Result.failure(IOException(e.message ?: "Realtime agent timed out", e))
} finally {
routeWatcher?.cancel()
@@ -2394,7 +2454,7 @@ class RelayVoiceClient(
resumeSupported: Boolean,
resumeToken: String?,
currentSocket: AtomicReference<WebSocket?>,
openResumeSocket: (String?) -> WebSocket?,
openResumeSocket: suspend (String?) -> WebSocket?,
onHandoff: (VoiceHandoffEvent) -> Unit,
completeFailure: (String, Throwable?) -> Unit,
): Job? {
@@ -2454,7 +2514,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase$path"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
try {
@@ -2493,7 +2553,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase$pathPrefix/${pathSegment(provider)}/options"))
.get()
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
try {
@@ -2541,7 +2601,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase$pathPrefix/${pathSegment(provider)}/validate"))
.post(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
try {
@@ -2593,7 +2653,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url(urlWithProfile("$httpBase$path"))
.patch(payload.toString().toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
try {
@@ -2678,7 +2738,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url("$httpBase/voice/realtime/session")
.post(body.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
return try {
@@ -2763,7 +2823,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url("$httpBase/voice/realtime-agent/session")
.post(body.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
return try {
@@ -2804,7 +2864,7 @@ class RelayVoiceClient(
val request = Request.Builder()
.url("$httpBase/voice/output/session")
.post(body.toRequestBody(JSON_MEDIA_TYPE))
.header("Authorization", "Bearer $token")
.relaySessionCredential(token, isDashboardRelayIngressUrl(httpBase))
.header("Accept", "application/json")
.build()
return try {
@@ -5,6 +5,7 @@ import android.util.Log
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.RelayEndpointContract
import com.hermesandroid.relay.data.isDashboardRelayIngressUrl
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.routeAuthority
import com.hermesandroid.relay.diagnostics.DiagnosticCategory
@@ -12,16 +13,24 @@ import com.hermesandroid.relay.diagnostics.DiagnosticSeverity
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
import com.hermesandroid.relay.diagnostics.NetworkDiagnosticGuidance
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.CoroutineStart
import kotlinx.coroutines.CancellationException
import kotlinx.coroutines.Deferred
import kotlinx.coroutines.SupervisorJob
import kotlinx.coroutines.TimeoutCancellationException
import kotlinx.coroutines.async
import kotlinx.coroutines.awaitAll
import kotlinx.coroutines.coroutineScope
import kotlinx.coroutines.channels.Channel
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.update
import kotlinx.coroutines.currentCoroutineContext
import kotlinx.coroutines.ensureActive
import kotlinx.coroutines.withContext
import kotlinx.coroutines.withTimeoutOrNull
import kotlinx.coroutines.launch
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
import okhttp3.OkHttpClient
import okhttp3.Request
@@ -43,7 +52,7 @@ import javax.net.ssl.SSLException
*/
data class RouteProbeOutcome(
val reachable: Boolean,
/** Short human-readable failure reason; null when [reachable]. */
/** Short result detail; protected ingress may be reachable but require authorization. */
val detail: String? = null,
/** Resolver-clock timestamp of when the probe finished. */
val atMillis: Long,
@@ -68,12 +77,15 @@ enum class EndpointSurface {
*
* ### Semantics (locked by ADR 24)
*
* * **Strict priority.** `priority = 0` is highest. If a priority-0
* candidate is reachable we use it; reachability never promotes a lower
* priority over a higher one. Reachability is **only** the tiebreaker
* among candidates that share the same priority.
* * **Reachability probe.** Dashboard-first routes use `GET
* ${dashboard.url}/api/status`; legacy API routes use `GET
* * **Strict selection priority with speculative probes.** `priority = 0`
* is highest. All supported priority groups start probing together so one
* dead route cannot add its full timeout before the fallback even starts,
* but a lower-priority result is considered only after every higher group
* has failed. Reachability is **only** the tiebreaker among candidates that
* share the same priority.
* * **Reachability probe.** Dashboard-first routes use lightweight `GET
* ${dashboard.url}/api/health` and fall back to `/api/status` only for a
* confirmed legacy host without the health route. Legacy API routes use `GET
* ${api.url}/health`. Relay-only routes use `GET ${relay.httpUrl}/health`.
* Each request has a 4-second
* per-candidate timeout. Positive results are cached longer than negative
@@ -126,9 +138,21 @@ class EndpointResolver(
val baseUrl: String,
val requestUrl: String,
val path: String,
val legacyFallbackRequestUrl: String? = null,
val legacyFallbackPath: String? = null,
)
private data class ProbeHttpResult(
val code: Int,
val successful: Boolean,
val bodyPreview: String,
)
private val probeCache = ConcurrentHashMap<String, CacheEntry>()
private val inFlightProbes = ConcurrentHashMap<String, Deferred<Boolean>>()
private val probeScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
private val probeStateLock = Any()
private var probeGeneration = 0L
private val _probeOutcomes = MutableStateFlow<Map<String, RouteProbeOutcome>>(emptyMap())
@@ -140,6 +164,12 @@ class EndpointResolver(
*/
val probeOutcomes: StateFlow<Map<String, RouteProbeOutcome>> = _probeOutcomes.asStateFlow()
/** Last independently observed verdict for one configured route surface. */
fun outcomeFor(
candidate: EndpointCandidate,
surface: EndpointSurface,
): RouteProbeOutcome? = probeOutcomes.value[outcomeKey(candidate, surface)]
private fun recordOutcome(
candidate: EndpointCandidate,
surface: EndpointSurface,
@@ -177,41 +207,48 @@ class EndpointResolver(
const val CACHE_TTL_MS = 60_000L
/**
* Failed probe-result cache TTL. Keep this intentionally short:
* Failed probe-result cache TTL. Keep this bounded but long enough
* that ordinary screen/profile lifecycle work cannot repeatedly pay
* the full probe timeout:
* Android may report a new cellular/VPN network before Tailscale has
* finished routing, so a single early ConnectException must not keep a
* viable fallback route suppressed through the voice resume window.
* viable fallback route suppressed for long. Network-change and
* explicit-probe paths invalidate the cache immediately.
*/
const val NEGATIVE_CACHE_TTL_MS = 2_000L
const val NEGATIVE_CACHE_TTL_MS = 15_000L
/** Shared timeout wording so HEAD-timeout and socket-timeout read the same. */
private const val PROBE_TIMEOUT_DETAIL = "No answer (timed out)"
/**
* Stable cache key for one candidate surface:
* `"<surface>|<role>|<surface host>:<port>"`.
* Stable outcome/cache key for one candidate surface:
* `"<surface>|<role>|<normalized service base>"`.
* Roles are preserved case-verbatim (HMAC canonicalization contract)
* but hostnames are lowercased — two roles pointing at the same
* host:port share reachability state.
*/
internal fun cacheKey(
fun outcomeKey(
candidate: EndpointCandidate,
surface: EndpointSurface = EndpointSurface.Standard,
): String {
val authority = when (surface) {
val serviceIdentity = when (surface) {
EndpointSurface.Standard ->
candidate.routeAuthority() ?: candidate.primaryRouteUrl().orEmpty().lowercase()
EndpointSurface.Dashboard ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl ?: candidate.dashboard?.url).orEmpty()
routeIdentity(candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl ?: candidate.dashboard?.url)
EndpointSurface.Api ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.apiBaseUrl ?: candidate.api?.url).orEmpty()
routeIdentity(candidate.pluginProxyRoutesOrNull()?.apiBaseUrl ?: candidate.api?.url)
EndpointSurface.Relay ->
candidate.pluginProxyRoutesOrNull()?.authority
?: routeAuthority(candidate.relay?.url).orEmpty()
routeIdentity(candidate.pluginProxyRoutesOrNull()?.relayHttpUrl ?: candidate.relay?.url)
}
return "${surface.name.lowercase()}|${candidate.role}|$authority"
return "${surface.name.lowercase()}|${candidate.role}|$serviceIdentity"
}
internal fun cacheKey(
candidate: EndpointCandidate,
surface: EndpointSurface = EndpointSurface.Standard,
): String = outcomeKey(candidate, surface)
private fun routeAuthority(rawUrl: String?): String? {
val candidate = rawUrl?.trim()?.takeIf { it.isNotBlank() } ?: return null
val httpUrl = when {
@@ -223,17 +260,31 @@ class EndpointResolver(
}
return httpUrl.toHttpUrlOrNull()?.let { url -> "${url.host}:${url.port}" }
}
private fun routeIdentity(rawUrl: String?): String {
val candidate = rawUrl?.trim()?.takeIf { it.isNotBlank() } ?: return ""
val httpCandidate = when {
candidate.startsWith("ws://", ignoreCase = true) ->
"http://${candidate.substringAfter("://")}"
candidate.startsWith("wss://", ignoreCase = true) ->
"https://${candidate.substringAfter("://")}"
else -> candidate
}
return httpCandidate.toHttpUrlOrNull()?.let { url ->
val path = url.encodedPath.trimEnd('/').takeIf { it.isNotEmpty() }.orEmpty()
"${url.scheme}://${url.host}:${url.port}$path"
} ?: candidate.lowercase().trimEnd('/')
}
}
/**
* Run the resolver against [candidates].
*
* 1. Group by `priority` ascending.
* 2. For each priority group, race the selected surface's health probe
* against every candidate in the group. First 2xx wins; ties
* broken by whichever response lands first.
* 3. If the entire group is unreachable, fall through to the next
* priority group.
* 1. Group by `priority` ascending and by supported/experimental tier.
* 2. Start every supported priority group speculatively, while awaiting
* their results in strict priority order. Within a group, first 2xx
* wins. If higher groups fail, a completed fallback is ready at once.
* 3. Probe the experimental tier only when every supported group fails.
* 4. If no candidate is reachable, return `null` — the caller falls back
* to its legacy single-URL path.
*
@@ -254,14 +305,15 @@ class EndpointResolver(
// last-resort fallback without displacing Tailscale or direct TLS.
val supported = eligible.filterNot { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val experimental = eligible.filter { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val groups = (supported.groupBy { it.priority }.toSortedMap().values +
experimental.groupBy { it.priority }.toSortedMap().values)
val tiers = listOf(
supported.groupBy { it.priority }.toSortedMap().values.toList(),
experimental.groupBy { it.priority }.toSortedMap().values.toList(),
)
for (group in groups) {
val priority = group.first().priority
Log.d(TAG, "probing priority=$priority group (size=${group.size})")
val winner = raceGroup(group, surface)
for (groups in tiers) {
val winner = racePriorityGroups(groups, surface)
if (winner != null) {
val priority = winner.priority
val winnerUrl = probeTarget(winner, surface)?.baseUrl
Log.i(TAG, "resolve winner: role=${winner.role} " +
"surface=$surface route=$winnerUrl priority=$priority")
@@ -287,6 +339,76 @@ class EndpointResolver(
return null
}
/**
* Start all groups in one stability tier together, but consume them in
* strict priority order. Cancelling losing waiters never cancels the shared
* physical probes, so their cache/outcome records still warm later calls.
*/
private suspend fun racePriorityGroups(
groups: List<List<EndpointCandidate>>,
surface: EndpointSurface,
): EndpointCandidate? = coroutineScope {
if (groups.isEmpty()) return@coroutineScope null
val races = groups.map { group ->
val priority = group.first().priority
Log.d(TAG, "probing priority=$priority group (size=${group.size})")
group to async(Dispatchers.IO) { raceGroup(group, surface) }
}
for ((_, race) in races) {
val winner = race.await()
if (winner != null) {
races.forEach { (_, other) -> if (other !== race) other.cancel() }
return@coroutineScope winner
}
}
null
}
/**
* Probe every independently configured route surface in parallel.
*
* Dashboard/Gateway, optional API fallback, and Relay do not vouch for one
* another even when they share a hostname. Unconfigured surfaces are
* omitted. Invalidated probes publish no result, preserving the prior
* outcome until a fresh physical probe completes.
*/
suspend fun probeSurfaces(
candidate: EndpointCandidate,
): Map<EndpointSurface, RouteProbeOutcome> = coroutineScope {
val configuredSurfaces = listOf(
EndpointSurface.Dashboard,
EndpointSurface.Api,
EndpointSurface.Relay,
).filter { probeTarget(candidate, it) != null }
configuredSurfaces
.map { surface ->
async {
isReachable(candidate, surface)
surface to currentCachedOutcomeFor(candidate, surface)
}
}
.mapNotNull { deferred ->
val (surface, outcome) = deferred.await()
outcome?.let { surface to it }
}
.toMap()
}
/** Return only an outcome still backed by this generation's probe cache. */
private fun currentCachedOutcomeFor(
candidate: EndpointCandidate,
surface: EndpointSurface,
): RouteProbeOutcome? = synchronized(probeStateLock) {
val key = cacheKey(candidate, surface)
val cached = probeCache[key]
if (cached != null && cached.expiresAt > clock()) {
probeOutcomes.value[key]
} else {
null
}
}
/**
* Race all candidates in [group] (same priority tier) in parallel. First
* candidate that reports reachable — whether from cache or a fresh probe
@@ -316,20 +438,23 @@ class EndpointResolver(
}
return coroutineScope {
val deferred = group.map { candidate ->
async(Dispatchers.IO) {
if (isReachable(candidate, surface)) candidate else null
val completions = Channel<EndpointCandidate?>(group.size)
val waiters = group.map { candidate ->
launch(Dispatchers.IO) {
completions.send(if (isReachable(candidate, surface)) candidate else null)
}
}
// Collect results in arrival order: iterate through awaitAll +
// pick the first non-null. awaitAll preserves input order, which
// means a slow-but-reachable priority-0 candidate would block a
// fast-and-reachable sibling. But HEAD /health against a healthy
// API route replies in <100ms and the timeout caps stragglers at 2s,
// so this is acceptable in practice. A true "first to arrive"
// would need kotlinx.coroutines Channel plumbing that's not
// worth the weight here.
deferred.awaitAll().firstOrNull { it != null }
repeat(group.size) {
val completed = completions.receive()
if (completed != null) {
// Cancelling these waiters does not cancel the shared
// physical probes below; their outcomes still populate
// the cache for the next resolution.
waiters.forEach { it.cancel() }
return@coroutineScope completed
}
}
null
}
}
@@ -350,10 +475,33 @@ class EndpointResolver(
return cached.reachable
}
val reachable = probe(candidate, surface)
val ttl = if (reachable) CACHE_TTL_MS else NEGATIVE_CACHE_TTL_MS
probeCache[key] = CacheEntry(expiresAt = now + ttl, reachable = reachable)
return reachable
// Resolution is triggered from several independent lifecycle paths
// (connection hydration, profile restoration, network callbacks, and
// explicit probes). Share one physical request per route/surface so a
// slow optional endpoint cannot accumulate duplicate 4-second probes.
val shared = synchronized(probeStateLock) {
inFlightProbes[key] ?: run {
val generation = probeGeneration
probeScope.async(start = CoroutineStart.LAZY) {
probe(candidate, surface, generation)
}.also { deferred ->
inFlightProbes[key] = deferred
deferred.invokeOnCompletion { inFlightProbes.remove(key, deferred) }
deferred.start()
}
}
}
return try {
shared.await()
} catch (_: CancellationException) {
// clearCache() owns cancellation of the shared physical probe. A
// still-active waiter treats that invalidated result as unknown so
// same-priority races can publish their non-winning completion.
// Genuine caller cancellation still propagates from ensureActive.
currentCoroutineContext().ensureActive()
Log.d(TAG, "probe invalidated for $key")
false
}
}
/**
@@ -367,6 +515,7 @@ class EndpointResolver(
private suspend fun probe(
candidate: EndpointCandidate,
surface: EndpointSurface,
generation: Long,
): Boolean {
val startedAtMs = clock()
val operation = when (surface) {
@@ -378,19 +527,25 @@ class EndpointResolver(
val target = probeTarget(candidate, surface)
val url = target?.requestUrl?.toHttpUrlOrNull()
?: run {
Log.w(TAG, "probe: invalid url for role=${candidate.role}")
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Error,
title = context?.getString(R.string.endpoint_diag_probe_invalid) ?: "Endpoint probe invalid",
detail = "No valid Dashboard, API, or Relay URL",
operation = operation,
endpointRole = candidate.role,
configuredUrl = candidate.primaryRouteUrl(),
suggestion = "Edit or re-pair this route so it contains a valid service URL.",
)
recordOutcome(candidate, surface, reachable = false, detail = "Invalid route URL")
return false
return completeProbe(
candidate = candidate,
surface = surface,
generation = generation,
reachable = false,
detail = "Invalid route URL",
) {
Log.w(TAG, "probe: invalid url for role=${candidate.role}")
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Error,
title = context?.getString(R.string.endpoint_diag_probe_invalid) ?: "Endpoint probe invalid",
detail = "No valid Dashboard, API, or Relay URL",
operation = operation,
endpointRole = candidate.role,
configuredUrl = candidate.primaryRouteUrl(),
suggestion = "Edit or re-pair this route so it contains a valid service URL.",
)
}
}
val fastClient = (clientForCandidate?.invoke(candidate) ?: httpClient).newBuilder()
.connectTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
@@ -398,49 +553,96 @@ class EndpointResolver(
.writeTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.callTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.build()
val requestBuilder = Request.Builder()
.url(url)
.header("Accept", "*/*")
// Hermes API's aiohttp health route accepts GET but returns 405 to
// HEAD. That response proves connectivity while the old probe marked
// the route unreachable. Health payloads are tiny, so follow the
// endpoint's actual public contract on every surface.
val request = requestBuilder.get().build()
return withContext(Dispatchers.IO) {
try {
withTimeoutOrNull(PROBE_TIMEOUT_MS + 200L) {
fastClient.newCall(request).execute().use { resp ->
val ok = resp.isSuccessful
val probeTitle = if (ok) {
val primary = executeProbeHttp(fastClient, url)
val fallbackUrl = target.legacyFallbackRequestUrl
?.takeIf { dashboardHealthNeedsLegacyFallback(primary) }
?.toHttpUrlOrNull()
val result = fallbackUrl?.let { executeProbeHttp(fastClient, it) } ?: primary
val resultPath = if (fallbackUrl != null) {
target.legacyFallbackPath ?: target.path
} else {
target.path
}
val resultUrl = fallbackUrl?.toString() ?: target.requestUrl
result.let { response ->
val authRequired = surface == EndpointSurface.Relay &&
isDashboardRelayIngressUrl(candidate.relay?.url) &&
response.code in setOf(401, 403)
val reachable = response.successful || authRequired
val probeTitle = if (reachable) {
context?.getString(R.string.endpoint_diag_probe_ok) ?: "Endpoint probe ok"
} else {
context?.getString(R.string.endpoint_diag_probe_failed) ?: "Endpoint probe failed"
}
completeProbe(
candidate = candidate,
surface = surface,
generation = generation,
reachable = reachable,
detail = when {
authRequired -> "HTTP ${response.code} · Dashboard authorization required"
reachable -> null
else -> "HTTP ${response.code} from $resultPath"
},
) {
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = if (reachable) DiagnosticSeverity.Info else DiagnosticSeverity.Warning,
title = probeTitle,
detail = when {
authRequired -> "HTTP ${response.code} · Dashboard authorization required"
reachable -> null
else -> "HTTP ${response.code}"
},
operation = operation,
endpointRole = candidate.role,
configuredUrl = target.baseUrl,
requestUrl = resultUrl,
elapsedMs = clock() - startedAtMs,
suggestion = if (reachable) {
null
} else {
NetworkDiagnosticGuidance.forHttpStatus(
response.code,
surface.diagnosticTarget(),
)
},
)
}
}
} ?: run {
completeProbe(
candidate = candidate,
surface = surface,
generation = generation,
reachable = false,
detail = PROBE_TIMEOUT_DETAIL,
) {
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = if (ok) DiagnosticSeverity.Info else DiagnosticSeverity.Warning,
title = probeTitle,
detail = if (ok) null else "HTTP ${resp.code}",
severity = DiagnosticSeverity.Warning,
title = context?.getString(R.string.endpoint_diag_probe_timeout) ?: "Endpoint probe timeout",
detail = "No ${target.path} response in ${PROBE_TIMEOUT_MS}ms",
operation = operation,
endpointRole = candidate.role,
configuredUrl = target.baseUrl,
requestUrl = target.requestUrl,
elapsedMs = clock() - startedAtMs,
suggestion = if (ok) {
null
} else {
NetworkDiagnosticGuidance.forHttpStatus(resp.code, surface.diagnosticTarget())
},
suggestion = "Check network routing or firewall rules between this device and ${surface.diagnosticTarget()}.",
)
recordOutcome(
candidate,
surface,
reachable = ok,
detail = if (ok) null else "HTTP ${resp.code} from ${target.path}",
)
ok
}
} ?: run {
}
} catch (_: TimeoutCancellationException) {
completeProbe(
candidate = candidate,
surface = surface,
generation = generation,
reachable = false,
detail = PROBE_TIMEOUT_DETAIL,
) {
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Warning,
@@ -453,45 +655,81 @@ class EndpointResolver(
elapsedMs = clock() - startedAtMs,
suggestion = "Check network routing or firewall rules between this device and ${surface.diagnosticTarget()}.",
)
recordOutcome(candidate, surface, reachable = false, detail = PROBE_TIMEOUT_DETAIL)
false
}
} catch (_: TimeoutCancellationException) {
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Warning,
title = context?.getString(R.string.endpoint_diag_probe_timeout) ?: "Endpoint probe timeout",
detail = "No ${target.path} response in ${PROBE_TIMEOUT_MS}ms",
operation = operation,
endpointRole = candidate.role,
configuredUrl = target.baseUrl,
requestUrl = target.requestUrl,
elapsedMs = clock() - startedAtMs,
suggestion = "Check network routing or firewall rules between this device and ${surface.diagnosticTarget()}.",
)
recordOutcome(candidate, surface, reachable = false, detail = PROBE_TIMEOUT_DETAIL)
false
} catch (e: CancellationException) {
throw e
} catch (e: Exception) {
Log.d(TAG, "probe failed role=${candidate.role} " +
"route=${target.baseUrl}: ${e.javaClass.simpleName}")
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Warning,
title = context?.getString(R.string.endpoint_diag_probe_failed) ?: "Endpoint probe failed",
completeProbe(
candidate = candidate,
surface = surface,
generation = generation,
reachable = false,
detail = humanProbeFailure(e),
operation = operation,
endpointRole = candidate.role,
configuredUrl = target.baseUrl,
requestUrl = target.requestUrl,
elapsedMs = clock() - startedAtMs,
suggestion = NetworkDiagnosticGuidance.forThrowable(e, surface.diagnosticTarget()),
)
recordOutcome(candidate, surface, reachable = false, detail = humanProbeFailure(e))
false
) {
Log.d(TAG, "probe failed role=${candidate.role} " +
"route=${target.baseUrl}: ${e.javaClass.simpleName}")
DiagnosticsLog.record(
category = DiagnosticCategory.Endpoint,
severity = DiagnosticSeverity.Warning,
title = context?.getString(R.string.endpoint_diag_probe_failed) ?: "Endpoint probe failed",
detail = humanProbeFailure(e),
operation = operation,
endpointRole = candidate.role,
configuredUrl = target.baseUrl,
requestUrl = target.requestUrl,
elapsedMs = clock() - startedAtMs,
suggestion = NetworkDiagnosticGuidance.forThrowable(e, surface.diagnosticTarget()),
)
}
}
}
}
private fun executeProbeHttp(client: OkHttpClient, url: okhttp3.HttpUrl): ProbeHttpResult {
val request = Request.Builder()
.url(url)
.header("Accept", "application/json")
.get()
.build()
return client.newCall(request).execute().use { response ->
ProbeHttpResult(
code = response.code,
successful = response.isSuccessful,
bodyPreview = response.peekBody(4_096L).string(),
)
}
}
/** Official Desktop compatibility for Hermes versions predating `/api/health`. */
private fun dashboardHealthNeedsLegacyFallback(result: ProbeHttpResult): Boolean =
result.code == 404 ||
(result.code == 401 && result.bodyPreview.contains("no_cookie", ignoreCase = true))
/** Commit one physical probe only if it still belongs to the active cache generation. */
private suspend fun completeProbe(
candidate: EndpointCandidate,
surface: EndpointSurface,
generation: Long,
reachable: Boolean,
detail: String?,
recordDiagnostic: () -> Unit,
): Boolean {
currentCoroutineContext().ensureActive()
synchronized(probeStateLock) {
if (generation != probeGeneration) {
throw CancellationException("Endpoint probe invalidated")
}
recordDiagnostic()
recordOutcome(candidate, surface, reachable, detail)
val ttl = if (reachable) CACHE_TTL_MS else NEGATIVE_CACHE_TTL_MS
probeCache[cacheKey(candidate, surface)] = CacheEntry(
expiresAt = clock() + ttl,
reachable = reachable,
)
}
return reachable
}
/** Choose the standard Dashboard/Gateway surface first when advertised. */
private fun probeTarget(
candidate: EndpointCandidate,
@@ -499,10 +737,22 @@ class EndpointResolver(
): ProbeTarget? {
if (surface == EndpointSurface.Dashboard) {
candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl?.let { base ->
return ProbeTarget(base, "$base/api/status", "/dashboard/api/status")
return ProbeTarget(
baseUrl = base,
requestUrl = "$base/api/health",
path = "/dashboard/api/health",
legacyFallbackRequestUrl = "$base/api/status",
legacyFallbackPath = "/dashboard/api/status",
)
}
candidate.dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }?.let { base ->
return ProbeTarget(base, "$base/api/status", "/api/status")
return ProbeTarget(
baseUrl = base,
requestUrl = "$base/api/health",
path = "/api/health",
legacyFallbackRequestUrl = "$base/api/status",
legacyFallbackPath = "/api/status",
)
}
return null
}
@@ -530,8 +780,10 @@ class EndpointResolver(
?.let { base ->
return ProbeTarget(
baseUrl = base,
requestUrl = "$base/api/status",
path = "/api/status",
requestUrl = "$base/api/health",
path = "/api/health",
legacyFallbackRequestUrl = "$base/api/status",
legacyFallbackPath = "/api/status",
)
}
@@ -602,17 +854,19 @@ class EndpointResolver(
candidate: EndpointCandidate,
surface: EndpointSurface = EndpointSurface.Standard,
) {
val key = cacheKey(candidate, surface)
probeCache[key] = CacheEntry(
expiresAt = clock() + NEGATIVE_CACHE_TTL_MS,
reachable = false,
)
recordOutcome(
candidate,
surface,
reachable = false,
detail = "Network changed — assumed offline",
)
synchronized(probeStateLock) {
val key = cacheKey(candidate, surface)
probeCache[key] = CacheEntry(
expiresAt = clock() + NEGATIVE_CACHE_TTL_MS,
reachable = false,
)
recordOutcome(
candidate,
surface,
reachable = false,
detail = "Network changed — assumed offline",
)
}
}
/**
@@ -623,7 +877,17 @@ class EndpointResolver(
* just-died route must not outlive the handoff.
*/
internal fun clearCache() {
probeCache.clear()
val staleProbes = synchronized(probeStateLock) {
probeGeneration += 1L
probeCache.clear()
inFlightProbes.values.toList().also { inFlightProbes.clear() }
}
// An explicit re-probe must not join a request that began before the
// invalidation signal. Cancellation is resolver-owned (not waiter-
// owned), so ordinary lifecycle cancellation still leaves shared
// probes alive for other callers. The generation check prevents a
// late InterruptedIOException/response from publishing stale state.
staleProbes.forEach { it.cancel() }
}
/** Test-only: snapshot the current cache for assertion purposes. */
@@ -43,15 +43,16 @@ object HermesLanDiscovery {
private const val TAG = "HermesLanDiscovery"
private const val MAX_HOSTS = 254
private const val MAX_CONCURRENT_PROBES = 32
private const val PROBE_TIMEOUT_MS = 650L
private const val PROBE_TIMEOUT_MS = 750L
private const val IPV4_MASK = 0xFFFF_FFFFL
suspend fun scan(
context: Context,
apiPort: Int = 8642,
dashboardPort: Int = 9119,
dashboardOnly: Boolean = false,
): List<HermesLanDiscoveryResult> = withContext(Dispatchers.IO) {
val hosts = localLanHosts(context.applicationContext)
val hosts = prioritizeHostSweep(localLanHosts(context.applicationContext))
if (hosts.isEmpty()) return@withContext emptyList()
val client = OkHttpClient.Builder()
@@ -66,7 +67,13 @@ object HermesLanDiscovery {
hosts.map { host ->
async {
semaphore.withPermit {
probeHost(client, host, apiPort, dashboardPort)?.let { result ->
probeHost(
client,
host,
apiPort,
dashboardPort,
dashboardOnly,
)?.let { result ->
result.copy(hostname = resolveHostname(host))
}
}
@@ -88,6 +95,7 @@ object HermesLanDiscovery {
host: String,
apiPort: Int,
dashboardPort: Int,
dashboardOnly: Boolean,
): HermesLanDiscoveryResult? {
val apiUrl = "http://$host:$apiPort"
val dashboardUrl = "http://$host:$dashboardPort"
@@ -95,12 +103,18 @@ object HermesLanDiscovery {
client = client,
url = "$dashboardUrl/api/status",
expectedBody = ::looksLikeDashboardStatus,
attempts = 2,
)
val apiReachable = probe(
client = client,
url = "$apiUrl/health",
expectedBody = ::looksLikeApiHealth,
)
if (dashboardOnly && !dashboardReachable) return null
val apiReachable = if (dashboardOnly) {
false
} else {
probe(
client = client,
url = "$apiUrl/health",
expectedBody = ::looksLikeApiHealth,
)
}
if (!dashboardReachable && !apiReachable) return null
return HermesLanDiscoveryResult(
host = host,
@@ -115,6 +129,7 @@ object HermesLanDiscovery {
client: OkHttpClient,
url: String,
expectedBody: (String, String) -> Boolean,
attempts: Int = 1,
): Boolean {
val httpUrl = url.toHttpUrlOrNull() ?: return false
val request = Request.Builder()
@@ -123,21 +138,25 @@ object HermesLanDiscovery {
.header("Accept", "application/json, text/plain, */*")
.build()
return try {
client.newCall(request).execute().use { response ->
if (response.code == 401 || response.code == 403) {
return true
repeat(attempts.coerceAtLeast(1)) { attempt ->
try {
client.newCall(request).execute().use { response ->
if (response.code == 401 || response.code == 403) {
return true
}
if (!response.isSuccessful) {
if (response.code >= 500 && attempt + 1 < attempts) return@use
return false
}
val contentType = response.header("Content-Type").orEmpty()
val body = response.body.string().take(2_048)
if (expectedBody(body, contentType)) return true
}
if (!response.isSuccessful) {
return false
}
val contentType = response.header("Content-Type").orEmpty()
val body = response.body.string().take(2_048)
expectedBody(body, contentType)
} catch (_: Exception) {
if (attempt + 1 >= attempts) return false
}
} catch (_: Exception) {
false
}
return false
}
private suspend fun resolveHostname(address: String): String? =
@@ -158,6 +177,23 @@ object HermesLanDiscovery {
return normalized
}
/** Interleave low/high host suffixes so `.1` and `.250` are both early. */
internal fun prioritizeHostSweep(hosts: List<String>): List<String> {
val sorted = hosts.distinct().sortedBy { address ->
address.split('.').fold(0L) { acc, part ->
(acc shl 8) + (part.toLongOrNull() ?: 0L)
}
}
val prioritized = ArrayList<String>(sorted.size)
var low = 0
var high = sorted.lastIndex
while (low <= high) {
prioritized += sorted[low++]
if (low <= high) prioritized += sorted[high--]
}
return prioritized
}
private fun looksLikeDashboardStatus(body: String, contentType: String): Boolean {
val lower = body.lowercase()
return contentType.contains("json", ignoreCase = true) && (
@@ -13,6 +13,7 @@ import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.MoaReference
import com.hermesandroid.relay.data.RealtimeTurnTrace
import com.hermesandroid.relay.data.ToolCall
import com.hermesandroid.relay.data.isImageGenerationToolName
import com.hermesandroid.relay.data.VoiceIntentTrace
import com.hermesandroid.relay.network.shared.LocalDispatchResult
import com.hermesandroid.relay.network.upstream.models.MessageItem
@@ -1006,6 +1007,56 @@ class ChatHandler {
}
}
/**
* Bound the ephemeral, read-only child-watch projection. This is stricter
* than the main transcript: system rows and tool results are not part of
* the preview contract, and one live child must not retain unbounded text.
*/
internal fun boundReadOnlyPreview(
maxMessages: Int = 100,
maxTotalChars: Int = 32_000,
maxFieldChars: Int = 8_000,
maxToolChars: Int = 1_000,
): Boolean {
var truncated = false
_messages.update { current ->
val visible = current.filterNot { it.role == MessageRole.SYSTEM }
if (visible.size != current.size || visible.size > maxMessages) truncated = true
var remaining = maxTotalChars
val kept = mutableListOf<ChatMessage>()
visible.takeLast(maxMessages).asReversed().forEach { message ->
if (remaining <= 0) {
truncated = true
return@forEach
}
fun bounded(value: String, limit: Int): String {
val allowed = minOf(limit, remaining)
val next = value.takeLast(allowed)
if (next.length != value.length) truncated = true
remaining -= next.length
return next
}
val content = bounded(message.content, maxFieldChars)
val thinking = bounded(message.thinkingContent, maxFieldChars)
val tools = message.toolCalls.takeLast(50).map { tool ->
if (message.toolCalls.size > 50) truncated = true
tool.copy(
args = tool.args?.let { bounded(it, maxToolChars) },
result = null,
error = tool.error?.let { bounded(it, maxToolChars) },
)
}
kept += message.copy(
content = content,
thinkingContent = thinking,
toolCalls = tools,
)
}
kept.asReversed()
}
return truncated
}
/**
* Rehydrate the last client-owned state of an unfinished turn.
*
@@ -1449,11 +1500,13 @@ class ChatHandler {
// Run the media marker parser on assistant content; strip matched
// lines and queue hits for post-assignment dispatch.
val messageMediaHits = mutableListOf<Pair<String, MediaMarkerHit>>()
val afterMedia = if (role == MessageRole.ASSISTANT && persistedImages.cleanedText.isNotEmpty()) {
extractMediaMarkersFromContent(messageId, persistedImages.cleanedText, pendingMediaHits)
extractMediaMarkersFromContent(messageId, persistedImages.cleanedText, messageMediaHits)
} else {
persistedImages.cleanedText
}
pendingMediaHits += messageMediaHits
// Cards are synchronous (no async fetch) so we attach them
// straight onto the reconstructed ChatMessage and strip their
@@ -1487,15 +1540,25 @@ class ChatHandler {
val prior = priorById[messageId]
// Outbound attachments: prefer an id-match (covers any future
// user-message id reconciliation), else fall back to the
// content-keyed queue. Inbound attachments are intentionally
// excluded — they come back via the marker re-dispatch.
// content-keyed queue. Inbound attachments normally come back via
// marker re-dispatch. One narrow exception retains a completed
// image_generate result when the immediate post-turn history read
// still lacks its MEDIA marker; otherwise the rendered image
// disappears during the persistence-lag window.
val carriedAttachments = run {
val persistedImagePaths = persistedImages.paths.toHashSet()
val priorGeneratedImage = prior?.toolCalls.orEmpty().any { tool ->
isImageGenerationToolName(tool.name) &&
tool.isComplete && tool.success != false
}
val byId = prior?.attachments.orEmpty().filter { attachment ->
attachment.relayToken == null ||
(role == MessageRole.USER && attachment.relayToken in persistedImagePaths) ||
(
role == MessageRole.USER &&
attachment.relayToken in persistedImagePaths
role == MessageRole.ASSISTANT &&
priorGeneratedImage &&
attachment.isImage &&
messageMediaHits.isEmpty()
)
}
when {
@@ -2036,7 +2099,7 @@ class ChatHandler {
/**
* Update sessions list from API response.
*/
fun updateSessions(items: List<SessionItem>) {
fun updateSessions(items: List<SessionItem>, append: Boolean = false) {
// Index the current rows so a server row that arrives without a title
// can inherit a title we already know locally. Auto-titling is a
// fire-and-forget background job on the server (upstream
@@ -2109,9 +2172,22 @@ class ChatHandler {
} else {
null
}
_sessions.value = if (pending != null) listOf(pending) + mapped else mapped
val resolved = if (append) {
(_sessions.value + mapped)
.distinctBy { it.sessionId }
.sortedByDescending { it.activityTimestamp }
} else {
mapped
}
_sessions.value = if (pending != null && resolved.none { it.sessionId == pending.sessionId }) {
listOf(pending) + resolved
} else {
resolved
}
}
fun appendSessions(items: List<SessionItem>) = updateSessions(items, append = true)
fun clearSessions() {
_sessions.value = emptyList()
}
@@ -3030,7 +3106,9 @@ class ChatHandler {
fun onSubagentEvent(messageId: String, event: GatewaySubagentEvent) {
val label = event.goal.trim().take(60).ifBlank { null }
when (event.phase) {
GatewaySubagentEvent.Phase.START -> {
GatewaySubagentEvent.Phase.SPAWN_REQUESTED,
GatewaySubagentEvent.Phase.START,
-> {
if (label != null) subagentLabels[event.taskIndex] = label
event.subagentId?.takeIf(String::isNotBlank)?.let {
subagentIds[event.taskIndex] = it
@@ -18,6 +18,8 @@ import com.hermesandroid.relay.auth.SecureStoreCache
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.buildRawTokenStore
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.suspendCancellableCoroutine
import kotlinx.coroutines.withTimeoutOrNull
import kotlinx.coroutines.withContext
import kotlinx.serialization.Serializable
import kotlinx.serialization.SerialName
@@ -34,6 +36,8 @@ import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.jsonObject
import kotlinx.serialization.json.jsonPrimitive
import kotlinx.serialization.json.put
import okhttp3.Call
import okhttp3.Callback
import okhttp3.Cookie
import okhttp3.CookieJar
import okhttp3.HttpUrl
@@ -50,6 +54,7 @@ import java.io.InputStream
import java.io.OutputStream
import java.net.URLEncoder
import java.util.concurrent.TimeUnit
import kotlin.coroutines.resume
import okio.BufferedSink
// Status/session/provider snapshots are @Serializable so the Manage tab's
@@ -316,12 +321,16 @@ data class ElevenLabsVoices(
class DashboardApiClient(
baseUrl: String,
private val okHttpClient: OkHttpClient = defaultClient(),
private val ownsHttpClient: Boolean = true,
private val json: Json = Json {
ignoreUnknownKeys = true
isLenient = true
coerceInputValues = true
},
private val nowMillis: () -> Long = System::currentTimeMillis,
private val sessionReadTimeoutMillis: Long = SESSION_READ_TIMEOUT_MILLIS,
private val controlReadTimeoutMillis: Long = CONTROL_READ_TIMEOUT_MILLIS,
private val sessionEnrichmentBudgetMillis: Long = SESSION_ENRICHMENT_BUDGET_MILLIS,
) {
private val baseUrl: String = baseUrl.trim().trimEnd('/')
private val sessionPrScanLock = Any()
@@ -1027,16 +1036,20 @@ class DashboardApiClient(
suspend fun listSessions(
profile: String? = null,
limit: Int = SESSION_LIST_WINDOW_LIMIT,
offset: Int = 0,
archived: String? = null,
excludeSources: Collection<String> = emptyList(),
): Result<List<SessionItem>> =
withContext(Dispatchers.IO) {
val readDeadlineNanos = System.nanoTime() +
TimeUnit.MILLISECONDS.toNanos(sessionReadTimeoutMillis.coerceAtLeast(1L))
val sessions = linkedMapOf<String, SessionItem>()
for (page in sessionListPages(limit)) {
val query = buildList {
// Upstream dashboard GET /api/sessions rejects pages over 100.
// Keep Android's 200-row drawer window via two bounded pages.
add("limit=${page.limit}")
add("offset=${page.offset}")
add("offset=${offset.coerceAtLeast(0) + page.offset}")
add("order=recent")
add("min_messages=1")
val name = profile?.trim().orEmpty()
@@ -1045,8 +1058,33 @@ class DashboardApiClient(
// Omitted unless requested so older hosts see an unchanged request.
val archivedMode = archived?.trim().orEmpty()
if (archivedMode.isNotBlank()) add("archived=${pathSegment(archivedMode)}")
val excluded = excludeSources
.asSequence()
.map(String::trim)
.filter(String::isNotBlank)
.map(String::lowercase)
.distinct()
.sorted()
.toList()
if (excluded.isNotEmpty()) {
add("exclude_sources=${queryValue(excluded.joinToString(","))}")
}
}.joinToString(prefix = "?", separator = "&")
val pageResult = getJson("/api/sessions$query").mapCatching { root ->
val remainingReadMillis = TimeUnit.NANOSECONDS.toMillis(
readDeadlineNanos - System.nanoTime(),
)
if (remainingReadMillis <= 0L) {
return@withContext Result.failure(
IOException("Dashboard session list exceeded its bounded read window"),
)
}
val pageResult = getJson(
"/api/sessions$query",
// One budget covers the complete 200-row operation. A slow
// first page cannot silently turn the nominal 8s bound into
// 16s when the second page is needed.
callTimeoutMillis = remainingReadMillis,
).mapCatching { root ->
val parsed = json.decodeFromJsonElement(SessionListResponse.serializer(), root)
parsed.sessions ?: parsed.items ?: parsed.data ?: emptyList()
}
@@ -1055,13 +1093,20 @@ class DashboardApiClient(
pageSessions.forEach { sessions.putIfAbsent(it.id, it) }
if (pageSessions.size < page.limit) break
}
Result.success(
val listed = sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT))
// Repository/PR decoration is useful drawer metadata, but it is not
// authoritative session data. Keep it off the critical path when an
// older host or an unavailable GitHub helper stalls: return the exact
// profile-scoped rows within a small budget and retry decoration on a
// later refresh. Cancellation also cancels the active OkHttp call.
val enriched = withTimeoutOrNull(sessionEnrichmentBudgetMillis) {
enrichSessionWorkState(
sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)),
listed,
fixedProfile = profile?.trim()?.takeIf { it.isNotBlank() }
?: DEFAULT_SESSION_PROFILE_SCOPE,
),
)
)
} ?: listed
Result.success(enriched)
}
/**
@@ -1227,7 +1272,10 @@ class DashboardApiClient(
add("order=${page.order}")
if (name.isNotBlank()) add("profile=${pathSegment(name)}")
}.joinToString(prefix = "?", separator = "&")
getJson("/api/sessions/${pathSegment(sessionId)}/messages$query").mapCatching { root ->
getJson(
"/api/sessions/${pathSegment(sessionId)}/messages$query",
callTimeoutMillis = sessionReadTimeoutMillis,
).mapCatching { root ->
val parsed = json.decodeFromJsonElement(MessageListResponse.serializer(), root)
SessionMessagePage(
messages = parsed.messages ?: parsed.data ?: parsed.items ?: emptyList(),
@@ -1471,10 +1519,14 @@ class DashboardApiClient(
.post(ByteArray(0).toRequestBody(null))
.build()
executeJson(request, "Dashboard websocket ticket").mapCatching { root ->
executeJson(
request,
"Dashboard websocket ticket",
callTimeoutMillis = controlReadTimeoutMillis,
).mapCatching { root ->
val ticket = root.stringField("ticket")
?: root.stringField("ws_ticket")
?: throw IOException("Dashboard websocket ticket response missing ticket")
?: throw IllegalStateException("Dashboard websocket ticket response missing ticket")
DashboardWsTicket(
ticket = ticket,
ttlSeconds = root.intField("ttl_seconds") ?: root.intField("ttl"),
@@ -1496,44 +1548,77 @@ class DashboardApiClient(
profile = profile,
)
fun shutdown() = shutdownOffMainThread("DashboardApiClient-shutdown") {
okHttpClient.dispatcher.executorService.shutdown()
okHttpClient.connectionPool.evictAll()
fun shutdown() {
if (!ownsHttpClient) return
shutdownOffMainThread("DashboardApiClient-shutdown") {
okHttpClient.dispatcher.executorService.shutdown()
okHttpClient.connectionPool.evictAll()
}
}
private suspend fun getJson(path: String): Result<JsonObject> = withContext(Dispatchers.IO) {
private suspend fun getJson(
path: String,
callTimeoutMillis: Long? = null,
): Result<JsonObject> = withContext(Dispatchers.IO) {
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val request = Request.Builder()
.url(httpUrl)
.get()
.build()
executeJson(request, path)
executeJson(request, path, callTimeoutMillis)
}
private fun executeJson(request: Request, operation: String): Result<JsonObject> {
return try {
okHttpClient.newCall(request).execute().use { response ->
if (!response.isSuccessful) {
return Result.failure(apiFailure(response, operation))
}
Result.success(response.readJsonObject(json))
}
} catch (e: Exception) {
Result.failure(e)
}
private suspend fun executeJson(
request: Request,
operation: String,
callTimeoutMillis: Long? = null,
): Result<JsonObject> = executeCancellable(request, operation, callTimeoutMillis) { response ->
response.readJsonObject(json)
}
private fun executeJsonElement(request: Request, operation: String): Result<JsonElement> {
return try {
okHttpClient.newCall(request).execute().use { response ->
if (!response.isSuccessful) {
return Result.failure(apiFailure(response, operation))
}
Result.success(response.readJsonElement(json))
}
} catch (e: Exception) {
Result.failure(e)
private suspend fun executeJsonElement(
request: Request,
operation: String,
): Result<JsonElement> = executeCancellable(request, operation) { response ->
response.readJsonElement(json)
}
/** Bridge OkHttp cancellation to the owning coroutine so superseded profile reads do not linger. */
private suspend fun <T> executeCancellable(
request: Request,
operation: String,
callTimeoutMillis: Long? = null,
decode: (Response) -> T,
): Result<T> = suspendCancellableCoroutine { continuation ->
val call = okHttpClient.newCall(request)
callTimeoutMillis?.takeIf { it > 0L }?.let {
call.timeout().timeout(it, TimeUnit.MILLISECONDS)
}
continuation.invokeOnCancellation { call.cancel() }
call.enqueue(object : Callback {
override fun onFailure(call: Call, e: IOException) {
runCatching {
if (continuation.isActive) continuation.resume(Result.failure(e))
}
}
override fun onResponse(call: Call, response: Response) {
val result = response.use {
try {
if (!it.isSuccessful) {
Result.failure(apiFailure(it, operation))
} else {
Result.success(decode(it))
}
} catch (error: Exception) {
Result.failure(error)
}
}
runCatching {
if (continuation.isActive) continuation.resume(result)
}
}
})
}
private suspend fun download(
@@ -1570,6 +1655,13 @@ class DashboardApiClient(
companion object {
private val JSON_MEDIA = "application/json; charset=utf-8".toMediaType()
private const val DEFAULT_SESSION_PROFILE_SCOPE = "__dashboard_default__"
// Desktop allows 60s for its 40-row recents request. Android uses a
// similarly small initial window and a bounded 20s mobile budget;
// the old 8s deadline repeatedly cancelled valid first-load reads on
// large profile databases before any row could be shown.
private const val SESSION_READ_TIMEOUT_MILLIS = 20_000L
private const val CONTROL_READ_TIMEOUT_MILLIS = 8_000L
private const val SESSION_ENRICHMENT_BUDGET_MILLIS = 1_500L
internal const val ACTIVE_SESSION_PR_MISS_TTL_MILLIS = 60_000L
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
@@ -1712,8 +1804,9 @@ class DashboardApiClient(
cookieStore: DashboardCookieStore = InMemoryDashboardCookieStore(),
bearerAuth: DashboardBearerAuth? = null,
): OkHttpClient {
val cookieJar = DashboardCookieJar(cookieStore)
val builder = OkHttpClient.Builder()
.cookieJar(DashboardCookieJar(cookieStore))
.cookieJar(cookieJar)
.connectTimeout(10, TimeUnit.SECONDS)
// Skills-hub search fans out server-side with a 30s overall
// timeout; keep the read window above it so a slow-but-successful
@@ -1721,6 +1814,7 @@ class DashboardApiClient(
.readTimeout(45, TimeUnit.SECONDS)
.writeTimeout(30, TimeUnit.SECONDS)
bearerAuth?.let {
it.preferCookiesWhen(cookieJar::hasCookiesFor)
builder.addInterceptor(it)
builder.authenticator(it)
}
@@ -2080,14 +2174,20 @@ class DashboardCookieJar(
private val store: DashboardCookieStore,
private val clockMillis: () -> Long = { System.currentTimeMillis() },
) : CookieJar {
fun hasCookiesFor(url: HttpUrl): Boolean = loadForRequest(url).isNotEmpty()
override fun saveFromResponse(url: HttpUrl, cookies: List<Cookie>) {
val now = clockMillis()
val incoming = cookies.map { StoredDashboardCookie.fromCookie(it) }
.filterNot { it.isExpired(now) }
val incomingSessionFamilies = incoming.mapNotNullTo(mutableSetOf()) {
it.sessionFamilyKey()
}
val retained = store.load()
.filterNot { it.isExpired(now) }
.filterNot { old -> incoming.any { it.key == old.key } }
store.save(retained + incoming)
.filterNot { old -> old.sessionFamilyKey() in incomingSessionFamilies }
store.save(collapseDashboardSessionCookieVariants(retained + incoming))
}
override fun loadForRequest(url: HttpUrl): List<Cookie> {
@@ -2095,7 +2195,9 @@ class DashboardCookieJar(
// Load once (each load() is a decrypt + JSON decode); prune expired
// entries back to disk only when something actually expired.
val all = store.load()
val stored = all.filterNot { it.isExpired(now) }
val stored = collapseDashboardSessionCookieVariants(
all.filterNot { it.isExpired(now) },
)
if (stored.size != all.size) {
store.save(stored)
}
@@ -2104,61 +2206,6 @@ class DashboardCookieJar(
}
}
/**
* Copy only Hermes' authenticated dashboard session cookies to another host
* that belongs to the same saved Connection. Dashboard cookies are host-only
* by design, while a Connection may reach one server through LAN and
* Tailscale hostnames/IPs. The encrypted store remains the source of truth and
* explicit sign-out clears every mirrored host together.
