Compare commits

...
Author SHA1 Message Date
Bailey Dixon 889c2fb316 Merge pull request #390 from Codename-11/dev
release(android): android-v1.11.0
2026-08-20 20:56:04 -04:00
Bailey Dixon 260c21737c merge: prepare Android 1.11.0 release 2026-08-20 20:12:40 -04:00
Bailey Dixon 7036219f90 release(android): android-v1.11.0 2026-08-20 20:12:06 -04:00
Bailey Dixon d741acab27 merge: clear Android release verification blockers 2026-08-20 19:53:04 -04:00
Bailey Dixon 8d9970449c test(android): align localized route diagnostics 2026-08-20 19:52:38 -04:00
Bailey Dixon be50f9a726 fix(android): preserve stopped recovery placeholders 2026-08-20 19:52:37 -04:00
Bailey Dixon f21923d39b merge: resync remote dev after website hotfix 2026-08-20 17:31:51 -04:00
Bailey Dixon 27970d4020 Merge pull request #389 from Codename-11/chore/backmerge-website-remote-access-link
chore: back-merge website link hotfix
2026-08-20 17:27:59 -04:00
Bailey Dixon 94992ff37f chore: back-merge website link hotfix 2026-08-20 17:27:01 -04:00
Bailey Dixon a25de7fe31 Merge pull request #388 from Codename-11/fix/website-remote-access-link
fix(website): repair remote access links
2026-08-20 17:24:45 -04:00
Bailey Dixon 2006d552e2 fix(website): repair remote access links 2026-08-20 17:22:23 -04:00
Bailey Dixon ab532d0696 merge: sync remote dev before release 2026-08-20 17:11:47 -04:00
Bailey Dixon 66971cb0e2 Merge pull request #383 from ophirhan/fix/soft-keyboard-newline
fix(android): only physical Enter sends; let IME return key insert newline
2026-08-20 14:20:47 -04:00
Bailey Dixon 9ae8de2c9d merge: fully expand Android Bridge screen access sheet 2026-08-20 13:17:59 -04:00
Bailey Dixon b5174d6279 fix(android): fully expand screen access sheet 2026-08-20 13:17:41 -04:00
Bailey Dixon 7ac5a48e18 merge: clarify Android Bridge access controls 2026-08-20 13:01:43 -04:00
Bailey Dixon ea6cb5a6a7 fix(android): clarify bridge access controls 2026-08-20 13:01:29 -04:00
Bailey Dixon d5cccd664a merge: preserve unlimited Android Bridge state 2026-08-20 12:40:14 -04:00
Bailey Dixon a48349e3cf fix(android): preserve unlimited bridge access state 2026-08-20 12:39:54 -04:00
Bailey Dixon d476704c3f merge: allow unlimited Android Bridge screen access 2026-08-20 11:53:15 -04:00
Bailey Dixon f7a070ecfe feat(android): allow unlimited bridge screen access 2026-08-20 11:52:52 -04:00
Bailey Dixon 37084566a0 merge: clarify Android Bridge access setup 2026-08-20 11:05:47 -04:00
Bailey Dixon c43f22f18d feat(android): clarify bridge access setup 2026-08-20 11:04:59 -04:00
Bailey Dixon 6244ab3781 merge: surface Android stored session resume failures 2026-08-20 09:14:08 -04:00
Bailey Dixon 9b1852a986 merge: reconcile current dev for Android resume failure fix
# Conflicts:
#	CHANGELOG.md
2026-08-20 08:54:52 -04:00
Bailey Dixon 99f853c98e fix(android): surface stored session resume failures 2026-08-20 08:53:49 -04:00
ophirhan 39782a5ff1 fix(android): only physical Enter sends; let IME return key insert newline
The #318 keyboard handling made any KEYCODE_ENTER key event submit the
message when physicalEnterSends is enabled. Some IMEs dispatch the soft
keyboard return key as a synthesized KEYCODE_ENTER key event (deviceId
-1), so on those keyboards the return key sent the message instead of
inserting a newline - leaving no way to type multi-line prompts from
the touchscreen.

Gate the submit path on physical keys (deviceId != -1) so IME-dispatched
Enter falls through to the default newline insertion while hardware Enter
keeps the send behavior. Adds a regression test for the IME key-event path.

Closes #367
2026-08-20 14:18:56 +03:00
Bailey Dixon 0d660c0e41 merge: add granular Android Bridge capability grants 2026-08-19 21:10:05 -04:00
Bailey Dixon 6b14ac0e0e Merge branch 'dev' into feature/android-bridge-capability-grants 2026-08-19 21:01:31 -04:00
Bailey Dixon 59b5424c49 Merge branch 'fix/android-power-audit-377' into dev 2026-08-19 20:58:24 -04:00
Bailey Dixon 0f83af76f6 fix(android): bound power-sensitive runtime work 2026-08-19 20:08:15 -04:00
Bailey Dixon 6a39e8dc1a feat(android): add granular bridge capability grants 2026-08-19 19:43:04 -04:00
Bailey Dixon e8473e14c8 Merge pull request #376 from Codename-11/chore/backmerge-android-1.10.0
chore: back-merge Android 1.10.0 release
2026-08-18 22:23:49 -04:00
Bailey Dixon e05018bd0b chore: back-merge Android 1.10.0 release 2026-08-18 22:22:49 -04:00
Bailey Dixon 97231eb291 Merge pull request #375 from Codename-11/dev
release(android): android-v1.10.0
2026-08-18 22:02:10 -04:00
Bailey Dixon f7c707be03 release(android): android-v1.10.0 2026-08-18 21:32:09 -04:00
Bailey Dixon 331fad0827 merge: fix Android completion bubble layout 2026-08-18 20:50:24 -04:00
Bailey Dixon f131fa08cc fix(android): keep completion bubble layout stable 2026-08-18 20:50:18 -04:00
Bailey Dixon cbc81513bd merge: fix Android completion scroll anchor 2026-08-18 19:56:48 -04:00
Bailey Dixon 3ad5ad8dc7 fix(android): preserve stream completion scroll anchor 2026-08-18 19:56:39 -04:00
Bailey Dixon d695553c0b merge: integrate native streaming Markdown renderer 2026-08-18 19:32:42 -04:00
Bailey Dixon 6b324fa822 fix(android): keep streaming markdown renderer stable 2026-08-18 19:32:28 -04:00
Bailey Dixon 52ee97f2b5 merge: fix Android streaming scroll settlement 2026-08-17 19:57:56 -04:00
Bailey Dixon 76bfe97c78 fix(android): stop streaming markdown scroll bounce 2026-08-17 19:57:47 -04:00
Bailey Dixon c8a3072704 merge: integrate Android streaming Markdown follow
# Conflicts:
#	app/src/main/kotlin/com/hermesandroid/relay/ui/screens/ChatScreen.kt
2026-08-17 18:43:50 -04:00
Bailey Dixon a7612d7f05 chore(android): reconcile localization catalog hash 2026-08-17 18:25:32 -04:00
Bailey Dixon e82ed47573 merge: integrate Android composer continuity 2026-08-17 18:18:34 -04:00
Bailey Dixon c6e4a2877d merge: fix Android reconnect and credential safety 2026-08-17 09:48:42 -04:00
Bailey Dixon 79335fea16 feat(android): persist composer drafts and attach large pastes 2026-08-17 09:40:07 -04:00
Bailey Dixon 9c8b6c30bf fix(android): recover chat sessions and reject malformed credentials 2026-08-17 09:11:21 -04:00
Bailey Dixon 4cf89df627 feat(android): stabilize streaming markdown follow 2026-08-17 09:10:53 -04:00
Bailey Dixon ad98ca9486 fix(android): expose newline on software keyboard 2026-08-17 08:38:50 -04:00
dependabot[bot] 9d50f401ad chore(deps): bump com.github.triplet.play from 4.0.0 to 4.1.1 (#373)
Bumps com.github.triplet.play from 4.0.0 to 4.1.1.

---
updated-dependencies:
- dependency-name: com.github.triplet.play
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 11:57:58 +00:00
dependabot[bot] 2bc62c84e0 chore(deps): bump androidx.appcompat:appcompat from 1.7.1 to 1.8.0 (#372)
Bumps androidx.appcompat:appcompat from 1.7.1 to 1.8.0.

---
updated-dependencies:
- dependency-name: androidx.appcompat:appcompat
  dependency-version: 1.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 11:57:08 +00:00
dependabot[bot] c3011e286c chore(deps): bump com.microsoft.onnxruntime:onnxruntime-android (#371)
Bumps [com.microsoft.onnxruntime:onnxruntime-android](https://github.com/microsoft/onnxruntime) from 1.28.0 to 1.29.0.
- [Release notes](https://github.com/microsoft/onnxruntime/releases)
- [Changelog](https://github.com/microsoft/onnxruntime/blob/main/docs/ReleaseNotesWorkflow.md)
- [Commits](https://github.com/microsoft/onnxruntime/compare/v1.28.0...v1.29.0)

---
updated-dependencies:
- dependency-name: com.microsoft.onnxruntime:onnxruntime-android
  dependency-version: 1.29.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 11:56:34 +00:00
dependabot[bot] 9458fea4f7 chore(deps): bump the testing group with 2 updates (#370)
Bumps the testing group with 2 updates: [io.github.takahirom.roborazzi:roborazzi](https://github.com/takahirom/roborazzi) and [io.github.takahirom.roborazzi:roborazzi-compose](https://github.com/takahirom/roborazzi).


Updates `io.github.takahirom.roborazzi:roborazzi` from 1.71.0 to 1.72.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.71.0...1.72.0)

Updates `io.github.takahirom.roborazzi:roborazzi-compose` from 1.71.0 to 1.72.0
- [Release notes](https://github.com/takahirom/roborazzi/releases)
- [Commits](https://github.com/takahirom/roborazzi/compare/1.71.0...1.72.0)

---
updated-dependencies:
- dependency-name: io.github.takahirom.roborazzi:roborazzi
  dependency-version: 1.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
- dependency-name: io.github.takahirom.roborazzi:roborazzi-compose
  dependency-version: 1.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: testing
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 11:55:21 +00:00
dependabot[bot] 94b29c4a01 chore(deps): bump androidx.compose:compose-bom in the compose group (#369)
Bumps the compose group with 1 update: androidx.compose:compose-bom.


Updates `androidx.compose:compose-bom` from 2026.06.01 to 2026.08.00

---
updated-dependencies:
- dependency-name: androidx.compose:compose-bom
  dependency-version: 2026.08.00
  dependency-type: direct:production
  dependency-group: compose
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2026-08-17 11:54:39 +00:00
Bailey Dixon 3d11cfb5f2 Merge pull request #366 from Codename-11/dev
release(android): android-v1.9.1
2026-08-16 17:09:20 -04:00
Bailey Dixon 0f589d030f release(android): android-v1.9.1 2026-08-16 16:38:38 -04:00
Bailey Dixon af96579e06 merge: sync main into dev after desktop release 2026-08-16 16:20:04 -04:00
Bailey Dixon f0167ee00f fix(android): persist shared profile avatars 2026-08-16 15:29:43 -04:00
Bailey Dixon a5798e5e6c merge: integrate upstream animated profile pets 2026-08-16 15:04:18 -04:00
Bailey Dixon 479d788967 feat(android): sync upstream animated profile pets 2026-08-16 11:04:24 -04:00
Bailey Dixon 3f6723da6f merge: fix Nous callback authentication 2026-08-16 10:01:10 -04:00
Bailey Dixon c1cd376d8b fix(android): align Nous callback authentication 2026-08-16 10:01:02 -04:00
Bailey Dixon 87e2fb710d feat(android): add phone-only animated profile icons 2026-08-16 09:46:52 -04:00
Bailey Dixon 5a617f9482 merge: integrate Hermes profile contracts 2026-08-15 22:57:33 -04:00
Bailey Dixon 13152a4fab feat(android): adopt Hermes profile contracts 2026-08-15 22:56:30 -04:00
Bailey Dixon 7f31c88f46 merge: integrate high-value Android and Relay enhancements 2026-08-15 21:39:14 -04:00
Bailey Dixon 3e857b54a2 test(android): align hardened gateway contracts 2026-08-15 21:36:50 -04:00
Bailey Dixon 163e3341da fix(android): verify draft profile ownership 2026-08-15 21:36:49 -04:00
Bailey Dixon a5419df579 fix(android): guard draft model selection 2026-08-15 21:36:49 -04:00
Bailey Dixon e834c603d0 fix(android): clear rejected recovery events 2026-08-15 21:36:49 -04:00
Bailey Dixon a31d715569 feat(android): surface resource and model risk 2026-08-15 21:36:49 -04:00
Bailey Dixon c6b8d891ac fix(android): harden attachment delivery 2026-08-15 21:35:38 -04:00
Bailey Dixon 8996f34347 feat(android): add bounded cron and reset evidence 2026-08-15 21:35:38 -04:00
Bailey Dixon f5f1a4c7d4 fix(android): enforce profile ownership 2026-08-15 21:34:36 -04:00
Bailey Dixon 31eccc631e fix(android): fail closed on ambiguous rewinds 2026-08-15 21:34:35 -04:00
Bailey Dixon 64ba979816 Merge pull request #364 from Codename-11/feature/proactive-away-summary
feat(threads): surface messages received while away
2026-08-15 21:24:04 -04:00
Bailey Dixon 5be0979d74 chore(android): refresh localization catalog status 2026-08-15 21:13:05 -04:00
Bailey Dixon 80b1a3b6df Merge remote-tracking branch 'origin/dev' into feature/proactive-away-summary 2026-08-15 21:08:57 -04:00
Bailey Dixon 257a11ffa2 feat(threads): surface messages received while away 2026-08-15 21:08:50 -04:00
Bailey Dixon 62f3572e11 Merge pull request #363 from Codename-11/fix/android-media-download-state
fix(android): settle media download states
2026-08-15 21:03:40 -04:00
Bailey Dixon 621e526c7d fix(android): settle media download states 2026-08-15 20:52:40 -04:00
Bailey Dixon a5afec36d9 Merge pull request #234 from Codename-11/dependabot/github_actions/dev/actions/setup-python-7
chore(deps): bump actions/setup-python from 6 to 7
2026-08-15 20:11:58 -04:00
Bailey Dixon 29bf9a08ac Merge branch 'dev' into dependabot/github_actions/dev/actions/setup-python-7 2026-08-15 20:10:46 -04:00
Bailey Dixon 342e977594 Merge pull request #233 from Codename-11/dependabot/github_actions/dev/actions/setup-node-7
chore(deps): bump actions/setup-node from 4 to 7
2026-08-15 20:10:39 -04:00
Bailey Dixon 24e767e7ae Merge branch 'dev' into dependabot/github_actions/dev/actions/setup-node-7 2026-08-15 20:09:21 -04:00
Bailey Dixon fdf210ec2b Merge pull request #361 from Codename-11/dev
release(desktop): desktop-v0.4.0-beta.4
2026-08-15 13:49:30 -04:00
Bailey Dixon d05ab31296 release(desktop): desktop-v0.4.0-beta.4 2026-08-15 13:42:14 -04:00
Bailey Dixon 0e0cc16f47 Merge branch 'fix/desktop-daemon-stopped-loading' into dev 2026-08-15 13:32:25 -04:00
Bailey Dixon e90be03f2e fix(desktop): load UI while daemon is stopped 2026-08-15 13:32:11 -04:00
Bailey Dixon f1e4fdcc91 Merge pull request #360 from Codename-11/chore/backmerge-android-1.9.0
chore: back-merge Android 1.9.0 release
2026-08-14 21:52:34 -04:00
Bailey Dixon 5b8b3da350 chore: back-merge Android 1.9.0 release 2026-08-14 21:52:16 -04:00
Bailey Dixon 447ec356d7 Merge pull request #359 from Codename-11/dev
release(android): android-v1.9.0
2026-08-14 21:32:50 -04:00
Bailey Dixon ab359e5efb release(android): android-v1.9.0 2026-08-14 21:01:51 -04:00
Bailey Dixon 86b8161cb7 feat(android): refine sessions and messaging 2026-08-14 20:58:31 -04:00
Bailey Dixon e401fdb0c7 fix(android): persist landed message reactions 2026-08-14 17:04:54 -04:00
Bailey Dixon d4325d5aab fix(android): restore compact chat interactions 2026-08-14 16:57:19 -04:00
Bailey Dixon c734d75484 feat(android): add desktop-style session profiles 2026-08-14 16:57:18 -04:00
Bailey Dixon 0411804780 fix(android): accept compatible session flags 2026-08-14 16:57:18 -04:00
Bailey Dixon 8f89c2841d fix(android): keep dashboard teardown off main thread 2026-08-14 16:57:18 -04:00
Bailey Dixon 933c1842a0 Merge pull request #358 from Codename-11/chore/backmerge-desktop-beta3
chore: back-merge Desktop beta.3 release
2026-08-14 16:31:24 -04:00
Bailey Dixon dfe1b53327 chore: back-merge desktop beta.3 release 2026-08-14 16:30:37 -04:00
Bailey Dixon d36580a983 Merge pull request #356 from Codename-11/dev
release: Desktop beta.3 process-containment patch
2026-08-14 16:11:35 -04:00
Bailey Dixon 2d178ff884 Merge pull request #357 from Codename-11/release/desktop-0.4.0-beta.3
fix(desktop): close process containment race
2026-08-14 16:05:00 -04:00
Bailey Dixon d61955f82a fix(desktop): close process containment race 2026-08-14 15:58:57 -04:00
Bailey Dixon adec6ed2c0 Merge pull request #355 from Codename-11/release/desktop-0.4.0-beta.3
release(desktop): desktop-v0.4.0-beta.3
2026-08-14 15:44:24 -04:00
Bailey Dixon e9e44c8bb2 release(desktop): desktop-v0.4.0-beta.3 2026-08-14 15:36:53 -04:00
Bailey Dixon c6b0732a02 Merge pull request #354 from Codename-11/fix/desktop-tray-process-containment
fix(desktop): contain tray subprocess storms
2026-08-14 15:22:21 -04:00
Bailey Dixon d919115788 fix(desktop): contain tray subprocess storms 2026-08-14 15:15:12 -04:00
Bailey Dixon 49da085ae8 Merge pull request #353 from Codename-11/chore/backmerge-desktop-beta2-server-1.8.0
chore: backmerge Desktop beta.2 and Server 1.8.0 releases
2026-08-14 15:05:21 -04:00
Bailey Dixon 889b6f0858 chore: merge desktop beta.2 and server 1.8.0 release history into dev 2026-08-14 15:05:12 -04:00
Bailey Dixon 5100c524f6 Merge pull request #351 from Codename-11/dev
release: Desktop beta.2 and Server 1.8.0
2026-08-14 15:04:03 -04:00
Bailey Dixon c609ae867f Merge pull request #352 from Codename-11/chore/backmerge-desktop-beta1
chore: back-merge Desktop beta.1 release history
2026-08-14 14:49:23 -04:00
Bailey Dixon 107f8c7720 chore: merge desktop beta.1 release history into dev 2026-08-14 14:49:08 -04:00
Bailey Dixon 8963e4fafd Merge pull request #350 from Codename-11/release/server-1.8.0
release(server): server-v1.8.0
2026-08-14 14:46:57 -04:00
Bailey Dixon 5d9624e2ef release(server): server-v1.8.0 2026-08-14 14:35:01 -04:00
Bailey Dixon 4b063d3fd7 Merge pull request #349 from Codename-11/release/desktop-0.4.0-beta.2
release(desktop): desktop-v0.4.0-beta.2
2026-08-14 12:56:04 -04:00
Bailey Dixon 9b9d7b654c release(desktop): desktop-v0.4.0-beta.2 2026-08-14 12:45:56 -04:00
Bailey Dixon a26e17e72c Merge pull request #348 from Codename-11/fix/cua-windows-health-compat
feat(desktop): enhance activity and control diagnostics
2026-08-14 12:38:12 -04:00
Bailey Dixon a3a6a9bb13 fix(desktop): satisfy tray release lint 2026-08-14 12:36:46 -04:00
Bailey Dixon 169bd09559 merge: sync desktop activity work with dev
# Conflicts:
#	CHANGELOG.md
2026-08-14 11:32:56 -04:00
Bailey Dixon 45d631e7ac feat(desktop): enhance activity and control diagnostics 2026-08-14 11:30:36 -04:00
Bailey Dixon eb6a6c95d2 merge: integrate official desktop relay plugin 2026-08-14 07:58:10 -04:00
Bailey Dixon 3b102663c2 feat(plugin): add official desktop relay surface 2026-08-14 07:56:26 -04:00
Bailey Dixon 0e5fc4c606 Merge branch 'fix/android-proactive-thread-entry' into dev 2026-08-14 07:50:07 -04:00
Bailey Dixon c3189f2cbb fix(android): open proactive messages as threads 2026-08-14 07:49:39 -04:00
Bailey Dixon 0d6c3bd6b0 Merge pull request #346 from Codename-11/dev
release(desktop): desktop-v0.4.0-beta.1
2026-08-13 21:18:41 -04:00
Bailey Dixon 06d88ad40a Merge pull request #345 from Codename-11/release/desktop-0.4.0-beta.1
release(desktop): desktop-v0.4.0-beta.1
2026-08-13 21:11:57 -04:00
Bailey Dixon 8ae5b3fbc2 release(desktop): desktop-v0.4.0-beta.1 2026-08-13 21:04:07 -04:00
Bailey Dixon 39b7a8f108 Merge pull request #344 from Codename-11/fix/desktop-updater-cua-hardening
feat(desktop): adopt CUA as primary control backend
2026-08-13 20:57:50 -04:00
Bailey Dixon af6e167692 fix(desktop): normalize Windows installer paths 2026-08-13 20:51:17 -04:00
Bailey Dixon 274bd6ae98 fix(desktop): honor CUA health schema 2026-08-13 20:45:58 -04:00
Bailey Dixon 9fc55b379a fix(desktop): clarify CUA readiness fallback 2026-08-13 20:34:45 -04:00
Bailey Dixon 559a0ffdc8 feat(desktop): make CUA the primary control backend 2026-08-13 20:16:03 -04:00
Bailey Dixon 75bcd9180f feat(desktop): add optional CUA control engine 2026-08-13 19:33:11 -04:00
Bailey Dixon 9c995a443d fix(desktop): harden bundle updates 2026-08-13 19:06:25 -04:00
Bailey Dixon 7440ef2948 Merge pull request #343 from Codename-11/dev
release: server 1.7.0 and desktop 0.4.0-alpha.8
2026-08-13 17:14:58 -04:00
Bailey Dixon a88539bc59 fix(android): dequeue reach frames compatibly 2026-08-13 16:56:54 -04:00
Bailey Dixon b2ccfdc500 fix(security): carry secure link trust anchor 2026-08-13 16:49:44 -04:00
Bailey Dixon 481c62ac59 fix(desktop): bind pinned secure link probes 2026-08-13 16:42:37 -04:00
Bailey Dixon 5d415fbaf0 fix(android): use compatible reach buffer removal 2026-08-13 16:39:26 -04:00
Bailey Dixon 074b715055 fix(android): complete secure route translations 2026-08-13 16:37:32 -04:00
Bailey Dixon f63ee8721e release(desktop): desktop-v0.4.0-alpha.8 2026-08-13 16:21:51 -04:00
Bailey Dixon 777bc80bcc release(server): server-v1.7.0 2026-08-13 16:21:50 -04:00
Bailey Dixon 9539975bb5 merge: integrate native secure routes 2026-08-13 15:41:46 -04:00
Bailey Dixon 2863a1bc8f merge: reconcile native secure routes with dev 2026-08-13 15:31:53 -04:00
Bailey Dixon b0a7cf0494 feat: add self-hosted secure connection routes 2026-08-13 15:31:46 -04:00
Bailey Dixon 76b4084310 merge: integrate Android and Relay upstream work 2026-08-13 13:24:32 -04:00
Bailey Dixon 2ace70c4fc test: close integration verification gaps 2026-08-13 13:24:02 -04:00
Bailey Dixon 4f52f371ba fix(ops): fail closed on unsafe certification state 2026-08-13 11:16:27 -04:00
Bailey Dixon 064c89bda4 docs: record Android and Relay integration 2026-08-13 11:08:27 -04:00
Bailey Dixon 0cb1e3642f feat(android): add gateway-native profile editor 2026-08-13 11:03:10 -04:00
Bailey Dixon cf4bf87242 fix(android): honor upstream routing contracts 2026-08-13 11:00:39 -04:00
Bailey Dixon 9cbed21014 fix(android): preserve durable gateway rewinds 2026-08-13 10:58:55 -04:00
Bailey Dixon ce75c0fa01 docs: add controlled runtime safety preflight 2026-08-13 10:50:52 -04:00
Bailey Dixon bf2aece6e6 docs: reconcile upstream architecture evaluations 2026-08-13 10:50:14 -04:00
Bailey Dixon 198da78fc8 fix(android): honor upstream approval and compression outcomes 2026-08-13 10:50:14 -04:00
Bailey Dixon 986ce3b12b fix(plugin): isolate profile-owned registrations 2026-08-13 10:50:14 -04:00
Bailey Dixon b53f757830 fix(plugin): support strict phone targets 2026-08-13 10:50:14 -04:00
Bailey Dixon cdeccd69e4 feat: add secure relay route selection 2026-08-12 20:10:41 -04:00
Bailey Dixon bb72516bb5 Merge pull request #340 from Codename-11/chore/backmerge-server-1.6.4
chore: back-merge server-v1.6.4 hotfix
2026-08-12 18:43:50 -04:00
Bailey Dixon 3a51644342 chore: merge server-v1.6.4 release history into dev
# Conflicts:
#	docs/decisions.md
#	user-docs/desktop/tools.md
2026-08-12 18:43:39 -04:00
Bailey Dixon 51c0c7dee9 Merge pull request #338 from Codename-11/fix/server-multidevice-hotfix
fix(server): release targeted multi-desktop routing
2026-08-12 18:39:31 -04:00
Bailey Dixon 7ef2420c85 release(server): server-v1.6.4 2026-08-12 18:38:32 -04:00
Bailey Dixon 6a810c850b fix(server): route concurrent desktop clients explicitly 2026-08-12 18:38:02 -04:00
Bailey Dixon d383002583 Merge pull request #336 from Codename-11/release/server-1.6.4
release(server): server-v1.6.4
2026-08-12 18:35:31 -04:00
Bailey Dixon e3aae829e1 release(server): server-v1.6.4 2026-08-12 18:35:16 -04:00
Bailey Dixon 5207ed4193 Merge pull request #335 from Codename-11/fix/desktop-placement-device-identity
feat(desktop): support targeted multi-device control
2026-08-12 18:32:06 -04:00
Bailey Dixon b46bb00ea8 test(desktop): serialize cross-platform suite 2026-08-12 18:31:50 -04:00
Bailey Dixon b8dde409c5 merge: synchronize desktop management with dev
# Conflicts:
#	CHANGELOG.md
#	docs/decisions.md
2026-08-12 18:26:20 -04:00
Bailey Dixon ca7ded3939 test(server): prove concurrent desktop routing 2026-08-12 18:24:44 -04:00
Bailey Dixon db85a26c68 feat(desktop): add contextual approvals and UI pairing 2026-08-12 18:24:43 -04:00
Bailey Dixon aa2595629d feat(desktop): expand tray management controls 2026-08-12 17:55:56 -04:00
Bailey Dixon d79146dc90 feat(desktop): add ask every time access preset 2026-08-12 17:13:51 -04:00
Bailey Dixon eabc4dd328 refactor(desktop): clarify access navigation 2026-08-12 16:57:50 -04:00
Bailey Dixon e165bfeff3 feat(desktop): animate bidirectional relay traffic 2026-08-12 15:42:43 -04:00
Bailey Dixon 40bcd796d1 refactor(desktop): simplify host access presets 2026-08-12 13:29:29 -04:00
Bailey Dixon 57ae0c9456 feat(desktop): unify capabilities and activity drilldown 2026-08-12 13:06:34 -04:00
Bailey Dixon 9b31a16c89 fix(desktop): preserve Hermes shortcut icons 2026-08-12 11:44:17 -04:00
Bailey Dixon f97bbdd395 feat(desktop): add host-wide raw USB control 2026-08-12 11:38:09 -04:00
Bailey Dixon 722a294947 feat(desktop): adopt compact capability ledger 2026-08-12 11:13:50 -04:00
Bailey Dixon bbfb57b462 feat(desktop): harden targeted remote management 2026-08-12 10:37:12 -04:00
Bailey Dixon 6db12a0bec merge: complete upstream app and Relay workflows 2026-08-12 09:24:24 -04:00
Bailey Dixon f1de957848 fix(android): translate Manage workflows 2026-08-12 09:08:31 -04:00
Bailey Dixon cc01d9c8ad test(android): compile upstream workflow fixtures 2026-08-12 09:00:04 -04:00
Bailey Dixon d574182d84 fix(android): wire Manage workflow dialogs 2026-08-12 08:46:10 -04:00
Bailey Dixon a328763da3 fix(android): localize backup completion 2026-08-12 08:46:05 -04:00
Bailey Dixon f53db68e7d feat(android): complete upstream Manage workflows 2026-08-12 07:45:55 -04:00
Bailey Dixon eb9e570fc0 feat(android): show session repository and PR state 2026-08-12 07:41:35 -04:00
Bailey Dixon 260f119637 fix(voice): align upstream auth and transport 2026-08-12 07:39:42 -04:00
Bailey Dixon d0fa2ea39d fix(android): preserve clarify selection semantics 2026-08-12 07:37:28 -04:00
Bailey Dixon a1c74b1567 fix(plugin): enumerate phone home target 2026-08-12 07:34:19 -04:00
Bailey Dixon 7c45acd38d chore: merge server-v1.6.3 release history into dev 2026-08-11 22:03:36 -04:00
dependabot[bot] de9211b7c5 chore(deps): bump actions/setup-node from 4 to 7
Bumps [actions/setup-node](https://github.com/actions/setup-node) from 4 to 7.
- [Release notes](https://github.com/actions/setup-node/releases)
- [Commits](https://github.com/actions/setup-node/compare/v4...v7)

---
updated-dependencies:
- dependency-name: actions/setup-node
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-25 18:37:14 +00:00
dependabot[bot] 7ca5c61be5 chore(deps): bump actions/setup-python from 6 to 7
Bumps [actions/setup-python](https://github.com/actions/setup-python) from 6 to 7.
- [Release notes](https://github.com/actions/setup-python/releases)
- [Commits](https://github.com/actions/setup-python/compare/v6...v7)

---
updated-dependencies:
- dependency-name: actions/setup-python
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-07-20 11:55:24 +00:00
378 changed files with 41539 additions and 3524 deletions
+1 -1
View File
@@ -67,7 +67,7 @@ jobs:
fetch-depth: 1
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+1 -1
View File
@@ -39,7 +39,7 @@ jobs:
run: npm run build
- name: Setup Python
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+2 -2
View File
@@ -44,7 +44,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
@@ -84,7 +84,7 @@ jobs:
uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+1 -1
View File
@@ -30,7 +30,7 @@ jobs:
working-directory: website
steps:
- uses: actions/checkout@v4
- uses: actions/setup-node@v4
- uses: actions/setup-node@v7
with:
node-version: 22
cache: npm
+1 -1
View File
@@ -44,7 +44,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.12"
+37 -2
View File
@@ -80,7 +80,7 @@ jobs:
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.x'
bun-version-file: 'desktop/.bun-version'
- name: Install deps
run: npm ci
@@ -153,6 +153,40 @@ jobs:
desktop/dist/bin/hermes-relay-darwin-arm64
retention-days: 7
smoke-windows-cli-release-asset:
name: Smoke exact Windows CLI release asset
runs-on: windows-latest
needs:
- validate-release
- build-cli-binaries
steps:
- uses: actions/download-artifact@v8
with:
name: cli-binaries
path: release-assets
- name: Repeated launch and process cleanup gate
shell: pwsh
env:
EXPECTED_DESKTOP_VERSION: ${{ needs.validate-release.outputs.version }}
run: |
$ErrorActionPreference = 'Stop'
$exe = (Resolve-Path 'release-assets/hermes-relay-win-x64.exe').Path
1..20 | ForEach-Object {
$output = & $exe --version
if ($LASTEXITCODE -ne 0) { throw "Windows CLI smoke failed with exit $LASTEXITCODE" }
if ($output -ne "hermes-relay $env:EXPECTED_DESKTOP_VERSION") {
throw "Unexpected Windows CLI version output: $output"
}
}
Start-Sleep -Milliseconds 500
$leftovers = Get-CimInstance Win32_Process | Where-Object {
$_.ExecutablePath -eq $exe
}
if ($leftovers) {
throw "Windows CLI smoke left $(@($leftovers).Count) process(es) behind"
}
build-windows-tray-installer:
name: Build Windows tray installer
runs-on: windows-latest
@@ -175,7 +209,7 @@ jobs:
- name: Setup Bun
uses: oven-sh/setup-bun@v2
with:
bun-version: '1.3.x'
bun-version-file: 'desktop/.bun-version'
- name: Setup Rust
uses: dtolnay/rust-toolchain@stable
@@ -375,6 +409,7 @@ jobs:
runs-on: ubuntu-latest
needs:
- build-cli-binaries
- smoke-windows-cli-release-asset
- build-windows-tray-installer
steps:
# Needed so CLI_RELEASE_NOTES.md is available to render into the release body
+2 -2
View File
@@ -53,7 +53,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
@@ -88,7 +88,7 @@ jobs:
- uses: actions/checkout@v7
- name: Set up Python 3.11
uses: actions/setup-python@v6
uses: actions/setup-python@v7
with:
python-version: "3.11"
+171 -1
View File
@@ -6,10 +6,180 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
## [Unreleased]
## [1.11.0] - 2026-08-20
### Added
- **Sideload Bridge access is explicitly capability-scoped.** Read-only, read-and-confirm, and custom presets grant only selected powers for the active connection. Screen inspection and control can be allowed for a bounded period or explicitly left unlimited, and Relay status reports the resulting permanent, timed, and unlimited grants.
### Changed
- **The sideload Bridge screen is a summary-first access cockpit.** Agent access, unattended mode, selected Android requirements, and advanced safety controls are separated clearly while the complete permission matrix and power-user controls remain available one tap deeper.
### Fixed
- **Android keeps failed session resumes visible and in context.** Continuing a stored Gateway session no longer falls through to a fresh session when Hermes rejects or mis-scopes the resume. Failed turns remain error-marked and expose a composer-adjacent recovery panel with route-aware details, explicit retry/dismiss actions, and sanitized Diagnostics evidence.
- **Software-keyboard Return inserts a newline across both common Android IME paths.** Keyboards that commit text directly and keyboards that synthesize `KEYCODE_ENTER` now keep multiline composition separate from physical-keyboard Send behavior. (#367)
- **Cancelled answer recovery retains its Stopped status.** Empty recovery placeholders with a persistent status badge are no longer discarded during stream finalization.
- **Android screen-on idle no longer continuously redraws the ASCII sphere.** Idle holds a stable frame while thinking, streaming, and voice states retain full-rate motion; inactive voice waveforms and closed session drawers also stop their frame loops.
- **Android capture and audio effects release power-sensitive resources at their actual lifecycle boundaries.** Screen capture attaches its MediaProjection surface only for a requested frame, unattended Bridge wake locks release when the command finishes, and barge-in AEC/noise suppression attach to the microphone capture session instead of playback.
- **Experimental wake-word listening reuses its PCM normalization buffer.** Continuous opt-in listening no longer allocates a new float frame for every inference call.
## [1.10.0] - 2026-08-18
### Added
- **Android preserves composer drafts across app restarts.** Text, quote/edit context, and pending attachments remain scoped to their exact connection, profile, and session in bounded app-private no-backup storage, and successful sends remove the saved draft.
- **Android can turn large pastes into reviewable text attachments.** The default-on Chat setting converts inserts of at least 5,000 characters into a compact attachment while preserving surrounding text; Gateway uploads the file through upstream Hermes and fallback transports retain the pasted content as text.
- **Android renders Markdown incrementally while replies stream.** The native streaming parser retains stable message, selection, and AST identities from the first token through completion, including provisional paragraphs, lists, links, fenced code, and tables.
### Fixed
- **The Android software keyboard exposes Return in the multiline composer.** The dedicated composer button sends, while physical Enter, Shift+Enter, and caret-arrow behavior remain unchanged. (#367)
- **Open chats reattach after Android returns to the foreground.** Gateway reconnect restores the visible session subscription and reconciles missed work without requiring the user to leave and reopen the conversation. (#365)
- **Imported credentials fail closed before network or secure-state mutation.** Control characters and malformed values are rejected before header construction or encrypted-state replacement without logging credential material.
- **Streaming follow remains stable through completion.** Deliberate scrollback stays untouched, bottom-follow uses one bounded owner, and Markdown, voice actions, timestamps, and token metadata settle without rebuilding the bubble or resetting its scroll anchor. (#341)
## [1.9.1] - 2026-08-16
### Added
- **Android adopts Hermes-owned profile creation, shared avatars, and animated pets.** Current Gateways provide the profile roster, explicit shared/copied/isolated authentication choices, partial create outcomes, validated avatar upload/fetch/clear, and profile-scoped pet selection that follows the agent across supported Hermes clients. Older hosts retain authenticated Dashboard creation plus Relay/local presentation fallbacks, and profile deletion remains Dashboard-only.
- **Android identifies proactive messages delivered after reconnect.** Relay marks messages flushed from its bounded offline queue, Thread bubbles label them as received “While away,” and Android shows one accessible localized summary for the completed batch.
- **Android can create finite recurring schedules from Manage.** The native editor uses the authenticated Hermes Gateway `cron.manage` contract, optionally stops after 1–999 runs, and rejects invalid counts rather than silently creating unlimited work.
- **Chat resets retain content-free local evidence.** New-chat and Thread transitions save a bounded app-private checkpoint for user-reviewed Diagnostics without prompts, message text, IDs, profile names, paths, URLs, media, tool payloads, secrets, or telemetry.
- **Android surfaces host resource risk before chat state is lost.** Current Hermes Dashboard memory and disk pressure signals render as a persistent, capability-gated warning; older hosts remain unchanged and no telemetry is added.
- **Android honors Hermes model-selection safeguards.** Every Gateway model transition, including fresh-chat and Server-default choices, now avoids raw session overrides; picks requiring cost or data-training consent show Hermes' exact warning and apply only after a confirmed second request.
### Changed
- **Profile identity sources are explicit in Agent Passport.** Server-owned static avatars and upstream pets follow the Hermes profile, while phone picks, Relay-host imports, phone-only animated icons, and Sphere skins remain separate local presentation choices.
- **Interactive Gateway asks remain resolver-bound.** Android continues to use upstream clarify, approval, sudo, and secret response RPCs; connector-only prompt/reaction operations are not copied into Relay cards as a second approval protocol.
### Fixed
- **Shared avatar picks now persist from Android's filesystem picker.** The app accepts any image Android can decode, applies display orientation, and safely resizes or re-encodes it to the upstream PNG/JPEG/WebP and 2,000,000-byte contract. Successful writes update the local shared cache immediately, and upload failures remain visible beside the control.
- **Nous-hosted Android sign-in follows the official native broker contract.** The gateway now selects its native provider exactly as Hermes Desktop does, callback attempts retain the upstream five-minute window, and post-callback failures explain whether the one-time code, hosted gateway, network, response, or secure storage prevented session creation without exposing auth material.
- **Android edit-and-regenerate fails closed on incomplete durable history.** Mixed Gateway transcripts now require the selected message's durable row identity instead of attempting an ordinal-only rewind, while older Hermes histories with no row identities remain editable.
- **Android fails closed when a Gateway does not confirm the selected profile.** Named-profile session creation and recovery now require Hermes to echo the exact owning profile, preventing stale or older gateways from silently running the launch profile under another agent's identity. Profile inspection also keeps read-only Gateway data available when `profiles.configure` is unsupported while disabling further write attempts without discarding drafts.
- **Android attachment sends are bounded and fail closed.** Picked files are size-limited while streaming into the encoder, cold and queued Gateway sends upload only after the exact session is ready, and an unsupported or interrupted document upload no longer falls through to a text-only route while its file card implies delivery. Every attachment type retains the same compact collapse/expand affordance.
## [0.4.0-beta.4] - 2026-08-15
### Fixed
- **The Windows management UI remains available while the daemon is stopped.** Missing, stale, malformed, or temporarily unavailable daemon status now resolves to an explicit stopped state instead of trapping the tray on its loading screen, so configuration, diagnostics, host management, and daemon controls remain accessible.
## [1.9.0] - 2026-08-14
### Added
- **Android session browsing matches Hermes Desktop's recent organization model.** The primary session drawer can toggle between the active profile and all profiles, group by recency, project, status, or profile, order by supported session metrics, and narrow rows by status, project, profile, or pull-request state without collapsing duplicate IDs across profile stores. Named profiles receive stable identity-color badges with locally persisted color overrides.
- **Android can edit current Hermes profiles through the standard Gateway.** The Profile Inspector capability-gates `profiles.describe` and `profiles.configure`, keeps Relay-only memory editing and older-Hermes fallback intact, and reports partial section saves without discarding failed drafts.
- **Android sessions show their coding context when Hermes supplies it.** Session rows can display repository, Git branch, and the current state of the pull request created by that session while older hosts remain unchanged.
- Android Manage can now finish host-owned backup workflows, edit or remove learning nodes with explicit recovery guidance, configure and activate memory providers, and complete profile-scoped WhatsApp QR onboarding through the authenticated upstream Dashboard contracts.
### Fixed
- **Android network clients shut down safely during route changes.** Replacing an authenticated Dashboard client now moves OkHttp connection-pool eviction off the main thread, preventing a live TLS socket close from crashing the app with `NetworkOnMainThreadException`. (#334)
- **Android preserves authoritative Gateway outcomes.** Protected-file cards cannot offer forbidden persistent scopes, compression no-ops show the server result, bounded resume failures do not create context-free replacement sessions, and edit/regenerate retains durable row identities across consecutive rewinds.
- **Android routes and uploads against live upstream truth.** Multiplex API fallback trusts `served_profiles` instead of installed profiles, and generic documents carry the Gateway-issued `@file:` reference into ordinary and queued prompts.
- **Android clarify cards preserve upstream decision semantics.** Multi-select prompts keep independent selections and submit one exact list, while server expiry events—not an invented local deadline—retire unanswered cards.
- **Android keeps profile management and retained automation truthful.** Custom Endpoint list and mutation routes now follow the selected Hermes profile, while completed one-shot cron jobs show their retained outcome and expose only valid Runs/Delete actions.
- **Android and Relay recover more generated media reliably.** Android accepts upstream-valid wrapped, punctuated, adjacent, spaced, and Windows `MEDIA:` markers without consuming fenced examples, and Relay translates Docker-visible workspace, home, cache, and configured-mount paths before applying its existing credential, sandbox, and size checks.
- **Android keeps cross-profile sessions with their owning agent.** Opening a session from All Profiles hydrates, resumes, sends, and renders with that session's profile without changing the global profile selection; New Chat from that view starts with the default profile.
- **Android reactions and standard voice follow the active conversation.** Reactions resolve durable rows for both user and assistant messages, while Vanilla Hermes voice remains on the authenticated Gateway instead of requiring the optional API fallback.
- **Android session navigation behaves predictably.** The drawer closes on outside taps, uses an ungrouped recent-session list by default, retains project grouping as an explicit option, and exposes secondary actions in All Profiles mode.
## [0.4.0-beta.3] - 2026-08-14
### Fixed
- **Windows tray polling can no longer accumulate unbounded helper processes.** Grant discovery now uses lightweight local state, management refreshes are single-flight and visibility-aware, and child probes have hard timeouts, bounded output, tree cleanup, caching, and backoff. A dedicated bounded `tray.log` records sanitized operational failures without mixing them into daemon logs.
- **Concurrent Desktop lifecycle requests cannot start duplicate daemons.** Cross-process lifecycle and runtime ownership locks serialize startup and recovery while preserving stale-owner cleanup.
## [1.8.0] - 2026-08-14
### Added
- **Official Hermes Desktop can surface Relay through its supported runtime Plugin SDK.** The unified plugin package now includes an opt-in, profile-scoped Desktop pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management. Loading, startup, reconnects, profile changes, and updates never open it; only labeled sidebar, status-bar, or command-palette actions register and reveal the movable native pane.
## [0.4.0-beta.2] - 2026-08-14
### Added
- **Desktop Activity now keeps inspectable local evidence.** Commands, files, devices, connection lifecycle, and computer control share a truthful event stepper with dedicated failure details; screenshot events can retain bounded local PNG evidence and open it in a larger borderless viewer. Settings controls retention as Off, 1 day, 7 days, or 30 days and shows local file usage.
### Fixed
- **Tunnel state stays responsive through interruption and retry.** The CLI UI distinguishes connected, reconnecting, and stopped states, exposes retry attempt/timing and a Retry now action, records connection failures and recovery in Activity, and shows compact connection cards only while the main UI is hidden.
- **Windows CUA readiness no longer depends on the flaky whole-desktop health scan.** Hermes-Relay verifies the canonical runtime, manifest, required tools, daemon, and safe permission mode before starting structured sessions, while accessibility health remains an explicit CLI/UI diagnostic that can be rechecked without forcing the compatibility backend. This temporary workaround is scoped to the upstream fixed-timeout issue and keeps individual actions fail-closed.
## [0.4.0-beta.1] - 2026-08-14
### Added
- **CUA Driver is the preferred Windows structured-control engine.** New local settings prefer a verified CUA runtime for window-targeted background actions, fresh snapshot tokens, and optional per-session animated agent cursors without moving the physical pointer; Windows Input is the explicit compatibility backend and backend choice is fixed for each control session. Full-display observation remains on the read-only system capture path. CLI and UI can explicitly install, check, or update the canonical CUA package after verifying the upstream release manifest and installer checksum; nothing is bundled or updated automatically, driver telemetry stays off for Hermes sessions, and activity records contain only bounded, redacted control metadata.
### Fixed
- **Windows bundle updates fail closed when installed processes retain a binary lock.** Setup waits for the invoking CLI, quiesces the tray and its short-lived CLI children, checks every payload extraction before writing release metadata, preserves custom install directories, and returns a failure instead of reporting a mixed-version installation.
- **CUA readiness follows the published driver contract.** Hermes accepts the documented `ok` health state, distinguishes an installed-but-degraded runtime from a missing installation, and constructs trusted Windows installer paths consistently across verification environments.
## [1.7.0] - 2026-08-13
### Added
- **Hermes Secure Link provides self-hosted pinned TLS ingress.** Relay, API, and Dashboard namespaces share one operator-owned TLS endpoint while retaining their native authentication boundaries, QR-carried certificate continuity, explicit rotation, and fail-closed route validation.
- **Hermes Reach is available for explicit experimentation.** The optional self-hosted rendezvous broker carries opaque Secure Link TLS records over outbound-only connections with bounded multiplexing, hashed credentials, replay protection, persistence, revocation, and no access to Hermes payloads.
- **Remote-access management exposes supported reachability clearly.** Dashboard status and pairing metadata distinguish Tailscale reachability, Secure Link transport protection, direct routes, and experimental Reach without presenting the broker as a replacement for authentication.
### Changed
- **Tailscale is the recommended remote route.** Pairing, Dashboard, documentation, and public site guidance present Tailscale as the easiest supported remote-access path; Reach remains disabled by default, advanced, and lower priority than supported routes.
- **Relay voice custom transports follow upstream provider security options.** Relay-owned OpenAI/xAI realtime and TTS clients honor custom headers, custom CA bundles, standard CA environment precedence, and an explicitly warned development-only verification override.
- **Voice Lab xAI sign-in uses device authorization.** The standalone login shows a verification URL and user code and polls for approval without requiring a loopback callback.
### Fixed
- **Phone delivery remains compatible with strict Hermes targets.** Version-tolerant parser and validator hooks retain older-host registration and exactly-once standalone delivery.
- **Profile-owned Relay registrations stay isolated.** Current Hermes uses profile-scoped ownership and context-local profile homes while legacy hosts retain a guarded compatibility path.
- **Phone is discoverable before its first historical session.** The Relay phone adapter publishes its configured home destination through Hermes' standard channel directory.
## [0.4.0-alpha.8] - 2026-08-13
### Added
- **Windows management separates each Relay host from this PC.** Host detail owns identity, pairing, access, capabilities, authorized clients, re-pairing, and guarded removal; Settings owns local daemon lifecycle, startup, privilege, terminal, logs, diagnostics, updates, and Help & About.
- **Desktop access uses clear host-scoped presets and capabilities.** Restricted, Ask Every Time, Standard, Full Access, and Custom remain explicit across commands, files, screen/input, USB, microphone, and camera controls.
- **Activity drilldown preserves bounded execution evidence.** Overview shows the latest three events and detail views expose request, output, result, exit, duration, and truncation metadata without copying sensitive inputs.
- **Connection presentation shows the live Agent-to-PC path.** Host selection, bidirectional packet motion, transition feedback, route details, and connection testing stay compact, responsive, and reduced-motion aware.
### Changed
- **Connect and disconnect remain responsive during daemon work.** Lifecycle calls and snapshot collection run outside the UI thread, transition status polls quickly without overlapping probes, and progress remains visible until authoritative daemon state arrives.
- **Tailscale is recommended for remote access.** Secure Link and direct TLS routes remain supported, while Hermes Reach is visibly experimental and lower priority.
### Fixed
- **Connection tests classify legacy private routes correctly.** A saved generic role is inferred from its actual endpoint, so LAN and Tailscale routes no longer appear as Custom VPN; results include reachability, latency, security, endpoint, and route count.
- **Ask-mode approval cards show the requested action.** A bounded preview appears in the compact card with full context and an Open in UI action.
- **Mixed capability policies are labeled Custom.** Overview no longer claims a preset when individual capability controls differ.
- **Tray placement follows the notification-area monitor and DPI.** Responsive popup geometry stays anchored above the tray icon across compact and high-DPI desktops.
- **PowerShell success output is complete and self-describing.** Scalar, pipeline, JSON, native stdout/stderr, exit status, and truncation metadata survive the desktop RPC response.
## [1.6.4] - 2026-08-12
### Added
- **Desktop tools support explicit host targeting.** Every client-routed desktop tool accepts a stable device ID or unambiguous computer name, and `/desktop/health` enumerates connected targets and their advertised tools.
- **USB operations retain both routing scopes.** Raw USB and ADB tools use `device` to select the desktop PC, while ADB operations continue to use `serial` to select hardware attached to that PC.
### Fixed
- **Multiple desktop clients remain connected simultaneously.** The Relay no longer replaces the previous desktop when another heartbeat arrives; concurrent requests are bound to their selected WebSockets, responses from another PC are ignored, and an untargeted call fails closed when several desktops are online.
- **Pairing another desktop preserves existing credentials.** Legacy placeholder device identifiers are treated as absent instead of shared ownership, preventing an unrelated PC from revoking the first desktop's session.
## [1.6.3] - 2026-08-11
@@ -581,7 +751,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/), and this
- **Spoken-turn badges (chat).** Voice-mode replies now carry a "Voice" chip and realtime replies a "Realtime Agent" chip — both with a speaker glyph — so spoken turns are distinguishable from typed ones in the scrollback.
- **App themes.** A new theme picker in Settings → Appearance ships eight looks: the signature Hermes Relay brand (with full light/dark) plus ports of the Nous Hermes baselines — Hermes Teal, Nous Blue (light), Midnight, Ember, Mono, Cyberpunk, and Rosé. The whole app — brand chrome, accents, and chat background — follows the chosen theme. Light/Dark/Auto applies to themes that ship both modes; fixed-mode themes show their own complete look.
- **Hot-swappable agent sphere.** The orb is now a pluggable "skin": an Adaptive skin that recolors to match your theme, built-in Classic / Aurora / Solar / Mono looks, and support for **user-authored skins** loaded from a small JSON spec. Each skin declares which live signals it reacts to (voice, tool bursts, activity), shown as capability badges in the picker. See `docs/sphere-spec.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. A plugin-provided **Secure proxy** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Connections separate features from routes (Android).** Connection settings now distinguish what a connection can *do* (a **Features** section) from how this phone *reaches* Hermes (a **Route** section), so you can enable Relay features over whichever transport you prefer. The optional plugin-provided **Hermes Secure Link** route is surfaced alongside LAN, Tailscale, public, and custom routes. The standard direct-to-upstream path is unchanged and still needs no plugin. See `docs/plans/2026-06-18-native-secure-routes.md`.
- **Enhanced voice control (Gemini & xAI).** When the relay uses a Gemini or xAI voice provider, Voice Settings can now steer it: pick a Gemini voice and model and turn on expressive tone tags (with optional natural-language voice direction), or set an xAI voice with expressive speech tags. Expressive tags also apply to xAI on the streaming voice-output renderer. Standard (no-plugin) voice stays configured server-side.
- **Voice render-path visibility.** Voice Settings shows which path is rendering speech (streaming vs. basic), and Diagnostics records it each session, making voice issues easier to troubleshoot.
- **Agent pets — a living, swappable avatar.** The orb can be replaced with an animated "pet" that reacts to what the agent is doing: idle / thinking / writing / speaking / listening states, a distinct **working** pose during tool calls, one-shot **greet** / **celebrate** reactions, and a loop that quickens as output streams. Add or remove pets right in Settings → Appearance (no `adb` needed), with a live state preview, a playback-speed slider, and optional frame auto-stabilization; capability badges (Voice · Tools · Activity) show honestly what each pet actually reacts to. Pets are pure data — an AI authoring kit and a JSON schema let you generate one from sprite art. See `docs/pet-spec.md` and the custom-avatars guide.
+4 -3
View File
@@ -235,9 +235,10 @@ This is a **public, distributed repo** — every committed file (CHANGELOG, DEVL
| **App — Bridge** | |
| `network/handlers/BridgeCommandHandler.kt` | Routes `bridge.command` → ActionExecutor; full path inventory + safety-rail integration |
| `viewmodel/BridgeViewModel.kt` | BridgeScreen VM — masterToggle, bridgeStatus, permissionStatus, activityLog |
| `bridge/BridgeSafetyManager.kt` | Blocklist + destructive-verb confirmation + auto-disable timer; fails-closed on /call and /send_sms |
| `data/BridgeSafetyPreferences.kt` | DataStore for blocklist, destructive verbs, auto-disable minutes, confirmation timeout |
| `ui/screens/BridgeScreen.kt` | Bridge UI — master → permission checklist → [Advanced] → unattended → safety → activity log (v0.4.1 reorder) |
| `bridge/BridgeSafetyManager.kt` | Connection-scoped capabilities + timed screen expiry + blocklist + destructive confirmation; unknown, denied, and expired commands fail closed |
| `bridge/BridgeCapabilities.kt` / `data/BridgeCapabilityPolicyRepository.kt` | Closed method/path registry + no-backup-bound per-Connection Always/Never/Timed policy; global safety vocabulary and timer duration remain in `BridgeSafetyPreferences.kt` |
| `ui/screens/BridgeScreen.kt` | Bridge cockpit — master → Agent access posture/setup → single Unattended Access control → capability-scoped Android readiness (expandable full matrix) → Advanced safety/full editor → activity log |
| `ui/components/BridgeAccessCards.kt` | Native access cockpit + first-use preset and screen-lease sheets (renewable idle limits or warned Until-off dedicated-device mode); preserves full permission/safety drilldowns while keeping selected policy/readiness above the fold |
| `ui/components/UnattendedAccessRow.kt` | Unattended toggle card (sideload); `enabled=masterEnabled`; inline `KeyguardDetectedAlert` |
| `ui/components/UnattendedGlobalBanner.kt` | 28dp amber strip at scaffold top when master+unattended on (sideload); tap → Bridge tab |
| `bridge/BridgeStatusOverlay.kt` | WindowManager overlay; `ConfirmationOverlayHost`; requires `SavedStateRegistryOwner` init order (CREATED→restore→RESUMED) |
+5 -22
View File
@@ -1,34 +1,17 @@
# Hermes-Relay CLI v__VERSION__
**Release Date:** 2026-08-11
**Release Date:** 2026-08-15
This alpha replaces the right-click-only Windows tray with the compact **Hermes-Relay CLI UI** popup while keeping Hermes-Relay's desktop boundary narrow. Chat, the remote TUI, plugins, voice, and agent sessions remain CLI or upstream desktop concerns.
This patch keeps the Windows management UI usable when the Relay daemon is stopped or its status cannot be read.
**Experimental phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the management tray is Windows-only.
**Beta phase.** Assets remain unsigned, so Windows SmartScreen and macOS Gatekeeper may warn on first launch. Standalone CLI binaries ship for Windows x64, Linux x64, and macOS x64/arm64; the management UI is Windows-only.
## What's changed
### Added
- **Compact Windows management tray.** The popup provides connection status, host selection, per-host access, pending approval dialogs, recent activity, daemon controls, startup settings, and authorized-client revocation.
- **Host-aware desktop access.** `hermes-relay hosts` lists and selects paired Hermes instances and stores independent Ask, Trusted, or Full Access policy for each canonical relay URL.
- **In-window grant decisions.** New computer-use requests bring the tray forward and show the requesting host, scope, reason, and duration with explicit Approve and Reject actions.
- **Supported UI lifecycle from the CLI.** `hermes-relay ui install|open|status` lets a CLI-only Windows installation add, reveal, or inspect the optional management UI without rerunning setup by hand.
### Changed
- **Daemon startup is connectivity-first.** Ask mode can keep an authenticated daemon connected with zero desktop tools attached, so starting the daemon does not itself grant authority.
- **Full Access is explicit and host-scoped.** Trusted hosts may use command and file tools while screen/input remains task-granted. Full Access also removes task prompts for screen, input, and file patches for that host, while authentication, audit, revocation, emergency stop, and UAC boundaries remain enforced.
