Compare commits

..
17 changed files with 578 additions and 672 deletions
+1 -1
View File
@@ -17,7 +17,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
### Fixed
- **Opening Android no longer claims or interrupts a turn already running in Hermes Desktop/TUI.** Passive foreground and session browsing now use read-only Gateway status plus profile-scoped history; live-session resume remains reserved for explicit Android actions and exact Android-owned recovery.
- **Android Continuous voice waits for barge-in microphone teardown before listening again.** Multi-turn hands-free conversations no longer lose the microphone after a response finishes with barge-in enabled. (#464)
- **The visible Android Sphere keeps its smooth procedural motion across startup and chat.** Backgrounded and motion-disabled surfaces remain still without reducing foreground animation to a stepped ambient pulse.
### Removed
-3
View File
@@ -26,9 +26,6 @@ model device-certified:
renders as Working.
- Run a background process that outlives its parent turn and verify Background
work remains separate from the conversation's Idle state.
- On a physical phone, open and repeatedly foreground Android while the same
session is working in official Desktop/TUI; verify Android sends no live
attach/interrupt RPC, the producer completes, and final history appears.
- Pursue an upstream `session.active_list` profile field/filter or an aggregate
activity route with explicit profile ownership so multi-profile clients do
not need to resolve process-wide rows from durable keys.
@@ -239,60 +239,6 @@ class GatewayForegroundRecoveryInstrumentedTest {
assertEquals(0, fixture.requestsTo("/v1/chat/completions"))
}
@Test
fun desktopOwnedTurn_remainsReadOnlyAcrossAndroidForegroundLifecycle() {
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val controlMethods = setOf(
"session.resume",
"session.activate",
"session.interrupt",
"prompt.submit",
)
val baseline = controlMethods.associateWith(fixture::rpcCount)
val baselineActiveList = fixture.rpcCount("session.active_list")
fixture.activeSessionStatus = "working"
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
val okHttp = OkHttpClient()
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = fixture.server.url("/").toString().trimEnd('/'),
okHttpClient = okHttp,
),
okHttpClient = okHttp,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
reconnectJitterUnit = { 0.0 },
)
viewModel.setChatTurnCheckpointStore(null)
viewModel.updateGatewayClient(gatewayClient)
viewModel.setChatVisible(true)
compose.activityRule.scenario.moveToState(Lifecycle.State.STARTED)
compose.activityRule.scenario.moveToState(Lifecycle.State.RESUMED)
viewModel.setChatVisible(false)
viewModel.setChatVisible(true)
fixture.awaitRpcCount("session.active_list", baselineActiveList + 1)
controlMethods.forEach { method ->
assertEquals(
"passive lifecycle sent $method",
baseline.getValue(method),
fixture.rpcCount(method),
)
}
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
assertEquals(
"observer teardown interrupted the Desktop turn",
baseline.getValue("session.interrupt"),
fixture.rpcCount("session.interrupt"),
)
}
private companion object {
const val STORED_SESSION_ID = "20260821_120000_fixture"
const val LIVE_SESSION_ID = "fixture-live-1"
@@ -317,9 +263,6 @@ internal class AndroidGatewayContractFixture {
@Volatile
var recoveryRunning = false
@Volatile
var activeSessionStatus: String? = null
private val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
sockets.add(webSocket)
@@ -339,18 +282,6 @@ internal class AndroidGatewayContractFixture {
"session.activate" -> sessionSnapshot(
(params["session_id"] as? JsonPrimitive)?.contentOrNull ?: "fixture-live-1",
)
"session.active_list" -> buildJsonObject {
put("sessions", kotlinx.serialization.json.buildJsonArray {
activeSessionStatus?.let { status ->
add(buildJsonObject {
put("id", LIVE_SESSION_ID)
put("session_key", STORED_SESSION_ID)
put("status", status)
put("last_active", 1.0)
})
}
})
}
"prompt.submit", "session.interrupt" -> buildJsonObject { put("ok", true) }
else -> JsonObject(emptyMap())
}
@@ -414,15 +345,6 @@ internal class AndroidGatewayContractFixture {
error("Gateway RPC $method not observed; saw ${rpcLog.map { it.first }}")
}
fun awaitRpcCount(method: String, count: Int) {
val deadline = System.nanoTime() + TimeUnit.SECONDS.toNanos(5)
while (System.nanoTime() < deadline) {
if (rpcCount(method) >= count) return
Thread.sleep(20)
}
error("Gateway RPC $method count $count not observed; saw ${rpcLog.map { it.first }}")
}
fun requestsTo(path: String): Int = requestPaths.count { it.startsWith(path) }
fun rpcCount(method: String): Int = rpcLog.count { it.first == method }
@@ -431,9 +353,4 @@ internal class AndroidGatewayContractFixture {
allSockets.forEach { socket -> runCatching { socket.close(1001, "teardown") } }
runCatching { server.shutdown() }
}
private companion object {
const val STORED_SESSION_ID = "20260821_120000_fixture"
const val LIVE_SESSION_ID = "fixture-live-1"
}
}
@@ -906,30 +906,6 @@ class GatewayChatClient(
scope.launch { prewarmAwait(storedSessionId) }
}
/**
* Establish only the shared Gateway socket for read-only observation.
*
* `session.resume` and `session.activate` attach a live runtime to this
* transport. Opening Chat, foreground restoration, and selecting a saved
* transcript must not claim a turn that another Desktop/TUI client owns,
* so those paths use this socket-only warmup and observe through REST
* history plus `session.active_list` instead.
*/
fun observe(onReady: (() -> Unit)? = null) {
scope.launch {
if (observeAwait() && onReady != null) callbackDispatcher(onReady)
}
}
/** Suspending [observe]; returns true once the read-only socket is ready. */
suspend fun observeAwait(): Boolean = try {
connectMutex.withLock { ensureConnected() }
true
} catch (e: Exception) {
Log.d(TAG, "Gateway observation warmup skipped: ${e.message}")
false
}
/**
* Suspending [prewarm]: establishes the socket and (when [storedSessionId]
* is non-null) resumes the existing session, returning only once that work
@@ -1119,16 +1119,12 @@ fun ChatScreen(
}
// Recover any durable in-flight chat checkpoint whenever Chat returns to
// the foreground. setChatVisible owns that edge; an ordinary Gateway open
// warms only the observation socket and never attaches a saved session.
// the foreground. On Gateway this also pre-warms/re-attaches the socket;
// sessions-SSE falls back to bounded persisted-history reconciliation.
val appForeground by com.hermesandroid.relay.util.AppForegroundTracker.isForeground.collectAsState()
LaunchedEffect(isGatewayTransport, appForeground, chatReady) {
val chatVisible = appForeground && chatReady
val visibilityChanged = chatViewModel.setChatVisible(chatVisible)
if (isGatewayTransport && chatVisible && !visibilityChanged) {
// Gateway availability can settle after Chat was already visible.
