Compare commits

...
Author SHA1 Message Date
Bailey Dixon c917a94fcb fix(android): polish voice errors and steer/queue controls 2026-09-02 21:09:32 -04:00
Bailey Dixon e1a72ee8af Merge pull request #537 from Codename-11/fix/android-session-refresh-oom
fix(android): harden chat sessions and media rendering
2026-09-02 13:49:02 -04:00
Bailey Dixon 94f9ba4305 fix(android): harden chat sessions and media rendering 2026-09-02 13:34:14 -04:00
Bailey Dixon 3186afdde8 Merge pull request #536 from Codename-11/fix/android-attachment-viewer-rotation-salvage
fix(android): preserve attachment previews across rotation
2026-09-02 06:59:34 -04:00
Bailey Dixon 0261a342cf merge: refresh attachment viewer salvage from dev
# Conflicts:
#	CHANGELOG.md
2026-09-01 22:16:20 -04:00
Bailey DixonandYuzhe Wang f4c212f800 fix(android): preserve attachment previews across rotation
Hoist full-screen media viewers above transcript rows so responsive portrait/landscape reflow cannot dismiss an active image, attachment, or gallery preview. Reset the host when its connection, session, or policy owner changes.

Render video through Media3's fitted Compose content frame, retain playback position and controls across player recreation, and respect the user's system rotation preference.

Add focused state-restoration and viewer-host coverage for attachments, images, galleries, and owner changes.

Co-authored-by: Yuzhe Wang <o_xkenshin@icloud.com>
2026-09-01 22:15:56 -04:00
Bailey Dixon 3bb294c6c3 Merge pull request #535 from Codename-11/fix/android-sherpa-r8-jni
fix(android): preserve sherpa JNI names through R8
2026-09-01 22:03:15 -04:00
Bailey Dixon dc73cc74b1 Merge remote-tracking branch 'origin/dev' into fix/android-sherpa-r8-jni 2026-09-01 21:52:27 -04:00
Bailey Dixon 607bc95b73 Merge chore/repository-organization-20260901 into integration/repository-organization-20260901 2026-09-01 21:47:50 -04:00
Bailey Dixon 3b4da0305e docs: organize project records 2026-09-01 21:37:16 -04:00
Bailey Dixon 3af0092b8f Merge remote-tracking branch 'origin/dev' into fix/android-sherpa-r8-jni
# Conflicts:
#	CHANGELOG.md
2026-09-01 21:14:38 -04:00
Bailey DixonandMattyB01 9cfa4c8b8c fix(android): preserve sherpa JNI names through R8
Co-authored-by: MattyB01 <141138642+MattyB01@users.noreply.github.com>
2026-09-01 21:14:15 -04:00
Bailey Dixon a7c860a2e3 Merge pull request #532 from Codename-11/fix/android-stream-dashboard-media
fix(android): stream dashboard media to disk
2026-09-01 21:02:39 -04:00
Bailey Dixon ed71b02b01 Merge remote-tracking branch 'origin/dev' into fix/android-stream-dashboard-media
# Conflicts:
#	CHANGELOG.md
2026-09-01 19:25:15 -04:00
Bailey Dixon a90dc85466 Merge pull request #533 from Codename-11/fix/android-gateway-owner-rejection
fix(android): wait for gateway session readiness
2026-09-01 19:08:41 -04:00
Bailey Dixon 67a60143cb fix(android): wait for gateway session readiness 2026-09-01 18:50:46 -04:00
Bailey Dixon c3276fa7e5 chore: quarantine Quest experiment 2026-09-01 18:17:22 -04:00
Bailey Dixon 99ac20de35 fix(android): stream dashboard media to disk 2026-09-01 13:06:15 -04:00
Bailey Dixon 0650102230 docs: organize localized readme entrypoints 2026-09-01 12:19:03 -04:00
Bailey Dixon 8d4f324717 feat(release): promote exact-tree artifacts and CI evidence (#530) 2026-09-01 11:00:43 -04:00
Bailey Dixon c9ee5348bf Merge origin/dev into feature/release-fast-path 2026-09-01 10:40:01 -04:00
Bailey Dixon ee2a7840a2 test(android): generalize release notice coverage 2026-09-01 10:39:40 -04:00
Bailey Dixon 52dd399565 Merge docs/refine-readme-connection-map-teknium into integration/readme-connection-map-refinement-20260901 2026-09-01 10:38:01 -04:00
Bailey Dixon 86a0421163 docs(release): record tray cache reuse 2026-09-01 10:37:54 -04:00
Bailey Dixon 0e191f946d fix(marketing): refine README connection graphic 2026-09-01 10:37:40 -04:00
Bailey Dixon 065912f2bf fix(release): keep coordinated approval stable-only 2026-09-01 10:37:30 -04:00
Bailey Dixon 075138433e fix(release): report promoted Android signing 2026-09-01 10:35:57 -04:00
Bailey Dixon 92e65bbfc2 Merge origin/dev into feature/release-fast-path
# Conflicts:
#	DEVLOG.md
2026-09-01 10:34:23 -04:00
Bailey Dixon 7ccd4ac4c9 docs(release): document exact-tree promotion 2026-09-01 10:33:49 -04:00
Bailey Dixon 5739e17750 test(ci): cover release fast paths 2026-09-01 10:33:49 -04:00
Bailey Dixon 037f4e91c8 ci(desktop): cache exact tray builds 2026-09-01 10:33:39 -04:00
Bailey Dixon 685c3c5a24 test(android): derive release presentation expectations 2026-09-01 10:33:30 -04:00
Bailey Dixon 6dc18abc4d ci(release): reuse exact-tree verification 2026-09-01 10:33:21 -04:00
Bailey Dixon ee43a87cec feat(release): promote verified Android artifacts 2026-09-01 10:33:09 -04:00
Bailey Dixon ce961b81d9 Merge pull request #529 from Codename-11/fix/desktop-unified-updater
fix(desktop): keep CLI and UI updates in sync
2026-09-01 10:32:16 -04:00
Bailey Dixon c7b392b26f test(desktop): honor injected updater platform 2026-09-01 10:14:52 -04:00
Bailey Dixon 0a04efbbcf chore: merge origin/dev into fix/desktop-unified-updater 2026-09-01 10:09:49 -04:00
Bailey Dixon 11977dad56 fix(release): validate extension tags before creation (#527) 2026-09-01 08:08:37 -04:00
Bailey Dixon c8fea9c061 Merge origin/dev into fix/release-tag-approval 2026-09-01 07:58:08 -04:00
Bailey Dixon b0a8909dc7 Merge pull request #522 from Codename-11/fix/android-tablet-chat-layout
fix(android): adapt Chat and Voice for tablets
2026-09-01 07:56:37 -04:00
Bailey Dixon 57c236e7da fix(release): validate extension tags before creation 2026-09-01 07:48:58 -04:00
Bailey Dixon 8156a821eb chore: refresh tablet layout branch from origin/dev
# Conflicts:
#	CHANGELOG.md
2026-09-01 07:38:43 -04:00
Bailey Dixon b015acb063 fix(desktop): keep CLI and UI updates in sync 2026-09-01 07:18:19 -04:00
Bailey Dixon 2f7bd843bc docs: note Android tablet layout improvements 2026-08-31 21:32:50 -04:00
Bailey Dixon d1527d47e4 chore: refresh tablet layout branch from origin/dev 2026-08-31 21:00:44 -04:00
Bailey Dixon bc0853360a fix(android): adapt chat and voice for tablets 2026-08-31 21:00:07 -04:00
Bailey Dixon 35362b8895 chore: refresh tablet layout branch from origin/dev 2026-08-31 20:06:05 -04:00
Bailey Dixon ff7ca89b90 fix(android): improve tablet chat layout 2026-08-31 20:06:05 -04:00
194 changed files with 5937 additions and 1289 deletions
+8 -1
View File
@@ -4,6 +4,7 @@ function classifyCiPaths(paths) {
const forceAll = paths.some((path) => [
'.github/workflows/ci-required.yml',
'.github/workflows/release-backmerge.yml',
'.github/workflows/approve-release-train.yml',
'.github/scripts/classify-ci-paths.cjs',
'.github/scripts/classify-ci-paths.test.cjs',
'scripts/plan_release_backmerge.py',
@@ -13,15 +14,17 @@ function classifyCiPaths(paths) {
const under = (prefixes) => paths.some((path) => prefixes.some((prefix) => path.startsWith(prefix)));
return {
android: forceAll || under(['app/', 'relay-core/', 'relay-ui/', 'ui-preview/', 'quest/', 'gradle/']) || exact([
android: forceAll || under(['app/', 'gradle/']) || exact([
'build.gradle.kts', 'settings.gradle.kts', 'gradle.properties', 'gradlew', 'gradlew.bat',
'scripts/check-android-locales.py', 'scripts/android-locale-harness.py',
'scripts/check-android-collection-apis.py', 'scripts/check-android-native-compat.py',
'scripts/check-android-release-notes.py',
'scripts/android_release_artifacts.py',
'scripts/android-lane.ps1', 'scripts/android-prepush.py', 'scripts/dev.bat', 'scripts/dev.sh',
'scripts/tests/android_prepush_test.py',
'scripts/tests/check_android_native_compat_test.py',
'scripts/tests/check_android_release_notes_test.py',
'scripts/tests/android_release_artifacts_test.py',
'.github/workflows/android-on-demand.yml', '.github/workflows/ci-android.yml',
'.github/workflows/play-preflight-android.yml',
'.github/workflows/approve-release-android.yml',
@@ -29,12 +32,16 @@ function classifyCiPaths(paths) {
]),
desktop: forceAll || under(['desktop/']) || exact([
'.github/workflows/ci-desktop.yml',
'.github/workflows/approve-release-extensions.yml',
'.github/workflows/release-cli.yml',
]),
plugin: forceAll || paths.some((path) => /^plugin\/[^/]+\.py$/.test(path)) ||
under(['plugin/relay/', 'plugin/tools/', 'plugin/tests/', 'relay_server/', 'hermes_relay_bootstrap/']) || exact([
'plugin/plugin.yaml', 'pyproject.toml', 'scripts/check-plugin-version-sync.py',
'scripts/check-server-version-sync.py', 'scripts/bump-plugin-version.sh',
'scripts/bump-server-version.sh', '.github/workflows/ci-plugin.yml',
'.github/workflows/approve-release-extensions.yml',
'.github/workflows/release-plugin.yml',
]),
dashboard: forceAll || under(['plugin/dashboard/']) || exact([
'.github/workflows/ci-dashboard.yml',
+80 -1
View File
@@ -1,6 +1,8 @@
'use strict';
const assert = require('node:assert/strict');
const { readFileSync } = require('node:fs');
const { join } = require('node:path');
const { classifyCiPaths } = require('./classify-ci-paths.cjs');
const none = {
@@ -14,9 +16,11 @@ const none = {
assert.deepEqual(classifyCiPaths(['README.md']), none);
assert.deepEqual(classifyCiPaths(['desktop/src/cli.ts']), { ...none, desktop: true });
assert.deepEqual(classifyCiPaths(['relay-core/src/main/kotlin/Wire.kt']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['experiments/quest/src/main/kotlin/Quest.kt']), none);
assert.deepEqual(classifyCiPaths(['scripts/check-android-release-notes.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/check-android-native-compat.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android_release_artifacts.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/android_release_artifacts_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/check_android_native_compat_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-lane.ps1']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/android-prepush.py']), { ...none, android: true });
@@ -24,6 +28,13 @@ assert.deepEqual(classifyCiPaths(['scripts/dev.bat']), { ...none, android: true
assert.deepEqual(classifyCiPaths(['scripts/dev.sh']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['scripts/tests/android_prepush_test.py']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/android-on-demand.yml']), { ...none, android: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/approve-release-extensions.yml']), {
...none,
desktop: true,
plugin: true,
});
assert.deepEqual(classifyCiPaths(['.github/workflows/release-cli.yml']), { ...none, desktop: true });
assert.deepEqual(classifyCiPaths(['.github/workflows/release-plugin.yml']), { ...none, plugin: true });
assert.deepEqual(classifyCiPaths(['plugin/relay/server.py']), { ...none, plugin: true });
assert.deepEqual(classifyCiPaths(['plugin/dashboard/src/App.tsx']), { ...none, dashboard: true });
assert.deepEqual(classifyCiPaths(['user-docs/index.md']), { ...none, docs: true });
@@ -47,5 +58,73 @@ assert.deepEqual(classifyCiPaths(['.github/workflows/release-backmerge.yml']), {
contract: true,
docs: true,
});
assert.deepEqual(classifyCiPaths(['.github/workflows/approve-release-train.yml']), {
android: true,
desktop: true,
plugin: true,
dashboard: true,
contract: true,
docs: true,
});
const repoRoot = join(__dirname, '..', '..');
const approvalWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-extensions.yml'),
'utf8',
);
const cliReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-cli.yml'),
'utf8',
);
const pluginReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-plugin.yml'),
'utf8',
);
const desktopCiWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'ci-desktop.yml'),
'utf8',
);
const androidPreflightWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'play-preflight-android.yml'),
'utf8',
);
const androidApprovalWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-android.yml'),
'utf8',
);
const androidReleaseWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'release-android.yml'),
'utf8',
);
const requiredChecksWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'ci-required.yml'),
'utf8',
);
const releaseTrainWorkflow = readFileSync(
join(repoRoot, '.github', 'workflows', 'approve-release-train.yml'),
'utf8',
);
assert.match(approvalWorkflow, /permissions:\r?\n contents: read/);
assert.match(
approvalWorkflow,
/approve:[\s\S]*?permissions:\r?\n actions: write\r?\n contents: write/,
);
assert.match(
approvalWorkflow,
/ref: \$\{\{ contains\(inputs\.version, '-'\) && 'dev' \|\| 'main' \}\}/,
);
assert.match(cliReleaseWorkflow, /workflow_dispatch:[\s\S]*?Approved CLI\+UI version/);
assert.match(cliReleaseWorkflow, /name: Restore exact-source tray build cache[\s\S]*?actions\/cache@v5/);
assert.match(desktopCiWorkflow, /name: Restore exact-source tray build cache[\s\S]*?actions\/cache@v5/);
assert.match(pluginReleaseWorkflow, /workflow_dispatch:[\s\S]*?Approved Plugin version/);
assert.match(androidPreflightWorkflow, /Package immutable preflight artifacts/);
assert.match(androidApprovalWorkflow, /Android public approval accepts stable SemVer only/);
assert.match(androidReleaseWorkflow, /Download exact stable preflight artifacts/);
assert.match(androidReleaseWorkflow, /artifact-ids: \$\{\{ needs\.validate\.outputs\.preflight_artifact_id \}\}/);
assert.match(requiredChecksWorkflow, /name: Reuse exact-tree required checks/);
assert.match(requiredChecksWorkflow, /name: required-checks-\$\{\{ needs\.changes\.outputs\.tree \}\}/);
assert.match(releaseTrainWorkflow, /name: Hermes-Relay Coordinated Release Approval/);
assert.match(releaseTrainWorkflow, /Coordinated Android approval is stable-only/);
console.log('CI path classification tests passed.');
+16 -4
View File
@@ -40,6 +40,10 @@ jobs:
echo "::error::Hermes-Relay Android Release Approval must run from main, not $GITHUB_REF"
exit 1
fi
if [[ ! "$REQUESTED_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+$ ]]; then
echo "::error::Android public approval accepts stable SemVer only: $REQUESTED_VERSION"
exit 1
fi
TOML_VERSION=$(grep -oP 'appVersionName\s*=\s*"\K[^"]+' gradle/libs.versions.toml)
if [ "$REQUESTED_VERSION" != "$TOML_VERSION" ]; then
echo "::error::Requested version $REQUESTED_VERSION does not match appVersionName $TOML_VERSION"
@@ -56,13 +60,21 @@ jobs:
RELEASE_TREE: ${{ steps.metadata.outputs.tree }}
run: |
ARTIFACT_NAME="play-preflight-${VERSION}-${RELEASE_TREE}"
COUNT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | length')
if [ "$COUNT" -lt 1 ]; then
ARTIFACT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
RUN_ID=$(jq -r '.workflow_run.id // empty' <<<"$ARTIFACT")
if [ -z "$RUN_ID" ]; then
echo "::error::No successful Play preflight found for version $VERSION with tree $RELEASE_TREE"
exit 1
fi
echo "Verified Play preflight proof: $ARTIFACT_NAME"
RUN=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${RUN_ID}")
CONCLUSION=$(jq -r '.conclusion' <<<"$RUN")
WORKFLOW_PATH=$(jq -r '.path' <<<"$RUN")
if [ "$WORKFLOW_PATH" != ".github/workflows/play-preflight-android.yml" ] || [ "$CONCLUSION" != "success" ]; then
echo "::error::Preflight artifact came from ${WORKFLOW_PATH} with conclusion ${CONCLUSION}"
exit 1
fi
echo "Verified immutable Play preflight artifacts: $ARTIFACT_NAME (run $RUN_ID)"
- name: Ensure release tag does not already exist
env:
@@ -0,0 +1,158 @@
name: Hermes-Relay Plugin and CLI+UI Release Approval
on:
workflow_dispatch:
inputs:
surface:
description: "Release surface"
required: true
type: choice
options:
- plugin
- desktop
version:
description: "Approved version (for example 1.11.2 or 0.4.0-beta.7)"
required: true
type: string
permissions:
contents: read
concurrency:
group: approve-${{ inputs.surface }}-release
cancel-in-progress: false
jobs:
validate:
name: Validate release source and metadata
runs-on: ubuntu-latest
outputs:
source_branch: ${{ steps.metadata.outputs.source_branch }}
source_sha: ${{ steps.metadata.outputs.source_sha }}
tag: ${{ steps.metadata.outputs.tag }}
workflow: ${{ steps.metadata.outputs.workflow }}
steps:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ contains(inputs.version, '-') && 'dev' || 'main' }}
- name: Validate approval request
id: metadata
env:
REQUESTED_SURFACE: ${{ inputs.surface }}
REQUESTED_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
if [[ ! "$REQUESTED_VERSION" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::Version must be SemVer with an optional prerelease suffix: $REQUESTED_VERSION"
exit 1
fi
if [[ "$REQUESTED_VERSION" == *-* ]]; then
source_branch="dev"
else
source_branch="main"
fi
if [ "$GITHUB_REF" != "refs/heads/main" ]; then
echo "::error::Release approval must run from the trusted main workflow definition, not $GITHUB_REF"
exit 1
fi
git fetch origin "$source_branch" --no-tags
source_sha="$(git rev-parse HEAD)"
expected_sha="$(git rev-parse FETCH_HEAD)"
if [ "$source_sha" != "$expected_sha" ]; then
echo "::error::Checked out $source_sha, but origin/$source_branch is $expected_sha"
exit 1
fi
case "$REQUESTED_SURFACE" in
plugin)
tag="server-v${REQUESTED_VERSION}"
workflow="release-plugin.yml"
python3 scripts/check-plugin-version-sync.py --expect "$REQUESTED_VERSION"
if ! grep -Eq "^## \[Plugin ${REQUESTED_VERSION}\]" CHANGELOG.md; then
echo "::error::CHANGELOG.md has no Plugin release heading for $REQUESTED_VERSION"
exit 1
fi
;;
desktop)
tag="desktop-v${REQUESTED_VERSION}"
workflow="release-cli.yml"
node desktop/scripts/cli-version-sync.mjs --expect "$REQUESTED_VERSION"
if ! grep -Fq "## [$REQUESTED_VERSION]" CHANGELOG.md; then
echo "::error::CHANGELOG.md has no CLI+UI release heading for $REQUESTED_VERSION"
exit 1
fi
;;
*)
echo "::error::Unsupported release surface: $REQUESTED_SURFACE"
exit 1
;;
esac
echo "tag=$tag" >> "$GITHUB_OUTPUT"
echo "workflow=$workflow" >> "$GITHUB_OUTPUT"
echo "source_branch=$source_branch" >> "$GITHUB_OUTPUT"
echo "source_sha=$source_sha" >> "$GITHUB_OUTPUT"
approve:
name: Create release tag and start publication
needs: validate
permissions:
actions: write
contents: write
runs-on: ubuntu-latest
steps:
- name: Verify release source has not moved
env:
GH_TOKEN: ${{ github.token }}
SOURCE_BRANCH: ${{ needs.validate.outputs.source_branch }}
SOURCE_SHA: ${{ needs.validate.outputs.source_sha }}
run: |
current_sha=$(gh api "/repos/${GITHUB_REPOSITORY}/git/ref/heads/${SOURCE_BRANCH}" --jq .object.sha)
if [ "$current_sha" != "$SOURCE_SHA" ]; then
echo "::error::$SOURCE_BRANCH moved from $SOURCE_SHA to $current_sha; run approval again"
exit 1
fi
- name: Ensure release tag does not already exist
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.validate.outputs.tag }}
run: |
if gh api "/repos/${GITHUB_REPOSITORY}/git/ref/tags/${RELEASE_TAG}" >/dev/null 2>&1; then
echo "::error::Tag $RELEASE_TAG already exists"
exit 1
fi
- name: Create approved release tag
env:
GH_TOKEN: ${{ github.token }}
RELEASE_TAG: ${{ needs.validate.outputs.tag }}
RELEASE_SHA: ${{ needs.validate.outputs.source_sha }}
run: |
gh api --method POST "/repos/${GITHUB_REPOSITORY}/git/refs" \
-f ref="refs/tags/${RELEASE_TAG}" \
-f sha="$RELEASE_SHA"
- name: Start the immutable tag release workflow
env:
GH_TOKEN: ${{ github.token }}
RELEASE_WORKFLOW: ${{ needs.validate.outputs.workflow }}
RELEASE_VERSION: ${{ inputs.version }}
run: |
# A tag created by GITHUB_TOKEN does not recursively start workflows.
# Dispatch the trusted definition from main; release jobs check out
# and validate the immutable tag created above.
gh workflow run "$RELEASE_WORKFLOW" \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f version="$RELEASE_VERSION"
- name: Approval summary
run: |
echo "## Release approved" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "Created \`${{ needs.validate.outputs.tag }}\` from \`${{ needs.validate.outputs.source_branch }}\` at \`${{ needs.validate.outputs.source_sha }}\`." >> "$GITHUB_STEP_SUMMARY"
echo "Dispatched \`${{ needs.validate.outputs.workflow }}\` to validate and publish that immutable tag." >> "$GITHUB_STEP_SUMMARY"
+120
View File
@@ -0,0 +1,120 @@
name: Hermes-Relay Coordinated Release Approval
on:
workflow_dispatch:
inputs:
android:
description: "Approve Hermes-Relay Android"
required: true
default: false
type: boolean
android_version:
description: "Android version when selected"
required: false
type: string
plugin:
description: "Approve Hermes-Relay Plugin"
required: true
default: false
type: boolean
plugin_version:
description: "Plugin version when selected"
required: false
type: string
desktop:
description: "Approve Hermes-Relay CLI+UI"
required: true
default: false
type: boolean
desktop_version:
description: "CLI+UI version when selected"
required: false
type: string
permissions:
actions: write
contents: read
concurrency:
group: approve-coordinated-release
cancel-in-progress: false
jobs:
validate:
name: Validate selected release surfaces
runs-on: ubuntu-latest
steps:
- name: Require versions for every selected surface
env:
ANDROID: ${{ inputs.android }}
ANDROID_VERSION: ${{ inputs.android_version }}
PLUGIN: ${{ inputs.plugin }}
PLUGIN_VERSION: ${{ inputs.plugin_version }}
DESKTOP: ${{ inputs.desktop }}
DESKTOP_VERSION: ${{ inputs.desktop_version }}
run: |
set -euo pipefail
if [ "$ANDROID" != "true" ] && [ "$PLUGIN" != "true" ] && [ "$DESKTOP" != "true" ]; then
echo "::error::Select at least one release surface"
exit 1
fi
for pair in \
"$ANDROID:$ANDROID_VERSION:Android" \
"$PLUGIN:$PLUGIN_VERSION:Plugin" \
"$DESKTOP:$DESKTOP_VERSION:CLI+UI"; do
IFS=: read -r selected version label <<<"$pair"
if [ "$selected" = "true" ] && [[ ! "$version" =~ ^[0-9]+\.[0-9]+\.[0-9]+(-[0-9A-Za-z.-]+)?$ ]]; then
echo "::error::$label requires a valid SemVer version"
exit 1
fi
done
if [ "$ANDROID" = "true" ] && [[ "$ANDROID_VERSION" == *-* ]]; then
echo "::error::Coordinated Android approval is stable-only; use a dev candidate tag for prereleases"
exit 1
fi
android:
name: Approve Hermes-Relay Android
needs: validate
if: inputs.android
runs-on: ubuntu-latest
steps:
- name: Dispatch Android approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.android_version }}
run: gh workflow run approve-release-android.yml --repo "$GITHUB_REPOSITORY" --ref main -f version="$VERSION"
plugin:
name: Approve Hermes-Relay Plugin
needs: validate
if: inputs.plugin
runs-on: ubuntu-latest
steps:
- name: Dispatch Plugin approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.plugin_version }}
run: |
gh workflow run approve-release-extensions.yml \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f surface=plugin \
-f version="$VERSION"
desktop:
name: Approve Hermes-Relay CLI+UI
needs: validate
if: inputs.desktop
runs-on: ubuntu-latest
steps:
- name: Dispatch CLI+UI approval
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ inputs.desktop_version }}
run: |
gh workflow run approve-release-extensions.yml \
--repo "$GITHUB_REPOSITORY" \
--ref main \
-f surface=desktop \
-f version="$VERSION"
-4
View File
@@ -20,10 +20,6 @@ on:
branches: [main, dev]
paths:
- "app/**"
- "relay-core/**"
- "relay-ui/**"
- "ui-preview/**"
- "quest/**"
- "gradle/**"
- "build.gradle.kts"
- "settings.gradle.kts"
+12
View File
@@ -107,6 +107,18 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Restore exact-source tray build cache
uses: actions/cache@v5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
desktop/tray/target
key: ${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-${{ hashFiles('desktop/tray/Cargo.toml', 'desktop/tray/build.rs', 'desktop/tray/src/**/*.rs') }}
restore-keys: |
${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-
- name: Install deps
run: npm ci && npm --prefix tray ci
+138 -16
View File
@@ -34,6 +34,7 @@ on:
- all-final
permissions:
actions: read
contents: read
pull-requests: read
@@ -52,6 +53,8 @@ jobs:
dashboard: ${{ steps.filter.outputs.dashboard }}
contract: ${{ steps.filter.outputs.contract }}
docs: ${{ steps.filter.outputs.docs }}
release_pr: ${{ steps.release.outputs.release_pr }}
tree: ${{ steps.tree.outputs.tree }}
steps:
- name: Checkout pull request merge
if: github.event_name == 'pull_request'
@@ -69,6 +72,26 @@ jobs:
- name: Test path classifier
run: node .github/scripts/classify-ci-paths.test.cjs
- name: Record checked tree
id: tree
run: echo "tree=$(git rev-parse 'HEAD^{tree}')" >> "$GITHUB_OUTPUT"
- name: Detect canonical release promotion
id: release
env:
BASE_REF: ${{ github.base_ref }}
HEAD_REF: ${{ github.head_ref }}
HEAD_REPOSITORY: ${{ github.event.pull_request.head.repo.full_name }}
run: |
if [ "$GITHUB_EVENT_NAME" = "pull_request" ] && \
[ "$BASE_REF" = "main" ] && \
[ "$HEAD_REF" = "dev" ] && \
[ "$HEAD_REPOSITORY" = "$GITHUB_REPOSITORY" ]; then
echo "release_pr=true" >> "$GITHUB_OUTPUT"
else
echo "release_pr=false" >> "$GITHUB_OUTPUT"
fi
- name: Classify changed files
id: filter
uses: actions/github-script@v8
@@ -123,43 +146,117 @@ jobs:
core.notice(`Changed paths: ${paths.join(', ')}`);
core.notice(`Selected checks: ${Object.entries(outputs).filter(([, value]) => value).map(([key]) => key).join(', ') || 'none'}`);
android:
release-proof:
name: Reuse exact-tree required checks
needs: changes
if: needs.changes.outputs.android == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
if: needs.changes.outputs.release_pr == 'true'
runs-on: ubuntu-latest
outputs:
reuse: ${{ steps.proof.outputs.reuse }}
artifact_id: ${{ steps.proof.outputs.artifact_id }}
run_id: ${{ steps.proof.outputs.run_id }}
tree: ${{ steps.proof.outputs.tree }}
steps:
- name: Checkout simulated release merge
uses: actions/checkout@v7
with:
fetch-depth: 0
- name: Locate exact-tree proof
id: proof
env:
GH_TOKEN: ${{ github.token }}
DEV_SHA: ${{ github.event.pull_request.head.sha }}
run: |
set -euo pipefail
merge_tree=$(git rev-parse 'HEAD^{tree}')
dev_tree=$(git rev-parse "${DEV_SHA}^{tree}")
echo "reuse=false" >> "$GITHUB_OUTPUT"
echo "tree=$dev_tree" >> "$GITHUB_OUTPUT"
if [ "$merge_tree" != "$dev_tree" ]; then
echo "Release merge changes the dev tree ($dev_tree -> $merge_tree); running full CI."
exit 0
fi
artifact_name="required-checks-${dev_tree}"
artifact=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${artifact_name}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
artifact_id=$(jq -r '.id // empty' <<<"$artifact")
run_id=$(jq -r '.workflow_run.id // empty' <<<"$artifact")
if [ -z "$artifact_id" ] || [ -z "$run_id" ]; then
echo "No reusable proof exists for tree $dev_tree; running full CI."
exit 0
fi
run=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${run_id}")
conclusion=$(jq -r '.conclusion' <<<"$run")
workflow_path=$(jq -r '.path' <<<"$run")
if [ "$workflow_path" != ".github/workflows/ci-required.yml" ] || [ "$conclusion" != "success" ]; then
echo "::error::Required-check proof came from ${workflow_path} with conclusion ${conclusion}"
exit 1
fi
echo "artifact_id=$artifact_id" >> "$GITHUB_OUTPUT"
echo "run_id=$run_id" >> "$GITHUB_OUTPUT"
echo "reuse=true" >> "$GITHUB_OUTPUT"
- name: Download exact-tree proof
if: steps.proof.outputs.reuse == 'true'
uses: actions/download-artifact@v8
with:
artifact-ids: ${{ steps.proof.outputs.artifact_id }}
github-token: ${{ github.token }}
repository: ${{ github.repository }}
run-id: ${{ steps.proof.outputs.run_id }}
path: required-check-proof
- name: Verify exact-tree proof
if: steps.proof.outputs.reuse == 'true'
env:
EXPECTED_TREE: ${{ steps.proof.outputs.tree }}
run: |
jq -e \
--arg repository "$GITHUB_REPOSITORY" \
--arg tree "$EXPECTED_TREE" \
'.schemaVersion == 1 and .repository == $repository and .tree == $tree' \
required-check-proof/required-checks.json
android:
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.android == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-android.yml
android_on_demand:
needs: changes
if: github.event_name == 'workflow_dispatch' && inputs.android_preset != 'auto'
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.release-proof.outputs.reuse != 'true' && github.event_name == 'workflow_dispatch' && inputs.android_preset != 'auto' }}
uses: ./.github/workflows/android-on-demand.yml
with:
head_sha: ${{ inputs.head_sha }}
preset: ${{ inputs.android_preset }}
desktop:
needs: changes
if: needs.changes.outputs.desktop == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.desktop == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-desktop.yml
plugin:
needs: changes
if: needs.changes.outputs.plugin == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.plugin == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-plugin.yml
dashboard:
needs: changes
if: needs.changes.outputs.dashboard == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.dashboard == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-dashboard.yml
contract:
needs: changes
if: needs.changes.outputs.contract == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.contract == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
uses: ./.github/workflows/ci-contract.yml
docs:
name: Build public docs
needs: changes
if: needs.changes.outputs.docs == 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto')
needs: [changes, release-proof]
if: ${{ always() && needs.changes.result == 'success' && needs.changes.outputs.docs == 'true' && needs.release-proof.outputs.reuse != 'true' && (github.event_name != 'workflow_dispatch' || inputs.android_preset == 'auto') }}
runs-on: ubuntu-latest
defaults:
run:
@@ -181,10 +278,12 @@ jobs:
guard:
name: Required checks
if: always()
needs: [changes, android, android_on_demand, desktop, plugin, dashboard, contract, docs]
needs: [changes, release-proof, android, android_on_demand, desktop, plugin, dashboard, contract, docs]
runs-on: ubuntu-latest
env:
CHANGES_RESULT: ${{ needs.changes.result }}
RELEASE_PROOF_RESULT: ${{ needs.release-proof.result }}
REUSED_REQUIRED_CHECKS: ${{ needs.release-proof.outputs.reuse }}
ANDROID_RESULT: ${{ needs.android.result }}
ANDROID_ON_DEMAND_RESULT: ${{ needs.android_on_demand.result }}
DESKTOP_RESULT: ${{ needs.desktop.result }}
@@ -197,7 +296,7 @@ jobs:
shell: bash
run: |
failed=0
for check in CHANGES ANDROID ANDROID_ON_DEMAND DESKTOP PLUGIN DASHBOARD CONTRACT DOCS; do
for check in CHANGES RELEASE_PROOF ANDROID ANDROID_ON_DEMAND DESKTOP PLUGIN DASHBOARD CONTRACT DOCS; do
result_var="${check}_RESULT"
result="${!result_var}"
echo "$check: $result"
@@ -207,3 +306,26 @@ jobs:
esac
done
exit "$failed"
- name: Write exact-tree proof
if: ${{ needs.release-proof.outputs.reuse != 'true' }}
env:
CHECKED_TREE: ${{ needs.changes.outputs.tree }}
run: |
mkdir -p required-check-proof
jq -n \
--arg repository "$GITHUB_REPOSITORY" \
--arg tree "$CHECKED_TREE" \
--arg commit "$GITHUB_SHA" \
--arg run_id "$GITHUB_RUN_ID" \
'{schemaVersion: 1, repository: $repository, tree: $tree, commit: $commit, runId: $run_id}' \
> required-check-proof/required-checks.json
- name: Upload exact-tree proof
if: ${{ needs.release-proof.outputs.reuse != 'true' }}
uses: actions/upload-artifact@v7
with:
name: required-checks-${{ needs.changes.outputs.tree }}
path: required-check-proof/required-checks.json
if-no-files-found: error
retention-days: 30
+32 -20
View File
@@ -2,10 +2,11 @@
#
# Run manually from the final dev or untagged main tree before creating
# android-v*. The job
# builds the same signed release artifacts, scans final DEX, and uploads the
# Google Play bundle as a production DRAFT. A successful upload is the automated
# Play gate while no public GitHub Release or sideload APK exists. Console-only
# pre-review and pre-launch reports are informational and do not block release.
# builds the signed release artifacts once, scans the final packages, and uploads
# the Google Play bundle as a production DRAFT. The exact signed APK/AAB,
# mappings, manifest, and checksums remain private Actions artifacts until
# approval publishes those same bytes. Console-only pre-review and pre-launch
# reports are informational and do not block release.
name: Hermes-Relay Android Play Preflight
@@ -98,7 +99,12 @@ jobs:
HERMES_KEYSTORE_PASSWORD: ${{ secrets.HERMES_KEYSTORE_PASSWORD }}
HERMES_KEY_ALIAS: ${{ secrets.HERMES_KEY_ALIAS }}
HERMES_KEY_PASSWORD: ${{ secrets.HERMES_KEY_PASSWORD }}
run: ./gradlew bundleRelease assembleRelease --console=plain
run: |
./gradlew \
:app:bundleGooglePlayRelease \
:app:assembleGooglePlayRelease \
:app:assembleSideloadRelease \
--console=plain
- name: Scan final release DEX
run: |
@@ -106,6 +112,12 @@ jobs:
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
- name: Verify packaged native compatibility
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
- name: Upload private production draft to Play
env:
PLAY_SERVICE_ACCOUNT_JSON: ${{ secrets.PLAY_SERVICE_ACCOUNT_JSON }}
@@ -121,27 +133,27 @@ jobs:
--resolution-strategy=ignore \
--release-name="Hermes-Relay Android v${{ steps.metadata.outputs.version }}"
- name: Record successful preflight for the exact commit
- name: Package immutable preflight artifacts
run: |
mkdir -p app/build/reports
cat > app/build/reports/play-preflight.json <<EOF
{
"version": "${{ steps.metadata.outputs.version }}",
"versionCode": "${{ steps.metadata.outputs.version_code }}",
"commit": "$GITHUB_SHA",
"tree": "${{ steps.metadata.outputs.tree }}",
"track": "production",
"status": "draft"
}
EOF
python3 scripts/android_release_artifacts.py package \
--version "${{ steps.metadata.outputs.version }}" \
--version-code "${{ steps.metadata.outputs.version_code }}" \
--commit "$GITHUB_SHA" \
--tree "${{ steps.metadata.outputs.tree }}" \
--sideload-apk app/build/outputs/apk/sideload/release/*.apk \
--google-play-aab app/build/outputs/bundle/googlePlayRelease/*.aab \
--sideload-mapping app/build/outputs/mapping/sideloadRelease/mapping.txt \
--google-play-mapping app/build/outputs/mapping/googlePlayRelease/mapping.txt \
--output app/build/preflight-artifacts
- name: Upload preflight proof
- name: Upload immutable preflight artifacts
uses: actions/upload-artifact@v7
with:
name: play-preflight-${{ steps.metadata.outputs.version }}-${{ steps.metadata.outputs.tree }}
path: app/build/reports/play-preflight.json
path: app/build/preflight-artifacts/*
if-no-files-found: error
retention-days: 30
compression-level: 0
- name: Preflight summary
run: |
@@ -152,4 +164,4 @@ jobs:
echo "- Release tree: \`${{ steps.metadata.outputs.tree }}\`" >> "$GITHUB_STEP_SUMMARY"
echo "- Play track/status: **Production draft**" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "The signed build, DEX scan, and Play draft upload passed. Ensure this exact release tree is on main, then run **Hermes-Relay Android Release Approval** from main. Console-only reports are informational and non-blocking." >> "$GITHUB_STEP_SUMMARY"
echo "The signed build, package scans, and Play draft upload passed. Approval will publish these exact private artifacts if the unchanged tree reaches main. Console-only reports are informational and non-blocking." >> "$GITHUB_STEP_SUMMARY"
+61 -57
View File
@@ -36,6 +36,9 @@ jobs:
version: ${{ steps.version.outputs.version }}
version_code: ${{ steps.version.outputs.version_code }}
prerelease: ${{ steps.version.outputs.prerelease }}
release_tree: ${{ steps.version.outputs.release_tree }}
preflight_artifact_id: ${{ steps.preflight.outputs.artifact_id }}
preflight_run_id: ${{ steps.preflight.outputs.run_id }}
steps:
- uses: actions/checkout@v7
with:
@@ -66,6 +69,7 @@ jobs:
echo "version=$REF_VERSION" >> "$GITHUB_OUTPUT"
echo "version_code=$VERSION_CODE" >> "$GITHUB_OUTPUT"
echo "prerelease=$PRERELEASE" >> "$GITHUB_OUTPUT"
echo "release_tree=$(git rev-parse 'HEAD^{tree}')" >> "$GITHUB_OUTPUT"
- name: Verify version sync
run: |
@@ -110,25 +114,38 @@ jobs:
fi
- name: Require successful Play preflight for this exact release tree
id: preflight
if: ${{ !contains(steps.version.outputs.version, '-') }}
env:
GH_TOKEN: ${{ github.token }}
VERSION: ${{ steps.version.outputs.version }}
run: |
RELEASE_TREE=$(git rev-parse 'HEAD^{tree}')
RELEASE_TREE="${{ steps.version.outputs.release_tree }}"
ARTIFACT_NAME="play-preflight-${VERSION}-${RELEASE_TREE}"
COUNT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | length')
if [ "$COUNT" -lt 1 ]; then
ARTIFACT=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/artifacts?name=${ARTIFACT_NAME}" \
--jq '[.artifacts[] | select(.expired == false)] | sort_by(.created_at) | last')
ARTIFACT_ID=$(jq -r '.id // empty' <<<"$ARTIFACT")
RUN_ID=$(jq -r '.workflow_run.id // empty' <<<"$ARTIFACT")
if [ -z "$ARTIFACT_ID" ] || [ -z "$RUN_ID" ]; then
echo "::error::No successful Play preflight found for version $VERSION with tree $RELEASE_TREE"
echo "Run Hermes-Relay Android Play Preflight from the final dev tree, merge that unchanged tree to main, then approve the release."
