Cold widget taps waited on TOP-resume (never fires for the
translucent trampoline) plus a DataStore consent read, costing
seconds and spurious app-opens when the read timed out. Fire from
onResume, cache consent in SharedPreferences, keep the first 15s
of banner on the stock template (now with Pause/Save/Discard
actions) until RemoteViews inflation is warm.
- Theme: derive primaryContainer from accent in both schemes (other container-tinted surfaces follow accent now)
- Home FAB: explicit containerColor=primary so button color == accent_color exactly
- Settings: hide 'Reset to default' on non-editable settings (App version showed it and threw 'not editable')
The custom RemoteViews layouts hard-set @color/shonar_widget_text (white)
for the dark navy card, but SystemUI paints the notification card with the
SYSTEM theme: in light mode the card is pale lavender and the title,
file name, and timer rendered white-on-white.
Add @color/notif_text = ink by default, #E6EDF3 in values-night, and use
it in notification_recording, notification_recording_small, and
notification_confirm_delete. The widget keeps its own white text (it paints
its own navy background).
On-device (Pixel 8 Pro, night=no): recording card text is dark-on-light;
zero white text pixels in the card region (was washed-out white before).
- ensureForeground() posts the FGS banner at the top of onStartCommand on a
cold-start START only (was: every action -> raced stopForeground(REMOVE)
and re-flipped the discard-confirm card back to the plain card)
- MediaRecorder prepare()/start() moved to Dispatchers.IO (StrictMode:
disk I/O was on the main thread); start failure reverts UI
- discardRecording() tears the banner down synchronously before stopSelf()
so a scope cancel in onDestroy can't leave a ghost notification
- ensureChannel() memoized + legacy channel cleanup kept (one IPC pass per
process instead of per call)
- restore migrateRestoreTimes() + runCatching around refreshRoot() in
Application.onCreate (dropped accidentally during timing instrumentation)
- Home screen: Column+verticalScroll -> LazyColumn with keyed items
- Notification layouts: explicit textColor for lockscreen/shade legibility
- Widget tap PendingIntent: FLAG_RECEIVER_FOREGROUND for prompt delivery
- All ShonarTiming instrumentation probes removed
On-device (Pixel 8 Pro): widget tap -> banner ~195ms; recording file grows
in .in-progress/; Discard->No survives, Discard->Yes removes service, temp,
and notification with nothing left live; no StrictMode recorder violation.
- buildConfirm had card buttons + addAction row: shade showed
green No/Yes plus black-text No/Yes pair (seen 2026-09-15)
- Keep only the card buttons; no system actions on any recording card
- Test now asserts zero system actions
- Post the foreground notification once on start (skip the duplicate
nm.notify that restarted SystemUI RemoteViews inflation).
- Collapsed shade row is a slim header-only card (lock shade clips
taller cards); expanded keeps the pills card. Restore
DecoratedCustomViewStyle (without it the system drops both custom
views and expansion breaks) plus a custom heads-up view.
- Fallback template leads with the timer; drop the SHONAR subtext
('SHONAR x SHONAR' header) and the system action row duplicating
the pills.
- Recording channel is DEFAULT: no heads-up banner pinning the shade
item expanded on every record start.
- Regression tests lock each behavior in
RecordingNotificationLayoutTest.
Phantom audio (playing with no UI and no way to stop it) is gone:
- New PlaybackController owns the single MediaPlayer process-wide.
Home rows and details mirror the same state; a generation counter
ignores stale async-prepare callbacks from rapid re-taps.
- Ongoing 'Now playing' notification with a Stop action works even
with the app closed (receiver clears card + releases player).
- Details keeps seek/speed UI on top of the shared player.
Fluidity (measured on-device, release build):
- StrictMode caught 192ms DateFormat disk I/O inside composition
(details info card) + library scans on the main thread. Date is
pre-formatted in the ViewModel on IO; scans moved to Dispatchers.IO.
- Detail-open on release: 84 frames, 1 janky (1.2%), p99 31ms
(was 6-8 janky, p99 ~130ms on debug).
Also: storage-access prompt card (fresh installs lose the file
grant; guides to system Settings), release signing via local
keystore (passwords in ~/.gradle/gradle.properties, key ignored
by git), default save name is now 'Recording - <date>'.
Phone is now a pure on-device recorder: no accounts, no servers, no
background uploads (INTERNET permission gone). File sync is the user's
own tooling; the library adopts externally added files.
Android:
- Delete provider package (Nextcloud, custom SHONAR, sync-folder,
registry, auth, TOFU/TLS), sync stack (SyncWorker/Drain/Slots,
MigrationRunner), provider/storage/folder UI, AI-via-server details.
- Home shows a fixed 'on this phone' library; details keep playback,
rename, file info. Settings lose Network/provider/HTTP-logging.
- Library root is the stored folder or Music/Recordings; import is
double-scan proof (mutex + unique filePath index, migration v3->v4
dedupes by path) with regression tests.
- Drop okhttp/work/security-crypto/media deps; delete their tests.