// Repeat the socket-only warmup for that edge; ordinary observation
// still cannot resume or activate a session.
chatViewModel.setChatVisible(appForeground && chatReady)
if (appForeground && chatReady) {
chatViewModel.prewarmGateway()
}
if (isGatewayTransport && appForeground && chatReady) {
@@ -257,7 +257,10 @@ private fun classifyErrorInternal(t: Throwable?, context: String?, ctx: Context?
val msg = t.message.orEmpty().lowercase()
if ("cannot create audiorecord" in msg || "audiorecord failed to initialize" in msg) {
if ("cannot create audiorecord" in msg ||
"audiorecord failed to initialize" in msg ||
"microphone is in use by another voice feature" in msg
) {
return HumanError(
title = ctx?.getString(R.string.error_classify_mic_unavailable) ?: "Microphone unavailable",
body = ctx?.getString(R.string.error_classify_mic_unavailable_body)
@@ -408,9 +408,6 @@ class ChatViewModel : ViewModel() {
private val sessionActivityGeneration = AtomicLong(0L)
private val sessionActivityPollMutex = Mutex()
private var sessionActivityPollJob: Job? = null
private var passiveGatewayHistoryRefreshJob: Job? = null
private var passivelyObservedGatewaySessionId: String? = null
private var passiveObservationCatchupPendingSessionId: String? = null
private var sessionActivityDirectory: Set<SessionActivityOwner> = emptySet()
private var lastProjectedProcessIds: Set<String> = emptySet()
private var lastProjectedProcessOwner: SessionActivityOwner? = null
@@ -2255,8 +2252,6 @@ class ChatViewModel : ViewModel() {
}
private suspend fun pollSessionActivity(client: GatewayChatClient) {
var hasPassiveCurrentLiveWork = false
var hasPassiveCatchupPending = false
sessionActivityPollMutex.withLock {
if (gatewayClient !== client || !chatVisible || streamingEndpoint != "gateway") return
val generation = sessionActivityGeneration.get()
@@ -2277,43 +2272,6 @@ class ChatViewModel : ViewModel() {
when (val result = client.listActiveSessions()) {
is GatewayActiveSessionsResult.Success -> {
if (gatewayClient !== client || generation != sessionActivityGeneration.get()) return
val currentStoredId = currentOwner?.storedSessionId
val passiveCurrentRows = if (currentStoredId == null) {
emptyList()
} else {
result.sessions.filter { row ->
row.storedSessionId == currentStoredId &&
client.knownSessionOwner(row.runtimeSessionId) == null
}
}
hasPassiveCurrentLiveWork = passiveCurrentRows.any { row ->
row.status != GatewayActiveSessionStatus.Idle
}
val initialCatchupPending =
passiveObservationCatchupPendingSessionId == currentStoredId
val needsFinalPassiveRefresh =
passivelyObservedGatewaySessionId == currentStoredId &&
!hasPassiveCurrentLiveWork
if (hasPassiveCurrentLiveWork) {
currentStoredId?.let(::refreshPassivelyObservedGatewayHistory)
if (initialCatchupPending) {
passiveObservationCatchupPendingSessionId = null
}
} else if (needsFinalPassiveRefresh || initialCatchupPending) {
val scheduled = currentStoredId?.let { storedId ->
refreshPassivelyObservedGatewayHistory(
storedSessionId = storedId,
retryUntilChanged = true,
)
} == true
if (scheduled && initialCatchupPending) {
passiveObservationCatchupPendingSessionId = null
}
}
passivelyObservedGatewaySessionId =
currentStoredId?.takeIf { hasPassiveCurrentLiveWork }
hasPassiveCatchupPending =
passiveObservationCatchupPendingSessionId == currentStoredId
val resolved = resolveGatewayActiveSessions(
sessions = result.sessions,
directory = directory,
@@ -2375,18 +2333,6 @@ class ChatViewModel : ViewModel() {
GatewayActiveSessionsResult.Unsupported,
is GatewayActiveSessionsResult.TransientFailure -> {
if (gatewayClient !== client || generation != sessionActivityGeneration.get()) return
val currentStoredId = currentOwner?.storedSessionId
if (passiveObservationCatchupPendingSessionId == currentStoredId) {
val scheduled = currentStoredId?.let { storedId ->
refreshPassivelyObservedGatewayHistory(
storedSessionId = storedId,
retryUntilChanged = true,
)
} == true
if (scheduled) passiveObservationCatchupPendingSessionId = null
}
hasPassiveCatchupPending =
passiveObservationCatchupPendingSessionId == currentStoredId
val scopes = directory.mapTo(mutableSetOf()) {
SessionActivityScope.of(it.connectionId, it.profile)
}.apply { add(currentScope) }
@@ -2405,9 +2351,7 @@ class ChatViewModel : ViewModel() {
record.freshness == SessionActivityFreshness.Confirmed &&
record.phase(System.currentTimeMillis()) != SessionActivityPhase.Idle
}
val delayMs = if (
hasConfirmedLiveWork || hasPassiveCurrentLiveWork || hasPassiveCatchupPending
) 1_500L else 30_000L
val delayMs = if (hasConfirmedLiveWork) 1_500L else 30_000L
sessionActivityPollJob = viewModelScope.launch {
delay(delayMs)
if (gatewayClient === client && chatVisible) pollSessionActivity(client)
@@ -2480,10 +2424,6 @@ class ChatViewModel : ViewModel() {
clearProjectedBackgroundProcesses()
sessionActivityPollJob?.cancel()
sessionActivityPollJob = null
passiveGatewayHistoryRefreshJob?.cancel()
passiveGatewayHistoryRefreshJob = null
passivelyObservedGatewaySessionId = null
passiveObservationCatchupPendingSessionId = null
sessionActivityGeneration.incrementAndGet()
sessionActivityDirectory = emptySet()
lastLocalActivityOwner = null
@@ -2603,9 +2543,8 @@ class ChatViewModel : ViewModel() {
// Foreground can race OkHttp's delayed close callback:
// the first prewarm sees the old socket as Ready, then
// the callback moves it to Idle. Re-run from this exact
// client transition so the observation socket is
// restored; only an exact Android checkpoint may
// resume/activate a live runtime.
// client transition so the visible durable session is
// resumed and its authoritative history reconciled.
prewarmGateway()
}
}
@@ -3060,103 +2999,6 @@ class ChatViewModel : ViewModel() {
}
}
/**
* Refresh a Desktop/TUI-owned turn through the profile-scoped history
* surface without attaching its live runtime. `session.active_list` drives
* the bounded cadence; one final read follows Working/Waiting -> Idle.
*/
private fun refreshPassivelyObservedGatewayHistory(
storedSessionId: String,
retryUntilChanged: Boolean = false,
): Boolean {
if (passiveGatewayHistoryRefreshJob?.isActive == true) return false
if (_isLoadingHistory.value) return false
val handler = chatHandler ?: return false
val contextKey = activeProfileContextKey
val profileName = currentSessionProfileName()
val refreshJob = viewModelScope.launch(start = CoroutineStart.LAZY) {
try {
repeat(if (retryUntilChanged) 8 else 1) { attempt ->
val serverMessages = runCatching {
loadGatewaySessionHistory(
sessionId = storedSessionId,
requireProfileScope = true,
profileName = profileName,
)
}.getOrNull() ?: return@launch
if (
chatHandler !== handler ||
activeProfileContextKey != contextKey ||
currentSessionProfileName() != profileName ||
handler.currentSessionId.value != storedSessionId ||
_isLoadingHistory.value ||
activeStream != null ||
handler.isStreaming.value
) return@launch
val visibleSignature = handler.messages.value
.filterNot { it.clientOnly }
.map { message ->
Triple(
message.role.name.lowercase(),
message.content,
message.thinkingContent,
)
}
val serverSignature = serverMessages.map { message ->
Triple(
message.role.lowercase(),
message.contentText.orEmpty(),
message.resolvedReasoning.orEmpty(),
)
}
if (visibleSignature != serverSignature) {
handler.loadMessageHistory(serverMessages)
refreshSessions()
scheduleTitleReconcile(storedSessionId)
return@launch
}
if (attempt < 7 && retryUntilChanged) delay(250L)
}
} finally {
if (passiveGatewayHistoryRefreshJob === coroutineContext[Job]) {
passiveGatewayHistoryRefreshJob = null
}
}
}
passiveGatewayHistoryRefreshJob = refreshJob
refreshJob.start()
return true
}
/** Open the read-only socket off Main, then publish observation ownership on Main. */
private fun observeGatewaySession(
client: GatewayChatClient?,
handler: ChatHandler,
storedSessionId: String,
) {
val observer = client ?: return
val contextKey = activeProfileContextKey
val profileName = currentSessionProfileName()
observer.observe {
if (
chatVisible &&
gatewayClient === observer &&
chatHandler === handler &&
activeProfileContextKey == contextKey &&
currentSessionProfileName() == profileName &&
handler.currentSessionId.value == storedSessionId
) {
passiveObservationCatchupPendingSessionId = storedSessionId
refreshPassivelyObservedGatewayHistory(
storedSessionId = storedSessionId,
retryUntilChanged = true,
)
requestSessionActivityRefresh()
}
}
}
/** One-shot `config.get personality` over a ready socket → drives the collector. */
private fun seedServerPersonality(client: GatewayChatClient) {
viewModelScope.launch {
@@ -3167,11 +3009,11 @@ class ChatViewModel : ViewModel() {
}
/**
* Warm the Gateway socket when Chat is visible without claiming a runtime
* that may belong to Desktop/TUI. Exact Android-owned checkpoints recover
* through `session.activate`/`session.resume`; an ordinary open observes
* through REST history and `session.active_list` until the user performs
* an explicit action that needs session ownership.
