ARIA
597a28050f
TLS: fingerprint-confirm flow for self-signed gateway certs (issue #14 )
...
CI / Gateway plugin tests (push) Successful in 5m29s
CI / Kotlin tests (android host + desktop) (push) Successful in 7m22s
docs/09 §9.4 promised a SSH-host-key-style fingerprint confirm on first
pair, but the app built a default OkHttpClient with no certificate
handling — self-signed gateway certs were simply rejected.
Build the flow:
- TlsPinning.kt: PinningTrustManager wraps the platform default trust
manager; a rejected cert is accepted only when its SHA-256 fingerprint
matches the user-confirmed pin, anything else fails with
TlsFingerprintRequired (hostname verification still applies).
- SecureStore.pinnedCertFingerprint (Android EncryptedSharedPreferences +
desktop settings.json), cleared on forget().
- GatewayClient: pinning socket factory on the shared client (all legs
inherit it), new terminal State.TlsConfirmRequired, unwrap the nested
TlsFingerprintRequired in connect loop / watchdog / SSE / poll /
testHello.
- ConnectScreen: confirm dialog showing the fingerprint ("Confirm &
pin" re-runs the connect); IrisApp routes TlsConfirmRequired there;
ChatScreen + desktop tray handle the new state.
- Docs: §9.4 now describes the real flow (incl. SAN requirement), gap
table item 6 → implemented, setup.md limitation note updated.
- Tests: TlsPinningTest (fingerprint vs openssl, pin accept/reject,
live pin read, unwrap) + TlsPinningIntegrationTest (real TLS
handshake: unpinned → confirm data, pinned → 200).
Live E2E verified on the phone: first pair against a self-signed
IRIS_HTTP_CERT gateway shows the dialog, confirm pins, chat works,
auto-reconnect after gateway restart uses the pin.
2026-08-24 21:30:42 +02:00
ARIA
3a33f6be15
formatting changes
CI / Gateway plugin tests (push) Successful in 4m43s
CI / Kotlin tests (android host + desktop) (push) Successful in 6m58s
2026-08-22 11:07:24 +02:00
ARIA
7309158e12
Add Gitea CI + release workflows (CI-SETUP.md)
...
CI / Gateway plugin tests (push) Failing after 2m6s
CI / Kotlin tests (android host + desktop) (push) Failing after 4m51s
- .gitea/workflows/ci.yml: gateway plugin tests + Kotlin host tests on
push/PR (hermes-agent cloned at pinned SHA, vendored test mirror)
- .gitea/workflows/release.yml: manual dispatch; runs tests, builds signed
Android APK (debug fallback) + Linux desktop app-image/deb via jpackage,
creates Gitea release v<version> with artifacts (re-run safe)
- androidApp: versionName from -PappVersion, CI release signing from
ANDROID_KEYSTORE_* env vars
- desktopApp: jpackage --app-version from -PappVersion
- scripts/make_release_keystore.sh: one-time keystore + Gitea secret setup
- vendor gateway-plugin/tests/test_android.py (byte-identical mirror) and
ignore it in .pi-lens.json
2026-08-22 03:32:07 +02:00
ARIA
96b60daf08
Update dependencies to latest + migrate to AGP 9.x
...
Kotlin 2.1.0->2.4.10, Compose Multiplatform 1.7.3->1.11.1, AGP 8.7.3->9.3.1, Gradle 8.10.2->9.7.1. The two libs that pinned us to Compose 1.7.x -- compose-webview-multiplatform (1.9.40->2.0.3) and multiplatform-markdown-renderer (0.33.0->0.44.0) -- now have Compose 1.8+ releases, so the whole stack moves. Also coroutines/serialization 1.11.0, okhttp 5.5.0, media3 1.11.0, activity-compose 1.13.0, firebase-messaging 25.1.2, compose-bom 2026.08.00, google-services 4.5.0, KCEF 2025.03.23 (JBR pin ->17.0.14); material3 1.9.0 / material-icons-extended 1.7.3 (each one's latest stable -- they lag the core).
AGP 9 migration: :shared swaps com.android.library->com.android.kotlin.multiplatform.library (android config moves into kotlin{android{}}, withHostTest{} keeps host tests); :androidApp drops kotlin(android) for AGP 9 built-in Kotlin. compileSdk 34->37 (minSdk stays 29 / Android 10).
Code fixes for API breaks: markdown link->textLink + highlights->highlightsBuilder; kotlinOptions{jvmTarget}->compilerOptions{jvmTarget}.
2026-08-21 12:14:09 +02:00
ARIA
7ba5632a03
HTML artifacts: render agent-sent HTML/CSS/JS code blocks in an in-app WebView (Android platform WebView, desktop JCEF/KCEF) via a full-screen preview; artifact card with Preview button + code toggle, shown only once the message stops streaming; webview-multiplatform 1.9.40 + KCEF deps, detection + unit tests
2026-08-21 00:43:39 +02:00
ARIA
1ec705727a
App icon: winged-bubble adaptive icon (Android) + window/jpackage icon (desktop); concept art in app/icons/
2026-08-20 19:48:57 +02:00
ARIA
0cc8b7aafe
M6: desktop app (tray, two-pane layout, shortcuts, inspector, jpackage)
2026-08-19 20:43:47 +02:00
ARIA
218c50d688
M1+M2: gateway core loop + agent transparency
...
M1 (gateway core loop / text round-trip):
- WS server (ws_server.py): bind, hello auth (constant-time), hello.ack, heartbeat, connection registry
- pairing.py: token generation, pairing store, QR payload
- adapter.py: send() -> message frame; inbound message.send -> MessageEvent -> handle_message
- app: Connect screen, GatewayClient (connect + reconnect), ChatScreen send/render, SecureStore (Android/Desktop)
- tests/ws_probe.py: probe harness driving a real turn
M2 (streaming + reasoning + tools + commentary):
- protocol.py: M2 frame types (message.start/update/stop, tool.start/progress/end, commentary)
- adapter.py: per-chat turn-state machine; classify outbound into frames; _split_reasoning; tool-line parsing
- reasoning in streaming: capture via on_stream_delta hook (kind=reasoning, gated by plugins.stream_reasoning_deltas) with a FIFO barrier, attach to message.stop
- app: live streaming bubble, ReasoningBlock (collapse + copy), ToolCard (Everything/Truncated/Nothing), dimmed commentary, typing
- docs/14-milestones.md: M1/M2 marked done; reasoning note corrected
2026-08-19 13:56:19 +02:00
ARIA
59acf66c89
M0: toolchain, monorepo scaffold, gateway plugin skeleton, CMP app
...
- gateway-plugin/: android platform plugin (plugin.yaml + adapter.py
register(ctx) + no-op AndroidAdapter) + stub modules for M1-M5
- app/: Compose Multiplatform project (shared KMP + androidApp +
desktopApp) with Gradle wrapper; builds :androidApp:assembleDebug
and :desktopApp:compileKotlin
- scripts/guard_hermes_agent.sh + pre-commit hook: fail if hermes-agent/
is staged (read-only reference, never committed)
- .gitignore excludes hermes-agent/; docs/ reference library
2026-08-19 11:27:02 +02:00