- **Host changes apply immediately.** Selecting a different host or changing its access mode restarts an already-running daemon and the UI verifies that the daemon URL matches the selected host before showing it as connected.
- **PowerShell remains first-class.** Agents should prefer the dedicated `desktop_powershell` RPC for native Windows work; `desktop_terminal` remains cmd-compatible for existing callers.
- **CLI and UI updates share one verified installer.** Bundle updates coordinate shutdown and restart, allow same-version UI repair, and refuse accidental downgrade unless explicitly forced.
### Fixed
- **Detached daemon start reports real readiness.** `daemon start` waits for the spawned PID to authenticate and connect, and reports configuration, authentication, early-exit, and timeout diagnostics instead of returning a false success.
- **Normal tray operation no longer requires opening a CLI for grants.** Pending requests are resolved directly in the focused management dialog.
- **Release checks match the management tray.** CI builds the React assets, validates Tauri metadata, and smoke-tests the packaged tray without obsolete menu-only size or window assertions.
- **Installed tray builds no longer depend on a localhost development server.** Local and packaged builds embed their UI assets, eliminating the `127.0.0.1 refused to connect` failure.
- **Stopped daemons no longer block the management UI.** Missing, stale, malformed, or temporarily unavailable daemon status falls back to an explicit stopped state while hosts, settings, activity, CLI details, diagnostics, and daemon controls continue loading normally.
- **Starting the daemon restores live status without reopening the UI.** A valid running status continues through the same bounded, single-flight snapshot path introduced in beta.3.
## Install
+65
View File
@@ -1,5 +1,70 @@
# Hermes-Relay — Dev Log
## 2026-08-20 — Android stored-session resume failures stay visible
Android now treats a failed Gateway `session.resume` as authoritative for the
selected stored conversation. The client no longer creates a replacement
session and submits the continuation after a resume rejection or profile-scope
mismatch, preventing a context-free turn from silently selecting different
runtime state.
Gateway terminal failures and pre-submit transport failures now share a
session-scoped panel immediately above the composer. The panel keeps the failed
transcript row intact, shows only confirmed route/model/provider identity,
offers explicit Details, Retry, and Dismiss actions, and records bounded,
redacted evidence in the existing Diagnostics review/share flow. No route or
model is changed automatically.
## 2026-08-18 — Android 1.10.0 chat continuity and streaming Markdown
Hermes-Relay Android 1.10.0 is published from the immutable
`android-v1.10.0` tag, with the production Play submission committed as
versionCode 45. The release preserves exact-session composer drafts across
restarts, converts large pastes into reviewable attachments, and keeps standard
chat compatible with unmodified upstream Hermes.
Assistant replies now render completed Markdown structures incrementally while
holding an incomplete streaming tail stable. Stable message identity and a
bounded bottom-follow controller prevent completion-time replacement, stacked
scroll animations, and transcript-distance velocity from moving a reader who
has deliberately scrolled away. Foreground reconnect reattaches the visible
Gateway session, malformed imported credentials fail closed, and software
keyboard Return remains distinct from the dedicated Send action.
## 2026-08-17 — Android composer continuity and large-paste review
Android's multiline composer now leaves the software IME action as Return while
the dedicated trailing button sends. Physical keyboard Enter, Shift+Enter, and
directional caret behavior retain their existing contracts.
Composer drafts now persist in bounded app-private no-backup storage using
small owner metadata plus content-addressed attachment blobs. Draft ownership
follows the exact connection, opened session profile, session, and draft slot;
profile and connection switches save before restoring, lifecycle stop flushes
the latest state, and successful sends remove the saved draft.
A default-on Chat setting converts a single insertion of at least 5,000
characters into a reviewable text attachment. Preparation runs off the UI
thread behind a visible loading card. Current Gateways send it through upstream
`file.attach`; API-server SSE and proactive Thread paths materialize the same
UTF-8 content into the prompt so no route silently loses the paste.
## 2026-08-14 — Android 1.9.0 session identity and conversation controls
Hermes-Relay Android 1.9.0 is published from the immutable
`android-v1.9.0` tag. Multi-profile session browsing now keeps the aggregate
drawer scope selected while transcript hydration, resume, sending, and header
identity follow the session's owning profile. New Chat from All Profiles uses
the default profile, and the session list starts ungrouped while retaining
project grouping and the other desktop-style views as explicit options.
Message reactions now resolve durable rows for both user and assistant
messages. Vanilla Hermes voice remains on the authenticated Gateway instead of
requiring the optional API fallback. Session rows can expose profile, project,
branch, and pull-request context without crowding the chat header, secondary
drawer actions remain available in All Profiles, and outside taps dismiss the
drawer.
## 2026-08-09 — Gateway activity recovery and chat speech
Successful Android Gateway turns now reconcile against their profile-owned,
+11 -5
View File
@@ -1,17 +1,22 @@
# Hermes-Relay-Server v__VERSION__
**Release Date:** August 11, 2026
**Release Date:** August 14, 2026
This patch improves gateway recovery diagnostics and prevents clients from reconnecting in lockstep after a shared restart.
This release adds an official, opt-in Relay pane for Hermes Desktop through the supported runtime Plugin SDK. It keeps Relay management profile-scoped and user-invoked without opening a pane during startup, reconnects, profile changes, or plugin updates.
Standard chat, session history, and Vanilla Hermes voice remain upstream-owned and do not require this plugin.
## What's changed
### Fixed
### Added
- **Bounded prior-exit diagnostics.** Relay Doctor and `/relay/info` distinguish a clean stop, an unclean exit, and unknown history, with an optional suspected out-of-memory hint. Raw logs are never returned through the API.
- **Desynchronized recovery.** Ordinary exponential reconnect delays use full jitter so multiple Relay clients do not retry in lockstep after the gateway restarts. Explicit reconnects and server-directed retry timing remain unchanged.
- **Official Hermes Desktop pane.** The unified plugin package registers a movable native pane for Relay status, paired devices, bridge activity, media, pairing, revocation, and remote-access management.
- **Explicit entry points.** Labeled sidebar, status-bar, and command-palette actions register and reveal the pane lazily; repeated opens reuse the same surface.
- **Profile-scoped state.** Cached Relay state follows the active Hermes profile and is disposed cleanly when the plugin unloads.
### Changed
- **Plugin loading stays passive.** Loading, startup, reconnects, profile changes, and updates never reveal the pane or perform pane-owned network work.
## Install / update
@@ -26,6 +31,7 @@ Standard chat, session history, and Vanilla Hermes voice remain upstream-owned a
## Verify
hermes relay doctor
# Agent/tool callers can use desktop_health to list desktop targets.
python scripts/check-plugin-version-sync.py --expect __VERSION__
---
+23
View File
@@ -70,6 +70,21 @@ an HTTPS reverse proxy. The [full walkthrough](https://hermes-relay.dev/docs/gui
covers Windows, remote access, and dashboard authentication. You do not need to
enable the separate API server or invent an API key for the standard path.
For plugin-enabled setups, optional **Hermes Secure Link** presents Relay, API,
and Dashboard routes through one pairing-pinned TLS origin. It protects traffic
to the paired endpoint while each service keeps its own authentication; it does
not provide reachability or independently identify the physical host. You still
use LAN routing, Tailscale or another VPN, or an operator-managed public route
to reach the listener. Secure Link is off by default and requires a fresh QR
pairing after it is enabled. See the
[remote-access guide](https://hermes-relay.dev/docs/guide/remote-access/).
**Hermes Reach** is an experimental, advanced outbound-broker route. It remains
available for development and self-hosted evaluation, but it is disabled by
default, ordered after supported routes, and not recommended for normal remote
access. Use Tailscale for the easiest supported remote setup, or a public TLS
domain / Direct Secure Link when you want to own the complete network path.
### 3 · Connect and talk
Open the app, choose **Connect to Hermes**, and enter or discover the dashboard
@@ -204,6 +219,14 @@ It pairs against the **same relay and credential store** as the Android app —
On Windows, the default installer adds the optional compact **Hermes-Relay CLI UI** tray popup for host selection and pairing, connection and daemon state, per-host Ask/Trusted/Full Access, local grant dialogs, authorized-client revocation, activity, settings, and emergency stop. It is a management surface only—chat, TUI, plugins, voice, and agent sessions remain CLI/upstream concerns.
Structured Windows computer control prefers a compatible local CUA Driver
runtime for window-targeted background actions and virtual per-session agent
cursors. It remains behind Hermes host policy, grants, targeting, audit, and
emergency stop; Windows input is an explicit compatibility backend. CUA is not
bundled or updated automatically, but the local CLI/UI can explicitly install,
check, or update its verified canonical package. It is never exposed as a raw
remote tool surface. See the [desktop tools guide](https://hermes-relay.dev/docs/desktop/tools.html#computer-use-engines).
- **Docs:** [CLI guide](https://hermes-relay.dev/docs/desktop/) · [`desktop/README.md`](desktop/README.md)
- **AI-agent setup recipe:** `/hermes-relay-desktop-setup`
+3
View File
@@ -128,6 +128,7 @@ optional Windows installer.
| File | Purpose |
|---|---|
| `desktop/package.json` | canonical CLI version |
| `desktop/.bun-version` | exact Bun compiler/runtime for standalone binaries |
| `desktop/package-lock.json` | npm root/workspace package metadata |
| `desktop/src/version.ts` | compiled CLI runtime version |
| `desktop/tray/Cargo.toml` | native systray package version |
@@ -152,6 +153,8 @@ manually, run `npm run sync:version` before checking. `npm run verify` is the
single Windows release-parity gate: version sync, type-check, tests, TypeScript
build, compiled CLI smoke, and tray formatting, Clippy, check, and tests. CI runs
the portable portions on every desktop change and the Windows tray gates separately.
Release jobs read `desktop/.bun-version`; cross-built and Windows-built artifacts
must not silently embed different Bun runtime versions.
## Branching policy
+23 -17
View File
@@ -1,10 +1,10 @@
# Hermes-Relay-Android v1.8.1
# Hermes-Relay-Android v1.11.0
**Release Date:** August 9, 2026
**Release Date:** August 20, 2026
## Download
> Installing on your phone? Download `hermes-relay-1.8.1-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
> Installing on your phone? Download `hermes-relay-1.11.0-sideload-release.apk` and tap it for the full feature set, or install the conservative build from [Google Play](https://play.google.com/store/apps/details?id=com.axiomlabs.hermesrelay).
The `.aab` file is a Play Console upload bundle and cannot be installed by tapping it on a phone.
@@ -12,23 +12,29 @@ Verify the download against `SHA256SUMS.txt`. See the [sideload guide](https://h
## Summary
This patch keeps long Hermes conversations complete and aligns Android's
Gateway behavior with current upstream turn contracts.
This release makes Android control more explicit and chat recovery more honest. Sideload users can grant only the Bridge capabilities they intend, including bounded or unlimited screen access, while every build gains clearer stored-session failures, complete multiline keyboard behavior, persistent cancellation status, and lower idle power use.
## Added
- Choose read-only, read-and-confirm, or custom Bridge capability presets for the active connection in sideload builds.
- Grant screen inspection and control for a bounded duration or explicitly keep them unlimited, with the active policy reflected in Relay status.
## Changed
- Use a summary-first Bridge screen that separates Agent access, unattended mode, Android readiness, and advanced safety without removing the full permission matrix.
## Fixed
- Complete transcript reads page explicitly across both API-server and
profile-scoped Dashboard routes, so sessions beyond Hermes' latest-500
default retain stable history, sharing, retry, edit, and recovery anchors.
- Gateway submit rejections preserve the authoritative server message without
silently falling through to SSE.
- Gateway event envelopes reconcile consistently, and edit-and-regenerate
requests send the required truncation confirmation.
- Keep stored-session resume failures in the conversation with route-aware details and explicit retry or dismiss actions instead of silently switching context.
- Insert newlines from both direct-text and synthesized-Enter software keyboards while preserving physical Enter, Shift+Enter, and Ctrl/Cmd+Enter behavior.
- Retain the Stopped status when a blank recovery placeholder is cancelled.
- Stop idle Sphere, waveform, and closed-drawer redraw loops when no motion is visible.
- Attach screen-capture surfaces only for requested frames, release unattended wake locks at command completion, and bind audio effects to the capture session.
- Reuse wake-word normalization buffers during continuous opt-in listening.
## Install / Verify
- App version: **1.8.1** (versionCode **42**).
- Standard Chat, sessions, Manage, and Vanilla Hermes voice continue to work
against unmodified upstream Hermes.
- The optional Relay plugin is not required for standard Android chat or hosted
Dashboard authentication.
- App version: **1.11.0** (versionCode **46**).
- Standard Chat, sessions, Manage, stored-session recovery, software-keyboard multiline input, and Vanilla Hermes voice continue to work against unmodified upstream Hermes.
- Granular Device Control grants and screen-access durations are sideload-only; the Google Play build continues to ship Hermes Bridge Core without AccessibilityService Device Control.
- The optional Relay plugin is not required for standard Android chat, session recovery, or multiline composition.
+76 -20
View File
@@ -6,26 +6,63 @@ For shipped work, see `DEVLOG.md`. For architectural decisions, see `docs/decisi
---
## Certify Android power fixes across the reported device matrix
Issue #377's static estimates are not device measurements. The code now keeps
the idle Sphere static, gates inactive waveform/drawer animation, detaches the
MediaProjection surface between requested frames, binds AEC/NS to the capture
session, releases unattended wake locks at command completion, and reuses the
wake-word normalization buffer. Complete the remaining physical proof before
assigning battery percentages or declaring the report closed:
- Re-run the reported Android 13 / Pixel 4 XL workload with screen-on and
screen-off intervals separated, and with experimental wake listening both
disabled and explicitly enabled. Capture scoped CPU/thread/network/wakelock
evidence plus Battery Historian or Perfetto without resetting batterystats
unless the device owner approves the reset.
- On Android 14+ and a foldable/rotation path, request two screenshots around a
geometry change and verify the existing VirtualDisplay resizes, its surface
is detached between requests, and the projection token is not reused.
- On at least one device with platform AEC, run Standard and Realtime barge-in
through playback and confirm the effect is enabled on the AudioRecord session,
the microphone remains single-owner, interruption still works, and teardown
leaves no audio effect or capture session active.
- Compare Wi-Fi and cellular separately. Treat radio-tail claims as unproven
until packet timing and mobile-radio active time reproduce them on hardware.
---
## Certify the official Desktop Relay plugin
The unified `plugin/desktop/plugin.js` implementation is covered by source-level
SDK contract, packaging, explicit-open, no-auto-open, close, unload, and profile
cache-isolation tests. A physical official Hermes Desktop session is still
required before calling the UX live-certified:
- Test default and named local profiles, ordinary authenticated remote mode,
and SSH mode with differently named local/remote profile mapping.
- In two full app windows, prove enabling, registration, explicit open,
requests, close/reopen, hot reload, and disable/unload remain window-local.
- Prove startup, reconnect, profile change, layout restore/reset, update, and
background events never open or focus Relay.
- Drag and dock the pane across native zones, close it, reopen it from all three
labeled actions, and verify no private-hook fallback is needed.
- Exercise Relay running/unreachable, zero/one/multiple devices, pairing,
revocation, bridge activity, media, remote access, and renderer error logging
without exposing credentials, pairing payloads, filesystem paths, or tokens.
---
## Structured desktop hardware capabilities
Desktop command, PowerShell, process, and job tools currently execute with the
desktop daemon's OS-user authority. Add typed hardware operations for reliable
schemas, audit detail, and task-scoped approval, but do not present hardware
toggles as isolation while an enabled general shell can reach the same device.
- Define per-host capabilities for commands, files, processes, clipboard,
screen, input, connected devices, microphone, and camera. Disabled must win,
hardware-sensitive capabilities must default off, and unavailable backends
must appear unavailable rather than as inert toggles.
- Add a **Structured only** access profile that withholds shell/process escape
hatches so individual capability toggles become enforceable boundaries.
- Implement connected-device support first with typed, serial-bound ADB
operations (`list`, `shell`, `push`, `pull`, `install`, and bounded logcat)
instead of a generic device-exec wrapper.
Structured access and per-host USB policy now ship with typed, serial-bound ADB
list, shell, push, pull, install, and bounded logcat operations. Remaining work:
- Add microphone and camera only with backend readiness detection, bounded local
grants, active-use indicators, audit events, and immediate cancellation.
- Reconcile legacy `desktop_screenshot` with the task-granted computer screenshot
path so screen capture follows one policy.
- Extend capability policy beyond hardware only where a typed broker provides a
meaningfully stronger boundary than Structured mode already provides.
---
@@ -932,7 +969,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
- Live gateway must discover the plugin (`~/.hermes/plugins/hermes-relay` → `plugin/`) and `plugins.enabled` must include `hermes-relay` for the `phone` platform to register. Confirm `phone` appears in `hermes gateway status` with `PHONE_ENABLED=1`.
- End-to-end: with the app paired + "Let Hermes message me" on, run `send_message target=phone text=...` (and a cron `deliver=phone`) and confirm a notification on the device. Verify 503 (no phone) and the off-by-default gates.
- **Phase 2c reply round-trip — ✅ DONE (verified on-device 2026-06-29).** Confirmed: agent → phone notification → inline reply → drained through the relay's loopback `GET /phone/replies` (different process) → `handle_message` (`role_authorized=True`, no `PHONE_ALLOW_ALL_USERS`) → agent answer back in the *same* thread. Both fixes required (see DEVLOG / the Phase 2c bullet above).
- **FIX: cron `deliver=phone` / standalone send is broken.** Live testing: `hermes send --to phone` returns `{"error": "Unknown platform: phone"}`. The standalone (non-gateway) send path doesn't run a `kind=standalone` plugin's programmatic `ctx.register_platform`, so it never learns `phone` — only the running gateway (which loads `register()` at startup) does. The agent path (`send_message target=phone` in the gateway) works and was verified end-to-end on-device; the standalone/cron path needs the platform discoverable there too (declare it so the standalone loader picks it up, or route cron through the gateway). Until then `cron deliver=phone` won't work.
- **Cron `deliver=phone` live certification pending.** The plugin now registers its standalone sender and enumerates the canonical phone home through the upstream adapter channel-directory hook. Re-run the device scenario above on the deployed plugin to certify scheduled delivery, including the offline queue and opt-in gates.
- **FIX SHIPPED (2026-07-07) — installer + doctor guard against stale duplicate plugin copies; live-host verify pending.** Root cause of the 2026-06-29 round-trip failure: the gateway loader dedups discovered plugins by manifest `name`, so a second directory declaring `name: hermes-relay` (an old-installer backup copy, or a stray native install) could win the dedup and make the gateway load stale code — silently ignoring every later deploy. `plugin/doctor.py` now emits a `plugin-name-unique` warning when more than one directory under `~/.hermes/plugins/` declares the same plugin name (distinct real targets only — two links to the same target are deduped), and `install.sh` sweeps any such duplicate so only the canonical `hermes-relay` symlink survives. (Current `install.sh` already `rm -rf`s the old link rather than backing it up inside the plugins dir, so the original "back up outside the plugins dir" half is moot.) **Verify on the live host:** `hermes relay doctor` reports the `plugin-name-unique` check, and a reinstall leaves exactly one `hermes-relay` entry under `~/.hermes/plugins/`.
## Phone platform — usability roadmap (post device-verification, 2026-06-29)
@@ -943,9 +980,9 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
**Refinement (2026-06-29) — unified-session model: "Threads."** Going further on "unified surface": the agent conversation is **not a separate tab/segment** at all — it is a **source-tagged session inside the one Chat surface**, a **Thread** (`source=phone`). What makes a Thread special vs. a normal gateway chat are *session properties*, not a separate UI: (a) the agent can initiate, (b) relay `proactive` transport + relay-gated, (c) standing/named DM. **Scrollback = the gateway session store** (same read path Chat uses); **live receive = relay `proactive` push** (→ notification); **send = `proactive.reply`**. `ProactiveInboxStore` is demoted to a live-push cache + outbox (no parallel history). The Thread capability shows in the **best-path/capability UI** (relay tier, like terminal/bridge/voice) and as a clean **Threads** entry — thread-spool icon, NOT a phone glyph — pinned atop the session drawer when active; never a connection-wizard step. Degrades cleanly (no plugin → no `source=phone` sessions → Chat unchanged). **Supersedes the "separate Agent lane / 4th nav segment" sketch** and merges with the "source attribution in Chat" goal below. Keep the two "gateway" senses straight: *platform layer* (the Thread's `source`) ≠ *dashboard `/api/ws` transport* (how live bytes flow). Full re-cut: docs/decisions.md ADR 12.
- **Outbound buffering — ✅ relay-side DONE (2026-06-29).** `ProactiveChannel.push()` now queues agent→phone messages in a bounded deque (drop-oldest, 24 h TTL) when no phone is subscribed and returns `{queued: true}` (not 503); `_flush_outbound` delivers FIFO on the next subscribe (stale pruned). Inspect/cancel via `peek_outbound`/`cancel_outbound` + loopback `GET`/`DELETE /phone/outbound`. **UI surfacing of the queued state** (host-side, since the queue exists while the phone is OFFLINE): (a) ✅ **desktop CLI `relay queue` / `relay queue --clear` / `--cancel <id>` DONE (2026-06-29)** over the new endpoints (loopback-only — run on the relay host); a dashboard Relay-tab view is the optional GUI equivalent; (b) **remaining** — in the threaded agent surface, mark messages that arrived-while-away, and show the user's OWN pending replies (the Phase 3 reply queue) with a sending/Cancel affordance — that's where phone-side "queued + cancel" belongs.
- **Outbound buffering — ✅ relay-side + arrived-while-away receive UX DONE.** `ProactiveChannel.push()` queues agent→phone messages in a bounded deque (drop-oldest, 24 h TTL) when no phone is subscribed and returns `{queued: true}`. `_flush_outbound` delivers FIFO on the next subscribe (stale pruned), marks flushed messages, and sends one batch-complete count; Android labels those Thread bubbles “While away” and shows one accessible batch summary without changing unread behavior. Inspect/cancel remains available through `peek_outbound`/`cancel_outbound`, loopback `GET`/`DELETE /phone/outbound`, and desktop `relay queue`. **Remaining:** show the user's OWN pending replies (the Phase 3 reply queue) with an honest Queued/Cancel affordance; a dashboard queue view remains optional.
- **Threads surface (unified-session model — see ADR 12 + the Refinement above).** Build order, each shippable: **(1)** source tags in the session drawer (`source=phone` → clean **Threads** chip + thread-spool icon, NOT a phone glyph) — also delivers the "source attribution in Chat" goal; **(2)** open a Thread in Chat from its session-store history (reuse the existing message-history path); **(3)** route the live `proactive` push into the session view + notification + unread, demoting `ProactiveInboxStore` to cache/outbox; **(4)** reply from the Chat composer via `proactive.reply` + persist the user turn + local `Sending/Queued/Failed` status — **MVP**; **(5)** a **Threads capability row** in the best-path UI + a pinned **Threads** entry atop the drawer (thread-spool icon, shown only when relay-paired + opted-in) + retire `HermesInboxScreen`, re-point the notification deep-link + Settings "View messages"; **(6)** outbox/retry on reconnect; **(7)** relay `proactive.reply.ack` (honest Delivered) + `proactive.cancel`; **(8)** multi-thread `chat_id` (named/project Threads). **Verify gate before (1):** confirm the app's session-list/history path surfaces a `source=phone` session cleanly (upstream `session.list` returns all sources flat, so it should — but check whether the drawer currently filters it out). Honesty call: do NOT show "Delivered" until (7) lands (can't confirm it client-side before the ack).
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering** (an agent reply lands in the open Thread as an ASSISTANT bubble, suppressing the notification/inbox — `injectIntoThread`); **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`** (deleted; route + nav removed; notification tap + Settings "View messages" re-pointed to Chat; surface renamed "Hermes messages" → **"Threads"**); relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DEFERRED (reasons):** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **exact-Thread deep-link** from the notification (opens Chat today, not the specific thread — needs select-session-on-entry); **remove the now-orphaned `ProactiveInboxStore`** (viewer-less write-only log); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **Status (2026-06-29, implemented UNBUILT — verify in Studio):** **CODE-COMPLETE on `dev`:** slice **1** (drawer source tags + `ThreadSpoolGlyph` + Threads filter), **2** (open a Thread from history — free via the existing `loadSessionHistory` path), **3-parse** (carry `reply_to` on `ProactiveMessage`), **4** (composer reply in a `source=phone` session routes over `proactive.reply`; `MessageDeliveryStatus` SENDING→DELIVERED/FAILED on the bubble), **5** (Threads capability row in `SessionPathCard` + `threadsCapabilityActive` drawer wiring), **7** (relay `proactive.reply.ack` + `proactive.cancel` — 25/25 `unittest` green — and client ack handling). **DONE since (2026-06-29, built + on phone):** live **in-thread reply rendering**; **user-created named Threads** ("+ New Thread"); **retire `HermesInboxScreen`**; relay slice-7 ack/cancel **DEPLOYED** to the host so **"Delivered" is live**. **DONE (2026-08-14):** notification taps survive cold start and open the exact `chat_id`; agent-initiated outbound messages appear as connection-scoped provisional Threads backed by the bounded proactive store, then promote to the real `source=phone` session after the first reply. **DEFERRED:** per-session **unread badge**; **outbox/retry** (needs multiplexer connection-state); **agent-initiated** named Threads (upstream `send_message` thread param). On-device verifies for the create-flow: fresh-`chat_id` auto-create, the `…:dm:<chat_id>` id form, `renameSession` on a phone session.
- **User-created Threads (slice 8, Discord-style) — CODE-COMPLETE on `dev` (built + installed 2026-06-29; on-device behavior pending).** "+ New Thread" in the drawer's Threads view → name dialog → `ChatViewModel.startNewThread` mints a fresh `chat_id`; the first composer message opens it over `proactive.reply` (gateway auto-creates the `source=phone` session) → `switchToCreatedThread` polls + switches to the real session + applies the name. Existing-thread replies route by the `chat_id` parsed from the session id (`…:dm:<chat_id>`; opaque id → home fallback). **On-device verifies:** (1) a fresh-`chat_id` no-`reply_to` inbound creates a new `source=phone` session; (2) the phone session id carries the `…:dm:<chat_id>` form the client parses; (3) `renameSession` titles a phone session. **Remaining slice-8:** AGENT-initiated named Threads (the upstream `send_message` thread/chat_id param so the agent can open its own named Threads).
- **`chat_id` not exposed by `/api/sessions` (root cause of the 2026-06-29 on-device create-flow bugs — fixed client-side).** Confirmed on the host: a phone session's `id` is a timestamp (e.g. `20260629_204755_94f391d6`); the real `chat_id` lives in the `session_key` (`agent:main:phone:dm:<chat_id>`) and a `chat_id` column — but `/api/sessions` returns **neither `chat_id` nor `session_key`**, only `source` + the timestamp `id`. So the client could not map a session ↔ its `chat_id`, which broke create-thread switch/rename + reply routing + in-thread injection. **Client workaround shipped:** find a created thread by session-list **diff** (the new `source=phone` session), keep an in-memory `sessionId → chat_id` map (learned at creation + from incoming `phone.message`s) for reply routing, and inject by source (+ learned chat_id) rather than a parsed id. **Limitation:** for a thread the app didn't create *this* session (agent-created, another device, or after an app restart) `chat_id` is unknown until a message arrives while viewing it → its replies fall back to the home channel until then. **RESOLVED via the plugin (2026-06-29, per upstream-or-plugin policy):** the relay now exposes `GET /phone/threads` (`plugin/relay/session_store.py` reads the gateway store read-only → `[{session_id, chat_id, title}]`; `server.py` `handle_phone_threads`, bearer for the app / loopback for diag; 5 unit tests). The app (`RelayHttpClient.fetchPhoneThreads` → `ConnectionViewModel.phoneThreadChatIds` on every `auth.ok` → `ChatViewModel.seedThreadChatIds`, authoritative over the learned map) now routes replies correctly for **any** Thread — incl. ones it didn't create + after restart. Deployed + verified live. **Still-nice-to-have (lower priority): the upstream PR** to add `chat_id`/`session_key` to `/api/sessions` (the standard-path proper fix; the relay route then becomes redundant + the client prefers upstream when present).
- **Threads as named/project conversations (Discord-parity — folds into multi-thread #8).** A stable *named* `chat_id` per project = a persistent, agent-reachable project Thread (Discord named-thread parity for "persist a session for a project"). Enables: the agent **opening** a new named Thread for a background job/topic (a relay/gateway "open thread" affordance + a `send_message`-adjacent tool); cron/job updates landing in their own Thread; and replying to a Thread from any surface (desktop CLI / dashboard) since it is just a gateway session. Also evaluate per-Thread profile binding (a project Thread uses the "work" profile — ties to profile=contact).
@@ -965,7 +1002,7 @@ Phase 1 (end-to-end spine) shipped on `Codename-11/phone-platform` — `send_mes
The gateway-platform model is the *correct + sufficient architecture* (the phone is a registered platform peer, so anything that routes to a platform — `send_message`, cron `deliver=`, channel directory, background jobs — can reach the phone). These are the concrete gaps between "architecturally a peer" and "I never open Discord":
- **Guaranteed background delivery (the biggest gap; no push today).** Delivery is **live-WSS-only** + a 24 h relay buffer; there is **no FCM/UnifiedPush** wake-up. If the app process is dead AND not holding a socket, a message waits for the next reconnect, and the relay buffer is ephemeral (lost on relay restart). Discord/Telegram feel instant because they wake the device via push even when the app is dead. Decide a **push transport**: **UnifiedPush/ntfy** (recommended — self-hostable, no Google dependency, upstream *already* ships an `ntfy` platform, on-brand for self-hosted) vs **FCM** (simplest UX but adds Play Services + a push relay; clashes with self-hosted ethos — at most the `googlePlay` flavor) vs **persistent foreground keep-alive service** holding the relay WSS (zero new infra, like `GatewayKeepAliveService`, but battery cost + Doze-fragile). Likely: UnifiedPush primary + foreground-keepalive fallback.
- **Cron / background-job delivery is BROKEN** (already tracked above): `deliver=phone` standalone path → `Unknown platform: phone`. This is load-bearing for "receiver of crons/background jobs" — fix is required, not optional, for the replacement goal.
- **Cron / background-job delivery needs live certification.** The standalone sender and channel-directory enumeration are implemented; certify `deliver=phone` against a deployed Relay and paired device, including reconnect delivery from the bounded offline queue.
- **Agent-initiated multi-thread creation remains.** The app already renders N
`source=phone` sessions, user-created Threads vary `chat_id`, and replies route
by `chat_id` + `reply_to`. The missing parity is letting the agent open/name a
@@ -974,7 +1011,7 @@ The gateway-platform model is the *correct + sufficient architecture* (the phone
session store; the relay buffer is only the live/offline-delivery layer, not a
parallel history database.
- **Profile = contact mapping (new idea, fold in).** Multiple Hermes **profiles** (distinct agent personas/configs) could each be a distinct thread *source*/"contact" — DMing different agents. Maps cleanly onto the per-thread `chat_id` + source-attribution work; lets the app feel like a contact list of agents.
- **Per-thread notification controls + deep-link (Discord-parity affordances).** Per-thread notification channels, mute/DND/quiet-hours (Phase 3 partially), and a notification that **deep-links into the exact thread** (tap → land in that conversation) so dipping in/out while multitasking is frictionless.
- **Per-thread notification controls (Discord-parity affordances).** Exact-thread notification deep-linking is shipped. Remaining: per-thread notification channels and mute/DND/quiet-hours controls (Phase 3 partially).
- **Agent-initiated rich content.** Agent → phone thread with **images/cards** (relay media infra + `InboundAttachmentCard`/`HermesCardBubble` already exist on the chat side — reuse). Inbound (phone → agent) reply media stays deferred (text-first), but outbound rich content is low-cost parity.
- **In-thread "agent is working" indicator.** A typing/working state in the thread while the agent thinks/runs tools (Discord typing-dots parity) — the chat surface already has thinking indicators to reuse.
@@ -1240,8 +1277,27 @@ When the answer becomes clearer, this section becomes either an ADR in `docs/dec
## Smaller deferred items
- **Certify the preferred CUA Driver backend (ADR 56).** The canonical-runtime
probe, bounded adapter, server-owned control-session envelope, per-session
grant state, local engine/status controls, telemetry-off process environment,
and Hermes snapshot-token primitives now exist. Before graduating the engine,
finish end-to-end enforcement of app/display/folder scopes and sensitive
pixel/accessibility denial or redaction, harden the grant-bridge ACL and nonce
lifecycle, and complete live Windows certification proving the physical cursor and
foreground app stay unchanged, stale or cross-window tokens fail, two remote
control sessions receive isolated animated cursors, and foreground escalation
never happens implicitly. Exercise revoke on grant expiry, disconnect,
re-pair, policy downgrade, emergency stop, Windows-session change, and daemon
shutdown. The explicit local CUA install/update surface now verifies upstream
manifest identity and installer SHA-256; add Windows publisher verification
when upstream signs the installer. Keep raw CUA tools, configuration,
recording, replay, and JavaScript outside the remote agent surface.
Remove the temporary Windows readiness/health split once
[trycua/cua#3103](https://github.com/trycua/cua/issues/3103) ships in the
supported CUA range; restore a mandatory health gate only if the upstream
probe is bounded and cannot leave UI Automation falsely busy.
- **MediaProjection consent flow** — wired in MainActivity (2026-04-12), needs end-to-end test on a real device
- **WorkManager upgrade for auto-disable timer** — currently a coroutine `Job + delay()` in `AutoDisableWorker.kt`; documented at top of file. Upgrade when androidx.work joins the classpath
- **WorkManager upgrade for timed screen-access expiry notification** — authority already fails closed from persisted absolute expiry after restart; the prompt notification is currently a coroutine `Job + delay()` coordinated by `BridgeSafetyManager` / `AutoDisableWorker`. Upgrade only if background notification timing becomes important after androidx.work joins the classpath.
- **Wave 3 voice-bridge multi-turn confirmation** — currently a 5s TTS countdown with cancel; conversational confirmation is the follow-up
- **LLM client wiring for `android_navigate`** — `_default_vision_model` is stubbed; production swap to a real Anthropic/OpenAI vision client
- **Real screenshots of each flavor's a11y permission dialog** — for `user-docs/guide/release-tracks.md`
+4 -2
View File
@@ -319,11 +319,13 @@ dependencies {
// Coil 3 — async image loading for generated images in chat
implementation(libs.coil.compose)
implementation(libs.coil.gif)
implementation(libs.coil.network.okhttp)
implementation(libs.exifinterface)
// QR Code scanning (ML Kit + CameraX)
implementation(libs.mlkit.barcode)
implementation(libs.zxing.core)
implementation(libs.camera.core)
implementation(libs.camera.camera2)
implementation(libs.camera.lifecycle)
@@ -370,8 +372,8 @@ dependencies {
// [POC] Roborazzi host-side screenshot rendering (src/test, Robolectric).
// Renders real composables on the JVM at an exact canvas — no device, no
// status bar, no clipping. See StoreScreenshotTest.
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.71.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.71.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi:1.72.0")
testImplementation("io.github.takahirom.roborazzi:roborazzi-compose:1.72.0")
testImplementation(libs.compose.ui.test.junit4)
testImplementation(libs.compose.ui.test.manifest)
testImplementation("androidx.test.ext:junit:1.3.0")
@@ -1 +1,3 @@
Long sessions now retain complete history beyond Hermes' latest-500 default, keeping edit, retry, sharing, and recovery anchors stable. Gateway submit rejections preserve the server's message without unintended SSE fallback, while event envelopes and edit-and-regenerate requests follow current upstream contracts.
v1.11.0 - More reliable chat
Keep stored-session failures visible with route-aware retry details. Use Return for multiline prompts across more software keyboards. Preserve Stopped status when cancelling answer recovery. Reduce idle redraws and release capture and audio resources sooner.
@@ -1 +1,3 @@
新增可在界面中漫游的 Petdex 浮动宠物、由已安装 Hermes 插件提供的安全原生页面,以及支持本地“Hey Hermes”的可选 Android 数字助理。本次更新还新增俄语,并改进语音恢复、路线切换、实时聊天稳定性和宠物移动。
v1.11.0 - 更可靠的聊天体验
已存会话恢复失败时会保留错误与重试信息。更多输入法可用回车键换行。取消回复恢复时会保留“已停止”状态。空闲动画更少,并更及时地释放屏幕捕获和音频资源。
+112
View File
@@ -1,5 +1,117 @@
{
"versions": [
{
"version": "1.11.0",
"title": "Access with clear boundaries",
"date": "2026-08-20",
"sections": [
{
"header": "Choose what Bridge can do",
"bullets": [
"Use read-only, read-and-confirm, or custom capability presets for the active connection in sideload builds.",
"Allow screen inspection and control for a bounded period or explicitly keep access unlimited."
]
},
{
"header": "Recover without losing context",
"bullets": [
"Keep stored-session failures visible with route-aware details and clear retry or dismiss actions.",
"Insert newlines across more software keyboards and retain Stopped status when answer recovery is cancelled."
]
},
{
"header": "Use less power while idle",
"bullets": [
"Pause invisible Sphere, waveform, and drawer animation loops when no motion is needed.",
"Attach capture surfaces only for requested frames and release audio or wake-lock resources at their lifecycle boundaries."
]
}
]
},
{
"version": "1.10.0",
"title": "Chat that stays put",
"date": "2026-08-18",
"sections": [
{
"header": "Watch replies take shape",
"bullets": [
"Render paragraphs, lists, links, fenced code, and tables incrementally without replacing the message at completion.",
"Keep bottom-follow smooth while intentional scrollback remains exactly where you left it."
]
},
{
"header": "Pick up where you left off",
"bullets": [
"Resume the visible Hermes session automatically after returning from another app.",
"Restore composer text, quote or edit context, and pending attachments in the correct conversation after an app restart."
]
},
{
"header": "Review before sending",
"bullets": [
"Turn large pastes into compact text attachments while preserving compatible fallback delivery.",
"Use Return on the software keyboard while the dedicated composer button remains the Send action."
]
}
]
},
{
"version": "1.9.1",
"title": "Profile identity that sticks",
"date": "2026-08-16",
"sections": [
{
"header": "Identity follows the right scope",
"bullets": [
"Change shared avatars from Android with automatic orientation, resizing, and safe conversion to the Hermes profile-asset contract.",
"Select upstream animated pets that follow the Hermes profile while phone-only animated icons, local avatar overrides, and Sphere skins stay local."
]
},
{
"header": "Profile setup stays explicit",
"bullets": [
"Create profiles with clear shared, copied, or isolated authentication choices and see partial setup outcomes.",
"Named-profile sessions and profile drafts fail closed when Hermes cannot confirm their owner."
]
},
{
"header": "Safer Gateway operations",
"bullets": [
"Attachments, rewinds, recovery, model-consent changes, and hosted sign-in now follow stricter upstream contracts.",
"Finite schedules, bounded reset evidence, and host resource warnings make consequential actions easier to review."
]
}
]
},
{
"version": "1.9.0",
"title": "Better sessions, reactions, and voice",
"date": "2026-08-14",
"sections": [
{
"header": "Sessions keep their identity",
"bullets": [
"Browse one profile or all profiles, customize sorting and filters, and optionally group sessions by project, recency, status, or profile.",
"Cross-profile sessions hydrate, resume, and send with their owning agent without changing the global profile selection; New Chat in All Profiles uses the default profile."
]
},
{
"header": "Conversation controls stay attached",
"bullets": [
"Reactions pin to durable rows on both user and assistant messages.",
"Vanilla Hermes voice stays on the authenticated Gateway instead of requiring the optional API fallback."
]
},
{
"header": "Context without clutter",
"bullets": [
"Session rows show profile, project, branch, and pull-request context when Hermes supplies it, while the default view remains ungrouped.",
"The session drawer restores secondary actions in All Profiles and closes when you tap outside it."
]
}
]
},
{
"version": "1.8.1",
"title": "Complete, reliable transcripts",
+7 -5
View File
@@ -1,6 +1,8 @@
v1.8.1 - Complete, reliable transcripts
v1.11.0 - Access with clear boundaries
* Keep complete history in long sessions beyond Hermes' latest-500 default.
* Preserve stable edit, retry, sharing, and recovery anchors while paging history.
* Show authoritative Gateway rejection messages without an unintended fallback.
* Reconcile Gateway events and edit-and-regenerate requests with current upstream contracts.
* Choose explicit Bridge capability presets in sideload builds.
* Allow screen inspection and control for a set time or explicitly keep access unlimited.
* Keep stored-session failures visible with route-aware retry details.
* Use Return for multiline prompts across more software keyboards.
* Preserve Stopped status when cancelling answer recovery.
* Reduce idle redraws and release capture and audio resources sooner.
@@ -7,6 +7,8 @@ import android.os.Build
import coil3.ImageLoader
import coil3.PlatformContext
import coil3.SingletonImageLoader
import coil3.gif.AnimatedImageDecoder
import coil3.gif.GifDecoder
import coil3.network.okhttp.OkHttpNetworkFetcherFactory
import coil3.request.crossfade
import com.hermesandroid.relay.bridge.UnattendedAccessManager
@@ -38,7 +40,14 @@ class HermesRelayApp : Application(), SingletonImageLoader.Factory {
*/
override fun newImageLoader(context: PlatformContext): ImageLoader =
ImageLoader.Builder(context)
.components { add(OkHttpNetworkFetcherFactory()) }
.components {
add(OkHttpNetworkFetcherFactory())
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.P) {
add(AnimatedImageDecoder.Factory())
} else {
add(GifDecoder.Factory())
}
}
.crossfade(true)
.build()
@@ -21,6 +21,8 @@ import kotlinx.coroutines.isActive
import kotlinx.coroutines.launch
import kotlinx.serialization.json.JsonNull
import kotlinx.serialization.json.buildJsonObject
import kotlinx.serialization.json.buildJsonArray
import kotlinx.serialization.json.add
import kotlinx.serialization.json.put
/**
@@ -226,6 +228,7 @@ class BridgeStatusReporter(
val destructiveVerbsCount = safetySnapshot?.destructiveVerbs?.size ?: 0
val autoDisableMinutes = safetySnapshot?.autoDisableMinutes ?: 0
val autoDisableAtMs = safetyManager?.autoDisableAtMs?.value
val capabilityPolicy = safetyManager?.activeCapabilityPolicy?.value
val deviceName = Build.MODEL ?: "unknown"
@@ -281,6 +284,33 @@ class BridgeStatusReporter(
put("auto_disable_at_ms", autoDisableAtMs)
}
})
put("capabilities", buildJsonObject {
put("schema_version", capabilityPolicy?.schemaVersion ?: 1)
put("permanent", buildJsonArray {
capabilityPolicy?.permanentGrants
?.sortedBy { it.wireId }
?.forEach { add(it.wireId) }
})
put("timed", buildJsonObject {
capabilityPolicy?.timedExpiriesMs
?.filterValues {
it != com.hermesandroid.relay.bridge.BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS
}
?.toSortedMap(compareBy { it.wireId })
?.forEach { (capability, expiry) ->
put(capability.wireId, expiry)
}
})
put("unlimited", buildJsonArray {
capabilityPolicy?.timedExpiriesMs
?.filterValues {
it == com.hermesandroid.relay.bridge.BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS
}
?.keys
?.sortedBy { it.wireId }
?.forEach { add(it.wireId) }
})
})
// v0.4.1: unattended-access state so the agent can decide
// upfront whether commands will reach apps with the screen
@@ -41,7 +41,7 @@ import kotlinx.coroutines.launch
*
* The Android system toggle in `Settings → Accessibility → Hermes-Relay` is
* the hard switch — if it's off we never receive events. On top of that the
* user can flip a soft master in Settings (`bridge_master_enabled`); when
* user can flip a soft master in Settings (`bridge_master_enabled_v2`); when
* that's false we still run (Android requires it to stay connected) but we
* refuse to execute commands. [isMasterEnabled] is a StateFlow the UI
* observes and the command handler checks before dispatching actions.
@@ -61,7 +61,9 @@ class HermesAccessibilityService : AccessibilityService() {
private const val TAG = "HermesA11yService"
/** Master-enable DataStore key — read + toggled from Settings UI. */
val KEY_BRIDGE_MASTER_ENABLED = booleanPreferencesKey("bridge_master_enabled")
val KEY_BRIDGE_MASTER_ENABLED = booleanPreferencesKey("bridge_master_enabled_v2")
private val KEY_LEGACY_BRIDGE_MASTER_ENABLED =
booleanPreferencesKey("bridge_master_enabled")
/**
* Static reference to the live service instance, or null if the
@@ -92,6 +94,7 @@ class HermesAccessibilityService : AccessibilityService() {
suspend fun setMasterEnabled(context: Context, enabled: Boolean) {
context.applicationContext.relayDataStore.edit { prefs ->
prefs[KEY_BRIDGE_MASTER_ENABLED] = enabled
prefs[KEY_LEGACY_BRIDGE_MASTER_ENABLED] = false
}
}
}
@@ -152,12 +152,14 @@ class ScreenCapture(
// 13 and below but breaks the second /screenshot request on 14+.
//
// Fix: keep the VirtualDisplay + ImageReader + HandlerThread alive
// across captures, keyed by the MediaProjection instance. Rebuild only
// when the projection reference changes (fresh consent grant) or the
// dimensions change (orientation flip). The ImageReader's
// setOnImageAvailableListener drains the buffer continuously; each
// captureAndUpload() installs a one-shot [pendingCapture] callback
// that fires on the next frame.
// across captures, keyed by the MediaProjection instance. The reader
// surface is attached only while a request is waiting, then detached so
// SurfaceFlinger is not continuously mirroring into a drain-and-drop loop.
// Rebuild only when the projection reference changes (fresh consent
// grant). Orientation/size changes resize the existing VirtualDisplay and
// replace its detached ImageReader, preserving Android 14's single-create
// contract. Each captureAndUpload() installs a one-shot [pendingCapture]
// callback that fires on the next attached frame.
//
// Thread model:
// - `captureMutex` serializes concurrent captureAndUpload() calls
@@ -273,6 +275,7 @@ class ScreenCapture(
*/
fun releaseCache() {
synchronized(cacheLock) {
runCatching { cachedDisplay?.setSurface(null) }
runCatching { cachedDisplay?.release() }
runCatching { cachedReader?.close() }
runCatching { cachedThread?.quitSafely() }
@@ -326,6 +329,7 @@ class ScreenCapture(
}
return try {
attachCaptureSurface()
val timeoutMs = captureTimeoutMs()
kotlinx.coroutines.withTimeout(timeoutMs) { deferred.await() }
} catch (e: kotlinx.coroutines.TimeoutCancellationException) {
@@ -336,6 +340,24 @@ class ScreenCapture(
} catch (t: Throwable) {
pendingCaptureRef.compareAndSet(deferred, null)
throw t
} finally {
detachCaptureSurface()
}
}
private fun attachCaptureSurface() {
synchronized(cacheLock) {
val display = cachedDisplay ?: throw IOException("capture display unavailable")
val surface = cachedReader?.surface ?: throw IOException("capture surface unavailable")
display.setSurface(surface)
Log.d(TAG, "screen capture surface attached for pending frame")
}
}
private fun detachCaptureSurface() {
synchronized(cacheLock) {
runCatching { cachedDisplay?.setSurface(null) }
.onFailure { Log.v(TAG, "screen capture surface detach failed: ${it.message}") }
}
}
@@ -350,11 +372,12 @@ class ScreenCapture(
/**
* Build (or reuse) the cached VirtualDisplay + ImageReader + HandlerThread
* for this projection. Rebuilds when:
* for this projection. Rebuilds the display when:
*
* - The projection reference has changed (new consent grant landed)
* - The captured dimensions don't match the current display (orientation
* flipped, foldable opened/closed, display switched)
*
* Geometry changes resize that existing display and replace its detached
* consumer surface, as required for Android 14's one-display-per-token rule.
*
* Must be called while [captureMutex] is held so the cached fields
* aren't racing another capture.
@@ -368,52 +391,41 @@ class ScreenCapture(
synchronized(cacheLock) {
val projectionChanged = cachedProjection !== projection
val dimensionsChanged = width != cachedWidth || height != cachedHeight
if (!projectionChanged && !dimensionsChanged && cachedDisplay != null && cachedReader != null) {
val densityChanged = densityDpi != cachedDensity
if (!projectionChanged && !dimensionsChanged && !densityChanged &&
cachedDisplay != null && cachedReader != null
) {
return
}
// Android 14 permits only one createVirtualDisplay() call per
// MediaProjection. Resize the existing display and replace only
// its detached consumer surface when the device geometry changes.
if (!projectionChanged && cachedDisplay != null && cachedThread != null) {
val display = cachedDisplay ?: return
val thread = cachedThread ?: return
val handler = cachedHandler ?: Handler(thread.looper)
display.setSurface(null)
runCatching { cachedReader?.close() }
display.resize(width, height, densityDpi)
cachedReader = createImageReader(width, height, handler)
cachedHandler = handler
cachedWidth = width
cachedHeight = height
cachedDensity = densityDpi
Log.i(TAG, "screen capture pipeline resized ${width}x$height dpi=$densityDpi")
return
}
// Tear down any stale cache before building fresh.
runCatching { cachedDisplay?.setSurface(null) }
runCatching { cachedDisplay?.release() }
runCatching { cachedReader?.close() }
runCatching { cachedThread?.quitSafely() }
val thread = HandlerThread("HermesScreenCapture").apply { start() }
val handler = Handler(thread.looper)
val reader = ImageReader.newInstance(
width, height, PixelFormat.RGBA_8888, MAX_IMAGES
)
// Persistent listener — fires on every frame the VirtualDisplay
// produces. If there's a pending capture request, we encode
// the frame and complete it; otherwise we just drain the image
// so the ImageReader buffer stays clear.
reader.setOnImageAvailableListener({ r ->
val waiter = pendingCaptureRef.get()
if (waiter == null || !waiter.isActive) {
// Drain-and-drop — nobody's asking for a screenshot
// right now but frames are still arriving.
runCatching { r.acquireLatestImage() }.getOrNull()?.close()
return@setOnImageAvailableListener
}
var image: Image? = null
try {
image = r.acquireLatestImage()
?: return@setOnImageAvailableListener
val png = imageToPngBytes(image, width, height)
// Only complete the EXACT deferred we latched onto,
// so a stale listener firing after supersession doesn't
// resolve a new request.
if (pendingCaptureRef.compareAndSet(waiter, null)) {
waiter.complete(png)
}
} catch (t: Throwable) {
if (pendingCaptureRef.compareAndSet(waiter, null)) {
waiter.completeExceptionally(t)
}
} finally {
runCatching { image?.close() }
}
}, handler)
val reader = createImageReader(width, height, handler)
val display = try {
projection.createVirtualDisplay(
@@ -422,7 +434,7 @@ class ScreenCapture(
height,
densityDpi,
DisplayManager.VIRTUAL_DISPLAY_FLAG_AUTO_MIRROR,
reader.surface,
null,
null,
handler,
)
@@ -461,6 +473,38 @@ class ScreenCapture(
}
}
private fun createImageReader(width: Int, height: Int, handler: Handler): ImageReader {
val reader = ImageReader.newInstance(
width, height, PixelFormat.RGBA_8888, MAX_IMAGES,
)
// The listener receives frames only while captureFrame() has attached
// this reader's surface. The empty-waiter branch drains a frame already
// queued at the detach boundary.
reader.setOnImageAvailableListener({ source ->
val waiter = pendingCaptureRef.get()
if (waiter == null || !waiter.isActive) {
runCatching { source.acquireLatestImage() }.getOrNull()?.close()
return@setOnImageAvailableListener
}
var image: Image? = null
try {
image = source.acquireLatestImage()
?: return@setOnImageAvailableListener
val png = imageToPngBytes(image, width, height)
if (pendingCaptureRef.compareAndSet(waiter, null)) {
waiter.complete(png)
}
} catch (t: Throwable) {
if (pendingCaptureRef.compareAndSet(waiter, null)) {
waiter.completeExceptionally(t)
}
} finally {
runCatching { image?.close() }
}
}, handler)
return reader
}
/**
* Convert an [Image] from `ImageReader` into a PNG byte array. The
* plane's `rowStride` may be wider than `width * 4` — we must crop
@@ -52,18 +52,12 @@ import kotlin.math.max
*
* We configure [AudioRecord] with [MediaRecorder.AudioSource.VOICE_COMMUNICATION]
* so the platform's voice-call AEC pipeline is in play, and additionally try
* to attach [AcousticEchoCanceler] + [NoiseSuppressor] keyed to the ExoPlayer
* audio session id so TTS audio is cancelled from the mic stream specifically.
* to attach [AcousticEchoCanceler] + [NoiseSuppressor] to the capture
* [AudioRecord] session. Android audio preprocessors belong to the capture
* path; a playback session is not a valid attachment target for AEC/NS.
* Without AEC, the device's own speaker output would trip the VAD the moment
* TTS started and we'd interrupt ourselves.
*
* The ExoPlayer audio session id is not stable at the moment we want to start
* listening — Media3 allocates the underlying AudioTrack lazily on first
* playback, and callers may hit [start] before that's happened (e.g. the very
* first sentence of a turn). We poll [audioSessionIdProvider] for up to 1 s
* before giving up on AEC and proceeding with the mic-hardware AEC alone.
* See the `AEC_SESSION_POLL_*` constants below.
*
* ### Graceful degradation
*
* - `AudioRecord.getState() != STATE_INITIALIZED` → log WARN, emit nothing,
@@ -93,8 +87,8 @@ import kotlin.math.max
class BargeInListener internal constructor(
private val audioSource: AudioFrameSource,
private val vadEngine: VadEngine,
private val audioSessionIdProvider: () -> Int,
private val readerDispatcher: CoroutineDispatcher = Dispatchers.IO,
private val nowMsProvider: () -> Long = System::currentTimeMillis,
) {
companion object {
@@ -108,12 +102,6 @@ class BargeInListener internal constructor(
* brief delay (GC pause, dispatcher contention). */
private const val AUDIO_BUFFER_FRAMES = 4
/** ExoPlayer may return `0` for its audio session id until its
* AudioTrack is first allocated (on playback start). Poll the
* provider briefly before giving up on AEC and proceeding without. */
private const val AEC_SESSION_POLL_INTERVAL_MS = 50L
private const val AEC_SESSION_POLL_TIMEOUT_MS = 1_000L
/**
* Factory for the production path. Builds an [AudioRecordSource] from
* a `Context` and wires it to the listener. The returned listener has
@@ -122,11 +110,9 @@ class BargeInListener internal constructor(
fun create(
context: Context,
vadEngine: VadEngine,
audioSessionIdProvider: () -> Int,
): BargeInListener = BargeInListener(
audioSource = AudioRecordSource(context.applicationContext),
vadEngine = vadEngine,
audioSessionIdProvider = audioSessionIdProvider,
)
}
@@ -239,9 +225,8 @@ class BargeInListener internal constructor(
return@launch
}
Log.i(TAG, "Barge-in AudioRecord reader started")
// Do not block generation-phase listening while waiting for an
// AudioTrack session that does not exist until playback. The
// effects attach races harmlessly beside the reader.
// Effects attach beside the reader so capture can begin even
// on devices that reject or omit the optional preprocessors.
effectsJob = launch { maybeAttachEffects() }
while (isActive) {
@@ -282,7 +267,7 @@ class BargeInListener internal constructor(
val gated = rmsGate.observe(
frame = frameBuffer,
rawSpeech = result.probability > 0f,
nowMs = System.currentTimeMillis(),
nowMs = nowMsProvider(),
playbackGraceMs = playbackGraceMs,
confirmedSpeech = result.isSpeech,
playbackActiveOverride = playbackActiveProvider?.invoke(),
@@ -368,14 +353,12 @@ class BargeInListener internal constructor(
}
private suspend fun maybeAttachEffects() {
val sessionId = awaitNonZeroSessionId()
val sessionId = audioSource.audioSessionId
if (sessionId == 0) {
Log.i(
TAG,
"AEC not attached — ExoPlayer audio session id was still 0 " +
"after ${AEC_SESSION_POLL_TIMEOUT_MS}ms poll; continuing " +
"without effects (mic-hardware AEC from VOICE_COMMUNICATION " +
"still in play)",
"AEC not attached — AudioRecord capture session id is 0; " +
"continuing without optional effects",
)
return
}
@@ -411,20 +394,6 @@ class BargeInListener internal constructor(
}
}
private suspend fun awaitNonZeroSessionId(): Int {
val immediate = audioSessionIdProvider()
if (immediate != 0) return immediate
var waited = 0L
while (waited < AEC_SESSION_POLL_TIMEOUT_MS) {
delay(AEC_SESSION_POLL_INTERVAL_MS)
waited += AEC_SESSION_POLL_INTERVAL_MS
val id = audioSessionIdProvider()
if (id != 0) return id
}
return 0
}
private fun releaseEffects() {
aec?.let {
runCatching { it.enabled = false }
@@ -445,6 +414,9 @@ class BargeInListener internal constructor(
* reader coroutine.
*/
internal interface AudioFrameSource {
/** Capture-session id used by Android audio preprocessors. */
val audioSessionId: Int
/**
* Allocate underlying native resources. Returns true on success.