* Warm the gateway socket (and resume the current session) when the chat
* surface is visible and the gateway is the resolved transport, so the
* first send is warm instead of paying the cold connect + `session.resume`
* on the send path. No-op without a gateway client; idempotent when warm.
* Driven by a foreground/visibility effect in ChatScreen.
*/
fun prewarmGateway() {
val client = gatewayClient
@@ -3179,16 +3021,17 @@ class ChatViewModel : ViewModel() {
val sessionId = handler.currentSessionId.value
selectBackgroundProcessSession(sessionId)
if (sessionId == null) {
client?.observe()
client?.prewarm(null)
} else {
// Preserve the original warm-up path before persistence wiring is
// available (early composition and JVM tests). Production installs
// the store from initializeMedia before Chat becomes ready.
if (chatTurnCheckpointStore == null) {
val gateway = client ?: return
// GatewayChatClient owns the socket IO scope, so the dial can
// progress while a paused UI dispatcher is being recreated.
observeGatewaySession(gateway, handler, sessionId)
// GatewayChatClient owns an IO scope, so this can progress even
// while a paused/blocked UI dispatcher is being recreated.
// Its cold-ready listener performs history/process refresh.
gateway.prewarm(sessionId)
return
}
if (activeStream == null && (streamRecovery == null || client != null)) {
@@ -3200,29 +3043,26 @@ class ChatViewModel : ViewModel() {
chatHandler === handler &&
handler.currentSessionId.value == sessionId
) {
observeGatewaySession(client, handler, sessionId)
if (client?.prewarmAwait(sessionId) == true) {
gatewayProcessController.sessionReady(sessionId)
}
}
checkpointRecoveryJob = null
}
return
}
// A locally-owned live mapper may revalidate its existing binding.
// A passive transcript must remain socket-only: resuming it here
// can replace another client's transport and turn Android teardown
// into a later session.interrupt.
if (client?.hasActiveTurnForSession(sessionId) == true) {
viewModelScope.launch {
if (client.prewarmAwait(sessionId) &&
gatewayClient === client &&
chatHandler === handler &&
handler.currentSessionId.value == sessionId
) {
gatewayProcessController.sessionReady(sessionId)
requestSessionActivityRefresh()
}
// prewarm() only emits the existing "cold ready" callback when it
// had to resume. An already-live session still needs its initial
// process snapshot when Chat opens, so confirm it explicitly.
viewModelScope.launch {
if (
client?.prewarmAwait(sessionId) == true &&
gatewayClient === client &&
chatHandler === handler &&
handler.currentSessionId.value == sessionId
) {
gatewayProcessController.sessionReady(sessionId)
}
} else {
observeGatewaySession(client, handler, sessionId)
}
}
}
@@ -3232,7 +3072,7 @@ class ChatViewModel : ViewModel() {
* Gateway chat owns automatic idle-socket reattachment; other tabs and a
* backgrounded app retain the normal no-reconnect behavior.
*/
fun setChatVisible(visible: Boolean): Boolean {
fun setChatVisible(visible: Boolean) {
val changed = chatVisible != visible
chatVisible = visible
if (visible && changed) {
@@ -3241,12 +3081,7 @@ class ChatViewModel : ViewModel() {
} else if (!visible) {
sessionActivityPollJob?.cancel()
sessionActivityPollJob = null
passiveGatewayHistoryRefreshJob?.cancel()
passiveGatewayHistoryRefreshJob = null
passivelyObservedGatewaySessionId = null
passiveObservationCatchupPendingSessionId = null
}
return changed
}
// === Gateway desktop-parity state ===
@@ -4630,9 +4465,7 @@ class ChatViewModel : ViewModel() {
)
if (stillCurrent()) {
handler.loadMessageHistory(messages)
if (streamingEndpoint == "gateway") {
observeGatewaySession(gatewayClient, handler, sessionId)
}
if (streamingEndpoint == "gateway") gatewayClient?.prewarm(sessionId)
}
}
} catch (e: kotlinx.coroutines.CancellationException) {
@@ -5143,9 +4976,7 @@ class ChatViewModel : ViewModel() {
handler.currentSessionId.value == sessionId
) {
handler.loadMessageHistory(messages)
if (streamingEndpoint == "gateway") {
observeGatewaySession(gatewayClient, handler, sessionId)
}
if (streamingEndpoint == "gateway") gatewayClient?.prewarm(sessionId)
}
} catch (e: kotlinx.coroutines.CancellationException) {
throw e
@@ -6735,10 +6566,6 @@ class ChatViewModel : ViewModel() {
* SSE cannot, so it retains the existing interrupt/cancel behavior.
*/
private fun releaseTurnForNavigation(handler: ChatHandler) {
passiveGatewayHistoryRefreshJob?.cancel()
passiveGatewayHistoryRefreshJob = null
passivelyObservedGatewaySessionId = null
passiveObservationCatchupPendingSessionId = null
val gateway = gatewayClient
val canBackground = streamingEndpoint == "gateway" &&
activeStreamIsGateway && activeStream != null && gateway != null
@@ -90,6 +90,7 @@ import java.util.Collections
import java.util.concurrent.atomic.AtomicBoolean
import java.util.concurrent.atomic.AtomicInteger
import java.util.concurrent.atomic.AtomicLong
import java.util.concurrent.atomic.AtomicReference
import com.hermesandroid.relay.data.VoicePreferencesRepository
import com.hermesandroid.relay.data.VoiceAudioRoute
@@ -1037,6 +1038,14 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
private var bargeInListener: BargeInListener? = null
private var bargeInListenerJob: Job? = null
private var bargeInVadEngine: VadEngine? = null
/**
* The most recent asynchronous AudioRecord shutdown still releasing the
* process-wide BargeIn microphone lease. Teardown is intentionally
* idempotent, so completion paths may call [stopBargeInListener] after the
* listener reference has already been cleared. Retaining this fence makes
* every subsequent VoiceCapture start join the same ownership handoff.
*/
private val pendingBargeInReaderRelease = AtomicReference<Job?>(null)
private val bargeInTurnEpoch = AtomicLong(0L)
@Volatile private var activeBargeInTurnEpoch: Long = 0L
@@ -1373,6 +1382,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
return
}
// A mode change supersedes any capture that is still waiting for the
// previous microphone owner to release. The selected mode below may
// start a fresh Continuous capture with its own generation.
cancelPendingListeningStart()
if (mode != InteractionMode.Continuous) {
continuousLoopArmed = false
continuousListeningPaused = false
@@ -1844,6 +1858,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
}
fun exitVoiceMode() {
cancelPendingListeningStart()
// Idempotence guard — added 2026-04-21 after logcat showed the voice-
// exit chime playing on every Add-connection tap.