*
* PKCE, SSO-attempt, and unrelated application cookies are intentionally not
* copied. Secure cookies also remain Secure; this helper never downgrades them
* for an HTTP route.
*/
fun mirrorDashboardSessionCookies(
store: DashboardCookieStore,
targetUrl: String,
trustedHosts: Set<String>,
clockMillis: () -> Long = { System.currentTimeMillis() },
): Int {
val targetHost = targetUrl.toHttpUrlOrNull()?.host?.lowercase() ?: return 0
val allowedHosts = trustedHosts.mapTo(mutableSetOf()) { it.lowercase() }
if (targetHost !in allowedHosts) return 0
val now = clockMillis()
val all = store.load()
val live = all.filterNot { it.isExpired(now) }
val existingTargetKeys = live.asSequence()
.filter { it.domain.equals(targetHost, ignoreCase = true) }
.map { "${it.name.lowercase()}|$targetHost|${it.path}" }
.toSet()
val mirrored = live.asSequence()
.filter { it.isDashboardSessionCookie() }
.filter { it.domain.lowercase() in allowedHosts }
.filterNot { it.domain.equals(targetHost, ignoreCase = true) }
.groupBy { "${it.name.lowercase()}|${it.path}" }
.values
.mapNotNull { candidates -> candidates.maxByOrNull { it.expiresAt } }
.map { it.copy(domain = targetHost, hostOnly = true) }
.filterNot { it.key in existingTargetKeys }
.toList()
if (mirrored.isNotEmpty() || live.size != all.size) {
store.save(live + mirrored)
}
return mirrored.size
}
private fun StoredDashboardCookie.isDashboardSessionCookie(): Boolean {
val bareName = name
.removePrefix("__Host-")
.removePrefix("__Secure-")
return bareName == "hermes_session" ||
bareName == "hermes_session_at" ||
bareName == "hermes_session_rt" ||
bareName == "hermes_session_provider"
}
/**
* Cookie jar that resolves the backing per-connection store at request time.
*
@@ -2220,13 +2267,78 @@ fun importDashboardCookieHeader(
.filterNot { it.isExpired(now) }
if (imported.isEmpty()) return 0
val importedSessionFamilies = imported.mapNotNullTo(mutableSetOf()) {
it.sessionFamilyKey()
}
val retained = store.load()
.filterNot { it.isExpired(now) }
.filterNot { old -> imported.any { it.key == old.key } }
store.save(retained + imported)
.filterNot { old -> old.sessionFamilyKey() in importedSessionFamilies }
store.save(collapseDashboardSessionCookieVariants(retained + imported))
return imported.size
}
private val DASHBOARD_SESSION_COOKIE_FAMILIES = setOf(
"hermes_session",
"hermes_session_at",
"hermes_session_rt",
"hermes_session_provider",
)
internal val DASHBOARD_SESSION_COOKIE_VARIANT_NAMES: List<String> =
DASHBOARD_SESSION_COOKIE_FAMILIES.flatMap { name ->
listOf(name, "__Host-$name", "__Secure-$name")
}
private fun isDashboardSessionCookieName(name: String): Boolean =
name.lowercase()
.removePrefix("__host-")
.removePrefix("__secure-") in DASHBOARD_SESSION_COOKIE_FAMILIES
/**
* Clear only Hermes session cookies that would be attached to [requestUrl].
* Called solely after an explicit provider selection; background 503 probes
* never mutate auth state.
*/
internal fun clearDashboardSessionCookiesForRequest(
store: DashboardCookieStore,
requestUrl: String,
): Int {
val url = requestUrl.toHttpUrlOrNull() ?: return 0
val current = store.load()
val retained = current.filterNot { stored ->
isDashboardSessionCookieName(stored.name) && stored.toCookie()?.matches(url) == true
}
if (retained.size != current.size) store.save(retained)
return current.size - retained.size
}
private fun StoredDashboardCookie.sessionFamilyKey(): String? {
val normalized = name.lowercase()
.removePrefix("__host-")
.removePrefix("__secure-")
if (normalized !in DASHBOARD_SESSION_COOKIE_FAMILIES) return null
return "$normalized|${domain.lowercase()}|$path"
}
/**
* HTTPS/proxy changes can leave bare, `__Host-`, and `__Secure-` variants in
* Android's imported WebView store. Hermes treats those names as one logical
* session family and prefers the strict prefix, so coexistence can revive an
* older provider session. Preserve list order and keep only the newest variant.
*/
private fun collapseDashboardSessionCookieVariants(
cookies: List<StoredDashboardCookie>,
): List<StoredDashboardCookie> {
val lastIndexByFamily = mutableMapOf<String, Int>()
cookies.forEachIndexed { index, cookie ->
cookie.sessionFamilyKey()?.let { lastIndexByFamily[it] = index }
}
return cookies.filterIndexed { index, cookie ->
cookie.sessionFamilyKey()?.let { lastIndexByFamily[it] == index } ?: true
}
}
@Serializable
data class StoredDashboardCookie(
val name: String,
@@ -2293,10 +2405,59 @@ private fun Response.readJsonElement(json: Json): JsonElement {
return json.parseToJsonElement(raw)
}
internal class DashboardHttpException(
val statusCode: Int,
message: String,
) : IOException(message)
internal fun Throwable.isDashboardAuthProviderUnavailable(): Boolean {
var current: Throwable? = this
val seen = java.util.Collections.newSetFromMap(
java.util.IdentityHashMap<Throwable, Boolean>(),
)
while (current != null && seen.add(current)) {
if (
current is DashboardHttpException &&
current.statusCode == 503 &&
current.message.orEmpty().contains("Auth provider", ignoreCase = true) &&
current.message.orEmpty().contains("unreachable", ignoreCase = true)
) {
return true
}
current = current.cause
}
return false
}
internal fun Throwable.isDashboardSignInRequiredFailure(): Boolean {
if (isDashboardAuthProviderUnavailable()) return true
var current: Throwable? = this
val seen = java.util.Collections.newSetFromMap(
java.util.IdentityHashMap<Throwable, Boolean>(),
)
while (current != null && seen.add(current)) {
if (
current is DashboardHttpException &&
current.statusCode == 401 &&
(
current.message.orEmpty().contains("no_cookie", ignoreCase = true) ||
current.message.orEmpty().contains("unauthenticated", ignoreCase = true)
)
) {
return true
}
current = current.cause
}
return false
}
private fun apiFailure(response: Response, operation: String): IOException {
val bodyDetail = runCatching { response.body.string() }.getOrDefault("")
val detail = bodyDetail.take(240).ifBlank { response.message }
return IOException("$operation failed - HTTP ${response.code}: $detail")
return DashboardHttpException(
statusCode = response.code,
message = "$operation failed - HTTP ${response.code}: $detail",
)
}
private fun JsonObject?.stringField(name: String): String? =
@@ -104,6 +104,12 @@ class GatewayChatClient(
private val callbackDispatcher: (block: () -> Unit) -> Unit = MainThreadDispatcher,
/** Surface for "this server has no usable /api/ws" — flips availability to Unsupported. */
private val onGatewayUnsupported: () -> Unit = {},
/** Ticket/upgrade auth rejection is distinct from an unsupported Gateway. */
private val onGatewaySignInRequired: () -> Unit = {},
/** A bounded ticket/connect failure makes this route unreachable for now. */
private val onGatewayUnreachable: () -> Unit = {},
/** A completed gateway.ready handshake is authoritative live transport evidence. */
private val onGatewayReady: () -> Unit = {},
private val scope: CoroutineScope = CoroutineScope(SupervisorJob() + Dispatchers.IO),
/** Max wall-clock a single mid-turn reconnect keeps retrying before failing the turn. */
private val midTurnRejoinWindowMs: Long = MAX_MIDTURN_REJOIN_MS,
@@ -204,11 +210,16 @@ class GatewayChatClient(
/** Cooldown after a failed connect so rapid sends don't hammer a down server. */
private const val CONNECT_FAILURE_COOLDOWN_MS = 5_000L
private const val MAX_CONNECT_FAILURE_COOLDOWN_MS = 30_000L
private const val COLD_START_FAILURE_EPISODE_LIMIT = 5
private const val RATE_LIMIT_COOLDOWN_MS = 300_000L
private const val CONNECT_ATTEMPTS = 2
private const val INBOUND_BIND_TIMEOUT_MS = 2_000L
private const val CANCELLED_TURN_SUBMIT_WAIT_MS = 2_000L
private const val MAX_RECOVERY_BUFFERED_EVENTS = 256
internal const val MAX_CHILD_WATCH_HISTORY_ITEMS = 200
internal const val MAX_CHILD_WATCH_HISTORY_CHARS = 64_000
private const val MAX_PENDING_CHILD_WATCH_EVENTS = 256
/** Distinct socket-loss (flap) events per turn we'll try to recover from. */
private const val MAX_TURN_REJOINS = 4
@@ -270,6 +281,13 @@ class GatewayChatClient(
private val _connectionState = MutableStateFlow(GatewayConnectionState.Idle)
val connectionState: StateFlow<GatewayConnectionState> = _connectionState.asStateFlow()
private val _reconnectDisposition = MutableStateFlow(GatewayReconnectDisposition.Retryable)
val reconnectDisposition: StateFlow<GatewayReconnectDisposition> =
_reconnectDisposition.asStateFlow()
/** Delay a foreground reconnect only while the bounded failure cooldown is active. */
fun remainingConnectCooldownMillis(nowMillis: Long = System.currentTimeMillis()): Long =
(connectCooldownUntil - nowMillis).coerceAtLeast(0L)
/**
* Per-socket feature probe for upstream's session-scoped `process.*` RPCs.
@@ -381,6 +399,15 @@ class GatewayChatClient(
private val prewarmRequestGeneration = AtomicLong(0)
private val pendingRpcs = ConcurrentHashMap<Long, CompletableDeferred<JsonObject>>()
/** Monotonic client-local fence for lazy child watch open/close races. */
private val childWatchGeneration = AtomicLong(0)
/** Live child runtime id -> exact watcher that owns its callbacks. */
private val childWatches = ConcurrentHashMap<String, ChildWatchRegistration>()
/** Events that race a lazy `session.resume` acknowledgement. */
private val pendingChildWatchOpens = ConcurrentHashMap<Long, PendingChildWatchOpen>()
/** Live (per-connection) session id ←→ the stored DB id it was resumed/created from. */
@Volatile
private var liveSessionId: String? = null
@@ -447,6 +474,62 @@ class GatewayChatClient(
@Volatile var pendingAsk: GatewayAsk? = null,
)
private class ChildWatchRegistration(
val storedSessionId: String,
val liveSessionId: String,
val profile: String?,
val generation: Long,
val callbacks: GatewayTurnCallbacks,
) {
lateinit var mapper: GatewayEventMapper
}
private data class ChildWatchEvent(
val sessionId: String,
val type: String,
val payload: JsonObject?,
)
private data class PendingChildWatchReplay(
val events: List<ChildWatchEvent>,
val truncated: Boolean,
)
private class PendingChildWatchOpen {
private val lock = Any()
private val events = mutableListOf<ChildWatchEvent>()
private var closed = false
private var truncated = false
fun capture(event: ChildWatchEvent): Boolean = synchronized(lock) {
if (closed) return@synchronized false
if (events.size >= MAX_PENDING_CHILD_WATCH_EVENTS) {
events.removeAt(0)
truncated = true
}
events += event
true
}
fun closeAndTake(sessionId: String): PendingChildWatchReplay = synchronized(lock) {
closed = true
PendingChildWatchReplay(
events = events.filter { it.sessionId == sessionId },
truncated = truncated,
).also { events.clear() }
}
fun close() = synchronized(lock) {
closed = true
events.clear()
}
}
private data class BoundedChildHistory(
val messages: List<MessageItem>,
val truncated: Boolean,
)
/**
* Upstream may emit the interrupted turn's tail and terminal event after
* `session.interrupt` returns. Keep a short exact-session tombstone so that
@@ -495,6 +578,10 @@ class GatewayChatClient(
@Volatile
private var processEventListener: ((GatewayProcessEvent) -> Unit)? = null
/** Process-wide durable-session invalidation/liveness edge. */
@Volatile
private var sessionDirectoryInvalidationListener: (() -> Unit)? = null
/**
* Which upload RPC name this socket understands — set after the first
* successful upload so the legacy fallback is probed at most once per
@@ -509,6 +596,8 @@ class GatewayChatClient(
@Volatile
private var connectCooldownUntil: Long = 0L
private var hasEverReachedReady = false
private var coldStartFailureEpisodes = 0
/**
* When true, the socket is never auto-closed on background — the opt-in
@@ -890,6 +979,10 @@ class GatewayChatClient(
processEventListener = listener
}
fun setSessionDirectoryInvalidationListener(listener: (() -> Unit)?) {
sessionDirectoryInvalidationListener = listener
}
/**
* Establish the socket (and resume an existing session) ahead of the
* user's first send, so a warm turn reaches first token in tens of ms
@@ -906,6 +999,30 @@ class GatewayChatClient(
scope.launch { prewarmAwait(storedSessionId) }
}
/**
* Establish only the shared Gateway socket for read-only observation.
*
* `session.resume` and `session.activate` attach a live runtime to this
* transport. Opening Chat, foreground restoration, and selecting a saved
* transcript must not claim a turn that another Desktop/TUI client owns,
* so those paths use this socket-only warmup and observe through REST
* history plus `session.active_list` instead.
*/
fun observe(onReady: (() -> Unit)? = null) {
scope.launch {
if (observeAwait() && onReady != null) callbackDispatcher(onReady)
}
}
/** Suspending [observe]; returns true once the read-only socket is ready. */
suspend fun observeAwait(): Boolean = try {
connectMutex.withLock { ensureConnected() }
true
} catch (e: Exception) {
Log.d(TAG, "Gateway observation warmup skipped: ${e.message}")
false
}
/**
* Suspending [prewarm]: establishes the socket and (when [storedSessionId]
* is non-null) resumes the existing session, returning only once that work
@@ -947,6 +1064,200 @@ class GatewayChatClient(
return sessionReady
}
/**
* Open the vanilla-upstream child-session watcher advertised by
* `subagent.*.child_session_id`. This RPC deliberately does not mutate
* [liveSessionId], [storedSessionId], or [liveSessionProfile]: the parent
* conversation keeps owning the main mapper while the returned short live
* id routes a second, read-only event stream on the same socket.
*
* Returned history is bounded locally even when an upstream gateway sends
* the child's entire transcript in the resume acknowledgement. The server
* may still enforce its own larger resume safety limit before replying.
*/
suspend fun openChildWatch(
childSessionId: String,
profile: String? = currentSessionProfile(),
callbacks: GatewayTurnCallbacks,
historyLimit: Int = MAX_CHILD_WATCH_HISTORY_ITEMS,
): Result<GatewayChildWatch> = runCatching {
val storedChildId = childSessionId.trim()
require(storedChildId.isNotEmpty()) { "child session id is required" }
val requestedProfile = profile?.trim()?.takeIf(String::isNotEmpty)
connectMutex.withLock {
// Allocate and register under the same mutex as the resume RPC so
// concurrent opens complete in generation order; an older caller
// can never `put` after a newer one for the same live child id.
val generation = childWatchGeneration.incrementAndGet()
val pending = PendingChildWatchOpen()
pendingChildWatchOpens[generation] = pending
try {
ensureConnected()
val result = rpc(
"session.resume",
buildJsonObject {
put("session_id", storedChildId)
put("cols", DEFAULT_COLS)
put("source", sessionSource)
put("lazy", true)
put("close_on_disconnect", true)
requestedProfile?.let { put("profile", it) }
},
).getOrElse { error ->
throw GatewayPreflightException(
"child session resume failed: ${error.message}",
)
}
val liveChildId = result.stringField("session_id")?.takeIf(String::isNotBlank)
?: throw GatewayPreflightException(
"child session resume returned no live session id",
)
try {
requireConfirmedSessionProfile(result, requestedProfile)
} catch (error: GatewayPreflightException) {
// The wrong profile must not leave an unowned lazy watcher behind.
rpc(
"session.close",
buildJsonObject { put("session_id", liveChildId) },
)
throw error
}
val registration = ChildWatchRegistration(
storedSessionId = storedChildId,
liveSessionId = liveChildId,
profile = requestedProfile,
generation = generation,
callbacks = callbacks,
)
val dispatchedCallbacks = dispatchOn(callbacks) {
childWatches[liveChildId] === registration
}
registration.mapper = GatewayEventMapper(
dispatchedCallbacks,
dedupeAdjacentMessageStarts = true,
)
childWatches.put(liveChildId, registration)?.let { prior ->
if (prior.generation != generation) {
notifyChildWatchFailure(
prior,
"Child watch was replaced by a newer view",
)
}
}
// Replay only frames tagged with the exact live id returned by
// this resume. Unknown gateway sessions captured during the
// narrow ack race remain foreign and are discarded.
val replay = pending.closeAndTake(liveChildId)
if (replay.truncated) dispatchedCallbacks.onReconcileRequired()
replay.events.forEach { event ->
if (childWatches[liveChildId] === registration) {
registration.mapper.onEvent(event.type, event.payload)
}
}
val replayedTerminal = replay.events.any {
it.type == "message.complete" || it.type == "error"
}
val history = parseChildWatchMessages(result, historyLimit)
GatewayChildWatch(
storedSessionId = storedChildId,
liveSessionId = liveChildId,
profile = requestedProfile,
generation = generation,
messages = history.messages,
historyTruncated = history.truncated,
running = !replayedTerminal && result.booleanField("running") == true,
status = if (replayedTerminal) "idle" else result.stringField("status"),
)
} finally {
pendingChildWatchOpens.remove(generation, pending)
pending.close()
}
}
}
/**
* Close only the exact lazy watcher represented by [watch]. A stale handle
* is a no-op so it can never close a newer watcher whose live id was reused.
* The parent session and delegated child continue running server-side.
*/
suspend fun closeChildWatch(watch: GatewayChildWatch): Result<Unit> =
connectMutex.withLock {
val registration = childWatches[watch.liveSessionId]
?: return@withLock Result.success(Unit)
if (
registration.generation != watch.generation ||
registration.storedSessionId != watch.storedSessionId ||
registration.profile != watch.profile ||
!childWatches.remove(watch.liveSessionId, registration)
) {
return@withLock Result.success(Unit)
}
if (webSocket == null || readySignal?.isCompleted != true) {
return@withLock Result.success(Unit)
}
val result = rpc(
"session.close",
buildJsonObject { put("session_id", watch.liveSessionId) },
)
result.fold(
onSuccess = { Result.success(Unit) },
onFailure = { error ->
// Permit an exact-handle retry. Opens share connectMutex,
// so no newer registration can race this restoration.
childWatches.putIfAbsent(watch.liveSessionId, registration)
Result.failure(error)
},
)
}
private fun parseChildWatchMessages(
result: JsonObject,
requestedLimit: Int,
): BoundedChildHistory {
val limit = requestedLimit.coerceIn(1, MAX_CHILD_WATCH_HISTORY_ITEMS)
val all = (result["messages"] as? JsonArray).orEmpty()
val raw = all.takeLast(limit)
var retainedChars = 0
var truncated = all.size > raw.size
val newestFirst = raw.asReversed().mapNotNull { element ->
val message = element as? JsonObject ?: run {
truncated = true
return@mapNotNull null
}
// Gateway display history uses `text`; the shared session DTO uses
// `content`. Normalize only that projection boundary.
val normalized = JsonObject(message.toMutableMap().apply {
if (!containsKey("content")) {
put("content", message["text"] ?: message["context"] ?: JsonNull)
}
if (!containsKey("tool_name") && message.containsKey("name")) {
put("tool_name", message["name"] ?: JsonNull)
}
})
val serializedChars = normalized.toString().length
if (serializedChars > MAX_CHILD_WATCH_HISTORY_CHARS - retainedChars) {
truncated = true
return@mapNotNull null
}
val decoded = runCatching {
json.decodeFromJsonElement(MessageItem.serializer(), normalized)
}.onFailure {
Log.w(TAG, "child watch returned an unreadable history row", it)
}.getOrNull()
if (decoded == null) {
truncated = true
null
} else {
retainedChars += serializedChars
decoded
}
}
return BoundedChildHistory(newestFirst.asReversed(), truncated)
}
/**
* Obtain a session-scoped target before a model-selection `config.set`.
*
@@ -2525,6 +2836,7 @@ class GatewayChatClient(
unmatchedTurnCompleteListener = null
backgroundInteractionListener = null
processEventListener = null
sessionDirectoryInvalidationListener = null
closeSocket("client shutdown")
backgroundCloseJob?.cancel()
// Stop the foreground collector — a replaced client must not keep
@@ -2544,21 +2856,73 @@ class GatewayChatClient(
throw GatewayPreflightException("gateway connect cooling down")
}
// Two attempts: a just-died socket (network switch, server restart)
// can poison the first try via a stale pooled connection. Each
// attempt mints a FRESH single-use ticket — never reuse one.
// A just-died pooled socket can poison the first WebSocket upgrade, so
// that narrow transport failure gets one fresh-ticket retry. A ticket
// 5xx and transport failures are transient (notably while the
// Dashboard or Android's active network settles). Auth rejection and
// rate limiting stay single-attempt; a bounded ticket timeout gets one
// fresh attempt instead of leaving cold start permanently disconnected.
var lastFailure = "gateway connect failed"
repeat(CONNECT_ATTEMPTS) { attempt ->
var terminalStage: GatewayConnectFailureStage? = null
var terminalRetryAfterCooldown = false
for (attempt in 0 until CONNECT_ATTEMPTS) {
try {
connectOnce()
connectCooldownUntil = 0L
return
} catch (e: GatewayConnectAttemptException) {
lastFailure = e.message ?: lastFailure
Log.w(TAG, "Gateway connect attempt ${attempt + 1}/$CONNECT_ATTEMPTS failed: $lastFailure")
terminalStage = e.stage
terminalRetryAfterCooldown = e.retryAfterCooldown
Log.w(
TAG,
"Gateway connect attempt ${attempt + 1}/$CONNECT_ATTEMPTS failed " +
"(stage=${e.stage.logName}, retryable=${e.retryable}): $lastFailure",
)
if (!e.retryable) break
}
}
connectCooldownUntil = System.currentTimeMillis() + CONNECT_FAILURE_COOLDOWN_MS
when (terminalStage) {
GatewayConnectFailureStage.TicketAuth,
GatewayConnectFailureStage.UpgradeAuth -> onGatewaySignInRequired()
GatewayConnectFailureStage.Ticket,
GatewayConnectFailureStage.Upgrade -> {
// A timeout is not a definitive availability verdict. Keep
// the Gateway unresolved so the visible-chat owner remains
// on this transport and can retry after the cooldown.
if (!terminalRetryAfterCooldown) onGatewayUnreachable()
}
GatewayConnectFailureStage.Unsupported -> onGatewayUnsupported()
null -> Unit
}
if (terminalRetryAfterCooldown && !hasEverReachedReady) {
coldStartFailureEpisodes += 1
}
val coldStartBudgetExhausted = terminalRetryAfterCooldown &&
!hasEverReachedReady &&
coldStartFailureEpisodes >= COLD_START_FAILURE_EPISODE_LIMIT
if (coldStartBudgetExhausted) onGatewayUnreachable()
_reconnectDisposition.value = if (
terminalRetryAfterCooldown && !coldStartBudgetExhausted
) {
GatewayReconnectDisposition.Retryable
} else {
GatewayReconnectDisposition.Terminal
}
val backoffCeiling = if (hasEverReachedReady) {
CONNECT_FAILURE_COOLDOWN_MS
} else {
(CONNECT_FAILURE_COOLDOWN_MS shl
(coldStartFailureEpisodes - 1).coerceIn(0, 3))
.coerceAtMost(MAX_CONNECT_FAILURE_COOLDOWN_MS)
}
connectCooldownUntil = maxOf(
connectCooldownUntil,
System.currentTimeMillis() + fullJitterDelayMs(
backoffCeiling,
reconnectJitterUnit(),
),
)
_connectionState.value = GatewayConnectionState.Idle
throw GatewayPreflightException(lastFailure)
}
@@ -2570,14 +2934,37 @@ class GatewayChatClient(
_approvalModeCapability.value = GatewayApprovalModeCapability.Unknown
_connectionState.value = GatewayConnectionState.MintingTicket
val ticket = dashboardClient.requestWsTicket().getOrElse { e ->
throw GatewayConnectAttemptException("ws-ticket mint failed: ${e.message}")
val statusCode = (e as? DashboardHttpException)?.statusCode
val authFailure = statusCode in setOf(401, 403)
val rateLimited = statusCode == 429
if (rateLimited) {
connectCooldownUntil = System.currentTimeMillis() + RATE_LIMIT_COOLDOWN_MS
}
val transportFailure = e is java.io.IOException && e !is javax.net.ssl.SSLException
throw GatewayConnectAttemptException(
message = "ws-ticket mint failed: ${e.message}",
stage = if (authFailure) {
GatewayConnectFailureStage.TicketAuth
} else {
GatewayConnectFailureStage.Ticket
},
retryable = !authFailure && !rateLimited &&
(statusCode in 500..599 || (statusCode == null && transportFailure)),
retryAfterCooldown = rateLimited ||
(!authFailure && (statusCode in 500..599 ||
(statusCode == null && transportFailure))),
)
}
val ticketMs = (System.nanoTime() - connectStart) / 1_000_000
val url = dashboardClient.gatewayWebSocketUrl(
ticket = ticket.ticket,
profile = currentSessionProfile(),
)
?: throw GatewayConnectAttemptException("could not build /api/ws URL")
?: throw GatewayConnectAttemptException(
"could not build /api/ws URL",
GatewayConnectFailureStage.Unsupported,
retryable = false,
)
_connectionState.value = GatewayConnectionState.Connecting
val ready = CompletableDeferred<Unit>()
@@ -2589,19 +2976,38 @@ class GatewayChatClient(
webSocket = socket
_connectionState.value = GatewayConnectionState.AwaitingReady
val readyOk = withTimeoutOrNull(CONNECT_TIMEOUT_MS) {
runCatching { ready.await() }.isSuccess
} ?: false
if (!readyOk) {
val readyResult: Result<Unit>? = withTimeoutOrNull(CONNECT_TIMEOUT_MS) {
runCatching { ready.await() }
}
val readyFailure = readyResult?.exceptionOrNull()
?: if (readyResult == null) {
GatewayConnectAttemptException(
"gateway.ready never arrived",
GatewayConnectFailureStage.Upgrade,
retryable = true,
)
} else {
null
}
if (readyFailure != null) {
socket.cancel()
webSocket = null
throw GatewayConnectAttemptException("gateway.ready never arrived")
throw (readyFailure as? GatewayConnectAttemptException
?: GatewayConnectAttemptException(
"gateway connection failed: ${readyFailure.message}",
GatewayConnectFailureStage.Upgrade,
retryable = true,
))
}
// Split the cold-connect cost so a slow ticket mint (HTTP) is told
// apart from a slow WS upgrade + gateway.ready (socket/TLS) on device.
val wsMs = (System.nanoTime() - connectStart) / 1_000_000 - ticketMs
Log.i(TAG, "Gateway connected (/api/ws ready) — ticket=${ticketMs}ms ws=${wsMs}ms")
hasEverReachedReady = true
coldStartFailureEpisodes = 0
_reconnectDisposition.value = GatewayReconnectDisposition.None
_connectionState.value = GatewayConnectionState.Ready
onGatewayReady()
}
/**
@@ -2629,6 +3035,14 @@ class GatewayChatClient(
put("session_id", storedId)
put("cols", DEFAULT_COLS)
put("source", sessionSource)
// Android already hydrates the visible transcript through the
// profile-scoped Dashboard REST owner. Match official Desktop's
// bounded resume contract: register the live runtime now and let
// Gateway hydrate model history off the RPC response path instead
// of synchronously reading and returning the same transcript.
// Older Gateways ignore these additive parameters.
put("defer_history", true)
put("omit_messages", true)
requestedProfile?.let { put("profile", it) }
},
)
@@ -2941,29 +3355,112 @@ class GatewayChatClient(
// the connection as gone immediately: the server is going away.
webSocket.close(code, null)
if (this@GatewayChatClient.webSocket === webSocket) {
onSocketDown("closing: $code $reason")
val wasReady = _connectionState.value == GatewayConnectionState.Ready
val closeFailure = if (!wasReady) preReadyCloseFailure(code, reason) else null
if (!ready.isCompleted) {
ready.completeExceptionally(closeFailure!!)
}
if (wasReady && code == 4401) onGatewaySignInRequired()
if (wasReady && code == 4403) onGatewayUnreachable()
onSocketDown(
"closing: $code $reason",
disposition = when {
wasReady && code !in setOf(4401, 4403) ->
GatewayReconnectDisposition.Retryable
closeFailure?.retryAfterCooldown == true ->
GatewayReconnectDisposition.Retryable
else -> GatewayReconnectDisposition.Terminal
},
)
}
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (this@GatewayChatClient.webSocket === webSocket) {
onSocketDown("closed: $code $reason")
val wasReady = _connectionState.value == GatewayConnectionState.Ready
val closeFailure = if (!wasReady) preReadyCloseFailure(code, reason) else null
if (!ready.isCompleted) {
ready.completeExceptionally(closeFailure!!)
}
if (wasReady && code == 4401) onGatewaySignInRequired()
if (wasReady && code == 4403) onGatewayUnreachable()
onSocketDown(
"closed: $code $reason",
disposition = when {
wasReady && code !in setOf(4401, 4403) ->
GatewayReconnectDisposition.Retryable
closeFailure?.retryAfterCooldown == true ->
GatewayReconnectDisposition.Retryable
else -> GatewayReconnectDisposition.Terminal
},
)
}
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
if (this@GatewayChatClient.webSocket !== webSocket) return
when (response?.code) {
404, 403 -> {
val connectFailure = when (response?.code) {
404 -> {
// No /api/ws on this build (or embedded chat disabled) —
// sticky downgrade so auto-resolution stops picking gateway.
Log.w(TAG, "Gateway WS upgrade rejected (${response.code}) — marking unsupported")
onGatewayUnsupported()
GatewayConnectAttemptException(
"gateway websocket is unsupported",
GatewayConnectFailureStage.Unsupported,
retryable = false,
)
}
429 -> connectCooldownUntil = System.currentTimeMillis() + RATE_LIMIT_COOLDOWN_MS
401, 403 -> GatewayConnectAttemptException(
"gateway websocket authentication was rejected",
GatewayConnectFailureStage.UpgradeAuth,
retryable = false,
)
429 -> {
connectCooldownUntil = System.currentTimeMillis() + RATE_LIMIT_COOLDOWN_MS
GatewayConnectAttemptException(
"gateway websocket rate limited",
GatewayConnectFailureStage.Upgrade,
retryable = false,
retryAfterCooldown = true,
)
}
else -> GatewayConnectAttemptException(
"gateway websocket upgrade failed: ${t.message}",
GatewayConnectFailureStage.Upgrade,
retryable = true,
)
}
if (!ready.isCompleted) ready.completeExceptionally(t)
onSocketDown("failure: ${t.message}")
if (!ready.isCompleted) ready.completeExceptionally(connectFailure)
onSocketDown(
"failure: ${t.message}",
disposition = if (connectFailure.retryAfterCooldown) {
GatewayReconnectDisposition.Retryable
} else {
GatewayReconnectDisposition.Terminal
},
)
}
}
private fun preReadyCloseFailure(code: Int, reason: String): GatewayConnectAttemptException {
val safeReason = reason.take(160).ifBlank { "closed before gateway.ready" }
return when (code) {
4401 -> GatewayConnectAttemptException(
"gateway authentication was rejected ($safeReason)",
GatewayConnectFailureStage.UpgradeAuth,
retryable = false,
)
4403 -> GatewayConnectAttemptException(
"gateway origin or access guard rejected the connection ($safeReason)",
GatewayConnectFailureStage.Upgrade,
retryable = false,
)
else -> GatewayConnectAttemptException(
"gateway closed before ready (code=$code, $safeReason)",
GatewayConnectFailureStage.Upgrade,
retryable = code in setOf(1001, 1011, 1012, 1013),
)
}
}
@@ -3013,6 +3510,11 @@ class GatewayChatClient(
return
}
if (type == "sessions.changed") {
callbackDispatcher { sessionDirectoryInvalidationListener?.invoke() }
return
}
// Upstream emits session.reclaimed process-wide, so it is identified
// by payload rather than params.session_id. Retire only an exact live
// runtime we own; preserve the durable id so the next send resumes it.
@@ -3022,6 +3524,9 @@ class GatewayChatClient(
val reason = payload?.stringField("reason")
val supportedReason = reason in setOf("idle_timeout", "lru_evict", "ws_orphan_reap")
if (!reclaimedLiveId.isNullOrBlank() && supportedReason) {
childWatches.remove(reclaimedLiveId)?.let { registration ->
notifyChildWatchFailure(registration, "Gateway reclaimed the child watch")
}
val background = backgroundTurns.remove(reclaimedLiveId)
if (background != null) {
callbackDispatcher {
@@ -3073,6 +3578,23 @@ class GatewayChatClient(
return
}
// A lazy child watcher is a second session on this shared socket. Route
// it before the main-session recovery/foreign-session gates and require
// the exact live id returned by its own session.resume acknowledgement.
val childWatch = eventSessionId?.let(childWatches::get)
if (childWatch != null) {
if (childWatches[eventSessionId] === childWatch) {
childWatch.mapper.onEvent(type, payload)
}
return
}
val capturedForPendingChildWatch = !eventSessionId.isNullOrBlank() &&
eventSessionId != liveSessionId &&
!backgroundTurns.containsKey(eventSessionId) &&
capturePendingChildWatchEvent(ChildWatchEvent(eventSessionId, type, payload))
if (capturedForPendingChildWatch) return
// A cold session.resume may schedule auto-continue before its RPC
// response reaches Android. The recovery buffer is an ownership gate,
// not an observational copy: an event is either claimed here for
@@ -3296,7 +3818,10 @@ class GatewayChatClient(
callbackDispatcher { processEventListener?.invoke(event) }
}
private fun onSocketDown(reason: String) {
private fun onSocketDown(
reason: String,
disposition: GatewayReconnectDisposition = GatewayReconnectDisposition.Retryable,
) {
Log.i(TAG, "Gateway socket down ($reason)")
// Capture the in-flight session id BEFORE clearing it — the mid-turn
// rejoin restores it so the running turn's tail (still tagged with this
@@ -3310,11 +3835,13 @@ class GatewayChatClient(
_processCapability.value = GatewayProcessCapability.Unknown
_activeSessionCapability.value = GatewayActiveSessionCapability.Unknown
_approvalModeCapability.value = GatewayApprovalModeCapability.Unknown
_reconnectDisposition.value = disposition
_connectionState.value = GatewayConnectionState.Idle
pendingRpcs.values.forEach {
it.completeExceptionally(GatewayRpcException("gateway connection lost"))
}
pendingRpcs.clear()
failChildWatches("Child watch disconnected from the gateway")
val turn = activeTurn
if (turn == null) {
if (backgroundTurns.isNotEmpty() && !backgroundRejoinInProgress) {
@@ -3496,7 +4023,9 @@ class GatewayChatClient(
_processCapability.value = GatewayProcessCapability.Unknown
_activeSessionCapability.value = GatewayActiveSessionCapability.Unknown
_approvalModeCapability.value = GatewayApprovalModeCapability.Unknown
_reconnectDisposition.value = GatewayReconnectDisposition.None
_connectionState.value = GatewayConnectionState.Idle
failChildWatches("Child watch closed with the gateway socket")
}
private fun scheduleBackgroundClose() {
@@ -3506,7 +4035,7 @@ class GatewayChatClient(
backgroundCloseJob?.cancel()
backgroundCloseJob = scope.launch {
delay(BACKGROUND_CLOSE_GRACE_MS)
if (activeTurn == null && backgroundTurns.isEmpty() &&
if (activeTurn == null && backgroundTurns.isEmpty() && childWatches.isEmpty() &&
!AppForegroundTracker.isForeground.value
) {
closeSocket("app backgrounded")
@@ -3514,6 +4043,28 @@ class GatewayChatClient(
}
}
private fun failChildWatches(message: String) {
if (childWatches.isEmpty()) return
val registrations = childWatches.values.toSet()
childWatches.clear()
registrations.forEach { notifyChildWatchFailure(it, message) }
}
private fun notifyChildWatchFailure(
registration: ChildWatchRegistration,
message: String,
) {
callbackDispatcher { registration.callbacks.onResumeFailure(message) }
}
private fun capturePendingChildWatchEvent(event: ChildWatchEvent): Boolean {
var captured = false
pendingChildWatchOpens.values.forEach { pending ->
if (pending.capture(event)) captured = true
}
return captured
}
// ------------------------------------------------------------------
// JSON-RPC
// ------------------------------------------------------------------
@@ -4062,44 +4613,55 @@ class GatewayChatClient(
}
/** Wrap callbacks so every invocation lands on the callback dispatcher (main thread). */
private fun dispatchOn(callbacks: GatewayTurnCallbacks) = GatewayTurnCallbacks(
onSessionId = { v -> callbackDispatcher { callbacks.onSessionId(v) } },
onStart = { callbackDispatcher { callbacks.onStart() } },
onTextDelta = { v -> callbackDispatcher { callbacks.onTextDelta(v) } },
private fun dispatchOn(
callbacks: GatewayTurnCallbacks,
stillCurrent: () -> Boolean = { true },
) = GatewayTurnCallbacks(
onSessionId = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onSessionId(v) } },
onStart = { dispatchIfCurrent(stillCurrent) { callbacks.onStart() } },
onTextDelta = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onTextDelta(v) } },
onInterimMessage = { text, alreadyStreamed ->
callbackDispatcher { callbacks.onInterimMessage(text, alreadyStreamed) }
dispatchIfCurrent(stillCurrent) { callbacks.onInterimMessage(text, alreadyStreamed) }
},
onInterimReconciled = { text ->
callbackDispatcher { callbacks.onInterimReconciled(text) }
dispatchIfCurrent(stillCurrent) { callbacks.onInterimReconciled(text) }
},
onThinkingDelta = { v -> callbackDispatcher { callbacks.onThinkingDelta(v) } },
onThinkingDelta = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onThinkingDelta(v) } },
onToolCallStart = { id, name, args ->
callbackDispatcher { callbacks.onToolCallStart(id, name, args) }
dispatchIfCurrent(stillCurrent) { callbacks.onToolCallStart(id, name, args) }
},
onToolCallDone = { a, b -> callbackDispatcher { callbacks.onToolCallDone(a, b) } },
onToolCallFailed = { a, b -> callbackDispatcher { callbacks.onToolCallFailed(a, b) } },
onToolOutputRisk = { v -> callbackDispatcher { callbacks.onToolOutputRisk(v) } },
onTurnComplete = { callbackDispatcher { callbacks.onTurnComplete() } },
onReconcileRequired = { callbackDispatcher { callbacks.onReconcileRequired() } },
onComplete = { callbackDispatcher { callbacks.onComplete() } },
onUsage = { v -> callbackDispatcher { callbacks.onUsage(v) } },
onError = { v -> callbackDispatcher { callbacks.onError(v) } },
onToolGenerating = { v -> callbackDispatcher { callbacks.onToolGenerating(v) } },
onSubagentEvent = { v -> callbackDispatcher { callbacks.onSubagentEvent(v) } },
onMoaReference = { v -> callbackDispatcher { callbacks.onMoaReference(v) } },
onInteractionRequest = { v -> callbackDispatcher { callbacks.onInteractionRequest(v) } },
onInteractionExpired = { v -> callbackDispatcher { callbacks.onInteractionExpired(v) } },
onResumeFailure = { v -> callbackDispatcher { callbacks.onResumeFailure(v) } },
onFailure = { v -> callbackDispatcher { callbacks.onFailure(v) } },
onToolCallDone = { a, b -> dispatchIfCurrent(stillCurrent) { callbacks.onToolCallDone(a, b) } },
onToolCallFailed = { a, b -> dispatchIfCurrent(stillCurrent) { callbacks.onToolCallFailed(a, b) } },
onToolOutputRisk = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onToolOutputRisk(v) } },
onTurnComplete = { dispatchIfCurrent(stillCurrent) { callbacks.onTurnComplete() } },
onReconcileRequired = { dispatchIfCurrent(stillCurrent) { callbacks.onReconcileRequired() } },
onComplete = { dispatchIfCurrent(stillCurrent) { callbacks.onComplete() } },
onUsage = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onUsage(v) } },
onError = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onError(v) } },
onToolGenerating = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onToolGenerating(v) } },
onSubagentEvent = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onSubagentEvent(v) } },
onMoaReference = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onMoaReference(v) } },
onInteractionRequest = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onInteractionRequest(v) } },
onInteractionExpired = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onInteractionExpired(v) } },
onResumeFailure = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onResumeFailure(v) } },
onFailure = { v -> dispatchIfCurrent(stillCurrent) { callbacks.onFailure(v) } },
// MUST be wrapped like every other member: GatewayTurnCallbacks gives
// onStatusUpdate a default no-op, so omitting it here silently swallows
// EVERY gateway status line — the ❌ terminal-error lifecycle update
// included. Without it markError never fires, the turn isn't badged
// "Error", and onComplete's history reload wipes the error bubble (the
// "reply appears then vanishes" bug).
onStatusUpdate = { kind, text -> callbackDispatcher { callbacks.onStatusUpdate(kind, text) } },
onStatusClear = { kind -> callbackDispatcher { callbacks.onStatusClear(kind) } },
onStatusUpdate = { kind, text ->
dispatchIfCurrent(stillCurrent) { callbacks.onStatusUpdate(kind, text) }
},
onStatusClear = { kind -> dispatchIfCurrent(stillCurrent) { callbacks.onStatusClear(kind) } },
)
private fun dispatchIfCurrent(stillCurrent: () -> Boolean, callback: () -> Unit) {
callbackDispatcher {
if (stillCurrent()) callback()
}
}
}
internal fun parseGatewayPersonalityOptions(result: JsonObject): List<String> =
@@ -4151,8 +4713,21 @@ internal class GatewayPreflightException(message: String) : Exception(message)
/** Attachment bytes were not safely bound to a Gateway turn; never silently fall through to SSE. */
internal class GatewayAttachmentPreflightException(message: String) : Exception(message)
/** One connect attempt failed; [GatewayChatClient] may retry with a fresh ticket. */
internal class GatewayConnectAttemptException(message: String) : Exception(message)
/** One connect attempt failed; only a transient WebSocket upgrade may retry immediately. */
internal class GatewayConnectAttemptException(
message: String,
val stage: GatewayConnectFailureStage,
val retryable: Boolean,
val retryAfterCooldown: Boolean = retryable,
) : Exception(message)
internal enum class GatewayConnectFailureStage(val logName: String) {
TicketAuth("ticket_auth"),
Ticket("ticket"),
UpgradeAuth("upgrade_auth"),
Upgrade("upgrade"),
Unsupported("unsupported"),
}
/** Server intentionally refused a durable resume; never create/fallback into a context-free turn. */
internal class GatewayAuthoritativeResumeException(message: String) : Exception(message)
@@ -281,11 +281,12 @@ class GatewayEventMapper(
callbacks.onError(payload.string("message") ?: "Gateway error")
}
"subagent.start", "subagent.thinking", "subagent.tool",
"subagent.spawn_requested", "subagent.start", "subagent.thinking", "subagent.tool",
"subagent.progress", "subagent.complete",
-> {
clearActivityStatuses()
val phase = when (type) {
"subagent.spawn_requested" -> GatewaySubagentEvent.Phase.SPAWN_REQUESTED
"subagent.start" -> GatewaySubagentEvent.Phase.START
"subagent.thinking" -> GatewaySubagentEvent.Phase.THINKING
"subagent.tool" -> GatewaySubagentEvent.Phase.TOOL
@@ -306,6 +307,10 @@ class GatewayEventMapper(
preview = payload.string("tool_preview") ?: payload.string("text"),
durationSeconds = payload.double("duration_seconds"),
subagentId = payload.string("subagent_id"),
childSessionId = payload.string("child_session_id"),
parentId = payload.string("parent_id"),
depth = payload.int("depth"),
model = payload.string("model"),
),
)
}
@@ -1,5 +1,6 @@
package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.UsageInfo
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonObject
@@ -28,7 +29,7 @@ enum class GatewayAvailability {
/** No probe has completed yet (startup, connection switch). */
Unknown,
/** Dashboard reachable and authenticated (or auth not required). */
/** The `/api/ws` socket completed `gateway.ready` for the active route. */
Ready,
/** Dashboard reachable and gated, but no signed-in session — Manage sign-in unlocks it. */
@@ -55,6 +56,13 @@ enum class GatewayConnectionState {
Ready,
}
/** Whether an idle Gateway may be retried automatically by a visible Chat surface. */
enum class GatewayReconnectDisposition {
None,
Retryable,
Terminal,
}
/** Profile-persisted approval policy introduced by upstream gateway contract v3. */
enum class GatewayApprovalMode(val wireValue: String) {
Manual("manual"),
@@ -257,7 +265,8 @@ data class GatewayToolOutputRisk(
/**
* One `subagent.*` lifecycle event, emitted on the PARENT session. Lifecycle
* per task: START → (THINKING | TOOL | PROGRESS)* → COMPLETE. Field
* per task: SPAWN_REQUESTED → START → (THINKING | TOOL | PROGRESS)* →
* COMPLETE. Field
* availability varies by phase — [toolName]/[preview] ride TOOL,
* [status]/[summary]/[durationSeconds] ride COMPLETE — and older emitters
* omit everything beyond the three defaults-bearing fields.