* Returning false from here short-circuits the listener without any
@@ -481,6 +453,9 @@ class BargeInListener internal constructor(
private class AudioRecordSource(context: Context) : AudioFrameSource {
private var record: AudioRecord? = null
override val audioSessionId: Int
get() = record?.audioSessionId ?: 0
@SuppressLint("MissingPermission")
override fun initialize(): Boolean {
val sampleRate = 16_000
@@ -5,16 +5,24 @@ import android.provider.Settings
import android.util.Log
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.BrokerEndpoint
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.replaceHermesReachCredential
import com.hermesandroid.relay.data.sameBrokerAuthority
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.data.Profile
import com.hermesandroid.relay.data.isSafeProfileUiMeta
import com.hermesandroid.relay.network.relay.ChannelMultiplexer
import com.hermesandroid.relay.network.relay.models.Envelope
import com.hermesandroid.relay.network.shared.InvalidCredentialException
import com.hermesandroid.relay.network.shared.normalizeCredentialForHeader
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asSharedFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.launch
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
@@ -211,21 +219,47 @@ class AuthManager(
tokenStoreKey: String,
secrets: ConnectionAuthSecrets,
) {
val normalized = normalizeStoredSecrets(secrets)
withContext(Dispatchers.IO) {
val store = tokenStoreForBackup(context, tokenStoreKey)
writeOrRemove(store, KEY_SESSION_TOKEN, secrets.sessionToken)
writeOrRemove(store, KEY_REFRESH_TOKEN, secrets.refreshToken)
writeOrRemove(store, KEY_DEVICE_ID, secrets.deviceId)
writeOrRemove(store, KEY_API_KEY, secrets.apiKey)
writeOrRemove(store, KEY_SESSION_TOKEN, normalized.sessionToken)
writeOrRemove(store, KEY_REFRESH_TOKEN, normalized.refreshToken)
writeOrRemove(store, KEY_DEVICE_ID, normalized.deviceId)
writeOrRemove(store, KEY_API_KEY, normalized.apiKey)
writeOrRemove(
store,
KEY_PROFILE_API_KEYS,
secrets.profileApiKeys.takeIf { it.isNotEmpty() }?.let(::encodeProfileApiKeys),
normalized.profileApiKeys
.takeIf { it.isNotEmpty() }
?.let(::encodeProfileApiKeys),
)
writeOrRemove(store, KEY_PAIRED_META, secrets.pairedSessionMetaJson)
writeOrRemove(store, KEY_PAIRED_META, normalized.pairedSessionMetaJson)
}
}
/** Validate a backup fully before any existing encrypted state is replaced. */
fun validateStoredSecrets(secrets: ConnectionAuthSecrets) {
normalizeStoredSecrets(secrets)
}
private fun normalizeStoredSecrets(secrets: ConnectionAuthSecrets): ConnectionAuthSecrets =
secrets.copy(
sessionToken = secrets.sessionToken?.let {
normalizeCredentialForHeader(it, "Relay session credential")
}?.takeIf { it.isNotEmpty() },
refreshToken = secrets.refreshToken?.let {
normalizeCredentialForHeader(it, "Relay refresh credential")
}?.takeIf { it.isNotEmpty() },
apiKey = secrets.apiKey?.let {
normalizeCredentialForHeader(it, "API credential")
}?.takeIf { it.isNotEmpty() },
profileApiKeys = secrets.profileApiKeys
.mapValues { (_, value) ->
normalizeCredentialForHeader(value, "Profile API credential")
}
.filterValues { it.isNotEmpty() },
)
private fun tokenStoreForBackup(
context: Context,
tokenStoreKey: String,
@@ -281,6 +315,7 @@ class AuthManager(
?: return@mapNotNull null
val model = obj["model"]?.jsonPrimitive?.contentOrNull
?: "unknown"
val provider = obj["provider"]?.jsonPrimitive?.contentOrNull.orEmpty()
val description = obj["description"]?.jsonPrimitive?.contentOrNull
?: ""
val systemMessage = obj["system_message"]?.jsonPrimitive?.contentOrNull
@@ -300,9 +335,15 @@ class AuthManager(
?.jsonPrimitive?.intOrNull
val apiServerKeyPresent = obj["api_server_key_present"]
?.jsonPrimitive?.booleanOrNull ?: false
val isDefault = obj["is_default"]?.jsonPrimitive?.booleanOrNull ?: false
val hasAvatar = obj["has_avatar"]?.jsonPrimitive?.booleanOrNull ?: false
val uiMeta = (obj["ui_meta"] as? JsonObject)
?.takeIf(::isSafeProfileUiMeta)
?: JsonObject(emptyMap())
Profile(
name = name,
model = model,
provider = provider,
description = description,
systemMessage = systemMessage,
gatewayRunning = gatewayRunning,
@@ -313,6 +354,9 @@ class AuthManager(
apiServerHost = apiServerHost,
apiServerPort = apiServerPort,
apiServerKeyPresent = apiServerKeyPresent,
isDefault = isDefault,
hasAvatar = hasAvatar,
uiMeta = uiMeta,
)
}
}
@@ -558,6 +602,12 @@ class AuthManager(
* Either way, we leave the previously-persisted list untouched.
*/
private var pendingEndpoints: List<EndpointCandidate>? = null
private var activeEndpointProvider: () -> EndpointCandidate? = { null }
/** Bind auth.ok route credentials to the transport that actually carried them. */
fun setActiveEndpointProvider(provider: () -> EndpointCandidate?) {
activeEndpointProvider = provider
}
/**
* Server-advertised agent profiles from the `auth.ok` payload's
@@ -585,6 +635,8 @@ class AuthManager(
*/
private val _apiKeyPresent = MutableStateFlow(false)
val apiKeyPresent: StateFlow<Boolean> = _apiKeyPresent.asStateFlow()
private val _apiKeyError = MutableStateFlow<String?>(null)
val apiKeyError: StateFlow<String?> = _apiKeyError.asStateFlow()
init {
// Register as system channel handler for auth messages
@@ -604,19 +656,40 @@ class AuthManager(
val s = store()
val existingToken = s.getString(KEY_SESSION_TOKEN)
if (existingToken != null) {
_authState.value = AuthState.Paired(existingToken)
_currentPairedSession.value = loadStoredMetadata(existingToken)
Log.i(
TAG,
"init: hydrated existing session_token=${existingToken.take(8)}… " +
"→ authState=Paired (stale-at-startup unless this is a real continuous session)"
)
runCatching {
normalizeCredentialForHeader(existingToken, "Relay session credential")
.also { require(it.isNotEmpty()) }
}.onSuccess { normalized ->
if (normalized != existingToken) s.putString(KEY_SESSION_TOKEN, normalized)
_authState.value = AuthState.Paired(normalized)
_currentPairedSession.value = loadStoredMetadata(normalized)
Log.i(TAG, "init: hydrated existing session credential")
}.onFailure {
_authState.value = AuthState.Failed(
"Saved Relay credential is malformed. Re-pair this connection.",
)
Log.w(TAG, "init: rejected malformed saved Relay credential")
}
} else {
Log.i(TAG, "init: no stored session_token → authState stays Unpaired")
}
// Converge the plain api-key-present hint with the decrypted
// truth (also repairs a hint that predates legacy migration).
recordApiKeyHint(!s.getString(KEY_API_KEY).isNullOrBlank())
val storedApiKey = s.getString(KEY_API_KEY)
if (storedApiKey != null) {
runCatching {
normalizeCredentialForHeader(storedApiKey, "API credential")
.also { require(it.isNotEmpty()) }
}.onSuccess { normalized ->
if (normalized != storedApiKey) s.putString(KEY_API_KEY, normalized)
_apiKeyError.value = null
}.onFailure {
_apiKeyError.value =
"Saved API credential is malformed. Replace or clear it."
Log.w(TAG, "init: rejected malformed saved API credential")
}
}
recordApiKeyHint(!storedApiKey.isNullOrBlank())
}
}
}
@@ -793,10 +866,20 @@ class AuthManager(
val deviceId = getDeviceId()
val payload = when (currentState) {
is AuthState.Paired -> {
val refreshToken = store().getString(KEY_REFRESH_TOKEN)
val refreshToken = store().getString(KEY_REFRESH_TOKEN)?.let { raw ->
runCatching {
normalizeCredentialForHeader(raw, "Relay refresh credential")
}.getOrElse {
_authState.value = AuthState.Failed(
"Saved Relay credential is malformed. Re-pair this connection.",
)
Log.w(TAG, "authenticate: rejected malformed refresh credential")
return@launch
}
}
Log.i(
TAG,
"authenticate: sending session_token (state=Paired, token=${currentState.token.take(8)}…, " +
"authenticate: sending saved session credential (state=Paired, " +
"refresh=${!refreshToken.isNullOrBlank()})"
)
buildJsonObject {
@@ -984,10 +1067,26 @@ class AuthManager(
// --- API Key storage (for direct Hermes API Server auth) ---
suspend fun getApiKey(): String? = store().getString(KEY_API_KEY)
suspend fun getApiKey(): String? {
val raw = store().getString(KEY_API_KEY) ?: return null
return runCatching {
normalizeCredentialForHeader(raw, "API credential")
.takeIf { it.isNotEmpty() }
}.onSuccess {
_apiKeyError.value = null
}.onFailure {
_apiKeyError.value = "Saved API credential is malformed. Replace or clear it."
Log.w(TAG, "getApiKey: rejected malformed saved API credential")
}.getOrNull()
}
suspend fun setApiKey(key: String) {
val trimmed = key.trim()
val trimmed = runCatching {
normalizeCredentialForHeader(key, "API credential")
}.getOrElse {
_apiKeyError.value = "API credentials must be a single line."
throw it
}
val s = store()
if (trimmed.isBlank()) {
s.remove(KEY_API_KEY)
@@ -996,11 +1095,13 @@ class AuthManager(
s.putString(KEY_API_KEY, trimmed)
recordApiKeyHint(true)
}
_apiKeyError.value = null
}
suspend fun clearApiKey() {
store().remove(KEY_API_KEY)
recordApiKeyHint(false)
_apiKeyError.value = null
}
suspend fun getProfileApiKey(profileName: String): String? =
@@ -1012,7 +1113,7 @@ class AuthManager(
profileApiKeysMutex.withLock {
val tokenStore = store()
val keys = decodeProfileApiKeys(tokenStore.getString(KEY_PROFILE_API_KEYS)).toMutableMap()
val normalizedKey = key.trim()
val normalizedKey = normalizeCredentialForHeader(key, "Profile API credential")
if (normalizedKey.isBlank()) keys.remove(normalizedProfile)
else keys[normalizedProfile] = normalizedKey
if (keys.isEmpty()) tokenStore.remove(KEY_PROFILE_API_KEYS)
@@ -1031,7 +1132,10 @@ class AuthManager(
scope.launch {
try {
val payload = envelope.payload
val token = payload["session_token"]?.jsonPrimitive?.contentOrNull
val token = payload["session_token"]?.jsonPrimitive?.contentOrNull?.let { raw ->
normalizeCredentialForHeader(raw, "Relay session credential")
.takeIf { it.isNotEmpty() }
}
if (token == null) {
Log.w(
@@ -1042,18 +1146,20 @@ class AuthManager(
}
if (token != null) {
applyBrokerRouteCredential(payload)
val s = store()
s.putString(KEY_SESSION_TOKEN, token)
val refreshToken = payload["refresh_token"]
?.jsonPrimitive
?.contentOrNull
?.takeIf { it.isNotBlank() }
?.let { normalizeCredentialForHeader(it, "Relay refresh credential") }
?.takeIf { it.isNotEmpty() }
if (refreshToken != null) {
s.putString(KEY_REFRESH_TOKEN, refreshToken)
Log.i(TAG, "handleAuthOk: stored rotated refresh token")
}
_authState.value = AuthState.Paired(token)
Log.i(TAG, "handleAuthOk: Paired(token=${token.take(8)}…)")
Log.i(TAG, "handleAuthOk: paired with server-issued session credential")
// Per-connection signal for socket-scoped consumers (e.g.
// re-sending proactive.subscribe). Fires on every auth.ok.
_authOkEvents.tryEmit(Unit)
@@ -1146,10 +1252,56 @@ class AuthManager(
// handler is exactly why the broken `_sessionLabels` parser
// (stringifying object entries) sat undetected for so long.
Log.w(TAG, "auth.ok parse failed: ${e.message}", e)
if (e is InvalidCredentialException) {
_authState.value = AuthState.Failed(
"Relay returned a malformed credential. Re-pair this connection.",
)
}
}
}
}
private suspend fun applyBrokerRouteCredential(payload: JsonObject) {
val active = activeEndpointProvider()?.takeIf { it.hasHermesReach() } ?: return
val current = active.broker ?: return
// Fresh pairing is scoped by pendingEndpoints; reconnect rotation is
// accepted only by this connection-scoped AuthManager's live session.
if (pendingEndpoints == null && _authState.value !is AuthState.Paired) return
val credential = payload["route_credential"] as? JsonObject ?: return
if (credential["kind"]?.jsonPrimitive?.contentOrNull != "broker_route") return
val brokerUrl = credential["broker_url"]?.jsonPrimitive?.contentOrNull ?: return
val hostId = credential["host_id"]?.jsonPrimitive?.contentOrNull ?: return
if (!sameBrokerAuthority(brokerUrl, current.url) || hostId != current.hostId) {
Log.w(TAG, "Ignoring broker route credential that does not match the active paired route")
return
}
val replacement = BrokerEndpoint(
url = current.url,
protocolVersion = current.protocolVersion,
hostId = current.hostId,
credentialKind = "route",
token = credential["token"]?.jsonPrimitive?.contentOrNull?.let {
runCatching {
normalizeCredentialForHeader(it, "Hermes Reach credential")
}.getOrElse {
Log.w(TAG, "Ignoring malformed Hermes Reach route credential")
return
}
} ?: return,
expiresAt = credential["expires_at"]?.jsonPrimitive?.longOrNull,
)
val validated = active.copy(broker = replacement).takeIf { it.hasHermesReach() } ?: return
val deviceId = getDeviceId()
val source = pendingEndpoints
?: PairingPreferences.getDeviceEndpoints(context, deviceId).first()
val updated = replaceHermesReachCredential(source, current, validated)
if (updated == source) return
if (pendingEndpoints != null) pendingEndpoints = updated
else PairingPreferences.setDeviceEndpoints(context, deviceId, updated)
Log.i(TAG, "Accepted a durable Hermes Reach route credential for the active paired route")
}
private fun handleAuthFail(envelope: Envelope) {
try {
val rawReason = envelope.payload["reason"]?.jsonPrimitive?.contentOrNull
@@ -90,12 +90,28 @@ class CertPinStore(private val context: Context) {
if (pins.isEmpty()) return CertificatePinner.DEFAULT
val builder = CertificatePinner.Builder()
for ((hostPort, pin) in pins) {
val host = hostPort.substringBefore(':')
val host = hostPort.substringBeforeLast(':')
builder.add(host, pin)
}
return builder.build()
}
/**
* Build a pinner for one exact URL authority. CertificatePinner keys by
* hostname only, so adding every stored host:port entry to one client
* accidentally lets a pin learned on one port govern another port.
*/
fun buildPinnerSnapshotFor(url: String): CertificatePinner {
val hostPort = hostPortFromUrl(url) ?: return CertificatePinner.DEFAULT
val pin = getPinsBlocking()[hostPort] ?: return CertificatePinner.DEFAULT
val host = runCatching { URI(url.trim()).host }.getOrNull()
?.takeIf { it.isNotBlank() }
?: return CertificatePinner.DEFAULT
return CertificatePinner.Builder()
.add(host, pin)
.build()
}
/**
* Record a pin for a host. Called from the WebSocket listener's `onOpen`
* when we have a successful connection and can read the peer certs from
@@ -15,25 +15,22 @@ import androidx.core.app.NotificationManagerCompat
import androidx.core.content.ContextCompat
import com.hermesandroid.relay.MainActivity
import com.hermesandroid.relay.R
import com.hermesandroid.relay.accessibility.HermesAccessibilityService
/**
* Phase 3 — safety-rails `bridge-safety-rails`
*
* Canonical "turn the bridge off after idle" unit of work. Not a real
* Canonical timed-screen-expiry notification unit. Not a real
* `androidx.work.CoroutineWorker` — the project intentionally does not
* depend on androidx.work — but its shape mirrors one exactly: a single
* suspend [run] method that performs the work and returns.
*
* Why this pattern instead of dropping a WorkManager dep:
* - Auto-disable is a pure in-memory decision: the toggle lives in our
* own DataStore, no inter-process scheduling is required.
* - Capability expiry is persisted as absolute wall-clock timestamps;
* the in-process job exists only to prune promptly and notify.
* - Android's AlarmManager / WorkManager are needed when the work must
* survive process death. For bridge, process death already implies
* the service is disconnected and the master toggle re-evaluates
* fresh on the next launch. So a coroutine-owned `delay` does it.
* - Every command reschedules the timer, so the idle window is always
* reset against wall clock. No drift concerns.
* survive process death. Authorization itself does survive because the
* command boundary compares persisted expiry with the current clock.
* - Only timed screen inspection/control commands reset the timer.
*
* When WorkManager is added later (say, if notif-listener needs background-posted
* notifications on a schedule), this file is a natural upgrade point:
@@ -51,17 +48,10 @@ class AutoDisableWorker(private val context: Context) {
}
/**
* Execute the auto-disable: flip the master toggle off and post a
* one-shot "bridge paused" notification. Idempotent — safe to call
* twice (the second call just re-writes the same DataStore value
* and overrides the existing notification).
* Post a one-shot notification after timed screen authority is revoked.
* Idempotent — a repeated call replaces the existing notification.
*/
suspend fun run() {
try {
HermesAccessibilityService.setMasterEnabled(context, false)
} catch (t: Throwable) {
Log.w(TAG, "run: failed to flip master toggle", t)
}
postNotification()
}
@@ -92,8 +82,7 @@ class AutoDisableWorker(private val context: Context) {
.setContentTitle(context.getString(R.string.bridge_notification_auto_disabled_title))
.setContentText(context.getString(R.string.bridge_notification_auto_disabled_body))
.setStyle(NotificationCompat.BigTextStyle().bigText(
"Hermes bridge was idle for too long, so device control has been turned off " +
"automatically. Open the Bridge tab to turn it back on if you still need it."
context.getString(R.string.bridge_notification_auto_disabled_body)
))
.setContentIntent(tapPending)
.setAutoCancel(true)
@@ -115,7 +104,7 @@ class AutoDisableWorker(private val context: Context) {
CHANNEL_NAME,
NotificationManager.IMPORTANCE_DEFAULT,
).apply {
description = "Fires once when the bridge auto-disables after being idle."
description = "Fires once when timed Bridge screen access expires after idle."
setShowBadge(false)
}
nm.createNotificationChannel(channel)
@@ -0,0 +1,113 @@
package com.hermesandroid.relay.bridge
import kotlinx.serialization.Serializable
/** Stable, auditable authority groups for every phone-side Bridge command. */
@Serializable
enum class BridgeCapability(val wireId: String, val timed: Boolean) {
DEVICE_INFO("device_info", false),
CONTACTS_READ("contacts_read", false),
LOCATION_READ("location_read", false),
CLIPBOARD_READ("clipboard_read", false),
CLIPBOARD_WRITE("clipboard_write", false),
MEDIA_CONTROL("media_control", false),
COMMUNICATIONS("communications", false),
OUTBOUND_SHARING("outbound_sharing", false),
SCREEN_INSPECTION("screen_inspection", true),
SCREEN_CONTROL("screen_control", true),
}
enum class BridgeCapabilityGrant { EXEMPT, PERMANENT, TIMED }
data class BridgeCommandAuthority(
val capability: BridgeCapability? = null,
val grant: BridgeCapabilityGrant,
)
/**
* Closed command registry. Authorization is resolved from both path and HTTP
* method so method-split commands such as clipboard read/write cannot share a
* grant accidentally. Unknown paths and method combinations return null and
* must be denied by the command boundary.
*
* Composite Python tools (android_navigate/android_macro) do not get a broad
* grant: every primitive route they dispatch is checked here independently.
*/
object BridgeCommandRegistry {
private data class Key(val method: String, val path: String)
private fun permanent(capability: BridgeCapability) =
BridgeCommandAuthority(capability, BridgeCapabilityGrant.PERMANENT)
private fun timed(capability: BridgeCapability) =
BridgeCommandAuthority(capability, BridgeCapabilityGrant.TIMED)
private val exempt = BridgeCommandAuthority(grant = BridgeCapabilityGrant.EXEMPT)
private val routes: Map<Key, BridgeCommandAuthority> = buildMap {
fun route(method: String, path: String, authority: BridgeCommandAuthority) {
put(Key(method, path), authority)
}
route("GET", "/ping", exempt)
route("POST", "/setup", exempt)
route("POST", "/wait", exempt)
route("GET", "/current_app", permanent(BridgeCapability.DEVICE_INFO))
route("GET", "/get_apps", permanent(BridgeCapability.DEVICE_INFO))
route("GET", "/apps", permanent(BridgeCapability.DEVICE_INFO))
route("POST", "/search_contacts", permanent(BridgeCapability.CONTACTS_READ))
route("GET", "/location", permanent(BridgeCapability.LOCATION_READ))
route("GET", "/clipboard", permanent(BridgeCapability.CLIPBOARD_READ))
route("POST", "/clipboard", permanent(BridgeCapability.CLIPBOARD_WRITE))
route("POST", "/media", permanent(BridgeCapability.MEDIA_CONTROL))
route("POST", "/call", permanent(BridgeCapability.COMMUNICATIONS))
route("POST", "/send_sms", permanent(BridgeCapability.COMMUNICATIONS))
route("POST", "/share_media", permanent(BridgeCapability.OUTBOUND_SHARING))
route("POST", "/send_mms", permanent(BridgeCapability.OUTBOUND_SHARING))
listOf("/screen", "/screenshot", "/screen_hash", "/events").forEach {
route("GET", it, timed(BridgeCapability.SCREEN_INSPECTION))
}
listOf("/find_nodes", "/describe_node", "/diff_screen", "/events/stream").forEach {
route("POST", it, timed(BridgeCapability.SCREEN_INSPECTION))
}
listOf(
"/tap", "/tap_text", "/long_press", "/type", "/swipe", "/drag",
"/scroll", "/press_key", "/open_app", "/return_to_hermes",
"/send_intent", "/broadcast",
).forEach { route("POST", it, timed(BridgeCapability.SCREEN_CONTROL)) }
}
fun resolve(path: String, method: String): BridgeCommandAuthority? =
routes[Key(method.trim().uppercase(), path.trim())]
fun registeredRoutes(): Set<Pair<String, String>> =
routes.keys.mapTo(linkedSetOf()) { it.method to it.path }
}
@Serializable
data class BridgeCapabilityPolicy(
val schemaVersion: Int = CURRENT_SCHEMA_VERSION,
val permanentGrants: Set<BridgeCapability> = emptySet(),
val timedExpiriesMs: Map<BridgeCapability, Long> = emptyMap(),
) {
companion object {
const val CURRENT_SCHEMA_VERSION = 1
/** Explicit sentinel for a user-selected "Until turned off" lease. */
const val NEVER_EXPIRES_AT_MS: Long = Long.MAX_VALUE
}
fun allows(capability: BridgeCapability, nowMs: Long): Boolean =
if (capability.timed) {
(timedExpiriesMs[capability] ?: 0L) > nowMs
} else {
capability in permanentGrants
}
fun expiryFor(capability: BridgeCapability): Long? = timedExpiriesMs[capability]
fun isUnlimited(capability: BridgeCapability): Boolean =
timedExpiriesMs[capability] == NEVER_EXPIRES_AT_MS
}
@@ -4,6 +4,7 @@ import android.content.Context
import android.util.Log
import com.hermesandroid.relay.data.BridgeSafetyPreferencesRepository
import com.hermesandroid.relay.data.BridgeSafetySettings
import com.hermesandroid.relay.data.BridgeCapabilityPolicyRepository
import kotlinx.coroutines.CompletableDeferred
import kotlinx.coroutines.CoroutineScope
import kotlinx.coroutines.Dispatchers
@@ -14,6 +15,8 @@ import kotlinx.coroutines.delay
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.StateFlow
import kotlinx.coroutines.flow.asStateFlow
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.collectLatest
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.launch
import kotlinx.coroutines.plus
@@ -25,8 +28,8 @@ import java.util.concurrent.atomic.AtomicLong
/**
* Phase 3 — safety-rails `bridge-safety-rails`
*
* Central enforcement point for Tier 5 safety: per-app blocklist, destructive
* verb confirmation, and idle-based auto-disable. Owned as a singleton-per-
* Central enforcement point for Tier 5 safety: connection-scoped capabilities,
* per-app blocklist, destructive confirmation, and timed screen access. Owned as a singleton-per-
* process by [ConnectionViewModel] and injected into [BridgeCommandHandler].
*
* # Integration surface
@@ -47,9 +50,9 @@ import java.util.concurrent.atomic.AtomicLong
* reacts, which is exactly the UX we want (the server sees a slow
* response, not a denial race).
*
* - [rescheduleAutoDisable] — every accepted command bumps the idle timer
* forward; after [BridgeSafetySettings.autoDisableMinutes] of silence
* the master toggle flips off and a one-shot notification fires.
* - [rescheduleAutoDisable] — accepted timed screen commands bump the idle
* expiry forward; after [BridgeSafetySettings.autoDisableMinutes] of
* silence only timed screen authority is revoked and a notification fires.
* [cancelAutoDisable] cancels the pending timer (called when the master
* toggle flips off manually, so we don't race the timer against the
* user).
@@ -71,15 +74,14 @@ import java.util.concurrent.atomic.AtomicLong
* The Android app does not depend on androidx.work. [AutoDisableWorker]
* documents the canonical pattern, but the live path is a coroutine
* `Job` owned by this manager, delayed by the configured minutes. This is
* acceptable because we are the in-memory owner of the master-toggle flow
* — no inter-process or cross-restart scheduling is needed. On process
* death the master toggle is simply evaluated fresh from DataStore, and
* any command not explicitly sent within the idle window never actually
* happens because the app isn't running.
* acceptable because authorization stores an absolute expiry in DataStore.
* After process death or reconnect, the command boundary compares that expiry
* to wall clock and denies stale authority even if the notification job did not run.
*/
class BridgeSafetyManager(
context: Context,
private val scope: CoroutineScope,
private val activeConnectionId: StateFlow<String?>,
) {
companion object {
private const val TAG = "BridgeSafetyMgr"
@@ -94,10 +96,14 @@ class BridgeSafetyManager(
*/
fun peek(): BridgeSafetyManager? = INSTANCE
fun install(context: Context, scope: CoroutineScope): BridgeSafetyManager {
fun install(
context: Context,
scope: CoroutineScope,
activeConnectionId: StateFlow<String?>,
): BridgeSafetyManager {
val existing = INSTANCE
if (existing != null) return existing
val created = BridgeSafetyManager(context.applicationContext, scope)
val created = BridgeSafetyManager(context.applicationContext, scope, activeConnectionId)
INSTANCE = created
return created
}
@@ -105,6 +111,10 @@ class BridgeSafetyManager(
private val appContext: Context = context.applicationContext
private val prefsRepo = BridgeSafetyPreferencesRepository(appContext)
private val capabilityRepo = BridgeCapabilityPolicyRepository(appContext)
private val _activeCapabilityPolicy = MutableStateFlow(BridgeCapabilityPolicy())
val activeCapabilityPolicy: StateFlow<BridgeCapabilityPolicy> =
_activeCapabilityPolicy.asStateFlow()
/** Latest settings snapshot — UI + checks read this via [settings]. */
private val _settings = MutableStateFlow(BridgeSafetySettings())
@@ -140,12 +150,12 @@ class BridgeSafetyManager(
private val pendingConfirmations = ConcurrentHashMap<Long, PendingConfirmation>()
private val nextRequestId = AtomicLong(0L)
/** Coroutine job that fires auto-disable after idle. */
/** Coroutine job that prunes timed screen authority after idle. */
@Volatile
private var autoDisableJob: Job? = null
/**
* Remaining time (epoch millis) for the current auto-disable job, or
* Remaining time (epoch millis) for current timed screen authority, or
* null when idle. BridgeSafetySummaryCard reads this as a countdown.
*/
private val _autoDisableAtMs = MutableStateFlow<Long?>(null)
@@ -167,6 +177,100 @@ class BridgeSafetyManager(
trustedHydrated = true
}
}
scope.launch {
activeConnectionId.collectLatest { connectionId ->
schedulePersistedExpiry(connectionId)
capabilityRepo.policy(connectionId).collect { policy ->
_activeCapabilityPolicy.value = policy
}
}
}
}
data class CapabilityAuthorization(
val allowed: Boolean,
val authority: BridgeCommandAuthority? = null,
val errorCode: String? = null,
)
fun capabilityPolicy(connectionId: String?): Flow<BridgeCapabilityPolicy> =
capabilityRepo.policy(connectionId)
suspend fun authorizeCapability(
path: String,
method: String,
nowMs: Long = System.currentTimeMillis(),
): CapabilityAuthorization {
val authority = BridgeCommandRegistry.resolve(path, method)
?: return CapabilityAuthorization(false, errorCode = "unknown_bridge_command")
if (authority.grant == BridgeCapabilityGrant.EXEMPT) {
return CapabilityAuthorization(true, authority)
}
val connectionId = activeConnectionId.value
?: return CapabilityAuthorization(false, authority, "bridge_policy_unbound")
val capability = authority.capability
?: return CapabilityAuthorization(false, authority, "bridge_policy_invalid")
val policy = capabilityRepo.snapshot(connectionId)
return if (policy.allows(capability, nowMs)) {
CapabilityAuthorization(true, authority)
} else {
CapabilityAuthorization(
false,
authority,
if (capability.timed) "bridge_capability_expired" else "bridge_capability_denied",
)
}
}
suspend fun setPermanentCapability(
connectionId: String?,
capability: BridgeCapability,
allowed: Boolean,
) {
capabilityRepo.setPermanent(connectionId, capability, allowed)
}
suspend fun replacePermanentCapabilities(
connectionId: String?,
capabilities: Set<BridgeCapability>,
) {
capabilityRepo.replacePermanent(connectionId, capabilities)
}
suspend fun setTimedCapability(
connectionId: String?,
capability: BridgeCapability,
allowed: Boolean,
) {
if (!allowed) {
capabilityRepo.revoke(connectionId, capability)
if (capability == BridgeCapability.SCREEN_CONTROL) {
prefsRepo.setUnattendedAccessEnabled(false)
}
schedulePersistedExpiry(connectionId)
return
}
val fireAt = System.currentTimeMillis() + currentSettings().autoDisableMinutes * 60_000L
capabilityRepo.grantTimed(connectionId, capability, fireAt)
schedulePersistedExpiry(connectionId)
}
suspend fun replaceTimedCapabilities(
connectionId: String?,
capabilities: Set<BridgeCapability>,
durationMinutes: Int,
unlimited: Boolean = false,
) {
val fireAt = if (unlimited) {
BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS
} else {
System.currentTimeMillis() + durationMinutes * 60_000L
}
capabilityRepo.replaceTimed(connectionId, capabilities, fireAt)
if (BridgeCapability.SCREEN_CONTROL !in capabilities) {
prefsRepo.setUnattendedAccessEnabled(false)
}
schedulePersistedExpiry(connectionId)
}
// ── Blocklist ────────────────────────────────────────────────────────
@@ -307,26 +411,35 @@ class BridgeSafetyManager(
pending.deferred.complete(allowed)
}
// ── Auto-disable timer ───────────────────────────────────────────────
// ── Timed screen-access expiry ──────────────────────────────────────
/**
* Cancel any pending timer and arm a fresh one. Called on every accepted
* bridge command — an actively-used bridge never auto-disables.
* Refresh active timed grants and arm their shared idle expiry. Permanent
* capability activity never calls this method.
*/
fun rescheduleAutoDisable() {
val connectionId = activeConnectionId.value ?: return
val minutes = _settings.value.autoDisableMinutes
val delayMs = minutes * 60_000L
val fireAt = System.currentTimeMillis() + delayMs
val fireAt = System.currentTimeMillis() + minutes * 60_000L
autoDisableJob?.cancel()
_autoDisableAtMs.value = fireAt
autoDisableJob = (scope + SupervisorJob()).launch {
try {
val snapshot = capabilityRepo.snapshot(connectionId)
val nowMs = System.currentTimeMillis()
val finite = snapshot.timedExpiriesMs.filterValues {
it != BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS && it > nowMs
}
if (finite.isEmpty()) {
_autoDisableAtMs.value = null
return@launch
}
capabilityRepo.refreshActiveTimed(connectionId, fireAt)
_autoDisableAtMs.value = fireAt
val delayMs = (fireAt - System.currentTimeMillis()).coerceAtLeast(0L)
delay(delayMs)
Log.i(TAG, "Auto-disable fired after $minutes min of idle")
// Hand off to the canonical worker so both code paths look
// identical from a behavioral standpoint (notification +
// master-toggle flip).
Log.i(TAG, "Timed Bridge capabilities expired after $minutes min of idle")
capabilityRepo.pruneExpired(connectionId, System.currentTimeMillis())
clearUnattendedIfControlEnded(connectionId)
AutoDisableWorker(appContext).run()
} catch (_: Throwable) {
// Cancellation is expected on reschedule — swallow quietly.
@@ -342,6 +455,48 @@ class BridgeSafetyManager(
_autoDisableAtMs.value = null
}
fun revokeTimedCapabilities() {
val connectionId = activeConnectionId.value ?: return
cancelAutoDisable()
scope.launch {
capabilityRepo.revokeTimed(connectionId)
prefsRepo.setUnattendedAccessEnabled(false)
}
}
private suspend fun schedulePersistedExpiry(connectionId: String?) {
autoDisableJob?.cancel()
val policy = capabilityRepo.snapshot(connectionId)
val nextExpiry = policy.timedExpiriesMs.values
.filter { it != BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS }
.maxOrNull()
if (nextExpiry == null) {
_autoDisableAtMs.value = null
return
}
if (nextExpiry <= System.currentTimeMillis()) {
capabilityRepo.pruneExpired(connectionId, System.currentTimeMillis())
clearUnattendedIfControlEnded(connectionId)
_autoDisableAtMs.value = null
return
}
_autoDisableAtMs.value = nextExpiry
autoDisableJob = (scope + SupervisorJob()).launch {
delay((nextExpiry - System.currentTimeMillis()).coerceAtLeast(0L))
capabilityRepo.pruneExpired(connectionId, System.currentTimeMillis())
clearUnattendedIfControlEnded(connectionId)
AutoDisableWorker(appContext).run()
if (activeConnectionId.value == connectionId) _autoDisableAtMs.value = null
}
}
private suspend fun clearUnattendedIfControlEnded(connectionId: String?) {
val policy = capabilityRepo.snapshot(connectionId)
if (!policy.allows(BridgeCapability.SCREEN_CONTROL, System.currentTimeMillis())) {
prefsRepo.setUnattendedAccessEnabled(false)
}
}
// ── Internals ────────────────────────────────────────────────────────
/**
@@ -242,11 +242,9 @@ object UnattendedAccessManager {
* returns [WakeOutcome.Success] / [SuccessNoKeyguardChange] /
* [KeyguardBlocked] depending on the dismiss attempt outcome.
*
* The wake lock auto-releases via the platform's 30s timeout — we
* don't release explicitly per call because the bridge command may
* take several gestures to complete and we want one continuous
* wake-up, not a stutter. [release] is provided for the master
* toggle off path.
* The caller must pair each successful acquire with [releaseAfterAction].
* The platform's 30s timeout remains a crash/stall backstop, not the normal
* lifetime. Nested or concurrent commands share the ref-counted lock.
*
* # Compatibility shim
*
@@ -300,6 +298,22 @@ object UnattendedAccessManager {
return requestDismiss()
}
/** Release one command's ownership without disturbing concurrent actions. */
fun releaseAfterAction() {
synchronized(countLock) {
if (lockCount <= 0) return
lockCount -= 1
if (lockCount == 0) {
val lock = wakeLock ?: return
try {
if (lock.isHeld) lock.release()
} catch (t: Throwable) {
Log.w(TAG, "wakeLock.release threw: ${t.message}")
}
}
}
}
/**
* Synchronous keyguard dismiss attempt. Returns:
* - [WakeOutcome.SuccessNoKeyguardChange] when there's no keyguard
@@ -0,0 +1,182 @@
package com.hermesandroid.relay.data
import android.content.Context
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import com.hermesandroid.relay.bridge.BridgeCapability
import com.hermesandroid.relay.bridge.BridgeCapabilityPolicy
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.first
import kotlinx.coroutines.flow.map
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
import java.io.File
import java.util.UUID
/** Connection-scoped Bridge authority. Missing, malformed, or future schemas deny all. */
class BridgeCapabilityPolicyRepository(private val context: Context) {
companion object {
private val KEY_POLICIES = stringPreferencesKey("bridge_capability_policies_v1")
}
@Serializable
private data class StoredPolicies(
val schemaVersion: Int = BridgeCapabilityPolicy.CURRENT_SCHEMA_VERSION,
val installId: String = "",
val byConnection: Map<String, BridgeCapabilityPolicy> = emptyMap(),
)
private val json = Json { ignoreUnknownKeys = true; encodeDefaults = true }
private val installId: String = localInstallId(context)
fun policy(connectionId: String?): Flow<BridgeCapabilityPolicy> =
context.relayDataStore.data.map { prefs ->
readPolicies(prefs[KEY_POLICIES])[connectionId.normalizedPolicyKey()]
?.takeIf { it.schemaVersion == BridgeCapabilityPolicy.CURRENT_SCHEMA_VERSION }
?: BridgeCapabilityPolicy()
}
suspend fun snapshot(connectionId: String?): BridgeCapabilityPolicy =
policy(connectionId).first()
suspend fun setPermanent(connectionId: String?, capability: BridgeCapability, allowed: Boolean) {
require(!capability.timed) { "Timed capabilities require an expiry" }
update(connectionId) { current ->
current.copy(
permanentGrants = if (allowed) {
current.permanentGrants + capability
} else {
current.permanentGrants - capability
},
)
}
}
suspend fun replacePermanent(
connectionId: String?,
capabilities: Set<BridgeCapability>,
) {
require(capabilities.none { it.timed }) { "Timed capabilities require an expiry" }
update(connectionId) { current -> current.copy(permanentGrants = capabilities) }
}
suspend fun grantTimed(
connectionId: String?,
capability: BridgeCapability,
expiresAtMs: Long,
nowMs: Long = System.currentTimeMillis(),
) {
require(capability.timed) { "Permanent capabilities do not accept an expiry" }
update(connectionId) { current ->
current.copy(
timedExpiriesMs = (
current.timedExpiriesMs.filterValues { it > nowMs }.keys + capability
)
.associateWith { expiresAtMs },
)
}
}
suspend fun revoke(connectionId: String?, capability: BridgeCapability) {
update(connectionId) { current ->
current.copy(
permanentGrants = current.permanentGrants - capability,
timedExpiriesMs = current.timedExpiriesMs - capability,
)
}
}
suspend fun revokeTimed(connectionId: String?) {
update(connectionId) { it.copy(timedExpiriesMs = emptyMap()) }
}
suspend fun replaceTimed(
connectionId: String?,
capabilities: Set<BridgeCapability>,
expiresAtMs: Long,
) {
require(capabilities.all { it.timed }) { "Permanent capabilities cannot be timed" }
update(connectionId) { current ->
current.copy(timedExpiriesMs = capabilities.associateWith { expiresAtMs })
}
}
suspend fun refreshActiveTimed(connectionId: String?, expiresAtMs: Long) {
update(connectionId) { current ->
current.copy(
timedExpiriesMs = current.timedExpiriesMs.mapNotNull { (capability, currentExpiry) ->
when {
currentExpiry == BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS ->
capability to currentExpiry
currentExpiry > System.currentTimeMillis() -> capability to expiresAtMs
else -> null
}
}.toMap(),
)
}
}
suspend fun pruneExpired(connectionId: String?, nowMs: Long) {
update(connectionId) { current ->
current.copy(timedExpiriesMs = current.timedExpiriesMs.filterValues { it > nowMs })
}
}
suspend fun clearConnection(connectionId: String) {
val key = connectionId.normalizedPolicyKey()
context.relayDataStore.edit { prefs ->
val current = readPolicies(prefs[KEY_POLICIES]).toMutableMap()
current.remove(key)
prefs[KEY_POLICIES] = json.encodeToString(
StoredPolicies(installId = installId, byConnection = current),
)
}
}
private suspend fun update(
connectionId: String?,
transform: (BridgeCapabilityPolicy) -> BridgeCapabilityPolicy,
) {
val key = connectionId.normalizedPolicyKey()
context.relayDataStore.edit { prefs ->
val current = readPolicies(prefs[KEY_POLICIES]).toMutableMap()
current[key] = transform(current[key] ?: BridgeCapabilityPolicy())
prefs[KEY_POLICIES] = json.encodeToString(
StoredPolicies(installId = installId, byConnection = current),
)
}
}
private fun readPolicies(raw: String?): Map<String, BridgeCapabilityPolicy> {
if (raw.isNullOrBlank()) return emptyMap()
val stored = runCatching { json.decodeFromString<StoredPolicies>(raw) }.getOrNull()
?: return emptyMap()
if (stored.schemaVersion != BridgeCapabilityPolicy.CURRENT_SCHEMA_VERSION ||
stored.installId != installId
) return emptyMap()
return stored.byConnection
}
private fun String?.normalizedPolicyKey(): String =
this?.trim()?.takeIf { it.isNotEmpty() } ?: "__unbound__"
private fun localInstallId(context: Context): String {
val file = File(context.noBackupFilesDir, "bridge-policy-install-id")
return runCatching {
if (file.isFile) {
file.readText().trim().takeIf { it.isNotEmpty() }
} else {
null
} ?: UUID.randomUUID().toString().also { id ->
file.parentFile?.mkdirs()
file.writeText(id)
}
}.getOrElse {
// An unavailable no-backup fence must never make restored grants
// usable. This process-only value causes every persisted read to
// mismatch and therefore deny.
"unavailable-${UUID.randomUUID()}"
}
}
}
@@ -70,7 +70,11 @@ data class BridgeSettings(
class BridgePreferencesRepository(private val context: Context) {
companion object {
private val KEY_MASTER_ENABLED = booleanPreferencesKey("bridge_master_enabled")
// v2 is deliberately separate. Older APKs know only the legacy key
// and therefore remain disabled after a downgrade instead of treating
// the new granular grants as blanket authority.
private val KEY_MASTER_ENABLED = booleanPreferencesKey("bridge_master_enabled_v2")
private val KEY_LEGACY_MASTER_ENABLED = booleanPreferencesKey("bridge_master_enabled")
private val KEY_ACTIVITY_LOG = stringPreferencesKey("bridge_activity_log")
/** Hard cap on persisted entries. See file-level KDoc for rationale. */
@@ -99,7 +103,10 @@ class BridgePreferencesRepository(private val context: Context) {
}
suspend fun setMasterEnabled(enabled: Boolean) {
context.relayDataStore.edit { it[KEY_MASTER_ENABLED] = enabled }
context.relayDataStore.edit {
it[KEY_MASTER_ENABLED] = enabled
it[KEY_LEGACY_MASTER_ENABLED] = false
}
}
/**
@@ -29,10 +29,9 @@ import kotlinx.serialization.json.Json
* appear in `/tap_text` or `/type` payloads. Seeded with a set of verbs
* that carry irreversible or high-stakes consequences. Editable.
*
* - [autoDisableMinutes] — idle timeout after which the master toggle
* auto-flips to false. Rescheduled on every command so an active agent
* never triggers it; a runaway agent that stops sending commands for
* this long loses bridge access automatically.
* - [autoDisableMinutes] — idle timeout for timed screen inspection and
* control grants. Only accepted timed commands refresh it; permanent
* read/action grants neither expire nor keep screen authority alive.
*
* - [statusOverlayEnabled] — opt-in floating-dot indicator (like the
* screen-recording red dot) that's visible while bridge is active.
@@ -1,9 +1,27 @@
package com.hermesandroid.relay.data
import java.io.File
import java.io.FileOutputStream
import java.security.MessageDigest
import java.util.Base64
import java.util.WeakHashMap
import java.nio.file.AtomicMoveNotSupportedException
import java.nio.file.Files
import java.nio.file.StandardCopyOption
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.MutableStateFlow
import kotlinx.coroutines.flow.distinctUntilChanged
import kotlinx.coroutines.flow.emitAll
import kotlinx.coroutines.flow.filter
import kotlinx.coroutines.flow.flow
import kotlinx.coroutines.flow.map
import kotlinx.coroutines.flow.MutableSharedFlow
import kotlinx.coroutines.sync.Mutex
import kotlinx.coroutines.sync.withLock
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.Json
/**
* Immutable owner of one composer draft.
@@ -86,15 +104,15 @@ data class ChatComposerDraft(
*/
interface ChatComposerDraftStore {
fun observe(key: ChatComposerDraftKey): Flow<ChatComposerDraft>
fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft
fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft)
fun update(
suspend fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft
suspend fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft)
suspend fun update(
key: ChatComposerDraftKey,
transform: (ChatComposerDraft) -> ChatComposerDraft,
)
fun remove(key: ChatComposerDraftKey)
fun removeSession(connectionId: String, profileId: String, sessionId: String)
fun clear()
suspend fun remove(key: ChatComposerDraftKey)
suspend fun removeSession(connectionId: String, profileId: String, sessionId: String)
suspend fun clear()
}
class InMemoryChatComposerDraftStore : ChatComposerDraftStore {
@@ -105,43 +123,370 @@ class InMemoryChatComposerDraftStore : ChatComposerDraftStore {
.map { it[key] ?: ChatComposerDraft() }
.distinctUntilChanged()
override fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft =
override suspend fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft =
drafts.value[key] ?: ChatComposerDraft()
@Synchronized
override fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft) {
val normalized = draft.normalized()
drafts.value = if (normalized.isEmpty) {
drafts.value - key
} else {
drafts.value + (key to normalized)
override suspend fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft) {
synchronized(drafts) {
val normalized = draft.normalized()
drafts.value = if (normalized.isEmpty) {
drafts.value - key
} else {
drafts.value + (key to normalized)
}
}
}
@Synchronized
override fun update(
override suspend fun update(
key: ChatComposerDraftKey,
transform: (ChatComposerDraft) -> ChatComposerDraft,
) {
save(key, transform(snapshot(key)))
}
@Synchronized
override fun remove(key: ChatComposerDraftKey) {
drafts.value = drafts.value - key
}
@Synchronized
override fun removeSession(connectionId: String, profileId: String, sessionId: String) {
drafts.value = drafts.value.filterKeys { key ->
key.connectionId != connectionId ||
key.profileId != profileId ||
key.sessionId != sessionId
override suspend fun remove(key: ChatComposerDraftKey) {
synchronized(drafts) {
drafts.value = drafts.value - key
}
}
@Synchronized
override fun clear() {
drafts.value = emptyMap()
override suspend fun removeSession(connectionId: String, profileId: String, sessionId: String) {
synchronized(drafts) {
drafts.value = drafts.value.filterKeys { key ->
key.connectionId != connectionId ||
key.profileId != profileId ||
key.sessionId != sessionId
}
}
}
override suspend fun clear() {
synchronized(drafts) {
drafts.value = emptyMap()
}
}
}
/**
* App-private durable composer storage.
*
* The caller supplies a directory under `noBackupFilesDir`: drafts survive
* process death and ordinary app exits but never enter Android cloud backup.
* Metadata stays small JSON while attachment bytes are content-addressed blobs,
* so typing does not repeatedly rewrite Base64 payloads.
*/
class PersistentChatComposerDraftStore(
private val root: File,
) : ChatComposerDraftStore {
private val mutex = Mutex()
private val updates = MutableSharedFlow<ChatComposerDraftKey>(extraBufferCapacity = 64)
private val json = Json { ignoreUnknownKeys = true; encodeDefaults = true }
private val draftsDir = File(root, "drafts")
private val blobsDir = File(root, "blobs")
private val contentBlobIds = WeakHashMap<String, String>()
override fun observe(key: ChatComposerDraftKey): Flow<ChatComposerDraft> = flow {
emit(snapshot(key))
emitAll(
updates
.filter { it == key }
.map { snapshot(key) }
.distinctUntilChanged(),
)
}.distinctUntilChanged()
override suspend fun snapshot(key: ChatComposerDraftKey): ChatComposerDraft = withContext(Dispatchers.IO) {
mutex.withLock { readDraft(key) }
}
override suspend fun save(key: ChatComposerDraftKey, draft: ChatComposerDraft) {
withContext(Dispatchers.IO) {
mutex.withLock {
val normalized = draft.normalized()
if (normalized.isEmpty) {
draftFile(key).delete()
} else {
ensureDirectories()
val persisted = normalized.toPersisted(key)
atomicWrite(
draftFile(key),
json.encodeToString(PersistedDraft.serializer(), persisted)
.toByteArray(Charsets.UTF_8),
)
}
pruneAndCollect(except = key)
}
}
updates.tryEmit(key)
}
override suspend fun update(
key: ChatComposerDraftKey,
transform: (ChatComposerDraft) -> ChatComposerDraft,
) {
withContext(Dispatchers.IO) {
mutex.withLock {
val normalized = transform(readDraft(key)).normalized()
if (normalized.isEmpty) {
draftFile(key).delete()
} else {
ensureDirectories()
atomicWrite(
draftFile(key),
json.encodeToString(
PersistedDraft.serializer(),
normalized.toPersisted(key),
).toByteArray(Charsets.UTF_8),
)
}
pruneAndCollect(except = key)
}
}
updates.tryEmit(key)
}
override suspend fun remove(key: ChatComposerDraftKey) {
withContext(Dispatchers.IO) {
mutex.withLock {
draftFile(key).delete()
collectOrphanBlobs()
}
}
updates.tryEmit(key)
}
override suspend fun removeSession(connectionId: String, profileId: String, sessionId: String) {
val removed = mutableListOf<ChatComposerDraftKey>()
withContext(Dispatchers.IO) {
mutex.withLock {
draftFiles().forEach { file ->
val persisted = readPersisted(file) ?: return@forEach
val key = persisted.key.toDomain()
if (
key.connectionId == connectionId &&
key.profileId == profileId &&
key.sessionId == sessionId
) {
file.delete()
removed += key
}
}
collectOrphanBlobs()
}
}
removed.forEach(updates::tryEmit)
}
override suspend fun clear() {
withContext(Dispatchers.IO) {
mutex.withLock {
root.listFiles().orEmpty().forEach(File::deleteRecursively)
contentBlobIds.clear()
}
}
}
private fun ChatComposerDraft.toPersisted(key: ChatComposerDraftKey): PersistedDraft =
PersistedDraft(
key = PersistedKey.from(key),
text = text,
selectionStart = selectionStart,
selectionEnd = selectionEnd,
quotedMessageId = context.quotedMessageId,
editingMessageId = context.editingMessageId,
attachments = attachments.mapNotNull(::persistAttachment),
savedAtEpochMs = System.currentTimeMillis(),
)
private fun persistAttachment(attachment: Attachment): PersistedAttachment? {
val rawBytes = attachment.composerRawText
?.takeIf { attachment.isLargePaste }
?.toByteArray(Charsets.UTF_8)
val cachedBlobId = if (rawBytes == null) contentBlobIds[attachment.content] else null
val cachedBlob = cachedBlobId?.let { File(blobsDir, "$it.blob") }
if (cachedBlobId != null && cachedBlob?.exists() == true) {
return attachment.toPersistedAttachment(cachedBlobId)
}
val bytes = rawBytes
?: runCatching { Base64.getDecoder().decode(attachment.content) }.getOrNull()
?: return null
if (bytes.isEmpty()) return null
val blobId = sha256(bytes)
val blob = File(blobsDir, "$blobId.blob")
if (!blob.exists()) atomicWrite(blob, bytes)
if (rawBytes == null) contentBlobIds[attachment.content] = blobId
return attachment.toPersistedAttachment(blobId)
}
private fun Attachment.toPersistedAttachment(blobId: String): PersistedAttachment =
PersistedAttachment(
contentType = contentType,
blobId = blobId,
fileName = fileName,
fileSize = fileSize,
sensitive = sensitive,
isLargePaste = isLargePaste,
composerId = composerId,
)
private fun readDraft(key: ChatComposerDraftKey): ChatComposerDraft {
val persisted = readPersisted(draftFile(key)) ?: return ChatComposerDraft()
if (persisted.key.toDomain() != key) return ChatComposerDraft()
return ChatComposerDraft(
text = persisted.text,
selectionStart = persisted.selectionStart,
selectionEnd = persisted.selectionEnd,
context = ChatComposerDraftContext(
quotedMessageId = persisted.quotedMessageId,
editingMessageId = persisted.editingMessageId,
),
attachments = persisted.attachments.mapNotNull { attachment ->
val blob = File(blobsDir, "${attachment.blobId}.blob")
val bytes = runCatching { blob.readBytes() }.getOrNull()
?.takeIf(ByteArray::isNotEmpty) ?: return@mapNotNull null
val content = Base64.getEncoder().encodeToString(bytes)
contentBlobIds[content] = attachment.blobId
Attachment(
contentType = attachment.contentType,
content = content,
fileName = attachment.fileName,
fileSize = attachment.fileSize ?: bytes.size.toLong(),
sensitive = attachment.sensitive,
isLargePaste = attachment.isLargePaste,
composerId = attachment.composerId,
)
},
).normalized()
}
private fun readPersisted(file: File): PersistedDraft? = runCatching {
json.decodeFromString(PersistedDraft.serializer(), file.readText(Charsets.UTF_8))
}.getOrNull()
private fun pruneAndCollect(except: ChatComposerDraftKey) {
val exceptFile = draftFile(except)
val candidates = draftFiles()
.filterNot { it == exceptFile }
.sortedBy(File::lastModified)
candidates
.take((draftFiles().size - MAX_DRAFTS).coerceAtLeast(0))
.forEach { it.delete() }
collectOrphanBlobs()
for (oldest in candidates) {
if (blobsDir.listFiles().orEmpty().sumOf(File::length) <= MAX_BLOB_BYTES) break
if (oldest.exists()) {
oldest.delete()
collectOrphanBlobs()
}
}
}
private fun collectOrphanBlobs() {
val referenced = draftFiles()
.mapNotNull(::readPersisted)
.flatMap { draft -> draft.attachments.map(PersistedAttachment::blobId) }
.toSet()
blobsDir.listFiles().orEmpty()
.filter { it.isFile && it.extension == "blob" && it.nameWithoutExtension !in referenced }
.forEach(File::delete)
}
private fun ensureDirectories() {
check(draftsDir.exists() || draftsDir.mkdirs()) { "Could not create composer draft directory" }
check(blobsDir.exists() || blobsDir.mkdirs()) { "Could not create composer blob directory" }
}
private fun draftFiles(): List<File> = draftsDir.listFiles().orEmpty()
.filter { it.isFile && it.extension == "json" }
private fun draftFile(key: ChatComposerDraftKey): File =
File(draftsDir, "${sha256(key.storageIdentity().toByteArray(Charsets.UTF_8))}.json")
private fun atomicWrite(target: File, bytes: ByteArray) {
target.parentFile?.let { parent ->
check(parent.exists() || parent.mkdirs()) { "Could not create composer storage directory" }
}
val temporary = File(target.parentFile, ".${target.name}.${System.nanoTime()}.tmp")
try {
FileOutputStream(temporary).use { output ->
output.write(bytes)
output.fd.sync()
}
try {
Files.move(
temporary.toPath(),
target.toPath(),
StandardCopyOption.ATOMIC_MOVE,
StandardCopyOption.REPLACE_EXISTING,
)
} catch (_: AtomicMoveNotSupportedException) {
Files.move(
temporary.toPath(),
target.toPath(),
StandardCopyOption.REPLACE_EXISTING,
)
}
} finally {
temporary.delete()
}
}
private fun ChatComposerDraftKey.storageIdentity(): String =
listOf(connectionId, profileId, sessionId, draftId).joinToString("\u0000")
private fun sha256(bytes: ByteArray): String = MessageDigest.getInstance("SHA-256")
.digest(bytes)
.joinToString("") { byte -> "%02x".format(byte) }
companion object {
private const val MAX_DRAFTS = 64
private const val MAX_BLOB_BYTES = 128L * 1024L * 1024L
}
}
@Serializable
private data class PersistedDraft(
val key: PersistedKey,
val text: String,
val selectionStart: Int,
val selectionEnd: Int,
val quotedMessageId: String? = null,
val editingMessageId: String? = null,
val attachments: List<PersistedAttachment> = emptyList(),
val savedAtEpochMs: Long,
)
@Serializable
private data class PersistedKey(
val connectionId: String,
val profileId: String,
val sessionId: String,
val draftId: String,
) {
fun toDomain(): ChatComposerDraftKey = ChatComposerDraftKey(
connectionId = connectionId,
profileId = profileId,
sessionId = sessionId,
draftId = draftId,
)
companion object {
fun from(key: ChatComposerDraftKey): PersistedKey = PersistedKey(
connectionId = key.connectionId,
profileId = key.profileId,
sessionId = key.sessionId,
draftId = key.draftId,
)
}
}
@Serializable
private data class PersistedAttachment(
val contentType: String,
val blobId: String,
val fileName: String? = null,
val fileSize: Long? = null,
val sensitive: Boolean = false,
val isLargePaste: Boolean = false,
val composerId: String? = null,
)
@@ -3,6 +3,7 @@ package com.hermesandroid.relay.data
import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.booleanPreferencesKey
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.stringPreferencesKey
import kotlinx.coroutines.flow.Flow
@@ -30,6 +31,8 @@ class ChatInputPreferencesRepository(
companion object {
internal val KEY_PHYSICAL_KEYBOARD_ENTER =
stringPreferencesKey("physical_keyboard_enter_behavior")
internal val KEY_CONVERT_LARGE_PASTES =
booleanPreferencesKey("convert_large_pastes_to_attachments")
}
val physicalKeyboardEnterBehavior: Flow<PhysicalKeyboardEnterBehavior> = dataStore.data
@@ -40,9 +43,19 @@ class ChatInputPreferencesRepository(
}
.distinctUntilChanged()
val convertLargePastesToAttachments: Flow<Boolean> = dataStore.data
.map { preferences -> preferences[KEY_CONVERT_LARGE_PASTES] ?: true }
.distinctUntilChanged()
suspend fun setPhysicalKeyboardEnterBehavior(behavior: PhysicalKeyboardEnterBehavior) {
dataStore.edit { preferences ->
preferences[KEY_PHYSICAL_KEYBOARD_ENTER] = behavior.storedValue
}
}
suspend fun setConvertLargePastesToAttachments(enabled: Boolean) {
dataStore.edit { preferences ->
preferences[KEY_CONVERT_LARGE_PASTES] = enabled
}
}
}
@@ -0,0 +1,44 @@
package com.hermesandroid.relay.data
import java.util.Base64
const val LARGE_PASTE_THRESHOLD_CHARS = 5_000
data class TextTransportAttachments(
val message: String,
val attachments: List<Attachment>,
)
fun largePasteAttachment(text: String, composerId: String? = null): Attachment {
val bytes = text.toByteArray(Charsets.UTF_8)
return Attachment(
contentType = "text/plain; charset=utf-8",
content = Base64.getEncoder().encodeToString(bytes),
fileName = "pasted-text.txt",
fileSize = bytes.size.toLong(),
isLargePaste = true,
composerId = composerId,
)
}
fun prepareTextTransportAttachments(
message: String,
attachments: List<Attachment>,
): TextTransportAttachments {
val largePastes = attachments.filter(Attachment::isLargePaste)
if (largePastes.isEmpty()) return TextTransportAttachments(message, attachments)
val materialized = largePastes.mapNotNull { attachment ->
runCatching {
val text = String(Base64.getDecoder().decode(attachment.content), Charsets.UTF_8)
val name = attachment.fileName?.takeIf(String::isNotBlank) ?: "pasted text"
"--- $name ---\n$text"
}.getOrNull()
}
return TextTransportAttachments(
message = (listOf(message) + materialized)
.filter(String::isNotBlank)
.joinToString("\n\n"),
attachments = attachments.filterNot(Attachment::isLargePaste),
)
}
@@ -141,6 +141,18 @@ data class ChatMessage(
* through `copy`, while [id] remains the authoritative lookup/wire id.