//
@@ -1995,6 +2010,10 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
// ---------------------------------------------------------------------
fun startListening() {
startListening(requireContinuousLoop = false)
}
private fun startListening(requireContinuousLoop: Boolean) {
// A direct mic tap starts a normal capture. Only the recorder opened by
// onBargeInDetected may carry response-interruption command context.
responseInterruptedForVoiceCommand = false
@@ -2003,7 +2022,11 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
setError("Recorder not initialized")
return
}
if (pendingListeningStartJob?.isActive == true) return
if (requireContinuousLoop && !canStartContinuousCapture()) return
// A direct/new capture request supersedes a stale handoff waiter. It
// will join the same retained microphone-release fence under a fresh
// epoch below instead of being silently dropped.
cancelPendingListeningStart()
if (rec.isRecording()) return
if (_uiState.value.state == VoiceState.Listening) {
// Listening is reserved for a live AudioRecord. Reconcile a stale
@@ -2037,7 +2060,9 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
try { realtimePcmPlayer?.stop() } catch (_: Exception) { /* ignore */ }
if (microphoneRelease == null || microphoneRelease.isCompleted) {
startVoiceCapture(rec)
if (!requireContinuousLoop || canStartContinuousCapture()) {
startVoiceCapture(rec)
}
return
}
@@ -2045,7 +2070,9 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
val pendingStart = viewModelScope.launch(start = CoroutineStart.LAZY) {
try {
microphoneRelease.join()
if (listeningStartEpoch == startEpoch) {
if (listeningStartEpoch == startEpoch &&
(!requireContinuousLoop || canStartContinuousCapture())
) {
startVoiceCapture(rec)
}
} finally {
@@ -2058,6 +2085,15 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
pendingStart.start()
}
private fun canStartContinuousCapture(): Boolean {
val state = _uiState.value
return state.voiceMode &&
state.interactionMode == InteractionMode.Continuous &&
state.state == VoiceState.Idle &&
continuousLoopArmed &&
!continuousListeningPaused
}
private fun startVoiceCapture(rec: VoiceRecorder) {
try {
rec.startRecording()
@@ -2218,6 +2254,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
* listening turn; until then, idle queue-drain callbacks are ignored.
*/
fun pauseContinuousMode() {
cancelPendingListeningStart()
continuousLoopArmed = false
continuousListeningPaused = _uiState.value.interactionMode == InteractionMode.Continuous
continuousResumeJob?.cancel()
@@ -5760,7 +5797,7 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
continuousLoopArmed &&
_uiState.value.state == VoiceState.Idle
) {
startListening()
startListening(requireContinuousLoop = true)
}
}
@@ -5825,6 +5862,29 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
)
return
}
if (!activeResponseOwnsBargeIn()) {
Log.i(TAG, "Barge-in listener skipped; no active voice response owns the microphone")
return
}
val pendingReaderRelease = pendingBargeInReaderRelease.get()?.takeUnless { it.isCompleted }
if (pendingReaderRelease != null) {
// A late playback/realtime callback may request the next turn's
// listener while the previous AudioRecord is still unwinding.
// Join the same ownership fence as VoiceCapture, then re-check the
// turn epoch so stale generations cannot reopen the microphone.
activeBargeInTurnEpoch = epoch
viewModelScope.launch {
pendingReaderRelease.join()
if (activeBargeInTurnEpoch == epoch &&
bargeInListener == null &&
activeResponseOwnsBargeIn()
) {
startBargeInListenerIfEnabled(epoch = epoch)
}
}
return
}
val vad = try {
vadFactory().also { it.setSensitivity(prefs.sensitivity) }
@@ -5873,6 +5933,12 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
}
}
private fun activeResponseOwnsBargeIn(): Boolean {
val state = _uiState.value
return state.voiceMode &&
(state.state == VoiceState.Thinking || state.state == VoiceState.Speaking)
}
/**
* Tear down the active [BargeInListener], cancel its event subscribers,
* unduck the player (in case a ducking watchdog hadn't yet restored
@@ -5906,7 +5972,13 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
try { realtimePcmPlayer?.unduck() } catch (_: Throwable) { /* ignore */ }
isDucked = false
}
return stoppedReaderJob
if (stoppedReaderJob != null) {
pendingBargeInReaderRelease.set(stoppedReaderJob)
stoppedReaderJob.invokeOnCompletion {
pendingBargeInReaderRelease.compareAndSet(stoppedReaderJob, null)
}
}
return pendingBargeInReaderRelease.get()?.takeUnless { it.isCompleted }
}
private fun markBargeInPlaybackStarted(graceMs: Long) {
@@ -5958,6 +6030,8 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
*/
internal fun onBargeInDetected() {
if (isBargeInStartupGuardActive()) return
val interruptedMode = _uiState.value.interactionMode
val interruptedEngine = voiceEngineMode
val interruptedSpokenReply = _uiState.value.outputAudioActive
if (interruptedSpokenReply) spokenInterruptionLatch.mark()
duckingWatchdog?.cancel(); duckingWatchdog = null
@@ -5991,18 +6065,63 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
responseText = "",
)
}
viewModelScope.launch {
val captureEpoch = ++listeningStartEpoch
val pendingStart = viewModelScope.launch(start = CoroutineStart.LAZY) {
try {
microphoneRelease?.join()
val rec = recorder
if (rec != null && !rec.isRecording()) {
if (!canStartBargeInCapture(captureEpoch, interruptedMode, interruptedEngine)) {
abandonBargeInCaptureIfCurrent(captureEpoch)
return@launch
}
val rec = recorder ?: error("Recorder not initialized")
if (!rec.isRecording()) {
rec.startRecording()
}
scheduleResumeWatchdog()
if (canStartBargeInCapture(captureEpoch, interruptedMode, interruptedEngine)) {
scheduleResumeWatchdog()
} else {
try { rec.cancel() } catch (_: Throwable) { /* ignore */ }
abandonBargeInCaptureIfCurrent(captureEpoch)
}
} catch (t: CancellationException) {
abandonBargeInCaptureIfCurrent(captureEpoch)
throw t
} catch (t: Throwable) {
responseInterruptedForVoiceCommand = false
Log.w(TAG, "barge-in microphone handoff failed: ${t.message}")
surfaceError(t, context = "record")
if (listeningStartEpoch == captureEpoch) {
responseInterruptedForVoiceCommand = false
Log.w(TAG, "barge-in microphone handoff failed: ${t.message}")
surfaceError(t, context = "record")
}
} finally {
if (listeningStartEpoch == captureEpoch) {
pendingListeningStartJob = null
}
}
}
pendingListeningStartJob = pendingStart
pendingStart.start()
}
private fun canStartBargeInCapture(
captureEpoch: Long,
interruptedMode: InteractionMode,
interruptedEngine: VoiceEngineMode,
): Boolean {
val state = _uiState.value
return listeningStartEpoch == captureEpoch &&
state.voiceMode &&
state.state == VoiceState.Listening &&
state.interactionMode == interruptedMode &&
voiceEngineMode == interruptedEngine &&
responseInterruptedForVoiceCommand
}
private fun abandonBargeInCaptureIfCurrent(captureEpoch: Long) {
if (listeningStartEpoch != captureEpoch) return
responseInterruptedForVoiceCommand = false
if (_uiState.value.state == VoiceState.Listening && recorder?.isRecording() != true) {
_uiState.update {
it.copy(state = VoiceState.Idle, amplitude = 0f, outputAudioActive = false)
}
}
}
@@ -6314,9 +6433,22 @@ class VoiceViewModel(application: Application) : AndroidViewModel(application) {
startBargeInListenerIfEnabled()
}
