fix: qualify mobile Cloud viewer and companion downloads

This commit is contained in:
archipelago
2026-10-05 14:41:08 -04:00
parent daac47cac4
commit 5aa74d0513
22 changed files with 1173 additions and 197 deletions
+117
View File
@@ -1425,3 +1425,120 @@ Nostr additions. The checker now rejects stale descriptions/dates for an existin
version; its regression passes. Latest notes UI built and deployed dev/yaya index
SHA256 `97aab07e67eccc1bb3d215534b537b83e1372bf5c36b505b6127a24a2b629e23`.
Phone background/reconnect acceptance question is pending, not passed.
## Mobile Cloud media viewer — 2026-10-05 release addition
Operator screenshot shows the filename behind the companion status bar and a
cramped video viewer. Confirmed mobile CSS positioned every toolbar button at the
same coordinates; fullscreen was only attached to a video double-click, and the
viewer ignored the companion's `--safe-area-top/bottom` values. Legacy global
lightbox maximum dimensions also constrained the component unexpectedly.
The viewer now reserves separate safe-area-aware title, media and action rows on
phones, keeps each action at least44px without shrinking, and places previous/next
beside the action row rather than over the media. Videos retain their intrinsic
picture ratio with native playback controls. Photos and videos have a labeled
fullscreen action: standard fullscreen where supported, native Safari video
fallback, and an expandable in-page viewer when embedded browsers deny it.
Escape/exit and keyboard focus remain usable. Decode failures offer retry, and
late media requests cannot replace a newly selected file or leak their blob URL.
Validation:11component tests pass, including existing PiP handoff, fullscreen
success/denial/Safari fallback, decode retry, fetch ordering and focus restoration.
Real Chromium checks at320x568,390x844,844x390 and1440x900 pass safe-area/control
geometry, fullscreen and exit, generated video playback and close. Screenshots
were inspected. This does not claim physical companion/Safari acceptance.
Evidence: `/tmp/archy-190-lightbox-focused.log`,
`/tmp/archy-190-lightbox-browser.log`; repeatable browser fixture
`tests/lifecycle/media-lightbox-browser.cjs`.
The operator separately accepted both physical phone upload background/reconnect
and Framework Cloud folder/upload/open checks. Those upload manual gates are
closed; this newly reported media viewer gate is separate. The ongoing candidate
ISO and staged OTA predate this addition and must not be published as final;
regenerate final artifacts and hashes after this fix is qualified.
### Permanent file menus and companion fullscreen follow-up
The operator additionally reported that touch users cannot reach hover-only file
actions without opening the file. Grid and list cards now have a permanent44px
translucent ellipsis action, and owned-file lightboxes expose the same menu.
Share/download/delete are available without opening the underlying file; delete
requires a separate explicit confirmation. Unsupported actions are omitted for
non-owned callers. The menu stays within the viewport, participates in native
fullscreen, traps keyboard focus, dismisses on Escape/outside tap and restores
focus. Cloud-folder delete failures now remain visible instead of becoming an
unhandled rejected promise.
Sixteen focused component tests pass. Real Chromium grid/list touch checks pass
at320,390and1440px, covering permanent visibility, unclipped menus, share and
cancelled delete with no preview triggered. Lightbox action access also passes
inside fullscreen at all four prior viewport sizes. The actual deployed dev
Cloud screenshot and3840x2160video decode successfully (75.633seconds, no media
error); native Chromium fullscreen/exit/close pass. No operator files changed.
The Android companion has no existing `onShowCustomView` implementation. Added a
shared fullscreen host to both dashboard and app WebViews: retains the current
WebView, accepts Chromium's custom view, hides system bars with swipe escape,
handles Back and Chromium exit, restores prior bars, releases the view on screen
disposal and rejects duplicate/reparented requests. Kotlin compilation passes.
Companion version0.5.33/build53 is reserved for this change. Lifecycle tests,
clean signed APK build and physical companion acceptance remain required; the
web fallback is not evidence of native Android fullscreen acceptance.
Updated qualification: all **1,222 frontend tests / 150 files** pass, production
build passes, and the permanent menus are deployed on the dev box. Live browser
checks pass for real Cloud photo/video decode, card-menu access without preview,
cancelled deletion, and the viewer's action menu during fullscreen. No files were
deleted or shared by the tests. Android's three lifecycle tests pass (zero errors
or failures). The clean APK build initially failed because the expected signing
keystore was absent. Recovered the existing local key after matching its public
certificate exactly to the currently served APK; a clean packaging retry is in
progress. No replacement signing identity was generated, and no private signing
material is included in this change.