exit 1
fi
echo "Play preflight proof found: $ARTIFACT_NAME"
RUN=$(gh api "/repos/${GITHUB_REPOSITORY}/actions/runs/${RUN_ID}")
CONCLUSION=$(jq -r '.conclusion' <<<"$RUN")
WORKFLOW_PATH=$(jq -r '.path' <<<"$RUN")
if [ "$WORKFLOW_PATH" != ".github/workflows/play-preflight-android.yml" ] || [ "$CONCLUSION" != "success" ]; then
echo "::error::Preflight artifact came from ${WORKFLOW_PATH} with conclusion ${CONCLUSION}"
exit 1
fi
echo "artifact_id=$ARTIFACT_ID" >> "$GITHUB_OUTPUT"
echo "run_id=$RUN_ID" >> "$GITHUB_OUTPUT"
echo "Play preflight artifacts verified: $ARTIFACT_NAME (run $RUN_ID, artifact $ARTIFACT_ID)"
ci:
name: CI Checks
name: CI Checks (prerelease only)
needs: validate
if: ${{ needs.validate.outputs.prerelease == 'true' }}
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
@@ -168,6 +185,7 @@ jobs:
release:
name: Build & Publish Release
needs: [validate, ci]
if: ${{ always() && needs.validate.result == 'success' && (needs.ci.result == 'success' || needs.ci.result == 'skipped') }}
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
@@ -186,31 +204,33 @@ jobs:
with:
cache-read-only: false
- name: Decode release keystore
- name: Download exact stable preflight artifacts
if: ${{ needs.validate.outputs.prerelease != 'true' }}
uses: actions/download-artifact@v8
with:
artifact-ids: ${{ needs.validate.outputs.preflight_artifact_id }}
github-token: ${{ github.token }}
repository: ${{ github.repository }}
run-id: ${{ needs.validate.outputs.preflight_run_id }}
path: app/build/preflight-artifacts
- name: Verify exact stable preflight artifacts
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/android_release_artifacts.py verify \
--version "${{ needs.validate.outputs.version }}" \
--version-code "${{ needs.validate.outputs.version_code }}" \
--tree "${{ needs.validate.outputs.release_tree }}" \
--directory app/build/preflight-artifacts
- name: Decode release keystore for candidate build
env:
HERMES_KEYSTORE_BASE64: ${{ secrets.HERMES_KEYSTORE_BASE64 }}
if: env.HERMES_KEYSTORE_BASE64 != ''
if: ${{ needs.validate.outputs.prerelease == 'true' && env.HERMES_KEYSTORE_BASE64 != '' }}
run: |
echo "$HERMES_KEYSTORE_BASE64" | base64 -d > "$RUNNER_TEMP/release.keystore"
echo "HERMES_KEYSTORE_PATH=$RUNNER_TEMP/release.keystore" >> "$GITHUB_ENV"
- name: Build stable release artifacts (APK + AAB)
if: ${{ needs.validate.outputs.prerelease != 'true' }}
env:
HERMES_KEYSTORE_PASSWORD: ${{ secrets.HERMES_KEYSTORE_PASSWORD }}
HERMES_KEY_ALIAS: ${{ secrets.HERMES_KEY_ALIAS }}
HERMES_KEY_PASSWORD: ${{ secrets.HERMES_KEY_PASSWORD }}
# `assembleRelease` and `bundleRelease` are flavor-wide task aliases
# (added by `flavorDimensions += "track"` in app/build.gradle.kts), so
# this one line builds ALL four artifacts at once. Filenames come from
# `archivesName` (set in app/build.gradle.kts) which injects the app
# version, so `<version>` below is `libs.versions.appVersionName`:
# app/build/outputs/apk/googlePlay/release/hermes-relay-<version>-googlePlay-release.apk
# app/build/outputs/apk/sideload/release/hermes-relay-<version>-sideload-release.apk
# app/build/outputs/bundle/googlePlayRelease/hermes-relay-<version>-googlePlay-release.aab
# app/build/outputs/bundle/sideloadRelease/hermes-relay-<version>-sideload-release.aab
run: ./gradlew bundleRelease assembleRelease
- name: Build side-by-side release candidate APK
if: ${{ needs.validate.outputs.prerelease == 'true' }}
env:
@@ -234,10 +254,10 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
uses: actions/upload-artifact@v7
with:
name: android-r8-mappings-${{ needs.validate.outputs.version }}-${{ github.sha }}
name: android-r8-mappings-${{ needs.validate.outputs.version }}-${{ needs.validate.outputs.release_tree }}
path: |
app/build/outputs/mapping/googlePlayRelease/mapping.txt
app/build/outputs/mapping/sideloadRelease/mapping.txt
app/build/preflight-artifacts/mapping-googlePlayRelease.txt
app/build/preflight-artifacts/mapping-sideloadRelease.txt
if-no-files-found: error
retention-days: 90
@@ -254,8 +274,7 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/check-android-collection-apis.py \
--apk app/build/outputs/apk/googlePlay/release/*.apk \
--apk app/build/outputs/apk/sideload/release/*.apk
--apk app/build/preflight-artifacts/*-sideload-release.apk
- name: Scan candidate DEX for unsupported collection APIs
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -267,8 +286,7 @@ jobs:
if: ${{ needs.validate.outputs.prerelease != 'true' }}
run: |
python3 scripts/check-android-native-compat.py \
app/build/outputs/apk/googlePlay/release/*.apk \
app/build/outputs/apk/sideload/release/*.apk
app/build/preflight-artifacts/*-sideload-release.apk
- name: Verify candidate packaged ONNX Runtime compatibility
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -278,23 +296,10 @@ jobs:
- name: List produced artifacts (debug aid)
run: |
echo "=== APK outputs ==="
echo "=== Reused stable artifacts ==="
find app/build/preflight-artifacts -maxdepth 1 -type f -print 2>/dev/null || true
echo "=== Candidate APK outputs ==="
find app/build/outputs/apk -name '*.apk' -print 2>/dev/null || true
echo "=== AAB outputs ==="
find app/build/outputs/bundle -name '*.aab' -print 2>/dev/null || true
- name: Generate stable checksums
if: ${{ needs.validate.outputs.prerelease != 'true' }}
# Flavor dimension adds an extra path segment to the AGP output layout.
# APKs live under `apk/<flavor>/release/`, AABs under `bundle/<flavor>Release/`
# (note the concatenated camelCase — AGP path quirk, documented but
# different between APK and AAB). Checksums cover EXACTLY the files
# attached to the GitHub Release (see the 2-asset policy on the
# release step below) so SHA256SUMS.txt matches the assets 1:1.
run: |
cd app/build/outputs
sha256sum apk/sideload/release/*.apk bundle/googlePlayRelease/*.aab > SHA256SUMS.txt
cat SHA256SUMS.txt
- name: Generate candidate checksums
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -340,9 +345,9 @@ jobs:
# Deliberate 2-asset policy (#144): attach ONLY the installable
# sideload APK and Play AAB, plus checksums covering those files.
files: |
app/build/outputs/apk/sideload/release/*.apk
app/build/outputs/bundle/googlePlayRelease/*.aab
app/build/outputs/SHA256SUMS.txt
app/build/preflight-artifacts/*-sideload-release.apk
app/build/preflight-artifacts/*-googlePlay-release.aab
app/build/preflight-artifacts/SHA256SUMS.txt
- name: Create candidate GitHub prerelease
if: ${{ needs.validate.outputs.prerelease == 'true' }}
@@ -364,18 +369,17 @@ jobs:
run: |
echo "## Hermes-Relay Android v${{ needs.validate.outputs.version }}" >> "$GITHUB_STEP_SUMMARY"
echo "" >> "$GITHUB_STEP_SUMMARY"
if [ "$PRERELEASE" = "true" ] && [ -n "$HERMES_KEYSTORE_BASE64" ]; then
echo "✅ **Release-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
elif [ "$PRERELEASE" = "true" ]; then
echo "⚠️ **Debug-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
if [ "$PRERELEASE" != "true" ]; then
echo "✅ **Published the exact signed Play-preflight artifacts**" >> "$GITHUB_STEP_SUMMARY"
elif [ -n "$HERMES_KEYSTORE_BASE64" ]; then
echo "✅ **Signed with release keystore** — suitable for Play Store upload" >> "$GITHUB_STEP_SUMMARY"
echo "✅ **Release-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
else
echo "⚠️ **Debug-signed** (no \`HERMES_KEYSTORE_BASE64\` secret) — NOT suitable for Play Store. Add the secret in repo settings to enable release signing." >> "$GITHUB_STEP_SUMMARY"
echo "⚠️ **Debug-signed HR Candidate app** — separate package ID; never uploaded to Play" >> "$GITHUB_STEP_SUMMARY"
fi
echo "" >> "$GITHUB_STEP_SUMMARY"
echo "### Artifacts" >> "$GITHUB_STEP_SUMMARY"
echo '```' >> "$GITHUB_STEP_SUMMARY"
find app/build/preflight-artifacts -maxdepth 1 -type f -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
find app/build/outputs/apk -name '*.apk' -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
find app/build/outputs/bundle -name '*.aab' -exec ls -la {} + >> "$GITHUB_STEP_SUMMARY" 2>/dev/null || true
echo '```' >> "$GITHUB_STEP_SUMMARY"
+49 -15
View File
@@ -3,6 +3,12 @@ name: Hermes-Relay CLI+UI Release
on:
push:
tags: ['desktop-v*']
workflow_dispatch:
inputs:
version:
description: "Approved CLI+UI version"
required: true
type: string
permissions:
contents: write
@@ -20,6 +26,7 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js
uses: actions/setup-node@v7
@@ -34,10 +41,16 @@ jobs:
- name: Extract and validate tag version
id: version
shell: bash
env:
DISPATCHED_VERSION: ${{ inputs.version }}
run: |
set -euo pipefail
version="${GITHUB_REF_NAME#desktop-v}"
if [[ -z "$version" || "$version" == "$GITHUB_REF_NAME" ]]; then
if [ -n "$DISPATCHED_VERSION" ]; then
version="$DISPATCHED_VERSION"
else
version="${GITHUB_REF_NAME#desktop-v}"
fi
if [ -z "$version" ] || { [ -z "$DISPATCHED_VERSION" ] && [ "$version" = "$GITHUB_REF_NAME" ]; }; then
echo "Expected a desktop-v* tag, got $GITHUB_REF_NAME" >&2
exit 1
fi
@@ -51,11 +64,12 @@ jobs:
- name: Verify tag belongs to the correct integration branch
shell: bash
working-directory: .
env:
TAG_VERSION: ${{ steps.version.outputs.version }}
run: |
set -euo pipefail
version="${GITHUB_REF_NAME#desktop-v}"
tag_commit="$(git rev-parse "${GITHUB_REF_NAME}^{commit}")"
if [[ "$version" == *-* ]]; then
tag_commit="$(git rev-parse HEAD)"
if [[ "$TAG_VERSION" == *-* ]]; then
git fetch origin dev --no-tags
if ! git merge-base --is-ancestor "$tag_commit" origin/dev; then
echo "CLI+UI prereleases must be tagged from dev; $tag_commit is not in origin/dev" >&2
@@ -78,6 +92,8 @@ jobs:
working-directory: desktop
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js (for npm ci + tsc)
uses: actions/setup-node@v7
@@ -271,6 +287,8 @@ jobs:
working-directory: desktop
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- name: Setup Node.js
uses: actions/setup-node@v7
@@ -289,6 +307,18 @@ jobs:
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
- name: Restore exact-source tray build cache
uses: actions/cache@v5
with:
path: |
~/.cargo/registry/index
~/.cargo/registry/cache
~/.cargo/git/db
desktop/tray/target
key: ${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-${{ hashFiles('desktop/tray/Cargo.toml', 'desktop/tray/build.rs', 'desktop/tray/src/**/*.rs') }}
restore-keys: |
${{ runner.os }}-tray-rust-${{ hashFiles('desktop/tray/Cargo.lock') }}-
- name: Install deps
run: npm ci && npm --prefix tray ci
@@ -411,6 +441,11 @@ jobs:
if ($versionOutput -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "installed CLI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$versionOutput'"
}
$tray = Join-Path $installDir 'hermes-relay-tray.exe'
$trayVersion = (Get-Item -LiteralPath $tray).VersionInfo.ProductVersion
if ($trayVersion -ne $env:EXPECTED_DESKTOP_VERSION) {
throw "installed UI version mismatch: expected $env:EXPECTED_DESKTOP_VERSION, got '$trayVersion'"
}
$helpOutput = (& $cli --help | Out-String)
if ($LASTEXITCODE -ne 0 -or $helpOutput -notmatch 'Usage:') {
throw 'installed CLI --help smoke failed'
@@ -451,7 +486,7 @@ jobs:
throw "installer lifecycle changed the pre-existing tray startup preference"
}
Write-Host "packaged installer lifecycle smoke OK version=$versionOutput install=$installDir"
Write-Host "packaged installer lifecycle smoke OK cli=$versionOutput ui=$trayVersion install=$installDir"
} finally {
Get-Process -Name 'hermes-relay-tray' -ErrorAction SilentlyContinue |
Stop-Process -Force -ErrorAction SilentlyContinue
@@ -483,6 +518,7 @@ jobs:
name: Publish GitHub Release
runs-on: ubuntu-latest
needs:
- validate-release
- build-cli-binaries
- smoke-windows-cli-release-asset
- smoke-macos-cli-release-asset
@@ -492,10 +528,8 @@ jobs:
# Needed so CLI_RELEASE_NOTES.md is available to render into the release body
# (the other publish-release steps only consume downloaded build artifacts).
- uses: actions/checkout@v7
- name: Extract CLI+UI version
id: version
run: echo "version=${GITHUB_REF_NAME#desktop-v}" >> "$GITHUB_OUTPUT"
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('desktop-v{0}', inputs.version) || github.ref }}
- uses: actions/download-artifact@v8
with:
@@ -515,8 +549,8 @@ jobs:
# (desktop-v0.3.0) so install/pin commands stay accurate without manual edits.
- name: Render release notes
env:
VERSION: ${{ steps.version.outputs.version }}
TAG: ${{ github.ref_name }}
VERSION: ${{ needs.validate-release.outputs.version }}
TAG: desktop-v${{ needs.validate-release.outputs.version }}
run: |
sed -e "s/__VERSION__/${VERSION}/g" -e "s/__TAG__/${TAG}/g" \
CLI_RELEASE_NOTES.md > cli_release_notes_rendered.md
@@ -525,10 +559,10 @@ jobs:
- name: Publish GitHub Release
uses: softprops/action-gh-release@v3
with:
name: Hermes-Relay CLI+UI v${{ steps.version.outputs.version }}
tag_name: ${{ github.ref_name }}
name: Hermes-Relay CLI+UI v${{ needs.validate-release.outputs.version }}
tag_name: desktop-v${{ needs.validate-release.outputs.version }}
draft: false
prerelease: ${{ contains(steps.version.outputs.version, 'alpha') || contains(steps.version.outputs.version, 'beta') || contains(steps.version.outputs.version, 'rc') }}
prerelease: ${{ contains(needs.validate-release.outputs.version, '-') }}
fail_on_unmatched_files: true
body_path: cli_release_notes_rendered.md
files: |
+20 -1
View File
@@ -4,6 +4,12 @@ on:
push:
tags:
- "server-v*"
workflow_dispatch:
inputs:
version:
description: "Approved Plugin version"
required: true
type: string
permissions:
contents: write
@@ -19,10 +25,19 @@ jobs:
- uses: actions/checkout@v7
with:
fetch-depth: 0
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Extract version from tag
id: version
run: echo "version=${GITHUB_REF#refs/tags/server-v}" >> "$GITHUB_OUTPUT"
env:
DISPATCHED_VERSION: ${{ inputs.version }}
run: |
if [ -n "$DISPATCHED_VERSION" ]; then
version="$DISPATCHED_VERSION"
else
version="${GITHUB_REF#refs/tags/server-v}"
fi
echo "version=$version" >> "$GITHUB_OUTPUT"
- name: Verify Plugin version sync and changelog
run: |
@@ -61,6 +76,8 @@ jobs:
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Set up Python 3.11
uses: actions/setup-python@v7
@@ -99,6 +116,8 @@ jobs:
timeout-minutes: 15
steps:
- uses: actions/checkout@v7
with:
ref: ${{ github.event_name == 'workflow_dispatch' && format('server-v{0}', inputs.version) || github.ref }}
- name: Set up Python 3.11
uses: actions/setup-python@v7
+1 -4
View File
@@ -24,10 +24,7 @@ Thumbs.db
local.properties
/build/
/app/build/
/relay-core/build/
/relay-ui/build/
/ui-preview/build/
/quest/build/
/experiments/quest/**/build/
/app/release/
*.apk
*.aab
+1 -1
View File
@@ -17,7 +17,7 @@ contract here and in `RELEASE.md`.
- Android local/cloud verification → **[docs/android-build-lane.md](docs/android-build-lane.md)**
- Android emulator lanes → **[docs/android-emulator-testing.md](docs/android-emulator-testing.md)** — suggest the smallest relevant API 36 lanes; never run the full matrix automatically
- `android_*` toolset + MCP → **[docs/mcp-tooling.md](docs/mcp-tooling.md)**
- Follow-ups / deferred work / known gaps → **[TODO.md](TODO.md)** (the single home for "what's next" — never DEVLOG, never scattered code comments)
- Follow-ups / deferred work / known gaps → **[docs/project/TODO.md](docs/project/TODO.md)** (the single home for "what's next" — never DEVLOG, never scattered code comments)
## Branch contract
+19 -2
View File
@@ -6,6 +6,23 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
### Changed
- **Chat and Bot Chat expose a clear mid-response send choice.** A slim translucent tray slides up behind the composer for Correct now or Queue next without covering the input. Chat settings sets the default; the tray overrides it for one message. Stop pauses pending messages until Resume, and editing or removing a queued message keeps its successors deliverable.
- **Android Chat and Voice use tablet space intentionally.** Expanded layouts keep introductions, transcripts, composer controls, and status chrome on readable centered rails, while landscape Voice Focus separates identity controls from conversation activity without changing phone or portrait interaction behavior.
### Fixed
- **Android message delivery labels remain readable inside user bubbles.** Steering confirmations and other delivery states use the bubble's contrasting text color instead of disappearing into its accent background.
- **Android voice errors open in a readable dialog.** Long provider messages stay inside a scrollable, selectable detail area with separate Retry and Dismiss actions instead of overlapping Chat or Voice Focus controls.
- **Android attachment previews survive rotation and preserve video proportions.** Full-screen image, video, audio, PDF, text, and file previews remain open while the chat reflows, respect the device rotation preference, and render portrait or landscape video through Media3's fitted content surface instead of a fixed 16:9 box. (#483)
- **Android wake-word JNI configuration survives release shrinking.** R8 now preserves sherpa-onnx configuration class and field names that the native keyword spotter resolves at runtime. (#444)
- **Android streams Standard Hermes attachments into its on-disk media cache.** Automatic Dashboard downloads no longer preallocate and duplicate the full response body on the OkHttp dispatcher, while declared and observed size limits remain enforced. (#531)
- **Android bounds automatic session refresh and large chat allocations.** A foreground directory refresh can no longer sustain a request loop, routine history opens read one latest 500-row page, Dashboard JSON and in-memory media exports reject oversized bodies, Markdown renders through a bounded presentation window, and chat image previews downsample before allocating pixels.
- **Android keeps visible progress through image-generation tool gaps.** Gateway interim replies immediately hand off to a new in-chat working owner, so the standard working animation remains visible until media arrives even when upstream hides tool lifecycle events. Older Tool Search gateways that do expose a structured `tool_call` bridge are normalized to the effective image tool.
- **Android fresh Gateway chats wait for their upstream runtime before sending.** Android now consumes the lazy `session.create` readiness edge instead of racing the first prompt into compute-host ownership rejection. Genuine ownership refusals keep the exact holder-aware error and retryable local prompt instead of falling into unfinished-message history recovery.
- **Windows desktop updates keep the installed CLI and UI on one release.** `hermes-relay update` now detects a colocated management UI, reports both installed versions, and uses the verified bundle installer to replace and restart the affected surfaces together. Explicit CLI-only installations retain the standalone binary updater.
## [Android 1.15.0] - 2026-08-31
### Changed
@@ -1271,7 +1288,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Voice-exit chime firing on every Add-connection tap.** `ConnectionSwitchCoordinator.switchConnection` fires the `voiceStopCallback` unconditionally at step 3 (correct for connection-to-connection switches while voice is active), but `beginAddConnection` also routes through `switchConnection` to bind the placeholder Connection's auth store before the pair wizard runs — and `VoiceViewModel.exitVoiceMode()` was playing `sfxPlayer.playExit()` regardless of whether voice mode was actually on. Logcat confirmed the chime on every Add-connection FAB tap. Fix adds an idempotence guard at the top of `exitVoiceMode()`: early-return when `_uiState.value.voiceMode` is already false. Teardown is still safe to skip because every inner statement is null-guarded + try/catch-wrapped and would be a no-op on an already-stopped voice session; the only meaningful line is the `playExit()` SFX, which is what we're silencing.
- **500 ms freeze on every Add-connection tap.** `ConnectionSwitchCoordinator.switchConnection` runs a `withTimeoutOrNull(AUTH_HYDRATE_TIMEOUT_MS = 500L)` block at step 10 to wait for the freshly-bound `AuthManager` to flip `AuthState` from `Loading` to `Paired`. The comment acknowledged Add-connection is the common path and the 500 ms was meant to be "imperceptible," but on-device it wasn't — the user perceived the delay (and the voice chime masking it) on every tap. The placeholder Connection created by `beginAddConnection` has `pairedAt == null` and an empty EncryptedSharedPreferences store, so `AuthState` will NEVER reach `Paired` — the 500 ms is pure stall. Fix short-circuits the hydrate wait when `target.pairedAt == null`: skip `withTimeoutOrNull` entirely for placeholders and log at DEBUG instead of the misleading "auth hydrate timeout" INFO. Real paired-to-paired switches still run the full hydrate wait because both sides have `pairedAt != null`.
- **KDoc nested-comment trap in `ConnectionViewModel.relayReady` doc block.** A literal `/voice/*` path pattern inside the `relayReady` KDoc opened a nested block comment (Kotlin supports nested `/* */`, Java does not) whose `*/` then closed only the nested level — leaving the outer `/**` open for the remaining ~2200 lines of the file. Symptom: `MainActivity.kt:67` "Unresolved reference 'isReady'" plus ~50 cascading "Cannot infer type" errors across `PairedDevicesScreen`, `SettingsScreen`, `TerminalScreen`. Real errors (`Missing '}`, `Unclosed comment`) were the last two lines of `./gradlew compileGooglePlayDebugKotlin` output, easy to miss. Fix was a two-character rewrite: path patterns now wrapped in backticks AND `/*` → `/...` so the glob-looking character isn't in a block-comment position. Lesson logged in `DEVLOG.md` 2026-04-21; worth a sweep of other KDoc blocks for shell/regex-looking patterns before the next large diff.
- **KDoc nested-comment trap in `ConnectionViewModel.relayReady` doc block.** A literal `/voice/*` path pattern inside the `relayReady` KDoc opened a nested block comment (Kotlin supports nested `/* */`, Java does not) whose `*/` then closed only the nested level — leaving the outer `/**` open for the remaining ~2200 lines of the file. Symptom: `MainActivity.kt:67` "Unresolved reference 'isReady'" plus ~50 cascading "Cannot infer type" errors across `PairedDevicesScreen`, `SettingsScreen`, `TerminalScreen`. Real errors (`Missing '}`, `Unclosed comment`) were the last two lines of `./gradlew compileGooglePlayDebugKotlin` output, easy to miss. Fix was a two-character rewrite: path patterns now wrapped in backticks AND `/*` → `/...` so the glob-looking character isn't in a block-comment position. Lesson logged in `docs/project/DEVLOG.md` 2026-04-21; worth a sweep of other KDoc blocks for shell/regex-looking patterns before the next large diff.
- **Orphan placeholder connections from abandoned Add-connection flows.** The `beginAddConnection` path pre-creates a placeholder Connection and switches to it before the pair wizard runs — so `applyPairingPayload` lands the token in the right auth store. Previously, cleanup of the placeholder was wired only to the explicit Cancel button and TopAppBar back arrow. System back (gesture back / predictive back) bypassed that branch, leaving the placeholder in the connection list forever. Two-part fix: (a) `PairScreen` now installs a `BackHandler` that routes system back through the same `onCancel` → `discardPlaceholderConnection` branch the explicit back arrow uses; (b) `ConnectionViewModel.init` sweeps for any existing orphans (tuple: `pairedAt == null && apiServerUrl.isBlank() && label == PLACEHOLDER_LABEL`) on cold start and removes them — the tuple cannot be produced by any real pairing, so the sweep is safe without a dry-run. If the active connection at startup points at an orphan, the sweep switches to the first surviving real connection before deleting. Fixes the "why does my chip say 'New connection…'" symptom on devices that were affected pre-fix.
- **Pair flow now auto-starts the camera on Add connection.** `ConnectionWizard` gains an `autoStart: String?` param (currently only `"scan"` is honored). The Add-connection FAB on `ConnectionsSettingsScreen` passes it so the wizard fires the camera permission launcher on first composition instead of forcing users through the Method chooser — one obvious next step, one-tap flow. Re-pair surfaces intentionally leave `autoStart` null so the full Scan / Enter code / Show code chooser stays available there. The deep-link arg is plumbed through `Screen.Pair`'s route (`pair?connectionId=...&autoStart=...`) and `PairScreen`'s new `autoStart` param; unrecognized values fall through to the default Method step so future builds can add more targets without breaking old ones.
@@ -2088,7 +2105,7 @@ picker.
- **`CLAUDE.md`** — updated Git section with the new branching policy,
added file-table entries for `hermes-relay-update`,
`register_code_command`, and the expanded `install.sh`
- **`TODO.md`** — captures open research questions around proper
- **`docs/project/TODO.md`** — captures open research questions around proper
Hermes plugin/skill/tool distribution
- **`user-docs` vitepress site** — new "For AI Agents" copy-paste
block on the home view, Feature Matrix component, two-track explainer,
+15 -6
View File
@@ -82,6 +82,11 @@ Use the narrowest command that proves the change:
5. `scripts/dev.bat prepush` only when full local verification is explicitly
wanted or cloud execution is unavailable.
Android release preparation uses `python scripts/android-prepush.py
--release-prep` while version notes are changing. It keeps local feedback to
metadata and release-presentation tests; the exact pushed commit still goes
through required CI and Play preflight before publication.
`install-fast` is intentionally phone-specific. Use `install` for a universal
sideload debug APK or when the target ABI is not arm64. Release builds remain
universal and are unaffected unless `-Phermes.devAbi` is explicitly supplied.
@@ -254,16 +259,20 @@ translations may ship as `ai-translated`; do not claim fluent review unless a
review reference is recorded. Focused correction PRs from fluent contributors
are the canonical way to improve wording and can advance a locale to
`community-reviewed` or `verified` under `docs/translation-playbook.md`.
Translated READMEs use separate `README.<locale>.md` files; `README.md` remains
the canonical project description. User docs may be added incrementally under
`user-docs/<locale>/`, with links back to canonical English reference material.
Translated README entrypoints live under `docs/readme/` as
`README.<locale>.md`; root `README.md` remains the canonical project
description. Keep translated entrypoints concise: summarize onboarding and
core capabilities, link to localized user docs where available, and link back
to English for fast-moving architecture, security, and operator detail. User
docs may be added incrementally under `user-docs/<locale>/`, with links back to
canonical English reference material.
## Changelog & writing conventions
This is a **public repo** — `CHANGELOG.md`, `DEVLOG.md`, the README, and everything under `docs/` ship publicly. Keep them clean:
This is a **public repo** — `CHANGELOG.md`, `docs/project/DEVLOG.md`, the README, and everything under `docs/` ship publicly. Keep them clean:
- **`CHANGELOG.md`** follows [Keep a Changelog](https://keepachangelog.com/) (Added / Changed / Fixed). Append your change to the `## [Unreleased]` block in the PR. Entries can carry detail while they accumulate, but at release-prep the version block is **condensed to crisp public bullets** (1–2 lines each) — the deep "how we debugged it" narrative belongs in commit messages and `DEVLOG.md`, not the public changelog.
- **`DEVLOG.md`** is a factual engineering log — what changed, why, and how it was verified. Keep it depersonalized and third-person; it's a record, not a diary.
- **`CHANGELOG.md`** follows [Keep a Changelog](https://keepachangelog.com/) (Added / Changed / Fixed). Append your change to the `## [Unreleased]` block in the PR. Entries can carry detail while they accumulate, but at release-prep the version block is **condensed to crisp public bullets** (1–2 lines each) — the deep "how we debugged it" narrative belongs in commit messages and `docs/project/DEVLOG.md`, not the public changelog.
- **`docs/project/DEVLOG.md`** is a factual engineering log — what changed, why, and how it was verified. Keep it depersonalized and third-person; it's a record, not a diary.
- **No non-public wording anywhere committed:** no personal names (attribute impersonally — identity lives in git history), no real server hostnames/IPs or internal deployment names, no AI/assistant process self-narration, no fork/branch plumbing in user-facing notes. Generic example IPs in setup docs are fine.
Release notes (`RELEASE_NOTES.md`, `app/src/main/assets/whats_new.txt`, `docs/play-store-listing.md`) are theme-framed and user-facing; see [RELEASE.md](RELEASE.md) §2 "Scrub for public distribution" for the full checklist.
+8 -2
View File
@@ -21,7 +21,13 @@
</p>
<p align="center">
<strong>English</strong> · <a href="README.zh-CN.md">简体中文</a><br>
<strong>English</strong> ·
<a href="docs/readme/README.de.md">Deutsch</a> ·
<a href="docs/readme/README.es.md">Español</a> ·
<a href="docs/readme/README.ja.md">日本語</a> ·
<a href="docs/readme/README.pt-BR.md">Português (Brasil)</a> ·
<a href="docs/readme/README.ru.md">Русский</a> ·
<a href="docs/readme/README.zh-CN.md">简体中文</a><br>
<a href="https://hermes-relay.dev/docs/">Documentation</a> ·
<a href="https://github.com/Codename-11/hermes-relay/releases">Releases</a> ·
<a href="https://github.com/Codename-11/hermes-relay/discussions">Discussions</a> ·
@@ -214,7 +220,7 @@ hermes-relay update # self-update via GitHub Releases
It pairs against the **same relay and credential store** as the Android app — pair once from either, both work. Tagged on the `desktop-v*` [release track](https://github.com/Codename-11/hermes-relay/releases?q=desktop), with historical releases still visible under `cli-v*`.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. It is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. `hermes-relay update` detects this bundle and updates the CLI and UI together; explicit CLI-only installations stay headless and continue using the standalone binary updater. The UI is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
<table>
<tr>
-109
View File
@@ -1,109 +0,0 @@
<p align="center">
<img src="assets/play-store-feature-1024x500.png" alt="Hermes-Relay — 随身携带您的 Hermes 代理" width="800">
</p>
<p align="center">
<strong>运行在您的电脑上,连接到您的设备。</strong><br>
Hermes-Relay 是 <a href="https://github.com/NousResearch/hermes-agent">Hermes Agent</a> 的原生 Android 客户端,提供流式聊天、免手动语音和代理管理;另有单文件 CLI,让代理在已配对的电脑上安全使用终端、文件和截图工具。
</p>
<p align="center">
<strong>简体中文</strong> · <a href="README.md">English</a><br>
<a href="https://hermes-relay.dev/docs/zh-CN/">中文文档</a> ·
<a href="https://github.com/Codename-11/hermes-relay/releases">版本下载</a> ·
<a href="https://github.com/Codename-11/hermes-relay/discussions">社区讨论</a> ·
<a href="CHANGELOG.md">更新日志</a>
</p>
> 英文 [README.md](README.md) 是最新、完整的项目说明。本页维护中文安装入口和核心功能摘要;协议、架构和维护者文档以英文版本为准。
## 功能简介
- **Android 应用**:流式聊天、会话历史、文件附件、Hermes 管理、语音模式、原生插件页面、Petdex 悬浮宠物、多连接和配置文件;也可将 Hermes 设为 Android 助手。
- **无需插件的标准路径**:聊天、管理和标准语音可直接连接未修改的上游 Hermes Agent。
- **可选 Relay 插件**:增加终端、手机控制、媒体传输、通知助手、Relay 语音、电脑工具,以及需确认的代理创建插件页面草稿。
- **安全连接**:二维码配对、Android Keystore、证书固定、按通道授权和可配置会话有效期。
- **远程使用**:可配置 Tailscale 或 HTTPS 地址,在家庭局域网和远程路由之间自动切换。
- **两种 Android 发行渠道**:Google Play 版本适合日常使用;sideload 版本包含完整手机控制能力。
## 快速开始
### 1. 安装 Android 应用
- [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay):自动更新,包含聊天、语音、管理、终端、媒体和通知功能。
- [GitHub Releases](https://github.com/Codename-11/hermes-relay/releases):下载最新 `android-v*` 版本中以 `-sideload-release.apk` 结尾的文件,获得完整手机控制功能。
### 2. 启动 Hermes API 服务
手机需要能够访问 Hermes API 服务,并使用 API 密钥进行身份验证:
```bash
hermes setup --portal
mkdir -p ~/.hermes
API_SERVER_KEY="$(openssl rand -hex 32)"
cat >> ~/.hermes/.env <<EOF
API_SERVER_ENABLED=true
API_SERVER_HOST=0.0.0.0
API_SERVER_PORT=8642
API_SERVER_KEY=$API_SERVER_KEY
EOF
chmod 600 ~/.hermes/.env
echo "Android API URL: http://<电脑IP>:8642 key: $API_SERVER_KEY"
hermes gateway
```
`0.0.0.0` 会让同一网络中的设备访问 API。请保留强密钥;离开可信局域网时,应使用 Tailscale 或 HTTPS 反向代理,不要直接把端口暴露到互联网。
### 3. 在手机上连接
打开应用后,可以:
- 扫描局域网中的 Hermes;
- 手动输入 `http://<主机>:8642` 和 API 密钥;
- 扫描包含 API、Dashboard 和可选 Relay 地址的设置二维码。
如需在手机上管理模型、密钥、技能和配置文件,请运行 Hermes Dashboard,并在应用的 **管理** 页面登录一次。同一登录会话也会启用标准语音。
### 4. 可选:安装 Relay
仅在需要终端、手机控制、媒体路由、Relay 会话、实时语音、电脑工具或代理创建插件页面草稿时安装:
```bash
hermes plugins install Codename-11/hermes-relay/plugin --enable
hermes relay doctor
hermes relay start --no-ssl
hermes pair
```
已安装的 Hermes 插件可通过已认证的 Dashboard 向 Android 提供由应用安全渲染的原生页面,无需在手机上运行插件代码。Relay 1.5.0 另支持需用户确认的代理创建页面草稿。
完整说明请阅读[中文快速开始](https://hermes-relay.dev/docs/zh-CN/guide/quick-start);远程访问、协议和高级配置暂时链接到英文参考文档。
安装问题、早期想法、一般交流和作品分享请使用 [GitHub Discussions](https://github.com/Codename-11/hermes-relay/discussions)。可复现的错误和明确、可执行的功能请求请提交到 [Issues](https://github.com/Codename-11/hermes-relay/issues/new)。
## 中文界面
<table>
<tr>
<td align="center" width="33%"><img src="assets/screenshots/Zh01.jpg" alt="中文设置界面" width="100%"><br><sub><b>设置</b></sub></td>
<td align="center" width="33%"><img src="assets/screenshots/Zh02.jpg" alt="中文管理界面" width="100%"><br><sub><b>管理</b></sub></td>
<td align="center" width="33%"><img src="assets/screenshots/Zh03.jpg" alt="中文导航界面" width="100%"><br><sub><b>导航</b></sub></td>
</tr>
</table>
## 参与翻译
Android 英文资源是规范来源。新增语言必须保持资源名称、类型和格式参数一致,并通过:
```bash
python scripts/check-android-locales.py
./gradlew lint
```
翻译规范、目录命名、复数和占位符规则见 [docs/localization.md](docs/localization.md)。
## 许可证
[MIT](LICENSE) — Copyright (c) 2026 [Axiom-Labs](https://codename-11.dev)
+87 -45
View File
@@ -628,6 +628,21 @@ and the release notes and learn only what the software does.
### 3. Build and verify locally
During release-note/version iteration, use the narrow release-prep lane:
```powershell
python scripts/android-prepush.py --release-prep
```
It runs release metadata checks plus the rendered Changelog/What's New tests in
the serialized Android lane. Once the exact commit is pushed, current-head CI
and Play preflight own lint, focused shards, both-flavor assemblies, signing,
and final package scans. Do not repeat the complete local release build unless
cloud execution is unavailable or explicit local artifact/device proof is
needed.
For that explicit full local proof:
```bat
scripts\dev.bat bundle
keytool -printcert -jarfile app\build\outputs\bundle\googlePlayRelease\hermes-relay-*-googlePlay-release.aab
@@ -661,14 +676,17 @@ The preflight workflow:
3. builds and release-signs the same APK/AAB variants used by the public release;
4. scans the final minified APK DEX for unsupported collection calls;
5. uploads the Google Play AAB as a private **Production draft**; and
6. records a 30-day preflight proof keyed to the version and Git tree hash.
6. retains the exact signed sideload APK, Play AAB, R8 mappings, manifest, and
checksums as one immutable 30-day artifact keyed to version and Git tree.
No sideload APK or GitHub Release is published by preflight. A successful signed
build, final DEX scan, and Production-draft upload is the automated Play release
gate. Play Console pre-review and pre-launch reports are informational and
non-blocking because their detailed results are not exposed through the release
automation API. If the release source changes after preflight, rerun it—the
approval workflow matches the complete Git tree, not just the version number.
build, final package scans, and Production-draft upload is the automated Play
release gate. The private artifact is immutable and hash-verified again before
publication; the stable release workflow does not rebuild those bytes. Play
Console pre-review and pre-launch reports are informational and non-blocking
because their detailed results are not exposed through the release automation
API. If the release source changes after preflight, rerun it—the approval
workflow matches the complete Git tree, not just the version number.
GitHub exposes manual workflows only after their workflow file exists on the
default branch. For the first release that introduces this process, merge the
@@ -709,12 +727,13 @@ from `main`; every release job explicitly checks out and verifies the immutable
an existing tag or changing its artifact tree. Manual stable tags are still
guarded by the same preflight proof in the tag workflow.
The tag-triggered `.github/workflows/release-android.yml` rebuilds and scans the
artifacts, changes the existing Play Production draft to `completed` (submitting
it for review), and only after Play accepts that operation creates the public
GitHub Release with the sideload APK. A missing preflight, changed release tree,
missing Play credential, or Play submission failure prevents public GitHub
publication.
The tag-triggered `.github/workflows/release-android.yml` downloads the exact
private preflight artifact by ID, verifies its source workflow, manifest, tree,
version, sizes, and hashes, reruns the package scanners, then changes the
existing Play Production draft to `completed` (submitting it for review). Only
after Play accepts that operation does it publish those same APK/AAB bytes on
GitHub. A missing preflight, changed release tree, artifact mismatch, missing
Play credential, or Play submission failure prevents public publication.
Plugin/Python version files are intentionally not part of an Android app
release unless the plugin package itself is also being released.
@@ -743,14 +762,19 @@ git commit -m "release(server): server-v0.6.2"
git push origin dev
# Open the release PR (dev -> main) and merge with --no-ff.
# After merge, tag from the new main tip:
git checkout main
git pull --ff-only origin main
git tag server-v0.6.2
git push origin server-v0.6.2
# Then run "Hermes-Relay Plugin and CLI+UI Release Approval" from main,
# select plugin, and enter 0.6.2. The workflow selects and validates main
# before it creates server-v0.6.2 and starts the immutable-tag release workflow.
```
Pushing `server-v*` triggers `.github/workflows/release-plugin.yml`, which
For a Plugin prerelease, keep the release-prepared commit on `dev` and run the
same trusted approval workflow from `main`; the version suffix makes it select
and validate the exact `origin/dev` tip before creating the tag. Stable versions
select `origin/main` instead.
Direct `server-v*` tag pushes remain a recovery path and are guarded by the same
branch-containment and metadata checks.
The approval workflow dispatches `.github/workflows/release-plugin.yml`, which
validates all plugin-owned version metadata with
`scripts/check-plugin-version-sync.py`. Run
`python scripts/check-version-tracks.py` locally before tagging when a change
@@ -781,20 +805,25 @@ git add desktop/package.json desktop/package-lock.json desktop/src/version.ts `
git commit -m "release(desktop): desktop-v0.4.0-alpha.2"
git push origin dev
# Open the release PR (dev -> main) and merge with --no-ff.
# After merge, tag from main:
git switch main
git pull --ff-only origin main
cd desktop
npm run check:version-sync -- --expect 0.4.0-alpha.2
cd ..
git tag desktop-v0.4.0-alpha.2
git push origin desktop-v0.4.0-alpha.2
# This is a prerelease: run "Hermes-Relay Plugin and CLI+UI Release Approval"
# from main, select desktop, and enter 0.4.0-alpha.2. The workflow validates dev
# before it creates the tag and starts the immutable-tag release workflow.
```
The tag workflow rejects version drift and tags whose commit is not in
`origin/main`, reruns CLI tests, builds all four standalone binaries, tests and
packages the Windows tray, generates checksums, and publishes the GitHub Release.
For a stable CLI+UI version, first merge the release PR from `dev` to `main`,
then run the approval workflow from `main`. The version determines the source:
prereleases select the exact `origin/dev` tip and stable releases select the
exact `origin/main` tip before creating any tag. Direct `desktop-v*` tag pushes
remain a recovery path.
The release workflow rejects version drift and requires prerelease tags to be
contained in `origin/dev` and stable tags to be contained in `origin/main`. It
reruns CLI tests, builds all four standalone binaries, tests and packages the
Windows tray, generates checksums, and publishes the GitHub Release.
Trusted desktop CI and the release installer job share a Cargo/target cache
keyed by the lockfile and exact tray sources. A `main` push for the release tree
warms the exact cache before the immutable tag build; a miss safely performs the
ordinary Rust/Tauri build.
### 6. Play review and publishing behavior
@@ -895,7 +924,7 @@ gradlew promoteReleaseArtifact --from-track=internal --promote-track=production
(This step was only needed as a retrofit for v0.1.0 — v0.1.1+ inherit
the Download section automatically from `RELEASE_NOTES.md`.)
- Confirm Play Console shows the new versionCode on the target track.
- Update `DEVLOG.md` with a short entry for the release.
- Update `docs/project/DEVLOG.md` with a short entry for the release.
## CI Behavior
@@ -903,28 +932,40 @@ Android, Plugin, dashboard, and desktop now have separate CI/release lanes.
This keeps a dashboard CSS fix from running the full server suite, and keeps
plugin changes from forcing an Android app `versionCode` bump.
Every successful `Required checks` run records a short-lived proof keyed to the
checked Git tree. For the canonical `dev` → `main` release PR, CI first proves
the simulated merge tree is identical to the `dev` tree. If an unexpired proof
from a successful Required-checks run exists, the PR verifies and reuses it;
otherwise it automatically falls back to the normal path-aware matrix. Content
changes can never reuse an older proof because they change the tree hash.
On every push of a tag matching `android-v*`, `.github/workflows/release-android.yml`:
1. Verifies a stable tag resolves to a commit contained in `main`, or a
prerelease tag resolves to a commit contained in `dev`, and that the tag matches `appVersionName` in
`gradle/libs.versions.toml` (mismatches fail the workflow).
2. Runs the Android debug build and the stable sideload pairing/connection
regression slice with explicit timeouts.
3. Decodes `HERMES_KEYSTORE_BASE64` into `$RUNNER_TEMP/release.keystore`
and exports `HERMES_KEYSTORE_PATH` (skipped if the secret is unset).
4. For stable releases, builds all four flavored release artifacts
(`./gradlew bundleRelease assembleRelease`); only the sideload APK and
googlePlay AAB are attached. For prereleases, builds only the side-by-side
`sideloadCandidate` APK.
5. Generates `SHA256SUMS.txt` covering the two attached files.
6. For stable releases only, promotes the exact preflighted Production draft to
2. For stable releases, verifies and downloads the exact immutable Play
preflight artifact; prereleases run the focused CI slice and build the
side-by-side `sideloadCandidate` APK.
3. Revalidates stable artifact hashes, DEX collection compatibility, packaged
native compatibility, and retained R8 mappings without recompiling.
4. Generates candidate checksums when applicable; stable checksums come from
the verified preflight artifact and cover the two public files.
5. For stable releases only, promotes the exact preflighted Production draft to
`completed`; prereleases never upload to Play.
7. Creates a GitHub Release named `Hermes-Relay Android v<version>` with `RELEASE_NOTES.md` as
6. Creates a GitHub Release named `Hermes-Relay Android v<version>` with `RELEASE_NOTES.md` as
the body. Attaches the APK, AAB, and `SHA256SUMS.txt`. Tags any version
containing a dash (e.g. `android-v0.2.0-beta.1`) as a prerelease automatically.
8. Prints a `$GITHUB_STEP_SUMMARY` with the release and Play result.
7. Prints a `$GITHUB_STEP_SUMMARY` with the release and Play result.
On every push of a tag matching `server-v*`,
For an approved multi-surface train, run **Hermes-Relay Coordinated Release
Approval** from `main`, select the affected surfaces, and enter their prepared
versions. It dispatches Android, Plugin, and CLI+UI approval jobs concurrently;
each surface keeps its independent source, validation, tag, artifact, and
publication workflow.
On every direct push of a tag matching `server-v*`, or after an approved
dispatch from `.github/workflows/approve-release-extensions.yml`,
`.github/workflows/release-plugin.yml`:
1. Verifies a stable tag commit is contained in `main`, or a prerelease tag is
@@ -937,7 +978,8 @@ On every push of a tag matching `server-v*`,
5. Creates a GitHub Release named `Hermes-Relay Plugin v<version>` with the wheel,
sdist, and checksum file attached.
On every push of a tag matching `desktop-v*`,
On every direct push of a tag matching `desktop-v*`, or after an approved
dispatch from `.github/workflows/approve-release-extensions.yml`,
`.github/workflows/release-cli.yml` builds and publishes the CLI binaries and
Windows tray installer. Its GitHub Release body comes from `CLI_RELEASE_NOTES.md`
(rewritten per release — the CLI counterpart of `RELEASE_NOTES.md`); the workflow
+2 -1
View File
@@ -367,8 +367,9 @@ dependencies {
implementation(libs.okhttp)
implementation(libs.okhttp.sse)
// Media3 ExoPlayer — gapless TTS queue playback (replaces MediaPlayer in VoicePlayer)
// Media3 ExoPlayer + lifecycle-aware Compose video surface.
implementation(libs.media3.exoplayer)
implementation(libs.media3.ui.compose)
// android-vad Silero — on-device VAD for barge-in (B2)
// Bundled ONNX Silero model (~2.2 MB); pulled from JitPack.