@@ -273,10 +282,36 @@ data class GatewaySubagentEvent(
val preview: String? = null,
val durationSeconds: Double? = null,
val subagentId: String? = null,
/** Durable child session id accepted by `session.resume {lazy:true}`. */
val childSessionId: String? = null,
/** Owning subagent id for nested delegation; null for first-level children. */
val parentId: String? = null,
/** Zero-based depth used by the upstream spawn-tree renderer. */
val depth: Int? = null,
/** Effective child model, when the emitter exposes it. */
val model: String? = null,
) {
enum class Phase { START, THINKING, TOOL, PROGRESS, COMPLETE }
enum class Phase { SPAWN_REQUESTED, START, THINKING, TOOL, PROGRESS, COMPLETE }
}
/**
* One profile-pinned, read-only child-session watch opened through the vanilla
* upstream Gateway. [storedSessionId] is the durable child id from
* `subagent.*`; [liveSessionId] is the short runtime id that tags subsequent
* mirror events on this socket. The bounded [messages] snapshot is child-only.
*/
data class GatewayChildWatch(
val storedSessionId: String,
val liveSessionId: String,
val profile: String?,
val generation: Long,
val messages: List<MessageItem>,
/** True when Android retained only a bounded recent tail of the response. */
val historyTruncated: Boolean,
val running: Boolean,
val status: String?,
)
/**
* One session-owned background process returned by the upstream gateway's
* `process.list` RPC. The registry calls its process id `session_id`; Android
@@ -1,5 +1,7 @@
package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.data.normalizeCredentialFreeAuthenticatedDashboardOrigin
import android.content.Context
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.SecureStoreCache
@@ -101,6 +103,7 @@ class NativeDashboardAuthorization internal constructor(
internal val verifier: String,
internal val state: String,
internal val generation: Long,
internal val usesAlternateOrigin: Boolean,
)
class NativeDashboardAuthClient(
@@ -144,14 +147,9 @@ class NativeDashboardAuthClient(
.addQueryParameter("code_challenge_method", "S256")
.addQueryParameter("redirect_uri", redirectUri)
.addQueryParameter("state", state)
// Match the official Desktop client for Nous-hosted gateways: the
// gateway selects its single native-eligible provider. The provider
// name advertised to UI clients is presentation/configuration data,
// not a stable native-broker identifier. Other providers retain the
// explicit selector for direct client use and tests.
.apply {
provider
?.takeIf { it.isNotBlank() && !it.equals("nous", ignoreCase = true) }
?.takeIf { it.isNotBlank() }
?.let { addQueryParameter("provider", it) }
}
.build()
@@ -159,29 +157,29 @@ class NativeDashboardAuthClient(
val generation = NativeTokenRefreshCoordinator.beginAuthorization(
tokenStore.coordinationKey,
)
return NativeDashboardAuthorization(url, verifier, state, generation)
return NativeDashboardAuthorization(
authorizationUrl = url,
verifier = verifier,
state = state,
generation = generation,
usesAlternateOrigin = !sameDashboardBase(authorizationBaseUrl, baseUrl),
)
}
/**
* A private-route dashboard may be configured with a canonical HTTPS
* callback origin for its provider. Starting the browser on the private
* origin would scope Hermes' temporary PKCE cookie to the wrong host, so
* discover the provider's declared callback and start native auth there.
* Token exchange still uses [baseUrl], keeping the resulting bearer bound
* to the active connection route.
* Discover the callback-owning Dashboard origin for every interactive
* redirect provider. Provider names do not imply topology; upstream may
* advertise a canonical origin that differs from a LAN/Tailscale entry.
* Token exchange still uses [baseUrl], keeping the bearer scoped to this
* connection while the shared gateway process consumes its one-time code.
*/
private fun resolveAuthorizationBaseUrl(provider: String?): String {
val configured = baseUrl.toHttpUrlOrNull() ?: return baseUrl
if (
!provider.equals("nous", ignoreCase = true) ||
configured.scheme != "http" ||
!isPrivateNetworkLiteral(configured.host)
) {
return baseUrl
}
val selectedProvider = provider?.takeIf { it.isNotBlank() } ?: return baseUrl
if (isLoopbackDashboardHost(configured.host)) return baseUrl
val loginUrl = configured.newBuilder()
.addPathSegments("auth/login")
.addQueryParameter("provider", provider)
.addQueryParameter("provider", selectedProvider)
.addQueryParameter("next", "/")
.build()
val discoveryClient = client.newBuilder()
@@ -193,14 +191,14 @@ class NativeDashboardAuthClient(
).execute().use { response ->
if (response.code !in 300..399) null else response.header("Location")
}
return canonicalDashboardBaseFromNousRedirect(location)
?: throw IOException("Dashboard did not advertise a secure Nous callback origin")
return canonicalDashboardBaseFromProviderRedirect(baseUrl, location)
}
fun exchangeCallback(
authorization: NativeDashboardAuthorization,
callbackTarget: String,
commitAllowed: () -> Boolean = { true },
onValidated: () -> Unit = {},
): NativeDashboardTokens {
val callback = callbackTarget.toHttpUrlOrNull()
?: "http://127.0.0.1$callbackTarget".toHttpUrlOrNull()
@@ -224,6 +222,7 @@ class NativeDashboardAuthClient(
?: throw NativeDashboardCallbackException(
"Native sign-in callback did not include an authorization code",
)
runCatching(onValidated)
val payload = NativeTokenExchange(code = code, codeVerifier = authorization.verifier)
return postTokens(
path = "/auth/native/token",
@@ -322,6 +321,10 @@ class NativeDashboardAuthClient(
throw NativeDashboardInactiveAuthorizationException()
}
tokenStore.save(tokens)
NativeTokenRefreshCoordinator.markBootstrapApproved(
tokenStore.coordinationKey,
tokens.accessToken,
)
}
return tokens
}
@@ -412,6 +415,63 @@ private fun isPrivateNetworkLiteral(host: String): Boolean {
(first == 100 && second in 64..127)
}
private fun isLoopbackDashboardHost(host: String): Boolean =
host.equals("localhost", ignoreCase = true) ||
host == "127.0.0.1" ||
host == "::1"
/**
* Extract a callback-owning Dashboard base from an auth-provider redirect.
* Different HTTPS origins are accepted after an HTTPS provider hop. HTTP is
* retained for upstream-supported local/overlay callbacks only when both the
* selected and callback hosts are private literals/loopback and no HTTPS-to-
* HTTP downgrade occurs. Arbitrary public cleartext origins are rejected.
*/
internal fun canonicalDashboardBaseFromProviderRedirect(
configuredBase: String,
location: String?,
): String {
val configured = configuredBase.trim().trimEnd('/').toHttpUrlOrNull()
?: return configuredBase
val fallback = configured.toString().trimEnd('/')
val providerUrl = location?.toHttpUrlOrNull() ?: return fallback
val callback = providerUrl.queryParameter("redirect_uri")
?.toHttpUrlOrNull()
?: return fallback
if (
providerUrl.username.isNotEmpty() || providerUrl.password.isNotEmpty() ||
callback.username.isNotEmpty() || callback.password.isNotEmpty() ||
callback.query != null || callback.fragment != null
) {
return fallback
}
val callbackSuffix = "/auth/callback"
if (!callback.encodedPath.endsWith(callbackSuffix)) return fallback
val callbackBase = callback.newBuilder()
.encodedPath(callback.encodedPath.removeSuffix(callbackSuffix).ifBlank { "/" })
.query(null)
.fragment(null)
.build()
if (
configured.scheme == callbackBase.scheme &&
configured.host.equals(callbackBase.host, ignoreCase = true) &&
configured.port == callbackBase.port &&
configured.encodedPath.trimEnd('/') == callbackBase.encodedPath.trimEnd('/')
) {
return fallback
}
if (providerUrl.scheme != "https") return fallback
val trustedDifferentOrigin = callbackBase.scheme == "https" || (
configured.scheme == "http" &&
callbackBase.scheme == "http" &&
normalizeCredentialFreeAuthenticatedDashboardOrigin(fallback) != null &&
normalizeCredentialFreeAuthenticatedDashboardOrigin(
callbackBase.toString().trimEnd('/'),
) != null
)
return if (trustedDifferentOrigin) callbackBase.toString().trimEnd('/') else fallback
}
internal fun canonicalDashboardBaseFromNousRedirect(location: String?): String? {
val providerUrl = location?.toHttpUrlOrNull() ?: return null
if (
@@ -420,28 +480,20 @@ internal fun canonicalDashboardBaseFromNousRedirect(location: String?): String?
) {
return null
}
val callback = providerUrl.queryParameter("redirect_uri")
?.toHttpUrlOrNull()
?: return null
if (callback.scheme != "https") return null
val callbackSuffix = "/auth/callback"
if (!callback.encodedPath.endsWith(callbackSuffix)) return null
val basePath = callback.encodedPath
.removeSuffix(callbackSuffix)
.ifBlank { "/" }
return callback.newBuilder()
.encodedPath(basePath)
.query(null)
.fragment(null)
.build()
.toString()
.trimEnd('/')
val resolved = canonicalDashboardBaseFromProviderRedirect(
configuredBase = "http://192.168.0.1:9119",
location = location,
)
return resolved.takeUnless { it == "http://192.168.0.1:9119" }
}
/**
* Adds the native bearer to dashboard REST calls and rotates it before expiry
* or after one 401. Refresh requests use a separate bare client, so neither a
* stale bearer nor the authenticator can recurse into token rotation.
* or after one 401. Ticket mint also gets one bounded refresh on 503 because a
* multi-provider Dashboard can report an expired token as provider-unreachable
* before the owning provider gets to reject it. Refresh requests use a separate
* bare client, so neither a stale bearer nor the authenticator can recurse into
* token rotation.
*/
class DashboardBearerAuth(
baseUrl: String,
@@ -449,20 +501,90 @@ class DashboardBearerAuth(
private val clockSeconds: () -> Long = { System.currentTimeMillis() / 1000L },
) : Interceptor, Authenticator {
private val authClient = NativeDashboardAuthClient(baseUrl, tokenStore)
@Volatile
private var cookieAuthAvailable: ((okhttp3.HttpUrl) -> Boolean)? = null
@Volatile
private var preferNativeBearerAfterCookieProviderFailure = false
internal fun preferCookiesWhen(predicate: (okhttp3.HttpUrl) -> Boolean) {
cookieAuthAvailable = predicate
}
private fun shouldPreferCookie(url: okhttp3.HttpUrl): Boolean =
!preferNativeBearerAfterCookieProviderFailure &&
runCatching { cookieAuthAvailable?.invoke(url) == true }.getOrDefault(false)
override fun intercept(chain: Interceptor.Chain): Response {
if (shouldPreferCookie(chain.request().url)) {
val cookieResponse = chain.proceed(chain.request())
if (!cookieResponse.isAuthProviderUnavailable()) return cookieResponse
val tokens = usableTokens(forceRefresh = false, failedAccessToken = null)
?: return cookieResponse
val accessToken = normalizeCredentialForHeader(
tokens.accessToken,
"Dashboard credential",
)
cookieResponse.close()
val bearerResponse = chain.proceed(
chain.request().newBuilder()
.bearerAuthorization(accessToken, "Dashboard credential")
.build(),
)
if (bearerResponse.isSuccessful) {
// Preserve the cookie on disk: upstream's 503 intentionally
// avoids logging browsers out during an IdP outage. This exact
// Dashboard client merely stops presenting the stranded cookie
// first after its connection-scoped bearer proves valid.
preferNativeBearerAfterCookieProviderFailure = true
}
return bearerResponse
}
val tokens = usableTokens(forceRefresh = false, failedAccessToken = null)
val request = tokens?.let {
chain.request().newBuilder()
.bearerAuthorization(it.accessToken, "Dashboard credential")
.build()
} ?: chain.request()
return chain.proceed(request)
val response = chain.proceed(request)
if (
response.code != 503 ||
!request.url.encodedPath.endsWith("/api/auth/ws-ticket")
) {
return response
}
val previous = request.header("Authorization") ?: return response
val failedAccessToken = previous.removePrefix("Bearer ").takeIf { it != previous }
?: return response
val refreshed = usableTokens(
forceRefresh = true,
failedAccessToken = failedAccessToken,
) ?: return response
val accessToken = normalizeCredentialForHeader(
refreshed.accessToken,
"Dashboard credential",
)
if (accessToken == failedAccessToken) return response
response.close()
return chain.proceed(
request.newBuilder()
.bearerAuthorization(accessToken, "Dashboard credential")
.build(),
)
}
override fun authenticate(route: Route?, response: Response): Request? {
if (responseCount(response) >= 2) return null
val previous = response.request.header("Authorization") ?: return null
val previous = response.request.header("Authorization")
if (previous == null) {
if (!shouldPreferCookie(response.request.url)) return null
val tokens = usableTokens(
forceRefresh = false,
failedAccessToken = null,
) ?: return null
return response.request.newBuilder()
.bearerAuthorization(tokens.accessToken, "Dashboard credential")
.build()
}
val failedAccessToken = previous.removePrefix("Bearer ").takeIf { it != previous }
val tokens = usableTokens(
forceRefresh = true,
@@ -487,11 +609,39 @@ class DashboardBearerAuth(
if (failedAccessToken != null && current.accessToken != failedAccessToken) {
return@synchronized current
}
val needsNousBootstrap = current.provider.equals("nous", ignoreCase = true) &&
current.refreshToken.isNotBlank() &&
!NativeTokenRefreshCoordinator.isBootstrapApproved(
tokenStore.coordinationKey,
current.accessToken,
)
if (needsNousBootstrap &&
NativeTokenRefreshCoordinator.isBootstrapRejected(
tokenStore.coordinationKey,
current.accessToken,
)
) {
return@synchronized null
}
val nearExpiry = current.expiresAt <= 0L || clockSeconds() >= current.expiresAt - 60L
if (!forceRefresh && !nearExpiry) return@synchronized current
runCatching { authClient.refresh(current) }.getOrNull()
if (!forceRefresh && !nearExpiry && !needsNousBootstrap) return@synchronized current
val refreshed = runCatching { authClient.refresh(current) }.getOrNull()
if (refreshed == null && needsNousBootstrap) {
NativeTokenRefreshCoordinator.markBootstrapRejected(
tokenStore.coordinationKey,
current.accessToken,
)
}
refreshed
}
private fun Response.isAuthProviderUnavailable(): Boolean {
if (code != 503) return false
val detail = runCatching { peekBody(1_024L).string() }.getOrDefault("")
return detail.contains("Auth provider", ignoreCase = true) &&
detail.contains("unreachable", ignoreCase = true)
}
private fun responseCount(response: Response): Int {
var count = 1
var prior = response.priorResponse
@@ -564,6 +714,8 @@ private inline fun <reified T : Throwable> Throwable.firstCauseOfType(): T? {
private object NativeTokenRefreshCoordinator {
private val locks = ConcurrentHashMap<String, Any>()
private val generations = ConcurrentHashMap<String, Long>()
private val bootstrapApproved = ConcurrentHashMap<String, String>()
private val bootstrapRejected = ConcurrentHashMap<String, String>()
fun lockFor(key: String): Any = locks.computeIfAbsent(key) { Any() }
@@ -583,10 +735,28 @@ private object NativeTokenRefreshCoordinator {
}
}
fun isBootstrapApproved(key: String, accessToken: String): Boolean =
bootstrapApproved[key] == accessToken
fun isBootstrapRejected(key: String, accessToken: String): Boolean =
bootstrapRejected[key] == accessToken
fun markBootstrapApproved(key: String, accessToken: String) {
bootstrapApproved[key] = accessToken
bootstrapRejected.remove(key)
}
fun markBootstrapRejected(key: String, accessToken: String) {
bootstrapRejected[key] = accessToken
bootstrapApproved.remove(key)
}
fun clear(store: NativeDashboardTokenStore) {
synchronized(lockFor(store.coordinationKey)) {
generations[store.coordinationKey] =
(generations[store.coordinationKey] ?: 0L) + 1L
bootstrapApproved.remove(store.coordinationKey)
bootstrapRejected.remove(store.coordinationKey)
store.clear()
}
}
@@ -3,6 +3,7 @@ package com.hermesandroid.relay.network.upstream
import com.hermesandroid.relay.BuildConfig
import java.io.IOException
import java.io.InputStream
import java.io.InterruptedIOException
import java.net.InetAddress
import java.net.InetSocketAddress
import java.net.ServerSocket
@@ -25,6 +26,9 @@ private const val ACCEPT_POLL_MILLIS = 500
internal const val DEFAULT_NATIVE_SIGN_IN_TIMEOUT_MILLIS = 5 * 60 * 1000L
internal val NATIVE_SIGN_IN_RETURN_URI = "${BuildConfig.APPLICATION_ID}://return"
internal class NativeDashboardSignInTimeoutException :
InterruptedIOException("Dashboard sign-in timed out")
private enum class CallbackPage(
val modifier: String,
val eyebrow: String,
@@ -109,23 +113,24 @@ internal fun dashboardRedirectAuthMode(authFlows: List<String>): DashboardRedire
DashboardRedirectAuthMode.WebView
}
/**
* Nous Portal uses Cloudflare Turnstile and does not support embedded Android
* WebViews. Keep self-hosted OIDC on the dashboard cookie flow, but use the
* gateway's brokered system-browser flow for Nous when it is advertised.
*/
/** Match upstream Desktop's capability-driven redirect policy. */
internal fun androidDashboardRedirectAuthMode(
providerName: String,
@Suppress("UNUSED_PARAMETER") providerName: String,
authFlows: List<String>,
): DashboardRedirectAuthMode =
if (
providerName.equals("nous", ignoreCase = true) &&
dashboardRedirectAuthMode(authFlows) == DashboardRedirectAuthMode.NativePkce
) {
DashboardRedirectAuthMode.NativePkce
} else {
DashboardRedirectAuthMode.WebView
}
@Suppress("UNUSED_PARAMETER") competingRedirectProviders: Int = 1,
): DashboardRedirectAuthMode = dashboardRedirectAuthMode(authFlows)
/**
* Hosted gateways commonly expose Nous as their single native provider and
* require the selector to be omitted. Multi-provider self-hosted gateways need
* the explicit selector so upstream can disambiguate the requested provider.
*/
internal fun nativeDashboardAuthorizationProvider(
providerName: String,
competingRedirectProviders: Int,
): String? = providerName.takeUnless {
it.equals("nous", ignoreCase = true) && competingRedirectProviders <= 1
}
/**
* Owns one native dashboard sign-in attempt.
@@ -141,6 +146,8 @@ class NativeDashboardSignInCoordinator(
) {
suspend fun signIn(
provider: String?,
onAuthorizationPrepared: (usesAlternateOrigin: Boolean) -> Unit = {},
onCallbackValidated: () -> Unit = {},
launchAuthorization: suspend (String) -> Unit,
): NativeDashboardTokens =
try {
@@ -165,11 +172,15 @@ class NativeDashboardSignInCoordinator(
val attemptContext = currentCoroutineContext()
var completed = false
try {
runCatching {
onAuthorizationPrepared(authorization.usesAlternateOrigin)
}
launchAuthorization(authorization.authorizationUrl)
awaitValidCallback(
server = server,
authorization = authorization,
commitAllowed = { attemptContext.isActive },
onCallbackValidated = onCallbackValidated,
).also { completed = true }
} finally {
if (!completed) {
@@ -180,13 +191,14 @@ class NativeDashboardSignInCoordinator(
}
}
} catch (_: TimeoutCancellationException) {
throw IOException("Dashboard sign-in timed out")
throw NativeDashboardSignInTimeoutException()
}
private suspend fun awaitValidCallback(
server: ServerSocket,
authorization: NativeDashboardAuthorization,
commitAllowed: () -> Boolean,
onCallbackValidated: () -> Unit,
): NativeDashboardTokens {
while (true) {
val callback = acceptCallback(server)
@@ -217,6 +229,7 @@ class NativeDashboardSignInCoordinator(
authorization,
target,
commitAllowed = commitAllowed,
onValidated = onCallbackValidated,
).also {
writeResponse(
socket,
@@ -74,13 +74,13 @@ object ProactiveMessageNotifier {
text: String,
messageId: String?,
chatId: String?,
) {
): Int? {
ensureChannel(context)
if (!hasPostNotificationsPermission(context)) {
Log.i(TAG, "POST_NOTIFICATIONS not granted — skipping proactive notification")
return
return null
}
if (text.isBlank()) return
if (text.isBlank()) return null
val tapIntent = Intent(context, MainActivity::class.java).apply {
flags = Intent.FLAG_ACTIVITY_NEW_TASK or Intent.FLAG_ACTIVITY_CLEAR_TOP
@@ -89,7 +89,7 @@ object ProactiveMessageNotifier {
val pendingFlags = PendingIntent.FLAG_UPDATE_CURRENT or PendingIntent.FLAG_IMMUTABLE
// Distinct requestCode per slot so each notification gets its own
// PendingIntent rather than all sharing slot 0's intent.
val notificationId = slotFor(messageId)
val notificationId = slotFor(messageId, chatId)
val tapPending =
PendingIntent.getActivity(context, notificationId, tapIntent, pendingFlags)
@@ -108,9 +108,15 @@ object ProactiveMessageNotifier {
.setCategory(NotificationCompat.CATEGORY_MESSAGE)
.setPriority(NotificationCompat.PRIORITY_HIGH)
runCatching {
return runCatching {
NotificationManagerCompat.from(context).notify(notificationId, builder.build())
}.onFailure { Log.w(TAG, "notify failed", it) }
notificationId
}.onFailure { Log.w(TAG, "notify failed", it) }.getOrNull()
}
/** Cancel one exact slot previously returned by [notificationIdFor]. */
fun cancel(context: Context, notificationId: Int) {
NotificationManagerCompat.from(context).cancel(notificationId)
}
/**
@@ -206,8 +212,12 @@ object ProactiveMessageNotifier {
}
/** Derive a stable notification slot from the message id. */
private fun slotFor(messageId: String?): Int {
val key = messageId?.takeIf { it.isNotBlank() } ?: return ID_BASE
internal fun notificationIdFor(messageId: String?, chatId: String?): Int =
slotFor(messageId, chatId)
private fun slotFor(messageId: String?, chatId: String?): Int {
val key = messageId?.takeIf { it.isNotBlank() }
?: "chat:${chatId?.takeIf { it.isNotBlank() } ?: "phone"}"
// Keep within a small positive window above the base so re-delivery of
// the same id collapses to one slot and distinct ids spread out.
return ID_BASE + (key.hashCode() and 0xFFFF)
@@ -240,6 +240,25 @@ class HermesProcessRuntime internal constructor(
}
}
fun republishAssistantSnapshot(activationId: String) {
val snapshot = synchronized(activationLock) {
if (currentActivationId != activationId ||
_initializationState.value != HermesRuntimeInitializationState.Ready
) {
null
} else {
binder.assistantSnapshot.value
}
} ?: return
if (snapshot.phase != com.hermesandroid.relay.assistant.AssistantSessionPhase.Closed) {
com.hermesandroid.relay.assistant.AssistantSessionProtocol.publish(
application,
activationId,
snapshot,
)
}
}
fun recordAssistantHeartbeat(
activationId: String,
nowElapsedMs: Long = SystemClock.elapsedRealtime(),
@@ -25,7 +25,9 @@ import com.hermesandroid.relay.data.VoiceSettings
import com.hermesandroid.relay.network.relay.RelayVoiceAudioClientAdapter
import com.hermesandroid.relay.network.relay.RelayVoiceClient
import com.hermesandroid.relay.network.shared.AutoVoiceAudioClient
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
import com.hermesandroid.relay.network.upstream.StandardHermesVoiceClient
import com.hermesandroid.relay.viewmodel.SESSION_DIRECTORY_PAGE_SIZE
import com.hermesandroid.relay.viewmodel.StandardVoiceAvailability
import com.hermesandroid.relay.viewmodel.VoiceState
import java.util.concurrent.TimeUnit
@@ -89,7 +91,10 @@ internal class HermesRuntimeBinder(
.build(),
relayUrlProvider = { connection.effectiveRelayUrl.value },
relayRouteChangesProvider = {
connection.activeEndpoint.mapNotNull { it?.relay?.url }
connection.activeRelayEndpoint.mapNotNull { endpoint ->
endpoint?.pluginProxyRoutesOrNull()?.relayWebSocketUrl
?: endpoint?.relay?.url
}
},
routeProbeRequester = connection::probeNow,
profileNameProvider = {
@@ -99,6 +104,8 @@ internal class HermesRuntimeBinder(
(connection.authState.value as? AuthState.Paired)?.token
},
apiBearerTokenProvider = connection::getApiKey,
dashboardHttpClientProvider = connection::dashboardHttpClientForRelayIngress,
dashboardIngressWebSocketRequestProvider = connection::dashboardRelayRequestForIngress,
)
val standardVoiceClient = StandardHermesVoiceClient(
context = application,
@@ -185,7 +192,19 @@ internal class HermesRuntimeBinder(
}
}
chat.setProfileSessionLister { profileName ->
connection.listProfileScopedSessions(profileName)
connection.listProfileScopedSessions(
profileName = profileName,
limit = SESSION_DIRECTORY_PAGE_SIZE,
excludeSources = connection.hiddenSources.value,
)
}
chat.setProfileSessionPageLister { profileName, offset, limit ->
connection.listProfileScopedSessions(
profileName = profileName,
limit = limit,
offset = offset,
excludeSources = connection.hiddenSources.value,
)
}
chat.setProfileMessageLoaderWithMode { profileName, sessionId, mode ->
connection.loadProfileScopedMessages(profileName, sessionId, mode)
@@ -292,23 +311,41 @@ internal class HermesRuntimeBinder(
connection.activeConnectionId,
connection.effectiveSessionProfileName,
connection.lastSessionId,
) { ready, connectionId, profileName, sessionId ->
ProfileContextInputs(ready, connectionId, profileName, sessionId)
connection.activeEndpoint,
) { ready, connectionId, profileName, sessionId, activeEndpoint ->
ProfileContextInputs(
ready,
connectionId,
profileName,
sessionId,
dashboardRouteResolved = activeEndpoint != null,
)
}
combine(
contextInputs,
connection.profileSelectionSettled,
connection.lockedProfileName,
) { inputs, settled, lockedProfileName ->
connection.hiddenSources,
) { inputs, settled, lockedProfileName, hiddenSources ->
inputs.copy(
profileSelectionSettled = settled,
profileLocked = lockedProfileName != null,
hiddenSources = hiddenSources,
)
}.collectLatest { inputs ->
profileContextReady.value = false
if (!inputs.chatReady) return@collectLatest
if (!inputs.profileSelectionSettled) delay(PROFILE_SETTLE_BACKSTOP_MS)
else delay(PROFILE_CONTEXT_COALESCE_MS)
if (!shouldRefreshSessionDirectory(inputs.chatReady, inputs.dashboardRouteResolved)) {
return@collectLatest
}
if (!inputs.profileSelectionSettled) {
delay(PROFILE_SETTLE_BACKSTOP_MS)
// The backstop is diagnostic patience, not permission to
// issue an unscoped read. Server-default ownership remains
// unknown until the lightweight active-profile scope lands.
if (!connection.profileSelectionSettled.value) return@collectLatest
} else {
delay(PROFILE_CONTEXT_COALESCE_MS)
}
val contextKey = AgentDisplay.profileContextKey(
connectionId = inputs.connectionId,
profileName = inputs.profileName,
@@ -322,6 +359,28 @@ internal class HermesRuntimeBinder(
profileContextReady.value = true
}
}
jobs += runtime.coroutineScope.launch {
var metadataHydratedRoute: Pair<String, String>? = null
chat.sessionDirectoryReadyEvents.collect { event ->
if (!chat.ownsSessionDirectoryReadyEvent(event)) return@collect
val connectionId = connection.activeConnectionId.value ?: return@collect
val expectedContextKey = AgentDisplay.profileContextKey(
connectionId = connectionId,
profileName = connection.effectiveSessionProfileName.value,
)
if (event.contextKey != expectedContextKey) return@collect
val dashboardUrl = connection.effectiveDashboardUrl.value
.takeIf(String::isNotBlank)
?: return@collect
val routeKey = connectionId to dashboardUrl.trim().trimEnd('/').lowercase()
if (metadataHydratedRoute == routeKey) return@collect
metadataHydratedRoute = routeKey
// `/api/profiles`, Gateway avatars, pets, skills, and model
// metadata are not session-directory prerequisites. Hydrate
// them only after exact-owner rows have already published.
connection.refreshDeferredProfileMetadata()
}
}
jobs += runtime.coroutineScope.launch {
connection.parseToolAnnotations.collect { enabled ->
connection.chatHandler.parseToolAnnotations = enabled
@@ -377,7 +436,9 @@ internal class HermesRuntimeBinder(
if (!AssistantAppSessionState.active.value) return@collect
if (state.voiceMode) AssistantAppSessionState.markVoiceStarted()
if (state.voiceMode || AssistantAppSessionState.hasVoiceStarted()) {
AssistantSessionProtocol.publish(application, snapshot)
state.assistantActivationId?.let { activationId ->
AssistantSessionProtocol.publish(application, activationId, snapshot)
}
}
}
}
@@ -490,8 +551,10 @@ internal class HermesRuntimeBinder(
val connectionId: String?,
val profileName: String?,
val sessionId: String?,
val dashboardRouteResolved: Boolean,
val profileSelectionSettled: Boolean = false,
val profileLocked: Boolean = false,
val hiddenSources: Set<String> = emptySet(),
)
private companion object {
@@ -501,6 +564,16 @@ internal class HermesRuntimeBinder(
}
}
/**
* Session browsing is Dashboard HTTP state, not Gateway-socket state. API-only
* connections still use chat readiness; Dashboard connections can refresh once
* the resolver has selected a live route, after the profile-settle fence.
*/
internal fun shouldRefreshSessionDirectory(
chatReady: Boolean,
dashboardRouteResolved: Boolean,
): Boolean = chatReady || dashboardRouteResolved
internal fun assistantCanTransmitScreenContext(engineMode: VoiceEngineMode): Boolean =
engineMode == VoiceEngineMode.HermesVoiceOutput
@@ -144,6 +144,7 @@ import com.hermesandroid.relay.data.VoicePresentationMode
import com.hermesandroid.relay.data.capabilities
import com.hermesandroid.relay.data.displayLabel
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.cancelAndJoin
import kotlinx.coroutines.flow.map
import kotlinx.coroutines.launch
import kotlinx.coroutines.withContext
@@ -249,14 +250,27 @@ internal fun resolvePairSetupReady(
authorizedHandoffId: String?,
activeConnectionId: String?,
connectionIds: Set<String>,
): Boolean = connectionId == null || storeHydrated && activeConnectionId != null &&
activeConnectionId in connectionIds &&
(activeConnectionId == connectionId || activeConnectionId == authorizedHandoffId)
draftConnectionId: String? = null,
): Boolean = connectionId == null || connectionId == draftConnectionId ||
storeHydrated && activeConnectionId != null && (
activeConnectionId == connectionId ||
activeConnectionId == authorizedHandoffId && activeConnectionId in connectionIds
)
/** A user retry replaces even a still-active preparation attempt. */
internal fun shouldStartPairPreparation(hasActiveJob: Boolean, retryRequested: Boolean): Boolean =
retryRequested || !hasActiveJob
internal fun shouldCommitPairDraftBeforeDashboardSignIn(
connectionId: String?,
draftConnectionId: String?,
): Boolean = connectionId != null && connectionId == draftConnectionId
/** Pair-origin sign-in must finish the staged Dashboard-ingress Relay handshake. */
internal fun shouldResumePairingAfterDashboardAuthentication(source: String): Boolean =
source == Screen.DashboardSignIn.SOURCE_PAIR ||
source == Screen.DashboardSignIn.SOURCE_ONBOARDING
/** A replaced/canceled attempt must not evict the newer job from the route map. */
internal fun isCurrentPairPreparation(mappedJob: Any?, completingJob: Any): Boolean =
mappedJob === completingJob
@@ -287,6 +301,28 @@ internal fun resolveAppChatRuntimeStatus(
return resolveChatRuntimeStatus(gateway = gateway, apiSse = api)
}
internal fun shouldSettleStartupUnreachable(
hasConfiguredChat: Boolean,
runtimeStatus: ChatRuntimeStatus,
): Boolean =
hasConfiguredChat &&
runtimeStatus is ChatRuntimeStatus.Unavailable
internal fun startupShellCanRender(
appReady: Boolean,
hasStartupConnection: Boolean,
endpointSelected: Boolean,
chatUp: Boolean,
narrationStage: Int,
unreachableConfirmed: Boolean,
timedOut: Boolean,
): Boolean = appReady && (
!hasStartupConnection ||
((endpointSelected || chatUp) && narrationStage >= 2) ||
unreachableConfirmed ||
timedOut
)
/** Route represented by the app footer's currently usable chat transport. */
internal fun resolveFooterRouteCandidate(
runtimeStatus: ChatRuntimeStatus,
@@ -319,6 +355,40 @@ internal fun resolveFooterRouteCandidate(
}
}
/**
* Compact, surface-aware label for the persistent chat footer.
*
* Endpoint roles are operator and wire metadata, so an internal role such as
* `authenticated_dashboard` must never leak into this constrained surface.
* Gateway labels describe how the Dashboard is reached; API fallback keeps
* the route's ordinary transport label.
*/
internal fun resolveFooterRouteLabel(
runtimeStatus: ChatRuntimeStatus,
route: EndpointCandidate?,
fallbackLabel: String,
): String {
val connected = runtimeStatus as? ChatRuntimeStatus.Connected ?: return ""
if (route == null) return fallbackLabel
if (connected.transport == ChatTransportPath.ApiSse) return route.displayLabel()
return when (route.role.trim().lowercase()) {
"lan" -> "LAN"
"tailscale" -> "Tailscale"
else -> if (
route.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
) {
"HTTP"
} else {
route.displayLabel()
}
}
}
/** Keep the footer's model identity compact; context-window suffixes belong in model details. */
internal fun compactFooterModelLabel(model: String): String =
model.substringAfterLast('/').replace(Regex("-\\d+[kKmM]$"), "")
/**
* Conversation voice remains part of chat, so its persistent connection
* footer stays visible. Focus voice is the only presentation that suppresses
@@ -484,10 +554,8 @@ sealed class Screen(
//
// Multi-connection: accepts an optional `connectionId` query arg —
// the ConnectionsSettings "Re-pair" button targets a specific
// connection. The "Add connection" path pre-creates a placeholder
// via `ConnectionViewModel.beginAddConnection()` and routes here
// with that id, so the wizard's standard connect / applyPairingPayload lands in the
// new connection's auth store instead of the outgoing one's.
// connection. The "Add connection" path creates a transient id-scoped
// auth draft; it is persisted and activated only after setup succeeds.
data object Pair : Screen(
"pair?connectionId={connectionId}&autoStart={autoStart}",
"Connect",
@@ -511,7 +579,7 @@ sealed class Screen(
return if (params.isEmpty()) "pair" else "pair?${params.joinToString("&")}"
}
}
data object ConnectionsSettings : Screen("settings/connections", "Connections", Icons.Filled.Settings)
data object ConnectionsSettings : Screen("settings/connections", "Gateways", Icons.Filled.Settings)
// Level-2 detail for a single connection (tabbed: Overview / Routes /
// Advanced / Security). Drilled into from the Connections list. The
// `connectionId` path segment survives process death via SavedStateHandle;
@@ -671,6 +739,10 @@ fun RelayApp() {
val pendingAddConnectionJobs = remember {
mutableMapOf<String, kotlinx.coroutines.Job>()
}
var pendingAddConnectionTargetId by rememberSaveable { mutableStateOf<String?>(null) }
val pendingAddConnectionAbortJobs = remember {
mutableMapOf<String, kotlinx.coroutines.Job>()
}
val prepareAddConnection: (String, Boolean) -> Unit = { id, retryRequested ->
val existingJob = pendingAddConnectionJobs[id]
if (shouldStartPairPreparation(existingJob?.isActive == true, retryRequested)) {
@@ -691,6 +763,25 @@ fun RelayApp() {
job.start()
}
}
val abortAddConnection: (String) -> kotlinx.coroutines.Job = { id ->
pendingAddConnectionAbortJobs[id] ?: connectionSwitchScope.launch {
try {
pendingAddConnectionJobs.remove(id)?.cancelAndJoin()
connectionViewModel.discardPlaceholderConnection(id)
} finally {
if (pendingAddConnectionTargetId == id) {
pendingAddConnectionTargetId = null
}
}
}.also { job ->
pendingAddConnectionAbortJobs[id] = job
job.invokeOnCompletion {
if (pendingAddConnectionAbortJobs[id] === job) {
pendingAddConnectionAbortJobs.remove(id)
}
}
}
}
// One-time init: the terminal channel ViewModel registers with the shared
// multiplexer and observes the relay connection state so it can attach/
@@ -750,6 +841,7 @@ fun RelayApp() {
val profileSelectionSettled by connectionViewModel.profileSelectionSettled.collectAsState()
val agentProfiles by connectionViewModel.agentProfiles.collectAsState()
val activeConnectionId by connectionViewModel.activeConnectionId.collectAsState()
val activeConnection by connectionViewModel.activeConnection.collectAsState()
val connectionStoreHydrated by
connectionViewModel.connectionStore.isHydrated.collectAsState()
val supervisedModeStore = remember(applicationContext) {
@@ -771,18 +863,14 @@ fun RelayApp() {
}
val ownedSupervisedPolicyState = supervisedPolicyState.value
?.takeIf { (ownerConnectionId, _) -> ownerConnectionId == activeConnectionId }
// Fail closed across process restoration. activeConnectionId starts as
// null while ConnectionStore reads DataStore, so null alone cannot prove
// this is a fresh install with no supervised policy to restore.
if (!isRelayNavigationHydrated(
connectionStoreHydrated = connectionStoreHydrated,
activeConnectionId = activeConnectionId,
supervisedPolicyHydrated = ownedSupervisedPolicyState != null,
)
) {
SupervisedStartupLoadingScreen()
return
}
// Keep navigation mounted while the new connection owner's supervised
// policy loads. Protected destinations are covered later in the NavHost
// box; returning here would dispose the controller and replay cold start.
val relayNavigationHydrated = isRelayNavigationHydrated(
connectionStoreHydrated = connectionStoreHydrated,
activeConnectionId = activeConnectionId,
supervisedPolicyHydrated = ownedSupervisedPolicyState != null,
)
val supervisedPolicy = ownedSupervisedPolicyState?.second ?: SupervisedModePolicy()
val supervisedPinnedProfile = supervisedPolicy.pinnedProfileName?.let { name ->
agentProfiles.firstOrNull { it.name.equals(name, ignoreCase = true) }
@@ -798,12 +886,14 @@ fun RelayApp() {
var parentAccessUnlocked by remember(activeConnectionId) { mutableStateOf(false) }
LaunchedEffect(
relayNavigationHydrated,
activeConnectionId,
supervisedPolicy,
agentProfiles,
selectedProfile,
profileSelectionSettled,
) {
if (!relayNavigationHydrated) return@LaunchedEffect
chatViewModel.updateSupervisedModePolicy(chatSupervisedPolicy)
connectionViewModel.authManager.updateSupervisedMode(chatSupervisedPolicy)
if (!supervisedPolicy.enabled) {
@@ -862,6 +952,7 @@ fun RelayApp() {
val serverCapabilities by connectionViewModel.serverCapabilities.collectAsState()
val gatewayAvailability by connectionViewModel.gatewayAvailability.collectAsState()
val effectiveDashboardUrl by connectionViewModel.effectiveDashboardUrl.collectAsState()
val gitRepoScanningEnabled = activeConnection?.gitRepoScanningEnabled == true
val gitOwnerKey = activeConnectionId?.takeIf { it.isNotBlank() }?.let { connectionId ->
effectiveDashboardUrl.takeIf { it.isNotBlank() }?.let { dashboardUrl ->
"$connectionId\u0000${effectiveSessionProfileName.orEmpty()}\u0000$dashboardUrl"
@@ -881,11 +972,15 @@ fun RelayApp() {
sessionId = currentChatSessionId,
)
}
LaunchedEffect(gitOwnerKey) {
LaunchedEffect(gitOwnerKey, gitRepoScanningEnabled) {
val dashboard = effectiveDashboardUrl
.takeIf { it.isNotBlank() }
?.let { connectionViewModel.dashboardClientForActive(it) }
gitStateViewModel.configure(dashboard, gitOwnerKey)
gitStateViewModel.configure(
dashboard = dashboard,
ownerKey = gitOwnerKey,
scanningEnabled = gitRepoScanningEnabled,
)
}
// Mirror the plugin.api.write grant into the Git view model so write
@@ -928,7 +1023,8 @@ fun RelayApp() {
}
}
val gitWorkspaceAvailable = gitReposState is GitStateUiState.Ready
val gitWorkspaceAvailable = gitRepoScanningEnabled &&
(gitReposState as? GitStateUiState.Ready)?.repos?.isNotEmpty() == true
val gitWorkspaceSummary = remember(
gitReposState,
gitDetailState,
@@ -1251,10 +1347,12 @@ fun RelayApp() {
// ineffective even before the state-clearing effect runs.