Companion packaging exposed an additional release-script defect: noisy successful
`apksigner` output caused `printf | grep -q` under `pipefail` to return141/SIGPIPE,
rejecting an APK whose v1/v2/v3 verification results were all true. The publisher
now uses input redirection for these checks and additionally pins the existing
companion certificate, protecting in-place update compatibility. Four executable
regressions exercise the actual verification block: large valid output, missing
signature schemes, wrong signer and verifier failure. All pass; the test is
included in `tests/release/run.sh`. A fresh canonical clean/package/sign run is
required after this script fix; no failed packaging attempt is marked published.
### Companion download regression — operator report after build53
The operator accepted the improved viewer, then reported Download did nothing,
confirmed companion-only. Real Chromium downloaded the exact Cloud screenshot
bytes (202,648 bytes; matching SHA256), so this is separate from the web menu.
Both companion WebViews lack a general DownloadListener. Added a shared native
Save dialog/download handler, with bounded streaming, existing WebView cookies,
progress, cancellation and deletion of the newly created incomplete destination
on failure. Redirects retain cookies only for the starting origin, HTTPS
downgrades are rejected, and authentication/login-page failures do not save an
error page as the user's file. TLS verification stays enabled. No broad storage
permission is introduced. Blob/data URLs currently report unsupported instead of
silently doing nothing; own Cloud files use authenticated HTTP(S) raw URLs.
Companion0.5.34/build54 is reserved for this repair. Compile, network regression
suite, canonical clean signing, dev deployment and a real phone download remain
required. Build53 must not be described as having working companion downloads.
The existing fullscreen suite also passed its Android28+35 matrix: six cases,
zero failures/errors. No release or APK fleet publication has occurred.
Download validation update: the sequential clean Android build and all12tests
pass (six network-download cases plus six fullscreen lifecycle cases across
Android28/35). Tests cover exact authenticated bytes/progress, same-origin versus
cross-origin redirects, bounded redirects, unsupported URLs, auth failure,
cancellation, destination failure, TLS downgrade refusal and login HTML rejection.
XML evidence was preserved before packaging in
`/tmp/archy-190-companion-download-test-results/`. The canonical clean0.5.34/build54
APK package passes v1/v2/v3 verification and the existing signing-certificate pin;
the APK contains the new download handler. Fleet publication remains held pending
physical save/open acceptance and the existing release gates.
2026-10-05 operator acceptance: companion0.5.34/build54 phone download check
(save/open/cancel) accepted: “works, we can proceed”. Viewer and physical upload
acceptance retained. Close this manual gate; other release/security/Angor gates
remain open. No fleet OTA, ISO or public demo publication inferred.
+63 -21
View File
@@ -12,19 +12,18 @@ whenever human acceptance is needed.
## Current evidence
- Latest alpha backend source: isolated suite 1,681 passed, zero failed,
four explicit ignores; separate container runtime suite 82 passed. Optimized
build including the Nostr security and File Browser changes is in progress.
- Frontend: full suite 1,211 passed across 148 files; production UI and AIUI
builds passed. Real dev desktop/mobile upload fault injection passes, including
interrupted JWT refresh and exact saved-file hashes.
- Currently deployed backend on dev/yaya SHA256
`e218e40f5c16c3d0cc4dc06c0a378c14b56b9087ded5c515b8a48351ceea3bcf`.
It includes Nostr/File Browser fixes but predates the alpha version suffix.
Private rollback backups exist.
- Latest deployed UI index SHA256 on dev/yaya
`67de835a25db59a483314eff583b809c3468c8529080bfa74c9962e44a6f54f9`.
Both served byte checks pass; unrelated production containers stayed unchanged.
- Alpha backend: isolated suite **1,681 passed**, zero failed, four explicit
ignores; separate container runtime suite **82 passed**. Optimized binary
SHA256 `a5a6cfc7dcab011963a6f18dc570446b6fa624180d206a108fab27504f4fd41d`
is deployed on dev, yaya and Framework with private rollback backups.
- Frontend: **1,222 passed across 150 files**; production build and real mobile/
desktop media/menu checks pass. Dev serves index SHA256
`c18b24024a78789fe65c74c5ce27efe2125ae869016ab65e33c5a2680b543f17`.
Yaya/Framework still have the preceding qualified upload UI `67de835a…`.
- Companion **0.5.34/build54**: 12 native tests, clean build, v1/v2/v3 signatures
and unchanged signer pass. Viewer and phone download are operator accepted.
Dev APK SHA256 `ceb58a7dc5f1398fe84f30255ec9ed79834f5db5f8fbc03eac52e14186fab1a1`.
Fleet publication remains part of the final release.
- NPM corrected gateway/client-IP integration: 23 Python checks and complete
disposable real-image integration passed. Catalog generator now requires both
migration-backup and legacy-gateway capabilities; its generator/drift selection
@@ -41,9 +40,10 @@ whenever human acceptance is needed.