+3
View File
@@ -55,6 +55,9 @@
-keep class androidx.camera.** { *; }
-dontwarn androidx.camera.**
# sherpa-onnx JNI resolves Kotlin configuration classes and fields by name.
-keep class com.k2fsa.sherpa.onnx.** { *; }
# ── General ──────────────────────────────────────────────────────────
-keepattributes SourceFile,LineNumberTable
-renamesourcefileattribute SourceFile
@@ -15,6 +15,10 @@ import androidx.compose.ui.test.assertTextEquals
import androidx.compose.ui.test.junit4.v2.createAndroidComposeRule
import androidx.compose.ui.test.onAllNodesWithText
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onAllNodesWithContentDescription
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.test.platform.app.InstrumentationRegistry
import androidx.lifecycle.compose.collectAsStateWithLifecycle
import com.hermesandroid.relay.data.MessageRole
@@ -171,6 +175,81 @@ class GatewayExternalFixtureInstrumentedTest {
}
}
@Test
fun queuedStopResume_preservesWorkAcrossLifecycleAndUsesExplicitResume() {
val base = InstrumentationRegistry.getArguments().getString(ARG_FIXTURE_BASE_URL)?.trimEnd('/')
assumeTrue("Pass a queued_stop_resume fixture URL", !base.isNullOrBlank())
requireNotNull(base)
val http = OkHttpClient.Builder().callTimeout(10, TimeUnit.SECONDS).build()
assertEquals("queued_stop_resume", readFixtureJson(http, "$base/__fixture__/state")["scenario"]?.jsonString())
val dashboard = DashboardApiClient(base, http)
val scope = CoroutineScope(SupervisorJob() + Dispatchers.IO).also { gatewayScope = it }
val gateway = GatewayChatClient(
initialDashboardClient = dashboard, okHttpClient = http, scope = scope,
callbackDispatcher = { block -> Handler(Looper.getMainLooper()).post(block) },
reconnectJitterUnit = { 0.0 },
).also { gatewayClient = it }
val handler = ChatHandler().also { it.setSessionId(STORED_SESSION_ID) }
val vm = ChatViewModel().also {
it.initialize(null, handler)
it.streamingEndpoint = "gateway"
it.setProfileMessageLoaderWithMode { profile, session, mode -> dashboard.getSessionMessages(session, profile, mode) }
it.updateGatewayClient(gateway)
it.switchProfileContext(com.hermesandroid.relay.data.AgentDisplay.profileContextKey("fixture-queue", null), STORED_SESSION_ID)
}.also { viewModel = it }
compose.setContent {
val queue by vm.queuedMessages.collectAsStateWithLifecycle()
val paused by vm.queuePaused.collectAsStateWithLifecycle()
com.hermesandroid.relay.ui.theme.HermesRelayTheme(themePreference = "dark") {
androidx.compose.material3.Surface {
Column {
com.hermesandroid.relay.ui.components.ChatBusyActionSelector(
com.hermesandroid.relay.data.BusyMessageAction.QueueNext, {}, onStop = vm::cancelStream,
)
com.hermesandroid.relay.ui.components.ChatMessageQueue(
queue, paused, vm::resumeQueue, vm::clearQueue, {}, vm::removeQueuedAt, canEdit = true,
)
}
}
}
}
assertTrue(runBlocking { gateway.prewarmAwait(STORED_SESSION_ID) })
compose.runOnIdle { vm.sendMessage("Original work") }
compose.waitUntil(10_000) { handler.isStreaming.value && vm.steerableTurn.value }
compose.runOnIdle {
vm.sendMessage("Remove this follow-up", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
vm.sendMessage("Keep this follow-up", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
}
compose.onAllNodesWithContentDescription("Remove queued message")[0].performClick()
compose.onNodeWithContentDescription("Stop streaming").performClick()
compose.onNodeWithText("Queue paused").assertIsDisplayed()
assertEquals(listOf("Keep this follow-up"), vm.queuedMessages.value)
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.CREATED)
compose.activityRule.scenario.moveToState(androidx.lifecycle.Lifecycle.State.RESUMED)
compose.onNodeWithText("Keep this follow-up").assertIsDisplayed()
compose.onNodeWithText("Resume").performClick()
try {
compose.waitUntil(15_000) {
vm.queuedMessages.value.isEmpty() && !handler.isStreaming.value &&
handler.messages.value.any { it.content == "Resumed follow-up." }
}
} catch (error: androidx.compose.ui.test.ComposeTimeoutException) {
throw AssertionError(
"Synthetic queue fixture did not settle: queued=${vm.queuedMessages.value.size}, " +
"paused=${vm.queuePaused.value}, streaming=${handler.isStreaming.value}, " +
"messages=${handler.messages.value.map { it.role to it.content }}, " +
"error=${handler.error.value}",
error,
)
}
val evidence = readFixtureJson(http, "$base/__fixture__/evidence")["entries"] as JsonArray
assertEquals(2, evidence.rpcCount("prompt.submit"))
assertEquals(1, evidence.rpcCount("session.interrupt"))
assertEquals(0, evidence.rpcCount("session.redirect"))
assertEquals("gateway", vm.streamingEndpoint)
}
private fun JsonArray.rpcCount(method: String): Int = count { element ->
val entry = element as? JsonObject ?: return@count false
entry["kind"]?.jsonString() == "rpc" && entry["method"]?.jsonString() == method
@@ -22,6 +22,26 @@ enum class PhysicalKeyboardEnterBehavior(val storedValue: String) {
}
}
/** Default intent for a message submitted while an agent is responding. */
enum class BusyMessageAction(val storedValue: String) {
CorrectNow("correct_now"),
QueueNext("queue_next");
companion object {
fun fromStoredValue(value: String?): BusyMessageAction =
entries.firstOrNull { it.storedValue == value } ?: CorrectNow
}
}
fun canCorrectBusyMessage(
steerable: Boolean,
hasAttachments: Boolean,
hasPendingInput: Boolean,
status: String?,
text: String,
): Boolean = steerable && !hasAttachments && !hasPendingInput &&
status?.contains("compact", ignoreCase = true) != true && !text.trimStart().startsWith("/")
/** Device-level chat input preferences shared by every Hermes profile. */
class ChatInputPreferencesRepository(
private val dataStore: DataStore<Preferences>,
@@ -29,6 +49,7 @@ class ChatInputPreferencesRepository(
constructor(context: Context) : this(context.relayDataStore)
companion object {
internal val KEY_BUSY_MESSAGE_ACTION = stringPreferencesKey("busy_message_action")
internal val KEY_PHYSICAL_KEYBOARD_ENTER =
stringPreferencesKey("physical_keyboard_enter_behavior")
internal val KEY_CONVERT_LARGE_PASTES =
@@ -45,6 +66,14 @@ class ChatInputPreferencesRepository(
}
.distinctUntilChanged()
val busyMessageAction: Flow<BusyMessageAction> = dataStore.data
.map { BusyMessageAction.fromStoredValue(it[KEY_BUSY_MESSAGE_ACTION]) }
.distinctUntilChanged()
suspend fun setBusyMessageAction(action: BusyMessageAction) {
dataStore.edit { it[KEY_BUSY_MESSAGE_ACTION] = action.storedValue }
}
val convertLargePastesToAttachments: Flow<Boolean> = dataStore.data
.map { preferences -> preferences[KEY_CONVERT_LARGE_PASTES] ?: true }
.distinctUntilChanged()
@@ -35,6 +35,9 @@ data class ChatTurnCheckpoint(
val baselineAssistantCount: Int,
val pendingAsk: ChatTurnAskCheckpoint? = null,
val queuedMessages: List<ChatQueuedMessageCheckpoint> = emptyList(),
val queuePaused: Boolean = false,
/** Only pending local work remains; never reattach the completed/stopped turn. */
val queueOnly: Boolean = false,
val startedAt: Long,
val updatedAt: Long,
) {
@@ -348,7 +348,7 @@ class BridgeCommandHandler(
* the multiplexer. The two paths are fully independent.
*
* Caught by Bailey's on-device test 2026-04-14 — see the v0.4.1
* "voice intent local dispatch loop" entry in ROADMAP.md.
* "voice intent local dispatch loop" entry in docs/project/ROADMAP.md.
*/
suspend fun handleLocalCommand(envelope: Envelope): LocalDispatchResult {
if (envelope.type != "bridge.command") {
@@ -49,10 +49,10 @@ import okhttp3.Request
import okhttp3.RequestBody
import okhttp3.RequestBody.Companion.toRequestBody
import okhttp3.Response
import java.io.ByteArrayOutputStream
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.io.ByteArrayOutputStream
import java.net.URLEncoder
import java.util.concurrent.TimeUnit
import kotlin.coroutines.resume
@@ -294,6 +294,34 @@ internal fun copyBounded(
return written
}
internal fun copyMediaBounded(
input: InputStream,
output: OutputStream,
declaredLength: Long?,
limitBytes: Long,
): Long {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
if (declaredLength != null && declaredLength > limitBytes) {
throw IOException("File exceeds the configured download limit")
}
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("File exceeds the configured download limit")
}
output.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Media file changed while it was being downloaded")
}
return written
}
/** One entry from `GET /api/audio/elevenlabs/voices` — non-secret voice metadata. */
data class ElevenLabsVoice(
val voiceId: String,
@@ -312,14 +340,14 @@ data class ElevenLabsVoices(
)
/**
* Bytes fetched from upstream's authenticated managed-files surface.
* Metadata for a file streamed from upstream's authenticated managed-files surface.
*
* The Dashboard applies its own managed-root, sensitive-file, and maximum-size
* policy before these bytes leave the Hermes host. Android applies the user's
* policy before the file leaves the Hermes host. Android applies the user's
* stricter inbound-media cap while reading the response as a second boundary.
*/
data class DashboardFetchedFile(
val bytes: ByteArray,
val sizeBytes: Long,
val contentType: String,
val fileName: String?,
)
@@ -401,13 +429,14 @@ class DashboardApiClient(
* This is the same authenticated `/api/files/download` route official
* Desktop uses for remote gateway files. The caller supplies its display
* cap so a malicious or stale Content-Length cannot cause an unbounded
* allocation. Audio/video are downloaded into Android's local media cache;
* allocation. The supplied output is normally Android's on-disk media cache;
* local playback supplies seeking, so `/api/files/stream` is unnecessary
* on this path.
*/
suspend fun downloadManagedFile(
serverPath: String,
maxBytes: Long,
output: OutputStream,
): Result<DashboardFetchedFile> = withContext(Dispatchers.IO) {
if (serverPath.isBlank()) {
return@withContext Result.failure(IOException("Media path is empty"))
@@ -428,29 +457,11 @@ class DashboardApiClient(
if (declaredLength != null && declaredLength > maxBytes) {
throw IOException("File exceeds the configured download limit")
}
val initialSize = declaredLength
?.coerceAtMost(Int.MAX_VALUE.toLong())
?.toInt()
?: DEFAULT_BUFFER_SIZE
val output = ByteArrayOutputStream(initialSize)
body.byteStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var readTotal = 0L
while (true) {
val count = input.read(buffer)
if (count < 0) break
readTotal += count
if (readTotal > maxBytes) {
throw IOException("File exceeds the configured download limit")
}
output.write(buffer, 0, count)
}
if (declaredLength != null && readTotal != declaredLength) {
throw IOException("Media file changed while it was being downloaded")
}
val readTotal = body.byteStream().use { input ->
copyMediaBounded(input, output, declaredLength, maxBytes)
}
DashboardFetchedFile(
bytes = output.toByteArray(),
sizeBytes = readTotal,
contentType = response.header("Content-Type")
?.substringBefore(';')
?.trim()
@@ -1345,7 +1356,7 @@ class DashboardApiClient(
suspend fun getSessionMessages(
sessionId: String,
profile: String? = null,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>> = withContext(Dispatchers.IO) {
val name = profile?.trim().orEmpty()
loadSessionMessages(mode) { page ->
@@ -1749,6 +1760,7 @@ class DashboardApiClient(
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
internal const val MAX_BACKUP_TRANSFER_BYTES = 100L * 1024L * 1024L
internal const val MAX_JSON_RESPONSE_BYTES = 8L * 1024L * 1024L
fun pathSegment(value: String): String =
URLEncoder.encode(value, "UTF-8").replace("+", "%20")
@@ -2477,17 +2489,44 @@ data class StoredDashboardCookie(
}
private fun Response.readJsonObject(json: Json): JsonObject {
val raw = body.string()
val raw = body.readUtf8Bounded(DashboardApiClient.MAX_JSON_RESPONSE_BYTES)
if (raw.isBlank()) return JsonObject(emptyMap())
return json.parseToJsonElement(raw).jsonObject
}
private fun Response.readJsonElement(json: Json): JsonElement {
val raw = body.string()
val raw = body.readUtf8Bounded(DashboardApiClient.MAX_JSON_RESPONSE_BYTES)
if (raw.isBlank()) return JsonObject(emptyMap())
return json.parseToJsonElement(raw)
}
internal fun okhttp3.ResponseBody.readUtf8Bounded(maxBytes: Long): String {
require(maxBytes in 1..Int.MAX_VALUE.toLong()) { "Invalid response byte limit" }
val declaredLength = contentLength()
if (declaredLength > maxBytes) {
throw IOException("Dashboard response exceeds Android's bounded JSON limit")
}
val initialSize = when {
declaredLength in 1..maxBytes -> declaredLength.toInt()
else -> minOf(maxBytes, DEFAULT_BUFFER_SIZE.toLong()).toInt()
}
val output = ByteArrayOutputStream(initialSize)
byteStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var total = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
total += read
if (total > maxBytes) {
throw IOException("Dashboard response exceeds Android's bounded JSON limit")
}
output.write(buffer, 0, read)
}
}
return output.toString(Charsets.UTF_8.name())
}
private fun contentDispositionFileName(header: String): String? {
val encoded = Regex("""filename\*=UTF-8''([^;]+)""", RegexOption.IGNORE_CASE)
.find(header)
@@ -2576,7 +2615,11 @@ internal fun Throwable.isDashboardManagedFilesUnsupported(): Boolean {
}
private fun apiFailure(response: Response, operation: String): IOException {
val bodyDetail = runCatching { response.body.string() }.getOrDefault("")
val bodyDetail = try {
response.body.readUtf8Bounded(4L * 1024L)
} catch (_: Exception) {
""
}
val detail = bodyDetail.take(240).ifBlank { response.message }
return DashboardHttpException(
statusCode = response.code,
@@ -119,6 +119,8 @@ class GatewayChatClient(
private val promptSubmitTimeoutMs: Long = PROMPT_SUBMIT_REQUEST_TIMEOUT_MS,
/** Test seam — idle-progress watchdog base. Production keeps [TURN_TIMEOUT_MS]. */
private val turnIdleTimeoutMs: Long = TURN_TIMEOUT_MS,
/** Test seam — lazy session.create/resume readiness barrier. */
private val sessionReadyTimeoutMs: Long = SESSION_READY_TIMEOUT_MS,
/** Test seam — compaction idle lease. Production keeps [COMPACTING_TIMEOUT_MS]. */
private val compactingTimeoutMs: Long = COMPACTING_TIMEOUT_MS,
/** Random source for ordinary reconnect full-jitter. */
@@ -191,6 +193,7 @@ class GatewayChatClient(
* would have been abandoned server-side anyway.
*/
private const val PROMPT_SUBMIT_REQUEST_TIMEOUT_MS = 1_800_000L
private const val SESSION_READY_TIMEOUT_MS = 300_000L
private const val CONNECT_TIMEOUT_MS = 20_000L
/**
@@ -413,6 +416,10 @@ class GatewayChatClient(
@Volatile
private var webSocket: WebSocket? = null
/** Profile explicitly routed by the Dashboard `/api/ws?profile=` handshake. */
@Volatile
private var connectedSocketProfile: String? = null
/** Completed when the server's `gateway.ready` event arrives for the current socket. */
@Volatile
private var readySignal: CompletableDeferred<Unit>? = null
@@ -421,6 +428,9 @@ class GatewayChatClient(
/** Invalidates an older async prewarm when a newer session selection wins. */
private val prewarmRequestGeneration = AtomicLong(0)
private val pendingRpcs = ConcurrentHashMap<Long, CompletableDeferred<JsonObject>>()
private val lazyLiveSessions = ConcurrentHashMap.newKeySet<String>()
private val readyLiveSessions = ConcurrentHashMap.newKeySet<String>()
private val sessionReadyWaiters = ConcurrentHashMap<String, CompletableDeferred<Unit>>()
/** Monotonic client-local fence for lazy child watch open/close races. */
private val childWatchGeneration = AtomicLong(0)
@@ -832,7 +842,7 @@ class GatewayChatClient(
// through the normal failed-turn callback instead.
cleanupStagedAttachments(stagedImagePaths)
turn.tracer.done("submit-rejected")
turn.callbacks.onError(
turn.callbacks.onSubmitRejected(
submitError?.message ?: "Hermes rejected the new session",
)
return@launch
@@ -899,6 +909,9 @@ class GatewayChatClient(
liveSessionId = null
storedSessionId = null
liveSessionProfile = null
failSessionReadyWaiters("gateway session cleared")
lazyLiveSessions.clear()
readyLiveSessions.clear()
cancelledTurnDrain = null
_serverTools.value = null
}
@@ -3057,9 +3070,10 @@ class GatewayChatClient(
)
}
val ticketMs = (System.nanoTime() - connectStart) / 1_000_000
val socketProfile = currentSessionProfile()
val url = dashboardClient.gatewayWebSocketUrl(
ticket = ticket.ticket,
profile = currentSessionProfile(),
profile = socketProfile,
)
?: throw GatewayConnectAttemptException(
"could not build /api/ws URL",
@@ -3093,6 +3107,7 @@ class GatewayChatClient(
if (readyFailure != null) {
socket.cancel()
webSocket = null
connectedSocketProfile = null
throw (readyFailure as? GatewayConnectAttemptException
?: GatewayConnectAttemptException(
"gateway connection failed: ${readyFailure.message}",
@@ -3105,6 +3120,7 @@ class GatewayChatClient(
val wsMs = (System.nanoTime() - connectStart) / 1_000_000 - ticketMs
Log.i(TAG, "Gateway connected (/api/ws ready) — ticket=${ticketMs}ms ws=${wsMs}ms")
hasEverReachedReady = true
connectedSocketProfile = socketProfile
coldStartFailureEpisodes = 0
_reconnectDisposition.value = GatewayReconnectDisposition.None
_connectionState.value = GatewayConnectionState.Ready
@@ -3279,7 +3295,8 @@ class GatewayChatClient(
?.stringField("profile_name")
?.trim()
?.takeIf { it.isNotEmpty() }
if (actual != expected) {
val socketConfirmed = actual == null && connectedSocketProfile == expected
if (actual != expected && !socketConfirmed) {
val detail = actual?.let { "Hermes returned profile '$it'" }
?: "Hermes did not confirm profile ownership"
throw GatewayPreflightException(
@@ -3389,6 +3406,7 @@ class GatewayChatClient(
requestedStoredId != null &&
liveSessionProfile == requestedProfile
) {
awaitSessionReadyIfRequired(liveSessionId!!)
return
}
@@ -3418,6 +3436,7 @@ class GatewayChatClient(
liveSessionProfile = requestedProfile
updateCancelledDrainLiveSession(requestedStoredId, live)
applySessionResultInfo(result)
awaitSessionReadyIfRequired(live, result)
return
}
throw GatewayAuthoritativeResumeException(
@@ -3453,6 +3472,45 @@ class GatewayChatClient(
if (cancelledTurnDrain?.storedSessionId != stored) cancelledTurnDrain = null
if (settledTurnDrain?.storedSessionId != stored) settledTurnDrain = null
turn.callbacks.onSessionId(stored)
awaitSessionReadyIfRequired(live, created)
}
/**
* Wait for current upstream's authoritative deferred-build edge instead of
* racing a lazy session into compute-host turn isolation. Without this
* barrier, the parent runtime can claim the durable lease before the child
* rechecks it, causing the child to reject itself as a second live owner.
*/
private suspend fun awaitSessionReadyIfRequired(
liveId: String,
sessionResult: JsonObject? = null,
) {
val lazy = (sessionResult?.get("info") as? JsonObject)?.booleanField("lazy") == true
if (lazy) lazyLiveSessions += liveId
if (liveId !in lazyLiveSessions) return
if (readyLiveSessions.remove(liveId)) {
lazyLiveSessions.remove(liveId)
return
}
val waiter = sessionReadyWaiters.computeIfAbsent(liveId) { CompletableDeferred() }
if (readyLiveSessions.remove(liveId)) waiter.complete(Unit)
try {
withTimeout(sessionReadyTimeoutMs) { waiter.await() }
lazyLiveSessions.remove(liveId)
} catch (error: Exception) {
throw GatewayPreflightException(
error.message ?: "Hermes session initialization timed out",
)
} finally {
sessionReadyWaiters.remove(liveId, waiter)
}
}
private fun failSessionReadyWaiters(message: String) {
sessionReadyWaiters.values.forEach {
it.completeExceptionally(GatewayRpcException(message))
}
sessionReadyWaiters.clear()
}
private fun createListener(ready: CompletableDeferred<Unit>) = object : WebSocketListener() {
@@ -3631,6 +3689,33 @@ class GatewayChatClient(
return
}
// Lazy create/resume returns before its AIAgent exists. The deferred
// build publishes exact-session session.info when it is ready. Record
// that edge before live-session routing so a fast build cannot race
// the RPC response and strand the first submit.
if (type == "session.info" && !eventSessionId.isNullOrBlank() &&
payload?.booleanField("lazy") != true
) {
readyLiveSessions += eventSessionId
sessionReadyWaiters.remove(eventSessionId)?.complete(Unit)
}
// Deferred agent construction can fail after lazy session.create/
// resume returns but before prompt.submit. Fail the readiness barrier
// immediately so the optimistic prompt remains retryable/Not sent
// instead of waiting for the five-minute readiness timeout.
if (type == "error" && !eventSessionId.isNullOrBlank() &&
(eventSessionId in lazyLiveSessions || sessionReadyWaiters.containsKey(eventSessionId))
) {
val message = payload?.stringField("message")
?: "Hermes session initialization failed"
lazyLiveSessions.remove(eventSessionId)
readyLiveSessions.remove(eventSessionId)
sessionReadyWaiters.remove(eventSessionId)
?.completeExceptionally(GatewayRpcException(message))
return
}
// Upstream emits session.reclaimed process-wide, so it is identified
// by payload rather than params.session_id. Retire only an exact live
// runtime we own; preserve the durable id so the next send resumes it.
@@ -3945,6 +4030,7 @@ class GatewayChatClient(
// id on the shared gateway stream) keeps matching after reconnect.
val preservedLiveId = liveSessionId
webSocket = null
connectedSocketProfile = null
readySignal = null
liveSessionId = null
attachMethodForSocket = null
@@ -3958,6 +4044,9 @@ class GatewayChatClient(
it.completeExceptionally(GatewayRpcException("gateway connection lost"))
}
pendingRpcs.clear()
failSessionReadyWaiters("gateway connection lost")
lazyLiveSessions.clear()
readyLiveSessions.clear()
failChildWatches("Child watch disconnected from the gateway")
val turn = activeTurn
if (turn == null) {
@@ -4133,8 +4222,12 @@ class GatewayChatClient(
private fun closeSocket(reason: String) {
webSocket?.close(1000, reason)
webSocket = null
connectedSocketProfile = null
readySignal = null
liveSessionId = null
failSessionReadyWaiters("gateway socket closed")
lazyLiveSessions.clear()
readyLiveSessions.clear()
attachMethodForSocket = null
commandsCatalogCache = null
_processCapability.value = GatewayProcessCapability.Unknown
@@ -4811,6 +4904,9 @@ class GatewayChatClient(
onStatusClear = { kind -> dispatchIfCurrent(stillCurrent) { callbacks.onStatusClear(kind) } },
onNoticeShow = { notice -> dispatchIfCurrent(stillCurrent) { callbacks.onNoticeShow(notice) } },
onNoticeClear = { key -> dispatchIfCurrent(stillCurrent) { callbacks.onNoticeClear(key) } },
onSubmitRejected = { message ->
dispatchIfCurrent(stillCurrent) { callbacks.onSubmitRejected(message) }
},
)
private fun dispatchIfCurrent(stillCurrent: () -> Boolean, callback: () -> Unit) {
@@ -196,7 +196,8 @@ class GatewayEventMapper(
"tool.start" -> {
clearActivityStatuses()
val name = payload.string("name") ?: "unknown"
val identity = payload.effectiveToolIdentity()
val name = identity.name
// A pending generating placeholder for this name is adopted
// (consumed FIFO) whether or not the server sent a real id.
val adopted = generatingIdsByName[name]?.removeFirstOrNull()
@@ -208,7 +209,7 @@ class GatewayEventMapper(
}
else -> syntheticToolId(name)
}
val argsPreview = payload?.get("args")
val argsPreview = identity.argsPreview ?: payload?.get("args")
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
@@ -220,7 +221,7 @@ class GatewayEventMapper(
"tool.complete" -> {
clearActivityStatuses()
val name = payload.string("name") ?: "unknown"
val name = payload.effectiveToolIdentity().name
val toolId = payload.string("tool_id")
?: openSyntheticIdsByName[name]?.removeFirstOrNull()
?: return
@@ -279,7 +280,12 @@ class GatewayEventMapper(
"error" -> {
turnEnded = true
callbacks.onError(payload.string("message") ?: "Gateway error")
val message = payload.string("message") ?: "Gateway error"
if (isSessionOwnershipRejection(message)) {
callbacks.onSubmitRejected(message)
} else {
callbacks.onError(message)
}
}
"subagent.spawn_requested", "subagent.start", "subagent.thinking", "subagent.tool",
@@ -469,6 +475,19 @@ class GatewayEventMapper(
private const val MAX_MOA_REFERENCE_CHARS = 16_000
private val OUTPUT_RISK_LEVELS = setOf("low", "medium", "high", "critical")
private val TERMINAL_EVENTS = setOf("message.complete", "error")
/**
* Isolated-turn paths can acknowledge `prompt.submit` and then emit
* the ownership refusal as a plain terminal `error` event. That event
* has no JSON-RPC code or structured reason, so match both stable
* clauses from upstream's canonical message.
*/
internal fun isSessionOwnershipRejection(message: String): Boolean {
val normalized = message.lowercase()
return "already has a live owner (" in normalized &&
"only one surface at a time may run a session" in normalized
}
internal fun isFailedMoaReference(text: String): Boolean {
val normalized = text.trimStart().lowercase()
return normalized.startsWith("[failed:") || normalized.startsWith("[skipped:")
@@ -609,6 +628,34 @@ private const val MAX_CLARIFY_CHOICES = 4
private const val SUDO_TIMEOUT_SECONDS = 120
private const val SECRET_TIMEOUT_SECONDS = 300
private data class GatewayToolIdentity(
val name: String,
val argsPreview: String?,
)
/**
* Older Tool Search gateways can expose the model-visible `tool_call` bridge
* instead of the effective tool identity that current upstream callbacks use.
* Unwrap only the bridge's explicit structured `{name, arguments}` envelope;
* never infer a tool from prompt text or result content.
*/
private fun JsonObject?.effectiveToolIdentity(): GatewayToolIdentity {
val outerName = string("name") ?: "unknown"
val outerArgs = this?.get("args") as? JsonObject
if (outerName != "tool_call" || outerArgs == null) {
return GatewayToolIdentity(outerName, null)
}
val effectiveName = outerArgs.string("name")
?.trim()
?.takeIf { it.isNotEmpty() }
?: return GatewayToolIdentity(outerName, null)
val effectiveArgs = outerArgs["arguments"]
?.takeUnless { it is JsonPrimitive && it.contentOrNull.isNullOrBlank() }
?.toString()
?.takeIf { it.isNotBlank() && it != "null" }
return GatewayToolIdentity(effectiveName, effectiveArgs)
}
private fun JsonObject?.string(key: String): String? =
(this?.get(key) as? JsonPrimitive)?.contentOrNull
@@ -741,6 +741,12 @@ class GatewayTurnCallbacks(
val onNoticeShow: (GatewayAgentNotice) -> Unit = { _ -> },
/** Exact-key dismissal for an upstream notice. */
val onNoticeClear: (key: String) -> Unit = { _ -> },
/**
* The Gateway authoritatively refused `prompt.submit` before a model turn
* began. The composed user row remains local and retryable; callers must
* not treat this as a dropped stream or reconcile it from history.
*/
val onSubmitRejected: (String) -> Unit = onError,
)
/**
@@ -726,10 +726,10 @@ class HermesApiClient(
suspend fun getMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): List<MessageItem> = withContext(Dispatchers.IO) {
loadSessionMessages(mode) { page ->
runCatching {
try {
val url = "$baseUrl/api/sessions/$sessionId/messages".toHttpUrlOrNull()
?.newBuilder()
?.addQueryParameter("limit", page.limit.toString())
@@ -740,14 +740,20 @@ class HermesApiClient(
val request = authRequest(url.toString()).get().build()
client.newCall(request).execute().use { response ->
if (!response.isSuccessful) error("HTTP ${response.code}")
val body = response.body?.string() ?: error("empty response body")
val body = response.body.readUtf8Bounded(
DashboardApiClient.MAX_JSON_RESPONSE_BYTES,
)
val parsed = json.decodeFromString<MessageListResponse>(body)
SessionMessagePage(
messages = parsed.data ?: parsed.items ?: parsed.messages ?: emptyList(),
pagination = parsed.pagination,
payloadChars = body.length,
)
}
}.let { Result.success(it) }
} catch (error: CancellationException) {
throw error
} catch (error: Exception) {
Result.failure(error)
}
}.getOrElse { error ->
if (error is CancellationException) throw error
@@ -72,7 +72,7 @@ internal suspend fun loadSessionMessages(
Result.success(collected)
} catch (error: CancellationException) {
throw error
} catch (error: Throwable) {
} catch (error: Exception) {
Result.failure(error)
}
}
@@ -195,7 +195,7 @@ class StandardHermesVoiceClient(
.let { Result.success<VoiceSpeechStream?>(it) }
} catch (cancelled: CancellationException) {
throw cancelled
} catch (error: Throwable) {
} catch (error: Exception) {
Result.failure(error)
}
}
@@ -222,7 +222,9 @@ class StandardHermesVoiceClient(
if (!response.isSuccessful) {
return Result.failure(apiFailure(response, operation))
}
val body = response.body.string()
val body = response.body.readUtf8Bounded(
DashboardApiClient.MAX_JSON_RESPONSE_BYTES,
)
if (body.isBlank()) {
return Result.failure(IOException("$operation returned an empty response"))
}
@@ -245,7 +247,11 @@ class StandardHermesVoiceClient(
}
private fun apiFailure(response: Response, operation: String): IOException {
val body = runCatching { response.body.string() }.getOrDefault("")
val body = try {
response.body.readUtf8Bounded(4L * 1024L)
} catch (_: Exception) {
""
}
val detail = body.takeIf { it.isNotBlank() } ?: response.message
val message = when (response.code) {
400 -> "$operation rejected that input - ${detail.ifBlank { "bad request" }}"
@@ -0,0 +1,40 @@
package com.hermesandroid.relay.ui
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
/** Width policy shared by Chat's content and persistent status surfaces. */
internal data class ChatResponsiveLayout(
val introMaxWidth: Dp?,
val avatarSize: Dp?,
val chromeMaxWidth: Dp?,
val transcriptMaxWidth: Dp?,
val focusVoiceMaxWidth: Dp?,
)
internal fun chatResponsiveLayout(screenWidthDp: Int): ChatResponsiveLayout = when {
screenWidthDp >= 840 -> ChatResponsiveLayout(
introMaxWidth = 720.dp,
avatarSize = 360.dp,
chromeMaxWidth = 960.dp,
transcriptMaxWidth = 960.dp,
focusVoiceMaxWidth = 1120.dp,
)
screenWidthDp >= 600 -> ChatResponsiveLayout(
introMaxWidth = 600.dp,
avatarSize = 300.dp,
chromeMaxWidth = 760.dp,
transcriptMaxWidth = 760.dp,
focusVoiceMaxWidth = 760.dp,
)
else -> ChatResponsiveLayout(
introMaxWidth = null,
avatarSize = null,
chromeMaxWidth = null,
transcriptMaxWidth = null,
focusVoiceMaxWidth = null,
)
}
internal fun useSplitVoiceLayout(screenWidthDp: Int, screenHeightDp: Int): Boolean =
screenWidthDp >= 840 && screenWidthDp > screenHeightDp
@@ -117,6 +117,7 @@ import com.hermesandroid.relay.ui.components.pet.PetSafeAreaRegistry
import com.hermesandroid.relay.ui.components.pet.petPerchSurface
import com.hermesandroid.relay.ui.components.pet.platformModalOwnsPetLayer
import com.hermesandroid.relay.ui.components.ConnectionSwitcherSheet
import com.hermesandroid.relay.ui.components.ChatMediaViewerHost
import com.hermesandroid.relay.ui.components.ChatTransportStatusBadge
import com.hermesandroid.relay.ui.components.ChatTransportTier
import com.hermesandroid.relay.ui.components.ConnectionSecurityGlyph
@@ -2200,6 +2201,9 @@ fun RelayApp() {
// Routine in-progress reconnect surfaces here (amber cue)
// instead of a take-space banner or a floating toast.
reconnecting = connectionReconnecting,
maxContentWidth = chatResponsiveLayout(
LocalConfiguration.current.screenWidthDp,
).chromeMaxWidth,
modifier = Modifier.petPerchSurface(
key = APP_STATUS_PET_WALK_REGION,
routes = APP_STATUS_PET_ROUTES,
@@ -2472,103 +2476,110 @@ fun RelayApp() {
val screenChatLabel = stringResource(R.string.screen_chat_label)
ChatScreen(
chatViewModel = chatViewModel,
connectionViewModel = connectionViewModel,
voiceViewModel = voiceViewModel,
voiceClient = voiceClient,
maxBubbleWidth = maxBubbleWidth,
voicePresentationMode = voicePresentationMode,
onVoicePresentationModeChange = { mode ->
connectionSwitchScope.launch {
voicePreferences.setPresentationMode(mode)
}
},
openAgentSheetOnEntry = openAgentSheetArg,
onAgentSheetArgConsumed = {
backStackEntry.arguments?.putBoolean(
Screen.Chat.ARG_OPEN_AGENT_SHEET, false,
)
},
// AgentInfoSheet footer jumps straight into the full
// Connections CRUD screen — saves a detour through
// Settings → Gateways.
onNavigateToConnections = {
navController.navigate(Screen.ConnectionsSettings.route)
},
onNavigateToConnect = {
navController.navigate(Screen.Pair.route()) {
launchSingleTop = true
}
},
onRepairConnection = {
navController.navigate(
Screen.Pair.route(
connectionId = activeConnectionId,
autoStart = "relay",
),
) {
launchSingleTop = true
}
},
// Empty-chat "needs connection" card also offers the offline
// demo, so a skipped / never-connected first run can explore
// without leaving Chat. Safe here — this state only shows when
// nothing is configured, so there's no placeholder in flight.
onTryDemo = enterDemo,
onNavigateToDashboardSignIn = {
navController.navigate(Screen.DashboardSignIn.route()) {
launchSingleTop = true
}
},
onNavigateToBridge = {
rememberBridgeReturn(
route = Screen.Chat.route(openAgentSheet = false),
label = screenChatLabel,
)
navController.navigate(Screen.Bridge.route) {
popUpTo(navController.graph.findStartDestination().id) {
saveState = true
ChatMediaViewerHost(
activeConnectionId,
effectiveSessionProfileName,
currentChatSessionId,
chatSupervisedPolicy,
) {
ChatScreen(
chatViewModel = chatViewModel,
connectionViewModel = connectionViewModel,
voiceViewModel = voiceViewModel,
voiceClient = voiceClient,
maxBubbleWidth = maxBubbleWidth,
voicePresentationMode = voicePresentationMode,
onVoicePresentationModeChange = { mode ->
connectionSwitchScope.launch {
voicePreferences.setPresentationMode(mode)
}
launchSingleTop = true
restoreState = true
}
},
onNavigateToTerminal = {
navController.navigate(Screen.Terminal.route) {
launchSingleTop = true
}
},
onNavigateToSettings = {
navController.navigate(Screen.Settings.route) {
launchSingleTop = true
}
},
onNavigateToAppearanceSettings = {
navController.navigate(Screen.AppearanceSettings.route) {
launchSingleTop = true
}
},
onNavigateToVoiceSettings = {
navController.navigate(Screen.VoiceSettings.route) {
launchSingleTop = true
}
},
onNavigateToProfileInspector = { profileName ->
navController.navigate(Screen.ProfileInspector.route(profileName)) {
launchSingleTop = true
}
},
supervisedPolicy = chatSupervisedPolicy,
onNavigateToBotMode = {
navController.navigate(Screen.BotMode.route) { launchSingleTop = true }
},
gitWorkspaceAvailable = gitWorkspaceAvailable,
gitWorkspaceSummary = gitWorkspaceSummary,
onNavigateToGitWorkspace = {
navController.navigate(Screen.GitState.route) { launchSingleTop = true }
},
)
},
openAgentSheetOnEntry = openAgentSheetArg,
onAgentSheetArgConsumed = {
backStackEntry.arguments?.putBoolean(
Screen.Chat.ARG_OPEN_AGENT_SHEET, false,
)
},
// AgentInfoSheet footer jumps straight into the full
// Connections CRUD screen — saves a detour through
// Settings → Gateways.
onNavigateToConnections = {
navController.navigate(Screen.ConnectionsSettings.route)
},
onNavigateToConnect = {
navController.navigate(Screen.Pair.route()) {
launchSingleTop = true
}
},
onRepairConnection = {
navController.navigate(
Screen.Pair.route(
connectionId = activeConnectionId,
autoStart = "relay",
),
) {
launchSingleTop = true
}
},
// Empty-chat "needs connection" card also offers the offline
// demo, so a skipped / never-connected first run can explore
// without leaving Chat. Safe here — this state only shows when
// nothing is configured, so there's no placeholder in flight.
onTryDemo = enterDemo,
onNavigateToDashboardSignIn = {
navController.navigate(Screen.DashboardSignIn.route()) {
launchSingleTop = true
}
},
onNavigateToBridge = {
rememberBridgeReturn(
route = Screen.Chat.route(openAgentSheet = false),
label = screenChatLabel,
)
navController.navigate(Screen.Bridge.route) {
popUpTo(navController.graph.findStartDestination().id) {
saveState = true
}
launchSingleTop = true
restoreState = true
}
},
onNavigateToTerminal = {
navController.navigate(Screen.Terminal.route) {
launchSingleTop = true
}
},
onNavigateToSettings = {
navController.navigate(Screen.Settings.route) {
launchSingleTop = true
}
},
onNavigateToAppearanceSettings = {
navController.navigate(Screen.AppearanceSettings.route) {
launchSingleTop = true
}
},
onNavigateToVoiceSettings = {
navController.navigate(Screen.VoiceSettings.route) {
launchSingleTop = true
}
},
onNavigateToProfileInspector = { profileName ->
navController.navigate(Screen.ProfileInspector.route(profileName)) {
launchSingleTop = true
}
},
supervisedPolicy = chatSupervisedPolicy,
onNavigateToBotMode = {
navController.navigate(Screen.BotMode.route) { launchSingleTop = true }
},
gitWorkspaceAvailable = gitWorkspaceAvailable,
gitWorkspaceSummary = gitWorkspaceSummary,
onNavigateToGitWorkspace = {
navController.navigate(Screen.GitState.route) { launchSingleTop = true }
},
)
}
}
composable(Screen.BotMode.route) {
BotModeScreen(
@@ -31,6 +31,7 @@ import androidx.compose.runtime.mutableStateMapOf
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
@@ -128,10 +129,11 @@ fun AttachmentGallery(
val exportAllowed = LocalImageExportAllowed.current
val scope = rememberCoroutineScope()
val blurMode = LocalMediaBlurMode.current
val viewerController = LocalChatMediaViewerController.current
val revealed = remember { mutableStateMapOf<String, Boolean>() }
var viewerStartIndex by remember { mutableStateOf<Int?>(null) }
var viewerStartIndex by rememberSaveable { mutableStateOf<Int?>(null) }
viewerStartIndex?.let { startIndex ->
viewerStartIndex?.takeIf { viewerController == null }?.let { startIndex ->
AttachmentGalleryViewer(
attachments = attachments,
initialIndex = startIndex.coerceIn(attachments.indices),
@@ -184,7 +186,21 @@ fun AttachmentGallery(
.testTag("attachment-gallery-tile-$galleryIndex")
.clip(RoundedCornerShape(GALLERY_CORNER))
.combinedClickable(
onClick = { viewerStartIndex = galleryIndex },
onClick = {
if (viewerController != null) {
viewerController.openGallery(
attachments = attachments,
initialIndex = galleryIndex,
initiallyRevealedKeys = revealed
.filterValues { it }
.keys,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerStartIndex = galleryIndex
}
},
onLongClick = { menuExpanded = true },
),
)
@@ -9,7 +9,6 @@ import android.media.audiofx.Visualizer
import android.net.Uri
import android.os.Build
import android.os.ParcelFileDescriptor
import android.view.SurfaceView
import android.widget.Toast
import androidx.annotation.OptIn
import androidx.compose.foundation.Image
@@ -63,10 +62,12 @@ import androidx.compose.runtime.Composable
import androidx.compose.runtime.DisposableEffect
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableLongStateOf
import androidx.compose.runtime.mutableStateMapOf
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import androidx.compose.ui.Alignment
@@ -86,13 +87,13 @@ import androidx.compose.ui.platform.testTag
import androidx.compose.ui.text.font.FontFamily
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.IntSize
import androidx.compose.ui.viewinterop.AndroidView
import androidx.compose.ui.window.Dialog
import androidx.compose.ui.window.DialogProperties
import androidx.media3.common.MediaItem
import androidx.media3.common.Player
import androidx.media3.common.util.UnstableApi
import androidx.media3.exoplayer.ExoPlayer
import androidx.media3.ui.compose.ContentFrame
import coil3.compose.AsyncImage
import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.AttachmentRenderMode
@@ -290,7 +291,7 @@ fun Modifier.zoomable(maxScale: Float = 6f): Modifier {
* Dispatches on [Attachment.renderMode]:
* - IMAGE → zoomable image (Coil from the cached URI, or a decoded bitmap),
* honoring the sensitive blur gate.
* - VIDEO → ExoPlayer on a hand-wired [SurfaceView] with transport controls.
* - VIDEO → ExoPlayer through Media3's lifecycle-aware Compose content frame.
* - AUDIO → ExoPlayer mini-player with scrubber + a Visualizer amplitude meter.
* - PDF → [PdfRenderer] paginated pages in a LazyColumn.
* - TEXT → in-app monospace text viewer.
@@ -384,7 +385,8 @@ fun AttachmentViewer(
Box(
modifier = modifier
.fillMaxSize()
.background(Color.Black.copy(alpha = 0.96f)),
.background(Color.Black.copy(alpha = 0.96f))
.testTag("attachment-viewer"),
) {
// Body fills; toolbar floats on top. PDF/TEXT add their own top
// inset so the first line clears the toolbar.
@@ -737,17 +739,27 @@ private fun VideoBody(attachment: Attachment) {
return
}
var savedPosition by rememberSaveable(uri.toString()) { mutableLongStateOf(0L) }
var wantsToPlay by rememberSaveable(uri.toString()) { mutableStateOf(true) }
var muted by rememberSaveable(uri.toString()) { mutableStateOf(false) }
val player = remember(uri) {
ExoPlayer.Builder(context).build().apply {
setMediaItem(MediaItem.fromUri(uri))
if (savedPosition > 0L) seekTo(savedPosition)
playWhenReady = wantsToPlay
volume = if (muted) 0f else 1f
prepare()
playWhenReady = true
}
}
DisposableEffect(player) { onDispose { player.release() } }
DisposableEffect(player) {
onDispose {
savedPosition = player.currentPosition.coerceAtLeast(0L)
wantsToPlay = player.playWhenReady
player.release()
}
}
var isPlaying by remember { mutableStateOf(true) }
var muted by remember { mutableStateOf(false) }
var isPlaying by remember { mutableStateOf(player.isPlaying) }
var position by remember { mutableStateOf(0L) }
var duration by remember { mutableStateOf(0L) }
@@ -761,24 +773,30 @@ private fun VideoBody(attachment: Attachment) {
LaunchedEffect(player) {
while (true) {
position = player.currentPosition.coerceAtLeast(0L)
savedPosition = position
duration = player.duration.takeIf { it > 0L } ?: 0L
delay(250)
}
}
Column(modifier = Modifier.fillMaxSize(), verticalArrangement = Arrangement.Center) {
AndroidView(
factory = { ctx ->
SurfaceView(ctx).also { player.setVideoSurfaceView(it) }
},
modifier = Modifier.fillMaxWidth().weight(1f, fill = false).aspectRatio(16f / 9f),
)
Box(
modifier = Modifier.fillMaxWidth().weight(1f),
contentAlignment = Alignment.Center,
) {
ContentFrame(
player = player,
modifier = Modifier.fillMaxSize().testTag("attachment-video-content"),
contentScale = ContentScale.Fit,
)
}
PlaybackControls(
isPlaying = isPlaying,
position = position,
duration = duration,
onPlayPause = {
if (player.isPlaying) player.pause() else player.play()
wantsToPlay = !player.playWhenReady
player.playWhenReady = wantsToPlay
},
onSeek = { player.seekTo(it) },
trailing = {
@@ -0,0 +1,215 @@
package com.hermesandroid.relay.ui.components
import androidx.activity.compose.BackHandler
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.core.tween
import androidx.compose.animation.expandVertically
import androidx.compose.animation.shrinkVertically
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
import androidx.compose.animation.slideInVertically
import androidx.compose.animation.slideOutVertically
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.selection.selectable
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Close
import androidx.compose.material.icons.filled.Check
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material.icons.filled.ExpandLess
import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.setValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.res.pluralStringResource
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.unit.dp
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.zIndex
import com.hermesandroid.relay.ui.theme.appearanceTopRoundedCornerShape
import com.hermesandroid.relay.R
import com.hermesandroid.relay.data.BusyMessageAction
private val COMPOSER_TRAY_UNDERLAP = 12.dp
/** A separate rear surface tucked beneath the composer's foreground edge. */
@Composable
fun ChatComposerLayers(
action: BusyMessageAction?,
onActionChange: (BusyMessageAction) -> Unit,
correctionAvailable: Boolean,
onStop: (() -> Unit)?,
modifier: Modifier = Modifier,
content: @Composable () -> Unit,
) {
Column(
modifier = modifier.fillMaxWidth(),
verticalArrangement = Arrangement.spacedBy(-COMPOSER_TRAY_UNDERLAP),
) {
if (action != null) {
ChatBusyActionSelector(
action, onActionChange,
correctionAvailable = correctionAvailable,
onStop = onStop,
bottomUnderlap = COMPOSER_TRAY_UNDERLAP,
modifier = Modifier.fillMaxWidth().padding(horizontal = 20.dp).zIndex(0f),
)
}
Box(Modifier.fillMaxWidth().zIndex(1f).testTag("chatComposerForeground")) { content() }
}
}
/** Compact current intent; optional plain-text choices slide out from behind it. */
@Composable
fun ChatBusyActionSelector(
action: BusyMessageAction,
onActionChange: (BusyMessageAction) -> Unit,
modifier: Modifier = Modifier,
correctionAvailable: Boolean = true,
onStop: (() -> Unit)? = null,
bottomUnderlap: Dp = 0.dp,
) {
var expanded by remember { mutableStateOf(false) }
BackHandler(enabled = expanded) { expanded = false }
Surface(
modifier = modifier.testTag("chatBusyActionTray"),
color = MaterialTheme.colorScheme.surfaceContainerLow.copy(alpha = 0.82f),
shape = appearanceTopRoundedCornerShape(12.dp),
tonalElevation = 0.dp,
) {
Column(Modifier.padding(bottom = bottomUnderlap)) {
AnimatedVisibility(
visible = expanded,
enter = expandVertically(tween(220), expandFrom = Alignment.Bottom) +
slideInVertically(tween(220)) { it } + fadeIn(tween(160)),
exit = shrinkVertically(tween(180), shrinkTowards = Alignment.Bottom) +
slideOutVertically(tween(180)) { it } + fadeOut(tween(120)),
) {
Row(
Modifier.fillMaxWidth().testTag("chatBusyActionDrawer").padding(horizontal = 8.dp),
verticalAlignment = Alignment.CenterVertically,
) {
BusyMessageAction.entries.forEach { option ->
val available = option == BusyMessageAction.QueueNext || correctionAvailable
Row(
Modifier.weight(1f).heightIn(min = 48.dp)
.testTag("chatBusyAction-${option.storedValue}")
.selectable(selected = option == action, enabled = available, role = Role.RadioButton) {
onActionChange(option)
expanded = false
}.padding(horizontal = 8.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(6.dp),
) {
if (option == action) {
Icon(Icons.Default.Check, null, Modifier.size(14.dp),
tint = MaterialTheme.colorScheme.onSurface)
} else Spacer(Modifier.size(14.dp))
Text(
stringResource(if (option == BusyMessageAction.CorrectNow) R.string.chat_correct_now else R.string.chat_queue_next),
style = MaterialTheme.typography.labelMedium,
color = MaterialTheme.colorScheme.onSurface.copy(alpha = if (available) 1f else 0.38f),
)
}
}
}
}
Row(
Modifier.fillMaxWidth().padding(horizontal = 12.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Row(
Modifier.weight(1f).heightIn(min = 40.dp)
.testTag("chatBusyActionTrigger")
.clickable(role = Role.Button) { expanded = !expanded },
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
Text(
stringResource(if (action == BusyMessageAction.CorrectNow) R.string.chat_correct_now else R.string.chat_queue_next),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Icon(
if (expanded) Icons.Default.ExpandMore else Icons.Default.ExpandLess,
null, Modifier.size(14.dp), tint = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (onStop != null) {
IconButton(onClick = onStop) {
Icon(Icons.Default.Stop, stringResource(R.string.chat_input_stop_streaming), Modifier.size(18.dp))
}
}
}
}
}
}
@Composable
fun ChatMessageQueue(
messages: List<String>,
paused: Boolean,
onResume: () -> Unit,
onClear: () -> Unit,
onEdit: (Int) -> Unit,
onRemove: (Int) -> Unit,
canEdit: Boolean,
modifier: Modifier = Modifier,
) {
if (messages.isEmpty()) return
Column(modifier) {
Row(Modifier.fillMaxWidth(), verticalAlignment = Alignment.CenterVertically) {
Text(
if (paused) stringResource(R.string.chat_queue_paused)
else pluralStringResource(R.plurals.chat_queue_count, messages.size, messages.size),
style = MaterialTheme.typography.labelMedium,
modifier = Modifier.weight(1f),
)
if (paused) TextButton(onClick = onResume) { Text(stringResource(R.string.chat_queue_resume)) }
TextButton(onClick = onClear) { Text(stringResource(R.string.chat_clear)) }
}
Column(
Modifier.heightIn(max = 144.dp).verticalScroll(rememberScrollState()),
verticalArrangement = Arrangement.spacedBy(2.dp),
) {
messages.forEachIndexed { index, text ->
Row(Modifier.fillMaxWidth(), verticalAlignment = Alignment.CenterVertically) {
Text(
text = text,
maxLines = 2,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
style = MaterialTheme.typography.bodySmall,
modifier = Modifier.weight(1f)
.clickable(enabled = canEdit, role = Role.Button) { onEdit(index) }
.padding(vertical = 12.dp),
)
IconButton(onClick = { onRemove(index) }) {
Icon(Icons.Default.Close, stringResource(R.string.chat_queue_remove))
}
}
}
}
}
}
@@ -53,7 +53,13 @@ fun ChatFailurePanel(
Spacer(Modifier.width(10.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.chat_failure_title),
text = stringResource(
if (isInferenceUnavailableFailure(failure.rawError)) {
R.string.chat_failure_inference_unavailable
} else {
R.string.chat_failure_title
},
),
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
@@ -148,3 +154,10 @@ internal fun failureIdentity(route: String, model: String?, provider: String?):
provider?.trim()?.takeIf { it.isNotEmpty() },
model?.trim()?.takeIf { it.isNotEmpty() },
).distinct().joinToString(" · ")
internal fun isInferenceUnavailableFailure(rawError: String): Boolean {
val message = rawError.lowercase()
return "agent init failed" in message ||
"no codex credentials stored" in message ||
"runtime resolution still failed" in message
}
@@ -2,6 +2,7 @@ package com.hermesandroid.relay.ui.components
import android.content.Intent
import android.graphics.BitmapFactory
import android.net.Uri
import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
@@ -29,6 +30,7 @@ import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import androidx.compose.ui.Alignment
@@ -97,9 +99,9 @@ private fun isSensitiveAltText(alt: String): Boolean {
/**
* Resolves a server-local image path — an absolute path the agent put in a
* markdown image `![alt](/abs/path)` — to raw bytes, via the relay's
* `/media/by-path` route when a relay session is paired. Returns null when no
* relay is available or the fetch fails, so the renderer falls back to the
* markdown image `![alt](/abs/path)` — to an on-disk cache URI, via the relay's
* authenticated Dashboard route (or Relay compatibility route). Returns a
* failure when no route is available or the fetch fails, so the renderer falls back to the
* "this image is on the server" notice. Provided by ChatScreen from
* [com.hermesandroid.relay.viewmodel.ChatViewModel.resolveServerImage]; the
* default is null, which preserves the standard (no-plugin) behavior where a
@@ -113,12 +115,12 @@ private fun isSensitiveAltText(alt: String): Boolean {
* `RelayServerImage` on app open with a server-local image in history).