*/
val uiKey: String = id,
/**
* Durable Gateway transcript row identity for rewind/edit-regenerate.
* This is server-owned and can change after a truncating rewrite; it is
* never used as a Compose key or synthesized client-side.
*/
val rowId: Long? = null,
/**
* Durable iOS-style tapbacks attached to this server message. Hermes keeps
* one reaction per author in the message's display metadata; the UI also
* updates this list optimistically while a reaction write is in flight.
*/
val reactions: List<MessageReaction> = emptyList(),
/**
* Mixture-of-Agents advisor responses surfaced during the live turn.
* Unavailable advisors retain only neutral state, never their raw failure
@@ -150,6 +162,29 @@ data class ChatMessage(
val moaReferences: List<MoaReference> = emptyList(),
)
data class MessageReaction(
val emoji: String,
val author: String,
/** Epoch seconds, matching the Gateway/Desktop contract. */
val at: Double,
)
/** Apply Hermes' one-reaction-per-author, re-tap-to-retract semantics. */
internal fun applyMessageReaction(
reactions: List<MessageReaction>,
emoji: String?,
author: String = "user",
at: Double = System.currentTimeMillis() / 1000.0,
): List<MessageReaction> {
val previous = reactions.firstOrNull { it.author == author }
val withoutAuthor = reactions.filterNot { it.author == author }
return if (emoji.isNullOrBlank() || previous?.emoji == emoji) {
withoutAuthor
} else {
withoutAuthor + MessageReaction(emoji = emoji, author = author, at = at)
}
}
data class MoaReference(
val index: Int,
val count: Int?,
@@ -293,7 +328,13 @@ data class Attachment(
* existing outbound/inbound call site stays valid and unflagged media
* renders exactly as before.
*/
val sensitive: Boolean = false
val sensitive: Boolean = false,
/** Local composer metadata; never serialized onto the Hermes wire. */
val isLargePaste: Boolean = false,
/** Stable id for an asynchronous composer preparation; never sent to Hermes. */
val composerId: String? = null,
/** Raw UTF-8 text retained only while a large-paste attachment is preparing. */
val composerRawText: String? = null,
) {
val isImage: Boolean get() = contentType.startsWith("image/")
@@ -406,6 +447,11 @@ data class ChatSession(
val title: String?,
val model: String?,
val messageCount: Int = 0,
val inputTokens: Int = 0,
val outputTokens: Int = 0,
val actualCostUsd: Double? = null,
val estimatedCostUsd: Double? = null,
val isActive: Boolean = false,
val updatedAt: Long = 0L,
val startedAt: Long = 0L,
val lastActivityAt: Long = 0L,
@@ -421,7 +467,21 @@ data class ChatSession(
/** Durable upstream session metadata, scoped by the owning connection/profile DB. */
val pinned: Boolean = false,
val archived: Boolean = false,
/** Optional newer-upstream workspace context; absent on legacy/API-only hosts. */
val workingDirectory: String? = null,
val gitBranch: String? = null,
val gitRepoRoot: String? = null,
val pullRequestNumber: Int? = null,
val pullRequestUrl: String? = null,
val pullRequestState: String? = null,
val pullRequestDraft: Boolean = false,
) {
val totalTokens: Int
get() = inputTokens + outputTokens
val costUsd: Double
get() = actualCostUsd ?: estimatedCostUsd ?: 0.0
val activityTimestamp: Long
get() = firstPositive(lastActivityAt, updatedAt, startedAt)
@@ -129,6 +129,7 @@ data class ChatTurnAskCheckpoint(
val requestId: String? = null,
val text: String,
val choices: List<String>? = null,
val multiSelect: Boolean = false,
val smartDenied: Boolean = false,
val envVar: String? = null,
val timeoutSeconds: Int,
@@ -14,6 +14,9 @@ data class DashboardConnectionStatus(
val gatewayTicketAvailable: Boolean? = null,
val message: String? = null,
val gatewayMode: String? = null,
/** Profiles positively advertised by the live multiplex gateway. */
val servedProfiles: List<String> = emptyList(),
/** Installed profiles reported by the dashboard; never routing authority. */
val profiles: List<String> = emptyList(),
)
@@ -63,12 +63,8 @@ fun EndpointCandidate?.isEncryptedOverlayRoute(isTailscaleDetected: Boolean): Bo
val hint = security.orEmpty().lowercase()
return r == "tailscale" ||
(isTailscaleDetected && hint.contains("tailscale")) ||
r == "plugin_proxy" ||
r == "plugin-proxy" ||
hasSecureProxy() ||
hint.contains("wireguard") ||
hint.contains("https") ||
hint.contains("tls")
(!hasSecureProxy() && (hint.contains("https") || hint.contains("tls")))
}
/** Human label for the overlay mechanism encrypting a route. */
@@ -78,7 +74,6 @@ fun EndpointCandidate?.overlayMechanism(isTailscaleDetected: Boolean): String {
val hint = security.orEmpty().lowercase()
return when {
r == "tailscale" || (isTailscaleDetected && hint.contains("tailscale")) -> "Tailscale"
r == "plugin_proxy" || r == "plugin-proxy" || hasSecureProxy() -> "Proxy"
hint.contains("wireguard") -> "WireGuard"
hint.contains("https") || hint.contains("tls") -> "TLS"
else -> "Encrypted"
@@ -92,7 +87,10 @@ fun classifySurfaceSecurity(
activeEndpoint: EndpointCandidate?,
isTailscaleDetected: Boolean,
): SurfaceSecurity {
val secureLinkProtected = activeEndpoint.secureLinkProtects(label, url)
val (kind, mechanism) = when {
secureLinkProtected -> SurfaceSecurityKind.Tls to
if (activeEndpoint?.hasHermesReach() == true) "Hermes Reach" else "Hermes Secure Link"
isTlsUrl(url) -> SurfaceSecurityKind.Tls to "TLS"
activeEndpoint.isEncryptedOverlayRoute(isTailscaleDetected) ->
SurfaceSecurityKind.Overlay to activeEndpoint.overlayMechanism(isTailscaleDetected)
@@ -101,6 +99,33 @@ fun classifySurfaceSecurity(
return SurfaceSecurity(label = label, kind = kind, mechanism = mechanism, url = url)
}
private fun EndpointCandidate?.secureLinkProtects(label: String, url: String): Boolean {
val candidate = this ?: return false
val routes = candidate.proxy?.takeIf { candidate.hasSecureProxy() }
?.let { proxy ->
val base = proxy.url.trim().trimEnd('/')
Triple(
"$base/dashboard",
"$base/api",
"wss://${base.substringAfter("://")}/relay/ws",
)
} ?: return false
val normalized = url.trim().trimEnd('/')
val service = when (label) {
"Chat & Manage" -> "dashboard"
"API / sessions" -> "api"
"Relay tools" -> "relay"
else -> return false
}
if (service !in candidate.secureLinkServices()) return false
val expected = when (service) {
"dashboard" -> routes.first
"api" -> routes.second
else -> routes.third
}
return normalized.equals(expected, ignoreCase = true)
}
/**
* Roll up the per-surface verdicts into one connection-level [ConnectionSecurity].
* Pure + side-effect free so it is unit-testable without Android.
@@ -172,6 +172,11 @@ class DataManager(
suspend fun restoreConnectionBackup(backup: AppBackup) {
val store = connectionStore ?: return
// Validate every credential before deleting or replacing any current
// encrypted state. A malformed/hostile backup fails atomically.
backup.connectionSecrets.forEach { secret ->
AuthManager.validateStoredSecrets(secret.auth)
}
deleteSensitivePreferenceFiles()
store.replaceConnections(
connections = backup.connections,
@@ -45,8 +45,13 @@ data class EndpointCandidate(
val relay: RelayEndpoint? = null,
val dashboard: DashboardEndpoint? = null,
val proxy: ProxyEndpoint? = null,
/** Optional outbound rendezvous carrying the pinned [proxy] byte stream. */
val broker: BrokerEndpoint? = null,
val security: String? = null,
val recommended: Boolean = false,
val experimental: Boolean = false,
@SerialName("display_name")
val displayName: String? = null,
)
/**
@@ -110,6 +115,27 @@ data class ProxyEndpoint(
val transportHint: String? = null,
@SerialName("pin_sha256")
val pinSha256: String? = null,
/** Independently authenticated services carried by this pinned origin. */
val surfaces: List<String> = listOf("relay"),
)
/**
* Hermes Reach rendezvous metadata from an operator-reviewed pairing payload.
* The token authenticates only this broker route; Hermes service credentials
* remain inside the QR-pinned Secure Link TLS connection.
*/
@Serializable
data class BrokerEndpoint(
val url: String,
@SerialName("protocol_version")
val protocolVersion: Int = 1,
@SerialName("host_id")
val hostId: String,
@SerialName("credential_kind")
val credentialKind: String,
val token: String,
@SerialName("expires_at")
val expiresAt: Long? = null,
)
/**
@@ -123,7 +149,7 @@ data class ProxyEndpoint(
*/
fun EndpointCandidate.isKnownRole(): Boolean {
return when (role.lowercase()) {
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "https" -> true
"lan", "tailscale", "public", "plugin_proxy", "plugin-proxy", "outbound_broker", "https" -> true
else -> false
}
}
@@ -146,7 +172,8 @@ fun EndpointCandidate.displayLabel(): String {
"Public"
}
"https" -> "HTTPS"
"plugin_proxy", "plugin-proxy" -> "Plugin proxy"
"plugin_proxy", "plugin-proxy" -> "Hermes Secure Link"
"outbound_broker", "broker", "relay_broker" -> "Hermes Reach · Experimental"
else -> "Custom VPN ($role)"
}
}
@@ -177,7 +204,69 @@ fun EndpointCandidate.routeAuthority(): String? {
}
fun EndpointCandidate.hasSecureProxy(): Boolean =
proxy?.url?.startsWith("https://", ignoreCase = true) == true ||
proxy?.url?.startsWith("wss://", ignoreCase = true) == true ||
role.equals("plugin_proxy", ignoreCase = true) ||
role.equals("plugin-proxy", ignoreCase = true)
proxy?.isValidPinnedProxy() == true
/** Product-facing service inventory; wire identifiers remain unchanged. */
fun EndpointCandidate.secureLinkServices(): List<String> =
if (!hasSecureProxy()) emptyList() else proxy.orEmptySurfaces()
fun EndpointCandidate.secureLinkCoversAllServices(): Boolean =
secureLinkServices().containsAll(listOf("relay", "api", "dashboard"))
fun EndpointCandidate.presentationRouteUrl(): String? =
broker?.url?.takeIf { hasHermesReach() } ?: proxy?.url?.takeIf { hasSecureProxy() } ?: primaryRouteUrl()
fun EndpointCandidate.hasHermesReach(): Boolean =
role.lowercase() in setOf("outbound_broker", "broker", "relay_broker") &&
broker?.isValidHermesReach() == true && hasSecureProxy()
fun BrokerEndpoint.isValidHermesReach(): Boolean {
if (protocolVersion != 1 || !hostId.isCanonicalBase64Url(16) || !token.isCanonicalBase64Url(32)) return false
if (credentialKind !in setOf("bootstrap", "route")) return false
if (credentialKind == "bootstrap" && expiresAt?.let { it <= System.currentTimeMillis() / 1000L } == true) return false
val uri = runCatching { URI(url.trim()) }.getOrNull() ?: return false
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
return uri.rawPath.orEmpty().let { it.isEmpty() || it == "/" || it == "/v1/connect" }
}
private fun String.isCanonicalBase64Url(byteCount: Int): Boolean {
if (isBlank() || '=' in this) return false
val decoded = runCatching { java.util.Base64.getUrlDecoder().decode(this) }.getOrNull() ?: return false
return decoded.size == byteCount &&
java.util.Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == this
}
/** Exact host locator + broker authority replacement; never crosses devices. */
internal fun replaceHermesReachCredential(
source: List<EndpointCandidate>,
expected: BrokerEndpoint,
replacement: EndpointCandidate,
): List<EndpointCandidate> = source.map { candidate ->
if (candidate.broker?.hostId == expected.hostId &&
sameBrokerAuthority(candidate.broker.url, expected.url)
) replacement else candidate
}
internal fun sameBrokerAuthority(left: String, right: String): Boolean = runCatching {
val a = URI(left.trim())
val b = URI(right.trim())
fun port(uri: URI) = if (uri.port > 0) uri.port else 443
a.scheme.equals("wss", true) && b.scheme.equals("wss", true) &&
a.host.equals(b.host, true) && port(a) == port(b) &&
a.rawPath.orEmpty().trimEnd('/') == b.rawPath.orEmpty().trimEnd('/')
}.getOrDefault(false)
private fun ProxyEndpoint?.orEmptySurfaces(): List<String> = this?.surfaces.orEmpty()
.map { it.trim().lowercase() }
.filter { it in setOf("relay", "api", "dashboard") }
.distinct()
fun ProxyEndpoint.isValidPinnedProxy(): Boolean {
val uri = runCatching { URI(url.trim().trimEnd('/')) }.getOrNull() ?: return false
if (!uri.scheme.equals("https", ignoreCase = true) || uri.host.isNullOrBlank()) return false
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return false
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" }) return false
val pin = pinSha256?.trim()?.removePrefix("sha256/") ?: return false
return runCatching { java.util.Base64.getDecoder().decode(pin).size == 32 }.getOrDefault(false)
}
@@ -2,6 +2,8 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
/**
* A rich content card emitted inline in an assistant message via the
@@ -117,6 +119,8 @@ data class HermesCardInput(
val kind: String,
/** Quick-answer chips (clarify). Empty = no chip row. */
val choices: List<String> = emptyList(),
/** Choices toggle independently and require an explicit submit. */
val multiSelect: Boolean = false,
/** Render the inline free-text mini field under the chips. */
val allowFreeText: Boolean = false,
/** Password-style field: masked glyphs + reveal toggle (secret/sudo). */
@@ -124,7 +128,7 @@ data class HermesCardInput(
/** Submit is a 650ms hold-to-confirm press-fill instead of a tap (sudo). */
val holdToConfirm: Boolean = false,
/**
* Wall-clock expiry for timed asks (sudo 120s, clarify/secret 300s).
* Wall-clock expiry for asks with an advertised deadline.
* The renderer shows a countdown footer (Amber under 30s) and
* self-collapses to "Expired — not granted" past it. Null = no timeout
* (approval is session-scoped).
@@ -155,6 +159,10 @@ data class HermesCardInput(
}
}
/** Exact JSON-array wire value expected by upstream multi-select clarify. */
internal fun encodeClarifyMultiSelectAnswer(values: List<String>): String =
Json.encodeToString(values.map(String::trim).filter(String::isNotEmpty).distinct())
/**
* A label/value row inside a card. [value] is rendered as markdown so the
* agent can embed emphasis, inline code, or links.
@@ -34,6 +34,10 @@ data class ProactiveInboxEntry(
* field).
*/
val chatId: String? = null,
/** Owning saved connection. Null only for entries written by older builds. */
val connectionId: String? = null,
/** Relay proved this row came from its bounded offline queue. */
val arrivedWhileAway: Boolean = false,
)
private val Context.proactiveInboxStore: DataStore<Preferences> by
@@ -49,10 +53,10 @@ private const val MAX_ENTRIES = 100
* newest-first, deduped by id (so a re-delivered message doesn't double up), and
* capped at [MAX_ENTRIES]. Survives app restart.
*
* Demoted (2026-06-29): the agent conversation now lives as a Thread in Chat (the
* gateway session is the durable history), so the in-app inbox view is retired.
* This store is only fed for messages NOT shown in an open Thread; it currently
* has no viewer and is fully retireable — see TODO.
* Demoted (2026-06-29): once a phone gateway session exists, it is the durable
* history. Outbound agent messages arrive before that session exists, so this
* bounded store also backs the provisional Thread until the user's first reply
* promotes it to a real `source=phone` session.
*/
class ProactiveInboxRepository(private val context: Context) {
@@ -0,0 +1,125 @@
package com.hermesandroid.relay.data
import android.content.Context
import android.graphics.Bitmap
import android.graphics.BitmapFactory
import android.graphics.ImageDecoder
import android.net.Uri
import android.os.Build
import java.io.ByteArrayOutputStream
import kotlin.math.roundToInt
internal fun profileAvatarMime(bytes: ByteArray): String? = when {
bytes.size >= 8 && bytes.copyOfRange(0, 8).contentEquals(
byteArrayOf(0x89.toByte(), 0x50, 0x4e, 0x47, 0x0d, 0x0a, 0x1a, 0x0a),
) -> "image/png"
bytes.size >= 3 && bytes[0] == 0xff.toByte() && bytes[1] == 0xd8.toByte() &&
bytes[2] == 0xff.toByte() -> "image/jpeg"
bytes.size >= 12 && bytes.copyOfRange(0, 4).contentEquals("RIFF".toByteArray()) &&
bytes.copyOfRange(8, 12).contentEquals("WEBP".toByteArray()) -> "image/webp"
else -> null
}
/**
* Convert any image Android can decode into the small static format accepted by
* upstream `profiles.set_asset`. ImageDecoder applies camera EXIF orientation
* and downsamples before allocating the bitmap on current Android releases.
*/
internal fun prepareProfileAvatar(
context: Context,
uri: Uri,
maxBytes: Int,
): ByteArray? {
val original = runCatching {
context.contentResolver.openInputStream(uri)?.use { input ->
val output = ByteArrayOutputStream(minOf(maxBytes + 1, 64 * 1024))
val buffer = ByteArray(16 * 1024)
while (output.size() <= maxBytes) {
val read = input.read(buffer)
if (read < 0) break
output.write(buffer, 0, read)
}
output.toByteArray()
}
}.getOrNull()
if (original != null && original.size <= maxBytes && profileAvatarMime(original) != null) {
return original
}
val bitmap = decodeProfileAvatar(context, uri) ?: return null
return try {
encodeProfileAvatar(bitmap, maxBytes)
} finally {
bitmap.recycle()
}
}
private fun decodeProfileAvatar(context: Context, uri: Uri): Bitmap? = runCatching {
if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.P) {
ImageDecoder.decodeBitmap(ImageDecoder.createSource(context.contentResolver, uri)) { decoder, info, _ ->
decoder.allocator = ImageDecoder.ALLOCATOR_SOFTWARE
val width = info.size.width
val height = info.size.height
val longest = maxOf(width, height)
if (longest > PROFILE_AVATAR_MAX_DIMENSION) {
val scale = PROFILE_AVATAR_MAX_DIMENSION.toFloat() / longest
decoder.setTargetSize(
(width * scale).roundToInt().coerceAtLeast(1),
(height * scale).roundToInt().coerceAtLeast(1),
)
}
}
} else {
val bounds = BitmapFactory.Options().apply { inJustDecodeBounds = true }
context.contentResolver.openInputStream(uri)?.use { BitmapFactory.decodeStream(it, null, bounds) }
var sample = 1
while (maxOf(bounds.outWidth, bounds.outHeight) / sample > PROFILE_AVATAR_MAX_DIMENSION) sample *= 2
context.contentResolver.openInputStream(uri)?.use {
BitmapFactory.decodeStream(it, null, BitmapFactory.Options().apply { inSampleSize = sample })
}
}
}.getOrNull()
internal fun encodeProfileAvatar(bitmap: Bitmap, maxBytes: Int): ByteArray? {
var working = bitmap.scaledToFit(PROFILE_AVATAR_MAX_DIMENSION)
var ownsWorking = working !== bitmap
try {
while (true) {
val format = if (working.hasAlpha()) Bitmap.CompressFormat.PNG else Bitmap.CompressFormat.JPEG
val qualities = if (format == Bitmap.CompressFormat.PNG) intArrayOf(100) else intArrayOf(92, 82, 72, 62)
for (quality in qualities) {
val encoded = ByteArrayOutputStream().use { output ->
if (!working.compress(format, quality, output)) null else output.toByteArray()
}
if (encoded != null && encoded.size <= maxBytes) return encoded
}
if (maxOf(working.width, working.height) <= PROFILE_AVATAR_MIN_DIMENSION) return null
val next = Bitmap.createScaledBitmap(
working,
(working.width * 0.75f).roundToInt().coerceAtLeast(1),
(working.height * 0.75f).roundToInt().coerceAtLeast(1),
true,
)
if (ownsWorking) working.recycle()
working = next
ownsWorking = true
}
} finally {
if (ownsWorking) working.recycle()
}
}
private fun Bitmap.scaledToFit(maxDimension: Int): Bitmap {
val longest = maxOf(width, height)
if (longest <= maxDimension) return this
val scale = maxDimension.toFloat() / longest
return Bitmap.createScaledBitmap(
this,
(width * scale).roundToInt().coerceAtLeast(1),
(height * scale).roundToInt().coerceAtLeast(1),
true,
)
}
private const val PROFILE_AVATAR_MAX_DIMENSION = 1024
private const val PROFILE_AVATAR_MIN_DIMENSION = 128
@@ -2,6 +2,35 @@ package com.hermesandroid.relay.data
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.contentOrNull
internal fun isSafeProfileUiMeta(meta: JsonObject): Boolean {
if (meta.toString().toByteArray(Charsets.UTF_8).size > 65_536) return false
fun containsEmbeddedAsset(value: String): Boolean {
val compact = value.trim()
return compact.startsWith("data:image/", ignoreCase = true) ||
compact.startsWith("iVBORw0KGgo") || // PNG
compact.startsWith("/9j/") || // JPEG
compact.startsWith("UklGR") || // RIFF/WebP
compact.startsWith("R0lGOD") || // GIF
compact.startsWith("UEsDB") // ZIP/pet archive
}
fun safe(element: JsonElement): Boolean = when (element) {
is JsonObject -> element.size <= 128 && element.all { (key, value) ->
key.length <= 128 && safe(value)
}
is JsonArray -> element.size <= 128 && element.all(::safe)
is JsonPrimitive -> {
val value = element.contentOrNull
value == null || (value.length <= 4_096 && !containsEmbeddedAsset(value))
}
}
return safe(meta)
}
/**
* An agent profile advertised by a Hermes server in its `auth.ok` payload.
@@ -56,6 +85,7 @@ import kotlinx.serialization.Serializable
data class Profile(
val name: String,
val model: String,
val provider: String = "",
val description: String = "",
@SerialName("system_message")
val systemMessage: String? = null,
@@ -75,6 +105,12 @@ data class Profile(
val apiServerPort: Int? = null,
@SerialName("api_server_key_present")
val apiServerKeyPresent: Boolean = false,
@SerialName("is_default")
val isDefault: Boolean = false,
@SerialName("has_avatar")
val hasAvatar: Boolean = false,
@SerialName("ui_meta")
val uiMeta: JsonObject = JsonObject(emptyMap()),
) {
val hasIsolatedApi: Boolean
get() = !apiServerUrl.isNullOrBlank()
@@ -4,13 +4,15 @@ import android.content.Context
import androidx.datastore.core.DataStore
import androidx.datastore.preferences.core.Preferences
import androidx.datastore.preferences.core.edit
import androidx.datastore.preferences.core.booleanPreferencesKey
import androidx.datastore.preferences.core.stringPreferencesKey
import androidx.datastore.preferences.preferencesDataStore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.map
/**
* Local-only per-profile agent icons — the visual twin of [ProfileDisplayAliasStore].
* Per-profile icon cache. Local fallback paths and Hermes-owned avatar cache
* paths use separate keys so syncing either side never silently overwrites the other.
*
* Stores a **file path** to an image that was copied into app storage (not a SAF
* content URI, so it survives without a persistable-permission grant). Like the
@@ -25,6 +27,8 @@ class ProfileIconStore(
companion object {
private const val PREFIX = "profile_icon__"
private const val SERVER_PREFIX = "profile_avatar_server__"
private const val LOCAL_OVERRIDE_PREFIX = "profile_icon_override__"
private fun keyName(connectionId: String, profileName: String?): String =
"$PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}"
@@ -34,6 +38,20 @@ class ProfileIconStore(
private fun connectionPrefix(connectionId: String): String =
"$PREFIX${connectionId}__"
private fun serverKeyFor(connectionId: String, profileName: String) =
stringPreferencesKey("$SERVER_PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}")
private fun serverConnectionPrefix(connectionId: String): String =
"$SERVER_PREFIX${connectionId}__"
private fun localOverrideKeyFor(connectionId: String, profileName: String?) =
booleanPreferencesKey(
"$LOCAL_OVERRIDE_PREFIX${connectionId}__${AgentDisplay.profileSessionKey(profileName)}",
)
private fun localOverrideConnectionPrefix(connectionId: String): String =
"$LOCAL_OVERRIDE_PREFIX${connectionId}__"
}
suspend fun setIcon(connectionId: String, profileName: String?, path: String?) {
@@ -52,11 +70,39 @@ class ProfileIconStore(
return dataStore.data.map { prefs -> prefs[key] }
}
suspend fun setServerAvatar(connectionId: String, profileName: String, path: String?) {
dataStore.edit { prefs ->
val key = serverKeyFor(connectionId, profileName)
if (path.isNullOrBlank()) prefs.remove(key) else prefs[key] = path
}
}
fun serverAvatarFlow(connectionId: String, profileName: String): Flow<String?> {
val key = serverKeyFor(connectionId, profileName)
return dataStore.data.map { prefs -> prefs[key] }
}
suspend fun setLocalOverride(connectionId: String, profileName: String?, enabled: Boolean) {
dataStore.edit { prefs ->
val key = localOverrideKeyFor(connectionId, profileName)
if (enabled) prefs[key] = true else prefs.remove(key)
}
}
fun localOverrideFlow(connectionId: String, profileName: String?): Flow<Boolean> {
val key = localOverrideKeyFor(connectionId, profileName)
return dataStore.data.map { prefs -> prefs[key] ?: false }
}
suspend fun clearConnection(connectionId: String) {
val prefix = connectionPrefix(connectionId)
val prefixes = listOf(
connectionPrefix(connectionId),
serverConnectionPrefix(connectionId),
localOverrideConnectionPrefix(connectionId),
)
dataStore.edit { prefs ->
prefs.asMap().keys
.filter { it.name.startsWith(prefix) }
.filter { key -> prefixes.any(key.name::startsWith) }
.forEach { prefs.remove(it) }
}
}
@@ -66,5 +112,11 @@ class ProfileIconStore(
}
}
internal fun preferredProfileIcon(
server: String?,
local: String?,
useLocalOverride: Boolean,
): String? = if (useLocalOverride && !local.isNullOrBlank()) local else server ?: local
internal val Context.profileIconsDataStore: DataStore<Preferences>
by preferencesDataStore(name = "profile_icons")
@@ -136,3 +136,154 @@ data class ProfileMemoryUpdateResponse(
@SerialName("bytes_written")
val bytesWritten: Long,
)
/** Authoritative upstream `profiles.describe` snapshot. */
data class GatewayProfileDescription(
val name: String,
val description: String,
val soul: String,
val provider: String,
val model: String,
val skills: List<GatewayProfileSkill>,
val toolsets: List<GatewayProfileToolset>,
val toolsetsPinned: Boolean,
)
data class GatewayProfileSkill(val name: String, val enabled: Boolean)
data class GatewayProfileToolset(
val name: String,
val description: String,
val toolCount: Int,
val enabled: Boolean,
)
enum class GatewayProfileSection(val wireName: String) {
Description("description"),
Soul("soul"),
Model("model"),
Skills("skills"),
Toolsets("toolsets"),
McpServers("mcp_servers"),
UiMeta("ui_meta"),
}
/** Null leaves a section unchanged; empty lists retain upstream replace semantics. */
data class GatewayProfilePatch(
val description: String? = null,
val soul: String? = null,
val provider: String? = null,
val model: String? = null,
val disabledSkills: List<String>? = null,
val enabledToolsets: List<String>? = null,
val enabledMcpServers: List<String>? = null,
/** Small interoperable preferences only; binary assets belong in profiles.set_asset. */
val uiMeta: JsonObject? = null,
) {
val requestedSections: Set<GatewayProfileSection>
get() = buildSet {
if (description != null) add(GatewayProfileSection.Description)
if (soul != null) add(GatewayProfileSection.Soul)
if (provider != null && model != null) add(GatewayProfileSection.Model)
if (disabledSkills != null) add(GatewayProfileSection.Skills)
if (enabledToolsets != null) add(GatewayProfileSection.Toolsets)
if (enabledMcpServers != null) add(GatewayProfileSection.McpServers)
if (uiMeta != null) add(GatewayProfileSection.UiMeta)
}
}
enum class GatewayProfileAuthChoice {
/** Share the launch profile's refreshable OAuth/token store; copy static environment keys. */
Shared,
/** Copy the current credential snapshot into a separate profile-owned store. */
Copied,
/** Copy no credentials or provider defaults. */
Isolated,
}
data class GatewayProfileCreateRequest(
val name: String,
val description: String? = null,
val cloneFrom: String? = null,
val cloneAll: Boolean = false,
val noSkills: Boolean = false,
val soul: String? = null,
val model: String? = null,
val provider: String? = null,
val authChoice: GatewayProfileAuthChoice = GatewayProfileAuthChoice.Shared,
)
data class GatewayProfileCreateResult(
val name: String,
val soulWritten: Boolean,
val modelSet: Boolean,
val mirroredEnvironment: Boolean,
val mirroredAuth: String?,
val modelInherited: Boolean,
val voiceMirrored: Boolean,
) {
fun partialMessages(request: GatewayProfileCreateRequest): List<String> = buildList {
if (!request.soul.isNullOrBlank() && !soulWritten) add("SOUL was not saved")
if (!request.model.isNullOrBlank() && !modelSet) add("model was not saved")
if (request.authChoice == GatewayProfileAuthChoice.Shared && mirroredAuth != "shared") {
add("shared sign-in was not confirmed")
}
if (
request.authChoice == GatewayProfileAuthChoice.Copied &&
!mirroredEnvironment && mirroredAuth != "true"
) {
add("no credential source was copied")
}
}
}
data class GatewayProfileAsset(
val data: ByteArray,
val mime: String,
)
class GatewayProfileManagementUnsupportedException(
operation: String,
) : Exception("$operation is not supported by this gateway")
data class GatewayProfileConfigureResult(
val requested: Set<GatewayProfileSection>,
val applied: Set<GatewayProfileSection>,
) {
val failed: Set<GatewayProfileSection> get() = requested - applied
}
interface GatewayProfileEditorClient {
suspend fun describeProfile(profileName: String): Result<GatewayProfileDescription>
suspend fun configureProfile(
profileName: String,
patch: GatewayProfilePatch,
): Result<GatewayProfileConfigureResult>
}
class GatewayProfileEditorUnsupportedException : Exception(
"Profile editing is not supported by this gateway",
)
/** Relay fallback retained for older gateways and Relay-only memory files. */
interface LegacyProfileInspectorClient {
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse>
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse>
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse>
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse>
suspend fun updateSoul(profileName: String, content: String): Result<ProfileSoulUpdateResponse>
suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
): Result<ProfileMemoryUpdateResponse>
suspend fun updateSkillToggle(skillName: String, enabled: Boolean): Result<RelaySkillToggleResult>
suspend fun probeSkillToggleSupported(): Boolean
}
sealed interface RelaySkillToggleResult {
data object Ok : RelaySkillToggleResult
data object NotImplemented : RelaySkillToggleResult
}
@@ -9,6 +9,7 @@ import androidx.datastore.preferences.preferencesDataStore
import kotlinx.coroutines.flow.Flow
import kotlinx.coroutines.flow.map
import kotlinx.serialization.builtins.ListSerializer
import kotlinx.serialization.builtins.MapSerializer
import kotlinx.serialization.builtins.serializer
import kotlinx.serialization.json.Json
@@ -16,6 +17,8 @@ import kotlinx.serialization.json.Json
data class ProfilePresentation(
val order: List<String> = emptyList(),
val hidden: Set<String> = emptySet(),
/** Local-only named-profile accent overrides, stored as normalized RGB hex. */
val colors: Map<String, String> = emptyMap(),
)
/**
@@ -63,14 +66,17 @@ class ProfilePresentationStore(
private val json = Json { ignoreUnknownKeys = true }
private val listSerializer = ListSerializer(String.serializer())
private val mapSerializer = MapSerializer(String.serializer(), String.serializer())
private fun orderKey(connectionId: String) = stringPreferencesKey("order_$connectionId")
private fun hiddenKey(connectionId: String) = stringPreferencesKey("hidden_$connectionId")
private fun colorsKey(connectionId: String) = stringPreferencesKey("colors_$connectionId")
fun presentationFlow(connectionId: String): Flow<ProfilePresentation> = dataStore.data.map { prefs ->
ProfilePresentation(
order = decode(prefs[orderKey(connectionId)]),
hidden = decode(prefs[hiddenKey(connectionId)]).toSet(),
colors = decodeMap(prefs[colorsKey(connectionId)]),
)
}
@@ -82,10 +88,18 @@ class ProfilePresentationStore(
dataStore.edit { it[hiddenKey(connectionId)] = json.encodeToString(listSerializer, hidden.sorted()) }
}
suspend fun setColors(connectionId: String, colors: Map<String, String>) {
dataStore.edit {
if (colors.isEmpty()) it.remove(colorsKey(connectionId))
else it[colorsKey(connectionId)] = json.encodeToString(mapSerializer, colors.toSortedMap())
}
}
suspend fun clear(connectionId: String) {
dataStore.edit {
it.remove(orderKey(connectionId))
it.remove(hiddenKey(connectionId))
it.remove(colorsKey(connectionId))
}
}
@@ -98,6 +112,12 @@ class ProfilePresentationStore(
} else {
runCatching { json.decodeFromString(listSerializer, raw) }.getOrDefault(emptyList())
}
private fun decodeMap(raw: String?): Map<String, String> = if (raw == null) {
emptyMap()
} else {
runCatching { json.decodeFromString(mapSerializer, raw) }.getOrDefault(emptyMap())
}
}
internal val Context.profilePresentationDataStore: DataStore<Preferences>
@@ -258,6 +258,7 @@ class BridgeCommandHandler(
private val pendingActivities =
java.util.concurrent.ConcurrentHashMap<String, PendingActivity>()
private val unattendedWakeRequests = java.util.concurrent.ConcurrentHashMap.newKeySet<String>()
// === END v0.4.1 polish ===
private val json = Json {
@@ -302,6 +303,8 @@ class BridgeCommandHandler(
put("error", t.message ?: "unknown executor error")
}
)
} finally {
releaseUnattendedWake(requestId)
}
}
}
@@ -396,6 +399,8 @@ class BridgeCommandHandler(
errorCode = "dispatch_exception",
resultJson = null,
)
} finally {
releaseUnattendedWake(requestId)
}
val resultJson = sink.get()
@@ -421,6 +426,54 @@ class BridgeCommandHandler(
method: String,
body: JsonObject,
) {
// Resolve path + method through the closed capability registry before
// any wake, confirmation, event read, executor, or run-tracker effect.
val registeredAuthority =
com.hermesandroid.relay.bridge.BridgeCommandRegistry.resolve(path, method)
val capabilityAuthorization = when {
registeredAuthority == null -> BridgeSafetyManager.CapabilityAuthorization(
allowed = false,
errorCode = "unknown_bridge_command",
)
!BuildFlavor.isSideload && registeredAuthority.grant !=
com.hermesandroid.relay.bridge.BridgeCapabilityGrant.EXEMPT ->
BridgeSafetyManager.CapabilityAuthorization(
allowed = false,
authority = registeredAuthority,
errorCode = "device_control_sideload_only",
)
registeredAuthority.grant ==
com.hermesandroid.relay.bridge.BridgeCapabilityGrant.EXEMPT ->
BridgeSafetyManager.CapabilityAuthorization(true, registeredAuthority)
else -> safetyManager?.authorizeCapability(path, method)
?: BridgeSafetyManager.CapabilityAuthorization(
allowed = false,
authority = registeredAuthority,
errorCode = "bridge_policy_unavailable",
)
}
if (!capabilityAuthorization.allowed) {
return respond(
requestId,
403,
buildJsonObject {
put(
"error",
if (capabilityAuthorization.errorCode == "device_control_sideload_only") {
"Device Control is not included in the Google Play build."
} else {
"Bridge capability is not granted for this connection."
},
)
put("error_code", capabilityAuthorization.errorCode ?: "bridge_capability_denied")
capabilityAuthorization.authority?.capability?.let {
put("capability", it.wireId)
}
put("required_action", "Review Bridge > Safety & capabilities on the phone")
},
)
}
// === v0.4.1 polish: keep auto-return idle timer alive ===
// Any non-polling bridge command during a run is evidence the
// agent is still working — reset BridgeRunTracker's idle timer
@@ -475,44 +528,6 @@ class BridgeCommandHandler(
return
}
// === PHASE3-event-stream: B1 android_events read-only polling ===
// /events is a read-only peek at the EventStore ring buffer. The
// buffer lives in our own process so there's no safety gate —
// the agent already opted into streaming via /events/stream
// which IS gated. This mirrors the /ping early-return path so
// polling works even when the service is transiently unbound.
if (path == "/events") {
val limitRaw = body["limit"]?.jsonPrimitive?.content?.toIntOrNull() ?: 50
val limit = limitRaw.coerceIn(1, EventStore.MAX_ENTRIES)
val since = body["since"]?.jsonPrimitive?.content?.toLongOrNull() ?: 0L
val entries = EventStore.recent(limit = limit, since = since)
val arr: JsonArray = buildJsonArray {
for (e in entries) {
add(
buildJsonObject {
put("timestamp", e.timestamp)
put("event_type", e.eventType)
e.packageName?.let { put("package_name", it) }
e.className?.let { put("class_name", it) }
e.text?.let { put("text", it) }
e.contentDescription?.let { put("content_description", it) }
put("source", e.source)
}
)
}
}
respond(
requestId, 200,
buildJsonObject {
put("entries", arr)
put("count", entries.size)
put("streaming", EventStore.isStreaming)
}
)
return
}
// === END PHASE3-event-stream ===
// /setup exists on the relay as a legacy bridge HTTP route, but
// android_setup() in plugin/tools/android_tool.py is host-side
// only (it just writes ANDROID_BRIDGE_TOKEN to ~/.hermes/.env)
@@ -576,10 +591,7 @@ class BridgeCommandHandler(
}
)
if (!service.isMasterEnabled() &&
path != "/current_app" &&
path != "/return_to_hermes"
) {
if (!service.isMasterEnabled()) {
// Crystal-clear error text + structured error_code. Bailey hit
// 2026-04-15: when the phone was paired + a11y granted but
// master toggle flipped off, the agent read the shorter
@@ -649,9 +661,13 @@ class BridgeCommandHandler(
}
}
// Reschedule the idle auto-disable timer on every accepted
// command. Safe to call even when no timer is currently armed.
safetyManager?.rescheduleAutoDisable()
// Permanent capabilities never keep screen control armed. Only an
// accepted timed inspection/control command refreshes the timer.
if (capabilityAuthorization.authority?.grant ==
com.hermesandroid.relay.bridge.BridgeCapabilityGrant.TIMED
) {
safetyManager?.rescheduleAutoDisable()
}
// === END PHASE3-safety-rails ===
// === v0.4.1 unattended-access wake + keyguard dismiss ===
@@ -673,6 +689,9 @@ class BridgeCommandHandler(
if (!isReadOnlyRoute) {
val outcome = runCatching { UnattendedAccessManager.acquireForAction() }
.getOrDefault(UnattendedAccessManager.WakeOutcome.Disabled)
if (outcome != UnattendedAccessManager.WakeOutcome.Disabled) {
unattendedWakeRequests += requestId
}
if (outcome == UnattendedAccessManager.WakeOutcome.KeyguardBlocked) {
respond(
requestId, 423,
@@ -705,6 +724,30 @@ class BridgeCommandHandler(
val executor = service.actionExecutor
when (path) {
"/events" -> {
val limitRaw = body["limit"]?.jsonPrimitive?.content?.toIntOrNull() ?: 50
val limit = limitRaw.coerceIn(1, EventStore.MAX_ENTRIES)
val since = body["since"]?.jsonPrimitive?.content?.toLongOrNull() ?: 0L
val entries = EventStore.recent(limit = limit, since = since)
val arr: JsonArray = buildJsonArray {
for (e in entries) {
add(buildJsonObject {
put("timestamp", e.timestamp)
put("event_type", e.eventType)
e.packageName?.let { put("package_name", it) }
e.className?.let { put("class_name", it) }
e.text?.let { put("text", it) }
e.contentDescription?.let { put("content_description", it) }
put("source", e.source)
})
}
}
respond(requestId, 200, buildJsonObject {
put("entries", arr)
put("count", entries.size)
put("streaming", EventStore.isStreaming)
})
}
"/current_app" -> respond(
requestId, 200,
buildJsonObject {
@@ -2417,6 +2460,12 @@ class BridgeCommandHandler(
}
multiplexer.send(envelope)
}
private fun releaseUnattendedWake(requestId: String) {
if (unattendedWakeRequests.remove(requestId)) {
UnattendedAccessManager.releaseAfterAction()
}
}
}
// LocalDispatchResult moved to network.shared (ADR 34 fence): it is a passive
@@ -12,6 +12,7 @@ import com.hermesandroid.relay.auth.CertPinStore
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.data.PairingPreferences
import com.hermesandroid.relay.network.shared.pluginProxyRoutesOrNull
import com.hermesandroid.relay.diagnostics.DiagnosticCategory
import com.hermesandroid.relay.diagnostics.DiagnosticSeverity
import com.hermesandroid.relay.diagnostics.DiagnosticsLog
@@ -77,6 +78,9 @@ internal fun buildRelayRequestOrNull(url: String): Request? =
null
}
private fun EndpointCandidate.relayWebSocketUrl(): String? =
pluginProxyRoutesOrNull()?.relayWebSocketUrl ?: relay?.url
class ConnectionManager(
private val multiplexer: ChannelMultiplexer,
/**
@@ -142,6 +146,10 @@ class ConnectionManager(
private val deviceIdProvider: (suspend () -> String?)? = null,
/** Random source for ordinary reconnect full-jitter; exact backoffs never use it. */
private val reconnectJitterUnit: () -> Double = { kotlin.random.Random.nextDouble() },
/** Exact-authority pinned client for a plugin-proxy WSS URL. */
private val proxyClientProvider: ((String) -> OkHttpClient?)? = null,
/** Test seam for observing lifecycle teardown without opening a socket. */
private val okHttpClientFactory: (() -> OkHttpClient)? = null,
) {
private val supervisorJob = SupervisorJob()
private val scope = CoroutineScope(supervisorJob + Dispatchers.IO)
@@ -151,7 +159,8 @@ class ConnectionManager(
encodeDefaults = true
}
private fun buildClient(): OkHttpClient {
private fun buildClient(url: String? = null): OkHttpClient {
okHttpClientFactory?.let { return it() }
val builder = OkHttpClient.Builder()
// OkHttp's 10s default connectTimeout is LAN-tuned; a Tailscale
// DERP-relayed cold-start handshake can exceed it, and a failed
@@ -165,7 +174,9 @@ class ConnectionManager(
// that wipes a pin would still be subject to the pre-wipe rules.
certPinStore?.let { store ->
try {
builder.certificatePinner(store.buildPinnerSnapshot())
builder.certificatePinner(
url?.let(store::buildPinnerSnapshotFor) ?: store.buildPinnerSnapshot(),
)
} catch (e: Exception) {
Log.w(TAG, "CertificatePinner build failed: ${e.message}")
builder.certificatePinner(CertificatePinner.DEFAULT)
@@ -224,10 +235,12 @@ class ConnectionManager(
// Endpoints card in Settings.
private val _activeEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeEndpoint: StateFlow<EndpointCandidate?> = _activeEndpoint.asStateFlow()
private val _activeApiEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeApiEndpoint: StateFlow<EndpointCandidate?> = _activeApiEndpoint.asStateFlow()
/** Relay-only winner, deliberately separate from the standard route. */
@Volatile
private var activeRelayEndpoint: EndpointCandidate? = null
private val _activeRelayEndpoint = MutableStateFlow<EndpointCandidate?>(null)
val activeRelayEndpoint: StateFlow<EndpointCandidate?> = _activeRelayEndpoint.asStateFlow()
/**
* Manual role override. When non-null, the resolver's output is replaced
@@ -348,11 +361,14 @@ class ConnectionManager(
// behavior for freshly-upgraded installs and for v1/v2 QRs where
// the synthesized list just collapses to the same URL anyway.
scope.launch {
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val resolvedRelayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
val resolvedRelayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
val targetUrl = resolvedRelayUrl ?: url.takeIf { it.isNotBlank() }
activeRelayEndpoint = relayResolved
_activeRelayEndpoint.value = relayResolved
_activeApiEndpoint.value = apiResolved
if (resolved != null) {
_activeEndpoint.value = resolved
Log.i(TAG, "connect: standard resolver picked role=${resolved.role} " +
@@ -379,7 +395,7 @@ class ConnectionManager(
Log.i(
TAG,
"connect: relay resolver picked role=${relayRoute.role} " +
"url=${relayRoute.relay?.url}",
"url=${relayRoute.relayWebSocketUrl()}",
)
}
if (targetUrl != null) {
@@ -534,7 +550,8 @@ class ConnectionManager(
* for any reason we don't block the connect loop forever.
*/
suspend fun resolveBestEndpoint(): EndpointCandidate? =
resolveBestEndpointSafe(EndpointSurface.Standard)
resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
private suspend fun resolveBestEndpointSafe(
surface: EndpointSurface,
@@ -612,7 +629,9 @@ class ConnectionManager(
suspend fun probeAndReconnectNow(): EndpointCandidate? {
endpointResolver?.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
@@ -621,8 +640,9 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
if (relayResolved != null) activeRelayEndpoint = relayResolved
val targetUrl = relayResolved?.relay?.url ?: current ?: return resolved
_activeApiEndpoint.value = apiResolved
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val targetUrl = relayResolved?.relayWebSocketUrl() ?: current ?: return resolved
val normalizedTarget = normalizeRelayUrl(targetUrl)
// Reconnect when the winner changed, and also when the socket is
// stale/disconnected on the same winner. The latter makes the
@@ -659,7 +679,9 @@ class ConnectionManager(
*/
suspend fun refreshActiveEndpoint(clearProbeCache: Boolean = false): EndpointCandidate? {
if (clearProbeCache) endpointResolver?.clearCache()
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null && _connectionState.value == ConnectionState.Connected) {
// Transient probe miss while the relay socket is demonstrably up
// (slow resume, mid-handoff blip) — keep publishing the live
@@ -668,6 +690,7 @@ class ConnectionManager(
return _activeEndpoint.value
}
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
return resolved
}
@@ -684,7 +707,7 @@ class ConnectionManager(
fun getManualRoleOverride(): String? = _manualRoleOverride.value
private fun markActiveRelayEndpointUnreachable(reason: String) {
val active = activeRelayEndpoint ?: return
val active = _activeRelayEndpoint.value ?: return
endpointResolver?.markUnreachable(active, EndpointSurface.Relay)
Log.i(TAG, "marked endpoint role=${active.role} unreachable ($reason)")
}
@@ -710,7 +733,9 @@ class ConnectionManager(
// manages its own cache (clear + markUnreachable) and passes false.
if (wipeCache) endpointResolver.clearCache()
val current = serverUrl
val resolved = resolveBestEndpointSafe(EndpointSurface.Standard)
val resolved = resolveBestEndpointSafe(EndpointSurface.Dashboard)
?: resolveBestEndpointSafe(EndpointSurface.Standard)
val apiResolved = resolveBestEndpointSafe(EndpointSurface.Api)
if (resolved == null) {
// Hysteresis for the AUTOMATIC (network-callback) path. A
// transient cold-route probe miss must NOT null the published
@@ -747,6 +772,7 @@ class ConnectionManager(
}
sustainedLossDeclared = false
_activeEndpoint.value = resolved
_activeApiEndpoint.value = apiResolved
if (current == null) return@launch
// After an explicit disconnect() the route still publishes above
// (HTTP surfaces keep roaming), but no socket action: without
@@ -756,8 +782,8 @@ class ConnectionManager(
// the swap path never re-checked it.)
if (!shouldReconnect) return@launch
val relayResolved = resolveBestEndpointSafe(EndpointSurface.Relay)
if (relayResolved != null) activeRelayEndpoint = relayResolved
val relayUrl = relayResolved?.relay?.url?.takeIf { it.isNotBlank() }
if (relayResolved != null) _activeRelayEndpoint.value = relayResolved
val relayUrl = relayResolved?.relayWebSocketUrl()?.takeIf { it.isNotBlank() }
?: return@launch
if (isRelayRateLimitBackoffActive(
rateLimitBackoffUntilMs,
@@ -902,7 +928,8 @@ class ConnectionManager(
// the ViewModel on the next connection load.
_manualRoleOverride.value = null
_activeEndpoint.value = null
activeRelayEndpoint = null
_activeApiEndpoint.value = null
_activeRelayEndpoint.value = null
reconnectState.reset()
}
@@ -982,7 +1009,18 @@ class ConnectionManager(
// Every new socket starts unauthenticated — the send-gate stays closed
// (auth frame excepted) until this socket's own auth.ok arrives.
authenticated = false
client = buildClient()
val isPluginProxyUrl = _activeRelayEndpoint.value?.pluginProxyRoutesOrNull()
?.relayWebSocketUrl
?.equals(url, ignoreCase = true) == true
client = if (isPluginProxyUrl) {
proxyClientProvider?.invoke(url) ?: run {
Log.e(TAG, "Pinned plugin proxy client unavailable — refusing generic TLS fallback")
_connectionState.value = ConnectionState.Disconnected
return
}
} else {
buildClient(url)
}
val request = buildRelayRequestOrNull(url)
if (request == null) {
@@ -1240,7 +1278,7 @@ class ConnectionManager(
// during the retry window).
if (shouldReconnect && reconnectGate()) {
val resolved = resolveBestEndpointSafe(EndpointSurface.Relay)
val targetUrl = resolved?.relay?.url
val targetUrl = resolved?.relayWebSocketUrl()
if (resolved != null) {
// Mirror scheduleNetworkReResolve: clear the sustained-loss
// latch on a successful resolve so a later transient miss
@@ -1248,7 +1286,7 @@ class ConnectionManager(
// in onLost's grace job but can be cleared on EITHER success
// edge — network-callback or relay-timer.)
sustainedLossDeclared = false
activeRelayEndpoint = resolved
_activeRelayEndpoint.value = resolved
}
if (targetUrl != null && normalizeRelayUrl(targetUrl) != url) {
Log.i(TAG, "scheduleReconnect: switching $url → ${normalizeRelayUrl(targetUrl)}")
@@ -5,7 +5,9 @@ import android.util.Log
import com.hermesandroid.relay.network.relay.models.Envelope
import com.hermesandroid.relay.notifications.ProactiveMessageNotifier
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.booleanOrNull
import kotlinx.serialization.json.contentOrNull
import kotlinx.serialization.json.intOrNull
import kotlinx.serialization.json.jsonPrimitive
/**
@@ -50,7 +52,7 @@ class ProactiveMessageHandler(
/** Sink for the dedicated Hermes inbox (Phase 2a) — the always-present log. */
private val toInbox: ((ProactiveMessage) -> Unit)? = null,
/** Sink for injecting into the active chat session (Phase 2b). */
var toSession: ((ProactiveMessage) -> Unit)? = null,
var toSession: ((ProactiveMessage) -> Boolean)? = null,
/**
* Sink for the relay's per-reply ack (`proactive.reply.ack`) — lets the
* chat layer settle a Thread reply bubble from SENDING → DELIVERED. Wired
@@ -61,11 +63,13 @@ class ProactiveMessageHandler(
/**
* Show an inbound message inline in the Chat **Thread** it belongs to, when
* that Thread is currently open. Returns true if it was shown there — in
* which case the message is NOT also notified or added to the inbox (you're
* already looking at the conversation). The unified-Threads counterpart of
* which case the message is persisted but not also notified (you're already
* looking at the conversation). The unified-Threads counterpart of
* [toSession]; wired after construction.
*/
var injectIntoThread: ((ProactiveMessage) -> Boolean)? = null,
/** One callback per completed queued-message flush, never per message. */
var onBacklogDelivered: ((Int) -> Unit)? = null,
) {
fun onMessage(envelope: Envelope) {
@@ -80,6 +84,10 @@ class ProactiveMessageHandler(
}
// Subscribe ack — informational; nothing to do client-side.
"proactive.subscribed" -> Log.d(TAG, "proactive subscribe acked")
"proactive.backlog.complete" -> {
val count = envelope.payload["count"]?.jsonPrimitive?.intOrNull ?: 0
if (count > 0) onBacklogDelivered?.invoke(count)
}
// Per-reply ack — settle the matching Thread reply bubble (the
// `client_msg_id` is the id the app stamped on its own reply).
"proactive.reply.ack" -> {
@@ -94,24 +102,28 @@ class ProactiveMessageHandler(
/** Route a parsed message: into the open Thread if it belongs there, else
* the durable inbox log + the surface its hint selects. */
private fun dispatch(msg: ProactiveMessage) {
// Unified Threads: if this message belongs to the Thread currently open
// in Chat, render it inline there and STOP — no notification, no inbox
// entry (you're already looking at the conversation).
if (injectIntoThread?.invoke(msg) == true) return
// Otherwise the inbox is the durable log of agent-initiated messages and
// the surfacing hint selects the additional surface.
// Persist first even when the currently open Thread consumes the live
// message. Agent-initiated outbound sends do not create a gateway
// session until the phone replies, so this cache is the provisional
// Thread transcript during that gap.
toInbox?.invoke(msg)
// The surfacing hint selects the additional surface. Thread injection
// is best-effort presentation of the persisted row, not itself a reason
// to suppress an explicitly requested notification.
when (msg.surfacing?.lowercase()) {
"inbox" -> { /* inbox only — already recorded above */ }
"inbox" -> {
injectIntoThread?.invoke(msg)
}
"session" -> {
val sink = toSession
// Legacy explicit "inject into active session" path; if no sink
// (or no active chat) fall back to a notification so it isn't
// silently missed (the inbox copy already exists either way).
if (sink != null) sink.invoke(msg) else notify(msg)
val delivered = injectIntoThread?.invoke(msg) == true ||
toSession?.invoke(msg) == true
if (!delivered) notify(msg)
}
// null / "default" / "notification" / anything unrecognized.
else -> notify(msg)
else -> {
injectIntoThread?.invoke(msg)
notify(msg)
}
}
}
@@ -136,6 +148,7 @@ class ProactiveMessageHandler(
surfacing = payload["surfacing"]?.jsonPrimitive?.contentOrNull,
sentAt = payload["sent_at"]?.jsonPrimitive?.contentOrNull?.toLongOrNull(),
replyTo = payload["reply_to"]?.jsonPrimitive?.contentOrNull,
arrivedWhileAway = payload["queued_delivery"]?.jsonPrimitive?.booleanOrNull == true,
)
}
@@ -157,4 +170,6 @@ data class ProactiveMessage(
val sentAt: Long?,
/** Id of the message this one answers, if any (server threading hint). */
val replyTo: String? = null,
/** True only when Relay explicitly marked this as a reconnect queue flush. */
val arrivedWhileAway: Boolean = false,
)
@@ -299,10 +299,10 @@ class RelayHttpClient(
Result.success(FetchedMedia(contentType, bytes, fileName, sensitive))
}
} catch (e: IOException) {
Log.w(TAG, "fetchMedia failed for $token: ${e.message}")
Log.w(TAG, "fetchMedia failed: ${e.message}")
Result.failure(e)
} catch (e: Exception) {
Log.w(TAG, "fetchMedia unexpected error for $token: ${e.message}")
Log.w(TAG, "fetchMedia unexpected error: ${e.message}")
Result.failure(e)
}
}
@@ -7,6 +7,8 @@ import com.hermesandroid.relay.data.ProfileSkillsResponse
import com.hermesandroid.relay.data.ProfileSoulResponse
import com.hermesandroid.relay.data.ProfileSoulUpdateResponse
import com.hermesandroid.relay.data.ProfileMemoryUpdateResponse
import com.hermesandroid.relay.data.LegacyProfileInspectorClient
import com.hermesandroid.relay.data.RelaySkillToggleResult
import kotlinx.coroutines.Dispatchers
import kotlinx.coroutines.withContext
import kotlinx.serialization.SerializationException
@@ -48,7 +50,7 @@ class RelayProfileInspectorClient(
private val okHttpClient: OkHttpClient,
private val relayUrlProvider: () -> String?,
private val sessionTokenProvider: suspend () -> String?,
) {
) : LegacyProfileInspectorClient {
companion object {
private const val TAG = "RelayProfileInspector"
@@ -79,19 +81,19 @@ class RelayProfileInspectorClient(
/** Fetch `GET /api/profiles/{name}/config`. */
suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
override suspend fun fetchConfig(profileName: String): Result<ProfileConfigResponse> =
get(profileName, "config", ProfileConfigResponse.serializer())
/** Fetch `GET /api/profiles/{name}/skills`. */
suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
override suspend fun fetchSkills(profileName: String): Result<ProfileSkillsResponse> =
get(profileName, "skills", ProfileSkillsResponse.serializer())
/** Fetch `GET /api/profiles/{name}/soul`. */
suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
override suspend fun fetchSoul(profileName: String): Result<ProfileSoulResponse> =
get(profileName, "soul", ProfileSoulResponse.serializer())
/** Fetch `GET /api/profiles/{name}/memory`. */
suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
override suspend fun fetchMemory(profileName: String): Result<ProfileMemoryResponse> =
get(profileName, "memory", ProfileMemoryResponse.serializer())
/**
@@ -108,7 +110,7 @@ class RelayProfileInspectorClient(
* would be a protocol violation; we send empty-string for an empty
* SOUL.