LaunchedEffect(
navController,
relayNavigationHydrated,
supervisedPolicy.enabled,
parentAccessForCurrentRoute,
) {
com.hermesandroid.relay.util.NavRouteRequest.requests.collect { route ->
if (!relayNavigationHydrated) return@collect
if (
supervisedPolicy.enabled &&
!isSupervisedRouteAllowed(route, parentAccessForCurrentRoute)
@@ -1265,16 +1363,21 @@ fun RelayApp() {
}
}
LaunchedEffect(
relayNavigationHydrated,
supervisedPolicy.enabled,
parentAccessForCurrentRoute,
currentRoute,
) {
if (!relayNavigationHydrated) return@LaunchedEffect
val redirect = shouldRedirectSupervisedRoute(
supervisedEnabled = supervisedPolicy.enabled,
parentAccessUnlocked = parentAccessForCurrentRoute,
currentRoute = currentRoute,
)
if (redirect) {
pendingAddConnectionTargetId?.let { targetId ->
abortAddConnection(targetId).join()
}
navController.navigate(Screen.Chat.route(openAgentSheet = false)) {
popUpTo(navController.graph.findStartDestination().id) { inclusive = false }
launchSingleTop = true
@@ -1312,11 +1415,12 @@ fun RelayApp() {
lifecycleOwner.lifecycle.addObserver(relockObserver)
onDispose { lifecycleOwner.lifecycle.removeObserver(relockObserver) }
}
val suppressGlobalChrome = shouldSuppressGlobalChrome(
onboardingCompleted = onboardingCompleted,
isDemoMode = isDemoMode,
currentRoute = currentRoute,
)
val suppressGlobalChrome = !relayNavigationHydrated ||
shouldSuppressGlobalChrome(
onboardingCompleted = onboardingCompleted,
isDemoMode = isDemoMode,
currentRoute = currentRoute,
)
// Safety net: landing on a real connect surface (onboarding or the
// Connect/Pair wizard) while demo is still active — via the banner's
@@ -1435,13 +1539,13 @@ fun RelayApp() {
}
val postResumeQuiet by connectionViewModel.postResumeQuiet.collectAsState()
val apiHealth by connectionViewModel.apiServerHealth.collectAsState()
val activeConnection by connectionViewModel.activeConnection.collectAsState()
val activeEndpoint by connectionViewModel.activeEndpoint.collectAsState()
val connectionSecurity by connectionViewModel.connectionSecurity.collectAsState()
val serverModelName by chatViewModel.serverModelName.collectAsState()
val gatewayCurrentModel by chatViewModel.gatewayCurrentModel.collectAsState()
val appReady by connectionViewModel.isReady.collectAsState()
val initialChatSettled by chatViewModel.initialChatSettled.collectAsState()
val startupSessionsLoading by chatViewModel.isLoadingSessions.collectAsState()
val shareConnectionId by rememberUpdatedState(
activeConnection?.id?.takeIf(String::isNotBlank) ?: "offline"
)
@@ -1528,15 +1632,24 @@ fun RelayApp() {
// first verdict was what flashed the disconnected chat UI at users
// who were connected-just-waiting. The keyed effect restarts on
// every health flip, cancelling a pending settle.
LaunchedEffect(appChatRuntimeStatus, startupGateReleased) {
LaunchedEffect(appChatRuntimeStatus, activeEndpoint, startupGateReleased) {
if (startupGateReleased) return@LaunchedEffect
if (hasStartupConnection && appChatRuntimeStatus is ChatRuntimeStatus.Unavailable) {
if (shouldSettleStartupUnreachable(
hasConfiguredChat = hasStartupConnection,
runtimeStatus = appChatRuntimeStatus,
)
) {
delay(3_000L)
startupUnreachableSettled = true
} else {
startupUnreachableSettled = false
}
}
val startupUnreachableConfirmed = startupUnreachableSettled &&
shouldSettleStartupUnreachable(
hasConfiguredChat = hasStartupConnection,
runtimeStatus = appChatRuntimeStatus,
)
// ---- Startup narration: real states the checklist verifies ----
val startupEndpoint = activeEndpoint
@@ -1563,8 +1676,14 @@ fun RelayApp() {
when {
startupChatUp ->
StartupCheck(StartupCheckState.Done, "hermes online")
appChatRuntimeStatus is ChatRuntimeStatus.Unavailable ->
startupUnreachableConfirmed ->
StartupCheck(StartupCheckState.Failed, "hermes unreachable")
appChatRuntimeStatus is ChatRuntimeStatus.Unavailable && startupEndpoint != null ->
StartupCheck(StartupCheckState.Active, "gateway retrying")
startupEndpoint != null -> StartupCheck(
StartupCheckState.Active,
"waking ${effectiveDisplayProfile?.name?.replaceFirstChar { it.uppercase() } ?: "Hermes"}",
)
appReady ->
StartupCheck(StartupCheckState.Active, "contacting hermes")
else -> StartupCheck(StartupCheckState.Pending, "hermes")
@@ -1573,10 +1692,12 @@ fun RelayApp() {
// renders from — so this row can never tick while the chat
// surface would still show its connect CTA.
when {
chatReady && initialChatSettled ->
StartupCheck(StartupCheckState.Done, "conversation ready")
initialChatSettled && !startupSessionsLoading ->
StartupCheck(StartupCheckState.Done, "sessions ready")
startupSessionsLoading ->
StartupCheck(StartupCheckState.Active, "loading sessions")
startupChatUp ->
StartupCheck(StartupCheckState.Active, "loading conversation")
StartupCheck(StartupCheckState.Active, "restoring conversation")
else -> StartupCheck(StartupCheckState.Pending, "conversation")
},
)
@@ -1600,25 +1721,22 @@ fun RelayApp() {
startupNarrationStage += 1
}
}
// Full-screen startup owns only process state + route selection. The
// mounted Chat surface owns Gateway wake and session hydration so the
// user can see cached rows and accurate inline progress instead of a
// global sphere that appears hung for the server's entire wake budget.
val startupNarrationComplete =
startupNarrationStage >= startupCheckTargets.size
startupNarrationStage >= minOf(2, startupCheckTargets.size)
val startupConnectionResolved = appReady && (
!hasStartupConnection ||
// Happy path: the chat surface's OWN readiness signal is
// true (client built + reachable verdict — what its connect
// CTA renders from), the last conversation has been restored
// (or there was none), and the checklist has visibly
// finished ticking. Anything weaker (e.g. the resolver's
// earlier health evidence) reveals a chat screen that still
// shows "Connect Vanilla Hermes" for the few hundred ms
// until the client-based verdict catches up.
(chatReady && initialChatSettled && startupNarrationComplete) ||
// Error path: a settled unreachable reveals the normal UI,
// which owns offline presentation (status pill, retry).
startupUnreachableSettled ||
startupGateTimedOut
)
val startupConnectionResolved = startupShellCanRender(
appReady = appReady,
hasStartupConnection = hasStartupConnection,
endpointSelected = startupEndpoint != null,
chatUp = startupChatUp,
narrationStage = startupNarrationStage,
unreachableConfirmed = startupUnreachableConfirmed,
timedOut = startupGateTimedOut,
)
LaunchedEffect(
onboardingCompleted,
startupGateMinElapsed,
@@ -1640,7 +1758,7 @@ fun RelayApp() {
if (
hasStartupConnection &&
!happyPathReady &&
!startupUnreachableSettled &&
!startupUnreachableConfirmed &&
startupGateTimedOut
) {
DiagnosticsLog.record(
@@ -2000,19 +2118,20 @@ fun RelayApp() {
connection = activeConnection,
effectiveDashboardUrl = effectiveDashboardUrl,
)
val routeLabel = footerRoute?.displayLabel()
?: activeConnection?.label
?: stringResource(R.string.status_no_route)
val routeLabel = resolveFooterRouteLabel(
runtimeStatus = appChatRuntimeStatus,
route = footerRoute,
fallbackLabel = activeConnection?.label
?: stringResource(R.string.status_no_route),
)
val transportStatus = resolveChatTransportStatus(
streamingEndpoint = streamingEndpoint,
gatewayAvailability = gatewayAvailability,
serverCapabilities = serverCapabilities,
)
val transportRouteLabel = if (transportStatus.tier == ChatTransportTier.Offline) {
""
} else {
routeLabel
}
val transportRouteLabel = if (
transportStatus.tier == ChatTransportTier.Offline
) "" else routeLabel
val profileLabel = AgentDisplay.profileDisplayName(effectiveDisplayProfile)
?: stringResource(R.string.status_profile_default)
val displayProfile = effectiveDisplayProfile
@@ -2020,16 +2139,21 @@ fun RelayApp() {
?: AgentDisplay.displayModelName(displayProfile?.model)
?: AgentDisplay.displayModelName(serverModelName)
?: stringResource(R.string.status_model_pending)
val safetyLabel = if (BuildFlavor.isSideload && masterEnabled) {
if (unattendedEnabled && timedScreenControlActive) stringResource(R.string.status_safety_unattended)
else stringResource(R.string.status_safety_on)
} else {
stringResource(R.string.status_profile_format, profileLabel)
}
val openConnections = {
navController.navigate(Screen.ConnectionsSettings.route) {
launchSingleTop = true
val footerModelLabel = compactFooterModelLabel(modelLabel)
val openConnections: (() -> Unit)? = if (
isSupervisedRouteContentAllowed(
supervisedEnabled = supervisedPolicy.enabled,
parentAccessUnlocked = parentAccessForCurrentRoute,
currentRoute = Screen.ConnectionsSettings.route,
)
) {
{
navController.navigate(Screen.ConnectionsSettings.route) {
launchSingleTop = true
}
}
} else {
null
}
RelayStatusStrip(
leadingBadge = {
@@ -2039,7 +2163,7 @@ fun RelayApp() {
)
},
routeLabel = transportRouteLabel,
trailing = "$modelLabel / $safetyLabel",
trailing = "$footerModelLabel / $profileLabel",
// Tap the persistent status/route readout to open
// Connections — preserves the affordance the dropped
// header endpoint chip used to provide.
@@ -2078,6 +2202,7 @@ fun RelayApp() {
modifier = Modifier.fillMaxSize(),
) {
composable(Screen.Onboarding.route) {
val onboardingDraftId by connectionViewModel.connectionDraftId.collectAsState()
// The wizard inside OnboardingScreen now owns credential
// application via ConnectionViewModel.applyPairingPayload,
// so the callback collapses to "mark complete + navigate
@@ -2096,19 +2221,69 @@ fun RelayApp() {
OnboardingScreen(
connectionViewModel = connectionViewModel,
onComplete = {
connectionViewModel.completeOnboarding()
// Concrete bare-"chat" URI — the Screen.Chat.route
// field is the route TEMPLATE (contains
// `{openAgentSheet}`) and must not be navigated
// to directly; build the URI via Screen.Chat.route(...).
navController.navigate(Screen.Chat.route(openAgentSheet = false)) {
popUpTo(Screen.Onboarding.route) { inclusive = true }
val draftId = onboardingDraftId
connectionSwitchScope.launch {
val prepared = runCatching {
if (draftId != null) {
connectionViewModel.commitConnectionDraft(draftId)
}
}
if (prepared.isFailure) {
val error = prepared.exceptionOrNull()
android.util.Log.e(
"GatewayPairFlow",
"Could not commit onboarding gateway",
error,
)
snackbarHostState.showSnackbar(
error?.message ?: "Could not finish gateway setup",
)
return@launch
}
connectionViewModel.completeOnboarding()
// Concrete bare-"chat" URI — the Screen.Chat.route
// field is the route TEMPLATE (contains
// `{openAgentSheet}`) and must not be navigated
// to directly; build the URI via Screen.Chat.route(...).
navController.navigate(Screen.Chat.route(openAgentSheet = false)) {
popUpTo(Screen.Onboarding.route) { inclusive = true }
}
}
},
onManageSignIn = {
navController.navigate(
Screen.DashboardSignIn.route(Screen.DashboardSignIn.SOURCE_ONBOARDING),
)
val draftId = onboardingDraftId
connectionSwitchScope.launch {
android.util.Log.i(
"GatewayPairFlow",
"Preparing onboarding gateway for Dashboard sign-in",
)
val prepared = runCatching {
if (draftId != null) {
connectionViewModel.commitConnectionDraft(draftId)
}
}
if (prepared.isFailure) {
val error = prepared.exceptionOrNull()
android.util.Log.e(
"GatewayPairFlow",
"Could not prepare onboarding Dashboard sign-in",
error,
)
snackbarHostState.showSnackbar(
error?.message ?: "Could not prepare Dashboard sign-in",
)
return@launch
}
android.util.Log.i(
"GatewayPairFlow",
"Opening Dashboard sign-in from onboarding",
)
navController.navigate(
Screen.DashboardSignIn.route(Screen.DashboardSignIn.SOURCE_ONBOARDING),
) {
launchSingleTop = true
}
}
},
onOpenPermissions = {
navController.navigate(Screen.PermissionsSettings.route)
@@ -2217,9 +2392,12 @@ fun RelayApp() {
(it.connectionId == null || it.connectionId == activeConnectionId) &&
(it.chatId ?: "phone") == chatId
}
if (entries.isEmpty()) return@LaunchedEffect
chatViewModel.openProactiveThread(chatId, entries)
if (entries.isNotEmpty()) {
chatViewModel.openProactiveThread(chatId, entries)
}
}
// Consume the request even when deletion removed its
// local row before a stale notification tap arrived.
backStackEntry.arguments?.putString(
Screen.Chat.ARG_PROACTIVE_CHAT_ID,
null,
@@ -2290,7 +2468,7 @@ fun RelayApp() {
},
// AgentInfoSheet footer jumps straight into the full
// Connections CRUD screen — saves a detour through
// Settings → Connections.
// Settings → Gateways.
onNavigateToConnections = {
navController.navigate(Screen.ConnectionsSettings.route)
},
@@ -2314,13 +2492,9 @@ fun RelayApp() {
// without leaving Chat. Safe here — this state only shows when
// nothing is configured, so there's no placeholder in flight.
onTryDemo = enterDemo,
onNavigateToManage = {
navController.navigate(Screen.Manage.route) {
popUpTo(navController.graph.findStartDestination().id) {
saveState = true
}
onNavigateToDashboardSignIn = {
navController.navigate(Screen.DashboardSignIn.route()) {
launchSingleTop = true
restoreState = true
}
},
onNavigateToBridge = {
@@ -2538,6 +2712,13 @@ fun RelayApp() {
DashboardSignInScreen(
connectionViewModel = connectionViewModel,
onBack = { navController.popBackStack() },
onAuthenticationReady = if (
shouldResumePairingAfterDashboardAuthentication(source)
) {
{ connectionViewModel.resumeDeferredDashboardRelayPairing() }
} else {
null
},
onAuthenticated = {
when (source) {
Screen.DashboardSignIn.SOURCE_ONBOARDING -> {
@@ -2687,6 +2868,7 @@ fun RelayApp() {
SettingsScreen(
connectionViewModel = connectionViewModel,
chatViewModel = chatViewModel,
gitRepoScanningEnabled = gitRepoScanningEnabled,
supervisedPolicy = supervisedPolicy,
parentAccessUnlocked = parentAccessForCurrentRoute,
onRequestParentAccess = { parentAccessUnlocked = true },
@@ -2862,6 +3044,7 @@ fun RelayApp() {
composable(Screen.GitState.route) {
GitStateScreen(
viewModel = gitStateViewModel,
onScanningEnabledChange = connectionViewModel::setGitRepoScanningEnabled,
onBack = { navController.popBackStack() },
)
}
@@ -3054,14 +3237,38 @@ fun RelayApp() {
onOpenConnection = { id ->
navController.navigate(Screen.ConnectionDetail.route(id))
},
onAddConnection = {
val id = java.util.UUID.randomUUID().toString()
// Draw step 1 immediately. Placeholder persistence
// and the heavy connection-context switch continue
// underneath the discovery UI instead of blocking
// navigation on encrypted-store/client setup.
navController.navigate(Screen.Pair.route(connectionId = id))
prepareAddConnection(id, false)
addConnectionEnabled = mayStartAddConnection(
supervisedEnabled = supervisedPolicy.enabled,
parentAccessUnlocked = parentAccessForCurrentRoute,
activeTargetId = pendingAddConnectionTargetId,
),
onAddConnection = addConnection@{
val liveConnectionId = connectionViewModel.activeConnectionId.value
val livePolicyState = supervisedPolicyState.value
?.takeIf { (ownerId, _) -> ownerId == liveConnectionId }
val livePolicy = when {
liveConnectionId == null -> SupervisedModePolicy()
livePolicyState != null -> livePolicyState.second
else -> return@addConnection
}
val liveRoute = navController.currentDestination?.route
val liveParentAccess = parentAccessUnlocked &&
!shouldRelockParentAccess(
supervisedEnabled = livePolicy.enabled,
parentAccessUnlocked = parentAccessUnlocked,
route = liveRoute,
)
runAddConnectionAction(
supervisedEnabled = livePolicy.enabled,
parentAccessUnlocked = liveParentAccess,
activeTargetId = pendingAddConnectionTargetId,
allocateTarget = { java.util.UUID.randomUUID().toString() },
recordTarget = { id -> pendingAddConnectionTargetId = id },
navigateToPair = { id ->
navController.navigate(Screen.Pair.route(connectionId = id))
},
prepareConnection = { id -> prepareAddConnection(id, false) },
)
},
onBack = { navController.popBackStack() },
// Pass the VM so the list cards can read live status
@@ -3155,6 +3362,7 @@ fun RelayApp() {
?.getString(Screen.Pair.ARG_AUTO_START)
val pairConnections by connectionViewModel.connections.collectAsState()
val pairActiveId by connectionViewModel.activeConnectionId.collectAsState()
val pairDraftId by connectionViewModel.connectionDraftId.collectAsState()
val pairStoreHydrated by connectionViewModel.connectionStore.isHydrated.collectAsState()
// Duplicate Renew authorizes one explicit route handoff
// before switching away from the placeholder. Persist the
@@ -3170,6 +3378,7 @@ fun RelayApp() {
authorizedHandoffId = authorizedPairHandoffId,
activeConnectionId = pairActiveId,
connectionIds = pairConnections.mapTo(mutableSetOf()) { it.id },
draftConnectionId = pairDraftId,
)
com.hermesandroid.relay.ui.screens.PairScreen(
connectionViewModel = connectionViewModel,
@@ -3199,22 +3408,66 @@ fun RelayApp() {
// flight that enterDemo would leave un-discarded.
onTryDemo = if (connectionIdArg == null) enterDemo else null,
onComplete = {
// Both "add new" and "re-pair in place" now
// route to this screen with connectionIdArg
// set — add-new goes through
// ConnectionViewModel.beginAddConnection()
// which pre-creates the placeholder + switches
// to it before navigating here, so
// applyPairingPayload lands on the correct
// auth store. Nothing extra to do on success
// beyond popping the backstack.
navController.popBackStack()
if (connectionIdArg != null && pairDraftId == connectionIdArg) {
connectionSwitchScope.launch {
connectionViewModel.commitConnectionDraft(connectionIdArg)
if (pendingAddConnectionTargetId == connectionIdArg) {
pendingAddConnectionTargetId = null
}
navController.popBackStack()
}
} else {
if (pendingAddConnectionTargetId == connectionIdArg) {
pendingAddConnectionTargetId = null
}
navController.popBackStack()
}
},
onManageSignIn = {
navController.navigate(
Screen.DashboardSignIn.route(Screen.DashboardSignIn.SOURCE_PAIR),
val targetId = connectionIdArg
if (
shouldCommitPairDraftBeforeDashboardSignIn(
connectionId = targetId,
draftConnectionId = pairDraftId,
) && targetId != null
) {
launchSingleTop = true
connectionSwitchScope.launch {
android.util.Log.i(
"GatewayPairFlow",
"Committing staged gateway before Dashboard sign-in",
)
runCatching {
connectionViewModel.commitConnectionDraft(targetId)
}.onSuccess {
if (pendingAddConnectionTargetId == targetId) {
pendingAddConnectionTargetId = null
}
android.util.Log.i(
"GatewayPairFlow",
"Opening Dashboard sign-in for staged gateway",
)
navController.navigate(
Screen.DashboardSignIn.route(Screen.DashboardSignIn.SOURCE_PAIR),
) {
launchSingleTop = true
}
}.onFailure { error ->
android.util.Log.e(
"GatewayPairFlow",
"Could not commit staged gateway before sign-in",
error,
)
snackbarHostState.showSnackbar(
error.message ?: "Could not prepare Dashboard sign-in",
)
}
}
} else {
navController.navigate(
Screen.DashboardSignIn.route(Screen.DashboardSignIn.SOURCE_PAIR),
) {
launchSingleTop = true
}
}
},
onCancel = {
@@ -3225,14 +3478,12 @@ fun RelayApp() {
// never got a pairedAt stamp.
if (connectionIdArg != null) {
connectionSwitchScope.launch {
// If Back wins the race with background
// preparation, wait until the placeholder
// exists before attempting to discard it.
pendingAddConnectionJobs.remove(connectionIdArg)?.join()
connectionViewModel.discardPlaceholderConnection(connectionIdArg)
abortAddConnection(connectionIdArg).join()
navController.popBackStack()
}
} else {
navController.popBackStack()
}
navController.popBackStack()
},
)
}
@@ -3402,6 +3653,8 @@ fun RelayApp() {
okHttpClient = profileInspectorHttpClient,
relayUrlProvider = { relayUrl },
sessionTokenProvider = { relayToken },
dashboardHttpClientProvider =
connectionViewModel::dashboardHttpClientForRelayIngress,
),
gatewayClient = inspectorGatewayClient,
savedStateHandle = ssh,
@@ -3430,9 +3683,15 @@ fun RelayApp() {
)
}
}
if (!routeContentAllowed) {
if (shouldCoverRelayNavigation(
navigationHydrated = relayNavigationHydrated,
routeContentAllowed = routeContentAllowed,
currentRoute = currentRoute,
)
) {
// Keep the graph mounted so the redirect can complete, but
// cover restored parent-only content with an opaque fail-closed surface.
// cover restored parent-only content and policy-owner
// hydration with an opaque fail-closed surface.
SupervisedStartupLoadingScreen()
}
}
@@ -12,6 +12,29 @@ internal fun isSupervisedRouteAllowed(route: String?, parentAccessUnlocked: Bool
normalized == Screen.SupervisedAppearanceSettings.route
}
internal fun mayStartAddConnection(
supervisedEnabled: Boolean,
parentAccessUnlocked: Boolean,
activeTargetId: String? = null,
): Boolean = activeTargetId == null && (!supervisedEnabled || parentAccessUnlocked)
internal inline fun runAddConnectionAction(
supervisedEnabled: Boolean,
parentAccessUnlocked: Boolean,
activeTargetId: String?,
allocateTarget: () -> String,
recordTarget: (String) -> Unit,
navigateToPair: (String) -> Unit,
prepareConnection: (String) -> Unit,
): String? {
if (!mayStartAddConnection(supervisedEnabled, parentAccessUnlocked, activeTargetId)) return null
val targetId = allocateTarget()
recordTarget(targetId)
navigateToPair(targetId)
prepareConnection(targetId)
return targetId
}
/** Do not inspect or mutate a NavController until its first destination exists. */
internal fun shouldRedirectSupervisedRoute(
supervisedEnabled: Boolean,
@@ -45,6 +68,25 @@ internal fun isRelayNavigationHydrated(
): Boolean = connectionStoreHydrated &&
(activeConnectionId == null || supervisedPolicyHydrated)
/**
* Keep the NavHost mounted while a new connection's supervised policy loads.
* Setup and Dashboard sign-in expose no protected conversation/settings data,
* so they may remain visible; every other route stays covered fail-closed.
*/
internal fun shouldCoverRelayNavigation(
navigationHydrated: Boolean,
routeContentAllowed: Boolean,
currentRoute: String?,
): Boolean {
if (!routeContentAllowed) return true
if (navigationHydrated) return false
return currentRoute?.substringBefore('?') !in setOf(
Screen.Onboarding.route,
Screen.Pair.route.substringBefore('?'),
Screen.DashboardSignIn.route.substringBefore('?'),
)
}
/** A parent unlock never follows the user back into the supervised chat root. */
internal fun shouldRelockParentAccess(
supervisedEnabled: Boolean,
File diff suppressed because it is too large Load Diff
@@ -47,7 +47,7 @@ import com.hermesandroid.relay.viewmodel.BridgeStatus
* Phase 3 Wave 1 — bridge-ui (`bridge-screen-ui`). Visual style mirrors the status
* cards in `PairedDevicesScreen`: surfaceVariant background, 16dp padding,
* 10dp row spacing. Uses [ConnectionStatusBadge] for the pulsing status dot
* so the Bridge tab looks visually consistent with the Settings → Connections
* so the Bridge tab looks visually consistent with the Settings → Gateways
* section.
*
* The headline switch is `enabled = allowEnable` so users can't flip it on
@@ -30,7 +30,7 @@ import com.hermesandroid.relay.viewmodel.BridgeStatus
* Phase 3 Wave 1 — bridge-ui (`bridge-screen-ui`). Kept distinct from
* [BridgeMasterToggle] so that Agent safety-rails in Wave 2 can relocate the master
* toggle without losing the status surface (and so we can reuse this card
* in the Settings → Connections section later if desired).
* in Settings → Gateways later if desired).
*/
@Composable
fun BridgeStatusCard(
@@ -14,6 +14,9 @@ import androidx.compose.material3.ModalBottomSheet
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.material3.rememberModalBottomSheetState
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.LinkOff
import androidx.compose.material.icons.filled.Shield
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
@@ -30,6 +33,7 @@ import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.data.ConnectionSecurity
import com.hermesandroid.relay.data.ConnectionSecurityLevel
import com.hermesandroid.relay.data.SurfaceSecurity
import com.hermesandroid.relay.data.SurfaceUseState
private const val LEARN_MORE_URL =
"https://hermes-relay.dev/docs/architecture/connection-security.html"
@@ -128,7 +132,23 @@ private fun SurfaceSecurityRow(surface: SurfaceSecurity) {
horizontalArrangement = Arrangement.spacedBy(10.dp),
verticalAlignment = Alignment.CenterVertically,
) {
SurfaceSecurityGlyph(kind = surface.kind, modifier = Modifier.size(16.dp))
if (surface.useState == SurfaceUseState.Unavailable) {
Icon(
imageVector = Icons.Filled.LinkOff,
contentDescription = null,
tint = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(16.dp),
)
} else if (surface.useState == SurfaceUseState.Available) {
Icon(
imageVector = Icons.Filled.Shield,
contentDescription = null,
tint = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(16.dp),
)
} else {
SurfaceSecurityGlyph(kind = surface.kind, modifier = Modifier.size(16.dp))
}
Column(modifier = Modifier.weight(1f)) {
Text(
text = surface.label,
@@ -142,7 +162,17 @@ private fun SurfaceSecurityRow(surface: SurfaceSecurity) {
)
}
Text(
text = surface.mechanism,
text = when (surface.useState) {
SurfaceUseState.InUse -> surface.mechanism
SurfaceUseState.Available -> stringResource(
R.string.security_sheet_available_mechanism,
surface.mechanism,
)
SurfaceUseState.Unavailable -> stringResource(
R.string.security_sheet_unavailable_mechanism,
surface.mechanism,
)
},
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
@@ -31,7 +31,7 @@ import com.hermesandroid.relay.data.Connection
/**
* Bottom sheet chooser for switching between Hermes connections. Driven by
* the top-bar [ConnectionChip] tap and the Settings → Connections row.
* the top-bar [ConnectionChip] tap and the Settings → Gateways row.
* Each row is a radio selection — tapping commits immediately and dismisses
* the sheet so the swap kicks off before the user's finger is off the screen.
*
File diff suppressed because it is too large Load Diff
@@ -6,6 +6,8 @@ import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.ExperimentalLayoutApi
import androidx.compose.foundation.layout.FlowRow
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
@@ -56,15 +58,16 @@ import com.hermesandroid.relay.ui.theme.appearanceRoundedCornerShape
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.SurfaceSecurityKind
import com.hermesandroid.relay.data.classifySurfaceSecurity
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.gatewayRouteUrl
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.isEncryptedOverlayRoute
import com.hermesandroid.relay.data.isKnownRole
import com.hermesandroid.relay.data.isTlsUrl
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.routeAuthority
import com.hermesandroid.relay.network.shared.EndpointSurface
import com.hermesandroid.relay.network.shared.RouteProbeOutcome
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import kotlinx.coroutines.launch
@@ -100,7 +103,7 @@ fun EndpointsCard(
/**
* Live transient override installed by "Use now" (or by preference
* restoration — equal to [preferredRole] in that case). Drives the
* automatic / preferred / manual annotation on the Current line.
* automatic / preferred / manual annotation on the selected-candidate line.
*/
manualOverrideRole: String?,
onUseNow: (EndpointCandidate) -> Unit,
@@ -117,6 +120,7 @@ fun EndpointsCard(
* resolver's cache-key scheme.
*/
outcomeFor: (EndpointCandidate) -> RouteProbeOutcome? = { null },
surfaceOutcomeFor: (EndpointCandidate, EndpointSurface) -> RouteProbeOutcome? = { _, _ -> null },
/** Auth state applies only to the currently active Dashboard route. */
dashboardAuthenticated: Boolean? = null,
dashboardSignInRequired: Boolean = false,
@@ -133,11 +137,11 @@ fun EndpointsCard(
// Pre-resolve strings
val noRoutesStoredText = stringResource(R.string.endpoints_no_routes_stored)
val addRouteText = stringResource(R.string.endpoints_add_route)
val resolvingText = stringResource(R.string.endpoints_resolving)
val manualUntilDisconnectText = stringResource(R.string.endpoints_manual_until_disconnect)
val preferredText = stringResource(R.string.endpoints_preferred)
val automaticText = stringResource(R.string.endpoints_automatic)
val currentRouteText = stringResource(R.string.endpoints_current_route)
val noActiveFallbackText = stringResource(R.string.endpoints_no_active_fallback)
if (endpoints.isEmpty()) {
Column(verticalArrangement = Arrangement.spacedBy(4.dp)) {
@@ -166,18 +170,41 @@ fun EndpointsCard(
val stopPreferringText = stringResource(R.string.endpoints_stop_preferring)
Column(verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(
text = currentRouteText.format(
activeEndpoint?.displayLabel() ?: resolvingText,
when {
manualSwitchActive -> manualUntilDisconnectText
manualOverrideRole != null -> preferredText
else -> automaticText
}
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
val activeOutcome = activeEndpoint?.let(outcomeFor)
if (activeEndpoint == null) {
Text(
text = noActiveFallbackText,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
} else {
Text(
text = currentRouteText.format(
activeEndpoint.displayLabel(),
when {
manualSwitchActive -> manualUntilDisconnectText
manualOverrideRole != null -> preferredText
else -> automaticText
}
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
text = stringResource(
R.string.endpoints_selection_reason,
activeEndpoint.priority,
when (routeReachabilityPresentation(isProbing, activeOutcome)) {
RouteReachabilityPresentation.Checking -> stringResource(R.string.endpoints_checking)
RouteReachabilityPresentation.Reachable -> stringResource(R.string.endpoints_reachable_now)
RouteReachabilityPresentation.Unreachable -> stringResource(R.string.endpoints_last_check_failed)
RouteReachabilityPresentation.NotChecked -> stringResource(R.string.endpoints_reachability_not_checked)
},
),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
endpoints.forEachIndexed { index, candidate ->
if (index > 0) HorizontalDivider()
EndpointRow(
@@ -188,6 +215,7 @@ fun EndpointsCard(
isPreferred = preferredRole?.equals(candidate.role, ignoreCase = true) == true,
isProbing = isProbing,
outcome = outcomeFor(candidate),
surfaceOutcomeFor = surfaceOutcomeFor,
dashboardAuthenticated = dashboardAuthenticated.takeIf { activeEndpoint != null &&
activeEndpoint.role.equals(candidate.role, ignoreCase = true) &&
activeEndpoint.routeAuthority() == candidate.routeAuthority()
@@ -232,6 +260,7 @@ fun EndpointsCard(
/**
* One row: role chip + host:port + transport hint + health chip + 3-dot menu.
*/
@OptIn(ExperimentalLayoutApi::class)
@Composable
private fun EndpointRow(
candidate: EndpointCandidate,
@@ -239,6 +268,7 @@ private fun EndpointRow(
isPreferred: Boolean,
isProbing: Boolean = false,
outcome: RouteProbeOutcome? = null,
surfaceOutcomeFor: (EndpointCandidate, EndpointSurface) -> RouteProbeOutcome? = { _, _ -> null },
dashboardAuthenticated: Boolean? = null,
dashboardSignInRequired: Boolean = false,
onUseNow: () -> Unit,
@@ -276,28 +306,38 @@ private fun EndpointRow(
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
modifier = Modifier.fillMaxWidth(),
) {
Text(
text = candidate.displayLabel(),
style = MaterialTheme.typography.bodyMedium,
modifier = Modifier.weight(1f),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
SurfaceSecurityGlyph(kind = candidate.routeSecurityKind())
if (isActive) {
ActiveChip(stringResource(R.string.endpoints_active))
} else if (isPreferred) {
PreferredChip(stringResource(R.string.endpoints_preferred_chip))
} else {
FallbackChip(stringResource(R.string.endpoints_fallback))
Text(
text = routeTransportLabel(candidate),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
FlowRow(
modifier = Modifier.padding(top = 4.dp),
horizontalArrangement = Arrangement.spacedBy(6.dp),
verticalArrangement = Arrangement.spacedBy(4.dp),
) {
when {
isActive -> ActiveChip(stringResource(R.string.endpoints_active))
isPreferred -> PreferredChip(stringResource(R.string.endpoints_preferred_chip))
else -> FallbackChip(stringResource(R.string.endpoints_fallback))
}
if (!candidate.isKnownRole()) {
// Show the raw role for custom-VPN entries so users
// can tell "netbird-eu" from "wireguard-home" at a
// glance without poking into the menu.
if (!candidate.isKnownRole() && candidate.displayName.isNullOrBlank()) {
Text(
text = "(${candidate.role})",
text = candidate.role,
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
fontFamily = FontFamily.Monospace,
modifier = Modifier.padding(horizontal = 4.dp, vertical = 2.dp),
)
}
}
@@ -307,7 +347,7 @@ private fun EndpointRow(
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
outcome == null -> Unit // never probed — say nothing
outcome == null || outcome.isSupersededProbeFailure() -> Unit
outcome.reachable -> Text(
text = stringResource(R.string.endpoints_reachable),
style = MaterialTheme.typography.labelSmall,
@@ -484,6 +524,7 @@ private fun EndpointRow(
candidate = candidate,
dashboardAuthenticated = dashboardAuthenticated,
dashboardSignInRequired = dashboardSignInRequired,
outcomeFor = { surface -> surfaceOutcomeFor(candidate, surface) },
modifier = Modifier.padding(start = 26.dp, end = 4.dp, top = 8.dp),
)
}
@@ -536,13 +577,16 @@ private fun RouteSurfaceMap(
candidate: EndpointCandidate,
dashboardAuthenticated: Boolean? = null,
dashboardSignInRequired: Boolean = false,
outcomeFor: (EndpointSurface) -> RouteProbeOutcome? = { null },
modifier: Modifier = Modifier,
) {
val dashboardUrl = candidate.dashboard?.url
?: candidate.api?.url?.let(Connection::deriveDefaultDashboardUrl)
val apiUrl = candidate.api?.url
val relayUrl = candidate.relay?.url
val dashboardOutcome = outcomeFor(EndpointSurface.Dashboard)
val apiOutcome = outcomeFor(EndpointSurface.Api)
val relayOutcome = outcomeFor(EndpointSurface.Relay)
Surface(
color = MaterialTheme.colorScheme.surfaceVariant.copy(alpha = 0.42f),
shape = appearanceRoundedCornerShape(10.dp),
@@ -558,26 +602,28 @@ private fun RouteSurfaceMap(
status = when {
dashboardSignInRequired -> stringResource(R.string.active_section_sign_in_required)
dashboardAuthenticated == true -> stringResource(R.string.active_section_signed_in)
dashboardUrl != null -> stringResource(R.string.active_section_configured)
else -> stringResource(R.string.active_section_not_configured)
else -> routeSurfaceRuntimeStatus(dashboardUrl, dashboardOutcome)
},
warning = dashboardSignInRequired,
warning = dashboardSignInRequired || dashboardOutcome.isDefinitiveFailure(),
security = routeSurfaceSecurityPresentation(
candidate,
EndpointSurface.Dashboard,
dashboardUrl,
),
)
RouteSurfaceRow(
label = stringResource(R.string.active_section_api_server),
url = apiUrl,
status = stringResource(
if (apiUrl != null) R.string.active_section_configured
else R.string.active_section_not_configured,
),
status = routeSurfaceRuntimeStatus(apiUrl, apiOutcome),
warning = apiOutcome.isDefinitiveFailure(),
security = routeSurfaceSecurityPresentation(candidate, EndpointSurface.Api, apiUrl),
)
RouteSurfaceRow(
label = stringResource(R.string.active_section_relay),
url = relayUrl,
status = stringResource(
if (relayUrl != null) R.string.active_section_configured
else R.string.active_section_not_configured,
),
status = routeSurfaceRuntimeStatus(relayUrl, relayOutcome),
warning = relayOutcome.isDefinitiveFailure(),
security = routeSurfaceSecurityPresentation(candidate, EndpointSurface.Relay, relayUrl),
)
}
}
@@ -589,6 +635,7 @@ private fun RouteSurfaceRow(
url: String?,
status: String,
warning: Boolean = false,
security: RouteSurfaceSecurityPresentation = RouteSurfaceSecurityPresentation.NotConfigured,
) {
Row(
modifier = Modifier.fillMaxWidth(),
@@ -609,6 +656,31 @@ private fun RouteSurfaceRow(
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
if (security != RouteSurfaceSecurityPresentation.NotConfigured) {
Text(
text = when (security) {
RouteSurfaceSecurityPresentation.ApplicationTls ->
stringResource(R.string.endpoints_security_application_tls)
RouteSurfaceSecurityPresentation.TailscaleOverlay ->
stringResource(R.string.endpoints_security_tailscale_overlay)
RouteSurfaceSecurityPresentation.WireGuardOverlay ->
stringResource(R.string.endpoints_security_wireguard_overlay)
RouteSurfaceSecurityPresentation.SecureLink ->
stringResource(R.string.endpoints_security_secure_link)
RouteSurfaceSecurityPresentation.PrivatePlain ->
stringResource(R.string.endpoints_security_private_plain)
RouteSurfaceSecurityPresentation.PublicPlain ->
stringResource(R.string.endpoints_security_public_plain)
RouteSurfaceSecurityPresentation.NotConfigured -> ""
},
style = MaterialTheme.typography.labelSmall,
color = if (security == RouteSurfaceSecurityPresentation.PublicPlain) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
)
}
}
Text(
text = status,
@@ -700,26 +772,241 @@ private fun FallbackChip(label: String) {
/**
* Role → Material icon. Known roles get their canonical glyph; anything
* else falls through to [Icons.Filled.Shield] (generic "Custom VPN").
* else falls through to [Icons.Filled.Shield] (generic custom route).
*/
private fun roleIcon(role: String): ImageVector = when (role.lowercase()) {
"lan" -> Icons.Filled.Lan
"tailscale" -> Icons.Filled.VpnKey
"public" -> Icons.Filled.Public
"dashboard", "authenticated_dashboard", "https" -> Icons.Filled.Public
else -> Icons.Filled.Shield
}
@Composable
private fun routeSurfaceRuntimeStatus(
url: String?,
outcome: RouteProbeOutcome?,
): String = when (routeSurfaceProbePresentation(url, outcome)) {
RouteSurfaceProbePresentation.NotConfigured ->
stringResource(R.string.active_section_not_configured)
RouteSurfaceProbePresentation.NotChecked ->
stringResource(R.string.active_section_not_checked_separately)
RouteSurfaceProbePresentation.Reachable -> stringResource(R.string.endpoints_reachable)
RouteSurfaceProbePresentation.Unreachable -> stringResource(
R.string.endpoints_unreachable,
outcome?.detail ?: stringResource(R.string.endpoints_unreachable_no_detail),
)
}
internal enum class RouteSurfaceProbePresentation {
NotConfigured,
NotChecked,
Reachable,
Unreachable,
}
internal enum class RouteReachabilityPresentation {
Checking,
Reachable,
Unreachable,
NotChecked,
}
/** Honest selection context: a selected route is not proof of a fresh probe. */
internal fun routeReachabilityPresentation(
isProbing: Boolean,
outcome: RouteProbeOutcome?,
): RouteReachabilityPresentation = when {
isProbing -> RouteReachabilityPresentation.Checking
outcome == null || outcome.isSupersededProbeFailure() -> RouteReachabilityPresentation.NotChecked
outcome.reachable -> RouteReachabilityPresentation.Reachable
else -> RouteReachabilityPresentation.Unreachable
}
internal enum class RouteSurfaceSecurityPresentation {
ApplicationTls,
TailscaleOverlay,
WireGuardOverlay,
SecureLink,
PrivatePlain,
PublicPlain,
NotConfigured,
}
/**
* Per-route security classification for the picker glyph. Keyed on the
* candidate's own scheme + role (no device-level Tailscale detection needed —
* a `tailscale`/`plugin_proxy` role is encrypted regardless), so each row can
* be classified independently before it's the active route.
* Separates application TLS from private overlay encryption. An HTTP/WS
* Tailscale route is WireGuard-encrypted in transit, but it does not have
* application-layer TLS; public plaintext remains an error.
*/
private fun EndpointCandidate.routeSecurityKind(): SurfaceSecurityKind = when {
hasSecureProxy() -> SurfaceSecurityKind.Tls
isTlsUrl(primaryRouteUrl().orEmpty()) -> SurfaceSecurityKind.Tls
isEncryptedOverlayRoute(isTailscaleDetected = false) -> SurfaceSecurityKind.Overlay
else -> SurfaceSecurityKind.Plain
internal fun routeSurfaceSecurityPresentation(
candidate: EndpointCandidate,
surface: EndpointSurface,
url: String?,
): RouteSurfaceSecurityPresentation {
if (url.isNullOrBlank()) return RouteSurfaceSecurityPresentation.NotConfigured
val label = when (surface) {
EndpointSurface.Standard,
EndpointSurface.Dashboard -> "Dashboard & Gateway"
EndpointSurface.Api -> "API fallback"
EndpointSurface.Relay -> "Relay tools"
}
val securityVerdict = classifySurfaceSecurity(
label = label,
url = url,
activeEndpoint = candidate,
isTailscaleDetected = false,
)
val role = candidate.role.trim().lowercase()
return when (securityVerdict.kind) {
SurfaceSecurityKind.Tls -> when (securityVerdict.mechanism) {
"Hermes Secure Link", "Hermes Reach" -> RouteSurfaceSecurityPresentation.SecureLink
else -> RouteSurfaceSecurityPresentation.ApplicationTls
}
SurfaceSecurityKind.Overlay -> when (securityVerdict.mechanism) {
"Tailscale" -> RouteSurfaceSecurityPresentation.TailscaleOverlay
else -> RouteSurfaceSecurityPresentation.WireGuardOverlay
}
SurfaceSecurityKind.Plain -> if (role == "public" || role == "https") {
RouteSurfaceSecurityPresentation.PublicPlain
} else {
RouteSurfaceSecurityPresentation.PrivatePlain
}
}
}
internal fun routeSurfaceProbePresentation(
url: String?,
outcome: RouteProbeOutcome?,
): RouteSurfaceProbePresentation = when {
url == null -> RouteSurfaceProbePresentation.NotConfigured
outcome == null || outcome.isSupersededProbeFailure() -> RouteSurfaceProbePresentation.NotChecked
outcome.reachable -> RouteSurfaceProbePresentation.Reachable
else -> RouteSurfaceProbePresentation.Unreachable
}
private fun RouteProbeOutcome?.isDefinitiveFailure(): Boolean =
this != null && !reachable && !isSupersededProbeFailure()
/** A cancelled shared probe is unknown/checking state, never proof of outage. */
internal fun RouteProbeOutcome.isSupersededProbeFailure(): Boolean {
if (reachable) return false
val value = detail.orEmpty().lowercase()
return value.contains("interruptedioexception") ||
value.contains("canceled") ||
value.contains("cancelled") ||
value.contains("superseded")
}
/** Explicit HTTP/HTTPS route identity; security warnings stay surface-scoped. */
internal fun routeTransportLabel(candidate: EndpointCandidate): String {
val routeUrl = candidate.dashboard?.url
?: candidate.api?.url?.let(Connection::deriveDefaultDashboardUrl)
?: candidate.primaryRouteUrl()
return when (runCatching { URI(routeUrl.orEmpty()).scheme?.lowercase() }.getOrNull()) {
"https" -> "HTTPS"
"http" -> "HTTP"
"wss" -> "WSS"
"ws" -> "WS"
else -> "—"
}
}
/** Plain transport warnings belong to Relay, not to an allowed HTTP Gateway. */
internal fun EndpointCandidate.hasPlainRelayTransport(): Boolean {
val relayScheme = runCatching { URI(relay?.url.orEmpty()).scheme?.lowercase() }.getOrNull()
if (relayScheme !in setOf("ws", "http")) return false
val routeHint = security.orEmpty().lowercase()
return role.lowercase() != "tailscale" &&
!routeHint.contains("tailscale") &&
!routeHint.contains("wireguard")
}
/** First-class editor for the Dashboard/Gateway origin used by Manage, chat, sessions, and OIDC. */
@Composable
fun DashboardAddressEditorDialog(
initialUrl: String,
onSave: (dashboardUrl: String, onResult: (String?) -> Unit) -> Unit,
onDismiss: () -> Unit,
) {
var url by remember(initialUrl) { mutableStateOf(initialUrl) }
var errorText by remember { mutableStateOf<String?>(null) }
var saving by remember { mutableStateOf(false) }
val normalized = remember(url) {
url.takeIf { it.isNotBlank() }?.let(Connection::normalizeDashboardUrlInput).orEmpty()
}
val valid = remember(normalized) { isValidDashboardEditorAddress(normalized) }
AlertDialog(
onDismissRequest = { if (!saving) onDismiss() },
title = { Text(stringResource(R.string.dashboard_address_editor_title)) },
text = {
Column(verticalArrangement = Arrangement.spacedBy(12.dp)) {
Text(
text = stringResource(R.string.dashboard_address_editor_body),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
OutlinedTextField(
value = url,
onValueChange = {
url = it
errorText = null
},
label = { Text(stringResource(R.string.dashboard_address_label)) },
placeholder = { Text(stringResource(R.string.dashboard_address_placeholder)) },
singleLine = true,
keyboardOptions = KeyboardOptions(keyboardType = KeyboardType.Uri),
isError = errorText != null,
supportingText = {
Text(
text = errorText ?: if (url.isBlank()) {
stringResource(R.string.dashboard_address_required)
} else {
stringResource(R.string.dashboard_address_preview, normalized)
},
)
},
modifier = Modifier.fillMaxWidth(),
)
Text(
text = stringResource(R.string.dashboard_address_oidc_hint),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
},
confirmButton = {
TextButton(
enabled = valid && !saving && normalized != initialUrl.trim().trimEnd('/'),
onClick = {
saving = true
onSave(normalized) { error ->
saving = false
if (error == null) onDismiss() else errorText = error
}
},
) {
Text(
if (saving) stringResource(R.string.endpoints_saving)
else stringResource(R.string.endpoints_save),
)
}
},
dismissButton = {
TextButton(onClick = onDismiss, enabled = !saving) {
Text(stringResource(R.string.endpoints_cancel))
}
},
)
}
private fun isValidDashboardEditorAddress(address: String): Boolean {
val parsed = runCatching { URI(address) }.getOrNull() ?: return false
return parsed.scheme?.lowercase() in setOf("http", "https") &&
!parsed.host.isNullOrBlank() &&
parsed.userInfo == null &&
parsed.query == null &&
parsed.fragment == null
}
/**
@@ -737,6 +1024,7 @@ private fun EndpointCandidate.routeSecurityKind(): SurfaceSecurityKind = when {
* receives a user-facing error string to render inline, or null on
* success (the dialog then closes itself).