*/
sealed interface ServerImageResult {
class Success(val bytes: ByteArray, val sensitive: Boolean = false) : ServerImageResult
class Success(val cachedUri: String, val sensitive: Boolean = false) : ServerImageResult
class Failure(val reason: String) : ServerImageResult
}
fun interface RelayServerImageResolver {
/** Fetch the server-local file's bytes over the relay, or a
/** Fetch the server-local file into the media cache, or a
* [ServerImageResult.Failure] whose reason explains why (unpaired /
* sandboxed / missing / decode) so the UI can surface it instead of a
* generic placeholder. */
@@ -293,8 +295,10 @@ private sealed interface DataUrlImagePhase {
@Composable
private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
var phase by remember(image.src) { mutableStateOf<DataUrlImagePhase>(DataUrlImagePhase.Loading) }
var viewerOpen by remember(image.src) { mutableStateOf(false) }
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
LaunchedEffect(image.src) {
phase = withInlineImageDecodeLock {
@@ -329,17 +333,17 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
reason = "Unsupported or oversized inline image.",
)
is DataUrlImagePhase.Loaded -> {
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Bitmap(
bitmap = current.bitmap,
displayName = image.alt.ifBlank { "image" },
mime = current.mime,
// Decode the already-retained data URL only when the user
// requests Save/Share; don't retain a second byte array.
bytesProvider = { decodeInlineImageDataUrlOffMain(image.src)?.bytes },
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Bitmap(
bitmap = current.bitmap,
displayName = image.alt.ifBlank { "image" },
mime = current.mime,
// Decode the already-retained data URL only when the
// user requests Save/Share; don't keep a second 5 MiB
// byte array beside every thumbnail.
bytesProvider = { decodeInlineImageDataUrlOffMain(image.src)?.bytes },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = image.sensitive,
initiallyRevealed = revealed,
@@ -358,7 +362,19 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = image.sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
)
}
}
@@ -368,18 +384,21 @@ private fun DataUrlChatImage(image: ChatInlineImage, maxWidth: Dp) {
@Composable
private fun RemoteChatImage(image: ChatInlineImage, maxWidth: Dp) {
var viewerOpen by remember { mutableStateOf(false) }
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
val blurred = !revealed && shouldBlurImage(blurMode, image.sensitive)
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Coil(
model = image.src,
displayName = image.alt.ifBlank { "image" },
mime = "image/*",
bytesProvider = { MediaSaver.fetchRemoteBytes(image.src).first },
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Coil(
model = image.src,
displayName = image.alt.ifBlank { "image" },
mime = "image/*",
bytesProvider = { MediaSaver.fetchRemoteBytes(image.src).first },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = image.sensitive,
initiallyRevealed = revealed,
@@ -395,7 +414,19 @@ private fun RemoteChatImage(image: ChatInlineImage, maxWidth: Dp) {
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = image.sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
) {
val state by painter.state.collectAsState()
when (state) {
@@ -461,6 +492,7 @@ private fun RelayServerImage(
maxWidth: Dp,
resolver: RelayServerImageResolver,
) {
val context = LocalContext.current
var phase by remember(image.src) {
mutableStateOf<RelayImagePhase>(
cachedInlineImage(image.src)
@@ -473,20 +505,22 @@ private fun RelayServerImage(
phase = withContext(Dispatchers.IO) {
val result = try {
resolver.fetch(image.src)
} catch (t: Throwable) {
ServerImageResult.Failure(t.message ?: "relay fetch failed")
} catch (error: Exception) {
ServerImageResult.Failure(error.message ?: "relay fetch failed")
}
when (result) {
is ServerImageResult.Success -> {
val bytes = result.bytes
val bmp = runCatching {
decodeOrientedBitmap(bytes)
}.getOrNull()?.asImageBitmap()
val cachedUri = Uri.parse(result.cachedUri)
val bmp = try {
decodeBoundedOrientedBitmap(context, cachedUri)
} catch (_: Exception) {
null
}?.asImageBitmap()
if (bmp != null) {
putInlineImage(image.src, bmp, result.sensitive)
RelayImagePhase.Loaded(bmp, result.sensitive)
} else {
RelayImagePhase.Failed("fetched ${bytes.size} B but couldn't decode the image")
RelayImagePhase.Failed("fetched file could not be decoded as an image")
}
}
is ServerImageResult.Failure -> RelayImagePhase.Failed(result.reason)
@@ -527,23 +561,32 @@ private fun RelayServerImageContent(
maxWidth: Dp,
resolver: RelayServerImageResolver,
) {
var viewerOpen by remember { mutableStateOf(false) }
val context = LocalContext.current
var viewerOpen by rememberSaveable(image.src) { mutableStateOf(false) }
val blurMode = LocalMediaBlurMode.current
val exportAllowed = LocalImageExportAllowed.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(image.src) { mutableStateOf(false) }
val sensitive = image.sensitive || fetchedSensitive
val blurred = !revealed && shouldBlurImage(blurMode, sensitive)
if (viewerOpen) {
val viewerSource = ChatImageViewerSource.Bitmap(
bitmap = bitmap,
displayName = image.alt.ifBlank {
image.src.substringAfterLast('/').ifBlank { "image" }
},
mime = "image/*",
// Save/Share re-fetch the original bytes on demand so we don't hold
// them in memory next to the decoded bitmap.
bytesProvider = {
(resolver.fetch(image.src) as? ServerImageResult.Success)?.let { fetched ->
context.contentResolver.openInputStream(Uri.parse(fetched.cachedUri))
?.use { it.readBytes() }
}
},
)
if (viewerController == null && viewerOpen) {
ChatImageViewer(
source = ChatImageViewerSource.Bitmap(
bitmap = bitmap,
displayName = image.alt.ifBlank {
image.src.substringAfterLast('/').ifBlank { "image" }
},
mime = "image/*",
// Save/Share re-fetch the original bytes on demand so we don't
// hold them in memory next to the decoded bitmap.
bytesProvider = { (resolver.fetch(image.src) as? ServerImageResult.Success)?.bytes },
),
source = viewerSource,
onDismiss = { viewerOpen = false },
sensitive = sensitive,
initiallyRevealed = revealed,
@@ -559,7 +602,19 @@ private fun RelayServerImageContent(
.widthIn(max = maxWidth)
.heightIn(max = 360.dp)
.clip(RoundedCornerShape(12.dp))
.clickable { viewerOpen = true },
.clickable {
if (viewerController != null) {
viewerController.openImage(
source = viewerSource,
sensitive = sensitive,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
)
}
}
@@ -170,7 +170,11 @@ fun ChatImageViewer(
onClick = {
scope.launch {
busy = true
val bytes = runCatching { source.bytesProvider() }.getOrNull()
val bytes = try {
source.bytesProvider()
} catch (_: Exception) {
null
}
busy = false
if (bytes == null) {
toast(context, errorMsg)
@@ -195,7 +199,11 @@ fun ChatImageViewer(
onClick = {
scope.launch {
busy = true
val bytes = runCatching { source.bytesProvider() }.getOrNull()
val bytes = try {
source.bytesProvider()
} catch (_: Exception) {
null
}
if (bytes == null) {
busy = false
toast(context, errorMsg)
@@ -1,5 +1,6 @@
package com.hermesandroid.relay.ui.components
import com.hermesandroid.relay.data.BusyMessageAction
import androidx.compose.animation.AnimatedContent
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.core.tween
@@ -191,6 +192,9 @@ fun ChatInputBar(
physicalEnterSends: Boolean = true,
largePasteThreshold: Int? = null,
onLargePaste: (String) -> Unit = {},
busyAction: BusyMessageAction? = null,
correctionAvailable: Boolean = true,
onBusyActionChange: (BusyMessageAction) -> Unit = {},
) {
val canSubmit = enabled && submitEnabled && trailing in setOf(
ChatInputTrailing.SEND,
@@ -236,7 +240,7 @@ fun ChatInputBar(
// Correction and queueing are materially different actions. Keep the
// explanation, but lead with a visible state pill so the distinction
// does not depend on the trailing icon or accent color alone.
AnimatedVisibility(visible = caption != null) {
AnimatedVisibility(visible = caption != null && busyAction == null) {
val detail = caption ?: lastCaption.orEmpty()
val actionLabel = when (trailing) {
ChatInputTrailing.STEER -> stringResource(R.string.chat_input_steer_response)
@@ -319,6 +323,12 @@ fun ChatInputBar(
)
}
ChatComposerLayers(
action = busyAction,
onActionChange = onBusyActionChange,
correctionAvailable = correctionAvailable,
onStop = onStop.takeUnless { trailing == ChatInputTrailing.STOP },
) {
Surface(
shape = appearanceComposerShape(),
color = MaterialTheme.colorScheme.surfaceContainerHigh,
@@ -646,6 +656,7 @@ fun ChatInputBar(
}
}
}
}
internal data class LargeTextInsertion(
val insertedText: String,
@@ -0,0 +1,146 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.runtime.Composable
import androidx.compose.runtime.CompositionLocalProvider
import androidx.compose.runtime.Stable
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.runtime.staticCompositionLocalOf
import com.hermesandroid.relay.data.Attachment
import com.hermesandroid.relay.data.BlurMode
private sealed interface ChatMediaViewerRequest {
val blurMode: BlurMode
val exportAllowed: Boolean
data class SingleAttachment(
val attachment: Attachment,
val initiallyRevealed: Boolean,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
data class AttachmentGallery(
val attachments: List<Attachment>,
val initialIndex: Int,
val initiallyRevealedKeys: Set<String>,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
data class InlineImage(
val source: ChatImageViewerSource,
val sensitive: Boolean,
val initiallyRevealed: Boolean,
override val blurMode: BlurMode,
override val exportAllowed: Boolean,
) : ChatMediaViewerRequest
}
@Stable
internal class ChatMediaViewerController {
private var activeRequest by mutableStateOf<ChatMediaViewerRequest?>(null)
internal fun openAttachment(
attachment: Attachment,
initiallyRevealed: Boolean,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.SingleAttachment(
attachment = attachment,
initiallyRevealed = initiallyRevealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun openGallery(
attachments: List<Attachment>,
initialIndex: Int,
initiallyRevealedKeys: Set<String>,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.AttachmentGallery(
attachments = attachments,
initialIndex = initialIndex,
initiallyRevealedKeys = initiallyRevealedKeys,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun openImage(
source: ChatImageViewerSource,
sensitive: Boolean,
initiallyRevealed: Boolean,
blurMode: BlurMode,
exportAllowed: Boolean,
) {
activeRequest = ChatMediaViewerRequest.InlineImage(
source = source,
sensitive = sensitive,
initiallyRevealed = initiallyRevealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
}
internal fun dismiss() {
activeRequest = null
}
@Composable
internal fun RenderActiveViewer() {
val request = activeRequest ?: return
CompositionLocalProvider(
LocalMediaBlurMode provides request.blurMode,
LocalImageExportAllowed provides request.exportAllowed,
) {
when (request) {
is ChatMediaViewerRequest.SingleAttachment -> AttachmentViewer(
attachment = request.attachment,
onDismiss = ::dismiss,
initiallyRevealed = request.initiallyRevealed,
)
is ChatMediaViewerRequest.AttachmentGallery -> AttachmentGalleryViewer(
attachments = request.attachments,
initialIndex = request.initialIndex,
onDismiss = ::dismiss,
initiallyRevealedKeys = request.initiallyRevealedKeys,
)
is ChatMediaViewerRequest.InlineImage -> ChatImageViewer(
source = request.source,
onDismiss = ::dismiss,
sensitive = request.sensitive,
initiallyRevealed = request.initiallyRevealed,
)
}
}
}
}
internal val LocalChatMediaViewerController =
staticCompositionLocalOf<ChatMediaViewerController?> { null }
/**
* Owns the active full-screen preview above transcript rows so responsive
* portrait/landscape reflow cannot dispose the viewer with its source bubble.
*/
@Composable
internal fun ChatMediaViewerHost(
vararg ownerKeys: Any?,
content: @Composable () -> Unit,
) {
// A preview never follows a connection/session/policy owner change. Aside
// from avoiding stale media, this makes export permission fail closed when
// supervised policy changes while a viewer is open.
val controller = remember(*ownerKeys) { ChatMediaViewerController() }
CompositionLocalProvider(LocalChatMediaViewerController provides controller) {
content()
controller.RenderActiveViewer()
}
}
@@ -73,7 +73,7 @@ private const val SWIPE_DISMISS_THRESHOLD_PX = 80f
* progress" moment (pairing, long upload, a bridge action sequence). When first
* reused, decouple it from [ConnectionStatusSnapshot] and rename to a generic
* `StatusToast`. It also anchors [UpdateAvailableBanner]'s visual language + the
* shared [ConnectionStepRow]/[StepGlyph] helpers. See TODO.md.
* shared [ConnectionStepRow]/[StepGlyph] helpers. See docs/project/TODO.md.
*
* Rendered as a top-aligned overlay inside a `Box` — it slides down OVER the UI
* without shifting layout. Pair it with `AnimatedVisibility(enter =
@@ -14,6 +14,7 @@ import androidx.compose.foundation.Image
import androidx.compose.foundation.clickable
import androidx.compose.foundation.combinedClickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.aspectRatio
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
@@ -44,6 +45,7 @@ import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.rememberCoroutineScope
import androidx.compose.runtime.saveable.rememberSaveable
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
@@ -302,17 +304,21 @@ private fun ImageRender(
}
LaunchedEffect(attachment.cachedUri, attachment.content) {
val decoded = withContext(Dispatchers.IO) {
runCatching {
val bytes: ByteArray? = when {
try {
when {
!attachment.cachedUri.isNullOrBlank() ->
context.contentResolver.openInputStream(Uri.parse(attachment.cachedUri))
?.use { it.readBytes() }
decodeBoundedOrientedBitmap(context, Uri.parse(attachment.cachedUri))
?.asImageBitmap()
attachment.content.isNotBlank() ->
android.util.Base64.decode(attachment.content, android.util.Base64.DEFAULT)
android.util.Base64.decode(
attachment.content,
android.util.Base64.DEFAULT,
).let { decodeBoundedOrientedBitmap(it)?.asImageBitmap() }
else -> null
}
bytes?.let { decodeOrientedBitmap(it)?.asImageBitmap() }
}.getOrNull()
} catch (_: Exception) {
null
}
}
if (decoded != null) bitmap = decoded else decodeFailed = true
}
@@ -329,9 +335,14 @@ private fun ImageRender(
}
val blurMode = LocalMediaBlurMode.current
val viewerController = LocalChatMediaViewerController.current
var revealed by remember(attachment.cachedUri, attachment.content) { mutableStateOf(false) }
val blurred = !revealed && shouldBlurImage(blurMode, attachment.sensitive)
var viewerOpen by remember { mutableStateOf(false) }
var viewerOpen by rememberSaveable(
attachment.cachedUri,
attachment.relayToken,
attachment.fileName,
) { mutableStateOf(false) }
var menuExpanded by remember { mutableStateOf(false) }
val bmp = bitmap
@@ -352,7 +363,7 @@ private fun ImageRender(
return
}
if (viewerOpen) {
if (viewerController == null && viewerOpen) {
AttachmentViewer(
attachment = attachment,
onDismiss = { viewerOpen = false },
@@ -367,12 +378,25 @@ private fun ImageRender(
contentDescription = attachment.fileName,
modifier = Modifier
.widthIn(max = maxWidth)
.fillMaxWidth()
.aspectRatio(bmp.width.toFloat() / bmp.height.coerceAtLeast(1))
.clip(RoundedCornerShape(8.dp))
.combinedClickable(
onClick = { viewerOpen = true },
onClick = {
if (viewerController != null) {
viewerController.openAttachment(
attachment = attachment,
initiallyRevealed = revealed,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
onLongClick = { menuExpanded = true },
),
contentScale = ContentScale.FillWidth,
contentScale = ContentScale.Fit,
)
}
// One-tap save overlay — hidden while the blur cover is up so it
@@ -406,15 +430,20 @@ private fun FileCardRender(
val scope = rememberCoroutineScope()
val (emoji, typeLabel) = emojiAndLabelFor(attachment.renderMode, attachment.contentType)
var menuExpanded by remember { mutableStateOf(false) }
var viewerOpen by remember { mutableStateOf(false) }
var viewerOpen by rememberSaveable(
attachment.cachedUri,
attachment.relayToken,
attachment.fileName,
) { mutableStateOf(false) }
// Real thumbnail when one is cheap (video first frame, PDF first page);
// null falls back to the type emoji.
val thumbnail = rememberAttachmentThumbnail(attachment)
val blurMode = LocalMediaBlurMode.current
val viewerController = LocalChatMediaViewerController.current
val blurThumb = thumbnail != null && shouldBlurThumb(blurMode, attachment)
if (viewerOpen) {
if (viewerController == null && viewerOpen) {
// Non-image types don't blur in the viewer; open straight through.
AttachmentViewer(
attachment = attachment,
@@ -430,7 +459,18 @@ private fun FileCardRender(
.widthIn(max = maxWidth)
// Tap previews in-app; long-press surfaces Open-externally / Share / Save.
.combinedClickable(
onClick = { viewerOpen = true },
onClick = {
if (viewerController != null) {
viewerController.openAttachment(
attachment = attachment,
initiallyRevealed = true,
blurMode = blurMode,
exportAllowed = exportAllowed,
)
} else {
viewerOpen = true
}
},
onLongClick = { menuExpanded = true },
)
) {
@@ -648,7 +688,11 @@ private fun rememberAttachmentThumbnail(attachment: Attachment): ImageBitmap? {
}
LaunchedEffect(attachment.cachedUri, attachment.content, attachment.renderMode) {
thumb = withContext(Dispatchers.IO) {
runCatching { generateThumbnail(context, attachment) }.getOrNull()
try {
generateThumbnail(context, attachment)
} catch (_: Exception) {
null
}
}
}
return thumb
@@ -46,7 +46,11 @@ internal fun decodeInlineImageDataUrl(
// ceil(maxBytes / 3) * 4 plus at most two trailing padding characters.
val maxEncoded = ((maxBytes.toLong() + 2L) / 3L) * 4L
if (encoded.length.toLong() > maxEncoded) return null
val bytes = runCatching { Base64.getDecoder().decode(encoded) }.getOrNull() ?: return null
val bytes = try {
Base64.getDecoder().decode(encoded)
} catch (_: IllegalArgumentException) {
return null
}
if (bytes.isEmpty() || bytes.size > maxBytes || !matchesImageMagic(mime, bytes)) return null
return DecodedInlineImageData(bytes, mime)
}
@@ -73,7 +73,7 @@ fun MarkdownContent(
modifier: Modifier = Modifier
) {
ConfiguredMarkdownContent(
content = content,
content = markdownRenderWindow(content),
textColor = textColor,
modifier = modifier,
)
@@ -318,7 +318,7 @@ fun StreamingMarkdownContent(
var generation by remember { mutableIntStateOf(0) }
key(generation) {
NativeStreamingMarkdownGeneration(
content = content.withoutLeadingBlankLines(),
content = markdownRenderWindow(content.withoutLeadingBlankLines()),
textColor = textColor,
modifier = modifier,
onResetRequired = { generation += 1 },
@@ -353,6 +353,17 @@ private fun NativeStreamingMarkdownGeneration(
)
}
internal const val MAX_RENDERED_MARKDOWN_CHARS = 256_000
private const val MARKDOWN_TRUNCATION_NOTICE =
"\n\n---\n_Response display was shortened for Android memory safety._"
internal fun markdownRenderWindow(content: String): String =
if (content.length <= MAX_RENDERED_MARKDOWN_CHARS) {
content
} else {
content.take(MAX_RENDERED_MARKDOWN_CHARS) + MARKDOWN_TRUNCATION_NOTICE
}
internal data class StreamingMarkdownAppendPlan(
val resetRequired: Boolean,
val delta: String,
@@ -856,13 +856,13 @@ fun MessageBubble(
}
}
// Delivery status — only on agent-Thread reply bubbles (a user
// message routed over the relay proactive channel). Null on every
// ordinary chat message, which render nothing here.
// Delivery status for local user messages, including steering.
// Use the bubble's foreground: accent-on-accent hides the label.
message.deliveryStatus?.takeIf { isUser }?.let { status ->
Spacer(modifier = Modifier.height(2.dp))
MessageDeliveryIndicator(
status = status,
contentColor = textColor,
text = MessageDeliveryIndicatorText(
sending = stringResource(R.string.msg_bubble_sending),
queued = stringResource(R.string.msg_bubble_queued),
@@ -18,6 +18,7 @@ import androidx.compose.material3.minimumInteractiveComponentSize
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.Role
@@ -57,6 +58,7 @@ fun MessageDeliveryIndicator(
modifier: Modifier = Modifier,
failureMessage: String? = null,
onRetry: (() -> Unit)? = null,
contentColor: Color? = null,
) {
val retryAction = onRetry.takeIf { status == MessageDeliveryStatus.FAILED }
val retryable = retryAction != null
@@ -67,7 +69,7 @@ fun MessageDeliveryIndicator(
retryable = retryable,
)
val presentation = messageDeliveryPresentation(status)
val tint = when (presentation.colorRole) {
val tint = contentColor ?: when (presentation.colorRole) {
DeliveryColorRole.NEUTRAL -> MaterialTheme.colorScheme.onSurfaceVariant
DeliveryColorRole.ACCENT -> MaterialTheme.colorScheme.primary
DeliveryColorRole.QUEUED -> MaterialTheme.colorScheme.tertiary
@@ -11,16 +11,15 @@ import androidx.compose.ui.platform.LocalContext
/**
* Temporarily allow the device to rotate (portrait or landscape, following the
* sensor) while this composable is in the composition, overriding the app-wide
* portrait lock declared in the manifest (`MainActivity` screenOrientation).
* user's rotation preference) while this composable is in the composition,
* overriding the app-wide portrait lock declared in the manifest
* (`MainActivity` screenOrientation).
* Restores the previous orientation (portrait) when it leaves the composition.
*
* Used by the full-screen media viewers ([ChatImageViewer], [AttachmentViewer])
* so wide images and video can be viewed in landscape while the rest of the app
* stays portrait-locked. Uses `SENSOR` (portrait + both landscapes, no
* upside-down) so the viewer rotates with the device regardless of the system
* auto-rotate toggle; swap to `SCREEN_ORIENTATION_USER` to instead respect that
* toggle.
* stays portrait-locked. Uses `USER` so the viewer follows the device only when
* the user has enabled rotation instead of overriding their system preference.
*/
@Composable
fun AllowDeviceRotation() {
@@ -28,7 +27,7 @@ fun AllowDeviceRotation() {
DisposableEffect(Unit) {
val activity = context.findActivity()
val previous = activity?.requestedOrientation
activity?.requestedOrientation = ActivityInfo.SCREEN_ORIENTATION_SENSOR
activity?.requestedOrientation = ActivityInfo.SCREEN_ORIENTATION_USER
onDispose {
activity?.requestedOrientation =
previous ?: ActivityInfo.SCREEN_ORIENTATION_PORTRAIT
@@ -1,8 +1,10 @@
package com.hermesandroid.relay.ui.components
import android.content.Context
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.Matrix
import android.net.Uri
import androidx.exifinterface.media.ExifInterface
import java.io.ByteArrayInputStream
@@ -25,6 +27,11 @@ internal fun imageOrientationTransform(orientation: Int): ImageOrientationTransf
else -> ImageOrientationTransform()
}
internal fun shouldApplyExifOrientation(mimeType: String?): Boolean = when (mimeType?.lowercase()) {
"image/png", "image/gif", "image/bmp" -> false
else -> true
}
/**
* Decode image bytes for display and apply their EXIF orientation. BitmapFactory
* returns the stored pixel layout and otherwise leaves portrait phone photos
@@ -41,14 +48,16 @@ internal fun decodeOrientedBitmap(
BitmapFactory.decodeByteArray(bytes, 0, bytes.size, options)
} ?: return null
val orientation = runCatching {
val orientation = try {
ByteArrayInputStream(bytes).use { stream ->
ExifInterface(stream).getAttributeInt(
ExifInterface.TAG_ORIENTATION,
ExifInterface.ORIENTATION_NORMAL,
)
}
}.getOrDefault(ExifInterface.ORIENTATION_NORMAL)
} catch (_: Exception) {
ExifInterface.ORIENTATION_NORMAL
}
val transform = imageOrientationTransform(orientation)
if (transform.rotationDegrees == 0f && !transform.flipHorizontal) return decoded
@@ -56,9 +65,81 @@ internal fun decodeOrientedBitmap(
if (transform.rotationDegrees != 0f) postRotate(transform.rotationDegrees)
if (transform.flipHorizontal) postScale(-1f, 1f)
}
return runCatching {
val oriented = try {
Bitmap.createBitmap(decoded, 0, 0, decoded.width, decoded.height, matrix, true)
}.getOrNull()?.also { oriented ->
if (oriented !== decoded) decoded.recycle()
} catch (_: Exception) {
null
}
return oriented?.also { bitmap ->
if (bitmap !== decoded) decoded.recycle()
} ?: decoded
}
/** Decode a cached content URI without copying the encoded file into RAM. */
internal fun decodeOrientedBitmap(context: Context, uri: Uri): Bitmap? =
decodeBoundedOrientedBitmap(context, uri)
internal fun decodeBoundedOrientedBitmap(context: Context, uri: Uri): Bitmap? {
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
val boundsInput = context.contentResolver.openInputStream(uri) ?: return null
boundsInput.use { input ->
// Bounds-only decode deliberately returns null; the populated Options
// are the result and must not be treated as a decode failure.
BitmapFactory.decodeStream(input, null, bounds)
}
val sample = inlineImageSampleSize(bounds.outWidth, bounds.outHeight) ?: return null
val decoded = context.contentResolver.openInputStream(uri)?.use { input ->
BitmapFactory.decodeStream(
input,
null,
BitmapFactory.Options().apply {
inSampleSize = sample
inPreferredConfig = Bitmap.Config.ARGB_8888
},
)
} ?: return null
val orientation = if (shouldApplyExifOrientation(bounds.outMimeType)) {
try {
context.contentResolver.openInputStream(uri)?.use { input ->
ExifInterface(input).getAttributeInt(
ExifInterface.TAG_ORIENTATION,
ExifInterface.ORIENTATION_NORMAL,
)
}
} catch (_: Exception) {
null
} ?: ExifInterface.ORIENTATION_NORMAL
} else {
ExifInterface.ORIENTATION_NORMAL
}
val transform = imageOrientationTransform(orientation)
if (transform.rotationDegrees == 0f && !transform.flipHorizontal) return decoded
val matrix = Matrix().apply {
if (transform.rotationDegrees != 0f) postRotate(transform.rotationDegrees)
if (transform.flipHorizontal) postScale(-1f, 1f)
}
val oriented = try {
Bitmap.createBitmap(decoded, 0, 0, decoded.width, decoded.height, matrix, true)
} catch (_: Exception) {
null
}
return oriented?.also { bitmap ->
if (bitmap !== decoded) decoded.recycle()
} ?: decoded
}
/** Decode an encoded chat image only after bounding its decoded pixel footprint. */
internal fun decodeBoundedOrientedBitmap(bytes: ByteArray): Bitmap? {
if (bytes.isEmpty()) return null
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
BitmapFactory.decodeByteArray(bytes, 0, bytes.size, bounds)
val sample = inlineImageSampleSize(bounds.outWidth, bounds.outHeight) ?: return null
return decodeOrientedBitmap(
bytes,
BitmapFactory.Options().apply {
inSampleSize = sample
inPreferredConfig = Bitmap.Config.ARGB_8888
},
)
}
@@ -296,12 +296,12 @@ internal fun formatAttachmentSize(bytes: Long): String {
private suspend fun decodePendingAttachmentImage(attachment: Attachment): ImageBitmap? =
withContext(Dispatchers.IO) {
runCatching {
try {
val bytes = Base64.decode(attachment.content, Base64.DEFAULT)
if (bytes.isEmpty()) return@runCatching null
if (bytes.isEmpty()) return@withContext null
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
BitmapFactory.decodeByteArray(bytes, 0, bytes.size, bounds)
if (bounds.outWidth <= 0 || bounds.outHeight <= 0) return@runCatching null
if (bounds.outWidth <= 0 || bounds.outHeight <= 0) return@withContext null
var sample = 1
while (
@@ -314,7 +314,9 @@ private suspend fun decodePendingAttachmentImage(attachment: Attachment): ImageB
bytes,
BitmapFactory.Options().apply { inSampleSize = sample },
)?.asImageBitmap()
}.getOrNull()
} catch (_: Exception) {
null
}
}
private sealed interface PendingPreviewState {
@@ -4,6 +4,7 @@ import androidx.compose.foundation.background
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.WindowInsets
@@ -15,6 +16,7 @@ import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.safeDrawing
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.layout.windowInsetsPadding
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.material3.Text
@@ -24,6 +26,7 @@ import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.alpha
import androidx.compose.ui.draw.clip
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.R
@@ -48,63 +51,70 @@ fun RelayStatusStrip(
* surfaces — the top chrome stays empty so chat content never shifts.
*/
reconnecting: Boolean = false,
maxContentWidth: Dp? = null,
) {
Column(
modifier = modifier
.fillMaxWidth()
.windowInsetsPadding(
WindowInsets.safeDrawing.only(
WindowInsetsSides.Horizontal + WindowInsetsSides.Bottom,
),
)
.padding(start = 14.dp, end = 14.dp, top = 3.dp, bottom = 4.dp)
.clip(appearanceRoundedCornerShape(16.dp))
.then(if (onClick != null) Modifier.clickable(onClick = onClick) else Modifier)
.relayPanel(
shape = appearanceRoundedCornerShape(16.dp),
background = RelayRefresh.Navy2.copy(alpha = 0.88f),
borderColor = RelayRefresh.Line,
),
Box(
modifier = Modifier.fillMaxWidth(),
contentAlignment = Alignment.Center,
) {
Row(
modifier = Modifier
Column(
modifier = modifier
.then(maxContentWidth?.let { Modifier.widthIn(max = it) } ?: Modifier)
.fillMaxWidth()
.heightIn(min = 22.dp)
.padding(horizontal = 14.dp, vertical = 2.dp),
horizontalArrangement = Arrangement.SpaceBetween,
verticalAlignment = Alignment.CenterVertically,
.windowInsetsPadding(
WindowInsets.safeDrawing.only(
WindowInsetsSides.Horizontal + WindowInsetsSides.Bottom,
),
)
.padding(start = 14.dp, end = 14.dp, top = 3.dp, bottom = 4.dp)
.clip(appearanceRoundedCornerShape(16.dp))
.then(if (onClick != null) Modifier.clickable(onClick = onClick) else Modifier)
.relayPanel(
shape = appearanceRoundedCornerShape(16.dp),
background = RelayRefresh.Navy2.copy(alpha = 0.88f),
borderColor = RelayRefresh.Line,
),
) {
Row(
modifier = Modifier.weight(1f),
horizontalArrangement = Arrangement.spacedBy(6.dp),
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 22.dp)
.padding(horizontal = 14.dp, vertical = 2.dp),
horizontalArrangement = Arrangement.SpaceBetween,
verticalAlignment = Alignment.CenterVertically,
) {
leadingBadge()
if (securityGlyph != null) {
securityGlyph()
}
// Route is in flux mid-reconnect, so the amber cue replaces the
// route label rather than stacking beside it in the 22dp strip.
when {
reconnecting -> ReconnectingCue(modifier = Modifier.weight(1f))
routeLabel.isNotBlank() -> Text(
text = "· $routeLabel",
style = relayMetadataStyle(),
color = RelayRefresh.Muted,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.weight(1f),
)
Row(
modifier = Modifier.weight(1f),
horizontalArrangement = Arrangement.spacedBy(6.dp),
verticalAlignment = Alignment.CenterVertically,
) {
leadingBadge()
if (securityGlyph != null) {
securityGlyph()
}
// Route is in flux mid-reconnect, so the amber cue replaces the
// route label rather than stacking beside it in the 22dp strip.
when {
reconnecting -> ReconnectingCue(modifier = Modifier.weight(1f))
routeLabel.isNotBlank() -> Text(
text = "· $routeLabel",
style = relayMetadataStyle(),
color = RelayRefresh.Muted,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.weight(1f),
)
}
}
Spacer(modifier = Modifier.width(10.dp))
Text(
text = trailing,
style = relayMetadataStyle(),
color = RelayRefresh.Muted,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
Spacer(modifier = Modifier.width(10.dp))
Text(
text = trailing,
style = relayMetadataStyle(),
color = RelayRefresh.Muted,
maxLines = 1,
overflow = TextOverflow.Ellipsis,
)
}
}
}
@@ -23,18 +23,26 @@ import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxHeight
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.navigationBarsPadding
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.statusBarsPadding
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.lazy.LazyColumn
import androidx.compose.foundation.lazy.LazyListState
import androidx.compose.foundation.lazy.items
import androidx.compose.foundation.lazy.rememberLazyListState
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.CenterFocusStrong
import androidx.compose.material.icons.filled.Close
@@ -44,10 +52,11 @@ import androidx.compose.material.icons.filled.ExpandMore
import androidx.compose.material.icons.filled.GraphicEq
import androidx.compose.material.icons.filled.Image
import androidx.compose.material.icons.filled.Mic
import androidx.compose.material.icons.filled.Refresh
import androidx.compose.material.icons.filled.ErrorOutline
import androidx.compose.material.icons.filled.Settings
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material3.Icon
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.IconButton
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.LinearProgressIndicator
@@ -71,7 +80,9 @@ import androidx.compose.ui.hapticfeedback.HapticFeedbackType
import androidx.compose.ui.input.key.onPreviewKeyEvent
import androidx.compose.ui.input.pointer.pointerInput
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.platform.LocalConfiguration
import androidx.compose.ui.platform.LocalHapticFeedback
import androidx.compose.ui.platform.LocalSoftwareKeyboardController
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.contentDescription
@@ -81,6 +92,7 @@ import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextAlign
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
import androidx.compose.ui.zIndex
import com.hermesandroid.relay.data.ChatMessage
@@ -92,7 +104,9 @@ import com.hermesandroid.relay.ui.components.avatar.AvatarRenderState
import com.hermesandroid.relay.ui.components.avatar.LocalAgentAvatar
import com.hermesandroid.relay.ui.components.avatar.LocalBackgroundVisualizationEnabled
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.ui.chatResponsiveLayout
import com.hermesandroid.relay.ui.showHumanError
import com.hermesandroid.relay.ui.useSplitVoiceLayout
import com.hermesandroid.relay.util.HumanError
import kotlinx.coroutines.delay
import com.hermesandroid.relay.viewmodel.BackgroundRunPhase
@@ -112,6 +126,8 @@ import com.hermesandroid.relay.R
import com.hermesandroid.relay.ui.theme.appearanceRoundedCornerShape
internal const val VOICE_MODE_MIC_TEST_TAG = "voiceModeMic"
internal const val VOICE_FOCUS_SPLIT_LAYOUT_TEST_TAG = "voiceFocusSplitLayout"
internal const val VOICE_FOCUS_STACKED_LAYOUT_TEST_TAG = "voiceFocusStackedLayout"
/**
* Full-screen voice-mode overlay. Renders the MorphingSphere in its voiceMode
@@ -135,8 +151,7 @@ fun VoiceModeOverlay(
onModeChange: (InteractionMode) -> Unit,
onClearError: () -> Unit,
modifier: Modifier = Modifier,
// Nullable so existing call sites compile; when wired, voice errors
// surface as global snackbars in addition to the inline banner below.
// Retained for callers; uiState.error owns the modal while voice is visible.
errorEvents: SharedFlow<HumanError>? = null,
// === PHASE3-voice-mode-transcript ===
// Compact rolling transcript of the last N chat messages — the
@@ -186,6 +201,56 @@ fun VoiceModeOverlay(
val backgroundVisualizationEnabled = LocalBackgroundVisualizationEnabled.current
val surface = MaterialTheme.colorScheme.surface
val haptic = LocalHapticFeedback.current
val configuration = LocalConfiguration.current
val responsiveLayout = chatResponsiveLayout(configuration.screenWidthDp)
val splitFocusLayout = useSplitVoiceLayout(
screenWidthDp = configuration.screenWidthDp,
screenHeightDp = configuration.screenHeightDp,
)
val focusMicTap: () -> Unit = {
dispatchVoiceMicTap(
uiState = uiState,
onStartListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onMicTap()
},
onStopListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.TextHandleMove)
} catch (_: Exception) { /* ignore */ }
onMicRelease()
},
onInterrupt = onInterrupt,
onPauseAutoMode = onPauseAutoMode,
)
}
val focusMicHoldPress: () -> Unit = {
dispatchVoiceMicHoldPress(
uiState = uiState,
onStartListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onMicTap()
},
onInterruptAndStart = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onInterrupt()
onMicTap()
},
)
}
val focusMicHoldRelease: () -> Unit = {
try {
haptic.performHapticFeedback(HapticFeedbackType.TextHandleMove)
} catch (_: Exception) { /* ignore */ }
onMicRelease()
}
var controlsExpanded by remember { mutableStateOf(false) }
val focusMode = presentationMode == VoicePresentationMode.Focus
@@ -195,7 +260,7 @@ fun VoiceModeOverlay(
)
}
// Voice errors surface ONLY on the overlay's own inline top banner
// Voice errors surface ONLY in the overlay's dialog
// (uiState.error) while the overlay is up — we deliberately do NOT also pipe
// them to the app-wide bottom snackbar. Doing both duplicated the message
// and left a retry-only, un-dismissable toast at the bottom during long /
@@ -253,6 +318,11 @@ fun VoiceModeOverlay(
onOpenSettings = onOpenSettings,
onExit = onDismiss,
modifier = Modifier
.then(
responsiveLayout.focusVoiceMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
)
.fillMaxWidth()
.statusBarsPadding()
.padding(horizontal = 12.dp, vertical = 8.dp)
@@ -328,162 +398,93 @@ fun VoiceModeOverlay(
exit = fadeOut(tween(120)),
modifier = Modifier.fillMaxSize(),
) {
Column(
modifier = Modifier
.fillMaxSize()
.padding(top = 92.dp, bottom = 160.dp, start = 20.dp, end = 20.dp),
horizontalAlignment = Alignment.CenterHorizontally,
Box(
modifier = Modifier.fillMaxSize(),
contentAlignment = Alignment.Center,
) {
Box(
modifier = Modifier
.fillMaxWidth()
.weight(1.0f),
contentAlignment = Alignment.Center,
) {
if (backgroundVisualizationEnabled) {
LocalAgentAvatar.current.Render(
state = AvatarRenderState(
state = voiceStateToSphereState(uiState.state),
voiceAmplitude = uiState.amplitude,
voiceMode = true,
),
modifier = Modifier.fillMaxSize(),
if (splitFocusLayout) {
Row(
modifier = Modifier
.widthIn(max = responsiveLayout.focusVoiceMaxWidth ?: 1120.dp)
.fillMaxSize()
.navigationBarsPadding()
.padding(top = 92.dp, bottom = 28.dp, start = 32.dp, end = 32.dp)
.testTag(VOICE_FOCUS_SPLIT_LAYOUT_TEST_TAG),
verticalAlignment = Alignment.CenterVertically,
) {
VoiceFocusIdentityPane(
uiState = uiState,
backgroundVisualizationEnabled = backgroundVisualizationEnabled,
onMicTap = focusMicTap,
onMicHoldPress = focusMicHoldPress,
onMicHoldRelease = focusMicHoldRelease,
showMic = true,
modifier = Modifier
.weight(0.86f)
.fillMaxHeight(),
)
Spacer(Modifier.width(32.dp))
VoiceFocusStatusAndTranscriptPane(
uiState = uiState,
transcriptMessages = visibleTranscriptMessages,
pendingTranscriptText = pendingTranscriptText,
transcriptListState = transcriptListState,
showThinking = showThinking,
onBackgroundRunCancel = onBackgroundRunCancel,
onBackgroundRunTap = onBackgroundRunTap,
onPermissionDeniedChipTap = onPermissionDeniedChipTap,
onHermesConfirmationAnswer = onHermesConfirmationAnswer,
onPresentationModeChange = onPresentationModeChange,
onCardAction = onCardAction,
onCardInput = onCardInput,
horizontalContentPadding = 0.dp,
modifier = Modifier
.weight(1.14f)
.fillMaxHeight(),
)
}
}
VoiceWaveform(
amplitude = uiState.amplitude,
state = uiState.state,
outputAudioActive = uiState.outputAudioActive,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 32.dp, vertical = 8.dp),
)
AnimatedVisibility(
visible = uiState.handoffStatus != null,
enter = fadeIn(tween(140)),
exit = fadeOut(tween(180)),
) {
VoiceHandoffStrip(
status = uiState.handoffStatus,
} else {
Column(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 24.dp, vertical = 4.dp),
)
}
BackgroundRunChip(
run = uiState.backgroundRun,
onCancel = onBackgroundRunCancel,
onTap = onBackgroundRunTap,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 24.dp, vertical = 4.dp),
)
Spacer(Modifier.height(8.dp))
DestructiveCountdownRow(
countdown = uiState.destructiveCountdown,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 24.dp),
)
PermissionDeniedChip(
callout = uiState.permissionDeniedCallout,
onTap = onPermissionDeniedChipTap,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 24.dp, vertical = 4.dp),
)
HermesConfirmationCard(
confirmation = uiState.hermesConfirmation,
onAnswer = onHermesConfirmationAnswer,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 24.dp, vertical = 4.dp),
)
Spacer(Modifier.height(4.dp))
Box(
modifier = Modifier
.fillMaxWidth()
.weight(1.25f, fill = true),
) {
val hasTranscript = visibleTranscriptMessages.isNotEmpty() ||
pendingTranscriptText != null
if (hasTranscript) {
val latestId = visibleTranscriptMessages.lastOrNull()?.id
LazyColumn(
state = transcriptListState,
modifier = Modifier.fillMaxSize(),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
// Match ChatScreen's identity contract. A history
// reconcile can adopt the same authoritative server
// id into a live row while Compose still holds the
// pre-reconcile row for a frame. uiKey remains stable
// and unique across that transition.
items(visibleTranscriptMessages, key = ::voiceTranscriptItemKey) { msg ->
CompactTranscriptRow(
message = msg,
showThinking = showThinking,
expanded = msg.id == latestId || msg.isStreaming,
onViewConversation = {
onPresentationModeChange(VoicePresentationMode.Conversation)
},
onCardAction = onCardAction,
onCardInput = onCardInput,
)
}
if (pendingTranscriptText != null) {
item(key = "aux:pending-voice-transcript") {
CompactTranscriptRow(
message = ChatMessage(
id = "pending-voice-transcript",
role = MessageRole.USER,
content = pendingTranscriptText,
timestamp = System.currentTimeMillis(),
isStreaming = true,
),
showThinking = showThinking,
expanded = true,
onViewConversation = {
onPresentationModeChange(VoicePresentationMode.Conversation)
},
onCardAction = onCardAction,
onCardInput = onCardInput,
)
}
}
item { Spacer(Modifier.height(12.dp)) }
}
} else {
Box(
modifier = Modifier.fillMaxSize(),
contentAlignment = Alignment.Center,
) {
AnimatedContent(
targetState = stateHint(uiState.state),
transitionSpec = {
fadeIn(tween(200)) togetherWith fadeOut(tween(200))
},
label = "stateHint",
) { hint ->
Text(
text = hint,
style = MaterialTheme.typography.labelLarge,
color = MaterialTheme.colorScheme.onSurfaceVariant,
textAlign = TextAlign.Center,
modifier = Modifier.fillMaxWidth(),
)
}
}
.then(
responsiveLayout.focusVoiceMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
)
.fillMaxSize()
.padding(top = 92.dp, bottom = 160.dp, start = 20.dp, end = 20.dp)
.testTag(VOICE_FOCUS_STACKED_LAYOUT_TEST_TAG),
horizontalAlignment = Alignment.CenterHorizontally,
) {
VoiceFocusIdentityPane(
uiState = uiState,
backgroundVisualizationEnabled = backgroundVisualizationEnabled,
onMicTap = focusMicTap,
onMicHoldPress = focusMicHoldPress,
onMicHoldRelease = focusMicHoldRelease,
showMic = false,
modifier = Modifier
.fillMaxWidth()
.weight(1f),
)
VoiceFocusStatusAndTranscriptPane(
uiState = uiState,
transcriptMessages = visibleTranscriptMessages,
pendingTranscriptText = pendingTranscriptText,
transcriptListState = transcriptListState,
showThinking = showThinking,
onBackgroundRunCancel = onBackgroundRunCancel,
onBackgroundRunTap = onBackgroundRunTap,
onPermissionDeniedChipTap = onPermissionDeniedChipTap,
onHermesConfirmationAnswer = onHermesConfirmationAnswer,
onPresentationModeChange = onPresentationModeChange,
onCardAction = onCardAction,
onCardInput = onCardInput,
horizontalContentPadding = 24.dp,
modifier = Modifier
.fillMaxWidth()
.weight(1.25f),
)
}
}
}
@@ -498,6 +499,12 @@ fun VoiceModeOverlay(
exit = fadeOut(tween(180)),
modifier = Modifier
.align(Alignment.BottomCenter)
.then(
responsiveLayout.chromeMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
)
.fillMaxWidth()
.padding(bottom = 176.dp, start = 24.dp, end = 24.dp),
) {
BackgroundRunChip(
@@ -508,53 +515,15 @@ fun VoiceModeOverlay(
)
}
// Error banner
AnimatedVisibility(
visible = uiState.error != null,
enter = fadeIn(),
exit = fadeOut(),
modifier = Modifier
.align(Alignment.TopCenter)
.padding(top = 64.dp, start = 16.dp, end = 16.dp),
) {
Surface(
shape = appearanceRoundedCornerShape(12.dp),
color = MaterialTheme.colorScheme.errorContainer,
tonalElevation = 2.dp,
) {
Row(
modifier = Modifier.padding(12.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(
text = uiState.error.orEmpty(),
color = MaterialTheme.colorScheme.onErrorContainer,
style = MaterialTheme.typography.bodySmall,
modifier = Modifier.weight(1f),
)
// Dismiss clears the error and returns to Idle without
// retrying, so a failed/timed-out turn never traps the user
// on a retry-only banner.