@androidx.annotation.VisibleForTesting
internal fun stopBargeInListenerForTest(): Job? = stopBargeInListener()
@androidx.annotation.VisibleForTesting
internal fun finishAgentAudioOutputForTest() {
finishAgentAudioOutput()
}
@androidx.annotation.VisibleForTesting
internal fun setVoiceEngineModeForTest(mode: VoiceEngineMode) {
voiceEngineMode = mode
}
@androidx.annotation.VisibleForTesting
internal fun beginBargeInTurnForTest() {
_uiState.update { it.copy(state = VoiceState.Thinking) }
_uiState.update { it.copy(voiceMode = true, state = VoiceState.Thinking) }
beginBargeInTurnIfEnabled()
}
@@ -231,14 +231,11 @@ class GatewayClientHarness(
val suppressAckMethods: MutableSet<String> = ConcurrentHashMap.newKeySet()
val pendingAcks = LinkedBlockingQueue<PendingAck>()
@Volatile
var suppressGatewayReady: Boolean = false
private val wsListener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: okhttp3.Response) {
serverSockets.add(webSocket)
allServerSockets.add(webSocket)
if (!suppressGatewayReady) sendGatewayReady(webSocket)
webSocket.send(eventFrame("gateway.ready", null, null))
}
override fun onMessage(webSocket: WebSocket, text: String) {
@@ -630,10 +627,6 @@ class GatewayClientHarness(
fun awaitServerSocket(): WebSocket =
serverSockets.poll(5, TimeUnit.SECONDS) ?: error("server socket never opened")
fun sendGatewayReady(webSocket: WebSocket) {
webSocket.send(eventFrame("gateway.ready", null, null))
}
fun awaitRpc(method: String): JsonObject {
val deadline = System.currentTimeMillis() + 5_000
while (System.currentTimeMillis() < deadline) {
@@ -1414,27 +1407,6 @@ class GatewayChatClientTest {
assertEquals(listOf("stored-session"), resumedSessions.toList())
}
@Test
fun `observation warmup never claims or interrupts a foreign runtime`() = runBlocking {
val registrations = AtomicInteger(0)
client.setUnsolicitedTurnProvider {
registrations.incrementAndGet()
GatewayInboundTurnRegistration(Recorder().callbacks) { true }
}
assertTrue(client.observeAwait())
val serverWs = harness.awaitServerSocket()
serverWs.send(harness.eventFrame("message.start", null, "foreign-runtime"))
delay(100)
client.shutdown()
assertEquals(0, registrations.get())
assertFalse(harness.rpcLog.any { it.first == "session.resume" })
assertFalse(harness.rpcLog.any { it.first == "session.activate" })
assertFalse(harness.rpcLog.any { it.first == "session.interrupt" })
assertFalse(harness.rpcLog.any { it.first == "prompt.submit" })
}
@Test
fun `newer prewarm selection wins when an older resume completes late`() = runBlocking {
harness.suppressAckMethods += "session.resume"
@@ -152,4 +152,15 @@ class RelayErrorClassifierTest {
assertEquals("Microphone unavailable", err.title)
assertTrue(err.retryable)
}
@Test
fun microphoneOwnershipConflictMapsToRetryableMicUnavailableHint() {
val err = classifyError(
IllegalStateException("Microphone is in use by another voice feature"),
context = "record",
)
assertEquals("Microphone unavailable", err.title)
assertTrue(err.retryable)
}
}
@@ -992,12 +992,11 @@ class ChatViewModelGatewayInboundTurnTest {
awaitCondition { handler.messages.value.any { it.content == "Partial A" } }
viewModel.switchSession(secondSession)
gatewayHarness.awaitRpcCount("session.resume", 2)
awaitCondition { handler.currentSessionId.value == secondSession && !handler.isStreaming.value }
assertEquals(1, gatewayHarness.rpcLog.count { it.first == "session.resume" })
assertTrue(gatewayHarness.rpcLog.none { it.first == "session.interrupt" })
viewModel.sendMessage("Run task B")
gatewayHarness.awaitRpcCount("session.resume", 2)
gatewayHarness.awaitRpcCount("prompt.submit", 2)
serverWs.send(
gatewayHarness.eventFrame(
@@ -1825,12 +1824,11 @@ class ChatViewModelGatewayInboundTurnTest {
awaitCondition { viewModel.queuedMessages.value == listOf("Follow up A") }
viewModel.switchSession(secondSession)
gatewayHarness.awaitRpcCount("session.resume", 2)
awaitCondition { handler.currentSessionId.value == secondSession && !handler.isStreaming.value }
assertEquals(1, gatewayHarness.rpcLog.count { it.first == "session.resume" })
assertTrue("session B must not show A's queue", viewModel.queuedMessages.value.isEmpty())
viewModel.sendMessage("Run task B")
gatewayHarness.awaitRpcCount("session.resume", 2)
gatewayHarness.awaitRpcCount("prompt.submit", 2)
serverWs.send(
gatewayHarness.eventFrame(
@@ -2033,16 +2031,13 @@ class ChatViewModelGatewayInboundTurnTest {
serverWs.close(1012, "test disconnect")
awaitCondition { gatewayClient.connectionState.value == GatewayConnectionState.Idle }
viewModel.setChatVisible(true)
viewModel.prewarmGateway()
gatewayHarness.awaitServerSocket()
gatewayHarness.awaitRpcCount("session.resume", 2)
awaitCondition {
handler.messages.value.singleOrNull()?.content == BACKGROUND_ANSWER
}
assertEquals(1, gatewayHarness.rpcLog.count { it.first == "session.resume" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.activate" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.interrupt" })
assertFalse(handler.isStreaming.value)
}
@@ -2053,19 +2048,16 @@ class ChatViewModelGatewayInboundTurnTest {
// Foreground arrives while OkHttp still reports the old socket ready,
// so the one-shot prewarm is an intentional no-op. The delayed close
// callback must itself restore the observation socket and catch up
// history without attaching the live session.
// callback must itself trigger an exact-session reattach.
viewModel.prewarmGateway()
serverWs.close(1012, "late background close")
awaitCondition { gatewayHarness.ticketMints.get() >= 2 }
serverWs = gatewayHarness.awaitServerSocket()
gatewayHarness.awaitRpcCount("session.resume", 2)
awaitCondition {
handler.messages.value.singleOrNull()?.content == BACKGROUND_ANSWER
}
assertEquals(1, gatewayHarness.rpcLog.count { it.first == "session.resume" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.activate" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.interrupt" })
assertFalse(handler.isStreaming.value)
}
@@ -2374,189 +2366,36 @@ class ChatViewModelGatewayInboundTurnTest {
}
@Test
fun reconnectCatchupClosesCompletionBetweenFirstReadAndIdleSnapshot() {
viewModel.switchProfileContext(PROFILE_CONTEXT, STORED_SESSION_ID)
awaitCondition { !viewModel.isLoadingHistory.value }
val firstReadStarted = CompletableDeferred<Unit>()
val releaseFirstRead = CompletableDeferred<Unit>()
val readCount = AtomicInteger(0)
viewModel.setProfileMessageLoader {
if (readCount.incrementAndGet() == 1) {
firstReadStarted.complete(Unit)
releaseFirstRead.await()
Result.success(emptyList())
} else {
Result.success(persistedHistory)
}
}
fun reconnectAfterMissedStartRecoversOnExactSessionCompletion() {
serverWs.close(1012, "missed start")
awaitCondition { gatewayClient.connectionState.value == GatewayConnectionState.Idle }
viewModel.setChatVisible(true)
viewModel.prewarmGateway()
serverWs = gatewayHarness.awaitServerSocket()
awaitCondition { firstReadStarted.isCompleted }
// Completion persists after the reconnect's first catch-up read began,
// while the first active-list snapshot is already empty/idle. The
// pending final-read marker must close this exact ordering window.
gatewayHarness.awaitRpcCount("session.resume", 2)
// Reconnected midway through the synthetic turn: no message.start is
// replayed, so the delta is intentionally ignored and completion drives
// authoritative history recovery.