*/
suspend fun updateSoul(
override suspend fun updateSoul(
profileName: String,
content: String,
): Result<ProfileSoulUpdateResponse> = withContext(Dispatchers.IO) {
@@ -137,7 +139,7 @@ class RelayProfileInspectorClient(
* Used for both creating a new memory entry (the relay writes the
* file if missing) and updating an existing entry.
*/
suspend fun updateMemoryEntry(
override suspend fun updateMemoryEntry(
profileName: String,
filename: String,
content: String,
@@ -270,10 +272,10 @@ class RelayProfileInspectorClient(
* server" snackbar and ghost out the toggle. When the real
* implementation lands server-side, this method needs no change.
*/
suspend fun updateSkillToggle(
override suspend fun updateSkillToggle(
skillName: String,
enabled: Boolean,
): Result<SkillToggleResult> = withContext(Dispatchers.IO) {
): Result<RelaySkillToggleResult> = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) {
return@withContext Result.failure(
@@ -319,8 +321,8 @@ class RelayProfileInspectorClient(
try {
okHttpClient.newCall(request).execute().use { response ->
when (response.code) {
in 200..299 -> Result.success(SkillToggleResult.Ok)
501 -> Result.success(SkillToggleResult.NotImplemented)
in 200..299 -> Result.success(RelaySkillToggleResult.Ok)
501 -> Result.success(RelaySkillToggleResult.NotImplemented)
401, 403 -> Result.failure(
IOException("Unauthorized — re-pair with the relay")
)
@@ -348,7 +350,7 @@ class RelayProfileInspectorClient(
* "not implemented" and any 2xx as "supported". The relay serves
* OPTIONS via aiohttp's CORS handling by default.
*/
suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
override suspend fun probeSkillToggleSupported(): Boolean = withContext(Dispatchers.IO) {
val relayUrl = relayUrlProvider()?.trim().orEmpty()
if (relayUrl.isEmpty()) return@withContext false
val sessionToken = sessionTokenProvider() ?: return@withContext false
@@ -402,11 +404,6 @@ class RelayProfileInspectorClient(
* answered 501 — not implemented yet" without inventing magic
* error strings.
*/
sealed class SkillToggleResult {
data object Ok : SkillToggleResult()
data object NotImplemented : SkillToggleResult()
}
/**
* Best-effort pull of a `detail` or `error` string out of a relay
* 400 body. Falls back to the first 120 chars of the payload when
@@ -0,0 +1,41 @@
package com.hermesandroid.relay.network.shared
import okhttp3.Request
import java.io.IOException
/** Secret-free failure raised before OkHttp sees a malformed credential. */
class InvalidCredentialException internal constructor(message: String) : IOException(message)
/**
* Normalize only harmless surrounding horizontal whitespace. Credentials are
* otherwise single-line visible ASCII: embedded whitespace, CR/LF, controls,
* and non-ASCII input are rejected instead of repaired or logged.
*/
fun normalizeCredentialForHeader(raw: String, label: String): String {
val normalized = raw.trim(' ', '\t')
if (normalized.any { it < '!' || it > '~' }) {
throw InvalidCredentialException(
"Invalid $label — enter or import a single-line value.",
)
}
return normalized
}
fun Request.Builder.bearerAuthorization(
rawCredential: String,
label: String,
): Request.Builder {
val credential = normalizeCredentialForHeader(rawCredential, label)
if (credential.isEmpty()) return this
return header("Authorization", "Bearer $credential")
}
fun Request.Builder.credentialHeader(
name: String,
rawCredential: String,
label: String,
): Request.Builder {
val credential = normalizeCredentialForHeader(rawCredential, label)
if (credential.isEmpty()) return this
return header(name, credential)
}
@@ -55,6 +55,8 @@ data class RouteProbeOutcome(
*/
enum class EndpointSurface {
Standard,
Dashboard,
Api,
Relay,
}
@@ -109,6 +111,8 @@ class EndpointResolver(
* expected path for plain JVM tests.
*/
private val context: Context? = null,
/** Route-aware client for pinned plugin proxy probes. */
private val clientForCandidate: ((EndpointCandidate) -> OkHttpClient?)? = null,
) {
/**
@@ -196,8 +200,13 @@ class EndpointResolver(
val authority = when (surface) {
EndpointSurface.Standard ->
candidate.routeAuthority() ?: candidate.primaryRouteUrl().orEmpty().lowercase()
EndpointSurface.Dashboard ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl ?: candidate.dashboard?.url).orEmpty()
EndpointSurface.Api ->
routeAuthority(candidate.pluginProxyRoutesOrNull()?.apiBaseUrl ?: candidate.api?.url).orEmpty()
EndpointSurface.Relay ->
routeAuthority(candidate.relay?.url).orEmpty()
candidate.pluginProxyRoutesOrNull()?.authority
?: routeAuthority(candidate.relay?.url).orEmpty()
}
return "${surface.name.lowercase()}|${candidate.role}|$authority"
}
@@ -239,11 +248,16 @@ class EndpointResolver(
val eligible = candidates.filter { probeTarget(it, surface) != null }
if (eligible.isEmpty()) return null
// Strict priority: sort ascending so priority-0 lands first. Grouping
// preserves emitted order within a priority class (DNS SRV parity).
val groups = eligible.groupBy { it.priority }.toSortedMap()
// Supported routes always run before experimental routes. Priority is
// strict inside each stability tier, so Reach remains available as a
// last-resort fallback without displacing Tailscale or direct TLS.
val supported = eligible.filterNot { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val experimental = eligible.filter { it.experimental || it.role.equals("outbound_broker", ignoreCase = true) }
val groups = (supported.groupBy { it.priority }.toSortedMap().values +
experimental.groupBy { it.priority }.toSortedMap().values)
for ((priority, group) in groups) {
for (group in groups) {
val priority = group.first().priority
Log.d(TAG, "probing priority=$priority group (size=${group.size})")
val winner = raceGroup(group, surface)
if (winner != null) {
@@ -356,6 +370,8 @@ class EndpointResolver(
val startedAtMs = clock()
val operation = when (surface) {
EndpointSurface.Standard -> "Dashboard or API route health probe"
EndpointSurface.Dashboard -> "Dashboard route health probe"
EndpointSurface.Api -> "API route health probe"
EndpointSurface.Relay -> "Relay route health probe"
}
val target = probeTarget(candidate, surface)
@@ -375,7 +391,7 @@ class EndpointResolver(
recordOutcome(candidate, surface, reachable = false, detail = "Invalid route URL")
return false
}
val fastClient = httpClient.newBuilder()
val fastClient = (clientForCandidate?.invoke(candidate) ?: httpClient).newBuilder()
.connectTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.readTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
.writeTimeout(PROBE_TIMEOUT_MS, TimeUnit.MILLISECONDS)
@@ -480,6 +496,29 @@ class EndpointResolver(
candidate: EndpointCandidate,
surface: EndpointSurface,
): ProbeTarget? {
if (surface == EndpointSurface.Dashboard) {
candidate.pluginProxyRoutesOrNull()?.dashboardBaseUrl?.let { base ->
return ProbeTarget(base, "$base/api/status", "/dashboard/api/status")
}
candidate.dashboard?.url?.trim()?.trimEnd('/')?.takeIf { it.isNotBlank() }?.let { base ->
return ProbeTarget(base, "$base/api/status", "/api/status")
}
return null
}
if (surface == EndpointSurface.Api) {
candidate.pluginProxyRoutesOrNull()?.apiBaseUrl?.let { base ->
return ProbeTarget(base, "$base/health", "/api/health")
}
candidate.api?.url?.let { base -> return ProbeTarget(base, "$base/health", "/health") }
return null
}
if (surface == EndpointSurface.Relay) candidate.pluginProxyRoutesOrNull()?.let { proxy ->
return ProbeTarget(
baseUrl = proxy.relayHttpUrl,
requestUrl = "${proxy.relayHttpUrl}/health",
path = "/relay/health",
)
}
if (surface == EndpointSurface.Relay) {
return relayProbeTarget(candidate)
}
@@ -529,6 +568,11 @@ class EndpointResolver(
return null
}
internal fun probeRequestUrlForTest(
candidate: EndpointCandidate,
surface: EndpointSurface,
): String? = probeTarget(candidate, surface)?.requestUrl
/**
* Map a probe exception to a short, actionable string for the Routes
* card. The TLS case is the headline: a route saved with `https://`
@@ -546,6 +590,8 @@ class EndpointResolver(
private fun EndpointSurface.diagnosticTarget(): String = when (this) {
EndpointSurface.Standard -> "Dashboard or API server"
EndpointSurface.Dashboard -> "Dashboard"
EndpointSurface.Api -> "API server"
EndpointSurface.Relay -> "Relay"
}
@@ -0,0 +1,402 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.isValidHermesReach
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.encodeToString
import kotlinx.serialization.json.Json
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.Response
import okhttp3.WebSocket
import okhttp3.WebSocketListener
import okio.ByteString
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.InetAddress
import java.net.InetSocketAddress
import java.net.Socket
import java.net.SocketAddress
import java.net.SocketException
import java.net.URI
import java.security.SecureRandom
import java.util.Base64
import java.util.ArrayDeque
import java.util.concurrent.CountDownLatch
import java.util.concurrent.TimeUnit
import javax.net.SocketFactory
private const val REACH_PROTOCOL_VERSION = 1
private const val REACH_MAX_FRAME_BYTES = 1024 * 1024
internal const val REACH_MAX_QUEUED_FRAMES = 32
internal const val REACH_MAX_QUEUED_BYTES = 8 * 1024 * 1024
private const val REACH_MATCH_TIMEOUT_MS = 10_000L
/**
* Connection metadata for Hermes Reach's outer WSS rendezvous.
*
* This is deliberately transport-only. The inner HTTPS/WSS origin and its
* pairing-authenticated SPKI pin continue to be owned by [PluginProxyRoutes],
* so broker reachability can never weaken Secure Link trust.
*/
data class HermesReachRoute(
val brokerUrl: String,
val hostId: String,
val credentialKind: String,
val token: String,
) {
fun tunnelUrlOrNull(): String? {
if (hostId.isBlank() || token.isBlank()) return null
if (credentialKind !in setOf("bootstrap", "route")) return null
val uri = runCatching { URI(brokerUrl.trim()) }.getOrNull() ?: return null
if (!uri.scheme.equals("wss", ignoreCase = true) || uri.host.isNullOrBlank()) return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
if (uri.rawPath.orEmpty().let { it.isNotEmpty() && it != "/" && it != "/v1/connect" }) return null
val authority = buildString {
append(if (':' in uri.host) "[${uri.host}]" else uri.host)
if (uri.port > 0 && uri.port != 443) append(":${uri.port}")
}
return "wss://$authority/v1/connect"
}
}
fun EndpointCandidate.hermesReachRouteOrNull(): HermesReachRoute? {
val metadata = broker?.takeIf { it.isValidHermesReach() } ?: return null
if (pluginProxyRoutesOrNull() == null) return null
return HermesReachRoute(
brokerUrl = metadata.url,
hostId = metadata.hostId,
credentialKind = metadata.credentialKind,
token = metadata.token,
)
}
/** Build the pinned inner Secure Link client over an outer Hermes Reach WSS. */
fun buildHermesReachClient(
baseBuilder: OkHttpClient.Builder,
outerClient: OkHttpClient,
candidate: EndpointCandidate,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
): OkHttpClient? {
val secureLink = candidate.pluginProxyRoutesOrNull() ?: return null
val reach = candidate.hermesReachRouteOrNull() ?: return null
return buildPluginProxyClient(
baseBuilder = baseBuilder,
routes = secureLink,
sessionTokenProvider = sessionTokenProvider,
includeRelaySessionHeader = includeRelaySessionHeader,
rawSocketFactory = HermesReachSocketFactory(outerClient, reach),
)
}
@Serializable
private data class ReachRegistration(
val type: String = "register",
@SerialName("protocol_version") val protocolVersion: Int = REACH_PROTOCOL_VERSION,
val role: String = "client",
@SerialName("host_id") val hostId: String,
@SerialName("connection_id") val connectionId: String,
@SerialName("credential_kind") val credentialKind: String,
val token: String,
)
@Serializable
private data class ReachControl(
val type: String? = null,
@SerialName("protocol_version") val protocolVersion: Int? = null,
@SerialName("stream_id") val streamId: String? = null,
val code: String? = null,
)
internal object HermesReachHandshake {
private val json = Json {
ignoreUnknownKeys = false
encodeDefaults = true
}
fun registration(route: HermesReachRoute, connectionId: String): String = json.encodeToString(
ReachRegistration(
hostId = route.hostId,
connectionId = connectionId,
credentialKind = route.credentialKind,
token = route.token,
),
)
fun validateMatched(payload: String): String? {
val control = runCatching { json.decodeFromString<ReachControl>(payload) }
.getOrElse { return "Hermes Reach returned an invalid match response" }
if (control.type == "error") {
return "Hermes Reach rejected the route (${control.code ?: "unknown"})"
}
val streamIdValid = control.streamId?.let(::isCanonicalId) == true
if (control.type != "matched" ||
control.protocolVersion != REACH_PROTOCOL_VERSION ||
!streamIdValid
) {
return "Hermes Reach returned a mismatched route response"
}
return null
}
private fun isCanonicalId(value: String): Boolean {
if (value.isBlank() || '=' in value) return false
val decoded = runCatching { Base64.getUrlDecoder().decode(value) }.getOrNull() ?: return false
return decoded.size == 16 && Base64.getUrlEncoder().withoutPadding().encodeToString(decoded) == value
}
}
/**
* Raw socket factory that carries bytes through Hermes Reach. OkHttp layers
* the normal Secure Link TLS socket factory over the returned socket, so SNI,
* hostname verification, and the QR SPKI pin all apply to the inner endpoint.
*/
class HermesReachSocketFactory(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : SocketFactory() {
init {
require(route.tunnelUrlOrNull() != null) { "Invalid Hermes Reach route" }
}
override fun createSocket(): Socket = HermesReachSocket(outerClient, route)
override fun createSocket(host: String?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(host: String?, port: Int, localHost: InetAddress?, localPort: Int): Socket =
createSocket().apply {
if (localHost != null) bind(InetSocketAddress(localHost, localPort))
connect(InetSocketAddress(host, port))
}
override fun createSocket(host: InetAddress?, port: Int): Socket =
createSocket().apply { connect(InetSocketAddress(host, port)) }
override fun createSocket(
address: InetAddress?,
port: Int,
localAddress: InetAddress?,
localPort: Int,
): Socket = createSocket().apply {
if (localAddress != null) bind(InetSocketAddress(localAddress, localPort))
connect(InetSocketAddress(address, port))
}
}
private class HermesReachSocket(
private val outerClient: OkHttpClient,
private val route: HermesReachRoute,
) : Socket() {
private val inbound = ReachInputStream()
private val matchLatch = CountDownLatch(1)
private val connectionId = randomConnectionId()
@Volatile private var matchError: IOException? = null
@Volatile private var webSocket: WebSocket? = null
@Volatile private var connected = false
@Volatile private var closed = false
@Volatile private var matched = false
@Volatile private var remote: InetSocketAddress? = null
private var readTimeoutMs: Int = 0
private val outbound = object : OutputStream() {
override fun write(value: Int) = write(byteArrayOf(value.toByte()))
override fun write(bytes: ByteArray, offset: Int, length: Int) {
if (length == 0) return
if (!matched || closed) throw SocketException("Hermes Reach tunnel is not open")
var cursor = offset
var remaining = length
while (remaining > 0) {
val count = minOf(remaining, REACH_MAX_FRAME_BYTES)
val accepted = webSocket?.send(ByteString.of(*bytes.copyOfRange(cursor, cursor + count))) == true
if (!accepted) throw SocketException("Hermes Reach could not queue tunnel bytes")
cursor += count
remaining -= count
}
}
}
override fun connect(endpoint: SocketAddress?) = connect(endpoint, REACH_MATCH_TIMEOUT_MS.toInt())
override fun connect(endpoint: SocketAddress?, timeout: Int) {
if (connected) throw SocketException("Socket is already connected")
if (closed) throw SocketException("Socket is closed")
remote = endpoint as? InetSocketAddress
?: throw SocketException("Hermes Reach requires an internet socket target")
val request = Request.Builder().url(requireNotNull(route.tunnelUrlOrNull())).build()
webSocket = outerClient.newWebSocket(request, listener)
val waitMs = minOf(
timeout.takeIf { it > 0 }?.toLong() ?: REACH_MATCH_TIMEOUT_MS,
REACH_MATCH_TIMEOUT_MS,
)
if (!matchLatch.await(waitMs, TimeUnit.MILLISECONDS)) {
closeWithError(IOException("Hermes Reach host match timed out"))
}
matchError?.let { throw it }
if (!matched) throw IOException("Hermes Reach closed before matching the host")
connected = true
}
private val listener = object : WebSocketListener() {
override fun onOpen(webSocket: WebSocket, response: Response) {
val registration = HermesReachHandshake.registration(route, connectionId)
if (!webSocket.send(registration)) {
closeWithError(IOException("Hermes Reach registration could not be sent"))
}
}
override fun onMessage(webSocket: WebSocket, text: String) {
if (matched) {
closeWithError(IOException("Hermes Reach sent text after matching"))
return
}
HermesReachHandshake.validateMatched(text)?.let { message ->
closeWithError(IOException(message))
return
}
matched = true
matchLatch.countDown()
}
override fun onMessage(webSocket: WebSocket, bytes: ByteString) {
if (!matched) {
closeWithError(IOException("Hermes Reach sent bytes before matching"))
return
}
if (bytes.size > REACH_MAX_FRAME_BYTES) {
closeWithError(IOException("Hermes Reach frame exceeds 1 MiB"))
return
}
if (!inbound.offer(bytes.toByteArray())) {
closeWithError(IOException("Hermes Reach receive queue exceeded its safe limit"))
}
}
override fun onClosing(webSocket: WebSocket, code: Int, reason: String) {
webSocket.close(code, null)
}
override fun onClosed(webSocket: WebSocket, code: Int, reason: String) {
if (!matched) matchError = IOException("Hermes Reach closed before matching the host")
closed = true
inbound.close(matchError)
matchLatch.countDown()
}
override fun onFailure(webSocket: WebSocket, t: Throwable, response: Response?) {
closeWithError(IOException("Hermes Reach connection failed", t))
}
}
private fun closeWithError(error: IOException) {
matchError = error
closed = true
webSocket?.cancel()
inbound.close(error)
matchLatch.countDown()
}
override fun getInputStream(): InputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
inbound.readTimeoutMs = readTimeoutMs
return inbound
}
override fun getOutputStream(): OutputStream {
if (!connected || closed) throw SocketException("Hermes Reach tunnel is not open")
return outbound
}
override fun close() {
if (closed) return
closed = true
webSocket?.close(1000, null)
inbound.close(null)
matchLatch.countDown()
}
override fun isConnected(): Boolean = connected
override fun isClosed(): Boolean = closed
override fun getRemoteSocketAddress(): SocketAddress? = remote
override fun getInetAddress(): InetAddress? = remote?.address
override fun getPort(): Int = remote?.port ?: 0
override fun setSoTimeout(timeout: Int) { readTimeoutMs = timeout }
override fun getSoTimeout(): Int = readTimeoutMs
override fun setTcpNoDelay(on: Boolean) = Unit
override fun getTcpNoDelay(): Boolean = true
override fun setKeepAlive(on: Boolean) = Unit
override fun getKeepAlive(): Boolean = true
override fun setReuseAddress(on: Boolean) = Unit
override fun getReuseAddress(): Boolean = false
}
internal class ReachInputStream : InputStream() {
private val chunks = ArrayDeque<ByteArray>()
private var offset = 0
private var queuedBytes = 0
private var terminalError: IOException? = null
private var closed = false
@Volatile var readTimeoutMs: Int = 0
@Synchronized
fun offer(bytes: ByteArray): Boolean {
if (closed) return false
if (chunks.size >= REACH_MAX_QUEUED_FRAMES || queuedBytes + bytes.size > REACH_MAX_QUEUED_BYTES) {
return false
}
chunks.addLast(bytes)
queuedBytes += bytes.size
(this as java.lang.Object).notifyAll()
return true
}
@Synchronized
fun close(error: IOException?) {
if (closed) return
closed = true
terminalError = error
(this as java.lang.Object).notifyAll()
}
override fun read(): Int {
val one = ByteArray(1)
return if (read(one, 0, 1) < 0) -1 else one[0].toInt() and 0xff
}
@Synchronized
override fun read(target: ByteArray, targetOffset: Int, length: Int): Int {
if (length == 0) return 0
val started = System.nanoTime()
while (chunks.isEmpty() && !closed) {
val waitMs = if (readTimeoutMs > 0) {
val elapsed = TimeUnit.NANOSECONDS.toMillis(System.nanoTime() - started)
(readTimeoutMs - elapsed).coerceAtLeast(0)
} else 0L
if (readTimeoutMs > 0 && waitMs == 0L) throw java.net.SocketTimeoutException("Hermes Reach read timed out")
(this as java.lang.Object).wait(if (readTimeoutMs > 0) waitMs else 0L)
}
if (chunks.isEmpty()) {
terminalError?.let { throw it }
return -1
}
val chunk = chunks.first()
val count = minOf(length, chunk.size - offset)
chunk.copyInto(target, targetOffset, offset, offset + count)
offset += count
queuedBytes -= count
if (offset == chunk.size) {
chunks.remove(chunk)
offset = 0
}
return count
}
}
private fun randomConnectionId(): String {
val bytes = ByteArray(16).also(SecureRandom()::nextBytes)
return Base64.getUrlEncoder().withoutPadding().encodeToString(bytes)
}
@@ -0,0 +1,149 @@
package com.hermesandroid.relay.network.shared
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.ProxyEndpoint
import com.hermesandroid.relay.data.isValidPinnedProxy
import okhttp3.CertificatePinner
import okhttp3.Interceptor
import okhttp3.OkHttpClient
import java.net.URI
import java.security.KeyStore
import java.security.MessageDigest
import java.security.SecureRandom
import java.security.cert.CertificateException
import java.security.cert.X509Certificate
import javax.net.ssl.SSLContext
import javax.net.ssl.TrustManagerFactory
import javax.net.ssl.X509TrustManager
import javax.net.SocketFactory
/** Runtime endpoints exposed beneath one plugin-owned pinned-TLS origin. */
data class PluginProxyRoutes(
val authority: String,
val host: String,
val port: Int,
val relayHttpUrl: String,
val relayWebSocketUrl: String,
val apiBaseUrl: String?,
val dashboardBaseUrl: String?,
val pinSha256: String,
)
/**
* Resolve and validate the pairing-advertised proxy contract. Invalid or
* incomplete advertisements are never treated as secure routes.
*/
fun ProxyEndpoint.toPluginProxyRoutesOrNull(): PluginProxyRoutes? {
if (!isValidPinnedProxy()) return null
val base = url.trim().trimEnd('/')
val uri = runCatching { URI(base) }.getOrNull() ?: return null
if (!uri.scheme.equals("https", ignoreCase = true)) return null
val host = uri.host?.lowercase()?.takeIf { it.isNotBlank() } ?: return null
if (!uri.rawUserInfo.isNullOrBlank() || uri.rawQuery != null || uri.rawFragment != null) return null
val rawPath = uri.rawPath.orEmpty()
if (rawPath.isNotEmpty() && rawPath != "/") return null
val port = if (uri.port > 0) uri.port else 443
val pin = pinSha256!!.trim()
val authority = "$host:$port"
val wsBase = "wss://${formatHost(host)}${if (port == 443) "" else ":$port"}$rawPath"
.trimEnd('/')
val surfaces = surfaces.map(String::lowercase).toSet()
return PluginProxyRoutes(
authority = authority,
host = host,
port = port,
relayHttpUrl = "$base/relay",
relayWebSocketUrl = "$wsBase/relay/ws",
apiBaseUrl = "$base/api".takeIf { "api" in surfaces },
dashboardBaseUrl = "$base/dashboard".takeIf { "dashboard" in surfaces },
pinSha256 = pin,
)
}
fun EndpointCandidate.pluginProxyRoutesOrNull(): PluginProxyRoutes? =
proxy?.toPluginProxyRoutesOrNull()
private fun formatHost(host: String): String = if (':' in host) "[$host]" else host
/**
* Build a client that trusts the system normally, plus exactly the
* pairing-advertised SPKI for this proxy. The authority guard keeps a pin
* scoped to host *and port*; OkHttp's CertificatePinner alone is host-only.
*/
fun buildPluginProxyClient(
baseBuilder: OkHttpClient.Builder,
routes: PluginProxyRoutes,
sessionTokenProvider: () -> String?,
includeRelaySessionHeader: Boolean = true,
rawSocketFactory: SocketFactory? = null,
): OkHttpClient {
val expectedHost = routes.host
val expectedPort = routes.port
val systemTrust = systemTrustManager()
val pinnedTrust = PinnedOrSystemTrustManager(systemTrust, routes.pinSha256)
val sslContext = SSLContext.getInstance("TLS").apply {
init(null, arrayOf(pinnedTrust), SecureRandom())
}
if (rawSocketFactory != null) baseBuilder.socketFactory(rawSocketFactory)
return baseBuilder
.sslSocketFactory(sslContext.socketFactory, pinnedTrust)
.certificatePinner(
CertificatePinner.Builder().add(expectedHost, routes.pinSha256).build(),
)
.addNetworkInterceptor(Interceptor { chain ->
val requestUrl = chain.request().url
if (!requestUrl.host.equals(expectedHost, ignoreCase = true) ||
requestUrl.port != expectedPort
) {
throw java.io.IOException("Pinned proxy redirect left its paired authority")
}
val token = sessionTokenProvider().takeIf { includeRelaySessionHeader }
?.takeIf { it.isNotBlank() }
val request = if (token != null) {
chain.request().newBuilder()
.credentialHeader(
"X-Hermes-Relay-Session",
token,
"Relay session credential",
)
.build()
} else {
chain.request()
}
chain.proceed(request)
})
.build()
}
private fun systemTrustManager(): X509TrustManager {
val factory = TrustManagerFactory.getInstance(TrustManagerFactory.getDefaultAlgorithm())
factory.init(null as KeyStore?)
return factory.trustManagers.filterIsInstance<X509TrustManager>().single()
}
private class PinnedOrSystemTrustManager(
private val system: X509TrustManager,
private val expectedPin: String,
) : X509TrustManager {
override fun checkClientTrusted(chain: Array<out X509Certificate>?, authType: String?) =
system.checkClientTrusted(chain, authType)
override fun checkServerTrusted(chain: Array<out X509Certificate>?, authType: String?) {
val certificates = chain?.takeIf { it.isNotEmpty() }
?: throw CertificateException("Proxy supplied no certificate chain")
val systemAccepted = runCatching { system.checkServerTrusted(chain, authType) }.isSuccess
if (systemAccepted) return
val leaf = certificates.first()
leaf.checkValidity()
val actual = "sha256/" + java.util.Base64.getEncoder().encodeToString(
MessageDigest.getInstance("SHA-256").digest(leaf.publicKey.encoded),
)
if (!MessageDigest.isEqual(actual.toByteArray(), expectedPin.toByteArray())) {
throw CertificateException("Plugin proxy certificate does not match the paired pin")
}
}
override fun getAcceptedIssuers(): Array<X509Certificate> = system.acceptedIssuers
}
@@ -471,7 +471,12 @@ class ChatHandler {
* across the history reconcile; idempotent on the proactive [messageId] so a
* re-delivered push (e.g. an outbound-buffer flush) never double-posts.
*/
fun addAgentThreadMessage(text: String, messageId: String?, agentName: String?) {
fun addAgentThreadMessage(
text: String,
messageId: String?,
agentName: String?,
arrivedWhileAway: Boolean = false,
) {
val id = messageId?.let { "proactive-$it" } ?: "proactive-${java.util.UUID.randomUUID()}"
_messages.update { list ->
if (messageId != null && list.any { it.id == id }) return@update list
@@ -481,6 +486,7 @@ class ChatHandler {
content = text,
timestamp = System.currentTimeMillis(),
agentName = agentName,
badges = if (arrivedWhileAway) listOf("While away") else emptyList(),
clientOnly = true,
)
(list + msg).let { if (it.size > MAX_MESSAGES) it.drop(it.size - MAX_MESSAGES) else it }
@@ -524,6 +530,42 @@ class ChatHandler {
}
}
/**
* Whether [messageId] can be addressed without downgrading a durable
* transcript to an ordinal-only rewind. A wholly legacy transcript has no
* row ids and remains compatible with older Gateways. Once any visible
* user turn has a durable row id, the selected turn must have one too;
* otherwise the caller must refresh instead of guessing by position.
*/
fun hasSafeGatewayRewindAddress(messageId: String): Boolean {
val userTurns = _messages.value.filter { it.isGatewayRewindUser() }
val target = userTurns.firstOrNull { it.matchesIdentity(messageId) } ?: return false
return target.rowId != null || userTurns.none { it.rowId != null }
}
/**
* Rebind visible user turns after Gateway rewrites a truncated durable
* prefix. The response is positional in the same user-ordinal space used
* for edit/regenerate. Missing entries clear cached ids so a later rewind
* cannot accidentally send an archived pre-rewrite row id.
*/
fun rebindSurvivorUserRowIds(rowIds: List<Long?>) {
var ordinal = 0
_messages.update { messages ->
messages.map { message ->
if (!message.isGatewayRewindUser()) return@map message
val rebound = rowIds.getOrNull(ordinal)
ordinal += 1
if (message.rowId == rebound) message else message.copy(rowId = rebound)
}
}
}
private fun ChatMessage.isGatewayRewindUser(): Boolean =
role == MessageRole.USER &&
!id.startsWith("voice-intent-") &&
!id.startsWith("steer-")
fun replaceMessageContent(messageId: String, content: String) {
_messages.update { messages ->
messages.map { message ->
@@ -1497,6 +1539,8 @@ class ChatHandler {
// this as the same visible row across the post-turn reload.
prior.copy(
id = messageId,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1527,6 +1571,8 @@ class ChatHandler {
// nothing local to carry).
ChatMessage(
id = messageId,
rowId = item.resolvedRowId,
reactions = item.reactions,
role = role,
content = cleanedContent,
attachments = carriedAttachments,
@@ -1599,7 +1645,7 @@ class ChatHandler {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay, reload): token=${hit.token}")
Log.d(TAG, "Media marker accepted from reloaded Relay history")
onMediaAttachmentRequested(messageId, hit.token)
}
}
@@ -2025,6 +2071,11 @@ class ChatHandler {
title = resolvedTitle,
model = item.model,
messageCount = item.messageCount ?: 0,
inputTokens = item.inputTokens ?: 0,
outputTokens = item.outputTokens ?: 0,
actualCostUsd = item.actualCostUsd,
estimatedCostUsd = item.estimatedCostUsd,
isActive = item.isActive,
updatedAt = activityAtMs,
startedAt = startedAtMs,
lastActivityAt = lastActivityAtMs,
@@ -2036,6 +2087,13 @@ class ChatHandler {
hasModelConfig = item.hasModelConfig,
pinned = item.pinned,
archived = item.archived,
workingDirectory = item.cwd,
gitBranch = item.gitBranch,
gitRepoRoot = item.gitRepoRoot,
pullRequestNumber = item.pullRequest?.number,
pullRequestUrl = item.pullRequest?.url,
pullRequestState = item.pullRequest?.state,
pullRequestDraft = item.pullRequest?.draft == true,
)
}.sortedByDescending { it.activityTimestamp }
// Preserve the active session's optimistic row when the server list
@@ -2453,7 +2511,7 @@ class ChatHandler {
is MediaMarkerHit.RelayToken -> {
val dedupeKey = "$messageId:relay:${hit.token}"
if (dispatchedMediaMarkers.add(dedupeKey)) {
Log.d(TAG, "Media marker (relay): token=${hit.token}")
Log.d(TAG, "Media marker accepted from Relay stream")
onMediaAttachmentRequested(messageId, hit.token)
}
}
@@ -3287,6 +3345,7 @@ class ChatHandler {
.filterNot { msg ->
msg.matchesIdentity(messageId) &&
msg.role == MessageRole.ASSISTANT &&
msg.badges.isEmpty() &&
msg.toolCalls.isEmpty() &&
msg.backgroundTask == null &&
msg.thinkingContent.isBlank() &&
@@ -0,0 +1,50 @@
package com.hermesandroid.relay.network.upstream
/**
* User-reviewed input for upstream `cron.manage` creation.
*
* Repeat is intentionally bounded on the client. Upstream treats zero and
* negative values as an unlimited schedule, which is unsafe when the user
* explicitly chose a finite run count.
*/
data class CronCreationDraft(
val name: String,
val schedule: String,
val prompt: String,
val repeat: Int? = null,
val profile: String? = null,
) {
fun validated(): Result<CronCreationDraft> = runCatching {
val cleanName = name.trim()
val cleanSchedule = schedule.trim()
val cleanPrompt = prompt.trim()
require(cleanName.isNotEmpty()) { "Schedule name is required" }
require(cleanSchedule.isNotEmpty()) { "Schedule is required" }
require(cleanPrompt.isNotEmpty()) { "Task instructions are required" }
require(repeat == null || repeat in MIN_REPEAT..MAX_REPEAT) {
"Run count must be between $MIN_REPEAT and $MAX_REPEAT"
}
copy(
name = cleanName,
schedule = cleanSchedule,
prompt = cleanPrompt,
profile = profile?.trim()?.takeIf(String::isNotEmpty),
)
}
companion object {
const val MIN_REPEAT = 1
const val MAX_REPEAT = 999
}
}
/** Parse an optional finite-count field without ever coercing invalid input to unlimited. */
internal fun parseFiniteRepeat(value: String): Result<Int?> = runCatching {
val clean = value.trim()
if (clean.isEmpty()) return@runCatching null
val parsed = clean.toIntOrNull() ?: throw IllegalArgumentException("Run count must be a whole number")
require(parsed in CronCreationDraft.MIN_REPEAT..CronCreationDraft.MAX_REPEAT) {
"Run count must be between ${CronCreationDraft.MIN_REPEAT} and ${CronCreationDraft.MAX_REPEAT}"
}
parsed
}
@@ -7,9 +7,12 @@ import com.hermesandroid.relay.network.upstream.models.MessageItem
import com.hermesandroid.relay.network.upstream.models.MessageListResponse
import com.hermesandroid.relay.network.upstream.models.SessionItem
import com.hermesandroid.relay.network.upstream.models.SessionListResponse
import com.hermesandroid.relay.network.upstream.models.SessionPullRequest
import com.hermesandroid.relay.network.upstream.models.SessionPullRequestScanResponse
import com.hermesandroid.relay.network.upstream.models.SessionPruneFilters
import com.hermesandroid.relay.network.upstream.models.SessionPrunePreview
import com.hermesandroid.relay.network.upstream.models.SessionPruneResult
import com.hermesandroid.relay.network.upstream.models.RepositoryPullRequestListResponse
import com.hermesandroid.relay.auth.SecureStoreCache
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.buildRawTokenStore
@@ -35,13 +38,18 @@ import okhttp3.CookieJar
import okhttp3.HttpUrl
import okhttp3.HttpUrl.Companion.toHttpUrlOrNull
import okhttp3.MediaType.Companion.toMediaType
import okhttp3.MultipartBody
import okhttp3.OkHttpClient
import okhttp3.Request
import okhttp3.RequestBody
import okhttp3.RequestBody.Companion.toRequestBody
import okhttp3.Response
import java.io.IOException
import java.io.InputStream
import java.io.OutputStream
import java.net.URLEncoder
import java.util.concurrent.TimeUnit
import okio.BufferedSink
// Status/session/provider snapshots are @Serializable so the Manage tab's
// disk cache (DashboardManageDiskCache) can persist Loaded entries verbatim.
@@ -58,6 +66,29 @@ data class DashboardStatus(
@SerialName("gateway_mode") val gatewayMode: String? = null,
val gateways: List<DashboardGatewayTopology> = emptyList(),
val componentHealth: DashboardComponentHealthRollup = DashboardComponentHealthRollup(),
val memory: DashboardMemoryStatus? = null,
val disk: DashboardDiskStatus? = null,
)
@Serializable
data class DashboardMemoryStatus(
val pressure: String,
@SerialName("gateway_rss_mb") val gatewayRssMb: Int? = null,
@SerialName("system_total_mb") val systemTotalMb: Int? = null,
@SerialName("system_available_mb") val systemAvailableMb: Int? = null,
@SerialName("swap_used_mb") val swapUsedMb: Int? = null,
@SerialName("sampled_at") val sampledAt: String? = null,
@SerialName("last_boot_unclean") val lastBootUnclean: Boolean = false,
@SerialName("last_boot_suspected_oom") val lastBootSuspectedOom: Boolean = false,
@SerialName("boot_id") val bootId: String? = null,
)
@Serializable
data class DashboardDiskStatus(
val pressure: String,
@SerialName("total_mb") val totalMb: Int? = null,
@SerialName("free_mb") val freeMb: Int? = null,
@SerialName("used_percent") val usedPercent: Double? = null,
)
@Serializable
@@ -67,6 +98,23 @@ data class DashboardGatewayTopology(
@SerialName("served_profiles") val servedProfiles: List<String> = emptyList(),
)
/**
* Return only profiles the launch gateway positively reports as served.
*
* `/api/status.profiles` is the installed-profile inventory. Selective
* multiplex serving can exclude an installed profile, so that list must never
* authorize construction of a `/p/<profile>` API fallback route.
*/
internal fun DashboardStatus.multiplexServedProfiles(): List<String> {
if (!gatewayMode.equals("multiplex", ignoreCase = true)) return emptyList()
return gateways.firstOrNull { it.profile.equals("default", ignoreCase = true) }
?.servedProfiles
.orEmpty()
.map(String::trim)
.filter(String::isNotBlank)
.distinct()
}
@Serializable
data class DashboardComponentHealthRollup(
val supported: Boolean = false,
@@ -173,6 +221,71 @@ data class DashboardCustomEndpointValidation(
val models: List<String>,
)
internal class BoundedStreamRequestBody(
private val declaredLength: Long?,
private val limitBytes: Long,
private val openStream: () -> InputStream,
) : RequestBody() {
init {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit."
}
}
override fun contentType() = "application/zip".toMediaType()
override fun contentLength(): Long = declaredLength ?: -1L
override fun writeTo(sink: BufferedSink) {
openStream().use { input ->
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB upload limit.")
}
sink.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being read.")
}
}
}
}
internal fun copyBounded(
input: InputStream,
output: OutputStream,
declaredLength: Long?,
limitBytes: Long,
): Long {
require(limitBytes > 0)
require(declaredLength == null || declaredLength >= 0)
require(declaredLength == null || declaredLength <= limitBytes) {
"Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit."
}
val buffer = ByteArray(DEFAULT_BUFFER_SIZE)
var written = 0L
while (true) {
val read = input.read(buffer)
if (read < 0) break
written += read
if (written > limitBytes) {
throw IOException("Backup archive exceeds the ${limitBytes / (1024 * 1024)} MB download limit.")
}
output.write(buffer, 0, read)
}
if (declaredLength != null && written != declaredLength) {
throw IOException("Backup archive changed while it was being downloaded.")
}
return written
}
/** One entry from `GET /api/audio/elevenlabs/voices` — non-secret voice metadata. */
data class ElevenLabsVoice(
val voiceId: String,
@@ -206,8 +319,14 @@ class DashboardApiClient(
isLenient = true
coerceInputValues = true
},
private val nowMillis: () -> Long = System::currentTimeMillis,
) {
private val baseUrl: String = baseUrl.trim().trimEnd('/')
private val sessionPrScanLock = Any()
private val sessionPrScannedAt = mutableMapOf<String, Long>()
private val sessionPrScanWasTerminal = mutableMapOf<String, Boolean>()
private val sessionPullRequests = mutableMapOf<String, SessionPullRequest>()
private var sessionPrScanSupported: Boolean? = null
/**
* Resolve a request URL without ever throwing. okhttp's
@@ -518,6 +637,157 @@ class DashboardApiClient(
suspend fun createServerBackup(): Result<JsonObject> =
postJsonObject("/api/ops/backup")
/** Download only archives created inside upstream's guarded dashboard backup directory. */
suspend fun downloadServerBackup(
archive: String,
openOutput: () -> OutputStream,
): Result<String> = download(
path = "/api/ops/backup/download?archive=${queryValue(archive)}",
operation = "Hermes backup",
openOutput = openOutput,
)
/** Import a server-local archive path after the user confirms the destructive restore. */
suspend fun importServerBackup(archive: String): Result<JsonObject> =
postJsonObject(
path = "/api/ops/import",
payload = buildJsonObject { put("archive", archive) },
)
/** Upload an Android-selected zip to upstream's guarded staging directory and start import. */
suspend fun uploadServerBackup(
filename: String,
contentLength: Long?,
openStream: () -> InputStream,
force: Boolean = false,
): Result<JsonObject> = withContext(Dispatchers.IO) {
val path = "/api/ops/import-upload"
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val body = MultipartBody.Builder()
.setType(MultipartBody.FORM)
.addFormDataPart("force", force.toString())
.addFormDataPart(
"file",
filename.ifBlank { "hermes-backup.zip" },
runCatching {
BoundedStreamRequestBody(contentLength, MAX_BACKUP_TRANSFER_BYTES, openStream)
}.getOrElse { return@withContext Result.failure(it) },
)
.build()
executeJson(Request.Builder().url(httpUrl).post(body).build(), path)
}
suspend fun getLearningNode(id: String, profile: String? = null): Result<JsonObject> =
getJsonObject("/api/learning/node?id=${queryValue(id)}${profileQuerySuffix(profile)}")
suspend fun updateLearningNode(
id: String,
content: String,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
put("content", content)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun deleteLearningNode(id: String, profile: String? = null): Result<JsonObject> =
deleteJsonObjectWithBody(
path = "/api/learning/node",
payload = buildJsonObject {
put("id", id)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun selectMemoryProvider(provider: String): Result<JsonObject> =
putJsonObject(
path = "/api/memory/provider",
payload = buildJsonObject { put("provider", provider) },
)
/** Activate an already-configured provider inside the selected upstream profile. */
suspend fun activateMemoryProvider(provider: String, profile: String? = null): Result<JsonObject> =
updateMemoryProviderConfig(provider, JsonObject(emptyMap()), profile)
suspend fun getMemoryProviderConfig(
provider: String,
profile: String? = null,
): Result<JsonObject> = getJsonObject(
"/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
)
suspend fun updateMemoryProviderConfig(
provider: String,
values: JsonObject,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/config${profileQuery(profile)}",
payload = buildJsonObject { put("values", values) },
)
suspend fun setupMemoryProvider(provider: String): Result<JsonObject> =
postJsonObject(
path = "/api/memory/providers/${pathSegment(provider)}/setup",
// Dependency installation is host-global upstream. Do not submit
// profile-owned values through this unscoped route.
payload = buildJsonObject { put("values", JsonObject(emptyMap())) },
)
suspend fun startWhatsAppOnboarding(
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/start",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun getWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
getJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun applyWhatsAppOnboarding(
pairingId: String,
mode: String,
allowedUsers: String,
profile: String? = null,
): Result<JsonObject> = postJsonObject(
path = "/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}/apply",
payload = buildJsonObject {
put("mode", mode)
put("allowed_users", allowedUsers)
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun cancelWhatsAppOnboarding(pairingId: String): Result<JsonObject> =
deleteJsonObject("/api/messaging/whatsapp/onboarding/${pathSegment(pairingId)}")
suspend fun setMessagingPlatformEnabled(
platform: String,
enabled: Boolean,
profile: String? = null,
): Result<JsonObject> = putJsonObject(
path = "/api/messaging/platforms/${pathSegment(platform)}${profileQuery(profile)}",
payload = buildJsonObject {
put("enabled", enabled)
put("env", JsonObject(emptyMap()))
put("clear_env", JsonArray(emptyList()))
profile?.trim()?.takeIf(String::isNotBlank)?.let { put("profile", it) }
},
)
suspend fun testMessagingPlatform(platform: String, profile: String? = null): Result<JsonObject> =
postJsonObject(
"/api/messaging/platforms/${pathSegment(platform)}/test${profileQuery(profile)}",
)
suspend fun setProfileDescription(name: String, description: String): Result<JsonObject> =
putJsonObject(
path = "/api/profiles/${pathSegment(name)}/description",
@@ -764,7 +1034,13 @@ class DashboardApiClient(
pageSessions.forEach { sessions.putIfAbsent(it.id, it) }
if (pageSessions.size < page.limit) break
}
Result.success(sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)))
Result.success(
enrichSessionWorkState(
sessions.values.take(limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)),
fixedProfile = profile?.trim()?.takeIf { it.isNotBlank() }
?: DEFAULT_SESSION_PROFILE_SCOPE,
),
)
}
/**
@@ -776,7 +1052,7 @@ class DashboardApiClient(
limit: Int = SESSION_LIST_WINDOW_LIMIT,
): Result<List<SessionItem>> = withContext(Dispatchers.IO) {
val boundedLimit = limit.coerceIn(1, SESSION_LIST_WINDOW_LIMIT)
getJson(
val result = getJson(
"/api/profiles/sessions?limit=$boundedLimit&offset=0&order=recent" +
"&min_messages=1&archived=include&profile=all",
).mapCatching { root ->
@@ -786,8 +1062,129 @@ class DashboardApiClient(
.distinctBy { "${it.profile}:${it.id}" }
.take(boundedLimit)
}
if (result.isFailure) return@withContext result
Result.success(enrichSessionWorkState(result.getOrThrow(), fixedProfile = null))
}
/**
* Attach the PR a coding session created using the current upstream
* transcript-backed endpoint. Repository and branch already arrive on the
* list row. Missing/older endpoints are deliberately ignored, leaving the
* original rows intact. Active misses retry on a bounded cadence; terminal
* rows get one final scan and resolved associations remain cached.
*/
private suspend fun enrichSessionWorkState(
sessions: List<SessionItem>,
fixedProfile: String?,
): List<SessionItem> {
val candidates = sessions.filter {
it.id.isNotBlank() &&
(!it.gitRepoRoot.isNullOrBlank() || !it.gitBranch.isNullOrBlank() || !it.cwd.isNullOrBlank())
}
val duplicateIds = if (fixedProfile == null) {
candidates.groupingBy { it.id }.eachCount().filterValues { it > 1 }.keys
} else {
emptySet()
}
val now = nowMillis()
val pending = synchronized(sessionPrScanLock) {
candidates.filter { session ->
if (session.id in duplicateIds) return@filter false
val key = sessionWorkKey(session, fixedProfile)
val scannedAt = sessionPrScannedAt[key]
val resolved = sessionPullRequests[key] != null
!resolved && when {
scannedAt == null -> true
session.endedAt != null -> sessionPrScanWasTerminal[key] != true
else -> now - scannedAt >= ACTIVE_SESSION_PR_MISS_TTL_MILLIS
}
}
}
val pendingIds = pending.map { it.id }.distinct()
if (pendingIds.isNotEmpty()) {
val payload = buildJsonObject {
put("ids", JsonArray(pendingIds.map { JsonPrimitive(it) }))
}
val scan = postJsonObject("/api/profiles/sessions/pull-requests", payload)
.mapCatching { root ->
json.decodeFromJsonElement(SessionPullRequestScanResponse.serializer(), root)
}
synchronized(sessionPrScanLock) {
// A legacy 404 is a compatibility outcome, not a session-list failure.
// Avoid hammering an unsupported host on every drawer refresh.
if (scan.isSuccess || sessionPrScanSupported == null) {
sessionPrScanSupported = scan.isSuccess
}
pending.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
sessionPrScannedAt[key] = now
sessionPrScanWasTerminal[key] = session.endedAt != null
scan.getOrNull()?.pullRequests?.get(session.id)?.takeIf {
it.number > 0 && it.url.isNotBlank()
}?.let { pullRequest ->
sessionPullRequests[key] = pullRequest
}
}
}
}
refreshPullRequestStates(candidates, fixedProfile)
val pullRequests = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
return sessions.map { session ->
session.copy(pullRequest = pullRequests[sessionWorkKey(session, fixedProfile)])
}
}
/** Refresh current PR lifecycle state using upstream's repo-scoped GitHub view. */
private suspend fun refreshPullRequestStates(
sessions: List<SessionItem>,
fixedProfile: String?,
) {
if (synchronized(sessionPrScanLock) { sessionPrScanSupported } != true) return
val known = synchronized(sessionPrScanLock) { sessionPullRequests.toMap() }
sessions.groupBy { (it.gitRepoRoot ?: it.cwd).orEmpty().trim() }
.filterKeys { it.isNotBlank() }
.forEach { (path, repositorySessions) ->
val branches = repositorySessions.mapNotNull { it.gitBranch?.trim() }
.filter { it.isNotBlank() }
.distinct()
val numbers = repositorySessions.mapNotNull {
known[sessionWorkKey(it, fixedProfile)]?.number
}
.filter { it > 0 }
.distinct()
if (branches.isEmpty() && numbers.isEmpty()) return@forEach
val payload = buildJsonObject {
put("path", path)
put("branches", JsonArray(branches.map { JsonPrimitive(it) }))
put("numbers", JsonArray(numbers.map { JsonPrimitive(it) }))
}
val response = postJsonObject("/api/git/review/pr-list", payload)
.mapCatching { root ->
json.decodeFromJsonElement(RepositoryPullRequestListResponse.serializer(), root)
}
.getOrNull()
?: return@forEach
if (!response.ghReady) return@forEach
synchronized(sessionPrScanLock) {
repositorySessions.forEach { session ->
val key = sessionWorkKey(session, fixedProfile)
val recovered = sessionPullRequests[key]
val current = response.prs.firstOrNull { pr ->
recovered != null && pr.number == recovered.number
} ?: response.prs.firstOrNull { pr ->
!session.gitBranch.isNullOrBlank() && pr.branch == session.gitBranch
}
if (current != null && current.number > 0 && current.url.isNotBlank()) {
sessionPullRequests[key] = current
}
}
}
}
}
private fun sessionWorkKey(session: SessionItem, fixedProfile: String?): String =
"${fixedProfile ?: session.profile.orEmpty()}\u0000${session.id}"
/**
* A session's message history, scoped to its owning profile via the dashboard
* `GET /api/sessions/{id}/messages?profile=`. Required twin of [listSessions]:
@@ -1110,8 +1507,44 @@ class DashboardApiClient(
}
}
private suspend fun download(
path: String,
operation: String,
openOutput: () -> OutputStream,
): Result<String> =
withContext(Dispatchers.IO) {
val httpUrl = resolveUrl(path) ?: return@withContext Result.failure(invalidUrlException())
val request = Request.Builder().url(httpUrl).get().build()
try {
okHttpClient.newCall(request).execute().use { response ->
if (!response.isSuccessful) return@withContext Result.failure(apiFailure(response, operation))
val disposition = response.header("Content-Disposition").orEmpty()
val filename = Regex("filename=\\\"?([^\\\";]+)").find(disposition)?.groupValues?.get(1)
?: "hermes-backup.zip"
val body = response.body
val declaredLength = body.contentLength().takeIf { it >= 0 }
if (declaredLength != null && declaredLength > MAX_BACKUP_TRANSFER_BYTES) {
throw IOException("Backup archive exceeds the ${MAX_BACKUP_TRANSFER_BYTES / (1024 * 1024)} MB download limit.")
}
openOutput().use { output ->
body.byteStream().use { input ->
copyBounded(input, output, declaredLength, MAX_BACKUP_TRANSFER_BYTES)
}
}
Result.success(filename)
}
} catch (e: Exception) {
Result.failure(e)
}
}
companion object {
private val JSON_MEDIA = "application/json; charset=utf-8".toMediaType()
private const val DEFAULT_SESSION_PROFILE_SCOPE = "__dashboard_default__"
internal const val ACTIVE_SESSION_PR_MISS_TTL_MILLIS = 60_000L
// Mirrors current upstream `_MANAGED_FILE_MAX_BYTES`; enforcing it
// client-side avoids uploading a body the Dashboard will reject.
internal const val MAX_BACKUP_TRANSFER_BYTES = 100L * 1024L * 1024L
fun pathSegment(value: String): String =
URLEncoder.encode(value, "UTF-8").replace("+", "%20")
@@ -1169,6 +1602,11 @@ class DashboardApiClient(
return if (trimmed.isBlank()) "" else "?profile=${pathSegment(trimmed)}"
}
private fun profileQuerySuffix(profile: String?): String {
val trimmed = profile?.trim().orEmpty()
return if (trimmed.isBlank()) "" else "&profile=${queryValue(trimmed)}"
}
private fun profileLimitQuery(profile: String?, limit: Int): String {
val params = buildList {
val trimmed = profile?.trim().orEmpty()
@@ -1296,6 +1734,35 @@ class DashboardApiClient(
gatewayMode = root.stringField("gateway_mode"),
gateways = gateways,
componentHealth = parseComponentHealth(root),
memory = parseMemoryStatus(root["memory"] as? JsonObject),
disk = parseDiskStatus(root["disk"] as? JsonObject),
)
}
private fun parseMemoryStatus(obj: JsonObject?): DashboardMemoryStatus? {
obj ?: return null
val pressure = obj.stringField("pressure")?.lowercase() ?: return null
return DashboardMemoryStatus(
pressure = pressure,
gatewayRssMb = obj.intField("gateway_rss_mb"),
systemTotalMb = obj.intField("system_total_mb"),
systemAvailableMb = obj.intField("system_available_mb"),
swapUsedMb = obj.intField("swap_used_mb"),
sampledAt = obj.stringField("sampled_at"),
lastBootUnclean = obj.booleanField("last_boot_unclean") ?: false,
lastBootSuspectedOom = obj.booleanField("last_boot_suspected_oom") ?: false,
bootId = obj.stringField("boot_id"),
)
}
private fun parseDiskStatus(obj: JsonObject?): DashboardDiskStatus? {
obj ?: return null
val pressure = obj.stringField("pressure")?.lowercase() ?: return null
return DashboardDiskStatus(
pressure = pressure,
totalMb = obj.intField("total_mb"),
freeMb = obj.intField("free_mb"),
usedPercent = (obj["used_percent"] as? JsonPrimitive)?.contentOrNull?.toDoubleOrNull(),
)
}
File diff suppressed because it is too large Load Diff
@@ -260,6 +260,13 @@ class GatewayEventMapper(
}
callbacks.onUsage(parseGatewayUsage(payload?.get("usage") as? JsonObject))
if (failed) {
callbacks.onFailure(
GatewayTurnFailure(
error = error?.takeIf { it.isNotBlank() }
?: text.orEmpty().ifBlank { "Turn failed" },
recoverable = payload.boolean("recoverable") == true,
),
)
callbacks.onStatusUpdate(
ERROR_STATUS_KIND,
error?.takeIf { it.isNotBlank() } ?: text.orEmpty().ifBlank { "Turn failed" },
@@ -444,15 +451,26 @@ class GatewayEventMapper(
}
fun interactionRequest(type: String, payload: JsonObject?): GatewayAsk? = when (type) {
"clarify.request" -> GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull }
?.takeIf { it.isNotEmpty() },
timeoutSeconds = CLARIFY_TIMEOUT_SECONDS,
)
"clarify.request" -> {
val choices = (payload?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.trim() }
?.filter { it.isNotEmpty() }
?.distinct()
?.take(MAX_CLARIFY_CHOICES)
?.takeIf { it.isNotEmpty() }
GatewayAsk(
kind = GatewayAsk.Kind.CLARIFY,
requestId = payload.string("request_id"),
text = payload.string("question") ?: "The agent needs clarification",
choices = choices,
multiSelect = payload.boolean("multi_select") == true && choices != null,
// Current upstream owns expiry through clarify.expire and
// does not advertise its configurable deadline. Never
// invent a local deadline; consume future additive
// metadata only when it is present and positive.
timeoutSeconds = payload.int("timeout_seconds")?.coerceAtLeast(0) ?: 0,
)
}
"approval.request" -> GatewayAsk(
kind = GatewayAsk.Kind.APPROVAL,
@@ -561,9 +579,9 @@ class GatewayEventMapper(
}
}
// Upstream `_block()` timeouts per ask kind (server.py) — the blocked thread
// resolves to "" when these elapse. Approval has none (session-scoped).
private const val CLARIFY_TIMEOUT_SECONDS = 300
// Upstream clarify tool accepts at most four choices. Sudo/secret retain fixed
// `_block()` timeouts; clarify is configurable and expires authoritatively.
private const val MAX_CLARIFY_CHOICES = 4
private const val SUDO_TIMEOUT_SECONDS = 120
private const val SECRET_TIMEOUT_SECONDS = 300
@@ -583,6 +601,12 @@ private fun JsonObject?.approvalChoices(): List<String>? =
(this?.get("choices") as? JsonArray)
?.mapNotNull { (it as? JsonPrimitive)?.contentOrNull?.lowercase() }
?.filter { it in setOf("once", "session", "always", "deny") }
// Scope-denial flags are authoritative. Current upstream protected-
// instruction requests set both flags false, but gateway event builders
// can still include the broader session choice in `choices`.