TextButton(onClick = { onClearError() }) {
Text(stringResource(R.string.common_dismiss))
}
TextButton(
onClick = {
onClearError()
onMicTap()
},
) {
Icon(
imageVector = Icons.Filled.Refresh,
contentDescription = null,
modifier = Modifier.size(16.dp),
)
Spacer(Modifier.size(4.dp))
Text(stringResource(R.string.voice_overlay_retry))
}
}
}
uiState.error?.let { error ->
VoiceErrorDialog(
error = error,
onDismiss = onClearError,
onRetry = {
onClearError()
onMicTap()
},
)
}
// Mic button — dispatch by current voice state.
@@ -570,57 +539,259 @@ fun VoiceModeOverlay(
// that visually said "Stop" but was actually wired to "Start."
VoiceMicButton(
uiState = uiState,
onTap = {
dispatchVoiceMicTap(
uiState = uiState,
onStartListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onMicTap()
},
onStopListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.TextHandleMove)
} catch (_: Exception) { /* ignore */ }
onMicRelease()
},
onInterrupt = onInterrupt,
onPauseAutoMode = onPauseAutoMode,
)
},
onHoldPress = {
dispatchVoiceMicHoldPress(
uiState = uiState,
onStartListening = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onMicTap()
},
onInterruptAndStart = {
try {
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
} catch (_: Exception) { /* ignore */ }
onInterrupt()
onMicTap()
},
)
},
onHoldRelease = {
try {
haptic.performHapticFeedback(HapticFeedbackType.TextHandleMove)
} catch (_: Exception) { /* ignore */ }
onMicRelease()
},
onTap = focusMicTap,
onHoldPress = focusMicHoldPress,
onHoldRelease = focusMicHoldRelease,
modifier = Modifier
.align(Alignment.BottomCenter)
.padding(bottom = 48.dp),
visible = focusMode,
visible = focusMode && !splitFocusLayout,
)
}
}
@Composable
private fun VoiceErrorDialog(
error: String,
onDismiss: () -> Unit,
onRetry: () -> Unit,
) {
val keyboard = LocalSoftwareKeyboardController.current
LaunchedEffect(error) { keyboard?.hide() }
// Match ChatFailureDetailsDialog: keep provider detail selectable and inside
// a bounded surface, with actions outside the scroll area. A real dialog
// owns focus and blocks the underlying chat in both voice presentations.
AlertDialog(
onDismissRequest = onDismiss,
containerColor = MaterialTheme.colorScheme.surface,
icon = {
Icon(
imageVector = Icons.Default.ErrorOutline,
contentDescription = null,
tint = MaterialTheme.colorScheme.error,
)
},
title = { Text(stringResource(R.string.voice_overlay_error_title)) },
text = {
Surface(
color = MaterialTheme.colorScheme.surfaceVariant,
shape = MaterialTheme.shapes.small,
) {
SelectionContainer {
Text(
text = error,
style = MaterialTheme.typography.bodySmall,
modifier = Modifier
.fillMaxWidth()
.heightIn(max = 320.dp)
.verticalScroll(rememberScrollState())
.padding(12.dp),
)
}
}
},
confirmButton = {
TextButton(onClick = onRetry) {
Text(stringResource(R.string.voice_overlay_retry))
}
},
dismissButton = {
TextButton(onClick = onDismiss) {
Text(stringResource(R.string.common_dismiss))
}
},
)
}
@Composable
private fun VoiceFocusIdentityPane(
uiState: VoiceUiState,
backgroundVisualizationEnabled: Boolean,
onMicTap: () -> Unit,
onMicHoldPress: () -> Unit,
onMicHoldRelease: () -> Unit,
showMic: Boolean,
modifier: Modifier = Modifier,
) {
Column(
modifier = modifier.testTag("voiceFocusIdentityPane"),
horizontalAlignment = Alignment.CenterHorizontally,
) {
Box(
modifier = Modifier
.fillMaxWidth()
.weight(1f),
contentAlignment = Alignment.Center,
) {
if (backgroundVisualizationEnabled) {
LocalAgentAvatar.current.Render(
state = AvatarRenderState(
state = voiceStateToSphereState(uiState.state),
voiceAmplitude = uiState.amplitude,
voiceMode = true,
),
modifier = Modifier.fillMaxSize(),
)
}
}
VoiceWaveform(
amplitude = uiState.amplitude,
state = uiState.state,
outputAudioActive = uiState.outputAudioActive,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 20.dp, vertical = 8.dp),
)
if (showMic) {
Spacer(Modifier.height(16.dp))
VoiceMicButton(
uiState = uiState,
onTap = onMicTap,
onHoldPress = onMicHoldPress,
onHoldRelease = onMicHoldRelease,
visible = true,
)
Spacer(Modifier.height(8.dp))
}
}
}
@Composable
private fun VoiceFocusStatusAndTranscriptPane(
uiState: VoiceUiState,
transcriptMessages: List<ChatMessage>,
pendingTranscriptText: String?,
transcriptListState: LazyListState,
showThinking: Boolean,
onBackgroundRunCancel: () -> Unit,
onBackgroundRunTap: () -> Unit,
onPermissionDeniedChipTap: (PermissionDeniedCallout) -> Unit,
onHermesConfirmationAnswer: (String) -> Unit,
onPresentationModeChange: (VoicePresentationMode) -> Unit,
onCardAction: (messageId: String, cardKey: String, action: HermesCardAction) -> Unit,
onCardInput: (messageId: String, cardKey: String, value: String) -> Unit,
horizontalContentPadding: Dp,
modifier: Modifier = Modifier,
) {
Column(modifier = modifier.testTag("voiceFocusTranscriptPane")) {
AnimatedVisibility(
visible = uiState.handoffStatus != null,
enter = fadeIn(tween(140)),
exit = fadeOut(tween(180)),
) {
VoiceHandoffStrip(
status = uiState.handoffStatus,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = horizontalContentPadding, vertical = 4.dp),
)
}
BackgroundRunChip(
run = uiState.backgroundRun,
onCancel = onBackgroundRunCancel,
onTap = onBackgroundRunTap,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = horizontalContentPadding, vertical = 4.dp),
)
Spacer(Modifier.height(8.dp))
DestructiveCountdownRow(
countdown = uiState.destructiveCountdown,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = horizontalContentPadding),
)
PermissionDeniedChip(
callout = uiState.permissionDeniedCallout,
onTap = onPermissionDeniedChipTap,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = horizontalContentPadding, vertical = 4.dp),
)
HermesConfirmationCard(
confirmation = uiState.hermesConfirmation,
onAnswer = onHermesConfirmationAnswer,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = horizontalContentPadding, vertical = 4.dp),
)
Spacer(Modifier.height(4.dp))
Box(
modifier = Modifier
.fillMaxWidth()
.weight(1f, fill = true),
) {
val hasTranscript = transcriptMessages.isNotEmpty() || pendingTranscriptText != null
if (hasTranscript) {
val latestId = transcriptMessages.lastOrNull()?.id
LazyColumn(
state = transcriptListState,
modifier = Modifier.fillMaxSize(),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
// uiKey remains stable while Gateway reconciliation adopts
// an authoritative server id into a live transcript row.
items(transcriptMessages, key = ::voiceTranscriptItemKey) { msg ->
CompactTranscriptRow(
message = msg,
showThinking = showThinking,
expanded = msg.id == latestId || msg.isStreaming,
onViewConversation = {
onPresentationModeChange(VoicePresentationMode.Conversation)
},
onCardAction = onCardAction,
onCardInput = onCardInput,
)
}
if (pendingTranscriptText != null) {
item(key = "aux:pending-voice-transcript") {
CompactTranscriptRow(
message = ChatMessage(
id = "pending-voice-transcript",
role = MessageRole.USER,
content = pendingTranscriptText,
timestamp = System.currentTimeMillis(),
isStreaming = true,
),
showThinking = showThinking,
expanded = true,
onViewConversation = {
onPresentationModeChange(VoicePresentationMode.Conversation)
},
onCardAction = onCardAction,
onCardInput = onCardInput,
)
}
}
item { Spacer(Modifier.height(12.dp)) }
}
} else {
Box(
modifier = Modifier.fillMaxSize(),
contentAlignment = Alignment.Center,
) {
AnimatedContent(
targetState = stateHint(uiState.state),
transitionSpec = {
fadeIn(tween(200)) togetherWith fadeOut(tween(200))
},
label = "stateHint",
) { hint ->
Text(
text = hint,
style = MaterialTheme.typography.labelLarge,
color = MaterialTheme.colorScheme.onSurfaceVariant,
textAlign = TextAlign.Center,
modifier = Modifier.fillMaxWidth(),
)
}
}
}
}
}
}
@Composable
private fun VoiceMicButton(
uiState: VoiceUiState,
@@ -1,5 +1,9 @@
package com.hermesandroid.relay.ui.screens
import com.hermesandroid.relay.data.BusyMessageAction
import com.hermesandroid.relay.data.canCorrectBusyMessage
import com.hermesandroid.relay.ui.components.ChatComposerLayers
import com.hermesandroid.relay.ui.components.ChatMessageQueue
import androidx.compose.foundation.BorderStroke
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
@@ -58,6 +62,7 @@ import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.GatewayChatClient
import com.hermesandroid.relay.network.upstream.SessionMessageLoadMode
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.ui.components.ChatMediaViewerHost
import com.hermesandroid.relay.ui.components.MessageBubble
import com.hermesandroid.relay.ui.theme.RelayRefresh
import com.hermesandroid.relay.viewmodel.ChatViewModel
@@ -84,24 +89,28 @@ fun BotChatScreen(
connectionViewModel: ConnectionViewModel,
onBack: () -> Unit,
) {
BotChatScreen(
route = route,
bot = bot,
sessionId = sessionId,
gatewayClient = gatewayClient,
dashboardClient = dashboardClient,
chatViewModel = chatViewModel,
onBack = onBack,
handlerFactory = ::ChatHandler,
historyLoader = { profileName, storedSessionId, mode ->
dashboardClient.getSessionMessages(
sessionId = storedSessionId,
profile = profileName,
mode = mode,
)
},
profileIconFlow = connectionViewModel::profileIconFlow,
)
val busyMessageAction by connectionViewModel.busyMessageAction.collectAsState()
ChatMediaViewerHost(route.key, sessionId) {
BotChatScreen(
route = route,
bot = bot,
sessionId = sessionId,
gatewayClient = gatewayClient,
dashboardClient = dashboardClient,
chatViewModel = chatViewModel,
onBack = onBack,
handlerFactory = ::ChatHandler,
historyLoader = { profileName, storedSessionId, mode ->
dashboardClient.getSessionMessages(
sessionId = storedSessionId,
profile = profileName,
mode = mode,
)
},
profileIconFlow = connectionViewModel::profileIconFlow,
busyMessageAction = busyMessageAction,
)
}
}
@OptIn(ExperimentalMaterial3Api::class)
@@ -117,6 +126,7 @@ internal fun BotChatScreen(
handlerFactory: () -> ChatHandler,
historyLoader: BotChatHistoryLoader,
profileIconFlow: BotChatProfileIconFlow,
busyMessageAction: BusyMessageAction = BusyMessageAction.CorrectNow,
) {
val handler = remember(route.key) { handlerFactory() }
val context = LocalContext.current
@@ -133,6 +143,21 @@ internal fun BotChatScreen(
.collectAsState(initial = null)
val listState = rememberLazyListState()
var composer by remember(route.key, sessionId) { mutableStateOf("") }
var editingQueuedMessage by remember(route.key, sessionId) { mutableStateOf(false) }
var busyActionOverride by remember(route.key, sessionId, busyMessageAction) {
mutableStateOf<BusyMessageAction?>(null)
}
val steerable by chatViewModel.steerableTurn.collectAsState()
val attachments by chatViewModel.pendingAttachments.collectAsState()
val pendingAsk by chatViewModel.pendingAsk.collectAsState()
val turnStatus by handler.turnStatus.collectAsState()
val queue by chatViewModel.queuedMessages.collectAsState()
val queuePaused by chatViewModel.queuePaused.collectAsState()
val correctionAvailable = canCorrectBusyMessage(
steerable, attachments.isNotEmpty(), pendingAsk != null, turnStatus, composer,
)
val effectiveBusyAction = if (correctionAvailable && !editingQueuedMessage) busyActionOverride ?: busyMessageAction
else BusyMessageAction.QueueNext
DisposableEffect(chatViewModel, gatewayClient, dashboardClient, route.key) {
chatViewModel.initialize(apiClient = null, chatHandler = handler)
@@ -234,49 +259,82 @@ internal fun BotChatScreen(
)
},
bottomBar = {
ChatComposerLayers(
action = effectiveBusyAction.takeIf { isStreaming },
onActionChange = {
editingQueuedMessage = false
busyActionOverride = it
},
correctionAvailable = correctionAvailable,
onStop = if (composer.isNotBlank()) chatViewModel::cancelStream else null,
modifier = Modifier.imePadding(),
) {
Surface(
color = MaterialTheme.colorScheme.surfaceContainer,
border = BorderStroke(1.dp, MaterialTheme.colorScheme.outlineVariant),
shape = RoundedCornerShape(topStart = 18.dp, topEnd = 18.dp),
modifier = Modifier.imePadding(),
) {
Row(
modifier = Modifier.padding(horizontal = 12.dp, vertical = 10.dp),
verticalAlignment = Alignment.Bottom,
) {
OutlinedTextField(
value = composer,
onValueChange = { composer = it },
placeholder = { Text(stringResource(R.string.chat_placeholder_message)) },
modifier = Modifier.weight(1f),
minLines = 1,
maxLines = 6,
)
Spacer(Modifier.width(6.dp))
IconButton(
onClick = {
if (isStreaming) {
chatViewModel.cancelStream()
} else {
val text = composer.trim()
if (text.isNotEmpty()) {
composer = ""
chatViewModel.sendMessage(text)
}
Column {
ChatMessageQueue(
messages = queue,
paused = queuePaused,
onResume = chatViewModel::resumeQueue,
onClear = chatViewModel::clearQueue,
onRemove = chatViewModel::removeQueuedAt,
canEdit = composer.isBlank() && attachments.isEmpty(),
onEdit = { index ->
chatViewModel.takeQueuedForEdit(index)?.let {
composer = it
editingQueuedMessage = true
}
},
enabled = isStreaming || composer.isNotBlank(),
modifier = Modifier.padding(horizontal = 12.dp),
)
Row(
modifier = Modifier.padding(horizontal = 12.dp, vertical = 10.dp),
verticalAlignment = Alignment.Bottom,
) {
Icon(
if (isStreaming) Icons.Filled.Stop else Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(
if (isStreaming) R.string.chat_input_stop_streaming
else R.string.chat_input_send_message,
),
OutlinedTextField(
value = composer,
onValueChange = { composer = it },
placeholder = { Text(stringResource(R.string.chat_placeholder_message)) },
modifier = Modifier.weight(1f),
minLines = 1,
maxLines = 6,
)
Spacer(Modifier.width(6.dp))
IconButton(
onClick = {
if (isStreaming && composer.isBlank()) {
chatViewModel.cancelStream()
} else {
val text = composer.trim()
if (text.isNotEmpty()) {
composer = ""
chatViewModel.sendMessage(text, effectiveBusyAction)
editingQueuedMessage = false
busyActionOverride = null
}
}
},
enabled = isStreaming || composer.isNotBlank(),
) {
Icon(
if (isStreaming && composer.isBlank()) Icons.Filled.Stop else Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(
when {
isStreaming && composer.isBlank() -> R.string.chat_input_stop_streaming
isStreaming && effectiveBusyAction == BusyMessageAction.CorrectNow -> R.string.chat_correct_now
isStreaming -> R.string.chat_queue_next
else -> R.string.chat_input_send_message
},
),
)
}
}
}
}
}
},
) { padding ->
Box(
@@ -2,6 +2,9 @@
package com.hermesandroid.relay.ui.screens
import com.hermesandroid.relay.data.BusyMessageAction
import com.hermesandroid.relay.data.canCorrectBusyMessage
import com.hermesandroid.relay.ui.components.ChatMessageQueue
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.animateContentSize
import androidx.compose.foundation.Canvas
@@ -98,6 +101,7 @@ import androidx.compose.ui.Modifier
import androidx.compose.foundation.layout.aspectRatio
import androidx.compose.ui.draw.alpha
import androidx.compose.ui.draw.clip
import androidx.compose.ui.draw.clipToBounds
import androidx.compose.ui.geometry.CornerRadius
import androidx.compose.ui.geometry.Offset
import androidx.compose.ui.geometry.Size
@@ -119,6 +123,7 @@ import androidx.compose.ui.unit.Dp
import androidx.compose.ui.unit.dp
import androidx.compose.ui.zIndex
import com.hermesandroid.relay.R
import com.hermesandroid.relay.ui.chatResponsiveLayout
import com.hermesandroid.relay.ui.theme.radialNavyBackground
import com.hermesandroid.relay.network.upstream.ApiModelOption
import com.hermesandroid.relay.network.upstream.ChatMode
@@ -749,6 +754,7 @@ fun ChatScreen(
gitWorkspaceAvailable: Boolean = gitWorkspaceSummary != null,
onNavigateToGitWorkspace: () -> Unit = {},
) {
val responsiveLayout = chatResponsiveLayout(LocalConfiguration.current.screenWidthDp)
val supervised = supervisedPolicy.enabled
val supervisedVisibility = supervisedPolicy.visibility.resolved()
LaunchedEffect(supervisedPolicy) {
@@ -1135,6 +1141,12 @@ fun ChatScreen(
val availableSkills by chatViewModel.availableSkills.collectAsState()
val queuedMessages by chatViewModel.queuedMessages.collectAsState()
val queuePaused by chatViewModel.queuePaused.collectAsState()
val busyMessageAction by connectionViewModel.busyMessageAction.collectAsState()
var busyActionOverride by remember(currentSessionId, busyMessageAction) {
mutableStateOf<BusyMessageAction?>(null)
}
var editingQueuedMessage by remember(currentSessionId) { mutableStateOf(false) }
val recentPrompts by chatViewModel.recentPrompts.collectAsState()
val recentPromptsEnabled by connectionViewModel.chatRecentPromptsEnabled.collectAsState()
// Effective approval-bypass (server-computed: ORs global approvals.mode=off,
@@ -1395,7 +1407,11 @@ fun ChatScreen(
}
var showCommandPalette by remember { mutableStateOf(false) }
var showTranscriptSearch by rememberSaveable { mutableStateOf(false) }
var pendingAttachmentPreview by remember { mutableStateOf<Attachment?>(null) }
var pendingAttachmentPreviewIndex by rememberSaveable(
composerDraftKey.connectionId,
composerDraftKey.profileId,
composerDraftKey.sessionId,
) { mutableStateOf<Int?>(null) }
var showModelSheet by remember { mutableStateOf(false) }
var showEffortSheet by remember { mutableStateOf(false) }
var showAgentInfo by remember { mutableStateOf(false) }
@@ -3311,7 +3327,13 @@ fun ChatScreen(
) {
Column(
horizontalAlignment = Alignment.CenterHorizontally,
modifier = Modifier.padding(horizontal = 32.dp)
modifier = Modifier
.padding(horizontal = 32.dp)
.then(
responsiveLayout.introMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
),
) {
Spacer(modifier = Modifier.weight(0.15f))
@@ -3320,12 +3342,15 @@ fun ChatScreen(
LocalBackgroundVisualizationEnabled.current &&
(!supervised || supervisedVisibility.showAgentIdentity)
) {
Box(
modifier = Modifier
.fillMaxWidth()
.aspectRatio(1f)
.weight(0.7f, fill = false)
) {
val avatarModifier = responsiveLayout.avatarSize?.let { size ->
Modifier
.size(size)
.clipToBounds()
} ?: Modifier
.fillMaxWidth()
.aspectRatio(1f)
.weight(0.7f, fill = false)
Box(modifier = avatarModifier) {
LocalAgentAvatar.current.Render(
state = AvatarRenderState(
state = if (error != null) SphereState.Error else SphereState.Idle,
@@ -3568,7 +3593,14 @@ fun ChatScreen(
LazyColumn(
state = listState,
modifier = Modifier
.fillMaxSize()
.align(Alignment.Center)
.fillMaxHeight()
.then(
responsiveLayout.transcriptMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
)
.fillMaxWidth()
.padding(horizontal = 12.dp)
.padding(top = if (showTranscriptSearch) 112.dp else 0.dp),
verticalArrangement = Arrangement.spacedBy(2.dp)
@@ -4091,69 +4123,21 @@ fun ChatScreen(
}
}
AnimatedVisibility(visible = queuedMessages.isNotEmpty()) {
Column(
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 20.dp),
) {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.SpaceBetween
) {
Text(
text = pluralStringResource(
R.plurals.chat_queue_count,
queuedMessages.size,
queuedMessages.size,
),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary
)
TextButton(
onClick = { chatViewModel.clearQueue() },
modifier = Modifier.height(28.dp)
) {
Text(
stringResource(R.string.chat_clear),
style = MaterialTheme.typography.labelSmall
)
}
ChatMessageQueue(
messages = queuedMessages,
paused = queuePaused,
onResume = chatViewModel::resumeQueue,
onClear = chatViewModel::clearQueue,
onRemove = chatViewModel::removeQueuedAt,
canEdit = inputText.isBlank() && pendingAttachments.isEmpty(),
onEdit = { index ->
chatViewModel.takeQueuedForEdit(index)?.let {
inputText = it
editingQueuedMessage = true
}
// Per-item: tap the text to pull it back into the composer
// for editing; ✕ to drop just that one. (Reorder omitted —
// low value vs. drag-handle complexity on a transient queue.)
queuedMessages.forEachIndexed { index, msg ->
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
) {
Text(
text = msg,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
maxLines = 2,
overflow = androidx.compose.ui.text.style.TextOverflow.Ellipsis,
modifier = Modifier
.weight(1f)
.clickable {
chatViewModel.takeQueuedForEdit(index)?.let { t ->
inputText = if (inputText.isBlank()) t else "$inputText $t"
}
}
.padding(vertical = 4.dp),
)
TextButton(
onClick = { chatViewModel.removeQueuedAt(index) },
modifier = Modifier.height(28.dp),
) {
Text("✕", style = MaterialTheme.typography.labelSmall)
}
}
}
}
}
},
modifier = Modifier.fillMaxWidth().padding(horizontal = 20.dp),
)
val quoteYouLabel = stringResource(R.string.chat_quote_you)
val quoteHermesLabel = stringResource(R.string.chat_quote_hermes)
@@ -4199,15 +4183,17 @@ fun ChatScreen(
PendingAttachmentComposer(
attachments = pendingAttachments,
onPreview = { attachment, _ -> pendingAttachmentPreview = attachment },
onPreview = { _, index -> pendingAttachmentPreviewIndex = index },
onRemove = chatViewModel::removeAttachment,
onMove = chatViewModel::moveAttachment,
modifier = Modifier.padding(horizontal = 16.dp, vertical = 4.dp),
)
pendingAttachmentPreview?.let { attachment ->
pendingAttachmentPreviewIndex
?.let(pendingAttachments::getOrNull)
?.let { attachment ->
AttachmentViewer(
attachment = attachment,
onDismiss = { pendingAttachmentPreview = null },
onDismiss = { pendingAttachmentPreviewIndex = null },
initiallyRevealed = true,
)
}
@@ -4260,25 +4246,32 @@ fun ChatScreen(
// Gateway redirect is text-only. Attachment-bearing follow-ups must
// retain their files in the session-owned queue instead of showing
// a correction action that cannot carry them.
val canSteerCurrentMessage = steerableTurn && pendingAttachments.isEmpty() &&
val canSteerCurrentMessage = canCorrectBusyMessage(
steerableTurn, pendingAttachments.isNotEmpty(), pendingAsk != null, turnStatus, inputText,
) &&
(!supervised || supervisedPolicy.capabilities.steerResponse)
val effectiveBusyAction = if (canSteerCurrentMessage && !editingQueuedMessage) busyActionOverride ?: busyMessageAction
else BusyMessageAction.QueueNext
val correctCurrentMessage = canSteerCurrentMessage &&
effectiveBusyAction == BusyMessageAction.CorrectNow
val trailing = when {
!isStreaming && hasContent -> ChatInputTrailing.SEND
!isStreaming -> ChatInputTrailing.VOICE
isStreaming && !hasContent -> ChatInputTrailing.STOP
canSteerCurrentMessage -> ChatInputTrailing.STEER
correctCurrentMessage -> ChatInputTrailing.STEER
else -> ChatInputTrailing.QUEUE
}
val inputCaption = when {
isStreaming && hasContent && canSteerCurrentMessage ->
isStreaming && hasContent && correctCurrentMessage ->
stringResource(R.string.chat_sends_now)
isStreaming && hasContent && queuePaused -> stringResource(R.string.chat_queue_paused)
isStreaming && hasContent -> stringResource(R.string.chat_delivered_after_turn)
isStreaming && steerNotice != null -> steerNotice
else -> null
}
val inputPlaceholder = when {
editingMessage != null -> stringResource(R.string.chat_placeholder_edit)
isStreaming && canSteerCurrentMessage -> stringResource(R.string.chat_placeholder_steer)
isStreaming && correctCurrentMessage -> stringResource(R.string.chat_placeholder_steer)
isStreaming -> stringResource(R.string.chat_placeholder_queue)
else -> stringResource(R.string.chat_placeholder_message)
}
@@ -4530,6 +4523,12 @@ fun ChatScreen(
}
ChatInputBar(
busyAction = effectiveBusyAction.takeIf { isStreaming },
correctionAvailable = canSteerCurrentMessage,
onBusyActionChange = {
editingQueuedMessage = false
busyActionOverride = it
},
value = inputText,
onValueChange = { inputText = it },
placeholder = inputPlaceholder,
@@ -4558,7 +4557,9 @@ fun ChatScreen(
}
}
} else {
chatViewModel.sendMessage(outboundText)
chatViewModel.sendMessage(outboundText, effectiveBusyAction)
editingQueuedMessage = false
busyActionOverride = null
inputText = ""
finishSuccessfulSend()
}
@@ -4650,6 +4651,13 @@ fun ChatScreen(
supervisedPolicy.capabilities.attachmentCategories
)) pasteImageFromClipboard else ({ }),
onLongPressAttach = { if (!supervised) showCommandPalette = true },
modifier = Modifier
.align(Alignment.CenterHorizontally)
.then(
responsiveLayout.chromeMaxWidth?.let {
Modifier.widthIn(max = it)
} ?: Modifier,
),
charLimit = charLimit,
caption = turnStatus ?: inputCaption,
voiceReady = voiceReady,
@@ -1,5 +1,6 @@
package com.hermesandroid.relay.ui.screens
import com.hermesandroid.relay.ui.components.ChatBusyActionSelector
import android.os.Build
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
@@ -499,6 +500,22 @@ fun ChatSettingsScreen(
HorizontalDivider()
val busyMessageAction by connectionViewModel.busyMessageAction.collectAsState()
Column(verticalArrangement = Arrangement.spacedBy(8.dp)) {
Text(stringResource(R.string.chat_busy_default_title), style = MaterialTheme.typography.bodyMedium)
Text(
stringResource(R.string.chat_busy_default_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
ChatBusyActionSelector(
action = busyMessageAction,
onActionChange = connectionViewModel::setBusyMessageAction,
modifier = Modifier.fillMaxWidth(),
)
}
HorizontalDivider()
val physicalKeyboardEnterBehavior by
connectionViewModel.physicalKeyboardEnterBehavior.collectAsState()
Column(verticalArrangement = Arrangement.spacedBy(8.dp)) {
@@ -6,6 +6,7 @@ import androidx.core.content.FileProvider
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import java.io.File
import java.io.InputStream
import java.security.MessageDigest
/**
@@ -98,7 +99,7 @@ class MediaCacheWriter(
suspend fun cache(bytes: ByteArray, contentType: String, fileName: String?): Uri =
withContext(Dispatchers.IO) {
val dir = cacheRoot
val targetName = buildFilename(bytes, contentType, fileName)
val targetName = buildFilename(bytes.sha1(), contentType, fileName)
val file = File(dir, targetName)
file.writeBytes(bytes)
// Best-effort LRU enforcement — never fatal on a cache operation.
@@ -113,6 +114,45 @@ class MediaCacheWriter(
)
}
/**
* Move a completed streaming download into the media cache without ever
* materializing the file as a ByteArray. The caller retains ownership of
* [source] when this throws; successful calls consume or copy it.
*/
suspend fun cache(source: File, contentType: String, fileName: String?): Uri {
val target = cacheFile(source, contentType, fileName)
return withContext(Dispatchers.IO) {
FileProvider.getUriForFile(
context,
"${context.packageName}.fileprovider",
target,
)
}
}
internal suspend fun cacheFile(source: File, contentType: String, fileName: String?): File =
withContext(Dispatchers.IO) {
require(source.isFile) { "Media cache source does not exist" }
val dir = cacheRoot
val target = File(dir, buildFilename(source.sha1(), contentType, fileName))
if (source.canonicalFile != target.canonicalFile) {
if (target.exists()) {
source.delete()
target.setLastModified(System.currentTimeMillis())
} else if (!source.renameTo(target)) {
source.inputStream().use { input ->
target.outputStream().use { output -> input.copyTo(output) }
}
source.delete()
}
}
try {
enforceCap()
} catch (_: Exception) { /* swallow */ }
target
}
/**
* Wipe the entire `hermes-media/` directory. Returns the number of bytes
* freed so the caller can show a "Freed X MB" snackbar/toast.
@@ -133,15 +173,8 @@ class MediaCacheWriter(
// --- internals ---
private fun buildFilename(bytes: ByteArray, contentType: String, fileName: String?): String {
private fun buildFilename(sha1: String, contentType: String, fileName: String?): String {
val ext = mimeToExt[contentType.lowercase().substringBefore(';').trim()] ?: "bin"
// SHA-1 of the bytes — stable + collision-resistant enough for cache keys.
val sha1 = try {
MessageDigest.getInstance("SHA-1").digest(bytes).joinToString("") { "%02x".format(it) }
} catch (_: Exception) {
// fallback to a weaker but always-available hash
bytes.contentHashCode().toUInt().toString(16)
}
// If the server supplied a filename, keep the base (sanitized) but
// force the extension we derived from the MIME. This keeps the
@@ -162,6 +195,33 @@ class MediaCacheWriter(
}
}
private fun ByteArray.sha1(): String = try {
MessageDigest.getInstance("SHA-1").digest(this).toHexString()
} catch (_: Exception) {
contentHashCode().toUInt().toString(16)
}
private fun File.sha1(): String = try {
inputStream().use { input ->
val digest = MessageDigest.getInstance("SHA-1")
input.updateDigest(digest)
digest.digest().toHexString()
}
} catch (_: Exception) {
"${length().toUInt().toString(16)}-${lastModified().toUInt().toString(16)}"
}
private fun InputStream.updateDigest(digest: MessageDigest) {
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
while (true) {
val read = read(buffer)
if (read < 0) return
digest.update(buffer, 0, read)
}
}
private fun ByteArray.toHexString(): String = joinToString("") { "%02x".format(it) }
/**
* Delete oldest-mtime files until the cache directory fits under the cap.
* Called after every write; safe to call more often.
@@ -14,6 +14,9 @@ import kotlinx.coroutines.withContext
import okhttp3.OkHttpClient
import okhttp3.Request
import java.io.File
import java.io.ByteArrayOutputStream
import java.io.IOException
import java.io.InputStream
import java.util.concurrent.TimeUnit
/**
@@ -39,6 +42,7 @@ object MediaSaver {
private const val SAVE_SUBDIR = "Hermes-Relay"
private const val SHARE_CACHE_DIR = "hermes-media"
private const val MAX_IN_MEMORY_MEDIA_BYTES = 25L * 1024L * 1024L
private val httpClient: OkHttpClient by lazy {
OkHttpClient.Builder()
@@ -70,7 +74,10 @@ object MediaSaver {
httpClient.newCall(request).execute().use { resp ->
if (!resp.isSuccessful) error("HTTP ${resp.code}")
val contentType = resp.header("Content-Type")?.substringBefore(';')?.trim()
val body = resp.body.bytes()
val responseBody = resp.body
val body = responseBody.byteStream().use { input ->
readBoundedBytes(input, responseBody.contentLength())
}
body to contentType
}
}
@@ -78,11 +85,42 @@ object MediaSaver {
/** Read the bytes behind a `content://` (or `file://`) [uri]. */
suspend fun readUriBytes(context: Context, uri: Uri): ByteArray? =
withContext(Dispatchers.IO) {
runCatching {
context.contentResolver.openInputStream(uri)?.use { it.readBytes() }
}.getOrNull()
try {
val declaredLength = context.contentResolver.openAssetFileDescriptor(uri, "r")
?.use { it.length }
?.takeIf { it >= 0L }
?: -1L
context.contentResolver.openInputStream(uri)?.use { input ->
readBoundedBytes(input, declaredLength)
}
} catch (_: Exception) {
null
}
}
private fun readBoundedBytes(input: InputStream, declaredLength: Long): ByteArray {
if (declaredLength > MAX_IN_MEMORY_MEDIA_BYTES) {
throw IOException("Media exceeds Android's in-memory export limit")
}
val initialSize = when {
declaredLength in 1..MAX_IN_MEMORY_MEDIA_BYTES -> declaredLength.toInt()
else -> DEFAULT_BUFFER_SIZE
}
val output = ByteArrayOutputStream(initialSize)
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var total = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
total += read
if (total > MAX_IN_MEMORY_MEDIA_BYTES) {
throw IOException("Media exceeds Android's in-memory export limit")
}
output.write(buffer, 0, read)
}
return output.toByteArray()
}
// --- Save ---------------------------------------------------------------
suspend fun saveImage(
@@ -1,5 +1,7 @@
package com.hermesandroid.relay.viewmodel
import com.hermesandroid.relay.data.BusyMessageAction
import com.hermesandroid.relay.data.canCorrectBusyMessage
import android.content.Context
import android.net.ConnectivityManager
import android.net.NetworkCapabilities
@@ -173,6 +175,8 @@ import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.intOrNull
import kotlinx.serialization.json.longOrNull
import okhttp3.sse.EventSource
import java.io.File
import java.io.IOException
import java.io.InterruptedIOException
import java.util.UUID
import java.util.concurrent.ConcurrentHashMap
@@ -743,6 +747,7 @@ class ChatViewModel : ViewModel() {
private const val CHECKPOINT_WRITE_INTERVAL_MS = 750L
private const val SESSION_REFRESH_RETRY_DELAY_MS = 1_000L
private const val SESSION_REFRESH_MAX_READINESS_RETRIES = 2
private const val MAX_COALESCED_SESSION_REFRESH_PASSES = 2
private const val SESSION_DRAWER_FRESHNESS_WINDOW_MS = 5_000L
private const val PROFILE_SESSION_CACHE_CONTEXTS = 24
private const val PROFILE_SESSION_CACHE_ROWS = 50
@@ -909,6 +914,10 @@ class ChatViewModel : ViewModel() {
)
private val queuedMessageItems = mutableListOf<QueuedMessage>()
private val pausedQueueDestinations = mutableSetOf<Pair<String, String>>()
private val retainedQueueCheckpoints = mutableMapOf<Pair<String, String>, ChatTurnCheckpoint>()
private val _queuePaused = MutableStateFlow(false)
val queuePaused: StateFlow<Boolean> = _queuePaused.asStateFlow()
private val completedQueueOwnerRuns = ConcurrentHashMap.newKeySet<String>()
private val _queuedMessages = MutableStateFlow<List<String>>(emptyList())
val queuedMessages: StateFlow<List<String>> = _queuedMessages.asStateFlow()
@@ -3400,8 +3409,6 @@ class ChatViewModel : ViewModel() {
}
if (visibleSignature != serverSignature) {
handler.loadMessageHistory(serverMessages)
refreshSessions()
scheduleTitleReconcile(storedSessionId)
return@launch
}
if (attempt < 7 && retryUntilChanged) delay(250L)
@@ -4035,7 +4042,7 @@ class ChatViewModel : ViewModel() {
private suspend fun loadSessionHistory(
sessionId: String,
requireProfileScope: Boolean = false,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
profileName: String? = currentSessionProfileName(),
): List<MessageItem> {
if (profileMessageLoader != null) {
@@ -4061,7 +4068,7 @@ class ChatViewModel : ViewModel() {
private suspend fun loadGatewaySessionHistory(
sessionId: String,
requireProfileScope: Boolean = false,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
profileName: String? = currentSessionProfileName(),
): List<MessageItem> {
val scoped = profileMessageLoader?.invoke(profileName, sessionId, mode)
@@ -4799,6 +4806,8 @@ class ChatViewModel : ViewModel() {
publishBackgroundSessionActivity()
queuedMessageItems.clear()
completedQueueOwnerRuns.clear()
pausedQueueDestinations.clear()
retainedQueueCheckpoints.clear()
publishQueuedMessages()
_steerableTurn.value = false
_steerNotice.value = null
@@ -5329,11 +5338,13 @@ class ChatViewModel : ViewModel() {
val sessionPageLoadFailed: StateFlow<Boolean> = _sessionPageLoadFailed.asStateFlow()
val sessionListUnavailable: StateFlow<Boolean> = _sessionListUnavailable.asStateFlow()
fun refreshSessions() = refreshSessions(
allowReadinessRetry = true,
preserveFailurePresentation = false,
readinessRetryAttempt = 0,
)
fun refreshSessions() {
refreshSessions(
allowReadinessRetry = true,
preserveFailurePresentation = false,
readinessRetryAttempt = 0,
)
}
/**
* Drawer-open freshness gate. Process-owned startup binding may already be
@@ -5458,8 +5469,10 @@ class ChatViewModel : ViewModel() {
var retryUnavailable = false
var retryReadiness = false
var refreshPass = 0
try {
do {
refreshPass += 1
sessionRefreshPending = false
// A queued trailing refresh owns a new outcome. Never let
// an earlier timeout overwrite a later successful list.