serverWs.send(
gatewayHarness.eventFrame(
"message.delta",
buildJsonObject { put("text", BACKGROUND_ANSWER) },
"live-resumed",
),
)
persistedHistory = persistedAnswerHistory()
releaseFirstRead.complete(Unit)
serverWs.send(
gatewayHarness.eventFrame(
"message.complete",
buildJsonObject { put("text", BACKGROUND_ANSWER) },
"live-resumed",
),
)
awaitCondition { handler.messages.value.any { it.content == BACKGROUND_ANSWER } }
assertEquals(1, gatewayHarness.rpcLog.count { it.first == "session.resume" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.activate" })
assertEquals(0, gatewayHarness.rpcLog.count { it.first == "session.interrupt" })
assertFalse(handler.isStreaming.value)
}
@Test
fun passiveForegroundObservationNeverClaimsOrInterruptsDesktopTurn() {
val observerProfile = Profile(
name = "observer",
model = "model-a",
description = "Observer",
)
viewModel.setSelectedProfileProvider { observerProfile }
viewModel.setSessionProfileNameProvider { observerProfile.name }
viewModel.setProfileMessageLoaderWithMode { profileName, sessionId, _ ->
assertEquals(STORED_SESSION_ID, sessionId)
Result.success(
if (profileName == observerProfile.name) {
persistedHistory
} else {
listOf(
MessageItem(
id = "wrong-profile",
sessionId = STORED_SESSION_ID,
role = "assistant",
content = JsonPrimitive("Wrong profile history"),
),
)
},
)
}
viewModel.switchProfileContext(
AgentDisplay.profileContextKey("connection-a", observerProfile.name),
STORED_SESSION_ID,
)
awaitCondition { !viewModel.isLoadingHistory.value }
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val ownershipMethods = setOf(
"session.resume",
"session.activate",
"session.interrupt",
"prompt.submit",
)
val baseline = ownershipMethods.associateWith { method ->
gatewayHarness.rpcLog.count { it.first == method }
}
val baselineActiveList = gatewayHarness.rpcLog.count { it.first == "session.active_list" }
gatewayHarness.activeSessionListPayload = activeSessionPayload("working")
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = gatewayHarness.server.url("/").toString().trimEnd('/'),
okHttpClient = OkHttpClient(),
),
okHttpClient = OkHttpClient(),
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
)
viewModel.setChatTurnCheckpointStore(MemoryCheckpointStore())
viewModel.updateGatewayClient(gatewayClient)
viewModel.setChatVisible(true)
viewModel.prewarmGateway()
awaitCondition {
gatewayHarness.rpcLog.count { it.first == "session.active_list" } > baselineActiveList
}
persistedHistory = listOf(
MessageItem(
id = "desktop-answer",
sessionId = STORED_SESSION_ID,
role = "assistant",
content = JsonPrimitive("Desktop completed without Android attachment."),
),
)
awaitCondition {
handler.messages.value.singleOrNull()?.content ==
"Desktop completed without Android attachment."
}
ownershipMethods.forEach { method ->
assertEquals(
"passive foreground sent $method",
baseline.getValue(method),
gatewayHarness.rpcLog.count { it.first == method },
)
}
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
assertEquals(
"observer teardown interrupted the Desktop turn",
baseline.getValue("session.interrupt"),
gatewayHarness.rpcLog.count { it.first == "session.interrupt" },
)
}
@Test
fun observerReadyAfterChatHidesCannotRestartPassiveWork() {
viewModel.switchProfileContext(PROFILE_CONTEXT, STORED_SESSION_ID)
awaitCondition { !viewModel.isLoadingHistory.value }
viewModel.setChatVisible(false)
viewModel.updateGatewayClient(null)
gatewayClient.shutdown()
gatewayScope.cancel()
val historyReads = AtomicInteger(0)
viewModel.setProfileMessageLoader {
historyReads.incrementAndGet()
Result.success(persistedHistory)
}
val controlMethods = setOf(
"session.resume",
"session.activate",
"session.interrupt",
"prompt.submit",
)
val baseline = controlMethods.associateWith { method ->
gatewayHarness.rpcLog.count { it.first == method }
}
val baselineActiveList = gatewayHarness.rpcLog.count { it.first == "session.active_list" }
gatewayHarness.suppressGatewayReady = true
gatewayScope = CoroutineScope(SupervisorJob() + Dispatchers.IO)
gatewayClient = GatewayChatClient(
initialDashboardClient = DashboardApiClient(
baseUrl = gatewayHarness.server.url("/").toString().trimEnd('/'),
okHttpClient = OkHttpClient(),
),
okHttpClient = OkHttpClient(),
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
scope = gatewayScope,
)
viewModel.setChatTurnCheckpointStore(MemoryCheckpointStore())
viewModel.updateGatewayClient(gatewayClient)
viewModel.setChatVisible(true)
val delayedSocket = gatewayHarness.awaitServerSocket()
viewModel.setChatVisible(false)
gatewayHarness.sendGatewayReady(delayedSocket)
shadowOf(Looper.getMainLooper()).idleFor(500, TimeUnit.MILLISECONDS)
Thread.sleep(100)
assertEquals(0, historyReads.get())
assertEquals(
baselineActiveList,
gatewayHarness.rpcLog.count { it.first == "session.active_list" },
)
controlMethods.forEach { method ->
assertEquals(baseline.getValue(method), gatewayHarness.rpcLog.count { it.first == method })
}
}
@Test
fun staleHistoryReadCannotEraseATurnCompletedDuringTheFetch() {
val loadCount = AtomicInteger(0)
@@ -10,8 +10,10 @@ import com.hermesandroid.relay.audio.VoiceSfxPlayer
import com.hermesandroid.relay.data.BargeInPreferences
import com.hermesandroid.relay.data.BargeInPreferencesRepository
import com.hermesandroid.relay.data.BargeInSensitivity
import com.hermesandroid.relay.data.VoiceEngineMode
import com.hermesandroid.relay.network.relay.RelayVoiceClient
import com.hermesandroid.relay.viewmodel.ChatViewModel
import com.hermesandroid.relay.viewmodel.InteractionMode
import com.hermesandroid.relay.viewmodel.VoiceState
import com.hermesandroid.relay.viewmodel.VoiceViewModel
import io.mockk.every
@@ -273,6 +275,360 @@ class VoiceViewModelBargeInTest {
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `continuous completion waits for queue-drain barge-in release before capture`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returnsMany listOf(readerRelease, null, null)
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.startBargeInListenerForTest()
runCurrent()
// The play worker tears down barge-in before the shared completion
// finalizer runs. Repeated teardown calls must retain that first
// asynchronous release instead of attempting VoiceCapture immediately.