*/
@OptIn(ExperimentalLayoutApi::class)
@Composable
fun RouteEditorDialog(
original: EndpointCandidate?,
@@ -745,11 +1033,11 @@ fun RouteEditorDialog(
onDismiss: () -> Unit,
) {
val uriHandler = LocalUriHandler.current
val knownRoles = listOf("tailscale", "public")
val knownRoles = GATEWAY_ROUTE_EDITOR_ROLES
var selectedRole by remember {
mutableStateOf(
when (original?.role?.lowercase()) {
null -> "tailscale"
null -> "lan"
in knownRoles -> original.role.lowercase()
else -> CUSTOM_ROLE
},
@@ -760,7 +1048,7 @@ fun RouteEditorDialog(
original?.role?.takeIf { it.lowercase() !in knownRoles }.orEmpty(),
)
}
var url by remember(original) { mutableStateOf(original?.primaryRouteUrl().orEmpty()) }
var url by remember(original) { mutableStateOf(routeEditorInitialGatewayUrl(original)) }
var errorText by remember { mutableStateOf<String?>(null) }
var saving by remember { mutableStateOf(false) }
@@ -784,7 +1072,12 @@ fun RouteEditorDialog(
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Row(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
FlowRow(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
FilterChip(
selected = selectedRole == "lan",
onClick = { selectedRole = "lan" },
label = { Text(stringResource(R.string.cw_role_lan)) },
)
FilterChip(
selected = selectedRole == "tailscale",
onClick = { selectedRole = "tailscale" },
@@ -908,3 +1201,6 @@ private const val REMOTE_ACCESS_DOCS_URL =
"https://hermes-relay.dev/docs/guide/remote-access"
private const val CUSTOM_ROLE = "__custom__"
internal val GATEWAY_ROUTE_EDITOR_ROLES = listOf("lan", "tailscale", "public")
internal fun routeEditorInitialGatewayUrl(original: EndpointCandidate?): String =
original?.gatewayRouteUrl().orEmpty()
@@ -20,13 +20,17 @@ import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.AccountTree
import androidx.compose.material.icons.filled.CheckCircle
import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.ErrorOutline
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material.icons.filled.Refresh
import androidx.compose.material.icons.filled.PauseCircleOutline
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material.icons.filled.Terminal
import androidx.compose.material.icons.filled.Visibility
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.ExperimentalMaterial3Api
import androidx.compose.material3.HorizontalDivider
@@ -39,9 +43,13 @@ import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.material3.rememberModalBottomSheetState
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.derivedStateOf
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.snapshotFlow
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
@@ -49,6 +57,7 @@ import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.heading
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.semantics.stateDescription
import androidx.compose.ui.text.font.FontFamily
@@ -56,6 +65,10 @@ import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.network.upstream.GatewayProcess
import com.hermesandroid.relay.viewmodel.SubagentActivity
import com.hermesandroid.relay.viewmodel.SubagentActivityPhase
import com.hermesandroid.relay.viewmodel.SubagentChildPreview
import kotlinx.coroutines.launch
/**
* Composer-adjacent summary of upstream Hermes processes for the active chat.
@@ -63,8 +76,10 @@ import com.hermesandroid.relay.network.upstream.GatewayProcess
* in the global session/navigation drawer.
*/
@Composable
fun GatewayBackgroundProcessStrip(
internal fun GatewayBackgroundProcessStrip(
processes: List<GatewayProcess>,
subagentActivities: List<SubagentActivity>,
subagentPreviewVisibility: SubagentPreviewVisibility,
loading: Boolean,
onClick: () -> Unit,
modifier: Modifier = Modifier,
@@ -72,16 +87,26 @@ fun GatewayBackgroundProcessStrip(
// Initial/switch refreshes are silent. The strip appears only after the
// session actually owns a process, avoiding a transient "Checking" row on
// every ordinary chat open.
if (processes.isEmpty()) return
val visibleActivities = subagentActivities.takeIf { subagentPreviewVisibility.showLifecycle }.orEmpty()
if (processes.isEmpty() && visibleActivities.isEmpty()) return
val running = processes.count { it.isRunning }
val runningAgents = visibleActivities.count { !it.isTerminal }
val failed = processes.count { !it.isRunning && (it.exitCode ?: 0) != 0 }
val displayedCount = if (running > 0) running else processes.size
val failedAgents = visibleActivities.count { it.phase == SubagentActivityPhase.FAILED }
val interruptedAgents = visibleActivities.count {
it.phase == SubagentActivityPhase.INTERRUPTED ||
it.phase == SubagentActivityPhase.ENDED_WITH_PARENT
}
val failureCount = failed + failedAgents
val status = when {
runningAgents > 0 -> stringResource(R.string.subagent_lane_running_count, runningAgents)
running > 0 -> "$running ${stringResource(R.string.bg_processes_running)}"
failed > 0 -> "$failed ${stringResource(R.string.task_status_failed)}"
failureCount > 0 -> "$failureCount ${stringResource(R.string.task_status_failed)}"
interruptedAgents > 0 -> stringResource(R.string.agent_activity_status_interrupted)
else -> stringResource(R.string.task_status_complete)
}
val openDescription = stringResource(R.string.current_chat_activity_open)
Surface(
modifier = modifier
@@ -90,11 +115,11 @@ fun GatewayBackgroundProcessStrip(
.heightIn(min = 48.dp)
.semantics {
contentDescription =
"Background processes, $status. Open current chat activity."
"$openDescription, $status"
stateDescription = status
}
.clickable(
onClickLabel = stringResource(R.string.bg_processes_open),
onClickLabel = openDescription,
onClick = onClick,
),
shape = RoundedCornerShape(14.dp),
@@ -105,37 +130,41 @@ fun GatewayBackgroundProcessStrip(
modifier = Modifier.padding(horizontal = 12.dp, vertical = 9.dp),
verticalAlignment = Alignment.CenterVertically,
) {
if (running > 0 || loading) {
if (running > 0 || runningAgents > 0 || loading) {
CircularProgressIndicator(modifier = Modifier.size(16.dp), strokeWidth = 2.dp)
} else {
Icon(
imageVector = if (failed > 0) Icons.Filled.ErrorOutline else Icons.Filled.CheckCircle,
imageVector = when {
failureCount > 0 -> Icons.Filled.ErrorOutline
interruptedAgents > 0 -> Icons.Filled.PauseCircleOutline
else -> Icons.Filled.CheckCircle
},
contentDescription = null,
modifier = Modifier.size(17.dp),
tint = if (failed > 0) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.primary
tint = when {
failureCount > 0 -> MaterialTheme.colorScheme.error
interruptedAgents > 0 -> MaterialTheme.colorScheme.tertiary
else -> MaterialTheme.colorScheme.primary
},
)
}
Spacer(Modifier.width(9.dp))
Text(
text = stringResource(R.string.background_process_count, displayedCount),
text = stringResource(R.string.current_chat_activity_title),
style = MaterialTheme.typography.labelLarge,
modifier = Modifier.weight(1f),
)
Text(
text = status,
style = MaterialTheme.typography.labelMedium,
color = if (failed > 0 && running == 0) {
color = if (failureCount > 0 && running == 0) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
)
Icon(
imageVector = Icons.Filled.ExpandLess,
imageVector = Icons.Filled.Visibility,
contentDescription = null,
modifier = Modifier
.padding(start = 6.dp)
@@ -149,18 +178,56 @@ fun GatewayBackgroundProcessStrip(
/** Mobile analogue of Hermes Desktop's composer process stack + terminal viewer. */
@OptIn(ExperimentalMaterial3Api::class)
@Composable
fun GatewayBackgroundProcessSheet(
internal fun GatewayBackgroundProcessSheet(
processes: List<GatewayProcess>,
subagentActivities: List<SubagentActivity>,
subagentChildPreview: SubagentChildPreview?,
subagentPreviewVisibility: SubagentPreviewVisibility,
loading: Boolean,
stoppingProcessIds: Set<String>,
onRefresh: () -> Unit,
onStop: (String) -> Unit,
onDismissProcess: (String) -> Unit,
onOpenSubagentChild: (String) -> Unit,
onDismiss: () -> Unit,
) {
val sheetState = rememberModalBottomSheetState(skipPartiallyExpanded = false)
val listState = androidx.compose.foundation.lazy.rememberLazyListState()
val scope = rememberCoroutineScope()
var expandedAgentKeys by remember { mutableStateOf<Set<String>>(emptySet()) }
val running = processes.filter { it.isRunning }
val recent = processes.filterNot { it.isRunning }
val visibleActivities = subagentActivities.takeIf { subagentPreviewVisibility.showLifecycle }.orEmpty()
val followTarget = subagentActivityFollowTarget(
visibleActivities,
expandedAgentKeys,
subagentPreviewVisibility,
subagentChildPreview,
)
val activityRevision = visibleActivities.sumOf { it.revision } +
subagentChildPreview?.messages.orEmpty().sumOf { message ->
message.content.length + message.thinkingContent.length +
message.toolCalls.sumOf { (it.args?.length ?: 0) + it.name.length }
}
val nearActivityTail by remember(followTarget, listState) {
derivedStateOf {
val last = listState.layoutInfo.visibleItemsInfo.lastOrNull()?.index ?: 0
followTarget >= 0 && last in maxOf(0, followTarget - 2)..followTarget
}
}
var followAgentTail by remember { mutableStateOf(true) }
LaunchedEffect(listState, followTarget) {
snapshotFlow { listState.isScrollInProgress to nearActivityTail }.collect { (scrolling, nearTail) ->
if (scrolling) followAgentTail = nearTail
else if (nearTail) followAgentTail = true
}
}
LaunchedEffect(activityRevision, followTarget) {
if (followAgentTail && followTarget >= 0) {
listState.scrollToItem(followTarget)
}
}
ModalBottomSheet(
onDismissRequest = onDismiss,
@@ -178,23 +245,48 @@ fun GatewayBackgroundProcessSheet(
verticalAlignment = Alignment.CenterVertically,
) {
Column(modifier = Modifier.weight(1f)) {
Text(stringResource(R.string.background_processes_title), style = MaterialTheme.typography.titleLarge)
Text(
stringResource(R.string.background_processes_subtitle),
stringResource(R.string.current_chat_activity_title),
modifier = Modifier.semantics { heading() },
style = MaterialTheme.typography.titleLarge,
)
Text(
stringResource(R.string.current_chat_activity_subtitle),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
IconButton(onClick = onRefresh, enabled = !loading) {
if (processes.isNotEmpty()) IconButton(onClick = onRefresh, enabled = !loading) {
if (loading) {
CircularProgressIndicator(modifier = Modifier.size(20.dp), strokeWidth = 2.dp)
} else {
Icon(Icons.Filled.Refresh, contentDescription = stringResource(R.string.background_processes_refresh_a11y))
}
}
IconButton(onClick = onDismiss) {
Icon(
Icons.Filled.Close,
contentDescription = stringResource(R.string.current_chat_activity_close),
)
}
}
if (!followAgentTail && followTarget >= 0) {
Row(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 12.dp),
horizontalArrangement = Arrangement.End,
) {
TextButton(onClick = {
followAgentTail = true
scope.launch { listState.animateScrollToItem(followTarget) }
}) {
Text(stringResource(R.string.current_chat_activity_latest))
}
}
}
if (processes.isEmpty() && !loading) {
if (processes.isEmpty() && visibleActivities.isEmpty() && !loading) {
Column(
modifier = Modifier
.fillMaxWidth()
@@ -202,23 +294,47 @@ fun GatewayBackgroundProcessSheet(
horizontalAlignment = Alignment.CenterHorizontally,
) {
Icon(
Icons.Filled.Terminal,
Icons.Filled.AccountTree,
contentDescription = null,
modifier = Modifier.size(30.dp),
tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
stringResource(R.string.bg_processes_empty),
stringResource(R.string.current_chat_activity_empty),
modifier = Modifier.padding(top = 12.dp),
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
} else {
LazyColumn(
state = listState,
modifier = Modifier
.fillMaxWidth()
.heightIn(max = 560.dp),
) {
subagentActivityItems(
activities = visibleActivities,
expandedKeys = expandedAgentKeys,
visibility = subagentPreviewVisibility,
childPreview = subagentChildPreview,
onToggle = { key ->
expandedAgentKeys = if (key in expandedAgentKeys) {
expandedAgentKeys - key
} else {
expandedAgentKeys + key
}
},
onOpenChild = onOpenSubagentChild,
)
if (visibleActivities.isNotEmpty() && processes.isNotEmpty()) {
item { HorizontalDivider(modifier = Modifier.padding(vertical = 6.dp)) }
item {
ProcessSectionLabel(
stringResource(R.string.background_processes_title),
processes.size,
)
}
}
if (running.isNotEmpty()) {
item { ProcessSectionLabel(stringResource(R.string.bg_processes_running), running.size) }
items(running, key = { it.id }) { process ->
@@ -14,7 +14,6 @@ import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.ExperimentalLayoutApi
import androidx.compose.foundation.layout.FlowRow
import androidx.compose.foundation.layout.IntrinsicSize
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxHeight
@@ -25,6 +24,7 @@ import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.text.BasicTextField
import androidx.compose.foundation.text.KeyboardActions
import androidx.compose.foundation.text.KeyboardOptions
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.Send
@@ -71,6 +71,7 @@ import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.input.KeyboardType
import androidx.compose.ui.text.input.ImeAction
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.input.PasswordVisualTransformation
import androidx.compose.ui.text.input.VisualTransformation
@@ -172,26 +173,26 @@ fun HermesCardBubble(
),
shape = appearanceRoundedCornerShape(12.dp),
) {
Row(
modifier = Modifier
.fillMaxWidth()
.height(IntrinsicSize.Min),
) {
Box(modifier = Modifier.fillMaxWidth()) {
// Accent stripe — runs full card height so tall cards keep the
// color tie. Using the SAME tertiary accent strategy as the
// voice/phone-action bubble marker in MessageBubble.kt so the
// visual language stays consistent.
Box(
modifier = Modifier
.width(3.dp)
.fillMaxHeight()
.background(accentColor),
)
modifier = Modifier.matchParentSize(),
) {
Box(
modifier = Modifier
.width(3.dp)
.fillMaxHeight()
.background(accentColor),
)
}
Column(
modifier = Modifier
.fillMaxWidth()
.padding(12.dp),
.padding(start = 15.dp, top = 12.dp, end = 12.dp, bottom = 12.dp),
) {
// Header
Row(
@@ -426,6 +427,19 @@ private fun CardInputSlot(
input.kind != HermesCardInput.Kinds.CONFIRM)
)
val submitFreeText = {
val customAnswer = answerText.trim()
if (customAnswer.isNotEmpty()) {
onSubmit(
if (isMultiSelect) {
encodeClarifyMultiSelectAnswer(selectedChoices + customAnswer)
} else {
customAnswer
},
)
}
}
Column(modifier = Modifier.fillMaxWidth()) {
// Choice chips
if (input.choices.isNotEmpty()) {
@@ -515,11 +529,16 @@ private fun CardInputSlot(
InlineAnswerField(
value = answerText,
onValueChange = { answerText = it },
placeholder = stringResource(
if (input.choices.isNotEmpty()) R.string.card_other_answer_placeholder
else R.string.card_answer_placeholder,
),
onSubmit = submitFreeText,
modifier = Modifier.weight(1f),
)
if (!isMultiSelect) {
IconButton(
onClick = { onSubmit(answerText.trim()) },
onClick = submitFreeText,
enabled = answerText.isNotBlank(),
) {
Icon(
@@ -593,6 +612,8 @@ private fun CardInputSlot(
private fun InlineAnswerField(
value: String,
onValueChange: (String) -> Unit,
placeholder: String,
onSubmit: () -> Unit,
modifier: Modifier = Modifier,
) {
val shape = appearanceRoundedCornerShape(16.dp)
@@ -605,7 +626,7 @@ private fun InlineAnswerField(
) {
if (value.isEmpty()) {
Text(
text = stringResource(R.string.card_answer_placeholder),
text = placeholder,
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant.copy(alpha = 0.6f),
)
@@ -617,8 +638,12 @@ private fun InlineAnswerField(
color = MaterialTheme.colorScheme.onSurface,
),
cursorBrush = SolidColor(MaterialTheme.colorScheme.primary),
keyboardOptions = KeyboardOptions(imeAction = ImeAction.Send),
keyboardActions = KeyboardActions(onSend = { onSubmit() }),
maxLines = 3,
modifier = Modifier.fillMaxWidth(),
modifier = Modifier
.fillMaxWidth()
.semantics { contentDescription = placeholder },
)
}
}
@@ -57,6 +57,7 @@ import androidx.compose.ui.unit.IntSize
import androidx.annotation.RequiresApi
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ToolCall
import com.hermesandroid.relay.data.isImageGenerationToolName
import kotlinx.coroutines.delay
import kotlinx.coroutines.isActive
import java.util.Locale
@@ -65,7 +66,6 @@ import kotlin.math.cos
import kotlin.math.floor
import kotlin.math.sin
private const val IMAGE_GENERATION_TOOL = "image_generate"
private const val GRID_COLUMNS = 42
private const val GRID_ROWS = 24
private const val DEFAULT_ANIMATION_DURATION_MS = 4_800
@@ -134,11 +134,11 @@ internal fun resolveImageGenerationVisualStyle(
}
internal fun ToolCall.showsImageGenerationPlaceholder(): Boolean =
!isComplete && name.trim().lowercase() == IMAGE_GENERATION_TOOL
!isComplete && isImageGenerationToolName(name)
internal fun imageGenerationStartedAt(toolCalls: List<ToolCall>): Long? =
toolCalls.lastOrNull {
it.name.trim().lowercase() == IMAGE_GENERATION_TOOL
isImageGenerationToolName(it.name)
}?.startedAt
internal fun formatGenerationDuration(elapsedMillis: Long): String =
@@ -155,7 +155,7 @@ internal fun shouldShowImageGenerationPlaceholder(
hasMediaResult: Boolean,
): Boolean {
val imageCalls = toolCalls.filter {
it.name.trim().lowercase() == IMAGE_GENERATION_TOOL
isImageGenerationToolName(it.name)
}
if (imageCalls.any { !it.isComplete }) return true
return !hasMediaResult &&
@@ -83,6 +83,7 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.MediaSettingsRepository
import com.hermesandroid.relay.data.MessageDeliveryStatus
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.data.isImageGenerationToolName
import com.hermesandroid.relay.data.parseChatQuotedPrompt
import com.hermesandroid.relay.ui.components.pet.petObstacleSurface
import com.hermesandroid.relay.ui.components.pet.petPerchSurface
@@ -292,9 +293,7 @@ fun MessageBubble(
append(streamingStatusLabel ?: visibleMessageContent.take(100))
}
val hasImageGenerationCall = remember(message.toolCalls) {
message.toolCalls.any {
it.name.trim().lowercase() == "image_generate"
}
message.toolCalls.any { isImageGenerationToolName(it.name) }
}
val imageGenerationStartMillis = remember(message.toolCalls) {
imageGenerationStartedAt(message.toolCalls)
@@ -81,8 +81,11 @@ import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.Json
import java.util.concurrent.atomic.AtomicBoolean
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.doubleOrNull
import kotlinx.serialization.json.intOrNull
import kotlinx.serialization.json.jsonPrimitive
import java.net.URI
@@ -277,23 +280,52 @@ private val json = Json {
*/
fun parseHermesPairingQr(raw: String): HermesPairingPayload? {
val trimmed = raw.trim()
return parseHermesRelayQr(trimmed)
?: parseGenericApiJsonQr(trimmed)
parseHermesRelayQr(trimmed)?.let { return it }
// Structured Hermes payloads fail closed. Falling through to the generic
// parser would silently discard Relay credentials and route candidates.
if (looksLikeStructuredHermesPayload(trimmed)) return null
return parseGenericApiJsonQr(trimmed)
?: parseGenericDashboardJsonQr(trimmed)
?: parseGenericApiUrlQr(trimmed)
}
private fun looksLikeStructuredHermesPayload(raw: String): Boolean = runCatching {
val obj = json.decodeFromString<JsonObject>(raw)
obj.keys.any { it in setOf("hermes", "relay", "endpoints", "sig") }
}.getOrDefault(false)
private fun normalizeIntegralDuration(element: JsonElement): JsonElement {
val numeric = (element as? JsonPrimitive)?.doubleOrNull ?: return element
if (!numeric.isFinite() || numeric < 0 || numeric % 1.0 != 0.0) return element
if (numeric > Long.MAX_VALUE.toDouble()) return element
return JsonPrimitive(numeric.toLong())
}
/** Accept older Relay emitters that wrote whole seconds as JSON floats. */
private fun normalizeRelayDurationFields(obj: JsonObject): JsonObject {
val relay = obj["relay"] as? JsonObject ?: return obj
val normalizedRelay = relay.toMutableMap()
relay["ttl_seconds"]?.let {
normalizedRelay["ttl_seconds"] = normalizeIntegralDuration(it)
}
(relay["grants"] as? JsonObject)?.let { grants ->
normalizedRelay["grants"] = JsonObject(
grants.mapValues { (_, duration) -> normalizeIntegralDuration(duration) },
)
}
return JsonObject(obj.toMutableMap().apply {
put("relay", JsonObject(normalizedRelay))
})
}
private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
return try {
// Quick check: must contain a `host` field and be valid JSON. We no
// longer reject based on the `hermes` version int — future v4+ QRs
// should still parse so wire-format growth does not require an app
// release for every compatible payload version.
val obj = json.decodeFromString<JsonObject>(raw)
// Future compatible versions remain accepted. The legacy top-level
// API host is optional when Dashboard plus Relay identity is present.
val obj = normalizeRelayDurationFields(json.decodeFromString<JsonObject>(raw))
val version = obj["hermes"]?.jsonPrimitive?.intOrNull ?: 1
if (version < 1) return null
val decoded = json.decodeFromString<HermesPairingPayload>(raw)
if (decoded.host.isBlank()) return null
val decoded = json.decodeFromString<HermesPairingPayload>(obj.toString())
val dashboardAlias = firstString(obj, "dashboardUrl")
val decodedWithAliases =
if (decoded.dashboardUrl.isNullOrBlank() && dashboardAlias != null) {
@@ -301,6 +333,9 @@ private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
} else {
decoded
}
if (decodedWithAliases.host.isBlank() &&
!decodedWithAliases.hasDashboardRelayIdentity()
) return null
val normalizedKey = normalizeCredentialForHeader(
decodedWithAliases.key,
"API credential",
@@ -318,7 +353,13 @@ private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
// v3+ payloads with an explicit array pass through untouched.
if (decodedWithSafeCredential.endpoints.isNullOrEmpty()) {
decodedWithSafeCredential.copy(
endpoints = listOf(synthesizeLegacyEndpoint(decodedWithSafeCredential)),
endpoints = listOf(
if (decodedWithSafeCredential.hasApiServer) {
synthesizeLegacyEndpoint(decodedWithSafeCredential)
} else {
synthesizeDashboardRelayEndpoint(decodedWithSafeCredential)
},
),
)
} else {
decodedWithSafeCredential
@@ -328,6 +369,30 @@ private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
}
}
private fun HermesPairingPayload.hasDashboardRelayIdentity(): Boolean {
if (!hasUsableRelayPairing()) return false
val uri = dashboardUrl
?.trim()
?.let { runCatching { URI(it) }.getOrNull() }
?: return false
return uri.scheme?.lowercase() in setOf("http", "https") && !uri.host.isNullOrBlank()
}
private fun synthesizeDashboardRelayEndpoint(
payload: HermesPairingPayload,
): EndpointCandidate {
val dashboardUrl = requireNotNull(payload.dashboardUrl).trim().trimEnd('/')
return EndpointCandidate(
role = Connection.inferRouteRole(dashboardUrl),
priority = 0,
dashboard = DashboardEndpoint(dashboardUrl),
relay = RelayEndpoint(
url = requireNotNull(payload.relay).url,
transportHint = payload.relay.transportHint,
),
)
}
private fun parseGenericApiJsonQr(raw: String): HermesPairingPayload? {
return try {
val obj = json.decodeFromString<JsonObject>(raw)
@@ -82,6 +82,7 @@ import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.runtime.snapshotFlow
import androidx.lifecycle.Lifecycle
import androidx.lifecycle.compose.LocalLifecycleOwner
import androidx.lifecycle.repeatOnLifecycle
@@ -122,6 +123,8 @@ import java.text.SimpleDateFormat
import java.util.Date
import java.util.Locale
import kotlinx.coroutines.delay
import kotlinx.coroutines.flow.collect
import kotlinx.coroutines.flow.distinctUntilChanged
internal enum class SessionDrawerFilter {
All,
@@ -196,6 +199,12 @@ internal fun resolveSessionDrawerFilter(
else -> filter
}
internal enum class SessionDrawerLoadPresentation {
Loading,
Unavailable,
Content,
}
@Composable
fun SessionDrawerContent(
sessions: List<ChatSession>,
@@ -204,6 +213,10 @@ fun SessionDrawerContent(
scopeSubtitle: String? = null,
activeProfileName: String = "default",
isLoading: Boolean = false,
loadFailed: Boolean = false,
isLoadingMore: Boolean = false,
hasMore: Boolean = false,
loadMoreFailed: Boolean = false,
isOpen: Boolean = true,
activityStates: Map<String, SessionActivityState> = emptyMap(),
animationEnabled: Boolean = true,
@@ -212,6 +225,8 @@ fun SessionDrawerContent(
supervisedSessionActions: SupervisedSessionActions? = null,
newChatEnabled: Boolean = true,
onRefresh: (() -> Unit)? = null,
onLoadMore: (() -> Unit)? = null,
onRetryLoadMore: (() -> Unit)? = null,
/** Opens the separate Bot Mode messenger workspace; never changes drawer filters. */
onOpenBotMode: (() -> Unit)? = null,
onNewChat: () -> Unit,
@@ -236,6 +251,8 @@ fun SessionDrawerContent(
onNewThread: ((String) -> Unit)? = null,
provisionalThreads: List<ProvisionalThreadRow> = emptyList(),
onSelectProvisionalThread: ((String) -> Unit)? = null,
/** Deletes only the local provisional inbox row; never a server session. */
onDeleteProvisionalThread: ((String) -> Unit)? = null,
/** Gateway sources currently hidden from the drawer (default: cron+webhook). */
hiddenSources: Set<String> = emptySet(),
/** Toggle a source's visibility (persisted). Null hides the source filter. */
@@ -243,6 +260,7 @@ fun SessionDrawerContent(
allProfilesSupported: Boolean = false,
allProfileSessions: List<ProfileSessionRow> = emptyList(),
allProfileSessionsLoading: Boolean = false,
allProfileSessionsLoadFailed: Boolean = false,
profileColors: Map<String, String> = emptyMap(),
onProfileColorChange: ((String, String?) -> Unit)? = null,
onRefreshAllProfiles: (() -> Unit)? = null,
@@ -296,8 +314,10 @@ fun SessionDrawerContent(
val activeFilter = resolveSessionDrawerFilter(filter, showThreads, effectiveArchiveSupported)
// External gateway sources present (discord/telegram/cron/…) for the source
// filter dropdown. Own chats (tui/api_server) + phone Threads aren't listed.
val presentSources = sourceSessions
.mapNotNull { it.source?.trim()?.lowercase()?.takeIf { s -> s.isNotBlank() } }
val presentSources = (
sourceSessions.mapNotNull { it.source?.trim()?.lowercase()?.takeIf { s -> s.isNotBlank() } } +
hiddenSources
)
.distinct()
.filter { sourceBadge(it) != null }
.sorted()
@@ -335,6 +355,29 @@ fun SessionDrawerContent(
.toList()
val visibleRows = filterAndSortSessionRows(categoryRows, viewOptions, scopedActivityStates)
val groupedRows = groupSessionRows(visibleRows, viewOptions.grouping, scopedActivityStates)
LaunchedEffect(
listState,
isOpen,
showAllProfiles,
hasMore,
isLoadingMore,
loadMoreFailed,
visibleRows.size,
onLoadMore,
) {
if (!isOpen || showAllProfiles || !hasMore || loadMoreFailed || onLoadMore == null) {
return@LaunchedEffect
}
snapshotFlow {
val layout = listState.layoutInfo
val lastVisible = layout.visibleItemsInfo.lastOrNull()?.index ?: -1
layout.totalItemsCount > 0 && lastVisible >= layout.totalItemsCount - 5
}
.distinctUntilChanged()
.collect { nearEnd ->
if (nearEnd && !isLoadingMore) onLoadMore()
}
}
val drawerNowMillis = rememberDrawerClock(
isEnabled = isOpen && (
viewOptions.showUpdated || viewOptions.grouping == SessionDrawerGrouping.Project
@@ -685,16 +728,23 @@ fun SessionDrawerContent(
// Crossfade the loading→content transition so the list fades in rather
// than the spinner snapping straight to rows.
val loadPresentation = when {
showAllProfiles && allProfileSessionsLoading && allProfileSessions.isEmpty() ->
SessionDrawerLoadPresentation.Loading
!showAllProfiles && isLoading && sessions.isEmpty() ->
SessionDrawerLoadPresentation.Loading
showAllProfiles && allProfileSessionsLoadFailed && sourceRows.isEmpty() ->
SessionDrawerLoadPresentation.Unavailable
!showAllProfiles && loadFailed && sourceRows.isEmpty() ->
SessionDrawerLoadPresentation.Unavailable
else -> SessionDrawerLoadPresentation.Content
}
Crossfade(
targetState = if (showAllProfiles) {
allProfileSessionsLoading && allProfileSessions.isEmpty()
} else {
isLoading && sessions.isEmpty()
},
targetState = loadPresentation,
animationSpec = tween(220),
label = "drawerSessions",
) { loading ->
if (loading) {
) { presentation ->
if (presentation == SessionDrawerLoadPresentation.Loading) {
// First load (or a profile switch) — show a quiet spinner instead of
// flashing "No sessions yet" before the list arrives.
Column(
@@ -714,6 +764,26 @@ fun SessionDrawerContent(
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
} else if (presentation == SessionDrawerLoadPresentation.Unavailable) {
Column(
modifier = Modifier
.fillMaxWidth()
.padding(32.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(
text = stringResource(R.string.drawer_activity_unavailable),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
val refresh = if (showAllProfiles) onRefreshAllProfiles else onRefresh
refresh?.let {
TextButton(onClick = it) {
Text(stringResource(R.string.drawer_refresh_sessions))
}
}
}
} else if (visibleRows.isEmpty()) {
Column(
modifier = Modifier
@@ -737,6 +807,28 @@ fun SessionDrawerContent(
state = listState,
modifier = Modifier.testTag(SESSION_DRAWER_LIST_TAG),
) {
if (!showAllProfiles && loadFailed && sourceRows.isNotEmpty()) {
item(key = "sessions-stale") {
Row(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 12.dp, vertical = 6.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween,
) {
Text(
text = stringResource(R.string.drawer_activity_unavailable),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
onRefresh?.let { refresh ->
TextButton(onClick = refresh) {
Text(stringResource(R.string.drawer_refresh_sessions))
}
}
}
}
}
groupedRows.forEach { group ->
val isProjectGroup = viewOptions.grouping == SessionDrawerGrouping.Project
val expanded = !isProjectGroup || group.key in expandedProjectGroups
@@ -782,13 +874,17 @@ fun SessionDrawerContent(
showTokens = viewOptions.showTokens,
showCost = viewOptions.showCost,
nowMillis = drawerNowMillis,
actionsEnabled = !provisional && (
actionsEnabled = if (provisional) {
onDeleteProvisionalThread != null &&
supervisedSessionActions?.delete != false
} else {
supervisedSessionActions == null ||
supervisedSessionActions.pin ||
supervisedSessionActions.rename ||
supervisedSessionActions.delete ||
(supervisedSessionActions.archive && archiveSupported)
),
},
provisional = provisional,
isActive = !showAllProfiles && session.sessionId == currentSessionId,
activityState = activityState,
animationEnabled = animationEnabled && isOpen,
@@ -835,6 +931,32 @@ fun SessionDrawerContent(
)
}
}
if (!showAllProfiles && isLoadingMore) {
item(key = "sessions-loading-more") {
Box(
modifier = Modifier
.fillMaxWidth()
.padding(16.dp),
contentAlignment = Alignment.Center,
) {
CircularProgressIndicator(modifier = Modifier.size(22.dp))
}
}
}
if (!showAllProfiles && loadMoreFailed && onRetryLoadMore != null) {
item(key = "sessions-load-more-retry") {
Box(
modifier = Modifier
.fillMaxWidth()
.padding(8.dp),
contentAlignment = Alignment.Center,
) {
TextButton(onClick = onRetryLoadMore) {
Text(stringResource(R.string.chat_retry))
}
}
}
}
}
}
}
@@ -927,15 +1049,38 @@ fun SessionDrawerContent(
// Delete confirmation dialog
deleteDialogTarget?.let { (row, allProfiles) ->
val session = row.session
val provisional = session.sessionId.startsWith(PROVISIONAL_THREAD_PREFIX)
AlertDialog(
onDismissRequest = { deleteDialogTarget = null },
title = { Text(stringResource(R.string.drawer_delete_session_title)) },
title = {
Text(
stringResource(
if (provisional) {
R.string.drawer_remove_provisional_thread_title
} else {
R.string.drawer_delete_session_title
},
),
)
},
text = {
Text(stringResource(R.string.drawer_delete_session_prefix) + (session.title ?: stringResource(R.string.drawer_untitled)) + stringResource(R.string.drawer_delete_session_suffix))
val title = session.title ?: stringResource(R.string.drawer_untitled)
Text(
if (provisional) {
stringResource(R.string.drawer_remove_provisional_thread_message, title)
} else {
stringResource(R.string.drawer_delete_session_prefix) + title +
stringResource(R.string.drawer_delete_session_suffix)
},
)
},
confirmButton = {
TextButton(onClick = {
if (allProfiles) {
if (session.sessionId.startsWith(PROVISIONAL_THREAD_PREFIX)) {
onDeleteProvisionalThread?.invoke(
session.sessionId.removePrefix(PROVISIONAL_THREAD_PREFIX),
)
} else if (allProfiles) {
onDeleteProfileSession?.invoke(row.profile, session.sessionId)
} else {
onDeleteSession(session.sessionId)
@@ -1351,6 +1496,7 @@ private fun SessionItem(
showCost: Boolean,
nowMillis: Long,
actionsEnabled: Boolean,
provisional: Boolean,
isActive: Boolean,
activityState: SessionActivityState?,
animationEnabled: Boolean,
@@ -1521,7 +1667,7 @@ private fun SessionItem(
expanded = menuOpen,
onDismissRequest = { menuOpen = false },
) {
if (supervisedSessionActions?.pin != false) DropdownMenuItem(
if (!provisional && supervisedSessionActions?.pin != false) DropdownMenuItem(
text = {
Text(
if (pinned) {
@@ -1547,7 +1693,7 @@ private fun SessionItem(
onTogglePinned()
},
)
if (supervisedSessionActions == null) DropdownMenuItem(
if (!provisional && supervisedSessionActions == null) DropdownMenuItem(
text = { Text(stringResource(R.string.chat_copy_session_id)) },
leadingIcon = {
Icon(Icons.Filled.ContentCopy, contentDescription = null)
@@ -1557,7 +1703,7 @@ private fun SessionItem(
onCopySessionId()
},
)
if (supervisedSessionActions?.rename != false) DropdownMenuItem(
if (!provisional && supervisedSessionActions?.rename != false) DropdownMenuItem(
text = { Text(stringResource(R.string.drawer_rename)) },
leadingIcon = {
Icon(Icons.Filled.Edit, contentDescription = null)
@@ -1567,7 +1713,7 @@ private fun SessionItem(
onRename()
},
)
if (archiveSupported && supervisedSessionActions?.archive != false) {
if (!provisional && archiveSupported && supervisedSessionActions?.archive != false) {
DropdownMenuItem(
text = { Text(if (archived) stringResource(R.string.drawer_restore) else stringResource(R.string.drawer_archive)) },
leadingIcon = {
@@ -0,0 +1,440 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.lazy.LazyListScope
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.AccountTree
import androidx.compose.material.icons.filled.CheckCircle
import androidx.compose.material.icons.filled.ErrorOutline
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material.icons.filled.HourglassTop
import androidx.compose.material.icons.filled.PauseCircleOutline
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.semantics.stateDescription
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ChatMessage
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.viewmodel.SubagentChildPreview
import com.hermesandroid.relay.viewmodel.SubagentActivity
import com.hermesandroid.relay.viewmodel.SubagentActivityEvent
import com.hermesandroid.relay.viewmodel.SubagentActivityEventKind
import com.hermesandroid.relay.viewmodel.SubagentActivityPhase
internal data class SubagentPreviewVisibility(
val showLifecycle: Boolean = true,
val showReasoning: Boolean = true,
val showToolNames: Boolean = true,
val showToolDetails: Boolean = true,
val showChildHistory: Boolean = true,
)
internal fun LazyListScope.subagentActivityItems(
activities: List<SubagentActivity>,
expandedKeys: Set<String>,
visibility: SubagentPreviewVisibility,
childPreview: SubagentChildPreview?,
onToggle: (String) -> Unit,
onOpenChild: (String) -> Unit,
) {
if (activities.isEmpty() || !visibility.showLifecycle) return
item(key = "subagent-section") {
Column(modifier = Modifier.padding(horizontal = 20.dp, vertical = 8.dp)) {
Text(
stringResource(R.string.agent_activity_section),
style = MaterialTheme.typography.labelLarge,
)
Text(
stringResource(R.string.agent_activity_disclosure),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
activities.forEach { activity ->
val key = activity.stableKey
item(key = "subagent-header-$key") {
SubagentActivityHeader(
activity = activity,
expanded = key in expandedKeys,
visibility = visibility,
onClick = {
if (key !in expandedKeys && visibility.showChildHistory) onOpenChild(key)
onToggle(key)
},
)
}
if (key in expandedKeys) {
if (activity.truncated) {
item(key = "subagent-truncated-$key") {
SubagentMetaRow(stringResource(R.string.agent_activity_older_omitted))
}
}
activity.events.forEach { event ->
item(key = "subagent-event-$key-${event.sequence}") {
SubagentEventRow(event, visibility)
}
}
if (activity.partialAfterGap) {
item(key = "subagent-gap-$key") {
SubagentMetaRow(stringResource(R.string.agent_activity_partial))
}
}
childPreview?.takeIf { visibility.showChildHistory && it.activityKey == key }?.let { preview ->
when (preview.childWatchAvailable) {
null -> item(key = "subagent-child-loading-$key") {
SubagentMetaRow(stringResource(R.string.agent_activity_child_loading))
}
false -> item(key = "subagent-child-unavailable-$key") {
SubagentMetaRow(
preview.error?.takeIf(String::isNotBlank)
?: stringResource(R.string.agent_activity_child_unavailable),
)
}
true -> {
item(key = "subagent-child-heading-$key") {
SubagentMetaRow(
if (preview.running) {
stringResource(R.string.agent_activity_child_live)
} else {
stringResource(R.string.agent_activity_child_history)
},
)
}
if (preview.historyTruncated) {
item(key = "subagent-child-truncated-$key") {
SubagentMetaRow(stringResource(R.string.agent_activity_child_truncated))
}
}
preview.messages.filterNot { it.role == MessageRole.SYSTEM }.forEach { message ->
item(key = "subagent-child-message-$key-${message.uiKey}") {
SubagentChildMessageRow(message, visibility)
}
}
preview.error?.takeIf(String::isNotBlank)?.let { error ->
item(key = "subagent-child-error-$key") { SubagentMetaRow(error) }
}
}
}
item(key = "subagent-child-tail-$key") {
Spacer(Modifier.height(1.dp))
}
}
}
}
}
internal fun subagentActivityItemCount(
activities: List<SubagentActivity>,
expandedKeys: Set<String>,
visibility: SubagentPreviewVisibility,
childPreview: SubagentChildPreview?,
): Int {
if (activities.isEmpty() || !visibility.showLifecycle) return 0
return 1 + activities.sumOf { activity ->
val expanded = activity.stableKey in expandedKeys
val preview = childPreview?.takeIf {
visibility.showChildHistory && it.activityKey == activity.stableKey
}
val previewRows = when (preview?.childWatchAvailable) {
null -> if (preview != null) 1 else 0
false -> 1
true -> 1 + preview.messages.count { it.role != MessageRole.SYSTEM } +
(if (preview.historyTruncated) 1 else 0) +
(if (preview.error.isNullOrBlank()) 0 else 1)
} + if (preview != null) 1 else 0 // explicit bottom anchor for growing rows
1 + if (!expanded) 0 else activity.events.size +
(if (activity.truncated) 1 else 0) +
(if (activity.partialAfterGap) 1 else 0) + previewRows
}
}
internal fun subagentActivityFollowTarget(
activities: List<SubagentActivity>,
expandedKeys: Set<String>,
visibility: SubagentPreviewVisibility,
childPreview: SubagentChildPreview?,
): Int {
if (activities.isEmpty() || !visibility.showLifecycle) return -1
var index = 0 // section heading
var selectedTarget = -1
activities.forEach { activity ->
index += 1 // lane header
if (activity.stableKey in expandedKeys) {
if (activity.truncated) index += 1
index += activity.events.size
if (activity.partialAfterGap) index += 1
if (visibility.showChildHistory && childPreview?.activityKey == activity.stableKey) {
index += when (childPreview.childWatchAvailable) {
null, false -> 1
true -> 1 + childPreview.messages.count { it.role != MessageRole.SYSTEM } +
(if (childPreview.historyTruncated) 1 else 0) +
(if (childPreview.error.isNullOrBlank()) 0 else 1)
}
index += 1 // explicit bottom anchor for growing child content
selectedTarget = index
}
}
}
return if (selectedTarget >= 0) selectedTarget else index
}
@Composable
private fun SubagentActivityHeader(
activity: SubagentActivity,
expanded: Boolean,
visibility: SubagentPreviewVisibility,
onClick: () -> Unit,
) {
val title = activity.goal.takeIf { visibility.showReasoning && it.isNotBlank() }
?: stringResource(R.string.agent_activity_fallback, activity.taskIndex + 1)
val phaseLabel = phaseLabel(activity.phase)
val description = stringResource(
R.string.agent_activity_lane_a11y,
title,
phaseLabel,
activity.taskIndex + 1,
activity.taskCount,
)
val icon: ImageVector = when (activity.phase) {
SubagentActivityPhase.COMPLETED -> Icons.Filled.CheckCircle
SubagentActivityPhase.FAILED -> Icons.Filled.ErrorOutline
SubagentActivityPhase.INTERRUPTED,
SubagentActivityPhase.ENDED_WITH_PARENT,
-> Icons.Filled.PauseCircleOutline
SubagentActivityPhase.STARTED,
SubagentActivityPhase.THINKING,
SubagentActivityPhase.TOOL,
SubagentActivityPhase.PROGRESS,
-> Icons.Filled.HourglassTop
}
val tint = when (activity.phase) {
SubagentActivityPhase.FAILED -> MaterialTheme.colorScheme.error
SubagentActivityPhase.COMPLETED -> MaterialTheme.colorScheme.primary
else -> MaterialTheme.colorScheme.tertiary
}
Surface(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 16.dp, vertical = 3.dp)
.heightIn(min = 48.dp)
.semantics {
contentDescription = description
stateDescription = phaseLabel
liveRegion = LiveRegionMode.Polite
}
.clickable(onClick = onClick),
shape = MaterialTheme.shapes.medium,
color = MaterialTheme.colorScheme.surfaceVariant.copy(alpha = 0.5f),
) {
Row(
modifier = Modifier.padding(horizontal = 12.dp, vertical = 9.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(icon, contentDescription = null, tint = tint, modifier = Modifier.size(18.dp))
Spacer(Modifier.width(9.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
title,
style = MaterialTheme.typography.labelLarge,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
Text(
stringResource(
R.string.agent_activity_task_position,
activity.taskIndex + 1,
activity.taskCount,
phaseLabel,
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
activity.durationSeconds?.takeIf { activity.isTerminal }?.let { seconds ->
Text(
stringResource(R.string.agent_activity_duration, seconds),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Spacer(Modifier.width(6.dp))
}
Icon(
if (expanded) Icons.Filled.ExpandLess else Icons.Filled.ExpandMore,
contentDescription = stringResource(
if (expanded) R.string.cd_subagent_collapse else R.string.cd_subagent_expand,
),
)
}
}
}
@Composable
private fun SubagentEventRow(
event: SubagentActivityEvent,
visibility: SubagentPreviewVisibility,
) {
val label = when (event.kind) {
SubagentActivityEventKind.STARTED -> stringResource(R.string.agent_activity_event_started)
SubagentActivityEventKind.UPDATE -> stringResource(R.string.agent_activity_event_update)
SubagentActivityEventKind.TOOL -> stringResource(R.string.agent_activity_event_tool)
SubagentActivityEventKind.COMPLETED -> phaseLabel(event.phase)
}
val showText = when (event.kind) {
SubagentActivityEventKind.STARTED -> false
SubagentActivityEventKind.UPDATE,
SubagentActivityEventKind.COMPLETED,
-> visibility.showReasoning
SubagentActivityEventKind.TOOL -> visibility.showToolDetails
}
val toolName = event.toolName?.takeIf { visibility.showToolNames || visibility.showToolDetails }
Column(
modifier = Modifier
.fillMaxWidth()
.padding(start = 38.dp, end = 20.dp, top = 5.dp, bottom = 5.dp),
) {
Row(verticalAlignment = Alignment.CenterVertically) {
Icon(
Icons.Filled.AccountTree,
contentDescription = null,
modifier = Modifier.size(14.dp),
tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
Spacer(Modifier.width(6.dp))
Text(label, style = MaterialTheme.typography.labelSmall)
toolName?.let {
Text(
" · $it",
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
event.text?.takeIf { showText && it.isNotBlank() }?.let { text ->
Text(
text,
modifier = Modifier.padding(top = 3.dp),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
fontFamily = if (event.kind == SubagentActivityEventKind.TOOL) {
FontFamily.Monospace
} else {
FontFamily.Default
},
maxLines = 8,
overflow = TextOverflow.Ellipsis,
)
}
}
}
@Composable
private fun SubagentMetaRow(text: String) {
Text(
text,
modifier = Modifier.padding(start = 38.dp, end = 20.dp, top = 4.dp, bottom = 6.dp),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
@Composable
private fun SubagentChildMessageRow(
message: ChatMessage,
visibility: SubagentPreviewVisibility,
) {
if (message.role == MessageRole.SYSTEM) return
val role = when (message.role) {
MessageRole.USER -> stringResource(R.string.agent_activity_child_role_task)
MessageRole.ASSISTANT -> stringResource(R.string.agent_activity_child_role_agent)
MessageRole.SYSTEM -> stringResource(R.string.agent_activity_child_role_system)
}
Column(
modifier = Modifier
.fillMaxWidth()
.padding(start = 38.dp, end = 20.dp, top = 6.dp, bottom = 6.dp),
) {
Text(
role,
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
message.thinkingContent.takeIf { visibility.showReasoning && it.isNotBlank() }?.let { thought ->
Text(
thought,
modifier = Modifier.padding(top = 3.dp),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 10,
overflow = TextOverflow.Ellipsis,
)
}
message.content.takeIf(String::isNotBlank)?.let { content ->
Text(
content,
modifier = Modifier.padding(top = 3.dp),
style = MaterialTheme.typography.bodyMedium,
maxLines = 20,
overflow = TextOverflow.Ellipsis,
)
}
if (visibility.showToolNames || visibility.showToolDetails) {
message.toolCalls.forEach { tool ->
Text(
buildString {
append(tool.name)
if (visibility.showToolDetails) {
tool.args?.takeIf(String::isNotBlank)?.let { append(" · ").append(it.take(500)) }
}
},
modifier = Modifier.padding(top = 3.dp),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
fontFamily = FontFamily.Monospace,
maxLines = 5,
overflow = TextOverflow.Ellipsis,
)
}
}
}
}
@Composable
private fun phaseLabel(phase: SubagentActivityPhase): String = stringResource(
when (phase) {
SubagentActivityPhase.STARTED -> R.string.agent_activity_status_started
SubagentActivityPhase.THINKING -> R.string.agent_activity_status_thinking
SubagentActivityPhase.TOOL -> R.string.agent_activity_status_tool
SubagentActivityPhase.PROGRESS -> R.string.agent_activity_status_progress
SubagentActivityPhase.COMPLETED -> R.string.agent_activity_status_completed
SubagentActivityPhase.FAILED -> R.string.agent_activity_status_failed
SubagentActivityPhase.INTERRUPTED -> R.string.agent_activity_status_interrupted
SubagentActivityPhase.ENDED_WITH_PARENT -> R.string.agent_activity_status_unavailable
},
)
@@ -31,23 +31,54 @@ import androidx.compose.ui.unit.sp
import androidx.compose.ui.window.Dialog
import androidx.compose.ui.window.DialogProperties
import com.hermesandroid.relay.R
import com.hermesandroid.relay.diagnostics.DiagnosticLogEntry
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
import com.hermesandroid.relay.reliability.ReliabilityEnvironment
import com.hermesandroid.relay.reliability.ReliabilityRedactor
import com.hermesandroid.relay.ui.theme.appearanceRoundedCornerShape
import com.hermesandroid.relay.reliability.ReliabilityReport
import com.hermesandroid.relay.reliability.SupportBundleBuilder
import com.hermesandroid.relay.util.IssueReport
data class SupportReviewState(
val reportCount: Int,
val recordCount: Int,
val text: String,
val shareEnabled: Boolean,
)
internal fun buildSupportReviewState(reports: List<ReliabilityReport>): SupportReviewState =
SupportReviewState(
reportCount = reports.takeLast(SupportBundleBuilder.MAX_REPORTS).size,
text = SupportBundleBuilder.build(reports),
shareEnabled = reports.isNotEmpty(),
internal fun buildSupportReviewState(
reports: List<ReliabilityReport>,
diagnostics: List<DiagnosticLogEntry> = emptyList(),
environment: ReliabilityEnvironment? = reports.lastOrNull()?.environment,
): SupportReviewState {
val reportCount = reports.takeLast(SupportBundleBuilder.MAX_REPORTS).size
val diagnosticCount = diagnostics.takeLast(DiagnosticsLog.SUPPORT_ENTRY_LIMIT).size
val diagnosticText = DiagnosticsLog.supportText(diagnostics)
val combined = buildString {
append(SupportBundleBuilder.build(reports))
environment?.let {
appendLine()
appendLine()
appendLine("Current environment")
appendLine("App: ${it.versionName} (code ${it.versionCode}) ${it.flavor}")
append(
"Device: ${it.manufacturer} ${it.model} — " +
"Android ${it.androidRelease} (SDK ${it.sdkInt})",
)
}
if (diagnosticText.isNotBlank()) {
appendLine()
appendLine()
append(diagnosticText)
}
}
val recordCount = reportCount + diagnosticCount
return SupportReviewState(
recordCount = recordCount,
text = ReliabilityRedactor.redact(combined, 64_000),
shareEnabled = recordCount > 0,
)
}
/** Exact review surface for the local text handed to clipboard/share. */
@Composable
@@ -70,7 +101,7 @@ fun SupportBundleDialog(state: SupportReviewState, onDismiss: () -> Unit) {
Text(stringResource(R.string.support_bundle_title), style = MaterialTheme.typography.titleMedium)
Spacer(Modifier.height(6.dp))
Text(
stringResource(R.string.support_bundle_privacy, state.reportCount),
stringResource(R.string.support_bundle_privacy, state.recordCount),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
@@ -43,6 +43,7 @@ import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.ToolCall
import com.hermesandroid.relay.data.isImageGenerationToolName
import com.hermesandroid.relay.ui.components.pet.petObstacleSurface
private val TOOL_ACTIVITY_PET_ROUTES = setOf("chat")
@@ -101,7 +102,8 @@ internal fun ToolCall.requiresStandaloneToolSurface(): Boolean {
!error.isNullOrBlank() ||
outputRisk != null ||
normalized in FILE_EDIT_TOOLS ||
normalized in ATTENTION_TOOLS
normalized in ATTENTION_TOOLS ||
isImageGenerationToolName(name)
}
internal data class ToolActivityCounts(
@@ -15,6 +15,7 @@ import androidx.compose.animation.fadeOut
import androidx.compose.animation.togetherWith
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.focusable
import androidx.compose.foundation.gestures.awaitEachGesture
import androidx.compose.foundation.gestures.awaitFirstDown
import androidx.compose.foundation.layout.Arrangement
@@ -63,13 +64,20 @@ import androidx.compose.runtime.rememberUpdatedState
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.composed
import androidx.compose.ui.draw.clip
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.hapticfeedback.HapticFeedbackType
import androidx.compose.ui.input.key.onPreviewKeyEvent
import androidx.compose.ui.input.pointer.pointerInput
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.platform.LocalHapticFeedback
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.onClick
import androidx.compose.ui.semantics.role
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.text.style.TextOverflow
@@ -103,6 +111,8 @@ import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.R
import com.hermesandroid.relay.ui.theme.appearanceRoundedCornerShape
internal const val VOICE_MODE_MIC_TEST_TAG = "voiceModeMic"
/**
* Full-screen voice-mode overlay. Renders the MorphingSphere in its voiceMode
* expanded state plus a mic button that drives the [VoiceViewModel] turn
@@ -152,6 +162,7 @@ fun VoiceModeOverlay(
voiceOutputEnabled: Boolean? = null,
voiceOutputFallbackEnabled: Boolean? = null,
onOverlayRequest: () -> Unit = {},
systemOverlayAvailable: Boolean = true,
presentationMode: VoicePresentationMode = VoicePresentationMode.Focus,
onPresentationModeChange: (VoicePresentationMode) -> Unit = {},
// === END PHASE3-voice-mode-transcript ===
@@ -238,6 +249,7 @@ fun VoiceModeOverlay(
onInterrupt = onInterrupt,
onPauseAutoMode = onPauseAutoMode,
onOverlayRequest = onOverlayRequest,
systemOverlayAvailable = systemOverlayAvailable,
onOpenSettings = onOpenSettings,
onExit = onDismiss,
modifier = Modifier
@@ -622,6 +634,22 @@ private fun VoiceMicButton(
) {
if (!visible) return
val micActionDescription = when (uiState.state) {
VoiceState.Idle, VoiceState.Error -> stringResource(R.string.voice_overlay_tap_action_idle)
VoiceState.Listening ->
if (uiState.interactionMode == InteractionMode.Continuous) {
stringResource(R.string.voice_overlay_tap_action_pause)
} else {
stringResource(R.string.voice_overlay_tap_action_listening)
}
VoiceState.Transcribing, VoiceState.Thinking, VoiceState.Speaking ->
if (uiState.interactionMode == InteractionMode.Continuous) {
stringResource(R.string.voice_overlay_tap_action_pause)
} else {
stringResource(R.string.voice_overlay_tap_action_interrupt)
}
}
val pulseScale by animateFloatAsState(
targetValue = when (uiState.state) {
VoiceState.Listening -> 1f + uiState.amplitude * 0.15f
@@ -656,34 +684,22 @@ private fun VoiceMicButton(
else -> Icons.Filled.Mic
}
val currentOnTap by rememberUpdatedState(onTap)
val currentOnHoldPress by rememberUpdatedState(onHoldPress)
val currentOnHoldRelease by rememberUpdatedState(onHoldRelease)
val gestureModifier = when (uiState.interactionMode) {
InteractionMode.HoldToTalk -> Modifier.pointerInput(Unit) {
awaitEachGesture {
awaitFirstDown(requireUnconsumed = false)
currentOnHoldPress()
// Hold until the finger genuinely lifts. Don't use
// waitForUpOrCancellation(): it ends the hold on ANY cancel — a
// consumed move event or the finger drifting just off the small
// circle — which made the button feel like it released by
// accident. Loop until no pointer is still pressed so drift and
// minor consumption don't cut the recording short.