// Never offer a scope the request explicitly forbids.
?.filterNot { it == "session" && this.boolean("allow_session") == false }
?.filterNot { it == "always" && this.boolean("allow_permanent") == false }
?.distinct()
?.takeIf { it.isNotEmpty() }
@@ -218,13 +218,15 @@ data class GatewayAsk(
val text: String,
/** Server-advertised answers for clarify and approval requests. */
val choices: List<String>? = null,
/** Clarify-only: several advertised choices may be returned together. */
val multiSelect: Boolean = false,
/** Approval-only: the smart observer denied and the owner may override once. */
val smartDenied: Boolean = false,
/** Secret-only: the env var the value will be stored under. */
val envVar: String? = null,
/**
* Upstream blocking timeout (clarify/secret 300s, sudo 120s). 0 means no
* countdown — approvals are session-scoped and never expire on their own.
* Server-advertised blocking timeout. 0 means no client countdown; the
* authoritative `*.expire` event still retires the interaction.
*/
val timeoutSeconds: Int,
) {
@@ -548,6 +550,12 @@ data class GatewaySessionModel(
val fast: Boolean? = null,
)
/** Structured terminal failure carried by Gateway `message.complete`. */
data class GatewayTurnFailure(
val error: String,
val recoverable: Boolean,
)
/** Result of the gateway `config.get {key:"reasoning"}` RPC. */
data class GatewayReasoningSettings(
val effort: String,
@@ -616,6 +624,10 @@ class GatewayTurnCallbacks(
val onInteractionRequest: (GatewayAsk) -> Unit,
/** Server declared a pending interaction expired; clear only the matching card. */
val onInteractionExpired: (GatewayAskExpiry) -> Unit,
/** Existing durable session could not be rebound; no prompt was submitted. */
val onResumeFailure: (String) -> Unit = { _ -> },
/** Terminal `message.complete {status:"error"}` without prose inspection. */
val onFailure: (GatewayTurnFailure) -> Unit = { _ -> },
/**
* Gateway `status.update` lifecycle line — model fallback, retries, and
* errors (often emoji-prefixed: 🔄 fallback, ⏳ retry, ❌ error). Default
@@ -6,6 +6,9 @@ import android.util.Log
import com.hermesandroid.relay.data.AgentDisplay
import com.hermesandroid.relay.data.AppAnalytics
import com.hermesandroid.relay.network.shutdownOffMainThread
import com.hermesandroid.relay.network.shared.InvalidCredentialException
import com.hermesandroid.relay.network.shared.bearerAuthorization
import com.hermesandroid.relay.network.shared.normalizeCredentialForHeader
import com.hermesandroid.relay.network.upstream.models.CreateSessionRequest
import com.hermesandroid.relay.network.upstream.models.HermesSseEvent
import com.hermesandroid.relay.network.upstream.models.MessageItem
@@ -431,15 +434,20 @@ private class RetryingEventSource(
*/
class HermesApiClient(
baseUrl: String,
private val apiKey: String,
apiKey: String,
httpClient: OkHttpClient? = null,
private val json: Json = Json {
ignoreUnknownKeys = true
isLenient = true
}
},
okHttpClient: OkHttpClient? = null,
) {
@Volatile
private var lastCapabilities: ServerCapabilities? = null
private val baseUrl: String = baseUrl.trimEnd('/')
private val apiCredential = runCatching {
normalizeCredentialForHeader(apiKey, "API credential")
}
companion object {
private const val TAG = "HermesApiClient"
@@ -479,7 +487,7 @@ class HermesApiClient(
private val mainHandler = Handler(Looper.getMainLooper())
private val client: OkHttpClient = OkHttpClient.Builder()
private val client: OkHttpClient = httpClient ?: okHttpClient ?: OkHttpClient.Builder()
.readTimeout(5, TimeUnit.MINUTES)
.connectTimeout(10, TimeUnit.SECONDS)
.build()
@@ -538,6 +546,8 @@ class HermesApiClient(
HealthCheckResult.Unhealthy("Server not found — check the hostname")
} catch (e: java.net.SocketTimeoutException) {
HealthCheckResult.Unhealthy("Connection timed out — is the server running?")
} catch (e: InvalidCredentialException) {
HealthCheckResult.Unhealthy(e.message ?: "Invalid API credential")
} catch (e: IOException) {
val msg = e.message ?: ""
when {
@@ -2021,9 +2031,8 @@ class HermesApiClient(
private fun authRequest(url: String): Request.Builder {
val builder = Request.Builder().url(url)
if (apiKey.isNotBlank()) {
builder.header("Authorization", "Bearer $apiKey")
}
val credential = apiCredential.getOrElse { throw it }
builder.bearerAuthorization(credential, "API credential")
return builder
}
@@ -2040,10 +2049,12 @@ class HermesApiClient(
*/
private fun authRequestOrNull(url: String): Request.Builder? {
val builder = buildApiRequestOrNull(url) ?: return null
if (apiKey.isNotBlank()) {
builder.header("Authorization", "Bearer $apiKey")
}
return builder
return runCatching {
builder.bearerAuthorization(
apiCredential.getOrElse { throw it },
"API credential",
)
}.getOrNull()
}
/**
@@ -2061,7 +2072,8 @@ class HermesApiClient(
/** Human message for a base URL that fails to parse (#131). */
private fun invalidBaseUrlMessage(): String =
"Invalid server address ($baseUrl) — edit the connection's API URL or re-pair."
apiCredential.exceptionOrNull()?.message
?: "Invalid server address ($baseUrl) — edit the connection's API URL or re-pair."
/**
* Make attachment drops on the SSE fallback transports explicit
@@ -4,6 +4,8 @@ import android.content.Context
import com.hermesandroid.relay.auth.SessionTokenStore
import com.hermesandroid.relay.auth.SecureStoreCache
import com.hermesandroid.relay.auth.buildRawTokenStore
import com.hermesandroid.relay.network.shared.bearerAuthorization
import com.hermesandroid.relay.network.shared.normalizeCredentialForHeader
import java.io.EOFException
import java.io.IOException
import java.io.InterruptedIOException
@@ -75,11 +77,13 @@ class EncryptedNativeDashboardTokenStore(
override fun load(): NativeDashboardTokens? =
store.getString(TOKEN_KEY)?.let { raw ->
runCatching { json.decodeFromString<NativeDashboardTokens>(raw) }.getOrNull()
runCatching {
json.decodeFromString<NativeDashboardTokens>(raw).normalizedForStorage()
}.getOrNull()
}
override fun save(tokens: NativeDashboardTokens) {
store.putString(TOKEN_KEY, json.encodeToString(tokens))
store.putString(TOKEN_KEY, json.encodeToString(tokens.normalizedForStorage()))
}
override fun clear() {
@@ -140,7 +144,16 @@ class NativeDashboardAuthClient(
.addQueryParameter("code_challenge_method", "S256")
.addQueryParameter("redirect_uri", redirectUri)
.addQueryParameter("state", state)
.apply { provider?.takeIf(String::isNotBlank)?.let { addQueryParameter("provider", it) } }
// Match the official Desktop client for Nous-hosted gateways: the
// gateway selects its single native-eligible provider. The provider
// name advertised to UI clients is presentation/configuration data,
// not a stable native-broker identifier. Other providers retain the
// explicit selector for direct client use and tests.
.apply {
provider
?.takeIf { it.isNotBlank() && !it.equals("nous", ignoreCase = true) }
?.let { addQueryParameter("provider", it) }
}
.build()
.toString()
val generation = NativeTokenRefreshCoordinator.beginAuthorization(
@@ -441,7 +454,7 @@ class DashboardBearerAuth(
val tokens = usableTokens(forceRefresh = false, failedAccessToken = null)
val request = tokens?.let {
chain.request().newBuilder()
.header("Authorization", "Bearer ${it.accessToken}")
.bearerAuthorization(it.accessToken, "Dashboard credential")
.build()
} ?: chain.request()
return chain.proceed(request)
@@ -455,9 +468,12 @@ class DashboardBearerAuth(
forceRefresh = true,
failedAccessToken = failedAccessToken,
) ?: return null
val next = "Bearer ${tokens.accessToken}"
val accessToken = normalizeCredentialForHeader(tokens.accessToken, "Dashboard credential")
val next = "Bearer $accessToken"
if (next == previous) return null
return response.request.newBuilder().header("Authorization", next).build()
return response.request.newBuilder()
.bearerAuthorization(accessToken, "Dashboard credential")
.build()
}
private fun usableTokens(
@@ -487,6 +503,14 @@ class DashboardBearerAuth(
}
}
private fun NativeDashboardTokens.normalizedForStorage(): NativeDashboardTokens = copy(
accessToken = normalizeCredentialForHeader(accessToken, "Dashboard credential")
.also { require(it.isNotEmpty()) { "Dashboard credential is empty" } },
refreshToken = if (refreshToken.isEmpty()) "" else {
normalizeCredentialForHeader(refreshToken, "Dashboard refresh credential")
},
)
internal class NativeDashboardAuthHttpException(
val statusCode: Int,
) : IOException("Dashboard native authentication failed (HTTP $statusCode)")
@@ -22,7 +22,7 @@ private const val CALLBACK_PATH = "/callback"
private const val MAX_REQUEST_LINE_BYTES = 8 * 1024
private const val MAX_HEADER_BYTES = 16 * 1024
private const val ACCEPT_POLL_MILLIS = 500
internal const val DEFAULT_NATIVE_SIGN_IN_TIMEOUT_MILLIS = 2 * 60 * 1000L
internal const val DEFAULT_NATIVE_SIGN_IN_TIMEOUT_MILLIS = 5 * 60 * 1000L
internal val NATIVE_SIGN_IN_RETURN_URI = "${BuildConfig.APPLICATION_ID}://return"
private enum class CallbackPage(
@@ -46,6 +46,48 @@ private enum class CallbackPage(
message = "No session details were saved from this attempt.",
guidance = "Return to Hermes Relay and start sign-in again.",
),
AuthorizationRejected(
modifier = "failure",
eyebrow = "Provider sign-in",
title = "Sign-in was not completed",
message = "The provider returned without an approved authorization for Hermes.",
guidance = "Return to Hermes Relay and start again if you still want to sign in.",
),
CodeRejected(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hermes rejected the sign-in code",
message = "Google sign-in finished, but hosted Hermes could not exchange its one-time callback code for a session.",
guidance = "Return to Hermes Relay and start a fresh sign-in attempt.",
),
GatewayUnavailable(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hosted Hermes could not finish sign-in",
message = "The callback reached Hermes Relay, but the hosted Hermes sign-in service was unavailable.",
guidance = "Return to Hermes Relay, wait a moment, and try again.",
),
TransportFailure(
modifier = "failure",
eyebrow = "Secure sign-in connection",
title = "Could not reach hosted Hermes",
message = "Google sign-in finished, but the secure connection back to hosted Hermes was interrupted.",
guidance = "Return to Hermes Relay and retry on a stable connection.",
),
ResponseUnsupported(
modifier = "failure",
eyebrow = "Hosted Hermes callback",
title = "Hermes returned an unsupported session",
message = "The hosted gateway answered, but its sign-in response was not compatible with this app.",
guidance = "Return to Hermes Relay and check for app and hosted Hermes updates.",
),
SessionStorageFailure(
modifier = "failure",
eyebrow = "Secure session storage",
title = "The session could not be saved",
message = "Google sign-in finished, but Android could not securely save the Hermes session on this device.",
guidance = "Return to Hermes Relay and try again. If it repeats, check the app's diagnostics.",
),
Rejected(
modifier = "rejected",
eyebrow = "Protected callback",
@@ -194,14 +236,14 @@ class NativeDashboardSignInCoordinator(
writeResponse(
socket,
status = "400 Bad Request",
page = CallbackPage.Failure,
page = CallbackPage.AuthorizationRejected,
)
throw error
} catch (error: Exception) {
writeResponse(
socket,
status = "400 Bad Request",
page = CallbackPage.Failure,
page = callbackFailurePage(error),
)
throw error
}
@@ -296,6 +338,20 @@ class NativeDashboardSignInCoordinator(
}
}
private fun callbackFailurePage(error: Throwable): CallbackPage {
val stage = nativeDashboardSignInFailureStage(error)
return when {
stage == "token_http_400" -> CallbackPage.CodeRejected
stage == "callback_error" -> CallbackPage.AuthorizationRejected
stage == "token_http_429" || stage.startsWith("token_http_5") ->
CallbackPage.GatewayUnavailable
stage == "token_shape" -> CallbackPage.ResponseUnsupported
stage == "token_store" -> CallbackPage.SessionStorageFailure
stage.startsWith("token_transport") -> CallbackPage.TransportFailure
else -> CallbackPage.Failure
}
}
private fun callbackPageHtml(page: CallbackPage): String = """
<!doctype html>
<html lang="en">
@@ -1,21 +1,27 @@
package com.hermesandroid.relay.network.upstream.models
import com.hermesandroid.relay.data.MessageReaction
import kotlinx.serialization.ExperimentalSerializationApi
import kotlinx.serialization.KSerializer
import kotlinx.serialization.SerialName
import kotlinx.serialization.Serializable
import kotlinx.serialization.SerializationException
import kotlinx.serialization.descriptors.PrimitiveKind
import kotlinx.serialization.descriptors.PrimitiveSerialDescriptor
import kotlinx.serialization.encoding.Decoder
import kotlinx.serialization.encoding.Encoder
import kotlinx.serialization.json.JsonArray
import kotlinx.serialization.json.Json
import kotlinx.serialization.json.JsonDecoder
import kotlinx.serialization.json.JsonElement
import kotlinx.serialization.json.JsonEncoder
import kotlinx.serialization.json.JsonNull
import kotlinx.serialization.json.JsonObject
import kotlinx.serialization.json.JsonPrimitive
import kotlinx.serialization.json.doubleOrNull
import kotlinx.serialization.json.jsonArray
import kotlinx.serialization.json.jsonPrimitive
import kotlinx.serialization.json.longOrNull
import java.time.Instant
/**
@@ -76,6 +82,56 @@ object FlexibleIdNonNullSerializer : KSerializer<String> {
}
}
/** Unknown-safe durable SQLite row id used by current Gateway history. */
@OptIn(ExperimentalSerializationApi::class)
object FlexibleLongSerializer : KSerializer<Long?> {
override val descriptor = PrimitiveSerialDescriptor("FlexibleLong", PrimitiveKind.LONG)
override fun deserialize(decoder: Decoder): Long? {
return try {
val jsonDecoder = decoder as? JsonDecoder
?: return decoder.decodeLong()
(jsonDecoder.decodeJsonElement() as? JsonPrimitive)?.longOrNull
} catch (_: Exception) {
null
}
}
override fun serialize(encoder: Encoder, value: Long?) {
if (value != null) encoder.encodeLong(value) else encoder.encodeNull()
}
}
/**
* Dashboard versions may expose SQLite JSON columns either as an object or as
* their raw JSON string. Normalize both shapes so persisted presentation data
* (notably message reactions) survives a history reload on every supported
* upstream version.
*/
object FlexibleJsonObjectSerializer : KSerializer<JsonObject?> {
override val descriptor = JsonObject.serializer().descriptor
override fun deserialize(decoder: Decoder): JsonObject? {
return try {
val jsonDecoder = decoder as? JsonDecoder ?: return null
when (val element = jsonDecoder.decodeJsonElement()) {
is JsonObject -> element
is JsonPrimitive -> element.content.takeIf { it.isNotBlank() }
?.let { Json.parseToJsonElement(it) as? JsonObject }
else -> null
}
} catch (_: Exception) {
null
}
}
override fun serialize(encoder: Encoder, value: JsonObject?) {
val jsonEncoder = encoder as? JsonEncoder
?: throw SerializationException("FlexibleJsonObjectSerializer requires JSON")
jsonEncoder.encodeJsonElement(value ?: JsonNull)
}
}
/** Timestamp serializer for Hermes session metadata.
*
* Upstream currently returns epoch seconds for `started_at` / `last_active`;
@@ -113,6 +169,32 @@ object FlexibleTimestampSerializer : KSerializer<Double?> {
}
}
/**
* Boolean serializer for session flags backed by SQLite integer columns.
*
* Older Dashboard responses can expose those columns as `0` / `1` instead of
* JSON booleans. Accept the equivalent primitive forms without making arbitrary
* numbers or strings truthy, and always serialize back to a real JSON boolean.
*/
object FlexibleBooleanSerializer : KSerializer<Boolean> {
override val descriptor = PrimitiveSerialDescriptor("FlexibleBoolean", PrimitiveKind.BOOLEAN)
override fun deserialize(decoder: Decoder): Boolean {
val jsonDecoder = decoder as? JsonDecoder ?: return decoder.decodeBoolean()
val element = jsonDecoder.decodeJsonElement()
val value = (element as? JsonPrimitive)?.content?.trim()?.lowercase()
return when (value) {
"true", "1" -> true
"false", "0" -> false
else -> throw SerializationException("Expected a boolean-compatible value, got $element")
}
}
override fun serialize(encoder: Encoder, value: Boolean) {
encoder.encodeBoolean(value)
}
}
// --- Session CRUD responses ---
@Serializable
@@ -166,15 +248,50 @@ data class SessionItem(
@SerialName("tool_call_count") val toolCallCount: Int? = null,
@SerialName("input_tokens") val inputTokens: Int? = null,
@SerialName("output_tokens") val outputTokens: Int? = null,
@SerialName("has_model_config") val hasModelConfig: Boolean = false,
@SerialName("actual_cost_usd") val actualCostUsd: Double? = null,
@SerialName("estimated_cost_usd") val estimatedCostUsd: Double? = null,
@SerialName("is_active") val isActive: Boolean = false,
@SerialName("has_model_config")
@Serializable(with = FlexibleBooleanSerializer::class)
val hasModelConfig: Boolean = false,
/** Durable flags returned by current Dashboard and API-server session resources. */
@Serializable(with = FlexibleBooleanSerializer::class)
val pinned: Boolean = false,
@Serializable(with = FlexibleBooleanSerializer::class)
val archived: Boolean = false,
/** Optional workspace metadata added by newer Dashboard session lists. */
val cwd: String? = null,
@SerialName("git_branch") val gitBranch: String? = null,
@SerialName("git_repo_root") val gitRepoRoot: String? = null,
/** Best-effort association from the Dashboard's read-only transcript scan. */
val pullRequest: SessionPullRequest? = null,
) {
val resolvedLastActivity: Double?
get() = lastActive ?: lastActivity ?: lastActivityAt ?: updatedAt
}
@Serializable
data class SessionPullRequest(
val number: Int,
val url: String,
val branch: String? = null,
val state: String? = null,
val draft: Boolean = false,
val title: String? = null,
)
@Serializable
data class SessionPullRequestScanResponse(
@SerialName("pull_requests") val pullRequests: Map<String, SessionPullRequest> = emptyMap(),
val scanned: List<String> = emptyList(),
)
@Serializable
data class RepositoryPullRequestListResponse(
val ghReady: Boolean = false,
val prs: List<SessionPullRequest> = emptyList(),
)
@Serializable
data class CreateSessionRequest(
val title: String? = null,
@@ -265,6 +382,9 @@ data class MessageItem(
@SerialName("session_id")
@Serializable(with = FlexibleIdSerializer::class)
val sessionId: String? = null,
@SerialName("row_id")
@Serializable(with = FlexibleLongSerializer::class)
val rowId: Long? = null,
val role: String,
val content: JsonElement? = null,
@SerialName("tool_calls") val toolCalls: JsonElement? = null,
@@ -275,7 +395,9 @@ data class MessageItem(
val timestamp: Double? = null,
@SerialName("finish_reason") val finishReason: String? = null,
@SerialName("display_kind") val displayKind: String? = null,
@SerialName("display_metadata") val displayMetadata: JsonObject? = null,
@SerialName("display_metadata")
@Serializable(with = FlexibleJsonObjectSerializer::class)
val displayMetadata: JsonObject? = null,
// Reasoning persisted with the assistant message (upstream serializes
// both names; reasoning is the canonical one). Restored into
// ChatMessage.thinkingContent so the Thought-process block survives a
@@ -283,11 +405,24 @@ data class MessageItem(
val reasoning: String? = null,
@SerialName("reasoning_content") val reasoningContent: String? = null,
) {
/**
* Dashboard history uses the SQLite row id as numeric `id`; Gateway
* history exposes the same value explicitly as `row_id`. Match Desktop by
* accepting either representation so persisted rows remain directly
* reactable after reload.
*/
val resolvedRowId: Long?
get() = rowId ?: id?.toLongOrNull()
/** Reasoning text under whichever field name the server used. */
val resolvedReasoning: String?
get() = reasoning?.takeIf { it.isNotBlank() }
?: reasoningContent?.takeIf { it.isNotBlank() }
/** Persisted tapbacks stored by Hermes in display_metadata.reactions. */
val reactions: List<MessageReaction>
get() = parseMessageReactions(displayMetadata?.get("reactions"))
/** Extract content as plain text string. Handles both string and array-of-parts formats. */
val contentText: String?
get() = when (content) {
@@ -315,6 +450,21 @@ data class MessageItem(
}
}
fun parseMessageReactions(element: JsonElement?): List<MessageReaction> =
(element as? JsonArray).orEmpty().mapNotNull { raw ->
val reaction = raw as? JsonObject ?: return@mapNotNull null
val emoji = (reaction["emoji"] as? JsonPrimitive)?.content?.takeIf { it.isNotBlank() }
?: return@mapNotNull null
val author = (reaction["author"] as? JsonPrimitive)?.content
?.takeIf { it == "user" || it == "agent" }
?: return@mapNotNull null
MessageReaction(
emoji = emoji,
author = author,
at = (reaction["at"] as? JsonPrimitive)?.doubleOrNull ?: 0.0,
)
}
// --- SSE streaming events from /api/sessions/{id}/chat/stream ---
//
// Hermes WebAPI event types (from server source):
@@ -9,6 +9,7 @@ import android.content.Context
import android.content.Intent
import android.content.pm.PackageManager
import android.os.Build
import android.net.Uri
import android.util.Log
import androidx.core.app.NotificationCompat
import androidx.core.app.NotificationManagerCompat
@@ -47,10 +48,13 @@ object ProactiveMessageNotifier {
/**
* Tap route — opens Chat, where the message lives as a Thread. Must match
* `Screen.Chat.route()` in RelayApp. Routed via the EXTRA_NAV_ROUTE deep-link
* path (MainActivity → NavRouteRequest → RelayApp collector). Opening the
* exact Thread by chat_id is a follow-up (see TODO).
* path (MainActivity → NavRouteRequest → RelayApp collector), carrying the
* `chat_id` so RelayApp opens the exact real or provisional Thread.
*/
private const val TAP_ROUTE = "chat"
private fun tapRoute(chatId: String?): String =
chatId?.takeIf { it.isNotBlank() }
?.let { "chat?proactiveChatId=${Uri.encode(it)}" }
?: "chat"
/**
* Post (or replace) a proactive-message notification.
@@ -80,7 +84,7 @@ object ProactiveMessageNotifier {
val tapIntent = Intent(context, MainActivity::class.java).apply {
flags = Intent.FLAG_ACTIVITY_NEW_TASK or Intent.FLAG_ACTIVITY_CLEAR_TOP
putExtra(MainActivity.EXTRA_NAV_ROUTE, TAP_ROUTE)
putExtra(MainActivity.EXTRA_NAV_ROUTE, tapRoute(chatId))
}
val pendingFlags = PendingIntent.FLAG_UPDATE_CURRENT or PendingIntent.FLAG_IMMUTABLE
// Distinct requestCode per slot so each notification gets its own
@@ -90,6 +90,29 @@ object ReliabilityCenter {
writer.execute { runCatching { target.append(report) } }
}
/** Persist a bounded, content-free checkpoint before a user-requested chat reset. */
fun recordSessionCheckpoint(context: Context, evidence: SessionResetEvidence) {
initialize(context)
val report = ReliabilityReport(
reportId = ReliabilityReport.newId("checkpoint"),
appSessionId = appSessionId,
timeIso = Instant.now().toString(),
kind = ReliabilityKind.SessionCheckpoint,
owner = ReliabilityOwner.Android,
severity = ReliabilitySeverity.Info,
summary = "Chat context reset",
recovery = "The prior context remains on Hermes when it had a stored session.",
reportRecommended = false,
technicalDetail = evidence.technicalDetail(),
routeRole = evidence.transport,
environment = environment(),
)
// A pre-reset checkpoint is useful only if it lands before state is
// replaced. The store is tiny and atomically rewritten, so persist it
// synchronously instead of queueing behind later failures.
runCatching { store?.append(report) }
}
fun reports(context: Context): List<ReliabilityReport> {
initialize(context)
return store?.readAll().orEmpty()
@@ -15,6 +15,7 @@ const val RELIABILITY_SCHEMA_VERSION = 1
enum class ReliabilityKind {
FatalCrash,
AnrSignal,
SessionCheckpoint,
RecoverableProductError,
Connectivity,
Authentication,
@@ -0,0 +1,33 @@
package com.hermesandroid.relay.reliability
/**
* Content-free evidence captured immediately before Android replaces a chat
* context. Deliberately excludes prompts, message text, IDs, profile names,
* URLs, paths, attachments, and tool arguments/results.
*/
data class SessionResetEvidence(
val reason: String,
val transport: String,
val messageCount: Int,
val toolCount: Int,
val queuedCount: Int,
val pendingAttachmentCount: Int,
val hadStoredSession: Boolean,
val turnActive: Boolean,
val askPending: Boolean,
) {
fun technicalDetail(): String = buildString {
appendLine("reason=${reason.safeToken()}")
appendLine("transport=${transport.safeToken()}")
appendLine("messages=${messageCount.coerceAtLeast(0)}")
appendLine("tools=${toolCount.coerceAtLeast(0)}")
appendLine("queued=${queuedCount.coerceAtLeast(0)}")
appendLine("pending_attachments=${pendingAttachmentCount.coerceAtLeast(0)}")
appendLine("had_stored_session=$hadStoredSession")
appendLine("turn_active=$turnActive")
append("ask_pending=$askPending")
}
private fun String.safeToken(): String =
lowercase().replace(Regex("[^a-z0-9_.-]"), "_").take(40).ifBlank { "unknown" }
}
@@ -5,6 +5,8 @@ import androidx.lifecycle.ViewModelStore
import com.hermesandroid.relay.HermesRelayApp
import com.hermesandroid.relay.data.VoicePreferencesRepository
import com.hermesandroid.relay.data.VoiceSettings
import com.hermesandroid.relay.data.PersistentChatComposerDraftStore
import java.io.File
import com.hermesandroid.relay.network.relay.RelayVoiceClient
import com.hermesandroid.relay.viewmodel.ChatViewModel
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
@@ -70,7 +72,13 @@ class HermesProcessRuntime internal constructor(
}
val chatViewModel: ChatViewModel by lazy(LazyThreadSafetyMode.SYNCHRONIZED) {
viewModelProvider[ChatViewModel::class.java]
viewModelProvider[ChatViewModel::class.java].also { chat ->
chat.installComposerDraftStore(
PersistentChatComposerDraftStore(
File(application.noBackupFilesDir, "chat-composer-drafts"),
),
)
}
}
val voiceViewModel: VoiceViewModel by lazy(LazyThreadSafetyMode.SYNCHRONIZED) {
@@ -142,8 +142,8 @@ internal class HermesRuntimeBinder(
voiceHandoffReporter = connection::recordVoiceHandoff,
bargeInPreferences = BargeInPreferencesRepository(application),
vadEngineFactory = { VadEngine(application) },
bargeInListenerFactory = { vad, audioSessionIdProvider ->
BargeInListener.create(application, vad, audioSessionIdProvider)
bargeInListenerFactory = { vad ->
BargeInListener.create(application, vad)
},
)
@@ -176,7 +176,9 @@ internal class HermesRuntimeBinder(
chat.setDisplayProfileProvider { connection.effectiveDisplayProfile.value }
chat.setDisplayAliasProvider { connection.profileDisplayAlias.value }
chat.setProfileSessionLister { connection.listProfileScopedSessions() }
chat.setProfileMessageLoaderWithMode(connection::loadProfileScopedMessages)
chat.setProfileMessageLoaderWithMode { profileName, sessionId, mode ->
connection.loadProfileScopedMessages(profileName, sessionId, mode)
}
chat.setDashboardConfigLoader { connection.loadActiveDashboardConfig() }
chat.profileSessionDeleter = connection::deleteProfileScopedSession
chat.profileSessionRenamer = connection::renameProfileScopedSession
@@ -96,6 +96,7 @@ import com.hermesandroid.relay.ui.components.avatar.LocalFloatingPet
import com.hermesandroid.relay.ui.components.avatar.LocalPetPlaybackSpeed
import com.hermesandroid.relay.ui.components.avatar.LocalPetStabilize
import com.hermesandroid.relay.ui.components.avatar.PetLoader
import com.hermesandroid.relay.ui.components.avatar.toAvatar
import com.hermesandroid.relay.ui.components.avatar.SphereAvatar
import com.hermesandroid.relay.ui.components.avatar.resolveBackgroundAvatar
import com.hermesandroid.relay.ui.components.FloatingPetCompanion
@@ -116,6 +117,7 @@ import com.hermesandroid.relay.ui.components.PowerFeatureGateStatus
import com.hermesandroid.relay.ui.components.RelayStatusStrip
import com.hermesandroid.relay.ui.components.UnattendedGlobalBanner
import com.hermesandroid.relay.ui.components.UpdateAvailableBanner
import com.hermesandroid.relay.ui.components.HostResourcePressureBanner
import com.hermesandroid.relay.ui.components.rememberUpdateAvailability
import com.hermesandroid.relay.ui.components.resolveChatTransportStatus
import com.hermesandroid.relay.ui.components.WhatsNewDialog
@@ -336,17 +338,20 @@ sealed class Screen(
// NavHost, and the NavigationBarItem click must navigate via [route]()
// so no unresolved `{openAgentSheet}` leaks into the destination.
data object Chat : Screen(
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}",
"chat?openAgentSheet={openAgentSheet}&sessionId={sessionId}&profile={profile}" +
"&proactiveChatId={proactiveChatId}",
"Chat",
Icons.AutoMirrored.Filled.Chat,
) {
const val ARG_OPEN_AGENT_SHEET: String = "openAgentSheet"
const val ARG_SESSION_ID: String = "sessionId"
const val ARG_PROFILE: String = "profile"
const val ARG_PROACTIVE_CHAT_ID: String = "proactiveChatId"
fun route(
openAgentSheet: Boolean = false,
sessionId: String? = null,
profile: String? = null,
proactiveChatId: String? = null,
): String {
val params = buildList {
if (openAgentSheet) add("$ARG_OPEN_AGENT_SHEET=true")
@@ -356,6 +361,9 @@ sealed class Screen(
profile?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROFILE=${android.net.Uri.encode(it)}")
}
proactiveChatId?.takeIf { it.isNotBlank() }?.let {
add("$ARG_PROACTIVE_CHAT_ID=${android.net.Uri.encode(it)}")
}
}
return if (params.isEmpty()) "chat" else "chat?${params.joinToString("&")}"
}
@@ -618,21 +626,11 @@ fun RelayApp() {
val standardVoiceAvailability by connectionViewModel.standardVoiceAvailability.collectAsState()
val relayVoiceReady by connectionViewModel.relayVoiceReady.collectAsState()
// Profile Inspector client. Shares the same lazy relay URL + bearer
// token providers as the voice client so any rotation/re-pair is
// automatically picked up on the next fetch. Process-stable via
// remember {} so the OkHttpClient isn't rebuilt on recomposition.
val profileInspectorClient = remember {
RelayProfileInspectorClient(
okHttpClient = okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build(),
relayUrlProvider = { connectionViewModel.effectiveRelayUrl.value },
sessionTokenProvider = {
(connectionViewModel.authState.value as? AuthState.Paired)?.token
},
)
val profileInspectorHttpClient = remember {
okhttp3.OkHttpClient.Builder()
.readTimeout(30, java.util.concurrent.TimeUnit.SECONDS)
.connectTimeout(15, java.util.concurrent.TimeUnit.SECONDS)
.build()
}
// === PHASE3-status: sync granular phone-status settings to chat ===
val appContextEnabled by connectionViewModel.appContextEnabled.collectAsState()
@@ -745,8 +743,12 @@ fun RelayApp() {
) {
value = withContext(Dispatchers.IO) { PetLoader.loadPets(sphereContext) }
}
val activeFloatingPet = remember(floatingPetId, availablePets) {
availablePets.firstOrNull { it.id == floatingPetId }
val hermesPetState by connectionViewModel.hermesPetState.collectAsState()
val upstreamProfilePet = remember(hermesPetState.active) {
hermesPetState.active?.toAvatar()
}
val activeFloatingPet = remember(floatingPetId, availablePets, upstreamProfilePet) {
availablePets.firstOrNull { it.id == floatingPetId } ?: upstreamProfilePet
}
var floatingPetMenuExpanded by remember(activeFloatingPet?.id) { mutableStateOf(false) }
val activeBackgroundAvatar = remember(backgroundAvatarId, availablePets) {
@@ -891,6 +893,7 @@ fun RelayApp() {
// ChatViewModel isn't available where ConnectionViewModel builds the
// handler, so the session sink is set here at the app root where both
// ViewModels are in scope.
val proactiveSummaryResources = LocalContext.current.resources
LaunchedEffect(connectionViewModel, chatViewModel) {
connectionViewModel.proactiveMessageHandler.toSession = { msg ->
val text = buildString {
@@ -899,6 +902,15 @@ fun RelayApp() {
}
chatViewModel.injectProactiveMessage(text)
}
connectionViewModel.proactiveMessageHandler.onBacklogDelivered = { count ->
UiMessageBus.info(
proactiveSummaryResources.getQuantityString(
R.plurals.proactive_messages_arrived_while_away,
count,
count,
),
)
}
// Agent Thread reply path: a send from the chat composer while a
// source=phone Thread is open routes over the relay proactive
// channel (continues the gateway phone session) instead of a normal
@@ -910,7 +922,8 @@ fun RelayApp() {
chatViewModel.onProactiveReplyAck(clientMsgId, status)
}
// Unified Threads: render an inbound agent message inline in the open
// Thread (suppressing the notification/inbox) when it belongs there.
// Thread when it belongs there. Surfacing semantics still decide
// independently whether a system notification is also required.
connectionViewModel.proactiveMessageHandler.injectIntoThread = { msg ->
chatViewModel.injectThreadMessage(msg)
}
@@ -1374,12 +1387,22 @@ fun RelayApp() {
}
val masterEnabled by masterEnabledFlow.collectAsState(initial = false)
val unattendedEnabled by unattendedEnabledFlow.collectAsState(initial = false)
val activeBridgePolicy by (connectionViewModel.bridgeSafety?.activeCapabilityPolicy
?: remember { kotlinx.coroutines.flow.MutableStateFlow(
com.hermesandroid.relay.bridge.BridgeCapabilityPolicy(),
) })
.collectAsState()
val timedScreenControlActive = activeBridgePolicy.allows(
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_CONTROL,
System.currentTimeMillis(),
)
// Sideload-only: googlePlay has no wake lock and the unattended
// flag never gets written there — gating here is defence in depth
// and makes the check cheap via R8 in release builds.
val showUnattendedBanner = BuildFlavor.isSideload &&
masterEnabled &&
unattendedEnabled &&
timedScreenControlActive &&
!suppressGlobalChrome &&
!showStartupSphere &&
!voiceUiState.voiceMode
@@ -1387,6 +1410,22 @@ fun RelayApp() {
// user always knows the chat is sample data with no live server, and
// can exit into the real Connect flow with one tap.
val showDemoBanner = isDemoMode && !voiceUiState.voiceMode
val hostResourcePressure by connectionViewModel.hostResourcePressure.collectAsState()
val showHostResourcePressure = hostResourcePressure.needsAttention &&
!isDemoMode && !voiceUiState.voiceMode && !showStartupSphere
val hostResourcePressureText = buildList {
if (hostResourcePressure.lastBootSuspectedOom) {
add(stringResource(R.string.host_resource_recent_oom))
}
when (hostResourcePressure.memoryPressure) {
"critical" -> add(stringResource(R.string.host_resource_memory_critical))
"elevated" -> add(stringResource(R.string.host_resource_memory_elevated))
}
when (hostResourcePressure.diskPressure) {
"critical" -> add(stringResource(R.string.host_resource_disk_critical))
"elevated" -> add(stringResource(R.string.host_resource_disk_elevated))
}
}.distinct().joinToString(" ")
// Transient info/status banner (UiMessageBus) — thin, takes its own
// space, auto-dismisses. Folded into the inset accounting below so a
// child TopAppBar doesn't double-pad when this banner owns the top edge.
@@ -1493,6 +1532,18 @@ fun RelayApp() {
DemoModeBanner(onConnect = exitDemoToConnect)
}
AnimatedVisibility(
visible = showHostResourcePressure,
enter = fadeIn(tween(200)),
exit = fadeOut(tween(200)),
) {
HostResourcePressureBanner(
text = hostResourcePressureText,
critical = hostResourcePressure.critical,
includeStatusBarPadding = !showUnattendedBanner && !showDemoBanner,
)
}
// Connection status intentionally has NO top-of-screen surface (no
// banner, no strip, no float). Chat/agent status rides the chat header
// subtitle; the relay socket rides the bottom RelayStatusStrip cue. See
@@ -1503,7 +1554,7 @@ fun RelayApp() {
// that banner already padded the top — avoid double padding).
MessageBannerHost(
includeStatusBarPadding =
!showUnattendedBanner && !showDemoBanner,
!showUnattendedBanner && !showDemoBanner && !showHostResourcePressure,
)
// The update banner AND the connection-status indicator now render as
@@ -1543,7 +1594,7 @@ fun RelayApp() {
// The connection-status toast is now a floating overlay and
// doesn't occupy space above the Scaffold, so it no longer
// participates in the top-inset accounting.
if (showUnattendedBanner || showDemoBanner || connectionChipVisible ||
if (showUnattendedBanner || showDemoBanner || showHostResourcePressure || connectionChipVisible ||
showMessageBanner
) {
Modifier.consumeWindowInsets(WindowInsets.statusBars)
@@ -1587,7 +1638,7 @@ fun RelayApp() {
?: AgentDisplay.displayModelName(serverModelName)
?: stringResource(R.string.status_model_pending)
val safetyLabel = if (BuildFlavor.isSideload && masterEnabled) {
if (unattendedEnabled) stringResource(R.string.status_safety_unattended)
if (unattendedEnabled && timedScreenControlActive) stringResource(R.string.status_safety_unattended)
else stringResource(R.string.status_safety_on)
} else {
stringResource(R.string.status_profile_format, profileLabel)
@@ -1695,6 +1746,11 @@ fun RelayApp() {
nullable = true
defaultValue = null
},
navArgument(Screen.Chat.ARG_PROACTIVE_CHAT_ID) {
type = NavType.StringType
nullable = true
defaultValue = null
},
),
) { backStackEntry ->
// Responsive bubble width based on screen width. The "Blend"
@@ -1725,6 +1781,35 @@ fun RelayApp() {
val requestedProfileRoute = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROFILE)
?.takeIf { it.isNotBlank() }
val requestedProactiveChatId = backStackEntry.arguments
?.getString(Screen.Chat.ARG_PROACTIVE_CHAT_ID)
?.takeIf { it.isNotBlank() }
val proactiveInboxEntries by connectionViewModel.inboxMessages.collectAsState()
val phoneThreadChatIds by connectionViewModel.phoneThreadChatIds.collectAsState()
LaunchedEffect(
requestedProactiveChatId,
proactiveInboxEntries,
phoneThreadChatIds,
) {
val chatId = requestedProactiveChatId ?: return@LaunchedEffect
val realSessionId = phoneThreadChatIds.entries
.firstOrNull { it.value == chatId }
?.key
if (realSessionId != null) {
chatViewModel.switchSession(realSessionId)
} else {
val entries = proactiveInboxEntries.filter {
(it.connectionId == null || it.connectionId == activeConnectionId) &&
(it.chatId ?: "phone") == chatId
}
if (entries.isEmpty()) return@LaunchedEffect
chatViewModel.openProactiveThread(chatId, entries)
}
backStackEntry.arguments?.putString(
Screen.Chat.ARG_PROACTIVE_CHAT_ID,
null,
)
}
LaunchedEffect(
requestedSessionId,
requestedProfileRoute,
@@ -2241,6 +2326,7 @@ fun RelayApp() {
composable(Screen.BridgeSafetySettings.route) {
if (BuildFlavor.isSideload) {
BridgeSafetySettingsScreen(
connectionId = activeConnectionId,
onBack = { navController.popBackStack() }
)
} else {
@@ -2619,7 +2705,8 @@ fun RelayApp() {
val sectionArg = backStackEntry.arguments
?.getString(Screen.ProfileInspector.ARG_SECTION)
?: Screen.ProfileInspector.SECTION_CONFIG
if (coldStartAuthState !is AuthState.Paired) {
val inspectorGatewayClient = connectionViewModel.activeGatewayChatClient()
if (coldStartAuthState !is AuthState.Paired && inspectorGatewayClient == null) {
PowerFeatureGateScreen(
title = stringResource(R.string.screen_profile_inspector_label),
summary = stringResource(R.string.power_gate_profile_inspector_summary),
@@ -2647,8 +2734,18 @@ fun RelayApp() {
// SavedStateHandle contains our
// `profileName` arg automatically.
val ssh = extras.createSavedStateHandle()
// Freeze both transports to the connection that
// owned this nav entry. A later connection/profile
// switch cannot redirect an open editor's writes.
val relayUrl = connectionViewModel.effectiveRelayUrl.value
val relayToken = (connectionViewModel.authState.value as? AuthState.Paired)?.token
return ProfileInspectorViewModel(
client = profileInspectorClient,
legacyClient = RelayProfileInspectorClient(
okHttpClient = profileInspectorHttpClient,
relayUrlProvider = { relayUrl },
sessionTokenProvider = { relayToken },
),
gatewayClient = inspectorGatewayClient,
savedStateHandle = ssh,
) as T
}
@@ -821,12 +821,21 @@ private fun ManualUrlSubsection(
val apiServerUrl by connectionViewModel.apiServerUrl.collectAsState()
val relayUrl by connectionViewModel.relayUrl.collectAsState()
val apiKeyPresent by connectionViewModel.authManager.apiKeyPresent.collectAsState()
val savedApiKeyError by connectionViewModel.authManager.apiKeyError.collectAsState()
val relayConnectionState by connectionViewModel.relayConnectionState.collectAsState()
// Keyed on the backing URL so a connection switch refreshes the input.
var apiUrlInput by remember(apiServerUrl) { mutableStateOf(apiServerUrl) }
var apiKeyInput by remember { mutableStateOf("") }
var apiKeyVisible by remember { mutableStateOf(false) }
val apiKeySingleLineError = stringResource(R.string.api_credential_single_line_error)
val inputApiKeyError = remember(apiKeyInput, apiKeySingleLineError) {
if (apiKeyInput.trim(' ', '\t').any { it < '!' || it > '~' }) {
apiKeySingleLineError
} else {
null
}
}
var relayUrlInput by remember(relayUrl) { mutableStateOf(relayUrl) }
var isTestingApi by remember { mutableStateOf(false) }
var apiVoiceSetupResult by remember {
@@ -900,13 +909,14 @@ private fun ManualUrlSubsection(
},
supportingText = {
Text(
if (apiKeyPresent && apiKeyInput.isBlank()) {
inputApiKeyError ?: savedApiKeyError ?: if (apiKeyPresent && apiKeyInput.isBlank()) {
apiKeyStoredHint
} else {
apiKeyNeededHint
},
)
},
isError = inputApiKeyError != null || (apiKeyInput.isBlank() && savedApiKeyError != null),
singleLine = true,
visualTransformation = if (apiKeyVisible) {
VisualTransformation.None
@@ -962,7 +972,7 @@ private fun ManualUrlSubsection(
).show()
}
},
enabled = apiUrlInput.isNotBlank() && !isTestingApi,
enabled = apiUrlInput.isNotBlank() && !isTestingApi && inputApiKeyError == null,
) {
Text(saveAndTestText)
}
@@ -1739,7 +1749,10 @@ fun ActiveCardRoutesSection(
var routeEditorOriginal by remember(connection.id) {
mutableStateOf<EndpointCandidate?>(null)
}
val hasTailscaleRoute = endpoints.any { it.role.equals("tailscale", ignoreCase = true) }
val hasTailscaleRoute = hasConfiguredTailscaleRoute(
endpoints = endpoints,
primaryEndpointUrl = connection.primaryEndpointUrl,
)
val tailscalePreferred = preferredRole?.equals("tailscale", ignoreCase = true) == true
val routeNeedsAttention = activeEndpoint == null && liveState != RelayUiState.Connected
val showTailscaleUnavailableHint =
@@ -2171,6 +2184,12 @@ fun ActiveCardRoutesSection(
}
}
internal fun hasConfiguredTailscaleRoute(
endpoints: List<EndpointCandidate>,
primaryEndpointUrl: String,
): Boolean = endpoints.any { it.role.equals("tailscale", ignoreCase = true) } ||
Connection.inferRouteRole(primaryEndpointUrl) == "tailscale"
/**
* Numbered step row for the Manual pairing code fallback. Tightly
* coupled to its Card 3 layout — step badge sizing + content shape —
@@ -3,105 +3,422 @@ package com.hermesandroid.relay.ui.components
import android.net.Uri
import androidx.activity.compose.rememberLauncherForActivityResult
import androidx.activity.result.contract.ActivityResultContracts
import androidx.compose.foundation.BorderStroke
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Box
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.ColumnScope
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.fillMaxSize
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.lazy.LazyColumn
import androidx.compose.foundation.lazy.items
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.CircularProgressIndicator
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.OutlinedButton
import androidx.compose.material3.Surface
import androidx.compose.material3.Switch
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
import androidx.compose.ui.layout.ContentScale
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.unit.dp
import coil3.compose.AsyncImage
import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.R
import com.hermesandroid.relay.ui.components.SphereState
import com.hermesandroid.relay.ui.components.avatar.AvatarRenderState
import com.hermesandroid.relay.ui.components.avatar.PetAvatar
import com.hermesandroid.relay.ui.components.avatar.toAvatar
import com.hermesandroid.relay.viewmodel.ConnectionViewModel
import java.io.File
/**
* Per-profile agent-icon picker — the visual twin of the local-name (alias) row.
* The chosen image is copied into app storage and shown beside the agent's name
* in chat. Client-side only: never sent to Hermes. Keyed per `(connection,
* profile)` by [ConnectionViewModel.setProfileIcon] / `ProfileIconStore`.