@@ -5557,7 +5570,7 @@ class ChatViewModel : ViewModel() {
)
} catch (e: CancellationException) {
throw e
} catch (e: Throwable) {
} catch (e: Exception) {
if (isCurrentRefresh()) {
android.util.Log.w(
"ChatViewModel",
@@ -5580,7 +5593,11 @@ class ChatViewModel : ViewModel() {
}
}
}
} while (sessionRefreshPending && isCurrentRefresh())
} while (
refreshPass < MAX_COALESCED_SESSION_REFRESH_PASSES &&
sessionRefreshPending &&
isCurrentRefresh()
)
} finally {
val shouldRetry = allowReadinessRetry &&
retryReadiness &&
@@ -6301,7 +6318,11 @@ class ChatViewModel : ViewModel() {
// --- Message sending ---
fun sendMessage(text: String) {
fun sendMessage(
text: String,
busyAction: BusyMessageAction =
BusyMessageAction.CorrectNow,
) {
if (text.isBlank()) return
supervisedMessageBlockReason(supervisedModePolicy, text)?.let { reason ->
chatHandler?.addSystemNotice(reason)
@@ -6388,9 +6409,13 @@ class ChatViewModel : ViewModel() {
// Mid-turn: redirect on the gateway transport, queue everywhere else.
if (activeStream != null) {
if (
_steerableTurn.value &&
busyAction == BusyMessageAction.CorrectNow &&
(!supervisedModePolicy.enabled || supervisedModePolicy.capabilities.steerResponse) &&
streamingEndpoint == "gateway" &&
_pendingAttachments.value.isEmpty()
canCorrectBusyMessage(
_steerableTurn.value, _pendingAttachments.value.isNotEmpty(),
_pendingAsk.value != null, chatHandler?.turnStatus?.value, text,
)
) {
steerActiveTurn(text.trim())
} else {
@@ -7570,8 +7595,7 @@ class ChatViewModel : ViewModel() {
queuedMessages = queuedMessageItems
.filter {
it.contextKey == contextKey &&
it.sessionId == sessionId &&
it.ownerRunId == seed.userMessageId
it.sessionId == sessionId
}
.map { item ->
ChatQueuedMessageCheckpoint(
@@ -7583,17 +7607,22 @@ class ChatViewModel : ViewModel() {
hadAttachments = item.attachments.isNotEmpty(),
)
},
queuePaused = (contextKey to sessionId) in pausedQueueDestinations,
startedAt = seed.startedAt,
updatedAt = now,
)
}
private fun restoreQueuedMessages(checkpoint: ChatTurnCheckpoint) {
val destination = checkpoint.contextKey to checkpoint.sessionId
if (checkpoint.queuePaused || checkpoint.queueOnly) pausedQueueDestinations += destination
var droppedAttachmentQueue = false
val droppedOwners = mutableMapOf<String, String>()
checkpoint.queuedMessages.forEach { saved ->
if (queuedMessageItems.any { it.id == saved.id }) return@forEach
if (saved.hadAttachments) {
droppedAttachmentQueue = true
droppedOwners[saved.id] = droppedOwners[saved.ownerRunId] ?: saved.ownerRunId
return@forEach
}
queuedMessageItems += QueuedMessage(
@@ -7602,11 +7631,16 @@ class ChatViewModel : ViewModel() {
contextKey = checkpoint.contextKey,
sessionId = checkpoint.sessionId,
transport = saved.transport,
ownerRunId = saved.ownerRunId,
ownerRunId = droppedOwners[saved.ownerRunId] ?: saved.ownerRunId,
attachments = emptyList(),
interfaceContextPrompt = saved.interfaceContextPrompt,
)
}
if (checkpoint.queueOnly) {
val ids = queuedMessageItems.mapTo(mutableSetOf()) { it.id }
queuedMessageItems.filter { it.contextKey == checkpoint.contextKey && it.sessionId == checkpoint.sessionId }
.map { it.ownerRunId }.filterNot { it in ids }.forEach { completedQueueOwnerRuns += it }
}
publishQueuedMessages()
if (droppedAttachmentQueue) {
_transientNotice.tryEmit(
@@ -7641,10 +7675,12 @@ class ChatViewModel : ViewModel() {
}
}
private fun clearTurnCheckpoint() {
private fun clearTurnCheckpoint(preserveQueue: Boolean = false) {
val queueSnapshot = if (preserveQueue) buildQueueOnlyCheckpoint() else null
queueSnapshot?.let { retainedQueueCheckpoints[it.contextKey to it.sessionId] = it }
val key = activeTurnCheckpointSeed?.let { seed ->
seed.contextKey?.let { TurnCheckpointKey(it, seed.sessionId) }
}
} ?: queueSnapshot?.let { TurnCheckpointKey(it.contextKey, it.sessionId) }
activeTurnCheckpointSeed = null
activeQueueOwnerRunId = null
val generation = checkpointGeneration.incrementAndGet()
@@ -7661,7 +7697,8 @@ class ChatViewModel : ViewModel() {
viewModelScope.launch {
checkpointMutex.withLock {
if (generation == checkpointGeneration.get() && activeTurnCheckpointSeed == null) {
if (key != null) runCatching { store.remove(key.contextKey, key.sessionId) }
if (queueSnapshot != null) runCatching { store.write(queueSnapshot) }
else if (key != null) runCatching { store.remove(key.contextKey, key.sessionId) }
}
}
}
@@ -7791,6 +7828,11 @@ class ChatViewModel : ViewModel() {
backgroundNeedsInputKeys -= key
publishBackgroundSessionActivity()
if (checkpoint.transport !in setOf("gateway", "sessions")) return false
if (checkpoint.queueOnly) {
retainedQueueCheckpoints[contextKey to sessionId] = checkpoint
restoreQueuedMessages(checkpoint)
return false
}
if (activeStream != null) return true
if (streamRecovery != null) {
if (checkpoint.transport == "gateway" && client != null) {
@@ -7804,7 +7846,13 @@ class ChatViewModel : ViewModel() {
}
adoptTurnCheckpoint(checkpoint)
val initialHistory = runCatching { loadSessionHistory(sessionId) }.getOrDefault(emptyList())
val initialHistory = try {
loadSessionHistory(sessionId)
} catch (error: CancellationException) {
throw error
} catch (_: Exception) {
emptyList()
}
if (!ownsTurnCheckpoint(checkpoint, handler)) return true
if (initialHistory.isNotEmpty()) handler.loadMessageHistory(initialHistory)
handler.restoreInFlightTurn(checkpoint)
@@ -8217,7 +8265,7 @@ class ChatViewModel : ViewModel() {
if (completedOwner != null && queuedMessageItems.any { it.ownerRunId == completedOwner }) {
completedQueueOwnerRuns += completedOwner
}
clearTurnCheckpoint()
clearTurnCheckpoint(preserveQueue = true)
activeStream = null
_steerableTurn.value = false
_steerNotice.value = null
@@ -8461,6 +8509,106 @@ class ChatViewModel : ViewModel() {
it.contextKey == destination.first && it.sessionId == destination.second
}.map(QueuedMessage::text)
}
_queuePaused.value = _queuedMessages.value.isNotEmpty() && destination in pausedQueueDestinations
}
private fun persistQueueChanges() {
scheduleCheckpointWrite(immediate = true)
val destination = currentQueueDestination() ?: return
if (activeTurnCheckpointSeed?.let { it.contextKey to it.sessionId } == destination) return
val template = retainedQueueCheckpoints[destination] ?: return
val items = queuedMessageItems.filter { it.contextKey to it.sessionId == destination }
val snapshot = template.copy(
queuePaused = destination in pausedQueueDestinations,
queuedMessages = items.map { item ->
ChatQueuedMessageCheckpoint(
id = item.id,
text = item.text.take(MAX_CHECKPOINT_TEXT_CHARS),
transport = item.transport,
ownerRunId = item.ownerRunId,
interfaceContextPrompt = item.interfaceContextPrompt,
hadAttachments = item.attachments.isNotEmpty(),
)
},
updatedAt = System.currentTimeMillis(),
)
if (items.isEmpty()) retainedQueueCheckpoints.remove(destination)
else retainedQueueCheckpoints[destination] = snapshot
val generation = checkpointGeneration.get()
val store = chatTurnCheckpointStore ?: return
viewModelScope.launch {
checkpointMutex.withLock {
if (generation != checkpointGeneration.get()) return@withLock
runCatching {
if (items.isEmpty()) store.remove(destination.first, destination.second)
else store.write(snapshot)
}
}
}
}
private fun buildQueueOnlyCheckpoint(): ChatTurnCheckpoint? {
val destination = currentQueueDestination() ?: return null
val items = queuedMessageItems.filter { (it.contextKey to it.sessionId) == destination }
if (items.isEmpty()) return null
buildTurnCheckpoint()?.let { return it.copy(queueOnly = true, pendingAsk = null) }
// A server-initiated turn has no outgoing user checkpoint. Retain only
// queue ownership metadata; queueOnly restoration never renders these
// empty turn fields or attempts to reattach the cancelled runtime.
val now = System.currentTimeMillis()
return ChatTurnCheckpoint(
contextKey = destination.first,
sessionId = destination.second,
transport = items.first().transport,
user = ChatTurnUserCheckpoint(items.first().ownerRunId, "", now),
assistant = ChatTurnAssistantCheckpoint(id = items.first().ownerRunId, timestamp = now, isStreaming = false),
priorUserMessageCount = 0,
baselineAssistantCount = 0,
queuedMessages = items.map { item ->
ChatQueuedMessageCheckpoint(
item.id, item.text.take(MAX_CHECKPOINT_TEXT_CHARS), item.transport,
item.ownerRunId, item.interfaceContextPrompt, item.attachments.isNotEmpty(),
)
},
queuePaused = destination in pausedQueueDestinations,
queueOnly = true,
startedAt = now,
updatedAt = now,
)
}
/** Stop preserves pending work. Resume is explicit and always keeps its destination. */
fun resumeQueue() {
val destination = currentQueueDestination() ?: return
val first = queuedMessageItems.firstOrNull { it.contextKey to it.sessionId == destination } ?: return
if (activeStream != null) {
val owner = activeQueueOwnerRunId ?: return
val index = queuedMessageItems.indexOf(first)
queuedMessageItems[index] = first.copy(ownerRunId = owner)
} else {
completedQueueOwnerRuns += first.ownerRunId
}
pausedQueueDestinations -= destination
publishQueuedMessages()
persistQueueChanges()
drainQueue()
}
private fun removeQueuedItem(item: QueuedMessage) {
queuedMessageItems.removeAll { it.id == item.id }
// Splice the run chain: successors now wait for the removed item's
// predecessor, never for a deleted turn that can no longer complete.
queuedMessageItems.replaceAll { next ->
if (next.contextKey == item.contextKey && next.sessionId == item.sessionId && next.ownerRunId == item.id) {
next.copy(ownerRunId = item.ownerRunId)
} else next
}
if (queuedMessageItems.none { it.ownerRunId == item.ownerRunId }) completedQueueOwnerRuns -= item.ownerRunId
if (queuedMessageItems.none { it.contextKey == item.contextKey && it.sessionId == item.sessionId }) {
pausedQueueDestinations -= item.contextKey to item.sessionId
}
publishQueuedMessages()
persistQueueChanges()
}
private fun removeQueuedMessagesFor(contextKey: String?, sessionId: String): Int {
@@ -8486,6 +8634,9 @@ class ChatViewModel : ViewModel() {
fun clearQueue() {
val destination = currentQueueDestination() ?: return
removeQueuedMessagesFor(destination.first, destination.second)
pausedQueueDestinations -= destination
publishQueuedMessages()
persistQueueChanges()
}
/** Drop a single queued message by index (no-op if out of range). */
@@ -8495,11 +8646,7 @@ class ChatViewModel : ViewModel() {
it.contextKey == destination.first && it.sessionId == destination.second
}
val item = visible.getOrNull(index) ?: return
queuedMessageItems.removeAll { it.id == item.id }
if (queuedMessageItems.none { it.ownerRunId == item.ownerRunId }) {
completedQueueOwnerRuns -= item.ownerRunId
}
publishQueuedMessages()
removeQueuedItem(item)
}
/**
@@ -8507,14 +8654,15 @@ class ChatViewModel : ViewModel() {
* the composer can prefill it. Null if the index is out of range.
*/
fun takeQueuedForEdit(index: Int): String? {
if (_pendingAttachments.value.isNotEmpty()) {
_transientNotice.tryEmit("Finish the current attachment draft before editing a queued message.")
return null
}
val destination = currentQueueDestination() ?: return null
val item = queuedMessageItems.filter {
it.contextKey == destination.first && it.sessionId == destination.second
}.getOrNull(index) ?: return null
queuedMessageItems.removeAll { it.id == item.id }
if (queuedMessageItems.none { it.ownerRunId == item.ownerRunId }) {
completedQueueOwnerRuns -= item.ownerRunId
}
removeQueuedItem(item)
_pendingAttachments.value = item.attachments
nextInterfaceContextPrompt = item.interfaceContextPrompt
publishQueuedMessages()
@@ -8528,6 +8676,7 @@ class ChatViewModel : ViewModel() {
if (streamingEndpoint == "gateway" && gatewayClient == null && client == null) return
if (activeStream != null || streamRecovery != null) return
val destination = currentQueueDestination() ?: return
if (destination in pausedQueueDestinations) return
val next = queuedMessageItems.firstOrNull {
it.contextKey == destination.first &&
it.sessionId == destination.second &&
@@ -9758,6 +9907,11 @@ class ChatViewModel : ViewModel() {
handler.onTurnComplete(currentMessageId)
gatewayInterimMessageId = currentMessageId
gatewayInterimSealedCurrentMessage = true
// `message.interim` closes one assistant segment but not the
// agent run. Create the next blank owner immediately so the chat
// retains its in-conversation working indicator even when the
// next tool/reasoning event is delayed or suppressed upstream.
ensurePostInterimMessage()
scheduleCheckpointWrite(immediate = true)
}
val onInterimReconciledCb = { text: String ->
@@ -10123,12 +10277,16 @@ class ChatViewModel : ViewModel() {
(streamingEndpoint == "sessions" || streamingEndpoint == "gateway")
) {
viewModelScope.launch {
runCatching {
try {
// Profile-aware read — see onCompleteCb: a bare
// getMessages 404s for a non-default-profile session
// and silently empties the transcript.
val serverMessages = loadSessionHistory(errorSessionId)
handler.loadMessageHistory(serverMessages)
} catch (error: CancellationException) {
throw error
} catch (_: Exception) {
// The existing local failure remains authoritative.
}
}
}
@@ -10531,6 +10689,10 @@ class ChatViewModel : ViewModel() {
_steerableTurn.value = false
onPreflightErrorCb(Exception(reason))
},
onSubmitRejected = { reason ->
_steerableTurn.value = false
onPreflightErrorCb(Exception(reason))
},
onFailure = { failure ->
val confirmedModel = gateway.serverModel.value
?.takeIf { it.isNotBlank() }
@@ -10580,7 +10742,7 @@ class ChatViewModel : ViewModel() {
_steerableTurn.value = false
onPreflightErrorCb(Exception(reason))
},
onPreflightFailure = {
onPreflightFailure = { reason ->
_steerableTurn.value = false
if (intentionallyCancelled) {
// User cancelled while preflight was in flight —
@@ -10592,11 +10754,11 @@ class ChatViewModel : ViewModel() {
// Nothing started server-side. Keep this turn bound
// to Gateway and settle it as retryable local state;
// API sessions are a different owner/database.
onPreflightErrorCb(
IllegalStateException(
"Hermes Dashboard chat is unavailable. Sign in or reconnect, then retry.",
),
)
// Preserve the authoritative Gateway explanation.
// Inference initialization failures happen before
// prompt.submit, and replacing them with generic
// reconnect advice hides the actual operator fix.
onPreflightErrorCb(IllegalStateException(reason))
}
},
)
@@ -10669,6 +10831,13 @@ class ChatViewModel : ViewModel() {
fun cancelStream() {
intentionallyCancelled = true
currentQueueDestination()?.let { destination ->
if (queuedMessageItems.any { it.contextKey to it.sessionId == destination }) {
pausedQueueDestinations += destination
activeQueueOwnerRunId?.let { completedQueueOwnerRuns += it }
}
}
publishQueuedMessages()
// User Stop also aborts a dropped-stream answer recovery. settleUi
// false: the Stopped-badge block below finalizes the placeholder
// itself (completing it here first would hide it from findLast).
@@ -10679,13 +10848,12 @@ class ChatViewModel : ViewModel() {
activeStream = null
imageActivityJob?.cancel()
imageActivityJob = null
clearQueue()
_steerableTurn.value = false
_steerNotice.value = null
// Gateway cancel issues session.interrupt, which force-denies any
// blocked approval server-side — stamp the card to match.
clearPendingAskAfterInterrupt()
clearTurnCheckpoint()
clearTurnCheckpoint(preserveQueue = true)
AppAnalytics.onStreamCancelled()
chatHandler?.let { handler ->
val streamingMsg = handler.messages.value.findLast { it.isStreaming }
@@ -10723,7 +10891,7 @@ class ChatViewModel : ViewModel() {
* placeholder as actionable FAILED with [MEDIA_TAP_TO_DOWNLOAD] in
* [Attachment.errorMessage]. The UI renders a retry card.
* 4. Otherwise → kick off a background fetch, enforce the max size cap,
* cache the bytes via [MediaCacheWriter], and update the attachment
* stream into [MediaCacheWriter], and update the attachment
* to LOADED (or FAILED on any error).
*
* Note: the matching happens by (messageId + relayToken). If the same
@@ -10787,7 +10955,10 @@ class ChatViewModel : ViewModel() {
expectedHistoryGeneration = historyGeneration,
) { _ ->
if (relay.mediaUrlConfigured()) {
relay.fetchMedia(token, maxBytes = settings.maxInboundSizeMb.toLong().coerceAtLeast(1L) * 1024L * 1024L)
relay.fetchMedia(
token,
maxBytes = settings.maxInboundSizeMb.toLong().coerceAtLeast(1L) * 1024L * 1024L,
).asInboundFetchedMedia()
} else {
Result.failure(MediaRouteUnavailableException())
}
@@ -10850,7 +11021,7 @@ class ChatViewModel : ViewModel() {
fetchServerPath(fetchKey, maxBytes, upstreamMediaClient)
} else {
if (relay.mediaUrlConfigured()) {
relay.fetchMedia(fetchKey, maxBytes = maxBytes)
relay.fetchMedia(fetchKey, maxBytes = maxBytes).asInboundFetchedMedia()
} else {
Result.failure(MediaRouteUnavailableException())
}
@@ -10909,7 +11080,22 @@ class ChatViewModel : ViewModel() {
return ServerImageResult.Failure("Connection changed while loading image")
}
return result.fold(
onSuccess = { ServerImageResult.Success(it.bytes, it.sensitive) },
onSuccess = { fetched ->
try {
val cachedUri = fetched.cachedUri ?: mediaCacheWriter?.cache(
requireNotNull(fetched.bytes),
fetched.contentType,
fetched.fileName,
)?.toString()
if (cachedUri == null) {
ServerImageResult.Failure("Media cache is unavailable")
} else {
ServerImageResult.Success(cachedUri, fetched.sensitive)
}
} catch (error: Exception) {
ServerImageResult.Failure(error.message ?: "Image cache failed")
}
},
onFailure = { ServerImageResult.Failure(it.message ?: "Image unavailable") },
)
}
@@ -11031,17 +11217,39 @@ class ChatViewModel : ViewModel() {
serverPath: String,
maxBytes: Long,
upstream: DashboardApiClient?,
): Result<RelayHttpClient.FetchedMedia> {
): Result<InboundFetchedMedia> {
if (upstream != null) {
val upstreamResult = upstream.downloadManagedFile(serverPath, maxBytes)
.map { fetched ->
RelayHttpClient.FetchedMedia(
contentType = fetched.contentType,
bytes = fetched.bytes,
fileName = fetched.fileName,
sensitive = false,
val cache = mediaCacheWriter
?: return Result.failure(IOException("Media cache is unavailable"))
val context = appContext
?: return Result.failure(IOException("Application context is unavailable"))
val staging = File.createTempFile("hermes-media-", ".part", context.cacheDir)
val upstreamResult = try {
val fetchedResult = staging.outputStream().buffered().use { output ->
upstream.downloadManagedFile(serverPath, maxBytes, output)
}
if (fetchedResult.isFailure) {
Result.failure(fetchedResult.exceptionOrNull()!!)
} else {
val fetched = fetchedResult.getOrThrow()
val uri = cache.cache(staging, fetched.contentType, fetched.fileName)
Result.success(
InboundFetchedMedia(
contentType = fetched.contentType,
fileName = fetched.fileName,
sensitive = false,
sizeBytes = fetched.sizeBytes,
cachedUri = uri.toString(),
),
)
}
} catch (error: CancellationException) {
throw error
} catch (error: Exception) {
Result.failure(error)
} finally {
staging.delete()
}
if (upstreamResult.isSuccess) return upstreamResult
val upstreamFailure = upstreamResult.exceptionOrNull()
if (upstreamFailure?.isDashboardManagedFilesUnsupported() != true) {
@@ -11050,13 +11258,14 @@ class ChatViewModel : ViewModel() {
val relay = relayHttpClient
if (relay?.mediaUrlConfigured() == true) {
return relay.fetchMediaByPath(serverPath, maxBytes = maxBytes)
.asInboundFetchedMedia()
}
return Result.failure(MediaRouteUnavailableException(upstreamFailure))
}
val relay = relayHttpClient
return if (relay?.mediaUrlConfigured() == true) {
relay.fetchMediaByPath(serverPath, maxBytes = maxBytes)
relay.fetchMediaByPath(serverPath, maxBytes = maxBytes).asInboundFetchedMedia()
} else {
Result.failure(MediaRouteUnavailableException())
}
@@ -11096,7 +11305,7 @@ class ChatViewModel : ViewModel() {
expectedRole: MessageRole = MessageRole.ASSISTANT,
expectedContextKey: String? = activeProfileContextKey,
expectedHistoryGeneration: Int = historyLoadGeneration.get(),
fetch: suspend (maxBytes: Long) -> Result<RelayHttpClient.FetchedMedia>,
fetch: suspend (maxBytes: Long) -> Result<InboundFetchedMedia>,
) {
val cache = mediaCacheWriter ?: return
val maxBytes = settings.maxInboundSizeMb.toLong().coerceAtLeast(1) * 1024L * 1024L
@@ -11117,8 +11326,8 @@ class ChatViewModel : ViewModel() {
) return
result.fold(
onSuccess = { fetched ->
if (fetched.bytes.size > maxBytes) {
val sizeMb = fetched.bytes.size / (1024.0 * 1024.0)
if (fetched.sizeBytes > maxBytes) {
val sizeMb = fetched.sizeBytes / (1024.0 * 1024.0)
updateAttachmentByToken(handler, messageId, fetchKey, expectedRole = expectedRole) { att ->
att.copy(
state = AttachmentState.FAILED,
@@ -11127,22 +11336,26 @@ class ChatViewModel : ViewModel() {
),
contentType = fetched.contentType,
fileName = fetched.fileName ?: att.fileName,
fileSize = fetched.bytes.size.toLong()
fileSize = fetched.sizeBytes
)
}
return
}
try {
val uri = cache.cache(fetched.bytes, fetched.contentType, fetched.fileName)
val cachedUri = fetched.cachedUri ?: cache.cache(
requireNotNull(fetched.bytes),
fetched.contentType,
fetched.fileName,
).toString()
updateAttachmentByToken(handler, messageId, fetchKey, expectedRole = expectedRole) { att ->
att.copy(
state = AttachmentState.LOADED,
errorMessage = null,
contentType = fetched.contentType,
fileName = fetched.fileName ?: att.fileName,
fileSize = fetched.bytes.size.toLong(),
cachedUri = uri.toString(),
fileSize = fetched.sizeBytes,
cachedUri = cachedUri,
// Carry the relay-authoritative sensitivity bit
// (X-Media-Sensitive header) onto the LOADED
// attachment so the renderer can blur per the
@@ -11188,6 +11401,26 @@ class ChatViewModel : ViewModel() {
)
}
private data class InboundFetchedMedia(
val contentType: String,
val fileName: String?,
val sensitive: Boolean,
val sizeBytes: Long,
val bytes: ByteArray? = null,
val cachedUri: String? = null,
)
private fun Result<RelayHttpClient.FetchedMedia>.asInboundFetchedMedia(): Result<InboundFetchedMedia> =
map { fetched ->
InboundFetchedMedia(
contentType = fetched.contentType,
fileName = fetched.fileName,
sensitive = fetched.sensitive,
sizeBytes = fetched.bytes.size.toLong(),
bytes = fetched.bytes,
)
}
/**
* Append an attachment to a specific assistant message, matched by id.
* No-ops if the message can't be found (e.g. it was trimmed from the
@@ -1,5 +1,6 @@
package com.hermesandroid.relay.viewmodel
import com.hermesandroid.relay.data.BusyMessageAction
import android.app.Application
import android.os.Build
import android.content.Context
@@ -2387,13 +2388,13 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
suspend fun loadProfileScopedMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>>? = profileController.loadProfileScopedMessages(sessionId, mode)
suspend fun loadProfileScopedMessages(
profileName: String?,
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>>? =
profileController.loadProfileScopedMessages(profileName, sessionId, mode)
@@ -3090,6 +3091,13 @@ class ConnectionViewModel(application: Application) : AndroidViewModel(applicati
}
}
val busyMessageAction = chatInputPreferencesRepository.busyMessageAction
.stateIn(viewModelScope, SharingStarted.Eagerly, BusyMessageAction.CorrectNow)
fun setBusyMessageAction(action: BusyMessageAction) {
viewModelScope.launch { chatInputPreferencesRepository.setBusyMessageAction(action) }
}
val physicalKeyboardEnterBehavior: StateFlow<PhysicalKeyboardEnterBehavior> =
chatInputPreferencesRepository.physicalKeyboardEnterBehavior
.stateIn(
@@ -909,7 +909,7 @@ class ProfileController(
*/
suspend fun loadProfileScopedMessages(
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>>? = loadProfileScopedMessages(
profileName = resolveSessionProfileName(),
sessionId = sessionId,
@@ -919,7 +919,7 @@ class ProfileController(
suspend fun loadProfileScopedMessages(
profileName: String?,
sessionId: String,
mode: SessionMessageLoadMode = SessionMessageLoadMode.COMPLETE,
mode: SessionMessageLoadMode = SessionMessageLoadMode.LATEST,
): Result<List<MessageItem>>? {
val connectionId = activeConnectionId.value ?: return null
val dashboardUrl = activeDashboardUrlProvider() ?: return null
@@ -122,6 +122,7 @@
<string name="chat_retry">Tentar novamente</string>
<string name="chat_dismiss">Dispensar</string>
<string name="chat_failure_title">O Hermes não conseguiu concluir esta resposta</string>
<string name="chat_failure_inference_unavailable">Inferência indisponível</string>
<string name="chat_failure_details">Detalhes</string>
<string name="chat_failure_details_title">Falha na resposta</string>
<string name="chat_failure_details_guidance">O Hermes relatou este erro. O app não mudará de rota nem de modelo automaticamente.</string>
@@ -4420,4 +4421,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">Erro de voz</string>
<string name="chat_correct_now">Corrigir agora</string>
<string name="chat_queue_next">Enviar depois</string>
<string name="chat_busy_default_title">Durante a resposta</string>
<string name="chat_busy_default_description">Escolha o que Enviar faz enquanto o Hermes trabalha. Este padrão do dispositivo também vale no campo de mensagem. Anexos e correções indisponíveis entram na fila.</string>
<string name="chat_queue_paused">Fila pausada</string>
<string name="chat_queue_resume">Retomar</string>
<string name="chat_queue_remove">Remover mensagem da fila</string>
</resources>
@@ -136,6 +136,7 @@
<string name="chat_retry">重试</string>
<string name="chat_dismiss">关闭</string>
<string name="chat_failure_title">Hermes 无法完成此回复</string>
<string name="chat_failure_inference_unavailable">推理服务不可用</string>
<string name="chat_failure_details">详情</string>
<string name="chat_failure_details_title">回复失败</string>
<string name="chat_failure_details_guidance">Hermes 报告了此错误。应用不会自动切换路由或模型。</string>
@@ -4501,4 +4502,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">语音错误</string>
<string name="chat_correct_now">立即纠正</string>
<string name="chat_queue_next">稍后发送</string>
<string name="chat_busy_default_title">回复期间</string>
<string name="chat_busy_default_description">选择 Hermes 工作时发送按钮的行为。此设备默认设置与输入框共用。附件及无法立即纠正的消息将进入队列。</string>
<string name="chat_queue_paused">队列已暂停</string>
<string name="chat_queue_resume">继续</string>
<string name="chat_queue_remove">移除队列消息</string>
</resources>
+9
View File
@@ -136,6 +136,7 @@
<string name="chat_retry">Erneut versuchen</string>
<string name="chat_dismiss">Schließen</string>
<string name="chat_failure_title">Hermes konnte diese Antwort nicht abschließen</string>
<string name="chat_failure_inference_unavailable">Inferenz nicht verfügbar</string>
<string name="chat_failure_details">Details</string>
<string name="chat_failure_details_title">Antwortfehler</string>
<string name="chat_failure_details_guidance">Hermes hat diesen Fehler gemeldet. Die App wechselt Routen oder Modelle nicht automatisch.</string>
@@ -4577,4 +4578,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">Sprachfehler</string>
<string name="chat_correct_now">Jetzt korrigieren</string>
<string name="chat_queue_next">Danach senden</string>
<string name="chat_busy_default_title">Während der Antwort</string>
<string name="chat_busy_default_description">Wähle, was Senden während der Arbeit ausführt. Dieser geräteweite Standard gilt auch im Eingabefeld. Anhänge und nicht verfügbare Korrekturen werden eingereiht.</string>
<string name="chat_queue_paused">Warteschlange pausiert</string>
<string name="chat_queue_resume">Fortsetzen</string>
<string name="chat_queue_remove">Nachricht aus Warteschlange entfernen</string>
</resources>
+9
View File
@@ -113,6 +113,7 @@
<string name="chat_retry">Reintentar</string>
<string name="chat_dismiss">Descartar</string>
<string name="chat_failure_title">Hermes no pudo completar esta respuesta</string>
<string name="chat_failure_inference_unavailable">Inferencia no disponible</string>
<string name="chat_failure_details">Detalles</string>
<string name="chat_failure_details_title">Error de respuesta</string>
<string name="chat_failure_details_guidance">Hermes informó de este error. La aplicación no cambiará automáticamente de ruta ni de modelo.</string>
@@ -4268,4 +4269,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">Error de voz</string>
<string name="chat_correct_now">Corregir ahora</string>
<string name="chat_queue_next">Enviar después</string>
<string name="chat_busy_default_title">Durante la respuesta</string>
<string name="chat_busy_default_description">Elige qué hace Enviar mientras Hermes trabaja. Este ajuste del dispositivo también se usa en el cuadro de mensaje. Los adjuntos y las correcciones no disponibles se ponen en cola.</string>
<string name="chat_queue_paused">Cola pausada</string>
<string name="chat_queue_resume">Reanudar</string>
<string name="chat_queue_remove">Quitar mensaje de la cola</string>
</resources>
+9
View File
@@ -136,6 +136,7 @@
<string name="chat_retry">リトライ</string>
<string name="chat_dismiss">却下する</string>
<string name="chat_failure_title">Hermes はこの応答を完了できませんでした</string>
<string name="chat_failure_inference_unavailable">推論を利用できません</string>
<string name="chat_failure_details">詳細</string>
<string name="chat_failure_details_title">応答エラー</string>
<string name="chat_failure_details_guidance">Hermes からこのエラーが報告されました。アプリがルートやモデルを自動的に切り替えることはありません。</string>
@@ -4572,4 +4573,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">音声エラー</string>
<string name="chat_correct_now">今すぐ修正</string>
<string name="chat_queue_next">次に送信</string>
<string name="chat_busy_default_title">応答中の動作</string>
<string name="chat_busy_default_description">Hermesの作業中に送信する際の動作を選択します。この端末の設定は入力欄と共通です。添付ファイルや修正できない場合はキューに追加します。</string>
<string name="chat_queue_paused">キューを一時停止中</string>
<string name="chat_queue_resume">再開</string>
<string name="chat_queue_remove">キューからメッセージを削除</string>
</resources>
+9
View File
@@ -130,6 +130,7 @@
<string name="chat_retry">Повторить</string>
<string name="chat_dismiss">Отменить</string>
<string name="chat_failure_title">Hermes не смог завершить ответ</string>
<string name="chat_failure_inference_unavailable">Генерация ответа недоступна</string>
<string name="chat_failure_details">Подробности</string>
<string name="chat_failure_details_title">Ошибка ответа</string>
<string name="chat_failure_details_guidance">Hermes сообщил об этой ошибке. Приложение не будет автоматически менять маршрут или модель.</string>
@@ -4316,4 +4317,12 @@
<string name="active_section_unavailable">Unavailable</string>
<string name="detail_inactive_badge">Not active</string>
<string name="detail_overview_clarity_summary">What works now, the path this phone is using, and what can take over if it becomes unavailable.</string>
<string name="voice_overlay_error_title">Ошибка голосового режима</string>
<string name="chat_correct_now">Исправить сейчас</string>
<string name="chat_queue_next">Отправить позже</string>
<string name="chat_busy_default_title">Во время ответа</string>
<string name="chat_busy_default_description">Выберите действие отправки, пока Hermes работает. Настройка общая для устройства и поля ввода. Вложения и недоступные исправления добавляются в очередь.</string>
<string name="chat_queue_paused">Очередь приостановлена</string>
<string name="chat_queue_resume">Продолжить</string>
<string name="chat_queue_remove">Удалить сообщение из очереди</string>
</resources>
+9
View File
@@ -140,6 +140,7 @@
<string name="chat_retry">Retry</string>
<string name="chat_dismiss">Dismiss</string>
<string name="chat_failure_title">Hermes couldn’t complete this response</string>
<string name="chat_failure_inference_unavailable">Inference unavailable</string>
<string name="chat_failure_details">Details</string>
<string name="chat_failure_details_title">Response failure</string>
<string name="chat_failure_details_guidance">Hermes reported this error. The app won’t switch routes or models automatically.</string>
@@ -4593,4 +4594,12 @@
<string name="settings_git_workspace">Git workspace</string>
<string name="settings_git_workspace_desc">Current-session Git first, with optional host discovery</string>
<string name="settings_git_workspace_off_desc">Session repository only · Host discovery is opt-in</string>
<string name="voice_overlay_error_title">Voice error</string>
<string name="chat_correct_now">Correct now</string>
<string name="chat_queue_next">Queue next</string>
<string name="chat_busy_default_title">While responding</string>
<string name="chat_busy_default_description">Choose what Send does while Hermes is working. This device-wide default is shared with the composer. Attachments and unavailable corrections queue instead.</string>
<string name="chat_queue_paused">Queue paused</string>
<string name="chat_queue_resume">Resume</string>
<string name="chat_queue_remove">Remove queued message</string>
</resources>
@@ -15,6 +15,26 @@ import org.junit.Test
class ChatInputPreferencesTest {
@Test
fun `busy action defaults to correction and is shared after repository recreation`() = runTest {
val store = InMemoryChatInputDataStore()
val repository = ChatInputPreferencesRepository(store)
assertEquals(BusyMessageAction.CorrectNow, repository.busyMessageAction.first())
repository.setBusyMessageAction(BusyMessageAction.QueueNext)
assertEquals(BusyMessageAction.QueueNext, ChatInputPreferencesRepository(store).busyMessageAction.first())
assertEquals(BusyMessageAction.CorrectNow, BusyMessageAction.fromStoredValue("unknown"))
}
@Test
fun `correction availability rejects attachments blocked input compaction and slash commands`() {
assertEquals(true, canCorrectBusyMessage(true, false, false, null, "Correct this"))
assertEquals(false, canCorrectBusyMessage(false, false, false, null, "Correct this"))
assertEquals(false, canCorrectBusyMessage(true, true, false, null, "Correct this"))
assertEquals(false, canCorrectBusyMessage(true, false, true, null, "Correct this"))
assertEquals(false, canCorrectBusyMessage(true, false, false, "Compacting context", "Correct this"))
assertEquals(false, canCorrectBusyMessage(true, false, false, null, "/model next"))
}
@Test
fun `large paste conversion defaults on and round trips`() = runTest {
val store = InMemoryChatInputDataStore()
@@ -13,6 +13,8 @@ import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.jsonObject
import okhttp3.HttpUrl.Companion.toHttpUrl
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.ResponseBody.Companion.toResponseBody
import okhttp3.mockwebserver.MockResponse
import okhttp3.mockwebserver.MockWebServer
import okhttp3.mockwebserver.SocketPolicy
@@ -31,6 +33,23 @@ import java.util.concurrent.TimeUnit
class DashboardApiClientTest {
@Test
fun boundedJsonReaderRejectsDeclaredAndObservedOverflow() {
val declared = "{}".toResponseBody("application/json".toMediaType())
assertThrows(IOException::class.java) {
declared.readUtf8Bounded(1)
}
val chunked = object : okhttp3.ResponseBody() {
override fun contentType() = "application/json".toMediaType()
override fun contentLength() = -1L
override fun source() = Buffer().writeUtf8("{\"value\":123}")
}
assertThrows(IOException::class.java) {
chunked.readUtf8Bounded(8)
}
}
@Test
fun `multiplex API routing uses served profiles instead of installed inventory`() {
val status = DashboardStatus(
@@ -1466,7 +1485,7 @@ class DashboardApiClientTest {
assertEquals("mizu", url.queryParameter("profile"))
assertEquals("500", url.queryParameter("limit"))
assertEquals("0", url.queryParameter("offset"))
assertEquals("oldest", url.queryParameter("order"))
assertEquals("latest", url.queryParameter("order"))
assertEquals(2, messages.size)
assertEquals("user", messages[0].role)
assertEquals("assistant", messages[1].role)
@@ -1478,7 +1497,11 @@ class DashboardApiClientTest {
server.enqueue(messagePageResponse(key = "messages", start = 500, count = 1, returned = 1))
val messages = DashboardApiClient(baseUrl = server.url("/").toString())
.getSessionMessages("sess-a", profile = "mizu")
.getSessionMessages(
"sess-a",
profile = "mizu",
mode = SessionMessageLoadMode.COMPLETE,
)
.getOrThrow()
val first = server.takeRequest().requestUrl!!
@@ -2042,13 +2065,15 @@ class DashboardApiClientTest {
.setBody("audio-bytes"),
)
val output = ByteArrayOutputStream()
val fetched = DashboardApiClient(baseUrl = server.url("/").toString())
.downloadManagedFile("/tmp/Hermes audio/voice reply.mp3", 1024)
.downloadManagedFile("/tmp/Hermes audio/voice reply.mp3", 1024, output)
.getOrThrow()
assertEquals("audio/mpeg", fetched.contentType)
assertEquals("voice reply.mp3", fetched.fileName)
assertEquals("audio-bytes", fetched.bytes.decodeToString())
assertEquals(11L, fetched.sizeBytes)
assertEquals("audio-bytes", output.toString(Charsets.UTF_8.name()))
val request = server.takeRequest()
assertEquals("/api/files/download", request.requestUrl!!.encodedPath)
assertEquals("/tmp/Hermes audio/voice reply.mp3", request.requestUrl!!.queryParameter("path"))
@@ -2059,11 +2084,28 @@ class DashboardApiClientTest {
server.enqueue(MockResponse().setHeader("Content-Length", 2048))
val result = DashboardApiClient(baseUrl = server.url("/").toString())
.downloadManagedFile("/tmp/large.bin", 1024)
.downloadManagedFile("/tmp/large.bin", 1024, ByteArrayOutputStream())
assertTrue(result.isFailure)
}
@Test
fun downloadManagedFile_rejectsChunkedBodyAfterStreamingCap() = runTest {
server.enqueue(
MockResponse()
.setHeader("Content-Type", "application/octet-stream")
.setChunkedBody("seventeen-byte-doc", 3),
)
val output = ByteArrayOutputStream()
val result = DashboardApiClient(baseUrl = server.url("/").toString())
.downloadManagedFile("/tmp/growing.bin", 16, output)
assertTrue(result.isFailure)
assertTrue(result.exceptionOrNull()?.message.orEmpty().contains("configured download limit"))
assertTrue(output.size() <= 16)
}
@Test
fun managedFileFallbackClassificationDistinguishesMissingRouteFromMissingFile() {
assertTrue(
@@ -133,6 +133,9 @@ class GatewayClientHarness(
@Volatile
var createdSessionProfileName: String? = null
@Volatile
var createdSessionLazy = false
/** Config keys rejected with the older-gateway unknown-key response. */
val unsupportedConfigKeys: MutableSet<String> = ConcurrentHashMap.newKeySet()
@@ -329,6 +332,7 @@ class GatewayClientHarness(
?: (params["profile"] as? JsonPrimitive)?.contentOrNull
?: "default",
)
if (createdSessionLazy) put("lazy", true)
})
}
}
@@ -768,6 +772,7 @@ class GatewayChatClientTest {
val thinkingDeltas = ConcurrentLinkedQueue<String>()
val sessionIds = ConcurrentLinkedQueue<String>()
val errors = ConcurrentLinkedQueue<String>()
val submitRejections = ConcurrentLinkedQueue<String>()
val resumeFailures = ConcurrentLinkedQueue<String>()
val interactions = ConcurrentLinkedQueue<GatewayAsk>()
val interactionExpiries = ConcurrentLinkedQueue<GatewayAskExpiry>()
@@ -805,6 +810,7 @@ class GatewayChatClientTest {
onResumeFailure = { resumeFailures += it; completeLatch.countDown() },
onStatusUpdate = { _, _ -> },
onStatusClear = { },
onSubmitRejected = { submitRejections += it; completeLatch.countDown() },
)
}
@@ -812,6 +818,7 @@ class GatewayChatClientTest {
rpcTimeoutMs: Long = 15_000L,
promptSubmitTimeoutMs: Long = 1_800_000L,
turnIdleTimeoutMs: Long = 180_000L,
sessionReadyTimeoutMs: Long = 300_000L,
compactingTimeoutMs: Long = 600_000L,
callbackDispatcher: (block: () -> Unit) -> Unit = { it() },
ticketTimeoutMs: Long = 8_000L,
@@ -834,6 +841,7 @@ class GatewayChatClientTest {
rpcTimeoutMs = rpcTimeoutMs,
promptSubmitTimeoutMs = promptSubmitTimeoutMs,
turnIdleTimeoutMs = turnIdleTimeoutMs,
sessionReadyTimeoutMs = sessionReadyTimeoutMs,
compactingTimeoutMs = compactingTimeoutMs,
)
@@ -872,6 +880,7 @@ class GatewayChatClientTest {
rpcTimeoutMs: Long = 15_000L,
promptSubmitTimeoutMs: Long = 1_800_000L,
turnIdleTimeoutMs: Long = 180_000L,
sessionReadyTimeoutMs: Long = 300_000L,
compactingTimeoutMs: Long = 600_000L,
ticketTimeoutMs: Long = 8_000L,
) {
@@ -881,6 +890,7 @@ class GatewayChatClientTest {
rpcTimeoutMs = rpcTimeoutMs,
promptSubmitTimeoutMs = promptSubmitTimeoutMs,
turnIdleTimeoutMs = turnIdleTimeoutMs,
sessionReadyTimeoutMs = sessionReadyTimeoutMs,
compactingTimeoutMs = compactingTimeoutMs,
ticketTimeoutMs = ticketTimeoutMs,
)
@@ -2687,13 +2697,28 @@ class GatewayChatClientTest {
}
@Test
fun `session create rejects older gateway without profile ownership metadata`() {
fun `profile scoped socket accepts older session result without duplicate ownership metadata`() {
val r = Recorder()
client.sessionProfileProvider = { "mizu" }
harness.omitSessionProfileMetadata = true
client.sendTurn(null, "hi", null, r.callbacks) { r.preflightFailures += it }
harness.awaitServerSocket()
harness.awaitRpc("prompt.submit")
assertTrue(r.preflightFailures.isEmpty())
}
@Test
fun `unscoped socket still rejects missing named profile ownership metadata`() {
val r = Recorder()
harness.omitSessionProfileMetadata = true
client.observe()
harness.awaitServerSocket()
awaitCondition { client.connectionState.value == GatewayConnectionState.Ready }
client.sessionProfileProvider = { "mizu" }
client.sendTurn(null, "hi", null, r.callbacks) { r.preflightFailures += it }
awaitCondition { r.preflightFailures.isNotEmpty() }
assertTrue(r.preflightFailures.single().contains("did not confirm profile ownership"))
@@ -3944,6 +3969,65 @@ class GatewayChatClientTest {
assertEquals(true, (submit["queued"] as? JsonPrimitive)?.booleanOrNull)
}
@Test
fun `lazy fresh session waits for authoritative ready edge before submit`() {
harness.createdSessionLazy = true
val r = Recorder()
client.sendTurn(null, "hello", null, r.callbacks) { r.preflightFailures += it }
harness.awaitRpc("session.create")
val serverWs = harness.awaitServerSocket()
Thread.sleep(100)
assertEquals(0, harness.rpcLog.count { it.first == "prompt.submit" })
serverWs.send(
harness.eventFrame(
"session.info",
buildJsonObject { put("lazy", false) },
"live-1",
),
)
harness.awaitRpc("prompt.submit")
assertTrue(r.preflightFailures.isEmpty())
}
@Test
fun `lazy fresh session readiness timeout never submits`() {
rebuildClient(sessionReadyTimeoutMs = 50L)
harness.createdSessionLazy = true
val r = Recorder()
client.sendTurn(null, "hello", null, r.callbacks) { r.preflightFailures += it }
harness.awaitRpc("session.create")
waitUntil { r.preflightFailures.isNotEmpty() }
assertEquals(0, harness.rpcLog.count { it.first == "prompt.submit" })
}
@Test
fun `lazy session initialization error fails before prompt submit`() {
harness.createdSessionLazy = true
val r = Recorder()
client.sendTurn(null, "hello", null, r.callbacks) { r.preflightFailures += it }
harness.awaitRpc("session.create")
val serverWs = harness.awaitServerSocket()
serverWs.send(
harness.eventFrame(
"error",
buildJsonObject {
put("message", "agent init failed: No Codex credentials stored")
},
"live-1",
),
)
waitUntil { r.preflightFailures.isNotEmpty() }
assertTrue(r.preflightFailures.single().contains("No Codex credentials stored"))
assertEquals(0, harness.rpcLog.count { it.first == "prompt.submit" })
}
@Test
fun `authoritative prompt rejections surface server message without preflight fallback`() {
val cases = listOf(
@@ -3964,8 +4048,9 @@ class GatewayChatClientTest {
client.sendTurn(null, "hello-$code", null, r.callbacks) { r.preflightFailures += it }
harness.awaitRpc("prompt.submit")
waitUntil { r.errors.isNotEmpty() }
assertEquals(listOf(message), r.errors.toList())
waitUntil { r.submitRejections.isNotEmpty() }
assertEquals(listOf(message), r.submitRejections.toList())
assertTrue(r.errors.isEmpty())
assertTrue("$code must not trigger SSE fallback", r.preflightFailures.isEmpty())
assertEquals(index + 1, harness.rpcLog.count { it.first == "prompt.submit" })
}
@@ -44,6 +44,7 @@ class GatewayEventMapperTest {
var usage: UsageInfo? = null
var usageCalls = 0
val errors = mutableListOf<String>()
val submitRejections = mutableListOf<String>()
val callbacks = GatewayTurnCallbacks(
onSessionId = { sessionIds += it },
@@ -74,6 +75,7 @@ class GatewayEventMapperTest {
onStatusClear = { statusClears += it },
onNoticeShow = { notices += it },
onNoticeClear = { noticeClears += it },
onSubmitRejected = { submitRejections += it },
)
}
@@ -483,10 +485,31 @@ class GatewayEventMapperTest {
val mapper = mapperWith(r)
mapper.onEvent("error", obj("""{"message":"model exploded"}"""))
assertEquals(listOf("model exploded"), r.errors)
assertTrue(r.submitRejections.isEmpty())
assertTrue(mapper.turnEnded)
assertEquals(0, r.completes)
}
@Test
fun `session ownership error is an authoritative submit rejection`() {
val r = Recorder()
val mapper = mapperWith(r)
val message =
"Session fresh-1 already has a live owner (webui, pid 42, running 0m). " +
"Only one surface at a time may run a session, because a second one would reason from stale history."
mapper.onEvent(
"error",
obj(
"""{"message":"Session fresh-1 already has a live owner (webui, pid 42, running 0m). Only one surface at a time may run a session, because a second one would reason from stale history."}""",
),
)
assertEquals(listOf(message), r.submitRejections)
assertTrue(r.errors.isEmpty())
assertTrue(mapper.turnEnded)
}
// --- Tools ---
@Test
@@ -547,6 +570,24 @@ class GatewayEventMapperTest {
)
}
@Test
fun `wrapped image generation start exposes the effective tool identity`() {
val recorder = Recorder()
val mapper = mapperWith(recorder)
mapper.onEvent(
"tool.start",
obj(
"""{"tool_id":"img-1","name":"tool_call","args":{"name":"image_generate","arguments":{"prompt":"test","aspect_ratio":"landscape"}}}""",
),
)
assertEquals(listOf("img-1" to "image_generate"), recorder.toolStarts)
assertEquals(
listOf("img-1" to "{\"prompt\":\"test\",\"aspect_ratio\":\"landscape\"}"),
recorder.toolStartArgs,
)
}
@Test
fun `tool complete with error routes to failed`() {
val r = Recorder()
@@ -30,7 +30,7 @@ class HermesApiClientTest {
server.enqueue(apiMessagePageResponse(start = 500, count = 1, returned = 1))
val messages = HermesApiClient(server.url("/").toString(), "test-key")
.getMessages("sess-a")
.getMessages("sess-a", SessionMessageLoadMode.COMPLETE)
val first = server.takeRequest().requestUrl!!
val second = server.takeRequest().requestUrl!!