do {
val event = awaitPointerEvent()
} while (event.changes.any { it.pressed })
currentOnHoldRelease()
}
}
else -> Modifier.clickable { currentOnTap() }
InteractionMode.HoldToTalk -> Modifier.voiceHoldGesture(
state = uiState.state,
inactiveActionLabel = micActionDescription,
activeActionLabel = stringResource(R.string.voice_overlay_tap_action_listening),
onPress = onHoldPress,
onRelease = onHoldRelease,
)
else -> Modifier.clickable(onClick = onTap)
}
Surface(
modifier = modifier
.size((baseSize * pulseScale).dp)
.clip(CircleShape)
.testTag(VOICE_MODE_MIC_TEST_TAG)
.then(gestureModifier),
shape = CircleShape,
color = containerColor,
@@ -692,7 +708,11 @@ private fun VoiceMicButton(
Box(contentAlignment = Alignment.Center) {
Icon(
imageVector = icon,
contentDescription = stringResource(R.string.voice_overlay_mic_cd),
contentDescription = if (uiState.interactionMode == InteractionMode.HoldToTalk) {
null
} else {
micActionDescription
},
tint = Color.White,
modifier = Modifier.size(iconSize.dp),
)
@@ -700,6 +720,96 @@ private fun VoiceMicButton(
}
}
/**
* Shared Hold-to-talk gesture for in-app and system-overlay voice controls.
* The callback refs update across recomposition without restarting the active
* gesture when its press changes VoiceUiState to Listening.
*/
internal fun Modifier.voiceHoldGesture(
state: VoiceState,
inactiveActionLabel: String,
activeActionLabel: String,
onPress: () -> Unit,
onRelease: () -> Unit,
inactiveContentDescription: String = inactiveActionLabel,
activeContentDescription: String = activeActionLabel,
): Modifier = composed {
val currentOnPress by rememberUpdatedState(onPress)
val currentOnRelease by rememberUpdatedState(onRelease)
var semanticHoldActive by remember { mutableStateOf(state == VoiceState.Listening) }
var semanticCaptureStarted by remember { mutableStateOf(state == VoiceState.Listening) }
LaunchedEffect(state) {
when {
state == VoiceState.Listening -> {
semanticHoldActive = true
semanticCaptureStarted = true
}
semanticCaptureStarted -> {
semanticHoldActive = false
semanticCaptureStarted = false
}
state == VoiceState.Error -> semanticHoldActive = false
}
}
val semanticToggle = {
if (semanticHoldActive) {
semanticHoldActive = false
semanticCaptureStarted = false
currentOnRelease()
} else {
semanticHoldActive = true
currentOnPress()
}
}
Modifier
.semantics(mergeDescendants = true) {
role = Role.Button
contentDescription = if (semanticHoldActive) {
activeContentDescription
} else {
inactiveContentDescription
}
onClick(
label = if (semanticHoldActive) activeActionLabel else inactiveActionLabel,
) {
semanticToggle()
true
}
}
.onPreviewKeyEvent { event ->
val native = event.nativeKeyEvent
val activationKey = native.keyCode == android.view.KeyEvent.KEYCODE_ENTER ||
native.keyCode == android.view.KeyEvent.KEYCODE_NUMPAD_ENTER ||
native.keyCode == android.view.KeyEvent.KEYCODE_SPACE ||
native.keyCode == android.view.KeyEvent.KEYCODE_DPAD_CENTER
if (native.action == android.view.KeyEvent.ACTION_UP && activationKey) {
semanticToggle()
true
} else {
false
}
}
.focusable()
.pointerInput(Unit) {
awaitEachGesture {
awaitFirstDown(requireUnconsumed = false)
currentOnPress()
// Hold until the finger genuinely lifts. Don't use
// waitForUpOrCancellation(): it ends the hold on ANY cancel — a
// consumed move event or the finger drifting just off the small
// circle — which made the button feel like it released by
// accident. Loop until no pointer is still pressed so drift and
// minor consumption don't cut the recording short.
do {
val event = awaitPointerEvent()
} while (event.changes.any { it.pressed })
currentOnRelease()
}
}
}
private fun voiceStateToSphereState(state: VoiceState): SphereState = when (state) {
VoiceState.Listening -> SphereState.Listening
VoiceState.Speaking -> SphereState.Speaking
@@ -773,6 +883,7 @@ fun ConversationVoiceDock(
onOverlayRequest: () -> Unit,
onOpenSettings: () -> Unit,
onExit: () -> Unit,
systemOverlayAvailable: Boolean = true,
modifier: Modifier = Modifier,
) {
var expanded by remember { mutableStateOf(false) }
@@ -816,17 +927,19 @@ fun ConversationVoiceDock(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
TextButton(
onClick = onOverlayRequest,
modifier = Modifier
.weight(1f)
.height(40.dp),
) {
Text(
text = stringResource(R.string.voice_overlay_overlay),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
if (systemOverlayAvailable) {
TextButton(
onClick = onOverlayRequest,
modifier = Modifier
.weight(1f)
.height(40.dp),
) {
Text(
text = stringResource(R.string.voice_overlay_overlay),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
TextButton(
onClick = onExit,
@@ -1006,6 +1119,7 @@ private fun VoiceSessionPill(
onInterrupt: () -> Unit,
onPauseAutoMode: () -> Unit,
onOverlayRequest: () -> Unit,
systemOverlayAvailable: Boolean,
onOpenSettings: () -> Unit,
onExit: () -> Unit,
modifier: Modifier = Modifier,
@@ -1158,21 +1272,23 @@ private fun VoiceSessionPill(
overflow = TextOverflow.Ellipsis,
)
}
TextButton(
onClick = {
onFocusModeChange(false)
onOverlayRequest()
},
modifier = Modifier
.weight(0.95f)
.height(40.dp),
) {
Text(
stringResource(R.string.voice_overlay_overlay),
style = MaterialTheme.typography.labelMedium,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
if (systemOverlayAvailable) {
TextButton(
onClick = {
onFocusModeChange(false)
onOverlayRequest()
},
modifier = Modifier
.weight(0.95f)
.height(40.dp),
) {
Text(
stringResource(R.string.voice_overlay_overlay),
style = MaterialTheme.typography.labelMedium,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
TextButton(
onClick = onExit,
@@ -1289,8 +1405,9 @@ internal fun dispatchVoiceMicHoldPress(
) {
when (uiState.state) {
VoiceState.Idle, VoiceState.Error -> onStartListening()
VoiceState.Speaking -> onInterruptAndStart()
VoiceState.Listening, VoiceState.Transcribing, VoiceState.Thinking -> Unit
VoiceState.Speaking, VoiceState.Transcribing, VoiceState.Thinking ->
onInterruptAndStart()
VoiceState.Listening -> Unit
}
}
@@ -294,7 +294,55 @@ fun VersionNotesBlock(
) {
Column(verticalArrangement = Arrangement.spacedBy(6.dp)) {
val highlight = entry.highlight
if (highlight == null) {
if (entry.changes.isNotEmpty()) {
if (showVersionLine) {
Text(
text = entry.versionLine(),
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
entry.title?.takeIf { it.isNotBlank() }?.let { title ->
Text(
text = title,
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
color = MaterialTheme.colorScheme.primary,
)
}
}
entry.summary?.takeIf { it.isNotBlank() }?.let { summary ->
Text(
text = summary,
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurface,
)
}
val highlights = entry.highlightedChanges()
if (highlights.isNotEmpty()) {
ReleaseSectionTitle(stringResource(R.string.changelog_highlights))
ReleaseChangeList(highlights)
}
listOf(
CHANGE_KIND_ADDED to R.string.changelog_added,
CHANGE_KIND_IMPROVED to R.string.changelog_improved,
CHANGE_KIND_FIXED to R.string.changelog_fixed,
).forEach { (kind, label) ->
val changes = entry.remainingChangesOfKind(kind)
if (changes.isNotEmpty()) {
ReleaseSectionTitle(stringResource(label))
ReleaseChangeList(changes)
}
}
if (entry.compatibility.isNotEmpty()) {
ReleaseSectionTitle(stringResource(R.string.changelog_compatibility))
VersionNotesBody(
listOf(WhatsNewGroup(header = null, bullets = entry.compatibility)),
)
}
} else if (highlight == null) {
if (showVersionLine) {
Text(
text = entry.subtitle(),
@@ -340,6 +388,47 @@ fun VersionNotesBlock(
}
}
@Composable
private fun ReleaseSectionTitle(title: String) {
Text(
text = title,
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold,
color = MaterialTheme.colorScheme.primary,
modifier = Modifier.padding(top = 6.dp),
)
}
@Composable
private fun ColumnScope.ReleaseChangeList(changes: List<ChangelogChange>) {
changes.forEach { change ->
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(
text = "•",
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Column(modifier = Modifier.weight(1f)) {
Text(
text = change.title,
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
change.summary?.takeIf { it.isNotBlank() }?.let { summary ->
Text(
text = summary,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
}
}
// ──────────────────────────────────────────────────────────────────────────
// Structured changelog model + loader (kotlinx.serialization).
// ──────────────────────────────────────────────────────────────────────────
@@ -363,16 +452,37 @@ data class ChangelogHighlight(
@Serializable
data class ChangelogToastDigest(
val additionalFeatureCount: Int = 0,
val improvementCount: Int = 0,
val fixCount: Int = 0,
val preview: List<String> = emptyList(),
)
const val CHANGE_KIND_ADDED = "added"
const val CHANGE_KIND_IMPROVED = "improved"
const val CHANGE_KIND_FIXED = "fixed"
/** One complete, user-visible change in a release. */
@Serializable
data class ChangelogChange(
val id: String,
val kind: String,
val title: String,
val summary: String? = null,
val highlight: Boolean = false,
) {
fun fallbackText(): String =
summary?.takeIf { it.isNotBlank() }?.let { "$title — $it" } ?: title
}
/** A single released version's user-facing notes. */
@Serializable
data class ChangelogVersion(
val version: String,
val title: String? = null,
val date: String? = null,
val summary: String? = null,
val changes: List<ChangelogChange> = emptyList(),
val compatibility: List<String> = emptyList(),
val highlight: ChangelogHighlight? = null,
val improvements: List<String> = emptyList(),
val toastDigest: ChangelogToastDigest? = null,
@@ -393,8 +503,48 @@ data class ChangelogVersion(
return "v$version$datePart"
}
fun highlightedChanges(): List<ChangelogChange> = changes.filter { it.highlight }
fun remainingChanges(): List<ChangelogChange> = changes.filterNot { it.highlight }
fun remainingChangesOfKind(kind: String): List<ChangelogChange> =
remainingChanges().filter { it.kind == kind }
/** Derive compact toast metadata from the same changes the expanded view renders. */
fun resolvedToastDigest(): ChangelogToastDigest? {
if (changes.isEmpty()) return toastDigest
val remaining = remainingChanges()
if (remaining.isEmpty()) return null
return ChangelogToastDigest(
additionalFeatureCount = remaining.count { it.kind == CHANGE_KIND_ADDED },
improvementCount = remaining.count { it.kind == CHANGE_KIND_IMPROVED },
fixCount = remaining.count { it.kind == CHANGE_KIND_FIXED },
preview = remaining.take(2).map { it.title },
)
}
fun toGroups(): List<WhatsNewGroup> =
highlight?.let { curated ->
if (changes.isNotEmpty()) {
buildList {
val highlights = highlightedChanges()
if (highlights.isNotEmpty()) {
add(WhatsNewGroup("Highlights", highlights.map { it.fallbackText() }))
}
listOf(
CHANGE_KIND_ADDED to "Added",
CHANGE_KIND_IMPROVED to "Improved",
CHANGE_KIND_FIXED to "Fixed",
).forEach { (kind, label) ->
val items = remainingChangesOfKind(kind)
if (items.isNotEmpty()) {
add(WhatsNewGroup(label, items.map { it.fallbackText() }))
}
}
if (compatibility.isNotEmpty()) {
add(WhatsNewGroup("Compatibility", compatibility))
}
}
} else highlight?.let { curated ->
buildList {
add(WhatsNewGroup(curated.title.takeIf { it.isNotBlank() }, curated.bullets))
if (improvements.isNotEmpty()) {
@@ -185,6 +185,10 @@ internal fun WhatsNewToastContent(
) {
val title = stringResource(R.string.whats_new_title)
val highlight = entry.highlight
val digest = entry.resolvedToastDigest()
val releaseTitle = entry.title?.takeIf(String::isNotBlank) ?: highlight?.title.orEmpty()
val releaseSummary = entry.summary?.takeIf(String::isNotBlank)
?: highlight?.summary?.takeIf(String::isNotBlank)
Surface(
color = MaterialTheme.colorScheme.surface,
contentColor = MaterialTheme.colorScheme.onSurface,
@@ -220,14 +224,14 @@ internal fun WhatsNewToastContent(
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
text = highlight?.title ?: entry.title.orEmpty(),
text = releaseTitle,
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold,
color = MaterialTheme.colorScheme.primary,
maxLines = 1,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
highlight?.summary?.takeIf(String::isNotBlank)?.let { summary ->
releaseSummary?.let { summary ->
Text(
text = summary,
style = MaterialTheme.typography.bodySmall,
@@ -251,9 +255,9 @@ internal fun WhatsNewToastContent(
)
}
}
entry.toastDigest?.takeIf {
it.additionalFeatureCount > 0 || it.fixCount > 0
}?.let { digest ->
digest?.takeIf {
it.additionalFeatureCount > 0 || it.improvementCount > 0 || it.fixCount > 0
}?.let { resolvedDigest ->
HorizontalDivider(
modifier = Modifier.padding(horizontal = 16.dp),
color = MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.32f),
@@ -272,21 +276,30 @@ internal fun WhatsNewToastContent(
) {
Column(modifier = Modifier.weight(1f)) {
val counts = buildList {
if (digest.additionalFeatureCount > 0) {
if (resolvedDigest.additionalFeatureCount > 0) {
add(
pluralStringResource(
R.plurals.changelog_additional_feature_count,
digest.additionalFeatureCount,
digest.additionalFeatureCount,
resolvedDigest.additionalFeatureCount,
resolvedDigest.additionalFeatureCount,
),
)
}
if (digest.fixCount > 0) {
if (resolvedDigest.improvementCount > 0) {
add(
pluralStringResource(
R.plurals.changelog_improvement_count,
resolvedDigest.improvementCount,
resolvedDigest.improvementCount,
),
)
}
if (resolvedDigest.fixCount > 0) {
add(
pluralStringResource(
R.plurals.changelog_fix_count,
digest.fixCount,
digest.fixCount,
resolvedDigest.fixCount,
resolvedDigest.fixCount,
),
)
}
@@ -298,11 +311,11 @@ internal fun WhatsNewToastContent(
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
Text(
text = digest.preview.joinToString(", ") + "…",
text = resolvedDigest.preview.joinToString(", ") + "…",
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
@@ -124,7 +124,7 @@ private val OnboardingAccent = Color(0xFF7B55F6)
* Hermes API/dashboard features first, Relay-only power tools second.
* 2. **Connect page** — embeds the shared [ConnectionWizard] so onboarding
* uses the exact same Standard API/dashboard and optional Relay pairing
* flow as Settings → Connections.
* flow as Settings → Gateways.
*
* The previous separate "ConnectPage" + "RelayPage" pair has been removed —
* it discarded the QR's relay block, never applied per-channel grants, never
@@ -177,6 +177,7 @@ fun OnboardingScreen(
) { granted ->
notificationsPermitted =
granted || AppPermissionStatusProbe.snapshot(context).notificationsPermitted
connectionViewModel.setNotifyTurnComplete(notificationsPermitted)
}
Surface(
@@ -288,7 +289,14 @@ fun OnboardingScreen(
)
},
onReviewPermissions = onOpenPermissions,
onFinish = onComplete,
onFinish = {
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU &&
!notificationsPermitted
) {
connectionViewModel.setNotifyTurnComplete(false)
}
onComplete()
},
)
}
}
@@ -56,11 +56,21 @@ import com.hermesandroid.relay.data.BotRosterEntry
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.SessionMessageLoadMode
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.ui.components.MessageBubble
import com.hermesandroid.relay.ui.theme.RelayRefresh
import com.hermesandroid.relay.viewmodel.ChatViewModel
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import java.io.File
import kotlinx.coroutines.flow.Flow
internal typealias BotChatHistoryLoader = suspend (
profileName: String,
sessionId: String,
mode: SessionMessageLoadMode,
) -> Result<List<MessageItem>>
internal typealias BotChatProfileIconFlow = (connectionId: String, profileName: String) -> Flow<String?>
@OptIn(ExperimentalMaterial3Api::class)
@Composable
@@ -74,14 +84,52 @@ fun BotChatScreen(
connectionViewModel: ConnectionViewModel,
onBack: () -> Unit,
) {
val handler = remember(route.key) { ChatHandler() }
BotChatScreen(
route = route,
bot = bot,
sessionId = sessionId,
gatewayClient = gatewayClient,
dashboardClient = dashboardClient,
chatViewModel = chatViewModel,
onBack = onBack,
handlerFactory = ::ChatHandler,
historyLoader = { profileName, storedSessionId, mode ->
dashboardClient.getSessionMessages(
sessionId = storedSessionId,
profile = profileName,
mode = mode,
)
},
profileIconFlow = connectionViewModel::profileIconFlow,
)
}
@OptIn(ExperimentalMaterial3Api::class)
@Composable
internal fun BotChatScreen(
route: BotGatewayRoute,
bot: BotRosterEntry,
sessionId: String,
gatewayClient: GatewayChatClient,
dashboardClient: DashboardApiClient,
chatViewModel: ChatViewModel,
onBack: () -> Unit,
handlerFactory: () -> ChatHandler,
historyLoader: BotChatHistoryLoader,
profileIconFlow: BotChatProfileIconFlow,
) {
val handler = remember(route.key) { handlerFactory() }
val context = LocalContext.current
val messages by chatViewModel.messages.collectAsState()
val isStreaming by chatViewModel.isStreaming.collectAsState()
// This route owns the handler but binds it to the ViewModel only after the
// first composition. Collecting delegated ViewModel getters here can pin
// Compose to their empty pre-bind fallback when history settles before the
// next frame. Observe the route-owned source directly so StateFlow replay
// covers fast history, live streaming, completion, and errors.
val messages by handler.messages.collectAsState()
val isStreaming by handler.isStreaming.collectAsState()
val isLoading by chatViewModel.isLoadingHistory.collectAsState()
val error by chatViewModel.error.collectAsState()
val iconPath by connectionViewModel
.profileIconFlow(route.connectionId, route.profileName)
val error by handler.error.collectAsState()
val iconPath by profileIconFlow(route.connectionId, route.profileName)
.collectAsState(initial = null)
val listState = rememberLazyListState()
var composer by remember(route.key, sessionId) { mutableStateOf("") }
@@ -101,11 +149,7 @@ fun BotChatScreen(
selected?.name == route.profileName
}
chatViewModel.setProfileMessageLoaderWithMode { _, storedSessionId, mode ->
dashboardClient.getSessionMessages(
sessionId = storedSessionId,
profile = route.profileName,
mode = mode,
)
historyLoader(route.profileName, storedSessionId, mode)
}
chatViewModel.updateApiClient(null)
chatViewModel.updateGatewayClient(gatewayClient)
@@ -169,6 +169,7 @@ import com.hermesandroid.relay.util.AttachmentTooLargeException
import com.hermesandroid.relay.util.readBase64Bounded
import com.hermesandroid.relay.data.ChatComposerDraftKey
import com.hermesandroid.relay.data.ChatQuoteReference
import com.hermesandroid.relay.data.BuildFlavor
import com.hermesandroid.relay.data.LARGE_PASTE_THRESHOLD_CHARS
import com.hermesandroid.relay.data.buildChatQuotedPrompt
import com.hermesandroid.relay.data.largePasteAttachment
@@ -216,6 +217,7 @@ import com.hermesandroid.relay.ui.components.CHAT_PET_STEP_MESSAGE_MARKER
import com.hermesandroid.relay.ui.components.CHAT_PET_USER_MESSAGE_PERCH_PREFIX
import com.hermesandroid.relay.ui.components.GatewayBackgroundProcessSheet
import com.hermesandroid.relay.ui.components.GatewayBackgroundProcessStrip
import com.hermesandroid.relay.ui.components.SubagentPreviewVisibility
import com.hermesandroid.relay.ui.components.InjectedContextSheet
import com.hermesandroid.relay.ui.components.InlineAutocomplete
import com.hermesandroid.relay.ui.components.loadedContentTransform
@@ -263,6 +265,7 @@ import com.hermesandroid.relay.ui.components.ToolTranscriptItem
import com.hermesandroid.relay.ui.components.groupTranscriptTools
import com.hermesandroid.relay.ui.components.isVisibleForToolDisplay
import com.hermesandroid.relay.ui.components.showsImageGenerationPlaceholder
import com.hermesandroid.relay.data.isImageGenerationToolName
import com.hermesandroid.relay.ui.components.VoiceModeOverlay
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.ui.showHumanError
@@ -437,6 +440,29 @@ internal fun ownedBottomFollowScroll(
return requiredBottomFollowScroll(previous, current)
}
internal fun shouldShowRetainedHistoryDashboardSignIn(
hasMessages: Boolean,
gatewayAvailability: GatewayAvailability,
apiReachable: Boolean,
supervised: Boolean,
): Boolean = hasMessages &&
!supervised &&
gatewayAvailability == GatewayAvailability.SignInRequired &&
!apiReachable
internal fun shouldPresentChatFailureDuringDashboardSignIn(
failure: ChatFailureNotice,
dashboardSignInRequired: Boolean,
): Boolean {
if (!dashboardSignInRequired || failure.route != ChatFailureRoute.GATEWAY) return true
val authFailure = failure.rawError.contains("no_cookie", ignoreCase = true) ||
(
failure.rawError.contains("Auth provider", ignoreCase = true) &&
failure.rawError.contains("unreachable", ignoreCase = true)
)
return !authFailure && !failure.turnId.startsWith("history-")
}
/**
* One frame of the live bottom-follow ramp. The maximum step is derived from
* the viewport, never the transcript distance, so a long session cannot make
@@ -708,7 +734,7 @@ fun ChatScreen(
// Offline demo entry, surfaced on the empty-chat "needs connection" card so a
// skipped / never-connected first run can explore without a server. null hides it.
onTryDemo: (() -> Unit)? = null,
onNavigateToManage: () -> Unit = {},
onNavigateToDashboardSignIn: () -> Unit = {},
onNavigateToBridge: () -> Unit = {},
onNavigateToTerminal: () -> Unit = {},
onNavigateToSettings: () -> Unit = {},
@@ -928,8 +954,14 @@ fun ChatScreen(
val backgroundProcesses by chatViewModel.backgroundProcesses.collectAsState()
val backgroundProcessesLoading by chatViewModel.backgroundProcessesLoading.collectAsState()
val stoppingProcessIds by chatViewModel.stoppingProcessIds.collectAsState()
val subagentActivities by chatViewModel.subagentActivities.collectAsState()
val subagentChildPreview by chatViewModel.subagentChildPreview.collectAsState()
val isLoadingHistory by chatViewModel.isLoadingHistory.collectAsState()
val isLoadingSessions by chatViewModel.isLoadingSessions.collectAsState()
val isLoadingMoreSessions by chatViewModel.isLoadingMoreSessions.collectAsState()
val hasMoreSessions by chatViewModel.hasMoreSessions.collectAsState()
val sessionPageLoadFailed by chatViewModel.sessionPageLoadFailed.collectAsState()
val sessionListUnavailable by chatViewModel.sessionListUnavailable.collectAsState()
val selectedPersonality by chatViewModel.selectedPersonality.collectAsState()
val personalityNames by chatViewModel.personalityNames.collectAsState()
val defaultPersonality by chatViewModel.defaultPersonality.collectAsState()
@@ -948,53 +980,69 @@ fun ChatScreen(
val agentProfiles by connectionViewModel.agentProfiles.collectAsState()
var allProfileSessions by remember { mutableStateOf<List<ProfileSessionRow>>(emptyList()) }
var allProfileSessionsLoading by remember { mutableStateOf(false) }
var allProfileSessionsUnavailable by remember { mutableStateOf(false) }
val snackbarHostState = remember { SnackbarHostState() }
suspend fun refreshAllProfileSessions(showError: Boolean) {
if (isProfileLocked || allProfileSessionsLoading) return
allProfileSessionsLoading = true
val result = connectionViewModel.listAllProfileSessions()
result?.fold(
onSuccess = { items ->
allProfileSessions = items.mapNotNull { item ->
val owner = item.profile?.takeIf { it.isNotBlank() } ?: return@mapNotNull null
ProfileSessionRow(
profile = owner,
session = com.hermesandroid.relay.data.ChatSession(
sessionId = item.id,
title = item.title ?: item.preview,
model = item.model,
messageCount = item.messageCount ?: 0,
inputTokens = item.inputTokens ?: 0,
outputTokens = item.outputTokens ?: 0,
actualCostUsd = item.actualCostUsd,
estimatedCostUsd = item.estimatedCostUsd,
recentlyActive = item.isActive,
startedAt = ((item.startedAt ?: 0.0) * 1000).toLong(),
lastActivityAt = ((item.resolvedLastActivity ?: 0.0) * 1000).toLong(),
source = item.source,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
),
allProfileSessionsUnavailable = false
try {
val result = connectionViewModel.listAllProfileSessions()
if (result == null) allProfileSessionsUnavailable = true
result?.fold(
onSuccess = { items ->
allProfileSessionsUnavailable = false
allProfileSessions = items.mapNotNull { item ->
val owner = item.profile?.takeIf { it.isNotBlank() }
?: return@mapNotNull null
ProfileSessionRow(
profile = owner,
session = com.hermesandroid.relay.data.ChatSession(
sessionId = item.id,
title = item.title ?: item.preview,
model = item.model,
messageCount = item.messageCount ?: 0,
inputTokens = item.inputTokens ?: 0,
outputTokens = item.outputTokens ?: 0,
actualCostUsd = item.actualCostUsd,
estimatedCostUsd = item.estimatedCostUsd,
recentlyActive = item.isActive,
startedAt = ((item.startedAt ?: 0.0) * 1000).toLong(),
lastActivityAt = ((item.resolvedLastActivity ?: 0.0) * 1000).toLong(),
source = item.source,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
),
)
}
chatViewModel.updateSessionActivityDirectory(
rows = allProfileSessions.map { it.profile to it.session.sessionId },
)
}
chatViewModel.updateSessionActivityDirectory(
rows = allProfileSessions.map { it.profile to it.session.sessionId },
)
},
onFailure = { error ->
if (showError) snackbarHostState.showSnackbar(
"Couldn't load all profiles: ${error.message ?: "unsupported"}",
)
},
)
allProfileSessionsLoading = false
},
onFailure = { error ->
allProfileSessionsUnavailable = true
if (showError) snackbarHostState.showSnackbar(
"Couldn't load all profiles: ${error.message ?: "unsupported"}",
)
},
)
} catch (e: CancellationException) {
throw e
} catch (e: Throwable) {
allProfileSessionsUnavailable = true
if (showError) snackbarHostState.showSnackbar(
"Couldn't load all profiles: ${e.message ?: "unsupported"}",
)
} finally {
allProfileSessionsLoading = false
}
}
val conversationBinding by chatViewModel.conversationBinding.collectAsState()
val explicitBindingProfileName = conversationBinding.profileName
@@ -1062,6 +1110,13 @@ fun ChatScreen(
supervisedVisibility.showToolNames -> "compact"
else -> "off"
}
val subagentPreviewVisibility = SubagentPreviewVisibility(
showLifecycle = !supervised || supervisedVisibility.showWorkingStatus,
showReasoning = showThinking,
showToolNames = toolDisplay == "compact" || toolDisplay == "detailed",
showToolDetails = toolDisplay == "detailed",
showChildHistory = !supervised,
)
val smoothAutoScroll by connectionViewModel.smoothAutoScroll.collectAsState()
val closeDrawerOnSend by connectionViewModel.closeDrawerOnSend.collectAsState()
val keepComposerFocusedOnSend by
@@ -1112,6 +1167,8 @@ fun ChatScreen(
val streamingEndpointPref by connectionViewModel.streamingEndpoint.collectAsState()
val chatServerCapabilities by connectionViewModel.serverCapabilities.collectAsState()
val chatGatewayAvailability by connectionViewModel.gatewayAvailability.collectAsState()
val dashboardSignInRequired =
chatGatewayAvailability == GatewayAvailability.SignInRequired && !apiReachable
val isGatewayTransport = remember(
streamingEndpointPref, chatServerCapabilities, chatGatewayAvailability,
) {
@@ -1119,18 +1176,15 @@ fun ChatScreen(
}
// Recover any durable in-flight chat checkpoint whenever Chat returns to
// the foreground. On Gateway this also pre-warms/re-attaches the socket;
// sessions-SSE falls back to bounded persisted-history reconciliation.
// the foreground. setChatVisible owns that edge; an ordinary Gateway open
// warms only the observation socket and never attaches a saved session.
val appForeground by com.hermesandroid.relay.util.AppForegroundTracker.isForeground.collectAsState()
LaunchedEffect(isGatewayTransport, appForeground, chatReady) {
chatViewModel.setChatVisible(appForeground && chatReady)
if (appForeground && chatReady) {
chatViewModel.prewarmGateway()
}
if (isGatewayTransport && appForeground && chatReady) {
chatViewModel.refreshModelOptions()
chatViewModel.refreshReasoningSettings()
}
val visibleGatewayOwner = appForeground && chatReady && isGatewayTransport
chatViewModel.setChatVisible(visibleGatewayOwner)
// updateGatewayClient owns the one-time catalog/reasoning bootstrap for
// a newly-ready socket. Repeating it here created a duplicate cold-open
// RPC burst while the session directory was also trying to hydrate.
}
DisposableEffect(chatViewModel) {
onDispose { chatViewModel.setChatVisible(false) }
@@ -1175,7 +1229,7 @@ fun ChatScreen(
buildMap {
messages.forEach { message ->
val generationCount = message.toolCalls.count {
it.name.trim().equals("image_generate", ignoreCase = true)
isImageGenerationToolName(it.name)
}
if (generationCount > 0) {
put(message.uiKey, nextOrdinal + generationCount - 1)
@@ -1362,6 +1416,7 @@ fun ChatScreen(
// A process inventory is scoped to one gateway session. Never leave a
// sheet opened onto a different chat after a drawer/profile switch.
LaunchedEffect(currentSessionId, selectedProfile?.name, activeConnection?.id) {
chatViewModel.closeSubagentChildPreview()
showBackgroundProcesses = false
}
@@ -1559,8 +1614,11 @@ fun ChatScreen(
voiceOutputConfig?.enabled
}
val voiceSystemOverlayAvailable = BuildFlavor.isSideload
val showVoiceSystemOverlay: () -> Unit = {
if (assistantSessionActive) {
if (!voiceSystemOverlayAvailable) {
pendingVoiceOverlayPermission = false
} else if (assistantSessionActive) {
voiceOverlayHost.hide()
} else if (!voiceOverlayHost.hasOverlayPermission()) {
pendingVoiceOverlayPermission = true
@@ -2102,13 +2160,6 @@ fun ChatScreen(
}
}
// Refresh sessions when screen appears and API is ready
LaunchedEffect(chatReady) {
if (chatReady) {
chatViewModel.refreshSessions()
}
}
// The drawer and composer share this screen's focus owner. Clear the
// composer's input focus as soon as an open transition is committed so
// menu activation, accessibility activation, and edge swipes all dismiss
@@ -2131,8 +2182,11 @@ fun ChatScreen(
// row for the active session is preserved by ChatHandler.updateSessions.