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
vm.startBargeInListenerForTest()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
verify(exactly = 1) { bargeInListener.start(any()) }
readerRelease.complete()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
verify(exactly = 1) { bargeInListener.start(any()) }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `continuous completion repeats serialized handoff across turns`() = runTest {
val firstRelease = Job()
val secondRelease = Job()
var stopCalls = 0
every { bargeInListener.stop() } answers {
when (stopCalls++) {
0 -> firstRelease
1 -> secondRelease
else -> null
}
}
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("First."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.startBargeInListenerForTest()
runCurrent()
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
runCurrent()
firstRelease.complete()
runCurrent()
vm.seedSpeakingStateForTest(chunks = listOf("Second."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
secondRelease.complete()
runCurrent()
verify(exactly = 2) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `barge-in disabled keeps continuous completion immediate`() = runTest {
val vm = buildViewModel(
BargeInPreferences(
enabled = false,
sensitivity = BargeInSensitivity.Off,
),
)
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.finishAgentAudioOutputForTest()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `exit cancels continuous capture waiting for microphone release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returnsMany listOf(readerRelease, null, null)
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.startBargeInListenerForTest()
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
runCurrent()
vm.exitVoiceMode()
vm.startBargeInListenerForTest()
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
verify(exactly = 1) { bargeInListener.start(any()) }
assertTrue(!vm.uiState.value.voiceMode)
}
@Test
fun `pause cancels continuous capture waiting for microphone release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returnsMany listOf(readerRelease, null, null)
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.startBargeInListenerForTest()
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
runCurrent()
vm.pauseContinuousMode()
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `rapid mode change starts only the newly armed continuous capture`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returnsMany listOf(readerRelease, null, null, null)
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.startBargeInListenerForTest()
vm.stopBargeInListenerForTest()
vm.finishAgentAudioOutputForTest()
runCurrent()
vm.setInteractionMode(InteractionMode.TapToTalk)
vm.setInteractionMode(InteractionMode.Continuous)
runCurrent()
readerRelease.complete()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `next barge-in generation waits for prior reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returnsMany listOf(readerRelease, null)
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("First."), currentIdx = 0)
vm.startBargeInListenerForTest()
runCurrent()
vm.stopBargeInListenerForTest()
vm.startBargeInListenerForTest()
vm.startBargeInListenerForTest()
runCurrent()
verify(exactly = 1) { bargeInListener.start(any()) }
readerRelease.complete()
runCurrent()
verify(exactly = 2) { bargeInListener.start(any()) }
}
@Test
fun `barge-in capture waits for reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
runCurrent()
vm.onBargeInDetected()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
readerRelease.complete()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `exit invalidates barge-in capture waiting for reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
vm.exitVoiceMode()
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
assertTrue(!vm.uiState.value.voiceMode)
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `continuous pause invalidates barge-in capture waiting for reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.setInteractionMode(InteractionMode.Continuous)
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
vm.pauseContinuousMode()
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `interaction mode switch invalidates barge-in capture waiting for reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
vm.setInteractionMode(InteractionMode.HoldToTalk)
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
assertEquals(InteractionMode.HoldToTalk, vm.uiState.value.interactionMode)
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `engine switch invalidates barge-in capture waiting for reader release`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
vm.setVoiceEngineModeForTest(VoiceEngineMode.RealtimeAgent)
readerRelease.complete()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
assertEquals(VoiceState.Idle, vm.uiState.value.state)
}
@Test
fun `newer manual capture supersedes barge-in release waiter`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
vm.startListening()
runCurrent()
verify(exactly = 0) { recorder.startRecording() }
readerRelease.complete()
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `reader release completion starts valid barge-in capture only once`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
assertTrue(readerRelease.complete())
runCurrent()
assertTrue(!readerRelease.complete())
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Listening, vm.uiState.value.state)
}
@Test
fun `failed barge-in recorder acquisition does not arm resume watchdog`() = runTest {
val readerRelease = Job()
every { bargeInListener.stop() } returns readerRelease
every { recorder.startRecording() } throws
IllegalStateException("Microphone is in use by another voice feature")
val vm = buildViewModel()
vm.seedSpeakingStateForTest(chunks = listOf("Speaking.", "Tail."), currentIdx = 0)
vm.startBargeInListenerForTest()
vm.onBargeInDetected()
runCurrent()
readerRelease.complete()
runCurrent()
advanceTimeBy(700)
runCurrent()
verify(exactly = 1) { recorder.startRecording() }
assertEquals(VoiceState.Error, vm.uiState.value.state)
}
@Test
fun `transient recorder ownership failures remain explicitly retryable`() = runTest {
var attempts = 0
every { recorder.startRecording() } answers {
attempts++
if (attempts <= 2) {
throw IllegalStateException("Microphone is in use by another voice feature")
}
java.io.File("voice-retry-test.wav")
}
val vm = buildViewModel(
BargeInPreferences(
enabled = false,
sensitivity = BargeInSensitivity.Off,
),
)
vm.seedSpeakingStateForTest(chunks = listOf("Finished."), currentIdx = 0)
vm.setInteractionMode(InteractionMode.Continuous)
vm.finishAgentAudioOutputForTest()
runCurrent()
assertEquals(VoiceState.Error, vm.uiState.value.state)
vm.startListening()
runCurrent()
assertEquals(VoiceState.Error, vm.uiState.value.state)
vm.startListening()
runCurrent()
assertEquals(VoiceState.Listening, vm.uiState.value.state)
verify(exactly = 3) { recorder.startRecording() }
}
// -------------------------------------------------------------------
// Test 2 — resume with resumeAfterInterruption=true + silence
// -------------------------------------------------------------------
-33
View File
@@ -3977,36 +3977,3 @@ disappearance, client-side profile isolation, and method-not-found; physical
and current-host certification remains tracked in `TODO.md`. An upstream
profile field/filter or explicitly owned aggregate activity route would remove
the remaining ambiguity for multi-profile clients.
---
## ADR 69 — Passive Android observation never attaches another client's Gateway turn
**Status:** Accepted (2026-08-28).
**Context.** `session.resume` and `session.activate` are live-runtime attachment
operations, not read-only subscriptions. Android previously called
`session.resume` while opening or foregrounding Chat and after loading a saved
session's history. When Desktop/TUI already owned a running turn, that passive
prewarm could rebind the runtime transport to Android. A later Android socket,
route, or client teardown could then strand the producer or promote the foreign
turn into an Android `GatewayTurn` whose cancellation sends `session.interrupt`.
The issue was distinct from the earlier stale-view and missing-terminal recovery
paths, which concern exact Android-owned checkpoints.
**Decision.** Ordinary visibility, foreground restoration, Idle-socket recovery,
and saved-session selection establish only the shared Gateway socket. They use
profile-scoped REST history plus process-wide `session.active_list`; while an
unowned row with the selected durable id is live, Android performs bounded
history refreshes and one final read after settlement. These observer paths send
no `session.resume`, `session.activate`, `prompt.submit`, or `session.interrupt`.
Exact Android-owned checkpoints retain `session.activate` with durable-resume
fallback, and explicit send or session-config actions may resume because the user
is intentionally taking control of that destination.
**Consequences.** Opening Android cannot replace, stop, or later cancel a turn
already running in Desktop/TUI. Live token frames remain with the producing
client; Android observes durable progress and final history without inventing a
multi-subscriber Gateway contract. The first explicit Android mutation may pay
the resume latency that passive prewarm previously hid. Cross-client fixtures
and Android lifecycle coverage enforce the no-control-RPC observation boundary.
-1
View File
@@ -41,7 +41,6 @@ the upstream contract identifiers it depends on.
| `active_status_lifecycle` | `session.active_list` reports starting, working, waiting, and idle, then a complete empty process-wide snapshot permits removal of unambiguously owned prior rows |
| `active_status_profile_scope` | A row has no profile metadata and a caller profile hint has no effect; the client must use exact client-held ownership and reject invented attribution |
| `active_status_unsupported` | An older Gateway returns JSON-RPC method-not-found; the client retains Unknown rather than inventing Idle or Working |
| `cross_client_observation` | A second client observes a Desktop-owned working session through active status and history without resume, activate, submit, or interrupt; the producing client receives the terminal event |
Fixture evidence is a bounded metadata-only ring. It records sequence,
connection number, RPC method, event type, scope classification, and outcome.
+1 -1
View File
@@ -481,7 +481,7 @@ Bottom navigation bar with 4 tabs:
- **Bot group projection** — Android merges the bounded `ui_meta["hermes-bots-groups"]` v3 projection across gateways by durable room identity and newest revision. Rooms and recent messages are visibly read-only; Android does not create, rename, disband, join, send, coordinate member turns, or become a second room-log authority. Binary room images are ignored at this metadata boundary.
- **Session drawer** (swipe from left or hamburger icon) — session list with title, timestamp, message count. Create, switch, rename, delete, pin/unpin, and archive/restore. The process-owned conversation binding is the single connection/profile/session identity for Chat; selecting an All Profiles row atomically makes its owner the selected agent and persists that profile/session, while merely browsing All Profiles changes no agent state. Lifecycle or locale-driven Activity recreation cannot replace an explicit binding with stale persisted state, and asynchronous list/history/mutation work is accepted only for the binding's exact namespace. A profile lock hides All Profiles and rejects stale/deep-linked cross-profile opens. The All Profiles browser mode otherwise survives Activity state restoration and refetches its rows after recreation. Pin and archive are durable upstream session fields loaded and patched through the owning connection/profile's Dashboard session API; Android does not keep a second local flag registry. Archived rows are requested explicitly so they remain restorable after recreation. Failed mutations roll back the optimistic row, while refresh and deletion reconcile from server truth. When a persisted title is absent, use upstream's first-user-message `preview`, matching the Hermes Desktop session picker; show "Untitled" only when neither value exists.