*/
/** Shared Hermes identity and a separately-scoped phone presentation override. */
@Composable
fun AgentIconRow(connectionViewModel: ConnectionViewModel) {
val iconPath by connectionViewModel.profileIcon.collectAsState()
val localIconPath by connectionViewModel.localProfileIcon.collectAsState()
val serverAvatarPath by connectionViewModel.serverProfileAvatar.collectAsState()
val useLocalOverride by connectionViewModel.useLocalProfileIconOverride.collectAsState()
val hostImportState by connectionViewModel.hostProfileIconImportState.collectAsState()
val launcher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument()
) { uri: Uri? -> uri?.let { connectionViewModel.setProfileIcon(it) } }
val sharedState by connectionViewModel.sharedProfileAvatarState.collectAsState()
val hermesPetState by connectionViewModel.hermesPetState.collectAsState()
val hermesPetAvatar = remember(hermesPetState.active) { hermesPetState.active?.toAvatar() }
var confirmSharedRemoval by remember { mutableStateOf(false) }
var showHermesPetPicker by remember { mutableStateOf(false) }
Column(verticalArrangement = Arrangement.spacedBy(6.dp)) {
LaunchedEffect(Unit) { connectionViewModel.refreshHermesPet() }
val sharedLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument(),
) { uri: Uri? -> uri?.let(connectionViewModel::setSharedProfileAvatar) }
val localLauncher = rememberLauncherForActivityResult(
ActivityResultContracts.OpenDocument(),
) { uri: Uri? -> uri?.let(connectionViewModel::setProfileIcon) }
Column(verticalArrangement = Arrangement.spacedBy(10.dp)) {
Text(
text = stringResource(R.string.agent_icon_title),
style = MaterialTheme.typography.labelLarge,
color = MaterialTheme.colorScheme.onSurface,
)
Row(
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Box(
modifier = Modifier
.size(44.dp)
.clip(CircleShape)
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
val path = iconPath
if (!path.isNullOrBlank()) {
AsyncImage(
model = File(path),
contentDescription = stringResource(R.string.agent_icon_title),
contentScale = ContentScale.Crop,
modifier = Modifier.fillMaxSize(),
HermesPetPreview(hermesPetAvatar)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_hermes_pet_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = when {
hermesPetState.supported == false -> stringResource(R.string.agent_icon_hermes_pet_unsupported)
hermesPetState.active != null -> stringResource(
R.string.agent_icon_hermes_pet_active,
hermesPetState.active?.displayName.orEmpty(),
)
else -> stringResource(R.string.agent_icon_hermes_pet_empty)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
if (hermesPetState.loading) {
CircularProgressIndicator(modifier = Modifier.size(24.dp), strokeWidth = 2.dp)
} else if (hermesPetState.supported != false) {
Switch(
checked = hermesPetState.active != null,
onCheckedChange = { enabled ->
if (enabled) {
showHermesPetPicker = true
connectionViewModel.loadHermesPetGallery()
} else {
connectionViewModel.disableHermesPet()
}
},
)
}
}
OutlinedButton(onClick = { launcher.launch(arrayOf("image/*")) }) {
Text(if (iconPath.isNullOrBlank()) stringResource(R.string.agent_icon_set) else stringResource(R.string.agent_icon_change))
}
if (!iconPath.isNullOrBlank()) {
TextButton(onClick = { connectionViewModel.clearProfileIcon() }) {
Text(stringResource(R.string.agent_icon_clear))
if (hermesPetState.supported != false) {
OutlinedButton(
onClick = {
showHermesPetPicker = true
connectionViewModel.loadHermesPetGallery()
},
enabled = !hermesPetState.loading,
modifier = Modifier.fillMaxWidth(),
) {
Text(stringResource(R.string.agent_icon_hermes_pet_browse))
}
}
}
OutlinedButton(
onClick = { connectionViewModel.importProfileIconFromHost() },
enabled = !hostImportState.loading,
) {
Text(
if (hostImportState.loading) {
stringResource(R.string.agent_icon_importing_host)
} else {
stringResource(R.string.agent_icon_import_host)
}
)
}
hostImportState.error?.let { error ->
Text(
text = error,
text = stringResource(R.string.agent_icon_hermes_pet_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
text = stringResource(R.string.agent_icon_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
AvatarPreview(serverAvatarPath)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_shared_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = if (serverAvatarPath.isNullOrBlank()) {
stringResource(R.string.agent_icon_shared_empty)
} else {
stringResource(R.string.agent_icon_shared_active)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
Row(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
OutlinedButton(
onClick = {
sharedLauncher.launch(arrayOf("image/*"))
},
enabled = !sharedState.loading,
) {
Text(stringResource(R.string.agent_icon_change_shared))
}
if (!serverAvatarPath.isNullOrBlank()) {
TextButton(
onClick = { confirmSharedRemoval = true },
enabled = !sharedState.loading,
) {
Text(
text = stringResource(R.string.agent_icon_remove_shared),
color = MaterialTheme.colorScheme.error,
)
}
}
}
sharedState.error?.let { AvatarError(it) }
}
AvatarSourceCard {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
AvatarPreview(localIconPath)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.agent_icon_phone_title),
style = MaterialTheme.typography.titleSmall,
)
Text(
text = stringResource(R.string.agent_icon_phone_description),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Switch(
checked = useLocalOverride,
onCheckedChange = connectionViewModel::setUseLocalProfileIconOverride,
)
}
OutlinedButton(
onClick = { localLauncher.launch(arrayOf("image/*")) },
modifier = Modifier.fillMaxWidth(),
enabled = useLocalOverride,
) {
Text(
if (localIconPath.isNullOrBlank()) {
stringResource(R.string.agent_icon_choose_phone)
} else {
stringResource(R.string.agent_icon_change_phone)
},
)
}
OutlinedButton(
onClick = connectionViewModel::importProfileIconFromHost,
modifier = Modifier.fillMaxWidth(),
enabled = useLocalOverride && !hostImportState.loading,
) {
Text(
if (hostImportState.loading) {
stringResource(R.string.agent_icon_importing_host)
} else {
stringResource(R.string.agent_icon_import_host)
},
)
}
if (!localIconPath.isNullOrBlank()) {
TextButton(
onClick = connectionViewModel::clearProfileIcon,
enabled = useLocalOverride,
) {
Text(stringResource(R.string.agent_icon_remove_phone))
}
}
Text(
text = stringResource(R.string.agent_icon_animation_note),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
hostImportState.error?.let { AvatarError(it) }
hermesPetState.error?.let { AvatarError(it) }
}
if (confirmSharedRemoval) {
AlertDialog(
onDismissRequest = { confirmSharedRemoval = false },
title = { Text(stringResource(R.string.agent_icon_remove_shared_title)) },
text = { Text(stringResource(R.string.agent_icon_remove_shared_message)) },
confirmButton = {
TextButton(
onClick = {
confirmSharedRemoval = false
connectionViewModel.clearSharedProfileAvatar()
},
) {
Text(
text = stringResource(R.string.agent_icon_remove_shared),
color = MaterialTheme.colorScheme.error,
)
}
},
dismissButton = {
TextButton(onClick = { confirmSharedRemoval = false }) {
Text(stringResource(R.string.common_cancel))
}
},
)
}
if (showHermesPetPicker) {
AlertDialog(
onDismissRequest = { showHermesPetPicker = false },
title = { Text(stringResource(R.string.agent_icon_hermes_pet_picker_title)) },
text = {
if (hermesPetState.galleryLoading && hermesPetState.gallery.isEmpty()) {
Box(
modifier = Modifier.fillMaxWidth().padding(24.dp),
contentAlignment = Alignment.Center,
) { CircularProgressIndicator() }
} else {
LazyColumn(modifier = Modifier.fillMaxWidth().heightIn(max = 420.dp)) {
if (hermesPetState.gallery.isEmpty()) {
item {
Text(
text = stringResource(R.string.agent_icon_hermes_pet_empty),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.padding(12.dp),
)
}
}
items(hermesPetState.gallery, key = { it.slug }) { pet ->
LaunchedEffect(pet.slug, pet.spritesheetUrl) {
connectionViewModel.loadHermesPetThumbnail(pet)
}
TextButton(
onClick = {
showHermesPetPicker = false
connectionViewModel.selectHermesPet(pet.slug)
},
modifier = Modifier.fillMaxWidth(),
) {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
PetGalleryPreview(hermesPetState.thumbnails[pet.slug])
Column(modifier = Modifier.weight(1f)) {
Text(pet.displayName, style = MaterialTheme.typography.titleSmall)
Text(
text = when {
pet.slug == hermesPetState.active?.slug -> stringResource(R.string.agent_icon_hermes_pet_selected)
pet.installed -> stringResource(R.string.agent_icon_hermes_pet_installed)
else -> stringResource(R.string.agent_icon_hermes_pet_adopt)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
}
}
}
},
confirmButton = {},
dismissButton = {
TextButton(onClick = { showHermesPetPicker = false }) {
Text(stringResource(R.string.common_cancel))
}
},
)
}
}
@Composable
private fun AvatarSourceCard(content: @Composable ColumnScope.() -> Unit) {
Surface(
shape = RoundedCornerShape(16.dp),
color = MaterialTheme.colorScheme.surfaceContainerLow,
border = BorderStroke(1.dp, MaterialTheme.colorScheme.outlineVariant.copy(alpha = 0.6f)),
) {
Column(
modifier = Modifier.padding(12.dp),
verticalArrangement = Arrangement.spacedBy(8.dp),
content = content,
)
}
}
@Composable
private fun AvatarPreview(path: String?) {
Box(
modifier = Modifier
.size(48.dp)
.clip(CircleShape)
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
) {
if (!path.isNullOrBlank()) {
AsyncImage(
model = File(path),
contentDescription = null,
contentScale = ContentScale.Crop,
modifier = Modifier.fillMaxSize(),
)
}
}
}
@Composable
private fun HermesPetPreview(pet: PetAvatar?) {
Box(
modifier = Modifier.size(56.dp),
contentAlignment = Alignment.Center,
) {
pet?.Render(
state = AvatarRenderState(state = SphereState.Idle),
modifier = Modifier.fillMaxSize(),
)
}
}
@Composable
private fun PetGalleryPreview(dataUri: String?) {
Box(
modifier = Modifier
.size(48.dp)
.clip(RoundedCornerShape(12.dp))
.background(MaterialTheme.colorScheme.surfaceVariant),
contentAlignment = Alignment.Center,
) {
if (dataUri != null) {
AsyncImage(
model = dataUri,
contentDescription = null,
contentScale = ContentScale.Fit,
modifier = Modifier.fillMaxSize().padding(3.dp),
)
}
}
}
@Composable
private fun AvatarError(message: String) {
Text(
text = message,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
)
}
@@ -0,0 +1,632 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.clickable
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.navigationBarsPadding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.verticalScroll
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.KeyboardArrowRight
import androidx.compose.material.icons.filled.CheckCircle
import androidx.compose.material.icons.filled.Security
import androidx.compose.material3.Button
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.Checkbox
import androidx.compose.material3.ExperimentalMaterial3Api
import androidx.compose.material3.FilterChip
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.ModalBottomSheet
import androidx.compose.material3.RadioButton
import androidx.compose.material3.rememberModalBottomSheetState
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.semantics.Role
import androidx.compose.ui.semantics.role
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.bridge.BridgeCapability
import com.hermesandroid.relay.bridge.BridgeCapabilityPolicy
@Composable
fun BridgeAgentAccessCard(
policy: BridgeCapabilityPolicy,
nowMs: Long,
onSetUp: () -> Unit,
onManage: () -> Unit,
onAllowScreen: () -> Unit,
modifier: Modifier = Modifier,
) {
val hasGrant = policy.hasAnyGrant(nowMs)
val preset = policy.displayPreset()
val timed = policy.activeTimedCapabilities(nowMs)
val screenUnlimited = timed.any(policy::isUnlimited)
val nextExpiry = policy.timedExpiriesMs.filterValues {
it > nowMs && it != BridgeCapabilityPolicy.NEVER_EXPIRES_AT_MS
}.values.maxOrNull()
val screenActive = timed.isNotEmpty()
Card(
modifier = modifier.fillMaxWidth(),
shape = RoundedCornerShape(14.dp),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(10.dp),
) {
Row(verticalAlignment = Alignment.CenterVertically) {
Icon(
Icons.Filled.Security,
contentDescription = null,
tint = MaterialTheme.colorScheme.primary,
)
Text(
text = stringResource(R.string.bridge_access_title),
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
color = MaterialTheme.colorScheme.primary,
modifier = Modifier.padding(start = 8.dp).weight(1f),
)
AccessStatePill(
text = when (preset) {
BridgeAccessPreset.READ_ONLY -> stringResource(R.string.bridge_access_preset_read_only)
BridgeAccessPreset.READ_CONFIRMED -> stringResource(R.string.bridge_access_preset_confirmed_short)
BridgeAccessPreset.CUSTOM -> stringResource(R.string.bridge_access_preset_custom)
null -> stringResource(R.string.bridge_access_not_set_up)
},
)
}
Text(
text = stringResource(R.string.bridge_access_summary_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
if (!hasGrant) {
Button(onClick = onSetUp, modifier = Modifier.fillMaxWidth()) {
Text(stringResource(R.string.bridge_access_set_up))
}
} else {
AccessSummaryRow(
title = stringResource(R.string.bridge_access_always),
subtitle = stringResource(
R.string.bridge_access_enabled_count,
policy.permanentGrants.size,
BridgeCapability.entries.count { !it.timed },
),
trailing = policy.permanentGrants.size.toString(),
onClick = onManage,
)
HorizontalDivider(color = MaterialTheme.colorScheme.outline.copy(alpha = 0.15f))
AccessSummaryRow(
title = stringResource(R.string.bridge_access_screen),
subtitle = if (screenActive) {
if (screenUnlimited) {
stringResource(R.string.bridge_access_screen_unlimited)
} else {
stringResource(R.string.bridge_access_screen_active)
}
} else {
stringResource(R.string.bridge_access_screen_off)
},
trailing = if (screenUnlimited) {
stringResource(R.string.bridge_access_until_off_short)
} else {
nextExpiry?.let { formatRemaining(it - nowMs) }
?: stringResource(R.string.bridge_access_allow_duration)
},
onClick = onAllowScreen,
)
}
}
}
}
@Composable
fun BridgeAndroidAccessSummaryCard(
summary: BridgeAndroidAccessSummary,
expanded: Boolean,
onToggle: () -> Unit,
modifier: Modifier = Modifier,
) {
Card(
modifier = modifier.fillMaxWidth().clickable(onClick = onToggle),
shape = RoundedCornerShape(14.dp),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant),
) {
Row(
modifier = Modifier.padding(16.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(12.dp),
) {
Icon(
imageVector = if (summary.allReady) Icons.Filled.CheckCircle else Icons.Filled.Security,
contentDescription = null,
tint = if (summary.allReady) MaterialTheme.colorScheme.primary else MaterialTheme.colorScheme.error,
)
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.bridge_android_access_title),
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold,
)
Text(
text = when {
summary.required.isEmpty() -> stringResource(R.string.bridge_android_access_none)
summary.allReady -> stringResource(R.string.bridge_android_access_ready)
else -> stringResource(
R.string.bridge_android_access_missing,
summary.ready.size,
summary.required.size,
summary.missing.size,
)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
text = if (expanded) {
stringResource(R.string.bridge_android_access_hide)
} else {
stringResource(R.string.bridge_android_access_review)
},
style = MaterialTheme.typography.labelLarge,
color = MaterialTheme.colorScheme.primary,
)
Icon(Icons.AutoMirrored.Filled.KeyboardArrowRight, contentDescription = null)
}
}
}
@Composable
fun BridgeSelectedAndroidAccessCard(
summary: BridgeAndroidAccessSummary,
onOpenAccessibility: () -> Unit,
onOpenAppSettings: () -> Unit,
onOpenOverlay: () -> Unit,
modifier: Modifier = Modifier,
) {
if (summary.missing.isEmpty()) return
Card(
modifier = modifier.fillMaxWidth(),
shape = RoundedCornerShape(14.dp),
colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant),
) {
Column(
modifier = Modifier.padding(16.dp),
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(
stringResource(R.string.bridge_android_selected_needs),
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold,
color = MaterialTheme.colorScheme.primary,
)
Text(
stringResource(R.string.bridge_android_selected_needs_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
summary.missing.forEach { requirement ->
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
) {
Text(
text = stringResource(requirement.labelResource()),
modifier = Modifier.weight(1f),
style = MaterialTheme.typography.bodyMedium,
)
TextButton(
onClick = when (requirement) {
BridgeAndroidRequirement.ACCESSIBILITY -> onOpenAccessibility
BridgeAndroidRequirement.OVERLAY -> onOpenOverlay
else -> onOpenAppSettings
},
) {
Text(stringResource(R.string.bridge_android_open_settings))
}
}
}
}
}
}
@OptIn(ExperimentalMaterial3Api::class)
@Composable
fun BridgeAccessSetupSheet(
selected: BridgeAccessPreset,
onSelected: (BridgeAccessPreset) -> Unit,
onDismiss: () -> Unit,
onContinue: () -> Unit,
) {
ModalBottomSheet(onDismissRequest = onDismiss) {
Column(
modifier = Modifier
.fillMaxWidth()
.height(600.dp)
.navigationBarsPadding()
.padding(horizontal = 20.dp, vertical = 8.dp),
) {
Column(
modifier = Modifier.weight(1f).verticalScroll(rememberScrollState()),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
stringResource(R.string.bridge_access_choose_title),
style = MaterialTheme.typography.headlineSmall,
fontWeight = FontWeight.SemiBold,
)
Text(
stringResource(R.string.bridge_access_choose_desc),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
PresetChoice(
title = stringResource(R.string.bridge_access_preset_read_only),
description = stringResource(R.string.bridge_access_preset_read_only_desc),
selected = selected == BridgeAccessPreset.READ_ONLY,
recommended = true,
onClick = { onSelected(BridgeAccessPreset.READ_ONLY) },
)
PresetChoice(
title = stringResource(R.string.bridge_access_preset_confirmed),
description = stringResource(R.string.bridge_access_preset_confirmed_desc),
selected = selected == BridgeAccessPreset.READ_CONFIRMED,
onClick = { onSelected(BridgeAccessPreset.READ_CONFIRMED) },
)
PresetChoice(
title = stringResource(R.string.bridge_access_preset_custom),
description = stringResource(R.string.bridge_access_preset_custom_desc),
selected = selected == BridgeAccessPreset.CUSTOM,
onClick = { onSelected(BridgeAccessPreset.CUSTOM) },
)
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.End,
verticalAlignment = Alignment.CenterVertically,
) {
TextButton(onClick = onDismiss) { Text(stringResource(R.string.bridge_cancel)) }
Button(onClick = onContinue) { Text(stringResource(R.string.bridge_access_continue)) }
}
Spacer(Modifier.size(4.dp))
}
}
}
}
@OptIn(ExperimentalMaterial3Api::class)
@Composable
fun BridgeTimedAccessSheet(
inspectEnabled: Boolean,
controlEnabled: Boolean,
durationMinutes: Int,
unlimited: Boolean,
accessibilityReady: Boolean,
overlayReady: Boolean,
currentlyActive: Boolean,
onInspectChanged: (Boolean) -> Unit,
onControlChanged: (Boolean) -> Unit,
onDurationChanged: (Int) -> Unit,
onUnlimitedChanged: (Boolean) -> Unit,
onOpenAccessibility: () -> Unit,
onOpenOverlay: () -> Unit,
onDismiss: () -> Unit,
onAllow: () -> Unit,
onEndNow: () -> Unit,
) {
val sheetState = rememberModalBottomSheetState(skipPartiallyExpanded = true)
ModalBottomSheet(
onDismissRequest = onDismiss,
sheetState = sheetState,
) {
Column(
modifier = Modifier
.fillMaxWidth()
.height(740.dp)
.navigationBarsPadding()
.padding(horizontal = 20.dp, vertical = 8.dp),
) {
Column(
modifier = Modifier.weight(1f).verticalScroll(rememberScrollState()),
verticalArrangement = Arrangement.spacedBy(12.dp),
) {
Text(
stringResource(R.string.bridge_timed_title),
style = MaterialTheme.typography.headlineSmall,
fontWeight = FontWeight.SemiBold,
)
Text(
stringResource(R.string.bridge_timed_desc),
style = MaterialTheme.typography.bodyMedium,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
stringResource(R.string.bridge_timed_lifetime_title),
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
)
Row(horizontalArrangement = Arrangement.spacedBy(8.dp)) {
listOf(5, 30, 120).forEach { minutes ->
FilterChip(
selected = !unlimited && durationMinutes == minutes,
onClick = {
onUnlimitedChanged(false)
onDurationChanged(minutes)
},
label = { Text(formatIdleDuration(minutes)) },
)
}
}
FilterChip(
selected = unlimited,
onClick = { onUnlimitedChanged(true) },
label = { Text(stringResource(R.string.bridge_timed_until_off)) },
)
Text(
text = if (unlimited) {
stringResource(R.string.bridge_timed_unlimited_warning)
} else {
stringResource(R.string.bridge_timed_idle_explainer, formatDuration(durationMinutes))
},
style = MaterialTheme.typography.bodySmall,
color = if (unlimited) {
MaterialTheme.colorScheme.error
} else {
MaterialTheme.colorScheme.onSurfaceVariant
},
)
Text(
stringResource(R.string.bridge_timed_scope_title),
style = MaterialTheme.typography.titleMedium,
fontWeight = FontWeight.SemiBold,
)
TimedChoice(
title = stringResource(R.string.bss_capability_screen_inspection),
description = stringResource(R.string.bridge_timed_inspection_desc),
checked = inspectEnabled,
onCheckedChange = onInspectChanged,
)
TimedChoice(
title = stringResource(R.string.bss_capability_screen_control),
description = stringResource(R.string.bridge_timed_control_desc),
checked = controlEnabled,
onCheckedChange = onControlChanged,
)
Card(colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant)) {
Column(
modifier = Modifier.padding(14.dp),
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
Text(
stringResource(R.string.bridge_timed_prerequisites),
style = MaterialTheme.typography.titleSmall,
fontWeight = FontWeight.SemiBold,
)
PrerequisiteRow(
stringResource(R.string.bpc_accessibility),
accessibilityReady,
onOpenAccessibility,
)
if (controlEnabled) {
PrerequisiteRow(
stringResource(R.string.bpc_overlay),
overlayReady,
onOpenOverlay,
)
}
Text(
stringResource(R.string.bridge_timed_capture_note),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.SpaceBetween,
verticalAlignment = Alignment.CenterVertically,
) {
if (currentlyActive) {
TextButton(onClick = onEndNow) {
Text(stringResource(R.string.bridge_timed_end_now))
}
} else {
Spacer(Modifier.size(1.dp))
}
Row(verticalAlignment = Alignment.CenterVertically) {
TextButton(onClick = onDismiss) { Text(stringResource(R.string.bridge_cancel)) }
Button(
onClick = onAllow,
enabled = (inspectEnabled || controlEnabled) &&
accessibilityReady && (!controlEnabled || overlayReady),
) {
Text(stringResource(R.string.bridge_timed_allow))
}
}
}
Spacer(Modifier.size(4.dp))
}
Spacer(Modifier.size(12.dp))
}
}
}
@Composable
private fun AccessSummaryRow(
title: String,
subtitle: String,
trailing: String,
onClick: () -> Unit,
) {
Row(
modifier = Modifier
.fillMaxWidth()
.clickable(onClick = onClick)
.padding(vertical = 6.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(10.dp),
) {
Column(modifier = Modifier.weight(1f)) {
Text(title, style = MaterialTheme.typography.bodyLarge)
Text(
subtitle,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(trailing, style = MaterialTheme.typography.labelLarge, color = MaterialTheme.colorScheme.primary)
Icon(Icons.AutoMirrored.Filled.KeyboardArrowRight, contentDescription = null)
}
}
@Composable
private fun PresetChoice(
title: String,
description: String,
selected: Boolean,
recommended: Boolean = false,
onClick: () -> Unit,
) {
Card(
modifier = Modifier
.fillMaxWidth()
.semantics { role = Role.RadioButton }
.clickable(onClick = onClick),
colors = CardDefaults.cardColors(
containerColor = if (selected) {
MaterialTheme.colorScheme.primaryContainer.copy(alpha = 0.35f)
} else {
MaterialTheme.colorScheme.surfaceVariant
},
),
) {
Row(
modifier = Modifier.padding(14.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(10.dp),
) {
RadioButton(selected = selected, onClick = null)
Column(modifier = Modifier.weight(1f)) {
Text(title, style = MaterialTheme.typography.titleSmall, fontWeight = FontWeight.SemiBold)
Text(
description,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
if (recommended) {
Text(
stringResource(R.string.bridge_access_recommended),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
}
}
}
}
}
@Composable
private fun TimedChoice(
title: String,
description: String,
checked: Boolean,
onCheckedChange: (Boolean) -> Unit,
) {
Card(colors = CardDefaults.cardColors(containerColor = MaterialTheme.colorScheme.surfaceVariant)) {
Row(
modifier = Modifier.fillMaxWidth().padding(12.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Checkbox(checked = checked, onCheckedChange = onCheckedChange)
Column(modifier = Modifier.weight(1f)) {
Text(title, style = MaterialTheme.typography.titleSmall)
Text(
description,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
}
@Composable
private fun PrerequisiteRow(label: String, ready: Boolean, onClick: () -> Unit) {
Row(
modifier = Modifier.fillMaxWidth().clickable(onClick = onClick).padding(vertical = 4.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Icon(
Icons.Filled.CheckCircle,
contentDescription = null,
tint = if (ready) MaterialTheme.colorScheme.primary else MaterialTheme.colorScheme.error,
modifier = Modifier.size(18.dp),
)
Text(label, modifier = Modifier.padding(start = 8.dp).weight(1f))
Text(
if (ready) stringResource(R.string.bridge_android_ready_short)
else stringResource(R.string.bridge_android_missing_short),
style = MaterialTheme.typography.labelLarge,
color = if (ready) MaterialTheme.colorScheme.primary else MaterialTheme.colorScheme.error,
)
Icon(
Icons.AutoMirrored.Filled.KeyboardArrowRight,
contentDescription = stringResource(R.string.bridge_android_open_settings),
modifier = Modifier.padding(start = 4.dp),
)
}
}
@Composable
private fun AccessStatePill(text: String) {
Surface(
shape = RoundedCornerShape(50),
color = MaterialTheme.colorScheme.primaryContainer,
contentColor = MaterialTheme.colorScheme.onPrimaryContainer,
) {
Text(
text,
style = MaterialTheme.typography.labelSmall,
fontWeight = FontWeight.SemiBold,
modifier = Modifier.padding(horizontal = 8.dp, vertical = 3.dp),
)
}
}
private fun formatRemaining(remainingMs: Long): String {
val totalSeconds = (remainingMs.coerceAtLeast(0L) / 1_000L).toInt()
return "%d:%02d".format(totalSeconds / 60, totalSeconds % 60)
}
private fun formatDuration(minutes: Int): String =
if (minutes == 120) "2 hr" else "$minutes min"
private fun formatIdleDuration(minutes: Int): String =
if (minutes == 120) "2 hr idle" else "$minutes min idle"
private fun BridgeAndroidRequirement.labelResource(): Int = when (this) {
BridgeAndroidRequirement.ACCESSIBILITY -> R.string.bpc_accessibility
BridgeAndroidRequirement.CONTACTS -> R.string.bpc_contacts
BridgeAndroidRequirement.LOCATION -> R.string.bpc_location
BridgeAndroidRequirement.SMS -> R.string.bpc_sms
BridgeAndroidRequirement.PHONE -> R.string.bpc_phone
BridgeAndroidRequirement.OVERLAY -> R.string.bpc_overlay
}
@@ -0,0 +1,97 @@
package com.hermesandroid.relay.ui.components
import com.hermesandroid.relay.bridge.BridgeCapability
import com.hermesandroid.relay.bridge.BridgeCapabilityPolicy
import com.hermesandroid.relay.viewmodel.BridgePermissionStatus
enum class BridgeAccessPreset {
READ_ONLY,
READ_CONFIRMED,
CUSTOM,
}
val READ_ONLY_BRIDGE_CAPABILITIES: Set<BridgeCapability> = setOf(
BridgeCapability.DEVICE_INFO,
BridgeCapability.CONTACTS_READ,
BridgeCapability.LOCATION_READ,
BridgeCapability.CLIPBOARD_READ,
)
val READ_CONFIRMED_BRIDGE_CAPABILITIES: Set<BridgeCapability> =
READ_ONLY_BRIDGE_CAPABILITIES + setOf(
BridgeCapability.COMMUNICATIONS,
BridgeCapability.OUTBOUND_SHARING,
)
enum class BridgeAndroidRequirement {
ACCESSIBILITY,
CONTACTS,
LOCATION,
SMS,
PHONE,
OVERLAY,
}
data class BridgeAndroidAccessSummary(
val required: Set<BridgeAndroidRequirement>,
val ready: Set<BridgeAndroidRequirement>,
) {
val missing: Set<BridgeAndroidRequirement> get() = required - ready
val allReady: Boolean get() = missing.isEmpty()
}
fun BridgeCapabilityPolicy.hasAnyGrant(nowMs: Long): Boolean =
permanentGrants.isNotEmpty() || timedExpiriesMs.any { (capability, expiry) ->
capability.timed && expiry > nowMs
}
fun BridgeCapabilityPolicy.activeTimedCapabilities(nowMs: Long): Set<BridgeCapability> =
timedExpiriesMs.filterValues { it > nowMs }.keys
fun BridgeCapabilityPolicy.displayPreset(): BridgeAccessPreset? = when (permanentGrants) {
READ_ONLY_BRIDGE_CAPABILITIES -> BridgeAccessPreset.READ_ONLY
READ_CONFIRMED_BRIDGE_CAPABILITIES -> BridgeAccessPreset.READ_CONFIRMED
else -> if (permanentGrants.isEmpty()) null else BridgeAccessPreset.CUSTOM
}
fun bridgeAndroidAccessSummary(
policy: BridgeCapabilityPolicy,
status: BridgePermissionStatus,
nowMs: Long,
): BridgeAndroidAccessSummary {
val timed = policy.activeTimedCapabilities(nowMs)
val required = buildSet {
// Current BridgeCommandHandler is service-owned even for passive
// commands. Keep this visible until non-screen executors are split.
if (policy.permanentGrants.isNotEmpty() || timed.isNotEmpty()) {
add(BridgeAndroidRequirement.ACCESSIBILITY)
}
if (BridgeCapability.CONTACTS_READ in policy.permanentGrants) {
add(BridgeAndroidRequirement.CONTACTS)
}
if (BridgeCapability.LOCATION_READ in policy.permanentGrants) {
add(BridgeAndroidRequirement.LOCATION)
}
if (BridgeCapability.COMMUNICATIONS in policy.permanentGrants) {
add(BridgeAndroidRequirement.SMS)
add(BridgeAndroidRequirement.PHONE)
}
if (BridgeCapability.SCREEN_CONTROL in timed ||
BridgeCapability.COMMUNICATIONS in policy.permanentGrants ||
BridgeCapability.OUTBOUND_SHARING in policy.permanentGrants
) {
add(BridgeAndroidRequirement.OVERLAY)
}
}
val ready = required.filterTo(linkedSetOf()) { requirement ->
when (requirement) {
BridgeAndroidRequirement.ACCESSIBILITY -> status.accessibilityServiceEnabled
BridgeAndroidRequirement.CONTACTS -> status.contactsPermitted
BridgeAndroidRequirement.LOCATION -> status.locationPermitted
BridgeAndroidRequirement.SMS -> status.smsPermitted
BridgeAndroidRequirement.PHONE -> status.phonePermitted
BridgeAndroidRequirement.OVERLAY -> status.overlayPermitted
}
}
return BridgeAndroidAccessSummary(required = required, ready = ready)
}
@@ -40,8 +40,8 @@ import com.hermesandroid.relay.data.DEFAULT_DESTRUCTIVE_VERBS
*
* - Blocklist count ("12 apps blocked")
* - Destructive-verb count ("12 verbs need confirmation")
* - Auto-disable window ("Auto-off after 30 min idle")
* - Auto-disable countdown when a timer is active
* - Timed screen-access window
* - Timed screen-access countdown when active
*
* Tap → navigate to [BridgeSafetySettingsScreen].
*
@@ -53,6 +53,8 @@ import com.hermesandroid.relay.data.DEFAULT_DESTRUCTIVE_VERBS
fun BridgeSafetySummaryCard(
settings: BridgeSafetySettings,
autoDisableAtMs: Long? = null,
screenAccessActive: Boolean = false,
screenAccessUnlimited: Boolean = false,
onManage: () -> Unit,
) {
// Tick a local clock every second when a countdown is active so the
@@ -114,14 +116,18 @@ fun BridgeSafetySummaryCard(
value = "${settings.destructiveVerbs.size}",
)
SafetySummaryRow(
label = stringResource(R.string.bssc_auto_disable),
value = if (autoDisableAtMs != null) {
label = stringResource(R.string.bridge_access_screen),
value = if (screenAccessUnlimited) {
stringResource(R.string.bridge_access_until_off_short)
} else if (!screenAccessActive) {
stringResource(R.string.bmt_off)
} else if (autoDisableAtMs != null) {
val remainMs = (autoDisableAtMs - nowMs).coerceAtLeast(0L)
val remainMin = (remainMs / 60_000L).toInt()
val remainSec = ((remainMs % 60_000L) / 1000L).toInt()
"in ${remainMin}:${remainSec.toString().padStart(2, '0')}"
} else {
"${settings.autoDisableMinutes} min"
stringResource(R.string.bridge_access_screen_active)
},
)
@@ -183,6 +189,7 @@ private fun BridgeSafetySummaryCardPreview_Countdown() {
destructiveVerbs = DEFAULT_DESTRUCTIVE_VERBS,
),
autoDisableAtMs = System.currentTimeMillis() + 12 * 60_000L + 34_000L,
screenAccessActive = true,
onManage = {},
)
}
@@ -0,0 +1,147 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.Spacer
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.filled.Warning
import androidx.compose.material3.AlertDialog
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
import androidx.compose.material3.TextButton
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.unit.dp
import com.hermesandroid.relay.R
import com.hermesandroid.relay.viewmodel.ChatFailureNotice
@Composable
fun ChatFailurePanel(
failure: ChatFailureNotice,
routeLabel: String,
onDetails: () -> Unit,
onRetry: () -> Unit,
onDismiss: () -> Unit,
modifier: Modifier = Modifier,
) {
Surface(
modifier = modifier
.fillMaxWidth()
.padding(horizontal = 12.dp, vertical = 6.dp),
color = MaterialTheme.colorScheme.errorContainer,
contentColor = MaterialTheme.colorScheme.onErrorContainer,
shape = MaterialTheme.shapes.medium,
) {
Column(modifier = Modifier.padding(start = 12.dp, top = 12.dp, end = 8.dp, bottom = 4.dp)) {
Row(verticalAlignment = Alignment.Top) {
Icon(
imageVector = Icons.Default.Warning,
contentDescription = null,
modifier = Modifier.padding(top = 2.dp),
)
Spacer(Modifier.width(10.dp))
Column(modifier = Modifier.weight(1f)) {
Text(
text = stringResource(R.string.chat_failure_title),
style = MaterialTheme.typography.bodyMedium,
fontWeight = FontWeight.SemiBold,
)
failureIdentity(routeLabel, failure.model, failure.provider)
.takeIf { it.isNotBlank() }
?.let { identity ->
Text(
text = identity,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onErrorContainer.copy(alpha = 0.78f),
)
}
}
}
Row(
modifier = Modifier.fillMaxWidth(),
horizontalArrangement = Arrangement.End,
verticalAlignment = Alignment.CenterVertically,
) {
TextButton(onClick = onDetails) {
Text(stringResource(R.string.chat_failure_details))
}
if (failure.recoverable) {
TextButton(onClick = onRetry) {
Text(stringResource(R.string.chat_retry))
}
}
TextButton(onClick = onDismiss) {
Text(stringResource(R.string.chat_dismiss))
}
}
}
}
}
@Composable
fun ChatFailureDetailsDialog(
failure: ChatFailureNotice,
routeLabel: String,
onCopy: () -> Unit,
onDismiss: () -> Unit,
) {
AlertDialog(
onDismissRequest = onDismiss,
title = { Text(stringResource(R.string.chat_failure_details_title)) },
text = {
Column(verticalArrangement = Arrangement.spacedBy(12.dp)) {
failureIdentity(routeLabel, failure.model, failure.provider)
.takeIf { it.isNotBlank() }
?.let { identity ->
Text(text = identity, style = MaterialTheme.typography.labelLarge)
}
Text(
text = stringResource(R.string.chat_failure_details_guidance),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Surface(
color = MaterialTheme.colorScheme.surfaceVariant,
shape = MaterialTheme.shapes.small,
) {
SelectionContainer {
Text(
text = failure.rawError,
modifier = Modifier
.fillMaxWidth()
.padding(12.dp),
style = MaterialTheme.typography.bodySmall,
)
}
}
}
},
confirmButton = {
TextButton(onClick = onCopy) {
Text(stringResource(R.string.chat_failure_copy_details))
}
},
dismissButton = {
TextButton(onClick = onDismiss) {
Text(stringResource(R.string.common_close))
}
},
)
}
internal fun failureIdentity(route: String, model: String?, provider: String?): String =
listOfNotNull(
route.takeIf { it.isNotBlank() },
provider?.trim()?.takeIf { it.isNotEmpty() },
model?.trim()?.takeIf { it.isNotEmpty() },
).distinct().joinToString(" · ")
@@ -29,7 +29,6 @@ import androidx.compose.foundation.layout.widthIn
import androidx.compose.foundation.shape.CircleShape
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.BasicTextField
import androidx.compose.foundation.text.KeyboardActions
import androidx.compose.foundation.text.KeyboardOptions
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.Send
@@ -65,6 +64,7 @@ import androidx.compose.ui.focus.focusProperties
import androidx.compose.ui.graphics.SolidColor
import androidx.compose.ui.input.key.onPreviewKeyEvent
import androidx.compose.ui.res.stringResource
import androidx.compose.ui.platform.LocalConfiguration
import androidx.compose.ui.platform.testTag
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.contentDescription
@@ -94,7 +94,7 @@ import kotlinx.coroutines.delay
*/
enum class ChatInputTrailing { SEND, VOICE, STOP, STEER, QUEUE }
private val ChatComposerShape = RoundedCornerShape(18.dp)
private val ChatComposerShape = RoundedCornerShape(26.dp)
private val ChatInputChipShape = RoundedCornerShape(12.dp)
internal const val CHAT_INPUT_FIELD_TEST_TAG = "chat-input-field"
@@ -187,14 +187,24 @@ fun ChatInputBar(
modifier: Modifier = Modifier,
surfaceModifier: Modifier = Modifier,
enabled: Boolean = true,
submitEnabled: Boolean = true,
physicalEnterSends: Boolean = true,
largePasteThreshold: Int? = null,
onLargePaste: (String) -> Unit = {},
) {
val canSubmit = enabled && trailing in setOf(
val canSubmit = enabled && submitEnabled && trailing in setOf(
ChatInputTrailing.SEND,
ChatInputTrailing.STEER,
ChatInputTrailing.QUEUE,
)
// Enter only means "send" when a physical keyboard is attached (see
// the key handler below). Read the configuration here, in the composable
// scope, and capture it for the non-composable onPreviewKeyEvent lambda.
val keyboardAttached =
LocalConfiguration.current.keyboard !=
android.content.res.Configuration.KEYBOARD_NOKEYS
// Keep the last caption around so the AnimatedVisibility exit doesn't
// flash an empty line while collapsing.
var lastCaption by remember { mutableStateOf<String?>(null) }
@@ -315,7 +325,7 @@ fun ChatInputBar(
border = BorderStroke(1.dp, MaterialTheme.colorScheme.outlineVariant),
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 8.dp, vertical = 6.dp)
.padding(horizontal = 8.dp, vertical = 3.dp)
.then(surfaceModifier),
) {
Column {
@@ -341,15 +351,24 @@ fun ChatInputBar(
}
Column(
modifier = Modifier.padding(horizontal = 8.dp, vertical = 6.dp),
modifier = Modifier.padding(horizontal = 6.dp, vertical = 3.dp),
) {
BasicTextField(
value = value,
onValueChange = { if (it.length <= charLimit) onValueChange(it) },
onValueChange = { updated ->
val converted = largePasteThreshold
?.let { threshold -> detectLargeTextInsertion(value, updated, threshold) }
if (converted != null) {
onValueChange(converted.remainingText)
onLargePaste(converted.insertedText)
} else if (updated.length <= charLimit) {
onValueChange(updated)
}
},
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 34.dp)
.padding(horizontal = 8.dp, vertical = 4.dp)
.heightIn(min = 30.dp)
.padding(horizontal = 10.dp, vertical = 2.dp)
// Keep directional keys inside the editor. Compose's
// BasicTextField owns normal caret/selection movement;
// cancelling focus traversal prevents a boundary arrow
@@ -364,10 +383,18 @@ fun ChatInputBar(
val native = event.nativeKeyEvent
val isEnter = native.keyCode == android.view.KeyEvent.KEYCODE_ENTER ||
native.keyCode == android.view.KeyEvent.KEYCODE_NUMPAD_ENTER
// Enter only means "send" when a physical keyboard is
// attached. IME-dispatched Enter (commitText or a
// synthesized KEYCODE_ENTER) must always fall through
// so the soft keyboard's return key inserts a newline
// instead of sending (issue #367). Key events alone
// cannot distinguish physical vs IME origin — deviceId
// is 0 or -1 depending on the IME — so gate on the
// hardware keyboard configuration (read above).
val isSubmitShortcut = native.isCtrlPressed || native.isMetaPressed
if (native.action != android.view.KeyEvent.ACTION_DOWN || !isEnter) {
false
} else if (isSubmitShortcut || (physicalEnterSends && !native.isShiftPressed)) {
} else if (isSubmitShortcut || (keyboardAttached && physicalEnterSends && !native.isShiftPressed)) {
if (canSubmit) onSend()
true
} else {
@@ -382,10 +409,10 @@ fun ChatInputBar(
enabled = enabled,
keyboardOptions = KeyboardOptions(
capitalization = KeyboardCapitalization.Sentences,
imeAction = ImeAction.Send,
),
keyboardActions = KeyboardActions(
onSend = { if (canSubmit) onSend() },
// The field is multiline and already has a dedicated
// send button. Leave the software keyboard action as
// Return; hardware Enter remains handled above.
imeAction = ImeAction.Default,
),
textStyle = MaterialTheme.typography.bodyLarge.copy(
color = MaterialTheme.colorScheme.onSurface,
@@ -408,7 +435,7 @@ fun ChatInputBar(
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 48.dp),
.heightIn(min = 44.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(4.dp),
) {
@@ -521,12 +548,12 @@ fun ChatInputBar(
when (state) {
ChatInputTrailing.SEND -> IconButton(
onClick = onSend,
enabled = enabled,
enabled = canSubmit,
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.chat_input_send_message),
tint = if (enabled) MaterialTheme.colorScheme.primary
tint = if (canSubmit) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
)
}
@@ -580,7 +607,7 @@ fun ChatInputBar(
ChatInputTrailing.STEER -> IconButton(
onClick = onSend,
enabled = enabled,
enabled = canSubmit,
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
@@ -591,7 +618,7 @@ fun ChatInputBar(
ChatInputTrailing.QUEUE -> IconButton(
onClick = onSend,
enabled = enabled,
enabled = canSubmit,
) {
Box {
Icon(
@@ -620,6 +647,39 @@ fun ChatInputBar(
}
}
internal data class LargeTextInsertion(
val insertedText: String,
val remainingText: String,
)
/** Finds one large contiguous edit without requiring clipboard access or retaining clipboard data. */
internal fun detectLargeTextInsertion(
previous: String,
updated: String,
threshold: Int,
): LargeTextInsertion? {
if (threshold <= 0 || updated == previous) return null
val prefixLength = previous.commonPrefixWith(updated).length
val maxSuffixLength = minOf(
previous.length - prefixLength,
updated.length - prefixLength,
)
var suffixLength = 0
while (
suffixLength < maxSuffixLength &&
previous[previous.lastIndex - suffixLength] == updated[updated.lastIndex - suffixLength]
) {
suffixLength++
}
val insertedEnd = updated.length - suffixLength
val inserted = updated.substring(prefixLength, insertedEnd)
if (inserted.length < threshold) return null
return LargeTextInsertion(
insertedText = inserted,
remainingText = updated.removeRange(prefixLength, insertedEnd),
)
}
@Composable
private fun ChatInputPickerChip(
control: ChatInputPickerControl,
@@ -105,6 +105,11 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.ConnectionValidation
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.hasHermesReach
import com.hermesandroid.relay.data.presentationRouteUrl
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.primaryRouteUrl
import com.hermesandroid.relay.network.shared.HermesLanDiscovery
import com.hermesandroid.relay.network.shared.HermesLanDiscoveryResult
@@ -2244,6 +2249,11 @@ private fun StandardEntryStep(
val apiError = apiUrlSchemeError(apiUrl, context)
val tailscaleError = optionalHttpUrlError(tailscaleApiUrl, context)
val dashboardError = optionalHttpUrlError(dashboardUrl, context)
val apiKeyError = if (apiKey.trim(' ', '\t').any { it < '!' || it > '~' }) {
stringResource(R.string.api_credential_single_line_error)
} else {
null
}
var advancedExpanded by remember { mutableStateOf(false) }
var scanBusy by remember { mutableStateOf(false) }
var scanResults by remember { mutableStateOf<List<HermesLanDiscoveryResult>>(emptyList()) }
@@ -2258,6 +2268,7 @@ private fun StandardEntryStep(
apiError == null &&
tailscaleError == null &&
dashboardError == null &&
apiKeyError == null &&
!isConnecting
val defaultDashboardUrl = Connection.deriveDefaultDashboardUrl(apiUrl)
val effectiveDashboardUrl = dashboardUrl
@@ -2402,8 +2413,9 @@ private fun StandardEntryStep(
label = { Text(stringResource(R.string.cw_api_key_label)) },
placeholder = { Text(stringResource(R.string.cw_api_key_placeholder)) },
singleLine = true,
isError = apiKeyError != null,
supportingText = {
Text(stringResource(R.string.cw_api_key_hint))
Text(apiKeyError ?: stringResource(R.string.cw_api_key_hint))
},
visualTransformation = if (apiKeyVisible) {
VisualTransformation.None
@@ -3174,7 +3186,7 @@ private fun ConfirmStep(
// app auto-falls back to the secure one, so a blanket "Insecure (dev)"
// badge from endpoint[0] alone would lie to the user.
val anySecure = endpoints.any { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}
@@ -3195,7 +3207,7 @@ private fun ConfirmStep(
// Mixed case ("Tailscale is encrypted..." vs "Public is encrypted...").
val firstSecureLabel = endpoints
.firstOrNull { c ->
c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.hasSecureProxy() || c.relay?.url?.startsWith("wss://") == true || c.api?.tls == true ||
c.relay?.transportHint.equals("wss", ignoreCase = true) ||
c.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
}?.displayLabel()
@@ -3208,6 +3220,7 @@ private fun ConfirmStep(
val distinctRoles = endpoints.map { it.role }.distinct()
var preferRole by remember(payload) { mutableStateOf<String?>(null) }
var preferMenuOpen by remember { mutableStateOf(false) }
val secureLink = endpoints.firstOrNull { it.hasSecureProxy() }
Column(
verticalArrangement = Arrangement.spacedBy(14.dp),
@@ -3318,6 +3331,15 @@ private fun ConfirmStep(
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
secureLink?.let { route ->
SecureLinkPairingSummary(
services = route.secureLinkServices(),
complete = route.secureLinkCoversAllServices(),
hasFallback = endpoints.size > 1,
usesReach = route.hasHermesReach(),
)
HorizontalDivider()
}
endpoints.forEachIndexed { index, candidate ->
if (index > 0) HorizontalDivider()
EndpointPreviewRow(
@@ -3720,7 +3742,7 @@ private fun EndpointPreviewRow(
) {
// Per-row security derived from the same three signals as the overall
// securityState computation — scheme, tls flag, transportHint.
val isSecure = candidate.relay?.url?.startsWith("wss://") == true ||
val isSecure = candidate.hasSecureProxy() || candidate.relay?.url?.startsWith("wss://") == true ||
candidate.api?.tls == true ||
candidate.relay?.transportHint.equals("wss", ignoreCase = true) ||
candidate.dashboard?.url?.startsWith("https://", ignoreCase = true) == true
@@ -3756,7 +3778,7 @@ private fun EndpointPreviewRow(
}
}
Text(
text = candidate.primaryRouteUrl().orEmpty() +
text = candidate.presentationRouteUrl().orEmpty() +
(candidate.relay?.transportHint?.let { " \u00b7 $it" } ?: ""),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
@@ -3772,6 +3794,75 @@ private fun EndpointPreviewRow(
}
}
@Composable
private fun SecureLinkPairingSummary(
services: List<String>,
complete: Boolean,
hasFallback: Boolean,
usesReach: Boolean,
) {
val relayLabel = stringResource(R.string.secure_link_service_relay)
val apiLabel = stringResource(R.string.secure_link_service_api)
val dashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val serviceText = services.map { service ->
when (service) {
"relay" -> relayLabel
"api" -> apiLabel
"dashboard" -> dashboardLabel
else -> service
}
}.joinToString(" · ")
Surface(
color = MaterialTheme.colorScheme.primary.copy(alpha = 0.08f),
shape = RoundedCornerShape(12.dp),
) {
Column(
modifier = Modifier.fillMaxWidth().padding(12.dp),
verticalArrangement = Arrangement.spacedBy(4.dp),
) {
Text(
stringResource(if (usesReach) R.string.hermes_reach_title else R.string.secure_link_title),
style = MaterialTheme.typography.titleSmall,
)
if (usesReach) {
Text(
stringResource(R.string.hermes_reach_summary),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Text(
stringResource(R.string.secure_link_pinned_tls),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.primary,
)
Text(
if (serviceText.isBlank()) stringResource(R.string.secure_link_no_services)
else stringResource(R.string.secure_link_protects, serviceText),
style = MaterialTheme.typography.bodySmall,
)
if (!complete) {
Text(
stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
if (hasFallback) stringResource(R.string.secure_link_fallback_ready)
else stringResource(R.string.secure_link_no_fallback),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Text(
stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
}
/**
* Compact pill used by [EndpointPreviewRow] — matches the "Preferred" soft
* chip style so the row reads as a row of related chips rather than a mix
@@ -57,6 +57,9 @@ import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.data.SurfaceSecurityKind
import com.hermesandroid.relay.data.displayLabel
import com.hermesandroid.relay.data.hasSecureProxy
import com.hermesandroid.relay.data.secureLinkCoversAllServices
import com.hermesandroid.relay.data.secureLinkServices
import com.hermesandroid.relay.data.isEncryptedOverlayRoute
import com.hermesandroid.relay.data.isKnownRole
import com.hermesandroid.relay.data.isTlsUrl
@@ -323,6 +326,9 @@ private fun EndpointRow(
val apiLabel = stringResource(R.string.active_section_api_server)
val relayLabel = stringResource(R.string.active_section_relay)
val surfaceSummary = listOfNotNull(
candidate.proxy?.takeIf { candidate.hasSecureProxy() }?.let {
stringResource(R.string.secure_link_pinned_tls_short)
},
dashboardSurfaceUrl?.let { "$dashboardLabel ${displayPort(it)}" },
candidate.api?.url?.let { "$apiLabel ${displayPort(it)}" },
candidate.relay?.url?.let { "$relayLabel ${displayPort(it)}" },
@@ -357,6 +363,36 @@ private fun EndpointRow(
)
}
}
if (candidate.hasSecureProxy()) {
val secureRelayLabel = stringResource(R.string.secure_link_service_relay)
val secureApiLabel = stringResource(R.string.secure_link_service_api)
val secureDashboardLabel = stringResource(R.string.secure_link_service_dashboard)
val services = candidate.secureLinkServices().map { service ->
when (service) {
"relay" -> secureRelayLabel
"api" -> secureApiLabel
"dashboard" -> secureDashboardLabel
else -> service
}
}.joinToString(" · ")
Text(
text = stringResource(R.string.secure_link_protects, services),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.primary,
)
if (!candidate.secureLinkCoversAllServices()) {
Text(
text = stringResource(R.string.secure_link_partial_warning),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.tertiary,
)
}
Text(
text = stringResource(R.string.secure_link_auth_note),
style = MaterialTheme.typography.labelSmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
}
// 3-dot overflow menu — actions per-row so the card stays flat
@@ -680,6 +716,7 @@ private fun roleIcon(role: String): ImageVector = when (role.lowercase()) {
* be classified independently before it's the active route.
*/
private fun EndpointCandidate.routeSecurityKind(): SurfaceSecurityKind = when {
hasSecureProxy() -> SurfaceSecurityKind.Tls
isTlsUrl(primaryRouteUrl().orEmpty()) -> SurfaceSecurityKind.Tls
isEncryptedOverlayRoute(isTailscaleDetected = false) -> SurfaceSecurityKind.Overlay
else -> SurfaceSecurityKind.Plain
@@ -45,6 +45,8 @@ import androidx.compose.material3.Button
import androidx.compose.material3.ButtonDefaults
import androidx.compose.material3.Card
import androidx.compose.material3.CardDefaults
import androidx.compose.material3.FilterChip
import androidx.compose.material3.FilterChipDefaults
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.MaterialTheme
@@ -81,6 +83,7 @@ import com.hermesandroid.relay.data.HermesCardAction
import com.hermesandroid.relay.data.HermesCardDispatch
import com.hermesandroid.relay.data.HermesCardField
import com.hermesandroid.relay.data.HermesCardInput
import com.hermesandroid.relay.data.encodeClarifyMultiSelectAnswer
import com.hermesandroid.relay.ui.theme.RelayRefresh
import com.hermesandroid.relay.ui.theme.relayMetadataStyle
import kotlinx.coroutines.coroutineScope
@@ -389,7 +392,8 @@ private fun ChoseRow(
/**
* The interactive answer surface for ask cards, composed from the
* [HermesCardInput] flags rather than the card type:
* - [HermesCardInput.choices] → AssistChip row, one tap dispatches.
* - [HermesCardInput.choices] → one-tap AssistChips, or independently
* selected FilterChips plus explicit submit for multi-select clarifies.
* - [HermesCardInput.allowFreeText] → [InlineAnswerField] mini pill +
* 18dp send affordance.
* - [HermesCardInput.masked] → password-style OutlinedTextField with a
@@ -411,6 +415,8 @@ private fun CardInputSlot(
// never be written into the saved-instance-state Bundle.
var answerText by remember { mutableStateOf("") }
var reveal by remember { mutableStateOf(false) }
var selectedChoices by remember(input.choices) { mutableStateOf(emptyList<String>()) }
val isMultiSelect = input.multiSelect && input.choices.isNotEmpty()
val showFreeText = !input.masked && (
input.allowFreeText ||
@@ -428,16 +434,45 @@ private fun CardInputSlot(
verticalArrangement = Arrangement.spacedBy(8.dp),
) {
input.choices.forEach { choice ->
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
if (isMultiSelect) {
val selected = choice in selectedChoices
FilterChip(
selected = selected,
onClick = {
selectedChoices = if (selected) {
selectedChoices - choice
} else {
selectedChoices + choice
}
},
label = { Text(choice, style = MaterialTheme.typography.labelMedium) },
leadingIcon = if (selected) {
{
Icon(
Icons.Filled.Check,
contentDescription = null,
modifier = Modifier.size(16.dp),
)
}
} else {
null
},
colors = FilterChipDefaults.filterChipColors(
selectedContainerColor = MaterialTheme.colorScheme.secondaryContainer,
),
)
} else {
AssistChip(
onClick = { onSubmit(choice) },
label = {
Text(choice, style = MaterialTheme.typography.labelMedium)
},
colors = AssistChipDefaults.assistChipColors(
containerColor = MaterialTheme.colorScheme.surfaceContainerHighest,
labelColor = MaterialTheme.colorScheme.onSurface,
),
)
}
}
}
}
@@ -482,21 +517,38 @@ private fun CardInputSlot(
onValueChange = { answerText = it },
modifier = Modifier.weight(1f),
)
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
if (!isMultiSelect) {
IconButton(
onClick = { onSubmit(answerText.trim()) },
enabled = answerText.isNotBlank(),
) {
Icon(
imageVector = Icons.AutoMirrored.Filled.Send,
contentDescription = stringResource(R.string.card_send_answer_a11y),
tint = if (answerText.isNotBlank()) MaterialTheme.colorScheme.primary
else MaterialTheme.colorScheme.onSurfaceVariant,
modifier = Modifier.size(18.dp),
)
}
}
}
}
if (isMultiSelect) {
val answers = selectedChoices +
listOfNotNull(answerText.trim().takeIf(String::isNotEmpty))
Spacer(Modifier.height(10.dp))
Button(
onClick = { onSubmit(encodeClarifyMultiSelectAnswer(answers)) },
enabled = answers.isNotEmpty(),
) {
Text(
stringResource(R.string.card_submit),
style = MaterialTheme.typography.labelMedium,
)
}
}
// Submit affordance for masked / hold-to-confirm inputs
when {
input.holdToConfirm -> {
@@ -0,0 +1,81 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.foundation.background
import androidx.compose.foundation.layout.Arrangement
import androidx.compose.foundation.layout.Column
import androidx.compose.foundation.layout.Row
import androidx.compose.foundation.layout.WindowInsets
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.heightIn
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.statusBars
import androidx.compose.foundation.layout.windowInsetsPadding
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.outlined.WarningAmber
import androidx.compose.material3.Icon
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.text.font.FontWeight
import androidx.compose.ui.text.style.TextOverflow
import androidx.compose.ui.unit.dp
/** Persistent, server-authored resource-pressure warning for the active Hermes host. */
@Composable
fun HostResourcePressureBanner(
text: String,
critical: Boolean,
includeStatusBarPadding: Boolean,
modifier: Modifier = Modifier,
) {
val background = if (critical) {
MaterialTheme.colorScheme.errorContainer
} else {
MaterialTheme.colorScheme.tertiaryContainer
}
val foreground = if (critical) {
MaterialTheme.colorScheme.onErrorContainer
} else {
MaterialTheme.colorScheme.onTertiaryContainer
}
Column(
modifier = modifier
.fillMaxWidth()
.background(background)
.then(
if (includeStatusBarPadding) {
Modifier.windowInsetsPadding(WindowInsets.statusBars)
} else {
Modifier
},
),
) {
Row(
modifier = Modifier
.fillMaxWidth()
.heightIn(min = 32.dp)
.padding(horizontal = 12.dp, vertical = 6.dp),
verticalAlignment = Alignment.CenterVertically,
horizontalArrangement = Arrangement.spacedBy(8.dp),
) {
Icon(
imageVector = Icons.Outlined.WarningAmber,
contentDescription = null,
tint = foreground,
modifier = Modifier.size(17.dp),
)
Text(
text = text,
color = foreground,
style = MaterialTheme.typography.labelMedium,
fontWeight = FontWeight.Medium,
maxLines = 2,
overflow = TextOverflow.Ellipsis,
modifier = Modifier.weight(1f),
)
}
}
}
@@ -15,9 +15,13 @@ import androidx.compose.foundation.layout.width
import androidx.compose.foundation.rememberScrollState
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Text
import androidx.compose.runtime.Composable
import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.getValue
import androidx.compose.runtime.key
import androidx.compose.runtime.mutableIntStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clip
@@ -51,6 +55,8 @@ import com.mikepenz.markdown.m3.markdownColor
import com.mikepenz.markdown.m3.markdownTypography
import com.mikepenz.markdown.model.markdownDimens
import com.mikepenz.markdown.model.markdownExtendedSpans
import com.mikepenz.markdown.model.rememberStreamingMarkdownState
import com.mikepenz.markdown.model.StreamingMarkdownState
import com.hermesandroid.relay.ui.theme.LocalBrand
import dev.snipme.highlights.Highlights
import dev.snipme.highlights.model.SyntaxThemes
@@ -66,6 +72,23 @@ fun MarkdownContent(
textColor: Color,
modifier: Modifier = Modifier
) {
ConfiguredMarkdownContent(
content = content,
textColor = textColor,
modifier = modifier,
)
}
@Composable
private fun ConfiguredMarkdownContent(
textColor: Color,
modifier: Modifier = Modifier,
content: String? = null,
streamingState: StreamingMarkdownState? = null,
) {
require((content == null) != (streamingState == null)) {
"Exactly one Markdown source must be provided"
}
val isDarkTheme = LocalBrand.current.isDark
val chatBodyStyle = MaterialTheme.typography.bodyMedium.copy(
fontSize = 15.sp,
@@ -75,109 +98,108 @@ fun MarkdownContent(
val highlightsBuilder = remember(isDarkTheme) {
Highlights.Builder().theme(SyntaxThemes.atom(darkMode = isDarkTheme))
}
Markdown(
content = content,
modifier = modifier,
// Code surfaces must contrast against the bubble (which is itself
// surfaceVariant for assistant turns) or code reads as invisible. The
// block uses the lowest container (a darker inset in dark themes, a
// clean white inset in light), inline code a subtle raised step.
colors = markdownColor(
text = textColor,
codeBackground = MaterialTheme.colorScheme.surfaceContainerLowest,
inlineCodeBackground = MaterialTheme.colorScheme.surfaceContainerHighest
),
// Chat-tuned type ramp. Left unset, the mikepenz M3 defaults map headings
// to DISPLAY roles (in this app's scale h1=displayLarge 57sp, h2=displayMedium
// ~45sp, h3=displaySmall 36sp) — a single `#` becomes a billboard inside the
// ~272dp bubble. Here every level derives from bodyLarge/bodyMedium (so the
// live font-picker still applies) and is capped so the largest heading is
// proportionate to the 15sp body, matching Discord / GitHub-mobile
// in-message headings.
typography = markdownTypography(
h1 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 20.sp, lineHeight = 26.sp, fontWeight = FontWeight.Bold, color = textColor,
),
h2 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 18.sp, lineHeight = 24.sp, fontWeight = FontWeight.Bold, color = textColor,
),
h3 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 16.sp, lineHeight = 22.sp, fontWeight = FontWeight.SemiBold, color = textColor,
),
h4 = MaterialTheme.typography.bodyMedium.copy(
fontSize = 15.sp, lineHeight = 20.sp, fontWeight = FontWeight.SemiBold, color = textColor,
),
h5 = MaterialTheme.typography.bodyMedium.copy(
fontWeight = FontWeight.Bold, color = textColor,
),
h6 = MaterialTheme.typography.bodyMedium.copy(
fontSize = 13.sp, fontWeight = FontWeight.SemiBold, letterSpacing = 0.4.sp,
color = textColor.copy(alpha = 0.85f),
),
// Prose, list items, and quotes share a 15sp/21sp reading rhythm.
// The library default 'text'/list role is bodyLarge (16sp), while
// bodyMedium was previously 14sp and unnecessarily small for long chat.
paragraph = chatBodyStyle,
text = chatBodyStyle,
bullet = chatBodyStyle,
ordered = chatBodyStyle,
list = chatBodyStyle,
quote = chatBodyStyle.copy(
fontStyle = FontStyle.Italic,
color = textColor.copy(alpha = 0.9f),
),
// Inline + fenced code at 13sp (one step under body, not two): monospace
// + the tinted chip already signal "code" without also shrinking it, and
// the loose 0.4sp default tracking is reset to 0 for tighter token runs.
code = MaterialTheme.typography.bodySmall.copy(
fontSize = 13.sp, letterSpacing = 0.sp,
fontFamily = FontFamily.Monospace,
color = textColor,
),
inlineCode = MaterialTheme.typography.bodyMedium.copy(
fontSize = 13.sp, letterSpacing = 0.sp,
fontFamily = FontFamily.Monospace, color = textColor,
),
// Links get an accent color + underline so they read as tappable on the
// muted assistant bubble (the default textLink is body-colored).
textLink = TextLinkStyles(
style = SpanStyle(
color = MaterialTheme.colorScheme.primary,
fontWeight = FontWeight.Medium,
textDecoration = TextDecoration.Underline,
),
),
),
// Tables get a phone-friendly minimum measure. The stock renderer uses
// one-line cells; our table component below keeps the same AST/inline
// annotator path but permits wrapping and exposes horizontal overflow.
dimens = markdownDimens(
tableCellWidth = 110.dp,
tableCellPadding = 12.dp,
),
components = markdownComponents(
codeBlock = {
SafeMarkdownHighlightedCodeBlock(
content = it.content,
node = it.node,
highlightsBuilder = highlightsBuilder,
showHeader = true
)
},
codeFence = {
SafeMarkdownHighlightedCodeFence(
content = it.content,
node = it.node,
highlightsBuilder = highlightsBuilder,
showHeader = true
)
},
table = { WideMarkdownTable(it) },
),
extendedSpans = markdownExtendedSpans {
remember { ExtendedSpans(RoundedCornerSpanPainter()) }
}
// Code surfaces must contrast against the assistant bubble. Keeping these
// exact values shared between static and streaming renderers prevents a
// typography/color change when a live turn completes.
val colors = markdownColor(
text = textColor,
codeBackground = MaterialTheme.colorScheme.surfaceContainerLowest,
inlineCodeBackground = MaterialTheme.colorScheme.surfaceContainerHighest,
)
val typography = markdownTypography(
h1 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 20.sp, lineHeight = 26.sp, fontWeight = FontWeight.Bold, color = textColor,
),
h2 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 18.sp, lineHeight = 24.sp, fontWeight = FontWeight.Bold, color = textColor,
),
h3 = MaterialTheme.typography.bodyLarge.copy(
fontSize = 16.sp, lineHeight = 22.sp, fontWeight = FontWeight.SemiBold, color = textColor,
),
h4 = MaterialTheme.typography.bodyMedium.copy(
fontSize = 15.sp, lineHeight = 20.sp, fontWeight = FontWeight.SemiBold, color = textColor,
),
h5 = MaterialTheme.typography.bodyMedium.copy(
fontWeight = FontWeight.Bold, color = textColor,
),
h6 = MaterialTheme.typography.bodyMedium.copy(
fontSize = 13.sp, fontWeight = FontWeight.SemiBold, letterSpacing = 0.4.sp,
color = textColor.copy(alpha = 0.85f),
),
paragraph = chatBodyStyle,
text = chatBodyStyle,
bullet = chatBodyStyle,
ordered = chatBodyStyle,
list = chatBodyStyle,
quote = chatBodyStyle.copy(
fontStyle = FontStyle.Italic,
color = textColor.copy(alpha = 0.9f),
),
code = MaterialTheme.typography.bodySmall.copy(
fontSize = 13.sp,
letterSpacing = 0.sp,
fontFamily = FontFamily.Monospace,
color = textColor,
),
inlineCode = MaterialTheme.typography.bodyMedium.copy(
fontSize = 13.sp,
letterSpacing = 0.sp,
fontFamily = FontFamily.Monospace,
color = textColor,
),
textLink = TextLinkStyles(
style = SpanStyle(
color = MaterialTheme.colorScheme.primary,
fontWeight = FontWeight.Medium,
textDecoration = TextDecoration.Underline,
),
),
)
val dimens = markdownDimens(tableCellWidth = 110.dp, tableCellPadding = 12.dp)
val components = markdownComponents(
codeBlock = {
SafeMarkdownHighlightedCodeBlock(
content = it.content,
node = it.node,
highlightsBuilder = highlightsBuilder,
showHeader = true,
)
},
codeFence = {
SafeMarkdownHighlightedCodeFence(
content = it.content,
node = it.node,
highlightsBuilder = highlightsBuilder,
showHeader = true,
)
},
table = { WideMarkdownTable(it) },
)
val extendedSpans = markdownExtendedSpans {
remember { ExtendedSpans(RoundedCornerSpanPainter()) }
}
if (streamingState != null) {
Markdown(
streamingMarkdownState = streamingState,
modifier = modifier,
colors = colors,
typography = typography,
dimens = dimens,
components = components,
extendedSpans = extendedSpans,
)
} else {
Markdown(
content = checkNotNull(content),
modifier = modifier,
colors = colors,
typography = typography,
dimens = dimens,
components = components,
extendedSpans = extendedSpans,
)
}
}
/**
@@ -291,39 +313,63 @@ private fun WideMarkdownTable(model: MarkdownComponentModel) {
fun StreamingMarkdownContent(
content: String,
textColor: Color,
isStreaming: Boolean = true,
modifier: Modifier = Modifier,
) {
if (isStreaming) {
// Keep one stable layout node for the entire live turn. Promoting each
// blank-terminated paragraph into Markdown replaced the Text subtree
// repeatedly; LazyColumn then exposed its fallback anchor for a frame,
// which looked like the whole chat reloaded. Updating this Text value
// only remeasures the growing bubble. Full Markdown is parsed once the
// owning row releases its stable live-tail layout.