LaunchedEffect(drawerState.isOpen) {
chatViewModel.setSessionActivityDrawerOpen(drawerState.isOpen)
if (drawerState.isOpen && chatReady) {
chatViewModel.refreshSessions()
// Session history is Dashboard HTTP state and remains usable while the
// independent Gateway socket is reconnecting. Never gate drawer-open
// refresh on chatReady; owner/generation fencing lives in ChatViewModel.
if (drawerState.isOpen) {
chatViewModel.refreshSessionsIfStale()
}
}
@@ -2438,6 +2492,26 @@ fun ChatScreen(
activeConnectionId = activeConnection?.id,
realThreadChatIds = phoneThreadChatIds.values,
)
val realPhoneSessionIds = remember(sessions) {
sessions.asSequence()
.filter { it.source.equals("phone", ignoreCase = true) }
.map { it.sessionId }
.toSet()
}
val provisionalThreadChatIds = provisionalThreadEntries.keys
LaunchedEffect(
activeConnection?.id,
realPhoneSessionIds,
provisionalThreadChatIds,
) {
// A reply promotes the local provisional row to a real Gateway
// source=phone session. Refresh the relay-owned chat_id index at
// that boundary so the local duplicate disappears immediately,
// without guessing a chat_id from the opaque session id.
if (realPhoneSessionIds.isNotEmpty() && provisionalThreadChatIds.isNotEmpty()) {
connectionViewModel.refreshPhoneThreadChatIds()
}
}
val provisionalThreads = provisionalThreadEntries.map { (chatId, entries) ->
val latest = entries.maxBy { it.receivedAt }
ProvisionalThreadRow(
@@ -2457,6 +2531,10 @@ fun ChatScreen(
scopeSubtitle = drawerSubtitle,
activeProfileName = drawerProfileName ?: "default",
isLoading = isLoadingSessions,
loadFailed = sessionListUnavailable,
isLoadingMore = isLoadingMoreSessions,
hasMore = hasMoreSessions,
loadMoreFailed = sessionPageLoadFailed,
isOpen = drawerState.isOpen,
activityStates = sessionActivityStates,
animationEnabled = animationEnabled,
@@ -2466,6 +2544,8 @@ fun ChatScreen(
.takeIf { supervised },
newChatEnabled = !supervised || supervisedPolicy.capabilities.newChat,
onRefresh = { chatViewModel.refreshSessions() },
onLoadMore = { chatViewModel.loadMoreSessions() },
onRetryLoadMore = { chatViewModel.retryLoadMoreSessions() },
onOpenBotMode = {
scope.launch { drawerState.close() }
onNavigateToBotMode()
@@ -2537,6 +2617,11 @@ fun ChatScreen(
)
scope.launch { drawerState.close() }
},
onDeleteProvisionalThread = { chatId ->
activeConnection?.id?.let { connectionId ->
connectionViewModel.removeProvisionalThread(chatId, connectionId)
}
},
hiddenSources = hiddenSources,
onToggleSourceHidden = { source, hidden ->
connectionViewModel.setSourceHidden(source, hidden)
@@ -2545,6 +2630,7 @@ fun ChatScreen(
!activeConnection?.resolvedDashboardUrl.isNullOrBlank(),
allProfileSessions = allProfileSessions,
allProfileSessionsLoading = allProfileSessionsLoading,
allProfileSessionsLoadFailed = allProfileSessionsUnavailable,
profileColors = profilePresentation.colors,
onProfileColorChange = connectionViewModel::setProfileColor,
onRefreshAllProfiles = {
@@ -2871,90 +2957,45 @@ fun ChatScreen(
modifier = Modifier.animateContentSize(
animationSpec = tween(durationMillis = 220),
),
verticalArrangement = if (isChatConnecting) {
Arrangement.spacedBy(6.dp)
} else {
Arrangement.Top
},
verticalArrangement = Arrangement.Top,
) {
AnimatedContent(
targetState = isChatConnecting,
transitionSpec = {
(
fadeIn(tween(180)) +
slideInVertically(tween(220)) { it / 6 }
) togetherWith (
fadeOut(tween(140)) +
slideOutVertically(tween(180)) { -it / 8 }
)
},
label = "chatHeaderIdentityTransition",
) { connecting ->
if (connecting) {
Column(verticalArrangement = Arrangement.spacedBy(6.dp)) {
ChatSkeletonLine(
modifier = Modifier.width(112.dp),
height = 15.dp,
)
ChatSkeletonLine(
modifier = Modifier.width(156.dp),
height = 11.dp,
)
}
Text(
text = if (supervised && !supervisedVisibility.showAgentIdentity) {
stringResource(R.string.screen_chat_label)
} else if (agentDisplayName.isNotBlank()) {
agentDisplayName
} else {
Column {
Text(
text = if (supervised && !supervisedVisibility.showAgentIdentity) {
stringResource(R.string.screen_chat_label)
} else if (agentDisplayName.isNotBlank()) {
agentDisplayName
} else {
stringResource(R.string.chat_agent_default)
},
style = MaterialTheme.typography.titleMedium,
maxLines = 1,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
stringResource(R.string.chat_agent_default)
},
style = MaterialTheme.typography.titleMedium,
maxLines = 1,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
)
// Keep the exact persisted identity visible while the
// Gateway wakes. The existing loaded-content motion
// animates status → confirmed model/personality without
// replacing the whole header with anonymous skeletons.
AnimatedContent(
targetState = subtitleText,
transitionSpec = { loadedContentTransform() },
label = "chatHeaderSubtitle",
) { line ->
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
) {
Text(
text = line,
style = MaterialTheme.typography.bodySmall,
color = subtitleColor,
maxLines = 1,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
)
if (showStreamingState && animationEnabled) {
StreamingDots(
color = subtitleColor,
modifier = Modifier.clearAndSetSemantics { },
)
// Context % lives in the per-session
// ContextMeterBar, and the approval-bypass
// marker now rides a compact ⚡ icon in the
// app bar actions (full detail in the agent
// sheet) instead of being appended here —
// so the subtitle stays a clean single line
// (`personality · model`) and no longer gets
// squeezed out by the trailing action icons.
// Fade the subtitle whenever it changes
// — most importantly the honest
// "Connected" → confirmed-model reveal
// once /api/config lands (the model
// arrives later than the identity, and
// used to pop in). AnimatedContent doesn't
// animate its initial state, so this only
// smooths real changes, not first paint.
AnimatedContent(
targetState = subtitleText,
transitionSpec = { loadedContentTransform() },
label = "chatHeaderSubtitle",
) { line ->
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
) {
Text(
text = line,
style = MaterialTheme.typography.bodySmall,
color = subtitleColor,
maxLines = 1,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
)
if (showStreamingState && animationEnabled) {
StreamingDots(
color = subtitleColor,
modifier = Modifier.clearAndSetSemantics { },
)
}
}
}
}
}
}
@@ -3138,6 +3179,22 @@ fun ChatScreen(
onClick = if (supervised) null else ({ showContextSheet = true }),
)
}
if (
shouldShowRetainedHistoryDashboardSignIn(
hasMessages = messages.isNotEmpty(),
gatewayAvailability = chatGatewayAvailability,
apiReachable = apiReachable,
supervised = supervised,
)
) {
ChatDashboardSignInCard(
dashboardRouteMovedHint = dashboardRouteMovedHint,
onNavigateToDashboardSignIn = onNavigateToDashboardSignIn,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 16.dp, vertical = 8.dp),
)
}
if (!supervised && showContextSheet) {
// Live audit of the exact extra context the agent will be
// injected with on the next turn (transparency / auditability).
@@ -3229,6 +3286,7 @@ fun ChatScreen(
?: activeConnection
?.apiServerUrl
?.let(Connection::extractDefaultLabel),
agentDisplayName = agentDisplayName,
chatMode = chatMode,
apiReachable = apiReachable,
chatReady = chatReady,
@@ -3236,7 +3294,7 @@ fun ChatScreen(
isLoadingSessions = isLoadingSessions,
gatewayAvailability = chatGatewayAvailability,
dashboardRouteMovedHint = dashboardRouteMovedHint,
onNavigateToManage = onNavigateToManage,
onNavigateToDashboardSignIn = onNavigateToDashboardSignIn,
onNavigateToConnections = onNavigateToConnections,
modifier = Modifier.fillMaxSize(),
)
@@ -3298,6 +3356,7 @@ fun ChatScreen(
stringResource(R.string.chat_start_conversation)
}
ChatConnectState.Connecting -> stringResource(R.string.chat_connect_to_hermes_dots)
ChatConnectState.Unavailable -> stringResource(R.string.chat_disconnected_label)
ChatConnectState.NeedsConnection -> stringResource(R.string.chat_needs_connection)
},
style = MaterialTheme.typography.titleMedium,
@@ -3366,6 +3425,31 @@ fun ChatScreen(
ChatConnectState.Connecting -> Unit
ChatConnectState.Unavailable -> {
if (dashboardSignInRequired) {
Spacer(modifier = Modifier.height(12.dp))
ChatDashboardSignInCard(
dashboardRouteMovedHint = dashboardRouteMovedHint,
onNavigateToDashboardSignIn = onNavigateToDashboardSignIn,
modifier = Modifier.fillMaxWidth(),
)
} else {
Spacer(modifier = Modifier.height(12.dp))
Button(
onClick = connectionViewModel::probeNow,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.chat_retry))
}
TextButton(
onClick = onNavigateToConnections,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.settings_connections))
}
}
}
ChatConnectState.Ready -> {
Spacer(modifier = Modifier.height(20.dp))
@@ -3942,6 +4026,8 @@ fun ChatScreen(
if (isGatewayTransport) {
GatewayBackgroundProcessStrip(
processes = backgroundProcesses,
subagentActivities = subagentActivities,
subagentPreviewVisibility = subagentPreviewVisibility,
loading = backgroundProcessesLoading,
onClick = { showBackgroundProcesses = true },
)
@@ -4375,7 +4461,14 @@ fun ChatScreen(
null
}
visibleChatFailure?.let { failure ->
visibleChatFailure
?.takeIf { failure ->
shouldPresentChatFailureDuringDashboardSignIn(
failure = failure,
dashboardSignInRequired = dashboardSignInRequired,
)
}
?.let { failure ->
val displayFailure = if (!supervised) failure else failure.copy(
model = failure.model.takeIf { supervisedVisibility.showModelName },
provider = failure.provider.takeIf { supervisedVisibility.showTechnicalRoute },
@@ -4644,6 +4737,7 @@ fun ChatScreen(
setVoicePresentationMode(VoicePresentationMode.Focus)
},
onOverlayRequest = showVoiceSystemOverlay,
systemOverlayAvailable = voiceSystemOverlayAvailable,
onOpenSettings = onNavigateToVoiceSettings,
onExit = { voiceViewModel.exitVoiceMode() },
)
@@ -4800,6 +4894,7 @@ fun ChatScreen(
presentationMode = effectiveVoicePresentationMode,
onPresentationModeChange = setVoicePresentationMode,
onOverlayRequest = showVoiceSystemOverlay,
systemOverlayAvailable = voiceSystemOverlayAvailable,
// Gear button in the overlay's expanded controls. The overlay
// exits voice mode before invoking this, so navigation lands
// on Voice Settings with no overlay left on top.
@@ -4851,12 +4946,19 @@ fun ChatScreen(
if (showBackgroundProcesses) {
GatewayBackgroundProcessSheet(
processes = backgroundProcesses,
subagentActivities = subagentActivities,
subagentChildPreview = subagentChildPreview,
subagentPreviewVisibility = subagentPreviewVisibility,
loading = backgroundProcessesLoading,
stoppingProcessIds = stoppingProcessIds,
onRefresh = chatViewModel::refreshBackgroundProcesses,
onStop = chatViewModel::stopBackgroundProcess,
onDismissProcess = chatViewModel::dismissBackgroundProcess,
onDismiss = { showBackgroundProcesses = false },
onOpenSubagentChild = chatViewModel::openSubagentChildPreview,
onDismiss = {
chatViewModel.closeSubagentChildPreview()
showBackgroundProcesses = false
},
)
}
@@ -4966,6 +5068,7 @@ private fun ChatColdStartLoadingState(
streamingIntensity: Float,
toolCallBurst: Float,
connectionLabel: String?,
agentDisplayName: String,
chatMode: ChatMode,
apiReachable: Boolean,
chatReady: Boolean,
@@ -4973,13 +5076,14 @@ private fun ChatColdStartLoadingState(
isLoadingSessions: Boolean,
gatewayAvailability: GatewayAvailability,
dashboardRouteMovedHint: String?,
onNavigateToManage: () -> Unit,
onNavigateToDashboardSignIn: () -> Unit,
onNavigateToConnections: () -> Unit,
modifier: Modifier = Modifier,
) {
val context = LocalContext.current
val commands = remember(
connectionLabel,
agentDisplayName,
chatMode,
apiReachable,
chatReady,
@@ -4989,6 +5093,7 @@ private fun ChatColdStartLoadingState(
buildChatLoadingCommands(
context = context,
connectionLabel = connectionLabel,
agentDisplayName = agentDisplayName,
chatMode = chatMode,
apiReachable = apiReachable,
chatReady = chatReady,
@@ -5042,38 +5147,14 @@ private fun ChatColdStartLoadingState(
val dashboardSignInRequired =
gatewayAvailability == GatewayAvailability.SignInRequired && !apiReachable
if (dashboardSignInRequired) {
ElevatedCard(
colors = CardDefaults.elevatedCardColors(
containerColor = MaterialTheme.colorScheme.surface.copy(alpha = 0.92f),
),
ChatDashboardSignInCard(
dashboardRouteMovedHint = dashboardRouteMovedHint,
onNavigateToDashboardSignIn = onNavigateToDashboardSignIn,
modifier = Modifier
.align(Alignment.BottomCenter)
.fillMaxWidth()
.padding(horizontal = 16.dp, vertical = 16.dp),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Text(
text = stringResource(R.string.dashboard_signin_required_title),
style = MaterialTheme.typography.titleMedium,
)
Text(
text = dashboardRouteMovedHint?.let { route ->
stringResource(R.string.dashboard_signin_route_hint, route)
} ?: stringResource(R.string.chat_settings_gateway_needs_signin_desc),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Button(
onClick = onNavigateToManage,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.voice_settings_sign_in_via_manage))
}
}
}
)
} else {
ChatLoadingCommandPanel(
commands = commands,
@@ -5087,9 +5168,47 @@ private fun ChatColdStartLoadingState(
}
}
@Composable
private fun ChatDashboardSignInCard(
dashboardRouteMovedHint: String?,
onNavigateToDashboardSignIn: () -> Unit,
modifier: Modifier = Modifier,
) {
ElevatedCard(
colors = CardDefaults.elevatedCardColors(
containerColor = MaterialTheme.colorScheme.surface.copy(alpha = 0.92f),
),
modifier = modifier,
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Text(
text = stringResource(R.string.dashboard_signin_required_title),
style = MaterialTheme.typography.titleMedium,
)
Text(
text = dashboardRouteMovedHint?.let { route ->
stringResource(R.string.dashboard_signin_route_hint, route)
} ?: stringResource(R.string.chat_settings_gateway_needs_signin_desc),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Button(
onClick = onNavigateToDashboardSignIn,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.cw_sign_in_to_hermes))
}
}
}
}
private fun buildChatLoadingCommands(
context: android.content.Context,
connectionLabel: String?,
agentDisplayName: String,
chatMode: ChatMode,
apiReachable: Boolean,
chatReady: Boolean,
@@ -5118,12 +5237,16 @@ private fun buildChatLoadingCommands(
),
ChatLoadingCommand(
state = when {
apiReachable -> ChatLoadingCommandState.Done
chatReady -> ChatLoadingCommandState.Done
hasConnection -> ChatLoadingCommandState.Active
else -> ChatLoadingCommandState.Pending
},
command = "/hermes ping",
detail = if (apiReachable) "online" else context.getString(R.string.chat_contacting_server),
command = "/gateway wake",
detail = if (chatReady) {
"${agentDisplayName.ifBlank { "Hermes" }} online"
} else {
"waking ${agentDisplayName.ifBlank { "Hermes" }}"
},
),
ChatLoadingCommand(
state = when {
@@ -5131,8 +5254,13 @@ private fun buildChatLoadingCommands(
apiReachable || isLoadingHistory || isLoadingSessions -> ChatLoadingCommandState.Active
else -> ChatLoadingCommandState.Pending
},
command = "/chat hydrate",
detail = if (chatReady) "ready via $chatModeDetail" else "loading conversation",
command = "/sessions load",
detail = when {
isLoadingSessions -> context.getString(R.string.drawer_loading_sessions)
isLoadingHistory -> context.getString(R.string.chat_loading_messages)
chatReady -> "ready via $chatModeDetail"
else -> "waiting for gateway"
},
),
)
}
@@ -549,7 +549,7 @@ fun ChatSettingsScreen(
val settingsContext = LocalContext.current
val notifyPermissionLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.RequestPermission()
) { /* Notifier re-checks the grant at post time. */ }
) { granted -> connectionViewModel.setNotifyTurnComplete(granted) }
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.SpaceBetween,
@@ -1,6 +1,8 @@
package com.hermesandroid.relay.ui.screens
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
@@ -14,13 +16,20 @@ import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.ArrowBack
import androidx.compose.material.icons.filled.CheckCircle
import androidx.compose.material.icons.filled.Chat
import androidx.compose.material.icons.filled.ChevronRight
import androidx.compose.material.icons.filled.Code
import androidx.compose.material.icons.filled.Dashboard
import androidx.compose.material.icons.filled.Edit
import androidx.compose.material.icons.filled.GraphicEq
import androidx.compose.material.icons.filled.Language
import androidx.compose.material.icons.filled.Link
import androidx.compose.material.icons.filled.MoreVert
import androidx.compose.material.icons.filled.QrCodeScanner
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.Badge
import androidx.compose.material3.Button
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.DropdownMenu
import androidx.compose.material3.DropdownMenuItem
import androidx.compose.material3.ExperimentalMaterial3Api
@@ -43,28 +52,38 @@ import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.platform.LocalContext
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.capabilities
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.gatewayRouteUrl
import com.hermesandroid.relay.ui.components.ActiveCardAdvancedSection
import com.hermesandroid.relay.ui.components.ActiveCardFeaturesSection
import com.hermesandroid.relay.ui.components.ActiveCardRoutesSection
import com.hermesandroid.relay.ui.components.ActiveCardSecurityPosture
import com.hermesandroid.relay.ui.components.ApiServerInfoSheet
import com.hermesandroid.relay.ui.components.DashboardAddressEditorDialog
import com.hermesandroid.relay.ui.components.InsecureConnectionAckDialog
import com.hermesandroid.relay.ui.components.RelayInfoSheet
import com.hermesandroid.relay.ui.components.SessionInfoSheet
import com.hermesandroid.relay.ui.components.sameGatewayRouteBase
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.ui.theme.LocalBrand
import com.hermesandroid.relay.network.upstream.GatewayAvailability
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import com.hermesandroid.relay.viewmodel.RelayUiState
import com.hermesandroid.relay.viewmodel.StandardVoiceAvailability
import kotlinx.coroutines.launch
/**
* Tabbed detail for a single Hermes connection — the level-2 screen the
@@ -75,10 +94,9 @@ import com.hermesandroid.relay.viewmodel.RelayUiState
* - TopAppBar: back + connection label + an `Active` badge (active conn) +
* an overflow `⋮` menu (Rename / Re-pair / Revoke / Remove).
* - When this connection is the **active** one, a 4-tab segmented bar:
* **Overview** (status header + the steps/timeline capability list) ·
* **Routes** (ADR 24 endpoint management) · **Advanced** (manual URL /
* insecure / manual pairing) · **Security** (transport posture + the
* prominent Relay sessions entry).
* **Overview** (current route + capability outcomes) · **Routes** (ADR 24
* endpoint management) · **Access** (transport posture + Relay sessions) ·
* **Advanced** (manual URL / insecure / manual pairing).
* - When this connection is **not** active, only Overview shows — the deep
* live content reads the single active-connection VM state, so we surface
* a "Switch to this connection" CTA instead of stale/foreign data.
@@ -105,34 +123,41 @@ fun ConnectionDetailScreen(
) {
val context = LocalContext.current
val isDarkTheme = LocalBrand.current.isDark
val snackbarHost = LocalSnackbarHost.current
val scope = rememberCoroutineScope()
val routeResetFailed = stringResource(R.string.active_section_use_selected_route_failed)
val connections by connectionViewModel.connections.collectAsState()
val connectionsHydrated by connectionViewModel.connectionsHydrated.collectAsState()
val activeConnectionId by connectionViewModel.activeConnectionId.collectAsState()
val relayUiState by connectionViewModel.relayUiState.collectAsState()
val connection = connections.firstOrNull { it.id == connectionId }
// Connection was removed (e.g. via the overflow menu) — leave the screen.
LaunchedEffect(connection == null) {
if (connection == null) onBack()
if (!connectionsHydrated) {
Box(modifier = Modifier.fillMaxSize(), contentAlignment = Alignment.Center) {
CircularProgressIndicator()
}
return
}
// Connection was removed (e.g. via the overflow menu) — leave the screen
// only after the store has authoritatively hydrated.
LaunchedEffect(connectionsHydrated, connection == null) {
if (connectionsHydrated && connection == null) onBack()
}
if (connection == null) return
val isActive = connectionId == activeConnectionId
// Screen-scoped sheet/dialog visibility (survives tab switches + scroll).
var showSessionInfoSheet by remember { mutableStateOf(false) }
var showApiInfoSheet by remember { mutableStateOf(false) }
var showRelayInfoSheet by remember { mutableStateOf(false) }
var showInsecureAckDialog by remember { mutableStateOf(false) }
var showRenameDialog by remember { mutableStateOf(false) }
var showDashboardEditor by remember { mutableStateOf(false) }
var showRevokeConfirm by remember { mutableStateOf(false) }
var showRemoveConfirm by remember { mutableStateOf(false) }
var menuExpanded by remember { mutableStateOf(false) }
val tabs = if (isActive) {
listOf(DetailTab.Overview, DetailTab.Routes, DetailTab.Advanced, DetailTab.Security)
} else {
listOf(DetailTab.Overview)
}
val tabs = detailTabs(isActive)
// Reset selection when the active/non-active shape changes so we never
// index past the available tabs.
var selectedTab by remember(isActive) { mutableStateOf(0) }
@@ -247,8 +272,8 @@ fun ConnectionDetailScreen(
Text(when (tab) {
DetailTab.Overview -> stringResource(R.string.detail_tab_overview)
DetailTab.Routes -> stringResource(R.string.detail_tab_routes)
DetailTab.Access -> stringResource(R.string.detail_tab_access)
DetailTab.Advanced -> stringResource(R.string.detail_tab_advanced)
DetailTab.Security -> stringResource(R.string.detail_tab_security)
})
},
)
@@ -276,7 +301,11 @@ fun ConnectionDetailScreen(
onOpenApiInfo = { showApiInfoSheet = true },
onOpenDashboard = onNavigateToManage,
onOpenRelayInfo = { showRelayInfoSheet = true },
onOpenSessionInfo = { showSessionInfoSheet = true },
onOpenRoutes = {
selectedTab = tabs.indexOf(DetailTab.Routes)
.takeIf { it >= 0 }
?: selectedTab
},
)
} else {
InactiveOverview(
@@ -291,8 +320,22 @@ fun ConnectionDetailScreen(
connectionViewModel = connectionViewModel,
connection = connection,
liveState = relayUiState,
onEditDashboard = {
selectedTab = tabs.indexOf(DetailTab.Advanced)
onEditDashboard = { showDashboardEditor = true },
)
DetailTab.Access -> ActiveCardSecurityPosture(
connectionViewModel = connectionViewModel,
onNavigateToPairedDevices = onNavigateToPairedDevices,
onRevokeRelay = { showRevokeConfirm = true },
onOpenDashboardSignIn = onNavigateToManage,
onUseSelectedRoute = {
connectionViewModel.useSelectedDashboardRoute { result ->
result.onFailure {
scope.launch {
snackbarHost.showSnackbar(routeResetFailed)
}
}
}
},
)
@@ -302,12 +345,6 @@ fun ConnectionDetailScreen(
onPairRelay = { onRepair(connectionId) },
onInsecureAckRequested = { showInsecureAckDialog = true },
)
DetailTab.Security -> ActiveCardSecurityPosture(
connectionViewModel = connectionViewModel,
onNavigateToPairedDevices = onNavigateToPairedDevices,
onRevokeRelay = { showRevokeConfirm = true },
)
}
Spacer(modifier = Modifier.height(24.dp))
@@ -316,12 +353,6 @@ fun ConnectionDetailScreen(
}
// ── Screen-scope sheets + dialogs ────────────────────────────────────
if (showSessionInfoSheet) {
SessionInfoSheet(
connectionViewModel = connectionViewModel,
onDismiss = { showSessionInfoSheet = false },
)
}
if (showApiInfoSheet) {
ApiServerInfoSheet(
connectionViewModel = connectionViewModel,
@@ -344,6 +375,15 @@ fun ConnectionDetailScreen(
onCancel = { showInsecureAckDialog = false },
)
}
if (showDashboardEditor) {
DashboardAddressEditorDialog(
initialUrl = connection.resolvedDashboardUrl,
onSave = { dashboardUrl, onResult ->
connectionViewModel.updateDashboardAddress(dashboardUrl, onResult)
},
onDismiss = { showDashboardEditor = false },
)
}
if (showRenameDialog) {
RenameConnectionDialog(
initialLabel = connection.label,
@@ -400,17 +440,22 @@ fun ConnectionDetailScreen(
}
}
private enum class DetailTab {
internal enum class DetailTab {
Overview,
Routes,
Access,
Advanced,
Security,
}
internal fun detailTabs(isActive: Boolean): List<DetailTab> = if (isActive) {
listOf(DetailTab.Overview, DetailTab.Routes, DetailTab.Access, DetailTab.Advanced)
} else {
listOf(DetailTab.Overview)
}
/**
* Overview for the **active** connection: a one-line status header followed
* by the steps/timeline capability list ([ActiveCardFeaturesSection]) and
* quick actions. The timeline is intentionally the hero of this tab.
* Overview for the **active** connection: the selected route, the three
* standard upstream outcomes, and optional Relay/API drill-down rows.
*/
@Composable
private fun ActiveOverview(
@@ -422,80 +467,165 @@ private fun ActiveOverview(
onOpenApiInfo: () -> Unit,
onOpenDashboard: () -> Unit,
onOpenRelayInfo: () -> Unit,
onOpenSessionInfo: () -> Unit,
onOpenRoutes: () -> Unit,
) {
val hostname = connection.primaryHost.ifBlank { connection.label }
val dashboardReady = connection.dashboardLastStatus?.reachable == true
val gatewayAvailability by connectionViewModel.gatewayAvailability.collectAsState()
val apiReachable by connectionViewModel.apiServerReachable.collectAsState()
val apiHealth by connectionViewModel.apiServerHealth.collectAsState()
val activeEndpoint by connectionViewModel.activeEndpoint.collectAsState()
val effectiveDashboardUrl by connectionViewModel.effectiveDashboardUrl.collectAsState()
val relayConfigured by connectionViewModel.relayConfigured.collectAsState()
val standardVoiceAvailability by connectionViewModel.standardVoiceAvailability.collectAsState()
val usingApiFallback = apiReachable && gatewayAvailability in setOf(
GatewayAvailability.SignInRequired,
GatewayAvailability.Unreachable,
GatewayAvailability.Unsupported,
)
val currentRouteUrl = if (usingApiFallback) {
activeEndpoint?.api?.url ?: connection.apiServerUrl
} else {
effectiveDashboardUrl
}
Surface(
color = MaterialTheme.colorScheme.surfaceVariant,
shape = RoundedCornerShape(12.dp),
modifier = Modifier.fillMaxWidth(),
val route = resolveDetailRoutePresentation(
activeEndpoint = activeEndpoint,
effectiveDashboardUrl = currentRouteUrl,
)
val routeStatus = when {
gatewayAvailability == GatewayAvailability.Ready || usingApiFallback ->
OverviewStatus(stringResource(R.string.active_section_reachable), OverviewTone.Good)
gatewayAvailability == GatewayAvailability.SignInRequired ->
OverviewStatus(stringResource(R.string.active_section_sign_in), OverviewTone.Info)
gatewayAvailability == GatewayAvailability.Unknown ||
apiHealth == ConnectionViewModel.HealthStatus.Probing ->
OverviewStatus(stringResource(R.string.active_section_checking), OverviewTone.Neutral)
gatewayAvailability == GatewayAvailability.Unsupported ->
OverviewStatus(stringResource(R.string.active_section_unsupported), OverviewTone.Warning)
else -> OverviewStatus(stringResource(R.string.active_section_unreachable), OverviewTone.Warning)
}
val chatStatus = when {
gatewayAvailability == GatewayAvailability.Ready || usingApiFallback ->
OverviewStatus(stringResource(R.string.active_section_ready), OverviewTone.Good)
gatewayAvailability == GatewayAvailability.SignInRequired ->
OverviewStatus(stringResource(R.string.active_section_sign_in), OverviewTone.Info)
gatewayAvailability == GatewayAvailability.Unreachable && !apiReachable ->
OverviewStatus(stringResource(R.string.active_section_offline), OverviewTone.Warning)
else -> OverviewStatus(stringResource(R.string.active_section_checking), OverviewTone.Neutral)
}
val dashboardStatus = connection.dashboardLastStatus
val dashboardSignInRequired =
dashboardStatus?.authRequired == true && dashboardStatus.authenticated != true
val manageStatus = when {
connection.resolvedDashboardUrl.isBlank() ->
OverviewStatus(stringResource(R.string.active_section_missing), OverviewTone.Warning)
dashboardStatus == null ->
OverviewStatus(stringResource(R.string.active_section_unchecked), OverviewTone.Neutral)
!dashboardStatus.reachable ->
OverviewStatus(stringResource(R.string.active_section_offline), OverviewTone.Warning)
dashboardSignInRequired ->
OverviewStatus(stringResource(R.string.active_section_sign_in), OverviewTone.Info)
else -> OverviewStatus(stringResource(R.string.active_section_ready), OverviewTone.Good)
}
val voiceStatus = when (standardVoiceAvailability) {
StandardVoiceAvailability.Ready ->
OverviewStatus(stringResource(R.string.active_section_ready), OverviewTone.Good)
StandardVoiceAvailability.SignInRequired ->
OverviewStatus(stringResource(R.string.active_section_sign_in), OverviewTone.Info)
StandardVoiceAvailability.Unsupported ->
OverviewStatus(stringResource(R.string.active_section_unsupported), OverviewTone.Warning)
StandardVoiceAvailability.Unreachable ->
OverviewStatus(stringResource(R.string.active_section_offline), OverviewTone.Warning)
StandardVoiceAvailability.Unknown ->
OverviewStatus(stringResource(R.string.active_section_checking), OverviewTone.Neutral)
}
val relayStatus = when (relayUiState) {
RelayUiState.NotConfigured ->
OverviewStatus(stringResource(R.string.relay_state_optional), OverviewTone.Neutral)
RelayUiState.Connected ->
OverviewStatus(stringResource(R.string.relay_state_ready), OverviewTone.Good)
RelayUiState.Connecting ->
OverviewStatus(stringResource(R.string.relay_state_reconnecting), OverviewTone.Info)
RelayUiState.Stale,
RelayUiState.Disconnected ->
OverviewStatus(stringResource(R.string.relay_state_unavailable), OverviewTone.Warning)
RelayUiState.Expired ->
OverviewStatus(stringResource(R.string.relay_state_needs_repair), OverviewTone.Warning)
}
val apiStatus = when (
resolveOptionalApiPresentation(
gatewayReady = gatewayAvailability == GatewayAvailability.Ready,
apiReachable = apiReachable,
apiConfigured = connection.apiServerUrl.isNotBlank(),
apiProbing = apiHealth == ConnectionViewModel.HealthStatus.Probing,
)
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Icon(
imageVector = Icons.Filled.Dashboard,
contentDescription = null,
tint = MaterialTheme.colorScheme.primary,
)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.detail_dashboard_primary),
style = MaterialTheme.typography.titleMedium,
)
Text(
text = connection.resolvedDashboardUrl.ifBlank { hostname },
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
HorizontalDivider()
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Icon(
imageVector = Icons.Filled.CheckCircle,
contentDescription = null,
tint = if (dashboardReady) Color(0xFF4CAF50) else MaterialTheme.colorScheme.primary,
modifier = Modifier.size(20.dp),
)
Text(
text = if (dashboardReady) {
stringResource(R.string.detail_core_ready)
} else {
stringResource(R.string.detail_core_configured)
},
style = MaterialTheme.typography.bodyMedium,
color = if (dashboardReady) Color(0xFF4CAF50) else MaterialTheme.colorScheme.onSurface,
)
}
}
OptionalApiPresentation.Checking ->
OverviewStatus(stringResource(R.string.active_section_checking), OverviewTone.Neutral)
OptionalApiPresentation.Ready ->
OverviewStatus(stringResource(R.string.active_section_ready), OverviewTone.Good)
OptionalApiPresentation.Optional ->
OverviewStatus(stringResource(R.string.relay_state_optional), OverviewTone.Neutral)
OptionalApiPresentation.Offline ->
OverviewStatus(stringResource(R.string.active_section_offline), OverviewTone.Warning)
}
Text(
text = stringResource(R.string.detail_overview_summary),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
text = stringResource(R.string.detail_current_route),
style = MaterialTheme.typography.titleSmall,
)
CurrentRouteOverviewCard(
route = route,
status = routeStatus,
onEdit = onOpenRoutes,
)
ActiveCardFeaturesSection(
connectionViewModel = connectionViewModel,
onOpenApiInfo = onOpenApiInfo,
onOpenDashboard = onOpenDashboard,
onOpenRelayInfo = onOpenRelayInfo,
onOpenSessionInfo = onOpenSessionInfo,
onPairRelay = onRepair,
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
OverviewCapabilityCard(
icon = Icons.Filled.Chat,
label = stringResource(R.string.conn_chat_label),
status = chatStatus,
modifier = Modifier.weight(1f),
)
OverviewCapabilityCard(
icon = Icons.Filled.Dashboard,
label = stringResource(R.string.conn_manage_label),
status = manageStatus,
modifier = Modifier.weight(1f),
onClick = onOpenDashboard,
)
OverviewCapabilityCard(
icon = Icons.Filled.GraphicEq,
label = stringResource(R.string.conn_voice_label),
status = voiceStatus,
modifier = Modifier.weight(1f),
onClick = if (
standardVoiceAvailability == StandardVoiceAvailability.SignInRequired
) {
onOpenDashboard
} else {
null
},
)
}
HorizontalDivider(modifier = Modifier.padding(top = 4.dp))
OverviewOptionalRow(
icon = Icons.Filled.Link,
label = stringResource(R.string.active_section_relay_connected_features),
description = stringResource(R.string.active_section_relay_optional_summary),
status = relayStatus,
onClick = if (relayConfigured) onOpenRelayInfo else onRepair,
)
HorizontalDivider()
OverviewOptionalRow(
icon = Icons.Filled.Code,
label = stringResource(R.string.api_fallback_title),
description = stringResource(R.string.active_section_api_not_required),
status = apiStatus,
onClick = onOpenApiInfo,
)
Row(
@@ -508,6 +638,220 @@ private fun ActiveOverview(
}
}
private enum class OverviewTone { Neutral, Good, Info, Warning }
internal enum class OptionalApiPresentation { Checking, Ready, Optional, Offline }
internal fun resolveOptionalApiPresentation(
gatewayReady: Boolean,
apiReachable: Boolean,
apiConfigured: Boolean,
apiProbing: Boolean,
): OptionalApiPresentation = when {
apiProbing -> OptionalApiPresentation.Checking
apiReachable -> OptionalApiPresentation.Ready
gatewayReady || !apiConfigured -> OptionalApiPresentation.Optional
else -> OptionalApiPresentation.Offline
}
private data class OverviewStatus(
val text: String,
val tone: OverviewTone,
)
@Composable
private fun overviewStatusColor(status: OverviewStatus): Color = when (status.tone) {
OverviewTone.Good -> com.hermesandroid.relay.ui.theme.RelayRefresh.Green
OverviewTone.Info -> MaterialTheme.colorScheme.primary
OverviewTone.Warning -> MaterialTheme.colorScheme.error
OverviewTone.Neutral -> MaterialTheme.colorScheme.onSurfaceVariant
}
internal data class DetailRoutePresentation(
val label: String,
val address: String,
)
internal fun resolveDetailRoutePresentation(
activeEndpoint: EndpointCandidate?,
effectiveDashboardUrl: String,
): DetailRoutePresentation {
val candidateGatewayUrl = activeEndpoint?.gatewayRouteUrl()
val address = effectiveDashboardUrl.trim().trimEnd('/').takeIf { it.isNotBlank() }
?: candidateGatewayUrl.orEmpty()
val candidateOwnsAddress = candidateGatewayUrl != null &&
address.isNotBlank() &&
sameGatewayRouteBase(candidateGatewayUrl, address)
val inferredRole = activeEndpoint?.role
?.lowercase()
?.takeIf { candidateOwnsAddress }
?: Connection.inferRouteRole(address)
val role = when (inferredRole) {
"lan" -> "LAN"
"tailscale" -> "Tailscale"
"public" -> "Public"
"https" -> "Public"
"dashboard", "authenticated_dashboard" -> "Dashboard"
else -> activeEndpoint?.displayLabel()?.takeIf { candidateOwnsAddress } ?: "Gateway"
}
val transport = when {
address.startsWith("https://", ignoreCase = true) -> "HTTPS"
address.startsWith("http://", ignoreCase = true) -> "HTTP"
else -> null
}
val label = transport?.let { if (role.equals(it, ignoreCase = true)) role else "$role ($it)" }
?: role
return DetailRoutePresentation(label = label, address = address)
}
@Composable
private fun CurrentRouteOverviewCard(
route: DetailRoutePresentation,
status: OverviewStatus,
onEdit: () -> Unit,
) {
Surface(
color = MaterialTheme.colorScheme.surfaceVariant,
shape = RoundedCornerShape(12.dp),
modifier = Modifier.fillMaxWidth(),
) {
Column(
modifier = Modifier.padding(horizontal = 16.dp, vertical = 12.dp),
verticalArrangement = Arrangement.spacedBy(6.dp),
) {
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(10.dp),
) {
Icon(
imageVector = Icons.Filled.Language,
contentDescription = null,
tint = MaterialTheme.colorScheme.primary,
modifier = Modifier.size(26.dp),
)
Column(modifier = Modifier.weight(1f)) {
Text(text = route.label, style = MaterialTheme.typography.titleSmall)
Text(
text = status.text,
style = MaterialTheme.typography.bodySmall,
color = overviewStatusColor(status),
)
}
TextButton(onClick = onEdit) {
Icon(
imageVector = Icons.Filled.Edit,
contentDescription = null,
modifier = Modifier.size(18.dp),
)
Spacer(modifier = Modifier.size(6.dp))
Text(stringResource(R.string.active_section_edit))
}
}
Text(
text = route.address.ifBlank { stringResource(R.string.active_section_not_configured) },
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
fontFamily = FontFamily.Monospace,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
}
@Composable
private fun OverviewCapabilityCard(
icon: ImageVector,
label: String,
status: OverviewStatus,
modifier: Modifier = Modifier,
onClick: (() -> Unit)? = null,
) {
Surface(
color = MaterialTheme.colorScheme.surfaceVariant,
shape = RoundedCornerShape(12.dp),
modifier = modifier.then(
if (onClick != null) {
Modifier.clickable(onClickLabel = label, onClick = onClick)
} else {
Modifier
},
),
) {
Column(
modifier = Modifier.padding(horizontal = 8.dp, vertical = 16.dp),
horizontalAlignment = Alignment.CenterHorizontally,
verticalArrangement = Arrangement.spacedBy(6.dp),
) {
Icon(
imageVector = icon,
contentDescription = null,
modifier = Modifier.size(24.dp),
)
Text(
text = label,
style = MaterialTheme.typography.labelLarge,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
Text(
text = status.text,
style = MaterialTheme.typography.labelMedium,
color = overviewStatusColor(status),
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
}
@Composable
private fun OverviewOptionalRow(
icon: ImageVector,
label: String,
description: String,
status: OverviewStatus,
onClick: () -> Unit,
) {
Row(
modifier = Modifier
.fillMaxWidth()
.clickable(onClickLabel = label, onClick = onClick)
.padding(vertical = 12.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Icon(
imageVector = icon,
contentDescription = null,
tint = MaterialTheme.colorScheme.onSurface,
modifier = Modifier.size(24.dp),
)
Column(modifier = Modifier.weight(1f)) {
Text(text = label, style = MaterialTheme.typography.titleSmall)
Text(
text = description,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
)
}
Text(
text = status.text,
style = MaterialTheme.typography.labelSmall,
color = overviewStatusColor(status),
maxLines = 1,
)
Icon(
imageVector = Icons.Filled.ChevronRight,
contentDescription = null,
tint = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
}
}
/**
* Overview for a **non-active** connection. The deep live content reads the
* single active-connection VM state, so rather than show stale/foreign data
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -248,7 +248,11 @@ fun DiagnosticsScreen(
onClick = {
scope.launch {
supportReview = withContext(Dispatchers.IO) {
buildSupportReviewState(ReliabilityCenter.reports(context))
buildSupportReviewState(
reports = ReliabilityCenter.reports(context),
diagnostics = entries,
environment = ReliabilityCenter.environment(),
)
}
}
},
@@ -20,6 +20,7 @@ import androidx.compose.foundation.lazy.items
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.selection.toggleable
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.ArrowBack
@@ -52,6 +53,7 @@ import androidx.compose.material3.OutlinedButton
import androidx.compose.material3.OutlinedTextField
import androidx.compose.material3.Scaffold
import androidx.compose.material3.Surface
import androidx.compose.material3.Switch
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.material3.TopAppBar
@@ -68,6 +70,7 @@ import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.contentDescription
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.text.font.FontWeight
@@ -98,7 +101,11 @@ private data class DisplayFile(
/** First-class native Git workspace backed by the optional Relay contribution. */
@OptIn(ExperimentalMaterial3Api::class)
@Composable
fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
fun GitStateScreen(
viewModel: GitStateViewModel,
onScanningEnabledChange: (Boolean) -> Unit,
onBack: () -> Unit,
) {
val reposState by viewModel.repos.collectAsState()
val detailState by viewModel.detail.collectAsState()
val contentState by viewModel.content.collectAsState()
@@ -107,6 +114,7 @@ fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
val stashNotice by viewModel.stashNotice.collectAsState()
val hasGrant by viewModel.writeGrant.collectAsState()
val selectedRepoId by viewModel.selectedRepoId.collectAsState()
val scanningEnabled by viewModel.scanningEnabled.collectAsState()
// A path can be staged and modified at the same time. Keep the category in
// the selection identity so selecting one row never silently selects the
@@ -122,6 +130,10 @@ fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
var pushAfter by rememberSaveable { mutableStateOf(false) }
var pendingConfirm by remember { mutableStateOf<ConfirmationRequest?>(null) }
LaunchedEffect(scanningEnabled) {
if (scanningEnabled) viewModel.loadRepos()
}
val repos = (reposState as? GitStateUiState.Ready)?.repos.orEmpty()
val selectedRepo = repos.firstOrNull { it.id == selectedRepoId }
val detail = detailState as? GitRepoDetailState.Ready
@@ -190,21 +202,23 @@ fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
}
},
actions = {
IconButton(onClick = { selectedRepo?.let { viewModel.selectRepo(it.id) } ?: viewModel.loadRepos() }) {
Icon(Icons.Filled.Refresh, "Refresh Git workspace")
}
Box {
IconButton(onClick = { showOverflow = true }) { Icon(Icons.Filled.MoreVert, "More Git actions") }
DropdownMenu(expanded = showOverflow, onDismissRequest = { showOverflow = false }) {
DropdownMenuItem(text = { Text("Choose repository") }, onClick = { showOverflow = false; showRepos = true })
DropdownMenuItem(text = { Text(stringResource(R.string.git_state_branches)) }, enabled = detail != null, onClick = { showOverflow = false; showBranches = true })
if (scanningEnabled) {
IconButton(onClick = { selectedRepo?.let { viewModel.selectRepo(it.id) } ?: viewModel.loadRepos() }) {
Icon(Icons.Filled.Refresh, "Refresh Git workspace")
}
Box {
IconButton(onClick = { showOverflow = true }) { Icon(Icons.Filled.MoreVert, "More Git actions") }
DropdownMenu(expanded = showOverflow, onDismissRequest = { showOverflow = false }) {
DropdownMenuItem(text = { Text("Choose repository") }, onClick = { showOverflow = false; showRepos = true })
DropdownMenuItem(text = { Text(stringResource(R.string.git_state_branches)) }, enabled = detail != null, onClick = { showOverflow = false; showBranches = true })
}
}
}
},
)
},
bottomBar = {
if (detail != null) {
if (scanningEnabled && detail != null) {
Surface(shadowElevation = 8.dp, tonalElevation = 2.dp) {
Column {
if (selection.isNotEmpty()) {
@@ -229,47 +243,55 @@ fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
}
},
) { padding ->
when (val state = reposState) {
GitStateUiState.Loading -> FullState(Modifier.padding(padding), true, "Finding repositories")
is GitStateUiState.Unavailable -> UnavailableState(Modifier.padding(padding), state.message, viewModel::loadRepos)
is GitStateUiState.Error -> UnavailableState(Modifier.padding(padding), state.message, viewModel::loadRepos)
is GitStateUiState.Ready -> when {
state.repos.isEmpty() -> FullState(Modifier.padding(padding), false, "No Git repositories found", "Add a repository to the host's configured Git roots, then refresh.")
selectedRepo == null -> RepositoryPrompt(Modifier.padding(padding), state.repos, viewModel::selectRepo)
else -> WorkspaceBody(
modifier = Modifier.padding(padding),
repo = selectedRepo,
reposNotice = state.notice,
detailState = detailState,
mutation = mutation,
stashNotice = stashNotice,
hasGrant = hasGrant,
filter = filter,
onFilter = { filter = it },
selection = selection,
onToggleSelected = { file ->
selection = if (file in selection) selection - file else selection + file
},
expandedPath = expandedPath,
contentMode = contentMode,
contentState = contentState,
onOpen = { file, mode ->
if (file.filter != FileFilter.Untracked) {
val opening = expandedPath != file.path || contentMode != mode
expandedPath = if (opening) file.path else null
contentMode = mode
if (opening) {
if (mode == ContentMode.File) viewModel.loadFile(file.path)
else viewModel.loadDiff(file.path, if (file.filter == FileFilter.Staged) "staged" else "unstaged")
}
}
},
onFetch = viewModel::fetch,
onPull = viewModel::pull,
onPush = { viewModel.currentTarget()?.let { pendingConfirm = ConfirmationRequest.Push(it) } },
onClearMutation = viewModel::clearMutationError,
onRetry = { viewModel.selectRepo(selectedRepo.id) },
)
Column(Modifier.padding(padding).fillMaxSize()) {
GitScanningConsentCard(
enabled = scanningEnabled,
onEnabledChange = onScanningEnabledChange,
)
if (scanningEnabled) {
when (val state = reposState) {
GitStateUiState.Loading -> FullState(Modifier.weight(1f), true, "Finding repositories")
is GitStateUiState.Unavailable -> UnavailableState(Modifier.weight(1f), state.message, viewModel::loadRepos)
is GitStateUiState.Error -> UnavailableState(Modifier.weight(1f), state.message, viewModel::loadRepos)
is GitStateUiState.Ready -> when {
state.repos.isEmpty() -> FullState(Modifier.weight(1f), false, "No Git repositories found", "Add a repository to the host's configured Git roots, then refresh.")
selectedRepo == null -> RepositoryPrompt(Modifier.weight(1f), state.repos, viewModel::selectRepo)
else -> WorkspaceBody(
modifier = Modifier.weight(1f),
repo = selectedRepo,
reposNotice = state.notice,
detailState = detailState,
mutation = mutation,
stashNotice = stashNotice,
hasGrant = hasGrant,
filter = filter,
onFilter = { filter = it },
selection = selection,
onToggleSelected = { file ->
selection = if (file in selection) selection - file else selection + file
},
expandedPath = expandedPath,
contentMode = contentMode,
contentState = contentState,
onOpen = { file, mode ->
if (file.filter != FileFilter.Untracked) {
val opening = expandedPath != file.path || contentMode != mode
expandedPath = if (opening) file.path else null
contentMode = mode
if (opening) {
if (mode == ContentMode.File) viewModel.loadFile(file.path)
else viewModel.loadDiff(file.path, if (file.filter == FileFilter.Staged) "staged" else "unstaged")
}
}
},
onFetch = viewModel::fetch,
onPull = viewModel::pull,
onPush = { viewModel.currentTarget()?.let { pendingConfirm = ConfirmationRequest.Push(it) } },
onClearMutation = viewModel::clearMutationError,
onRetry = { viewModel.selectRepo(selectedRepo.id) },
)
}
}
}
}
}
@@ -317,6 +339,51 @@ fun GitStateScreen(viewModel: GitStateViewModel, onBack: () -> Unit) {
}
}
@Composable
private fun GitScanningConsentCard(
enabled: Boolean,
onEnabledChange: (Boolean) -> Unit,
) {
Surface(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 16.dp, vertical = 8.dp)
.toggleable(
value = enabled,
role = Role.Switch,
onValueChange = onEnabledChange,
),
shape = RoundedCornerShape(12.dp),
color = MaterialTheme.colorScheme.surfaceContainer,
) {
Row(
modifier = Modifier.padding(horizontal = 14.dp, vertical = 12.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Icon(Icons.Filled.AccountTree, contentDescription = null)
Column(Modifier.weight(1f), verticalArrangement = Arrangement.spacedBy(3.dp)) {
Text(
text = stringResource(R.string.git_state_host_scanning),
style = MaterialTheme.typography.bodyLarge,
)
Text(
text = stringResource(
if (enabled) {
R.string.git_state_host_scanning_on_desc
} else {
R.string.git_state_host_scanning_off_desc
},
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Switch(checked = enabled, onCheckedChange = null)
}
}
}
@Composable
private fun WorkspaceBody(
modifier: Modifier,
@@ -48,7 +48,7 @@ private const val PAIR_SETUP_TIMEOUT_MS = 15_000L
* Full-screen connection route. Wraps [ConnectionWizard] in a real Scaffold so
* the chooser tiles, manual-entry forms, and camera viewport all get the
* actual window — not a Compose Dialog that leaked the Settings cards
* underneath. Reached via Settings → Connections → Add/Pair Relay (or any "Re-pair"
* underneath. Reached via Settings → Gateways → Access → Pair Relay (or any "Re-pair"
* button), and pops back to wherever it came from on complete or cancel.