- [ ] **NPM:** corrected private signature, dev/yaya selection and yaya override
retirement now PASS (2026-10-05). Remaining: full boot/OTA/ISO and
staging-CA issuance/renewal and full legacy-backend migration/rollback
full legacy-backend migration/rollback
acceptance; retain the completed
fresh/nested disposable and actual yaya state-preservation checks.
fresh/nested disposable, public staging issuance/forced renewal and actual
yaya state-preservation checks.
- [ ] **Shorty NPM:** shop certificate12/Force SSL are operator accepted and
independently verified; qualify and apply the manual-route migration. Preserve live
management containment and current public app routing.
@@ -56,14 +56,14 @@ whenever human acceptance is needed.
No production spending or channel closure is authorized by this checklist.
- [ ] **Paid files:** finish buyer restart/outage and updated-seller persistence
acceptance; preserve atomic ownership and safe retries without repayment.
- [ ] **Uploads:** prior physical companion flow is operator accepted. New
resumable-transfer requirement needs interrupted-network/background
recovery acceptance; viewport checks alone are not physical-phone proof.
- [x] **Uploads:** real dev/yaya interrupted-network, offset recovery, lost
replies, hashes, cancellation and compact origin-screen display pass.
Physical companion background/reconnect and Framework Cloud flow are
operator accepted. Final packaged-artifact checks remain below.
- [ ] **File Browser credentials:** unique managed login, default-password
removal, account/file preservation and rollback pass real Podman fixtures
including actual Quadlet restart. Deploy/verify dev and yaya, rerun yaya
upload tests, qualify Framework's reported auth issue, and verify packaged
OTA/ISO startup. Docker behavior is not inferred from Podman fixtures.
including actual Quadlet restart. Dev/yaya/Framework migration and Cloud
acceptance pass. Remaining: packaged OTA/ISO startup. Docker behavior is not inferred from Podman fixtures.
- [ ] **Apps:** complete upgrade inventory matrix for installed/stopped/removed/
restarting/legacy aliases; Immich/retired-app removal and unexpected-service
identification; Portainer/Gitea migration from actual request namespace.
@@ -517,3 +517,45 @@ reported1.8.8. Existing Docker Compose demo deployment located read-only; do not
confuse it with Yaya's v4v stack. Update after release, preserving rollback and
qualifying mock backend compatibility with new Cloud uploads. No demo deployed yet.
No OTA/catalog/ISO has been published.
## 2026-10-05 additional mobile media and file-action qualification
Operator accepted both physical phone upload recovery and Framework Cloud
folder/upload/open checks. These manual gates are closed.
A subsequent Cloud screenshot and touch-action report introduced new release
requirements: safe-area-aware photo/video viewing, separated touch controls,
fullscreen/exit, permanent translucent file-card actions, and the same actions
inside the viewer. Source and component tests are in the regression ledger.
The complete updated frontend suite passes: **1,222 tests in 150 files**.
Production frontend build passes. Chromium checks cover phone portrait,
landscape and desktop geometry, native fullscreen, action-menu access while
fullscreen, video decoding/playback, no accidental preview from a menu tap,
and cancellation before deletion. The deployed dev box reads the operator's
actual screenshot and 4K video without changing either file.
The new Android fullscreen callback implementation compiles and its three
Robolectric lifecycle tests pass with zero failures/errors. It still requires a
clean APK, signature verification and physical companion acceptance; compilation
and browser fullscreen do not establish that acceptance. Version 0.5.33/build53
is reserved for the companion update. No native fullscreen APK published yet.
Final OTA/frontend/ISO checksums and source attribution must be regenerated after
these additions. Candidate ISO build215 is superseded for publication purposes.
Previously recorded NPM fleet migration, exact signed OTA/rollback and ISO install
qualification, full-chain/Angor scope, mirror parity and public-demo requirements
remain open unless separately closed by direct evidence. No prior publication
hold is waived by the mobile test results.
### Companion download qualification update
Operator accepted the viewer but reported companion-only download failure.
Browser download of the same file matches its exact bytes. Added native saving
through Android's system file picker with authentication, streamed progress,
cancellation and error cleanup. The clean download/fullscreen suite passes all
12cases. Canonical clean companion0.5.34/build54 packaging passes v1/v2/v3 and
existing-signer verification. Dev serving is verified byte-for-byte with SHA256
`ceb58a7dc5f1398fe84f30255ec9ed79834f5db5f8fbc03eac52e14186fab1a1`.
The operator reports “works, we can proceed” after the phone save/open/cancel
check. This physical companion download gate is **accepted (2026-10-05)**. The APK is staged for fleet OTA/ISO and official/demo downloads;
only the dev-box test download is updated now. No fleet/public release is claimed.