Text(
// CommonMark ignores blank lines before the first block. The live
// Text renderer must do the same or a response whose transport
// prefix contains newlines appears to start several lines down.
// Preserve indentation on the first non-blank line so indented
// code and deliberately spaced prose are not altered.
text = content.withoutLeadingBlankLines(),
modifier = modifier,
style = MaterialTheme.typography.bodyMedium.copy(
fontSize = 15.sp,
lineHeight = 21.sp,
),
color = textColor,
)
} else {
MarkdownContent(
content = content,
var generation by remember { mutableIntStateOf(0) }
key(generation) {
NativeStreamingMarkdownGeneration(
content = content.withoutLeadingBlankLines(),
textColor = textColor,
modifier = modifier,
onResetRequired = { generation += 1 },
)
}
}
@Composable
private fun NativeStreamingMarkdownGeneration(
content: String,
textColor: Color,
modifier: Modifier,
onResetRequired: () -> Unit,
) {
val streamingState = rememberStreamingMarkdownState()
LaunchedEffect(content, streamingState) {
val plan = planStreamingMarkdownAppend(
renderedContent = streamingState.content.toString(),
nextContent = content,
)
if (plan.resetRequired) {
onResetRequired()
} else if (plan.delta.isNotEmpty()) {
streamingState.append(plan.delta)
}
}
ConfiguredMarkdownContent(
streamingState = streamingState,
textColor = textColor,
modifier = modifier,
)
}
internal data class StreamingMarkdownAppendPlan(
val resetRequired: Boolean,
val delta: String,
)
internal fun planStreamingMarkdownAppend(
renderedContent: String,
nextContent: String,
): StreamingMarkdownAppendPlan = if (nextContent.startsWith(renderedContent)) {
StreamingMarkdownAppendPlan(
resetRequired = false,
delta = nextContent.substring(renderedContent.length),
)
} else {
StreamingMarkdownAppendPlan(resetRequired = true, delta = "")
}
internal fun String.withoutLeadingBlankLines(): String {
var contentStart = 0
while (contentStart < length) {
@@ -42,6 +42,9 @@ import androidx.compose.runtime.setValue
import androidx.compose.runtime.snapshots.SnapshotStateList
import androidx.compose.ui.Alignment
import androidx.compose.ui.Modifier
import androidx.compose.ui.semantics.LiveRegionMode
import androidx.compose.ui.semantics.liveRegion
import androidx.compose.ui.semantics.semantics
import androidx.compose.ui.graphics.Color
import androidx.compose.ui.graphics.vector.ImageVector
import androidx.compose.ui.res.stringResource
@@ -252,6 +255,7 @@ private fun MessageRow(
Row(
modifier = Modifier
.fillMaxWidth()
.semantics { liveRegion = LiveRegionMode.Polite }
.heightIn(min = ROW_MIN_HEIGHT_DP.dp)
.padding(horizontal = 10.dp, vertical = 7.dp),
horizontalArrangement = Arrangement.spacedBy(9.dp),
@@ -1,7 +1,6 @@
package com.hermesandroid.relay.ui.components
import androidx.compose.animation.AnimatedVisibility
import androidx.compose.animation.animateContentSize
import androidx.compose.animation.expandVertically
import androidx.compose.animation.fadeIn
import androidx.compose.animation.fadeOut
@@ -27,6 +26,7 @@ import androidx.compose.foundation.layout.fillMaxHeight
import androidx.compose.foundation.layout.fillMaxWidth
import androidx.compose.foundation.layout.height
import androidx.compose.foundation.layout.padding
import androidx.compose.foundation.layout.offset
import androidx.compose.foundation.layout.size
import androidx.compose.foundation.layout.width
import androidx.compose.foundation.layout.widthIn
@@ -34,7 +34,6 @@ import androidx.compose.foundation.shape.CircleShape
import androidx.compose.ui.draw.clip
import androidx.compose.foundation.shape.RoundedCornerShape
import androidx.compose.foundation.text.selection.SelectionContainer
import androidx.compose.foundation.text.selection.DisableSelection
import androidx.compose.material.icons.Icons
import androidx.compose.material.icons.automirrored.filled.VolumeUp
import androidx.compose.material.icons.filled.ContentCopy
@@ -43,6 +42,7 @@ import androidx.compose.material.icons.filled.FormatQuote
import androidx.compose.material.icons.filled.Stop
import androidx.compose.material3.Icon
import androidx.compose.material3.IconButton
import androidx.compose.material3.HorizontalDivider
import androidx.compose.material3.MaterialTheme
import androidx.compose.material3.Surface
import androidx.compose.material3.Text
@@ -90,6 +90,7 @@ import java.text.SimpleDateFormat
import java.util.Date
internal const val CHAT_PET_IDENTITY_OBSTACLE_PREFIX = "chat-message-identity:"
private val MESSAGE_REACTIONS = listOf("❤️", "👍", "👎", "😂", "‼️", "❓")
@OptIn(ExperimentalFoundationApi::class)
@Composable
@@ -100,13 +101,6 @@ fun MessageBubble(
showThinking: Boolean = true,
isFirstInGroup: Boolean = true,
isLastInGroup: Boolean = true,
/**
* Keeps the current live tail on its stable Text layout while a final
* streaming frame commits. The owning list releases it immediately after
* completion so the same row transitions to full Markdown with its bottom
* anchor preserved.
*/
retainStreamingLayout: Boolean = false,
onCopyMessage: (String) -> Unit = {},
/**
* Select this message as a structured composer quote. Null hides Quote.
@@ -455,11 +449,51 @@ fun MessageBubble(
val showEditAction = onEditMessage != null && isUser
val showSpeakAction = shouldShowSpeakResponseAction(message, onSpeakMessage != null)
val showStopSpeakingAction = shouldShowStopSpeakingAction(message, onStopSpeaking != null)
val selectedUserReaction = message.reactions.firstOrNull { it.author == "user" }?.emoji
if (onQuoteMessage != null || onReact != null || showEditAction || showSpeakAction || showStopSpeakingAction) {
DropdownMenu(
expanded = showMessageActions,
onDismissRequest = { showMessageActions = false },
shape = RoundedCornerShape(24.dp),
containerColor = MaterialTheme.colorScheme.surfaceContainerHigh,
tonalElevation = 3.dp,
shadowElevation = 8.dp,
) {
if (onReact != null) {
Row(
horizontalArrangement = Arrangement.SpaceEvenly,
verticalAlignment = Alignment.CenterVertically,
modifier = Modifier
.fillMaxWidth()
.padding(horizontal = 4.dp, vertical = 6.dp),
) {
MESSAGE_REACTIONS.forEach { emoji ->
IconButton(
onClick = {
showMessageActions = false
onReact(emoji)
},
modifier = Modifier.background(
color = if (selectedUserReaction == emoji) {
MaterialTheme.colorScheme.secondaryContainer
} else {
Color.Transparent
},
shape = CircleShape,
),
) {
Text(
text = emoji,
fontSize = 24.sp,
modifier = Modifier.semantics {
contentDescription = "React with $emoji"
},
)
}
}
}
HorizontalDivider()
}
DropdownMenuItem(
text = { Text(stringResource(R.string.msg_bubble_copy)) },
onClick = {
@@ -515,32 +549,26 @@ fun MessageBubble(
},
)
}
if (onReact != null && selectedUserReaction != null) {
DropdownMenuItem(
text = { Text("Remove reaction") },
onClick = {
showMessageActions = false
onReact(null)
},
)
}
}
}
Box(
modifier = Modifier.padding(
bottom = if (message.reactions.isNotEmpty()) 8.dp else 0.dp,
),
) {
Surface(
shape = bubbleShape,
color = backgroundColor,
modifier = Modifier
.then(
if (!isUser && !isSystem &&
(message.isStreaming || retainStreamingLayout)
) {
// The frame-paced text node is already measured at its
// new size. Animate and clip the owning surface so a
// newly wrapped line is revealed inside the expanding
// bubble instead of drawing below the previous bounds
// for one frame. TopStart keeps existing prose fixed.
Modifier.animateContentSize(
animationSpec = tween(
durationMillis = 72,
easing = LinearOutSlowInEasing,
),
alignment = Alignment.TopStart,
)
} else {
Modifier
}
)
.then(
if (!isUser && !isSystem && isDarkTheme) {
Modifier.leftEdgeGlow(
@@ -558,7 +586,7 @@ fun MessageBubble(
// same tactile confirm every chat app fires.
haptic.performHapticFeedback(HapticFeedbackType.LongPress)
if (
onQuoteMessage != null || showEditAction || showSpeakAction ||
onQuoteMessage != null || onReact != null || showEditAction || showSpeakAction ||
showStopSpeakingAction
) {
showMessageActions = true
@@ -613,57 +641,29 @@ fun MessageBubble(
color = textColor
)
} else {
// Keep one plain Text node stable only while content is
// incomplete (plus the final committed live frame).
// Completion releases this flag and selects the full
// Markdown tree on the same stable message row.
// The renderer owns one incremental AST for the entire
// visible lifetime of this row. Stable and provisional
// blocks therefore use the same typography/components;
// completion is data state, not a renderer swap.
if (markdownBody.isNotEmpty()) {
StreamingMarkdownContent(
content = markdownBody,
textColor = textColor,
isStreaming = message.isStreaming || retainStreamingLayout,
)
}
}
}
// Compose's SelectionManager assumes that selectable IDs
// captured by a drag remain registered. Reset its owner when
// a live Text node becomes a Markdown tree, or settled
// Markdown content changes its node topology, so a handle
// cannot keep pointing at a removed selectable.
if (showSpeakAction || showStopSpeakingAction) {
DisableSelection { messageTextContent() }
} else {
key(
messageSelectionTopologyKey(
isPlainText = isUser || isSystem,
isStreaming = message.isStreaming,
retainStreamingLayout = retainStreamingLayout,
markdownBody = markdownBody,
),
) {
SelectionContainer { messageTextContent() }
}
// Voice actions live outside the message body and must never
// replace its selection owner. Speak becomes available exactly
// at completion; branching on it here recreated the complete
// incremental Markdown state for one frame.
key(
messageSelectionTopologyKey(
isPlainText = isUser || isSystem,
),
) {
SelectionContainer { messageTextContent() }
}
if (onReact != null) {
listOf("👍", "❤️", "😂").forEach { emoji ->
DropdownMenuItem(
text = { Text("React $emoji") },
onClick = {
showMessageActions = false
onReact(emoji)
},
)
}
DropdownMenuItem(
text = { Text("Remove reaction") },
onClick = {
showMessageActions = false
onReact(null)
},
)
}
if (onSessionReference != null && sessionReferences.isNotEmpty()) {
sessionReferences.forEach { reference ->
TextButton(
@@ -788,26 +788,39 @@ fun MessageBubble(
}
}
val hasTokenUsage = !isUser &&
(message.inputTokens != null || message.outputTokens != null)
// Timestamp — only on the LAST bubble of a same-author run so a
// burst of fragments doesn't stack three near-touching time labels.
// Grouping breaks on a >5min gap (ChatScreen), so every pause still
// surfaces its own time. Alpha floored at 0.6 for 11sp contrast.
// Reserve the footer from the first streaming frame so
// completion is a color-only transition and cannot resize the
// row. Hide the reserved timestamp from accessibility until it
// becomes visible.
// This row is reserved from the first streaming frame. Completion
// can reveal both timestamp and token usage without adding a new
// footer line or changing the bubble's measured height.
if (isLastInGroup) {
Spacer(modifier = Modifier.height(2.dp))
Text(
text = timeFormat.format(Date(message.timestamp)),
style = MaterialTheme.typography.labelSmall,
color = textColor.copy(alpha = if (message.isStreaming) 0f else 0.6f),
modifier = if (message.isStreaming) {
Modifier.clearAndSetSemantics { }
} else {
Modifier
},
)
Row(
horizontalArrangement = Arrangement.spacedBy(6.dp),
verticalAlignment = Alignment.CenterVertically,
) {
Text(
text = timeFormat.format(Date(message.timestamp)),
style = MaterialTheme.typography.labelSmall,
color = textColor.copy(alpha = if (message.isStreaming) 0f else 0.6f),
modifier = if (message.isStreaming) {
Modifier.clearAndSetSemantics { }
} else {
Modifier
},
)
if (hasTokenUsage) {
TokenDisplay(
inputTokens = message.inputTokens,
outputTokens = message.outputTokens,
)
}
}
}
// Delivery status — only on agent-Thread reply bubbles (a user
@@ -828,16 +841,30 @@ fun MessageBubble(
)
}
// Token display (assistant messages only)
if (!isUser && (message.inputTokens != null || message.outputTokens != null)) {
// Non-tail historical fragments have no reserved timestamp row.
// Preserve their existing standalone token metadata layout.
if (!isLastInGroup && hasTokenUsage) {
Spacer(modifier = Modifier.height(2.dp))
TokenDisplay(
inputTokens = message.inputTokens,
outputTokens = message.outputTokens
outputTokens = message.outputTokens,
)
}
}
}
if (message.reactions.isNotEmpty()) {
MessageReactionBadge(
reactions = message.reactions.map { it.emoji },
onOpen = onReact?.let { { showMessageActions = true } },
modifier = Modifier
.align(if (isUser) Alignment.BottomEnd else Alignment.BottomStart)
.offset(
x = if (isUser) (-10).dp else 10.dp,
y = 9.dp,
),
)
}
}
val inlineActions: @Composable () -> Unit = {
MessageInlineActions(
showQuote = onQuoteMessage != null,
@@ -890,6 +917,41 @@ fun MessageBubble(
} // end CompositionLocalProvider(LocalMediaBlurMode)
}
@OptIn(ExperimentalFoundationApi::class)
@Composable
private fun MessageReactionBadge(
reactions: List<String>,
onOpen: (() -> Unit)?,
modifier: Modifier = Modifier,
) {
val description = "Reactions: ${reactions.joinToString(" ")}"
Surface(
shape = RoundedCornerShape(12.dp),
color = MaterialTheme.colorScheme.surfaceContainerHighest,
tonalElevation = 2.dp,
shadowElevation = 2.dp,
modifier = modifier
.then(
if (onOpen != null) {
Modifier.combinedClickable(onClick = onOpen, onLongClick = onOpen)
} else {
Modifier
},
)
.semantics { contentDescription = description },
) {
Row(
horizontalArrangement = Arrangement.spacedBy(2.dp),
verticalAlignment = Alignment.CenterVertically,
modifier = Modifier.padding(horizontal = 7.dp, vertical = 3.dp),
) {
reactions.forEach { emoji ->
Text(text = emoji, fontSize = 14.sp, lineHeight = 16.sp)
}
}
}
}
@Composable
private fun MessageInlineActions(
showQuote: Boolean,
@@ -966,14 +1028,9 @@ internal data class MessageSelectionTopologyKey(
internal fun messageSelectionTopologyKey(
isPlainText: Boolean,
isStreaming: Boolean,
retainStreamingLayout: Boolean,
markdownBody: String,
): MessageSelectionTopologyKey = when {
isPlainText -> MessageSelectionTopologyKey(renderer = "plain", markdownBody = null)
isStreaming || retainStreamingLayout ->
MessageSelectionTopologyKey(renderer = "live", markdownBody = null)
else -> MessageSelectionTopologyKey(renderer = "markdown", markdownBody = markdownBody)
else -> MessageSelectionTopologyKey(renderer = "streaming-markdown", markdownBody = null)
}
/**
@@ -14,7 +14,6 @@ import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableFloatStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.withFrameNanos
import kotlinx.coroutines.delay
import androidx.compose.ui.Modifier
import androidx.compose.ui.draw.clipToBounds
import androidx.compose.ui.geometry.Offset
@@ -55,9 +54,6 @@ private const val SPHERE_TIME_UNITS_PER_SEC = 1f
private const val SPHERE_TWO_PI = 6.2832f
private const val SPHERE_COLOR_RADIANS_PER_SEC = 0.7854f
// Idle cadence: this delay plus the next frame wait nets a ~33ms period (~30fps).
private const val SPHERE_IDLE_FRAME_INTERVAL_MS = 25L
@Composable
fun MorphingSphere(
modifier: Modifier = Modifier,
@@ -108,19 +104,14 @@ fun MorphingSphere(
val cg2 by animateFloatAsState(targetC.g2, spec, label = "cg2")
val cb2 by animateFloatAsState(targetC.b2, spec, label = "cb2")
// Continuous motion is driven by a manual frame loop rather than
// rememberInfiniteTransition so the redraw rate can follow the orb's
// activity. An infinite transition pins the Canvas at the display refresh
// (120Hz) forever — even when Idle — which needlessly drains battery and,
// on Android 15, makes the platform log `setRequestedFrameRate` on every
// frame. Here we advance every frame while ACTIVE (full-smoothness
// thinking/streaming/voice pulse) and throttle to ~30fps while Idle, where
// the slower cadence is imperceptible for the chunky ASCII glyphs.
// dt-based accumulation keeps the animation speed identical at either rate.
// Continuous motion runs only for active agent/voice states. Idle is a
// stable frame: the 58x34 text grid is expensive enough that even a
// throttled cosmetic drift dominated measured screen-on CPU. Active states
// retain full display-rate motion and dt-based timing.
val animatedTime = remember { mutableFloatStateOf(0f) }
val animatedColorPhase = remember { mutableFloatStateOf(0f) }
val driveAnimation = fixedTime == null || fixedColorPhase == null
val fullFrameRate = state != SphereState.Idle || effVoiceMode
val driveAnimation = (fixedTime == null || fixedColorPhase == null) && fullFrameRate
if (driveAnimation) {
LaunchedEffect(fullFrameRate) {
var lastNanos = withFrameNanos { it }
@@ -133,7 +124,6 @@ fun MorphingSphere(
animatedColorPhase.floatValue =
(animatedColorPhase.floatValue + dtSec * SPHERE_COLOR_RADIANS_PER_SEC) %
SPHERE_TWO_PI
if (!fullFrameRate) delay(SPHERE_IDLE_FRAME_INTERVAL_MS)
}
}
}
@@ -146,6 +136,7 @@ fun MorphingSphere(
// Cache covers the ~25 distinct glyphs across charSets/dataChars/debrisChars.
val textMeasurer = rememberTextMeasurer(cacheSize = 64)
val glyphStrings = remember { HashMap<Char, String>(32) }
Canvas(modifier = modifier.fillMaxSize().clipToBounds()) {
val canvasW = size.width
@@ -176,7 +167,8 @@ fun MorphingSphere(
)
forEachSphereCell(frame) { cell ->
val layout = textMeasurer.measure(cell.char.toString(), style)
val glyph = glyphStrings.getOrPut(cell.char) { cell.char.toString() }
val layout = textMeasurer.measure(glyph, style)
// Legacy Paint used y as baseline (`row*cellH + cellH*0.8f`).
// Compose `drawText` uses top-left — offset by firstBaseline to match.
val px = cell.col * cellW
@@ -73,6 +73,7 @@ import com.hermesandroid.relay.data.ApiEndpoint
import com.hermesandroid.relay.data.Connection
import com.hermesandroid.relay.data.DashboardEndpoint
import com.hermesandroid.relay.data.EndpointCandidate
import com.hermesandroid.relay.network.shared.normalizeCredentialForHeader
import com.hermesandroid.relay.data.RelayEndpoint
import androidx.compose.ui.res.stringResource
import com.hermesandroid.relay.R
@@ -300,6 +301,11 @@ private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
} else {
decoded
}
val normalizedKey = normalizeCredentialForHeader(
decodedWithAliases.key,
"API credential",
)
val decodedWithSafeCredential = decodedWithAliases.copy(key = normalizedKey)
// TODO(security): verify `decoded.sig` against the server's HMAC
// secret once the pairing protocol exposes a public verification
@@ -310,12 +316,12 @@ private fun parseHermesRelayQr(raw: String): HermesPairingPayload? {
// Synthesize a single priority-0 candidate from the top-level fields
// when the wire payload didn't carry an explicit `endpoints` array.
// v3+ payloads with an explicit array pass through untouched.
if (decodedWithAliases.endpoints.isNullOrEmpty()) {
decodedWithAliases.copy(
endpoints = listOf(synthesizeLegacyEndpoint(decodedWithAliases)),
if (decodedWithSafeCredential.endpoints.isNullOrEmpty()) {
decodedWithSafeCredential.copy(
endpoints = listOf(synthesizeLegacyEndpoint(decodedWithSafeCredential)),
)
} else {
decodedWithAliases
decodedWithSafeCredential
}
} catch (_: Exception) {
null
@@ -396,10 +402,13 @@ private fun payloadFromApiUrl(
else -> return null
}
val host = uri.host?.takeIf { it.isNotBlank() } ?: return null
val normalizedKey = runCatching {
normalizeCredentialForHeader(apiKey, "API credential")
}.getOrNull() ?: return null
val payload = HermesPairingPayload(
host = host,
port = if (uri.port > 0) uri.port else 8642,
key = apiKey.trim(),
key = normalizedKey,
tls = tls,
dashboardUrl = dashboardUrl?.trim()?.takeIf { it.isNotBlank() },
relay = null,
File diff suppressed because it is too large Load Diff
@@ -0,0 +1,167 @@
package com.hermesandroid.relay.ui.components
import com.hermesandroid.relay.data.ChatSession
import com.hermesandroid.relay.data.SessionActivityState
import java.util.Locale
internal enum class SessionDrawerGrouping {
None,
Updated,
Project,
Status,
Profile,
}
internal enum class SessionDrawerOrdering {
Updated,
Created,
Title,
Status,
Tokens,
Cost,
}
internal enum class SessionDrawerStatus {
NeedsInput,
Working,
Idle,
}
internal enum class SessionDrawerPrState {
Open,
Draft,
Merged,
Closed,
None,
}
internal data class SessionDrawerViewOptions(
val grouping: SessionDrawerGrouping = SessionDrawerGrouping.None,
val ordering: SessionDrawerOrdering = SessionDrawerOrdering.Updated,
val statuses: Set<SessionDrawerStatus> = emptySet(),
val profiles: Set<String> = emptySet(),
val projects: Set<String> = emptySet(),
val pullRequests: Set<SessionDrawerPrState> = emptySet(),
val showProfile: Boolean = false,
val showUpdated: Boolean = true,
val showTokens: Boolean = false,
val showCost: Boolean = false,
)
internal data class SessionDrawerGroup(
val key: String,
val label: String?,
val rows: List<ProfileSessionRow>,
)
internal fun sessionRowKey(row: ProfileSessionRow): String =
"${row.profile.lowercase(Locale.ROOT)}:${row.session.sessionId}"
internal fun sessionProjectLabel(session: ChatSession): String {
val raw = (session.gitRepoRoot ?: session.workingDirectory)
?.trim()
?.trimEnd('/', '\\')
.orEmpty()
if (raw.isBlank()) return "No project"
return raw.substringAfterLast('/').substringAfterLast('\\').ifBlank { raw }
}
internal fun sessionDrawerStatus(
row: ProfileSessionRow,
activityStates: Map<String, SessionActivityState>,
): SessionDrawerStatus = when (
activityStates[sessionRowKey(row)] ?: activityStates[row.session.sessionId]
) {
SessionActivityState.NeedsInput -> SessionDrawerStatus.NeedsInput
SessionActivityState.Working -> SessionDrawerStatus.Working
null -> if (row.session.isActive) SessionDrawerStatus.Working else SessionDrawerStatus.Idle
}
internal fun sessionDrawerPrState(session: ChatSession): SessionDrawerPrState = when {
session.pullRequestNumber == null -> SessionDrawerPrState.None
session.pullRequestDraft -> SessionDrawerPrState.Draft
session.pullRequestState.equals("merged", ignoreCase = true) -> SessionDrawerPrState.Merged
session.pullRequestState.equals("closed", ignoreCase = true) -> SessionDrawerPrState.Closed
else -> SessionDrawerPrState.Open
}
internal fun filterAndSortSessionRows(
rows: List<ProfileSessionRow>,
options: SessionDrawerViewOptions,
activityStates: Map<String, SessionActivityState> = emptyMap(),
): List<ProfileSessionRow> {
val filtered = rows.asSequence()
.filter { options.statuses.isEmpty() || sessionDrawerStatus(it, activityStates) in options.statuses }
.filter { options.profiles.isEmpty() || it.profile in options.profiles }
.filter { options.projects.isEmpty() || sessionProjectLabel(it.session) in options.projects }
.filter { options.pullRequests.isEmpty() || sessionDrawerPrState(it.session) in options.pullRequests }
.toList()
val statusRank = mapOf(
SessionDrawerStatus.NeedsInput to 0,
SessionDrawerStatus.Working to 1,
SessionDrawerStatus.Idle to 2,
)
val comparator = when (options.ordering) {
SessionDrawerOrdering.Updated -> compareByDescending<ProfileSessionRow> { it.session.activityTimestamp }
SessionDrawerOrdering.Created -> compareByDescending { it.session.startTimestamp }
SessionDrawerOrdering.Title -> compareBy { it.session.title.orEmpty().lowercase(Locale.ROOT) }
SessionDrawerOrdering.Status -> compareBy { statusRank.getValue(sessionDrawerStatus(it, activityStates)) }
SessionDrawerOrdering.Tokens -> compareByDescending { it.session.totalTokens }
SessionDrawerOrdering.Cost -> compareByDescending { it.session.costUsd }
}
return filtered.sortedWith(
compareByDescending<ProfileSessionRow> { it.session.pinned }
.then(comparator)
.thenBy { it.session.title.orEmpty().lowercase(Locale.ROOT) },
)
}
internal fun groupSessionRows(
rows: List<ProfileSessionRow>,
grouping: SessionDrawerGrouping,
activityStates: Map<String, SessionActivityState> = emptyMap(),
nowMillis: Long = System.currentTimeMillis(),
): List<SessionDrawerGroup> {
if (rows.isEmpty()) return emptyList()
val grouped = rows.groupBy { row ->
when (grouping) {
SessionDrawerGrouping.None -> null
SessionDrawerGrouping.Updated -> updatedBucket(row.session.activityTimestamp, nowMillis)
SessionDrawerGrouping.Project -> sessionProjectLabel(row.session)
SessionDrawerGrouping.Status -> sessionDrawerStatus(row, activityStates).displayLabel
SessionDrawerGrouping.Profile -> row.profile
}
}
val groups = grouped.map { (label, groupRows) ->
SessionDrawerGroup(key = "${grouping.name}:$label", label = label, rows = groupRows)
}
return if (grouping == SessionDrawerGrouping.Project) {
groups.sortedWith(
compareBy<SessionDrawerGroup> { it.label != "No project" }
.thenByDescending { group -> group.rows.maxOfOrNull { it.session.activityTimestamp } ?: 0L }
.thenBy { it.label.orEmpty().lowercase(Locale.ROOT) },
)
} else {
groups
}
}
private val SessionDrawerStatus.displayLabel: String
get() = when (this) {
SessionDrawerStatus.NeedsInput -> "Needs input"
SessionDrawerStatus.Working -> "Working"
SessionDrawerStatus.Idle -> "Idle"
}
private fun updatedBucket(timestamp: Long, nowMillis: Long): String {
if (timestamp <= 0L) return "Older"
val age = (nowMillis - timestamp).coerceAtLeast(0L)
return when {
age < DAY_MILLIS -> "Today"
age < 2 * DAY_MILLIS -> "Yesterday"
age < 7 * DAY_MILLIS -> "Last 7 days"
else -> "Older"
}
}
private const val DAY_MILLIS = 24L * 60L * 60L * 1_000L
@@ -70,6 +70,8 @@ fun UnattendedAccessRow(
// should reflect that reality — otherwise users flip it and see no
// observable change, which reads as a broken control.
masterEnabled: Boolean = true,
screenControlAvailable: Boolean = true,
screenAccessUnlimited: Boolean = false,
) {
var showWarning by remember { mutableStateOf(false) }
var pendingEnableAfterWarning by remember { mutableStateOf(false) }
@@ -77,7 +79,7 @@ fun UnattendedAccessRow(
// "Effectively on" — the persisted preference AND the master gate.
// Drives the keyguard warning (no point showing it when master is
// off — the feature isn't active regardless of lock state).
val effectivelyOn = enabled && masterEnabled
val effectivelyOn = enabled && masterEnabled && screenControlAvailable
Card(
modifier = modifier.fillMaxWidth(),
@@ -104,6 +106,7 @@ fun UnattendedAccessRow(
Text(
text = when {
!masterEnabled -> stringResource(R.string.unattended_requires_master)
!screenControlAvailable -> stringResource(R.string.unattended_requires_timed_control)
enabled -> stringResource(R.string.unattended_on)
else -> stringResource(R.string.unattended_off)
},
@@ -113,7 +116,7 @@ fun UnattendedAccessRow(
}
Switch(
checked = enabled,
enabled = masterEnabled,
enabled = masterEnabled && screenControlAvailable,
onCheckedChange = { wantsOn ->
if (wantsOn && !warningSeen) {
// First enable → show the scary dialog and
@@ -129,7 +132,13 @@ fun UnattendedAccessRow(
}
Text(
text = stringResource(R.string.unattended_description),
text = stringResource(
if (screenAccessUnlimited) {
R.string.unattended_description_unlimited
} else {
R.string.unattended_description
},
),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
@@ -190,17 +190,23 @@ fun VoiceWaveform(
// Three phase accumulators driven by a single per-frame ticker. Phase
// velocity scales with the current amplitude so the wave visibly surges
// when the user speaks instead of running on its own fixed clock.
val phases = rememberAmplitudeDrivenPhases(phaseDurationsMs, displayAmplitude)
val waitingForOutputAudio = state == VoiceState.Speaking && !outputAudioActive
val processing = state == VoiceState.Transcribing ||
state == VoiceState.Thinking ||
waitingForOutputAudio
val waveformMotionActive = compactBars || state == VoiceState.Listening ||
(state == VoiceState.Speaking && outputAudioActive)
val phases = rememberAmplitudeDrivenPhases(
phaseDurationsMs,
displayAmplitude,
active = waveformMotionActive,
)
val waveformUnfold by animateFloatAsState(
targetValue = if (processing) 0f else 1f,
animationSpec = tween(durationMillis = 360),
label = "waveformUnfold",
)
val spinnerPhase = rememberProcessingSpinnerPhase(processing)
val spinnerPhase = rememberProcessingSpinnerPhase(active = processing)
val canvasModifier = if (compactBars) {
modifier.height(height)
@@ -361,10 +367,12 @@ fun VoiceWaveform(
private fun rememberAmplitudeDrivenPhases(
baseDurationsMs: IntArray,
amplitude: Float,
active: Boolean,
): FloatArray {
val ampRef = rememberUpdatedState(amplitude)
var phases by remember { mutableStateOf(FloatArray(baseDurationsMs.size)) }
LaunchedEffect(Unit) {
LaunchedEffect(active) {
if (!active) return@LaunchedEffect
val twoPi = (2f * PI).toFloat()
// Precompute base angular velocities (rad/s) so we don't divide on
// every frame. Each wave's full cycle at silence = durationMs.
@@ -400,9 +408,9 @@ private fun rememberAmplitudeDrivenPhases(
@Composable
private fun rememberProcessingSpinnerPhase(active: Boolean): Float {
val activeRef = rememberUpdatedState(active)
var phase by remember { mutableStateOf(0f) }
LaunchedEffect(Unit) {
LaunchedEffect(active) {
if (!active) return@LaunchedEffect
var prevNanos = 0L
while (true) {
withFrameNanos { nanos ->
@@ -412,9 +420,7 @@ private fun rememberProcessingSpinnerPhase(active: Boolean): Float {
}
val dtSec = (nanos - prevNanos) / 1_000_000_000f
prevNanos = nanos
if (activeRef.value) {
phase = (phase + dtSec * 220f) % 360f
}
phase = (phase + dtSec * 220f) % 360f
}
}
}
@@ -0,0 +1,34 @@
package com.hermesandroid.relay.ui.components.avatar
import com.hermesandroid.relay.viewmodel.connection.ProfileController
import java.io.File
/** Adapt upstream `pet.info` geometry to the existing bounded sprite renderer. */
fun ProfileController.HermesPetPresentation.toAvatar(): PetAvatar? {
val sheet = File(spritesheetPath)
if (!sheet.isFile || frameWidth <= 0 || frameHeight <= 0 || framesPerState <= 0) return null
val fps = (framesPerState * 1000f / loopMs.coerceAtLeast(1)).coerceIn(1f, 60f)
val clips = stateRows.mapIndexedNotNull { row, name ->
val normalized = name.trim().takeIf { it.isNotEmpty() } ?: return@mapIndexedNotNull null
val count = (framesByRow[normalized] ?: framesByState[normalized] ?: framesPerState)
.coerceIn(1, framesPerState)
normalized to PetClipSpec(
sheet = sheet.name,
frameWidth = frameWidth,
frameHeight = frameHeight,
frameCount = count,
startFrame = row * framesPerState,
fps = fps,
)
}.toMap()
if (clips["idle"] == null) return null
return runCatching {
PetSpec(
id = "hermes:$slug",
label = displayName,
description = "Profile-scoped Hermes animated pet",
reactive = PetReactiveSpec(voice = false, tools = true, intensity = true),
states = clips,
).toAvatar(sheet.parentFile ?: return null)
}.getOrNull()
}
@@ -61,6 +61,9 @@ import androidx.lifecycle.LifecycleEventObserver
import androidx.lifecycle.compose.LocalLifecycleOwner
import com.hermesandroid.relay.data.BridgeSafetyPreferencesRepository
import com.hermesandroid.relay.data.BridgeSafetySettings
import com.hermesandroid.relay.bridge.BridgeCapability
import com.hermesandroid.relay.bridge.BridgeCapabilityPolicy
import com.hermesandroid.relay.bridge.BridgeSafetyManager
import com.hermesandroid.relay.data.DEFAULT_BLOCKLIST
import com.hermesandroid.relay.data.MAX_AUTO_DISABLE_MINUTES
import com.hermesandroid.relay.data.MAX_CONFIRMATION_TIMEOUT_SECONDS
@@ -85,11 +88,18 @@ import kotlinx.coroutines.launch
*/
@OptIn(ExperimentalMaterial3Api::class)
@Composable
fun BridgeSafetySettingsScreen(onBack: () -> Unit) {
fun BridgeSafetySettingsScreen(
connectionId: String? = null,
onBack: () -> Unit,
) {
val context = LocalContext.current
val scope = rememberCoroutineScope()
val repo = remember { BridgeSafetyPreferencesRepository(context) }
val settings by repo.settings.collectAsState(initial = BridgeSafetySettings())
val safetyManager = BridgeSafetyManager.peek()
val capabilityPolicy by (safetyManager?.capabilityPolicy(connectionId)
?: remember { kotlinx.coroutines.flow.MutableStateFlow(BridgeCapabilityPolicy()) })
.collectAsState(initial = BridgeCapabilityPolicy())
// Overlay-permission live check — recompute on resume so returning
// from Settings flips the switch's availability without nav churn.
@@ -140,6 +150,22 @@ fun BridgeSafetySettingsScreen(onBack: () -> Unit) {
verticalArrangement = Arrangement.spacedBy(16.dp),
) {
CapabilityGrantCards(
policy = capabilityPolicy,
timerMinutes = settings.autoDisableMinutes,
enabled = safetyManager != null && connectionId != null,
onPermanentChanged = { capability, allowed ->
scope.launch {
safetyManager?.setPermanentCapability(connectionId, capability, allowed)
}
},
onTimedChanged = { capability, allowed ->
scope.launch {
safetyManager?.setTimedCapability(connectionId, capability, allowed)
}
},
)
// ── Blocklist ───────────────────────────────────────────────
SectionCard(title = stringResource(R.string.bss_blocked_apps)) {
Text(
@@ -359,6 +385,152 @@ fun BridgeSafetySettingsScreen(onBack: () -> Unit) {
}
}
@Composable
internal fun CapabilityGrantCards(
policy: BridgeCapabilityPolicy,
timerMinutes: Int,
enabled: Boolean,
onPermanentChanged: (BridgeCapability, Boolean) -> Unit,
onTimedChanged: (BridgeCapability, Boolean) -> Unit,
) {
SectionCard(title = stringResource(R.string.bridge_access_read_group)) {
Text(
text = stringResource(R.string.bridge_access_read_group_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
if (!enabled) {
Text(
text = stringResource(R.string.bss_capabilities_unavailable),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.error,
modifier = Modifier.padding(top = 8.dp),
)
}
Spacer(Modifier.size(8.dp))
listOf(
BridgeCapability.DEVICE_INFO,
BridgeCapability.CONTACTS_READ,
BridgeCapability.LOCATION_READ,
BridgeCapability.CLIPBOARD_READ,
).forEach { capability ->
val allowed = capability in policy.permanentGrants
CapabilityRow(
capability = capability,
checked = allowed,
stateLabel = stringResource(
if (allowed) R.string.bss_capability_always else R.string.bss_capability_never,
),
enabled = enabled,
onCheckedChange = { onPermanentChanged(capability, it) },
)
}
}
SectionCard(title = stringResource(R.string.bridge_access_actions_group)) {
Text(
text = stringResource(R.string.bridge_access_actions_group_desc),
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Spacer(Modifier.size(8.dp))
listOf(
BridgeCapability.CLIPBOARD_WRITE,
BridgeCapability.MEDIA_CONTROL,
BridgeCapability.COMMUNICATIONS,
BridgeCapability.OUTBOUND_SHARING,
).forEach { capability ->
val allowed = capability in policy.permanentGrants
CapabilityRow(
capability = capability,
checked = allowed,
stateLabel = stringResource(
if (allowed) R.string.bss_capability_always else R.string.bss_capability_never,
),
enabled = enabled,
onCheckedChange = { onPermanentChanged(capability, it) },
)
}
}
SectionCard(title = stringResource(R.string.bss_timed_capabilities_title)) {
val now = System.currentTimeMillis()
val activeScreenCapabilities = BridgeCapability.entries
.filter { it.timed && policy.allows(it, now) }
val hasUnlimited = activeScreenCapabilities.any(policy::isUnlimited)
Text(
text = when {
hasUnlimited -> stringResource(R.string.bss_screen_access_unlimited_desc)
activeScreenCapabilities.isNotEmpty() ->
stringResource(R.string.bss_timed_capabilities_desc, timerMinutes)
else -> stringResource(R.string.bss_screen_access_off_desc, timerMinutes)
},
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
Spacer(Modifier.size(8.dp))
BridgeCapability.entries.filter { it.timed }.forEach { capability ->
val active = (policy.expiryFor(capability) ?: 0L) > now
CapabilityRow(
capability = capability,
checked = active,
stateLabel = when {
policy.isUnlimited(capability) ->
stringResource(R.string.bridge_timed_until_off)
active -> stringResource(R.string.bss_capability_timed_on)
else -> stringResource(R.string.bss_capability_timed_off)
},
enabled = enabled,
onCheckedChange = { onTimedChanged(capability, it) },
)
}
}
}
@Composable
private fun CapabilityRow(
capability: BridgeCapability,
checked: Boolean,
stateLabel: String,
enabled: Boolean,
onCheckedChange: (Boolean) -> Unit,
) {
Row(
modifier = Modifier.fillMaxWidth(),
verticalAlignment = Alignment.CenterVertically,
) {
Column(modifier = Modifier.weight(1f).padding(vertical = 6.dp)) {
Text(
text = stringResource(capability.titleResource()),
style = MaterialTheme.typography.bodyLarge,
)
Text(
text = stateLabel,
style = MaterialTheme.typography.bodySmall,
color = MaterialTheme.colorScheme.onSurfaceVariant,
)
}
Switch(
checked = checked,
enabled = enabled,
onCheckedChange = onCheckedChange,
)
}
}
private fun BridgeCapability.titleResource(): Int = when (this) {
BridgeCapability.DEVICE_INFO -> R.string.bss_capability_device_info
BridgeCapability.CONTACTS_READ -> R.string.bss_capability_contacts
BridgeCapability.LOCATION_READ -> R.string.bss_capability_location
BridgeCapability.CLIPBOARD_READ -> R.string.bss_capability_clipboard_read
BridgeCapability.CLIPBOARD_WRITE -> R.string.bss_capability_clipboard_write
BridgeCapability.MEDIA_CONTROL -> R.string.bss_capability_media
BridgeCapability.COMMUNICATIONS -> R.string.bss_capability_communications
BridgeCapability.OUTBOUND_SHARING -> R.string.bss_capability_sharing
BridgeCapability.SCREEN_INSPECTION -> R.string.bss_capability_screen_inspection
BridgeCapability.SCREEN_CONTROL -> R.string.bss_capability_screen_control
}
@Composable
private fun SectionCard(title: String, content: @Composable () -> Unit) {
Card(
@@ -44,6 +44,7 @@ import androidx.compose.runtime.LaunchedEffect
import androidx.compose.runtime.collectAsState
import androidx.compose.runtime.getValue
import androidx.compose.runtime.mutableStateOf
import androidx.compose.runtime.mutableLongStateOf
import androidx.compose.runtime.remember
import androidx.compose.runtime.setValue
import androidx.compose.ui.Alignment
@@ -61,12 +62,23 @@ import androidx.lifecycle.viewmodel.compose.viewModel
// === PHASE3-safety-rails: safety summary card ===
import com.hermesandroid.relay.bridge.BridgeSafetyManager
import com.hermesandroid.relay.data.BridgeSafetySettings
import com.hermesandroid.relay.bridge.BridgeCapabilityPolicy
import com.hermesandroid.relay.ui.components.BridgeSafetySummaryCard
// === END PHASE3-safety-rails ===
import com.hermesandroid.relay.ui.LocalSnackbarHost
import com.hermesandroid.relay.ui.components.BridgeActivityLog
import com.hermesandroid.relay.ui.components.BridgeMasterToggle
import com.hermesandroid.relay.ui.components.BridgePermissionChecklist
import com.hermesandroid.relay.ui.components.BridgeAccessPreset
import com.hermesandroid.relay.ui.components.BridgeAccessSetupSheet
import com.hermesandroid.relay.ui.components.BridgeAgentAccessCard
import com.hermesandroid.relay.ui.components.BridgeAndroidAccessSummaryCard
import com.hermesandroid.relay.ui.components.BridgeTimedAccessSheet
import com.hermesandroid.relay.ui.components.BridgeSelectedAndroidAccessCard
import com.hermesandroid.relay.ui.components.READ_CONFIRMED_BRIDGE_CAPABILITIES
import com.hermesandroid.relay.ui.components.READ_ONLY_BRIDGE_CAPABILITIES
import com.hermesandroid.relay.ui.components.activeTimedCapabilities
import com.hermesandroid.relay.ui.components.bridgeAndroidAccessSummary
import com.hermesandroid.relay.ui.components.RelayChromeIconButton
import com.hermesandroid.relay.ui.components.RelayHeroPanel
import com.hermesandroid.relay.ui.components.RelayReturnStrip
@@ -84,13 +96,15 @@ import kotlinx.coroutines.launch
* Bridge tab — phase 3 Wave 1 rewrite (Agent bridge-ui, `bridge-screen-ui`).
*
* Replaces the Phase 0 "Coming Soon" placeholder with the real control
* surface described in `Plans/Phase 3 — Bridge Channel.md` §5. Four stacked
* cards in a verticalScroll column:
* surface described in `Plans/Phase 3 — Bridge Channel.md` §5. The main page
* is a summary-first cockpit with complete drill-downs:
*
* 1. [BridgeMasterToggle] — "Allow Agent Control" + live status
* 2. [BridgePermissionChecklist] — accessibility / capture / overlay / notif
* 3. [BridgeActivityLog] — scrollable recent-command history
* 4. Safety placeholder — stub owned by Agent safety-rails in Wave 2
* 1. [BridgeMasterToggle] — global kill switch + live device status
* 2. [BridgeAgentAccessCard] — permanent and screen-access policy posture
* 3. Unattended access — single authoritative sideload control
* 4. Android readiness summary — selected requirements + expandable full matrix
* 5. Advanced safety controls — complete power-user controls
* 6. [BridgeActivityLog] — scrollable recent-command history
*
* State comes from [BridgeViewModel] which in turn reads from the
* [com.hermesandroid.relay.data.BridgePreferencesRepository] DataStore for
@@ -151,6 +165,9 @@ fun BridgeScreen(
// === END PHASE3-safety-rails-followup ===
val context = LocalContext.current
val accessScope = androidx.compose.runtime.rememberCoroutineScope()
val accessSavedMessage = stringResource(R.string.bridge_access_saved_review_android)
val timedAccessEndedMessage = stringResource(R.string.bridge_timed_ended_snackbar)
// Result callback used by every runtime-permission launcher on this screen.
// If the user has permanently denied the permission (two declines on
@@ -197,6 +214,63 @@ fun BridgeScreen(
val trustedVerbs by (safetyManager?.trustedDestructiveVerbs
?: remember { kotlinx.coroutines.flow.MutableStateFlow<Set<String>>(emptySet()) })
.collectAsState()
val activeConnectionId by (connectionViewModel?.activeConnectionId
?: remember { kotlinx.coroutines.flow.MutableStateFlow<String?>(null) })
.collectAsState()
val activeCapabilityPolicy by (safetyManager?.activeCapabilityPolicy
?: remember { kotlinx.coroutines.flow.MutableStateFlow(BridgeCapabilityPolicy()) })
.collectAsState()
val screenControlAvailable = activeCapabilityPolicy.allows(
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_CONTROL,
System.currentTimeMillis(),
)
val screenControlUnlimited = activeCapabilityPolicy.isUnlimited(
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_CONTROL,
)
val screenAccessActive = activeCapabilityPolicy.activeTimedCapabilities(
System.currentTimeMillis(),
).isNotEmpty()
val anyScreenAccessUnlimited = activeCapabilityPolicy.activeTimedCapabilities(
System.currentTimeMillis(),
).any(activeCapabilityPolicy::isUnlimited)
val overlayRequired = screenControlAvailable ||
com.hermesandroid.relay.bridge.BridgeCapability.COMMUNICATIONS in
activeCapabilityPolicy.permanentGrants ||
com.hermesandroid.relay.bridge.BridgeCapability.OUTBOUND_SHARING in
activeCapabilityPolicy.permanentGrants
var nowMs by remember { mutableLongStateOf(System.currentTimeMillis()) }
if (autoDisableAtMs != null) {
LaunchedEffect(autoDisableAtMs) {
while (true) {
nowMs = System.currentTimeMillis()
kotlinx.coroutines.delay(1_000L)
}
}
}
val androidAccessSummary = bridgeAndroidAccessSummary(
policy = activeCapabilityPolicy,
status = permissionStatus,
nowMs = nowMs,
)
var permissionsExpanded by remember { mutableStateOf(false) }
var showSetupSheet by remember { mutableStateOf(false) }
var selectedPreset by remember { mutableStateOf(BridgeAccessPreset.READ_ONLY) }
var showTimedSheet by remember { mutableStateOf(false) }
var timedInspect by remember { mutableStateOf(true) }
var timedControl by remember { mutableStateOf(true) }
var timedMinutes by remember { mutableStateOf(safetySettings.autoDisableMinutes) }
var timedUnlimited by remember { mutableStateOf(false) }
val timedCurrentlyActive = activeCapabilityPolicy.activeTimedCapabilities(nowMs).isNotEmpty()
fun openTimedSheet() {
val current = activeCapabilityPolicy.activeTimedCapabilities(nowMs)
timedInspect = if (current.isEmpty()) true else
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_INSPECTION in current
timedControl = if (current.isEmpty()) true else
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_CONTROL in current
timedMinutes = safetySettings.autoDisableMinutes
timedUnlimited = current.any(activeCapabilityPolicy::isUnlimited)
showTimedSheet = true
}
// === END PHASE3-safety-rails ===
// Re-run permission + system-status probes whenever the screen resumes.
@@ -328,6 +402,7 @@ fun BridgeScreen(
// needed and the nag would confuse users + reviewers.
if (BuildFlavor.isSideload &&
masterToggle &&
overlayRequired &&
!permissionStatus.overlayPermitted
) {
OverlayPermissionNagCard(
@@ -397,58 +472,20 @@ fun BridgeScreen(
stringResource(R.string.bridge_enable_bridge_mode),
)
// 2. Permissions — prerequisites come before advanced features.
BridgePermissionChecklist(
status = permissionStatus,
// === PHASE3-safety-rails-followup: in-app permission Test handlers ===
onTestAccessibility = { viewModel.testAccessibilityService() },
onTestScreenCapture = { viewModel.testScreenCapture() },
onTestOverlay = { viewModel.testOverlayPermission() },
// === END PHASE3-safety-rails-followup ===
// === PHASE3-bridge-ui-followup: extended interactions ===
onRequestScreenCapture = { viewModel.requestScreenCapture() },
onTestNotificationListener = { viewModel.testNotificationListener() },
// === END PHASE3-bridge-ui-followup ===
onRequestNotifications = if (Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU) {
// Same "tap always goes to Settings" treatment as the
// other runtime-permission rows. The master-toggle
// auto-request path (BridgeMasterToggle onToggle) still
// uses the launcher directly since that's a programmatic
// flow where a dialog is appropriate.
{ openAppDetailsSettings(context) }
} else null,
// === v0.4.1 polish: runtime-permission row taps go to Settings ====
// Earlier iteration tried launcher.launch(permission) with a
// post-denial fallback to app-details Settings. That
// fallback depended on (context as? Activity) succeeding
// which quietly returned null in the Compose context chain
// — so taps after a permanent denial were a silent no-op.
// Simpler + matches user expectation: tap ALWAYS opens the
// app-details Settings page. Parity with Accessibility /
// Notification Listener / Overlay rows which also open
// Settings unconditionally. First-time grant is one extra
// tap vs. a system dialog — acceptable trade-off for
// "tap always does something visible".
onRequestMicrophone = { openAppDetailsSettings(context) },
onRequestCamera = { openAppDetailsSettings(context) },
onRequestContacts = { openAppDetailsSettings(context) },
onRequestSms = { openAppDetailsSettings(context) },
onRequestPhone = { openAppDetailsSettings(context) },
onRequestLocation = { openAppDetailsSettings(context) },
// === END v0.4.1 polish ====
// 2. Capability policy stays visible directly under the master.
// Detailed toggles remain one tap away on the full safety screen.
BridgeAgentAccessCard(
policy = activeCapabilityPolicy,
nowMs = nowMs,
onSetUp = { showSetupSheet = true },
onManage = onNavigateToBridgeSafety,
onAllowScreen = { openTimedSheet() },
)
// 3. Advanced section — unattended access + safety. Sideload
// only — these features don't exist on googlePlay (no wake
// lock, no destructive-verb routes).
// 3. One authoritative unattended control, kept beside the
// access policy it extends. Do not duplicate this state inside
// Agent access or Advanced: one switch owns one mode.
if (BuildFlavor.isSideload) {
AdvancedSectionHeader()
// 4. Unattended access — a SUB-FEATURE of the master
// toggle. Gated: Switch is non-interactive when the
// master toggle is off so users can't flip it and
// observe nothing happening (the acquire path
// short-circuits when master is off anyway).
UnattendedAccessRow(
enabled = unattendedEnabled,
warningSeen = unattendedWarningSeen,
@@ -456,15 +493,76 @@ fun BridgeScreen(
onToggle = { viewModel.setUnattendedAccessEnabled(it) },
onWarningSeen = { viewModel.markUnattendedWarningSeen() },
masterEnabled = masterToggle,
screenControlAvailable = screenControlAvailable,
screenAccessUnlimited = screenControlUnlimited,
)
}
// 5. Safety summary — auto-disable, destructive verbs,
// blocklist. Belongs adjacent to unattended because
// they share the "advanced / opt-in / sideload-only"
// mental model.
// 4. Android permission state is summarized against the selected
// policy. Expanding preserves the complete existing matrix and
// every Settings/Test action—no power-user surface is removed.
BridgeAndroidAccessSummaryCard(
summary = androidAccessSummary,
expanded = permissionsExpanded,
onToggle = { permissionsExpanded = !permissionsExpanded },
)
if (permissionsExpanded) {
BridgeSelectedAndroidAccessCard(
summary = androidAccessSummary,
onOpenAccessibility = {
runCatching {
context.startActivity(
Intent(Settings.ACTION_ACCESSIBILITY_SETTINGS).apply {
addFlags(Intent.FLAG_ACTIVITY_NEW_TASK)
},
)
}
},
onOpenAppSettings = { openAppDetailsSettings(context) },
onOpenOverlay = {
runCatching {
context.startActivity(
Intent(
Settings.ACTION_MANAGE_OVERLAY_PERMISSION,
Uri.parse("package:${context.packageName}"),
).apply { addFlags(Intent.FLAG_ACTIVITY_NEW_TASK) },
)
}
},
)
BridgePermissionChecklist(
status = permissionStatus,
onTestAccessibility = { viewModel.testAccessibilityService() },
onTestScreenCapture = { viewModel.testScreenCapture() },
onTestOverlay = { viewModel.testOverlayPermission() },
onRequestScreenCapture = { viewModel.requestScreenCapture() },
onTestNotificationListener = { viewModel.testNotificationListener() },
onRequestNotifications = if (
Build.VERSION.SDK_INT >= Build.VERSION_CODES.TIRAMISU
) {
{ openAppDetailsSettings(context) }
} else null,
onRequestMicrophone = { openAppDetailsSettings(context) },
onRequestCamera = { openAppDetailsSettings(context) },
onRequestContacts = { openAppDetailsSettings(context) },
onRequestSms = { openAppDetailsSettings(context) },
onRequestPhone = { openAppDetailsSettings(context) },
onRequestLocation = { openAppDetailsSettings(context) },
)
}
// 5. Advanced safety controls. Sideload only — these features
// don't exist on googlePlay (no destructive-verb routes).
if (BuildFlavor.isSideload) {
AdvancedSectionHeader()
// Safety summary — auto-disable, destructive verbs,
// blocklist, and the complete granular editor.
BridgeSafetySummaryCard(
settings = safetySettings,
autoDisableAtMs = autoDisableAtMs,
screenAccessActive = screenAccessActive,
screenAccessUnlimited = anyScreenAccessUnlimited,
onManage = onNavigateToBridgeSafety,
)
@@ -492,6 +590,102 @@ fun BridgeScreen(
Spacer(modifier = Modifier.height(16.dp))
}
}
if (showSetupSheet) {
BridgeAccessSetupSheet(
selected = selectedPreset,
onSelected = { selectedPreset = it },
onDismiss = { showSetupSheet = false },
onContinue = {
when (selectedPreset) {
BridgeAccessPreset.CUSTOM -> {
showSetupSheet = false
onNavigateToBridgeSafety()
}
BridgeAccessPreset.READ_ONLY,
BridgeAccessPreset.READ_CONFIRMED -> accessScope.launch {
val grants = if (selectedPreset == BridgeAccessPreset.READ_ONLY) {
READ_ONLY_BRIDGE_CAPABILITIES
} else {
READ_CONFIRMED_BRIDGE_CAPABILITIES
}
safetyManager?.replacePermanentCapabilities(activeConnectionId, grants)
showSetupSheet = false
permissionsExpanded = true
snackbarHost.showSnackbar(accessSavedMessage)
}
}
},
)
}
if (showTimedSheet) {
BridgeTimedAccessSheet(
inspectEnabled = timedInspect,
controlEnabled = timedControl,
durationMinutes = timedMinutes,
unlimited = timedUnlimited,
accessibilityReady = permissionStatus.accessibilityServiceEnabled,
overlayReady = permissionStatus.overlayPermitted,
currentlyActive = timedCurrentlyActive,
onInspectChanged = { timedInspect = it },
onControlChanged = { timedControl = it },
onDurationChanged = { timedMinutes = it },
onUnlimitedChanged = { timedUnlimited = it },
onOpenAccessibility = {
runCatching {
context.startActivity(
Intent(Settings.ACTION_ACCESSIBILITY_SETTINGS).apply {
addFlags(Intent.FLAG_ACTIVITY_NEW_TASK)
},
)
}
},
onOpenOverlay = {
runCatching {
context.startActivity(
Intent(
Settings.ACTION_MANAGE_OVERLAY_PERMISSION,
Uri.parse("package:${context.packageName}"),
).apply { addFlags(Intent.FLAG_ACTIVITY_NEW_TASK) },
)
}
},
onDismiss = { showTimedSheet = false },
onAllow = {
accessScope.launch {
val capabilities = buildSet {
if (timedInspect) add(
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_INSPECTION,
)
if (timedControl) add(
com.hermesandroid.relay.bridge.BridgeCapability.SCREEN_CONTROL,
)
}
viewModel.setTimedAccessMinutes(timedMinutes)
safetyManager?.replaceTimedCapabilities(
activeConnectionId,
capabilities,
timedMinutes,
unlimited = timedUnlimited,
)
showTimedSheet = false
}
},
onEndNow = {
accessScope.launch {
safetyManager?.replaceTimedCapabilities(
activeConnectionId,
emptySet(),
timedMinutes,
)
viewModel.setUnattendedAccessEnabled(false)
showTimedSheet = false
snackbarHost.showSnackbar(timedAccessEndedMessage)
}
},
)
}
}
/**

Some files were not shown because too many files have changed in this diff Show More