*
* [autoStart] lets the caller deep-link into a specific pair method. When
@@ -70,8 +70,8 @@ fun PairScreen(
onConnectionTargetChanged: (String) -> Unit = {},
/**
* Optional offline "Try the demo" entry, forwarded to [ConnectionWizard].
* Wired by [RelayApp] only for the bare Connect entry (no placeholder
* connection in flight); null on add-connection / re-pair flows.
* Wired by [RelayApp] only for the bare Connect entry (no connection draft
* in flight); null on add-connection / re-pair flows.
*/
onTryDemo: (() -> Unit)? = null,
) {
@@ -88,12 +88,10 @@ fun PairScreen(
}
}
// Route system back / predictive back through the same discard path
// Route system back / predictive back through the same draft-discard path
// the TopAppBar arrow uses. Without this, the NavController just pops
// the backstack and [RelayApp]'s wired `discardPlaceholderConnection`
// in the Pair route's `onCancel` never fires — leaving the placeholder
// orphaned in the connection list. Matches the defensive sweep in
// [ConnectionViewModel.init] but fires at the right moment.
// in the Pair route's `onCancel` never fires.
BackHandler(enabled = true) { onCancel() }
Scaffold(
@@ -172,6 +172,7 @@ fun SettingsScreen(
// `connection · model · personality` without re-reading ChatViewModel
// state from a different place.
chatViewModel: ChatViewModel,
gitRepoScanningEnabled: Boolean,
// (The `onNavigateToChatWithAgentSheet` param that used to live here
// was removed as part of the 2026-04-21 pairing-audit fix. Tapping the
// Active Agent card now opens the consolidated AgentInfoSheet INLINE
@@ -608,7 +609,13 @@ fun SettingsScreen(
SettingsCategoryRow(
icon = Icons.Filled.AccountTree,
title = stringResource(R.string.settings_git_workspace),
subtitle = stringResource(R.string.settings_git_workspace_desc),
subtitle = stringResource(
if (gitRepoScanningEnabled) {
R.string.settings_git_workspace_desc
} else {
R.string.settings_git_workspace_off_desc
},
),
onClick = onNavigateToGitWorkspace,
isDarkTheme = isDarkTheme,
)
@@ -1017,7 +1024,7 @@ private fun QuickControlsCard(
val context = LocalContext.current
val notificationPermissionLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.RequestPermission(),
) { /* Posting re-checks the grant. */ }
) { granted -> connectionViewModel.setNotifyTurnComplete(granted) }
val requestNotificationPermission = {
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU &&
androidx.core.content.ContextCompat.checkSelfPermission(
@@ -257,7 +257,10 @@ private fun classifyErrorInternal(t: Throwable?, context: String?, ctx: Context?
val msg = t.message.orEmpty().lowercase()
if ("cannot create audiorecord" in msg || "audiorecord failed to initialize" in msg) {
if ("cannot create audiorecord" in msg ||
"audiorecord failed to initialize" in msg ||
"microphone is in use by another voice feature" in msg
) {
return HumanError(
title = ctx?.getString(R.string.error_classify_mic_unavailable) ?: "Microphone unavailable",
body = ctx?.getString(R.string.error_classify_mic_unavailable_body)
File diff suppressed because it is too large Load Diff
File diff suppressed because it is too large Load Diff
@@ -109,6 +109,8 @@ class GitStateViewModel(application: Application) : AndroidViewModel(application
private val _selectedRepoId = MutableStateFlow<String?>(null)
val selectedRepoId: StateFlow<String?> = _selectedRepoId.asStateFlow()
private val _scanningEnabled = MutableStateFlow(false)
val scanningEnabled: StateFlow<Boolean> = _scanningEnabled.asStateFlow()
private var api: GitStateApiClient? = null
private var reposJob: Job? = null
@@ -118,31 +120,33 @@ class GitStateViewModel(application: Application) : AndroidViewModel(application
private var messageJob: Job? = null
private var scopeKey: String? = null
private var targetGeneration: Long = 0
fun selectedRepoIdForDisplay(): String? = _selectedRepoId.value
fun currentTarget(): GitTarget? {
if (!_scanningEnabled.value) return null
val owner = scopeKey ?: return null
val repo = _selectedRepoId.value ?: return null
return GitTarget(owner, repo, targetGeneration)
}
fun configure(dashboard: DashboardApiClient?, ownerKey: String?) {
reposJob?.cancel()
detailJob?.cancel()
contentJob?.cancel()
mutationJob?.cancel()
messageJob?.cancel()
fun configure(
dashboard: DashboardApiClient?,
ownerKey: String?,
scanningEnabled: Boolean,
) {
clearWorkspaceState()
targetGeneration += 1
scopeKey = ownerKey
_selectedRepoId.value = null
_scanningEnabled.value = scanningEnabled
_writeGrant.value = false
_detail.value = GitRepoDetailState.Idle
_content.value = GitContentViewState.Idle
_mutation.value = GitMutationState.Idle
_messageGeneration.value = GitMessageGenerationState.Idle
_stashNotice.value = null
api = dashboard?.let(::GitStateApiClient)
loadRepos()
}
fun setScanningEnabled(enabled: Boolean) {
if (_scanningEnabled.value == enabled) return
_scanningEnabled.value = enabled
if (!enabled) clearWorkspaceState()
}
/** Grants the plugin.api.write capability for this connection/profile. */
@@ -154,6 +158,7 @@ class GitStateViewModel(application: Application) : AndroidViewModel(application
fun hasWriteGrant(): Boolean = _writeGrant.value
fun loadRepos() {
if (!_scanningEnabled.value) return
val client = api ?: run {
_repos.value = GitStateUiState.Error("Dashboard connection unavailable")
return
@@ -187,7 +192,23 @@ class GitStateViewModel(application: Application) : AndroidViewModel(application
}
}
private fun clearWorkspaceState() {
reposJob?.cancel()
detailJob?.cancel()
contentJob?.cancel()
mutationJob?.cancel()
messageJob?.cancel()
_repos.value = GitStateUiState.Loading
_detail.value = GitRepoDetailState.Idle
_content.value = GitContentViewState.Idle
_mutation.value = GitMutationState.Idle
_messageGeneration.value = GitMessageGenerationState.Idle
_stashNotice.value = null
_selectedRepoId.value = null
}
fun selectRepo(repoId: String) {
if (!_scanningEnabled.value) return
val client = api ?: return
targetGeneration += 1
_selectedRepoId.value = repoId
@@ -0,0 +1,276 @@
package com.hermesandroid.relay.viewmodel
import com.hermesandroid.relay.network.upstream.GatewaySubagentEvent
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
internal enum class SubagentActivityPhase {
STARTED,
THINKING,
TOOL,
PROGRESS,
COMPLETED,
FAILED,
INTERRUPTED,
ENDED_WITH_PARENT,
}
internal enum class SubagentActivityEventKind { STARTED, UPDATE, TOOL, COMPLETED }
internal data class SubagentActivityEvent(
val sequence: Long,
val kind: SubagentActivityEventKind,
val text: String? = null,
val toolName: String? = null,
val phase: SubagentActivityPhase,
val observedAtMillis: Long,
)
/**
* A bounded, ephemeral projection of parent-session `subagent.*` events.
*
* This is intentionally not a child transcript. Upstream currently exposes no
* durable child-session key or child-history route, so the projection is owned
* by the exact profile-scoped parent session and parent turn that emitted it.
*/
internal data class SubagentActivity(
val laneId: Long,
val turnId: String,
val taskIndex: Int,
val taskCount: Int,
val goal: String,
val subagentId: String? = null,
val childSessionId: String? = null,
val parentId: String? = null,
val depth: Int? = null,
val model: String? = null,
val profile: String? = null,
val phase: SubagentActivityPhase,
val summary: String? = null,
val durationSeconds: Double? = null,
val events: List<SubagentActivityEvent> = emptyList(),
val truncated: Boolean = false,
val partialAfterGap: Boolean = false,
val revision: Long = 0L,
) {
val stableKey: String
get() = "$turnId:$laneId"
val isTerminal: Boolean
get() = phase in setOf(
SubagentActivityPhase.COMPLETED,
SubagentActivityPhase.FAILED,
SubagentActivityPhase.INTERRUPTED,
SubagentActivityPhase.ENDED_WITH_PARENT,
)
}
/**
* Keeps live child activity isolated from the unrelated `process.list`
* registry. All text is control-sanitized and bounded before entering UI state.
*/
internal class SubagentActivityController(
private val clock: () -> Long = System::currentTimeMillis,
) {
companion object {
internal const val MAX_EVENTS_PER_CHILD = 50
internal const val MAX_CHARS_PER_CHILD = 32_000
internal const val MAX_GOAL_CHARS = 500
internal const val MAX_EVENT_TEXT_CHARS = 2_000
internal const val MAX_TOOL_NAME_CHARS = 160
}
private val _activities = MutableStateFlow<List<SubagentActivity>>(emptyList())
val activities: StateFlow<List<SubagentActivity>> = _activities.asStateFlow()
private var storedSessionId: String? = null
private var scopeKey: String? = null
private var activeTurnId: String? = null
private var sequence = 0L
private var laneSequence = 0L
private var connectionWasReady = false
private var pendingGap = false
fun selectSession(sessionId: String?, newScopeKey: String?) {
if (storedSessionId == sessionId && scopeKey == newScopeKey) return
storedSessionId = sessionId
scopeKey = newScopeKey
activeTurnId = null
sequence = 0L
laneSequence = 0L
connectionWasReady = false
pendingGap = false
_activities.value = emptyList()
}
fun resetConnection() {
activeTurnId = null
sequence = 0L
laneSequence = 0L
connectionWasReady = false
pendingGap = false
_activities.value = emptyList()
}
fun onConnectionReady(ready: Boolean) {
if (connectionWasReady && !ready && _activities.value.any { !it.isTerminal }) {
pendingGap = true
}
if (ready && pendingGap) {
_activities.value = _activities.value.map { activity ->
if (activity.isTerminal) activity else activity.copy(
partialAfterGap = true,
revision = activity.revision + 1,
)
}
pendingGap = false
}
connectionWasReady = ready
}
fun beginTurn(sessionId: String?, eventScopeKey: String?, turnId: String) {
if (sessionId == null || sessionId != storedSessionId || eventScopeKey != scopeKey) return
if (activeTurnId == turnId) return
activeTurnId = turnId
sequence = 0L
laneSequence = 0L
_activities.value = emptyList()
}
fun onEvent(
sessionId: String?,
eventScopeKey: String?,
turnId: String,
event: GatewaySubagentEvent,
profile: String? = null,
) {
if (sessionId == null || sessionId != storedSessionId || eventScopeKey != scopeKey) return
if (activeTurnId != turnId) return
val taskIndex = event.taskIndex.coerceAtLeast(0)
val eventIdentity = event.subagentId?.takeIf(String::isNotBlank)
?: event.childSessionId?.takeIf(String::isNotBlank)
val identityMatch = eventIdentity?.let { identity ->
_activities.value.firstOrNull {
it.subagentId == identity || it.childSessionId == identity
}
}
val compatibleIndexMatches = _activities.value.filter { activity ->
activity.taskIndex == taskIndex &&
(event.subagentId.isNullOrBlank() || activity.subagentId.isNullOrBlank() ||
event.subagentId == activity.subagentId) &&
(event.childSessionId.isNullOrBlank() || activity.childSessionId.isNullOrBlank() ||
event.childSessionId == activity.childSessionId) &&
(event.parentId.isNullOrBlank() || activity.parentId.isNullOrBlank() ||
event.parentId == activity.parentId) &&
(event.depth == null || activity.depth == null || event.depth == activity.depth)
}
val current = identityMatch ?: compatibleIndexMatches.singleOrNull()
if (
current?.isTerminal == true &&
event.phase != GatewaySubagentEvent.Phase.SPAWN_REQUESTED &&
event.phase != GatewaySubagentEvent.Phase.START
) return
val base = if (current?.isTerminal == true) null else current
val phase = event.toActivityPhase()
val goal = sanitize(event.goal, MAX_GOAL_CHARS)
val preview = sanitize(event.preview, MAX_EVENT_TEXT_CHARS).ifBlank { null }
val summary = sanitize(event.summary, MAX_EVENT_TEXT_CHARS).ifBlank { null }
val toolName = sanitize(event.toolName, MAX_TOOL_NAME_CHARS).ifBlank { null }
val eventRow = SubagentActivityEvent(
sequence = sequence++,
kind = when (event.phase) {
GatewaySubagentEvent.Phase.SPAWN_REQUESTED,
GatewaySubagentEvent.Phase.START,
-> SubagentActivityEventKind.STARTED
GatewaySubagentEvent.Phase.THINKING,
GatewaySubagentEvent.Phase.PROGRESS,
-> SubagentActivityEventKind.UPDATE
GatewaySubagentEvent.Phase.TOOL -> SubagentActivityEventKind.TOOL
GatewaySubagentEvent.Phase.COMPLETE -> SubagentActivityEventKind.COMPLETED
},
text = if (event.phase == GatewaySubagentEvent.Phase.COMPLETE) summary else preview,
toolName = toolName,
phase = phase,
observedAtMillis = clock(),
)
val priorEvents = base?.events.orEmpty()
val coalesced = eventRow.kind == SubagentActivityEventKind.UPDATE &&
priorEvents.lastOrNull()?.let { previous ->
previous.kind == eventRow.kind && previous.text == eventRow.text
} == true
val appended = if (coalesced) priorEvents else priorEvents + eventRow
val (boundedEvents, truncated) = boundEvents(appended)
val next = SubagentActivity(
laneId = base?.laneId ?: laneSequence++,
turnId = turnId,
taskIndex = taskIndex,
taskCount = maxOf(1, event.taskCount, base?.taskCount ?: 1),
goal = goal.ifBlank { base?.goal.orEmpty() },
subagentId = event.subagentId?.takeIf(String::isNotBlank) ?: base?.subagentId,
childSessionId = event.childSessionId?.takeIf(String::isNotBlank) ?: base?.childSessionId,
parentId = event.parentId?.takeIf(String::isNotBlank) ?: base?.parentId,
depth = event.depth ?: base?.depth,
model = event.model?.takeIf(String::isNotBlank) ?: base?.model,
profile = profile?.takeIf(String::isNotBlank) ?: base?.profile,
phase = phase,
summary = summary ?: base?.summary,
durationSeconds = event.durationSeconds ?: base?.durationSeconds,
events = boundedEvents,
truncated = base?.truncated == true || truncated,
partialAfterGap = base?.partialAfterGap == true,
revision = (base?.revision ?: 0L) + 1,
)
_activities.value = (_activities.value.filterNot { it.stableKey == next.stableKey } + next)
.sortedWith(compareBy<SubagentActivity> { it.isTerminal }.thenBy { it.taskIndex })
}
fun endTurn(turnId: String) {
if (activeTurnId != turnId) return
_activities.value = _activities.value.map { activity ->
if (activity.isTerminal) activity else activity.copy(
phase = SubagentActivityPhase.ENDED_WITH_PARENT,
partialAfterGap = true,
revision = activity.revision + 1,
)
}
}
private fun boundEvents(
events: List<SubagentActivityEvent>,
): Pair<List<SubagentActivityEvent>, Boolean> {
val bounded = events.toMutableList()
var truncated = false
fun charCount(): Int = bounded.sumOf { (it.text?.length ?: 0) + (it.toolName?.length ?: 0) }
while (bounded.size > MAX_EVENTS_PER_CHILD || charCount() > MAX_CHARS_PER_CHILD) {
if (bounded.size <= 1) break
bounded.removeAt(if (bounded.first().kind == SubagentActivityEventKind.STARTED) 1 else 0)
truncated = true
}
return bounded to truncated
}
}
private fun GatewaySubagentEvent.toActivityPhase(): SubagentActivityPhase = when (phase) {
GatewaySubagentEvent.Phase.SPAWN_REQUESTED,
GatewaySubagentEvent.Phase.START -> SubagentActivityPhase.STARTED
GatewaySubagentEvent.Phase.THINKING -> SubagentActivityPhase.THINKING
GatewaySubagentEvent.Phase.TOOL -> SubagentActivityPhase.TOOL
GatewaySubagentEvent.Phase.PROGRESS -> SubagentActivityPhase.PROGRESS
GatewaySubagentEvent.Phase.COMPLETE -> when (status?.trim()?.lowercase()) {
"failed", "error" -> SubagentActivityPhase.FAILED
"interrupted", "cancelled", "canceled" -> SubagentActivityPhase.INTERRUPTED
else -> SubagentActivityPhase.COMPLETED
}
}
private val ANSI_ESCAPE = Regex("\\u001B(?:\\[[0-?]*[ -/]*[@-~]|\\][^\\u0007]*(?:\\u0007|\\u001B\\\\))")
private fun sanitize(value: String?, maxChars: Int): String = value.orEmpty()
.replace(ANSI_ESCAPE, "")
.filter { it == '\n' || it == '\t' || it >= ' ' }
.trim()
.take(maxChars)
@@ -0,0 +1,317 @@
package com.hermesandroid.relay.viewmodel
import com.hermesandroid.relay.data.ChatMessage
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.network.upstream.ChatHandler
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.GatewayChildWatch
import com.hermesandroid.relay.network.upstream.GatewayTurnCallbacks
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.launch
import java.util.concurrent.atomic.AtomicLong
internal data class SubagentChildPreview(
val activityKey: String,
val parentSessionId: String,
val parentScopeKey: String?,
/** null while opening, false for a truthful parent-event fallback. */
val childWatchAvailable: Boolean? = null,
val messages: List<ChatMessage> = emptyList(),
val running: Boolean = false,
val status: String? = null,
val historyTruncated: Boolean = false,
val partialAfterGap: Boolean = false,
val error: String? = null,
)
internal class SubagentChildPreviewController(
private val scope: CoroutineScope,
private val openWatch: suspend (
GatewayChatClient,
String,
String?,
GatewayTurnCallbacks,
) -> Result<GatewayChildWatch> = { client, sessionId, profile, callbacks ->
client.openChildWatch(sessionId, profile, callbacks)
},
private val closeWatch: suspend (GatewayChatClient, GatewayChildWatch) -> Result<Unit> =
{ client, watch -> client.closeChildWatch(watch) },
) {
private class WatchContext(
val activity: SubagentActivity,
val client: GatewayChatClient,
val parentSessionId: String,
val parentScopeKey: String?,
val generation: Long,
val stillOwnsParent: () -> Boolean,
) {
val handler = ChatHandler()
var messageOrdinal = 0
var messageId = "child-watch-$generation-0"
var contentTruncated = false
var initialized = false
var pendingOverflow = false
val pendingCallbacks = mutableListOf<() -> Unit>()
}
private val _state = MutableStateFlow<SubagentChildPreview?>(null)
val state: StateFlow<SubagentChildPreview?> = _state.asStateFlow()
private val generation = AtomicLong(0)
private var watch: GatewayChildWatch? = null
private var watchClient: GatewayChatClient? = null
fun open(
activity: SubagentActivity,
client: GatewayChatClient?,
parentSessionId: String,
parentScopeKey: String?,
gatewayRouteActive: Boolean,
stillOwnsParent: () -> Boolean,
) {
if (isAlreadyOpen(activity.stableKey, parentSessionId, parentScopeKey)) return
close(clearState = false)
if (activity.childSessionId.isNullOrBlank() || client == null || !gatewayRouteActive) {
_state.value = fallbackState(activity, parentSessionId, parentScopeKey)
return
}
val context = WatchContext(
activity = activity,
client = client,
parentSessionId = parentSessionId,
parentScopeKey = parentScopeKey,
generation = generation.incrementAndGet(),
stillOwnsParent = stillOwnsParent,
)
_state.value = baseState(context)
// Once upstream creates a lazy watcher, only the resume acknowledgement
// reveals the live id needed to close it. Let a dismissed open finish;
// generation invalidation makes [acceptOpenedWatch] close the late handle.
scope.launch { openWatch(context) }
}
fun close() = close(clearState = true)
private suspend fun openWatch(context: WatchContext) {
openWatch(
context.client,
context.activity.childSessionId.orEmpty(),
context.activity.profile,
callbacks(context),
).fold(
onSuccess = { opened -> acceptOpenedWatch(context, opened) },
onFailure = { error -> publishOpenFailure(context, error.message) },
)
}
private suspend fun acceptOpenedWatch(context: WatchContext, opened: GatewayChildWatch) {
if (!owns(context)) {
closeWatch(context.client, opened)
return
}
watch = opened
watchClient = context.client
context.handler.setSessionId(opened.storedSessionId)
context.handler.loadMessageHistory(opened.messages)
context.contentTruncated = context.handler.boundReadOnlyPreview()
val pending = synchronized(context.pendingCallbacks) {
context.initialized = true
context.pendingCallbacks.toList().also { context.pendingCallbacks.clear() }
}
publish(
context = context,
running = opened.running,
status = opened.status,
historyTruncated = opened.historyTruncated || context.contentTruncated,
partial = context.activity.partialAfterGap || context.pendingOverflow,
)
pending.forEach { callback -> if (owns(context)) callback() }
}
private fun callbacks(context: WatchContext) = GatewayTurnCallbacks(
onSessionId = { },
onStart = { runOrQueue(context) { startMessage(context) } },
onTextDelta = { delta ->
runOrQueue(context) { mutate(context) { onTextDelta(context.messageId, delta) } }
},
onThinkingDelta = { delta ->
runOrQueue(context) { mutate(context) { onThinkingDelta(context.messageId, delta) } }
},
onToolCallStart = { id, name, preview ->
runOrQueue(context) {
mutate(context) { onToolCallStart(context.messageId, id, name, preview) }
}
},
onToolCallDone = { id, preview ->
runOrQueue(context) {
mutate(context, ensureMessage = false) {
onToolCallComplete(context.messageId, id, preview)
}
}
},
onToolCallFailed = { id, error ->
runOrQueue(context) {
mutate(context, ensureMessage = false) {
onToolCallFailed(context.messageId, id, error)
}
}
},
onTurnComplete = {
runOrQueue(context) {
if (owns(context)) context.handler.onTurnComplete(context.messageId)
}
},
onReconcileRequired = { runOrQueue(context) { publish(context, partial = true) } },
onComplete = { runOrQueue(context) { complete(context) } },
onUsage = { },
onError = { message ->
runOrQueue(context) {
publish(context, running = false, partial = true, error = message)
}
},
onToolGenerating = { },
onSubagentEvent = { event ->
runOrQueue(context) { mutate(context) { onSubagentEvent(context.messageId, event) } }
},
onMoaReference = { },
onInteractionRequest = { },
onInteractionExpired = { },
onResumeFailure = { message ->
runOrQueue(context) {
publish(context, running = false, partial = true, error = message)
}
},
)
private fun runOrQueue(context: WatchContext, callback: () -> Unit) {
if (!owns(context)) return
val runNow = synchronized(context.pendingCallbacks) {
if (context.initialized) {
true
} else {
if (context.pendingCallbacks.size >= 256) {
context.pendingCallbacks.removeAt(0)
context.pendingOverflow = true
}
context.pendingCallbacks += callback
false
}
}
if (runNow) callback()
}
private fun startMessage(context: WatchContext) {
if (!owns(context)) return
context.messageId = "child-watch-${context.generation}-${context.messageOrdinal++}"
ensureLiveMessage(context)
publish(context)
}
private inline fun mutate(
context: WatchContext,
ensureMessage: Boolean = true,
mutation: ChatHandler.() -> Unit,
) {
if (!owns(context)) return
if (ensureMessage) ensureLiveMessage(context)
context.handler.mutation()
context.contentTruncated = context.handler.boundReadOnlyPreview() || context.contentTruncated
publish(context)
}
private fun complete(context: WatchContext) {
if (!owns(context)) return
context.handler.onStreamComplete(context.messageId)
// The child mirror's message.complete omits failed/interrupted status.
// Keep this neutral; the parent activity lane is authoritative.
publish(context, running = false)
}
private fun ensureLiveMessage(context: WatchContext) {
if (context.handler.messages.value.any { it.id == context.messageId }) return
context.handler.addPlaceholderMessage(
ChatMessage(
id = context.messageId,
role = MessageRole.ASSISTANT,
content = "",
timestamp = System.currentTimeMillis(),
isStreaming = true,
),
)
}
private fun publish(
context: WatchContext,
running: Boolean = true,
status: String? = _state.value?.status,
historyTruncated: Boolean =
_state.value?.historyTruncated == true || context.contentTruncated,
partial: Boolean = _state.value?.partialAfterGap == true,
error: String? = null,
) {
if (!owns(context)) return
_state.value = baseState(context).copy(
childWatchAvailable = true,
messages = context.handler.messages.value.takeLast(200),
running = running,
status = status,
historyTruncated = historyTruncated,
partialAfterGap = partial,
error = error,
)
}
private fun publishOpenFailure(context: WatchContext, message: String?) {
if (!owns(context)) return
_state.value = fallbackState(
context.activity,
context.parentSessionId,
context.parentScopeKey,
).copy(error = message)
}
private fun owns(context: WatchContext): Boolean =
generation.get() == context.generation && context.stillOwnsParent()
private fun isAlreadyOpen(key: String, sessionId: String, scopeKey: String?): Boolean =
_state.value?.let {
it.activityKey == key &&
it.parentSessionId == sessionId &&
it.parentScopeKey == scopeKey &&
it.error.isNullOrBlank() &&
it.childWatchAvailable != false
} == true
private fun baseState(context: WatchContext) = SubagentChildPreview(
activityKey = context.activity.stableKey,
parentSessionId = context.parentSessionId,
parentScopeKey = context.parentScopeKey,
)
private fun fallbackState(
activity: SubagentActivity,
parentSessionId: String,
parentScopeKey: String?,
) = SubagentChildPreview(
activityKey = activity.stableKey,
parentSessionId = parentSessionId,
parentScopeKey = parentScopeKey,
childWatchAvailable = false,
partialAfterGap = activity.partialAfterGap,
)
private fun close(clearState: Boolean) {
generation.incrementAndGet()
val closingWatch = watch
val closingClient = watchClient
watch = null
watchClient = null
if (closingWatch != null && closingClient != null) {
scope.launch { closeWatch(closingClient, closingWatch) }
}
if (clearState) _state.value = null
}
}
@@ -52,6 +52,7 @@ import com.hermesandroid.relay.voice.VoiceCommandInterpreter
import com.hermesandroid.relay.voice.SpokenInterruptionLatch
import com.hermesandroid.relay.voice.voiceInterfaceContextPrompt
import com.hermesandroid.relay.assistant.assistantContextStore
import com.hermesandroid.relay.assistant.AssistantSessionNotice
import com.hermesandroid.relay.assistant.buildAssistantVoiceTurnPayload
// === PHASE3-voice-intents: voice→bridge intent routing ===
import com.hermesandroid.relay.voice.IntentResult
@@ -90,6 +91,7 @@ import java.util.Collections
import java.util.concurrent.atomic.AtomicBoolean
import java.util.concurrent.atomic.AtomicInteger
import java.util.concurrent.atomic.AtomicLong
import java.util.concurrent.atomic.AtomicReference
import com.hermesandroid.relay.data.VoicePreferencesRepository
import com.hermesandroid.relay.data.VoiceAudioRoute
@@ -126,6 +128,25 @@ internal fun voiceSubmissionRetryState(state: VoiceUiState): VoiceUiState = stat
error = null,
)
internal fun voiceNoSpeechState(state: VoiceUiState): VoiceUiState = state.copy(
state = VoiceState.Idle,
amplitude = 0f,
outputAudioActive = false,
transcribedText = null,
error = null,
assistantNotice = AssistantSessionNotice.NoSpeech,
)
internal fun voiceCaptureCancellationState(
state: VoiceUiState,
notice: AssistantSessionNotice? = null,
): VoiceUiState = state.copy(
state = VoiceState.Idle,
amplitude = 0f,
outputAudioActive = false,
assistantNotice = notice,
)
internal data class AssistantContextTurnDisposition(
val retireForLaterTurns: Boolean,
val consumeOnTransportAcceptance: Boolean,
@@ -328,6 +349,10 @@ data class VoiceUiState(
val responseText: String = "",
/** Human-readable error surfaced in the overlay. */
val error: String? = null,
/** Content-free retry status safe for the system Assistant surface. */
val assistantNotice: AssistantSessionNotice? = null,
/** Stable owner for cross-process Assistant status; null for ordinary voice. */
val assistantActivationId: String? = null,
/** Currently-selected interaction mode. */
val interactionMode: InteractionMode = InteractionMode.TapToTalk,
/**
@@ -440,6 +465,7 @@ internal fun voiceSessionExitState(state: VoiceUiState): VoiceUiState =
transcribedText = null,
responseText = "",
error = null,
assistantNotice = null,
destructiveCountdown = null,
hermesConfirmation = null,
handoffStatus = null,
@@ -1037,6 +1063,14 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
private var bargeInListener: BargeInListener? = null
private var bargeInListenerJob: Job? = null
private var bargeInVadEngine: VadEngine? = null
/**
* The most recent asynchronous AudioRecord shutdown still releasing the
* process-wide BargeIn microphone lease. Teardown is intentionally
* idempotent, so completion paths may call [stopBargeInListener] after the
* listener reference has already been cleared. Retaining this fence makes
* every subsequent VoiceCapture start join the same ownership handoff.
*/
private val pendingBargeInReaderRelease = AtomicReference<Job?>(null)
private val bargeInTurnEpoch = AtomicLong(0L)
@Volatile private var activeBargeInTurnEpoch: Long = 0L
@@ -1373,6 +1407,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
return
}
// A mode change supersedes any capture that is still waiting for the
// previous microphone owner to release. The selected mode below may
// start a fresh Continuous capture with its own generation.
cancelPendingListeningStart()
if (mode != InteractionMode.Continuous) {
continuousLoopArmed = false
continuousListeningPaused = false
@@ -1630,6 +1669,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
state = VoiceState.Idle,
outputAudioActive = false,
error = null,
assistantActivationId = activationId,
hermesConfirmation = null,
backgroundRun = if (orphanedRun != null) null else it.backgroundRun,
)
@@ -1844,6 +1884,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
}
fun exitVoiceMode() {
cancelPendingListeningStart()
// Idempotence guard — added 2026-04-21 after logcat showed the voice-
// exit chime playing on every Add-connection tap.
//
@@ -1995,6 +2036,10 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
// ---------------------------------------------------------------------
fun startListening() {
startListening(requireContinuousLoop = false)
}
private fun startListening(requireContinuousLoop: Boolean) {
// A direct mic tap starts a normal capture. Only the recorder opened by
// onBargeInDetected may carry response-interruption command context.
responseInterruptedForVoiceCommand = false
@@ -2003,7 +2048,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
setError("Recorder not initialized")
return
}
if (pendingListeningStartJob?.isActive == true) return
if (requireContinuousLoop && !canStartContinuousCapture()) return
// A direct/new capture request supersedes a stale handoff waiter. It
// will join the same retained microphone-release fence under a fresh
// epoch below instead of being silently dropped.
cancelPendingListeningStart()
if (rec.isRecording()) return
if (_uiState.value.state == VoiceState.Listening) {
// Listening is reserved for a live AudioRecord. Reconcile a stale
@@ -2037,7 +2086,9 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
try { realtimePcmPlayer?.stop() } catch (_: Exception) { /* ignore */ }
if (microphoneRelease == null || microphoneRelease.isCompleted) {
startVoiceCapture(rec)
if (!requireContinuousLoop || canStartContinuousCapture()) {
startVoiceCapture(rec)
}
return
}
@@ -2045,7 +2096,9 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
val pendingStart = viewModelScope.launch(start = CoroutineStart.LAZY) {
try {
microphoneRelease.join()
if (listeningStartEpoch == startEpoch) {
if (listeningStartEpoch == startEpoch &&
(!requireContinuousLoop || canStartContinuousCapture())
) {
startVoiceCapture(rec)
}
} finally {
@@ -2058,8 +2111,20 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
pendingStart.start()
}
private fun startVoiceCapture(rec: VoiceRecorder) {
try {
private fun canStartContinuousCapture(): Boolean {
val state = _uiState.value
return state.voiceMode &&
state.interactionMode == InteractionMode.Continuous &&
state.state == VoiceState.Idle &&
continuousLoopArmed &&
!continuousListeningPaused
}
private fun startVoiceCapture(
rec: VoiceRecorder,
bargeInCapture: Boolean = false,
): Boolean {
return try {
rec.startRecording()
listeningStartedAtMs = System.currentTimeMillis()
_uiState.update {
@@ -2067,6 +2132,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
state = VoiceState.Listening,
outputAudioActive = false,
error = null,
assistantNotice = null,
responseText = "",
// v0.4.1 — fresh turn, drop any stale JIT permission chip
// from the previous dispatch.
@@ -2074,16 +2140,20 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
handoffStatus = null,
)
}
// 2026-04-18: arm silence-based auto-stop. HoldToTalk skips
// this — the physical release is the authoritative stop.
if (_uiState.value.interactionMode != InteractionMode.HoldToTalk) {
// A normal Hold-to-talk capture ends on physical release. A
// barge-in capture is VAD-owned instead, so it always needs the
// silence watchdog even when Hold-to-talk is the saved mode;
// otherwise the steering utterance remains open indefinitely.
if (shouldArmVoiceSilenceWatchdog(_uiState.value.interactionMode, bargeInCapture)) {
startSilenceWatchdog()
}
true
} catch (e: Exception) {
listeningStartedAtMs = 0L
Log.e(TAG, "startListening failed: ${e.message}")
// SecurityException path becomes "Permission needed" via the classifier.
surfaceError(e, context = "record")
false
}
}
@@ -2176,7 +2246,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
private fun shouldDiscardVoiceCaptureBeforeStop(durationMs: Long): Boolean =
durationMs < MIN_VOICE_CAPTURE_DURATION_MS
private fun cancelListeningWithoutProcessing(title: String, detail: String? = null) {
private fun cancelListeningWithoutProcessing(
title: String,
detail: String? = null,
notice: AssistantSessionNotice? = null,
) {
responseInterruptedForVoiceCommand = false
silenceWatchdogJob?.cancel()
silenceWatchdogJob = null
@@ -2188,9 +2262,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
title = title,
detail = detail,
)
_uiState.update {
it.copy(state = VoiceState.Idle, amplitude = 0f, outputAudioActive = false)
}
_uiState.update { voiceCaptureCancellationState(it, notice) }
}
/** Reconcile microphone state after the Activity returns to foreground. */
@@ -2218,6 +2290,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
* listening turn; until then, idle queue-drain callbacks are ignored.
*/
fun pauseContinuousMode() {
cancelPendingListeningStart()
continuousLoopArmed = false
continuousListeningPaused = _uiState.value.interactionMode == InteractionMode.Continuous
continuousResumeJob?.cancel()
@@ -2327,6 +2400,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
cancelListeningWithoutProcessing(
title = getApplication<Application>().getString(R.string.voice_status_no_speech),
detail = "No speech within ${IDLE_NO_SPEECH_MS / 1000}s",
notice = AssistantSessionNotice.NoSpeech,
)
return@launch
}
@@ -3547,9 +3621,9 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
val message = when {
raw.contains("timeout", ignoreCase = true) ||
raw.contains("not responding", ignoreCase = true) ->
"Relay is not responding. Check Connections."
"Relay is not responding. Check Gateways."
raw.contains("not configured", ignoreCase = true) ->
"Relay is not configured. Check Connections."
"Relay is not configured. Check Gateways."
else -> raw
}
DiagnosticsLog.record(
@@ -5760,7 +5834,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
continuousLoopArmed &&
_uiState.value.state == VoiceState.Idle
) {
startListening()
startListening(requireContinuousLoop = true)
}
}
@@ -5825,6 +5899,29 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
)
return
}
if (!activeResponseOwnsBargeIn()) {
Log.i(TAG, "Barge-in listener skipped; no active voice response owns the microphone")
return
}
val pendingReaderRelease = pendingBargeInReaderRelease.get()?.takeUnless { it.isCompleted }
if (pendingReaderRelease != null) {
// A late playback/realtime callback may request the next turn's
// listener while the previous AudioRecord is still unwinding.
// Join the same ownership fence as VoiceCapture, then re-check the
// turn epoch so stale generations cannot reopen the microphone.
activeBargeInTurnEpoch = epoch
viewModelScope.launch {
pendingReaderRelease.join()
if (activeBargeInTurnEpoch == epoch &&
bargeInListener == null &&
activeResponseOwnsBargeIn()
) {
startBargeInListenerIfEnabled(epoch = epoch)
}
}
return
}
val vad = try {
vadFactory().also { it.setSensitivity(prefs.sensitivity) }
@@ -5873,6 +5970,12 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
}
}
private fun activeResponseOwnsBargeIn(): Boolean {
val state = _uiState.value
return state.voiceMode &&
(state.state == VoiceState.Thinking || state.state == VoiceState.Speaking)
}
/**
* Tear down the active [BargeInListener], cancel its event subscribers,
* unduck the player (in case a ducking watchdog hadn't yet restored
@@ -5906,7 +6009,13 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
try { realtimePcmPlayer?.unduck() } catch (_: Throwable) { /* ignore */ }
isDucked = false
}
return stoppedReaderJob
if (stoppedReaderJob != null) {
pendingBargeInReaderRelease.set(stoppedReaderJob)
stoppedReaderJob.invokeOnCompletion {
pendingBargeInReaderRelease.compareAndSet(stoppedReaderJob, null)
}
}
return pendingBargeInReaderRelease.get()?.takeUnless { it.isCompleted }
}
private fun markBargeInPlaybackStarted(graceMs: Long) {
@@ -5958,6 +6067,8 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
*/
internal fun onBargeInDetected() {
if (isBargeInStartupGuardActive()) return
val interruptedMode = _uiState.value.interactionMode
val interruptedEngine = voiceEngineMode
val interruptedSpokenReply = _uiState.value.outputAudioActive
if (interruptedSpokenReply) spokenInterruptionLatch.mark()
duckingWatchdog?.cancel(); duckingWatchdog = null
@@ -5991,18 +6102,68 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
responseText = "",
)
}
viewModelScope.launch {
val captureEpoch = ++listeningStartEpoch
val pendingStart = viewModelScope.launch(start = CoroutineStart.LAZY) {
try {
microphoneRelease?.join()
val rec = recorder
if (rec != null && !rec.isRecording()) {
rec.startRecording()
if (!canStartBargeInCapture(captureEpoch, interruptedMode, interruptedEngine)) {
abandonBargeInCaptureIfCurrent(captureEpoch)
return@launch
}
scheduleResumeWatchdog()
val rec = recorder ?: error("Recorder not initialized")
val captureStarted = rec.isRecording() ||
startVoiceCapture(rec, bargeInCapture = true)
if (!captureStarted) {
abandonBargeInCaptureIfCurrent(captureEpoch)
return@launch
}
if (canStartBargeInCapture(captureEpoch, interruptedMode, interruptedEngine)) {
scheduleResumeWatchdog()
} else {
silenceWatchdogJob?.cancel()
silenceWatchdogJob = null
try { rec.cancel() } catch (_: Throwable) { /* ignore */ }
abandonBargeInCaptureIfCurrent(captureEpoch)
}
} catch (t: CancellationException) {
abandonBargeInCaptureIfCurrent(captureEpoch)
throw t
} catch (t: Throwable) {
responseInterruptedForVoiceCommand = false
Log.w(TAG, "barge-in microphone handoff failed: ${t.message}")
surfaceError(t, context = "record")
if (listeningStartEpoch == captureEpoch) {
responseInterruptedForVoiceCommand = false
Log.w(TAG, "barge-in microphone handoff failed: ${t.message}")
surfaceError(t, context = "record")
}
} finally {
if (listeningStartEpoch == captureEpoch) {
pendingListeningStartJob = null
}
}
}
pendingListeningStartJob = pendingStart
pendingStart.start()
}
private fun canStartBargeInCapture(
captureEpoch: Long,
interruptedMode: InteractionMode,
interruptedEngine: VoiceEngineMode,
): Boolean {
val state = _uiState.value
return listeningStartEpoch == captureEpoch &&
state.voiceMode &&
state.state == VoiceState.Listening &&
state.interactionMode == interruptedMode &&
voiceEngineMode == interruptedEngine &&
responseInterruptedForVoiceCommand
}
private fun abandonBargeInCaptureIfCurrent(captureEpoch: Long) {
if (listeningStartEpoch != captureEpoch) return
responseInterruptedForVoiceCommand = false
if (_uiState.value.state == VoiceState.Listening && recorder?.isRecording() != true) {
_uiState.update {
it.copy(state = VoiceState.Idle, amplitude = 0f, outputAudioActive = false)
}
}
}
@@ -6314,9 +6475,22 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
startBargeInListenerIfEnabled()
}
@androidx.annotation.VisibleForTesting
internal fun stopBargeInListenerForTest(): Job? = stopBargeInListener()
@androidx.annotation.VisibleForTesting
internal fun finishAgentAudioOutputForTest() {
finishAgentAudioOutput()
}
@androidx.annotation.VisibleForTesting
internal fun setVoiceEngineModeForTest(mode: VoiceEngineMode) {
voiceEngineMode = mode
}
@androidx.annotation.VisibleForTesting
internal fun beginBargeInTurnForTest() {
_uiState.update { it.copy(state = VoiceState.Thinking) }
_uiState.update { it.copy(voiceMode = true, state = VoiceState.Thinking) }
beginBargeInTurnIfEnabled()
}
@@ -6497,13 +6671,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
detail = detail,
)
_uiState.update {
it.copy(
state = VoiceState.Idle,
amplitude = 0f,
outputAudioActive = false,
error = null,
transcribedText = null,
)
voiceNoSpeechState(it)
}
Toast.makeText(context, message, Toast.LENGTH_SHORT).show()
}
@@ -6850,6 +7018,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
}
internal fun shouldArmVoiceSilenceWatchdog(
interactionMode: InteractionMode,
bargeInCapture: Boolean,
): Boolean = bargeInCapture || interactionMode != InteractionMode.HoldToTalk
// -------------------------------------------------------------------------
// Voice capture guards and sentence-boundary detection (top-level so they're
// unit-testable without instantiating an AndroidViewModel + Application).

Some files were not shown because too many files have changed in this diff Show More