- **Authoritative session activity** — one composite registry keyed by connection, normalized profile, and durable session id drives the drawer, filters, grouping, animation, accessibility, and the visible composer. Exact pending approval/clarify/sudo/secret/MCP requests produce **Needs input**; the Gateway's process-wide `session.active_list` supplies **Starting**, **Working**, and **Idle**; exact terminal or `session.info {running:false}` can settle the matching generation. Because active-list rows normally have no profile metadata, Android assigns a row only through exact foreground/detached ownership already held by that client, or explicit profile metadata if a future upstream sends it. A bounded REST directory never proves global uniqueness. Unresolved rows create no status. Resolved rows from a partial snapshot may update their exact owners, but disappearance settles a scope only when the successful process-wide snapshot was completely and unambiguously resolved for it. Restart/checkpoint recovery is **Checking**; a failed or unsupported live refresh is **Unavailable**, never inferred Idle. REST `is_active` remains recency metadata only. `process.list` may add a separate **Background work** indicator and never keeps the parent conversation Working. Old socket generations, bare session ids from another profile, and delayed snapshots cannot revive newer settled state.
- **Concurrent Gateway chats** — switching sessions, profiles, drafts, or Threads detaches the visible Android-owned turn without sending `session.interrupt`; each Android-owned running chat keeps a connection/profile/session-scoped checkpoint and reattaches to its live Gateway session when reopened. Opening, foregrounding, or selecting a saved session without that exact checkpoint is read-only observation: Android warms only the socket, reads profile-scoped history, and polls `session.active_list` without `session.resume`, `session.activate`, `prompt.submit`, or `session.interrupt`. A Desktop/TUI-owned turn therefore remains owned by its producing client; Android refreshes persisted progress and performs one final history read when the runtime settles. Explicit send/config actions may resume the destination session, explicit Stop still interrupts, and SSE fallback stays single-stream and cancels on navigation.
- **Concurrent Gateway chats** — switching sessions, profiles, drafts, or Threads detaches the visible turn without sending `session.interrupt`; each running chat keeps a connection/profile/session-scoped checkpoint and reattaches to its live Gateway session when reopened. Explicit Stop still interrupts. SSE fallback stays single-stream and cancels on navigation.
- **Queued Gateway follow-ups** — every local queued item is immutably scoped to its originating connection, profile, stored session, transport, and run generation; only that run's completion can make it eligible, and switching sessions shows only that session's queue. Restored text queues retain the same scope, while unavailable/deleted destinations and non-restorable attachment queues fail visibly instead of following the current composer. Drained messages add `queued: true` to `prompt.submit`; ordinary sends omit the field. Authoritative submit rejections (`4004`, `4018`, `4028`, `4029`, `4030`, `4090`, `5008`, `5070`, and `5071`) preserve the server message and never fall through to API-server SSE.
- **Durable composer drafts** — each connection/profile/session owns one app-private draft containing text, quote/edit context, and pending attachment bytes. Metadata and content-addressed blobs live under Android's no-backup directory, are capped at 64 drafts and 128 MB of retained blobs outside the active draft, flush when Chat backgrounds, and are removed after a successful send. Session/profile/connection navigation saves the previous owner before restoring the destination; an opened cross-profile session uses its actual owning profile rather than the global picker.
- **Large paste review** — a default-on Chat setting converts any single insertion of at least 5,000 characters into a visible `pasted-text.txt` attachment before the normal message-length limit rejects it. Gateway uses upstream `file.attach`; API-server SSE and proactive Thread paths materialize the same UTF-8 text into the outgoing prompt and remove only the synthetic attachment from that transport, so the behavior never requires Relay or silently drops content.
@@ -100,47 +100,6 @@ class FixtureTestCase(unittest.IsolatedAsyncioTestCase):
self.assertEqual(["user", "assistant"], [row["role"] for row in history["messages"]])
self.assertEqual(2, history["pagination"]["returned"])
async def test_cross_client_observer_never_claims_or_interrupts_producer(self) -> None:
fixture, base_url = await self.start("cross_client_observation")
producer, _ = await self.connect(base_url)
await self.rpc(producer, 1, "session.resume", {"session_id": fixture.scenario.stored_session_id})
await producer.receive_json()
await self.rpc(producer, 2, "prompt.submit", {"text": "producer-only content"})
producer_frames = await self.frames_until(
producer,
lambda frame: frame.get("params", {}).get("type") == "message.delta",
)
observer, _ = await self.connect(base_url)
await self.rpc(observer, 3, "session.active_list")
active = (await observer.receive_json())["result"]["sessions"]
self.assertEqual("working", active[0]["status"])
async with self.session.get(
f"{base_url}/api/sessions/{fixture.scenario.stored_session_id}/messages",
params={"profile": "default", "limit": 500, "offset": 0, "order": "asc"},
) as response:
self.assertEqual(200, response.status)
self.assertIsInstance((await response.json())["messages"], list)
await observer.close()
producer_frames += await self.frames_until(
producer,
lambda frame: frame.get("params", {}).get("type") == "message.complete",
)
self.assertIn(
"message.complete",
[frame.get("params", {}).get("type") for frame in producer_frames],
)
async with self.session.get(f"{base_url}/__fixture__/evidence") as response:
evidence = await response.json()
observer_methods = [
entry.get("method")
for entry in evidence["entries"]
if entry.get("kind") == "rpc" and entry.get("connection") == 2
]
self.assertEqual(["session.active_list"], observer_methods)
self.assertNotIn("session.interrupt", observer_methods)
async def test_rapid_chunks_tools_and_interims_keep_wire_order(self) -> None:
_, base_url = await self.start("rapid_tools_interims")
ws, _ = await self.connect(base_url)
@@ -306,7 +265,6 @@ class ScenarioTestCase(unittest.TestCase):
"active_status_lifecycle",
"active_status_profile_scope",
"active_status_unsupported",
"cross_client_observation",
"ordinary_turn",
"rapid_tools_interims",
"terminal_gap_activate",
@@ -346,10 +304,6 @@ class ScenarioTestCase(unittest.TestCase):
("gateway.settled_session_info",),
load_scenario("terminal_gap_session_info").contract_requirements,
)
self.assertEqual(
("gateway.message_complete", "gateway.session_active_list"),
load_scenario("cross_client_observation").contract_requirements,
)
def test_tls_arguments_must_be_paired(self) -> None:
with contextlib.redirect_stderr(io.StringIO()):
@@ -1,40 +0,0 @@
{
"name": "cross_client_observation",
"live_session_id": "fixture-desktop-live",
"stored_session_id": "fixture-shared-session",
"profile": "default",
"contract_requirements": [
"gateway.message_complete",
"gateway.session_active_list"
],
"initial_history": [],
"turns": [
{
"steps": [
{"op": "event", "type": "message.start"},
{"op": "event", "type": "message.delta", "payload": {"text": "Desktop still owns this turn."}},
{"op": "sleep", "milliseconds": 250},
{
"op": "persist",
"messages": [
{"id": 1, "role": "user", "content": "Desktop prompt.", "timestamp": 1.0},
{"id": 2, "role": "assistant", "content": "Desktop still owns this turn.", "timestamp": 2.0, "finish_reason": "stop"}
]
},
{"op": "set_running", "value": false},
{"op": "event", "type": "message.complete", "payload": {"text": "Desktop still owns this turn.", "status": "complete"}}
]
}
],
"active_list": {
"supported": true,
"snapshots": [
[
{"id": "fixture-desktop-live", "session_key": "fixture-shared-session", "status": "working", "current": false}
],
[
{"id": "fixture-desktop-live", "session_key": "fixture-shared-session", "status": "idle", "current": false}
]
]
}
}