@@ -5,6 +5,8 @@ import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.onRoot
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.github.takahirom.roborazzi.captureRoboImage
import com.hermesandroid.relay.ui.components.ChangelogStore
import com.hermesandroid.relay.ui.components.ChangelogVersion
import com.hermesandroid.relay.ui.screens.ChangelogScreen
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import org.junit.Rule
@@ -20,15 +22,19 @@ class ChangelogHistoryScreenshotTest {
@get:Rule val compose = createComposeRule()
@Test fun latestReleaseShowsHighlightsAndCompleteDetails() {
lateinit var latest: ChangelogVersion
compose.setContent {
latest = ChangelogStore.load(androidx.compose.ui.platform.LocalContext.current).versions.first()
HermesRelayTheme(appThemeId = "hermes-relay", themePreference = "dark") {
ChangelogScreen(onClose = {})
}
}
compose.onNodeWithText("v1.15.0 — Standard Hermes first, with clearer Relay boundaries").assertExists()
compose.onNodeWithText("v${latest.version} — ${requireNotNull(latest.title)}").assertExists()
compose.onNodeWithText("Highlights").assertExists()
compose.onNodeWithText("Fixed").assertExists()
compose.onNodeWithText("Keep Standard voice after removing Relay").assertExists()
latest.remainingChangesOfKind("fixed").firstOrNull()?.let { fixed ->
compose.onNodeWithText("Fixed").assertExists()
compose.onNodeWithText(fixed.title).assertExists()
}
compose.onNodeWithText("Compatibility").assertExists()
compose.onNodeWithText("Installed").assertExists()
compose.onRoot().captureRoboImage("build/ui-regression/changelog-history.png")
@@ -21,6 +21,7 @@ import androidx.compose.ui.unit.dp
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.github.takahirom.roborazzi.captureRoboImage
import com.hermesandroid.relay.ui.components.ChangelogStore
import com.hermesandroid.relay.ui.components.ChangelogVersion
import com.hermesandroid.relay.ui.components.WhatsNewToast
import com.hermesandroid.relay.ui.components.WhatsNewToastContent
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
@@ -38,10 +39,12 @@ class WhatsNewToastScreenshotTest {
@get:Rule val compose = createComposeRule()
@Test fun compactNoticeRemainsClearAtLargeText() {
lateinit var latest: ChangelogVersion
compose.setContent {
val context = LocalContext.current
val density = LocalDensity.current
val entry = ChangelogStore.load(context).versions.first()
latest = entry
CompositionLocalProvider(LocalDensity provides Density(density.density, 1.35f)) {
HermesRelayTheme(appThemeId = "hermes-relay", themePreference = "dark") {
Box(
@@ -61,12 +64,12 @@ class WhatsNewToastScreenshotTest {
}
}
}
compose.onNodeWithText("Standard Hermes first, with clearer Relay boundaries").assertExists()
compose.onNodeWithText("Also: 2 improvements · 9 fixes").assertExists()
compose.onNodeWithText(
"See which features need Relay, Read the complete release record…",
).assertExists()
compose.onNodeWithText("View all").assertExists()
compose.onNodeWithText(requireNotNull(latest.title)).assertExists()
latest.visibleDigest()?.let { digest ->
compose.onNodeWithText("Also: ${digest.countText()}").assertExists()
compose.onNodeWithText(digest.preview.joinToString(", ") + "…").assertExists()
compose.onNodeWithText("View all").assertExists()
}
compose.onNodeWithContentDescription("Close").assertExists()
compose.onRoot().captureRoboImage("build/ui-regression/whats-new-toast-large-text.png")
}
@@ -74,8 +77,10 @@ class WhatsNewToastScreenshotTest {
@Test fun exposesExpandAndCloseActions() {
var expanded = false
var dismissed = false
lateinit var latest: ChangelogVersion
compose.setContent {
val entry = ChangelogStore.load(LocalContext.current).versions.first()
latest = entry
HermesRelayTheme(appThemeId = "hermes-relay", themePreference = "dark") {
WhatsNewToastContent(
entry = entry,
@@ -86,9 +91,12 @@ class WhatsNewToastScreenshotTest {
}
}
compose.onNodeWithText("Standard Hermes first, with clearer Relay boundaries").performClick()
expanded = false
compose.onNodeWithText("View all").performClick()
compose.onNodeWithText(requireNotNull(latest.title)).performClick()
assertTrue(expanded)
latest.visibleDigest()?.let {
expanded = false
compose.onNodeWithText("View all").performClick()
}
compose.onNodeWithContentDescription("Close").performClick()
assertTrue(expanded)
@@ -97,8 +105,10 @@ class WhatsNewToastScreenshotTest {
@Test fun horizontalSwipeDismissesTheNotice() {
var dismissed = false
lateinit var latest: ChangelogVersion
compose.mainClock.autoAdvance = false
compose.setContent {
latest = ChangelogStore.load(LocalContext.current).versions.first()
HermesRelayTheme(appThemeId = "hermes-relay", themePreference = "dark") {
WhatsNewToast(
onDismiss = { dismissed = true },
@@ -108,10 +118,29 @@ class WhatsNewToastScreenshotTest {
}
}
compose.mainClock.advanceTimeBy(300L)
compose.onNodeWithText("Standard Hermes first, with clearer Relay boundaries")
compose.onNodeWithText(requireNotNull(latest.title))
.performTouchInput { swipeLeft(durationMillis = 300L) }
compose.mainClock.advanceTimeBy(300L)
assertTrue(dismissed)
}
private fun com.hermesandroid.relay.ui.components.ChangelogToastDigest.countText(): String =
buildList {
if (additionalFeatureCount > 0) {
add("$additionalFeatureCount additional ${if (additionalFeatureCount == 1) "feature" else "features"}")
}
if (improvementCount > 0) {
add("$improvementCount ${if (improvementCount == 1) "improvement" else "improvements"}")
}
if (fixCount > 0) {
add("$fixCount ${if (fixCount == 1) "fix" else "fixes"}")
}
}.joinToString(" · ")
private fun ChangelogVersion.visibleDigest():
com.hermesandroid.relay.ui.components.ChangelogToastDigest? =
resolvedToastDigest()?.takeIf {
it.additionalFeatureCount > 0 || it.improvementCount > 0 || it.fixCount > 0
}
}
@@ -0,0 +1,50 @@
package com.hermesandroid.relay.ui
import androidx.compose.ui.unit.dp
import org.junit.Assert.assertEquals
import org.junit.Assert.assertFalse
import org.junit.Assert.assertNull
import org.junit.Assert.assertTrue
import org.junit.Test
class ChatResponsiveLayoutTest {
@Test
fun compactPhonesKeepExistingUnboundedLayout() {
val layout = chatResponsiveLayout(screenWidthDp = 599)
assertNull(layout.introMaxWidth)
assertNull(layout.avatarSize)
assertNull(layout.chromeMaxWidth)
assertNull(layout.transcriptMaxWidth)
assertNull(layout.focusVoiceMaxWidth)
}
@Test
fun mediumWindowsUseBoundedChatSurfaces() {
val layout = chatResponsiveLayout(screenWidthDp = 600)
assertEquals(600.dp, layout.introMaxWidth)
assertEquals(300.dp, layout.avatarSize)
assertEquals(760.dp, layout.chromeMaxWidth)
assertEquals(760.dp, layout.transcriptMaxWidth)
assertEquals(760.dp, layout.focusVoiceMaxWidth)
}
@Test
fun expandedTabletsUseReadableCenteredRails() {
val layout = chatResponsiveLayout(screenWidthDp = 1280)
assertEquals(720.dp, layout.introMaxWidth)
assertEquals(360.dp, layout.avatarSize)
assertEquals(960.dp, layout.chromeMaxWidth)
assertEquals(960.dp, layout.transcriptMaxWidth)
assertEquals(1120.dp, layout.focusVoiceMaxWidth)
}
@Test
fun focusVoiceSplitsOnlyOnExpandedLandscapeWindows() {
assertTrue(useSplitVoiceLayout(screenWidthDp = 1280, screenHeightDp = 800))
assertFalse(useSplitVoiceLayout(screenWidthDp = 800, screenHeightDp = 1280))
assertFalse(useSplitVoiceLayout(screenWidthDp = 839, screenHeightDp = 600))
}
}
@@ -1,6 +1,8 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.material3.MaterialTheme
import androidx.compose.runtime.mutableStateOf
import androidx.compose.ui.test.junit4.StateRestorationTester
import androidx.compose.ui.test.junit4.v2.createComposeRule
import androidx.compose.ui.test.onAllNodesWithText
import androidx.compose.ui.test.assertIsNotEnabled
@@ -76,6 +78,173 @@ class AttachmentGalleryUiTest {
compose.onNodeWithText("2 / 3").assertExists()
}
@Test
fun `selected gallery page survives activity state restoration`() {
val attachments = listOf("one.png", "two.png", "three.png").map { name ->
Attachment(
contentType = "image/png",
content = ONE_PIXEL_PNG,
fileName = name,
)
}
val restoration = StateRestorationTester(compose)
restoration.setContent {
MaterialTheme {
AttachmentGallery(attachments = attachments)
}
}
compose.onNodeWithTag("attachment-gallery-tile-1").performClick()
compose.onNodeWithText("2 / 3").assertExists()
restoration.emulateSavedInstanceStateRestore()
compose.onNodeWithText("2 / 3").assertExists()
}
@Test
fun `generic attachment viewer survives activity state restoration`() {
val restoration = StateRestorationTester(compose)
restoration.setContent {
MaterialTheme {
InboundAttachmentCard(
attachment = Attachment(
contentType = "application/octet-stream",
content = "",
fileName = "notes.bin",
),
onRetry = {},
onManualFetch = {},
)
}
}
compose.onNodeWithText("notes.bin").performClick()
compose.onNodeWithTag("attachment-viewer").assertExists()
restoration.emulateSavedInstanceStateRestore()
compose.onNodeWithTag("attachment-viewer").assertExists()
}
@Test
fun `host keeps generic viewer mounted when its transcript row leaves composition`() {
val showSource = mutableStateOf(true)
compose.setContent {
MaterialTheme {
ChatMediaViewerHost {
if (showSource.value) {
InboundAttachmentCard(
attachment = Attachment(
contentType = "application/octet-stream",
content = "",
fileName = "notes.bin",
),
onRetry = {},
onManualFetch = {},
)
}
}
}
}
compose.onNodeWithText("notes.bin").performClick()
compose.onNodeWithTag("attachment-viewer").assertExists()
compose.runOnIdle { showSource.value = false }
compose.onNodeWithTag("attachment-viewer").assertExists()
}
@Test
fun `host keeps image viewer mounted when its transcript row leaves composition`() {
val showSource = mutableStateOf(true)
compose.setContent {
MaterialTheme {
ChatMediaViewerHost {
if (showSource.value) {
InboundAttachmentCard(
attachment = Attachment(
contentType = "image/png",
content = ONE_PIXEL_PNG,
fileName = "image.png",
),
onRetry = {},
onManualFetch = {},
)
}
}
}
}
compose.waitUntil(timeoutMillis = 5_000) {
runCatching {
compose.onNodeWithContentDescription("image.png").fetchSemanticsNode()
}.isSuccess
}
compose.onNodeWithContentDescription("image.png").performClick()
compose.onNodeWithTag("attachment-viewer").assertExists()
compose.runOnIdle { showSource.value = false }
compose.onNodeWithTag("attachment-viewer").assertExists()
}
@Test
fun `host keeps selected gallery page mounted when its source leaves composition`() {
val showSource = mutableStateOf(true)
val attachments = listOf("one.png", "two.png", "three.png").map { name ->
Attachment(
contentType = "image/png",
content = ONE_PIXEL_PNG,
fileName = name,
)
}
compose.setContent {
MaterialTheme {
ChatMediaViewerHost {
if (showSource.value) {
AttachmentGallery(attachments = attachments)
}
}
}
}
compose.onNodeWithTag("attachment-gallery-tile-1").performClick()
compose.onNodeWithText("2 / 3").assertExists()
compose.runOnIdle { showSource.value = false }
compose.onNodeWithText("2 / 3").assertExists()
}
@Test
fun `host dismisses active viewer when its chat owner changes`() {
val owner = mutableStateOf("session-a")
compose.setContent {
MaterialTheme {
ChatMediaViewerHost(owner.value) {
InboundAttachmentCard(
attachment = Attachment(
contentType = "application/octet-stream",
content = "",
fileName = "notes.bin",
),
onRetry = {},
onManualFetch = {},
)
}
}
}
compose.onNodeWithText("notes.bin").performClick()
compose.onNodeWithTag("attachment-viewer").assertExists()
compose.runOnIdle { owner.value = "session-b" }
compose.onNodeWithTag("attachment-viewer").assertDoesNotExist()
}
@Test
fun `sensitive page actions stay disabled until that page is revealed`() {
val attachments = listOf(
@@ -0,0 +1,121 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.material3.Surface
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.assertIsFocused
import androidx.compose.ui.test.hasSetTextAction
import androidx.compose.ui.test.isDialog
import androidx.compose.ui.test.assertIsNotEnabled
import androidx.compose.ui.test.assertIsSelected
import androidx.compose.ui.test.junit4.v2.createComposeRule
import androidx.compose.ui.test.onNodeWithContentDescription
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.onNodeWithTag
import androidx.compose.ui.test.onRoot
import androidx.compose.ui.test.performClick
import androidx.compose.ui.test.performTextInput
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.github.takahirom.roborazzi.captureRoboImage
import com.hermesandroid.relay.data.BusyMessageAction
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import org.junit.Assert.assertEquals
import org.junit.Assert.assertTrue
import org.junit.Rule
import org.junit.Test
import org.junit.runner.RunWith
import org.robolectric.annotation.Config
import org.robolectric.annotation.GraphicsMode
@RunWith(AndroidJUnit4::class)
@GraphicsMode(GraphicsMode.Mode.NATIVE)
@Config(qualifiers = "w400dp-h800dp-xhdpi")
class ChatBusyControlsTest {
@get:Rule val compose = createComposeRule()
@Test fun selectorChangesIntentWithoutSendingAndKeepsStopSeparate() {
var selected by mutableStateOf(BusyMessageAction.CorrectNow)
var stopped = 0
compose.setContent {
HermesRelayTheme(themePreference = "dark") {
ChatBusyActionSelector(selected, { selected = it }, onStop = { stopped++ })
}
}
compose.onNodeWithText("Queue next").assertDoesNotExist()
compose.onNodeWithTag("chatBusyActionTrigger").performClick()
compose.onNodeWithTag("chatBusyAction-queue_next").performClick()
compose.waitForIdle()
compose.onNodeWithTag("chatBusyActionDrawer").assertDoesNotExist()
compose.onNodeWithText("Queue next").assertIsDisplayed()
assertEquals(BusyMessageAction.QueueNext, selected)
assertEquals(0, stopped)
compose.onNodeWithContentDescription("Stop streaming").performClick()
assertEquals(1, stopped)
}
@Test fun unavailableCorrectionKeepsQueueSelectable() {
compose.setContent {
HermesRelayTheme {
ChatBusyActionSelector(BusyMessageAction.QueueNext, {}, correctionAvailable = false)
}
}
compose.onNodeWithTag("chatBusyActionTrigger").performClick()
compose.onNodeWithTag("chatBusyAction-correct_now").assertIsNotEnabled()
compose.onNodeWithTag("chatBusyAction-queue_next").assertIsSelected()
compose.onNodeWithTag("chatBusyActionDrawer")
.captureRoboImage("build/ui-evidence/chat-busy-drawer.png")
}
@Test fun pausedQueueActionsAndComposerRenderTogether() {
var resumed = 0
var cleared = 0
var draft by mutableStateOf("A correction")
compose.setContent {
HermesRelayTheme(themePreference = "dark") {
Surface(Modifier.fillMaxSize()) {
Column(verticalArrangement = Arrangement.Bottom) {
ChatMessageQueue(listOf("A saved follow-up", "Another follow-up"), true,
{ resumed++ }, { cleared++ }, {}, {}, canEdit = true)
ChatInputBar(
value = draft, onValueChange = { draft = it }, placeholder = "Message",
trailing = ChatInputTrailing.STEER, onSend = {}, onVoice = {}, onStop = {},
onAttachPhotos = {}, onAttachFiles = {}, onAttachCamera = {}, onPasteImage = {},
onLongPressAttach = {}, charLimit = 20_000, caption = "Changes the current response",
voiceReady = false, showVoiceHint = false, onVoiceHintShown = {}, isDarkTheme = true,
busyAction = BusyMessageAction.CorrectNow,
)
}
}
}
}
compose.onNodeWithText("Resume").assertIsDisplayed().performClick()
compose.onNodeWithText("Clear").performClick()
assertEquals(1, resumed)
assertEquals(1, cleared)
compose.onRoot().captureRoboImage("build/ui-evidence/chat-busy-controls-dark.png")
val input = compose.onNode(hasSetTextAction())
input.performClick()
val inputBottom = input.fetchSemanticsNode().boundsInRoot.bottom
val composerHeight = compose.onNodeWithTag("chatComposerForeground").fetchSemanticsNode().boundsInRoot.height
compose.onNodeWithTag("chatBusyActionTrigger").performClick()
compose.onNodeWithTag("chatBusyActionDrawer").assertIsDisplayed()
compose.onNode(isDialog()).assertDoesNotExist()
input.assertIsDisplayed().assertIsFocused()
assertEquals(inputBottom, input.fetchSemanticsNode().boundsInRoot.bottom, 1f)
val foreground = compose.onNodeWithTag("chatComposerForeground").fetchSemanticsNode().boundsInRoot
val rearTray = compose.onNodeWithTag("chatBusyActionTray").fetchSemanticsNode().boundsInRoot
assertEquals(composerHeight, foreground.height, 1f)
assertTrue("Rear tray must tuck behind the foreground composer", rearTray.bottom > foreground.top)
assertTrue(compose.onNodeWithTag("chatBusyActionDrawer").fetchSemanticsNode().boundsInRoot.bottom <= foreground.top)
input.performTextInput(" updated")
assertTrue(draft.contains("updated"))
compose.onRoot().captureRoboImage("build/ui-evidence/chat-busy-composer-expanded.png")
}
}
@@ -10,4 +10,16 @@ class ChatFailurePanelTest {
assertEquals("Gateway", failureIdentity("Gateway", null, null))
assertEquals("", failureIdentity("", null, null))
}
@Test
fun `inference initialization errors get a specific presentation`() {
assertEquals(
true,
isInferenceUnavailableFailure(
"agent init failed: No Codex credentials stored. " +
"setup.status reports configured credentials, but runtime resolution still failed.",
),
)
assertEquals(false, isInferenceUnavailableFailure("gateway connect cooling down"))
}
}
@@ -0,0 +1,81 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.padding
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.ui.Modifier
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.semantics.SemanticsActions
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.junit4.v2.createComposeRule
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.onRoot
import androidx.compose.ui.test.performSemanticsAction
import androidx.compose.ui.text.TextLayoutResult
import androidx.compose.ui.unit.dp
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.github.takahirom.roborazzi.captureRoboImage
import com.hermesandroid.relay.data.ChatMessage
import com.hermesandroid.relay.data.MessageDeliveryStatus
import com.hermesandroid.relay.data.MessageRole
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import org.junit.Assert.assertEquals
import org.junit.Assert.assertNotEquals
import org.junit.Rule
import org.junit.Test
import org.junit.runner.RunWith
import org.robolectric.annotation.Config
import org.robolectric.annotation.GraphicsMode
@RunWith(AndroidJUnit4::class)
@GraphicsMode(GraphicsMode.Mode.NATIVE)
@Config(qualifiers = "w400dp-h800dp-xhdpi")
class MessageDeliveryContrastTest {
@get:Rule val compose = createComposeRule()
@Test fun darkUserBubblesUseContrastingDeliveryText() = verifyDeliveryColors("dark")
@Test fun lightUserBubblesUseContrastingDeliveryText() = verifyDeliveryColors("light")
private fun verifyDeliveryColors(theme: String) {
var foreground = Color.Unspecified
var background = Color.Unspecified
compose.setContent {
HermesRelayTheme(themePreference = theme) {
foreground = MaterialTheme.colorScheme.onPrimary
background = MaterialTheme.colorScheme.primary
Surface(Modifier.fillMaxSize()) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
MessageDeliveryStatus.entries.forEach { status ->
MessageBubble(
message = ChatMessage(
id = status.name,
role = MessageRole.USER,
content = "Test",
timestamp = 1_700_000_000_000L,
deliveryStatus = status,
),
animationEnabled = false,
)
}
}
}
}
}
assertNotEquals(background, foreground)
listOf("Sending…", "Queued", "Correction sent", "Delivered", "Not sent").forEach { label ->
val layouts = mutableListOf<TextLayoutResult>()
compose.onNodeWithText(label, useUnmergedTree = true)
.assertIsDisplayed()
.performSemanticsAction(SemanticsActions.GetTextLayoutResult) { it(layouts) }
assertEquals("Delivery label must use the user bubble foreground: $label", foreground, layouts.single().layoutInput.style.color)
}
compose.onRoot().captureRoboImage("build/ui-evidence/message-delivery-$theme.png")
}
}
@@ -1,10 +1,15 @@
package com.hermesandroid.relay.ui.components
import android.graphics.Bitmap
import android.media.ExifInterface
import android.net.Uri
import androidx.test.ext.junit.runners.AndroidJUnit4
import org.junit.Assert.assertEquals
import org.junit.Assert.assertNotNull
import org.junit.Test
import org.junit.runner.RunWith
import org.robolectric.RuntimeEnvironment
import java.io.File
@RunWith(AndroidJUnit4::class)
class OrientedBitmapDecoderTest {
@@ -36,4 +41,34 @@ class OrientedBitmapDecoderTest {
imageOrientationTransform(ExifInterface.ORIENTATION_TRANSVERSE),
)
}
@Test
fun `cached raster orientation matches viewer mime policy`() {
assertEquals(false, shouldApplyExifOrientation("image/png"))
assertEquals(false, shouldApplyExifOrientation("image/gif"))
assertEquals(true, shouldApplyExifOrientation("image/jpeg"))
assertEquals(true, shouldApplyExifOrientation("image/heif"))
}
@Test
fun `content uri decoder reads encoded image without byte array handoff`() {
val context = RuntimeEnvironment.getApplication()
val source = File.createTempFile("oriented-bitmap-", ".png", context.cacheDir)
val bitmap = Bitmap.createBitmap(3, 2, Bitmap.Config.ARGB_8888)
try {
source.outputStream().use { output ->
bitmap.compress(Bitmap.CompressFormat.PNG, 100, output)
}
} finally {
bitmap.recycle()
}
val decoded = decodeOrientedBitmap(context, Uri.fromFile(source))
assertNotNull(decoded)
assertEquals(3, decoded?.width)
assertEquals(2, decoded?.height)
decoded?.recycle()
source.delete()
}
}
@@ -65,4 +65,15 @@ class StreamingMarkdownContentTest {
planStreamingMarkdownAppend("", "authoritative final response"),
)
}
@Test
fun oversizedMarkdownKeepsDataOutsideTheBoundedRenderWindow() {
val source = "x".repeat(MAX_RENDERED_MARKDOWN_CHARS + 1)
val rendered = markdownRenderWindow(source)
assertEquals(MAX_RENDERED_MARKDOWN_CHARS, rendered.takeWhile { it == 'x' }.length)
assertFalse(rendered.startsWith(source))
assertTrue(rendered.contains("shortened for Android memory safety"))
}
}
@@ -0,0 +1,149 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.setValue
import androidx.compose.ui.Modifier
import androidx.compose.ui.semantics.SemanticsProperties
import androidx.compose.ui.test.assertIsDisplayed
import androidx.compose.ui.test.isDialog
import androidx.compose.ui.test.junit4.v2.createComposeRule
import androidx.compose.ui.test.onNodeWithText
import androidx.compose.ui.test.performClick
import androidx.compose.ui.test.performTouchInput
import androidx.compose.ui.test.swipeUp
import androidx.test.ext.junit.runners.AndroidJUnit4
import com.github.takahirom.roborazzi.captureRoboImage
import com.hermesandroid.relay.data.VoicePresentationMode
import com.hermesandroid.relay.ui.theme.HermesRelayTheme
import com.hermesandroid.relay.viewmodel.InteractionMode
import com.hermesandroid.relay.viewmodel.VoiceState
import com.hermesandroid.relay.viewmodel.VoiceUiState
import org.junit.Assert.assertEquals
import org.junit.Assert.assertTrue
import org.junit.Rule
import org.junit.Test
import org.junit.runner.RunWith
import org.robolectric.annotation.Config
import org.robolectric.annotation.GraphicsMode
@RunWith(AndroidJUnit4::class)
@GraphicsMode(GraphicsMode.Mode.NATIVE)
@Config(qualifiers = "w360dp-h780dp-xhdpi")
class VoiceErrorDialogTest {
@get:Rule val compose = createComposeRule()
@Test
fun conversationError_isModalAndDismissesWithoutStartingMicrophone() {
val actions = mutableListOf<String>()
renderError(onClear = { actions += "clear" }, onMicTap = { actions += "mic" })
compose.onNode(isDialog()).assertExists()
compose.onNodeWithText("Voice error").assertIsDisplayed()
compose.onNodeWithText("Dismiss").assertIsDisplayed()
compose.onNodeWithText("Retry").assertIsDisplayed()
compose.onNode(isDialog()).captureRoboImage("build/ui-evidence/voice-error-conversation-dark.png")
compose.onNodeWithText("Dismiss").performClick()
compose.mainClock.advanceTimeByFrame()
compose.onNode(isDialog()).assertDoesNotExist()
compose.runOnIdle { assertEquals(listOf("clear"), actions) }
}
@Test
fun focusError_retryClearsErrorBeforeStartingMicrophone() {
val actions = mutableListOf<String>()
renderError(
mode = VoicePresentationMode.Focus,
onClear = { actions += "clear" },
onMicTap = { actions += "mic" },
)
compose.onNode(isDialog()).assertExists()
compose.onNodeWithText("Retry").performClick()
compose.mainClock.advanceTimeByFrame()
compose.onNode(isDialog()).assertDoesNotExist()
compose.runOnIdle { assertEquals(listOf("clear", "mic"), actions) }
}
@Test
@Config(qualifiers = "w780dp-h360dp-xhdpi")
fun landscapeLargeText_longErrorScrollsWithoutHidingActions() {
val longError = List(8) { PROVIDER_ERROR }.joinToString("\n\n")
renderError(error = longError, theme = "light", fontScale = 1.5f)
compose.onNodeWithText("Dismiss").assertIsDisplayed()
compose.onNodeWithText("Retry").assertIsDisplayed()
val detail = compose.onNodeWithText(longError)
val scrollRange = detail.fetchSemanticsNode().config[SemanticsProperties.VerticalScrollAxisRange]
assertTrue(scrollRange.maxValue() > 0f)
detail.performTouchInput { swipeUp() }
compose.runOnIdle { assertTrue(scrollRange.value() > 0f) }
compose.onNodeWithText("Dismiss").assertIsDisplayed()
compose.onNodeWithText("Retry").assertIsDisplayed()
compose.onNode(isDialog()).captureRoboImage("build/ui-evidence/voice-error-landscape-light-large-text.png")
}
@Test
fun noError_doesNotShowDialog() {
renderError(error = null)
compose.onNode(isDialog()).assertDoesNotExist()
}
private fun renderError(
error: String? = PROVIDER_ERROR,
mode: VoicePresentationMode = VoicePresentationMode.Conversation,
theme: String = "dark",
fontScale: Float = 1f,
onClear: () -> Unit = {},
onMicTap: () -> Unit = {},
) {
var state by mutableStateOf(
VoiceUiState(
voiceMode = true,
state = if (error == null) VoiceState.Idle else VoiceState.Error,
interactionMode = InteractionMode.TapToTalk,
error = error,
),
)
compose.mainClock.autoAdvance = false
compose.setContent {
HermesRelayTheme(themePreference = theme, fontScale = fontScale) {
Surface(Modifier.fillMaxSize()) {
Box {
Text("Chat remains behind the modal")
VoiceModeOverlay(
uiState = state,
presentationMode = mode,
onMicTap = onMicTap,
onMicRelease = {},
onInterrupt = {},
onDismiss = {},
onModeChange = {},
onClearError = {
onClear()
state = state.copy(error = null, state = VoiceState.Idle)
},
)
}
}
}
}
compose.mainClock.advanceTimeBy(500)
}
private companion object {
const val PROVIDER_ERROR = "Hermes audio transcribe rejected that input - " +
"{\"detail\":\"No STT provider available. Install faster-whisper for free local " +
"transcription, configure HERMES_LOCAL_STT_COMMAND or install a local whisper CLI, " +
"set GROQ_API_KEY for free Groq Whisper, set MISTRAL_API_KEY for Mistral Voxtral " +
"Transcribe, configure xAI OAuth or set XAI_API_KEY for xAI Grok STT, set " +
"ELEVENLABS_API_KEY for ElevenLabs Scribe, or set VOICE_TOOLS_OPENAI_KEY or " +
"OPENAI_API_KEY for the OpenAI Whisper API.\"}"
}
}
@@ -86,6 +86,35 @@ class VoiceModeOverlayInteractionTest {
}
}
@Test
@Config(qualifiers = "w1280dp-h800dp-xhdpi")
fun expandedLandscape_usesSplitLayoutAndKeepsMicSemanticAction() {
var micTaps = 0
compose.mainClock.autoAdvance = false
compose.setContent {
MaterialTheme {
VoiceModeOverlay(
uiState = idleVoiceState(),
onMicTap = { micTaps += 1 },
onMicRelease = {},
onInterrupt = {},
onDismiss = {},
onModeChange = {},
onClearError = {},
)
}
}
compose.onNodeWithTag(VOICE_FOCUS_SPLIT_LAYOUT_TEST_TAG).assertExists()
compose.onNodeWithTag(VOICE_FOCUS_STACKED_LAYOUT_TEST_TAG).assertDoesNotExist()
compose.onNodeWithTag(VOICE_MODE_MIC_TEST_TAG)
.assertHasClickAction()
.performSemanticsAction(SemanticsActions.OnClick)
compose.runOnIdle { assertEquals(1, micTaps) }
}
@Test
fun focusMode_emptySpaceDoesNotClickThroughToChat() {
var backgroundTaps = 0
@@ -0,0 +1,30 @@
package com.hermesandroid.relay.util
import kotlinx.coroutines.test.runTest
import org.junit.Assert.assertEquals
import org.junit.Assert.assertFalse
import org.junit.Test
import org.junit.runner.RunWith
import org.robolectric.RobolectricTestRunner
import org.robolectric.RuntimeEnvironment
import org.robolectric.annotation.Config
import java.io.File
@RunWith(RobolectricTestRunner::class)
@Config(sdk = [34])
class MediaCacheWriterTest {
@Test
fun cacheFile_promotesStreamedFileWithoutByteArrayHandoff() = runTest {
val context = RuntimeEnvironment.getApplication()
val source = File.createTempFile("hermes-media-test-", ".part", context.cacheDir)
.apply { writeText("streamed-media") }
val writer = MediaCacheWriter(context) { 32 }
val cached = writer.cacheFile(source, "audio/mpeg", "voice reply.mp3")
assertFalse(source.exists())
assertEquals("streamed-media", cached.readText())
writer.clear()
}
}
@@ -517,6 +517,40 @@ class ChatViewModelGatewayInboundTurnTest {
)
}
@Test
fun ownershipErrorAfterFreshSubmitStaysVisibleWithoutHistoryRecovery() {
val ownershipError =
"Session 20260612_120000_abc123 already has a live owner (webui, pid 42, running 0m). " +
"Only one surface at a time may run a session, because a second one would reason from stale history."
val historyReads = AtomicInteger(0)
viewModel.setProfileMessageLoader {
historyReads.incrementAndGet()
Result.success(emptyList())
}
viewModel.createNewChat()
viewModel.sendMessage("Keep this retryable")
gatewayHarness.awaitRpc("prompt.submit")
serverWs.send(
gatewayHarness.eventFrame(
"error",
buildJsonObject { put("message", ownershipError) },
"live-1",
),
)
awaitCondition { viewModel.chatFailure.value?.rawError == ownershipError }
assertFalse(handler.isStreaming.value)
assertFalse(viewModel.recoveringAnswer.value)
assertEquals(0, historyReads.get())
assertTrue(handler.messages.value.any { it.content == "Keep this retryable" })
assertFalse(
handler.messages.value.any {
it.content.contains("unfinished message was not found", ignoreCase = true)
},
)
}
@After
fun tearDown() {
DiagnosticsLog.clear()
@@ -879,6 +913,28 @@ class ChatViewModelGatewayInboundTurnTest {
assertEquals(2, calls.get())
}
@Test
fun reentrantSessionPublicationCannotKeepTheRefreshBatchAlive() {
val calls = AtomicInteger(0)
viewModel.setProfileSessionLister {
calls.incrementAndGet()
// Reproduce a downstream publication observer requesting another
// refresh while every successful directory read is still active.
viewModel.refreshSessions()
Result.success(listOf(SessionItem(id = "stable", title = "Stable session")))
}
viewModel.refreshSessions()
awaitCondition { calls.get() >= 2 }
Thread.sleep(150)
val settledCalls = calls.get()
Thread.sleep(150)
assertEquals(settledCalls, calls.get())
assertTrue(settledCalls <= 3)
assertEquals("stable", handler.sessions.value.singleOrNull()?.sessionId)
}
@Test
fun coalescedTrailingSuccessClearsTheInitialFailure() {
val calls = AtomicInteger(0)
@@ -1927,6 +1983,33 @@ class ChatViewModelGatewayInboundTurnTest {
assertFalse(gatewayHarness.rpcLog.any { it.first == "prompt.submit" })
}
@Test
fun gatewayInterimImmediatelyLeavesAStreamingConversationOwner() {
viewModel.sendMessage("Generate an image")
gatewayHarness.awaitRpc("prompt.submit")
serverWs.send(gatewayHarness.eventFrame("message.start", null, "live-resumed"))
serverWs.send(
gatewayHarness.eventFrame(
"message.interim",
buildJsonObject {
put("text", "Generating it now.")
put("already_streamed", false)
},
"live-resumed",
),
)
awaitCondition {
handler.messages.value.any { it.content == "Generating it now." }
}
assertTrue(handler.isStreaming.value)
val activeOwner = handler.messages.value.last()
assertTrue(activeOwner.isStreaming)
assertEquals(MessageRole.ASSISTANT, activeOwner.role)
assertTrue(activeOwner.content.isBlank())
}
@Test
fun queuedMainDispatchAdmitsBackgroundStartAfterLocalCompletion() {
viewModel.sendMessage("Local gateway turn")
@@ -3104,6 +3187,87 @@ class ChatViewModelGatewayInboundTurnTest {
assertTrue(viewModel.queuedMessages.value.isEmpty())
}
@Test
fun explicitQueueChoiceDoesNotAttemptRedirect() {
startTurnForQueueTest()
viewModel.sendMessage("Run next", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
assertEquals(listOf("Run next"), viewModel.queuedMessages.value)
assertFalse(gatewayHarness.rpcLog.any { it.first == "session.redirect" || it.first == "session.steer" })
}
@Test
fun deletingQueuedHeadReconnectsSuccessorToActiveTurn() {
startTurnForQueueTest()
viewModel.sendMessage("Remove me", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.sendMessage("Keep me", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.removeQueuedAt(0)
completeQueueTestTurn()
awaitCondition { gatewayHarness.rpcLog.any { it.first == "prompt.submit" && it.second["text"] == JsonPrimitive("Keep me") } }
assertFalse(gatewayHarness.rpcLog.any { it.first == "prompt.submit" && it.second["text"] == JsonPrimitive("Remove me") })
}
@Test
fun editingQueuedHeadDoesNotStrandSuccessor() {
startTurnForQueueTest()
viewModel.sendMessage("Edit me", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.sendMessage("Keep me", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
assertEquals("Edit me", viewModel.takeQueuedForEdit(0))
completeQueueTestTurn()
awaitCondition { gatewayHarness.rpcLog.any { it.first == "prompt.submit" && it.second["text"] == JsonPrimitive("Keep me") } }
}
@Test
fun stopPausesQueueUntilExplicitResumeAndPersistsWholeChain() {
val store = MemoryCheckpointStore()
viewModel.setChatTurnCheckpointStore(store)
startTurnForQueueTest()
viewModel.sendMessage("First pending", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.sendMessage("Second pending", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.cancelStream()
shadowOf(Looper.getMainLooper()).idle()
assertEquals(listOf("First pending", "Second pending"), viewModel.queuedMessages.value)
assertTrue(viewModel.queuePaused.value)
assertFalse(gatewayHarness.rpcLog.any { it.first == "prompt.submit" })
awaitCondition { store.checkpoint?.queueOnly == true }
assertEquals(true, store.checkpoint?.queuePaused)
assertEquals(2, store.checkpoint?.queuedMessages?.size)
viewModel.resumeQueue()
awaitCondition { gatewayHarness.rpcLog.any { it.first == "prompt.submit" && it.second["text"] == JsonPrimitive("First pending") } }
assertFalse(viewModel.queuePaused.value)
assertEquals(listOf("Second pending"), viewModel.queuedMessages.value)
}
@Test
fun pausedQueueCheckpointRestoresWithoutRecoveringStoppedTurn() {
val store = MemoryCheckpointStore()
viewModel.setChatTurnCheckpointStore(store)
startTurnForQueueTest()
viewModel.sendMessage("Keep paused", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
viewModel.cancelStream()
awaitCondition { store.checkpoint?.queueOnly == true }
val saved = requireNotNull(store.checkpoint)
viewModel.clearQueue()
shadowOf(Looper.getMainLooper()).idle()
store.checkpoint = saved
val activationsBefore = gatewayHarness.rpcLog.count { it.first == "session.activate" }
viewModel.prewarmGateway()
awaitCondition { viewModel.queuedMessages.value == listOf("Keep paused") }
assertTrue(viewModel.queuePaused.value)
assertFalse(handler.isStreaming.value)
assertEquals(activationsBefore, gatewayHarness.rpcLog.count { it.first == "session.activate" })
}
private fun startTurnForQueueTest() {
viewModel.switchProfileContext(PROFILE_CONTEXT, STORED_SESSION_ID)
serverWs.send(gatewayHarness.eventFrame("message.start", null, "live-resumed"))
awaitCondition { handler.isStreaming.value }
}
private fun completeQueueTestTurn() {
serverWs.send(gatewayHarness.eventFrame("message.complete", buildJsonObject { put("text", "Original complete") }, "live-resumed"))
}
@Test
fun queuedMessageStaysWithOriginWhileAnotherRunningSessionCompletes() {
val secondSession = "stored-session-b"
@@ -3249,6 +3413,29 @@ class ChatViewModelGatewayInboundTurnTest {
)
}
@Test
fun connectionSwitchKeepsRunningCheckpointWhenQueueExists() {
val store = MemoryCheckpointStore()
val switches = MutableSharedFlow<String>(extraBufferCapacity = 1)
viewModel.setChatTurnCheckpointStore(store)
viewModel.switchProfileContext(PROFILE_CONTEXT, STORED_SESSION_ID)
viewModel.observeConnectionSwitches(switches)
viewModel.sendMessage("Keep the running turn recoverable")
gatewayHarness.awaitRpc("prompt.submit")
viewModel.sendMessage("Follow up on this connection", com.hermesandroid.relay.data.BusyMessageAction.QueueNext)
awaitCondition { viewModel.queuedMessages.value.size == 1 }
switches.tryEmit("connection-b")
awaitCondition { viewModel.queuedMessages.value.isEmpty() }
shadowOf(Looper.getMainLooper()).idle()
val checkpoint = requireNotNull(store.checkpoint)
assertFalse("A detached running turn must not become queue-only", checkpoint.queueOnly)
assertEquals("Keep the running turn recoverable", checkpoint.user.content)
assertEquals(listOf("Follow up on this connection"), checkpoint.queuedMessages.map { it.text })
assertFalse(gatewayHarness.rpcLog.any { it.first == "session.interrupt" })
}
@Test
fun deletingDestinationCancelsItsQueueAndEditRestoresOnlyThatItem() {
gatewayHarness.redirectStatus = "rejected"
@@ -3296,7 +3483,7 @@ class ChatViewModelGatewayInboundTurnTest {
}
@Test
fun retryQueuedForActiveRunIsCancelledWithThatRun() {
fun retryQueuedForActiveRunIsPausedWhenThatRunStops() {
gatewayHarness.redirectStatus = "rejected"
viewModel.switchProfileContext(
AgentDisplay.profileContextKey("connection-a", null),
@@ -3311,7 +3498,8 @@ class ChatViewModelGatewayInboundTurnTest {
viewModel.cancelStream()
gatewayHarness.awaitRpc("session.interrupt")
assertTrue(viewModel.queuedMessages.value.isEmpty())
assertEquals(listOf("Retry this turn"), viewModel.queuedMessages.value)
assertTrue(viewModel.queuePaused.value)
serverWs.send(
gatewayHarness.eventFrame(
@@ -3754,6 +3942,7 @@ class ChatViewModelGatewayInboundTurnTest {
@Test
fun passiveForegroundObservationNeverClaimsOrInterruptsDesktopTurn() {
val directoryReads = AtomicInteger(0)
val observerProfile = Profile(
name = "observer",
model = "model-a",
@@ -3821,7 +4010,12 @@ class ChatViewModelGatewayInboundTurnTest {
viewModel.backgroundSessionActivityStates.value["observer:$STORED_SESSION_ID"] ==
SessionActivityState.Working
}
viewModel.setProfileSessionLister {
directoryReads.incrementAndGet()
Result.success(emptyList())
}
gatewayHarness.activeSessionListPayload = activeSessionPayload("waiting")
val directoryReadsBeforeHistoryPublication = directoryReads.get()
viewModel.requestSessionActivityRefresh()
awaitCondition {
viewModel.backgroundSessionActivityStates.value["observer:$STORED_SESSION_ID"] ==
@@ -3839,6 +4033,9 @@ class ChatViewModelGatewayInboundTurnTest {
handler.messages.value.singleOrNull()?.content ==
"Desktop completed without Android attachment."
}
shadowOf(Looper.getMainLooper()).idleFor(4, TimeUnit.SECONDS)
Thread.sleep(100)
assertEquals(directoryReadsBeforeHistoryPublication, directoryReads.get())
ownershipMethods.forEach { method ->
assertEquals(
"passive foreground sent $method",
@@ -11,6 +11,7 @@ import com.hermesandroid.relay.network.upstream.DashboardApiClient
import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.util.MediaCacheWriter
import io.mockk.coEvery
import io.mockk.coVerify
import io.mockk.mockk
import kotlinx.serialization.json.JsonPrimitive
import okhttp3.OkHttpClient
@@ -25,6 +26,7 @@ import org.robolectric.RobolectricTestRunner
import org.robolectric.RuntimeEnvironment
import org.robolectric.Shadows.shadowOf
import org.robolectric.annotation.Config
import java.io.File
@RunWith(RobolectricTestRunner::class)
@Config(sdk = [34])
@@ -52,7 +54,9 @@ class ChatViewModelMediaStateTest {
pairedTokenSnapshot = { "paired-session" },
)
cache = mockk()
coEvery { cache.cache(any(), any(), any()) } returns
coEvery { cache.cache(any<ByteArray>(), any(), any()) } returns
Uri.parse("content://com.axiomlabs.hermesrelay.fileprovider/hermes-media/photo.jpg")
coEvery { cache.cache(any<File>(), any(), any()) } returns
Uri.parse("content://com.axiomlabs.hermesrelay.fileprovider/hermes-media/photo.jpg")
handler = ChatHandler()
viewModel = ChatViewModel().also {
@@ -197,6 +201,8 @@ class ChatViewModelMediaStateTest {
}.attachments.single()
assertEquals("audio/mpeg", loaded.contentType)
assertEquals("test-voice-message.mp3", loaded.fileName)
coVerify(exactly = 1) { cache.cache(any<File>(), "audio/mpeg", "test-voice-message.mp3") }
coVerify(exactly = 0) { cache.cache(any<ByteArray>(), any(), any()) }
val request = dashboardServer.takeRequest()
assertEquals("/api/files/download", request.requestUrl?.encodedPath)
assertEquals(path, request.requestUrl?.queryParameter("path"))
Binary file not shown.