Repo: backend/, desktop/, worker/, deploy/, shared/, server scripts
and docs removed; README rewritten; CI keeps the android job only.
The working tree had reverted RecordingNotificationHelper to plain
system MediaStyle, which renders the small 'SHONAR - SHONAR' text row
with truncated filename and no big timer. Restore the user-verified
custom RemoteViews card (mic + Recording + filename + big timer, X /
pause / check pills, same view collapsed and expanded) and drop the
non-compiling MediaSession dead code from RecordingService
(unresolved activeNotifId / mediaSession / alertOnce references).
Add RecordingNotificationLayoutTest to fail the build if MediaStyle
is reintroduced or the timer/pills leave the layout.
Backend:
- PUT /recordings/{id}/transcript and /summary — user-edited, versioned;
the pipeline never clobbers user versions
- Model registry (tiny/base/small/medium/large-v3), global default via
PUT /models/default (future rows only), per-recording override on
finalize/upload-session (finalize wins), GET /api/v1/models
- processing_jobs gain stage/progress; faster-whisper model cache +
fail-fast on unavailable models; migration m8models000001
- 10 model tests + 5 transcript-edit tests (backend suite 64 green, ruff clean)
Android:
- detail/{id} route: transcript/summary/status tabs, tap-to-seek, speed
control, edit dialogs, title rename via CustomShonarProvider AI methods
- pure AiContent parsing/sync mapping; honest empty states for
local-only/unsynced rows; 19 new unit tests (Android suite green)
- server_url setting deleted (no code referenced it; it predated the
provider pivot and misled users into pasting Nextcloud URLs into a
field nothing reads). The provider-selection flow (P2) replaces it.
- Wi-Fi-only / charging-only uploads now carry a description stating
they apply once a sync provider is connected.
Verified: 47 unit tests green, APK builds, on-device (Pixel 8 Pro)
Settings > Network shows no SHONAR server URL field and the new
descriptions render.
ISOLATE (nothing deleted):
- moved HA module (ha/, ui/devices/, HA client tests), e2e scripts, and HA
docs under deferred/home-assistant/ with a README explaining status + how
to revive; complete snapshot preserved on branch deferred/home-assistant
REMOVE FROM ACTIVE PRODUCT:
- HomeScreen: Devices card + route gone; MainActivity nav updated
- ShonarApplication: haRepository removed
- BuiltInSettings: Home Assistant category/settings removed from defaults
- SettingsManagerTest: secret tests rewritten around a user-created
SECRET-type setting (no built-in secret ships)
- Manifest + URL-validation test fixture wording neutralized
- README/ROADMAP: HA marked deferred with pointer to preserved branch
ADD (design, per product direction):
- docs/server-providers.md: ShonarProvider interface, Room data model,
auth ladder (OIDC/PKCE -> Nextcloud login-flow-v2 -> token paste),
sync strategy, provider-selection UX (Nextcloud default; Start9/Umbrel
as platform-probe + explicit service binding, never universal APIs;
custom SHONAR server; local-only), TLS TOFU pinning policy,
no-secret-logging rules, provider contract test strategy, phased plan P0-P7
VERIFY: 19 Android unit tests green, APK builds, on-device launch OK
(consent dialog renders; no Devices entry). Backend unchanged (26 tests).
Generic settings architecture (data-driven, no per-setting UI code):
- SettingDefinition (id/name/description/category/type/default/min/max/
choices/editable/sensitive/requiresRestart/visibleIf) x 8 types:
boolean/string/number/select/multi-select/color/url/secret
- SettingsManager: validation, reset, custom CRUD, export/import
(all-or-nothing with per-key rejection reasons; custom definitions
travel in the export), secrets routed to EncryptedSharedPreferences
(AndroidKeyStore master key) and excluded from export by default
- Settings screen renders controls from the type; search; add/edit/delete
dialogs for custom settings; import/export dialogs
- Built-ins: General / Home Assistant / Appearance / Network / Advanced
Home Assistant integration (official REST + WebSocket APIs only):
- HomeAssistantClient: GET /api/, /api/states, /api/states/{id},
POST /api/services/{domain}/{service}, WS /api/websocket
(auth -> subscribe_events state_changed) with exponential-backoff
reconnect; safe HaError types that never contain the token
- HaRepository: single service layer between UI and client; optimistic
toggles reconciled by WS; poll fallback from refresh-interval setting
- Devices screen: discovery list, search, live states, toggles
(light/switch/fan/input_boolean/humidifier)
- Cleartext permitted for LAN http:// URLs (same stance as the official
HA companion app; TLS verification untouched); consent dialog on first
launch; Record button present but inert until M4 (honest label)
- Tests: 29 unit tests (19 settings incl. secret routing, import
validation, persistence; 10 HA via MockWebServer incl. 401 handling,
unreachable, WS handshake + event + auth_invalid). All green.
Docs: docs/home-assistant.md (install, token creation, storage,
troubleshooting, endpoint table); README + ROADMAP updated honestly
(live e2e against a real HA server still in progress).