Before

Width:  |  Height:  |  Size: 1.5 MiB

After

Width:  |  Height:  |  Size: 1.1 MiB

+1 -1
View File
@@ -751,7 +751,7 @@ one-time pairing, the interactive PTY/TUI shell, client-side tool routing,
auto-reconnect with TOFU cert pinning, server-side session management, the
headless daemon, local diagnostics, and the optional Windows management tray.
What's next (see [ROADMAP.md](../ROADMAP.md#desktop-track) for the full track):
What's next (see [docs/project/ROADMAP.md](../docs/project/ROADMAP.md#desktop-track) for the full track):
- Service installers — `install-service-{win,linux,mac}` to register the daemon with `sc.exe` / systemd user unit / `launchd` so it auto-starts on login.
- Multi-client server-side routing — today a connected desktop client is single-slot; allow laptop + home-desktop + work-box attached simultaneously with per-client tool dispatch via a new hermes-agent `ContextVar`.
+2 -17
View File
@@ -1,26 +1,11 @@
import { spawn } from 'node:child_process'
import { existsSync } from 'node:fs'
import { homedir } from 'node:os'
import { basename, dirname, join, win32 } from 'node:path'
import type { ParsedArgs } from '../cli.js'
import { uiExecutablePath } from '../windowsBundle.js'
import { updateCommand } from './update.js'
export function uiExecutablePath(env = process.env, executable = process.execPath): string {
if (env.HERMES_RELAY_UI_PATH) return env.HERMES_RELAY_UI_PATH
if (env.HERMES_RELAY_INSTALL_DIR) {
const pathApi = win32.isAbsolute(env.HERMES_RELAY_INSTALL_DIR) ? win32 : { join }
return pathApi.join(env.HERMES_RELAY_INSTALL_DIR, 'hermes-relay-tray.exe')
}
const executableName = win32.basename(executable).toLowerCase()
if (executableName === 'hermes-relay.exe') {
return win32.join(win32.dirname(executable), 'hermes-relay-tray.exe')
}
if (basename(executable).toLowerCase() === 'hermes-relay') {
return join(dirname(executable), 'hermes-relay-tray.exe')
}
return join(homedir(), '.hermes', 'bin', 'hermes-relay-tray.exe')
}
export { uiExecutablePath }
function printHelp(): void {
process.stdout.write(`Usage: hermes-relay ui [open|status|install]\n\n`)
+108 -33
View File
@@ -29,8 +29,23 @@ import {
} from '../updater.js'
import { VERSION } from '../version.js'
import { scheduleWindowsInstaller } from '../windowsInstaller.js'
import { detectWindowsBundle, type WindowsBundleState } from '../windowsBundle.js'
import { isDaemonProcessAlive, readDaemonStatus } from '../lib/daemonStatus.js'
export interface UpdateCommandOptions {
platform?: NodeJS.Platform
arch?: string
bundle?: WindowsBundleState
}
export function installerRunsSilently(
bundleInstalled: boolean,
autoYes: boolean,
wantJson: boolean
): boolean {
return bundleInstalled || autoYes || wantJson
}
function humanBytes(n: number | null): string {
if (n === null) return '?'
if (n < 1024) return `${n} B`
@@ -80,6 +95,10 @@ function renderProgressBar(bytes: number, total: number, width = 28): string {
interface JsonReport {
current: string
target: 'cli' | 'cli_ui'
ui_installed: boolean
ui_version: string | null
versions_in_sync: boolean
up_to_date: boolean
ahead_of_latest: boolean
latest_tag: string | null
@@ -96,9 +115,13 @@ interface JsonReport {
error: string | null
}
function emptyReport(): JsonReport {
function emptyReport(target: 'cli' | 'cli_ui', bundle: WindowsBundleState): JsonReport {
return {
current: VERSION,
target,
ui_installed: bundle.installed,
ui_version: bundle.version,
versions_in_sync: !bundle.installed || bundle.version === VERSION,
up_to_date: true,
ahead_of_latest: false,
latest_tag: null,
@@ -116,11 +139,22 @@ function emptyReport(): JsonReport {
}
}
function reportFromInfo(info: UpdateInfo): JsonReport {
function reportFromInfo(
info: UpdateInfo,
target: 'cli' | 'cli_ui',
bundle: WindowsBundleState
): JsonReport {
const versionsInSync = !bundle.installed || bundle.version === VERSION
const bundleNeedsRepair = target === 'cli_ui' && bundle.installed && !versionsInSync
const uiAhead = bundle.version !== null && compareVersions(bundle.version, info.latest_version) > 0
return {
current: info.current,
up_to_date: !info.is_upgrade,
ahead_of_latest: compareVersions(info.current, info.latest_version) > 0,
target,
ui_installed: bundle.installed,
ui_version: bundle.version,
versions_in_sync: versionsInSync,
up_to_date: !info.is_upgrade && !bundleNeedsRepair,
ahead_of_latest: compareVersions(info.current, info.latest_version) > 0 || uiAhead,
latest_tag: info.latest_tag,
latest_version: info.latest_version,
is_prerelease: info.is_prerelease,
@@ -136,27 +170,38 @@ function reportFromInfo(info: UpdateInfo): JsonReport {
}
}
export async function updateCommand(args: ParsedArgs): Promise<number> {
export async function updateCommand(
args: ParsedArgs,
options: UpdateCommandOptions = {}
): Promise<number> {
const wantJson = !!args.flags.json
const checkOnly = !!args.flags.check
const autoYes = !!args.flags.yes
const installer = !!args.flags.installer
const installerRequested = !!args.flags.installer
const downloadOnly = !!args.flags['download-only']
const force = !!args.flags.force
const repo = typeof args.flags.repo === 'string' ? args.flags.repo : undefined
const platform = options.platform ?? process.platform
const arch = options.arch ?? process.arch
const bundle = options.bundle ?? detectWindowsBundle({ platform })
const installer = installerRequested || (platform === 'win32' && bundle.installed)
const target = installer ? 'cli_ui' : 'cli'
const selectedAssetName = installer
? 'hermes-relay-windows-x64-setup.exe'
: assetNameForPlatform(platform, arch)
let info: UpdateInfo | null = null
try {
const checkOpts = {
...(repo !== undefined ? { repo } : {}),
...(installer ? { assetName: 'hermes-relay-windows-x64-setup.exe' } : {})
...(selectedAssetName !== null ? { assetName: selectedAssetName } : {})
}
info = await checkForUpdate(checkOpts)
} catch (err) {
const msg = err instanceof Error ? err.message : String(err)
if (wantJson) {
const report = emptyReport()
const report = emptyReport(target, bundle)
report.error = msg
process.stdout.write(JSON.stringify(report, null, 2) + '\n')
return 1
@@ -168,7 +213,7 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
if (!info) {
// No CLI release-track rows at all — surface truthfully, don't crash.
if (wantJson) {
process.stdout.write(JSON.stringify(emptyReport(), null, 2) + '\n')
process.stdout.write(JSON.stringify(emptyReport(target, bundle), null, 2) + '\n')
return 0
}
process.stdout.write(`Current version: ${VERSION}\n`)
@@ -176,7 +221,7 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
return 0
}
const report = reportFromInfo(info)
const report = reportFromInfo(info, target, bundle)
if (wantJson && checkOnly) {
process.stdout.write(JSON.stringify(report, null, 2) + '\n')
@@ -184,7 +229,10 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
}
if (installer && report.ahead_of_latest && !force) {
const msg = `latest UI bundle (${info.latest_version}) is older than this CLI (${VERSION}); pass --force to downgrade explicitly`
const installedVersions = bundle.version === null
? `CLI ${VERSION}`
: `CLI ${VERSION}, UI ${bundle.version}`
const msg = `latest CLI+UI bundle (${info.latest_version}) is older than the installed ${installedVersions}; pass --force to downgrade explicitly`
if (wantJson) {
report.error = msg
process.stdout.write(JSON.stringify(report, null, 2) + '\n')
@@ -195,28 +243,45 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
}
if (!wantJson) {
process.stdout.write(`Current version: ${info.current}\n`)
if (installer && bundle.installed) {
process.stdout.write(`Installed versions: CLI ${info.current}, UI ${bundle.version ?? 'unknown'}\n`)
if (!report.versions_in_sync) {
process.stdout.write('CLI/UI drift detected; the verified Windows bundle will repair both surfaces together.\n')
}
} else {
process.stdout.write(`Current version: ${info.current}\n`)
}
process.stdout.write(`Checking GitHub Releases...\n`)
}
// The full Windows installer is also how a CLI-only installation adds the
// optional UI. Do not suppress that operation merely because the bundled
// CLI version is already current.
if (!info.is_upgrade && !installer) {
if (report.up_to_date && !installerRequested) {
if (wantJson) {
process.stdout.write(JSON.stringify(report, null, 2) + '\n')
return 0
}
process.stdout.write(`Up to date — you're on the latest CLI release.\n`)
process.stdout.write(
target === 'cli_ui'
? `Up to date — the installed CLI and UI match the latest release.\n`
: `Up to date — you're on the latest CLI release.\n`
)
return 0
}
// Upgrade available.
if (!wantJson) {
const pre = info.is_prerelease ? ' (prerelease)' : ''
process.stdout.write(
`Upgrade available: ${info.current} → ${info.latest_version}${pre}\n`
)
if (info.is_upgrade) {
process.stdout.write(
`Upgrade available: ${info.current} → ${info.latest_version}${pre}\n`
)
} else if (!report.versions_in_sync) {
process.stdout.write(`Bundle repair available: align CLI and UI on ${info.latest_version}${pre}\n`)
} else if (installerRequested && !bundle.installed) {
process.stdout.write(`CLI+UI bundle ready: ${info.latest_version}${pre}\n`)
}
process.stdout.write(` published: ${humanDate(info.published_at)}\n`)
process.stdout.write(
` asset: ${info.asset_name} (${humanBytes(info.asset_size)})\n`
@@ -232,7 +297,7 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
}
// Refuse to proceed if this platform has no matching asset.
const wantAsset = installer ? 'hermes-relay-windows-x64-setup.exe' : assetNameForPlatform()
const wantAsset = selectedAssetName
if (!wantAsset || !info.asset_url) {
const msg = `no binary available for ${process.platform}/${process.arch}`
if (wantJson) {
@@ -278,29 +343,35 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
: undefined
try {
const downloadOpts: DownloadOptions = onProgress ? { onProgress } : {}
if (installer) {
downloadOpts.targetPath = join(
tmpdir(),
`hermes-relay-${info.latest_version}-${process.pid}-${Date.now()}-setup.exe`
)
downloadOpts.cooperative = false
}
const downloadOpts: DownloadOptions = onProgress ? { onProgress } : {}
if (installer) {
downloadOpts.targetPath = join(
tmpdir(),
`hermes-relay-${info.latest_version}-${process.pid}-${Date.now()}-setup.exe`
)
downloadOpts.cooperative = false
}
const result = await downloadAndInstall(info, downloadOpts)
if (installer && !downloadOnly) {
if (process.platform !== 'win32') {
if (platform !== 'win32') {
throw new Error('the Hermes-Relay CLI UI installer is Windows-only')
}
const daemon = await readDaemonStatus()
const installDir = process.execPath.toLowerCase().endsWith('hermes-relay.exe')
? dirname(process.execPath)
: join(homedir(), '.hermes', 'bin')
const installDir = bundle.installed
? dirname(bundle.path)
: process.execPath.toLowerCase().endsWith('hermes-relay.exe')
? dirname(process.execPath)
: join(homedir(), '.hermes', 'bin')
scheduleWindowsInstaller(result.installedPath, {
silent: autoYes || wantJson,
// An existing bundle update already received CLI confirmation. Run
// setup silently so its finish-page checkbox cannot start a tray that
// was stopped before the update; the helper restores exact state.
silent: installerRunsSilently(bundle.installed, autoYes, wantJson),
restartDaemon: daemon ? isDaemonProcessAlive(daemon) : false,
installDir,
cliPath: join(installDir, 'hermes-relay.exe'),
trayPath: join(installDir, 'hermes-relay-tray.exe')
trayPath: join(installDir, 'hermes-relay-tray.exe'),
restartTray: bundle.installed ? bundle.running : true
})
}
if (useTtyProgress) process.stdout.write('\n')
@@ -315,7 +386,11 @@ export async function updateCommand(args: ParsedArgs): Promise<number> {
: `-> installed at ${result.installedPath}\n`
)
if (installer && !downloadOnly) {
process.stdout.write(' The installer updates the CLI and lets you enable the optional tray at sign-in.\n')
process.stdout.write(
bundle.installed
? ' The installer updates the CLI and UI together and restores their prior running state.\n'
: ' The installer adds the CLI and optional UI and lets you enable the tray at sign-in.\n'
)
} else if (result.needsRestart) {
process.stdout.write(
` On next \`hermes-relay\` invocation, the CLI will swap this in automatically.\n`
+88
View File
@@ -0,0 +1,88 @@
import { spawnSync } from 'node:child_process'
import { existsSync } from 'node:fs'
import { homedir } from 'node:os'
import { basename, dirname, join, win32 } from 'node:path'
export interface WindowsBundleState {
installed: boolean
path: string
version: string | null
running: boolean
}
interface BundleProbe {
version: string | null
running: boolean
}
export function uiExecutablePath(env = process.env, executable = process.execPath): string {
if (env.HERMES_RELAY_UI_PATH) return env.HERMES_RELAY_UI_PATH
if (env.HERMES_RELAY_INSTALL_DIR) {
const pathApi = win32.isAbsolute(env.HERMES_RELAY_INSTALL_DIR) ? win32 : { join }
return pathApi.join(env.HERMES_RELAY_INSTALL_DIR, 'hermes-relay-tray.exe')
}
const executableName = win32.basename(executable).toLowerCase()
if (executableName === 'hermes-relay.exe') {
return win32.join(win32.dirname(executable), 'hermes-relay-tray.exe')
}
if (basename(executable).toLowerCase() === 'hermes-relay') {
return join(dirname(executable), 'hermes-relay-tray.exe')
}
return join(homedir(), '.hermes', 'bin', 'hermes-relay-tray.exe')
}
function probeWindowsBundle(path: string): BundleProbe | null {
const script = [
"$item = Get-Item -LiteralPath $env:HERMES_RELAY_UI_PROBE_PATH -ErrorAction Stop",
"$running = @(Get-Process -Name 'hermes-relay-tray' -ErrorAction SilentlyContinue | Where-Object { $_.Path -eq $item.FullName }).Count -gt 0",
'[pscustomobject]@{ version = $item.VersionInfo.ProductVersion; running = $running } | ConvertTo-Json -Compress'
].join('; ')
const result = spawnSync('powershell.exe', [
'-NoProfile',
'-NonInteractive',
'-ExecutionPolicy',
'Bypass',
'-Command',
script
], {
encoding: 'utf8',
timeout: 5_000,
windowsHide: true,
env: { ...process.env, HERMES_RELAY_UI_PROBE_PATH: path }
})
if (result.status !== 0 || !result.stdout.trim()) return null
try {
const value = JSON.parse(result.stdout) as { version?: unknown; running?: unknown }
return {
version: typeof value.version === 'string' && value.version.trim()
? value.version.trim()
: null,
running: value.running === true
}
} catch {
return null
}
}
export function detectWindowsBundle(options: {
platform?: NodeJS.Platform
env?: NodeJS.ProcessEnv
executable?: string
exists?: (path: string) => boolean
probe?: (path: string) => BundleProbe | null
} = {}): WindowsBundleState {
const path = uiExecutablePath(options.env, options.executable)
const installed = (options.platform ?? process.platform) === 'win32' &&
(options.exists ?? existsSync)(path)
if (!installed) return { installed: false, path, version: null, running: false }
const probe = (options.probe ?? probeWindowsBundle)(path)
return {
installed: true,
path,
version: probe?.version ?? null,
// If the process probe fails, restarting is safer than leaving a UI that
// was running before setup permanently stopped.
running: probe?.running ?? true
}
}
+5 -2
View File
@@ -12,6 +12,7 @@ export interface WindowsInstallerLaunchOptions {
installDir?: string
cliPath?: string
trayPath?: string
restartTray?: boolean
delayMs?: number
callerPid?: number
}
@@ -31,6 +32,7 @@ export function windowsInstallerLaunchPlan(
installDir = '',
cliPath = '',
trayPath = '',
restartTray = true,
delayMs = 1200,
callerPid = process.pid
} = options
@@ -44,7 +46,7 @@ export function windowsInstallerLaunchPlan(
'$process = Start-Process -FilePath $installer -ArgumentList $installerArgs -PassThru',
'$process.WaitForExit()',
"if ($process.ExitCode -eq 0 -and $env:HERMES_RELAY_SETUP_RESTART_DAEMON -eq '1') { Start-Process -FilePath $env:HERMES_RELAY_SETUP_CLI -ArgumentList @('daemon','start') -WindowStyle Hidden | Out-Null }",
"if ($process.ExitCode -eq 0 -and $env:HERMES_RELAY_SETUP_TRAY) { Start-Process -FilePath $env:HERMES_RELAY_SETUP_TRAY -ArgumentList '--show' | Out-Null }",
"if ($process.ExitCode -eq 0 -and $env:HERMES_RELAY_SETUP_RESTART_TRAY -eq '1' -and $env:HERMES_RELAY_SETUP_TRAY) { Start-Process -FilePath $env:HERMES_RELAY_SETUP_TRAY -ArgumentList '--show' | Out-Null }",
'Remove-Item -LiteralPath $installer -Force -ErrorAction SilentlyContinue',
'exit $process.ExitCode'
].join('; ')
@@ -73,7 +75,8 @@ export function windowsInstallerLaunchPlan(
HERMES_RELAY_SETUP_RESTART_DAEMON: restartDaemon ? '1' : '0',
HERMES_RELAY_SETUP_INSTALL_DIR: installDir,
HERMES_RELAY_SETUP_CLI: cliPath,
HERMES_RELAY_SETUP_TRAY: trayPath
HERMES_RELAY_SETUP_TRAY: trayPath,
HERMES_RELAY_SETUP_RESTART_TRAY: restartTray ? '1' : '0'
}
}
}
+32
View File
@@ -6,6 +6,7 @@ import { tmpdir } from 'node:os'
import test from 'node:test'
import { uiExecutablePath } from '../src/commands/ui.js'
import { detectWindowsBundle } from '../src/windowsBundle.js'
import { windowsInstallerLaunchPlan } from '../src/windowsInstaller.js'
test('UI executable follows an explicit install directory', () => {
@@ -31,6 +32,7 @@ test('installer launch is delayed until the running CLI can exit', () => {
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_PATH, 'C:\\Temp\\hermes setup.exe')
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_SILENT, '1')
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_INSTALL_DIR, 'C:\\Hermes custom')
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_RESTART_TRAY, '1')
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_CALLER_PID, String(process.pid))
assert.match(plan.args.join(' '), /Wait-Process -Id \$callerPid/)
assert.match(plan.args.join(' '), /Start-Sleep/)
@@ -39,6 +41,35 @@ test('installer launch is delayed until the running CLI can exit', () => {
assert.equal(plan.options.detached, true)
})
test('Windows bundle detection reads the installed UI version and running state', () => {
const state = detectWindowsBundle({
platform: 'win32',
executable: 'C:\\Hermes\\hermes-relay.exe',
exists: () => true,
probe: path => ({
version: path.endsWith('hermes-relay-tray.exe') ? '0.4.0-beta.4' : null,
running: true
})
})
assert.deepEqual(state, {
installed: true,
path: 'C:\\Hermes\\hermes-relay-tray.exe',
version: '0.4.0-beta.4',
running: true
})
})
test('installer helper preserves a stopped tray state during a bundle update', () => {
const plan = windowsInstallerLaunchPlan('C:\\Temp\\hermes setup.exe', {
silent: true,
installDir: 'C:\\Hermes',
trayPath: 'C:\\Hermes\\hermes-relay-tray.exe',
restartTray: false
})
assert.equal(plan.options.env?.HERMES_RELAY_SETUP_RESTART_TRAY, '0')
assert.match(plan.args.join(' '), /HERMES_RELAY_SETUP_RESTART_TRAY/)
})
test('PowerShell launches an installer whose path contains spaces via environment transport', {
skip: process.platform !== 'win32'
}, async () => {
@@ -129,6 +160,7 @@ test('POSIX installer only advertises artifacts produced by the release workflow
assert.match(workflow, /if \[ "\$exit_code" -ne 0 \]/)
assert.match(workflow, /Smoke exact macOS CLI release asset/)
assert.match(workflow, /release-assets\/\$native_asset" --version/)
assert.match(workflow, /installed UI version mismatch/)
})
test('bootstrap installers paginate release discovery beyond the first API page', async () => {
+110 -2
View File
@@ -5,7 +5,7 @@ import { tmpdir } from 'node:os'
import { join } from 'node:path'
import test from 'node:test'
import { updateCommand } from '../src/commands/update.js'
import { installerRunsSilently, updateCommand } from '../src/commands/update.js'
import {
assetNameForPlatform,
checkForUpdate,
@@ -147,6 +147,14 @@ test('installer check reports a newer local preview without treating it as an er
command: 'update',
positional: [],
flags: { installer: true, check: true, json: true, repo: 'example/hermes-relay' }
}, {
platform: 'win32',
bundle: {
installed: false,
path: 'C:\\Hermes\\hermes-relay-tray.exe',
version: null,
running: false
}
}))
assert.equal(check.code, 0)
const report = JSON.parse(check.output)
@@ -160,10 +168,110 @@ test('installer check reports a newer local preview without treating it as an er
command: 'update',
positional: [],
flags: { installer: true, yes: true, json: true, repo: 'example/hermes-relay' }
}, {
platform: 'win32',
bundle: {
installed: false,
path: 'C:\\Hermes\\hermes-relay-tray.exe',
version: null,
running: false
}
}))
assert.equal(install.code, 2)
assert.match(JSON.parse(install.output).error, /older than this CLI/)
assert.match(JSON.parse(install.output).error, /older than the installed CLI/)
} finally {
globalThis.fetch = originalFetch
}
})
test('default Windows update targets the installer when an older UI is installed', async () => {
const originalFetch = globalThis.fetch
globalThis.fetch = async () => new Response(JSON.stringify([{
tag_name: `desktop-v${VERSION}`,
prerelease: VERSION.includes('-'),
published_at: '2026-09-01T00:00:00Z',
assets: [
{
name: 'hermes-relay-win-x64.exe',
browser_download_url: 'https://download.test/hermes-relay.exe',
size: 10
},
{
name: 'hermes-relay-windows-x64-setup.exe',
browser_download_url: 'https://download.test/setup.exe',
size: 20
}
]
}]), { status: 200, headers: { 'content-type': 'application/json' } })
try {
const check = await captureStdout(() => updateCommand({
command: 'update',
positional: [],
flags: { check: true, json: true, repo: 'example/hermes-relay' }
}, {
platform: 'win32',
bundle: {
installed: true,
path: 'C:\\Hermes\\hermes-relay-tray.exe',
version: '0.4.0-beta.4',
running: true
}
}))
assert.equal(check.code, 0)
const report = JSON.parse(check.output)
assert.equal(report.target, 'cli_ui')
assert.equal(report.asset_name, 'hermes-relay-windows-x64-setup.exe')
assert.equal(report.ui_installed, true)
assert.equal(report.ui_version, '0.4.0-beta.4')
assert.equal(report.versions_in_sync, false)
assert.equal(report.up_to_date, false)
} finally {
globalThis.fetch = originalFetch
}
})
test('default Windows update preserves a headless CLI-only installation', async () => {
const originalFetch = globalThis.fetch
globalThis.fetch = async () => new Response(JSON.stringify([{
tag_name: `desktop-v${VERSION}`,
prerelease: VERSION.includes('-'),
published_at: '2026-09-01T00:00:00Z',
assets: [{
name: 'hermes-relay-win-x64.exe',
browser_download_url: 'https://download.test/hermes-relay.exe',
size: 10
}]
}]), { status: 200, headers: { 'content-type': 'application/json' } })
try {
const check = await captureStdout(() => updateCommand({
command: 'update',
positional: [],
flags: { check: true, json: true, repo: 'example/hermes-relay' }
}, {
platform: 'win32',
bundle: {
installed: false,
path: 'C:\\Hermes\\hermes-relay-tray.exe',
version: null,
running: false
}
}))
assert.equal(check.code, 0)
const report = JSON.parse(check.output)
assert.equal(report.target, 'cli')
assert.equal(report.asset_name, 'hermes-relay-win-x64.exe')
assert.equal(report.ui_installed, false)
assert.equal(report.versions_in_sync, true)
assert.equal(report.up_to_date, true)
} finally {
globalThis.fetch = originalFetch
}
})
test('existing bundle updates suppress the installer finish-page restart choice', () => {
assert.equal(installerRunsSilently(true, false, false), true)
assert.equal(installerRunsSilently(false, false, false), false)
assert.equal(installerRunsSilently(false, true, false), true)
})
+10
View File
@@ -74,6 +74,16 @@ Check the lane without starting work:
`status` exits 0 when idle and 1 when busy. It intentionally does not expose the
owning process's arguments because Gradle properties can contain credentials.
For Android release-note/version iteration, use the narrow release-prep lane:
```powershell
python scripts/android-prepush.py --release-prep
```
It runs repository metadata checks plus the rendered Changelog and What's New
tests. It intentionally omits lint and assembly; after the exact commit is
pushed, required CI and Play preflight provide those expensive proofs.
Use `exec` for a connected/device workflow that must exclude every
wrapper-managed Gradle lane, including explicit APK installation:
+6 -3
View File
@@ -1,6 +1,7 @@
# Hermes Relay Android UI Design Reference
Status: design reference for future Android, Quest, and pairing-flow work.
Status: design reference for Android and pairing-flow work. The quarantined
Quest prototype is retained under `experiments/quest/` for historical context.
Use this document when a future session asks for mobile UI polish, pairing flow changes, QR scanning, connection setup, onboarding, terminal cockpit, or "make it feel more like Orca." It is intentionally a reference, not an implementation task list.
@@ -11,7 +12,6 @@ This project should keep its native Android stack:
- Kotlin + Jetpack Compose + Material 3 for app chrome and interaction flows.
- CameraX + ML Kit for QR scanning.
- Android WebView only where it is already the correct tool, such as xterm.
- Meta Spatial SDK for Quest/XR surfaces where needed.
Do not propose a React Native or Expo migration just because Orca's mobile app uses that stack. The useful lesson from Orca is the visual discipline and pairing UX, not the framework choice.
@@ -205,7 +205,10 @@ Target layout:
### Quest / XR
Use this reference for Quest visual tone, but do not force the phone layout into XR. Quest should keep the spatial cockpit concept:
The inactive Quest prototype is quarantined under `experiments/quest/` and is
not part of the production Android build or normal CI. If development resumes,
use this reference for its visual tone, but do not force the phone layout into
XR. The spatial cockpit concept was:
- MorphingSphere and voice pipeline remain first-class.
- Terminal panels should be spatial, readable, and anchored.
+28 -28
View File
@@ -30,8 +30,8 @@ Status: **passed**
### Compared
- Source: `C:\Users\Bailey\.codex\generated_images\019f6640-e6dc-7c33-8aca-a1610e2a19f0\call_JzVlJKlG8KWTJRo2xup7oTlq.png`
- Implementation: `C:\Users\Bailey\.codex\visualizations\2026\07\25\agent-drawer-audit\passport-qa-final.png`
- Source: `<session-generated-reference>`
- Implementation: `<session-visualization-artifact>`
- Source size: 852 x 1846 px
- Device viewport: Android, 1080 x 2340 px, font scale 1.0
- State: Agent tab, Victor pinned profile, disconnected gateway
@@ -105,11 +105,11 @@ final result: passed
## Assistant overlay
- Reference: `C:\Users\Bailey\.codex\generated_images\019fb003-68ea-7052-85c7-3745fa7e838e\call_jPwpDr9QfaCDA6k2c01StBYe.png`
- Reference: `<session-generated-reference>`
- Implementation captures:
- `C:\Users\Bailey\.codex\visualizations\2026\07\29\019fb003-68ea-7052-85c7-3745fa7e838e\assistant-live-compact.png`
- `C:\Users\Bailey\.codex\visualizations\2026\07\29\019fb003-68ea-7052-85c7-3745fa7e838e\assistant-live-expanded.png`
- Combined comparison: `C:\Users\Bailey\.codex\visualizations\2026\07\29\019fb003-68ea-7052-85c7-3745fa7e838e\assistant-design-comparison.png`
- `<session-visualization-artifact>`
- `<session-visualization-artifact>`
- Combined comparison: `<session-visualization-artifact>`
- Device viewport: 1080 × 2340, portrait, Samsung SM-S938U
- States reviewed: system assistant compact overlay and expanded overlay over a non-Hermes app
@@ -146,18 +146,18 @@ final result: blocked
## Appearance customization and visual assets
- Selected reference: `C:\Users\Bailey\.codex\generated_images\019fe6f7-920d-7be1-b287-608a0bc2ff49\exec-facb08cb-3d8f-400a-b6ff-6f1a11a74d95.png`
- Selected reference: `<session-generated-reference>`
- Reference pixels: 852 x 1843.
- Final real-screen captures:
- `C:\Users\Bailey\.codex\worktrees\af0f\hermes-relay\app\build\store-shots\05_themes.png`
- `C:\Users\Bailey\.codex\worktrees\af0f\hermes-relay\app\build\store-shots\05_theme_customizer.png`
- `C:\Users\Bailey\.codex\worktrees\af0f\hermes-relay\app\build\store-shots\08_appearance.png`
- `app/build/store-shots/05_themes.png`
- `app/build/store-shots/05_theme_customizer.png`
- `app/build/store-shots/08_appearance.png`
- Implementation pixels: 1080 x 2160, portrait Robolectric/Roborazzi capture of the production Compose screen at its 360 dp Android viewport.
- Normalization: the selected reference was scaled to 1080 px wide and cropped to the same 2160 px viewport for the full-view comparison. The reference's taller aspect ratio remains visible as an expected viewport difference; the focused customizer capture verifies the below-fold editor content.
- Comparison evidence:
- Initial full-view comparison: `C:\Users\Bailey\.codex\visualizations\2026\08\09\019fe6f7-920d-7be1-b287-608a0bc2ff49\appearance-reference-v-current.png`
- Final normalized full-view comparison: `C:\Users\Bailey\.codex\visualizations\2026\08\09\019fe6f7-920d-7be1-b287-608a0bc2ff49\appearance-reference-v-current-2.png`
- Focused customizer comparison: `C:\Users\Bailey\.codex\visualizations\2026\08\09\019fe6f7-920d-7be1-b287-608a0bc2ff49\appearance-customizer-reference-v-current.png`
- Initial full-view comparison: `<session-visualization-artifact>`
- Final normalized full-view comparison: `<session-visualization-artifact>`
- Focused customizer comparison: `<session-visualization-artifact>`
- State: Hermes Relay dark preset, customizer expanded. The focused capture expands the real control by click and scrolls its Shape row into view.
### Comparison history
@@ -187,15 +187,15 @@ final result: passed
## Conversation voice dock
- Reference: `C:\Users\Bailey\.codex\generated_images\019fba42-1e93-78e1-9cd6-6919fb52d5bc\exec-89feab69-9caf-4084-b107-6bff43e511d6.png`
- Reference: `<session-generated-reference>`
- Implementation captures:
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\implemented_conversation_final.png`
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\conversation_refined_expanded.png`
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\focus_final_expanded.png`
- Combined comparison: `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\voice-dock-design-comparison-final.png`
- Expanded before/after comparison: `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\voice-expanded-before-after.png`
- Entry transition recording: `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\voice_entry_transition.mp4`
- Entry transition frame sequence: `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit\voice_entry_transition_frames.png`
- `<session-visualization-artifact>`
- `<session-visualization-artifact>`
- `<session-visualization-artifact>`
- Combined comparison: `<session-visualization-artifact>`
- Expanded before/after comparison: `<session-visualization-artifact>`
- Entry transition recording: `<session-visualization-artifact>`
- Entry transition frame sequence: `<session-visualization-artifact>`
- Reference size: 853 x 1844 px
- Device viewport: 1080 x 2340, portrait, Samsung SM-S938U
- States reviewed: collapsed idle dock, expanded Tap-mode controls, collapsed and expanded Focus header, Focus-to-Conversation transition
@@ -229,8 +229,8 @@ copying the mockup's illustrative content.
6. Compared the original and refined expanded Conversation and Focus states together; the final panels remove metadata fragmentation, header truncation, and avatar bleed-through.
7. Recorded a persisted-Focus voice entry, inspected the 30 fps frame sequence, and verified that Conversation appears first through a continuous composer expansion before Focus is offered as an explicit action.
8. Re-audited the installed Standard-mode drawer in both presentations. The final Conversation and Focus captures are:
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit-standard\21-final-expanded.png`
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit-standard\24-final-focus-expanded.png`
- `<session-visualization-artifact>`
- `<session-visualization-artifact>`
The route summary is now two clearly separated lines (`Standard mode · Victor` and `xAI TTS · Leo`), with duplicate provider/model aliases removed and configuration provenance left to Voice Settings.
9. Verified the Conversation long-press menu on-device in `22-final-speak-menu.png`: completed assistant messages expose Copy, Quote in reply, and Speak response without stacking Android's text-selection toolbar over the app menu.
10. Verified the connection footer remains present under the Conversation composer. Focus remains the only in-app voice presentation that hides it.
@@ -242,13 +242,13 @@ final result: passed
## System voice overlay redesign
- Selected reference: `C:\Users\Bailey\.codex\generated_images\019fba42-1e93-78e1-9cd6-6919fb52d5bc\exec-6a606b04-58c3-4a6d-b11b-cd25f99a047d.png`
- Selected reference: `<session-generated-reference>`
- Source concepts:
- `C:\Users\Bailey\.codex\generated_images\019fba42-1e93-78e1-9cd6-6919fb52d5bc\exec-31a5512a-9cb7-455a-b111-d5797ab09e93.png`
- `C:\Users\Bailey\.codex\generated_images\019fba42-1e93-78e1-9cd6-6919fb52d5bc\exec-bbfd616e-3847-4a2e-bbd0-65deb5e4e98c.png`
- `<session-generated-reference>`
- `<session-generated-reference>`
- Baseline captures:
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit-standard\29-current-overlay-expanded.png`
- `C:\Users\Bailey\.codex\visualizations\2026\07\31\019fba42-1e93-78e1-9cd6-6919fb52d5bc\voice-ui-audit-standard\30-current-overlay-expanded.png`
- `<session-visualization-artifact>`
- `<session-visualization-artifact>`
- Device viewport: 1080 x 2340, portrait, Samsung SM-S938U
- States to review: collapsed system overlay and expanded system overlay over a non-Hermes app
+102 -4
View File
@@ -267,7 +267,7 @@ not require an API endpoint or API bearer when dashboard chat is ready.
### 12. Android as a Hermes Platform/Channel — "Threads" (Shipped 2026-06-28; unified-session model 2026-06-29)
> **Status (2026-08-12):** SHIPPED as the `phone` platform plugin (`plugin/phone_platform.py`) — registered via `ctx.register_platform` with **no fork** (the ~16-file upstream change sketched below was avoided; the original research predates the open plugin-platform registry). Two-way reply is device-verified. Agent-facing entry is `send_message target=phone` (the stale `target=mobile:<device_id>` syntax below is superseded); standalone cron delivery uses the registered sender, and the adapter publishes its canonical home destination through upstream's channel directory. Live cron certification remains tracked in TODO.md.
> **Status (2026-08-12):** SHIPPED as the `phone` platform plugin (`plugin/phone_platform.py`) — registered via `ctx.register_platform` with **no fork** (the ~16-file upstream change sketched below was avoided; the original research predates the open plugin-platform registry). Two-way reply is device-verified. Agent-facing entry is `send_message target=phone` (the stale `target=mobile:<device_id>` syntax below is superseded); standalone cron delivery uses the registered sender, and the adapter publishes its canonical home destination through upstream's channel directory. Live cron certification remains tracked in docs/project/TODO.md.
>
> **Decision (2026-06-29) — unified-session "Threads", not a separate surface:** the proactive agent↔phone conversation is **not** a separate app lane/tab/segment. It is a **source-tagged session inside the one Chat surface** — a **Thread** (`source=phone`). The three things distinguishing a Thread from a normal gateway chat are *session properties*, not a separate UI: (a) the agent can initiate a turn, (b) it rides the relay `proactive` transport and is relay-gated, (c) it's a standing/named DM. **Scrollback = the gateway session store** (same read path Chat uses); **live receive = the relay `proactive` push** (→ notification); **send = `proactive.reply`**. The local `ProactiveInboxStore` is demoted to a live-push cache + outbox (no parallel history). The Thread capability is surfaced in the **connection best-path/capability UI** (a relay-tier capability, like terminal/bridge/voice) and as a clean **Threads** entry (thread-spool icon, NOT a phone glyph) pinned atop the session drawer when active — never a connection-wizard step. Degrades cleanly: no relay plugin → no `source=phone` sessions → Chat is unchanged (standard-path-safe). This **supersedes the earlier "separate Agent lane / 4th nav segment" sketch** and folds in the "show chat source/platform attribution in Chat" goal in one stroke.
>
@@ -3240,7 +3240,7 @@ escalation remains reserved and reports disabled. The optional driver is not
bundled or updated by Hermes-Relay, and Hermes forces driver telemetry off for
every child process it starts. The legacy engine remains the default and the
fail-closed fallback while the live Windows acceptance and remaining scope,
redaction, and grant-bridge hardening gates tracked in `TODO.md` stay open.
redaction, and grant-bridge hardening gates tracked in `docs/project/TODO.md` stay open.
**Second-phase refinement (2026-08-13).** CUA is the preferred/default setting
for new structured-control sessions; the original Windows input path is named
@@ -3743,7 +3743,7 @@ the session, duplicate submission, wrong-session events, or an arbitrary timer.
Normal terminal delivery is unchanged, queued turns retain their existing
ownership, Relay remains optional, and unmodified upstream compatibility is
preserved. Physical certification across the reported device/network matrix
remains tracked in `TODO.md`.
remains tracked in `docs/project/TODO.md`.
---
@@ -4118,7 +4118,7 @@ visible without mislabeling their parent turn. Older Gateways remain usable
but show Unavailable when no exact local terminal truth exists. Declarative
Gateway scenarios cover all four upstream states, complete-snapshot
disappearance, client-side profile isolation, and method-not-found; physical
and current-host certification remains tracked in `TODO.md`. An upstream
and current-host certification remains tracked in `docs/project/TODO.md`. An upstream
profile field/filter or explicitly owned aggregate activity route would remove
the remaining ambiguity for multi-profile clients.
@@ -4226,6 +4226,12 @@ longer current.
hidden-source exclusions server-side. Near-end scrolling appends subsequent
50-row `offset` pages under the same owner/generation; older rows never block
the first-open critical path.
- Routine transcript open, restore, and post-turn reconciliation request one
latest 500-row page, matching the rows Android can retain. Complete
oldest-first pagination is reserved for positional recovery that proves it
needs older anchors. Each Dashboard JSON response is rejected above the
Android byte limit before parsing, and aggregate complete reads retain their
independent row/payload ceilings.
- A refresh over existing rows is quiet. The exact connection/profile cache
remains visible until authoritative replacement rows arrive. An uncached
profile may show loading, but a failed read never means "no sessions."
@@ -4304,3 +4310,95 @@ API-only/headless clients, compatibility testing, and existing API records, but
they are no longer automatic recovery for standard Chat. Users retry or sign in
without losing local work, named profiles cannot cross databases silently, and
readiness reflects the conversation that will actually receive the next turn.
---
## ADR 72 — Plugin and CLI+UI release tags are approval-created
**Status:** Accepted (2026-09-01).
**Context.** Plugin and CLI+UI tag workflows correctly rejected stable tags
outside `main` and prerelease tags outside `dev`, but that validation occurred
only after an operator pushed the tag. The CLI+UI release recipe also told
operators to tag a prerelease from `main`, contradicting the canonical branch
contract. A rejected tag therefore left a failed check on an otherwise healthy
release commit and required destructive tag recovery before publication.
**Decision.** The normal Plugin and CLI+UI release path validates first and
creates the tag second. A single manual approval workflow:
- always runs the trusted workflow definition from `main`, then selects the
exact `origin/main` tip for stable versions or `origin/dev` for prereleases;
- verifies the surface-owned version metadata and matching changelog heading;
- refuses an existing tag, then creates the exact `server-v*` or `desktop-v*`
ref at the validated commit; and
- dispatches the trusted release workflow from `main`, whose jobs explicitly
check out and revalidate that immutable tag.
Direct tag pushes remain a recovery path and retain the same fail-closed
metadata and branch-containment checks. Approval does not weaken release tests,
change stable/prerelease source branches, or combine the independently
versioned Plugin and CLI+UI artifacts.
**Consequences.** Routine releases cannot create a known-invalid tag before
discovering a branch mismatch. A tag created with `GITHUB_TOKEN` does not
recursively trigger Actions, so approval explicitly dispatches the release
workflow and the release workflow supports both tag-push and approved-dispatch
events. The workflow must exist on `main` before the approval surface is used.
**Key files:**
- `.github/workflows/approve-release-extensions.yml`
- `.github/workflows/release-plugin.yml`
- `.github/workflows/release-cli.yml`
- `RELEASE.md`
---
## ADR 73 — Release promotion reuses immutable exact-tree evidence
**Status:** Accepted (2026-09-01).
**Context.** A coordinated release previously compiled Android up to four
times: local release verification, release-prep PR CI, private Play preflight,
and public tag publication. The canonical `dev` to `main` PR also repeated the
same path-aware matrix even when its synthetic merge produced the exact Git
tree already tested before integration. Rebuilding identical source increased
elapsed time without adding byte-level provenance.
**Decision.** Release evidence is content-addressed by Git tree and promoted
only through immutable GitHub Actions artifacts.
- Play preflight is the one stable Android signing/build authority. It stores
the exact signed sideload APK, Play AAB, both R8 mappings, a manifest with
version/commit/tree/size/hash metadata, and checksums for public assets.
- Stable Android publication downloads that artifact by immutable ID, verifies
its successful trusted workflow run and full manifest, reruns package-level
DEX/native checks, promotes the existing Play draft, and publishes the same
APK/AAB bytes. Prerelease candidates retain their independent build path.
- Every successful Required-checks run stores a small tree-keyed proof after
all selected jobs pass. A canonical `dev` to `main` PR may reuse it only when
the simulated merge tree equals the `dev` tree exactly. Missing proof or any
content change automatically runs the ordinary matrix.
- Local Android release iteration runs metadata and release-presentation tests;
exact pushed commits still require CI and Play preflight.
- A coordinated approval workflow dispatches independently validated surface
approvals concurrently; it does not combine tags or artifact contracts.
- Trusted desktop CI and the CLI+UI release workflow share a lockfile- and
exact-source-keyed Rust/Tauri target cache. Release tags may restore the
default branch's exact build state; cache misses retain the full build path.
**Consequences.** Stable Android bytes are built once, evidence reuse fails
closed on tree or hash drift, and release PRs avoid duplicate work without
weakening branch protection. Actions artifact retention becomes part of the
release window: expired evidence causes a safe rebuild/fallback, never an
approval bypass.
**Key files:**
- `.github/workflows/play-preflight-android.yml`
- `.github/workflows/release-android.yml`
- `.github/workflows/ci-required.yml`
- `.github/workflows/approve-release-train.yml`
- `scripts/android_release_artifacts.py`
- `scripts/android-prepush.py`
+12
View File
@@ -68,9 +68,11 @@ the upstream contract identifiers it depends on.
|---|---|
| `initial_history_bind` | Durable, profile-scoped history is already available when the client resumes and first binds its rendered transcript |
| `ordinary_turn` | Normal message start, deltas, completion, and persisted history |
| `ownership_rejection` | A submit acknowledged before the defense-in-depth ownership check emits the canonical terminal refusal; no user/model row is persisted and clients must not enter history recovery |
| `compaction_status` | Compaction status is client-visible before terminal completion and may repeat as a heartbeat |
| `rapid_tools_interims` | Rapid chunks, reasoning, tool activity, and interim assistant boundaries |
| `queued_follow_up` | Two explicitly owned turns and ordered queue drainage |
| `queued_stop_resume` | Explicit queue choice, removal of a predecessor, Stop/pause, lifecycle return, and explicit Resume through production Android controls |
| `scope_rejection_inputs` | Exact, foreign, and unscoped event inputs |
| `terminal_gap_activate` | Socket closes after live output; replacement `session.activate` reports `running=false`; history is authoritative |
| `terminal_gap_active_list` | An exact Android-owned turn receives deltas but no terminal; `session.active_list` reports the same live/durable owner idle; history is authoritative |
@@ -123,6 +125,16 @@ unreviewed endpoint.
## Physical-device certification
The queue-control instrumentation uses the `queued_stop_resume` fixture on
loopback with an explicit ADB reverse. Run only
`GatewayExternalFixtureInstrumentedTest#queuedStopResume_preservesWorkAcrossLifecycleAndUsesExplicitResume`
with `gatewayFixtureBaseUrl` set to that fixture. It verifies two submits, one
interrupt, no redirect, and a single completed resumed reply. This is a separate
scenario from the terminal-gap certification runner below, whose evidence
contract requires socket loss and activation. The fixture emits the upstream
interrupted terminal before the next turn; omitting it would exercise a broken
server contract rather than the queue controls.
Inspect the exact plan first. The runner requires an explicit serial or
transport ID, targets only `com.axiomlabs.hermesrelay.sideload`, and performs no
installation unless its corresponding install flag is supplied.

Some files were not shown because too many files have changed in this diff Show More